1. General

1.1 What is personal data

Personal data is information that discloses or can disclose the identity of the user. We adhere to the principle of data avoidance. As far as possible, we refrain from collecting personal data.

1.2 Handling of personal data

Personal data is used exclusively for the purpose of establishing the contract, defining its content, implementing or processing the contractual relationship (Art. 6 I 1 b GDPR).

In addition, personal data will only be processed if we have received your consent to do so (Art. 6 I 1 a GDPR) or if the processing of the data is necessary for our legitimate interests and if the assessment shows that there are no overriding interests, fundamental rights or freedoms on your part (Art. 6 I 1 f GDPR).

We may use processors to process your personal data, with whom we have concluded an order processing agreement if necessary, but will not pass on the personal data to third parties beyond this as a matter of principle.

Processing of payments, the payment data required for this will be passed on to the credit institution commissioned with the payment and, if applicable, to the commissioned and selected payment service provider.

The processing of your personal data takes place in the EU and in countries classified by the EU as safe or appropriate. If the processing of personal data takes place in the USA, we try to ensure that the services we use are certified under the “Data Privacy Framework”.

1.3 Usage data

When visiting the website, general technical information is collected. This is the IP address used, time, duration of the visit, browser type and, if applicable, the page of origin. This usage data is registered in a log file for technical reasons and can be used and stored for statistical evaluation of this website. This usage data is not linked to your other personal data.

1.4 Registration data

Registration is required for the extensive use of the functions of our website. The registration data is collected through your corresponding entries and used for the expressly stated purpose by your consent (Art. 6 I 1 a GDPR).

1.5 Duration of storage

We store your personal data after the termination of the purpose for which the data was collected only as long as required by law (especially tax law).

2. Your rights

2.1 Information

You can request information from us as to whether we process personal data about you and, if this is the case, you have a right to information about this personal data and the further information mentioned in Art. 15 GDPR.

2.2 Right to rectification

You have the right to rectification of inaccurate personal data concerning you and may request the completion of incomplete personal data in accordance with Art. 16 GDPR.

2.3 Right to erasure

You have the right to demand that we delete the personal data concerning you without undue delay. We are obliged to delete them without delay, in particular, if one of the following reasons applies:

  • Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
  • You revoke your consent on which the processing of your data was based, and there is no other legal basis for the processing.
  • Your data has been processed unlawfully.

The right to erasure does not exist insofar as your personal data is necessary for the assertion, exercise or defense of our legal claims.

2.4 Right to restriction of processing

You have the right to request us to restrict the processing of your personal data if

  • you dispute the accuracy of the data, and we, therefore, verify the accuracy,
  • the processing is unlawful, and you refuse the deletion and demand the restriction of use instead,
  • we no longer need the data, but you need it to assert, exercise or defend legal claims,
  • you have objected to the processing of your data, and it has not yet been determined whether our legitimate reasons outweigh your reasons.

2.5 Right to data portability

You have the right to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format, and you have the right to transfer this data to another controller without hindrance from us, provided that the processing is based on consent or a contract and the processing is carried out by us with the help of automated processes.

2.6 Right of revocation and objection

If your personal data is processed based on consent (Art. 6 sentence 1 a GDPR), you have the right to withdraw this consent at any time. This right does not affect the lawfulness of the process based on the consent until revocation.

Insofar as the processing of your personal data is based on Art. 6 sentence 1 e GDPR or Art. 6 sentence 1 f GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation in accordance with Art. 21 GDPR. We will no longer process your personal data unless we can demonstrate compelling, legitimate grounds for the processing that override your interests, rights and freedoms or the processing serves the establishment, exercise or defense of legal claims.

2.7 General and right of appeal

The exercise of your above rights is generally free of charge for you. In the event of complaints, you have the right to contact the supervisory authority responsible for us, the State Data Protection Officer, directly.

3. Data security

3.1 Data security

All data on our website is secured by technical and organizational measures against loss, destruction, access, modification and distribution.

3.2 Sessions and cookies

To operate the website, we use cookies or server-side sessions in which data can be stored. We ensure that no personal data is taken from sessions or through cookies without your express consent and cookies are only used if this is technically necessary for the website (e.g. spam protection for contact form, shopping cart function) and thus the weighing shows that there are no overriding interests on your part (Art. 6 I 1 f GDPR) or there is express consent on your part.

We use cookies after your explicit consent to personalize content and ads, to offer social media features and to analyze the access to our website. We may share information about your use of our website with our social media, advertising and analytics partners with your consent. Our partners may be able to merge this information with other data that the partners already have about you.

Below you will find the domain, name and duration of cookies used only based on your consent:

4. Newsletter

If you register for our newsletter, we will use the data required for this purpose or separately provided by you to send you our e-mail newsletter regularly based on your consent according to Art. 6 I 1 a GDPR.

Unsubscribing from the newsletter is possible at any time and can be done either by sending us a message via the contact options provided in the imprint or via the link provided for this purpose in the newsletter. After unsubscribing, we will delete your e-mail address unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this statement.

5. Comments

Insofar as you use the comment function on our website, the time of creation, your chosen pseudonym and temporarily also your IP address will be stored in addition to these comments. This is done so that we can protect our rights in the event of illegal content.

6. Third-party services

6.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) and collects and stores some of your data via this web analytics service. This data includes

  • Your approximate location (region)
  • Your IP address (in truncated form)
  • Technical browser information
  • Technical information about the devices used (e.g. screen resolution)
  • Your internet provider
  • Page views
  • First visit to the website
  • Start of the session
  • Click sequence
  • Interaction with and on our website (e.g. clicking on links or videos, ads clicked on)
  • Scrolls on the website
  • Search queries
  • File downloads
  • Language setting
  • Referrer URL

We use the service to evaluate visitor behavior on our website and to design and improve the offer presented on our website in line with requirements.

Google Analytics 4 also uses so-called “cookies”, small text files that are stored on your computer and enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.

In addition to Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and Alphabet Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA also receive the data.

Google is certified under the EU-US Data Privacy Framework, which ensures the GDPR-compliant processing of personal data of EU citizens within the USA.

IP anonymization is preset in Google Analytics 4. This means that Google will shorten your IP address within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before it is transmitted. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.

Google will use the collected data on our behalf to evaluate the website’s use, compile reports on website activity and provide us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics 4 will not be merged with other Google data. Google Analytics 4 is only used with your express consent (Art. 6 I 1 a GDPR). The data collected by Google Analytics 4 is automatically deleted after 2 months.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link (https://tools.google.com/dlpage/gaoptout?hl). You can also prevent the collection of your data by Google Analytics 4 by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this website: Deactivate Google Analytics 4. This does not affect the lawfulness of processing based on consent before its withdrawal. You can view Google’s privacy policy at https://www.google.com/policies/privacy/. You can find more information on the terms of use of Google Analytics 4 at https://www.google.com/analytics/terms

6.2 Use of Facebook Pixels

We use Facebook Pixel of the Facebook network (operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94304, USA). This function allows us to target visitors to this website with advertising on Facebook. For this purpose, personalized and interest-related Facebook ads are displayed when Facebook pages are visited. The function is enabled on our website by a pixel from Facebook, which is implemented on the page. Via the pixel, a direct connection to the Facebook server is established when you visit our website if you have consented to the setting of the pixel (Art. 6 I 1 a GDPR). Once you have consented, you can object at any time using this opt-out link: [ ]

For more information about the collection and use of data by Facebook, about your rights in this regard and options for protecting your privacy, please refer to Facebook’s privacy policy at https://www.facebook.com/about/privacy/.

If you do not want Facebook to assign the collected information directly to your Facebook user account, you can edit the function in your account settings at: https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Fsettings%2F%3Ftab%3Dads#=_. To do so, you must be logged in to Facebook.

You can also manage your basic advertising preference at the following link: https://www.youronlinechoices.com/de/praferenzmanagement/?tid=331636739121.

6.3 JotForm

This website uses JotForm, a service of JotForm Inc, 111 Pine St. Suite 1815, San Francisco, CA 94111, USA. When you enter text and confirm the SEND button in the corresponding box, this text is transmitted to us and stored on the European servers of JotForm Inc. When you visit one of our pages equipped with a JotForm plugin, a connection is established to the servers of JotForm Inc. In doing so, the JotForm server is informed which of our pages you have visited. JotForm is used within our legitimate interest in enabling a quick and easy exchange with us (Art. 6 (1 f) GDPR). Here, no users’ interests are affected, which outweigh this technical necessity. For more information on the handling of user data, please refer to the privacy policy of JotForm Inc. at: https://www.jotform.com/privacy/.

 6.4 Use of Google ReCAPTCHA

This website uses the reCAPTCHA service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The function distinguishes whether the input is made by a human or abusively by automated, machine processing. The query includes sending the IP address and possibly other data required by Google for the reCAPTCHA service to Google. For this purpose, your input is transmitted to Google and used there. However, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of reCaptcha is not merged with other data from Google. The processing thus serves to prevent misuse of this website and ultimately takes place anonymously. ReCAPTCHA is only used with your consent (Art. 6 I 1 a GDPR). Google’s privacy policy applies, you can find it at: https://policies.google.com/privacy?hl=de.

 6.5 Google Tag Manager

This website also uses Google Tag Manager (operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). This tool implements tags and makes it possible to manage these website tags via an interface. No cookies are used for this purpose. However, your IP address may be transmitted to the Google Tag Manager. The Google Tag Manager triggers other tags, which may collect different data. However, the Google Tag Manager does not access this data. If deactivation has been carried out at the domain or cookie level, it will remain in place for all tracking tags if implemented with Google Tag Manager. The service is only used with your consent (Art. 6 I 1 a GDPR). You can view Google’s privacy policy here: https://policies.google.com/privacy

 6.6 Google Ads

 6.6.1 Google Ads Conversion

We use the Google Ads Conversion service (operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to draw attention to our offers on external websites with the help of advertising media (so-called Google Ads). These advertisements are delivered by Google via so-called “Ad Servers”. Ad server cookies are used for this purpose, through which specific parameters for measuring success, such as display of the ads or clicks by users, can be measured. If you access our website via a Google ad, Google Ads will store a cookie on your end device. These cookies usually lose their validity after 30 days and are not intended to identify you personally. For this cookie, the unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions) and opt-out information are usually stored as analysis values. If you visit our site as a result of such an ad and the cookie stored on your computer has not yet expired, Google and we can recognize that you clicked on the ad and were redirected to this page. A different cookie is assigned to each Ads customer. Cookies can therefore not be tracked across Ads on customers’ websites. We ourselves do not collect or process any personal data in the advertising mentioned above measures. We only receive statistical evaluations from Google. Based on these evaluations, we can see which advertising measures are particularly effective. We do not receive any further data from the use of the advertising tools; in particular, we cannot identify users based on this information. Due to the marketing tools used, your browser automatically establishes a direct connection with Google’s server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and can therefore only inform you that Google, through the integration of the above-mentioned service, receives the possibility to assign the visit to our website to your Google account, provided that you are registered there. In addition, there is the possibility that Google, regardless of the existence or non-existence of a user account, learns your IP address and stores it. You can view Google’s privacy policy here: http://www.google.com/intl/de/policies/privacy

 6.6.2 Google Ads Remarketing

This website uses the remarketing function of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The function is used to present website visitors with interest-based advertisements within the Google advertising network. A so-called “cookie” is stored in the browser of the website visitor, which makes it possible to recognize the visitor pseudonymously when he or she visits websites that belong to Google’s advertising network. On these pages, the visitor can be presented with advertisements that relate to content that the visitor has previously accessed on websites that use Google’s remarketing function. According to its own information, Google does not collect any personal data during this process. If you nevertheless do not wish to use Google’s remarketing function, you can generally deactivate it by making the appropriate settings at http://www.google.com/settings/ads. Alternatively, you can deactivate the use of cookies for interest-based advertising via the advertising network initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.

You can view Google’s privacy policy here: http://www.google.com/intl/de/policies/privacy

 6.7 hcaptcha

This website uses the hcaptcha service (operated by Intuition Machines, Inc. 350 Alabama St, San Francisco, CA 94110, USA). This service is used to distinguish whether the input on our website is made by a human or abusively by automated, machine processing. The query includes the sending of the IP address and possibly other data required by hcaptcha for the service to hcaptcha. These are then further processed by hcaptcha. The data transfer may also take place outside the European Union. The processing serves to prevent the misuse of this website. Using hcaptcha is based on our legitimate interest in preventing misuse of our website (Art. 6 I 1 f GDPR). You can view the privacy policy of hcaptcha here: https://www.hcaptcha.com/privacy

 6.8 Google DoubleClick

This website uses the online marketing tool DoubleClick (operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). DoubleClick uses cookies to serve ads that are relevant to users, to improve campaign performance reports, or to prevent a user from seeing the same ads more than once. Google uses a cookie ID to record which ads are displayed in which browser and can thus prevent them from being displayed more than once. In addition, DoubleClick can use cookie IDs to record so-called conversions that are related to ad requests. This is the case, for example, when a user sees a DoubleClick ad and later calls up the advertiser’s website with the same browser and buys something there. According to Google, DoubleClick cookies do not contain any personal information. Due to the marketing tools used, your browser automatically establishes a direct connection with Google’s server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our state of knowledge: Through the integration of DoubleClick, Google receives the information that you have called up the relevant part of our website or clicked on the ad from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, there is a possibility that the provider learns your IP address and stores it.

You can prevent participation in this tracking process by making the appropriate setting in your browser. We would like to point out that in this case you may not be able to use all functions of our offer in full. DoubleClick is only used with your consent (Art. 6 I  1 a GDPR). You can view Google’s privacy policy here: http://www.google.com/intl/de/policies/privacy

6.9 Payment provider Swiftcourt

We have commissioned the provider Swiftcourt (operated by Swiftcourt AB, Dockplatsen 1, 211 19 Malmö, Sweden) to handle our payment process. In addition, we can also provide digital purchase contracts via the provider and have them filled out automatically so that buyers and sellers only have to check these purchase contracts and note their signatures. For this purpose, Swiftcourt will pass on the information provided to us during the booking process together with the information about your booking (name, address, account number, bank code, credit card number if applicable, invoice amount, currency and transaction number) in accordance with Art. 6 I 1 b GDPR. Your data will be passed on to Swiftcourt exclusively for payment processing or the conclusion of the purchase contract between buyer and seller and only to the extent necessary for this purpose. Please also note that Swiftcourt may request proof of funds origin from you if money laundering is suspected. For transactions over €50,000, Swiftcourt may also request the KYC data we collected through iDenfy.

You can find more information on Swiftcourt’s data protection at

https://swiftcourt.com/de/privacy-policy

 6.10 Use of SendGrid

Our e-mail communication is handled by using “SendGrid” (operated by Twilio Inc., 889 Winslow St, Redwood City, California 94063, USA; contact address in Germany: Twilio Germany GmbH, Rosenheimer Str. 143C, 81671 Munich, Germany). In this process, your e-mail address and also your other entered data are stored and processed on the servers of SendGrid in the USA and in other countries, e.g. by subcontracted processors of SenGrid. A list of subcontracted processors can be found here: https://www.twilio.com/de/legal/sub-processors.

SendGrid uses the information above to send and analyze e-mails on our behalf. Furthermore, SendGrid may use this data to optimize or improve its services, e.g. to technically optimize the sending and presentation of the mails, e.g. to determine from which countries the recipients come. However, SendGrid does not use the data of our mail recipients to write to them. SendGrid is used within our legitimate interest in facilitating e-mail communication (Art. 6 (1 f) GDPR). Here, no users’ interests are affected which outweigh this technical necessity. You can view SendGrid’s privacy policy at https://www.twilio.com/legal/privacy.

6.11 Cookiebot

We use the tool Cookiebot (operated by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark) on our website. This tool allows us to inform you about the cookies used on our website and to obtain your consent in advance for certain cookies. The information provided as part of the tool (consent, rejection or preference including date and time) as well as your IP address (in anonymized form) and technical browser data are also sent to Cookiebot in this context to enable this function. In addition, Cookiebot can track user behavior on our website and also use the information to improve its own service. Cookies are stored for 12 months or shorter if we cancel the service in advance. Furthermore, the processing of your data will only take place within the European Union or within a country for which an adequacy decision exists. The legal basis for the processing of your data is Art. 6 I 1 c GDPR (fulfillment of legal obligation) or Art. 6 I 1 a GDPR (consent) or Art. 6 I 1 f GDPR (legitimate interest).

You can view the privacy policy of Cookiebot here: https://www.cookiebot.com/en/privacy-policy/

 6.12 CDN by jsdelivr

Our website makes use of a so-called Content Delivery Network (CDN) by jsdelivr (operated by ProspectOne, Królewska 65A/1, 30-081, Kraków, Poland). A CDN is a network of powerful servers that cache content in various locations worldwide. In doing so, a CDN essentially has two tasks: on the one hand, it should provide content in the shortest possible time and, on the other hand, it should relieve the web host by distributing the data traffic. The legal basis is Art. 6 I 1 f GDPR.

You can view the privacy policy of jsdelivr here: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net

6.13 iDenfy

We also use the services of the provider iDenfy (operated by UAB “iDenfy”, Baršausko street 59, 51423 Kaunas, Lithuania). This service identifies and verifies new and existing customers for us based on money laundering requirements. We have to carry out such a check because high-priced luxury goods are sold on our platform and there is an increased risk of money laundering. The legal basis for using the service is Art. 6 I 1 c GDPR (legal obligation) and Art. 6 I 1 f GDPR (legitimate interest). As part of the identification and verification process, you must scan an ID document and then take a photo of yourself. The following data is then processed and checked by iDenfy

  • Surname
  • First name
  • Gender (if available)
  • Document type
  • Document No.
  • Personal code (if available)
  • Address
  • Nationality
  • Issuing country
  • Selected country
  • Address (if available)
  • Date of birth
  • Date of issue
  • Valid until
  • Pictures of the documents (front/back)
  • Photo of you

You can decide whether to carry out the check via PC or smartphone. IDenfy stores the data for 5 years. We only receive the result of the identification and verification, e.g. “Approved”, “Denied”, “Failed” etc. We can view the details of the individual verifications via the iDenfy dashboard. We could also export password-protected reports from there.

You can view iDenfy’s privacy policy here: https://www.idenfy.com/privacy-policy/

6.14 PremiumMedia Verlags GmbH

In the context of our cooperation with PremiumMedia Verlags GmbH, registered at Benedikt-Hagn-Str. 5b, 80689 Munich, we offer you the opportunity to obtain a complimentary three-month trial subscription to “Octane” magazine. Should you wish to avail yourself of this offer, we will transmit your email address to PremiumMedia Verlags GmbH, enabling them to provide you with information pertaining to the trial subscription and to initiate any further steps that may be necessary for the subscription process.

The transfer of your email address shall be executed solely on the basis of your explicit consent (Art. 6  I 1 a GDPR).

You may access and review the Privacy Policy of PremiumMedia Verlags GmbH at the following URL: https://www.octane-magazin.de/datenschutz/

7. Contact

To contact us regarding data protection, you are welcome to use the following contact options. Responsible in terms of the GDPR:

FutureLabs GmbH
Schneebergstraße 1
95632 Wunsiedel
E-mail: info@heartbids.de
Phone: +49 (0) 9232/9769940