Skip to main content Skip to search Skip to main navigation

Privacy Notice

Last updated: 22/04/2026

devolo solutions GmbH takes the protection of your personal data very seriously. We want you to know when we collect which data and how we use it. We have implemented technical and organizational measures to ensure that the data protection regulations are observed by both us and external service providers.

1. Access data and hosting Hosting
2. Data processing for contract processing and for contacting us
3. Data processing for the purposes of shipment
4. Data processing for the purposes of payment
5. Marketing via e-mail
6. Cookies and further technologies
7. Use of cookies and other technologies
8. Social Media
9. Contact options and your rights


Data controller is:

devolo solutions GmbH
Charlottenburger Allee 67
52068 Aachen
Germany
E-Mail: info@devolo.de
Phone: +49 241 18279-0

Thank you for visiting our online shop. Protection of your privacy is very important to us. Below you will find extensive information about how we handle your data.

1. Access data and hosting

You may visit our website without revealing any personal information. With every visit on the website, the web server stores automatically only a so-called server log file which contains e.g. the name of the requested file, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request. These access data are analysed exclusively for the purpose of ensuring the smooth operation of the website and improving our offer. This serves according to Art. 6 (1) (f) GDPR the protection of our legitimate interests in the proper presentation of our offer that are overriding in the process of balancing of interests. All access data are deleted no later than thirty days after the end of your visit on our website.


Hosting

The services for hosting and displaying the website are partly provided by our service providers on the basis of processing on our behalf. Unless otherwise stated in this privacy policy, all access data and all data collected in forms provided for this purpose on this website are processed on their servers. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

2. Data processing for contract processing and for contacting us

2.1 Data processing for the purposes of performing the contract

For the purpose of performing the contract (including enquiries regarding the processing of any existing warranty and performance fault claims as well as any statutory updating obligations) in accordance with Art. 6 (1) (b) GDPR, we collect personal data if you provide it to us voluntarily as part of your order. Mandatory fields are marked as such, as in these cases we necessarily need the data to process the contract and we cannot send the order without their specification. Which data is collected can be seen from the respective input forms. Further information on the processing of your data, in particular on the forwarding of the data to our service providers for the purpose of order, payment and shipping, can be found in the following sections of this privacy policy. After complete processing of the contract, your data will be restricted for further processing and deleted after expiry of the retention periods under tax and commercial law in accordance with Art. 6 (1) (c) GDPR, unless you have expressly consented to further use of your data in accordance with Art. 6 (1) (a) GDPR or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this privacy policy.


Merchandise management system

We use merchandise management systems of external service providers for order and contract processing. We engage our service providers on the basis of processing on our behalf. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

Our service providers are located and/or use servers in countries outside the UK, EU and the EEA for which an adequate level of data protection has been identified by means of the UK adequacy regulation.

Our service providers are located and/or use servers in countries outside the UK, the EU and the EEA. For these countries, there is no UK adequacy regulation. Our cooperation is based on standard data protection clauses of the European Commission, appended by the UK Addendum.

2.2 Customer account

Insofar as you have given your consent to this in accordance with Art. 6 (1) (a) GDPR by deciding to open a customer account, we will use and store your data for the purpose of opening the customer account as well as for further future orders on our website. Deletion of your customer account is possible at any time and can be done either by sending a message to the contact option described in this privacy policy or via a function provided for this purpose in the customer account. After deletion of your customer account, your data will be deleted unless you have expressly consented to further use of your data in accordance with Art. 6 (1) (a) GDPR or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this privacy policy.


2.3 Establishing contact

As part of our customer communication, we collect personal data in order to process your enquiries in accordance with Art. 6 (1) (b) GDPR if you voluntarily provide us with this data when contacting us (e.g. via contact form or e-mail). Mandatory fields are marked as such, as in these cases we necessarily need the data to process your enquiry. Which data is collected can be seen from the respective input forms. After your enquiry has been fully processed, your data will be deleted unless you have expressly consented to further use of your data in accordance with Art. 6 (1) (a) GDPR or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this privacy policy.

3. Data processing for the purposes of shipment

We forward your data to the shipping company within the scope required for the delivery of the ordered goods according to Art. 6 (1) (b) GDPR. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.


Data transmission to a shipping provider for the purposes of shipment notification

Provided that you have given us your explicit consent, during or after your order, we will forward your e-mail address in accordance with Art. 6 (1) (a) GDPR to the selected shipping provider in order to enable them to contact you for the purpose of shipment notification or coordination prior to shipment. This consent may be withdrawn at any time by sending a message to the contact information described in this privacy policy or directly to the shipping provider using the contact address listed below. After consent withdrawal, we will delete the data you have provided for this purpose, unless you have expressly consented to further use of your data or we have reserved the right to use your data for other purposes which are permitted by law and about which we inform you in this privacy policy. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.


exporto GmbH
Bücklestraße 5
78467 Konstanz
Germany


Trusted Returns GmbH
Peter-Josef-Lenné-Straße 5
51377 Leverkusen
Germany

4. Data processing for the purposes of payment

As part of the payment process in our online shop, we work together with these partners: technical service provider, credit institution, payment service provider.

4.1 Data processing for the purposes of transaction processing

Depending on the selected payment method, we transfer the data necessary for processing the payment transaction to our technical service providers, to the commissioned credit institutions, or to the selected payment service provider, insofar as this is required for processing the payment. This is done for the performance of the contract pursuant to Art. 6 (1) (b) GDPR. In some cases, the payment service providers themselves collect the data required for processing the payment, e.g. on their own website or via a technical integration in the ordering process. In this respect, the privacy policy of the respective payment service provider applies.

Depending on the selected payment method, data transfers may occur to third countries outside the EU/EEA for which the European Commission has determined an adequate level of data protection by decision. Insofar as data transfers take place to third countries outside the EU/EEA for which the European Commission has not issued a decision on an adequate level of data protection, the cooperation is based on the European Commission’s standard contractual clauses.

If you have any questions regarding our partners for payment processing or the basis of our cooperation with them, please contact the point of contact specified in this privacy policy. 

4.2 Data processing for the purposes of fraud prevention and optimisation of our payment processes

We may forward other data to our service providers, which they use for the purpose of fraud prevention and to optimise our payment processes (e.g. invoicing, processing of contested payments, accounting support) together with the data necessary to process the payment as our processors. This serves to safeguard our legitimate interests in fraud prevention or an efficient payment management in accordance with Art. 6 (1) (f) GDPR that are overriding in the process of balancing of interests.

4.3 Identity and credit assessment when selecting Klarna payment services

Klarna Pay now (Direct debit), Klarna Pay later (Invoice), Klarna Slice it (Payment by instalments) If you choose to use the payment services of Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter Klarna), we request your consent that we may forward to Klarna the data necessary for processing the payment and for an identity and credit assessment in accordance with Art. 6 (1) (a) GDPR. In Germany, the credit agencies listed in Klarna's privacy policy can be used for identity and credit assessment. Klarna will use information obtained on the statistical probability of payment default for a balanced decision on the establishment, execution or termination of the contractual relationship. You can withdraw your consent at any time by sending a message to the contact option specified in this privacy policy. As a result, we may no longer be able to offer you certain payment methods. You may also withdraw your consent to this use of your personal data at any time, also to Klarna.


4.4 Identity and credit checks when selecting purchase on account via PayPal and Ratepay

If you choose the payment method purchase on account (offered via Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin, Germany (hereinafter referred to as Ratepay) and PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg (hereinafter referred to as PayPal)), we request your consent pursuant to Art. 6 (1) (a) GDPR that we may transmit to Ratepay the data necessary for the processing of the payment and an identity and credit check. In Germany, the credit agencies named in Ratepay's data protection declaration may be used for the identity and credit check. Ratepay uses the information received about the statistical probability of a payment default for a weighed decision about the establishment, implementation or termination of the contractual relationship. You can revoke your consent at any time by sending a message to the contact option mentioned in this privacy policy. This may result in us no longer being able to offer you certain payment options. Additional information on data protection at PayPal can be found here.

5. Marketing via e-mail

5.1 E-mail newsletter with subscription and newsletter tracking

If you subscribe to our newsletter, we will regularly send you our email newsletter based on your consent according to Art. 6 (1) (a) GDPR, using the data required or disclosed by you separately for this purpose.

ou can unsubscribe from the newsletter at any time. This can either be done by sending a message to the contact option described in this privacy policy or via a link provided for this purpose in the newsletter. After unsubscribing, we will delete your e-mail address from the list of recipients, unless you have expressly consented to the further use of your data according to Art. 6 (1) (a) GDPR or we have reserved the right to use your data for other purposes that are permitted by law and about which we inform you in this privacy policy.

We would like to point out that we evaluate your user behaviour when sending the newsletter. For this purpose, we also analyse your interaction with our newsletter by measuring, storing and evaluating opening rates and click-through rates for the purpose of designing future newsletter campaigns ("newsletter tracking").

For this evaluation, the emails sent contain single-pixel technologies (e.g. so-called web beacons, tracking pixels) that are stored on our website. For the evaluations, we link the following "newsletter data" in particular

  • the page from which the page was requested (so-called referrer URL),
  • the date and time of the request,
  • the description of the type of web browser used,
  • the IP address of the requesting computer,
  • the e-mail address,
  • the date and time of registration and confirmation

and the single-pixel technologies with your e-mail address or your IP address and, if applicable, an individual ID. Links contained in the newsletter may also contain this ID.

If you do not wish to receive newsletter tracking, it is possible to unsubscribe from the newsletter at any time - as described above.

The information will be stored as long as you have subscribed to the newsletter.

5.2 E-Mail advertising without subscription to the newsletter and your right to opt out

If we receive your email address in connection with the sale of a product or service and you have not opted out, we reserve the right to regularly email you offers for products from our product range that are similar to those you have already purchased. This serves the protection of our legitimate interests in promoting and advertising our products to customers according to Art. 6 (1) (f) GDPR that are overriding in the process of balancing of interests. You can opt out of this use of your email address at any time by sending a message to the contact option specified in this privacy policy or by using the opt-out link in the advertising email, without incurring any costs beyond the cost of transfer calculated at the base rates. After unsubscribing, we will delete your e-mail address from the list of recipients, unless you have expressly consented to the further use of your data according to Art. 6 (1) (a) GDPR or we have reserved the right to use your data for other purposes that are permitted by law and about which we inform you in this privacy policy. 


5.3 Newsletter mailing

The newsletter is sent to you by our service provider who processes data on our behalf and to whom we disclose your email address. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

The newsletter and the newsletter tracking shown above may also be sent by our service providers as part of processing on our behalf. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.

6. Cookies and further technologies

6.1 General information

In order to make visiting our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use technologies on various pages, including so-called cookies. Cookies are small text files that are automatically stored on your end device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognise your browser during your next visit (persistent cookies).

Protection of privacy for terminal devices

When you use our online services, we use technologies that are absolutely necessary in order to provide the telemedia service you have expressly requested. The storage of information in your terminal device or access to information that is already stored in your terminal device does not require consent in this respect.

For functions that are not absolutely necessary, the storage of information in your terminal device or access to information that is already stored in your terminal device requires your consent. Please note that if you do not give your consent, parts of the website may not be available for unrestricted use. Any consent you may have given will remain valid until you adjust or reset the respective settings in your terminal device.

Any downstream data processing through cookies and other technologies

We use such technologies that are strictly necessary for the use of certain functions of our website (e.g. shopping cart function). These technologies are used to collect and process IP addresses, time of visit, device and browser information as well as information on your use of our website (e.g. information on your preferences). This serves to safeguard our legitimate interests in an optimised presentation of our offer that are overriding in the process of balancing of interests.

In addition, we use technologies to fulfil the legal obligations, which we are subject to (e.g. to be able to prove consent to the processing of your personal data) as well as for web analysis and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.

On our website we may use other technologies, which are not listed individually in this privacy policy. Further information on these technologies and the respective legal basis can be found on the platform of our consent management service Usercentrics.

You can access the platform by clicking on the fingerprint button in the bottom right or left corner of the page.


What types of cookies are being used?

Functional cookies: These cookies are used for certain features of our website, e.g. to improve the website’s navigation, or deliver to you customised and relevant information (e.g. ads that match your interests).

Essential cookies: These cookies are necessary to enable you to use our website. This includes e.g. cookies that enable you to log into the customer area or add items to your shopping cart.

Marketing cookies: These cookies record information about your visit to the website, previously viewed pages and links you clicked. We use this information to tailor our website and displayed ads to your interests.

Analytical / performance cookies: These cookies enable collecting anonymised data about user behaviour on our website. We analyse them e.g. to improve the functionality of our website and recommend you products that will be interesting to you.


Cookie settings

You can find the cookies settings for your browser by clicking on the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera

If you have consented to the use of the technologies in accordance with Art. 6 (1) (a) GDPR, you can withdraw your consent at any time by sending a message to the contact option described in the privacy policy. Alternatively, you can also click on the fingerprint button in the lower right or left corner of the page. If cookies are not accepted, the functionality of our website may be limited.
 

6.2 Use of Usercentrics Consent Management Platform to Manage Consents

We use the consent management solution of Usercentrics GmbH, Sendlinger Str. 7, 80331 Munich, Germany (“Usercentrics”), to obtain and document your consent to cookies or other technologies in compliance with data protection laws.

When visiting our website, the following data is transmitted to Usercentrics:

  • Your consents or revocation of consents
  • Your IP address
  • Information about browser and terminal device
  • Time of visit

Usercentrics sets a cookie for this purpose, which stores the status of your consents. Storage takes place until you delete the cookie or request us to delete it.

Processing is carried out to fulfill our legal obligation pursuant to Art. 6(1)(c) GDPR.

6.3 Information on Third-Country Transfers (Data Transfer to Third Countries)

We use technologies from service providers on our website whose registered office and/or server locations may be in third countries outside the EU or EEA. If there is no adequacy decision by the EU Commission for the respective country, an adequate level of data protection must be ensured by means of other suitable safeguards.

Suitable safeguards in the form of contractually agreed Standard Contractual Clauses (SCCs) of the EU Commission or Binding Corporate Rules are generally possible, but require prior verification by the contracting parties as to whether an adequate level of protection can be guaranteed. According to ECJ jurisprudence, it may be necessary to take additional protective measures.

We have generally agreed the Standard Data Protection Clauses issued by the EU Commission with the technology providers we use who process personal data in a third country. Where possible, we also agree additional safeguards designed to ensure that adequate data protection is guaranteed in third countries without an adequacy decision.

Regardless of this, despite all contractual and technical measures, the level of data protection in the third country may not correspond to that of the EU. For these cases, we ask for your consent pursuant to Art. 49(1)(a) GDPR for the transfer of your personal data to a third country, if necessary within the framework of cookie consent.

In particular, there is a risk that local authorities of the third country may obtain access rights to your personal data that are not sufficiently restricted from a European data protection perspective, that we as data exporter or you as data subject may not be aware of this, and/or that you may not have sufficient legal remedies available to prevent this and/or take action against such access.

In particular, the following countries are currently among the third countries without an adequacy decision by the EU Commission (example list):

  • China
  • Russia
  • Taiwan

In which third countries data is transferred by us can be found in the privacy notices for the respective tool used and/or the Consent Management Platform (CMP) service used by us.

7. Use of Cookies and Other Technologies

We use the following cookies and other third-party technologies on our website. Unless otherwise stated for individual technologies, this is done on the basis of your consent pursuant to Art. 6(1)(a) GDPR. After the purpose no longer applies and the use of the respective technology by us ends, the data collected in this context will be deleted. You can revoke your consent at any time with effect for the future. Further information on your revocation options can be found in the "Cookies and other technologies" section. Further information, including the basis of our cooperation with individual providers, can be found under the individual technologies. If you have any questions about the providers and the basis of our cooperation with them, please contact the option described in this privacy policy.

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is used for technical management and deployment of scripts (e.g. for Google Analytics or marketing tools). The Tag Manager itself does not perform analysis, store cookies, or create its own user profiles.

To deliver the Tag Manager, technical data (e.g. IP address, browser information) is processed. Where possible, the Tag Manager is not loaded directly from googletagmanager.com servers, but via our own infrastructure (e.g. a so-called GTAG Gateway). This reduces data transfer to Google and makes the processing of technical connection data more privacy-friendly.

If data is transmitted to Google (e.g. when loading the Tag Manager directly), this may also be sent to servers in the USA. Google is certified under the EU-US Data Privacy Framework (DPF).

The use of Tag Manager is based on Art. 6(1)(f) GDPR (legitimate interest in efficient and privacy-compliant management of tracking and marketing services). Insofar as consent is required for integrated tools, these will only be activated by Tag Manager if you have consented pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TTDDG.

Google Fonts

For uniform presentation of content on our website, data (IP address, time of visit, device and browser information) is collected by the "Google Fonts" script code, transmitted to Google, and subsequently processed by Google. We have no influence on this subsequent data processing.

YouTube Video Plugin

To integrate third-party content via the YouTube Video Plugin in the enhanced data protection mode used by us, data (IP address, time of visit, device and browser information) is collected, transmitted to Google, and subsequently processed by Google only when you play a video.

7.1 Use of Google Services

We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) described below. The information automatically collected by Google technologies about your use of our website is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. Unless otherwise specified for individual technologies, data processing takes place on the basis of an agreement concluded for the respective technology between joint controllers pursuant to Art. 26 GDPR. Further information about data processing by Google can be found in Google's privacy policy.

Our service providers are located and/or use servers in countries outside the EU and EEA for which the European Commission has determined an adequate level of data protection by decision.

Our service providers are located and/or use servers in countries outside the EU and EEA. For these countries, there is no adequacy decision by the European Commission. Our cooperation with them is based on Standard Contractual Clauses of the European Commission.

Google Analytics

We use Google Analytics 4 on our website, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). With the help of Google Analytics 4, we analyze the use of our website, create reports on visitor activities, and evaluate them to optimize our content.

Google Analytics 4 uses cookies and similar technologies. However, the information collected about your use of the website (e.g. pages viewed, browser information used, operating system, click paths) is not directly passed on to Google, but first processed via our Server-Side Tagging (SST) server, which we operate in the EU West 3 (Frankfurt) region on Google Cloud Run.

On this server, your data — in particular the IP address transmitted by your device — is already anonymized or pseudonymized before being forwarded to Google servers for further processing. In this way, we reduce direct data exchange between your terminal device and Google and strengthen the protection of your personal data.

The data is used by Google on our behalf solely to create reports on website activity and to provide other services associated with website use. Merging with other Google data does not take place according to our settings. The retention period for Analytics data is 14 months.

In addition, we use the Google Signals feature within Google Analytics 4. It enables cross-device reporting if you have activated "personalized advertising" in your Google account. In this context, we receive exclusively anonymous, statistical evaluations, no personal data. You can deactivate use at any time in your Google account settings.

The legal basis for using Google Analytics 4 is your consent pursuant to Art. 6(1)(a) GDPR, which you grant via our cookie consent tool. Without consent, Google Analytics 4 will not be used. You can revoke your consent at any time with effect for the future via the consent tool.

We have concluded a data processing agreement (Art. 28 GDPR) with Google. For any transfers to third countries (e.g. USA), Google relies on standard contractual clauses approved by the EU Commission. Further information can be found in Google's privacy policy at:

https://policies.google.com/privacy?hl=en

https://policies.google.com/technologies/partner-sites?hl=en

7.2 Server-Side Tagging (SST) for the Use of Further Services

In addition to Google Analytics 4, we also use our Server-Side Tagging container (Google Cloud Run, Region EU West 3 / Frankfurt) for processing and forwarding data to other marketing and analytics tools, e.g. Google Ads, Meta Ads (Facebook/Instagram) or Conversion APIs.

The procedure is identical:

  • Data regarding your website usage is first transmitted to our SST server in the EU.
  • There, anonymization or pseudonymization takes place where technically possible (e.g. shortening the IP address).
  • Only then is the processed information forwarded to the respective providers.

The use of these tools generally takes place only with your express consent (Art. 6(1)(a) GDPR) via our cookie consent tool. We process purely technical log data necessary to ensure trouble-free operation and IT security based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

If we pass on data to third-party providers (e.g. Google, Meta) based on your consent, data may also be processed in countries outside the EU (in particular the USA). In these cases, transfer takes place on the basis of standard contractual clauses approved by the EU Commission or other safeguards.

You can revoke your consent for the respective services at any time with effect for the future via our consent management tool.

Google Ads

We use Google Ads Conversion Tracking, a service of Google Ireland Limited.

If you reach our website via a Google ad, a cookie with a limited duration (max. 90 days) is stored, which serves exclusively to measure advertising effectiveness. We only learn aggregated values, such as how many users clicked on an ad and subsequently executed a conversion. Personal identification is not possible.

The legal basis is your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TTDDG. Without consent, no transmission of personal data takes place.

Any transfers to the USA are based on the EU Commission's standard contractual clauses. Furthermore, Google is certified under the EU-US Data Privacy Framework (DPF).

From March 2024, Consent Mode v2 is mandatory. Our cookie banner ensures that consents for the categories "ad_user_data" and "ad_personalization" are obtained in compliance with GDPR. Without consent, Google only processes anonymized, modeled conversions.

Meta Pixel (Client-Side)

We use the Meta Pixel of the social network Facebook or Instagram on our website (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; “Meta”).

The Meta Pixel enables us to determine visitors to our website as a target group for displaying ads ("Facebook/Instagram Ads") and to measure the effectiveness of our advertising measures ("Conversion Tracking"). With the help of the pixel, we can recognize you after a visit to our website within Meta's platforms and show you interest-based advertising there.

For this purpose, when you call up our website, your device establishes a direct connection to Meta's servers. The following data is processed:

  • HTTP headers (IP address, browser information, page request time),
  • Pixel-specific data (Pixel ID, cookie information),
  • Event data (e.g. viewed products, shopping cart, purchase or registration actions).

This data can be linked by Meta to your Facebook or Instagram account. Meta may also use it for its own purposes, e.g. profiling and advertising. We have no influence on further processing by Meta.

Meta Conversion API (Server-Side via SST)

In addition to the client-side pixel, we use the Meta Conversion API (CAPI). Here, event data is transmitted server-side via our Server-Side Tagging container (Google Cloud Run, Region EU West 3, Frankfurt) to Meta.

How it works:

  • Your interactions on the website (e.g. purchases, leads, form completions) are first transmitted to our SST server.
  • Data is pseudonymized there (e.g. hashing email addresses with SHA256) and then forwarded via a secure interface to Meta.
  • In this way, we ensure that sensitive data is not sent directly from your terminal device to Meta servers in the USA, but processed first via our EU infrastructure.

The use of both the Pixel and the Conversion API serves marketing and optimization purposes, i.e. targeted placement of advertising to appropriate user groups and statistical performance evaluation of ad campaigns.

LinkedIn Insight Tag (Client-Side)

We use the LinkedIn Insight Tag of the social network LinkedIn on our website (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland; “LinkedIn”).

The LinkedIn Insight Tag enables us to identify visitors to our website as a target group for displaying ads ("LinkedIn Ads") and to measure the effectiveness of our advertising measures ("Conversion Tracking"). Via the tag, we can recognize you after visiting our website within the LinkedIn platform and present interest-based advertising to you there.

When visiting our website, a direct connection to LinkedIn servers is established. The following data, among others, may be processed:

  • HTTP headers (e.g. IP address, browser information, timestamp of page visit)
  • Tag-specific data (Tag ID, LinkedIn cookie information)
  • Event data (e.g. viewed pages, product interactions, form submissions, or purchases)

This data can be linked by LinkedIn to your LinkedIn account. LinkedIn can also use the data for its own purposes, e.g. profiling or ad serving. We have no influence on further data processing by LinkedIn.

LinkedIn Conversion API (Server-Side via SST)

In addition to the client-side Insight Tag, we use the LinkedIn Conversion API. Event data is transmitted server-side via our Server-Side Tagging container (Google Cloud Run, Region EU West 3, Frankfurt) to LinkedIn.

How it works:

  • Your website interactions (e.g. purchases, leads, form completions) are first transmitted to our SST server.
  • Data is pseudonymized there (e.g. by hashing email addresses with SHA256) and subsequently forwarded to LinkedIn via a secure interface.
  • As a result, we ensure that sensitive data is not sent directly from your device to LinkedIn servers in the USA, but processed first via our EU infrastructure.

The use of both the Insight Tag and the Conversion API serves marketing and optimization purposes, meaning the targeted placement of advertising to relevant user groups and statistical evaluation of our ad campaigns.

Legal Basis & Data Transfer:

Legal Basis: The use of the LinkedIn Insight Tag and Conversion API takes place exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with § 25 TTDDG. Without your consent, no processing takes place.

Revocation Option: You can revoke your consent at any time via our consent management tool.

Transfers to the USA: We point out that data may also be transmitted to the USA. LinkedIn Corporation (USA) is certified under the EU-US Data Privacy Framework (DPF), ensuring an adequate level of data protection. Additionally, we rely on standard contractual clauses (SCCs) approved by the EU Commission.

Further information on data processing by LinkedIn can be found in their privacy policy: https://www.linkedin.com/legal/privacy-policy

7.3 Analysis and optimisation tools

Microsoft Clarity

To provide statistics on the use of our website in the form of heatmaps (primarily created by tracking mouse movements) and session recordings, we use the Microsoft Clarity service from provider Microsoft Corporation, One Microsoft Way, Redmond, WA 98052 USA (“Microsoft”).

To analyze website usage, Microsoft Clarity uses cookies and pixels. Your IP address, mouse movements, clicks, time, frequency, location, user behavior, interaction data, and scrolling activity during your website visit as well as similar information are collected, transmitted to Microsoft (Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland), and stored there.

To assign statistics to individual campaigns, Microsoft Clarity is linked with Google Analytics 4 (see separate section in this privacy policy regarding the latter service), provided you have also consented to the use of Google Analytics 4.

The legal basis for using Microsoft Clarity including the link to Google Analytics 4 is your consent pursuant to Art. 6(1)(a) GDPR. Insofar as personal data is transferred to the USA, this takes place on the basis of Art. 45 GDPR in conjunction with the adequacy decision C(2023) 4745 of the European Commission. Both Microsoft and Google have committed to complying with the data processing principles of the Data Privacy Framework (DPF).

Please note Microsoft's privacy policy at https://privacy.microsoft.com/en-us/privacystatement and https://clarity.microsoft.com/terms.

Mouseflow

This website uses Mouseflow, a web analytics tool from Mouseflow ApS, Flaesketorvet 68, 1711 Copenhagen, Denmark. Data processing serves the purpose of analyzing this website and its visitors. For this purpose, data is collected and stored for marketing and optimization purposes. Usage profiles can be created from this data under a pseudonym. Cookies may be used for this purpose. With the Mouseflow web analytics tool, randomly selected individual visits (only with anonymized IP address) are recorded. This creates a log of mouse movements and clicks with the intention of replaying individual website visits on a sample basis and deriving potential improvements for the website. The data collected with Mouseflow will not be used to personally identify the visitor to this website without the separately granted consent of the data subject and will not be merged with personal data about the bearer of the pseudonym. Processing is based on Art. 6(1)(f) GDPR out of legitimate interest in direct customer communication and user-oriented website design. You have the right to object at any time, for reasons arising from your particular situation, to this processing of personal data concerning you based on Art. 6(1)(f) GDPR. To do so, you can globally deactivate recording on all websites using Mouseflow for your currently used browser under the following link: https://mouseflow.com/opt-out/

7.4 Use of Bloomreach Customer Data Platform (CDP)

To optimize our customer communication, provide personalized content on our website and in newsletters, and improve your digital user experience, we use the Customer Data Platform of Bloomreach B.V., Fred. Roeskestraat 109, 1076 EE Amsterdam, Netherlands. Bloomreach, a European subsidiary of the Bloomreach group of companies, processes personal data on our behalf as a data processor pursuant to Art. 28 GDPR.

Purpose of Processing

Processing of your personal data by Bloomreach takes place for:

  • Personalization of content on our website and in newsletters.
  • Target group segmentation for targeted marketing measures.
  • Automation of marketing campaigns (e.g. product recommendations, trigger emails).
  • Analysis of user behavior for continuous optimization of our digital offerings.

These processing purposes correspond to the processing purposes specified in Annex 1(B) of the DPA.

Categories of Processed Data

When using Bloomreach CDP, the following categories of personal data may be processed depending on your use of our services:

  • Identification data: Name, email address.
  • Technical data: IP address, device type, browser information, login information, log files.
  • Usage data: Pages visited, click behavior, search terms, information about viewed or searched products, duration of visits, page interactions (scrolling, clicks, mouse-overs).
  • Transaction data: Order history, shopping cart contents, browse and purchase activities (purchased pages/products, clicked links, searches performed).
  • Limited location data (city).

We point out that according to Bloomreach's own statements, Bloomreach does not collect or process special categories of personal data within the meaning of the GDPR.

Legal Basis

The processing of your personal data using Bloomreach CDP takes place on the basis of your explicit consent pursuant to Art. 6(1)(a) GDPR.

Revocation of Consent

You have the right to revoke your consent at any time with effect for the future. Revocation can generally be made via our consent management tool or by email to the contact address provided in the imprint/legal notice.

Data Transfer to Third Countries

In exceptional cases, personal data may be transferred to the parent company in the USA (Bloomreach Inc.). An adequate level of data protection is guaranteed through the conclusion and application of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Bloomreach is also contractually obligated to implement appropriate technical and organizational measures.

Retention Period

Personal data is stored only as long as necessary for the aforementioned purposes or as required by statutory retention periods. The exact retention period depends on the nature of the data and the duration of the contractual relationship.

The DPA states that the customer determines the duration of processing in accordance with the provisions of the DPA.

Your Rights

You have the right to information at any time regarding personal data stored about you, as well as the right to rectification, erasure, restriction of processing, data portability, and objection to processing. Detailed information on your rights and how to exercise them can be found in the general sections of our privacy policy.

7.5 Voucher partner

Sovendus

For selecting a voucher offer that is currently of interest to you, the hash value of your email address and your IP address are transmitted in pseudonymized and encrypted form to Sovendus GmbH, Hermann-Veit-Str. 6, 76135 Karlsruhe, Germany (Sovendus) (Art. 6(1)(f) GDPR). The pseudonymized hash value of the email address is used to take into account a possible objection to advertising from Sovendus (Art. 21(3), Art. 6(1)(c) GDPR). The IP address is used by Sovendus exclusively for data security purposes and is generally anonymized after seven days (Art. 6(1)(f) GDPR). In addition, for billing purposes, we transmit pseudonymized order number, order value with currency, session ID, coupon code, and timestamp to Sovendus (Art. 6(1)(f) GDPR). If you are interested in a voucher offer from Sovendus, there is no advertising objection for your email address, and you click on the voucher banner displayed only in this case, title, name, postal code, country, and your email address are transmitted in encrypted form to Sovendus to prepare the voucher (Art. 6(1)(b), (f) GDPR).

For further information on the processing of your data by Sovendus, please refer to the online privacy notice at https://web.sovendus.com/legal#privacy-policy

8. Social Media

Our online presence on Facebook (by Meta), X (formerly Twitter), Instagram (by Meta), Youtube, LinkedIn, Xing

If you have given your consent to the respective social media provider in accordance with Art. 6 (1) (a) GDPR, when you visit our online presence on the social media mentioned above, your data will be automatically collected and stored for market research and advertising purposes, from which user profiles are created using pseudonyms. These can be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. Cookies are usually used for this purpose. For detailed information on the processing and use of data by the respective social media provider, as well as a contact option and your rights and settings options for the protection of your privacy, please refer to the provider's privacy policies linked below. Should you still require assistance in this regard, please contact us.


Facebook (by Meta) is provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (hereafter "Meta Platforms Ireland ") The information automatically collected by Meta Platforms Ireland about your use of our online presence on Facebook (by Meta) is usually transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. Data processing in the context of a visit to a Facebook (by Meta) fan page is based on an agreement between joint controllers in accordance with Art. 26 GDPR. Further information (information on Insights data) can be found here. Our service providers are located and/or use servers in the following countries, for which a UK adequacy regulation identifies an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, Argentina. The adequacy decision for the USA applies as the basis for third country transfers, provided that the respective service provider is certified. Certification is available. Our service providers are located and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. There is no UK adequacy regulation for these countries. Our cooperation with them is based on these safeguards: standard data protection clauses of the European Commission, appended by the UK Addendum.


X is provided by Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland ("X"). The information automatically collected by X about your use of our online presence on X is generally transmitted to and stored on a server at X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Our service providers are located and/or use servers in countries outside the UK, EU and the EEA for which an adequate level of data protection has been identified by means of the UK adequacy regulation. Our service providers are located and/or use servers in countries outside the UK, the EU and the EEA. For these countries, there is no UK adequacy regulation. Our cooperation is based on standard data protection clauses of the European Commission, appended by the UK Addendum.


Instagram (by Meta) is provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (hereafter "Meta Platforms Ireland ") The information automatically collected by Meta Platforms Ireland about your use of our online presence on Instagram is typically transferred to and stored on a server at Meta Platforms Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Data processing in the context of a visit to an Instagram (by Meta) fan page is based on an agreement between joint controllers in accordance with art. 26 GDPR. Further information (information on Insights data) can be found here. Our service providers are located and/or use servers in the following countries, for which a UK adequacy regulation identifies an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, Argentina. The adequacy decision for the USA applies as the basis for third country transfers, provided that the respective service provider is certified. Certification is available. Our service providers are located and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. There is no UK adequacy regulation for these countries. Our cooperation with them is based on these safeguards: standard data protection clauses of the European Commission, appended by the UK Addendum.


YouTube is provided by Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland (hereafter "Google"). The information automatically collected by Google about your use of our online presence on YouTube is generally transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. Our service providers are located and/or use servers in countries outside the UK, EU and the EEA for which an adequate level of data protection has been identified by means of the UK adequacy regulation. Our service providers are located and/or use servers in countries outside the UK, the EU and the EEA. For these countries, there is no UK adequacy regulation. Our cooperation is based on standard data protection clauses of the European Commission, appended by the UK Addendum.


LinkedIn is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland ("LinkedIn"). The information LinkedIn automatically collects about your use of our online presence on LinkedIn is generally sent to a server at LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA and stored there. Our service providers are located and/or use servers in the following countries, for which a UK adequacy regulation identifies an adequate level of data protection: USA. The adequacy decision for the USA applies as the basis for third country transfers, provided that the respective service provider is certified. Certification is available.


Xing is provided by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.


Our service providers are located and/or use servers in countries outside the UK, EU and the EEA for which an adequate level of data protection has been identified by means of the UK adequacy regulation.

Our service providers are located and/or use servers in countries outside the UK, the EU and the EEA. For these countries, there is no UK adequacy regulation. Our cooperation is based on standard data protection clauses of the European Commission, appended by the UK Addendum.

9. Contact options and your rights

9.1 Your rights

Being the data subject, you have the following rights according to:

art. 15 GDPR, the right to obtain information about your personal data which we process, within the scope described therein;

art. 16 GDPR, the right to immediately demand rectification of incorrect or completion of your personal data stored by us;

art. 17 GDPR, the right to request erasure of your personal data stored with us, unless further processing is required to exercise the right of freedom of expression and information; for compliance with a legal obligation; for reasons of public interest or for establishing, exercising or defending legal claims;

art. 18 GDPR, the right to request restriction of processing of your personal data, insofar as the accuracy of the data is contested by you; the processing is unlawful, but you refuse their erasure; we no longer need the data, but you need it to establish, exercise or defend legal claims, or you have lodged an objection to the processing in accordance with art. 21 GDPR;

art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;

art. 77 GDPR, the right to complain to a supervisory authority . As a rule, you can contact the supervisory authority at your habitual place of residence or workplace or at our company headquarters.


Right to object

If we process personal data as described above to protect our legitimate interests that are overriding in the process of balancing of interests, you may object to such data processing with future effect. If your data are processed for direct marketing purposes, you may exercise this right at any time as described above. If your data are processed for other purposes, you have the right to object only on grounds relating to your particular situation.

After you have exercised your right to object, we will no longer process your personal data for such purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.

This does not apply to the processing of personal data for direct marketing purposes. In such a case we will no longer process your personal data for such purposes.

9.2 Contact options

If you have any questions about how we collect, process or use your personal data, want to enquire about, correct, restrict or delete your data, or withdraw any consents you have given, or opt-out of any particular data use, please contact our in-house data protection officer:

datenschutz@devolo.de