Personal data (hereinafter referred to as “data”) will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered there.
According to Article 4(1) of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as “GDPR”), “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
With the following privacy policy, we inform you in particular about the type, scope, purpose, duration and legal basis of the processing of personal data, insofar as we decide either alone or together with others on the purposes and means of processing. In addition, we inform you below about the third-party components we use for optimization purposes and to increase the quality of use, insofar as third parties process data on their own responsibility.
Our privacy policy is structured as follows
I. Information about us as the controller
II. rights of users and data subjects
III. Information on data processing
EnergieKaufhaus AG
Mühlenstr. 8a
14167 Berlin
Berlin, Germany
Phone: +49 (0) 30 22 39 08 99
E-mail: anfrage@energiekaufhaus.com
is the data protection officer of the provider:
Less than 10 employees are involved in the processing of automated personal data.
Regarding the data processing described in more detail below, users and data subjects have the right:
Furthermore, the provider is obligated to inform all recipients to whom data has been disclosed about any correction or deletion of data or any restriction of processing that takes place in accordance with Articles 16, 17 para. 1, and 18 GDPR. However, this obligation does not apply if such notification is impossible or would involve disproportionate effort. Notwithstanding this, the user has the right to information about these recipients.
Additionally, under Article 21 GDPR, users and data subjects have the right to object to the future processing of data concerning them, provided the data is processed by the provider according to Article 6 para. 1 lit. f) GDPR. In particular, objection to data processing for direct marketing purposes is permissible.
Serverdata
For technical reasons, particularly to ensure a secure and stable website, data is transmitted from your internet browser to us or to our webspace provider. These so-called server log files collect, among other things, the type and version of your internet browser, the operating system, the website from which you accessed our website (referrer URL), the pages of our website that you visit, the date and time of each access, as well as the IP address of the internet connection used to access our website.
The data collected in this way is temporarily stored but is not combined with any other data about you.
This storage is based on Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.
The data is deleted no later than seven days after collection, unless further retention is required for evidentiary purposes. In such cases, the data will be excluded from deletion, either wholly or partially, until the incident is fully resolved.
Cookies
a) Session Cookies
Our website uses cookies, which are small text files or other storage technologies placed and stored on your device by the internet browser you use. These cookies process certain information from you, such as your browser or location data or your IP address, to a limited extent.
This processing makes our website more user-friendly, effective, and secure, as it enables functionalities such as displaying our website in different languages or providing a shopping cart function.
The legal basis for this processing is Article 6 para. 1 lit. b) GDPR, provided that these cookies process data for initiating or fulfilling a contract.
If the processing does not serve to initiate or fulfill a contract, our legitimate interest lies in improving the functionality of our website. In this case, the legal basis is Article 6 para. 1 lit. f) GDPR.
These session cookies are deleted when you close your internet browser.
b) Third-Party Cookies
Our website may also use cookies from partner companies with whom we collaborate for advertising, analytics, or website functionality purposes.
For specific details, particularly regarding the purposes and legal bases for processing such third-party cookies, please refer to the information provided below.
c) Options for Disabling Cookies
You can prevent or restrict the installation of cookies by adjusting the settings of your internet browser. You can also delete cookies that have already been stored at any time. The necessary steps and measures depend on the specific internet browser you use. For questions, please refer to the help function or documentation of your browser or contact the browser’s manufacturer or support team.
Note that the processing of Flash cookies cannot be disabled through your browser settings. Instead, you will need to adjust the settings of your Flash player. The necessary steps and measures depend on the specific Flash player you are using. For questions, please consult the help function or documentation of your Flash player or contact the manufacturer or user support.
Please be aware that preventing or restricting the installation of cookies may result in some features of our website being unusable in full.
Contract Fulfillment
The data you provide to use our goods and/or services is processed by us for the purpose of contract fulfillment and is necessary for this purpose. Without your data, contract formation and fulfillment are not possible.
The legal basis for this processing is Article 6 para. 1 lit. b) GDPR.
We delete the data once the contract has been fully processed, though we must comply with tax and commercial law retention periods.
As part of contract fulfillment, we share your data with the transport company responsible for delivering the goods or with the financial service provider, as necessary for delivery or payment purposes.
The legal basis for sharing the data in this case is also Article 6 para. 1 lit. b) GDPR.
Customer Account / Registration Function
If you create a customer account on our website, we will collect and store the data you provide during registration (e.g., your name, address, or email address) exclusively for pre-contractual services, contract fulfillment, or customer care purposes (e.g., to provide you with an overview of your previous orders or to offer you a "wishlist" feature). At the same time, we will store your IP address, the date of registration, and the time. These data will not be shared with third parties.
During the further registration process, your consent for this processing will be obtained, and you will be referred to this privacy policy. The data collected by us will only be used for the provision of the customer account.
If you consent to this processing, the legal basis for the processing is Article 6 para. 1 lit. a) GDPR.
If the creation of the customer account also serves pre-contractual measures or contract fulfillment, the legal basis for this processing is also Article 6 para. 1 lit. b) GDPR.
You can withdraw your consent for the creation and maintenance of the customer account at any time with effect for the future, in accordance with Article 7 para. 3 GDPR. To do so, you only need to inform us of your withdrawal.
The data collected in this context will be deleted as soon as the processing is no longer required. However, we must observe tax and commercial law retention periods.
Contact Inquiries / Contact Options
If you contact us via the contact form or email, the data you provide will be used to process your inquiry. Providing this data is necessary to process and respond to your request – without this information, we may not be able to respond or can only respond in a limited manner.
The legal basis for this processing is Article 6 para. 1 lit. b) GDPR.
Your data will be deleted once your inquiry has been fully addressed, unless legal retention obligations prevent deletion, such as in the case of a subsequent contract fulfillment.
Google Analytics
On our website, we use Google Analytics, which is a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as "Google").
Through certification under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active), Google guarantees that the data protection requirements of the EU are also adhered to when processing data in the USA.
Google Analytics is used to analyze the usage behavior of visitors on our website. The legal basis for this processing is Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in analyzing, optimizing, and operating our website efficiently.
Usage and user-related information, such as IP address, location, time, or frequency of visits to our website, are transferred to a server of Google in the USA and stored there. However, we use Google Analytics with the so-called anonymization feature. This function shortens the IP address within the EU or the European Economic Area (EEA).
The data collected in this way is then used by Google to provide us with reports on visits to our website and user activities on the site. These data may also be used to provide further services related to the use of our website and the internet.
Google states that it does not combine your IP address with other data. Additionally, Google provides more information about privacy and data usage at [Google Privacy Policy](https://www.google.com/intl/de/policies/privacy/partners) and explains how to opt-out from data usage.
Furthermore, Google offers a so-called deactivation add-on at [Google Analytics Opt-out](https://tools.google.com/dlpage/gaoptout?hl=de) along with further details. This add-on can be installed on common internet browsers and provides you with additional control over the data that Google collects when visiting our website. The add-on informs Google Analytics' JavaScript (ga.js) that no information about your visit should be sent to Google Analytics. However, this does not prevent information from being sent to us or other web analytics services. You will also find information about any other web analytics services we may use in this privacy policy.
„Google+“-Social-Plug-in
On our website, we use the plug-in of the social network Google+ ("Google Plus"). Google+ is an internet service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (hereinafter referred to as "Google").
Through certification under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active), Google guarantees that the data protection requirements of the EU are also adhered to when processing data in the USA.
The legal basis for processing is Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website.
Further information about the available plug-ins and their respective functions is provided by Google at [Google+ Developer Information](https://developers.google.com/+/web/).
If the plug-in is embedded on one of the pages you visit on our website, your internet browser will download a representation of the plug-in from Google's servers in the USA. For technical reasons, Google must process your IP address. In addition, the date and time of your visit to our website are also recorded.
If you are logged into Google while visiting one of our pages with the plug-in, Google will recognize the information gathered by the plug-in about your specific visit. This information may be associated with your personal user account on Google. For example, if you use the "Share" button on Google, this information will be stored in your Google user account and potentially published on Google's platform. If you do not wish this, you must either log out of Google before visiting our website or adjust the relevant settings in your Google user account.
For further information about the collection and use of data, as well as your rights and protection options, Google provides privacy notices, which are available at [Google Privacy Policy](https://policies.google.com/privacy).
Google-Maps
On our website, we use Google Maps to display our location and provide directions. This service is provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA (hereinafter referred to as "Google").
Through certification under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active), Google guarantees that the data protection requirements of the EU are also adhered to when processing data in the USA.
To enable the display of specific fonts on our website, a connection to Google's servers in the USA is established when our website is accessed.
When you use the Google Maps component embedded in our website, Google will store a cookie on your device via your internet browser. To display our location and provide directions, your user settings and data are processed. We cannot exclude the possibility that Google may use servers in the USA.
The legal basis for this processing is Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in optimizing the functionality of our website.
By establishing this connection to Google, Google can determine which website your request was sent from and which IP address the directions should be transmitted to.
If you do not agree with this processing, you have the option to prevent the installation of cookies by adjusting the settings in your internet browser. For details on this, please refer to the section "Cookies" above.
Furthermore, the use of Google Maps and the information obtained via Google Maps are subject to Google's terms of service [Google Terms of Service](https://policies.google.com/terms?gl=DE&hl=de) and the [Google Maps Terms](https://www.google.com/intl/de_de/help/terms_maps.html).
Additionally, Google provides further information at the following links:
- [Google Ads Settings](https://adssettings.google.com/authenticated)
- [Google Privacy Policy](https://policies.google.com/privacy).
„Facebook“-Social-Plug-in
On our website, we use the plugin of the social network Facebook. Facebook is an internet service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. In the EU, this service is operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, hereinafter both referred to as "Facebook."
Through certification under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active), Facebook guarantees that the data protection requirements of the EU are also adhered to when processing data in the USA.
The legal basis for this processing is Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website.
For further information about the available plugins and their respective functions, Facebook provides information at the following link:
[Facebook Developers Plugins](https://developers.facebook.com/docs/plugins/)
If the plugin is embedded on one of the pages you visit on our website, your internet browser will download a representation of the plugin from Facebook's servers in the USA. For technical reasons, it is necessary for Facebook to process your IP address. Additionally, the date and time of your visit to our website are also recorded.
If you are logged into Facebook while visiting one of our pages with the plugin, Facebook will recognize the information gathered by the plugin about your specific visit. The collected information may be associated with your personal Facebook account. For example, if you use the "Like" button on Facebook, this information will be saved in your Facebook account and possibly published on the Facebook platform. If you wish to prevent this, you must either log out of Facebook before visiting our website or use an add-on for your browser that blocks the loading of the Facebook plugin.
For further information on the collection and use of data, as well as your related rights and protective measures, Facebook provides details in its privacy policy, which can be accessed at:
[Facebook Privacy Policy](https://www.facebook.com/policy.php).
„Twitter“-Social-Plug-in
On our website, we use the plugin of the social network Twitter. Twitter is an internet service provided by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA, hereinafter referred to as "Twitter."
Through certification under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active), Twitter guarantees that the data protection requirements of the EU are also adhered to when processing data in the USA.
The legal basis for this processing is Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website.
If the plugin is embedded on one of the pages you visit on our website, your internet browser will download a representation of the plugin from Twitter's servers in the USA. For technical reasons, it is necessary for Twitter to process your IP address. Additionally, the date and time of your visit to our website are also recorded.
If you are logged into Twitter while visiting one of our pages with the plugin, Twitter will recognize the information gathered by the plugin about your specific visit. The collected information may be associated with your personal Twitter account. For example, if you use the "Share" button on Twitter, this information will be saved in your Twitter account and possibly published on the Twitter platform. If you wish to prevent this, you must either log out of Twitter before visiting our website or adjust the corresponding settings in your Twitter account.
For further information on the collection and use of data, as well as your related rights and protective measures, Twitter provides details in its privacy policy, which can be accessed at:
[Twitter Privacy Policy](https://twitter.com/privacy).
Google AdWords with Conversion-Tracking
On our website, we use the advertising component Google AdWords, specifically the so-called Conversion Tracking. This service is provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google."
Through certification under the EU-US Privacy Shield (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active), Google guarantees that the data protection requirements of the EU are also adhered to when processing data in the USA.
We use Conversion Tracking for targeted advertising of our services. The legal basis for this processing is Article 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis, optimization, and economic operation of our website.
If you click on an advertisement placed by Google, the Conversion Tracking tool we use will store a cookie on your device. These "conversion cookies" are valid for 30 days and are not used for personal identification.
If the cookie is still valid and you visit a specific page on our website, both we and Google can analyze that you clicked on one of our advertisements on Google and were subsequently directed to our website.
From the information collected, Google generates a statistic about the visits to our website. We receive information about the number of users who clicked on our advertisement(s) and the pages they subsequently visited on our site. Neither we nor third parties who also use Google AdWords are able to identify you through this process.
You can prevent or limit the installation of cookies by adjusting the settings of your internet browser. You can also delete cookies that have already been stored at any time. However, the steps required depend on the browser you use. If you have questions, please refer to the help function or documentation of your browser or contact its manufacturer or support.
Additionally, Google offers further information on this subject, including options to prevent data usage, on the following pages:
- [Google Services Statistics](https://services.google.com/sitestats/de.html)
- [Google Ads Policies](http://www.google.com/policies/technologies/ads/)
- [Google Privacy Policy](http://www.google.de/policies/privacy/)
affilinet-Tracking-Cookies
On our website, we also promote third-party offers and services. If you enter into a contract with a third-party provider as a result of our advertisement, we receive a commission for this.
To correctly track successful referrals, we use the so-called **affilinet tracking cookie**. However, this cookie does not store any of your personal data. It merely records our identification number as the referring provider and the order number of the advertisement you clicked on (such as a banner or a text link). We require this information for the purpose of processing payments or distributing our commissions.
If you do not agree with this processing, you have the option to prevent the storage of cookies by adjusting the settings in your internet browser. For more information, please refer to the section on "Cookies" above.
Online Job Applications / Publication of Job Advertisements
We offer you the possibility to apply digitally via our website. In the context of these digital applications, your applicant and application data will be collected and processed electronically by us for the purpose of processing the application procedure.
Legal basis for this processing: § 26 para. 1 sentence 1 BDSG in conjunction with Art. 88 para. 1 GDPR.
If an employment contract is concluded after the application process, we will store the data you provided in your application in your personnel file for the usual organizational and administrative process – of course, in compliance with further legal obligations.
Legal basis for this processing: Also § 26 para. 1 sentence 1 BDSG in conjunction with Art. 88 para. 1 GDPR.
In the case of a rejection, we will automatically delete the data you provided two months after the rejection has been communicated. However, the deletion will not take place if the data needs to be stored for a longer period due to legal requirements, e.g., due to evidence obligations under the General Equal Treatment Act (AGG), for up to four months or until the conclusion of a legal process.
Legal basis in this case: Art. 6 para. 1 lit. f) GDPR and § 24 para. 1 no. 2 BDSG. Our legitimate interest lies in the defense or enforcement of legal claims.
If you explicitly consent to a longer storage of your data, e.g., for inclusion in a database of applicants or interested parties, the data will be further processed based on your consent. The legal basis is then Art. 6 para. 1 lit. a) GDPR. However, you can revoke your consent at any time pursuant to Art. 7 para. 3 GDPR by notifying us, with effect for the future.