Data protection
1. Controller and Scope
The controller responsible for the processing described in this statement is:
Fidu Brands GmbH
Otto-Hesse-Str. 19/T9
64293 Darmstadt
Germany
Represented by the managing directors Christian Hinz and Erdem Keles. Commercial Register: Amtsgericht Darmstadt, HRB 95515.
Email: info@lobsterlemonade.com
Phone: +49 6151 384340
Central contact for brand-wide data protection concerns: info@fidubrands.com
This statement applies to the Lobster & Lemonade offer at lobsterlemonade.com as well as to the associated customer and business processes described below. In particular, it explains the type, purpose, legal basis, recipients, and duration of personal data processing, as well as your rights. Not every described process occurs during every visit; your usage, the specific business process, and your consents are decisive.
2. Data Types, Data Sources, and Legal Bases
We process, in particular, identification and contact data, communication content, contract, order, and billing data, as well as technical access and usage data. Which information actually arises depends on your use of our services. Pure product or revenue totals without reference to an identifiable person are not personal data. Customer IDs, cookie IDs, and hashed contact information, however, can still be personal data.
We receive data directly from you, through technically necessary processes during website visits, and, within the framework of the processes described below, from payment and shipping service providers, sales systems, or your company. If data of another person, such as a delivery recipient or a business contact, is communicated to us, we process it only for the corresponding purpose. We will inform you about data not collected from you in accordance with Art. 14 GDPR, provided there is no legal exception.
Consent is the legal basis according to Art. 6 Para. 1 lit. a GDPR. The preparation or fulfillment of a contract with you is carried out according to Art. 6 Para. 1 lit. b GDPR. We fulfill legal obligations, especially regarding accounting and retention, according to Art. 6 Para. 1 lit. c GDPR. Where we rely on Art. 6 Para. 1 lit. f GDPR, we name the respective legitimate interest in the relevant section; the prerequisite is that your interests and fundamental rights do not override.
The legal basis for accessing or storing information in your terminal device must be assessed separately. For this, § 25 TDDDG applies in particular. A legal basis under the GDPR does not replace a required consent under the TDDDG.
3. Website Operation and Hosting with Shopify
We operate our online shop with Shopify. The provider for European platform usage is Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland. Shopify provides, in particular, hosting, content delivery, shopping cart, checkout, and customer account functionalities.
Upon access, the IP address, date and time, requested pages and files, referrer information, browser, operating system, language, device information, transferred data volumes, as well as technical error and security information are processed. For an order, the information described in the section on contract processing is added. IP addresses and other technical identifiers can be personal data.
The processing required to execute an order or account process requested by you is based on Art. 6 Para. 1 lit. b GDPR. General provision, troubleshooting, and protection against attacks are based on Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in the secure and functional operation of the shop. This does not form a general authorization for advertising tracking.
Shopify processes shop data as part of its commissioned processing according to Art. 28 GDPR. For certain of its own services and purposes, Shopify can also be independently responsible, particularly if you use your own Shopify offers such as Shop or Shop Pay. The roles are to be distinguished according to the respective service used.
Shopify companies and subcontractors may process data, in particular, in Ireland, Canada, the USA, and other countries mentioned in the provider information. The Shopify contract documents provide for adequacy decisions and/or standard contractual clauses for recorded international transfers. Details and the possibility to request information on the guarantees can also be found in the section on international data transfers.
Technical logs are retained based on their purpose for provision, troubleshooting, and investigation of security incidents. In the event of a specific incident, only the information required for this will be further processed until its clarification and any necessary legal prosecution. Order and account data are subject to the separate retention rules of this statement.
Further information: Shopify Privacy, Shopify Privacy for Consumers, Shopify Data Processing Addendum.
Optional Shopify Features and Network Intelligence
When using optional personalization and marketing features based on Shopify Network Intelligence, Shopify may combine data about interactions with our shop with information from interactions with other merchants and Shopify. This may particularly affect technical identifiers, device and usage data, viewed products, and purchase interactions. The processing serves the respective improved functions offered, such as personalized recommendations and the measurement or control of advertising.
To the extent that this processing requires consent, we will only integrate it with your consent according to Art. 6 Para. 1 lit. a GDPR and, for corresponding terminal device access, § 25 Para. 1 TDDDG. The required technical shop provision is treated separately. Consent to the general terms and conditions does not replace tracking consent.
To the extent that Shopify is itself responsible for such improved services, Shopify explains its processing, retention rules, international recipients, and legal bases in the linked consumer privacy policy. You can change your selection for our website via the privacy settings. You can also exercise your rights vis-à-vis Shopify via the Shopify Privacy Portal. For our own processing, we remain your contact person.
4. Cookies and Consent Management
Our website uses cookies and similar technologies. This may also include entries in local browser storage, pixels, scripts, and other methods for storing or reading information. A distinction must be made between accessing your terminal device and the subsequent processing of personal data.
Required Functions
Without consent, we only store or read information if a legal exception applies, particularly if it is absolutely necessary to provide a digital service expressly requested by you (§ 25 Para. 2 No. 2 TDDDG), or exclusively serves the transmission of a message (§ 25 Para. 2 No. 1 TDDDG). This may include secure session management, a shopping cart used by you, and saving your privacy selections. Not every useful or economically beneficial function is therefore technically necessary.
The subsequent personal processing is based, depending on the function, on Art. 6 Para. 1 lit. b GDPR, on Art. 6 Para. 1 lit. f GDPR for the necessary technical security, or on Art. 6 Para. 1 lit. c GDPR to fulfill legal proof obligations.
Voluntary Analysis and Marketing Functions
For non-essential analysis, personalized advertising, and other services requiring consent, your prior consent according to § 25 Para. 1 TDDDG and Art. 6 Para. 1 lit. a GDPR is decisive. The purposes and providers are explained in the respective service sections. You can refuse consent without losing basic website or order functionality.
Selection, Proof, and Revocation
Your selection is managed via the cookie or privacy settings. For assignment and proof, the decisions made, the time, the corresponding information version, and a technical consent identifier are processed. The necessary proof processing is based on Art. 6 Para. 1 lit. c in conjunction with Art. 7 Para. 1 GDPR; the terminal device storage of the selection on § 25 Para. 2 No. 2 TDDDG. Recipients are the technical service providers used for website operation and consent management.
You can change or revoke your selection at any time with effect for the future via the cookie or privacy settings available on the website. Additionally, you can contact us using the contact details provided above. The lawfulness of the processing until revocation remains unaffected.
Session identifiers expire at the end of the session or their technically defined validity. Permanent identifiers exist until their expiration or your prior deletion. The specific durations vary depending on the technology; consent proofs are stored as long as the processing based on them and its necessary proof continue to exist. Legally required proofs or those needed for specific legal defense may be retained in a limited manner beyond that.
You can also delete or block cookies in your browser. Deleting them alone does not necessarily revoke previously given consents and does not remove already transmitted data. After changing your browser or device, a new selection may be required.
5. Contact and Customer Service
If you contact us by email, phone, contact form or via an offered customer service, we process the information you provide. This includes name, contact information, your request, if applicable company and function, as well as relevant order, project or complaint information. We only process voluntarily submitted files or images for handling the request. Please do not send sensitive data unnecessary for the request.
If it concerns a contract with you or pre-contractual measures at your request, Art. 6 Para. 1 lit. b GDPR is decisive. For general inquiries or communication with employees and representatives of a business partner, Art. 6 Para. 1 lit. f GDPR is the basis. Our interest lies in the proper processing of inquiries, reliable business relationships, and the documentation of agreements. We process legally required business correspondence according to Art. 6 Para. 1 lit. c GDPR.
Recipients are the respective competent persons at Fidu and the communication and IT service providers used for email, form submission or customer service. Contacting us does not automatically lead to a newsletter subscription or consent to personalized advertising.
Providing a suitable contact option and the information necessary for clarifying the matter is required for a response. After the process is completed, information that is no longer needed will be deleted. Contract documents, business letters, and content necessary for specific legal claims are subject to separate retention rules.
6. Orders, Customer Account and Contract Processing
For offers and orders, we process names, billing and shipping addresses, email address, ordered items, prices, discounts, payment method and payment status, and, if applicable, a phone number or business details required for the specific transaction. The processing serves contract conclusion, delivery, billing, customer service, and the handling of warranty and other contractual claims.
The legal basis is Art. 6 Para. 1 lit. b GDPR; for business contacts of a company, the balancing of interests described in the section on business communication applies. We fulfill commercial and tax law obligations according to Art. 6 Para. 1 lit. c GDPR, in particular in conjunction with § 257 HGB and § 147 AO.
If you use a customer account, we additionally process login and account management data, stored addresses, and the orders assigned to your account. This serves the account function desired by you and is carried out according to Art. 6 Para. 1 lit. b GDPR. You can request the deletion of the account; legally required order and billing documents remain stored separately.
The data marked as required in the ordering process is needed for contract processing. Without it, an order may not be possible. Voluntary information is marked accordingly. Data for newsletters, reach measurement, or personalized advertising is not a prerequisite for a purchase.
7. Payment Processing
When making a payment, we process the identification, billing, order, amount, and transaction data required for the selected payment method. Recipients are the payment service providers, banks, and, if applicable, card or wallet providers involved in the respective payment transaction. Payment instrument data may be collected directly by the payment provider. We receive, in particular, payment status, transaction references, and the information necessary for billing or refund.
Our processing for the execution of the payment is carried out according to Art. 6 Para. 1 lit. b GDPR. Legal documentation is based on Art. 6 Para. 1 lit. c GDPR. To the necessary and proportionate extent, security checks serve our legitimate interest in preventing payment fraud and financial damages (Art. 6 Para. 1 lit. f GDPR). This does not imply permission for general advertising tracking.
PayPal
If you choose PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, receives the data required for the payment. PayPal processes this data for payment processing, fraud prevention, and legal obligations also under its own responsibility. Depending on the PayPal product selected, identity, fraud or credit checks and international transfers are possible. Further relevant information is contained in the PayPal Privacy Policy.
Shopify Payments, Card Payments and Wallets
If you choose a payment method provided via Shopify Payments, Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland, processes the data necessary for providing the payment function. The actual payment processing is carried out by the payment processors and financial institutions integrated for the payment product. When using a wallet, its provider also processes the payment initiated by you. The available payment methods can be seen in the checkout; not every provider receives data for every order.
The payment companies involved also process data to fulfill their own legal obligations, for example, for money laundering prevention and to check payment security. Details are contained in the Shopify Payments Terms and the payment processors referred to therein, as well as the Shopify Privacy Policy.
For an invoice or bank transfer chosen by you, we process the necessary invoice, bank details, and payment receipt data. Payment processing does not occur solely because a payment logo is displayed on our website.
Independently responsible payment service providers determine their retention periods and, if applicable, automated review procedures according to their legal obligations and privacy notices. Your rights against us regarding our own order, accounting, and refund data remain unaffected.
8. Merchandise Management and Order Administration with Xentral
For merchandise management, customer and order administration, offers, invoices, deliveries, and returns, we use Xentral from Xentral ERP Software GmbH, Viktoriastraße 3b, 86150 Augsburg, Germany.
Processed data includes, in particular, customer and contact person data, contact information, billing and delivery addresses, customer and order identifiers, items and quantities, amounts, payment status, invoice and shipping information, as well as return or complaint data. Information from our sales systems can be automatically synchronized with Xentral for this purpose.
Processing for the fulfillment of a contract with you is based on Art. 6 Para. 1 lit. b GDPR. For business contacts and necessary internal organization, Art. 6 Para. 1 lit. f GDPR is decisive; our interest lies in reliable merchandise management, coordinated order processing, and error-free billing. We fulfill legal documentation and retention obligations according to Art. 6 Para. 1 lit. c GDPR.
Xentral is used as a data processor according to Art. 28 GDPR for the data processed under the order. Operational and support service providers receive data only within the scope of their respective tasks. A German provider address alone does not indicate that every technical sub-processing takes place exclusively in Germany. For international sub-processing, the transfer regulations described below also apply.
If you use a returns portal provided via Xentral, the information required to identify the order and process the return, such as order number, contact information, affected items, and reason for return, will be processed for this purpose. Mandatory information is used to process the return; voluntary information beyond this is not a prerequisite for exercising legal rights.
The storage period depends on the respective order and the described contractual, accounting, and retention rules. Further provider information: Xentral Data Protection.
9. Shipping, Delivery and Returns
For delivery or return, we transmit the necessary data to the parcel or transport service provider commissioned for the specific shipping route. This includes name, delivery or pickup address, shipment and tracking number, shipping method, and, if applicable, customs-related information. We receive delivery, return, and, if applicable, damage information.
For shipments handled by DPD, DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany, is the recipient of the necessary delivery data. If another explicitly agreed shipping method is used, the transport service provider commissioned for this purpose will receive the necessary information. The specific carrier is indicated in the shipping or order information.
The transmission of necessary delivery data is for contract fulfillment in accordance with Art. 6 para. 1 lit. b GDPR. For a different named recipient or a business contact person, Art. 6 para. 1 lit. f GDPR may be the basis; our interest lies in the proper execution of the commissioned delivery. Legal customs and documentation obligations are based on Art. 6 para. 1 lit. c GDPR.
An email address or phone number for an additional, voluntary notification service from the carrier is transmitted based on a corresponding consent in accordance with Art. 6 para. 1 lit. a GDPR. If contact information is necessary for an explicitly commissioned special delivery service, such as scheduling an appointment, it will be processed for this specific purpose. The general provision of an email address when placing an order is not considered a blanket consent for further services of the carrier.
For the actual transport, transport service providers regularly act on their own responsibility. Their own storage rules and recipients are also governed by their data protection information. Information on DPD: DPD Data Protection. For cross-border deliveries, necessary recipients in the destination country may be added.
Cancellation, Returns, and Complaints
In the event of a cancellation, return, or complaint, we process the order assignment, your declaration, affected items, and necessary communication, shipping, inspection, and refund information. This serves to process the contract and fulfill legal claims in accordance with Art. 6 para. 1 lit. b or lit. c GDPR. In the case of disputed claims, the necessary legal pursuit or defense may be based on Art. 6 para. 1 lit. f GDPR.
A legal cancellation does not require a reason. Voluntary information on reasons for return is treated separately from the data required for processing. Retention is based on the business transaction and the rules explained in the section on storage duration.
10. Google Analytics
We use Google Analytics for the statistical evaluation of the use of our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The evaluation helps us to assess content, usability, and the effectiveness of our offers.
Subject to appropriate consent, page views, search and click events, sessions, visit times, referrers, technical device and browser information, approximate location information, as well as technical user and session identifiers can be processed. For shop operations, product views, shopping cart actions, and purchase events with item, value, and transaction information may be added. Such identifiers can establish a personal reference, even if we do not see names in the evaluations.
IP addresses are technically processed for communication and the derivation of approximate location information. For access from the EU, Switzerland, and the United Kingdom, Google states that it does not log or store individual IP addresses during this Analytics data collection. This does not mean that all other Analytics data is anonymous.
The processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR; storage or access in the end device requiring consent is based on Section 25 para. 1 TDDDG. You can revoke your consent for the future via our cookie or data protection settings. A server-side transmission method or the omission of a specific cookie does not automatically replace the required legal basis.
Google processes the analysis data collected for us in accordance with its order processing terms. Google companies and subcontractors may also process data outside the EEA, particularly in the USA. Google's contractual documents provide for applicable adequacy decisions or standard contractual clauses for recorded transmissions.
Storage at user and event level depends on the settings of the respective Analytics property. Google distinguishes this data from aggregated standard reports and allows for its automatic deletion after the configured period. For identifiers, an activated extension during renewed use can delay the expiration. The purpose and deletion limits applicable in our area of responsibility also apply to exports or internal evaluations; an export file may not circumvent them.
We only use consent-bound analysis information for the evaluations covered by the consent. For further internal use of reports, please refer to the section on the Fidu Portal. Additional advertising purposes are to be distinguished from mere reach measurement and are not permitted solely by a general statistics consent.
Further information: Google Privacy Policy, Data Processing on Partner Sites, Analytics Data Retention. The Google Browser Add-on is an additional browser-dependent option to limit Analytics collection and does not replace our revocation option.
11. Google Ads, Conversion Measurement and Remarketing
We use Google Ads from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to draw attention to our offers and to measure the success of advertising campaigns. As part of conversion measurement, it can be recorded whether a specific action on our website, such as an inquiry or a purchase, occurs after an ad contact. Remarketing allows targeting previous visitors on other offers with interest-based advertising.
Subject to appropriate consent, advertising and cookie identifiers, click information, referrers, browser and device data, IP address, viewed content, as well as event, product, and purchase value data can be processed for this purpose. Google can assign information to its own user account, provided that the corresponding assignment and its legal requirements are met. A statistical report view on our part does not mean that Google only receives anonymous data.
The legal basis for personal conversion measurement and remarketing is your consent in accordance with Art. 6 para. 1 lit. a GDPR, and for end-device access, additionally Section 25 para. 1 TDDDG. Consent can be revoked via our cookie or data protection settings. A mere viewing of our advertising outside our website is also subject to the data protection information of the respective offer.
Recipients are Google and the technical entities involved in ad delivery. For Google companies and subcontractors in third countries, the transfer regulations provided by Google and the section on international transfers apply. Advertising identifiers and audience assignments are only used within the time windows valid for the respective measurement or re-engagement; after their expiration or an effective revocation, the corresponding future use ends. Google's independent storage is additionally governed by its privacy policies.
Further information: Google Ad Technologies and Google Privacy Policy.
12. Meta, Facebook and Instagram Advertising
We use advertising and measurement services from Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. These include measuring advertising success and creating audiences for Facebook and Instagram advertising. Insofar as events on our website are recorded via the Meta Pixel or corresponding Business Tools, this is done with your corresponding consent.
IP address, browser and device information, technical identifiers, referrers, page and product views, clicks, shopping cart actions, purchases, order values, and timestamps can be processed. Meta can thus associate an ad contact with a later action and, if possible, link the information to a Meta user account. We receive evaluations of ad performance; this does not exclude personal processing by Meta.
The legal basis for our consent-based marketing and measurement processing is Art. 6 para. 1 lit. a GDPR. For storing or reading information from end devices, Section 25 para. 1 TDDDG also applies. You can revoke your consent for the future in the cookie or data protection settings. Meta also provides information on your own Meta account settings.
Insofar as we and Meta jointly determine the purposes and means for the collection and transmission of event data, there is joint responsibility according to Art. 26 GDPR to the extent of the relevant Meta agreement. This specifically regulates responsibility for information, consents, security, and the processing of data subject rights. We are responsible for the lawful integration on our offer and the necessary information. Meta assumes the obligations assigned in the agreement within its systems. You can assert your rights against both controllers irrespective of this division of tasks. For subsequent independent processing by Meta, its privacy policy applies.
A server-side transmission, for example via a Conversions API, or a comparison of hashed contact information, is still subject to the respective consent and information requirements. Hash values are not automatically anonymous. The general use of our website or the completion of a purchase does not constitute blanket permission for customer list matching.
Data may also be processed by Meta companies and technical subcontractors in the USA or other third countries. Meta describes applicable adequacy decisions and standard contractual clauses for this. The validity of these mechanisms is related to the respective recipient and processing operation. Audience and measurement identifiers are used within the validity and retention periods relevant for the specific campaign; Meta provides separate information on its own storage rules.
Further information: Meta Privacy Policy, Meta Business Tools and Joint Controller Addendum.
13. Newsletter and Email Marketing with Klaviyo
For newsletters and the technical administration of our email marketing, we use Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02110, USA.
Registration and Proof of Consent
When you register for a newsletter, we process your email address and voluntary information, such as name or interests. In addition, the registration method, time, given consent, and the technical information required to prove it are also processed. The sending of newsletters based on your registration is based on Art. 6 para. 1 lit. a GDPR and the requirements for electronic advertising under Section 7 UWG.
If the registration method you use requests confirmation of your address, you will receive a confirmation message (double opt-in). The confirmation and the associated times will then also be documented. A confirmation message does not serve as permission for further advertising.
We process necessary proofs in accordance with Art. 6 para. 1 lit. c in conjunction with Art. 7 para. 1 GDPR, and to the extent necessary for specific legal defense in accordance with Art. 6 para. 1 lit. f GDPR. Our legitimate interest in this case is the proof of lawful communication and the defense against unjustified claims.
Content, Personalization, and Automated Messages
Our newsletters provide information about products, collections, promotions, and news of the brand specified during registration or the offer described there. Consent for one brand does not automatically constitute consent for any other brands or communication channels.
Insofar as your consent includes personalization, interests you have indicated, customer identification, purchased items, order values, and times can be linked to the newsletter profile. The processing serves to provide suitable content and avoid irrelevant mailings. The legal basis is Art. 6 para. 1 lit. a GDPR. Technically triggered advertising messages, such as shopping cart reminders, re-engagement messages, or review requests, also require the respective necessary shipping authorization.
Required order and service messages are treated separately from advertising. Their processing is governed by the specific contract and in particular Art. 6 para. 1 lit. b GDPR. The fact that a message is sent automatically does not automatically make it advertising, nor does it automatically make it a permissible contractual message.
Unsubscription, Recipients, and Storage
You can revoke your newsletter consent at any time via the unsubscribe link in a marketing email or by contacting our data protection department. Unsubscription does not affect the legality of processing already carried out. Independently required contractual messages may still be sent.
Klaviyo processes the data provided on our behalf in accordance with its Data Processing Agreement, which is incorporated into the contractual terms, as per Art. 28 GDPR. Processing may take place in the USA. The published DPA provides for the EU-U.S. Data Privacy Framework, where applicable, as well as standard contractual clauses for recorded transfers.
A newsletter profile is used for the duration of the existing shipping authorization. After unsubscription, its use for the revoked advertising purposes ends. Profile and interaction data that are no longer required are deleted or anonymized. A blocking note limited to email address, blocking status, and necessary proof data may remain stored, as long as this is necessary to ensure that the unsubscription is respected even in the event of a new system reconciliation. Consent proofs are only retained for the required proof and, if applicable, specific legal claims; they are not permission to continue advertising.
Further information: Klaviyo Privacy Policy and Klaviyo Data Processing Agreement.
Advertising to existing customers
If we receive your email address in connection with the sale of goods or services, we may use it for our own similar offers under the strict conditions of Section 7 para. 3 UWG. The cumulative requirements are that the address originates from the sale, the advertising concerns our own similar goods or services, you have not objected, and you are clearly informed of the possibility to object at any time, both when the data is collected and with every use. No costs other than the transmission costs at basic rates are incurred.
Our data protection legal basis in this case is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in direct marketing for our own similar offers within an existing customer relationship. You can object at any time without giving reasons via the unsubscribe link or by contacting our data protection department. This exception does not replace any required consent for personalized email success measurement, website tracking, or the creation of more extensive advertising profiles.
14. Newsletter Success Measurement and Website Tracking
Insofar as you have consented to corresponding personalized success measurement, marketing emails may contain individual tracking pixels and assignable links. This allows for the processing of retrievals and clicks, times, message and recipient identifiers, as well as technical information about the device or email program. This information helps us to evaluate content and sending times and to adapt them to interests to the permitted extent. Protection and preloading functions of email programs can influence the measured values.
A mere newsletter registration or the existing customer exception does not automatically constitute consent to personalized tracking. The legal basis for corresponding personalized success measurement is Art. 6 Para. 1 lit. a GDPR; for device access requiring consent, § 25 Para. 1 TDDDG additionally applies.
When using Klaviyo website technologies, page and product views, shopping cart actions, and other website events can be assigned to a known profile after the required consent. This serves the personalization and success measurement covered by the consent. Newsletter consent does not replace this website tracking consent.
You can withdraw website tracking consent via the privacy settings. You can inform us about a withdrawal of personalized email success measurement via the data protection contact; complete unsubscription from marketing emails is also possible via the unsubscribe link. Unsubscription may not be circumvented by new imports.
Interaction data will only be used within the associated sending authorization as long as it is still required for the specific content or campaign evaluation and the consented personalization. This use ends after the purpose is fulfilled or a relevant withdrawal; necessary, separate consent records remain unaffected. Providers, recipients, and international transfer regulations correspond to the preceding Klaviyo section.
15. Embedded YouTube Videos
On pages with embedded YouTube videos, we use the video service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The embedding serves to display product, brand, or other video content you access.
If you activate an embedding that requires consent, your browser may establish a connection to YouTube or Google. During this process, IP address, accessed page, device and browser information, technical identifiers, as well as usage and playback events may be transmitted. Depending on your login and settings, an assignment to a Google account may be possible. Google may also use the information for its own purposes described in its privacy policy.
The embedding requiring consent is based on Art. 6 Para. 1 lit. a GDPR and, insofar as device information is stored or read out, § 25 Para. 1 TDDDG. An extended data protection mode or a different embedding domain is not, in itself, a guarantee that no data will be transmitted. Consent can be revoked via our cookie or privacy settings.
Google companies and subcontractors may also process information in the USA and other third countries. The transfer and storage regulations described in Google's documentation apply in addition. A simple link to a video is to be distinguished from a player already loaded on our website.
Further information: Google Privacy and YouTube Embedding Information.
16. External Links and Social Media
Our website may contain links to our presences on social networks. Simply displaying a simple link does not establish a connection to the target offering solely based on this link. Only when you click the link will the respective provider process information according to their own privacy policies.
This is to be distinguished from embedded posts, feeds, buttons or other external content that already establish a data connection to the provider within our website. For such consent-requiring embeddings, personal data processing takes place according to Art. 6 Para. 1 lit. a GDPR and corresponding device access according to § 25 Para. 1 TDDDG. IP address, visited page, device information, technical identifiers and your interaction with the content may be transmitted. A provider may assign this data to its own user profile depending on the login.
For Facebook and Instagram content, Meta Platforms Ireland Limited, Ireland, is the provider. For other social media offerings you activate or access, the provider information identifiable with the respective content applies. Operators may also process data outside the EEA; the protective mechanisms applicable to the respective embedding must also be observed.
You are not required to enable external content to read other content on our website or to make an inquiry. Given consent can be revoked via the privacy settings. Settings in your own social network account are not automatically changed as a result.
17. Promotions, Contests, and Voluntary Reviews
For a promotion, contest, or review function chosen by you, we process the information necessary for participation, such as contact details, your contribution, a participation or order assignment, and in case of a win, a delivery address. For the execution of an agreed participation, Art. 6 Para. 1 lit. b GDPR is decisive. Voluntary publications or additional advertising use require the respective separate legal basis, especially consent.
A joint promotional partner receives personal data only insofar as it is necessary for the specifically described participation or separately permitted. Special recipients, publication rules, and storage periods are explained with the respective offer. A contest is not a blanket permission to include participants in all brand distributors.
Participation data will be deleted after the conclusion of the promotion and the processing of associated claims, unless legal evidence or valid separate consents preclude this. Promotional review requests via email are treated separately from the necessary processing of an order.
18. Internal Company Management: Fidu Portal
Fidu Brands GmbH operates an internal data platform, the Fidu Portal. Data from merchandise management, associated sales systems, and deployed marketing and analysis systems are provided and evaluated for operational purposes.
Data sources include, in particular, Xentral and - for shop operations - Shopify, as well as Google and Meta reports and, where applicable to the brand, Klaviyo. Not every source system is used on every website. Simply accessing this website does not automatically lead to your data being processed in all mentioned systems.
The central processing serves for the assignment and control of orders, deliveries, returns, and payments, the correction of data errors, and the creation of revenue, cost, inventory, and profitability evaluations. Depending on the task, customer and order identifiers, master data, contact information, items, quantities, amounts, timestamps, and status information are affected. In marketing reports, aggregated campaign metrics are to be distinguished from personal events and profiles.
Processing necessary for the specific contract fulfillment is based on Art. 6 Para. 1 lit. b GDPR; for business contacts, Art. 6 Para. 1 lit. f GDPR applies. Legally required documentation is done according to Art. 6 Para. 1 lit. c GDPR. Necessary internal coordination and business evaluations are based on Art. 6 Para. 1 lit. f GDPR after weighing the interests involved; our interest lies in correct billing, economic planning, and traceable business processes.
Storage in the portal does not create a new blanket permission for advertising or profiling. Data requiring consent may only be further processed within the permissible purpose; a denied or revoked consent may not be circumvented by an internal copy. Cross-brand advertising profiling is not covered by a general permission for company management.
Access is granted according to task and necessity. If personal individual data is not required for an evaluation, data will be reduced accordingly or summarized in an appropriate form. Deletion and restriction also extend to associated copies and exports; legally required documents are handled separately.
19. Database and Backend Infrastructure with Supabase
For the central data platform and the Fidu Portal, we utilize database, backend, and infrastructure services from Supabase. The provider of the published cloud services is Supabase Pte. Ltd., Singapore.
The project set up for our portal uses the region eu-central-1 (Frankfurt am Main, Germany). This means that the primary storage of project data is configured in this region. This does not imply that all support, security, infrastructure, or other secondary processing occurs exclusively in Germany.
The data described in the Fidu Portal section is processed, insofar as it is stored or processed in this infrastructure, as well as technical log, access, and authorization information required for operation. Supabase is used as a data processor according to Art. 28 GDPR for this purpose. The material legal basis depends on the specific purpose of the respective data processing; the choice of a database does not create additional permission.
According to the provider's documentation, Supabase and commissioned technical entities may also process data in Singapore, the USA, or other countries. For recorded transfers to countries without an adequate decision, the Supabase DPA provides, in particular, EU standard contractual clauses. In addition, the actual protection conditions and necessary supplementary measures must be considered. You can request information and a copy of the essential guarantees from us.
The duration of storage is determined by the described processing purposes and the applicable deletion or retention rules. Neither the duration of a Supabase subscription nor the mere existence of a data export justifies unlimited personal storage.
Further information: Supabase Data Processing, Supabase Subprocessors and Supabase Privacy.
20. Other recipients and international data transfers
Within Fidu Brands GmbH, only individuals responsible for the respective process have access. External recipients may include, in addition to the named providers, in particular IT and communication service providers, transport and payment companies, necessary project partners, tax advisors, legal advisors, and competent authorities. Disclosure occurs only to the extent necessary and on the basis specified for the specific purpose. Official disclosures particularly require a corresponding legal obligation or authorization.
Processors are contractually bound according to Art. 28 GDPR. Independent controllers, such as certain payment companies or professional secrecy holders, do not become processors solely due to a business relationship. Joint controllership is only assumed insofar as the actual processing and the applicable regulations provide for it.
For transfers outside the EU and the EEA, we additionally check the required level of data protection. An adequacy decision according to Art. 45 GDPR only applies to its specific scope. The EU-U.S. Data Privacy Framework therefore does not indiscriminately apply to all companies based in the USA. If there is no relevant decision, standard contractual clauses according to Art. 46 GDPR are considered, along with an assessment of the actual protection conditions and, if applicable, supplementary measures.
Access from a third country to data in a European data center may also be relevant. The specific basis is described for the respective service. You can request information and a copy of the essential agreed guarantees via our data protection contact; legitimate confidentiality interests are thereby protected.
21. Storage Duration, Deletion, and Restriction
We distinguish between ongoing business data, legal archives, consent records, and voluntary analysis or marketing data. There is no general retention obligation for all customer data.
Inquiries are deleted when they have been fully processed and there is no other permissible purpose. In the event of a contract conclusion, necessary content is included in the contract documentation. Commercial and business letters are generally to be retained for six years, accounting vouchers for eight years, and certain accounting documents, inventories, or financial statements for ten years. The classification is based on § 257 HGB, § 147 AO, and the respective applicable special regulations. Commencement, extensions, and exceptions are determined by law.
Insofar as data remains necessary for the assertion, exercise, or defense of legal claims, a correspondingly limited retention may take place until the matter is clarified or relevant deadlines expire. The legal basis is Art. 6 Para. 1 lit. f GDPR. A merely abstract interest in a possible later use does not justify unlimited storage.
For newsletters, analysis identifiers, advertising target groups, consent records, and technical logs, the periods or criteria described for the respective service apply. A revocation ends the future processing covered by it. Invoices legally required to be retained and a necessary advertising block note limited to a few details may be exempt from this.
If data must be retained after the end of its operational purpose, its further use is limited to the permissible retention purpose. Deletions and restrictions must also be considered for commissioned service providers and internal copies. Backup copies are handled according to the defined backup and recovery concept.
22. Your Data Protection Rights
Under the legal conditions, you have a right to information about your personal data and the associated processing, as well as a copy of this data (Art. 15 GDPR). You can have incorrect data corrected and incomplete data completed (Art. 16 GDPR).
You can request deletion, for example, if the data is no longer needed or if processing is unlawful (Art. 17 GDPR). This right is not unlimited; in particular, legal retention obligations or necessary legal defense may preclude it. Under the conditions of Art. 18 GDPR, you can instead request a restriction of processing.
Insofar as you have provided us with data and its automated processing is based on your consent or a contract, you have the right, according to Art. 20 GDPR, to receive this data in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller.
You can revoke consents at any time for the future. The legality of processing until revocation is not affected. For practical exercise, use the settings described in the respective section or contact our data protection contact.
Special note on the right to object according to Art. 21 GDPR
You can object at any time to processing based on Art. 6 Para. 1 lit. e or lit. f GDPR for reasons arising from your particular situation. This also applies to profiling based on these provisions. We will then no longer process the affected data, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
You can object at any time without giving reasons to the processing of your data for direct marketing. This includes related profiling. After such an objection, your data will no longer be used for these advertising purposes.
Complaint and processing of your concerns
You can lodge a complaint with a data protection supervisory authority in accordance with Art. 77 GDPR, particularly in your habitual residence, place of work, or the place of the alleged infringement. For our company, the Hessian Commissioner for Data Protection and Freedom of Information is particularly relevant: Contact and complaint options. You do not have to contact us first.
We generally respond to requests within one month. We will inform you of a legally permissible extension of up to two additional months within the first month, stating the reasons. In case of justified doubts about the identity, we may request the necessary additional information. The exercise of rights is generally free of charge; legal exceptions remain unaffected.
23. Profiling and Automated Decisions
The consent-based assignment of product interests or the formation of marketing segments may constitute profiling. The data used for this, purposes, and revocation options are described in the respective marketing services. An automatic evaluation is not, for that reason alone, a decision within the meaning of Art. 22 GDPR.
In accordance with Art. 22 GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. In cases of legally permitted exceptions, the предусмотренных safeguards exist, including, where applicable, the right to human intervention, to express your point of view, and to challenge the decision.
Consent to audience measurement, newsletters, or personalized advertising is not a blanket consent to legally significant automated decisions. For independent identity, fraud, or credit checks by a chosen payment service provider, their separate information on the logic, significance, effects, and the exercise of your rights also applies. Your rights regarding processing for which we are responsible remain unaffected.
24. Data Security and Changes
We implement technical and organizational measures appropriate to the risk to protect personal data. These include, in particular, appropriate access permissions, secure transmission paths, and procedures for maintaining confidentiality, integrity, and availability. The measures are adapted to actual risks.
If our processing operations change, we will adapt this information accordingly. Necessary information about new purposes will be provided before the corresponding further processing. A change to this declaration does not replace any potentially newly required consent.