MEDION AG Privacy Policy (as of September 2021)

Thank you for visiting MEDION (responsible party: MEDION AG, Am Zehnthof 77, 45307 Essen, Germany). We take the protection of your personal data very seriously and want you to feel secure when using our HOMEPAGE and our products. The protection of your privacy when processing personal data is a central and important concern for MEDION, which we also take into account in all our business processes.

We take care to protect the data we collect, process and use when you visit the MEDION website. And we are happy to be your contact for any questions you may have on the subject of MEDION data protection, and we will also take your suggestions on board and see to it that they are dealt with in a very timely manner. The declaration may be updated from time to time. We therefore ask you to read it regularly. The last line of this statement below indicates when it was last updated.

Table of contents

  1. PRINCIPLES
  2. SOURCES AND DATA USED
  3. PURPOSE OF PROCESSING AND LEGAL BASIS
  4. CUSTOMER ACCOUNT
  5. CUSTOMER SERVICE
  6. TRANSFER OF DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS
  7. RETENTION PERIODS
  8. YOUR DATA PROTECTION RIGHTS
  9. OBLIGATION TO PROVIDE DATA
  10. AUTOMATED DECISION-MAKING AND PROFILING
  11. ONSITE TARGETING AND WEBSITE OPTIMISATION
  12. COLLECTION OF PERSONAL DATA WHEN VISITING OUR WEBSITE
  13. HANDLING OF YOUR DATA DURING PAYMENT PROCESSING
  14. NEWSLETTER
  15. DATA PROTECTION INFORMATION ON SOCIAL PLUGINS
  16. INFORMATION ABOUT YOUR RIGHT TO OBJECT ACCORDING TO ART. 21 BASIC DATA PROTECTION REGULATION (GDPR)
  17. INFORMATION ON APPS
  18. RESPONSIBLE PARTY

1. Principles

Your personal data will be collected, processed and used exclusively in accordance with the statutory provisions and in good faith. As far as possible, we design our business processes in such a way that data protection requirements are already taken into account during the development of products and service offerings and that personal data is anonymised in such a way that the data subject cannot be identified or can no longer be identified if this does not jeopardise the agreed purpose. MEDION uses your personal data for the technical administration and further development of this website, for customer, user administration and marketing purposes, to inform you about our services and products and for other precisely defined purposes.

Back to the table of contents

2. Sources and data used

In the course of our business relationships, we process personal data that we have received directly from you. In addition, we process personal data that we have permissibly obtained from publicly accessible sources or that is legitimately transmitted to us by other third parties, insofar as this data is required for the provision of the corresponding services and within the scope of the agreed purpose.

We store your data which is necessary for the processing of your order, the use of our products or the provision of services, e.g. repairs, and - if selected by you - for the processing of payments. This is personal data such as your address details, date of birth (for transactions with age verification) and data required for certain types of payment. The respective order data (article, quantity, price, etc.) is assigned to your address data. In most cases, MEDION is already legally obliged to collect this data (for example, in the case of age verification in accordance with the German Youth Protection Act or the German Tax Code).

Back to the table of contents

3. Purpose of processing and legal basis

Your personal data is processed in accordance with the provisions of the European Data Protection Regulation (GDPR) and the Federal Data Protection Act (Bundesdatenschutzgesetz)

For the fulfilment of contractual obligations (Art. 6 para. 1 b GDPR):

Personal data is processed in the context of trade in products and services in the field of consumer electronics. The purposes of the data processing primarily depend on the specific product (e.g. physical or digital) and its application possibilities or also on the order placed with us (e.g. repair). Further details on the data processing purposes can be found in the contract documents, the operating instructions and the terms and conditions or the conditions of use.

Within the framework of the balancing of interests (Art. 6 para. 1 f GDPR):

Insofar as necessary, we process your data beyond the actual fulfilment of the contract in order to protect the legitimate interests of us or of third parties. This includes the testing and optimisation of procedures for needs analysis for the purpose of direct customer contact, advertising or market and opinion research, insofar as you have not objected to the use of your data for this purpose, the assertion of legal claims and defence in the event of legal disputes, the guarantee of MEDION's IT security and IT operations, the prevention and clarification of criminal offences on the basis of official orders, and the measures for business management and further development of MEDION services and products.

On the basis of your consent (Art. 6 para. 1 a GDPR):

Insofar as we have your consent to process personal data for certain purposes (e.g. transfer of data within the group, evaluation of data for marketing purposes), this processing is lawful on the basis of your consent. The consent given can be revoked at any time. This also applies to the revocation of declarations of consent given to us prior to the application of the GDPR, i.e. prior to 25.05.2018. The revocation of consent does not affect the lawfulness of the data processed until the revocation.

Due to legal requirements (Art. 6 para. 1 c GDPR) or in the public interest (Art. 6 para. 1 e GDPR):

This includes, for example, identity and age checks or the fulfilment of tax control and reporting obligations. As far as not shown in detail below, no personal data is processed when using this website, i.e. it is not stored or changed or passed on to third parties.

Back to the table of contents

4. Customer account

In order to provide you with the greatest possible convenience when shopping, we offer you the permanent storage of your personal data in a password-protected MEDION customer account for online offers and services from MEDION. Once this customer account has been set up, it is not necessary to re-enter your personal data for the order process or service. If you already have an account for an online offer at MEDION, the master data stored there will be transferred to your MEDION customer account. From then on, your MEDION customer account can be used to place orders in MEDION's online offers without having to register separately or provide detailed user data again. In addition, you can view and change certain data stored about you in your customer account at any time and, for example, permanently save items for a later purchase.

In addition to the data requested when placing an order, you must enter a password of your choice to set up a customer account. This is used together with your e-mail address to access your MEDION customer account. The legal basis for this is Article 6 (1) b) GDPR, i.e. you provide us with the data on the basis of the contractual relationship between you and us. Your data will be passed on to the operator of the respective offer for the purpose of processing purchase contracts or other services that have been commissioned via the offers included by MEDION. The latter receives the data required for the provision of the service ordered in each case, i.e. verification of the log-in data (e-mail address, password, telephone number if applicable). We generally exclude any further disclosure of this data to third parties.

If you request the deletion of the MEDION customer account, your data will be deleted accordingly. The processing and storage of data is also the responsibility of the respective operator of the service used, who uses the data required to provide the service ordered for this purpose and then archives it in accordance with the statutory retention periods.

Back to the table of contents

5. Customer service

Personal data that you provide to us when filling out contact forms, by phone, by email or via social media is, of course, treated confidentially. We use your data exclusively for the purpose of processing your enquiry. The legal basis for data processing is Article 6 (1) f) or Article 6 (1) b) GDPR. Our and your concurrent (legitimate) interest in this data processing results from the aim of answering your enquiries, solving any problems that may exist and thus maintaining and promoting your satisfaction as a customer or user of our website.

If you participate in one of our customer surveys, this is done on a purely voluntary basis. In these anonymous surveys, no information is stored that allows conclusions to be drawn about the participants in the surveys. Only the date and time of your participation are stored. Any personal information you provide while answering our survey will be considered voluntarily given and will be stored in accordance with the GDPR. Please refrain from mentioning names or similar in the free text fields that would allow conclusions to be drawn about you or other persons.

In the event that a declaration of consent is submitted as part of a customer survey, Article 6 (1) a) GDPR is the legal basis for the data processing based on the consent. If you have given your consent in the context of a customer survey, you have the option of revoking this consent at any time with effect for the future. In these cases, further details are regulated in the special data protection principles of the respective customer survey.

Exceptionally, data is processed on our behalf by order processors from the customer service sector. These are carefully selected in each case, are also audited by us and are contractually obligated in accordance with Article 28 GDPR. To the extent necessary to process your request, the data you provide may be passed on to MEDION companies.

Furthermore, it may be necessary for us to pass on extracts of your enquiry to contractual partners (e.g. suppliers in the case of product-specific enquiries) in order to process your enquiry. In these cases, the enquiry is anonymised beforehand so that the third party cannot establish any reference to you. If it is necessary to pass on your personal data in individual cases, we will inform you of this beforehand and obtain your consent.

The results of our customer surveys are only used for internal evaluations. Personal data will not be passed on to third parties unless you have expressly consented to this.

Back to the table of contents

6. Data transfer to third countries or international organisations

Data is only transferred to countries outside the European Union (so-called third countries) if this is necessary to execute your orders, if it is required by law or if you have given us your consent. MEDION does not transfer any personal data to third countries or international organisations. However, MEDION uses service providers for certain orders, which also use service providers that may have their registered office, parent company or data centres in a third country. According to Art. 45 GDPR, the transfer is permitted if the European Commission has decided that an adequate level of protection exists in a third country. If such a decision has not been made, MEDION or the service provider may only transfer personal data to a third country or to an international organisation if appropriate safeguards are provided (e.g. standard data protection clauses adopted by the Commission or the supervisory authority in a specific procedure) and enforceable rights and effective remedies are available. MEDION has agreed to contracts with these service providers on so-called commissioned processing, which regulate that basic data protection principles are always concluded with their contractual partners in compliance with the European level of data protection.

Back to the table of contents

7. Storage periods

MEDION processes and stores your personal data for as long as is necessary for the fulfilment of our contractual and legal obligations. If the data is no longer required for the fulfilment of contractual or legal obligations, it is regularly deleted, unless its temporary further processing is necessary for the following purposes: preservation of evidence within the framework of the statutory limitation provisions.

According to the respective regulations, these limitation periods can be up to 30 years, whereby the regular limitation period is 3 years. Furthermore, this includes the fulfilment of retention obligations under commercial and tax law.

The periods for retention or documentation specified in the respective laws are 2 to 10 years.

Back to the table of contents

8. Your data subject rights

Every person affected by the processing of personal data has the right to:

Information, Art. 15 GDPR),
Correction (Art. 16 GDPR),
deletion (, Art. 17 GDPR),
restriction of processing (Art. 18 GDPR),
Data portability (Art. 20 GDPR) and
Objection (Art. 21 GDPR)

However, restrictions apply to the right of access and the right to erasure (Art. 23 of the GDPR). In addition, there is a right of appeal to a competent data protection supervisory authority. (Art. 77 GDPR).

Back to the table of contents

9. Obligation to provide data

In the context of our business relationship, you must provide such personal data as is necessary for the establishment and performance of a business relationship and the fulfilment of the related contractual obligations or as we are required to collect by law. Without this data, we will generally not be able to enter into or perform the contract with you or the enforcement of your legal rights (e.g. warranties and guarantees) will be at risk.

Back to the table of contents

10 Automated decision making and profiling

As a matter of principle, we do not use fully automated decision-making pursuant to Art. 22 GDPR for the establishment and implementation of the business relationship. Should we use these procedures in individual cases, we will inform you about this separately if this is required by law. We sometimes process your data automatically with the aim of evaluating certain personal aspects (profiling).

We use profiling, for example, to provide you with targeted information about products and services or we use evaluation tools. These enable us to carry out needs-based communication and advertising, including market and opinion research.

Back to the table of contents

11. Onsite targeting and website optimisation

On our website, information is collected and evaluated using cookies to optimise our websites and the advertisements displayed on them. In particular, this is to ensure that you are only shown advertising on your end devices that is geared to your actual or perceived interests, based on your previous usage behaviour.

The information processed for these purposes contains, for example, details of which of our products you were interested in. The legal basis for this data processing is Article 6 (1) f) GDPR. The optimisation of our websites for a better shopping experience and the avoidance of advertisements that are not interesting for you is in your interest as well as ours.

The collection and evaluation of data is exclusively pseudonymous and does not allow us to identify you directly. In particular, the information is not merged with your other personal data.

Back to the table of contents

12. Collection of personal data when visiting our website

In the case of mere informational use of the website, so-called viewing, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. When you view our website, we therefore collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (legal basis is Art. 6 para. 1 p. 1 f) GDPR):

In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive in relation to the browser you are using and which provide the party setting the cookie (in this case, us) with certain information. This is used, for example, to analyse the performance of the website through cookies which help to improve our website by providing us with aggregate statistics about the number of visitors to a page, which areas of a page are viewed the most and the city or location of users. These may be installed by external analytics providers contracted by us. These cookies do not identify you personally. Cookies cannot run programs or deliver viruses to your computer. They only serve to make the Internet offer more user-friendly and effective overall. MEDION uses the following types of cookies: transient cookies and persistent cookies.

Transient cookies are automatically deleted when you close the browser. These include, in particular, session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This enables your computer to be recognised when you return to our website. Session cookies are deleted when you log out or close your browser.

Persistent cookies are automatically deleted after a set period of time, which may vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time

You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all the functions of this website. Please note that most browsers offer different ways to protect your privacy. For example, you can allow first-party cookies but block third-party cookies or be notified each time a website wants to install a cookie. Please note that disabling cookies in this way means that it is not possible to set new cookies. However, it does not prevent previously set cookies from continuing to work on your device until you have deleted all cookies in your browser settings. The instructions for managing cookies on your browser can usually be found under the help function of the browser or in the operating instructions of your smartphone or the stationary or mobile product used with Internet access.

In addition, we use cookies to identify you for subsequent visits if you have an account or separate individual access to our offers. Otherwise you would have to log in again for each visit. The Flash cookies used are not recorded by your browser, but by your Flash plug-in. Furthermore, we use so-called HTML5 storage objects that are stored on your end device. These objects store the required data independently of the browser you are using and have no automatic expiry date. If you do not want Flash cookies to be processed, you must install an appropriate add-on, for example for Mozilla Firefox or the Adobe Flash Killer Cookie for Google Chrome. You can prevent the use of HTML5 storage objects by using private mode in your browser.

List of our cookies:

Name des CookiesArt des Cookies/ ZweckCookieLaufzeit
Performance Profiles (Adition)MarketingThe Provider Code is used to mark and unmark users in the MEDION Online Shop for advertising purposes outside the MEDION Online Shop. 1 year
.AditionMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 1 year
BingMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 90 days
CriteoMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 30 days
DoubleclickMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 90 days
Dynamic YieldMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 30 days
GoogleMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 540 days
Performance MediaMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 1 year
ArtefactMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 30 days
FacebookMarketingTracking cookie from Facebook to provide a range of advertising products such as Real Time Bidding from third-party advertisers. 180 days
WebtrekkAnalyse/BasicCreation of user profiles using pseudonyms for the analysis of visitor behaviour and for the improvement and needs-based design of our offer. 6 month
ABTastyAnalyse/BasicThe provider's code is used to evaluate and optimise MEDION's online campaigns. 13 month
atribaAnalyse/BasicThe provider's code is used to evaluate and optimise MEDION's online campaigns. 2 years
EmarsysAnalyse/BasicThe provider's code is used to evaluate and optimise MEDION's online campaigns. 1 year
ZenloopMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 30 days
PinterestMarketingThe provider's code is used to evaluate and optimise MEDION's online campaigns. 1 year

Overview and description of the cookies we use

On this website, various data are measured by our partners mentioned below to control advertising (= measurement data). For this purpose, among other things, the frequencies of use of various subject areas are stored on a website-related basis and advertising-relevant target groups are identified according to socio-demographic characteristics and product interests. Only the statistical patterns resulting from the use of online advertising and editorial content are processed. The information on your internet usage can also be used across websites to make a rough estimate of which advertisements you may be most interested in. You have the right to stop the recording of measurement data by our partners at any time by using the opt-out options listed below.

We use the web analysis service AB Tasty of the company AB TASTY SAS, 3 impasse de la Planchette, F-75003 Paris ("AB Tasty") to carry out A/B and multivariate tests in order to continuously improve our online offer.

In doing so, AB Tasty collects statistical information about visitor traffic. This information is usage data (browser used, number of pages viewed, number of visits, order of visit, duration of visit, interactive actions such as filling/emptying a shopping basket, recording of the use of individual web pages (except in the check-out and the "My MEDION" area), etc.) that is recorded anonymously and analysed statistically. It is not possible to draw conclusions about a specific person or an individual purchase at any time.

In addition, AB Tasty carries out geolocation (regional details of your location) with the help of your IP address. After geolocation, which takes place immediately when you visit the site, your IP address is deleted immediately. In order to display content that responds to your interests, a personalised pattern is formed. This pattern is encrypted and does not allow any conclusions to be drawn about your person. Cookies are stored for the storage and recognition of page visitors. These have a maximum duration of 13 months and are then automatically deleted. You also have the option of manually deleting the cookies or preventing them from being saved in the future.

An opt-out cookie is set via the link https://www.medion.com/de/shop/#abtastyoptout=1, which prevents future storage. If you delete your browser cookies, you will need to opt out again via this link. We would like to point out that with an opt-out, some functions of the website will not be available or will only be available to a limited extent.

Mapp Digital/ Webtrekk

We use the services of Mapp Digital c/o Webtrekk Gmbh, Robert-Koch-Platz 4, 10115 Berlin, Germany, for the analysis, optimisation and economic operation of our online offering.

Webtrekk maintains its registered office in Germany. This company is thus subject to the scope of application of German and European data protection law. It has been certified for data protection in the area of web controlling in Germany after its data processing has been checked for data protection conformity and data security.

1.1. Placed Cookies

We use the services of Webtrekk GmbH on our online offer in two ways:

1. simple statistics: when you visit our website, information transmitted by your browser is collected and analysed, e.g. page visited, information on the browser, operating system used, IP address (is immediately anonymised and then deleted), time of access. No personal data is transferred to Webtrekk

2. extended statistics: if you agree to the use of cookies in our webshop, an ID will be created by Webtrekk and stored in cookies

i. Session cookie is used to identify the session and is deleted at the end of the session.

ii. Long-term cookie contains the CookieID (pseudonym) assigned by Webtrekk and is deleted after 6 months.

The legal basis for the use of Advanced Statistics is your consent in accordance with Art. 6 (1) a) GDPR.

If you have consented to the use of cookies in our webshop, pseudonymous usage profiles are created based on the ID formed by Webtrekk. This means that the information collected during your visit to the website is analysed cookie-related and pseudonymously. A combination with data on the bearer of the pseudonym (name, e-mail address) is not possible.

The aim of using the Webtrekk services in our webshop is to perform aggregated analyses in order to tailor the content of our websites more specifically to the needs of the users and to optimise our offer.

1.2 Ordering, newsletter registration and account registration

If you create an account in the webshop, order goods or register for a newsletter, Webtrekk will also create a customer-specific pseudonym for cross-device statistics. A combination of the pseudonymous data with data on the bearer of the pseudonym does not take place.

1.3. Commissioned data processing

Webtrekk GmbH provides its services on the basis of contractual stipulations only on our behalf.

1.4. Opt Out

If you have already agreed to the use of cookies in our webshop and subsequently wish to opt out of the Advanced Statistics by Webtrekk, you can do so here: OptOut.

Google Analytics

We use Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Google uses cookies. The information generated by the cookie about the use of the website by the user is usually transmitted to a Google server in the USA and stored there. Google will use this information on our behalf for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. In doing so, pseudonymous user profiles can be created from the processed data.

We only use Google Analytics with IP anonymisation activated. This means that the IP address of the user is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by the user's browser will not be merged with other data from Google. Users can prevent the storage of cookies by setting their browser software accordingly; users can also prevent the collection of the data generated by the cookie and related to their use of the online offer to Google as well as the processing of this data by Google by downloading and installing the browser plugin available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en. As an alternative to the browser plug-in, you can click this link to prevent Google Analytics from collecting data on this website in the future. This will place an opt-out cookie on your terminal device. If you delete your cookies, you must click the link again.

For more information on Google's use of data for advertising purposes, settings and opt-out options, please visit the Google websites: https://policies.google.com/technologies/partner-sites?hl=en ("Google's use of data when you use our partners' websites or apps"), http://www.google.com/policies/technologies/ads ("Use of data for advertising purposes"), http://www.google.com/settings/ads ("Manage the information Google uses to show you ads") and http://www.google.com/ads/preferences("Determine what ads Google shows you").

AdTriba

This website uses technology from AdTriba GmbH - Hoheluftchaussee 112, 20253 Hamburg (https://www.adtriba.com/) to collect and store data, from which user profiles are created using pseudonyms.

These user profiles are used to analyse visitor behaviour and are evaluated in order to improve and design our offer in line with requirements. Cookies may be used for this purpose. These are small text files that are stored locally on the end device of the site visitor and thus enable recognition when visiting our website again.

The pseudonymised usage profiles are not combined with personal data about the bearer of the pseudonym without a separate, express consent. This website collects and uses cross-app and cross-device information for reporting purposes. This is explicitly not personal data, from which information about individual users can be viewed and traced back to specific users. Techniques are used to track users across apps and devices, including cookie and ID synchronisation.

You can object to the collection and storage of data at any time with effect for the future by clicking on the url https://www.adtriba.com/privacy-policy to opt out of tracking by Adtriba (Opt-out from Adtriba Tracking).

Google Marketing Plattform (vormals DoubleClick by Google)

This website continues to use Google's online marketing tool Campaign Manager. Campaign Manager uses cookies to serve ads that are relevant to users, to improve campaign performance reports or to prevent a user from seeing the same ads more than once. Google uses a cookie ID to record which ads are shown in which browser and can thus prevent them from being shown more than once. In addition, Campaign Manager can use cookie IDs to record so-called conversions that are related to ad requests. This is the case, for example, when a user sees a Campaign Manager ad and later visits the advertiser's website with the same browser and makes a purchase. According to Google, Campaign Manager cookies do not contain any personal information.

Due to the marketing tools used, your browser automatically establishes a direct connection with Google's server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our state of knowledge: Through the integration of Campaign Manager, Google receives the information that you have called up the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, it is still possible for the provider to obtain and store your IP address.

In addition, the Campaign Manager (DoubleClick Floodlight) cookies used allow us to understand whether you take certain actions on our website after you have accessed or clicked on one of our display / video ads on Google or on another platform via Campaign Manager (conversion tracking). Campaign Manager uses this cookie to understand the content you have interacted with on our websites in order to send you targeted advertising later.

You can prevent participation in this tracking process in several ways:

  1. by disabling cookies for conversion tracking by setting your browser to block cookies from the googleadservices.com domain, https://www.google.com/settings/ads, this setting being deleted when you delete your cookies;
  2. by disabling the interest-based ads of the providers that are part of the self-regulatory campaign "About Ads", via the link http://www.aboutads.info/choices, this setting being deleted when you delete your cookies;
  3. by permanently deactivating them in your Firefox, Internetexplorer or Google Chrome browsers at the link http://www.google.com/settings/ads/plugin,
  4. by means of the corresponding cookie setting (see point 9 Collection of personal data when visiting our website). Please note that in this case you may not be able to use all the functions of this website to their full extent

In addition, you can prevent Google from collecting the data generated by the cookies about your use of the websites and the processing of this data by Google by downloading and installing the browser plugin available at https://support.google.com/adsense/answer/142293?hl=en under "Display settings", "Extension for Campaign Manager deactivation".

For more information on the Google Marketing Platform, please visit https://marketingplatform.google.com/about/ and on data protection at Google in general: https://policies.google.com/privacy?hl=en-GB&gl=uk. Alternatively, you can visit the Network Advertising Initiative (NAI) website at http://www.networkadvertising.org. Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. Legal basis: Art. 6 1 a) GDPR

Artefact

Our website uses the tracking and reporting tool of Artefact Germany GmbH, Philosophenweg 21, 47051 Duisburg, Germany (hereinafter "Artefact"). This tool enables us to measure and deliver online marketing measures. In addition, we want to ensure a needs-based design and the ongoing optimisation of our website. Cookie and pixel technologies are used for this purpose. These interests are to be regarded as legitimate within the meaning of Art. 6 para. 1 p. 1 f) GDPR. In connection with the playout of advertising material and the evaluation of click behaviour and conversion rate, information about the use of this website such as campaign, service provider, conversion, click, partner, order and product ID, date and time of the server request, referrer URL, user agent, anonymised IP address, geo data, MLIDs (cookies), timestamp of the touchpoint and currency is collected and stored. You can prevent the installation of cookies by setting your browser software accordingly. However, we would like to point out that in this case not all functions of this website can be used to their full extent. As an alternative to the browser setting, especially for browsers on mobile devices, you can also prevent the collection of data by Artefact by clicking on this link (https://www.artefact.com/cookies/). An opt-out cookie will be set, which prevents the future collection of your data when visiting this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. For more information on data protection in connection with Artefact, please see Artefact's privacy policy (https://www.artefact.com/data-privacy).

Dynamic Yield

MEDION uses the services of Dynamic Yield Ltd. (Highlands House, Basingstoke Road, Spencers Wood, Reading, Berkshire, England, RG7 1NT) in the course of this website. Dynamic Yield optimises the content of this website for you on the basis of your consent in accordance with Art. 6 Para. 1 lit. a DSGVO.

This includes customised recommendations, equivalent products or other personalised content that is relevant to you in order to make your visit to the website a personal experience.

Dynamic Yield uses cookies for this purpose and collects only pseudonymised information about your usage activities on our site. A direct reference to a person is therefore not possible.

You can prevent the collection or analysis of your data by Dynamic Yield by setting and saving the available opt-out cookie. To deactivate Dynamic Yield, please click here (https://st.dynamicyield.com/optout).

For further information on data protection at Dynamic Yield, please click on the following link: https://www.dynamicyield.com/platform-privacy-policy/

FACT-Finder

Description and purpose of data processing:

For personal product recommendations and to offer you the best results via our search function on the website, we use the FACT-Finder service of Omikron Data Quality GmbH, Habermehlstr. 17, 75172 Pforzheim. Your shopping history is used for this purpose. This includes, in particular, articles and product categories that you have already viewed, searched for or purchased. All information collected for this purpose remains on FACT-Finder's servers and can only be viewed by persons authorised to do so. The data is stored anonymously and it is not possible to draw any conclusions about your person.

What information and data is processed:

This is a user and/or session ID of the user transmitted by us to FACT-Finder, if applicable, information on the search, time of the search, the geolocation transmitted by us to FACT-Finder as the starting point for the search, if applicable, when using the geo-search, as well as interactions assigned to the user and/or session ID transmitted by us to FACT-Finder.

Legal basis of data processing:

Data processing serves the purpose of presenting the best possible results to users via the search function in the webshop and represents a legitimate interest of MEDION. The legal basis for data processing is Art. 6 Para. 1 lit. f) GDPR. You have the right to object to the data processing at any time. For further information on your right to object, please refer to section 18 of this data protection declaration.

Recipients of the data:

The data is transmitted exclusively within the scope of the aforementioned purposes to Omikron Data Quality GmbH, Habermehlstr. 17, 75172 Pforzheim, which processes the data as described above on behalf of MEDION.

Duration of data storage:

The data will be stored anonymously for the entire duration of the contract between FACT-Finder and MEDION. The data will be deleted three months after termination of the contract.

Zenloop

We work with zenloop GmbH, Brunnenstrasse 196, 10119 Berlin. zenloop is a business-to-business software-as-a-service platform that allows us to collect and analyse feedback from our customers through various channels. This allows us to align and improve our offering to the needs of our customers.

When using the feedback tool, zenloop collects the public IP address, device and browser data and the website from which you use the feedback platform. zenloop also uses cookies and similar technologies to collect aggregate data about users. In addition, zenloop collects survey responses and your email address on our behalf to the extent that we provide them to zenloop (only after your explicit consent).

The legal basis for the data processing by zenloop is Art. 6 para. 1 lit. b DSGVO.

We have concluded a commission processing agreement with zenloop in accordance with Art. 28 (3) DSGVO and are satisfied that zenloop has implemented appropriate technical and organisational measures in such a way that the processing is carried out in accordance with the requirements of the DSGVO and ensures the protection of your rights.

You can find more information on this in zenloop's privacy policy.

Push Nachrichten

You can sign up to receive our push notifications. To send our push notifications, we use the "Accengage" delivery service operated by Accengage SAS, 31, Rue du 4 Septembre, 75 002 Paris - France.

You will receive regular information about our offers in the webshop via our push notifications.

To sign up, you must confirm your browser's request to receive notifications. This process is documented and stored by Accengage. This includes storing the time of login and your browser ID or device ID. The collection of this data is necessary so that we can trace the processes in the event of misuse and therefore serves our legal protection.

In order to be able to show you the push notifications, Accengage collects and processes your browser ID on our behalf, as well as your device ID in the case of mobile access.

By subscribing to our push notifications, you agree to receive them. The legal basis for the processing of your data after you have subscribed to our push notifications is Art. 6 (1) lit. a DSGVO if you have given your consent.

Accengage and MEDION also evaluate the push notifications statistically. Accengage can thus see whether and when our push notifications were displayed and clicked on by you.

You can revoke your consent to the storage and use of your personal data, to receiving our push notifications and to the statistical collection described above at any time with effect for the future. For the purpose of revoking consent, you can change the setting provided for this purpose in your browser for receiving push notifications. If you use our push notifications on a desktop PC with the "Windows" operating system, you can also unsubscribe from our push notifications by right-clicking on the respective push notification in the settings that appear there.

Your data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. Your data will therefore be stored as long as the subscription to our push notifications is active.

Parcellab

For the delivery of goods, we use shipping service providers such as DHL, DPD, UPS, who receive your name and address. In this respect, the personal data collected by us for the delivery of goods will be passed on to the transport company commissioned in each case as part of the contract processing. If your goods order requires a forwarding delivery or timely delivery by a shipping service provider, we will also pass on your telephone number and e-mail address to the forwarding/shipping service provider in addition to the aforementioned data in order to be able to guarantee proper shipping (e.g. by arranging the delivery date, for notification of the shipping status, etc.).

We use third party services for the processing of payments.

When shipping goods, we use the service provider parcelLab GmbH, Kapellenweg 6, 81371 Munich, to handle the shipping notifications in the direction of our customers and to provide them with the shipping status and tracking number of their shipment. For this purpose, the personal data required for the shipment information (name, address, order number, etc.) are forwarded to parcelLab. You can find more information in parcelLab's privacy policy: https://parcellab.com/privacy-policy

Pinterest Retargeting (Pinterest Tag)

A Pinterest tag (hereinafter: tag) of Pinterest Europe Ltd. Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland is integrated into this website. Through this tag, information about the use of this website (e.g. information about viewed articles and actions) is collected jointly by Pinterest Europe Ltd and MEDION and transmitted to Pinterest Europe Ltd. The further processing of the data transmitted to Pinterest Europe Ltd is the sole responsibility of Pinterest Europe Ltd under data protection law. This information transmitted to Pinterest Europe Ltd can be assigned to your person with the aid of further information that Pinterest Europe Ltd has stored about you, e.g. due to your ownership of an account on the social network "Pinterest". The information collected via the tag can be used to display interest-based advertisements on our offers to you in your Pinterest account (retargeting). The information collected via the tag can also be aggregated by Pinterest Europe Ltd and the aggregated information can be used by Pinterest Europe Ltd for its own advertising purposes as well as for advertising purposes of third parties. For example, Pinterest Europe Ltd may infer certain interests from your browsing behaviour on this website and may also use this information to promote third party offers. Pinterest Europe Ltd may also combine the information collected via the tag with other information that Pinterest Europe Ltd has collected about you via other websites and/or in connection with the use of the social network "Pinterest", so that a profile about you can be stored at Pinterest Europe Ltd. This profile can be used for advertising purposes. The legal basis for this data processing is Article 6(1)(a) DSGVO (consent).

You can find more information on data protection at Pinterest Europe Ltd here: https://policy.pinterest.com/en/privacy-policy

Here you can also assert your data subject rights (e.g. right to deletion) with regard to the data that Pinterest Europe Ltd processes about you as a data controller. You can revoke your consent given with regard to the use of Pinterest Retargeting here.

Back to the table of contents

13. Handling of your data during payment processing

Paypal
When paying via PayPal, your payment data will be forwarded to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" via PayPal. PayPal uses the result of the credit check with regard to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognised mathematical-statistical procedure. Among other things, address data is included in the calculation of the score values. For further information on data protection law, including information on the credit agencies used, please refer to PayPal's data protection statement: http://www.paypal.com/uk/webapps/mpp/ua/privacy-full

Prepayment
After sending the order and deciding to pay in advance, you will receive a confirmation by e-mail. In this e-mail, you will be informed of the data required for the transfer, such as the invoice amount, order number and bank details. When making the transfer, please state the exact purpose of use, which will be displayed in the e-mail.

Back to the table of contents

14. Newsletter

The newsletter is sent and the e-mail address is used by the service provider commissioned by MEDION: emarsys eMarketing Systems AG, Hans-Fischer-Strasse 10, 80339 Munich, Germany) If you register for the free newsletter, we collect your e-mail address and other personal data provided by you (surname, first name, possibly date of birth, etc.).

You will then be informed regularly about new products, valuable tips as well as exclusive offers, voucher and gift campaigns. After registering, you will receive an email with a confirmation link, which you click to complete your registration for the MEDION newsletter and the MEDION factory outlet newsletter. If you no longer wish to receive our MEDION Newsletter and/or the MEDION Factory Outlet Newsletter, you can unsubscribe at any time by clicking on the unsubscribe link contained in each newsletter mailing or by visiting our service portal at https://www.medion.com/selfcare/ in the Data Use and Advertising Consent section. There you can view, review and change any consent you have given. Alternatively, you can send an email to datenschutz@medion.com.

Your details, including your e-mail address, may be processed and used by MEDION for the purpose of providing you with further support, sending you information on products and services, and conducting surveys. Your shopping history will also be used for personal product recommendations. This includes, in particular, articles and product categories that you have already viewed, searched for or purchased.

This data is stored in pseudonymised form. We use this data to send you personal product recommendations and thus make it easier for you to find relevant products.

It will not be passed on to third parties without your consent. You may at any time object to the use of your data for the aforementioned purposes, in particular for advertising and market or opinion research, vis-à-vis MEDION as the party responsible for data processing with effect for the future, without incurring any costs other than the transmission costs in accordance with the basic rates. Your data will be stored after your registration until revocation.

Within the scope of the legal permission, we are entitled to use the e-mail address that you provided when purchasing a paid service for direct advertising for our own similar products or services. If you no longer wish to receive advertising for similar products or services, you can object to the corresponding use of your e-mail address at any time without incurring any costs other than the transmission costs according to the basic rates. To do so, you can unsubscribe from the product recommendations by clicking on the unsubscribe link contained in each mailing or by sending an e-mail to datenschutz@medion.com.

The legal basis for data processing after newsletter registration is consent in accordance with Art. 6 1 a) GDPR, or in the case of dispatch as a result of the purchase of goods or services.... The legal basis for logging user behaviour and the registration process are legitimate interests according to Art. 6 1 f) GDPR. The interest here is directed towards a high-quality and technically secure newsletter offer.

Back to the table of contents

15. Data protection information on social plugins

Our website does not currently use social plugins from social networks (Twitter, Facebook, etc.). Should this change in the future, the social plugins will only start transmitting data after you have activated the buttons. Each time you call up a website of our Internet presence that is provided with such a plugin, the plugin causes the browser you are using to load and display the visual representation of the plugin from the social network server.

In the process, the social network server, insofar as you are registered there, is informed which particular website of our Internet presence you are currently visiting as well as other data such as, in particular, your IP address. We have no influence on the scope of the data that the social network collects with the help of this plugin. Please refer to the data protection information of the respective social network for more information: e.g. facebook google and twitter

Back to the table of contents

16. Information about your right to object in accordance with Art. 21 of the General Data Protection Regulation (GDPR)

You may revoke your consent to the processing of personal data at any time by contacting MEDION. This also applies to the revocation of declarations of consent that were given to us before the applicability of the General Data Protection Regulation (GDPR), i.e. before 25 May 2018. Please note that the revocation is only effective for the future. Processing that took place before the revocation is not affected.

Right to object on a case-by-case basis

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) GDPR (data processing in the public interest); this also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

Insofar as we base the processing of your personal data on the balance of interests, you may object to the processing. This is the case if the processing is not necessary, in particular, for the performance of a contract with you, which is shown by us in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done.

In the event of your justified objection, we will examine the merits of the case and either discontinue or adapt the data processing or show you our compelling legitimate grounds on the basis of which we must continue the processing.

Right to object to processing of data for direct marketing purposes In individual cases, we process your personal data to carry out direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purposes of such advertising; this also applies to profiling insofar as it is related to such direct advertising. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

The objection can be made form-free and should preferably be addressed to: MEDION AG, Datenschutz, Am Zehnthof 77, 45307 Essen, Germany.

Back to the table of contents

17. Informationen on apps

App stores / installation
The MEDION apps are available via app platforms operated by third parties, so-called app stores (e.g. Google Play and Apple App Store).

Downloading may therefore require prior registration with the respective app store. MEDION has no influence on the processing of your data in connection with your registration and use of these app stores.

In this respect, the operator of the respective app store is solely responsible. If necessary, please contact the respective app store operator directly for more information.

App permissions:
In order to provide you with the functionalities of the apps, the apps must be able to access various functions and data of your mobile device. For this purpose, it is technically imperative that you grant the apps selected access authorisations. With certain operating systems, this also includes the Bluetooth function. Otherwise, the apps cannot be used for technical reasons.

Before using the apps for the first time, we will explicitly inform you of the requested access rights. In most cases, these are the following permissions:

Location:
This authorisation is required to determine your current location for location-based services. This authorisation allows your smartphone to access your GPS data, Wi-Fi identifiers and / or Bluetooth, depending on which you have activated, to determine your location.

Address book:
This permission supports the selection of contacts to be informed for the user and provides the possibility to search for and select the corresponding persons in the contact data.

In order for this to be possible, the apps need the "Contacts" permission to access the contact data.

WLAN connection information:
This authorisation requires access to the WLAN status in order to be able to automatically inform the user whether there is a connection to the Internet and to be able to advise him/her to switch to "offline" control. If the Internet connection is not established or cannot be established, it is necessary to query the status of the network and to be able to search for WLAN connections/home networks.

Push-notifications
Push notifications are messages sent by the apps to your device and displayed there in a prioritised manner.Our apps use push notifications by default, provided that the user has consented to this when installing the app or using it for the first time.The receipt of push notifications can be deactivated at any time in the settings of the device or the app.

User behaviour:
Within the framework of the legal regulations, we, or companies commissioned by us, create usage profiles under a pseudonym.

These can be evaluated for advertising and market research or for the needs-based design of the apps.

It is not possible to draw any direct conclusions about the user. The profile data is not linked to further information about the user.

Protocol data:
This permission allows the automatic storage of log data, such as the information your browser sends when you visit a website or your mobile app sends when you use it.

This log data may include your IP address, the address of the websites visited, the type and settings of the browser, the date and time of your request and cookies.

Device information:
In addition to log data, MEDION may also collect information about the device on which the apps are used.

This includes device type, operating system used, device settings, unique device identifiers, and crash data. Whether some or all of this information is collected depends on the type of device used and its settings. This allows error messages and system crashes to be analysed in order to improve future operation. Personal data is not required for this and is not collected.

Social media:
If you connect to our apps via third-party social media sites (such as Facebook or Twitter or Instagram or Google), you agree to the permissions stored there under your personal account. MEDION does not gain access to the personal data you store there.

Back to the table of contents

18. Responsible entity

The responsible entity is MEDION AG Am Zehnthof 77, 45307 Essen, Germany. You can also reach the company data protection and the company data protection officer via the e-mail address

datenschutz@medion.com

MEDION AG Management Board: Gerd Brachmann (Chairman),
Christian Eigen (Deputy Chairman)
Chairman of the Supervisory Board of MEDION AG: Dr. Rudolf Stützle
Registered Office of the Company: Essen AG Essen HRB 132 74

(Status of this data protection declaration of MEDION AG: September 2021)