data protection
Privacy policy
1.0 Data protection at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit our website. Personal data is any data with which you can be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.
Data collection on our website
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.
How do we collect your data?
Your data is collected in part by you providing it to us. This may include, for example, data that you enter into a contact form.
Other data is automatically collected when you visit the website by our IT systems. This mainly includes technical data (e.g. internet browser, operating system, or time of page access). The collection of this data occurs automatically as soon as you enter our website.
What do we use your data for?
Some of the data is collected to ensure error-free provision of the website. Other data can be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to receive free information about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction, blocking, or deletion of this data. For this and other questions on the subject of data protection, you can contact us at any time at the address given in the imprint. Furthermore, you have the right to complain to the competent supervisory authority.
Use of a live support system
On this website, your shared chat content is collected and stored for processing your request for the purpose of operating a live chat system to answer live inquiries. Cookies are used to operate the chat function. Cookies are small text files stored locally in the cache of the visitor's internet browser. The cookies enable the recognition of the visitor's internet browser to distinguish between individual users of the chat function on our website.
If the information collected in this way contains personal data, processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in effective customer support and the statistical analysis of user behavior for optimization purposes.
To avoid storing cookies, you can configure your internet browser so that no cookies can be stored on your computer in the future or already stored cookies are deleted. However, disabling all cookies may result in the chat function on our website no longer working.
Analysis tools and third-party tools
When visiting our website, your surfing behavior may be statistically evaluated. This is done primarily with cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information can be found in the following privacy policy.
You can object to this analysis. We will inform you about the options for objection in this privacy policy.
2. General information and mandatory information
Data protection
The operators of this site take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the legal data protection regulations as well as this privacy policy.
When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This privacy policy explains which data we collect and what we use them for. It also explains how and for what purpose this happens.
We point out that data transmission over the Internet (e.g., when communicating by e-mail) can have security vulnerabilities. Complete protection of data from access by third parties is not possible.
Note on the responsible entity
The responsible entity for data processing on this website is:
Tim Funke
KÖsmetik GmbH
Königsallee 60b
40212 Düsseldorf
Phone: 021178179999
E-mail: info@koesmetik.de
The responsible entity is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, e-mail addresses, or similar).
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke a consent you have already given at any time. A simple notification by e-mail to us is sufficient. The legality of the data processing carried out up to the revocation remains unaffected by the revocation.
Right to complain to the competent supervisory authority
In the event of data protection violations, the affected person has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority in data protection matters is the state data protection officer of the federal state in which our company is based. A list of data protection officers and their contact details can be found at the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Right to data portability
You have the right to receive data that we process automatically based on your consent or in fulfillment of a contract, either to yourself or to a third party, in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this page uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the lock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after the conclusion of a paid contract, there is an obligation to provide us with your payment data (e.g. account number for direct debit authorization), this data is required for payment processing.
Payment transactions via common payment methods (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
In the case of encrypted communication, your payment data that you transmit to us cannot be read by third parties.
Information, blocking, deletion
You have the right at any time under the applicable legal provisions to receive free information about your stored personal data, their origin and recipients, and the purpose of data processing, and, if applicable, a right to correction, blocking, or deletion of this data. For this purpose and for further questions on the subject of personal data, you can contact us at any time at the address given in the imprint.
Objection to advertising emails
The use of contact details published within the scope of the imprint obligation for sending unsolicited advertising and informational materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
3. Data protection officer
Statutorily mandated data protection officer
We have appointed a data protection officer for our company.
Mark Finkenrath
KÖsmetik GmbH
Königsallee 60b
40212 Düsseldorf
Phone: 021193672290
E-mail: mark.finkenrath@koe-hair.de
4. Data collection on our website
Cookies
The websites partially use so-called cookies. Cookies do not harm your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called “session cookies.” They are automatically deleted after your visit ends. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser on your next visit.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may restrict the functionality of this website.
Cookies that are necessary for the execution of the electronic communication process or for the provision of certain functions desired by you (e.g. shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. As far as other cookies (e.g. cookies for analyzing your surfing behavior) are stored, these are treated separately in this privacy policy.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
A merging of this data with other data sources does not take place.
The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data to fulfill a contract or pre-contractual measures.
Contact form
If you send inquiries to us via the contact form, your details from the inquiry form including the contact data you provide there will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent.
The processing of the data entered in the contact form is therefore carried out exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. A simple notification by email to us is sufficient for this. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.
The data you entered in the contact form will remain with us until you request its deletion, revoke your consent to storage, or the purpose for data storage ceases to exist (e.g., after your request has been processed). Mandatory legal provisions – in particular, retention periods – remain unaffected.
Registration on this website
You can register on our website to use additional features on the site. The data entered for this purpose will only be used for the purpose of utilizing the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration.
For important changes, such as changes in the scope of the offer or technically necessary changes, we use the email address provided during registration to inform you in this way.
The processing of the data entered during registration is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent at any time. A simple notification by email to us is sufficient. The legality of the data processing that has already taken place remains unaffected by the revocation.
The data collected during registration will be stored by us as long as you are registered on our website and will then be deleted. Legal retention periods remain unaffected.
Processing of data (customer and contract data)
We collect, process and use personal data only to the extent necessary for the establishment, content design or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. We only collect, process and use personal data about the use of our websites (usage data) to the extent necessary to enable or bill the user for the use of the service.
The collected customer data will be deleted after the completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transmission upon conclusion of contract for online shops, merchants, and goods shipping
We only transmit personal data to third parties if this is necessary for contract processing, for example to companies responsible for delivering the goods or the credit institution responsible for payment processing. No further transmission of data takes place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your explicit consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
Data transmission upon conclusion of contract for services and digital content
We only transmit personal data to third parties if this is necessary for the processing of the contract, for example to the credit institution commissioned with payment processing.
No further transmission of the data takes place or only if you have expressly consented to the transmission. Your data will not be passed on to third parties without your explicit consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
5. Analysis Tools and Advertising
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called "cookies". These are text files that are stored on your computer and allow for an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
The storage of Google Analytics cookies is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its web offerings and its advertising.
IP Anonymization
We have activated the IP anonymization function on this website. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator. The IP address transmitted by your browser within Google Analytics will not be merged with other Google data.
Browser Plugin
You can prevent the storage of cookies by adjusting the settings of your browser software; however, we point out that in this case you may not be able to use all functions of this website fully. Furthermore, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
Objection to data collection
You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set that prevents the collection of your data during future visits to this website: Disable Google Analytics.
More information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Order data processing
We have concluded a contract with Google for order data processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic features in Google Analytics
This website uses the “demographic features” function of Google Analytics. This allows reports to be created that contain statements about the age, gender, and interests of the site visitors. These data come from interest-based advertising by Google as well as from visitor data from third-party providers. These data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the section “Objection to data collection.”
Google Analytics Remarketing
Our websites use the functions of Google Analytics Remarketing in conjunction with the cross-device functions of Google AdWords and Google DoubleClick. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This function allows the advertising audiences created with Google Analytics Remarketing to be linked with the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalized advertising messages that were adapted to you on one device (e.g., mobile phone) based on your previous usage and browsing behavior can also be displayed on another of your devices (e.g., tablet or PC).
If you have given the corresponding consent, Google links your web and app browsing history with your Google account for this purpose. This way, the same personalized advertising messages can be displayed on every device where you sign in with your Google account.
To support this function, Google Analytics collects google-authenticated user IDs, which are temporarily linked to our Google Analytics data to define and create audiences for cross-device advertising.
You can permanently object to cross-device remarketing/targeting by disabling personalized advertising in your Google account; follow this link: https://www.google.com/settings/ads/onweb/.
The summary of the data collected in your Google account is done solely based on your consent, which you can give or withdraw at Google (Art. 6 para. 1 lit. a GDPR). For data collection processes that are not merged in your Google account (e.g., because you do not have a Google account or have objected to the merging), the data collection is based on Art. 6 para. 1 lit. f GDPR. The legitimate interest arises from the fact that the website operator has an interest in the anonymized analysis of website visitors for advertising purposes.
Further information and the privacy policy can be found in Google's privacy statement at: https://www.google.com/policies/technologies/ads/.
Google AdWords and Google Conversion Tracking
This website uses Google AdWords. AdWords is an online advertising program by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States ("Google").
As part of Google AdWords, we use the so-called conversion tracking. When you click on an ad placed by Google, a cookie for conversion tracking is set. Cookies are small text files that the internet browser stores on the user's computer. These cookies expire after 30 days and are not used for personal identification of users. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page.
Each Google AdWords customer receives a different cookie. The cookies cannot be tracked across the websites of AdWords customers. The information collected using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. The customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that would allow users to be personally identified. If you do not want to participate in tracking, you can object to this use by easily disabling the Google conversion tracking cookie via your internet browser's user settings. You will then not be included in the conversion tracking statistics.
The storage of "conversion cookies" is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its web offering and its advertising.
More information about Google AdWords and Google Conversion Tracking can be found in Google's privacy policy: https://www.google.de/policies/privacy/.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may restrict the functionality of this website.
Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on our websites. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
reCAPTCHA is used to verify whether the data entry on our websites (e.g., in a contact form) is made by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of the website visitor's stay on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run completely in the background. Website visitors are not informed that an analysis is taking place.
Data processing is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated scanning and from SPAM.
Further information about Google reCAPTCHA and Google's privacy policy can be found at the following links: https://www.google.com/intl/de/policies/privacy/ and https://www.google.com/recaptcha/intro/android.html.
Facebook Pixel
Our website uses the Facebook visitor action pixel from Facebook, Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”) for conversion measurement.
This allows the behavior of site visitors to be tracked after they have been redirected to the provider's website by clicking on a Facebook advertisement. This enables the effectiveness of Facebook advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The data collected is anonymous to us as the operators of this website; we cannot draw conclusions about the identity of the users. However, the data is stored and processed by Facebook, so a connection to the respective user profile is possible, and Facebook can use the data for its own advertising purposes in accordance with the Facebook Data Use Policy . This allows Facebook to enable the placement of advertisements on Facebook pages as well as outside of Facebook. This use of the data cannot be influenced by us as the site operator.
In Facebook's privacy notices, you will find further information on protecting your privacy: https://www.facebook.com/about/privacy/.
You can also disable the remarketing function “Custom Audiences” in the ad settings under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen disable. For this, you must be logged into Facebook.
If you do not have a Facebook account, you can deactivate usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.
6. Newsletter
Newsletter data
If you want to subscribe to the newsletter offered on the website, we need an email address from you as well as information that allows us to verify that you are the owner of the specified email address and agree to receive the newsletter. No further data is collected or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.
The processing of the data entered into the newsletter registration form is carried out exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke the consent given for the storage of the data, the email address, and their use for sending the newsletter at any time, for example, via the “Unsubscribe” link in the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
The data you provide to us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after the newsletter subscription is canceled. Data stored with us for other purposes (e.g., email addresses for the member area) remain unaffected.
MailChimp
This website uses the services of MailChimp for sending newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
MailChimp is a service that can be used, among other things, to organize and analyze the sending of newsletters. If you enter data for the purpose of subscribing to the newsletter (e.g., email address), this data is stored on the servers of MailChimp in the USA.
MailChimp has a certification under the “EU-US-Privacy-Shield.” The “Privacy-Shield” is an agreement between the European Union (EU) and the USA that aims to ensure compliance with European data protection standards in the USA.
With the help of MailChimp, we can analyze our newsletter campaigns. When you open an email sent with MailChimp, a file contained in the email (so-called web beacon) connects to the servers of MailChimp in the USA. This allows us to determine whether a newsletter message was opened and which links were clicked, if any. Technical information is also collected (e.g., time of access, IP address, browser type, and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better tailor future newsletters to the interests of the recipients.
If you do not want analysis by MailChimp, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. Furthermore, you can also unsubscribe from the newsletter directly on the website.
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing carried out prior to the revocation remains unaffected.
The data you provide to us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted from both our servers and MailChimp's servers after unsubscribing. Data stored for other purposes (e.g., email addresses for the member area) remain unaffected.
You can find more details in MailChimp's privacy policy at: https://mailchimp.com/legal/terms/.
Conclusion of a Data-Processing-Agreement
We have concluded a so-called "Data-Processing-Agreement" with MailChimp, in which we commit MailChimp to protect our customers' data and not to disclose it to third parties. This contract can be viewed at the following link: https://mailchimp.com/legal/forms/data-processing-agreement/sample-agreement/.
SMS marketing
If you have given your explicit consent, we use your phone number to send you information about our products, special offers, and promotions via SMS. Processing is based on Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future – e.g., by sending an SMS with the text "STOP" or via the unsubscribe links provided in the SMS. The SMS is sent via our service provider Mailchimp (Intuit Inc.), with whom we have concluded a data processing agreement according to Art. 28 GDPR.
Uptain
To improve interaction with our visitors, we use a JavaScript plugin from Uptain GmbH ("Uptain plugin" https://www.uptain.de). This allows us to analyze your use of the website and improve customer engagement (e.g., through a dialog window). For this purpose, we collect information about your usage behavior, i.e., cursor movement, dwell time, clicked links, and any information provided. The legal basis for processing is our legitimate interest in direct marketing and providing our website (Art. 6 para. 1 lit. f GDPR). Uptain GmbH acts as a processor strictly bound by our instructions. The collected information is not shared with third parties unless we are legally obliged to do so. If the information collected by the Uptain plugin contains personal data, it will be deleted immediately after your visit to our website.
You can deactivate the use of the uptain plugin at any time via the following link: https://www.koesmetik.de/datenschutz?__up_tracking_unsubscribe
7. Plugins and Tools
Google Web Fonts
This page uses so-called Web Fonts provided by Google for a uniform presentation of fonts. When you access a page, your browser loads the required Web Fonts into its browser cache to display texts and fonts correctly.
For this purpose, the browser you are using must connect to Google's servers. This allows Google to know that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
For more information about Google Web Fonts, please visit https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/.
Google Maps
This site uses the Google Maps service via an API. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the functions of Google Maps, it is necessary to store your IP address. This information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transmission.
The use of Google Maps is in the interest of an appealing presentation of our online offers and easy findability of the locations we specify on the website. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.
More information on handling user data can be found in Google's privacy policy: https://www.google.de/intl/de/policies/privacy/.
8. Payment provider
PayPal
On our website, we offer, among other things, payment via PayPal. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
If you choose to pay via PayPal, the payment data you enter will be transmitted to PayPal.
The transmission of your data to PayPal is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing to fulfill a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the validity of data processing operations that took place in the past.
Klarna
On our website, we offer, among other things, payment with Klarna services. The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna").
Klarna offers various payment options (e.g., installment purchase). If you choose to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Details can be found in Klarna's privacy policy at the following link: https://www.klarna.com/de/datenschutz/.
Klarna uses cookies to optimize the use of the Klarna checkout solution. The optimization of the checkout solution constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Cookies are small text files stored on your device and do not cause any harm. They remain on your device until you delete them. Details on the use of Klarna cookies can be found at the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
The transmission of your data to Klarna is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing to fulfill a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the legality of data processing operations carried out in the past.
Instant bank transfer
On our website, we offer payment via 'Sofortüberweisung', among other options. The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter 'Sofort GmbH').
With the help of the 'Sofortüberweisung' procedure, we receive a payment confirmation from Sofort GmbH in real-time and can immediately begin fulfilling our obligations.
If you have chosen the payment method "Sofortüberweisung", you transmit the PIN and a valid TAN to Sofort GmbH, which allows them to log into your online banking account. Sofort GmbH automatically checks your account balance after logging in and carries out the transfer to us using the TAN you provided. Afterwards, they immediately send us a transaction confirmation. After logging in, your transactions, the credit limit of the overdraft facility, and the existence of other accounts as well as their balances are also checked automatically.
In addition to the PIN and TAN, the payment data you entered as well as data about you will be transmitted to Sofort GmbH. The data about you includes first and last name, address, phone number(s), email address, IP address, and possibly other data required for payment processing. The transmission of this data is necessary to unequivocally establish your identity and to prevent fraud attempts.
The transmission of your data to Sofort GmbH is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the fulfillment of a contract). You have the option to revoke your consent to data processing at any time. A revocation does not affect the validity of data processing operations that occurred in the past.
You can find details about payment via Sofortüberweisung at the following links: https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/.
