Privacy Policy

Last updated: 29/07/2026

Table of Contents

  1. Controller
  2. Personal data we process
  3. Visiting our website and server log files
  4. Shopify and technical shop infrastructure
  5. AI-powered product recommendation quiz
  6. Cloudflare
  7. Cookies, pixels, local storage and similar technologies
  8. Necessary technologies
  9. Consent-based technologies
  10. Cookie Consent Tool
  11. Contact requests and customer support
  12. Shopify Inbox
  13. Customer account
  14. Hook One Tap Social Login and Google Sign-In
  15. Orders and contract processing
  16. Payment providers
  17. Fulfilment, warehouse and shipping
  18. Picqer
  19. Mirakl Connect
  20. Newsletter and email marketing / Mailchimp
  21. Direct marketing to existing customers
  22. Google Analytics 4
  23. Google Tag Manager
  24. Google Ads Conversion Tracking and Remarketing
  25. Meta Pixel / Facebook Pixel
  26. TikTok Pixel
  27. Twitter/X Conversion Tracking
  28. Facebook and Pinterest social plugins
  29. YouTube videos
  30. Judge.me reviews
  31. UpPromote Affiliate
  32. Cozy Country Redirect
  33. Tools not currently used
  34. International data transfers
  35. Legal obligations and record keeping
  36. Data retention
  37. Your rights
  38. Right to object
  39. Withdrawal of consent
  40. DACH-specific notes
  41. Updates to this Privacy Policy

This Privacy Policy explains how GTI GmbH, Königsallee 92a, 40212 Düsseldorf, Germany, email: privacy@maxler.com, phone: +49 211 54039788, processes personal data when you use our website, online shop, customer account, checkout, marketing features, customer support, affiliate features and related services.

This Privacy Policy is drafted for use in the DACH market. The main legal basis is the EU General Data Protection Regulation (“GDPR”) and, for Germany, the German Telecommunications Digital Services Data Protection Act (“TDDDG”). For Austria and Switzerland, additional local privacy and cookie rules may apply.

1. Controller

The controller responsible for the processing of personal data is:

GTI GmbH
Königsallee 92a
40212 Düsseldorf
Germany
Email: privacy@maxler.com
Phone: +49 211 54039788

2. Personal data we process

Depending on how you use our website and shop, we may process the following categories of personal data:

Category Examples
Technical data IP address, device data, browser, operating system, log files, access time
Contact data Name, email address, phone number, billing address, delivery address
Account data Login details, customer account information, order history
Order data Products ordered, order number, delivery status, return data
Payment data Payment method, payment status, transaction information
Marketing data Newsletter consent, campaign interactions, advertising identifiers
Tracking data Cookie IDs, pixel IDs, conversion events, website behaviour
Support data Chat messages, support requests, communication history
Review data Product review, rating, name, email address, order reference
Affiliate data Referral links, coupon codes, attribution data, commission data
AI quiz data Quiz answers, optional free-text input, product preferences, technical session data

3. Visiting our website and server log files

When you visit our website, we automatically process technical data that is necessary to display the website securely and correctly.

This may include:

  • IP address;
  • date and time of access;
  • browser type and version;
  • operating system;
  • referrer URL;
  • pages visited;
  • amount of data transferred.

Legal basis: Art. 6(1)(f) GDPR.

Our legitimate interest is the secure, stable and functional operation of the website.

Server log files are stored only for as long as necessary for security and technical purposes, unless longer storage is required for legal claims, fraud prevention or security investigations.

4. Shopify and technical shop infrastructure

Our online store is operated using the Shopify e-commerce platform. The service provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland.

Shopify processes personal data on our behalf where this is necessary to operate the online store, process purchases, manage customer accounts, provide payment and delivery functions, prevent fraud and perform related e-commerce services.

Depending on your interaction with the store, Shopify may process identification and contact details, billing and delivery information, order and transaction data, customer account information, device and usage information, communications relating to a purchase, and fraud-prevention or security information.

Legal basis:

  • Art. 6(1)(b) GDPR where processing is necessary to conclude or perform a contract;
  • Art. 6(1)(c) GDPR where processing is necessary to comply with legal obligations;
  • Art. 6(1)(f) GDPR where processing is necessary for the secure and efficient operation of the store, fraud prevention, legal claims or other legitimate business interests.

Shopify acts as a processor where it processes personal data on our instructions. Data processing is governed by Shopify’s Data Processing Addendum.

Shopify International Limited initially processes personal data relating to customers in the European Economic Area and Switzerland. Shopify may engage affiliated companies and other subprocessors.

Where personal data is transferred outside the European Economic Area, the transfer is protected through an applicable adequacy decision, Standard Contractual Clauses approved by the European Commission or another legally recognised transfer mechanism.

Shopify AI-assisted administrative features

We may use AI-assisted features made available within the Shopify administration environment, including Shopify Magic or Sidekick, to support internal activities such as drafting or editing product and marketing content, assisting with store administration and supporting internal operational tasks.

Shopify Sidekick is an internal administrative assistant available only to authorised store users. It is not directly available to customers. These internal Shopify tools are separate from the AI-powered product recommendation quiz described below.

We do not intentionally enter sensitive personal data into Shopify’s generative AI tools. The specific functions enabled in our Shopify account and the information accessible to them are subject to internal access controls, data-minimisation requirements and human review.

Further information:

5. AI-powered product recommendation quiz

Purpose and function

Our website provides an AI-powered product recommendation quiz. The quiz is configured and made available by GTI GmbH using Voiceflow technology and the OpenAI API.

The quiz helps visitors navigate our product range and receive an automated, non-binding product suggestion based on the answers they provide.

The quiz is not a customer-support or order-tracking service. It does not intentionally access or process Shopify customer accounts, order status, order numbers, delivery status, refunds, payment information, billing details, delivery addresses, changes to orders or changes to customer accounts.

The quiz does not provide medical advice, diagnosis, treatment recommendations or an individual assessment of a person’s health. Product suggestions are provided only for general informational and product-navigation purposes.

Information processed

Depending on how you interact with the quiz, the following information may be processed:

  • answers selected during the quiz;
  • text voluntarily entered into a free-text field;
  • product preferences, general product goals or intended product use selected by you;
  • technical session information required to display and operate the quiz;
  • technical information generated during communication between the website, Voiceflow and the OpenAI API.

The quiz is not intended to collect your name, postal address, customer account details, Shopify customer identifiers, order information, payment information, delivery information, identity documents or medical records.

Please do not enter sensitive or confidential information into the quiz. In particular, do not provide payment card information, bank account information, passwords, login credentials, authentication codes, passport details, national identification numbers, medical diagnoses, health records, information about medication or treatment, detailed information about illnesses, symptoms or medical conditions, or personal information relating to another person.

If you voluntarily include personal data in a free-text response, that information may be processed as part of the quiz interaction.

Legal basis

We process information submitted through the quiz on the basis of our legitimate interest under Art. 6(1)(f) GDPR in helping visitors navigate our product range, identify potentially relevant products, improve the usability of the online store and provide an efficient product-selection tool.

You are not required to use the quiz and may browse the product catalogue directly.

Where the operation of the quiz requires access to or storage of information on your device that is not strictly necessary, such processing takes place only in accordance with your consent choices through our consent-management system.

AI transparency and automated decisions

The recommendations are generated with the support of an artificial intelligence system. You interact with an automated system and not with a human representative.

The result is not binding. You remain free to disregard the recommendation, review other products, browse the full product catalogue or contact GTI GmbH for further information.

The quiz does not make decisions that produce legal effects or similarly significantly affect you within the meaning of Art. 22 GDPR. No purchase, subscription, customer-account change, payment or other contractual action is completed solely as a result of the quiz recommendation.

Technology providers

Voiceflow Inc., Toronto, Canada, provides the technical infrastructure used to configure and operate the quiz and manage its conversation flow.

Voiceflow may process quiz responses, conversation-flow data, technical session information and related service data on our behalf to the extent necessary to operate and secure the quiz.

Further information: Voiceflow Privacy Policy

OpenAI Ireland Ltd., Dublin, Ireland, provides the artificial intelligence model accessed through the OpenAI API.

OpenAI states that data submitted by business and API customers is not used to train its models by default, unless the customer expressly enables an applicable data-sharing option.

OpenAI may retain API input and output data for up to 30 days for abuse-monitoring and security purposes, unless longer retention is required by law or a different retention period applies to a specific API feature, endpoint or account configuration.

Further information:

These providers may process information on our behalf to the extent necessary to provide, secure and maintain the relevant technical services.

International data transfers

Voiceflow Inc. is based in Canada. Transfers to Voiceflow in Canada may be based on the European Commission’s adequacy decision for commercial organisations subject to Canada’s Personal Information Protection and Electronic Documents Act, Commission Decision 2002/2/EC.

Where the adequacy decision does not apply to a particular processing activity, recipient or onward transfer, the transfer is protected by Standard Contractual Clauses or another legally recognised transfer mechanism.

OpenAI provides the relevant service through OpenAI Ireland Ltd. Voiceflow, OpenAI and their authorised subprocessors may process data outside the European Economic Area.

Where personal data is transferred outside the European Economic Area, we apply an appropriate transfer mechanism under Chapter V GDPR, including an applicable adequacy decision, Standard Contractual Clauses approved by the European Commission or another legally recognised safeguard.

Cookies, local storage and consent

The quiz may use cookies, local storage, session storage or similar technologies to display the quiz, maintain your progress, prevent abuse, support security and provide technical functionality.

Some technologies may be strictly necessary for the operation of a quiz that you expressly request. Cookies or similar technologies that are not strictly necessary, including technologies used for analytics, extended performance measurement, profiling or marketing, are activated only in accordance with your consent choices.

The Voiceflow script and related technologies are classified according to their actual purpose and technical behaviour. The integration is not treated as strictly necessary solely because it is embedded through custom Shopify code.

Where consent is required, the relevant non-essential script, cookie or similar technology is not activated until you have provided valid consent. You may withdraw or change your consent at any time through the cookie settings on our website.

Retention

GTI GmbH retains chat and quiz-session data under its control for a maximum of 30 days, unless shorter retention is possible or longer retention is required to establish, exercise or defend legal claims, investigate a security incident, comply with a legal obligation or respond to a valid request from a competent authority.

After the applicable retention period, the data is deleted or anonymised in accordance with our retention and deletion procedures.

OpenAI may retain API input and output data for up to 30 days for abuse-monitoring and security purposes. Voiceflow retention periods are governed by the applicable Data Processing Addendum, contractual terms and technical account settings.

Contact and data-protection rights

You may exercise your applicable data-protection rights as described in the section “Your rights” of this Privacy Policy.

Questions concerning processing through the AI-powered product recommendation quiz may be sent to privacy@maxler.com.

6. Cloudflare

We use Cloudflare for content delivery, performance optimisation, security, DDoS protection and stable website delivery.

Cloudflare may process IP addresses, device data, log data and security-related access information.

Legal basis: Art. 6(1)(f) GDPR.

Our legitimate interest is secure, fast and stable website delivery.

Where Cloudflare transfers data outside the EU/EEA, we rely on appropriate safeguards such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses. The European Commission adopted the EU-US Data Privacy Framework adequacy decision on 10 July 2023, but it applies only to certified US recipients. EUR-Lex

7. Cookies, pixels, local storage and similar technologies

We use cookies, pixels, tags, local storage and similar technologies.

Some technologies are technically necessary for the website and shop. Others are used only with your consent, especially analytics, marketing, retargeting, affiliate tracking, social plugins and embedded media.

Under German TDDDG and EU ePrivacy rules, consent may be required not only for cookies, but also for access to or storage of information on a user’s device through pixels, local storage, SDKs or similar technologies. The EDPB published final Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy Directive on 16 October 2024. European Data Protection Board

8. Necessary technologies

Necessary technologies may be used for:

  • shopping cart;
  • checkout;
  • login;
  • security;
  • fraud prevention;
  • country and language settings;
  • cookie consent preferences;
  • technical shop operation.

Legal basis: Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR and TDDDG where applicable.

We use the following categories only after consent:

  • analytics;
  • marketing pixels;
  • retargeting;
  • advertising conversion tracking;
  • affiliate tracking where not strictly necessary;
  • social plugins;
  • embedded videos.

Legal basis: Art. 6(1)(a) GDPR and consent under TDDDG where required.

You can withdraw or change your consent at any time through the cookie settings on our website.

We use a cookie consent tool to manage consent for non-essential cookies, pixels and similar technologies.

The tool may process:

  • consent status;
  • timestamp;
  • selected preferences;
  • technical device data;
  • IP address, where required for documentation;
  • consent ID.

Legal basis:

  • Art. 6(1)(c) GDPR for compliance and documentation;
  • Art. 6(1)(f) GDPR for legally compliant consent management.

Our cookie banner offers a “Decline” option at the first layer and uses equal button design for accepting and declining non-essential technologies.

If the native Shopify consent banner does not keep sufficient consent logs for audit purposes, we may use a third-party consent management platform.

11. Contact requests and customer support

If you contact us by email, contact form, chat or another support channel, we process the data you provide to handle your request.

Legal basis:

  • Art. 6(1)(b) GDPR if your request relates to an order or contract;
  • Art. 6(1)(f) GDPR for general customer communication;
  • Art. 6(1)(c) GDPR if legal obligations apply.

12. Shopify Inbox

We use Shopify Inbox for customer support chat and customer communication.

Shopify Inbox may process your name, email address, chat messages, order information, device data and technical communication data.

Legal basis:

  • Art. 6(1)(b) GDPR for order-related support;
  • Art. 6(1)(f) GDPR for efficient customer service.

Please do not send sensitive personal data through the chat.

13. Customer account

If you create a customer account, we process the data required for account creation, login, order history and account management.

Legal basis: Art. 6(1)(b) GDPR.

You may request deletion of your customer account at any time. We will delete the account unless legal retention obligations or legitimate interests require further storage.

14. Hook One Tap Social Login and Google Sign-In

We use Hook One Tap Social Login and may offer login via Google Sign-In.

If you use social login, the relevant provider may transmit account information to us, such as name, email address, profile ID or authentication token.

Legal basis:

  • Art. 6(1)(a) GDPR for optional social login;
  • Art. 6(1)(b) GDPR for creating and managing your customer account after login.

Google or other login providers may process your data independently under their own privacy policies.

15. Orders and contract processing

When you place an order, we process the data necessary to fulfil the contract.

This includes:

  • name;
  • billing address;
  • delivery address;
  • email address;
  • phone number, if provided;
  • order details;
  • payment status;
  • delivery information;
  • invoice data.

Legal basis: Art. 6(1)(b) GDPR.

We also process order and invoice data to comply with tax, accounting and commercial law obligations.

Legal basis: Art. 6(1)(c) GDPR.

16. Payment providers

We use payment providers to process payments securely.

Depending on the selected payment method, data may be processed by:

  • Apple Pay;
  • Google Pay;
  • PayPal Checkout.

Payment providers may process payment data, billing data, transaction data, fraud prevention data and device data.

Legal basis:

  • Art. 6(1)(b) GDPR for payment processing;
  • Art. 6(1)(f) GDPR for fraud prevention and payment security;
  • Art. 6(1)(c) GDPR for legal obligations.

Payment providers may act as independent controllers for parts of their processing.

17. Fulfilment, warehouse and shipping

To deliver your order, we share necessary order and delivery data with fulfilment, warehouse and shipping providers.

We use Verzendbazen for fulfilment, shipping and logistics support.

Verzendbazen may process:

  • name;
  • delivery address;
  • email address;
  • phone number, if provided;
  • order number;
  • ordered products;
  • shipping status;
  • return information.

Legal basis: Art. 6(1)(b) GDPR.

Where Verzendbazen acts as our service provider, we process data on the basis of a data processing agreement.

18. Picqer

We use Picqer for warehouse, order and fulfilment management.

Picqer may process order data, customer data, delivery address, product data, stock data and fulfilment status.

Legal basis:

  • Art. 6(1)(b) GDPR for order fulfilment;
  • Art. 6(1)(f) GDPR for efficient warehouse and logistics management.

19. Mirakl Connect

We use Mirakl Connect in connection with marketplace, platform or partner integrations.

Mirakl may process business contact data, order data, product data, marketplace transaction data, delivery status and communication data.

Legal basis:

  • Art. 6(1)(b) GDPR where processing is necessary for marketplace orders;
  • Art. 6(1)(f) GDPR for marketplace operations and partner management.

20. Newsletter and email marketing / Mailchimp

If you subscribe to our newsletter, we process your email address and, where applicable, your name, consent timestamp, IP address and subscription preferences.

We use Mailchimp to send newsletters and manage email marketing.

Legal basis for newsletter subscription: Art. 6(1)(a) GDPR.

For Germany, we generally use a double opt-in process to document newsletter consent.

Newsletter tracking, such as open tracking and click tracking, is used only where legally valid consent has been obtained.

You can unsubscribe at any time through the unsubscribe link in each newsletter or by contacting us.

21. Direct marketing to existing customers

Where legally permitted, we may send marketing emails to existing customers for similar products or services.

Legal basis may be Art. 6(1)(f) GDPR together with applicable German direct marketing rules.

You may object to direct marketing at any time without incurring costs other than transmission costs according to basic tariffs.

22. Google Analytics 4

We use Google Analytics 4 to analyse website usage, improve our shop and measure performance.

Google Analytics may process:

  • device data;
  • browser data;
  • IP address;
  • page views;
  • events;
  • approximate location;
  • interactions;
  • conversion data.

Google Analytics is used only with your consent.

Legal basis: Art. 6(1)(a) GDPR.

Google may process data in the United States. Transfers may be based on the EU-US Data Privacy Framework where applicable or Standard Contractual Clauses where required.

23. Google Tag Manager

We use Google Tag Manager to manage website tags.

Google Tag Manager helps us load and control other tools. It does not itself create analytics profiles for us, but it may process technical data such as IP address when loaded.

Where Google Tag Manager is used to manage consent-based tags, those tags are loaded only after consent.

Legal basis:

  • Art. 6(1)(f) GDPR for technical tag management where strictly necessary;
  • Art. 6(1)(a) GDPR where Tag Manager is used in connection with consent-based analytics or marketing tags.

We use Google Ads for conversion tracking and remarketing.

Google Ads may process:

  • ad clicks;
  • website visits;
  • conversions;
  • products viewed;
  • purchases;
  • device and browser data.

Google Ads is used only with your consent.

Legal basis: Art. 6(1)(a) GDPR.

We do not use Google Customer Match.

25. Meta Pixel / Facebook Pixel

We use Meta Pixel / Facebook Pixel to measure conversions, improve ads and create remarketing audiences.

Meta may process:

  • pixel ID;
  • IP address;
  • browser data;
  • device data;
  • page views;
  • purchase events;
  • cart events;
  • conversion events;
  • hashed customer data where advanced matching is enabled.

Meta Pixel is used only with your consent.

Legal basis: Art. 6(1)(a) GDPR.

Where required, we enter into Meta’s applicable controller or joint controller terms.

26. TikTok Pixel

We use TikTok Pixel for conversion tracking, ad measurement and retargeting.

TikTok may process technical data, event data, device data, browser data and conversion data.

TikTok Pixel is used only with your consent.

Legal basis: Art. 6(1)(a) GDPR.

27. Twitter/X Conversion Tracking

We use Twitter/X Conversion Tracking to measure the performance of advertising campaigns and conversions.

Twitter/X may process device data, browser data, ad interaction data, conversion events and website behaviour.

Twitter/X Conversion Tracking is used only with your consent.

Legal basis: Art. 6(1)(a) GDPR.

Provider details should be checked before publication against the current X/Twitter legal entity and applicable data transfer terms.

28. Facebook and Pinterest social plugins

We use social plugins from Facebook and Pinterest.

Where possible, social plugins are integrated through a two-click or consent-based solution. This means that data is not transmitted to the provider until you activate the plugin or give consent.

Legal basis: Art. 6(1)(a) GDPR.

If you are logged into the relevant social network, the provider may associate your interaction with your account.

29. YouTube videos

We embed YouTube videos on our website.

YouTube videos are loaded only after your consent, unless embedded in a privacy-friendly mode that does not trigger consent-relevant access before activation.

Legal basis: Art. 6(1)(a) GDPR.

Google/YouTube may process IP address, device data, playback data, interaction data and cookie or similar identifiers.

30. Judge.me reviews

We use Judge.me to collect and display customer reviews.

Judge.me may process:

  • name;
  • email address;
  • order number;
  • product purchased;
  • review content;
  • rating;
  • photos, if uploaded;
  • IP address;
  • review metadata.

Legal basis:

  • Art. 6(1)(a) GDPR if you voluntarily submit a review;
  • Art. 6(1)(f) GDPR for displaying verified reviews and improving customer trust;
  • Art. 6(1)(b) GDPR where review communication is connected to a purchase process and legally permitted.

If review request emails are sent, we ensure that they are covered by consent or another legally valid basis under German marketing rules.

31. UpPromote Affiliate

We use UpPromote Affiliate to manage affiliate, referral or partner marketing.

UpPromote may process:

  • affiliate name and contact details;
  • referral links;
  • coupon codes;
  • attribution data;
  • order data linked to referrals;
  • commission data;
  • tracking identifiers.

Legal basis:

  • Art. 6(1)(b) GDPR for affiliate contract management;
  • Art. 6(1)(f) GDPR for referral attribution and fraud prevention;
  • Art. 6(1)(a) GDPR where affiliate tracking on user devices requires consent.

Affiliate tracking that is not strictly necessary is activated only after consent.

32. Cozy Country Redirect

We use Cozy Country Redirect to show country-specific shop versions, language options, currency options or regional redirects.

The tool may process:

  • IP address;
  • approximate location;
  • browser language;
  • device data;
  • selected country/language settings.

Legal basis:

  • Art. 6(1)(f) GDPR for user-friendly localisation and correct regional shop display;
  • Art. 6(1)(b) GDPR where localisation is necessary for contract or checkout information.

Where cookies or similar technologies are used for non-essential purposes, consent may be required.

33. Tools not currently used

According to our current setup, the following tools are not used:

  • Odoo;
  • Stripe;
  • Hotjar;
  • Google Customer Match;
  • LinkedIn Insight Tag;
  • Microsoft Advertising / UET;
  • Snap Pixel;
  • reCAPTCHA;
  • Gravity Forms.

If these tools are activated in the future, this Privacy Policy and the cookie consent settings must be updated before activation.

34. International data transfers

Some providers may process data outside the EU/EEA, especially in the United States.

Where data is transferred to third countries, we rely on one or more of the following safeguards:

  • adequacy decision;
  • EU-US Data Privacy Framework where the recipient is certified;
  • Standard Contractual Clauses;
  • additional technical and organisational safeguards;
  • consent where required.

The EU-US Data Privacy Framework applies only to participating certified US organisations. dataprivacyframework.gov

We process certain personal data to comply with legal obligations, especially commercial, tax, accounting, consumer protection and legal defence obligations.

Legal basis: Art. 6(1)(c) GDPR.

36. Data retention

We store personal data only for as long as necessary for the relevant purpose.

Data type Typical retention
Server logs Short-term, unless security investigation requires longer
Customer account Until deletion request, unless legal retention applies
Orders and invoices Usually 6–10 years under German commercial/tax rules
Newsletter consent Until withdrawal plus documentation period
Cookie consent logs As long as needed to prove consent
Support requests As long as needed to handle the request and legal defence
Analytics data According to tool settings
Affiliate records Contract term plus accounting/legal retention periods
AI quiz data under GTI GmbH control Maximum 30 days, unless a longer period is legally required

37. Your rights

You have the following rights under GDPR:

  • right of access, Art. 15 GDPR;
  • right to rectification, Art. 16 GDPR;
  • right to erasure, Art. 17 GDPR;
  • right to restriction of processing, Art. 18 GDPR;
  • right to data portability, Art. 20 GDPR;
  • right to object, Art. 21 GDPR;
  • right to withdraw consent, Art. 7(3) GDPR;
  • right to lodge a complaint with a supervisory authority, Art. 77 GDPR.

You may contact us at: privacy@maxler.com

The competent supervisory authority for GTI GmbH in Düsseldorf, Germany is generally the data protection authority of North Rhine-Westphalia.

38. Right to object

If we process your personal data based on legitimate interests under Art. 6(1)(f) GDPR, you may object to this processing at any time on grounds relating to your particular situation.

If we process your personal data for direct marketing, you may object at any time without giving reasons.

After your objection, we will stop processing your data for direct marketing.

39. Withdrawal of consent

Where processing is based on consent, you may withdraw your consent at any time with effect for the future.

You can withdraw cookie and tracking consent through the cookie settings on our website.

You can withdraw newsletter consent through the unsubscribe link in each email.

40. DACH-specific notes

Germany

For Germany, this Privacy Policy is based on the GDPR, the German Federal Data Protection Act where applicable, and the TDDDG for cookies, pixels, local storage and similar technologies.

For Germany, non-essential analytics, marketing, retargeting and social media tracking should not load before valid consent.

Austria

For Austria, the GDPR also applies. Cookie and tracking rules are additionally governed by Austrian telecommunications rules, especially for storage of or access to information on user devices. Consent is generally required for non-essential cookies and similar technologies.

Switzerland

For Switzerland, the Swiss Federal Act on Data Protection may apply in addition. The revised Swiss FADP has applied since 1 September 2023. Federal Office of SMEs

Swiss users may have rights under Swiss data protection law, including rights to information, access, correction and, where applicable, deletion or restriction.

41. Updates to this Privacy Policy

We may update this Privacy Policy if our website, tools, providers, legal requirements or processing activities change.

The current version is available on our website.

GET STARTED TODAY

Take the first step in changing your life - today.