General data privacy
Data Privacy
Current Version: July 2026
1. Data Protection at a Glance
General Information
We are pleased that you are visiting our website https://feiler.de and we thank you for your interest in our products. Protecting your privacy when using our website is of utmost importance to us. We treat your personal data with the highest level of confidentiality and only collect, store, and process it to the extent necessary. Any collection and processing of personal data from users is carried out in compliance with the applicable data protection laws.
The following information provides an overview of what happens to your personal data when you visit this shop.
Personal data refers to any information that can identify you as an individual.
How do we collect your data?
Your data is collected primarily when you provide it to us.
For example, this may involve information you enter into a contact form.
Other data is collected automatically or with your consent when visiting the website via our IT systems.
This includes technical data (e.g., internet browser, operating system, or the time of the page view).
The collection of this data occurs automatically as soon as you enter the shop.
How do we use your data?
Some of the data is collected to ensure the proper functionality of the website. Other data may be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right to request, free of charge, information regarding the origin, recipients, and purpose of your stored personal data at any time.
You also have the right to request the correction or deletion of this data. If you have given consent for data processing, you may withdraw this consent at any time for the future.
Additionally, you have the right to request the restriction of the processing of your personal data under certain circumstances.
Furthermore, you have the right to lodge a complaint with the relevant supervisory authority.
Should you have any further questions regarding data protection, please feel free to contact us at any time.
2. Data Controller
The data controller within the meaning of the GDPR and the Federal Data Protection Act (BDSG) is:
Ernst Feiler GmbH
Greimweg 4
95691 Hohenberg an der Eger
Phone: +49 (0)9233-77280
Fax: +49 (0)9233 – 772899
E-Mail: info@feiler.de
The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, or similar).
3. Hosting und Content Delivery Networks (CDN)
This website is hosted by an external service provider (host).
The personal data collected on this website is stored on the host’s servers.
This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
The use of the host is for the purpose of fulfilling our contractual obligations to potential and existing customers (Art. 6(1)(b) GDPR)
and in the interest of providing a secure, fast, and efficient online service through a professional provider (Art. 6(1)(f) GDPR).
Our host will process your data only to the extent necessary to fulfil its performance obligations and will follow our instructions regarding this data.
We use the following host:
Mittwald CM Service GmbH & Co. KG
Königsberger Str. 4-6
32339 Espelkamp
To ensure data protection-compliant processing, we have entered into a Data Processing Agreement with our host.
4. General Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously.
We treat your personal data confidentially and in accordance with the statutory data protection regulations as well as this Privacy Policy.
When you use this website, various personal data will be collected. Personal data refers to any data that can be used to identify you personally.
This Privacy Policy explains what data we collect and how we use it. It also explains how and for what purposes this data is processed.
Please note that data transmission over the internet (e.g., when communicating via email) may have security vulnerabilities.
Complete protection of data from third-party access is not possible.
Data Retention
Unless a more specific retention period is specified within this Privacy Policy, your personal data will remain with us until the purpose for its processing no longer applies.
If you submit a legitimate request for deletion or withdraw your consent for data processing, your data will be deleted, unless we have other legally permissible grounds for retaining your personal data (e.g., tax or commercial retention periods);
in the latter case, the data will be deleted once these reasons no longer apply.
We have appointed a Data Protection Officer for our company.
Herr Claus Nagel-Piciorus
Danziger Straße 4
95126Schwarzenbach/Saale
Tel: +49 (0) 9284 – 58 14 900
E-Mail: datenschutz@nagel-kollegen.de
Webseite: https://www.nagel-kollegen.de
Notice on Data Transfer to the USA and Other Third Countries
We use tools from companies based in the USA or other third countries that do not have an adequate level of data protection. When these tools are active, your personal data may be transferred to and processed in these third countries. Please note that in these countries, there is no guarantee of data protection comparable to that of the EU. For example, US companies are required to disclose personal data to security authorities without the possibility for you, as the data subject, to take legal action against it. It cannot be ruled out that US authorities (e.g., intelligence agencies) may process, evaluate, and permanently store your data stored on US servers for surveillance purposes. We have no control over these processing activities.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the change in the address bar of your browser from "http://" to "https://" and by the lock symbol in your browser bar. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Withdrawal of Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You can withdraw your consent at any time. The legality of the data processing carried out until the withdrawal remains unaffected by the withdrawal.
Right to Object to Data Processing in Specific Cases as well as to Direct Marketing (Art. 21 GDPR)
IF THE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE LEGAL BASIS ON WHICH A PARTICULAR PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR). IF YOUR PERSONAL DATA IS BEING PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING PURPOSES; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ART. 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In case of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, their place of work, or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to Data Portability
You have the right to receive the data we process based on your consent or in the performance of a contract in an automated manner, in a structured, commonly used, and machine-readable format, and to transmit it to another data controller. If you request the direct transfer of the data to another controller, this will only occur if it is technically feasible.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data. You may contact us at any time regarding this right.
The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of the personal data we have stored about you, we generally require time to verify this.
During the verification period, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/continues to be unlawful, you may request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you require it for the establishment, exercise, or defence of legal claims, you have the right to request the restriction of processing instead of deletion.
- If you have lodged an objection under Art. 21(1) GDPR, a balancing of interests must be carried out between your and our interests.
As long as it has not been determined whose interests outweigh, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, such data—apart from its storage—may only be processed with your consent, or for the establishment, exercise, or defence of legal claims, or to protect the rights of another natural or legal person, or for reasons of substantial public interest of the European Union or a Member State.
Objection to Advertising Emails
We hereby object to the use of contact details published as part of the legal notice for the purpose of sending unsolicited advertising and informational materials. The operators of this website expressly reserve the right to take legal action in the event of unsolicited advertising communications, such as spam emails.
5. Data Collection on This Website
Cookies
To make the visit to our website more attractive, user-friendly, and secure, we use so-called cookies in several places on our site.
These are small text files that your browser automatically creates and stores on your device (laptop, tablet, smartphone, etc.) when you visit our site.
Cookies are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device.
Session cookies are automatically deleted after your visit. Persistent cookies remain on your device until you delete them yourself or until your web browser automatically deletes them.
In some cases, third-party cookies may also be stored on your device when you visit our site (third-party cookies).
These allow us or you to use specific services of the third-party company (e.g., cookies for processing payment services).
Cookies serve various functions. Many cookies are technically necessary, as certain website features would not function without them (e.g., the shopping cart function or video display).
Other cookies are used to evaluate user behaviour or display advertisements.
Cookies that are necessary for the execution of electronic communication processes (necessary cookies) or to provide certain features desired by you (functional cookies, e.g., for the shopping cart function) or to optimise the website (e.g., cookies to measure the web audience) are stored based on Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing cookies for the technically error-free and optimised provision of its services. If consent to the storage of cookies has been requested, the storage of the relevant cookies will take place exclusively based on this consent (Art. 6(1)(a) GDPR);
the consent can be withdrawn at any time.
You can configure your browser to inform you about the setting of cookies and to allow cookies only in specific cases, to exclude the acceptance of cookies for certain situations,
or to activate the automatic deletion of cookies when closing the browser. Deactivating cookies may limit the functionality of this website.
If cookies from third parties or for analysis purposes are used, we will inform you separately in this Privacy Policy and, if necessary, request your consent.
Cookies do not cause any harm to your device and do not contain viruses, trojans, or other malicious software. Most browsers automatically accept cookies.
However, you can configure your browser to inform you about the setting of cookies and to decide individually whether to accept them or to exclude the acceptance of cookies for specific cases or altogether.
If cookies are not accepted, the functionality of our website may be limited in individual cases.
When you visit our website, the user is also informed about the use of cookies for analysis purposes and their consent is obtained according to Art. 6(1)(a) GDPR for the processing of the personal data used in this context.
A reference to this Privacy Policy is also provided in this regard.
Server Log Files
The provider of the pages automatically collects and stores information in so-called server log files that your browser automatically transmits to us. These include:
- Browser type and browser version
- Used operating system
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources.
The collection of this data is based on Art. 6(1)(f) GDPR.
The website operator has a legitimate interest in the technically error-free display and optimisation of the website – for this purpose, the server log files must be collected.
6. Collection, Storage, and Use of Personal Data
We process personal data of our users primarily to the extent necessary to provide a functional website and our content and services.
The processing of personal data is generally only carried out with the consent of the user.
When you place an order or make an enquiry through our online shop, personal data is collected when you voluntarily provide it to us in order to perform a contract or when creating a customer account.
The legal basis for this is Art. 6(1)(a) GDPR. The personal data transmitted will be used by us for the execution of the resulting contractual relationship and stored in accordance with legal requirements.
The legal basis for the processing and transfer of data is Art. 6(1)(b) GDPR.
Data deletion is possible at any time and can be requested by contacting us.
We will only transfer your personal data if this is necessary for contract execution and permitted within the legal framework or if you explicitly consent.
After the full completion of the contract or deletion of your customer account, your data will be deleted after the expiration of statutory retention periods, especially tax and commercial retention periods, unless you have explicitly consented to further use of your data or a legally permitted further use of the data has been reserved. If the processing of personal data is required to fulfil a legal obligation to which our company is subject, the legal basis for the processing is Art. 6(1)(c) GDPR.
If the processing is necessary to safeguard a legitimate interest of our company or a third party, and the interests, fundamental rights, and freedoms of the data subject do not outweigh the first-mentioned interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.
Order Process
In our online shop, you have the option to place an order either as a guest or by creating a customer account. All data entered by you during the order process will be stored for contract processing. This includes:
- First and last name
- Gender (so we can address you correctly)
- Address, as well as any alternative delivery address
- Payment method and, depending on the selection, payment details
- E-Mail address
- Phone number (for potential follow-up questions)
Customer Account
If you wish to create a customer account in order to place orders without having to re-enter your details each time, you will need to provide the same personal information as required for guest orders. Additionally, you must set a password to protect the customer account. The customer account provides an overview of past orders and active order processes. If you leave the online shop, you will be automatically logged out after 24 hours at the latest.
We are not liable for any misuse of passwords, unless it was caused by us.
You can delete your customer account at any time by sending a request to the contact information provided below.
Contact Form
When you send us inquiries via the contact form, the information you provide in the inquiry form, including the contact details you entered, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in effectively processing the inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if requested. The data you enter in the contact form will remain with us until you request its deletion, revoke your consent for storage, or the purpose for storing the data no longer applies (e.g., after the completion of processing your inquiry). Mandatory legal provisions, particularly retention periods, remain unaffected.
Withdrawal Form
If you use our online withdrawal form, we process the personal data you provide (in particular your first and last name, order number, and email address) in order to process and handle your withdrawal request and, where necessary, to respond to any follow-up questions regarding your withdrawal.
The processing of this data is carried out on the basis of Art. 6(1)(b) GDPR for the performance and administration of the contractual relationship between you and us.
Where statutory retention and documentation obligations apply, the processing is also carried out on the basis of Art. 6(1)(c) GDPR.
The data collected through the withdrawal form will be stored for as long as necessary to process your withdrawal and to comply with statutory retention and documentation requirements.
Once the purpose of processing no longer applies and the applicable retention periods have expired, the data will be deleted.
Your data will only be shared where necessary for the processing of your withdrawal, for compliance with legal obligations, or in connection with the engagement of data processors acting on our behalf.
Inquiries via Email, Phone, or Fax
When you contact us via email, phone, or fax, your inquiry, including all personal data derived from it (such as name, inquiry), will be stored and processed for the purpose of handling your request.
We do not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures.
In all other cases, the processing is based on our legitimate interest in effectively processing the inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if requested.
The data you send us via contact inquiries will remain with us until you request its deletion, revoke your consent for storage, or the purpose for storing the data no longer applies (e.g., after the completion of processing your request).
Mandatory legal provisions, particularly legal retention periods, remain unaffected.
Newsletter
If you wish to subscribe to the newsletter offered on the website, we require your email address and information that allows us to verify that you are the owner of the provided email address and that you consent to receiving the newsletter.
No other data is collected, or only voluntarily provided data is collected. This data is used solely for sending the requested information and is not shared with third parties.
The processing of the data entered in the newsletter registration form is based exclusively on your consent (Art. 6 (1)(a) GDPR).
You may revoke the consent given for storing the data, the email address, and its use for sending the newsletter at any time, such as through the “unsubscribe” link in the newsletter.
The lawfulness of data processing carried out prior to the revocation remains unaffected.
The data you provided for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter or until the purpose for storing it ceases to apply.
After unsubscribing from the newsletter, your data will be deleted from the newsletter distribution list.
We reserve the right to delete or block email addresses in our newsletter distribution list at our discretion, as part of our legitimate interest under Art. 6 (1)(f) GDPR.
After unsubscribing from the newsletter distribution list, your email address may be stored on a blacklist with us or with the newsletter service provider to prevent future mailings.
The data from the blacklist is only used for this purpose and will not be merged with other data.
This serves both your interest and our interest in ensuring compliance with the legal requirements for sending newsletters (legitimate interest according to Art. 6 (1)(f) GDPR).
The storage in the blacklist is not time-limited. You may object to the storage if your interests outweigh our legitimate interest.
Newsletter via Brevo
This website uses Brevo for sending newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.
Brevo is a service that can be used, among other things, to organize and analyze the distribution of newsletters.
The data you enter for the purpose of subscribing to the newsletter is stored on the servers of Sendinblue GmbH in Germany.
Data Analysis by Brevo
With the help of Brevo, we are able to analyze our newsletter campaigns. For example, we can determine whether a newsletter message has been opened and which links, if any, have been clicked.
This allows us to identify, among other things, which links are clicked most frequently.
We can also determine whether certain predefined actions were carried out after opening or clicking the newsletter (conversion rate).
For example, we can see whether you made a purchase after clicking on a link in the newsletter.
Brevo also enables us to segment ("cluster") newsletter recipients into different categories.
For example, recipients can be grouped by age, gender, or place of residence.
This allows newsletters to be tailored more effectively to specific target groups.
If you do not wish your activity to be analyzed by Brevo, you must unsubscribe from the newsletter.
We provide a corresponding unsubscribe link in every newsletter message for this purpose.
Detailed information about Brevo's features can be found at the following link:
https://www.brevo.com/de/blog/newsletter-software/.
Legal Basis
Data processing is carried out on the basis of your consent (Art. 6(1)(a) GDPR).
You may withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of any data processing carried out prior to the withdrawal.
Retention Period
The data you provide for the purpose of receiving our newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be removed from the newsletter distribution list after you unsubscribe.
Data stored by us for other purposes remains unaffected.
After you unsubscribe from the newsletter distribution list, your email address may be stored in a blacklist by us or the newsletter service provider if this is necessary to prevent future mailings.
The data contained in the blacklist will be used solely for this purpose and will not be combined with any other data.
This serves both your interests and our interests in complying with the legal requirements for sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR).
Storage in the blacklist is not limited in time.
You may object to this storage if your interests outweigh our legitimate interest.
For further details, please refer to Brevo’s Privacy Policy::
https://www.brevo.com/de/datenschutz-uebersicht/
sowie https://www.brevo.com/de/legal/privacypolicy/.
Whistleblower Channel
Our whistleblower channel offers employees, business partners, and external parties the opportunity to report incidents or misconduct that violate applicable laws or our code of conduct.
Any report submitted will be treated with the utmost confidentiality and will be forwarded directly to the management, with the option to remain completely anonymous if desired.
We take the protection of reports submitted through this channel and the confidentiality of any personal data contained within them very seriously.
Collection and Processing of Personal Data
When submitting a report through our whistleblower channel, we may collect the following personal data:
First name (not mandatory)
Last name (not mandatory)
E-Mail address (not mandatory)
Your relationship with the company
The processing of your personal data is carried out exclusively for the purpose of processing and investigating the reported incident.
Legal Basis for Processing
The processing of your personal data within the whistleblower channel is carried out based on the fulfilment of a legal obligation and/or the legitimate
interest in investigating potential violations of legal or internal regulations.
Data Retention
Your personal data will only be retained for as long as is necessary for the processing of the report.
After this, the data will be securely deleted in accordance with our internal guidelines.
7. Disclosure of Personal Data
Your personal data will not be transmitted to third parties for purposes other than those outlined below. We will only disclose your personal data to third parties if:
- You have explicitly consented to such disclosure pursuant to Article 6(1) sentence 1 lit. a of the GDPR,
- The disclosure is necessary for the establishment, exercise, or defence of legal claims, as per Article 6(1) sentence 1 lit. f of the GDPR,
and there is no reason to believe that you have a prevailing legitimate interest in preventing the disclosure of your data,
- There is a legal obligation to disclose the data, as per Article 6(1) sentence 1 lit. c of the GDPR, or
- The disclosure is legally permissible and necessary for the performance of a contract with you, pursuant to Article 6(1) sentence 1 lit. b of the GDPR.
Disclosure of Personal Data for Order Processing
Shipping
Your personal data will be shared with third-party service providers, specifically with the transport company responsible for delivery, to the extent necessary for the delivery of the goods.
In the case of shipping to a postal station, it may be necessary to provide your email address to the logistics service provider in addition to your shipping address.
Payment Services
We integrate payment services provided by third-party companies on our website.
When you make a purchase from us, your payment data (e.g., name, payment amount, bank account details, credit card number) is processed by the payment service provider for the purpose of payment processing.
The respective contractual and privacy policies of the individual providers apply to these transactions.
The use of payment service providers is based on Art. 6(1)(b) GDPR (performance of a contract) and on our legitimate interest in ensuring a smooth, convenient, and secure payment process (Art. 6(1)(f) GDPR).
Where your consent is requested for certain actions, the legal basis for data processing is Art. 6(1)(a) GDPR; consent may be withdrawn at any time with future effect.
The following payment services/payment service providers are used on this website:
Paypal
The provider of this payment service is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”).
The transfer of data to the United States is based on the European Commission’s Standard Contractual Clauses (SCCs).
Further details can be found here:
https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full
Please refer to PayPal’s Privacy Policy for further details:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
All terms and conditions for the “Pay Later in 30 Days” payment option can be found here:
https://www.paypal.com/de/digital-wallet/bezahlungnach30tagen/terms
For terms for Installment Payment please visit:
https://www.paypal.com/de/digital-wallet/ratenzahlung/terms
Apple Pay
The provider of this payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple’s Privacy Policy can be found at:
https://www.apple.com/legal/privacy/de-ww/.
Google Pay
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google’s Privacy Policy can be found here:
https://policies.google.com/privacy.
Klarna
The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter referred to as “Klarna”). Klarna offers various payment options (e.g., installment payments).
If you choose to pay using Klarna (Klarna Checkout solution), Klarna will collect various personal data from you.
Klarna uses cookies to optimize the use of the Klarna Checkout solution.
Details regarding the use of Klarna cookies can be found at the following link:
https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
Further details can be found in Klarna’s Privacy Policy at the following link:
https://www.klarna.com/de/datenschutz/.
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter referred to as “Mastercard”).
Mastercard may transfer data to its parent company in the United States. The transfer of data to the United States is based on Mastercard’s Binding Corporate Rules (BCRs).
Further details can be found here:
https://www.mastercard.de/de-de/datenschutz.html and
https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter referred to as “VISA”).
The United Kingdom is considered a secure third country under data protection law. This means that the United Kingdom provides a level of data protection equivalent to that of the European Union.
VISA may transfer data to its parent company in the United States. The transfer of data to the United States is based on the European Commission’s Standard Contractual Clauses (SCCs).
Further details can be found here:
https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zuzustandigkeitsfragen-fur-den-ewr.html.
For further information, please refer to VISA’s Privacy Policy:
https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
Nexi
Payments made by credit card in our online shop are processed by the payment service provider Nexi Germany GmbH, Helfmann-Park 7, 65760 Eschborn.
Nexi processes the personal data required for payment execution on its own responsibility, in particular for the purposes of payment processing, fraud prevention, risk management and compliance with legal obligations (e.g. money laundering prevention).
The legal basis is Art. 6 (1) (b) GDPR (contract performance) and, where relevant, Art. 6 (1) (c) GDPR (legal obligations).
Nexi acts as an independent controller, not as a processor.
You can therefore assert your data subject rights (information, correction, deletion, restriction, objection, data portability) directly against Nexi.
Further information can be found in Nexi's privacy policy at https://www.nexigroup.com/de/datenschutzrichtlinie.
Please note that when making payments via Nexi, the name ‘Nexi Germany GmbH’ may appear on your bank statement.
8. Plug-ins und Tools
Google Maps
This website uses the Google Maps mapping service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of this service, we can integrate map material into our website.
To use the functions of Google Maps, it is necessary to store your IP address.
This information is generally transferred to a Google server in the United States and stored there.
The provider of this website has no influence over this data transfer.
If Google Maps is activated, Google may use Google Fonts for the purpose of displaying fonts consistently.
When you access Google Maps, your browser loads the required web fonts into its browser cache in order to display text and fonts correctly.
The use of Google Maps is in the interest of providing an attractive presentation of our online services and making the locations specified on our website easy to find.
This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG.
Consent may be withdrawn at any time.
The transfer of data to the United States is based on the European Commission's Standard Contractual Clauses (SCCs). Further details can be found here:
https://privacy.google.com/businesses/gdprcontrollerterms/ and
https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
For more information on how Google handles user data, please refer to Google's Privacy Policy:
https://policies.google.com/privacy?hl=en.
The company is certified under the EU–US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Analytics
This website uses functions of the web analytics service Google Analytics.
The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors.
In doing so, the website operator receives various usage data, such as page views, time spent on the website, operating systems used, and the user's origin.
This data is assigned to the respective user's device. It is not linked to a user ID.
Google Analytics uses technologies that enable the recognition of users for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting).
The information collected by Google about the use of this website is generally transferred to a Google server in the United States and stored there.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
You may withdraw your consent at any time.
The transfer of data to the United States is based on the European Commission's Standard Contractual Clauses (SCCs). Further details can be found here:
https://business.safety.google/adscontrollerterms/sccs/.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that enables us to integrate tracking, analytics, and other technologies into our website.
Google Tag Manager itself does not create user profiles, store cookies, or perform any independent analyses.
It merely serves to manage and deploy the tools integrated through it.
However, Google Tag Manager does collect your IP address, which may also be transferred to Google's parent company in the United States.
The use of Google Tag Manager is based on Art. 6(1)(f) GDPR.
The website operator has a legitimate interest in the fast and straightforward integration and management of various tools on the website.
Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), insofar as the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG.
Consent may be withdrawn at any time.
The company is certified under the EU–US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780
9. Our Services
Handling of Applicant Data
We offer you the opportunity to apply for a position with us (e.g., by email or post).
Below, we inform you about the scope, purpose, and use of the personal data collected during the application process.
We assure you that your data will be collected, processed, and used in accordance with the applicable data protection laws and all other legal requirements and will be treated with the strictest confidentiality.
Scope and Purpose of Data Collection
If you submit an application to us, we process the personal data associated with your application (e.g., contact and communication details, application documents, notes taken during interviews, etc.) insofar as this is necessary for deciding whether to establish an employment relationship.
The legal basis for this processing is Section 26 of the German Federal Data Protection Act (BDSG) (initiation of an employment relationship), Art. 6(1)(b) GDPR (pre-contractual measures), and—where you have given your consent—Art. 6(1)(a) GDPR. You may withdraw your consent at any time.
Your personal data will only be shared within our company with persons who are involved in processing your application.
If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Section 26 BDSG and Art. 6(1)(b) GDPR for the purpose of carrying out the employment relationship.
Data Retention Period
If we are unable to offer you a position, if you decline a job offer, or if you withdraw your application, we reserve the right to retain the data you have submitted for up to six months after the completion of the application process (rejection or withdrawal of the application), based on our legitimate interests (Art. 6(1)(f) GDPR).
After this period, the data will be deleted and any physical application documents will be destroyed.
This retention serves in particular as evidence in the event of a legal dispute.
If it is apparent that the data will be required beyond the six-month retention period (e.g., due to a pending or anticipated legal dispute), deletion will only take place once the purpose for the extended retention no longer applies.
A longer retention period may also apply if you have given your consent (Art. 6(1)(a) GDPR) or if statutory retention obligations prevent deletion.
10. Social Media
You can find all the details about our social media presence here.
11. Data Security
We take precautions to protect your data and to prevent misuse from external sources, safeguarding your data against accidental or intentional manipulation, complete destruction, or access by unauthorised persons. Data transmission on the internet is encrypted. Our security measures are regularly reviewed and updated in line with technological developments. Measures such as encryption (SSL encryption), firewalls, anti-hacking programs, and manual security precautions are applied. If encryption is not active, you should carefully consider whether you still wish to send sensitive information over the internet. You can check whether encryption is active by looking for the lock symbol at the bottom of your browser or if the address begins with "https://".
Data transmission is only SSL-encrypted when you use the online contact form on our website, but not when you use your own email address to send your application by email. In such cases, your personal email settings or those of your email provider apply.
12. Rights of the Data Subject
You have the right to:
-
According to Art. 15 GDPR, request information about your personal data processed by us.
In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned retention period, the existence of a right to rectification, erasure, restriction of processing, or objection, the existence of a right to lodge a complaint, the origin of your data, if it was not collected by us, as well as the existence of automated decision-making, including profiling, and, if applicable, meaningful information about the details of such processing;
- According to Art. 16 GDPR, request the correction of inaccurate or the completion of your personal data stored by us without undue delay;
- According to Art. 17 GDPR, request the erasure of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for the fulfilment of a legal obligation, for reasons of public interest, or for the establishment, exercise, or defence of legal claims;
-
According to Art. 18 GDPR, request the restriction of the processing of your personal data, insofar as the accuracy of the data is contested by you, the processing is unlawful, but you oppose its erasure, and we no longer need the data, but you require it for the establishment, exercise, or defence of legal claims, or you have objected to the processing according to Art. 21 GDPR;
-
According to Art. 20 GDPR, receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format, or request its transmission to another controller;
-
According to Art. 7(3) GDPR, withdraw your consent once given at any time. This will result in the future cessation of the data processing based on that consent;
- According to Art. 77 GDPR, lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or place of work, or the location of our company headquarters.
13. Right of withdrawal
If your personal data is processed based on legitimate interests according to Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to object to the processing of your personal data according to Art. 21 GDPR, provided that there are reasons arising from your particular situation, or if the objection is directed against direct marketing. In the latter case, you have a general right to object, which will be implemented by us without the need to specify a particular situation. If you wish to exercise your right of withdrawal or objection, simply send an email to our Data Protection Officer: Claus Nagel-Piciorus,datenschutz@nagel-kollegen.de
14. Currency and Amendments to this Privacy Policy
This privacy policy is currently valid. Due to the ongoing development of our website and services or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy.
Data privacy Social Media
Data privacy Social Media
The following privacy information applies to our social media presence on the following platforms:
Facebook
https://www.facebook.com/feiler.de/
https://www.instagram.com/feilergermany/
https://www.instagram.com/feilermini/
YouTube
https://www.youtube.com/ErnstFeilerGmbH/
https://www.linkedin.com/company/feilergermany/
Data Processing Through Social Networks
We maintain publicly accessible profiles on social networks. The individual social networks we use are listed below.
Social networks such as Facebook, X, and others can generally analyze your user behavior comprehensively when you visit their website or a website that incorporates social media content (e.g., Like buttons or advertising banners).
Visiting our social media pages triggers numerous data processing operations relevant under data protection law. Specifically:
If you are logged into your social media account and visit one of our social media pages, the operator of the respective social media platform may associate your visit with your user account.
However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media platform.
In such cases, data collection may occur, for example, through cookies stored on your device or by recording your IP address.
Using the data collected in this way, the operators of the social media platforms can create user profiles containing your preferences and interests.
This enables interest-based advertising to be displayed both on and outside the respective social media platforms.
If you have an account with the relevant social network, interest-based advertising may be displayed on all devices on which you are or have been logged in.
Please also note that we cannot track all processing activities carried out by the social media platforms.
Depending on the provider, additional processing operations may therefore be carried out by the operators of the respective social media platforms.
Further details can be found in the terms of use and privacy policies of the respective social media platforms.
Legal Basis
Our social media presence is intended to ensure the broadest possible visibility on the internet.
This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.
The analysis processes initiated by the social networks may be based on different legal grounds specified by the operators of the respective social networks (e.g., consent within the meaning of Art. 6(1)(a) GDPR).
Controller and Exercise of Your Rights
When you visit one of our social media pages (e.g., Facebook), we and the operator of the respective social media platform are jointly responsible for the data processing operations triggered during your visit.
In principle, you may exercise your rights (right of access, rectification, erasure, restriction of processing, data portability, and the right to lodge a complaint) both against us and against the operator of the respective social media platform (e.g., Facebook).
Please note that, despite the joint controllership with the operators of the social media platforms, we do not have full influence over the data processing activities carried out by these platforms.
Our ability to influence such processing is largely determined by the corporate policies of the respective provider.
Retention Period
The data collected directly by us via our social media pages will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies.
Stored cookies remain on your device until you delete them.
Mandatory statutory provisions—particularly statutory retention periods—remain unaffected.
We have no influence over the retention period of your data that is stored by the operators of the social networks for their own purposes.
For details, please refer directly to the privacy policies of the respective social network operators (see below).
Your Rights
You have the right at any time to obtain, free of charge, information about the origin, recipients, and purpose of your stored personal data.
You also have the right to object, the right to data portability, and the right to lodge a complaint with the competent supervisory authority.
Furthermore, you may request the rectification, restriction, or deletion of your personal data and, under certain circumstances, the restriction of its processing.
Individual Social Networks
Facebook
We maintain a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (hereinafter referred to as "Meta").
According to Meta, the data collected is also transferred to the United States and other third countries.
We have entered into a Joint Controller Agreement (Controller Addendum) with Meta.
This agreement defines which data processing activities are the responsibility of us or Meta when you visit our Facebook page.
You can view this agreement at the following link:
https://www.facebook.com/legal/terms/page_controller_addendum.
You can adjust your advertising preferences yourself in your user account. To do so, please click on the following link and log in:
https://www.facebook.com/settings?tab=ads.
The transfer of data to the United States is based on the European Commission's Standard Contractual Clauses (SCCs).
Further details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum and
https://www.facebook.com/help/566994660333381.
Please refer to Facebook's Privacy Policy for further details:
https://www.facebook.com/privacy/policy/.
The company is certified under the EU–US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.
Instagram
We maintain a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
The transfer of data to the United States is based on the European Commission's Standard Contractual Clauses (SCCs).
Further details can be found here:
https://privacycenter.instagram.com/policy/.
The company is certified under the EU–US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452.
YouTube
We maintain a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
For details on how YouTube handles your personal data, please refer to YouTube's Privacy Policy:
https://policies.google.com/privacy?hl=en.
The company is certified under the EU–US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5780.
LinkedIn
We maintain a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.
If you wish to disable LinkedIn advertising cookies, please use the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
The transfer of data to the United States is based on the European Commission's Standard Contractual Clauses (SCCs). Further details can be found here:
https://www.linkedin.com/legal/l/dpa and
https://www.linkedin.com/legal/l/eu-sccs.
For details on how LinkedIn handles your personal data, please refer to LinkedIn's Privacy Policy:
https://www.linkedin.com/legal/privacy-policy.
The company is certified under the EU–US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/5448.
Meta Pixel (formerly Facebook Pixel)
This website uses the Meta Visitor Action Pixel to measure conversions. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
According to Meta, the data collected is also transferred to the United States and other third countries.
This allows the behavior of website visitors to be tracked after they have been redirected to the provider's website by clicking on a Meta advertisement.
This enables the effectiveness of Meta advertisements to be evaluated for statistical and market research purposes and helps optimize future advertising measures.
The data collected is anonymous to us as the operator of this website, meaning we cannot draw any conclusions about the identity of individual users.
However, the data is stored and processed by Meta, making it possible to associate it with the respective Facebook or Instagram user profile.
Meta may use this data for its own advertising purposes in accordance with the Meta Privacy Policy.
This enables Meta to display advertisements on Facebook, Instagram, and other advertising channels. As the website operator, we have no influence over this use of the data.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
You may withdraw your consent at any time.
Where personal data is collected on our website using the tool described above and forwarded to Meta, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, are jointly responsible for this data processing (Art. 26 GDPR).
This joint responsibility is limited exclusively to the collection of the data and its transmission to Meta.
Any processing carried out by Meta after the data has been transferred is not part of the joint responsibility.
The obligations jointly incumbent upon us have been set out in a Joint Controller Agreement. The text of this agreement is available at:
https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for providing the required privacy information when using the Meta tool and for implementing the tool on our website in compliance with applicable data protection laws.
Meta is responsible for the security of Meta products.
You may exercise your data subject rights (e.g., requests for access) regarding data processed by Facebook or Instagram directly with Meta.
If you exercise your data subject rights with us, we are obliged to forward your request to Meta.
The transfer of data to the United States is based on the European Commission's Standard Contractual Clauses (SCCs). Further details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum
and
https://www.facebook.com/help/566994660333381
For further information on how Meta protects your privacy, please refer to the Meta Privacy Policy:
https://www.facebook.com/privacy/policy/
You can also disable the Custom Audiences remarketing feature in your advertising settings at:
https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.
To do so, you must be logged in to Facebook.
If you do not have a Facebook or Instagram account, you can disable interest-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance:
http://www.youronlinechoices.com/
The company is certified under the EU–US Data Privacy Framework (DPF).
The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing carried out in the United States.
Every company certified under the DPF is committed to complying with these data protection standards.
Further information is available from the provider at the following link:
https://www.dataprivacyframework.gov/participant/4452