Privacy policy
Privacy Policy, of 14 September 2026
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations as well as this Privacy Policy.
1. Controller and contact
The controller for data processing is:
MBR Skin GmbH
Edelhofweg 8-9
08280 Aue-Bad Schlema
Telefon: +49 3772 39528-0
email: info@mbrskin.com
2. General information and scope
This Privacy Policy applies to the online shop and the website of MBR Skin GmbH (“Website” / “Shop”) as well as to the functions and services associated with them.
“Personal data” means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
When you visit our Website, make a purchase or otherwise communicate with us, we process personal data. We herein below inform you which data we process for which purposes, on which legal basis and for which duration, and which rights you have.
3. Recipients, processing and transfers to third countries
Within our company, only those departments and employees who need your data for the relevant purposes have access to it.
In addition, we disclose personal data to service providers that support us in providing our services (e.g. hosting and shop system, payment processing, shipping and logistics, consent management, customer service, email dispatch and email marketing, web analytics, usage analysis and server-side tagging). Insofar as these service providers process data on our behalf and in accordance with our instructions, we have concluded data processing agreements with them pursuant to Art. 28 GDPR. Individual service providers also process your data for their own purposes as independent controllers, as described in the relevant sections.
Transfers of your data to public authorities or government bodies only take place where required by mandatory legal provisions or on the basis of an official or court order.
Where data is transferred to countries outside the EU or the European Economic Area (EEA), this only occurs if an adequate level of data protection is ensured. We base such transfers on an adequacy decision of the European Commission (e.g. the EU‑U.S. Data Privacy Framework for appropriately certified recipients in the USA) or on appropriate safeguards within the meaning of Art. 46 GDPR, in particular the Standard Contractual Clauses of the European Commission, where applicable supplemented by additional protective measures. You can request a copy of the respective safeguards from us.
4. Hosting and shop system (Shopify)
Our Website and our online shop are hosted on the platform of the provider Shopify. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1‑2 Haddington Road, Dublin 4, D04 XN32, Ireland.
Shopify provides the technical infrastructure through which we operate our Shop (including the provision of the Website, management of products, orders and customer accounts, checkout). In this context, Shopify processes the personal data that arises in connection with visiting and using the shop (e.g. order, contact, usage and access data). A transfer to third countries (including Canada and the USA) may occur; such transfers are safeguarded by the mechanisms described in the section “Recipients, processing and transfers to third countries”.
The legal basis for the use of Shopify is our legitimate interest in the secure and efficient operation of our online shop (Art. 6(1)(f) GDPR) and, insofar as processing is carried out for the performance of contracts, Art. 6(1)(b) GDPR. Insofar as information that is not strictly technically necessary for the operation is stored on or accessed from your end device via the Shop, this only takes place with your consent (Sec. 25(1) TDDDG). We have concluded a data processing agreement with Shopify pursuant to Art. 28 GDPR.
Insofar as Shopify uses data from your interactions with our Shop, with other merchants and with Shopify in order to provide, secure and further develop the platform and its features, Shopify acts as an independent controller. For this processing, Shopify’s own privacy policy applies; you may address requests to exercise your rights in relation to this processing directly to Shopify.
Further information can be found in Shopify’s privacy policy: https://www.shopify.com/legal/privacy.
5. Provision of the Website and server log files
Each time our Website is accessed, information that your browser transmits to the server is automatically collected. This in particular includes:
· the IP address of the requesting end device
· date and time of access
· name and URL of the retrieved file as well as the transferred data volume
· the website from which the access originates (referrer URL)
· the browser used, the operating system and the name of your access provider
This data is technically required to display the Website to you, to ensure stability and security and to ward off attacks. The legal basis is our legitimate interest in the functionality and security of the Website (Art. 6(1)(f) GDPR). We do not combine this data with other data sources to identify you.
6. Cookies and consent management
Our Website uses cookies and similar technologies (e.g. information stored in your browser’s local storage). Cookies are small text files that are stored on your end device. They do not cause any damage and do not contain malware.
We distinguish between technically necessary cookies, which are required for the operation of the Website and the Shop (e.g. shopping cart, login status, security and language settings), and non‑necessary cookies (e.g. for statistics/analytics, marketing and the integration of third‑party content).
Technically necessary cookies are set without consent on the basis of Sec. 25(2) TDDDG; the related processing of personal data is based on Art. 6(1)(f) GDPR and – in the context of contract performance – on Art. 6(1)(b) GDPR. All non‑necessary cookies and technologies are only set or triggered after you have given your consent via our consent banner (Sec. 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR). You can withdraw or adjust your consent at any time with effect for the future by opening the cookie settings again via the link/reference to the cookie settings.
Consent management with Cookiebot. To obtain, manage and document your consents, we use the consent management platform Cookiebot. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark (“Cookiebot”). When you first access our Website, Cookiebot displays the consent banner, blocks cookies and services requiring consent until you have made your selection, and stores your decision so that it can be respected on subsequent page views and demonstrated.
When the banner is loaded, Cookiebot processes the URL of the page accessed, the browser language, your browser’s user agent and your IP address in order to display the banner in the appropriate language and configuration; according to the provider, this data is processed solely to serve the banner and is not retained afterwards. When you give or refuse consent, Cookiebot logs your IP address in truncated form, the date and time, the user agent, the URL from which the consent was submitted, an anonymous, random and encrypted key and your consent state. The key and the consent state are also stored in the cookie “CookieConsent” in your browser, which has a lifetime of up to twelve months.
The legal basis for storing the cookie “CookieConsent” on your end device and accessing it is Sec. 25(2) no. 2 TDDDG; the storage is strictly necessary in order to respect your cookie selection on subsequent page views and therefore does not require consent. The legal basis for logging your consent decision is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) and Art. 5(2) GDPR; we thereby fulfil our obligation to be able to demonstrate the consents given. Insofar as we additionally use the logs to establish, exercise or defend legal claims, this is based on our legitimate interest in legally secure documentation of our consent practice (Art. 6(1)(f) GDPR). According to the provider, the consent logs are deleted on an ongoing basis twelve months after collection, and at the latest upon termination of our contract with Cookiebot.
The consent logs are stored in Microsoft data centres within the European Union (Ireland, with failover to the Netherlands). For delivering the consent banner, we use the European variant of Cookiebot’s content delivery network, so that connection data including your IP address is not processed in third countries in this context. Cookiebot acts as our processor; we have concluded a data processing agreement with Usercentrics A/S pursuant to Art. 28 GDPR. Further information can be found in Cookiebot’s privacy policy: https://www.cookiebot.com/en/privacy-policy/.
7. Customer account and registration
You can create a customer account in our Shop. In doing so, we process the data you provide (in particular name, address, email address and login data). The customer account makes ordering and managing your addresses and orders easier for you. The legal basis is Art. 6(1)(b) GDPR (performance of pre‑contractual measures and fulfilment of the contract). Creating a customer account is voluntary; you can also order as a guest.
We process the data stored in the customer account for as long as the account exists and then delete it, subject to statutory retention obligations (see section “Storage period and erasure”). You can request the deletion of your customer account at any time.
8. Order and contract performance
The legal basis for the processing of data required for contract performance (name, address, email address, ordered items, order and transaction data) is Art. 6(1)(b) GDPR. Providing a telephone number is voluntary; if you provide it, we process it to facilitate processing and communication in connection with your order on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Insofar as we retain contract and invoice data due to commercial and tax law obligations, this is based on Art. 6(1)(c) GDPR.
For order processing we transfer data to our shipping service provider, to the carriers UPS and DHL and to the respective payment service provider, insofar as this is necessary for delivering the products and processing the payment. Details can be found in the sections “Shipping (Sendcloud, UPS and DHL)” and “Payment service providers (Shopify Payments, Mollie and PayPal)”.
9. Shipping (Sendcloud, UPS and DHL)
For shipping, we use the shipping software Sendcloud of Sendcloud GmbH, Fürstenrieder Str. 70, 80686 Munich, Germany (“Sendcloud”). Via Sendcloud we create the shipping labels and transmit the shipment data electronically to the carrier commissioned in each case. For this purpose, the data required for shipping is transferred to Sendcloud, in particular name, delivery address, company (if any), order number and shipment data (e.g. weight, dimensions, tracking number), for shipments requiring customs clearance additionally the description and value of the goods, and your email address and telephone number insofar as these are passed on to the carrier under the rules set out below or used by us for our own shipping notifications. The legal basis is Art. 6(1)(b) GDPR.
Sendcloud processes this data exclusively on our behalf and in accordance with our instructions; we have concluded a data processing agreement with Sendcloud pursuant to Art. 28 GDPR. According to Sendcloud, processing takes place in data centres within the EU (Frankfurt am Main and other EU regions). Sendcloud automatically deletes shipment data no later than 365 days and order data no later than 180 days after their creation in the platform, and the history of shipping notifications sent after 90 days; otherwise, we delete data stored there as soon as it is no longer required for the stated purposes and no statutory retention obligations apply. Insofar as we send you shipping notifications with the shipment status and a tracking link by email via Sendcloud in our name, this is based on our legitimate interest in transparent and reliable information about the shipping status (Art. 6(1)(f) GDPR); you may object to this processing at any time in accordance with Art. 21(1) GDPR (see section “Right to object (Art. 21 GDPR)”). For sending these emails, Sendcloud uses email delivery providers as sub-processors; insofar as these are established outside the EU/EEA, the transfer is, according to Sendcloud, safeguarded by the Standard Contractual Clauses of the European Commission (Art. 46(2)(c) GDPR). Further information can be found in Sendcloud’s privacy policy: https://www.sendcloud.com/privacy-policy/.
Delivery is carried out by the carriers commissioned by us, UPS (United Parcel Service Deutschland S.à r.l. & Co. OHG, Görlitzer Straße 1, 41460 Neuss, Germany) and DHL (DHL Paket GmbH, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany). We transfer your name, your delivery address and the shipment data required for delivery to the respective carrier (Art. 6(1)(b) GDPR). If a shipment requires customs clearance, we transfer the information required for this purpose, including your email address and telephone number, to the carrier, which acts as customs declarant in this respect (Art. 6(1)(b) and (c) GDPR). Otherwise, we pass on your email address and telephone number to the carrier only if you have expressly consented to this during the ordering process, so that the carrier can inform you about the delivery or coordinate the delivery date with you (Art. 6(1)(a) GDPR). Giving this consent is voluntary; your order will be delivered without consent as well, and in that case we will inform you about the shipping status ourselves. You can withdraw the consent at any time with effect for the future, either towards us or directly towards the carrier; the lawfulness of processing carried out up to the withdrawal remains unaffected. The carriers are independent controllers for the processing of your data for the purpose of transport and delivery; their privacy notices apply in this respect (UPS: https://www.ups.com/de/de/support/shipping-support/legal-terms-conditions/privacy-notice.page; DHL: https://www.dhl.de/de/toolbar/footer/datenschutz.html).
10. Payment service providers (Shopify Payments, Mollie and PayPal)
For payment processing in our Shop, we use the payment service providers Shopify Payments and Mollie as well as – as an independent payment service provider integrated directly by us – PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg). Which payment service provider processes your payment depends on the payment method you select; credit and debit card payments may be processed either via Shopify Payments or via Mollie, depending on the payment method and availability. You generally enter your payment data directly with the respective payment service provider; we do not receive full card data (in particular the full card number and the card verification code).
Shopify Payments. Shopify Payments is provided by Shopify International Limited (address see section “Hosting and shop system (Shopify)”); in this respect, Shopify processes the payment data on our behalf as a processor. The technical payment processing is carried out by the payment processors engaged by Shopify for Germany. These are currently Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland (“Stripe”), PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, and Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, the Netherlands; which of these payment processors is involved in an individual case depends on the payment method selected. Shopify publishes the current list at https://www.shopify.com/legal/processor-list. The data required for the payment is transferred to the respective payment processor, in particular name, address, email address, payment instrument or card data, invoice amount, currency and transaction number as well as device and connection data such as the IP address (Art. 6(1)(b) GDPR). The payment processors additionally process this data as independent controllers, in particular for fraud prevention and transaction monitoring and to fulfil their own regulatory and anti-money-laundering obligations, for example screening against sanctions and embargo lists; their privacy notices apply in this respect. Further information can be found in Shopify’s Consumer Privacy Policy (https://www.shopify.com/legal/privacy/customers) and in the privacy notices of Stripe (https://stripe.com/privacy), PayPal (https://www.paypal.com/de/legalhub/paypal/privacy-full) and Adyen (https://www.adyen.com/policies-and-disclaimer/privacy-policy).
The following payment methods are currently available via Shopify Payments:
· Credit and debit cards: Visa, Mastercard, American Express, Maestro, UnionPay
· Klarna and Sofortüberweisung (provider: Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden)
· Shop Pay (accelerated checkout by Shopify)
· Apple Pay (provider: Apple)
· Google Pay (provider: Google)
· eps transfer, iDEAL, Bancontact and TWINT
Mollie. Mollie is a payment service of Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, the Netherlands (“Mollie”), a company licensed and supervised as an electronic money institution by the Dutch central bank (De Nederlandsche Bank) under registration number F0038. If you select a payment method offered via Mollie, you will be redirected to Mollie to enter your payment data, or your payment data will be transmitted directly to Mollie. Mollie receives the data required for the payment, in particular your payment data (e.g. card data or bank account details), your name, where applicable your address and email address, order information (amount, currency, order number) as well as your IP address and information about your browser and device. Payment amounts are settled via Stichting Mollie Payments, Keizersgracht 126, 1015 CW Amsterdam, the Netherlands, a foundation established by Mollie that holds the funds collected for merchants separately from the assets of Mollie B.V.; “Mollie” or “Stg Mollie Payments” may therefore appear as the payee on your bank statement. Mollie processes the data for the execution of the payment, for fraud prevention and to fulfil its own legal obligations as an independent controller; Mollie’s privacy statement applies in this respect: https://www.mollie.com/en/privacy. Insofar as Mollie uses recipients outside the EEA, Mollie states that it ensures that an appropriate transfer mechanism is in place, such as the Standard Contractual Clauses of the European Commission.
Card payments (3-D Secure). For card payments, the respective payment service provider uses the 3-D Secure procedure for strong customer authentication. In the process, payment details (e.g. invoice amount and transaction identifier) as well as device and connection data are transmitted to your card-issuing bank, which performs the authentication. The legal basis is Art. 6(1)(b) GDPR and the legitimate interest in secure payment processing and fraud prevention (Art. 6(1)(f) GDPR).
If you pay via PayPal, the data required for processing the payment is transferred to PayPal; details can be found at https://www.paypal.com/de/legalhub/paypal/privacy-full.
The processing of your payment data is carried out for the performance of the contract and the execution of the payment transaction (Art. 6(1)(b) GDPR) and, insofar as it concerns the prevention of fraud and ensuring the security of payments, on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Insofar as we retain payment and transaction data due to commercial and tax law retention obligations, this is based on Art. 6(1)(c) GDPR (see section “Storage period and erasure”). For certain payment methods, the respective provider may carry out a credit check; data processing in this respect is governed by the privacy policy of the respective provider. The respective providers are independently responsible for the processing of data carried out by them; as supervised payment or electronic money institutions, they are subject to their own statutory retention and review obligations (Art. 6(1)(c) GDPR), the duration of which is governed by their own privacy notices.
11. Contacting us
If you contact us by email, telephone or via a contact form, we process the data you provide (e.g. name, contact details, content of the enquiry) in order to process and respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or the implementation of pre‑contractual measures, and otherwise our legitimate interest in handling the enquiry (Art. 6(1)(f) GDPR). The data is deleted once the enquiry has been finally processed, subject to statutory retention obligations.
12. Newsletter and email marketing
You can subscribe to our newsletter, with which we inform you about offers, products and promotions. We use the double opt‑in procedure for registration: After you register, you will receive an email in which we ask you to confirm that you wish to receive the newsletter. This ensures that nobody can register you without your consent. The only mandatory information for sending the newsletter is your email address; further, separately marked details are voluntary.
The legal basis for sending the newsletter is your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 7(2) UWG). To prove registration, we store the time of registration and confirmation as well as the IP address used. The legal basis is our legitimate interest in being able to demonstrate the consent given, since the burden of proof lies with us (Art. 6(1)(f) GDPR in conjunction with Art. 7(1) GDPR). You can withdraw your consent at any time with effect for the future, for example via the unsubscribe link in each newsletter or by sending us a message. The lawfulness of processing carried out up to the withdrawal remains unaffected. After you unsubscribe, we may store your email address in a blocking list in order to reliably prevent future mailings. The legal basis is our legitimate interest in permanently respecting your objection and preventing renewed promotional emails (Art. 6(1)(f) GDPR).
Insofar as we measure opening and click behaviour (success measurement) in connection with the newsletter, this is based on your separate consent. You can withdraw this consent at any time with effect for the future without having to unsubscribe from the newsletter entirely.
Advertising to existing customers: If you have purchased products from us and provided us with your email address in the process, we reserve the right to inform you by email about our own similar products. The basis for this is Sec. 7(3) UWG; no separate consent is required. You may object to this use at any time free of charge, without incurring any costs other than the transmission costs according to the basic tariffs. We draw your attention to the right to object when we collect the email address and in every marketing email.
Newsletter dispatch and marketing automation with Klaviyo. For sending our newsletter and other marketing emails, for managing registrations and consents and for evaluating our email campaigns, we use the marketing platform Klaviyo. The provider is Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02111, USA (“Klaviyo”). In addition to the newsletter, we also use Klaviyo to send automated marketing emails that relate to your behaviour in our shop (e.g. a welcome series after registration, reminders about uncompleted orders or products you have viewed, and messages following a purchase). You will only receive such messages if you have consented to receiving marketing emails or if, as an existing customer, we are permitted to send you advertising for our own similar products in accordance with the provisions above.
Klaviyo processes your email address, your name and the data collected upon registration (time of registration and confirmation, IP address, form used) as well as the status of your consents. Klaviyo is connected to our shop system; through this connection, the master data stored in your customer account or with your orders (name, email address, telephone number, city, postal code and country), your order, shopping cart and shipping data (products ordered, order value, discount codes, order and shipping status) and – only with your consent (see below) – your activities in our shop (pages and products viewed, search queries, products added to the shopping cart) are combined into a customer profile at Klaviyo. We use these profiles to tailor our marketing emails to your interests (e.g. references to products you have viewed or purchased), to form recipient groups (segmentation) and to evaluate the success of our campaigns. From the order and interaction data, Klaviyo also calculates statistical predictive values (e.g. the expected future order value, the probability of a repeat purchase, the expected date of the next order and an estimate of gender derived from the first name), which we use exclusively to select and design our advertising; no decisions producing legal effects concerning you are based on these values.
The legal basis for sending newsletters and other marketing emails is your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 7(2) UWG) or, in the case of existing customers, Sec. 7(3) UWG in conjunction with Art. 6(1)(f) GDPR. We base the combination of your customer and order data in Klaviyo, the segmentation, the personalisation of our advertising and the calculation of the predictive values described above on our legitimate interest in addressing customers in a needs-based and efficient manner (Art. 6(1)(f) GDPR); you may object to this processing at any time in accordance with Art. 21(2) GDPR (see section “Right to object (Art. 21 GDPR)”). Your activities in our shop are recorded (onsite tracking) by means of a script provided by Klaviyo which stores a cookie (“__kla_id”) containing a random identifier in your browser; as soon as you identify yourself via a registration form, a link in one of our emails or during the order process, the activity recorded is assigned to your customer profile. The script is only loaded with your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG); the cookie has a lifetime of up to two years, which may be shorter depending on the browser, and is listed with its storage period in our cookie settings. Opens and clicks in our emails are measured (see above) by means of a counting pixel embedded in the email and links routed via Klaviyo; in this context, Klaviyo processes the time, your IP address and information about your email client or browser.
Recognition of returning visitors (First-Party ID). Browsers store the “__kla_id” cookie only for a limited period; once it has expired, we are initially unable to recognise you on a return visit. In order to be able to recognise you over a longer period and to assign your activities to your customer profile, we use Klaviyo’s “First-Party ID” feature. In this case, a further cookie (“__kle_id”) is not set by the script in your browser but by the response of a server that is accessible under a subdomain of our website; requests to this subdomain are routed through Klaviyo’s infrastructure. Cookies set on the server side are not subject to the lifetime limits that browsers apply to cookies set by scripts; the “__kle_id” cookie therefore has a longer storage period, which is listed in our cookie settings. If the “__kla_id” cookie has expired when you visit us again, it is renewed on the basis of the “__kle_id” cookie; your further activity in our shop is then assigned to your existing customer profile again. The feature serves solely to re-assign already existing profiles; it does not create new profiles, and recognition across devices or browsers does not take place. According to Klaviyo, neither fingerprinting techniques nor IP addresses, device data or browser identifiers (user agent) are evaluated for this purpose. The “__kle_id” cookie is also only set and read with your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG); you can withdraw your consent at any time with effect for the future by calling up your cookie settings again. After a withdrawal and after you delete the cookies in your browser, no further recognition takes place.
Klaviyo processes the data on our behalf; we have concluded a data processing agreement with Klaviyo pursuant to Art. 28 GDPR (available at https://www.klaviyo.com/legal/dpa). The data is stored on Klaviyo's servers in the USA (an Amazon Web Services data centre in the US state of Virginia); our emails are also dispatched via the infrastructure operated there by Klaviyo and its sub-processors. The transfer to the USA is safeguarded by the fact that Klaviyo, Inc. is certified under the EU-U.S. Data Privacy Framework; in addition, Klaviyo has agreed the standard contractual clauses of the European Commission with us (Art. 46(2)(c) GDPR). Your data remains stored at Klaviyo for as long as you receive our newsletter or for as long as we need your customer data for the purposes described; following your withdrawal or objection, we restrict the processing to the blocking list described above and delete the remaining profile data as soon as it is no longer required for the advertising purposes. All data stored at Klaviyo is deleted no later than 90 days after the termination of our contract with Klaviyo. Further information can be found in Klaviyo's privacy notice: https://privacy.klaviyo.com/.
13. Web analytics and marketing (Google Analytics, Google Tag Manager, server-side tagging, Google Ads conversion tracking)
We use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics uses cookies and similar technologies that enable an analysis of your use of the Website (e.g. pages viewed, time spent on pages, approximate location, device used). The information generated thereby is transmitted to servers of Google and processed there. Google Analytics 4 uses IP addresses solely to derive coarse location information; According to Google, storage or logging of full IP addresses does not take place, as IP anonymisation in Google Analytics 4 is active by default and cannot be deactivated. A transfer to third countries (in particular USA) may occur and is safeguarded by the mechanisms described in the section “Recipients, processing and transfers to third countries”.
Google Analytics. We use Google Analytics exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG). The service is only loaded after you have consented via our consent banner. You can withdraw your consent at any time with effect for the future by opening the cookie settings again. We have concluded a data processing agreement with Google pursuant to Art. 28 GDPR. The usage data collected via Google Analytics is automatically deleted after the retention period of 14 months that we have set has expired.
Google Tag Manager. We use Google Tag Manager on our Website. It is used to manage and trigger website tags (e.g. for analytics and marketing services). When Google Tag Manager is loaded, a script is executed on your end device; in the process, your IP address and device information may be transmitted to Google’s servers and a transfer to USA may occur, which is safeguarded by the mechanisms described in the section “Recipients, processing and transfers to third countries”. We use Google Tag Manager exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG); it is only loaded after you have consented via our consent banner. You can withdraw your consent at any time with effect for the future by opening the cookie settings again.
Server-side tagging (Stape). We additionally operate Google Tag Manager as a server-side container (server-side tagging). In this setup, the data on your use of the Website is not transmitted directly from your browser to Google, but is first sent to a tagging server operated on our behalf, which is reachable under a subdomain of our Website, processed there (e.g. filtered and cleaned of information that is not required) and only then forwarded to the Google services described in this section. As the tagging server runs under our own domain, it can also set cookies itself via the server response or extend their lifetime; the cookies used and their storage periods are listed in our cookie settings. The tagging server is operated for us by Stape Europe OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia (“Stape”) on the infrastructure of the European cloud provider Scaleway S.A.S. in a data centre within the EU; only we and Stape have access to the data processed there. On the tagging server, in particular your IP address, your browser’s user agent, the URL accessed and the referrer URL, identifiers from cookies (e.g. the Google Analytics client ID), the event data captured by the tags (e.g. page views, purchases including order value and currency) and the status of your consent are processed. Stape processes this data exclusively on our behalf; we have concluded a data processing agreement with Stape pursuant to Art. 28 GDPR (available at https://stape.io/eu-dpa). Processing on the tagging server takes place within the EU; no transfer to a third country occurs in this respect. The subsequent forwarding to the Google services is safeguarded by the mechanisms described in the section “Recipients, processing and transfers to third countries”. The server logs of the tagging server (operational and error logs) are stored by Stape for a maximum of ten days; the retention periods described for the Google services apply to the event data forwarded to them. We use server-side tagging exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG); data is only sent to the tagging server after you have consented via our consent banner. You can withdraw your consent at any time with effect for the future by opening the cookie settings again; the lawfulness of processing carried out up to the withdrawal remains unaffected. Stape’s privacy notice for its own website can be found at https://stape.io/eu-privacy-notice.
Google Ads conversion tracking. We use the conversion tracking feature of Google Ads. This allows us to evaluate whether users have reached our Website via one of our Google ads and then carried out a predefined action there (e.g. a purchase). For this purpose, a cookie is set once you click on a Google ad; the information generated may be transmitted to Google’s servers – including in USA – and is safeguarded by the mechanisms described in the section “Recipients, processing and transfers to third countries”. We are not able to identify you personally in this context. We use conversion tracking exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG) and have concluded a data processing agreement with Google pursuant to Art. 28 GDPR. You can withdraw your consent at any time with effect for the future by opening the cookie settings again.
We use Google Consent Mode v2 to manage consent. As long as you have not given consent, neither cookies nor data – including cookie-less signals (so-called pings) – are transmitted to our tagging server or to Google; the relevant tags are only triggered after your consent.
Further information on data processing by Google can be found at: https://policies.google.com/privacy.
14. Usage analysis (Microsoft Clarity)
To improve the usability of our shop, we use the analytics service Microsoft Clarity. Our contractual partner is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; the data processing is carried out by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA (together “Microsoft”). Clarity records how visitors use our pages: it captures mouse movements, clicks, scrolling behaviour, time spent, the pages accessed and their structure, and generates session recordings (so-called session replays), heatmaps and analyses of user journeys and drop-offs (e.g. during the order process) from this data. Through the connection to our shop system, events from the order process (e.g. start of the order process, completed order and order value) are also included. We use these analyses – including automated, AI-supported summaries provided by Microsoft – to identify errors and obstacles on our pages and to improve our shop.
For this purpose, Clarity processes a randomly generated, pseudonymous user identifier stored in cookies (in particular “_clck” to recognise your browser on our Website and “_clsk” to combine several page views into one session), your IP address (which Microsoft also uses to determine your approximate location), information about your browser, operating system and end device, the pages accessed and the referring page (referrer) as well as the interaction data described above. In addition, when the service is loaded, Microsoft sets cookies under its own domains (in particular “MUID” and “CLID”) which Microsoft uses to recognise browsers across various Microsoft services. The cookies used and their storage periods are listed in our cookie settings. Entries in form fields and drop-down menus (e.g. in the customer account or during the order process) are not recorded by Clarity but are masked in your browser beforehand; according to our configuration, numbers and email addresses on our pages are also masked before any content is transmitted to Microsoft.
We use Microsoft Clarity exclusively on the basis of your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG). The service is only loaded, and cookies are only set, after you have consented via our consent banner; we transmit your consent status to Microsoft, which sets cookies only where consent has been given. You can withdraw your consent at any time with effect for the future by opening the cookie settings again; the lawfulness of processing carried out up to the withdrawal remains unaffected. Only if you have additionally consented to cookies for marketing purposes does Microsoft also use the data collected via Clarity for its advertising network Microsoft Advertising (e.g. for measuring campaign success and delivering ads); otherwise, according to Microsoft, no disclosure to Microsoft Advertising takes place.
Microsoft does not process the data collected via Clarity on our behalf but as an independent controller for its own purposes, in particular in order to provide the service, to improve its products and services and – within the scope of the consent you have given – to create user profiles, including for advertising purposes. Microsoft's privacy statement applies to this processing (https://privacy.microsoft.com/en-gb/privacystatement); requests to exercise your rights in relation to this processing can be addressed directly to Microsoft. The data is stored in Microsoft's cloud infrastructure; a transfer to the USA takes place in this context, which is safeguarded by the fact that Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework; in addition, the standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR) are in place between Microsoft Ireland Operations Limited and Microsoft Corporation. According to Microsoft, session recordings are stored for 30 days and aggregated click and heatmap data for nine months, and are deleted thereafter.
15. Social media links (Facebook, Instagram, LinkedIn)
On our Website, you will find links to our profiles on the social networks Facebook and Instagram (provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) as well as LinkedIn (provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland). These links are implemented as simple icons; merely accessing our Website does not result in the transmission of personal data to these providers. Only when you click on such an icon will you be redirected to the respective platform. The subsequent processing of your data on the platform is the sole responsibility of the respective provider; its privacy notice applies.
16. Google Maps
We use the Google Maps map service to show you our location, for example, and to make it easier for you to find your way. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). When Google Maps is loaded, a connection to Google’s servers is established, and your IP address and, where applicable, further data are transmitted to Google. Google also processes this data for its own purposes and is therefore an independent controller with respect to such processing; for details, please refer to Google’s privacy policy (https://policies.google.com/privacy). A transfer to Google LLC in USA may occur and is safeguarded by the mechanisms described in the section “Recipients, processing and transfers to third countries”.
Google Maps is only embedded after you have given your consent (Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG). The map is only loaded after you have consented. You can withdraw your consent at any time with effect for the future by opening the cookie settings again.
17. Storage period and erasure
We process and store your personal data only for as long as is necessary to achieve the respective processing purpose or as long as statutory retention obligations require. After the purpose ceases to apply and any retention periods have expired, the data is routinely deleted or its processing is restricted.
For contract, invoice and booking data, statutory commercial and tax retention obligations apply (in particular under the German Commercial Code and the German Fiscal Code) of generally six, eight or ten years; Accounting records such as invoices must, since 1 January 2025, only be retained for eight years. During this period, we restrict processing to the fulfilment of the statutory obligations.
18. Data security
We take appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, manipulation and unauthorised access and continuously adapt these measures to the state of the art.
Our Website uses TLS encryption. Please note that data transmission on the internet (e.g. when communicating by email) can have security gaps; complete protection against access by third parties is not possible.
19. Your rights as a data subject
Under the GDPR, you in particular have the following rights:
· Access (Art. 15 GDPR): You can request information about the personal data we process about you.
· Rectification (Art. 16 GDPR): You can request the correction of inaccurate data or the completion of your data.
· Erasure (Art. 17 GDPR): You can request the deletion of your data, subject to statutory retention obligations.
· Restriction of processing (Art. 18 GDPR): You can request that we restrict the processing of your data.
· Data portability (Art. 20 GDPR): You can request that we provide you with the data concerning you in a structured, commonly used and machine‑readable format or transfer it to another controller.
· Withdrawal of consent (Art. 7(3) GDPR): You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to the withdrawal remains unaffected.
· Objection (Art. 21 GDPR): Under the conditions of Art. 21 GDPR you can object to processing; details can be found in the separate section “Right to object (Art. 21 GDPR)”.
· Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority (see section “Right to lodge a complaint with a supervisory authority”).
To exercise your rights, a simple notification to the contact details above is sufficient.
20. Right to object (Art. 21 GDPR)
Where we process your personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time, on grounds relating to your particular situation. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Where we process your data for direct marketing purposes, you have the right to object to such processing at any time; this also applies to profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, your data will no longer be processed for these purposes.
21. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The following supervisory authority is responsible for MBR Skin GmbH:
The Saxon Commissioner for Data Protection and Transparency
Maternistraße 17, 01067 Dresden, Germany
(Postal address: Postfach 11 01 32, 01330 Dresden)
Telephone: +49 351 85471‑101
Email: post@sdtb.sachsen.de
Internet: http://www.datenschutz.sachsen.de
22. No automated decision‑making
No decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR) takes place. Should individual payment providers use automated procedures in the context of credit checks, they will inform you thereof in their own privacy notices. The predictive values described in the section “Newsletter and email marketing” serve solely to select and design our advertising and have no legal effect on you.
23. Current version and changes to this Privacy Policy
This Privacy Policy reflects the status indicated above. Due to the further development of our Website and our offers or due to changes in legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current Privacy Policy can be accessed on our Website at any time.