Solutions
Digistore24 Digistore24
Migration Service

A one-on-one experience with the Digistore24 team to ensure your offer is optimally set-up and ready to rake in the sales.

Features & Pricing
More
Hall of Fame Awards

Claim your Hall of Fame Award for your exceptional performance achieving over $1,000,000 in revenue with Digistore24.

Press portal & newsroom

Explore the latest press information, company updates and media resources for your reporting.

Club24 Awards

The most exclusive community for Digistore24’s most elite marketers.

Digistore24 Blog

Discover marketing tips & trends for the successful digital entrepreneur

Svencast Podcast

Listen. Grow. Repeat. With the founder & CEO of Digistore24.

Migration Service

Switch to Digistore24 and we'll help migrate your business seamlessly.

Conversion report

Maximize profitability with the Conversion Cockpit, your sales funnel optimization tool.

Status Page

Check the uptime on our live status page.

Help

Search for help with Digistore24.

For Buyers
Find your order

Assign debits and payments to an order or find your order ID and order.

Manage orders

Manage your orders centrally – including invoices, payment plans and product access.

Cancel contract

Cancel ongoing contracts and subscriptions online.

Withdraw from contract

Withdraw from your contract online.

Help with online purchase

Step-by-step guides and concrete information on ordering, payment, access and cancellation

en
Select your language
Privacy Policy

Privacy Policy

1. General

This Privacy Policy provides information about the processing of personal data in connection with the use of our website and our other online presences. It applies in particular to general visits to our website and to our activities as a reseller vis-à-vis end customers.

Please note that we reserve the right to amend this Privacy Policy from time to time. When you visit this page again, the updated Privacy Policy applies.

Note: The type and scope of data processing depend on the respective role of the data subject.

Vendor: A Vendor is the provider of a product or the product manufacturer that creates the respective product and makes it available for marketing.

Affiliate: An Affiliate is an advertising third party that promotes a Vendor's products and draws potential customers' attention to them.

End Customer: The End Customer is DS24’s contractual partner who purchases a product through DS24 and thereby makes use of the service offered.

This Privacy Policy is intended solely for our End Customers.

2. Who is responsible for processing the data?

Digistore24 GmbH
St.-Godehard-Straße 32, 31139 Hildesheim, Germany
Phone: +49 (5121) 9288860
Email: datenschutz@digistore24.com

For more information about our company, please see our legal notice (https://www.digistore24.com/page/imprint).

3. Who can you contact if you have questions about data protection?

Data Protection Officer: Simon Hofer
Email: datenschutz@digistore24.com

4. How do we process your personal data?

We collect and process personal data only to the extent necessary to fulfill our purposes and based on a legal basis in accordance with Art. 6 of the GDPR. We will treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.

The data may also be processed outside the EU or the EEA. Data may be transferred to third countries only if appropriate safeguards are in place, standard contractual clauses have been entered into, or the European Commission has issued an adequacy decision in accordance with Art. 45(3) GDPR.
If you have any further questions about this, please feel free to contact datenschutz@digistore24.com.

4.1. Hosting the website and creating log files

What data is processed?

Every time our website is accessed, our system automatically collects data and information from the computer system of the device used to access the site.

The following data is processed in this context:

This data is not stored together with the user's other personal data.

Since the data is transmitted automatically when you visit the website, it is not possible to use our website without this data being processed. There is no legal or contractual obligation to provide this information; furthermore, providing it is not necessary for the conclusion of a contract.

For what purpose is the data processed?

The system must temporarily store the IP address in order to deliver the website to the user's computer (website provision). To do this, the user's IP address must be stored for the duration of the session.

Data is stored in log files to ensure the proper functioning of the website. The data is also used to ensure the security of our information technology systems, to defend against and analyze attacks, and to analyze errors and ensure the stability of our systems.
In addition, we use the data in aggregated form to optimize the website from a technical standpoint.

In this context, the data is not analyzed for marketing purposes.

On what legal basis is this data processed?

The legal basis for the temporary storage of data and log files is Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the technically flawless display and operation of our website, optimizing the website, ensuring system security and stability, and detecting, defending against, and analyzing attacks on our information technology systems.

Who is the recipient of the data?

In connection with the operation of the website, we use external service providers, such as hosting providers and IT service providers, who act as data processors in accordance with Art. 28 GDPR. These parties receive only the data necessary to perform the respective service. Data processing is carried out on the basis of a data processing agreement in accordance with Art. 28 GDPR.

How long is the data stored?

The data will be erased as soon as it is no longer necessary to achieve the purpose.

Storage for the purpose of providing the website (session data)
In cases where data is collected for the purpose of providing the website, this is generally when the respective session has ended.

Storage of data in log files
The IP address and the HTTP user agent are stored in plain text in the web server log files for a maximum of six weeks for the purpose of detecting and analyzing attacks on our website.

Data will only be retained beyond this period in justified individual cases, when it is necessary in connection with specific security-related incidents to preserve evidence or pursue legal action. In such cases, the data will be erased as soon as the purpose for its continued retention no longer applies.

4.2. Provision of order forms and contract processing

4.2a. Order form for the Digistore24 GmbH website

What data is processed?

As part of providing the order form and processing the contract, we process personal data—some of which is collected automatically, and some of which you enter into the order form. This includes, in particular, the following data:

If you repeatedly purchase products from the same Vendor through us, these orders will be consolidated under a single customer ID (customer number).

To view your orders, you must enter the email address you used to place them. A one-time password valid for a limited time (15 minutes) will be sent to this email address. Using this one-time password along with your email address, you can access your order summary page.

There is no legal obligation to provide the data. The data marked as required on the order form is necessary for the conclusion and performance of the contract; without providing this information, the order cannot be completed or the contract cannot be performed.
This does not apply to information provided voluntarily; failure to provide such information has no effect on the conclusion of the contract.

For what purpose is the data processed?

Your personal data is processed through the order form for the purpose of taking pre-contractual measures in response to your request, processing and fulfilling orders, handling payments, providing an order summary and other customer services, and grouping and managing multiple orders from a single customer, as well as for the technical provision, security, and optimization of the ordering process (such as fraud prevention and error analysis).

On what legal basis is this data processed?

The legal basis for the processing of personal data in connection with order fulfillment is Art. 6(1)(b) GDPR.

To the extent that processing is necessary to ensure the security and stability of the ordering process or to prevent fraud, and goes beyond the mere fulfillment of the contract, such processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR to ensure a secure and seamless ordering process.

The processing of voluntary additional information provided during the ordering process is based on your consent in accordance with Art. 6(1)(a) GDPR. Providing this information is voluntary and is not required for the conclusion or performance of the contract. To the extent that we transmit voluntary additional information to the respective vendor, such transmission is based on Art. 6(1)(f) GDPR. Our legitimate interest in this regard lies in the proper assignment of referral and brokerage relationships, the traceability of the origin of orders, and the analysis and optimization of our sales, partnership, and ordering processes.

Who is the recipient of the data?

The data collected on the order form will be transmitted to the respective vendor whose product you are purchasing, to the extent necessary for the performance of the contract.

In addition, IT and hosting service providers are involved in the processing as part of the technical provision of the order form and the systems. We enter into data processing agreements with service providers who process personal data on our behalf, in accordance with Art. 28 GDPR.

How long is the data stored?

Personal data will be stored only for as long as is necessary to process the order and to fulfill contractual and legal obligations.

Contract and order data are stored for the duration of the contractual relationship and beyond, in accordance with statutory retention periods.

Data relevant to payments and billing is retained in accordance with tax and commercial law regulations, among others, and is deleted after eight years.

4.2b. Multi-Step Order Box—note on joint liability

The Multi-Step Order Box (MSOB) is a version of our order form that allows Vendors to integrate it into their own websites. In this case, the Vendor is responsible for the content and design of the sales page.

What data is processed?

When using the Multi-Step Order Box, the same categories of personal data are processed for the same purposes as when using the order form on our website (see 4.2a). The data in question is as follows:

There is no legal obligation to provide the data. The data marked as required on the order form is necessary for the conclusion and performance of the contract; without providing this information, the order cannot be completed or the contract cannot be performed.
This does not apply to information provided voluntarily; failure to provide such information has no effect on the conclusion of the contract.

For what purpose is the data processed?

Data is processed for the purposes of carrying out pre-contractual measures and fulfilling the order, processing payments, providing an order summary and customer services, and grouping and managing multiple orders from a single customer, as well as the technical implementation, security, and optimization of the ordering process.

On what legal basis is this data processed?

The processing of personal data in connection with the use of the Multi-Step Order Box is carried out in accordance with Art. 6(1)(b) GDPR for order and contract processing, as well as, in addition, Art. 6(1)(f) GDPR for security- and functionality-related processing, such as ensuring the security and stability of the ordering process and preventing fraud.

Joint controllership under Art. 26 GDPR

In connection with the use of the Multi-Step Order Box, we and the respective vendor are joint controllers for certain processing operations within the meaning of Art. 26 GDPR. This applies in particular to the collection of personal data via the order form and its transmission to us for the purpose of processing the order. Upon completion of the order, Digistore24 GmbH becomes the End Customer's contractual partner.

As part of a joint responsibility agreement, we and the Vendor have defined our respective responsibilities under data protection law.

The Vendor is responsible, in particular, for the processing of personal data in connection with its sales page (specifically, content, advertising, and other offers on its website), the collection of data on that page, the fulfillment of its information obligations under Art. 13 and 14 GDPR, and the technical and organizational measures within its sphere of responsibility.

We are specifically responsible for processing the personal data collected during the ordering process and transmitted to us for the purpose of contract fulfillment, for further processing in connection with the performance of the contract, and for complying with our obligations under data protection law in this regard.

Both joint controllers support each other in handling inquiries from data subjects and coordinate with each other as necessary.

The vendor provides you with the information required under Art. 13 and 14 GDPR regarding the processing operations for which it is responsible in connection with its sales page. We will inform you about the data processing activities for which we are responsible as part of the ordering process and contract fulfillment.

If you have any questions regarding the processing of your personal data in connection with order fulfillment, you can contact us as your central contract point.

Regardless of this internal allocation of responsibilities, you may exercise your rights as a data subject under Art. 15 through 22 GDPR (in particular, the right to access, rectification, erasure, restriction of processing, data portability, and objection), as well as your other rights under the GDPR, both with us and with the respective Vendor.

4.4. Payment processing

What data is processed?

As part of the ordering process, we process the personal data necessary to complete the payment transaction. This includes:

The actual payment details (e.g., (full credit card number, security code, online banking login credentials) are generally processed and stored directly by the respective payment service providers. We receive only information from the payment service providers regarding whether a payment has been authorized, confirmed, or declined, as well as general transaction identifiers, if applicable.

If you select “credit card” as your payment method, we will also store the first six digits of your credit card number. These digits provide information about the issuing bank and the card's country of origin, and we use them to analyze payment declines and improve payment acceptance.

There is no legal obligation to provide this information. However, the information required for the selected payment method is necessary for processing the payment and, therefore, for concluding the contract; without this information, the payment cannot be processed and the contract cannot be concluded.

For what purpose is the data processed?

The aforementioned data is processed for the purpose of executing payment transactions within the framework of contractual relationships, ensuring proper payment flows (matching payments to orders, posting payments, chargebacks, refunds), preventing fraud and detecting misuse, and ensuring the secure and efficient processing of domestic and international payment transactions.

On what legal basis is this data processed?

The processing of data for the purpose of carrying out payment transactions and fulfilling the underlying contract is based on Art. 6(1)(b) GDPR for the fulfillment of a contract.

The processing of certain data to ensure payment flows, prevent fraud, and analyze and optimize payment processes is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in ensuring secure and efficient payment processes and protecting against payment and fraud risks.

Who is the recipient of the data?

The categories of recipients of the data processed as part of payment processing are:

In certain cases, payment service providers may also transmit personal data to credit agencies or other service providers in order to perform identity or credit checks or to prevent fraud. The privacy policies and terms and conditions of the respective selected payment service providers apply to this independent data processing.

How long is the data stored?

The storage period for the data is based on statutory retention periods, in particular tax and commercial law provisions; after the expiration of eight years, the data is automatically deleted.

4.5. Credit check when selecting the direct debit payment method

What data is processed?

As part of the credit check, we process personal data that is required to assess your creditworthiness. This includes:

We transmit the data required for the credit check to a credit agency.

The master data and address data used for the credit check come from the information you previously provided during the ordering process. We receive creditworthiness information and score values from the credit agency used in each case. Without processing the required data, it cannot be determined whether the “direct debit” payment method can be offered to you.

Automated decision-making as part of the credit check

As part of the credit check, an automated assessment of your creditworthiness information, including a score value provided by the credit agency, is carried out. The score value is used to assess the risk of payment default and is used to decide whether the “direct debit” payment method can be offered to you.

If the credit check indicates an increased risk of payment default, this may result in the “direct debit” payment method not being available to you. In this case, you can choose another payment method offered by us. The decision concerns only the availability of the payment method and has no impact on the conclusion of the contract as such, provided that another offered payment method is selected.

If a decision is based solely on automated processing and produces legal effects concerning you or similarly significantly affects you, you have the right to request that the decision be reviewed by a person, to state your own position, and to contest the decision. To exercise these rights, you may contact us at any time using the contact options provided in this Privacy Policy.

For what purpose is the data processed?

The processing is carried out for the purpose of checking your creditworthiness and your previous payment behavior, as well as assessing the risk of payment default associated with a contractual relationship.

The credit check and credit monitoring serve in particular to economically safeguard our contractual relationships, prevent payment defaults, assess whether and under what conditions a contractual relationship can be established or continued, and enforce and secure our contractual claims.

The credit check is carried out only if you select the “direct debit” payment method. Depending on the result of the check, the “direct debit” payment method may be offered or rejected.

On what legal basis is this data processed?

This processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in economically safeguarding our contractual relationships, preventing payment defaults, and supporting business decisions in connection with the establishment, performance, or enforcement of contractual relationships.

A legitimate interest in obtaining a credit report exists in particular in connection with the conclusion of a contract if we bear an economic default risk.

Who is the recipient of the data?

The recipient of the data transmitted as part of the credit check is:

infoscore Consumer Data GmbH
Rheinstrasse 99
76532 Baden-Baden

You can find the information pursuant to Art. 14 GDPR on the data processing carried out by infoscore Consumer Data GmbH at: https://www.experian.de/icd-infoblatt.

How long is the data stored?

We store the data processed by us as part of the credit check only for as long as this is necessary for the decision on approving the “direct debit” payment method and for the performance or handling of the respective contractual relationship. The data required for the specific credit inquiry is processed only for a short period in order to determine whether the “direct debit” payment method can be offered.

The storage period for the data processed by infoscore Consumer Data GmbH under its own responsibility is based on its own erasure and storage periods. Further information on this can be found pursuant to Art. 14 GDPR in the information provided by infoscore Consumer Data GmbH at: https://www.experian.de/icd-infoblatt.

4.6. Receivables management and debt collection in the event of late payment

What data is processed?

In the event of late payment, we process personal data that you provided to us during the ordering process and for payment processing and that is required to process and enforce outstanding receivables. This includes:

We use this data to map the respective receivables process.

For what purpose is the data processed?

The processing is carried out for the purpose of receivables management and the enforcement of outstanding payment claims in the event of late payment. This includes, in particular, managing and documenting outstanding receivables, contacting the debtor (e.g. issuing payment reminders and dunning notices), reviewing and allocating incoming payments, deciding on further measures in debt collection, and out-of-court and, if applicable, judicial enforcement of claims.

On what legal basis is this data processed?

The processing of the aforementioned data as part of receivables management is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Our legitimate interest lies in enforcing legitimate receivables, economically safeguarding our company, and properly documenting and handling contractual relationships.

Where the receivable results from a contractual relationship with you, the processing is additionally based on Art. 6(1)(b) GDPR for the performance of a contract and handling of the contractual relationship.

Who is the recipient of the data?

Recipients of the data as part of receivables management are our debt collection partners:

Creditreform Essen Stenmans & Waterkamp KG
Hohenzollernstraße 40
45128 Essen

and

PAIR Finance GmbH
Knesebeckstraße 62-63
10719 Berlin

The disclosure takes place only to the extent necessary to review, process, and enforce the respective receivable. This may include the debtor data already mentioned (name, address, contact and communication data, and, if applicable, company data), contract, invoice, and payment data, and order data (e.g., contract date, currency, amount of the receivable, case or reference numbers).

In individual cases, it may also be necessary to disclose information about outstanding receivables to the respective Vendor, insofar as this is necessary to clarify the facts, coordinate receivables management, or enforce contractual claims. In these cases as well, disclosure takes place only to the extent necessary and on the basis of our legitimate interest (in this respect, we refer to the section above).

How long is the data stored?

The data is stored only for as long as this is necessary to enforce the receivable and to fulfill statutory retention obligations.

Commercial and tax law retention periods generally apply to receivables and invoice data. These are eight years, calculated from the end of the calendar year in which the respective invoice was issued.

As soon as the receivable has been settled and there are no statutory or contractual retention obligations and no legitimate interests in further storage, the relevant data will be erased or anonymized.

4.7. Contact or support inquiries

What data is processed?

If you contact us as an End Customer, we process the personal data transmitted as part of the communication. This includes:

In addition, technical data may be processed that is required to ensure system security and proper transmission.

Contacting us is voluntary; there is no legal obligation to provide your data. However, the information required for processing your request must be provided. Without this information, we may not be able to process your inquiry, or may be able to do so only to a limited extent. If your inquiry relates to an existing contract, processing the data may also be necessary for its performance.

For what purpose is the data processed?

The data transmitted when you contact us is processed to handle and answer your inquiry, document the process, clarify contract-related matters such as questions about orders, invoices, withdrawal, termination, and warranty, and ensure the functionality and security of our support and communication system.

On what legal basis is this data processed?

The legal basis for processing the data transmitted in the course of contacting us is Art. 6(1)(f) GDPR. Our legitimate interest lies in handling and answering your inquiry and in providing an efficient and secure support system.

If the contact is aimed at concluding, performing, or modifying a contract (such as termination, withdrawal, or contract content), the processing is additionally carried out on the basis of Art. 6(1)(b) GDPR.

Who is the recipient of the data?

To process support inquiries, we use service providers for the recording, management, and processing of support tickets and for the transcription of telephone inquiries as processors pursuant to Art. 28 GDPR.

Disclosure to other third parties takes place only insofar as this is necessary in the individual case to process your inquiry (e.g., to the respective Vendor for contract-related questions) or there is a legal obligation to do so.

How long is the data stored?

The data is erased as soon as it is no longer required to achieve the purpose for which it was collected.

For documentation and legal defense purposes, we generally store support inquiries as well as data subject requests and our responses to them for up to three years after the respective inquiry has been completed.

Insofar as statutory retention obligations (e.g., commercial or tax law provisions) or legitimate interests (e.g., preservation of evidence in legal disputes) exist, storage beyond this period may take place to the extent necessary. The data will then be erased or anonymized.

Note on partially automated processing

To process inquiries more quickly, we partially use AI-supported procedures. In this context, your inquiry may be processed, pre-sorted, summarized, or answered with the help of an AI system.

If the AI system merely supports our employees and the final decision is made by a natural person, no solely automated decision within the meaning of Art. 22 GDPR takes place.

For inquiries regarding returns, withdrawals, or terminations, an AI-supported process may automatically check, based on a defined decision tree with predefined criteria, whether the requirements for carrying out the requested action are met. In particular, the type and time of the inquiry, order or contract status, relevant deadlines, and statutory or contractual requirements are taken into account. You can identify the automated response to your inquiry by the label “Response automatically generated in accordance with our defined support workflows” within our response to you.

If this results in a solely automated decision that produces legal effects concerning you or similarly significantly affects you (automatic acceptance or rejection of a return, withdrawal, or termination), you have the right to request a review by a natural person, to state your own position, and to contest the decision. You can exercise this right by replying to our email and requesting human review. In this case, your request will be reviewed individually by an employee.
Such an automated decision is made pursuant to Art. 22(2)(a) GDPR, insofar as it is necessary for the conclusion, performance, or rescission of the contract between you and us. The effects of the decision are that the action you requested may be carried out or rejected automatically. In the event of a rejection, you will be informed of the main reason for the decision.

The personal data processed as part of your inquiry is not used to train generally available AI models. We have contractually obligated the service providers used accordingly. The service provider is used for this purpose on the basis of a data processing agreement pursuant to Art. 28 GDPR. The data may also be processed outside the EU or the EEA. Data transfer takes place only where appropriate safeguards are in place, standard contractual clauses have been concluded, or an adequacy decision exists.

4.8. Newsletter delivery

What data is processed?

If you subscribe to our newsletter, we use your email address to send our newsletter. In addition, we send newsletters as part of advertising to existing customers under the statutory requirements for our own similar goods or services.

The following data is processed as part of newsletter delivery:

The data is used exclusively for sending and managing our newsletters or for permissible direct advertising to existing customers.

Subscribing to the newsletter is voluntary. There is no legal or contractual obligation to provide your email address, and it is not required for the conclusion of a contract.

For what purpose is the data processed?

The email address is processed for sending newsletters containing direct advertising.

If we received your email address in connection with the sale of goods or services, we may use it, subject to the requirements of Section 7(3) UWG [German Act Against Unfair Competition], for direct advertising for our own similar goods or services. Such use takes place only if you have not objected to the use of your email address for advertising purposes. Both when your email address is collected and each time it is used for advertising, you will be informed that you may object to its use at any time free of charge.

On what legal basis is this data processed?

Insofar as you expressly subscribe to our newsletter, processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Art. 7 GDPR.

The processing of your email address for direct advertising to existing customers is carried out on the basis of our legitimate interest in advertising our own similar goods or services pursuant to Art. 6(1)(f) GDPR, taking into account the requirements of Section 7(3) UWG.

Who is the recipient of the data?

For sending and managing the newsletters, we use email marketing service providers as processors.

A data processing agreement pursuant to Art. 28 GDPR exists with this service provider. The service providers use the data exclusively according to our instructions and not for their own purposes.

How long is the data stored?

The data is erased as soon as it is no longer required to achieve the purpose for which it was collected. After unsubscribing, withdrawing consent, or objecting, your email address and the associated marketing data will be removed from the active mailing lists.

Option to object and remove

You may withdraw your consent to receiving the newsletter at any time with effect for the future. The lawfulness of the processing carried out on the basis of your consent until withdrawal remains unaffected.

The newsletter subscription can be canceled at any time using the unsubscribe link included in every newsletter email. Alternatively, you may declare your withdrawal of consent using the contact methods specified in this Privacy Policy.

After you withdraw your consent, your email address will no longer be used to send the consent-based newsletter.

You may object to the processing of your email address for direct advertising purposes at any time with effect for the future. The objection is free of charge; the only costs that may be incurred are transmission costs according to the basic rates.

You may use the unsubscribe link included in every advertising email or declare your objection using the contact methods specified in this Privacy Policy. After your objection, your email address will no longer be used for direct advertising.

4.9. Applications

You can find the Privacy Policy for applicants at the following link:

https://careers.digistore24.com/privacy

4.10. Tracking and cookies

4.10.1. Google Analytics

On our website, we use Google Analytics, an analytics service provided by the U.S. company Google Inc. ("Google"), 1600 Amphitheatre Parkway, Mountain View, CA 94043, U.S.A. Google Analytics uses "cookies," which are small text files stored on your computer. These cookies are used to analyze your use of our website. The corresponding data about your user behavior is forwarded to a Google server in the U.S., where it is evaluated and stored.
If IP anonymization is activated on this website within the member states of the European Union and the Agreement on the European Economic Area, Google will shorten your IP address for anonymization purposes. Only in exceptional cases will the full IP address be transmitted to the U.S. and shortened on a server there.
Google will use this information at the request of the owner of this website to evaluate how you use the website. Google will also use this information to prepare reports on website activity and to provide other services related to website use and internet use for the website operator. Google does not combine the IP address transmitted by your browser through the use of Google Analytics with other Google data.
You can prevent cookies from being stored by making the appropriate setting in your browser. However, in this case, you may not be able to use all functions of the website to their full extent. You can prevent the collection of the data generated by the cookie (including your IP address) about your use of the website and the processing of this data by Google. To do this, you only need to download and install an additional browser plug-in. You can download this plug-in at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.

4.10.2. Google Maps

We use Google Maps (API) provided by the software company Google Inc. The controller for the European region is Google Ireland Limited, Gordon House, Barrow Street Dublin 4, Ireland.
Google Maps is an interactive map service for visualizing geographic data and for determining and processing location data. We use Google Maps to help our customers fill in address fields.
We use Google Maps on the basis of your consent within the meaning of Art. 6(1)(a) GDPR.
When Google Maps is used, your personal data is processed and stored. This includes:

Because Google Maps is integrated into our website, cookies are also set that collect data concerning your user behavior.
Google does not clearly communicate whether, where, and for how long this data is stored by Google. However, because Google operates a large portion of its servers in the U.S., it can be assumed that the data mentioned above is also processed and stored there. You can find a list of Google data centers here: explore our data center locations. We have no influence over the storage location of the data mentioned above.
We point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the U.S. This may be associated with various risks for the lawfulness and security of data processing.
As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway) or for data transfers there, Google uses standard contractual clauses approved by the EU Commission (Art. 46(2) and (3) GDPR). These clauses oblige Google to comply with the EU level of data protection when processing relevant data outside the EU as well. These clauses, in turn, are based on an implementing decision of the EU Commission.
If you generally do not want cookies, you can configure your browser so that it always informs you when a cookie is about to be set. You can then decide for each individual cookie whether to allow it or not.
Further information is available at Privacy and Data Collection | Google Fonts | Google Developers and Privacy Policy—Privacy Policy & Terms of Service—Google
To have data stored by Google erased, please contact Google Support at Google Help.

4.10.3. Google Marketing Platform

We use Google Marketing Platform (formerly “Google Doubleclick”) provided by the software company Google Inc. The controller for the European region is Google Ireland Limited, Gordon House, Barrow Street Dublin 4, Ireland.
This service sets cookies to serve relevant advertisements and to optimize reports and analyses on campaign performance. Google records which ads have already been displayed in the user's browser and thereby prevents them from being displayed multiple times. Google can also use the cookies set to determine whether a user accesses the advertiser's website after being shown an ad and purchases a product there. According to Google, however, the cookies used do not contain any personal data.
However, your browser also establishes a direct connection to one or more Google servers. In this process, your personal data is processed. This includes:
The website / website area accessed Your IP address Usage data / metadata
Google does not clearly communicate whether, where, and for how long this data is stored by Google. However, because Google operates a large portion of its servers in the U.S., it can be assumed that the data mentioned above is also processed and stored there. You can find a list of Google data centers here: explore our data center locations. We have no influence over the storage location of the data mentioned above.
We point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the U.S. This may be associated with various risks for the lawfulness and security of data processing.
As the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway) or for data transfers there, Google uses standard contractual clauses approved by the EU Commission (Art. 46(2) and (3) GDPR). These clauses oblige Google to comply with the EU level of data protection when processing relevant data outside the EU as well. These clauses, in turn, are based on an implementing decision of the EU Commission.
Further information is available at Google Marketing Platform | Unified Advertising and Analytics and Privacy Policy | Privacy Policy & Terms of Service—Google
To have data stored by Google erased, please contact Google Support at Google Help.
The processing is carried out on the basis of your consent within the meaning of Art. 6(1)(a) GDPR.

4.10.4. Hotjar

We use Hotjar to better understand the needs of our users and to optimize the offering on this website. Using Hotjar's technology, we gain a better understanding of our users' experiences (e.g., how much time users spend on which pages, which links they click, what they like and dislike), and this helps us align our offering with our users' feedback. Hotjar uses cookies and other technologies to collect information about the behavior of our users and about their devices (in particular, the device's IP address (collected and stored only in anonymized form), screen size, device type (unique device identifiers), information about the browser used, location (country only), and preferred language for displaying our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we use the information to identify individual users or combine it with further data about individual users. You can object to Hotjar storing a user profile and information about your visit to our website, as well as to Hotjar tracking cookies being set on other websites, by clicking this opt-out link.
Hotjar's Privacy Policy provides information about Hotjar's handling of personal data at:
https://www.hotjar.com/legal/policies/privacy

4.10.4. External tracking

We allow our Vendors, after prior review by Digistore24, to use their own tracking code on our order forms. In this process, personal data such as master data (e.g., name, address), usage data (e.g., order ID, time of order) and metadata (e.g., IP address, geodata) is processed.
This data is used exclusively on the basis of your consent within the meaning of Art. 6(1)(a) GDPR and Section 25(1) TTDSG [German Telecommunications Telemedia Data Protection Act].
We refer to our list of approved external tracking providers and their privacy policies:
https://www.digistore24.com/de/home/extern/cms/page/frontend/legal/privacy3rdparty

5. What rights do you have with respect to your data?

5.1. Right of access

You may request confirmation from us as to whether personal data concerning you is being processed by us.
If such processing exists, you may request information from us about the following:

You have the right to request information as to whether the personal data concerning you is transferred to a third country or to an international organization. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.

5.2. Right to rectification

You have the right to rectification and/or completion vis-à-vis us if the processed personal data concerning you is inaccurate or incomplete. We must carry out the rectification without undue delay.

5.3. Right to restriction of processing

Under the following conditions, you may request restriction of the processing of personal data concerning you:

If the processing of personal data concerning you has been restricted, this data may—apart from being stored—be processed only with your consent or for the assertion, exercise, or defense of legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the Union or a member state.

If processing has been restricted under the conditions mentioned above, we will inform you before the restriction is lifted.

5.4. Right to erasure

5.4.1. Obligation to erase

You may request that we erase the personal data concerning you without undue delay. We are obligated to erase this data without undue delay if one of the following reasons applies:

5.4.2. Information to third parties

If we have made the personal data concerning you public and are obligated pursuant to Art. 17(1) GDPR to erase it, we will take appropriate measures, including technical measures, taking into account the available technology and implementation costs, to inform the controllers responsible for data processing that you, as the data subject, have requested that they erase all links to this personal data or copies or replications of this personal data.

5.4.3. Exceptions

The right to erasure does not exist insofar as the processing is necessary:

5.6. Right to be informed

If you have exercised your right to rectification, erasure, or restriction of processing with us, we are required to notify all recipients to whom your personal data has been disclosed of such rectification, erasure, or restriction of processing, unless this proves impossible or involves a disproportionate effort.

You have the right to be informed about these recipients.

5.7. Right to data portability

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format. In addition, you have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that:

In exercising this right, you also have the right to have your personal data transferred directly from one controller to another, provided that this is technically feasible. This must not infringe upon the freedoms and rights of others.

5.8. Right to object

You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you that is based on Art. 6(1)(e) or (f) GDPR.

If you exercise your right to object, we will no longer process the personal data concerning you, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes. This also applies to profiling, to the extent that it is related to such direct marketing.

If you object to the processing of your personal data for direct marketing purposes, your personal data will no longer be processed for those purposes.

In connection with the use of information society services—notwithstanding Directive 2002/58/EC—you have the option to exercise your right to object through automated procedures that use technical specifications.

5.9. Right to withdraw consent under data protection law

You have the right to withdraw your consent under data protection law at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of that consent prior to its withdrawal.

5.10. Right to lodge a complaint with a supervisory authority

Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority—without prejudice to any other administrative or judicial remedy—if you believe that the processing of your personal data violates the GDPR.

The data protection supervisory authority responsible for us is:

The State Data Protection Commissioner of Lower Saxony
Prinzenstraße 5
30159 Hanover
Germany

https://www.lfd.niedersachsen.de/