Privacy policy
Information on Data Processing for this Website pursuant to Art. 13 GDPR when collecting personal data from the data subject
Privacy Notice (Version: GDPR 2.0 of 01/10/2021)
Töpfer GmbH is the controller for this website and, as a provider of telemedia services, must inform you at the start of your visit—clearly, transparently, and in simple language—about the type, scope, and purposes of collecting and using personal data. This information must be available to you at all times.
We place the highest value on the security of your data and compliance with data protection regulations. The processing of personal data is subject to the provisions of currently applicable European and national laws.
Below, we explain how we handle your personal data and how you can contact us:
Töpfer GmbH
Heisinger Straße 6
D-87463 Dietmannsried
Commercial Register No.: 441
Managing Director: Ulf Silbernagel
Phone: +49 8374 934-0
Email: info@toepfer-babywelt.de
Our Data Protection Officer
IKO Industrie-Kontor GmbH
Matthias Dickmann, Data Protection Officer
Phone: +49 4131 7899 559
Mobile: +49 162 8936 320
For questions on data protection, please email: dickmann@industrie-kontor.de
A. General
For better readability, we do not differentiate by gender. Corresponding terms apply equally to all genders. Definitions of terms used (e.g., “personal data” or “processing”) can be found in Art. 4 GDPR.
Personal data processed on this website include:
- Inventory data (e.g., names and addresses of customers)
- Contract data (e.g., services used, payment information)
- Usage data (e.g., pages visited on our website)
- Content data (e.g., entries in online forms)
B. Specific
Privacy Notice
We ensure that we process your data only in connection with handling your inquiries, for internal purposes, and to provide services or content you request.
Legal Bases for Processing
We process your personal data only in compliance with applicable data protection law. The relevant legal bases are:
- Performance of our services and contractual measuresArt. 6(1)(b) GDPR
- Compliance with our legal obligationsArt. 6(1)(c) GDPR
- ConsentArt. 6(1)(a) and Art. 7 GDPR
- Legitimate interestsArt. 6(1)(f) GDPR
Disclosure of Data to Third Parties
Please note that data is transferred to third parties.
We only disclose your data within the scope of legal provisions—for example, when required for contractual purposes, or on the basis of our legitimate interest in the efficient operation of our business.
Where we engage subprocessors to provide our services, we take appropriate legal, technical, and organizational measures to ensure the protection of personal data in accordance with statutory requirements.
Data Transfers to Third Countries or International Organizations
“Third countries” are countries where the GDPR does not apply directly—generally all countries outside the EU/EEA.
Data transfers to a third country or an international organization do occur.
Because we use various Google services, YouTube, and Facebook Pixel on our website, data may be transferred to the USA, provided you have given consent under Art. 49(1)(a) GDPR. Under current law, the USA is deemed to have an inadequate level of data protection. There is a risk that your data may be processed by US authorities for monitoring and surveillance purposes. There are currently no legal remedies against this practice.
To withdraw consent, disable these services in the “cookie consent tool” provided on the website or via the option in this privacy notice.
Storage Period
We adhere to the principles of data minimization and storage limitation. We store your data only as long as necessary to fulfill the aforementioned purposes or as required by statutory retention periods. Once the purpose ceases to apply or the retention period expires, your data will be routinely blocked or deleted in accordance with legal requirements.
Contacting Us
If you contact us via the website, you consent to electronic communication. Personal data will be processed in this context. The information you provide will be stored solely for the purpose of processing your inquiry and for possible follow-up questions.
Legal basis:
Performance of our services and contractual measures, Art. 6(1)(b) GDPR.
Please note that emails can be read or altered unlawfully and without detection during transmission. We also use spam filters; emails may be rejected if incorrectly identified as spam.
Your Rights
a) Right of access
You have the right to obtain free information about your stored data. On request, we will inform you in writing which personal data we have stored about you, including origin, recipients, and the purpose of processing.
b) Right to rectification
You may have inaccurate data corrected. You can also request restriction of processing, e.g., if you contest the accuracy of your data.
c) Right to restriction (blocking)
You may have your data restricted. To ensure your restriction request is honored at any time, your data must be kept in a blocking file for control purposes.
d) Right to erasure
You may request deletion of your personal data insofar as no statutory retention obligations exist. Where such obligations exist, we will restrict your data on request. If the legal conditions are met, we will delete your personal data even without your request.
e) Right to data portability
You may request provision of the personal data you have provided to us in a format that permits transfer to another controller.
f) Right to lodge a complaint with a supervisory authority
You may lodge a complaint with any data protection supervisory authority.
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, 91522 Ansbach, Germany
Phone: +49 981 53-1300 | Fax: +49 981 53-981300
Complaint form: https://www.lda.bayern.de/de/beschwerde.html
Note: You may also lodge a complaint with any supervisory authority within the EU.
g) Right to object
You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions.
Töpfer GmbH will then no longer process your personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
If personal data are processed for direct marketing, you have the right to object at any time to such processing, including profiling related to direct marketing. In that case, we will no longer process your data for direct marketing. To object, simply send us an email.
h) Right to withdraw consent
You may withdraw your consent at any time with effect for the future without stating reasons, without any disadvantages to you. To do so, simply email us.
Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal (Art. 6(1)(a) GDPR).
To exercise your rights, email: datenschutz@toepfer-gmbh.de
Protection of Your Personal Data
We implement contractual, technical, and organizational security measures according to the state of the art to ensure compliance with data protection laws and to protect data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons.
Security measures include encrypted transmission of data between your browser and our server:
- https://www.toepfer-babywelt.de uses 128-bit SSL (AES 128)
- https://jobs.toepfer-babywelt.de uses 256-bit SSL (AES 256)
Your personal data is protected in particular as follows (examples):
a) Confidentiality – access, entry, and access control measures
b) Integrity – transfer and input control measures
c) Availability – order and availability control measures
We continually improve security measures in line with technological developments. However, due to the nature of the internet, we cannot guarantee the security of data transmission to our website; any transmission is at your own risk.
Protection of Minors
Persons under 16 years of age may provide us with personal information only with the express consent of their legal guardians. Such data will be processed in accordance with this privacy notice.
Server Log Files
The provider automatically collects and stores information in server log files transmitted by your browser:
- Domain
- IP address
- Requests
- User agent
- Time of server request
- Status code
These data are not merged with other data sources.
Legal basis: Our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Online Applications via Form
Applicants can apply online via a form. Participation requires that applicants provide all personal data necessary for an informed assessment and selection.
Required information includes general personal details (name, address, phone/email) and evidence of qualifications. Health-related information may be required for social protection considerations.
Data are transmitted encrypted and processed solely for application handling.
Legal basis: Art. 6(1)(b) GDPR in conjunction with § 26(1) BDSG (initiation of employment).
If special categories of personal data (Art. 9(1) GDPR) are processed (e.g., disability status), processing is based on Art. 9(2)(b) GDPR(employment/social security obligations) or Art. 9(2)(h) GDPR(occupational health/assessment of working capacity).
If no offer is made or an application is withdrawn, data will be deleted no later than six months after notification, based on our legitimate interest in follow-up and compliance with equal treatment obligations. In case of a successful application, data will be further processed for employment purposes (Art. 6(1)(b) GDPR, § 26(1) BDSG).
Cookies
Cookies are small text files stored in your browser’s cache. They enable, for example, recognizing the browser, navigating the site, and using all functions.
CookieBot
We use the cookie consent tool from Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark (“CookieBot”), which sets technically necessary cookies to store your preferences.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing consent management).
Google Analytics
With your consent, we use Google Analytics (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; “Google”). Cookies collect information usually transferred to and stored on Google servers in the USA.
We use IP anonymization (anonymizeIP) so your IP is shortened within the EU/EEA; only in exceptional cases is the full IP sent to the USA and then shortened. The IP address transmitted by your browser is not merged with other Google data.
Data collected during your visit include: pages viewed/click path, goal completions (conversions), user behavior (clicks, time on site, bounce rate), approximate region, truncated IP, technical info (language, screen resolution), ISP, referrer URL.
Google uses this information to evaluate (pseudonymous) usage and compile reports. Recipients: Google Ireland Limited; Google LLC (USA) and US authorities may access data. Transfers to the USA cannot be excluded. Google processes data for its own purposes; there is joint responsibility under Art. 26 GDPR, but Google does not offer such an agreement.
Data linked to cookies are automatically deleted after 14 months. You can prevent collection by:
a) not giving consent, or
b) installing the browser add-on to disable Analytics.
You can also block cookies in your browser (may limit site functionality).
Legal basis: Consent, Art. 6(1)(a) GDPR. You can withdraw consent at any time via the cookie settings.
Because of Google Analytics, data may be transferred to the USA with your consent under Art. 49(1)(a) GDPR. Risks as noted above apply.
Further info:
https://www.google.com/analytics/terms/ and https://policies.google.com/
Facebook Pixel (Custom Audiences)
We use the Facebook Pixel (Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). If you click a Facebook ad linking to our site, a URL parameter is appended and stored via a cookie if our site permits sharing data with Facebook. Facebook reads this cookie and receives the data.
Processing occurs only with your explicit consent (Art. 6(1)(a) GDPR), which you can withdraw anytime via the cookie tool (“Facebook Pixel”).
Because of Facebook Pixel, data may be transferred to the USA with your consent under Art. 49(1)(a) GDPR. Risks as noted above apply.
The Pixel helps define target groups for Facebook ads (“Custom Audiences”), assess ad effectiveness (“conversion”), and avoid irrelevant ads. The data are anonymous to us, but Facebook may link them to user profiles and use them per its policy: https://www.facebook.com/about/privacy/
Google Ads Conversion Tracking
We use Google Ads and Conversion Tracking (Google Ireland Limited). A cookie is set when a user clicks our ad; it typically expires after 30 days and does not personally identify users. The cookie helps compile conversion statistics.
Legal basis: Consent, Art. 6(1)(a) GDPR. You may withdraw consent at any time via the cookie tool or by using Google’s opt-out options. Transfers to the USA may occur with your consent under Art. 49(1)(a) GDPR.
Further info: https://www.google.de/policies/privacy/
Opt-out plugin: https://www.google.com/settings/ads/plugin?hl=de
Google reCAPTCHA
We use Google reCAPTCHA (Google Ireland Limited) to distinguish human input from automated misuse. Personal data may be transferred to Google LLC in the USA.
Legal basis: Consent, Art. 6(1)(a) GDPR. You can withdraw consent via the cookie tool. Transfers to the USA may occur with your consent under Art. 49(1)(a) GDPR.
Info: https://www.google.com/intl/de/policies/privacy/
YouTube Videos
We use YouTube embedding (Google Ireland Limited). Legal basis:Consent, Art. 6(1)(a) GDPR. Transfers to the USAmay occur with your consent under Art. 49(1)(a) GDPR. You may withdraw consent at any time via the cookie tool or the privacy settings.
If you are logged in to Google, your data may be associated with your account when you play a video. Log out to avoid association. Google creates usage profiles for analysis/optimization; you can object via YouTube. Visiting a page with embedded videos may initiate further processing by Google.
Privacy: https://www.google.de/intl/de/policies/privacy
Adform (Adform Germany GmbH)
We use Adform retargeting (Adform Germany GmbH, Großer Burstah 50-52, 20457 Hamburg). Cookies store pseudonymized interest data to display personalized ads. No personal data is stored.
You can generally disable cookies in your browser or set an Adform opt-out cookie: https://site.adform.com/datenschutz-opt-out/
Legal basis: Consent, Art. 6(1)(a) GDPR. You may withdraw consent via the cookie tool or by using the opt-out described above.
Google Web Fonts
For consistent font display, we use Google Web Fonts (Google Ireland Limited). Your browser connects to Google servers; personal data may be transferred to Google LLC in the USA. Legal basis: Consent, Art. 6(1)(a) GDPR. You may withdraw consent via the cookie tool. If your browser does not support Web Fonts, a standard font is used.
Info: https://developers.google.com/fonts/faq and https://www.google.com/policies/privacy/
Newsletter
If you subscribe to our email newsletter, we regularly send information about our offers. We collect personal data for this purpose. The only mandatory field is your email address; additional data is optional and used to address you personally. We use these data for our own advertising via email, provided you have expressly consented (“Subscribe to newsletter”).
We use a double opt-in: you will receive a confirmation email and must click the link to activate your subscription.
By activating the confirmation link, you consent to processing under Art. 6(1)(a) GDPR. We store your IP address and the date/time of subscription to track possible misuse.
You can unsubscribe at any time via the link in the newsletter or by emailing socialmedia@toepfer-babywelt.de. After unsubscribing, your email address is promptly deleted from the distribution list and placed on a blocklist to enforce your withdrawal.
Newsletter Tracking
If you have expressly consented, we use tracking (web beacons/tracking pixels). The external server can capture time of access, IP address, and client information. A unique ID allows us to determine that a newsletter has been opened.
We record user behavior pseudonymously, including: recipients (minus bounces), queued/skipped, unique unsubscribe rate, bounces (hard/soft), unique open rate/opens, click rate/clicks, effective unique click rate, and clicks for segmentation.
Newsletter Delivery via BREVO (Sendinblue GmbH)
We send newsletters via Brevo (Sendinblue GmbH), Köpenicker Str. 126, 10179 Berlin. We transfer your data to Brevo for this purpose under Art. 6(1)(f) GDPR (legitimate interest in a secure, user-friendly system). Data are stored on EU servers.
Brevo uses web beacons/tracking pixels for statistics. Data are collected pseudonymously and are not linked to your other personal data. If you object to statistical analysis, please unsubscribe.
Brevo may use data for legitimate interests (service optimization/market research), but does not contact our recipients or pass data to third parties. We have a data processing agreement with Brevo.
Brevo privacy info: Datenschutz-Übersicht: Alles was du wissen musst! | Brevo
Registration in the Midwives’ Forum
You can register on our website by providing personal data (as per the form). We use double opt-in; if not confirmed within 24 hours, the registration is deleted. The aforementioned details are mandatory; additional data may be provided voluntarily.
If you use the portal, we store the data required to perform the contract (including payment details if applicable) until you permanently delete your account. Voluntary data are stored for the duration of portal use unless you delete them. You can manage all details in the protected customer area. Legal basis: Art. 6(1)(f) GDPR.
We also store all content you publish (e.g., public posts) to operate the website—our legitimate interest (Art. 6(1)(f) GDPR). If you delete your account, public statements (especially in the forum) remain visible, but your account is no longer accessible. All other data are deleted.
Disclosure of Personal Data for Order Processing
We transfer personal data to the shipping company to deliver goods, and payment data to the payment institution to process payments, where necessary for contract performance.
Changes to this Privacy Notice
We reserve the right to update this privacy notice at short notice to reflect legal requirements or changes to our services (e.g., introduction of new services). The updated notice applies on your next visit.
Surveys
Surveys with umfrageonline.com
We use Umfrageonline.com by enuvo GmbH, Huobstrasse 10, CH-8808 Pfäffikon SZ (“Umfrageonline”) to design and analyze surveys and online forms. In addition to the personal data you enter, further information may be collected, transmitted to, and stored on Umfrageonline’s servers.
Legal basis: Consent, Art. 6(1)(a) GDPR.
We have a data processing agreement with Umfrageonline.
Umfrageonline privacy policy: https://www.umfrageonline.com/datenschutz
Our information obligations for surveys: https://www.toepfer-babywelt.de/datenschutz-umfragen