With us, you remain undisturbed by Facebook and other advertising octopuses that want to obtain your personal data and know your purchasing behavior. It is also not possible for these providers to track your Internet traces on our site via so-called "fingerprinting".
We have deliberately decided against the use of Google analysis software and the use of social media plugins, as these often read out a large amount of data that often goes beyond the use of the individual website. We want to convince you with our products and enable you to purchase these products with the greatest possible degree of privacy. It is therefore not necessary for us to ask you for your consent for third parties to read your data, as many other websites do. We simply do not allow it.
We cannot avoid the use of individual cookies from our own store system, which are absolutely necessary so that you can shop with us without functional restrictions and we receive basic statistical data about the use of our site. However, we do this without the help of the widely used "Google Analytics", but rather exclusively through the use of locally installed software (Matomo), which completely anonymizes access to our site and thus does not allow any conclusions to be drawn about you. The few cookies that make it easier for you to use our online store are set exclusively by our own server operated in Germany and are deleted at the end of your visit or at the latest after your browser cache has been cleared manually.
We only collect personal data if you make a purchase via our website and if we need it for order processing.
Unfortunately, we have no influence on the cookie policy of the payment provider PayPal. But we have taken precautions and give you the choice here: If you want to use PayPal as a payment method, you can activate it in our order process (you will be expressly informed of this there and then). Until this point, PayPal has no access to your (and our) data.
In this way we guarantee - contrary to the general development in online shipping - a conscious and careful handling of your personal data.
1. Data protection at a glance
2. Hosting and Web Application Firewall (WAF)
3. General notes and mandatory information
4. Data collection on our website
5. Analysis tools
6. Payment provider
7. Our newsletter
-
1. Data protection at a glance
-
General information
The following information provides a simple overview of what happens to your personal data when you visit our website. Personal data is any data that can be used to identify you personally. Detailed information on the subject of data protection can be found in our data protection declaration listed below this text.
Data collection on our website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find the operator's contact details in the legal notice of this website.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form.
Other data is collected automatically by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of page view). This data is collected automatically as soon as you enter our website.
What do we use your data for?
Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice if you have any further questions on the subject of data protection. You also have the right to lodge a complaint with the competent supervisory authority.
Analysis tools and tools from third-party providers
When you visit our website, your surfing behavior may be statistically evaluated. This is primarily done using cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. You can find detailed information on this in the following privacy policy.
You can object to this analysis. We will inform you about the objection options in this privacy policy.
-
2. Hosting and web application firewall (WAF)
-
We host the content of our website with the following provider:
External hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hoster(s). This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses and other data generated via a website.
External hosting is carried out for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR). If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Our hoster(s) will only process your data to the extent necessary to fulfill its performance obligations and follow our instructions with regard to this data.
We use the following host(s):
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Gunzenhausen, GermanyOrder processing
We have concluded an order processing contract (AVV) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that it processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Cloudflare
We use the "Cloudflare" service. The provider is Cloudflare Inc, 101 Townsend St., San Francisco, CA 94107, USA (hereinafter referred to as "Cloudflare").
Cloudflare offers a globally distributed content delivery network with DNS. The information transfer between your browser and our website is technically routed via the Cloudflare network. This enables Cloudflare to analyze the traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the Internet.
The use of Cloudflare is based on our legitimate interest in providing our website as error-free and secure as possible (Art. 6 para. 1 lit. f GDPR).
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https: //www.cloudflare.com/privacypolicy/.
Further information on security and data protection at Cloudflare can be found here: https: //www.cloudflare.com/privacypolicy/.
Order processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, which ensures that it processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Friendly Captcha
We use Friendly Captcha (hereinafter "Friendly Captcha") on this website. The provider is Friendly Captcha GmbH, Am Anger 3-5, 82237 Woerthsee, Germany.
Friendly Captcha is used to check whether the data input on this website (e.g. in a contact form) is made by a human or by an automated program. For this purpose, Friendly Captcha analyzes the behavior of the website visitor based on various characteristics. For the analysis, Friendly Captcha evaluates various information (e.g. anonymized IP address, referrer, visit time, etc.). Further information on this can be found at: https: //friendlycaptcha.com/legal/privacy-end-users/.
The data is stored and analyzed on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its website from abusive automated spying and SPAM. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
-
3. General notes and mandatory information
-
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible.
Note on the responsible body
The controller responsible for data processing on this website is
Harald Daub
Thomas Hoof Produktgesellschaft mbH & Co. KG
Bahnhofstraße 3
59348 LüdinghausenTelephone: +49 2591 2590-210
E-mail: info@thpg.deThe controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, e-mail addresses, etc.).
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw your consent at any time. All you need to do is send us an informal email. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to lodge a complaint with the competent supervisory authority
In the event of breaches of data protection law, the data subject has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is based. A list of data protection officers and their contact details can be found at the following link: https: //www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place if it is technically feasible.
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If there is an obligation to send us your payment data (e.g. account number for direct debit authorization) after the conclusion of a fee-based contract, this data is required for payment processing.
Payment transactions via the usual means of payment (Visa/MasterCard, direct debit) are made exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.
With encrypted communication, the payment data you transmit to us cannot be read by third parties.
Information, blocking, deletion
Within the framework of the applicable legal provisions, you have the right to free information about your stored personal data, its origin and recipient and the purpose of the data processing and, if necessary, a right to correction, blocking or deletion of this data at any time. You can contact us at any time at the address given in the legal notice if you have further questions on the subject of personal data.
Objection to advertising emails
We hereby object to the use of contact data published in the context of the legal notice obligation to send unsolicited advertising and information material. The operators of the website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.
-
4. Data collection on our website
-
Cookies
Some of the Internet pages use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies are used to make our website more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your end device until you delete them. These cookies enable us to recognize your browser on your next visit.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
Cookies that are required to carry out the electronic communication process or to provide certain functions you wish to use (e.g. shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimized provision of its services. Insofar as other cookies (e.g. cookies to analyze your surfing behavior) are stored, these are treated separately in this privacy policy.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are
- Browser type and browser version
- operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources.
The basis for data processing is Art. 6 para. 1 lit. f GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
Contact form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We will not pass on this data without your consent.
The data entered in the contact form is therefore processed exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. All you need to do is send us an informal email. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.
We will retain the data you provide on the contact form until you request its deletion, revoke your consent for its storage, or the purpose for its storage no longer pertains (e.g. after fulfilling your request). Mandatory statutory provisions - in particular retention periods - remain unaffected.
Registration on this website
You can register on our website in order to use additional functions on the site. We use the data entered for this purpose only for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise we will reject the registration.
In the event of important changes, for example to the scope of the offer or technically necessary changes, we will use the e-mail address provided during registration to inform you in this way.
The data entered during registration is processed on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can withdraw your consent at any time. All you need to do is send us an informal email. The legality of the data processing that has already taken place remains unaffected by the revocation.
The data collected during registration will be stored by us for as long as you are registered on our website and will then be deleted. Statutory retention periods remain unaffected.
Processing of data (customer and contract data)
We collect, process and use personal data only insofar as it is necessary for the establishment, content or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. We collect, process and use personal data about the use of our website (usage data) only insofar as this is necessary to enable or charge the user for the use of the service.
The customer data collected will be deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
Data transmission when concluding contracts for online stores, retailers and shipping goods
We only transfer personal data to third parties if this is necessary in the context of contract processing, for example to the companies entrusted with the delivery of the goods or the credit institution commissioned with payment processing. Any further transmission of data will not take place or will only take place if you have expressly consented to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures.
-
5. Analysis tools
-
Matomo (formerly Piwik)
This website uses the open source web analysis service Matomo. Matomo uses technologies that enable the cross-page recognition of the user to analyze user behavior (e.g. cookies or device fingerprinting). The information collected by Matomo about the use of this website is stored on our server. The IP address is anonymized before storage.
With the help of Matomo, we are able to collect and analyze data about the use of our website by website visitors. This enables us to find out, among other things, when which pages were accessed and from which region. We also record various log files (e.g. IP address, referrer, browser and operating system used) and can measure whether our website visitors perform certain actions (e.g. clicks, purchases, etc.).
The use of this analysis tool is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the anonymized analysis of user behavior in order to optimize both its website and its advertising. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.
IP anonymization
We use IP anonymization for the analysis with Matomo. Your IP address is shortened before the analysis so that it can no longer be clearly assigned to you.
-
6. Payment provider
-
PayPal
We offer payment via PayPal on our website. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as "PayPal").
If you select payment via PayPal, the payment data you enter will be transmitted to PayPal.
The transmission of your data to PayPal is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). You have the option of withdrawing your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations in the past.
-
7. Newsletter
-
Newsletter data
If you subscribe to our newsletter (info letter), we will use the email address you provide to regularly send you our email newsletter based on your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
If we receive your e-mail address in connection with the sale of a product and you have not objected to this, we reserve the right to regularly send you offers for similar products to those you have already purchased from our range by e-mail on the basis of Section 7 (3) UWG. This serves to safeguard our legitimate interests, which predominate in the context of a balancing of interests, in a promotional approach to our customers in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
We use the so-called double opt-in procedure to subscribe to our newsletter. This means that after you have entered your email address, we will send you a confirmation email to the email address you have provided, in which we ask you to confirm that you wish to receive the newsletter. If you do not confirm this, your registration will be automatically deleted. If you confirm your wish to receive the newsletter, we will store your e-mail address until you unsubscribe from the newsletter. The sole purpose of this storage is to be able to send you the newsletter. Furthermore, we store your IP address and the time of registration and confirmation in order to prevent misuse of your personal data.
You can revoke your consent to receive the newsletter at any time. You can declare your revocation by clicking on the link provided in every newsletter e-mail, by sending an e-mail to info@thpg.de or by sending a message to the contact details given in the legal notice. You will not incur any costs other than the transmission costs according to the basic rates.
We use a newsletter service provider, which is described below, to process the newsletter.
Inxmail
This website uses Inxmail to send newsletters. The provider is Inxmail GmbH, Wetzinger Straße 17, 79106 Freiburg, Germany (hereinafter referred to as Inxmail). Inxmail is a service that can be used to organize and analyse the sending of newsletters, among other things. The data you enter for the purpose of subscribing to the newsletter is processed on Inxmail's servers.
Data analysis by Inxmail
With the help of Inxmail, we are able to analyze our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links have been clicked on. In this way, we can determine, among other things, which links were clicked on particularly often. We can also see whether certain previously defined actions were carried out after opening/clicking (conversion rate). For example, we can recognize whether you have made a purchase after clicking on the newsletter.
You can find Inxmail's privacy policy at: https://www.inxmail.de/datenschutz.
Anonymized tracking
We use Inxmail's anonymized tracking, which does not allow us to identify you personally if you have expressly consented to this in advance.
Legal basis
Data processing is based on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time for the future.
Storage period
The data you provide us with for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and deleted from the newsletter distribution list after you unsubscribe from the newsletter or after the purpose no longer applies. We reserve the right to delete or block e-mail addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR. Data stored by us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.
Order processing
We have concluded a data processing agreement (DPA) with the above-mentioned provider. This is a contract prescribed by data protection law, which ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
Website Cookies
The table below lists the cookies we collect and what information they store. All cookies are technically necessary and are used to ensure the technical performance of the website.
Cookie Name | Host(s) | Expiration | Cookie Description |
---|---|---|---|
FORM_KEY Form_key |
thpg.de .thpg.de |
Session 1 hour |
Stores randomly generated key used to prevent forged requests. |
PHPSESSID | thpg.de | Session | Your session ID on the server. |
MAGE MESSAGES | thpg.de | 1 hour | Facilitates caching of content on the browser to make pages load faster. |
login_redirect | thpg.de | Session | Preserves the destination page that was loading before the customer was directed to log in. Is only set when required. |
Facilitates caching of content on the browser to make pages load faster. | |||
MAGE-CACHE-STORAGE | thpg.de | 1 hour | Facilitates caching of content on the browser to make pages load faster. |
MAGE-CACHE-STORAGE-SECTION-INVALIDATION | thpg.de | depending on the browser's local storage settings | Facilitates caching of content on the browser to make pages load faster. |
SECTION_DATA_CLEAN | thpg.de | 1 hour | Facilitates caching of content on the browser to make pages load faster. |
SECTION-DATA-IDS | thpg.de | 1 hour | Facilitates caching of content on the browser to make pages load faster. |
PRIVATE_CONTENT_VERSION | thpg.de | 1 day | Facilitates caching of content on the browser to make pages load faster. |
X-Magento-Vary | thpg.de | 1 hour | This cookie is used to deliver the correct custom views of the shop from the cache. |
MATOMO_SESSID | stats.thpg.de | 2 Weeks | Used to save Matomo opt-out status. |