Privacy Policy
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data includes all data with which you can be personally identified. Detailed information on the topic of data protection can be found in our privacy policy, which is provided below this text.
Data Collection on this Website
Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the "Notice on the Responsible Entity" section of this privacy policy.
How do we collect your data?
Your data is collected by providing it to us. This could be data you enter into a contact form, for example.
Other data is collected automatically or after your consent during your visit to the website by our IT systems. This primarily includes technical data (e.g., internet browser, operating system, or the time the website is accessed). Data collection occurs automatically when you visit this website.
What do we use your data for?
Some of the data is collected to ensure the error-free operation of the website. Other data may be used to analyze your user behavior.
What rights do you have concerning your data?
You have the right to obtain information at any time about the origin, recipient, and purpose of your stored personal data free of charge. You also have the right to request the correction or deletion of these data. If you have given consent to data processing, you can revoke it at any time with effect for the future. Additionally, you have the right to request the restriction of processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority.
For these and other questions about data protection, you can contact us at any time.
Analytics Tools and Third-Party Tools
When visiting this website, your surfing behavior can be statistically analyzed. This occurs primarily using so-called analytics programs.
Detailed information about these analysis programs can be found in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
External Hosting
This website is hosted externally. The personal data collected on this website is stored on the servers of the hosting provider(s). This mainly includes IP addresses, contact requests, meta and communication data, contract data, contact data, names, website access, and other data generated through a website.
External hosting is done to fulfill contracts with our potential and existing customers (Art. 6(1)(b) GDPR) and to ensure a secure, fast, and efficient provision of our online services through a professional provider (Art. 6(1)(f) GDPR). If specific consent is requested, processing is solely based on Art. 6(1)(a) GDPR and § 25(1) TTDSG, provided the consent involves storing cookies or accessing information on the user's device (e.g., device fingerprinting) in the sense of TTDSG. Consent can be revoked at any time.
Our hosting provider(s) will only process your data to the extent necessary to fulfill their performance obligations and follow our instructions regarding this data.
We use the following hosting provider:
goneo Internet GmbH
Dresdener Str. 18,
32423 Minden
3. General Information and Mandatory Information
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data includes data with which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this occurs.
Please note that data transmission on the internet (e.g., when communicating via email) may have security vulnerabilities. Complete protection of the data from third-party access is not possible.
Notice on the Responsible Entity
The entity responsible for data processing on this website is:
IBO International Brands Online GmbH
Marshallstraße. 1
52146 Würselen
Phone number
e Mail: info(at)international-brands-online.com
The responsible entity is the natural or legal person who, alone or jointly with others, decides the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage Duration
Unless a specific storage duration is mentioned in this privacy policy, your personal data remains with us until the purpose for data processing no longer exists. If you request the deletion of your data or revoke your consent to data processing, we will delete your data unless we have other legally permissible reasons for retaining it (e.g., tax or commercial retention periods). In the latter case, we will delete the data once these reasons no longer apply.
General Information on the Legal Basis for Data Processing on this Website
If you have given consent to data processing, we process your personal data based on Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR if special data categories are processed according to Art. 9(1) GDPR. If there is express consent for transferring personal data to third countries, data processing also occurs based on Art. 49(1)(a) GDPR. If you have given consent to storing cookies or accessing information on your device (e.g., via device fingerprinting), data processing is additionally based on § 25(1) TTDSG. Consent can be revoked at any time. If your data is required to fulfill a contract or for pre-contractual measures, we process your data based on Art. 6(1)(b) GDPR. Additionally, if data processing is required to fulfill a legal obligation, we process your data based on Art. 6(1)(c) GDPR. Data processing can also be based on our legitimate interest according to Art. 6(1)(f) GDPR. Specific information on the applicable legal basis is provided in the following sections of this privacy policy.
Notice on Data Transfer to Non-EU Countries with Lower Data Protection Standards and Transfer to US Companies Not Certified Under DPF
We use, among other things, tools from companies based in non-EU countries with lower data protection standards and US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). If these tools are active, your personal data can be transferred to and processed in these countries. We inform you that countries without comparable data protection standards to the EU do not offer the same data protection level.
We point out that the USA is generally a secure third country with data protection levels comparable to the EU. Data transfer to the USA is permissible if the recipient has certification under the "EU-US Data Privacy Framework" (DPF) or other adequate guarantees. Information on data transfers to third countries, including data recipients, is available in this privacy policy.
Recipients of Personal Data
As part of our business operations, we collaborate with various external entities. This may require transferring personal data to these external entities. We only share personal data with external entities when it is necessary for contract fulfillment, if we are legally obligated (e.g., sharing data with tax authorities), if we have a legitimate interest under Art. 6(1)(f) GDPR, or if another legal basis permits data transfer. When using processors, we only share personal data with valid processing agreements. If processing is shared, a joint processing agreement is established.
Revoking Your Consent to Data Processing
Many data processing operations are only possible with your explicit consent. You can revoke previously granted consent at any time. The legality of the data processing carried out up to the time of revocation remains unaffected.
Right to Object to Data Collection in Specific Cases and Direct Marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS FOR PROCESSING IS PROVIDED IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR DIRECT MARKETING PURPOSES AT ANY TIME; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority
In the event of GDPR violations, affected individuals have the right to lodge a complaint with a supervisory authority, especially in the member state of their usual residence, workplace, or the location of the alleged violation. This right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Right to Data Portability
You have the right to receive data processed automatically based on your consent or to fulfill a contract in a common, machine-readable format. If you request direct transmission of the data to another responsible party, this will only occur if it is technically feasible.
Access, Correction, and Deletion
Within the framework of applicable legal provisions, you have the right at any time to request information about your stored personal data, its origin, recipients, and the purpose of data processing, and the right to request its correction or deletion. For these and other questions on personal data, you can contact us at any time.
Right to Restrict Processing
You have the right to request the restriction of processing of your personal data. You can contact us at any time for this. The right to restrict processing exists in the following cases:
- You have the right to request the restriction of processing of your personal data. You can contact us at any time for this. The right to restrict processing exists in the following cases:
- If the processing of your personal data is or was unlawful, you can request restriction of processing instead of deletion.
- If we no longer need your personal data, but you require it to exercise, defend, or assert legal claims, you have the right to request restriction of processing instead of deletion.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, we need to balance your and our interests. As long as it is not yet clear whose interests prevail, you have the right to request restriction of processing of your personal data.
If processing is restricted, these data—except for storage—may only be processed with your consent or to assert, exercise, or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of significant public interest in the European Union or a member state.
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as orders or inquiries sent to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser's address line changes from "http://" to "https://" and by the padlock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
4. Data Collection on This Website
Cookies
Our websites use so-called "cookies." Cookies are small data packages that do not harm your end device. They are stored either temporarily for the duration of a session (session cookies) or permanently (permanent cookies) on your end device. Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them or they are automatically deleted by your web browser.
Cookies may originate from us (first-party cookies) or third-party companies (so-called third-party cookies). Third-party cookies enable the integration of specific services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or video display). Other cookies can be used to analyze user behavior or for marketing purposes.
Cookies required for electronic communication processes, to provide specific functions requested by you (e.g., shopping cart function), or to optimize the website (e.g., cookies for measuring website traffic) are stored based on Art. 6(1)(f) GDPR, unless another legal basis is indicated. The website operator has a legitimate interest in storing necessary cookies to ensure the technically flawless and optimized provision of its services. If consent for storing cookies and comparable recognition technologies is requested, processing is solely based on that consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG). Consent can be revoked at any time.
You can set your browser to inform you about the setting of cookies, allow cookies only in individual cases, generally exclude the acceptance of cookies, and activate automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
You can find out which cookies and services are used on this website in this privacy policy.
Contact Form
If you send inquiries to us via the contact form, your information from the inquiry form, including the contact data provided, will be stored by us for processing the inquiry and in case of follow-up questions. We do not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR if your inquiry relates to fulfilling a contract or pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if it was obtained; consent can be revoked at any time.
The data entered in the contact form remains with us until you ask us to delete it, revoke your consent for storage, or the purpose for data storage no longer exists (e.g., after completing your inquiry). Mandatory legal provisions—particularly retention periods—remain unaffected.
Inquiries via Email, Phone, or Fax
If you contact us via email, phone, or fax, your inquiry, including all resulting personal data (name, inquiry), is stored and processed for processing your request. We do not share this data without your consent.
The processing of this data is based on Art. 6(1)(b) GDPR if your inquiry relates to fulfilling a contract or pre-contractual measures. In all other cases, processing is based on our legitimate interest in effectively handling inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if it was obtained; consent can be revoked at any time.
The data you send via contact inquiries remains with us until you ask us to delete it, revoke your consent for storage, or the purpose for data storage no longer exists (e.g., after processing your request). Mandatory legal provisions—particularly legal retention periods—remain unaffected.
5. Social Media
X (formerly Twitter)
This website includes features of the X (formerly Twitter) service. These features are offered by the parent company X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. For data processing of non-US residents, the responsible party is Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.
If the social media element is active, a direct connection is established between your device and the X server. X (formerly Twitter) receives information about your visit to this website. Using X (formerly Twitter) and the "Re-Tweet" or "Repost" function, the websites you visit are linked to your X (formerly Twitter) account and made known to other users. Please note that as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by X (formerly Twitter). Further information can be found in the privacy policy of X (formerly Twitter) at: https://twitter.com/en/privacy. https://twitter.com/de/privacy.
The use of this service is based on your consent under Art. 6(1)(a) GDPR and § 25(1) TTDSG. Consent can be revoked at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://gdpr.twitter.com/en/controller-to-controller-transfers.html. https://gdpr.twitter.com/en/controller-to-controller-transfers.html.
Your privacy settings on X (formerly Twitter) can be changed in the account settings at https://twitter.com/account/settings. https://twitter.com/account/settings ändern.
This website includes features of the Instagram service. These features are offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
If the social media element is active, a direct connection is established between your device and the Instagram server. Instagram receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate the visit to this website with your user account. Please note that as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram.
The use of this service is based on your consent under Art. 6(1)(a) GDPR and § 25(1) TTDSG. Consent can be revoked at any time.
To the extent that personal data collected on our website is shared with Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited solely to data collection and its sharing with Facebook or Instagram. Processing after sharing with Facebook or Instagram is not part of the joint responsibility. The obligations assigned to us have been outlined in a joint processing agreement. The text of the agreement can be found here: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook or Instagram tool and for implementing the tool securely on our website. Facebook is responsible for data security concerning Facebook or Instagram products. You can assert data subject rights (e.g., access requests) regarding the data processed by Facebook or Instagram directly with Facebook. If you assert data subject rights with us, we are obligated to forward them to Facebook.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/, and https://de-de.facebook.com/help/566994660333381.
Additional information can be found in the Instagram privacy policy: https://privacycenter.instagram.com/policy/. https://privacycenter.instagram.com/policy/.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA to ensure European data protection standards for data processing in the USA. Each DPF-certified company commits to complying with these data protection standards. More information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participantdetail?contact=true&id=a2zt0000000GnywAAC&status=Active. https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active
6. Plugins and Tools
Google Fonts (Local Hosting)
This site uses Google Fonts, provided by Google, for uniform font representation. Google Fonts are installed locally. No connection to Google servers occurs. Further information about Google Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=en.
Weitere Informationen zu Google Fonts finden Sie unter https://developers.google.com/fonts/faq und in der Datenschutzerklärung von Google: https://policies.google.com/privacy?hl=de.
Google Maps
This site uses the Google Maps mapping service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
To use Google Maps features, your IP address must be stored. This information is typically transferred to a Google server in the USA and stored there. The provider of this page has no influence over this data transfer. If Google Maps is activated, Google may use Google Fonts to ensure uniform font representation. When accessing Google Maps, your browser downloads the required web fonts into its cache to display text and fonts correctly.
The use of Google Maps is based on our interest in presenting our online services attractively and making it easy to locate the places mentioned on our website. This represents a legitimate interest under Art. 6(1)(f) GDPR. If consent was requested for this, processing is based solely on Art. 6(1)(a) GDPR and § 25(1) TTDSG, provided the consent involves storing cookies or accessing information on the user's device (e.g., device fingerprinting) in the sense of TTDSG. Consent can be revoked at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: https://gdpr.twitter.com/en/controller-to-controller-transfers.html. https://privacy.google.com/businesses/gdprcontrollerterms/ und https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
Further information on the handling of user data can be found in Google's privacy policy: https://policies.google.com/privacy?hl=en. https://policies.google.com/privacy?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA to ensure European data protection standards for data processing in the USA. Each DPF-certified company commits to complying with these data protection standards. More information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participantdetail?contact=true&id=a2zt0000000GnywAAC&status=Active. https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Google reCAPTCHA
We use "Google reCAPTCHA" (referred to as "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA is intended to check whether data entry on this website (e.g., in a contact form) is carried out by a human or an automated program. reCAPTCHA analyzes the website visitor's behavior based on various characteristics. This analysis begins automatically as soon as the website visitor enters the site. reCAPTCHA evaluates various information for the analysis (e.g., IP address, the length of time a visitor spends on the site, or mouse movements made by the user). The data collected during the analysis is transmitted to Google.
The reCAPTCHA analysis runs entirely in the background. Website visitors are not informed that the analysis is occurring.
Data storage and analysis are based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website from abusive automated scanning and spam. If specific consent is requested, processing is solely based on Art. 6(1)(a) GDPR and § 25(1) TTDSG, provided the consent involves storing cookies or accessing information on the user's device (e.g., device fingerprinting) in the sense of TTDSG. Consent can be revoked at any time.
Further information about Google reCAPTCHA can be found in Google's privacy policy and Google's terms of use at the following links: https://policies.google.com/privacy?hl=en and https://policies.google.com/terms?hl=en. https://policies.google.com/privacy?hl=de und https://policies.google.com/terms?hl=de.
The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA to ensure European data protection standards for data processing in the USA. Each DPF-certified company commits to complying with these data protection standards. More information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participantdetail?contact=true&id=a2zt0000000GnywAAC&status=Active. https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Source: https://www.e-recht24.de