Privacy statement

Please note: Only the German original of this privacy statement is legally binding. The English translation is provided for information purposes only and has no legal force.

1. General information

1.1 Information on the collection of personal data

The information below deals with the collection and processing of your personal data. Your data is collected for various purposes. A description of these purposes, the respective data categories, the categories of data subjects, the legal basis as well as further information can be found under No. 2 of this privacy statement.

1.2 Responsible

Responsible for the present data processing is

Galaxus Deutschland GmbH
Schützenstraße 5
22761 Hamburg

Phone: +49 (0)40 - 334 614 747
E-mail: galaxus@galaxus.de
Internet: www.galaxus.de

1.3 Data protection officer

Contact our data protection officer here:

datenschutzbuero.hamburg
Mag. Jur. Djoko Lukic
Suhrenkamp 59
22335 Hamburg

Phone: +49 (0)40 414313070
Website: https://datenschutzbuero.hamburg
E-mail: galaxus@datenschutzbuero.hamburg

If you wish to contact the data protection officer via encrypted messages, please use the following contact form: https://datenschutzbuero.hamburg/kontakt/

Alternatively, you can send an e-mail encrypted using S/MIME.

1.4 Supervisory authority

The supervisory authority responsible for us is

The Hamburg Commissioner for Data Protection and Freedom of Information
Klosterwall 6 (Block C)
20095 Hamburg

Phone: +49 (0)40 - 4 28 54 - 40 40
E-mail: mailbox@datenschutz.hamburg.de

1.5 Your rights

Provided that the respective legal requirements have been met, you are entitled to the following rights:

  • According to Art. 15 GDPR, you have the right to obtain information as to whether personal data was stored or processed by us or contractual partners.
  • According to Art. 16 GDPR, you have the right to the rectification of inaccurate personal data.
  • According to Art. 17 GDPR, you have the right to the erasure of personal data provided that no legal obligation makes further storage necessary.
  • In addition, according to Art. 18 GDPR, you have the right to obtain restriction of data processing if, among other things, the accuracy of the data is disputed or you object to their processing according to Art. 21 GDPR.
  • Furthermore, according to Art. 20 GDPR, you have the right to receive the data in a machine-readable format.
  • You may revoke the consents given to us in accordance with Art. 7 III GDPR. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
  • You also have the right to file a complaint to a data protection supervisory authority about the processing of your personal data by us.
  • According to Art. 21 GDPR, you have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data collected on the basis of Art. 6, paragraph 1, under point e or f.
  • You may object to the processing of your personal data for advertising and data analysis purposes at any time.

In case of revocation or objection, please send an e-mail to widerruf@galaxus.de.

1.6 Data disclosure

1.6.1 Disclosing data within the corporate group

We are part of a corporate group (Migros) and are supported by the companies affiliated with us. Our parent company, Digitec Galaxus AG, supports us in technical and HR matters.

Data transmissions to Switzerland are subject to an adequacy decision (commission decision 2002/518/EG, ABl. 2002 L 215, 1) according to Art. 45 I S. 1 GDPR without prior authorisation by the persons concerned.

1.6.2 Data disclosure to US service providers

Your data is also transferred to service providers (Microsoft, Google, zendesk, sendgrid) headquartered in the US.  Data transfers to the US are possible under the implementation of the commission decision (2016/1250, ABl. 2016 L 207, 1), provided that the companies have certified for the privacy shield. The US companies commissioned by us process data in line with these requirements. Therefore, according to Art. 45 I S. 1 GDPR, data transfers to these companies are possible without prior consent of those concerned. Data transfers to the US are carried out on the basis of EU standard contractual clauses.

1.6.3 Contact details of data recipients

The contact details of the data recipients are as follows:

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA
Privacy statement: https://privacy.microsoft.com/en-us/privacystatement
Website: https://www.microsoft.com/en-us/

Google Ireland Limited
Gordon House, Barrow Street
Dublin 4
Ireland
Privacy statement: https://support.google.com/analytics/answer/6004245?hl=en&ref_topic=2919631
Website: https://www.google.com/

Digitec Galaxus AG
Corporate Communications
Pfingstweidstrasse 60, CH-8005 Zurich
Privacy statement: https://www.galaxus.ch/en/wiki/2791
Website: https://www.galaxus.ch/

Migros-Genossenschafts-Bund
Limmatstrasse 152
CH-8031 Zurich
Privacy statement: https://www.migros.ch/de/datenschutz.html
Website: https://www.migros.ch/de/unternehmen/migros-gruppe.html

Zendesk Inc.
989 Market Street #300
San Francisco
CA 94102
USA
Privacy statement: https://www.zendesk.com/company/customers-partners/privacy-policy/?_ga=2.122922187.196979010.1583850399-951531470.1583850399
Website: https://www.zendesk.com/?_ga=2.23695354.196979010.1583850399-951531470.1583850399

Facebook Inc.
1 Hacker Way
Menlo Park
CA 94025
USA
Privacy statement: https://www.facebook.com/privacy/explanation
Website: https://www.facebook.com/

Pintrest Inc.
651 Brannan Street
San Francisco
CA 94107
USA
Privacy statement: https://privacy.microsoft.com/en-us/privacystatement

SendGrid UK Limited
6th Floor One London Wall
London
EC2Y 5EB
UK
Privacy statement: https://sendgrid.com/policies/privacy/website-privacy-policy/
Website: https://sendgrid.com/

Klaus D. Meier + Bastian Kröhnke PartG mbB
Semmelweisstr.  19
79576 Weil am Rhein
Privacy statement: https://www.steuerberater-weilamrhein.com/impressum/
Website: https://www.steuerberater-weilamrhein.com/

 

2. The processing of your data

2.1 Data categories

Below, we will inform you about the individual processing activities. The processed data categories are summarised in the following category groups:

  • Login data (LoginD): user name and password, time of login, session data (session ID)
  • Master data (StammD): title, form of address, gender, first name, last name, date of birth
  • Address data (AdressD) : street, house number, address suffix, postal code, town
  • Contact details (KontaktD): e-mail address, phone number
  • Order data (BestellD): ordered products, prices, payment information, delivery dates
  • Newsletter profile data (NutzungDN): time of opening newsletter, content of newsletter, opened links, technical protocol data (IP address, description of computer, browser, etc.)
  • Access protocols (ZugriffD): services/websites used, time of use, previous website visit, computer description, browser type and version, operating system and other technical data

Where other categories of data not mentioned in the above categories are processed, they are mentioned individually in the respective processing activities.

2.2 Visiting the website

2.2.1 Data processing purpose

The purpose of the data processing described below is the presentation of our website and the offers available on it.

2.2.2 Data processing

Whenever our website or online shop is used for information purposes, we only collect the personal data your browser transmits to our servers. The data from the category group «ZugriffD» are processed.

2.2.3 Legal basis

The legal basis for the processing of the above data is Art. 6 I lit. f) GDPR. Our legitimate interests are as follows:

  • ensuring that system operation is as error-free as possible,
  • analysing any error functions as well as
  • optimising the contents for a user-friendly presentation.

2.2.4 Storage period

The data collected in the course of these measures is automatically deleted if no longer required.

2.2.5 Origin of the data

The processed data is provided by you.

2.3 Website usage analysis for online offer optimisation

2.3.1 Data processing purpose

To optimise our content, we use Google Analytics on our website.

2.3.2 Data processing

Google uses cookies that analyse how the website is used. This allows Google to collect information about your behaviour on our website and the device used (data from the category group ZugriffD).

Based on this information, Google sends us evaluations. Within the framework of these usage analyses, purchasing behaviour is also assessed and products related to other products are offered in a targeted manner.

2.3.3 Data disclosure

As this analysis is carried out by Google, your data is also passed on to Google.

Our processing activity is actively supported by our parent company, so that the data can also be viewed by the entitled persons of the parent company. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.3.4 Legal basis

The legal basis for this data processing is your consent within the meaning of Art. 6 I lit. a) GDPR, which you have given us via the cookie banner.

2.3.5 Storage period

The data is deleted provided that it is no longer required.

2.3.6 Origin of the data

The processed data is provided by you.

2.4 Execution of the contract

2.4.1 Data processing purpose

We process personal data to meet our claims and to fulfil our obligations arising from the sales contract.

2.4.2 Data processing

For the purpose described, we process the category groups StammD, AdressD, KontaktD, BestellD and ZugriffD.

2.4.3 Data disclosure

We are supported by the specialist departments at Digitec Galaxus AG in Switzerland in carrying out these processing activities. In addition, parts of our infrastructure are provided by Cloud services provided by Microsoft Corporation (USA). Find more information on data disclosure under No. 1.6 of this privacy statement.

Furthermore, we transmit your data to lawyers and debt collection companies to establish legal claims.

In order to be able to deliver the ordered goods to you, we also transmit your data to transport companies.

2.4.4 Legal basis

We process data to fulfil our contractual obligations. Therefore, the legal basis is Art. 6 I lit. b) GDPR.

2.4.5 Storage period

If the data is no longer required to fulfil its purpose (e.g. by deleting the user account), the data required for the user account will be deleted.

The data we are obliged to keep for tax law reasons will be kept according to the legal deadlines (10 years according to § 147 of the fiscal code of Germany).

2.4.6 Origin of the data

The processed data is provided by you.

2.5 customer account

2.5.1 Data processing purpose

To enable you to participate in our Community, you may create a personal customer account. A customer account also allows for a comfortable execution of orders by permanently saving your data.

2.5.2 Data processing

When a user account is created, the category groups LoginD, StammD, AdressD, KontaktD, BestellD, NutzungsDN and ZugangD are processed.

2.5.3 Legal basis

Creating a user account, e.g. to participate in the Community, is voluntary. Therefore, the legal basis is Art. 6 I lit. a) GDPR. If you would like to place orders, creating a customer account is required for contract processing. In this case, the legal basis is Article 6 I lit. b) GDPR.

2.5.4 Data disclosure

The collected data is stored in the infrastructure of our parent company. See also No. 1.6 of this privacy policy.

2.6 Apps for Android and iOS

2.6.1 Data processing purpose

To make it easier for you to use our online shop on mobile platforms (Android and iOS), we provide an app.

2.6.2 Data processing

The apps make the already available online shop available in a separate browser. The data that is processed is the same as the data processed when the online shop is called up via the browser (see No. 2.2 to 2.5 of this privacy statement). Thus, the following data category groups are processed: LoginD, StammD, AdressD, KontaktD, BestellD, NutzungDN and ZugriffD.

Please note that the providers of the App Store (Google and Apple) also process other data (e.g. number of installations, time of use, etc.). To find out what data is involved in these processes, please check with the respective provider.

2.6.3 App authorisations

The apps require different access rights. The access rights and the purpose of the respective data processing are listed below:

Photos/Media/Files

(original description in the Google Play Store: «read the contents of your USB storage; modify or delete the contents of your USB storage»)

This authorisation is necessary to enable the upload of profile pictures or image documents.

Storage

(original description in the Google Play Store: «read the contents of your USB storage; modify or delete the contents of your USB storage»)

This authorisation is necessary to enable the upload of documents.

Miscellaneous

(original description in the Google Play Store: «download files without notification»)

This authorisation allows the download of documents (order confirmations, etc.). Downloads are not carried out without prior consultation. The note «without notification» is incorrect and erroneously displayed by the App Store.

Miscellaneous

(original description in the Google Play Store: «view network connections»)

The network connectivity request is necessary to provide the data connection to our online shop.

Miscellaneous

(original description in the Google Play Store: «full network access»)

This authorisation is also necessary to realise the network communication with our online shop.

2.6.4 Legal basis

If you use the app to be part of the Community, you do so at your own request. The legal basis is your implied consent according to Art. 6 I lit. a) GDPR. If you would like to place orders by means of the apps, creating a customer account is required for contract processing. In this case, the legal basis is Article 6 I lit. b) GDPR.

2.6.5 Data disclosure

The collected data is stored in the infrastructure of our parent company. See also No. 1.6 of this privacy policy.

2.7 Payments via Paypal

2.7.1 Data processing purpose

The purpose of processing data is to receive payments by the payment service provider Paypal in the course of the contract processing.

2.7.2 Data processing data disclosure

PayPal (PayPal Europe S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg) receives information about the ordered goods as well as the payments you legitimised. PayPal reserves the right to carry out credit checks. The result of the credit check is used by PayPal to decide whether certain payment methods can be offered to the paying party. The credit check is able to take probability values (score values) into account. The calculation of these probability values is carried out on the basis of recognised mathematical procedures. Among other things, address data of the paying party is included in the calculation of these probability values. Further information on data processing can be found in the PayPal privacy statement: https://www.paypal.com/va/webapps/mpp/ua/privacy-full

2.7.3 Legal basis

Data processing is carried out to exercise our contractual rights within the meaning of Art. 6 I lit. b) GDPR.

2.8 Accounting and record retention obligation

2.8.1 Data processing purpose

In order to fulfil our accounting obligations within the meaning of § 238 HGB (German commercial code), all business-relevant occurrences are recorded and stored within the meaning of § 147 AO (German fiscal code) (or § 257 HGB).

2.8.2 Data processing

For accounting purposes, we must be able to record and store the data associated with your purchase (StammD, AdressD, KontaktD, BestellD) and be able to present it in the event of tax audits.

2.8.3 Data disclosure

In the event of official inspections, this data can be viewed by public bodies, such as the tax authorities. We are supported by the law firm Klaus D. Meier + Bastian Kröhnke in terms of tax law and accounting. Therefore, the firm also has access to this data.

Our parent company, which supports us in technical and HR matters, can also access the data. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.8.4 Legal basis

The legal basis for the present data processing is Art. 6 I lit. c) GDPR in connection with the respective legal provisions (e.g. § 147 AO (fiscal code of Germany) or § 257 HGB).

2.8.5 Storage period

The data is kept for 10 years for tax law reasons (§ 147 AO). Data which we have to keep for reasons of commercial law (§ 257 HGB) will be stored for 6 years.

2.8.6 Origin of the data

The processed data is provided by you.

2.9 Logging in with Facebook

2.9.1 Data processing purpose

The purpose of the process described below is to simplify the registration procedure to use our online shop.

2.9.2 Data processing

If you have a Facebook profile, you can use it to create a customer account in our online shop and to log in. The plugin called «Facebook» is on the registration page in the «login» field.

Before the registration process and the transfer of the name, profile picture and e-mail address from Facebook to us can be carried out, you must approve the process.

2.9.3 Data disclosure

Facebook will be informed that you are using your Facebook user account to log in to our online shop. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.9.4 Legal basis

The legal basis for this process is Art. 6 I lit. a) GDPR.

2.9.5 Further information

Even if your settings give us access to further information, e.g. your friend list, this information will not be processed by us.

2.9.6 Storage period

The data is deleted provided that it is no longer required.

2.10 Logging in with Google

2.10.1 Data processing purpose

The purpose of the process described below is to simplify the registration procedure to use our online shop.

2.10.2 Data processing

If you have a Google account, you can use it to create a customer account in our online shop and to log in. The plugin called «Google» is on the registration page in the «login» field.

2.10.3 Data disclosure

Google will be informed that you are using your Google user account to log in to our online shop. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.10.4 Legal basis

By signing in with your Google account, you implicitly agree to the transfer of your name, profile picture and e-mail address. The legal basis for this process is Art. 6 I lit. a) GDPR.

2.10.5 Further information

Even if your settings give us access to further information, this information will not be processed by us.

2.10.6 Storage period

The data is deleted provided that it is no longer required.

2.11 Data processing for communication purposes

2.11.1 Data processing purpose

We process personal data not only for communication within the scope of contractual relationships, but also for other forms of communication.

2.11.2 Data processing

For this purpose, we use the e-mail infrastructure and a ticket system as well as our contact form. The data communicated for this purpose can be of various types (support requests, applications, status requests, etc.), making a uniform categorisation impossible.

2.11.3 Data disclosure

For communication by e-mail, we use communication solutions by Microsoft, SendGrid and Zendesk. If you contact us via social media, the forms of communication offered there are used.

The service providers used in connection with the communication receive the communicated data by means of communication transport.

As we are supported by the IT department of our parent company in the context of this processing activity, the data can be viewed by the respective authorised parties. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.11.4 Legal basis

Provided that the communication is contractually related to our goods and services, the legal basis is Art. 6 I lit. b) GDPR. In all other cases, our legitimate interest is to be able to communicate with you. In these cases, the legal basis is Art. 6 I lit. f) GDPR.

2.11.5 Storage period

The data is deleted provided that it is no longer required. Commercial letters are deleted after 6 years (§ 257 HGB) and tax-relevant communication contents are deleted after 10 years (§ 147 AO). If the communication content is necessary to exercise legal claims or to defend against them, the data can be stored until it is no longer required for this purpose.

2.11.6 Origin of the data

Provided that you contact us, the data will be provided by you. If we contact you, you will have given us your data in advance.

2.12 Display of embedded videos

2.12.1 Data processing purpose

The purpose of data processing is the presentation of videos on our website to increase the attractiveness of our offer.

2.12.2 Data processing

The videos may be played back on the website. The data processed here is the same information that is collected when the website is displayed (category group ZugriffD). Furthermore, Google uses cookies to provide the website.

YouTube https://www.youtube.com/t/terms
Google http://www.google.com/policies/privacy

2.12.3 Data disclosure

We use the platform YouTube (Google) to display videos. Thus Google also gains access to the data associated with the display (ZugriffD). If you were previously logged in with your Google account, Google may also associate this information with your Google account.

As we are supported by of our parent company in the context of this processing activity, the data can be viewed by the respective authorised parties. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.12.4 Legal basis

The legal basis for this is our own legitimate interest according to Art. 6 I lit. f) GDPR in providing an interesting offer.

2.12.5 Storage period

The data is deleted provided that it is no longer required.

2.12.6 Origin of the data

The processed data is provided by you.

2.13 E-mail marketing

2.13.1 Data processing purpose

The purpose of data processing is to offer our products by e-mail (newsletter).

2.13.2 Data processing

The distribution of newsletters enables us to determine whether pictures were displayed within the newsletter and thus whether content was perceived. Your e-mail programme will inform you about this usage analysis and give you the possibility to stop the usage analysis. Your name and e-mail address will be processed.

2.13.3 Data disclosure

We use the provider SendGrid for the distribution. As the provider carries out the distribution of e-mails and enables the analysis of usage, the provider receives the data linked to this. Find more information on data disclosure under No. 1.6 of this privacy statement.

2.13.4 Legal basis

The legal basis is the consent given by you according to Art. 6 I lit .a) GDPR.

2.13.5 Storage period

The data is deleted provided that it is no longer required.

2.13.6 Origin of the data

The processed data is provided by you.

2.13.7 Revocation

You may revoke your consent at any time for the future. To exercise your right of revocation, please click on the link marked accordingly in the newsletter. Alternatively, you may also send your revocation by e-mail to widerruf@galaxus.de.

2.14 Community

2.14.1 Data processing purpose

All customers have the opportunity to comment on products and articles. Customers may start their own discussions and use our online shop as a platform for information exchange.

2.14.2 Data processing

The Community features are an integral part of our website. As a result, the data that is processed is the same data that is processed when a website is displayed. Additionally, a login process is required. A contribution is published together with the freely selectable user name.

2.14.3 Data disclosure

The collected data is stored at our parent company. See also No. 1.6 of this privacy policy.

2.14.4 Legal basis

If you write contributions, you implicitly agree to the publication of your contribution and the associated data processing. The legal basis the data processing is Art. 6 I lit. a) GDPR.

In addition, it is in our own legitimate interest according to Art. 6 I lit. f) GDPR to make our website more attractive by means of the Community.

The interests of the persons concerned (right to privacy for free development of personality) must not outweigh our interests (marketing measures for professional activities).

Participants are aware that any comments they write are published. By doing so, participants demonstrate that protection of privacy is not more important to them, and that they agree with the publication. Furthermore, as user names are used, the identification of the person concerned can only happen to a limited extent. The interest of those affected does not predominate.

2.14.5 Storage period

The data is deleted provided that it is no longer required.

2.14.6 Origin of the data

The processed data is provided by you.

2.15 Carrying out prize draws

2.15.1 Data processing purpose

The purpose of data processing is to carry out prize draws to increase the attractiveness of online shop.

2.15.2 Data processing

You take part in prize draws by posting comments on our website. This is why technical data is collected that is necessary for the provision of the website (IP address, protocol data, etc.).

Any comments you publish will be accompanied by your user name.

2.15.3 Data disclosure

The collected data is stored in the infrastructure of our service providers and our parent company. See also No. 1.6 of this privacy statement.

2.15.4 Legal basis

If you write contributions (even if they are only for the purpose of participating in a prize draw), you implicitly agree to the publication of your contribution and the associated data processing. The legal basis the data processing is Art. 6 I lit. a) GDPR.

In addition, it is in our own legitimate interest according to Art. 6 I lit. f) GDPR to make our website more attractive by means of the Community.

The interests of the persons concerned (right to privacy for free development of personality) must not outweigh our interests (marketing measures for professional activities).

Participants are aware that any comments they write are published. By doing so, participants demonstrate that protection of privacy is not more important to them, and that they agree with the publication. Furthermore, as user names are used, the identification of the person concerned can only happen to a limited extent. The interest of those affected does not predominate.

2.15.5 Storage period

The data is deleted provided that it is no longer required.

2.15.6 Origin of the data

The processed data is provided by you.

2.16 Application procedure

2.16.1 Data processing purpose

The purpose of the processing activity is to carry out application procedures.

2.16.2 Data processing

We only accept applications made through our application portal set up for this purpose https://www.digitec.ch/en/JobOffer

Applicants who contact us by e-mail are referred to this portal. Applications sent in by e-mail will be processed in accordance with the above-mentioned processing activities (data processing for communication purposes) and deleted as quickly as possible. The personal data that you provide us with will be processed. These are, in particular, the following category groups:

  • StammD,
  • AdressD,
  • KontaktD as well as
  • data on your professional career, your education and certificates.

As you are using the website, the data collected during the use of websites is also processed. Find more information under No. 2.2 of this privacy statement.

2.16.3 Data disclosure

The collected data is stored in the infrastructure of our parent company. See also No. 1.6 of this privacy statement.

2.16.4 Legal basis

We carry out application procedures in our own legitimate interest according to Art. 6 I lit. f) GDPR. Our interest here is the maintenance of business activities. For the assumption of a legitimate interest according to Art. 6 I lit. f) GDPR, your interest (right to privacy for the free development of your personality) must not outweigh our interest. As you are applying yourself and providing your documents, you are making clear that the protection of your privacy does not outweigh our interest in the application process.

2.16.5 Storage period

Data of employees will remain stored until they leave the company, provided that this information is necessary for the continuation of employment. Data of rejected applicants will be stored for 6 months to protect against possible claims arising from the AGG (General Act on Equal Treatment).

2.16.6 Origin of the data

The data is provided by you.

2.17 Online marketing through conversion tracking

2.17.1 Data processing purpose

The purpose of conversion tracking is to determine whether our marketing measures are successful.

2.17.2 Data processing

As part of the analytics services provided by Google, conversion tracking allows us to determine which external advertising efforts were successful and resulted in prospective customers clicking on ads.

The information collected in this process is not intended to identify you personally. We only learn how many interested prospective customers clicked on our ads.

2.17.3 Data disclosure

Since we use Google technology (see also No. 1.6.3) for conversion tracking, the data is also passed on to Google.

2.17.4 Legal basis

The legal basis for conversion tracking is your consent according to Art. 6 I lit. a) GDPR.

2.17.5 Deactivation

You have the option of preventing the data processing on which this usage analysis is based. To do so, it is sufficient to deactivate third-party cookies in your browser. Alternatively, you may also use the plugin provided by Google https://www.google.com/settings/ads/plugin

2.17.6 Storage period

The cookies have a life of 30 days. Therefore, the information stored in these cookies is deleted after 30 days at the latest.

However, you can also delete the cookies yourself using the appropriate browser functions.

2.18 Remarketing through the Google Marketing Platform

2.18.1 Data processing purpose

To increase the attractiveness of our offer, we use the analysis methods of the Google Marketing Platform.

2.18.2 Data processing

Cookies are used to identify which products or content you are interested in. When you leave our online shop, the offers and contents that are interesting for you are advertised on external sites.

2.18.3 Data disclosure

Since we use Google technology (see also No. 1.6.3) for this data processing, the data is also passed on to Google.

2.18.4 Legal basis

The legal basis for the existing data processing is your consent according to Art. 6 I lit. a) GDPR.

2.18.5 Deactivation

You have the option of preventing the data processing on which this usage analysis is based. To do so, it is sufficient to deactivate third-party cookies in your browser. Alternatively, you may also use the plugin provided by Google https://www.google.com/settings/ads/plugin

2.18.6 Storage period

The cookies have a life of 24 months. Therefore, the information stored in these cookies is deleted after 24 months at the latest.

However, you can also delete the cookies yourself using the appropriate browser functions.

2.19 Affiliate or network marketing

2.19.1 Data processing purpose

The purpose of the present processing activity is the marketing of our products and services.

2.19.2 Data processing

Our advertising partner (Tradedoubler GmbH, Herzog-Wilhelm-Straße 26, 80331 Munich, https://www.tradedoubler.com/en/privacy-policy/) operates a service for publishing advertisements. The advertisements are published within the distribution network of our advertising partner.

The processed data is stored in the cookies of the website visitors.

2.19.3 Data disclosure

For the invoicing of marketing services rendered, our advertising partners document all successful advertising measures. The data collected in this process are the order value, the order number, the click ID of the buyer (tduid) and any voucher code. Both sales and the display of the linked contents are considered successful advertising measures. As in the operation of the website, technically essential information of the website visitor is processed (category group ZugriffD).

Since the affiliates publish the advertisements, they also record technically necessary information.

2.19.4 Legal basis

The legal basis for the present data processing is our own legitimate interest in the marketing of our products and services according to Art. 6 I lit. f) GDPR.

2.19.5 Deactivation

You have the option of preventing the data processing on which this usage analysis is based. To do so, it is sufficient to deactivate cookies in your browser. Alternatively, you may also use the opt-out provided by tradedoubler: http://publisher.tradedoubler.com/include/functions/optout.html

2.20 Use of tracking pixels for advertising platforms

2.20.1 Data processing purpose

The purpose of data processing is to optimise the marketing measures by transferring website usage analyses to marketing platforms.

2.20.2 Data processing

Tracking pixels are used to record website usage. Tracking pixels are graphic elements that are integrated into the provider's website and are loaded from an external provider's server when a website is visited. The server of the external provider registers this loading process and recognises various information on the user (data category ZugriffD):

  • the operating system used,
  • the browser used,
  • the time of access,
  • the visit duration,
  • the visitor’s IP address.

In addition, the click numbers and thus the attractiveness of individual pages can be recorded in this way.

The information collected by these methods is stored in so-called cookies or locally, in similarly functioning text files, in the end devices of the website visitors.

2.20.3 Data disclosure

The data is forwarded to the following marketing partners:

Connexity Europe GmbH, Ruschgraben 133, 76139 Karlsruhe, Germany
The privacy statement of Connexity is here: https://europe.connexity.com/gb/privacy-policy/.

shopping24 affiliate of shopping24 Gesellschaft für multimediale Anwendungen mbH, Poßmoorweg 2, 22301 Hamburg, Germany
The privacy statement of shopping24 is here: https://www.s24.com/en/privacy-policy/ .

billiger.de Affiliate of solute GmbH Zeppelinstraße 15 D-76185 Karlsruhe
Privacy statement: https://www.solute.de/eng/privacy/

Criteo DPO 32 Rue Blanche 75009 Paris - France
Privacy statement: https://www.criteo.com/de/privacy/corporate-privacy-policy/

idealo internet GmbH Zimmerstraße 50 10888 Berlin, Germany
Privacy statement: https://www.idealo.de/preisvergleich/Datenschutz.html

Taboola, Inc. 16 Madison Square West 7th Floor New York, New York 10010
Privacy statement: https://www.taboola.com/policies/privacy-policy

Twitter International Company Z. Hddn.: Data Protection Officer One Cumberland Place, Fenian Street Dublin 2, D02 AX07 IRELAND
Privacy statement: https://twitter.com/en/privacy

Snapchat Affiliate of Fieldfisher (Germany) LLP Am Sandtorkai 68 20457 Hamburg
Privacy statement: https://www.snap.com/en-US/privacy/privacy-policy

Outbrain UK Limited, 5th Floor, The Place, 175 High Holborn, London, WC1V 7AA, United Kingdom
Privacy statement: https://www.outbrain.com/legal/privacy#privacy-policy

2.20.4 Legal basis

The legal basis for the existing data processing is your consent according to Art. 6 I lit. a) GDPR.

2.21 Processing of cancellation claims

2.21.1 Data processing purpose

The purpose of data processing is the deletion of personal data.

2.21.2 Data processing

To carry out your request for deletion, your stored data will be deleted. This applies in particular to this following data category groups:   LoginD, MasterD, AddressD, ContactD, OrderD, UsageD and AccessD. (The explanation of the respective category groups can be found under No. 2.1. of this Privacy Statement).

You can initiate the data deletion yourself in your customer account under Settings. An identity check, e.g. by showing ID cards, is generally not necessary and is ensured by the login in the customer account.

Please note: To prevent misuse, the deletion of your data is possible only after the settlement of all outstanding claims.

2.21.3 Data disclosure

Within the scope of this deletion claim, we are supported by the parent company, Digitec Galaxus AG.

2.21.24 Legal basis

The legal basis for the present data processing is the legal obligation to do so pursuant to Art. 6 I lit. c) GDPR in conjunction with Art. 17 I GDPR.

2.21.5 Storage period

We can only delete data that must be retained for legal reasons after the relevant period has expired. This includes tax-relevant data according to § 147 AO, which may only be deleted after 10 years. Data relevant under commercial law within the meaning of § 257 HGB must be retained for 6 years.  Only after this period has expired may this data be deleted. To ensure that no other persons can access this data, access is restricted.

2.21.6 Warranty rights

After the deletion request has been implemented, your data will no longer be available to the Customer Service. If you wish to assert warranty rights, you must provide proof of purchase of the goods. Please provide corresponding receipts for this in the warranty case.

2.22 Processing of cancellation claims

2.22.1 Data processing purpose

The purpose of the data processing is to provide data extracts of the personal data concerning you.

2.22.2 Data processing

To carry out your request for deletion, your stored data will be extracted from the database systems and transferred to an information document and a CSV/Excel document. This process concerns all data that has been stored in relation to you. This applies in particular to this following data category groups: LoginD, MasterD, AddressD, ContactD, OrderD, UsageD and AccessD. (The explanation of the respective category groups can be found under No. 2.1. of this Privacy Statement).

To ensure that the requesting person is actually the owner of the customer account, the data statement is sent in an encrypted archive to the e-mail address stored in the customer menu. The password for decrypting the archive is sent by e-mail to the address stored in the customer menu.

If, in individual cases, doubts about the identity of the applicant cannot be reasonably overcome with the help of available information, further proof of identification may be requested.  If personal documents are presented for this purpose, only the name, address, date of birth and period of validity are regularly required. To meet the requirement for data minimisation, the remaining data need to be redacted. The presentation of official documents is an exceptional case.

2.22.3 Data disclosure

Within the scope of this right to information, we are supported by the employees of the parent company, Digitec Galaxus AG.

2.22.4 Legal basis

The legal basis for the present data processing is the legal obligation to do so pursuant to Art. 6 I lit. c) GDPR in conjunction with Art. 15 I GDPR.

2.22.5 Storage period

To prove that the right to information has been met, the information document is kept for 6 months.

2.23 Identification of customers

2.23.1 Data processing purpose

The purpose of data processing is the identification of customers.

2.23.2 Data processing

If the provision of our services makes it necessary to identify you, this requirement would be conceivable, for example, if you have lost access to your e-mail inbox and can no longer access the customer menu. To the extent possible, we identify you through the contact information we have on file.

Only in exceptional cases (e.g. if there is reasonable doubt about your identity) may it be necessary for us to view your ID card. In these cases, it is sufficient if your name, address, date of birth and expiration date are visible on the ID card. The rest of the information needs to be redacted by you.

2.23.3 Data disclosure

Our customer service is supported by our parent company Digitec Galaxus AG.

2.23.4 Legal basis

If the identification becomes necessary for the fulfilment of contractual obligations (e.g. to grant access to the user account), the legal basis is Art. 6 I lit. b) GDPR. If we make the identification in order to comply with our legal obligations, e.g. to fulfil data subject rights, the legal basis is Art. 6 I lit. c) GDPR.

2.23.5 Storage period

If no further proof is required, any ID card copies will be deleted after identification.

2.24 Marketing by letter

2.24.1 Data processing purpose

The purpose of data processing is the postal provision of information on our products, services and other offers. 

2.24.2 Data processing data disclosure

The documents will be sent by a postal service provider. The latter must process the address data within the scope of the mailing in order to fulfil its tasks.

2.24.3 Legal basis

Marketing measures by letter are carried out on the basis of Art. 6 para. 1 lit. f) GDPR. The own legitimate interest in this case is advertising the own offers (cf. recital no. 47). Possible interest of the data subject is protection against harassment by advertising by letter. According to Section 7 UWG, unreasonable harassment is always to be assumed in the case of an approach by telephone pursuant to Section 7 (2) No. 2 UWG or by electronic means (e-mail, fax) pursuant to Section 7 (2) No. 3 UWG. Advertising by letter is excluded from this. Thus, in the opinion of the legislator, unreasonable harassment cannot be assumed in the case of advertising by letter. In the absence of unreasonableness, the interest of the data subject in protection against harassment does not outweigh the interest of the responsible body.
If you do not wish to receive offers from us by letter, you can object to the data processing by sending an e-mail to galaxus@galaxus.de.

2.24.4 Storage period

With the deletion of your user account, your address data will also be deleted.

3. Cookies used

3.1.1 What are cookies?

Cookies are files that are stored in your computer by websites, such as our website. These files may contain information on the use of the website. Cookies are used to store login processes, for example. This means you do not have to authenticate yourself again after an initial login when you revisit the website.

3.1.2 What are transient cookies?

Transient cookies are automatically deleted when you close the browser. These particularly include session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the shared session. This allows your computer to be recognised when you return to our website. The session cookies are deleted when you log out or close the browser.

3.1.3 What are persistent cookies?

Persistent cookies are automatically deleted after a specified period of time, which may vary depending on the cookie.

3.1.4 Refusing and deleting cookies

You have the option to configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. We would like to point out that this could mean that you may not be able to use all functions of this website.

Furthermore, you can delete the cookies in the security settings of your browser at any time.

The cookie banner allows you to select your cookie settings directly before using the site. 

Under «Services», you can adjust these settings at any time.

3.2 Cookies in use

We distinguish between 4 categories of cookies.

3.2.1 Essential

No cookies isn’t possible. Essential cookies are necessary to ensure functionality of the website. These cookies enable you to use functions such as secure login, shopping cart or watch lists.

1st Party Cookies are marked with Domain galaxus.de, digitecgalaxus.ch, GMT (Google Tag Manager) or Akamai. All other domains are 3rd party cookies.

Cookie Key

Domain

Cookie lifespan

Data processing purpose

Legal basis

.consent

galaxus.de

1 year

This cookie stores the preferences configured by users in the cookie banner.

The legal basis is our legitimate interest in providing a legally compliant Internet presence within the meaning of Art. 6 I lit. f) DS-GVO.

Signout.{...}

galaxus.de

10 minutes

This cookie enables an error-free logout from the online shop.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

enableFraming

galaxus.de

-

This cookie is security-related and prevents unlawful use of the content of this website.

The prevention of unlawful use of our Internet presence is our legitimate interest within the meaning of Art. 6 I lit. f) GDPR.

corr

galaxus.de

5 minutes

This cookie is essential for the security of the website and the visitor.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.e-proc

galaxus.de

14 days

This cookie is essential for the security of the website and the visitor. It is necessary for part of the log-in process.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.e-procname

galaxus.de

14 days

This cookie is necessary for the proper display of the online shop.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.sum

galaxus.de

30 years

The cookie is used to store user-specific preferences of configurations.

The legal basis is our legitimate interest in providing of a user-friendly online store within the meaning of Art. 6 I lit. f) GDPR.

releasesystem

galaxus.de

30 years

This cookie is essential for the security of the website and the visitor.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.idt

galaxus.de

-

Additional information about the logged in user (e.g. name, age, language, avatar, etc.) which is only used for display.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.at

galaxus.de

-

This cookie is essential for the security of the website and the visitor.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.atinfo

galaxus.de

-

This cookie is essential for the security of the website and the visitor.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.sid

galaxus.de

2 hours

This cookie contains the session identification of a user.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.sidexp

galaxus.de

2 hours

This cookie contains the session lifespan of a user.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.bid

galaxus.de

10 years

This cookie is essential for the security of the website and the visitor. The user's browser ID is captured.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.bidexp

galaxus.de

10 years

This cookie is essential for the security of the website and the visitor.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

.plistsc

galaxus.de

2 years

This cookie contains information regarding the shopping cart.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.plistpc

galaxus.de

2 years

This cookie contains information regarding the comparison list.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

comparisonList_

expandedProduct

TypeIds

galaxus.de

-

This cookie contains information regarding the comparison list.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.plistsl

galaxus.de

2 years

This cookie contains information regarding the watch list.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

redirectAfter

Registration

Cookie

galaxus.de

7 days

This cookie is important for redirection after registration.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

avatarUpdateDate

galaxus.de

100 days

This cookie contains information regarding the avatar.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.shopmessage

galaxus.de

2 months

This cookie is required for the display of messages.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

DG_EU

galaxus.de

-

Used for testing

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

DeviceCookie_*

galaxus.de

-

With the help of this cookie, login from unknown devices can be detected. The purpose of the processing is to inform the user to prevent improper use.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

ak_bmsc

Akamai

2 hours

This cookie is used to distinguish between humans and bots.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

bm_mi

Akamai

2 hours

This cookie makes it possible to determine whether the online store is used by software or by a human. This cookie is necessary to prevent abuse.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

_abck

Akamai

1 year

This cookie makes it possible to determine whether the online store is used by software or by a human. This cookie is necessary to prevent abuse.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

bm_sz

Akamai

4 hours

This cookie makes it possible to determine whether the online store is used by software or by a human. This cookie is necessary to prevent abuse.

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

CONSENT

.youtube.com

18 years

This cookie enables the collection of consent to the use of cookies.

This cookie is set to meet legal requirements. The legal basis is the protection of our own legitimate interests pursuant to Art. 6 I lit. f) GDPR.

xs

.facebook.com

90 days

This cookie is provided by Facebook and is part of any login process at Facebook.

The provision of a functional internet offer is a legitimate interest within the meaning of Art. 6 I lit. f) GDPR.

srv_id

.taboola.com

Session
(until browser tab is closed)

This cookie stores technically necessary data regarding the browser session.

The provision of a functional Internet offer is a legitimate interest within the meaning of Art. 6 I lit. f) GDPR.

 

3.2.2 Functional

We require functional cookies for extended website functions – also from third-party providers. For example, we can offer you your most recently visited products as a navigation aid during product research.

1st Party Cookies are marked with Domain galaxus.de, digitecgalaxus.ch, GMT (Google Tag Manager) or Akamai. All other domains are 3rd party cookies.

Cookie Key / Identifier

Domain

Cookie lifespan

Description for users/ Data processing purpose

Legal basis

DisplayCulture

galaxus.de

30 days

This cookie contains the display settings of the user.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

DisplayCountryId

galaxus.de

30 days

This cookie contains the country settings of the user.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

DisplayLanguageId

galaxus.de

30 days

This cookie contains the language settings of the user.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

DisplayCurrencyId

galaxus.de

30 days

This cookie contains the currency settings of the user.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

RecentlyVisitedProducts_

galaxus.de

29 days

This cookie contains information regarding last visited products.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

 

3.2.3 Marketing

Our approach: If advertising, then we’re going to get it right. That’s why we use marketing cookies to show you personalised advertisements that interest you (at least a little bit).

1st Party Cookies are marked with Domain galaxus.de, digitecgalaxus.ch, GMT (Google Tag Manager) or Akamai. All other domains are 3rd party cookies.

Cookie Key / Identifier

Domain

Cookie lifespan

Description for users/ Data processing purpose

Legal basis

_fbp

GTM, facebook.com

.taboola.com

90 days

This cookie is used to advertise other products.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_fbc

GTM, 

facebook.com

90 days

This cookie is only set if you landed on this website by opening a Facebook link. It is used to track interactions on this website to the Facebook click.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_gac_UA-xxx

GTM

90 days

This cookie is set when a user arrives at the website via a click on a Google ad. It contains information about which ad was clicked, so that successes achieved, such as orders or contact requests, can be attributed to the ad.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_gid

GTM, .twitter.com, .taboola.com

24 hours

A randomly generated user ID allows Google to recognise the visitor and link it to data from a previous visit.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_gcl_au

GTM, 

.taboola.com

90 days

This cookie is used to measure the effectiveness of marketing activities.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_gcl_aw

GTM

90 days

This cookie is set when a user arrives at the website via a click on a Google ad. It contains information about which ad was clicked, so that successes achieved, such as orders or contact requests, can be attributed to the ad.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_gcl_dc

GTM

90 days

This cookie allows us to analyse and track how our website is found and whether transactions are derived from it. This way we can optimise our ads and AdWords expressions. This information is shared with Google.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_gat-UA-xxx

GTM

1 minute

This cookie is used to throttle the request rate. If Google Analytics is deployed via Google Tag Manager, this cookie is called dc_gtm<property-id>.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

last_order_id

GTM

30 days

The ID of the last order is captured to prevent transactions from being sent to Tools multiple times.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

TRADEDOUBLER

GTM

1 year

This cookie processes the identification number of the marketer (affiliate) and the ordinal number of the visitor to the marketer's website. In addition, the clicked wording is recorded. The purpose of the processing is to handle commission payments through the Tradedoubler network.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

idealo

GTM

1 year

The purpose of data processing is optimising marketing campaigns.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

s24_click_id

GTM

1 year

The purpose of data processing is optimising marketing campaigns.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

Facebook Core SDK

App, facebook.com

-

This cookie helps us run marketing campaigns on Facebook. Events are transmitted (e.g. which products were viewed) so that targeted marketing campaigns can be played out.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

outbrain_cid_fetch

GTM

24 hours

 

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

AID

.google.ch

.googleadservices.com

10 years

This cookie records a unique ID that enables statistical analysis of website usage.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

ANID

.google.com

10 years

This cookie records a unique ID that enables statistical analysis of website usage.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

APISID

.google.ch

1 year

This cookie records a unique ID that enables statistical analysis of website usage.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

IDE

.doubleclick.net

.pinterest.com

10 years

Used by Google DoubleClick to register and report the user's actions on the website after viewing or clicking on one of the provider's ads. The purpose is to measure the effectiveness of an advertisement and to display targeted advertising to the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

datr

.facebook.com

2 years

This cookie allows Facebook to identify the web browser and deliver ads accordingly.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

eu_cn

.twitter.com

1 year

This cookie is set by Twitter and enables the analysis of the website usage by the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

external_referer

.twitter.com

7 days

This cookie is set by Twitter and enables the analysis of the website usage by the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

fr

.facebook.com

90 days

This cookie is used to deliver ads and measure and improve their relevance.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

guest_id

.twitter.com

24 hours

This cookie is set by Twitter and enables the analysis of the website usage by the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

personalization_id

.twitter.com

2 years

This cookie is set by Twitter and enables the analysis of the website usage by the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

sb

facebook.com

2 years

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

spin

facebook.com

25 hours

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

syndication_guest_id

.twitter.com

2 years

This cookie is set by Twitter and enables the analysis of the website usage by the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

tfw_exp

.twitter.com

14 days

This cookie is set by Twitter and enables the analysis of the website usage by the user.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

pinterest_ct_rt

.ct.pinterest.com

1 year

This cookie is used for marketing measurement and website usage analysis.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_pws

.taboola.com

30 minutes

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_mkto_trk

.taboola.com

2 years

This cookie is used to measure the effectiveness of marketing activities.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_ma_cookie

.taboola.com

12 hours

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_sid

.taboola.com

30 minutes

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_pw

.taboola.com

1 year

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_uetvid

.taboola.com

16 days

This cookie is used to analyse and track
website usage and display relevant advertising. The data is transferred to Microsoft.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_uetsid

.taboola.com

24 hours

This cookie is used to analyse and
track website usage and display relevant advertising.  The data is transferred to Microsoft.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_hjid

.taboola.com

Session 
(until browser tab is closed)

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

ufcStatus

.taboola.com

2 years

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_vid_l

.taboola.com

1 year

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_first_visit

.taboola.com

1 year

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_cid

.taboola.com

1 year

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_vuid_l

.taboola.com

1 year

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

tbp-consent

.taboola.com

>2 years

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

t_gid

.taboola.com

1 year

This cookie assigns a unique user ID to the visitor. This allows to provide personalised advertising.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

ga_cid

.taboola.com

2 years

This cookie is set to meet legal requirements. 
Tracking of website usage and for the display of relevant advertising. The data is transferred to Google.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

d_id

.taboola.com

2 years

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

__utmzzses

.taboola.com

Session 
(until browser tab is closed)

This cookie is set to meet legal requirements. 
Tracking of website usage and for the display of relevant advertising. The data is transferred to Google.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

trd_referral

.taboola.com

1 year

This cookie is used for marketing purposes.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

SAPISID

.google.com

2 years

This cookie is set to meet legal requirements. 
Tracking of website usage and for the display of relevant advertising. The data will be transferred to YouTube (Google).

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

 

3.2.4 Performance


We are constantly trying to improve our shop. We gain much of the input on this by evaluating performance cookies. They show us how our customers move around the site. Your data will be used anonymously.3.2.4 Performance

1st Party Cookies are marked with Domain galaxus.de, digitecgalaxus.ch, GMT (Google Tag Manager) or Akamai. All other domains are 3rd party cookies.

Cookie Key / Identifier

Domain

Cookie lifespan

Description for users/ Data processing purpose

Legal basis

AMP_TOKEN

galaxus.de

1 day

This cookie is essential for the security of the website and the visitor.

 

The guarantee of secure data processing is a secondary performance obligation arising from the contractual relationship and is thus carried out on the basis of Art. 6 I lit. b) GDPR.

DisplayedMarketing

Teasers

galaxus.de

16 days

Provision of essential functions of the website.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

ClickedMarketing

TeaserPerformanceIds

galaxus.de

-

Provision of essential functions of the website.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

.cid

galaxus.de

-

Provision of essential functions of the website.

The processing is carried out to protect our legitimate interest in providing a user-friendly and functional online shop. Therefore, the legal basis is Art. 6 I lit. a) GDPR.

ai_user

galaxus.de

-

The purpose of the processing is the statistical analysis of telemetry and usage data of uniquely identifiable users through the Microsoft insights software.

The collection of statistical information to optimise our offer takes place to protect our legitimate interest pursuant to Art. 6 I lit. f) GDPR.

ai_session

galaxus.de

-

The purpose of the processing is the statistical analysis of telemetry and usage data of uniquely identifiable Sessions through the Microsoft insights software.

The collection of statistical information to optimise our offer takes place to protect our legitimate interest pursuant to Art. 6 I lit. f) GDPR.

_dc_gtm_UA-xxx

GTM (Google Tag Manager)

1 minute

Google Analytics cookie to throttle requests.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

_ga

GTM,

 digitecgalaxus.ch, .twitter.com, .taboola.com

2 years

A randomly generated user ID allows Google to recognise the visitor and link it to data from a previous visit.

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

AMP_TOKEN

GTM

1 year

Generates User ID Google Analytics tracking of AMP pages (page hosted by Google for faster loading in mobile devices).

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

.cid

GTM

10 years

Fixer identifier analogous to BrowserId for Google Analytics

The legal basis is your consent according to Art. 6 I lit. a) GDPR.

siteState

.taboola.com

>2 years

This cookie stores the affiliation to a US state for the fulfilment of legal obligations.

The fulfilment of legal obligation according to Art. 6 I lit. c) GDPR.

siteCountryCode

.taboola.com

>2 years

To improve the provisioning time, the user's country code is recorded in this cookie.

The provision of a user-friendly internet offer is a legitimate interest within the meaning of Art. 6 I lit. f) GDPR.

 

4. Encryption

To prevent unauthorised access to your personal data by third parties, the connection is encrypted using TLS technology.

 

Date 25.08.2021

Version 2.0