PRIVACY POLICY

Information on the Collection of Personal Data and Contact Information of the Data Controller

1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we provide information on how your personal data is processed when you use our website. Personal data refers to all data that can be used to personally identify you.

1.2 The data controller for data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is RESPIRA™. The data controller is the person or legal entity who, alone or jointly with others, determines the purposes and means of processing personal data.

1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the “https://” prefix and the lock symbol in your browser’s address bar.

Data Collection When Visiting Our Website

When you visit our website for purely informational purposes, i.e., without registering or otherwise providing us with information, we only collect data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which is technically necessary for us to display the website:

• The website you visited

• Date and time of access

• Amount of data transmitted in bytes

• Source/reference from which you accessed the site

• Browser used

• Operating system used

• IP address used (if applicable: in anonymized form)

The processing is carried out in accordance with Art. 6 (1) lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not transmitted or used in any other way. However, we reserve the right to check the server log files later if there are concrete indications of illegal use.

Cookies

To make your visit to our website more attractive and to enable the use of certain functions, we use cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the browser session ends, i.e., after you close your browser (session cookies). Other cookies remain on your device and enable us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). If cookies are set, they collect and process specific user information such as browser and location data as well as IP address values. Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie.

Some cookies serve to simplify the ordering process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). If personal data is also processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6 (1) lit. b GDPR either for the execution of the contract or in accordance with Art. 6 (1) lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.

We may collaborate with advertising partners to make our online offering more interesting for you. For this purpose, cookies from partner companies may also be stored on your hard drive (third-party cookies) when you visit our website. If we cooperate with such advertising partners, you will be individually and separately informed about the use of such cookies and the scope of the information collected in the following sections.

Please note that you can set your browser to inform you about the setting of cookies and to decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general. Each browser differs in the way it handles cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers under the following links:

• Internet Explorer: [Link]

• Firefox: [Link]

• Chrome: [Link]

• Safari: [Link]

• Opera: [Link]

Please note that if you do not accept cookies, the functionality of our website may be limited.

Contact

When contacting us (e.g., via a contact form or email), personal data is collected. The specific data collected in the case of a contact form can be seen from the respective contact form. These data are stored and used solely for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6 (1) lit. f GDPR. If your contact aims at concluding a contract, the additional legal basis for processing is Art. 6 (1) lit. b GDPR. Your data will be deleted after the final processing of your request, provided that the circumstances indicate that the matter in question has been fully clarified and there are no statutory retention obligations to the contrary.

Data Processing for Account Creation and Contract Processing

In accordance with Art. 6 (1) lit. b GDPR, personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. The specific data collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be requested by sending a message to the address mentioned above for the data controller. We store and use the data you provide for contract processing. After the contract is fully processed or your customer account is deleted, your data will be blocked concerning tax and commercial retention periods and deleted after these periods have expired unless you have expressly consented to further use of your data or legally permitted further use of data has been reserved by our side, about which we inform you accordingly below.

Use of Your Data for Direct Advertising

6.1 Subscription to Our Newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing any additional data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an email newsletter if you have expressly confirmed to us that you consent to receiving newsletters. We will then send you a confirmation email asking you to confirm that you wish to receive newsletters in the future by clicking on an appropriate link.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 (1) lit. a GDPR. When subscribing to the newsletter, we store your IP address as provided by the Internet Service Provider (ISP) as well as the date and time of registration to trace possible misuse of your email address at a later time. The data collected by us when you subscribe to the newsletter will be used solely for the purpose of addressing you in an advertising manner through the newsletter. You can unsubscribe from the newsletter at any time by using the link provided in the newsletter or by sending a corresponding message to the data controller mentioned at the beginning. After you have unsubscribed, your email address will be immediately deleted from our newsletter distribution list unless you have expressly consented to further use of your data, or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this statement.

6.2 Sending of Email Newsletters to Existing Customers

If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range via email. For this, we do not need to obtain separate consent from you. Data processing in this context is based solely on our legitimate interest in personalized direct advertising in accordance with Art. 6 (1) lit. f GDPR. If you initially objected to the use of your email address for this purpose, no email will be sent by us. You have the right to object to the use of your email address for the above-mentioned advertising purposes at any time with effect for the future by notifying the data controller mentioned at the beginning. You will only incur transmission costs according to the basic rates. Upon receipt of your objection, the use of your email address for advertising purposes will immediately cease.

Data Processing for Order Processing

7.1 The personal data collected by us will be transferred to the transport company entrusted with the delivery as part of contract processing, to the extent that this is necessary for the delivery of the goods. Your payment data will be transferred to the commissioned credit institution as part of payment processing, to the extent that this is necessary for payment processing. If payment service providers are used, we explicitly inform you about this below. The legal basis for data transfer is Art. 6 (1) lit. b GDPR.

7.2 Use of Payment Service Providers

• PayPal

When paying via PayPal, credit card via PayPal, direct debit via PayPal, or—if offered—“purchase on invoice” or “installment payment” via PayPal, we transmit your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”) as part of payment processing. Data transfer takes place in accordance with Art. 6 (1) lit. b GDPR and only to the extent necessary for payment processing.

• SOFORT

If you select the payment method “SOFORT,” the payment will be processed via the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “SOFORT”), to whom we transmit the information provided during the ordering process, along with information about your order, in accordance with Art. 6 (1) lit. b GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Data transfer takes place solely for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this purpose.

Contact for Review Reminders

Own Review Reminder (No Submission to a Customer Review System)

We use your email address for a one-time reminder to submit a review of your order for the review system we use, provided you have given us your express consent to do so either during or after your order in accordance with Art. 6 (1) lit. a GDPR. You can withdraw your consent at any time by sending a message to the data controller.

Use of Social Media: Social Plugins

9.1 Facebook Plugins with Shariff Solution

Our website uses social plugins (“plugins”) from the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”).

To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins, but merely through an HTML link. This type of integration ensures that no connection is established with Facebook’s servers when you access a page on our website that contains such buttons. If you click on the button, a new browser window opens and retrieves the Facebook page on which you can interact with the plugins there (if necessary, after entering your login details).

Facebook Inc., based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

For the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your rights in this regard and setting options for protecting your privacy, please see Facebook’s privacy policy: [Link].

9.2 Google+ Plugins with Shariff Solution

Our website uses social plugins (“plugins”) from the social network Google+, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins, but merely through an HTML link. This type of integration ensures that no connection is established with Google’s servers when you access a page on our website that contains such buttons. If you click on the button, a new browser window opens and retrieves the Google+ page on which you can interact with the plugins there (if necessary, after entering your login details).

Google LLC, based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

For the purpose and scope of data collection and the further processing and use of data by Google, as well as your rights in this regard and setting options for protecting your privacy, please see Google’s privacy policy: [Link].

9.3 Instagram Plugin with Shariff Solution

Our website uses social plugins (“plugins”) from the online service Instagram, operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA (“Instagram”).

To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins, but merely through an HTML link. This type of integration ensures that no connection is established with Instagram’s servers when you access a page on our website that contains such buttons. If you click on the button, a new browser window opens and retrieves the Instagram page on which you can interact with the plugins there (if necessary, after entering your login details).

Instagram LLC, based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

For the purpose and scope of data collection and the further processing and use of data by Instagram, as well as your rights in this regard and setting options for protecting your privacy, please see Instagram’s privacy policy: [Link].

Online Marketing

10.1 DoubleClick by Google

This website uses the online marketing tool DoubleClick by Google, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“DoubleClick”).

DoubleClick uses cookies to display ads relevant to users, improve campaign reports, or prevent a user from seeing the same ads multiple times. Google uses a cookie ID to track which ads are displayed in which browser, thereby preventing them from being shown more than once. Processing is based on our legitimate interest in optimizing the marketing of our website in accordance with Art. 6 (1) lit. f GDPR.

Further, DoubleClick can use cookie IDs to track conversions related to ad requests. This happens, for example, when a user sees a DoubleClick ad and later visits the advertiser’s website with the same browser and makes a purchase. According to Google, DoubleClick cookies do not contain personally identifiable information.

Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s servers. We have no influence on the extent and further use of the data collected by Google through the use of this tool and therefore inform you according to our knowledge: By integrating DoubleClick, Google receives information that you have accessed the corresponding part of our website or clicked on an ad from us. If you are registered with a Google service, Google can associate the visit with your account. Even if you are not registered with Google or are not logged in, it is possible that the provider will obtain and store your IP address.

If you wish to object to participation in this tracking process, you can disable cookies for conversion tracking by setting your browser to block cookies from the domain www.googleadservices.com, [Link], where this setting will be deleted if you delete your cookies. Alternatively, you can learn about the setting of cookies and make the necessary adjustments on the website of the Digital Advertising Alliance at [Link]. Finally, you can set your browser to inform you about the setting of cookies and to decide individually whether to accept them or to exclude the acceptance of cookies in certain cases or generally. If cookies are not accepted, the functionality of our website may be limited.

Google LLC, based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

Further information on DoubleClick by Google’s privacy policy can be found here: [Link].

10.2 Use of Google AdWords Conversion Tracking

This website uses the online advertising program “Google AdWords” and, as part of Google AdWords, conversion tracking from Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). We use Google AdWords to draw attention to our attractive offers by means of advertising material (so-called Google AdWords) on external websites. We can determine how successful individual advertising campaigns are in relation to the data from advertising campaigns. We pursue the interest of showing you ads that interest you, making our website more interesting for you, and achieving a fair calculation of advertising costs.

The conversion tracking cookie is set when a user clicks on an ad placed by Google. Cookies are small text files that are stored on your computer system. These cookies usually expire after 30 days and are not intended for personal identification. If the user visits certain pages on this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. Therefore, cookies cannot be tracked through the websites of AdWords customers. The information obtained using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that personally identifies users. If you do not want to participate in the tracking, you can opt-out of this usage by deactivating the Google conversion tracking cookie in your browser’s user settings. You will then not be included in the conversion tracking statistics. We use Google AdWords based on our legitimate interest in targeted advertising in accordance with Art. 6 (1) lit. f GDPR.

Google LLC, based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

Further information about Google’s privacy policy can be found here: [Link].

You can permanently disable cookies for ad preferences by preventing them through a corresponding setting in your browser software or by downloading and installing the browser plugin available at the following link: [Link].

Please note that certain functions on this website may not be available or only partially available if you have deactivated the use of cookies.

Web Analytics Services

Google (Universal) Analytics

This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses “cookies,” which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website (including the shortened IP address) is generally transmitted to and stored by Google on servers in the United States.

This website uses Google Analytics exclusively with the extension “_anonymizeIp(),” which ensures anonymization of the IP address by shortening and excludes direct personal reference. By activating this extension, your IP address will be shortened by Google within member states of the EU or other parties to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and shortened there. In these exceptional cases, processing is carried out in accordance with Art. 6 (1) lit. f GDPR based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.

On our behalf, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide us with other services related to website and internet use. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

You can prevent the storage of cookies by selecting the appropriate settings on your browser; however, please note that if you do this, you may not be able to use all the functions of this website to their fullest extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: [Link].

As an alternative to the browser plugin or within browsers on mobile devices, click the following link to set an opt-out cookie that will prevent future collection of Google Analytics within this website (this opt-out cookie only works in this browser and only for this domain. If you delete your cookies in this browser, you must click this link again): Disable Google Analytics.

Google LLC, based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

This website also uses Google Analytics for cross-device analysis of visitor flows, which is carried out via a user ID. When you first visit a page, you will be assigned a unique, permanent, and anonymized ID that is set across devices. This allows interaction data from different devices and sessions to be linked to a single user. The user ID does not contain any personal data and does not transmit such data to Google.

You can object to the collection and storage of data via the user ID at any time with effect for the future. To do this, you must deactivate Google Analytics on all systems you use, such as in another browser or on your mobile device.

You can disable it by using a Google browser plugin: [Link]. Alternatively, within browsers on mobile devices, click the following link to set an opt-out cookie that will prevent future collection of Google Analytics within this website (this opt-out cookie only works in this browser and only for this domain. If you delete your cookies in this browser, you must click this link again): Disable Google Analytics.

Further information about Universal Analytics can be found here: [Link]

Retargeting/Remarketing/Referral Advertising

Facebook Custom Audience via Pixel Process

This website uses “Facebook Pixel” from Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”). With explicit consent, user behavior can be tracked after they have viewed or clicked on a Facebook advertisement. This process is used to evaluate the effectiveness of Facebook ads for statistical and market research purposes and may help optimize future advertising campaigns.

The data collected is anonymous to us, so it provides no conclusions about the identity of users. However, the data is stored and processed by Facebook, so it can be linked to the respective user profile and Facebook may use the data for its own advertising purposes in accordance with Facebook’s Data Use Policy (Link). You can allow Facebook and its partners to display ads on and off Facebook. A cookie may also be stored on your computer for these purposes. These processing operations are only carried out if explicit consent is given in accordance with Art. 6 (1) lit. a GDPR.

Consent to the use of Facebook Pixel may only be declared by users over 13 years of age. If you are younger, please ask your legal guardian for permission.

Facebook Inc., based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

To disable the use of cookies on your computer, you can set your browser so that no cookies are stored on your computer in the future or so that already stored cookies are deleted. Disabling all cookies may, however, mean that some functions on our website cannot be executed. You can also deactivate the use of cookies by third-party providers such as Facebook on the website of the Digital Advertising Alliance: [Link].

Google AdWords Remarketing

Our website uses the features of Google AdWords Remarketing, through which we advertise this website in Google search results as well as on third-party websites. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). For this purpose, Google sets a cookie in the browser of your device, which automatically enables interest-based advertising based on a pseudonymized cookie ID and the pages you visit. Processing is based on our legitimate interest in optimal marketing of our website in accordance with Art. 6 (1) lit. f GDPR.

Further data processing only occurs if you have agreed with Google that your Internet and app browsing history will be linked to your Google account and information from your Google account will be used to personalize the ads you see online. In this case, if you are logged in with Google during your visit to our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. For this purpose, Google will temporarily link your personal data with Google Analytics data to form target groups.

You can permanently deactivate cookies for ad preferences by downloading and installing the browser plugin available at the following link: [Link]. Alternatively, you can learn about the setting of cookies and make the necessary settings on the website of the Digital Advertising Alliance at [Link]. Finally, you can set your browser to inform you about the setting of cookies and to decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be limited.

Google LLC, based in the USA, is certified under the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

Further information and Google’s privacy policy regarding advertising can be found here: [Link].

Data Subject Rights

13.1 Applicable data protection law grants you comprehensive rights as a data subject (rights of access and intervention) vis-à-vis the data controller with regard to the processing of your personal data, about which we inform you below:

• Right of access according to Art. 15 GDPR: You have the right to obtain information about your personal data processed by us, the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients to whom your data have been or will be disclosed, the planned storage period or criteria for determining the storage period, the existence of a right to rectification, deletion, restriction of processing, objection to processing, the right to lodge a complaint with a supervisory authority, the origin of your data if they were not collected by us, the existence of automated decision-making, including profiling, and, if applicable, meaningful information about the logic involved and the scope and intended effects of such processing, as well as your right to be informed about the guarantees pursuant to Art. 46 GDPR when your data are transferred to third countries.

• Right to rectification according to Art. 16 GDPR: You have the right to have incorrect personal data concerning you corrected without undue delay and/or to have your incomplete data stored by us completed.

• Right to deletion according to Art. 17 GDPR: You have the right to request the deletion of your personal data under the conditions set out in Art. 17 (1) GDPR. However, this right does not apply if the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.

• Right to restriction of processing according to Art. 18 GDPR: You have the right to request the restriction of the processing of your personal data as long as the accuracy of your data contested by you is verified when you refuse the deletion of your data due to unlawful data processing and instead request the restriction of the use of your data when you need your data for the establishment, exercise, or defense of legal claims after we no longer need these data after achieving the purpose, or if you have objected on grounds related to your particular situation, as long as it has not yet been determined whether our legitimate grounds override yours.

• Right to be informed according to Art. 19 GDPR: If you have asserted the right to rectification, deletion, or restriction of processing against the data controller, the data controller is obliged to inform all recipients to whom the personal data concerning you have been disclosed of this rectification or deletion of data or restriction of processing, unless this proves to be impossible or involves disproportionate effort. You have the right to be informed about these recipients.

• Right to data portability according to Art. 20 GDPR: You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request the transfer of these to another data controller, where technically feasible.

• Right to withdraw consent according to Art. 7 (3) GDPR: You have the right to withdraw consent once given for data processing at any time with effect for the future. In the event of withdrawal, we will delete the data concerned without delay unless further processing can be based on a legal basis for processing without consent. The withdrawal of consent does not affect the lawfulness of the processing carried out based on the consent before its withdrawal.

• Right to lodge a complaint according to Art. 77 GDPR: If you believe that the processing of personal data concerning you violates the GDPR, you have the right—without prejudice to any other administrative or judicial remedy—to lodge a complaint with a supervisory authority, in particular in the Member State where you have your habitual residence, place of work, or place of the alleged infringement.

13.2 Right to Object

If we process your personal data on the basis of our overriding legitimate interest as part of a balancing of interests, you have the right to object to this processing at any time for reasons arising from your particular situation, with effect for the future.

If you exercise your right to object, we will stop processing the data concerned. Further processing is, however, reserved if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims.

If your personal data is processed by us for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. You can exercise the right to object as described above.

If you exercise your right to object, we will stop processing the data concerned for direct marketing purposes.

Duration of Storage of Personal Data

The duration of the storage of personal data is determined by the respective statutory retention period (e.g., commercial and tax retention periods). After the period expires, the corresponding data is routinely deleted, provided that they are no longer necessary for the fulfillment of the contract or the initiation of a contract and/or we have no legitimate interest in further storage.