Privacy policy
Privacy Policy
1) Introduction and Contact Details of the Controller
1.1
We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data means all data by which you can be personally identified.
1.2
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
LU REN GmbH
Thuillestrasse 50
81247 Munich
Germany
Phone: +49 8152 99 81 396
Email: sales-marketing@lu-ren.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
2) Data Collection When Visiting Our Website
2.1 Server Log Files
When you use our website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called “server log files”).
When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
-
Visited website
-
Date and time of access
-
Amount of data transferred in bytes
-
Source/reference from which you accessed the page
-
Browser used
-
Operating system used
-
IP address used (possibly in anonymized form)
Processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.
The data will not be disclosed or otherwise used. However, we reserve the right to subsequently review the server log files if there are concrete indications of unlawful use.
2.2 SSL/TLS Encryption
For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries), this website uses SSL or TLS encryption.
You can recognize an encrypted connection by the “https://” address line and the lock symbol in your browser.
3) Hosting & Content Delivery Network
Shopify
For hosting our website and displaying page content, we use the services of:
Shopify International Limited
Victoria Buildings, 2nd Floor
1-2 Haddington Road
Dublin 4, D04 XN32
Ireland
Data may also be transferred to:
Shopify Inc.
150 Elgin Street
Ottawa, ON K2P 1L4
Canada
All data collected on our website is processed on the provider’s servers.
We have concluded a Data Processing Agreement (DPA) with the provider that ensures the protection of our website visitors’ data and prohibits unauthorized disclosure to third parties.
For transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies. Cookies are small text files stored on your device.
Some cookies are automatically deleted after you close your browser (“session cookies”), while others remain on your device for a longer period and enable the storage of page settings (“persistent cookies”).
In the case of persistent cookies, the storage duration can be found in your browser’s cookie settings.
Where personal data is processed through cookies used by us, processing takes place:
-
pursuant to Art. 6(1)(b) GDPR for the performance of a contract,
-
pursuant to Art. 6(1)(a) GDPR based on your consent, or
-
pursuant to Art. 6(1)(f) GDPR based on our legitimate interests in ensuring optimal website functionality and a user-friendly and effective website experience.
You can configure your browser to notify you when cookies are set and decide individually whether to accept them, or exclude the acceptance of cookies for specific cases or in general.
Please note that if cookies are not accepted, the functionality of our website may be limited.
5) Contacting Us
5.1 Shopify Inbox
This website uses the live chat system of the following provider:
Shopify International Limited
Victoria Buildings, 2nd Floor
1-2 Haddington Road
Dublin 4, D04 XN32
Ireland
Personal data transmitted via the chat is processed either in accordance with Art. 6(1)(b) GDPR, where it is necessary for the initiation or performance of a contract, or in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in providing effective support to visitors of our website.
The data transmitted in this manner will be deleted once the matter concerned has been conclusively resolved, unless statutory retention obligations require otherwise.
In addition, further information may be collected and analyzed through cookies for the purpose of creating pseudonymized user profiles. This information does not serve to personally identify you and is not merged with other datasets. Where such information constitutes personal data, processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization purposes.
The setting of cookies can be prevented through appropriate browser settings. However, in this case the functionality of our website may be restricted.
You may object at any time with future effect to the collection and storage of data for the purpose of creating pseudonymized user profiles.
Data may also be transferred to:
Shopify Inc.
150 Elgin Street
Ottawa, ON K2P 1L4
Canada
We have concluded a Data Processing Agreement with the provider to ensure the protection of our visitors’ data and to prevent unauthorized disclosure to third parties.
For transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
5.2 Contact Form and Email Contact
When contacting us (e.g., via contact form or email), personal data is processed exclusively for the purpose of handling and responding to your request and only to the extent necessary for that purpose.
The legal basis for processing this data is our legitimate interest in responding to your inquiry pursuant to Art. 6(1)(f) GDPR.
If your inquiry is related to the conclusion of a contract, the additional legal basis is Art. 6(1)(b) GDPR.
Your data will be deleted once the circumstances indicate that the matter has been conclusively resolved, provided that no statutory retention obligations prevent deletion.
6) Data Processing When Opening a Customer Account
Pursuant to Art. 6(1)(b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide such data when opening a customer account.
The data required for account registration can be found in the respective input form on our website.
You may request the deletion of your customer account at any time by sending a message to the controller at the contact details provided above.
After deletion of your customer account, your data will be deleted provided that all contracts concluded through the account have been fully performed, no statutory retention obligations apply, and we have no legitimate interest in retaining the data.
7) Use of Customer Data for Direct Advertising
7.1 Subscription to Our Email Newsletter
If you subscribe to our email newsletter, we will regularly send you information about our offers.
The only mandatory information required for receiving the newsletter is your email address. The provision of additional data is voluntary and is used to address you personally.
We use the double opt-in procedure for newsletter subscriptions. This means that we will only send newsletters after you have expressly confirmed your consent by clicking a verification link sent to the email address provided.
By activating the confirmation link, you consent to the use of your personal data pursuant to Art. 6(1)(a) GDPR.
We store your IP address as recorded by your Internet Service Provider (ISP), as well as the date and time of registration, in order to be able to trace any possible misuse of your email address at a later date.
The data collected for newsletter registration is used strictly for the intended purpose.
You may unsubscribe from the newsletter at any time via the unsubscribe link provided in each newsletter or by contacting us directly.
Upon unsubscribing, your email address will be removed from our mailing list without undue delay, unless you have expressly consented to further use of your data or we reserve the right to further use your data as permitted by law.
7.2 Klaviyo
Our email newsletters and other marketing emails are sent via:
Klaviyo, Inc.
125 Summer Street, Suite 600
Boston, MA 02110
USA
Based on our legitimate interest in effective and user-friendly email marketing, we transfer the data provided during newsletter registration to Klaviyo pursuant to Art. 6(1)(f) GDPR.
Subject to your explicit consent pursuant to Art. 6(1)(a) GDPR, Klaviyo may also perform statistical analyses of newsletter campaigns using web beacons or tracking pixels to measure open rates and interactions with newsletter content.
Device information (such as IP address, browser type, operating system, and access time) may also be collected and analyzed but will not be merged with other datasets.
You may revoke your consent to email tracking at any time with future effect.
We have concluded a Data Processing Agreement with Klaviyo.
Klaviyo participates in the EU-U.S. Data Privacy Framework.
7.3 Mailchimp
Our newsletters may also be sent through:
The Rocket Science Group LLC d/b/a Mailchimp
675 Ponce de Leon Avenue NE
Suite 5000
Atlanta, GA 30308
USA
Mailchimp processes newsletter subscriber data in accordance with Art. 6(1)(f) GDPR for the purpose of delivering newsletters on our behalf.
Subject to your consent pursuant to Art. 6(1)(a) GDPR, Mailchimp may evaluate newsletter performance through tracking technologies such as web beacons and tracking pixels.
You may withdraw your consent to tracking at any time.
We have entered into a Data Processing Agreement with Mailchimp.
Mailchimp participates in the EU-U.S. Data Privacy Framework.
7.4 Shopify Email
Our newsletters may also be sent through:
Shopify International Limited
Victoria Buildings, 2nd Floor
1-2 Haddington Road
Dublin 4, D04 XN32
Ireland
Data may also be transferred to:
Shopify Inc.
150 Elgin Street
Ottawa, ON K2P 1L4
Canada
Newsletter registration data is processed on the basis of Art. 6(1)(f) GDPR for the purpose of delivering newsletters.
Subject to your consent pursuant to Art. 6(1)(a) GDPR, Shopify Email may also evaluate newsletter performance through tracking technologies and statistical analyses.
You may revoke your consent to tracking at any time.
We have entered into a Data Processing Agreement with Shopify.
For transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
8) Data Processing for Order Fulfilment
8.1 General Information
To the extent necessary for contract performance, personal data collected by us will be transferred to the commissioned shipping provider and payment service provider in accordance with Art. 6(1)(b) GDPR.
If we owe updates for goods with digital elements or digital products, we will process the contact information provided during the order process to inform you personally about legally required updates in accordance with Art. 6(1)(c) GDPR.
Your contact data will be used exclusively for this purpose and only to the extent necessary.
For order processing, we also cooperate with service providers who assist us in fulfilling contractual obligations. Personal data may be transferred to such providers as required.
8.2 Use of Payment Service Providers
Google Pay
If you choose the payment method Google Pay, offered by Google Ireland Limited, Gordon House, 4 Barrow Street, Dublin, D04 E5W5, Ireland (“Google”), payment processing is carried out via the Google Pay application on your mobile device running at least Android 4.4 (“KitKat”) and equipped with NFC functionality by charging a payment card stored in Google Pay or another payment system verified there (e.g. PayPal).
To authorize a payment via Google Pay exceeding EUR 25.00, your mobile device must first be unlocked using the verification method configured on the device (e.g. facial recognition, password, fingerprint, or pattern).
For the purpose of payment processing, the information provided during the ordering process, together with information regarding your order, will be transmitted to Google.
Google then transmits the payment information stored in Google Pay to the merchant website in the form of a unique transaction number, which is used to verify the completed payment.
This transaction number contains no information regarding the actual payment details of the payment method stored in Google Pay but is generated and transmitted as a one-time valid numerical token.
For all transactions via Google Pay, Google acts solely as an intermediary for payment processing.
Where personal data is processed as part of these transfers, processing takes place exclusively for payment processing purposes in accordance with Art. 6(1)(b) GDPR.
Google reserves the right to collect, store, and evaluate certain transaction-specific information for each Google Pay transaction. This may include:
-
Date, time, and amount of the transaction
-
Merchant location and description
-
Description of purchased goods or services
-
Photos attached to the transaction
-
Name and email address of buyer and seller
-
Payment method used
-
User description of the transaction
-
Related offers or promotions
According to Google, such processing is carried out pursuant to Art. 6(1)(f) GDPR based on Google's legitimate interests in proper accounting, transaction verification, and service optimization.
Google may also combine transaction data with information collected through other Google services.
Further information can be found in Google's privacy and Google Pay policies.
Klarna
This website offers one or more payment methods provided by:
Klarna Bank AB
Sveavägen 46
111 34 Stockholm
Sweden
If you select a payment method requiring advance payment (e.g. credit card payment), the payment data provided during checkout (including name, address, banking and card details, currency, and transaction number) as well as order information will be transferred to Klarna in accordance with Art. 6(1)(b) GDPR.
If you select a payment method where Klarna assumes financial risk (such as invoice purchase, installment payments, or direct debit), you may be asked to provide additional personal information, including:
-
First and last name
-
Address
-
Postal code and city
-
Date of birth
-
Email address
-
Telephone number
-
Alternative payment information where applicable
To protect our legitimate interest in assessing customers’ creditworthiness, such data may be transmitted to Klarna for credit assessment purposes pursuant to Art. 6(1)(f) GDPR.
Klarna evaluates whether the selected payment option can be granted based on the information provided, order history, shopping basket value, and payment experience.
The credit assessment may include probability values ("credit scores") calculated using scientifically recognized statistical methods.
You may object to this processing at any time. However, Klarna may remain entitled to process your data where required for contractual payment processing.
PayPal
This website offers one or more payment methods provided by:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
When selecting a PayPal payment method, payment information required for processing your transaction is transferred to PayPal pursuant to Art. 6(1)(b) GDPR.
Where PayPal assumes financial risk (e.g. invoice purchase, direct debit, installment payment), additional personal information may be collected and evaluated for creditworthiness assessment purposes.
PayPal may obtain information from credit agencies and calculate score values to determine payment default risks.
You may object to such processing at any time, although PayPal may continue processing where required for contractual payment execution.
PayPal Checkout
This website uses PayPal Checkout, an online payment solution that includes PayPal payment methods as well as local third-party payment methods.
Depending on the selected payment option, payment data may be transferred to PayPal and subsequently to the relevant local payment provider.
Available providers may include:
-
Apple Pay
-
Google Pay
-
iDEAL
-
Bancontact
-
BLIK
-
EPS
-
MyBank
-
Przelewy24
Data processing is carried out in accordance with Art. 6(1)(b) GDPR for payment execution.
Where applicable, PayPal may perform creditworthiness checks in accordance with Art. 6(1)(f) GDPR.
Further information can be found in PayPal’s Privacy Policy.
Shopify Payments
This website offers payment methods provided by:
Shopify International Limited
Victoria Buildings
1-2 Haddington Road
Dublin 4, D04 XN32
Ireland
If you select a payment method processed through Shopify Payments, payment information necessary for the transaction will be transferred to Shopify in accordance with Art. 6(1)(b) GDPR.
The transfer is limited to the extent necessary for payment processing.
8.3 Electronic Withdrawal Function
Consumers who conclude contracts via this website and are entitled to a statutory right of withdrawal may submit their withdrawal electronically through our online withdrawal function.
For this purpose, we use a solution provided by:
247APPS UG (haftungsbeschränkt)
In der Goldgrube 28
56073 Koblenz
Germany
When using the withdrawal function, personal information such as:
-
Name
-
Email address
-
Contract identification details
must be provided or confirmed.
The provider initially processes this information pursuant to Art. 6(1)(f) GDPR based on our legitimate interest in offering a user-friendly, stable, and optimized withdrawal process.
The provider confirms receipt of the withdrawal declaration on our behalf and subsequently forwards the information to us.
We process the transmitted data pursuant to Art. 6(1)(b) and Art. 6(1)(c) GDPR for the lawful handling of withdrawal requests.
The provider routinely deletes the data once the withdrawal process has been completed, unless statutory retention obligations require otherwise.
We have concluded a Data Processing Agreement with the provider.
9) Web Analytics Services
9.1 Google Analytics 4
This website uses Google Analytics 4, a web analytics service provided by:
Google Ireland Limited
Gordon House
4 Barrow Street
Dublin D04 E5W5
Ireland
Google Analytics 4 uses cookies and similar technologies to analyze how visitors use our website.
Information collected may include:
-
IP address (shortened before storage)
-
Device information
-
Browser information
-
Website interactions
-
Usage behavior
Google processes this information on our behalf to generate reports about website usage and provide additional services related to website activity.
The shortened IP address transmitted by your browser is not merged with other Google data.
Data collected through Google Analytics 4 is retained for two months and then deleted.
All processing activities described above are carried out only with your explicit consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time through the cookie consent tool available on our website.
We have entered into a Data Processing Agreement with Google.
Google participates in the EU-U.S. Data Privacy Framework.
Demographic Characteristics
Google Analytics 4 may use the "Demographic Characteristics" feature to generate statistical information regarding visitors' age, gender, and interests.
This information is derived from advertising data and third-party information and cannot be assigned to specific individuals.
Google Signals
Google Signals may be used to generate cross-device reports.
If personalized advertising is enabled and your devices are linked to your Google account, Google may analyze user behavior across devices and create conversion models, subject to your consent.
We receive only aggregated statistics and no personally identifiable information.
User IDs
Where enabled, User IDs allow activities and conversions to be analyzed across multiple devices when users log in with the same account.
Such processing occurs only with your consent pursuant to Art. 6(1)(a) GDPR.
9.2 Shopify Analytics
This website uses Shopify Analytics provided by:
Shopify International Limited
Victoria Buildings, 2nd Floor
1-2 Haddington Road
Dublin 4, D04 XN32
Ireland
Data may also be transferred to:
Shopify Inc.
150 Elgin Street
Ottawa, ON K2P 1L4
Canada
Shopify Analytics uses cookies, tracking technologies, and similar tools to collect pseudonymized visitor data, including:
-
IP address
-
Browser information
-
Device information
-
User interactions
-
Heatmap data
-
Session duration
-
Click and scrolling behavior
The purpose is to evaluate website usage statistically and create pseudonymized usage profiles.
The collected data cannot generally be directly linked to a specific individual.
Processing takes place only on the basis of your explicit consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time through the cookie consent tool.
We have entered into a Data Processing Agreement with Shopify.
For transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
10) Retargeting, Remarketing and Conversion Tracking
10.1 Meta Pixel
Within our online offering, we use the Meta Pixel service provided by:
Meta Platforms Ireland Limited
4 Grand Canal Square
Dublin 2
Ireland
When a user clicks on an advertisement placed by us on Facebook and/or Instagram, a parameter is added to the URL of our linked website through Meta Pixel.
This URL parameter is then stored in the user’s browser via a cookie after redirection to our website.
This enables Meta to identify visitors to our website as a target group for advertising purposes (“Ads”). We use the service to display Facebook and/or Instagram advertisements only to users who have shown an interest in our website or who exhibit certain characteristics (e.g. interests in specific topics or products) that we transmit to Meta (“Custom Audiences”).
Meta Pixel also allows us to determine whether users were redirected to our website after clicking on an advertisement and which actions they perform there (“Conversion Tracking”).
The data collected is anonymous to us and does not allow us to identify individual users. However, the data is stored and processed by Meta, enabling a connection to the respective user profile. Meta may use the data for its own advertising purposes.
All processing activities described above, in particular the storage and retrieval of information on the user’s device through cookies, are carried out only with your explicit consent pursuant to Art. 6(1)(a) GDPR.
You may revoke your consent at any time via the cookie consent tool provided on our website.
We have entered into a Data Processing Agreement with Meta.
Meta may transfer data to servers in the United States.
Meta participates in the EU-U.S. Data Privacy Framework.
10.2 Google Ads Conversion Tracking
This website uses the online advertising program Google Ads and, within Google Ads, Conversion Tracking provided by:
Google Ireland Limited
Gordon House
4 Barrow Street
Dublin D04 E5W5
Ireland
We use Google Ads to draw attention to our products and services through advertising on external websites.
Conversion Tracking allows us to determine the effectiveness of individual advertising campaigns.
A conversion tracking cookie is set when a user clicks on a Google Ads advertisement.
These cookies generally expire after 30 days and are not used for personal identification.
If a user visits certain pages of our website and the cookie has not yet expired, Google and we can recognize that the user clicked on the advertisement and was redirected to our website.
Each Google Ads customer receives a different cookie, making cross-site tracking between Google Ads customers impossible.
The information collected through conversion cookies is used to generate conversion statistics for advertisers using Google Ads.
Advertisers receive information about the total number of users who clicked on their advertisement and were redirected to a conversion tracking page. However, they do not receive information that personally identifies users.
All processing activities described above take place only with your explicit consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time through the cookie consent tool.
Google participates in the EU-U.S. Data Privacy Framework.
Further information regarding Google's privacy practices can be found in Google's Privacy Policy.
11) Website Functionalities
11.1 Microsoft Teams
For online meetings, video conferences, and webinars, we use:
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA
The provider processes various categories of personal data depending on the information communicated before or during participation in a meeting.
This may include:
-
Name
-
Email address
-
Telephone number (optional)
-
Password
-
Meeting subject
-
Participant IP address
-
Device information
-
Optional meeting descriptions
-
Audio contributions
-
Video contributions
-
Chat messages
Where processing is necessary for the performance of a contract or pre-contractual measures, the legal basis is Art. 6(1)(b) GDPR.
Where consent has been provided, processing is based on Art. 6(1)(a) GDPR.
Otherwise, processing is based on our legitimate interest in the effective conduct of online meetings pursuant to Art. 6(1)(f) GDPR.
We have entered into a Data Processing Agreement with Microsoft.
Microsoft participates in the EU-U.S. Data Privacy Framework.
11.2 Job Applications by Email
Vacant positions are published on our website and interested applicants may apply by email.
Applicants must provide all information necessary for a proper assessment of their application, including:
-
Name
-
Address
-
Contact information
-
Qualifications
-
Supporting documents
Additional information may be requested depending on the position advertised.
Application data is processed exclusively for recruitment purposes.
The legal basis is Art. 6(1)(b) GDPR and, where applicable in Germany, Section 26(1) BDSG.
Special categories of personal data within the meaning of Art. 9 GDPR may be processed where required by employment law or social security obligations.
If an application is unsuccessful or withdrawn, the application data and correspondence will be deleted no later than six months after completion of the recruitment process unless legal obligations require longer retention.
If an employment relationship is established, the data will be processed for the purpose of carrying out the employment relationship.
12) Tools and Miscellaneous
Cookie Consent Tool
This website uses a cookie consent tool to obtain legally required consent for cookies and cookie-based applications.
The tool is displayed to users when they visit the website and enables them to provide consent through an interactive interface.
Cookies and services requiring consent are activated only after the user has provided the relevant consent.
The tool itself stores cookie preferences using technically necessary cookies.
Personal data is generally not processed for this purpose.
If personal data such as an IP address is processed in connection with storing or documenting cookie preferences, processing is carried out pursuant to Art. 6(1)(f) GDPR based on our legitimate interest in legally compliant consent management.
An additional legal basis is Art. 6(1)(c) GDPR, as we are legally obliged to obtain consent before setting non-essential cookies.
Where required, we have entered into a Data Processing Agreement with the provider.
Further information regarding the operator and settings of the cookie consent tool can be found directly within the tool interface on our website.
13) Rights of Data Subjects
13.1 Your Rights Under Data Protection Law
Applicable data protection law grants you the following rights:
-
Right of access (Art. 15 GDPR)
-
Right to rectification (Art. 16 GDPR)
-
Right to erasure (Art. 17 GDPR)
-
Right to restriction of processing (Art. 18 GDPR)
-
Right to notification (Art. 19 GDPR)
-
Right to data portability (Art. 20 GDPR)
-
Right to withdraw consent (Art. 7(3) GDPR)
-
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
13.2 Right to Object
Where we process your personal data based on our legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing with future effect.
If you exercise your right to object, we will cease processing the affected data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defense of legal claims.
Where personal data is processed for direct marketing purposes, you have the right to object at any time to such processing.
If you object to processing for direct marketing purposes, we will cease processing your personal data for those purposes.
14) Storage Period of Personal Data
The duration of storage of personal data depends on:
-
The applicable legal basis
-
The purpose of processing
-
Statutory retention obligations
Where processing is based on consent pursuant to Art. 6(1)(a) GDPR, the data will be stored until consent is withdrawn.
Where statutory retention periods apply to data processed on the basis of Art. 6(1)(b) GDPR, the data will be routinely deleted after the retention periods expire, provided it is no longer required for contract performance or contract initiation and no legitimate interest in continued storage exists.
Where processing is based on Art. 6(1)(f) GDPR, data will be stored until the data subject exercises the right to object under Art. 21 GDPR, unless compelling legitimate grounds for processing exist.
Where personal data is processed for direct marketing purposes based on Art. 6(1)(f) GDPR, the data will be stored until the data subject exercises the right to object pursuant to Art. 21(2) GDPR.
Unless otherwise stated in this Privacy Policy, stored personal data will be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.