Privacy policy

1. An overview of data protection

General information

The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.

Data recording on this website

Analysis tools and tools provided by third parties

There is a possibility that your browsing patterns will be statistically analyzed when you visit this website. Such analyses are performed primarily with what we refer to as analysis programs. For detailed information about these analysis programs please consult our Data Protection Declaration below.

2. Hosting

We are hosting the content of our website at the following providers:

Shopify

The provider is Shopify International Limited, Victoria Building, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter: “Shopify”). Shopify is a tool for creating and hosting websites. When you visit our website, Shopify collects your IP address and information about the device and browser you use. Shopify stores cookies in your browser for the purpose of analysis. The use of Shopify is based on Art. 6(1)(f) GDPR. Details at https://www.shopify.de/legal/datenschutz.

External Hosting

This website is hosted externally. Personal data collected on this website are stored on the servers of the host. The external hosting serves the purpose of fulfilling the contract with our potential and existing customers (Art. 6(1)(b) GDPR) and in the interest of secure, fast, and efficient provision of our online services by a professional provider (Art. 6(1)(f) GDPR).

We are using the following host(s):

Vercel Inc., 650 California St, San Francisco, CA 94108, USA
Sanity Inc., 695 Minna St, San Francisco, CA 94103, USA

3. General information and mandatory information

Data protection

The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration. Whenever you use this website, a variety of personal information will be collected. We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.

Information about the responsible party (controller)

The data processing controller on this website is:

Horl 1993 GmbH
Zollhallenstraße 13
D-79106 Freiburg
Phone: +49 (0) 761-888 723 00
E-mail: info@horl.com

The controller is the natural person or legal entity that single-handedly or jointly with others makes decisions as to the purposes of and resources for the processing of personal data.

Storage duration

Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods).

General information on the legal basis for the data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR.

Designation of a data protection officer

We have appointed a data protection officer.

IT-Kanzlei Lutz
Stefan Lutz, LL.M.
Bachstraße 44
88214 Ravensburg
Phone: 0751 | 27 088 53 - 0
E-mail: lutz@datenschutz-rv.de

Information on the data transfer to third-party countries that are not secure under data protection law and the transfer to US companies that are not DPF-certified

We use, among other technologies, tools from companies located in third-party countries that are not safe under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). If these tools are enabled, your personal data may be transferred to and processed in these countries. The US, as a secure third-party country, generally has a level of data protection comparable to that of the EU when the recipient is certified under the DPF or has appropriate additional assurances.

Recipients of personal data

In the scope of our business activities, we cooperate with various external parties. We only disclose personal data to external parties if this is required as part of the fulfillment of a contract, if we are legally obligated to do so, if we have a legitimate interest in the disclosure pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the disclosure. When using processors, we only disclose personal data on the basis of a valid data processing contract.

Revocation of your consent to the processing of data

A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.

Right to object to the collection of data in special cases; right to object to direct advertising (Art. 21 GDPR)

In the event that data are processed on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to at any time object to the processing of your personal data based on grounds arising from your unique situation (objection pursuant to Art. 21(1) GDPR). If your personal data is being processed in order to engage in direct advertising, you have the right to object to the processing of your affected personal data for the purposes of such advertising at any time (objection pursuant to Art. 21(2) GDPR).

Right to log a complaint with the competent supervisory agency

In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format. If you should demand the direct transfer of the data to another controller, this will be done only if it is technically feasible.

Information about, rectification and eradication of data

Within the scope of the applicable statutory provisions, you have the right to demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data at any time. You may also have a right to have your data rectified or eradicated.

Right to demand processing restrictions

You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. This applies if you dispute the correctness of your data, if the processing is unlawful, if we no longer need your data but you need it for legal claims, or if you have raised an objection pursuant to Art. 21(1) GDPR.

SSL and/or TLS encryption

For security reasons and to protect the transmission of confidential content, such as purchase orders or inquiries you submit to us, this website uses either an SSL or a TLS encryption program. You can recognize an encrypted connection by checking whether the address line of the browser switches from “http://” to “https://” and also by the appearance of the lock icon in the browser line.

Encrypted payment transactions on this website

Payment transactions using common modes of paying (Visa/MasterCard, debit to your bank account) are processed exclusively via encrypted SSL or TLS connections. If the communication with us is encrypted, third parties will not be able to read the payment information you share with us.

4. Recording of data on this website

Cookies

Our websites and pages use what the industry refers to as “cookies.” Cookies are small data packages that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently archived on your device (permanent cookies). Cookies can be issued by us (first-party cookies) or by third-party companies (third-party cookies). Cookies required for the performance of electronic communication transactions or for certain functions shall be stored on the basis of Art. 6(1)(f) GDPR. If consent has been requested, processing occurs exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG; this consent may be revoked at any time. If cookies are deactivated, the functions of this website may be limited.

Consent with Usercentrics

This website uses the consent technology of Usercentrics to obtain your consent to the storage of certain cookies and to document it in a data protection compliant manner. Provider: Usercentrics GmbH, Sendlinger Straße 7, 80331 München, Germany. Transferred: your declaration(s) of consent or revocation, your IP address, information about your browser and device, the date and time of your visit, geolocation. Legal basis: Art. 6(1)(c) GDPR.

Request by e-mail, telephone, or fax

If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent. Legal basis: Art. 6(1)(b) GDPR if related to a contract, otherwise Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR. The data remain with us until you request deletion, revoke consent, or the purpose lapses.

5. Analysis tools and advertising

Google Tag Manager

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Google Tag Manager allows us to integrate tracking or statistical tools. The Tag Manager itself does not create user profiles or store cookies but collects your IP address, which may be transferred to Google’s parent company in the US. Legal basis: Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR and § 25(1) TDDDG on consent. DPF-certified: https://www.dataprivacyframework.gov/participant/5780.

Google Analytics

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables analysis of visitor behavior (page views, time spent, operating system, origin). Data is usually transferred to a Google server in the US. Uses technologies for user recognition (cookies, device fingerprinting). Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. SCC-based US transfers. DPF-certified: https://www.dataprivacyframework.gov/participant/5780. IP anonymization is active. We have a data processing agreement with Google. E-commerce tracking is enabled (orders, order values, shipping costs, time-to-purchase).

Microsoft Advertising

Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Microsoft Advertising enables ads in the Bing search engine or on third-party websites via keyword and audience targeting. Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. SCC-based US transfers. DPF-certified: https://www.dataprivacyframework.gov/participant/6474.

Google Ads

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads enables ads in the Google search engine or on third-party websites (keyword/audience targeting). Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. SCC-based US transfers. DPF-certified: https://www.dataprivacyframework.gov/participant/5780.

Google AdSense

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google AdSense displays targeted third-party ads and uses cookies, web beacons, and comparable recognition technologies. Usage information (including IP address) is transferred to a Google server in the US. Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. SCC-based US transfers. DPF-certified: https://www.dataprivacyframework.gov/participant/5780.

Google Ads Remarketing

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads Remarketing allows us to assign users who interacted with our online offering to target groups and display interest-based ads in the Google advertising network. Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. Opt-out: https://adssettings.google.com/anonymous. DPF-certified: https://www.dataprivacyframework.gov/participant/5780.

Google Conversion Tracking

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Conversion Tracking allows us to identify whether users completed certain actions (e.g., clicks, purchases). This is used to compile conversion statistics. Google uses cookies or comparable recognition technologies for identification. Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. DPF-certified: https://www.dataprivacyframework.gov/participant/5780.

Klaviyo

Provider: Klaviyo Inc., 125 Summer Street, Floor 6, Boston, MA 02110, USA. Klaviyo is a marketing automation tool for sending emails, SMS, push messages and collecting customer reviews. Processed data: name, phone, email, address data, IP address, device identifiers, usage data. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG. DPF-certified: https://www.dataprivacyframework.gov/participant/6149. SCC: https://www.klaviyo.com/legal/data-processing-agreement.

Meta Pixel (formerly Facebook Pixel)

Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Collected data is also transferred to the USA and other third-party countries. The Meta Pixel enables tracking of visitor behavior after clicking a Meta ad to measure effectiveness and optimize future advertising. Use based on your consent per Art. 6(1)(a) GDPR and § 25(1) TDDDG. Joint controllership with Meta per Art. 26 GDPR. DPF-certified: https://www.dataprivacyframework.gov/participant/4452.

TikTok Pixel

Provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. TikTok Pixel enables interest-based advertising on TikTok and measurement of effectiveness. Processed: IP address, page views, time spent, operating system, user origin, click/event info. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG. SCC-based third-country transfers.

6. Newsletter

Newsletter data

If you would like to subscribe to the newsletter offered on this website, we will need from you an e-mail address as well as information that allow us to verify that you are the owner of the e-mail address provided and consent to the receipt of the newsletter. We shall use such data only for the sending of the requested information and shall not share such data with any third parties. Legal basis: Art. 6(1)(a) GDPR. You may revoke the consent at any time via the “Unsubscribe” link in the newsletter. After you unsubscribe, your e-mail address may be stored in a blacklist if necessary to prevent future mailings (Art. 6(1)(f) GDPR).

7. Plug-ins and Tools

Google Maps

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Your IP address is transferred to a Google server in the US and archived. Legal basis: Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR and § 25(1) TDDDG on consent. SCC-based US transfers. DPF-certified: https://www.dataprivacyframework.gov/participant/5780.

Cloudflare Turnstile

Provider: Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile checks whether the data input is done by a human or automated program (analyzes IP address, time on site, mouse movements). Legal basis: Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR and § 25(1) TDDDG on consent. SCC: https://www.cloudflare.com/cloudflare-customer-scc/. DPF-certified: https://www.dataprivacyframework.gov/participant/5666.

8. Online marketing and partner programs

Affiliate Programs on this website

We participate in affiliate partner programs. Cookies or comparable recognition technologies (e.g., device fingerprinting) are used. Legal basis: Art. 6(1)(f) GDPR or Art. 6(1)(a) GDPR and § 25(1) TDDDG on consent. We participate in the following affiliate program:

CJ Affiliate
530 E Montecito St,
Santa Barbara, CA 93103.

9. eCommerce and payment service providers

Processing of Customer and Contract Data

We collect, process, and use personal customer and contract data for the establishment, content arrangement and modification of our contractual relationships. Data with personal references to the use of this website (usage data) will be collected, processed, and used only if necessary to enable the user to use our services or required for billing purposes. Legal basis: Art. 6(1)(b) GDPR. The collected customer data shall be deleted upon completion of the order or termination of the business relationship and upon expiration of any statutory archiving periods.

Data transfer upon closing of contracts for online stores, retailers, and the shipment of merchandise

Whenever you order merchandise from us, we will share your personal data with the transportation company entrusted with the delivery as well as the payment service commissioned to handle the payment transactions. Legal basis: Art. 6(1)(b) GDPR. If you give us your consent per Art. 6(1)(a) GDPR, we will share your email address with the transportation company so they can notify you about the shipping status; you may revoke consent at any time.

Payment services

We integrate payment services of third-party companies on our website. Legal basis: Art. 6(1)(b) GDPR (contract processing), Art. 6(1)(f) GDPR (smooth payment), or Art. 6(1)(a) GDPR (consent). We use: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg – SCC: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full; Shopify Payment – Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. Details: https://www.shopify.de/legal/datenschutz.

Privacy policy | HORL® Premium Sharpness for Your Knives