Privacy Policy
Data Protection Declaration
Controller for Data Processing:
Protekto Gruppe
Wendenstraße 279
20537 Hamburg
Germany
datenschutz@protekto.de
Thank you for your interest in our online shop. Protecting your privacy is a priority for us. Below, we provide detailed information about how we handle your data.
1. Access Data and Hosting
You can visit our website without disclosing any personal information. Each time you access the website, the web server automatically stores a server log file containing information such as the name of the requested file, your IP address, date and time of the request, data volume transferred, and the requesting provider (access data). This file documents the access.
We analyse this access data solely to ensure the smooth operation of the site and to improve our services. In accordance with Art. 6 (1) (f) GDPR, this is done to safeguard our legitimate interest in providing a correct and optimized presentation of our services. All access data is deleted no later than seven days after your visit to the website ends.
Hosting Services by a Third-Party Provider
We engage a third-party provider to host and display our website as part of data processing on our behalf. This ensures proper presentation of our online offerings, a legitimate interest under Art. 6 (1) (f) GDPR. All data collected via this website or in designated online shop forms is processed on the provider’s servers. No data is processed on other servers unless specified otherwise here.
This service provider is located within a country of the European Union (EU) or the European Economic Area (EEA).
2. Data Collection and Use for Contract Processing and Contact Requests
We collect personal data that you voluntarily provide to us when placing an order or contacting us (e.g., via contact form or email). Mandatory fields are clearly marked, as the information is necessary to process your order or respond to your contact request. Without this data, it is not possible to complete the order or send your inquiry. The specific data collected can be found in the corresponding input forms.
We process the data you provide in accordance with Art. 6 (1)(b) GDPR for the purpose of fulfilling contracts and managing your inquiries. This includes addressing warranty claims, resolving performance issues, and meeting statutory update obligations. If you have provided explicit consent under Art. 6 (1)(a) GDPR by opting to create a customer account, we will use your data to establish and maintain the account. This allows us to store your information for future transactions on our website.
Once the contract has been fully executed or your customer account has been deleted, your data will be restricted from further processing and erased after the expiration of statutory tax and commercial retention periods. Exceptions apply if you have expressly consented to continued use of your data or if further use is permitted by law, which we will inform you about in this declaration. You may delete your customer account at any time, either by contacting us using the details provided below or by using the relevant function within your account.
Customer Relationship Management (CRM) with Greyhound
To manage customer inquiries efficiently, we use technologies provided by GREYHOUND Software GmbH & Co. KG, Segelfliegerweg 53, 49324 Melle, Germany (“Greyhound”).
When you contact us (e.g., via contact form, email, telephone, fax, or letter), your information is processed to handle your request in accordance with Art. 6 (1)(b) GDPR. Details such as your surname, first name, and email address are stored and organized in the Greyhound customer relationship management system to ensure chronological handling and improve service quality. This data is collected, transmitted to Greyhound, stored, and accessed exclusively to facilitate the organization and resolution of your inquiry.
The legal basis for processing this data is our legitimate interest under Art. 6 (1)(f) GDPR. This includes designing an efficient customer service experience, addressing your inquiries promptly, and optimizing our service offerings. Your data will be deleted once your request has been conclusively resolved, provided there are no legal obligations requiring its retention.
We have a data processing agreement in place with Greyhound to ensure the protection of our customers' data. This agreement explicitly prohibits the disclosure of your data to unauthorized third parties. Greyhound complies fully with GDPR requirements, hosting all data exclusively within Germany.
You can access Greyhound Software GmbH & Co. KG’s data protection policies at https://greyhound-software.com/datenschutz.
3. Data Transfers
To fulfil our contractual obligations in accordance with Art. 6 (1)(b) GDPR, we share your data with the shipping companies responsible for delivering your order, but only to the extent necessary for the delivery of the goods. Along with domestic shipping providers in Germany, we may also engage shipping services outside the European Union. Any transfer of personal data to such companies is strictly limited to what is required for contract fulfilment.
The same applies to data transfers to our manufacturers or wholesalers in cases where they handle shipping directly on our behalf (drop shipment).
Depending on the payment method you choose during checkout, we will transfer your payment data to the credit institution or payment service provider responsible for processing your transaction. If the payment service provider collects your payment data directly (e.g., through account creation on their platform), you will need to log in using your credentials. The privacy policy of the respective payment service provider applies in such cases.
Data Transfer to Shipping Service Providers
If you explicitly consent during or after your order process, we will share your email address and phone number with the selected shipping service provider in accordance with Art. 6 (1)(a) GDPR. This enables the shipping provider to contact you to schedule a delivery date or time.
You may revoke your consent at any time by notifying us via the contact information provided below or by contacting the shipping service provider directly at their address:
GE Transport und Logistik GmbH
Hans-Böckler-Straße 11
59348
Lüdinghausen
Germany
United Parcel Service Deutschland S.à r.l. & Co. OHG
Görlitzer Straße 1
41460
Neuss
Germany
DHL Paket GmbH
Sträßchensweg 10
53113
Bonn
Germany
shipcloud GmbH
Heinz-Fangman-Straße 2-4, Haus 4
42287
Wuppertal
Germany
Once consent is revoked, we will delete your data unless you have explicitly authorized further use or a legal basis permits continued use, as detailed in this privacy notice.
Data Transfer for Age Verification
For orders containing age-restricted goods, we use a reliable process to verify identity and age, ensuring compliance with legal requirements. This involves the SCHUFA identity check, operated by SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, Germany.
To verify that the minimum age requirement is met, personal data such as name, address, and date of birth is transmitted to SCHUFA Holding AG. The identity check includes a process (Q-Bit) approved by the Commission for the Protection of Minors in the Media (KJM) for age verification.
This data transfer is conducted in accordance with Art. 6 (1)(f) GDPR, ensuring compliance with youth protection laws and safeguarding our legitimate interests in adhering to these regulations. No credit check is performed as part of this process.
Your data will be deleted following full contract fulfilment and the expiration of tax and commercial retention periods unless you have explicitly consented to further use or legal provisions permit continued use, as outlined in this notice.
Data Transfer for Occhio Warranty Registration
If you purchase an Occhio lamp, you qualify for their 5-year warranty. To activate this warranty, we will register your product on your behalf after the purchase is completed. This registration involves the transfer of personal data to Occhio. The warranty registration also includes periodic updates on lighting topics, new product launches, and technological innovations. These updates may contain promotional content.
Personal data will be stored by Occhio only as long as necessary to fulfil its intended purpose. Your data will not be shared with third parties. For detailed information on Occhio’s data protection policies, visit https://www.occhio.com/en-gb/legals. Warranty conditions can also be found here: https://www.occhio.com/en-gb/warranty-terms.
Provider and Contact:
Occhio GmbH
Wiener-Platz 7
81667
München
Germany
4. E-Mail Newsletter and Postal Advertising
Email Advertising with Newsletter Registration
When you subscribe to our newsletter, we use the information you provide to send periodic updates and promotions based on your explicit consent in accordance with Art. 6 (1)(a) GDPR.
You can unsubscribe from the newsletter at any time by using the link provided in the email or by contacting us directly. After unsubscribing, your email address will be deleted unless further use is legally permitted or explicitly authorized.
Newsletter distribution is handled by a service provider under our instruction. This provider is located within the European Union or European Economic Area.
Postal Advertising and Right to Object
We reserve the right to use your name and postal address for our own advertising purposes, such as sending you exclusive offers or product updates via direct mail. This processing is conducted under Art. 6 (1)(f) GDPR, safeguarding our legitimate interests in customer engagement.
Mailings are handled by a service provider acting on our behalf. You may object to the use of your data for these purposes at any time by contacting us via the details below.
5. Data Use for Payment Processing
Credit Checks
For purchases requiring payment in advance (e.g., payment on account), we may conduct a credit check to assess identity and creditworthiness in accordance with Art. 22 (2)(a) GDPR. For this purpose, we share your personal data with the following service provider:
Creditreform Boniversum GmbH
Hellersbergstraße 11
41460 Neuss
Germany
Appropriate measures are taken to protect your rights and legitimate interests. You may express your viewpoint or challenge the decision by contacting us. Your data will be deleted after the contract is fully processed, unless further use is legally permitted or authorized as detailed in this statement.
6. Cookies and Web Analysis
We use cookies on various pages of our website to enhance your browsing experience, enable certain features, display relevant products, and conduct market research. This serves to protect our legitimate interest in providing an optimized and user-friendly presentation of our services, in accordance with Art. 6 (1)(f) GDPR. Cookies are small text files that are automatically stored on your device. Some cookies (session cookies) are deleted when you close your browser, while others (persistent cookies) remain on your device and allow us to recognize your browser the next time you visit. The duration of storage is displayed in your browser’s cookie settings. You can configure your browser to notify you when cookies are set and decide whether to accept them individually, reject them in specific cases, or disable them altogether.
Each browser handles cookie settings differently. For detailed instructions, refer to the help menu of your browser:
Internet Explorer™: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Safari™: https://support.apple.com/de-de/guide/safari/sfri11471/12.0/mac/10.14
Chrome™: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en
Firefox™: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Opera™ : https://help.opera.com/de/latest/web-preferences/#cookies
Please note that disabling cookies may limit the functionality of our website.
If you have consented in accordance with Art. 6 (1)(a) GDPR, this website also uses the DoubleClick cookie for advertising purposes in conjunction with Google Analytics. This enables recognition of your browser when visiting other websites. Data generated by the cookie about your use of this website is typically transmitted to and stored on Google servers in the United States. To protect your privacy, IP anonymization is enabled on this website, ensuring your IP address is shortened within the EU or EEA before transmission. Only in exceptional cases is the full IP address sent to a Google server in the US and anonymized there. The anonymized IP address provided by Google Analytics is not merged with other Google data.
Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Once we have ceased using Google DoubleClick and its purpose has ended, the data collected in this context will be deleted. Google DoubleClick is provided by Google Ireland Limited, a company incorporated and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). Insofar as information is transferred to and stored on Google servers in the United States, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
You can revoke your consent at any time with effect for the future by deactivating the DoubleClick cookie via this link. In addition, you can find out about the setting of cookies and make settings for this at the Digital Advertising Alliance. Finally, you can adjust your browser settings so that you are informed when cookies are set and can decide whether to accept them individually or to exclude the acceptance of cookies in certain cases or in general. Note that disabling cookies may affect website functionality.
Use of Google (Universal) Analytics for Web Analysis
If you have given your consent in accordance with Art. 6 (1) point a GDPR, this website uses Google (Universal) Analytics for the purpose of website analysis. The web analysis service is provided by Google Ireland Limited, a company incorporated and operated under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. (www.google.de). Google (Universal) Analytics uses methods such as cookies that make it possible to analyse your use of the website. The information collected automatically about your use of this website is usually transferred to a Google server in the United States and stored there. Due to the activation of IP anonymisation on this website, the IP address is shortened before transmission within the member states of the European Union or in other states that are party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the US and shortened there. The anonymised IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. After the purpose and end of our use of Google Analytics, the data collected in this context will be deleted.
Insofar as information is transferred to and stored on Google servers in the United States, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the United States and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
You can revoke your consent at any time by downloading and installing the browser plugin: https://tools.google.com/dlpage/gaoptout?hl=de. This will prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google.
As an alternative to the browser plug-in, you can click this linkto prevent Google Analytics from collecting data on this website in the future. This stores an opt-out cookie on your device. If you delete your cookies, you will be asked to give your consent again.
Use of Sentry for Error Detection
We use the Sentry system from Functional Software inc. 45 Fremont Street 8th Floor, San Francisco, CA 94105, USA to detect and record errors. We use the self-hosted version of Sentry. In our case, our service provider WEBiDEA Köpenickerstraße 325, Haus 40, 12555 Berlin, Germany hosts Sentry. The Sentry plug-in offers a code-based system for recording and logging errors (PR1) with visualisation options in the frontend and backend. Cookies are stored on your device for this purpose. The following personal data is processed using Sentry:
- Name and contact details
- Payment information
- Customer data
- Device and browser information
- IP address
Data may be transmitted to our service provider WEBiDEA. Our service provider's servers are located in Germany. We have concluded an order processing contract with our service provider in accordance with Art. 28 Para. 3 DSGVO. We use Sentry for visualisation and as a direct system for recording and logging in the event of an error. If you do not give us your consent to use Sentry in accordance with Art. 6 (1) (a) GDPR, no Cookies will be stored on or read from your device. The data processing described in the previous paragraphs will not take place.
7. Online Marketing
Google Ads Remarketing
We use Google Ads to advertise this website in Google search results and on third-party websites. If you have given us your consent to do so in accordance with Art. 6 (1) 1 lit. a GDPR, the so-called remarketing cookie from Google is set when you visit our website, which automatically enables interest-based advertising by means of a pseudonymous cookie ID and based on the pages you visit. After the purpose and our use of Google Ads Remarketing has ended, the data collected in this context will be deleted.
Any further data processing will only take place if you have agreed to Google linking your web and app browsing history to your Google account and using information from your Google account to personalise ads you see on the web. If you are logged into Google while visiting our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. To do this, Google will temporarily link your personal data with Google Analytics data to create target groups.
Google Ads is provided by Google Ireland Limited, a company incorporated and operated under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). Insofar as information is transferred to and stored on Google servers in the United States, the American company Google LLC is certified under the EU-US Privacy Shield.
A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield.
You can revoke your consent at any time with effect for the future by deactivating the remarketing cookie via this link. In addition, you can find out more about the setting of cookies and adjust your settings at the Digital Advertising Alliance.
AdRoll Retargeting
We use our advertising partner AdRoll Advertising Limited, Level 6, 1, Burlington Plaza, Burlington Road, Dublin 4, Ireland to advertise this website in search results and on third-party websites. If you have given us your consent to do so in accordance with Art. 6 (1) 1 lit. a GDPR, a cookie from these providers or their partners will be set automatically when you visit our website, which enables interest-based advertising by means of a pseudonymous cookie ID and based on the pages you visit. After the purpose and our use of AdRoll Retargeting has ended, the data collected in this context will be deleted.
You can revoke your consent at any time with effect for the future by deactivating the retargeting cookie by clicking on one of the following links: https://app.adroll.com/optout/safari.
Alternatively, you can disable the use of cookies by third parties by visiting the opt-out page of the Network Advertising Initiative.
Affilinet Partner Programme
Our website participates in the affilinet partner programme. This is provided by AWIN AG, Eichhornstraße 3, 10785 Berlin (hereinafter referred to as ‘affilinet’). This is a so-called affiliate system in which persons registered with affilinet (also referred to as ‘publishers’) advertise the products or services of so-called ‘advertisers’ on their websites by means of advertising material.
This serves to safeguard our legitimate interests, which are overriding in the process of balancing of interests, in optimising and commercially exploiting our online offer pursuant to Art. 6 (1) lit. f) GDPR.
By means of cookies, affilinet can track the progress of the respective order and can verify that you clicked on the respective link and then ordered the product via the affiliate partner programme.
You can prevent the setting of cookies by our contractual partners or our website at any time by means of a corresponding setting in your internet browser. In addition, cookies that have already been set can be deleted at any time via the internet browser or other software programs.
Further information on data processing at affilinet can be found here.
Google Maps
This website uses Google Maps to visually display geographical information. Google Maps is a service provided by Google Ireland Limited, a company incorporated and operated under Irish law, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves to safeguard our legitimate interests, which are overriding in the process of balancing interests, in an optimised presentation of our offer and easy accessibility to our locations in accordance with Art. 6 (1) point f GDPR.
When Google Maps is used, Google transmits and processes data about how website visitors use the Maps functions, which may include the IP address and location data. We have no influence on this data processing.
Insofar as information is transferred to and stored on Google servers in the United States, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
To disable the Google Maps service and thus prevent the transfer of data to Google, you must disable the JavaScript function in your browser. In this case, Google Maps cannot be used or can only be used to a limited extent.
Further information about data processing by Google can be found in the Googleprivacy policy. The Google Maps terms of use contain detailed information about the map service.
Data processing is carried out on the basis of an agreement between jointly responsible parties in accordance with Art. 26 DSGVO, which you can view here.
Our Online Presence on Facebook, Google, Instagram, Pinterest/h5>
Our presence on social networks and platforms serves to improve active communication with our customers and prospects. We use these platforms to provide information about our products and current promotions.
When you visit our online presence on social media, your data may be automatically collected and stored for market research and advertising purposes. Pseudonyms are used to create so-called user profiles from this data. These can be used, for example, to place advertisements inside and outside the platforms that presumably correspond to your interests. For this purpose, cookies are usually placed on your end device. These cookies store visitor behaviour and the interests of the users. According to Art. 6 para. 1 lit. f. GDPR to safeguard our legitimate interests in optimising the presentation of our offer and communicating effectively with customers and prospects, which are overriding in the process of balancing interests. If you are asked by the respective social media platform operators for consent (permission) to process your data, e.g. by means of a checkbox, the legal basis for data processing is Art. 6 para. 1 lit. a GDPR.
Insofar as the social media platforms are headquartered in the United States, the following applies: The European Commission has issued an adequacy decision for the United States. This is based on the EU-US Privacy Shield. A current certificate for the respective company can be viewed here.
Please refer to the providers’ data protection information linked below for detailed information on the processing and use of data by the providers on their pages, as well as a contact option and your rights and setting options for protecting your privacy, in particular opt-out options. If you still require assistance in this regard, you can contact us.
Facebook: https://www.facebook.com/about/privacy/
Data processing is carried out on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR, which you can view here:
https://www.facebook.com/legal/terms/page_controller_addendum
Google/ YouTube: https://policies.google.com/privacy
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://about.pinterest.com/de/privacy-policy
Opt-out::
Facebook: https://www.facebook.com/settings?tab=ads
Google/ YouTube: https://adssettings.google.com/authenticated
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://www.pinterest.de/?next=/settings/
8. Contact Options and Your Rights
As a data subject, you are entitled to the following rights under the GDPR:
- Right of Access (Art. 15 GDPR): You have the right to request detailed information about the personal data we process about you, as specified in the regulation.
- Right to Rectification (Art. 16 GDPR): You can request the immediate correction of any inaccurate or incomplete personal data stored by us.
- Right to Erasure (Art. 17 GDPR): You can request the deletion of your personal data unless further processing is necessary:
- To exercise the right to freedom of expression and information;
- To fulfil a legal obligation;
- For reasons of public interest; or
- To assert, exercise, or defend legal claims. - Right to Restriction of Processing (Art. 18 GDPR): You have the right to request a restriction on the processing of your personal data if
- You contest the accuracy of the data;
- The processing is unlawful, but you oppose its deletion;
- We no longer need the data, but you require it for the establishment, exercise, or defence of legal claims; or
- You have objected to the processing pursuant to Art. 21 GDPR. - Right to Data Portability (Art. 20 GDPR): You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to request the transfer of this data to another controller.
- Right to Lodge a Complaint (Art. 77 GDPR): You can lodge a complaint with a supervisory authority, typically the authority located in your habitual place of residence, your workplace, or our company headquarters.
If you have any questions regarding the collection, processing, or use of your personal data—or if you wish to exercise any of your rights, including requesting information, rectifying inaccuracies, restricting, or deleting data, or revoking previously given consent—please contact us:
Protekto Gruppe
Wendenstraße 279
20537 Hamburg
Germany
datenschutz@protekto.de
Data Protection Officer::
Kent Schwirz
Wendenstraße 279
20537 Hamburg
Germany
Telephone: +49 40 422 369 24
Email: datenschutz@protekto.de
Right to Object
If we process your personal data as described above to protect our legitimate interests—interests which are deemed to outweigh your rights after careful balancing—you have the right to object to this processing at any time with effect for the future. If your data is processed for direct marketing purposes, you may exercise your right to object at any time, as outlined above. Once you object, we will cease processing your personal data for such marketing purposes. If the data processing is for purposes other than direct marketing, you may object only if your objection is based on grounds related to your specific situation.
Upon receiving your objection, we will stop processing your personal data for the specified purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
For direct marketing purposes, your objection is absolute. Once exercised, we will immediately stop processing your personal data for these purposes.**