Privacy Policy / Data Protection Declaration
We, INUVET GmbH (hereinafter: "Inuvet", "we" or "us"), take the protection of your personal data seriously and would like to inform you here about data protection at our company.
As part of our responsibility under data protection law, obligations have been imposed on us, among other things by the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter: "GDPR"), to ensure the protection of personal data of the person affected by processing (we also address you as a data subject hereinafter as "customer", "user", "you", "your" or "data subject").
Insofar as we decide on the purposes and means of data processing either alone or jointly with others, this includes in particular the duty to inform you transparently about the nature, scope, purpose, duration, and legal basis of the processing (cf. Art. 13 and Art. 14 GDPR). With this statement (hereinafter: "Privacy Policy"), we inform you of the manner in which your personal data is processed by us.
1. Definitions
Following the model of Art. 4 GDPR, this Privacy Policy is based on the following definitions:
-
"Personal Data" (Art. 4 No. 1 GDPR) means any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Identifiability can also be established by combining such information or other additional knowledge. The origin, form, or embodiment of the information is irrelevant (photos, video, or audio recordings can also contain personal data).
-
"Processing" (Art. 4 No. 2 GDPR) means any operation or set of operations which is performed on personal data, whether or not by automated (i.e. technology-assisted) means. This includes, in particular, collection (i.e. procurement), recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data, as well as changing a specification of targets or purposes that was originally the basis of data processing.
-
"Controller" (Art. 4 No. 7 GDPR) means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
-
"Third Party" (Art. 4 No. 10 GDPR) means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data; this also includes other legal entities belonging to the group.
-
"Processor" (Art. 4 No. 8 GDPR) means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller, in particular in accordance with its instructions (e.g. IT service providers). In terms of data protection law, a processor is, in particular, not a third party.
-
"Consent" (Art. 4 No. 11 GDPR) of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2. Controller & Contact
2.1 The controller responsible for processing your personal data within the meaning of Art. 4 No. 7 GDPR is us:
INUVET GmbH
Berner Weg 7–25
79539 Lörrach
Germany
-
E-Mail: info@inuvet.com
-
Phone: +49 7621 57915-10
-
Fax: +49 7621 57915-12
2.2 If you wish to assert your rights or have questions or comments regarding the collection and processing of your personal data that this Privacy Policy cannot answer, or if you would like in-depth information on any point, please contact the address stated above.
2.3 Our Data Protection Officer is:
heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, datenschutz@heydata.eu.
3. Data Collection When Contacting Us
3.1 When you contact us by email, phone, via a messenger service, or via a contact form, your email address, name, phone number, and any other personal data provided during the contact will be stored by us so that we can contact you to answer your question.
3.2 We delete this data as soon as storage is no longer required. If legal retention periods exist, the data remains stored, but we restrict its processing.
4. Rights of the Data Subject
You have the following data subject rights:
4.1 Right of Access
-
4.1.1 You have the right to obtain confirmation from us to the extent of Art. 15 GDPR as to whether or not personal data concerning you is being processed.
-
4.1.2 A request from you is required for this, which must be sent either by email or by post to the addresses given above (see 2.1).
4.2 Right to Object to Processing and Revocation of Consent
-
4.2.1 Pursuant to Art. 21 GDPR, you have the right to object at any time to the processing of personal data concerning you. We will stop processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves to establish, exercise, or defend legal claims.
-
4.2.2 Pursuant to Art. 7 (3) GDPR, you have the right to revoke your consent given to us at any time (including prior to the application of the GDPR, i.e., before May 25, 2018) – i.e., your freely given, informed, and unambiguous indication of will expressed by a declaration or other clear affirmative action that you agree to the processing of personal data concerning you for one or more specific purposes. As a result, we may no longer continue the data processing based on this consent in the future.
-
4.2.3 In this regard, please contact the contact point indicated above (see 2.1).
4.3 Right to Rectification and Erasure
-
4.3.1 Insofar as personal data concerning you is inaccurate, you have the right pursuant to Art. 16 GDPR to demand immediate rectification from us. Please send a request in this regard to the contact point specified above (see 2.1).
-
4.3.2 Under the conditions specified in Art. 17 GDPR, you have the right to demand the erasure of personal data concerning you. Please send a request in this regard to the contact point specified above (see 2.1). You have the right to erasure, in particular, if the data in question is no longer necessary for the purposes for which it was collected or processed, if the storage period (see Sec. 6) has expired, if an objection has been lodged (see 4.2), or if unlawful processing has taken place.
4.4 Right to Restriction of Processing
-
4.4.1 In accordance with Art. 18 GDPR, you have the right to demand that we restrict the processing of your personal data.
-
4.4.2 Please send a request in this regard to the contact point specified above (see 2.1).
-
4.4.3 You have the right to restriction of processing, in particular, if the accuracy of the personal data is disputed between you and us; in this case, you have the right for a period enabling us to verify the accuracy. The same applies if the successful exercise of a right to object (see 4.2) is still disputed between you and us. Furthermore, you are entitled to this right in particular if you are entitled to a right to erasure (see 4.3) and you request restricted processing instead of erasure.
4.5 Right to Data Portability
-
4.5.1 In accordance with Art. 20 GDPR, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format.
-
4.5.2 Please send a request in this regard to the contact point specified above (see 2.1).
4.6 Right to Lodge a Complaint with a Supervisory Authority
-
4.6.1 Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority regarding the collection and processing of your personal data.
-
4.6.2 You can reach the competent supervisory authority under the following contact details:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Postfach 10 29 32
70025 Stuttgart, Germany
E-Mail: poststelle@lfdi.bwl.de
5. Purpose of Processing
5.1 We process the personal data specified in detail above in accordance with the provisions of the GDPR, other relevant data protection regulations, and only to the required extent. Insofar as the processing of personal data is based on Art. 6 (1) sentence 1 lit. f GDPR, the stated purposes also represent our legitimate interests.
5.2 Inevitably, we can only provide you with our contractual services if certain personal data required for contract performance and the operation of our online portal is collected when using it.
5.3 We only collect this data if this is necessary for the performance of the contract between you and us (Art. 6 (1) lit. b GDPR). Furthermore, we collect this data if it is necessary for the functionality of the portal or the contractual service and your interest in protecting your personal data does not override this (Art. 6 (1) lit. f GDPR).
5.4 The processing of log data ("server log files") serves statistical purposes and the improvement of the quality of our website, in particular the stability and security of the connection (legal basis is Art. 6 (1) sentence 1 lit. f GDPR).
5.5 Contact form data is processed to handle customer inquiries (legal basis is Art. 6 (1) sentence 1 lit. b or lit. f GDPR).
5.6 Newsletter data is processed for the purpose of sending the newsletter. The remaining provisions regarding the dispatch of our newsletter can be found in Section 8.
5.7 Processing of your personal data for purposes other than those described will only take place insofar as a legal provision permits this or you have consented to the changed purpose of data processing.
5.8 In the event of further processing for purposes other than those for which the data was originally collected, we will inform you about these other purposes prior to further processing and provide you with all other relevant information.
6. Duration of Storage & Erasure
6.1 We delete your personal data as soon as it is no longer required for the purposes for which we collected or used it (see 5.). As a rule, we store your personal data for the duration of the usage or contractual relationship. Your data is generally stored only on our servers in Germany, subject to any transfer in accordance with the provisions in Sections 10–17 and 24–26.
6.2 However, storage may take place beyond the specified time in the event of an (impending) legal dispute with you or other legal proceedings.
6.3 Third parties employed by us (see Sections 8, 10–23, 24–26) will store your data on their systems for as long as is necessary in connection with the provision of the service for us in accordance with the respective order.
6.4 Statutory requirements for the retention and deletion of personal data remain unaffected by the above (e.g., Section 257 HGB or Section 147 AO). When the retention period prescribed by statutory regulations expires, the personal data is blocked or erased unless further storage by us is necessary and there is a legal basis for it.
7. Website Usage & Log Files
When using the website for informational purposes, the following categories of personal data are collected, stored, and further processed by us:
7.1 "Log Files": Our online shop is operated via the Shopify platform, a service of Shopify International Ltd., 2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. Precise information on the use and disclosure of your data by this service can be found in Section 23 of this Privacy Policy. As part of operating our online shop, technical log data is stored by Shopify to ensure the security, stability, and functionality of our web presence. This log data includes in particular:
-
The page from which the file was requested (so-called referrer URL)*
-
Name and URL of the requested page
-
Date and time of access
-
Description of the type, language, and version of the web browser used*
-
IP address of the requesting computer, shortened so that personal reference can no longer be established
-
Volume of data transferred
-
Operating system*
-
Browser type*
-
Status message as to whether access was successful (access status / HTTP status code)
-
GMT time zone difference
-
System and application logs (e.g. technical access, error messages, system events)
-
Store activity logs (e.g. access by apps and users)
*This data is only stored by us if your browser transmits this data to us.
7.2 "Contact Form Data": When using contact forms, the data transmitted thereby is processed (e.g., surname and first name, email address, phone number, and time of transmission).
8. Registration & User Account
8.1 Insofar as you wish to use our services via our online portal, you must register by specifying a valid email address, a password chosen by you, phone number, postal code, country, and your full first and last name, and create a corresponding user account. Providing the aforementioned data is mandatory; all further information can be provided voluntarily by using our online portal.
8.2 When you use our online portal, we store your data required for contract fulfillment, including payment method information, until you permanently delete your access. Furthermore, we store the voluntary data provided by you for the period of your use of the online portal, unless you delete it beforehand. You can manage and change all information in the protected customer area. Legal basis is Art. 6 (1) sentence 1 lit. f GDPR.
8.3 On our online portal, there is the possibility of using different user types (e.g., veterinarians and pet owners). These are equipped with different permissions and, depending on implementation, can view data of other user types. In no case will data be passed on to unauthorized third parties.
8.4 User Type "Veterinarian": Consent to Publication and Data Sharing
-
8.4.1 Upon registration and participation in our "Referral Program", users of the "Veterinarian" type also consent to the use and provision of their data as part of our "Vet Referral Program". If you register as a veterinarian or veterinary practice in our database, we process the personal data you transmit (e.g., name, practice name, address, telephone number, email address, opening hours, areas of expertise) based on your explicit consent pursuant to Art. 6 (1) lit. a GDPR.
-
8.4.2 This data is used to display your practice on our website in a public vet database and/or an interactive map or list that is publicly accessible to interested users. The purpose is to support consumers in finding suitable veterinary contact points.
-
8.4.3 Additionally, we may pass on your contact details to interested consumers provided they make a specific request to us, such as for matching a veterinarian in their region. Disclosure takes place exclusively for this purpose and based on your consent.
-
8.4.4 Your consent can be revoked at any time with effect for the future. The revocation can be made informally by email to info@inuvet.com. In the event of revocation, your data will be removed from the public display and our referral database.
-
8.4.5 Further information on the processing of your data and your rights as a data subject (e.g., to access, rectification, erasure, restriction of processing, data portability, and lodging a complaint with a supervisory authority) can be found in the general notes of this Privacy Policy.
9. Newsletter
9.1 With your consent, you can subscribe to our newsletter, with which we inform you about our current interesting offers. The advertised goods and services are named in the declaration of consent.
9.2 For subscribing to our newsletter, we use the double opt-in procedure. This means that after your registration, we will send an email to the email address provided, in which we ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration within one month, your information will be automatically deleted after one month. In addition, we store the respective times of registration and confirmation. The purpose of this procedure is to be able to prove your registration and, if necessary, clarify any potential misuse of your personal data.
9.3 Mandatory fields for sending the newsletter are your email address, postal code, country, and practice name. Providing additional, separately marked data is voluntary and is used to address you personally. After your confirmation, we store your email address for the purpose of sending the newsletter. Legal basis is Art. 6 (1) sentence 1 lit. a GDPR.
9.4 You can revoke your consent to receive the newsletter at any time and unsubscribe from the newsletter. You can declare the revocation by clicking on the link provided in every newsletter email, by email to info@inuvet.com, or by sending a message to the contact details provided in the legal notice (Impressum).
9.5 The dispatch of the newsletter is carried out by the service provider Salesforce Marketing Cloud.
9.6 We use Salesforce Marketing Cloud based on our legitimate interests pursuant to Art. 6 (1) lit. f GDPR and a data processing agreement pursuant to Art. 28 (3) sentence 1 GDPR.
9.7 Salesforce Marketing Cloud uses this information to send and evaluate the newsletter on our behalf. These purposes also constitute our legitimate interest in processing your data. Furthermore, according to its own information, Salesforce Marketing Cloud may use this data to optimize or improve its own services, e.g., for technical optimization of dispatch and presentation of newsletters. However, Salesforce Marketing Cloud does not use the data of our newsletter recipients to write to them directly or pass it on to third parties.
9.8 The Privacy Policy of Salesforce Marketing Cloud can be found at:
9.9 We point out that we evaluate your user behavior when sending the newsletter. For this evaluation, the sent emails contain so-called web beacons or tracking pixels, which are one-pixel image files stored on our website. For evaluations, we link the data referred to in Section 3 and the web beacons with your email address and an individual ID. The data is collected exclusively in pseudonymous form; the IDs are not linked to your other personal data, and direct personal reference is excluded.
9.10 You can object to this tracking at any time by clicking the separate link provided in each email or by informing us via another contact method. The information will be stored as long as you are subscribed to the newsletter. After unsubscribing, we store the data purely statistically and anonymously. Such tracking is also not possible if you have disabled the display of images by default in your email application. In this case, the newsletter will not be displayed in full and you may not be able to use all functions. If you display the images manually, the above-mentioned tracking takes place.
10. Personalized Advertising and Retargeting
10.1 We use technologies on our website for personalized advertising and retargeting in order to display advertisements tailored to your interests – both on our website and on third-party websites or social networks.
10.2 For this purpose, information about your user behavior on our website, such as visited pages or viewed products, is recorded and processed with your consent. This usually occurs via cookies, pixels, or comparable tracking technologies. The data obtained in this way can be merged with further information from third-party sources (e.g., your user profile at Google or Meta) to provide personalized ad content for you.
10.3 Processing takes place exclusively on the basis of your explicit consent pursuant to Art. 6 (1) lit. a GDPR and Section 25 (1) TDDDG (for setting cookies/trackers), which you can grant via our Consent Management Tool (cookie banner).
10.4 The services used may also transfer data to servers outside the European Union (e.g., to the USA). In these cases, the transfer takes place on the basis of suitable guarantees pursuant to Art. 44 et seq. GDPR, in particular Standard Contractual Clauses or within the framework of the EU–U.S. Data Privacy Framework, where applicable.
10.5 You can revoke your consent at any time with effect for the future by changing the settings in our Consent Banner or disabling personalized advertising via the respective services.
10.6 Further information on the specific services used (e.g., Google Ads Remarketing, Bing, Hotjar, etc.) and data processing by third parties can be found in the relevant sections of this Privacy Policy.
11. Cookies
11.1 We use cookies on our websites. Cookies are small text files that are stored on your hard drive associated with the browser you are using via a characteristic string of characters, and through which certain information flows to the entity that sets the cookie. Cookies cannot run programs or transmit viruses to your computer and therefore cannot cause damage. They serve to make the overall internet offer more user-friendly and effective, i.e., more pleasant for you.
11.2 Cookies can contain data that makes recognition of the device used possible. In some cases, however, cookies only contain information on certain settings that cannot be linked to a person. Cookies cannot directly identify a user.
11.3 A distinction is made between session cookies, which are deleted as soon as you close your browser, and permanent cookies, which are stored beyond the individual session. Regarding their function, cookies are distinguished as follows:
-
"Technical Cookies": These are strictly necessary to move around the website, use basic functions, and ensure website security; they neither collect information about you for marketing purposes nor store which websites you visited;
-
"Performance Cookies": These collect information about how you use our website,Here is the complete, professional English translation of your Privacy Policy, structured and formatted to match your original text.
Privacy Policy
We, INUVET GmbH (hereinafter: "Inuvet", "we", or "us"), take the protection of your personal data seriously and would like to inform you about data protection in our company at this point.
Within the scope of our responsibility under data protection law, obligations have been imposed on us, among other things, by the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter: "GDPR"), to ensure the protection of personal data of the person affected by processing (we also address you as the data subject hereinafter as "customer", "user", "you", "your", or "data subject").
Insofar as we decide on the purposes and means of data processing either alone or jointly with others, this primarily includes the obligation to inform you transparently about the nature, scope, purpose, duration, and legal basis of the processing (cf. Art. 13 and Art. 14 GDPR). With this statement (hereinafter: "Privacy Policy"), we inform you about the manner in which your personal data is processed by us.
1. Definitions
Modeled after Art. 4 GDPR, this Privacy Policy is based on the following definitions:
-
"Personal data" (Art. 4 No. 1 GDPR) means any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. Identifiability can also be given by combining such information or other additional knowledge. The origin, form, or embodiment of the information does not matter (photos, video, or audio recordings can also contain personal data).
-
"Processing" (Art. 4 No. 2 GDPR) means any operation or set of operations performed on personal data, whether or not by automated (i.e., technology-supported) means. This includes, in particular, collection (i.e., procurement), recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of personal data, as well as changing an original purpose underlying the data processing.
-
"Controller" (Art. 4 No. 7 GDPR) means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
-
"Third party" (Art. 4 No. 10 GDPR) means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data; this also includes other legal entities belonging to the same group of companies.
-
"Processor" (Art. 4 No. 8 GDPR) means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller, in particular according to its instructions (e.g., IT service providers). In the sense of data protection law, a processor is, in particular, not a third party.
-
"Consent" (Art. 4 No. 11 GDPR) of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2. Controller & Contact
2.1
The controller responsible for the processing of your personal data within the meaning of Art. 4 No. 7 GDPR is:
INUVET GmbH
Berner Weg 7–25
79539 Lörrach
Germany
Email: info@inuvet.com
Phone: +49 7621 57915-10
Fax: +49 7621 57915-12
2.2
If you wish to assert your rights or have questions or comments regarding the collection and processing of your personal data that this Privacy Policy cannot answer, or if you request more in-depth information on any point, please contact the address stated above.
2.3
Our Data Protection Officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, www.heydata.eu, datenschutz@heydata.eu.
3. Data Collection Upon Contacting Us
3.1
When you contact us by email, phone, via a messenger service, or via a contact form, your email address, name, phone number, and all other personal data provided during the contact process will be stored by us to contact you and answer your inquiry.
3.2
We delete this data as soon as storage is no longer required. If statutory retention requirements apply, the data remains stored, but we restrict its processing.
4. Rights of the Data Subject
You have the following rights as a data subject:
4.1 Right of Access
-
4.1.1 You have the right to obtain information from us about your personal data to the extent of Art. 15 GDPR.
-
4.1.2 A request sent either by email or by post to the contact details provided above (see 2.1) is required for this purpose.
4.2 Right to Object to Processing and Right to Withdraw Consent
-
4.2.1 In accordance with Art. 21 GDPR, you have the right to object at any time to the processing of personal data concerning you. We will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
-
4.2.2 Pursuant to Art. 7 (3) GDPR, you have the right to withdraw your consent granted to us at any time (including consent given prior to the applicability of the GDPR, i.e., before May 25, 2018). As a result, we may no longer continue the data processing based on this consent in the future.
-
4.2.3 In this regard, please contact the address indicated above (see 2.1).
4.3 Right to Rectification and Erasure
-
4.3.1 Insofar as your personal data is inaccurate, you have the right under Art. 16 GDPR to request immediate rectification from us. Please send such a request to the contact address specified above (see 2.1).
-
4.3.2 Under the conditions listed in Art. 17 GDPR, you have the right to demand the erasure of personal data concerning you. Please send such a request to the contact address specified above (see 2.1). The right to erasure applies, in particular, if the data is no longer necessary for the purposes for which it was collected or processed, if the storage period has expired, if an objection has been raised (see 4.2), or if processing is unlawful.
4.4 Right to Restriction of Processing
-
4.4.1 Subject to Art. 18 GDPR, you have the right to demand that we restrict the processing of your personal data.
-
4.4.2 Please direct requests in this regard to the contact point stated above (see 2.1).
-
4.4.3 You have the right to restriction of processing, in particular, if the accuracy of the personal data is contested between you and us; in this case, the right applies for a period enabling us to verify the accuracy. The same applies if the successful exercise of a right to object (see 4.2) remains disputed between you and us, or if you are entitled to erasure (see 4.3) and demand restricted processing instead of erasure.
4.5 Right to Data Portability
-
4.5.1 Subject to Art. 20 GDPR, you have the right to receive personal data concerning you that you provided to us in a structured, commonly used, and machine-readable format.
-
4.5.2 Please direct requests in this regard to the contact point stated above (see 2.1).
4.6 Right to Lodge a Complaint with a Supervisory Authority
-
4.6.1 Pursuant to Art. 77 GDPR, you have the right to lodge a complaint regarding the collection and processing of your personal data with the competent supervisory authority.
-
4.6.2 You can reach the competent supervisory authority using the following contact details:
The State Officer for Data Protection and Freedom of Information Baden-Württemberg
Postfach 10 29 32
70025 Stuttgart
Email: poststelle@lfdi.bwl.de
5. Purpose of Processing
5.1
We process the personal data detailed above in compliance with the provisions of the GDPR and other applicable data protection regulations, and only to the required extent. Insofar as processing is based on Art. 6 (1) sentence 1 lit. f GDPR, the stated purposes also represent our legitimate interests.
5.2
We can only provide you with our contractual services if certain personal data required for contract performance and the operation of our online portal is collected during your use.
5.3
We collect this data only if necessary for fulfilling the contract between you and us (Art. 6 (1) lit. b GDPR). Furthermore, we collect this data if necessary for the functionality of the portal or contractual services and where your interests in protecting your personal data do not override this (Art. 6 (1) lit. f GDPR).
5.4
The processing of protocol data ("Server Log Files") serves statistical purposes and the improvement of our website's quality, particularly the stability and security of the connection (legal basis: Art. 6 (1) sentence 1 lit. f GDPR).
5.5
Contact form data is processed to manage customer requests (legal basis: Art. 6 (1) sentence 1 lit. b or lit. f GDPR).
5.6
Newsletter data is processed for the purpose of delivering the newsletter. Further provisions on sending our newsletter can be found in Section 8.
5.7
Processing of your personal data for purposes other than those described will only take place to the extent permitted by law or if you have consented to the changed purpose.
5.8
In the event of further processing for purposes other than those for which the data was originally collected, we will inform you of these other purposes prior to further processing and provide you with all other relevant information.
6. Duration of Storage & Erasure
6.1
We erase your personal data as soon as it is no longer required for the purposes for which we collected or used it (see Section 5). Generally, we store your personal data for the duration of the usage or contractual relationship. Your data is stored primarily on our servers in Germany, subject to potential transfers under Sections 10-17.
6.2
Storage may extend beyond the specified time in the event of an (impending) legal dispute with you or other legal proceedings.
6.3
Third parties employed by us (see Sections 8, 10-17) will store your data on their systems for as long as necessary in connection with providing services for us under the respective order.
6.4
Statutory retention and deletion requirements remain unaffected by the above (e.g., § 257 Commercial Code / HGB or § 147 Tax Code / AO). When statutory retention periods expire, personal data will be blocked or deleted unless further storage by us is necessary and a legal basis exists.
7. Website Usage Data
When using the website for informational purposes, the following categories of personal data are collected, stored, and processed by us:
7.1 "Log Files"
Our online shop is operated via the Shopify platform, a service of Shopify International Ltd., 2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. Precise information on data use and disclosure by this service can be found under Section 23. In running our online shop, technical log data is stored by Shopify to guarantee security, stability, and functionality. This log data includes in particular:
-
Page from which the file was requested (Referrer URL)*
-
Name and URL of the requested page
-
Date and time of access
-
Description of web browser type, language, and version used*
-
IP address of the requesting computer, shortened so a personal reference is removed
-
Volume of data transferred
-
Operating system*
-
Browser type*
-
Status message regarding whether access was successful (HTTP status code)
-
GMT time zone difference
-
System and application logs (e.g., technical access, error messages, system events)
-
Store activity logs (e.g., access by apps and users)
*This data is stored by us only if your browser transmits it to us.
7.2 "Contact Form Data"
When using contact forms, the submitted data is processed (e.g., first and last name, email address, phone number, and submission timestamp).
8. Registration & User Account
8.1
If you wish to use our services via our online portal, you must register by specifying a valid email address, a password of your choice, telephone number, postal code, country, and your full first and last name to create a user account. Providing this data is mandatory; all other information can be provided voluntarily.
8.2
When using our portal, we store data necessary for contract fulfillment, including payment method details, until you permanently delete your account. We also store voluntary data for the duration of your portal usage unless deleted earlier. You can manage and change all information in the protected customer area. The legal basis is Art. 6 (1) sentence 1 lit. f GDPR.
8.3
Our online portal offers different user types (e.g., veterinarians and pet owners). These are equipped with distinct permissions and can view data of other user types depending on implementation. In no case is data disclosed to unauthorized third parties.
8.4 User Type "Veterinarian": Consent to Publication and Data Disclosure
-
8.4.1 By registering and participating in our "Recommendation Program", users of the "Veterinarian" type consent to the use and provision of their data as part of our "Vet Recommendation Program". When registering your practice in our database, we process provided personal data (e.g., name, practice name, address, phone number, email address, opening hours, specialties) based on your explicit consent pursuant to Art. 6 (1) lit. a GDPR.
-
8.4.2 This data is used to display your practice on our website in a public vet database and/or interactive map/list. The purpose is to assist consumers searching for veterinary care.
-
8.4.3 Additionally, we may forward your contact details to interested consumers who submit specific inquiries (e.g., for finding a local vet). Forwarding occurs strictly for this purpose based on your consent.
-
8.4.4 Your consent can be revoked at any time with future effect via informal email to info@inuvet.com. Upon revocation, data will be removed from public display and our referral database.
-
8.4.5 Further details regarding data processing and your rights (access, rectification, deletion, restriction, portability, complaints) can be found in the general notes of this Privacy Policy.
9. Newsletter
9.1
With your consent, you can subscribe to our newsletter informing you about current offers. Advertised goods and services are named in the consent declaration.
9.2
We use the double opt-in procedure for registration. After registering, we send a confirmation request email to the provided address. If unconfirmed within one month, your information is automatically deleted. We also store timestamps of registration and confirmation to prove your signup and prevent misuse.
9.3
Mandatory information for receiving the newsletter includes your email address, postal code, country, and practice name. Additional marked data is voluntary and used to address you personally. Following confirmation, we store your email address to send the newsletter (legal basis: Art. 6 (1) sentence 1 lit. a GDPR).
9.4
You can revoke consent and unsubscribe at any time via the link provided in every newsletter email, by emailing info@inuvet.com, or sending a message to the contact details in our Legal Notice (Impressum).
9.5
Newsletter delivery is conducted via the service provider Salesforce Marketing Cloud.
9.6
We deploy Salesforce Marketing Cloud based on legitimate interests per Art. 6 (1) lit. f GDPR and a Data Processing Agreement per Art. 28 (3) sentence 1 GDPR.
9.7
Salesforce Marketing Cloud uses this information to send and evaluate newsletters on our behalf. This constitutes our legitimate interest. According to Salesforce, they may use data to optimize their services (e.g., technical delivery optimization). However, Salesforce does not contact recipients directly or pass data to third parties.
9.8
The Privacy Policy for Salesforce Marketing Cloud can be found at:
9.9
We note that we evaluate user behavior when sending newsletters. For this, emails contain web beacons or tracking pixels (one-pixel image files stored on our website). For evaluation, we link the data in Section 3 and web beacons with your email address and an individual ID. Data is collected pseudonymously; IDs are not linked to personal data, excluding direct personal reference.
9.10
You can object to tracking at any time by clicking the dedicated link in each email or contacting us. Information is stored for as long as you subscribe. After unsubscribing, data is kept for purely statistical and anonymous evaluation. Tracking is also prevented if image loading is disabled by default in your email client.
10. Personalized Advertising and Retargeting
10.1
We use personalized advertising and retargeting technologies on our website to show tailored advertisements based on your interests—both on our website and on third-party websites or social networks.
10.2
With your consent, information about your browsing behavior (e.g., visited pages, viewed products) is recorded via cookies, pixels, or similar tracking technologies. This data may be merged with information from third-party sources (e.g., your Google or Meta profile) to display personalized content.
10.3
Processing occurs exclusively based on your explicit consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) TDDDG (for setting cookies/trackers), granted via our Consent Management Tool (cookie banner).
10.4
Services used may transfer data to servers outside the European Union (e.g., USA). Transfers rely on appropriate safeguards per Art. 44 et seq. GDPR, notably Standard Contractual Clauses or the EU–U.S. Data Privacy Framework where applicable.
10.5
You can revoke consent at any time with future effect by updating settings in our consent banner or disabling personalized ads via respective services.
10.6
Further details on specific services (e.g., Google Ads Remarketing, Bing, Hotjar) are outlined in corresponding sections below.
11. Cookies
11.1
We use cookies on our websites. Cookies are small text files stored on your hard drive associated with your browser via a character string, providing specific information to the party setting the cookie. Cookies cannot run programs or transmit viruses. They make our internet offering more user-friendly and effective.
11.2
Cookies may contain data allowing device recognition, or simply non-personally identifiable setting details. Cookies cannot identify a user directly.
11.3
We distinguish between session cookies (deleted upon closing your browser) and permanent cookies (stored beyond individual sessions). By function, cookies are categorized as:
-
Technical Cookies: Strictly necessary to navigate the website, use basic functions, and ensure security. They do not collect marketing information or store visited pages.
-
Performance Cookies: Collect information on website usage, pages visited, or errors encountered. Collected data is anonymous and used solely to improve performance and user interest.
-
Advertising / Targeting Cookies: Serve to deliver tailored advertisements or third-party offers and measure campaign effectiveness. Stored for a maximum of 13 months.
-
Sharing Cookies: Enhance website interactivity with other services (e.g., social networks). Stored for a maximum of 13 months.
11.4
Any cookie usage not strictly technically necessary constitutes data processing permissible only with explicit active consent under Art. 6 (1) sentence 1 lit. a GDPR.
11.5 Consent Technology
Our website uses consent technology to obtain and document your legally required consent for storing cookies or using technologies (legal basis: Art. 6 (1) lit. c GDPR). When entering our website, a connection is made to our servers to record your consent declarations. A cookie is stored in your browser to map your preferences. Collected data is stored until you request deletion, delete the cookie yourself, or the storage purpose lapses.
12. Commissioned Data Processing & Data Sharing
12.1
For individual functions of our services, we utilize external domestic and foreign service providers (e.g., for IT, logistics, telecommunications, sales, marketing). They act strictly on our instructions and are contractually bound under Art. 28 GDPR to uphold data protection standards.
12.2
The following recipient categories (typically processors) may receive access to your personal data:
-
Service providers operating our website and processing stored/transmitted data (legal basis: Art. 6 (1) sentence 1 lit. b or lit. f GDPR, if not processors).
-
Public authorities/agencies where necessary to fulfill legal obligations (legal basis: Art. 6 (1) sentence 1 lit. c GDPR).
-
Entities involved in our business operations (e.g., auditors, banks, insurers, legal advisors, corporate transaction participants) (legal basis: Art. 6 (1) sentence 1 lit. b or lit. f GDPR).
12.3
Regarding safeguards for third-country data transfers, see Section 13.
12.4
Furthermore, we pass data to third parties only if you have granted explicit consent per Art. 6 (1) sentence 1 lit. a GDPR.
12.5
Data shared between us and affiliated companies (e.g., for promotional purposes) relies on existing data processing agreements.
13. Data Transfer to Third Countries
13.1
Within our business relationships, personal data may be transferred to or disclosed to third-party companies located outside the European Economic Area (EEA). Such processing occurs exclusively to fulfill contractual and business obligations.
13.2
Some third countries are certified by the European Commission as offering a data protection level comparable to EEA standards via adequacy decisions. For countries lacking a consistently high data protection level due to missing legislation, we ensure adequate protection via Binding Corporate Rules, EU Standard Contractual Clauses, certificates, or recognized codes of conduct.
14. Google Analytics
14.1
This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses cookies to analyze website usage. Information generated by the cookie is usually transferred to a Google server in the USA and stored there. With IP anonymization active, your IP address is truncated within EU member states or other EEA agreement states prior to transfer. Only in exceptional cases is the full IP address sent to a Google server in the USA and shortened there.
14.2
The IP address transmitted by your browser within Google Analytics will not be merged with other Google data.
14.3
14.4
This website uses Google Analytics with the extension _anonymizeIp(), ensuring IP addresses are processed in shortened form to rule out direct personal identification.
14.5
We use Google Analytics to analyze and regularly improve website usage (legal basis: Art. 6 (1) sentence 1 lit. f GDPR). Standard Contractual Clauses have been executed for potential US transfers.
14.6 Provider Information:
Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland.
15. Google Ads Conversion
15.1
We use Google AdWords to draw attention to our offers on external websites using ad media. We can evaluate campaign success relative to campaign data to display relevant ads and ensure fair ad cost calculation.
15.2
Ad media is delivered by Google via "Ad Servers". We use Ad Server cookies measuring parameters such as ad impressions or clicks. AdWords cookies typically expire after 30 days and are not intended to identify you personally.
15.3
These cookies enable Google to recognize your web browser upon return visits. We do not collect or process personal data in these ad measures; we receive only statistical evaluations from Google (legal basis: Art. 6 (1) sentence 1 lit. f GDPR).
15.4
Due to marketing tools used, your browser automatically establishes a direct connection with Google's server.
15.5
15.6 Data Privacy Framework:
15.7 Server-Side Tracking (Stape.io):
Data transmission to Google Analytics / Google Ads / Meta Ads is performed server-side via a proxy solution using Stape.io rather than directly from the user's browser. Tracking data is sent to our server, controlled, truncated if necessary, and forwarded to third parties. Stape.io acts strictly as a technical service provider on our behalf based on your consent (Art. 6 (1) lit. a GDPR). Privacy info:
https://stape.io/privacy-policy
16. Google Ads Remarketing
16.1
We use Google Ads Remarketing (Google Ireland Limited, Dublin, Ireland) to present targeted ads across the Google network to users who previously visited our site.
16.2
Processing occurs only with explicit consent per Art. 6 (1) lit. a GDPR via our consent banner.
16.3
Data collected may be processed on Google LLC servers in the USA based on EU Standard Contractual Clauses and the EU-U.S. DPF. You can revoke consent in the cookie banner or disable personalized ads at
https://adssettings.google.com/.
16.4
Server-side tracking via Stape.io applies as detailed in Section 15.7.
17. Google Tag Manager
17.1
We use Google Tag Manager (Google Ireland Limited) to manage website tags centrally. The Tag Manager itself creates no user profiles, stores no cookies, and performs no analyses; it merely triggers other tags that may collect data.
17.2
17.3
Server-side tracking via Stape.io applies as detailed in Section 15.7.
18. Tracify
18.1
We use the web analytics service Tracify (Tracify GmbH, Agnes-Pockels-Bogen 1, 80992 Munich) to analyze visitor behavior and optimize marketing efficiency. Tracify acts as a processor under Art. 28 GDPR.
18.2
Tracify analyzes the customer journey without storing cookies on end devices, relying on browser/device information (IP address, User-Agent, order info, resolution, processor). Transmitted info is immediately and irreversibly anonymized.
18.3
Data processing takes place entirely in Germany without transfer to unsafe third countries. Legal basis: Art. 6 (1) lit. f GDPR.
19. Salesforce Data & Marketing Cloud
19.1
We use Salesforce Data & Marketing Cloud (Salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 Munich).
19.2
Salesforce Data Cloud consolidates pseudonymized usage data in real time to build current customer profiles for optimization and marketing (legal basis: Art. 6 (1) lit. f GDPR).
19.3
Salesforce Marketing Cloud creates and evaluates personalized marketing campaigns based on your consent (Art. 6 (1) lit. a GDPR). Data is processed in secure data centers using EU Standard Contractual Clauses where applicable.
19.4
Salesforce acts as a processor under Art. 28 GDPR under an executed Data Processing Addendum (DPA).
20. Stape.io
20.1
We use Stape.io (Stape Inc., 30 N Gould St Ste R, Sheridan, WY 82801, USA) for privacy-friendly server-side tracking via server containers.
20.2
Stape.io improves load times, accuracy, and security without storing or analyzing personal data for its own purposes. Transfers to US servers rely on EU Standard Contractual Clauses per Art. 46 GDPR. Privacy policy:
https://stape.io/privacy-policy.
21. Bing Ads (Microsoft Advertising)
21.1
We use conversion tracking by Microsoft Advertising (Microsoft Ireland Operations Limited, Dublin, Ireland). Cookies track whether a user clicked a Bing ad and reached a target page.
21.2
22. Hotjar
22.1
We use Hotjar (Hotjar Ltd., Dragonara Business Centre, Paceville St Julian’s STJ 3141, Malta) to understand user interactions (clicks, scrolls, mouse movements). Collected information is stored pseudonymously.
22.2
23. Outbrain
23.1
We use Outbrain (Outbrain Inc., 39 West 13th Street, New York, NY 10011, USA) to display recommended content and ads using pseudonymous profiles created via cookies.
23.2
Processing relies on consent per Art. 6 (1) lit. a GDPR / § 25 (1) TDDDG. Third-country transfers rely on EU SCCs and the EU-U.S. DPF. Privacy policy:
https://www.outbrain.com/legal/privacy.
24. Shopify
24.1
Our online shop is hosted on Shopify (Shopify International Ltd., Dublin, Ireland), providing technical infrastructure, payment handling, and secure data storage. Personal data (name, address, payment details) is processed on our behalf.
24.2
Transfers to Canada rely on an EU adequacy decision; US transfers rely on SCCs and the EU-U.S. DPF. Processing occurs for contract performance (Art. 6 (1) lit. b GDPR) and legitimate operation interests (Art. 6 (1) lit. f GDPR). Privacy info:
https://www.shopify.com/legal/privacy.
25. Data Security
We employ appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized third-party access, taking into account the state of the art, implementation costs, context, and potential risks. Security measures are continuously updated alongside technological advancements.
26. LinkedIn Insight Tag, LinkedIn Ads, and LinkedIn Lead Gen Forms
26.1
We use the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Dublin, Ireland) for campaign evaluation, usage analysis, and retargeting.
26.2
Processed data includes IP addresses, device/browser details, referrer URLs, timestamps, page events, LinkedIn IDs, and ad interactions.
26.3
26.4
27. LinkedIn Lead Gen Forms and Salesforce CRM
27.1
We use LinkedIn "Lead Gen Forms" to collect requests regarding products and services. Submitted details (name, email, phone, job title, company, country) are processed based on consent (Art. 6 (1) lit. a GDPR).
27.2
Transmitted data is automatically imported into our Salesforce CRM (Salesforce acts as a processor per Art. 28 GDPR) and retained as required for processing inquiries or legal obligations.
28. Meta Ads (Meta Pixel, Conversion Tracking, and Remarketing)
28.1
We use Meta Business Tools, including Meta Pixel and Meta Conversion API (Meta Platforms Ireland Limited, Dublin, Ireland), to measure ad effectiveness and display targeted ads on Facebook/Instagram.
28.2
Processed data includes IP addresses, device info, visited pages, interactions, conversion events, and Meta User IDs.
28.3
28.4
29. No Automated Decision-Making (Including Profiling)
We do not intend to use personal data collected from you for automated decision-making processes (including profiling).
30. Statutory Obligation to Transmit Certain Data
Under certain circumstances, we may be subject to specific statutory or legal obligations to provide lawfully processed personal data to third parties, in particular public bodies (Art. 6 (1) sentence 1 lit. c GDPR).
31. Miscellaneous
As data protection laws evolve and technological or organizational changes occur, our privacy notices are regularly reviewed for necessary updates. You will be informed of any changes.