page1image73987904

Privacy policy

Thank you for visiting our website audiolounge-pro.com and for your interest in our company.
The protection of your personal data, such as date of birth, name, telephone number, address, etc., is important to us.

The purpose of this privacy policy is to inform you about the processing of your personal data that we collect from you when you visit our site. Our data protection practices are in accordance with the legal regulations of the Swiss Federal Data Protection Act (FADP) and the EU's General Data Protection Regulation (GDPR). The following data protection declaration serves to fulfil the information obligations arising from the FADP and the GDPR. These can be found, for example, in Art. 19 ff. FADP as well as Art. 13 ff. of the GDPR.

Owner or responsible person

The controller within the meaning of Art. 5 let. j FADP or Art. 4 no. 7 GDPR is the person who alone or jointly with others decides on the purposes and means of the processing of personal data. The controller pursuant to Art. 4 No. 7 GDPR is also the recipient of the personal data within the meaning of Art. 4 No. 9 GDPR. Any third party recipient shall be identified separately.

With regard to our website, the owner or responsible person is:

Audiolounge Bannwart Arkadenweg 5a
8600 Dübendorf Switzerland

E-mail: info@audiolounge-pro.com Tel: §41765612028

Provision of the website and creation of log files

Each time our website is accessed, our system automatically collects data and information from the device (e.g. computer, mobile phone, tablet, etc.) used to access it.

What personal data is collected and to what extent is it processed?

(1) Information about the browser type and version used; (2) The operating system of the retrieval device;
(3) Host name of the accessing computer;
(4) The IP address of the retrieval device;

(5) Date and time of access;
(6) Websites and resources (images, files, other page content) accessed on our website; (7) Websites from which the user's system accessed our website (referrer tracking);

page1image73988320

Page 1 of 29

page2image73850592

(8) Message whether the retrieval was successful; (9) Amount of data transmitted

This data is stored in the log files of our system. This data is not stored together with the personal data of a specific user, so that individual site visitors cannot be identified.

Legal basis for the processing of personal data

Personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP or Art. 2 CC) as well as Art. 6 para. 1 lit. f GDPR (legitimate interest).

Purpose of data processing

The temporary (automated) storage of data is necessary for the course of a website visit in order to enable delivery of the website. The storage and processing of personal data is also carried out to maintain the compatibility of our website for as many visitors as possible and to combat abuse and eliminate malfunctions. For this purpose, it is necessary to log the technical data of the accessing computer in order to be able to react as early as possible to display errors, attacks on our IT systems and/or errors in the functionality of our website. In addition, we use the data to optimise the website and to generally ensure the security of our information technology systems.

Duration of storage

The deletion of the aforementioned technical data takes place as soon as they are no longer required to ensure the compatibility of the website for all visitors, but no later than 3 months after accessing our website.

Possibility of restriction, objection, correction and deletion

You may at any time request the restriction of processing pursuant to Art. 18 GDPR or object to processing pursuant to Art. 21 GDPR as well as request the correction or deletion of data pursuant to Art. 16 or 17 GDPR. You can find out which rights you have and how to exercise them in the lower section of this privacy policy.

Special functions of the website

Our site offers you various functions, during the use of which personal data is collected, processed and stored by us. We explain below what happens to this data:

Contact form(s)
What personal data is collected and to what extent is it processed?

The data you have entered in our contact forms, which you have entered in the input mask of the contact form.

Legal basis for the processing of personal data

Personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP or Art. 2 CC) as well as Art. 6 para. 1 lit. a FADP (consent through unambiguous confirmatory action or behaviour).

Page 2 of 29

page3image73691328

Purpose of data processing

We will only use the data collected via our contact form or contact forms for processing the specific contact request received through the contact form. Please note that in order to fulfil your contact request, we may also send you e-mails to the address you have provided. The purpose of this is so that you can receive confirmation from us that your enquiry has been correctly forwarded to us. However, the sending of this confirmation e-mail is not obligatory for us and is only for your information.

Duration of storage

After processing your request, the collected data will be deleted immediately, unless there are legal retention periods.

Possibility of restriction, objection, correction and deletion

You may at any time request the restriction of processing pursuant to Art. 18 GDPR or object to processing pursuant to Art. 21 GDPR as well as request the correction or deletion of data pursuant to Art. 16 or 17 GDPR. You can find out which rights you have and how to exercise them in the lower section of this privacy policy.

Necessity of providing personal data

The use of the contact forms is on a voluntary basis. You are not obliged to contact us via the contact form, but can also use the other contact options provided on our website. If you wish to use our contact form, you must fill in the fields marked as mandatory. If you do not fill in the required information on the contact form, you will either not be able to send the enquiry or we will not be able to process your enquiry due to a lack of information.

Login area / Registration
Scope of personal data processing and personal data collected

The registration and login details you have entered with us or have been provided to you.

Legal basis for the processing of personal data

Personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP or Art. 2 CC) as well as Art. 6 para. 1 lit. b FADP (implementation of (pre)contractual measures).

Purpose of data processing

You have the option of using a separate login area on our website. In order for us to check your authorisation to use the protected area or the protected documents, you must enter your login data (e-mail or user name and password) in the corresponding form. If required, we can send you your login data or the option to reset the password by e-mail on request.

Duration of storage

The data collected will be stored for as long as you maintain a user account with us.

Possibility of restriction, objection, correction and deletion

Page 3 of 29

page4image73689872

You may at any time request the restriction of processing pursuant to Art. 18 GDPR or object to processing pursuant to Art. 21 GDPR as well as request the correction or deletion of data pursuant to Art. 16 or 17 GDPR. You can find out which rights you have and how to exercise them in the lower section of this privacy policy.

Necessity of providing personal data

Certain pages and their contents are not publicly accessible. Via the login area on our site, certain users can gain access to the protected area. The use of the content protected by the login area is not possible without entering personal data. If you wish to use our login area, you must fill in the fields marked as mandatory (user name and password). The entry of the data requires the existence of a user account. Registration is not possible if the data you have entered is incorrect. If the data you enter is incorrect or not entered at all, the protected area cannot be used. However, the rest of the site can still be used without a login.

Newsletter registration form
What personal data is collected and to what extent is it processed?

By registering for the newsletter on our website, we receive the e-mail address entered by you in the registration field and, if applicable, further contact data, provided that you communicate this to us via the newsletter registration form.

Legal basis for the processing of personal data

Personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP or Art. 2 CC) as well as Art. 6 para. 1 lit. a FADP (consent through unambiguous confirmatory action or conduct).

Purpose of data processing

The data recorded in the registration mask of our newsletter will be used by us exclusively for sending our newsletter, in which we inform you about all our services and our news. After registration, we will send you a confirmation e-mail containing a link that you must click to complete the registration for our newsletter (double opt-in). By doing so, you give your consent to data processing in accordance with Art. 6 para. 6 FADP.

Duration of storage

You can unsubscribe from our newsletter at any time by clicking on the unsubscribe link, which is also included in every newsletter. Your data will be deleted by us immediately after unsubscribing, provided that there are no legal retention obligations. Likewise, your data will be deleted by us immediately in the event that your subscription is not completed. We reserve the right to delete without giving reasons and without prior or subsequent information.

Possibility of restriction, objection, correction and deletion

You may at any time request the restriction of processing pursuant to Art. 18 GDPR or object to processing pursuant to Art. 21 GDPR as well as request the correction or deletion of data pursuant to Art. 16 or 17 GDPR. You can find out which rights you have and how to exercise them in the lower section of this privacy policy.

Necessity of providing personal data

Page 4 of 29

page5image73790880

If you would like to use our newsletter, you must fill in the fields marked as mandatory and confirm your e-mail address by clicking on the double opt-in link. The newsletter registration details are necessary in order to be able to make use of the newsletter offer. The information is used exclusively for sending our newsletter. If you do not fill in the mandatory fields, we will not be able to provide you with our newsletter service.

Disclosure of information to third parties

Personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP and Art. 2 CC).

The disclosure of information to third parties depends on the scope of the activities or offers of our website or our business model described below.

As a matter of principle, we only keep your information for as long as necessary and treat it confidentially. Exceptions to this are the transfer of personal data to debt collection service providers, to public bodies and authorities and to private individuals, who have a right to it due to legal regulations, court decisions or official orders as well as the transfer to authorities for the purpose of initiating legal proceedings or for law enforcement purposes if our legally protected rights are attacked.

Automatic identity and credit check for shipping on account or online payment What personal data is collected and to what extent is it processed?

If you choose the payment method purchase on account or order online using a payment service, you will be asked during the ordering process to consent to the transmission of the data required for the processing of the payment and an identity and credit check. First name and surname, street, house number, postcode, town, date of birth, as well as the data related to your order.

Legal basis for the processing of personal data

Personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP and Art. 2 CC).

In direct connection with the conclusion or performance of a contract (Art. 31 para. 2 let. a FADP), there is an overriding interest in obtaining information about the identity of a contracting party. Directly in connection with the conclusion of a contract, personal data may be processed for the purpose of checking creditworthiness, provided that the personal data is not particularly sensitive or involves high-risk profiling, the data is disclosed to third parties only if they require the data for the conclusion or performance of a contract with the data subject, the data is not more than ten years old and the data subject is of legal age (Art. 31 para. 2 let. c. FADP). See also Art. 6 para. 1 lit. b GDPR (implementation of (pre)contractual measures).

Purpose of data processing

For the purpose of checking identity and creditworthiness, we transmit data to credit agencies and receive information and, if necessary, creditworthiness information from them. We receive information and, if applicable, creditworthiness information from these agencies on the basis of mathematical-statistical procedures, the calculation of which includes,

Page 5 of 29

page6image73470432

among other things, address data (so-called score values). When using online payment services, we transmit your details to the corresponding partners and receive information from them to release the order for dispatch.

Duration of storage

We will store the relevant data for the processing of the payment for as long as it is necessary for the execution of the transaction. Insofar as the data is subject to statutory retention obligations, it will be deleted after the retention obligation has expired.

Possibility of restriction, objection, correction and deletion as well as information

You can restrict processing at any time in accordance with Art. 18 GDPR, object to processing in accordance with Art. 21 GDPR and request correction or deletion of data in accordance with Art. 16 or 17 GDPR. In accordance with Art. 25 FADP, you can request information at any time about whether personal data about you is being processed. You can thus at any time view the information that is necessary to enable you to assert your rights under the Data Protection Act and to ensure transparent data processing. If the information stored about you is incorrect, we will delete it and, if necessary, consult with the data protection advisor. You can find out which rights you are entitled to and how to assert them in the lower section of this data protection declaration.

Statistical analysis of visits to this website - Webtracker

We collect, process and store the following data when this website or individual files on the website are accessed: IP address, website from which the file was accessed, name of the file, date and time of access, amount of data transferred and report on the success of the access (so-called web log). We use this access data exclusively in non-personalised form for the continuous improvement of our website and for statistical purposes.

Any personal data is processed in accordance with the principle of legality (Art. 6 para. 1 FADP) and the principle of good faith (Art. 6 para. 2 FADP and Art. 2 CC). We also use the following web trackers to evaluate visits to this website:

Custom Audiences

We use on our site the service Custom Audiences of the company Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5 Dublin 4, Ireland, e-mail: impressum-support@support.facebook.com, website: http://facebook.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel- und-wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d- 4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

Facebook Custom Audience is an advertising tool from Facebook that can be used to run targeted advertising campaigns to page visitors.

page6image73470848 page6image73471056 page6image73471264 page6image73471472page6image73471680 page6image73471888

Page 6 of 29

page7image73469600

You can access the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://www.facebook.com/about/privacy.

The provider also offers an opt-out option at https://www.facebook.com/about/privacyFacebook Connect

We use on our site the service Facebook Connect of the company Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5 Dublin 4, Ireland, e-mail: impressum-support@support.facebook.com, website: http://www.facebook.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel- und-wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d- 4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

Via Facebook Connect, users can use their Facebook profile to simplify logging in to other web services. You can access the provider's certification under the EU-US Data Privacy Framework at

https://www.dataprivacyframework.gov/list.
You can revoke your consent at any time. You will find more information on revoking your consent either with the consent

itself or at the end of this privacy policy.
For further information on the handling of transmitted data, please refer to the provider's privacy policy at

https://www.facebook.com/about/privacy.
The provider also offers an opt-out option at 
https://www.facebook.com/about/privacy.

Google

We use on our site the service Google of the company Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: https://www.google.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und- wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d-

page7image73469184 page7image73468976 page7image73468768 page7image73468560page7image73468352 page7image73468144 page7image73467936page7image73467728 page7image73467520 page7image73467312 page7image73467104page7image73364064 page7image73366768 page7image73334784 page7image73334992page7image73335200 page7image73335408

Page 7 of 29

page8image73180304

4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

We use Google in order to be able to load further services from Google on the website. The service is used to provide further Google services, such as the data processing required for the provision of streams and fonts and relevant Google search content. It is technically required in order to be able to exchange the site visitor's information already available to Google between the Google services and to be able to provide the site visitor with individual content adapted to his or her Google account.

For the processing itself, the service or we collect the following data: Background data stored in the Google user account or at other Google services about the page visitor, background data for the provision of Google services such as streaming data or advertising data, data about the page user's use of Google search, details of the terminal device used, the IP address and the user's browser and other data from Google services for the provision of Google services related to our website.

If the service is activated on our website, our website establishes a connection to the servers of Google Ireland Limited and transmits the required data. As part of order processing, personal data may also be transmitted to the servers of Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States. when using the Google service on our website, Google may transmit and process information from other Google services in order to provide background services for the display and data processing of the services provided by Google. For this purpose, data may also be transferred to the Google services Google Apis, Doubleclick, Google Cloud, Google Ads and Google Fonts in accordance with the Google Privacy Policy. You can view the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://policies.google.com/privacy.

The provider also offers an opt-out option at https://support.google.com/My-Ad-Center-Help/answer/12155451?hl=deGoogle Analytics

Scope of the processing of personal data

On our site we use the web tracking service of the company Google Ireland Ltd., Gordon House, Barrow Street, 4 Dublin, Ireland, email: support-deutschland@google.com, website: https://www.google.com/ (hereinafter: Google Analytics). Within the scope of web tracking, Google-Analytics uses cookies that are stored on your computer and enable an analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis on the basis of the Google Analytics tracking service in order to constantly optimise our website and make it more accessible. When you use our website, data such as your IP address and your user activities in particular are transmitted to servers of Google Ireland Limited. We carry out this analysis on the basis of Google's tracking service in order to constantly optimise our website and make it more accessible. We also need the web tracking for security reasons. Web tracking allows us to track whether third parties are attacking our website. The information from the web tracker enables us to take effective countermeasures and protect the personal data we process from these cyber

page8image73180720 page8image73180928 page8image73181136 page8image73181344page8image73181552 page8image73181760

Page 8 of 29

page9image73055888

attacks. By activating IP anonymisation within the Google Analytics tracking code of this website, your IP address will be anonymised by Google Analytics before transmission. This website uses a Google Analytics tracking code that has been extended by the operator gat._anonymizeIp(); to enable only anonymised collection of IP addresses (so- called IP masking).

Legal basis for the processing of personal data

The legal basis for data processing is your consent in our information banner regarding the use of cookies and web tracking (consent through clear confirming action or behaviour) in accordance with Art. 13 Para. 1 FADP and Art. 6 Para. 1 lit. a GDPR.

Purpose of data processing

Google will use this information on our behalf for the purpose of evaluating your visit to this website, compiling reports on website activity and providing us with other services relating to website activity and internet usage. We also require web tracking for security reasons. Web tracking allows us to track whether third parties are attacking our website. The information from the web tracker allows us to take effective countermeasures and protect the personal data we process from these cyber attacks.

Duration of storage

Google will store the data relevant to the provision of web tracking for as long as is necessary to fulfil the booked web service. The data collection and storage is anonymised. If there is a reference to a person, the data will be deleted immediately, insofar as this is not subject to any statutory retention obligations. In any case, the data will be deleted after expiry of the retention period.

Opposition and deletion options

You can prevent the collection and forwarding of personal data to Google (in particular your IP address) and the processing of this data by Google by deactivating the execution of script code in your browser or activating the "Do Not Track" setting of your browser. You can also prevent the collection of data generated by the Google cookie and related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plug-in available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de). Google's security and privacy policy can be found at https://policies.google.com/privacy.

Gstatic

We use on our site the service Gstatic of the company Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: https://www.google.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und- wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d- 4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

page9image73179472 page9image73179680 page9image73179264 page9image73179056page9image73178848 page9image73178640 page9image73178432page9image73178224

Page 9 of 29

page10image73054640

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

Gstatic is a background service used by Google to retrieve static content in order to reduce bandwidth usage and preload required catalogue files. In particular, the service loads background data for Google Fonts and Google Maps.

As part of the order processing, personal data may also be transmitted to the servers of Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States. You can access the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://policies.google.com/privacy.

The provider also offers an opt-out option at https://support.google.com/My-Ad-Center-Help/answer/12155451?hl=deKliken

We use on our site the service Kliken of the company Kliken GmbH, Baarerstrasse 8, 6302 Zug, Switzerland, e-mail: privacy@sitewit.com, website: https://www.kliken.com/. Processing is carried out exclusively in Switzerland in accordance with the data protection legislation applicable there. From the EU's perspective, the data processing takes place in a third country for which there is no adequacy decision by the EU Commission. Therefore, the usual level of protection for the GDPR cannot be guaranteed for the transfer, as it cannot be ruled out that in the third country, e.g. authorities can access the collected data.your data can only be transferred to these third countries if it is ensured that the personal data are sufficiently protected at the recipient's. This can be done through the use of standard contractual clauses, in the case of data transfers within a corporate group through so-called Binding Corporate Rules, through an obligation to comply with codes of conduct that have been declared generally applicable by the Commission or through certification of the processing operation.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

Kliken's plugin enables users to optimise their website with customised marketing strategies to increase traffic and boost conversion rates. It offers tools for analysing user behaviour, campaign management and ad creation to support successful online marketing.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://www.kliken.com/privacy-policy.html.

POWR

We use on our site the service POWR of the company POWR HQ, 44 Tehama Street, 94105 San Francisco, United States, e- mail: support@powr.io, website: https://www.powr.io/. Your personal data will be transferred to so-called insecure third countries which do not guarantee adequate data protection through their legislation. Your data will only be transferred if appropriate data protection is guaranteed. This can be guaranteed by:

page10image73054224 page10image73054016 page10image73053808 page10image73053600page10image73053392 page10image73053184 page10image73052976 page10image73052768

Page 10 of 29

page11image72805760

contracts under international law
Data protection clauses in a contract between the controller or processor and his contractual partner, which have been notified in advance to the FDPIC
specific safeguards drawn up by the competent federal body and communicated in advance to the FDPIC
Standard data protection clauses which the FDPIC has approved, issued or recognised in advance, or
binding internal company data protection regulations which have been approved in advance by the FDPIC or by an authority responsible for data protection in a state which guarantees adequate protection

If such guarantees do not exist, your data may only be disclosed if you have given your consent, if the disclosure is directly related to the conclusion or performance of a contract, or if the disclosure is necessary in the context of the enforcement of claims before courts and authorities or to protect public interests. From the EU's perspective, the data processing takes place in a third country for which there is no adequacy decision by the EU Commission. Therefore, the usual level of protection for the GDPR cannot be guaranteed for the transfer, as it cannot be ruled out that in the third country, e.g. authorities can access the collected data.your data can only be transferred to these third countries if it is ensured that the personal data are sufficiently protected at the recipient's. This can be done through the use of standard contractual clauses, in the case of data transfers within a corporate group through so-called Binding Corporate Rules, through an obligation to comply with codes of conduct that have been declared generally applicable by the Commission or through certification of the processing operation.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

The Service allows us to include various tools on our website to make it more attractive and to interact with our users. These tools may include: a newsletter, pop-up questionnaires, countdowns, videos, galleries, displaying entries from social media platforms, a live chat, FAQs, forums, collecting information about our customers.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at

https://www.powr.io/privacy.
The provider also offers an opt-out option at 
https://www.powr.io/privacy.

YouTube

We use on our site the service YouTube of the company Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: https://www.google.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und- wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d- 4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

page11image72806176 page11image72806384 page11image72806592 page11image72806800page11image72807008 page11image72807216 page11image72807424page11image72807632

Page 11 of 29

page12image72803264

Videos from the Youtube platform are integrated on our website via the Youtube service. Through the integration, we can show you videos directly on our website. In this way, visitors to our website can view information about our services without having to visit the Youtube platform.

For the processing itself, the service or we collect the following data: Data for displaying the stream, data on videos clicked on, playlists created, ratings and comments, information on the terminal device used, the IP address and the user's browser and further data from Google services for providing the video in accordance with the Google privacy policy

if YouTube is activated on our website and a video is played, our website establishes a connection to the servers of Google Ireland Limited and transmits the data required to display the stream or video. As part of order processing, personal data may also be transmitted to the servers of Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States. personal data is also transferred to the USA. With regard to the transfer of personal data to the USA, there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en). The operator of the service is certified under the GDPR, so that the usual level of protection of the GDPR applies to the transfer. When YouTube videos are displayed on our website, YouTube may transmit and process information from other Google services in order to provide background services for the video, such as streaming data. For this purpose, data may also be transferred to the Google services Google Fonts, Google Apis, Google Video, Doubleclick. You can view the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://policies.google.com/privacy.

The provider also offers an opt-out option at https://support.google.com/My-Ad-Center-Help/answer/12155451?hl=delightspeed

We use on our site the service lightspeed of the company Lightspeed Commerce Inc., Friedrichstraße 95, 10117 Berlin, Germany, e-mail: info@datenschutzbeauftragte-berlin.eu, website: https://www.lightspeedhq.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel- und-wirtschaft/uebermittlung-ins-ausland.html. The processing also takes place in a third country outside the EU. For this third country, there is an adequacy decision of the Commission. On the page of the EU Commission (link:https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_de) you will find an up-to-date list of all adequacy decisions.

The legal basis for the transmission of personal data is the contract already concluded or to be concluded between you and us pursuant to Art. 31 para. 2 let. a FADP and Art. 6 para. 1 let. b GDPR.

By using the plugin, we use the services of Lightspeed. Lightspeed is aimed at restaurateurs and offers them functions such as reservation systems, ordering and cash register systems, laboratory and inventory tracking.

You can find out what rights you have with regard to processing at the end of this privacy statement.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://www.ecwid.com/privacy-policy.

page12image72802848 page12image72646656 page12image72646864page12image72647072 page12image72647280 page12image72647488page12image72647696 page12image72647904page12image72648112 page12image72648320

Page 12 of 29

page13image72547984

Integration of external web services and processing of data outside the EU

On our website, we use active content from external providers, so-called web services. By calling up our website, these external providers may receive personal information about your visit to our website. This may involve the processing of data outside of Switzerland and the EU. You can prevent this by installing an appropriate browser plug-in or deactivating the execution of scripts in your browser. This may result in functional restrictions on Internet pages that you visit.

We use the following external web services:

Amazon CloudFront (CDN)

We use on our site the service Amazon CloudFront (CDN) of the company Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg, Luxembourg, e-mail: privacyshield@amazon.com, website: https://aws.amazon.com/de/cloudfront/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und-wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

The legal basis for the transmission of personal data is our legitimate interest in processing pursuant to Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in achieving the purpose described below.

Amazon CloudFront CDN is a content delivery network that mirrors our content across multiple servers to ensure optimal accessibility worldwide.

You can access the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

With regard to the processing, you have the right of objection listed in Art. 21 GDPR. You can find more information at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://aws.amazon.com/de/privacy/?nc1=f_pr.

Google Cloud APIs

We use on our site the service Google Cloud APIs of the company Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: https://www.google.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und- wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d- 4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

page13image72678848 page13image72678640 page13image72678432page13image72678224 page13image72803472 page13image72804096page13image72803888 page13image72804304 page13image72804512 page13image72804720page13image72805136 page13image72804928

Page 13 of 29

page14image72365680

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

We use Google APIs in order to be able to load additional services from Google on the website. Google Apis is a collection of interfaces for communication between the various Google services used on your website. The service is used in particular to display the Google Fonts fonts and to provide the Google Maps map.

For the processing itself, the service or we collect the following data: IP address

If the service is activated on our website, our website establishes a connection to the servers of Google Ireland Limited and transmits the required data. As part of order processing, personal data may also be transmitted to the servers of Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States. when using the Google service on our website, Google may transmit and process information from other Google services in order to provide background services for the display and data processing of the services provided by Google. For this purpose, data may also be transferred to the Google services Google Cloud, Google Maps, Google Ads and Google Fonts in accordance with the Google data protection declaration under Google's responsibility under data protection law. You can access the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://policies.google.com/privacy.

The provider also offers an opt-out option at https://support.google.com/My-Ad-Center-Help/answer/12155451?hl=deGoogle Fonts

We use on our site the service Google Fonts of the company Google Ireland Limited, Gordon House, Barrow Street, 4 Dublin, Ireland, e-mail: support-deutschland@google.com, website: https://www.google.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und- wirtschaft/uebermittlung-ins-ausland.html. Personal data is also transferred to the U.S. With regard to the transfer of personal data to the U.S., there is an adequacy decision on the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 of the GDPR (hereinafter: DPF - https://commission.europa.eu/document/fa09cbad-dd7d- 4684-ae60-be03fcb0fddf_en ). The operator of the service is certified under the DPF, so that the usual level of protection of the GDPR applies to the transfer.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

We use the Google Fonts service to be able to integrate attractive fonts on our website in order to be able to show you our website in a visually better version. The service may also be used on our website if other Google services are reloaded on our website that require Google Fonts fonts to run. This is the case, for example, if our website uses Google services that require Google Fonts to run.

For the processing itself, the service or we collect the following data: Data on fonts, IP address of the page visitor, statistics on the use of fonts and other data from Google services related to our website.

page14image72366096 page14image72366304 page14image72366512page14image72366720 page14image72366928 page14image72367136 page14image72367344page14image72367552 page14image72367760

Page 14 of 29

page15image141480000

If the service is activated on our website, our website establishes a connection to the servers of Google Ireland Limited and transmits the required data. As part of order processing, personal data may also be transmitted to the servers of Google LLC, 1600 Amphitheatre Parkway, 94043 Mountain View, United States. when using the Google service on our website, Google may transmit and process information from other Google services in order to provide background services for the display and data processing of the services provided by Google. For this purpose, data may also be transferred to the Google services Google Apis, Google Cloud and Google Ads in accordance with the Google Privacy Policy. You can view the provider's certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/list.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://policies.google.com/privacy.

The provider also offers an opt-out option at https://support.google.com/My-Ad-Center-Help/answer/12155451?hl=deJimstatic / Jimdo

We use on our site the service Jimstatic / Jimdo of the company Jimdo GmbH, Stresemannstraße 375, 22761 Hamburg, Germany, e-mail: info@jimdo.de, website: https://www.jimdo.com/de/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und-wirtschaft/uebermittlung-ins- ausland.html. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is our legitimate interest in processing pursuant to Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in achieving the purpose described below.

The service is the technical system behind our website for operating our website. We need the integration so that we can display our website to you and maintain content.

With regard to the processing, you have the right of objection listed in Art. 21 GDPR. You can find more information at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy athttps://de.jimdo.com/info/datenschutzerklaerung/.

The provider also offers an opt-out option at https://de.jimdo.com/info/datenschutzerklaerung/Legally ok Rechtstextsnippet und Module

We use on our site the service Legally ok Rechtstextsnippet und Module of the company Legally ok GmbH, Schochenmühlestrasse 6, 6340 Baar, Switzerland, e-mail: hello@legally-ok.com, website: https://www.legally-ok.com/. Processing is carried out exclusively in Switzerland in accordance with the data protection legislation applicable there. The processing also takes place in a third country outside the EU. For this third country, there is an adequacy decision of the Commission. On the page of the EU Commission (link: https://ec.europa.eu/info/law/law-topic/data-protection/international- dimension-data-protection/adequacy-decisions_de) you will find an up-to-date list of all adequacy decisions.

The legal basis for the transmission and processing is Art. 31 para. 1 FADP and Art. 6 para. 1 lit. c GDPR. The use of the service helps us to comply with our legal obligations.

page15image141480416 page15image141480624 page15image141480832 page15image141481040page15image141481248 page15image141481456 page15image141481664page15image141481872 page15image141482080 page15image141482288 page15image141482496page15image141482704 page15image141482912

Page 15 of 29

page16image141306224

With the help of the service, the contents of our legal texts are reloaded on our website. The respective current legal texts are reloaded via the integration on our page. This integration may also be used to reload further technical modules with regard to the legal texts or legally required elements.

You can find out what rights you have with regard to processing at the end of this privacy statement.
For further information on the handling of transmitted data, please refer to the provider's privacy policy at

https://www.legally-ok.com/datenschutz/PayPal

We use the service PayPal of the company PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg on our website. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und-wirtschaft/uebermittlung-ins-ausland.html. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is the contract already concluded or to be concluded between you and us pursuant to Art. 31 para. 2 let. a FADP and Art. 6 para. 1 let. b GDPR.

The service is integrated by us in order to be able to show you the PayPal button on every sub-page in our online shop, so that you know which payment method you can use to shop with us....

Due to the contract concluded between you and PayPal, data may be transferred to companies affiliated with PayPal in the event of payment via PayPal. These companies may also be located in the USA, which is why it cannot be ruled out that US authorities may have access to your data.

You can find out what rights you have with regard to processing at the end of this privacy statement.
For further information on the handling of transmitted data, please refer to the provider's privacy policy at

https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DEPayPalObjects

We use the service PayPalObjects of the company PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg on our website. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und-wirtschaft/uebermittlung-ins-ausland.html. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is the contract already concluded or to be concluded between you and us pursuant to Art. 31 para. 2 let. a FADP and Art. 6 para. 1 let. b GDPR.

The service is integrated by us in order to be able to show you the PayPal button on every subpage in our online shop, so that you know which payment method you can use to shop with us.

Due to the contract concluded between you and PayPal, data may be transferred to companies affiliated with PayPal in the event of payment via PayPal. These companies may also be located in the USA, which is why it cannot be ruled out that US authorities may have access to your data.

page16image141306640 page16image141306848page16image141307056page16image141307264

Page 16 of 29

page17image141196528

You can find out what rights you have with regard to processing at the end of this privacy statement.
For further information on the handling of transmitted data, please refer to the provider's privacy policy at

https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DESoundcloud

We use on our site the service Soundcloud of the company SoundCloud Global Limited & Co. KG, Rheinsberger Str. 76/77, 10115 Berlin, Germany, e-mail: contact@soundcloud.com, website: https://soundcloud.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und- wirtschaft/uebermittlung-ins-ausland.html. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is the contract already concluded or to be concluded between you and us pursuant to Art. 31 para. 2 let. a FADP and Art. 6 para. 1 let. b GDPR.

With the help of the service, we can load and display media such as videos, sound streams or similar on our website. The use of the service is necessary to be able to offer you the function on our site.

You can find out what rights you have with regard to processing at the end of this privacy statement.
For further information on the handling of transmitted data, please refer to the provider's privacy policy at

https://soundcloud.com/pages/privacy.
The provider also offers an opt-out option at 
https://soundcloud.com/pages/privacy.

ecomm.events

We use on our site the service ecomm.events of the company ma-edv GmbH, Irsham 68, 94081 Fürstenzell, Germany, e- mail: dsb@omnis-consulting.de, website: https://www.ma-edv.com/. According to the assessment of Swiss authorities, the processing takes place in safe third countries. You can find the list of countries in Switzerland and further information at the following link: https://www.edoeb.admin.ch/edoeb/de/home/datenschutz/handel-und-wirtschaft/uebermittlung-ins- ausland.html. The transmission and processing of personal data takes place exclusively on servers in the European Union.

The legal basis for the transmission of personal data is your consent pursuant to Art. 6 para. 6 FADP or Art. 31 para. 2 FADP and pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have given on our website.

An advertising network is accessed via the service. The service thus serves us to display advertising of any kind.

You can revoke your consent at any time. You will find more information on revoking your consent either with the consent itself or at the end of this privacy policy.

For further information on the handling of transmitted data, please refer to the provider's privacy policy at https://www.ma- edv.com/datenschutz.

Social Plug-In - "Facebook by META"

page17image141306016 page17image141305392 page17image141305600page17image141305184 page17image141304976 page17image141304768page17image141304560 page17image141304352 page17image141304144page17image141303936 page17image141303728 page17image141303520 page17image141303312

What personal data is collected and to what extent is it processed?

Page 17 of 29

page18image141271168

On our website we have integrated a social plug-in of the social network "Facebook by META", which is operated by the Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5 Dublin 4, Ireland, e-mail: impressum- support@support.facebook.com, website: http://www.facebook.com/ ("Facebook by META"). When you call up a page that contains such a plug-in, your browser automatically establishes a background connection to the servers of Facebook by META. The content of the plug-in is transmitted directly to your browser by Facebook by META and only integrated into our site. Through this integration, Facebook by META receives the information that your browser has loaded a specific page of our website. This also applies if you do not have a Facebook by META profile or are not currently logged in to Facebook by META. This information (including your IP address) is transmitted by your browser directly to a server of Facebook by META in Ireland and stored there. If you are logged in to Facebook by META, Facebook by META can immediately assign your visit to our website to your Facebook by META profile. If you interact with the plug-ins, for example by clicking the "Like" button or posting a comment, this information is also transmitted directly to a server of Facebook by META and stored there. The information is also published on your Facebook by META profile and displayed to your Facebook by META contacts that you have activated for this purpose.

Legal basis for the processing of personal data

Relevant are Art. 6 ff. FADP as well as Art. 6 para. 1 lit. a GDPR (if you have registered with "Facebook by META") and Art. 6 para. 3 FADP as well as Art. 6 para. 1 lit. f GDPR (if you have not registered with Facebook by META ). Insofar as the processing is carried out on the basis of Art. 6 para. 1 sentence 1 lit. f GDPR, the legitimate interest of the site operator is to enable user interaction with the content of the site operator at Facebook by META.

Purpose of data processing

The primary purpose of the data collection is to offer you a possibility of social interaction linked to Facebook by META and thus to make our website interactive. The scope of data collection and the further processing and use of the data you leave behind by Facebook by META as well as your rights in this regard and setting options for protecting your privacy can be found in the data protection notes of Facebook by META:https://www.facebook.com/about/privacy

Duration of storage

Facebook by META will store the data relevant for the provision of the web service for as long as it is necessary. Insofar as the data is subject to statutory retention obligations, it will be deleted after the retention obligation has expired.

Possibility of objection and deletion

If you do not want the social plug-in from Facebook by META to run, you can also prevent it from running by installing an appropriate add-on or script blocker. If you do not want Facebook by META to assign the data collected via our website to your Facebook by META profile, you must log out of Facebook by META before visiting our website. The right to information, correction and deletion, as well as the right to restrict processing and the right to object, are also governed by the general regulations on the right to object and the right to deletion under data protection law described below in this data protection declaration.

page18image141271584 page18image141271792 page18image141272000 page18image141272208

Information on the use of cookies

Page 18 of 29

page19image141142800

Scope of the processing of personal data

We integrate and use cookies on various pages to enable certain functions of our website and to integrate external web services. The so-called "cookies" are small text files that your browser can store on your access device. These text files contain a characteristic string that uniquely identifies the browser when you return to our website. The process of saving a cookie file is also referred to as "setting a cookie". Cookies can be set both by the website itself and by external web services.

Legal basis for the processing of personal data

Relevant are Art. 6 ff. FADP (principles) as well as Art. 6 para. 1 lit. f GDPR (legitimate interest) and Art. 6 para. 1 lit. a and Art. 9 para. 2 lit. a GDPR (consent).

Which legal basis is relevant can be seen from the cookie table listed later in this point.

In general, in the case of cookies that are collected on the basis of a legitimate interest, our legitimate interest is to ensure the functionality of our website and the services integrated on it (technically necessary cookies). In addition, it may be that the cookies increase their user-friendliness and enable a more individualised approach. Here we have weighed up your interests against our interests.

With the help of cookie technology, we can only identify, analyse and track individual website visitors if the website visitor has consented to the use of the cookie in accordance with Art. 6 para. 6 FADP or Art. 6 para. 1 lit. a GDPR.

Purpose of the data processing

The cookies are set by our website or the external web services in order to maintain the full functionality of our website, to improve the user-friendliness or to pursue the purpose stated with your consent. Cookie technology also allows us to recognise individual visitors by pseudonyms, e.g. an individual or random IDs, so that we can offer more personalised services. Details are provided in the table below.

Duration of storage

The cookies listed below are stored in your browser until they are deleted or, in the case of a session cookie, until the session has expired. Details are listed in the table below:

page19image141143424

Cookie name ASP.NET_SessionId

page19image141143632

Server analytics.sitewit.com

page19image141143840

Provider Kliken

page19image141144048

Purpose We use ASP.NET_SessionId to manage the state of your session on our website. This cookie generates a unique session ID for each visitor and allows us to store information

about your current session state. This allows us to retain, for example, your login information, selected language settings and other user-specific data during your visit to our website to provide you with a seamless and personalised experience.

page19image141144256

Legal basis Contract performance

page19image141144464

Storage period Session

page19image141144672

Type Configuration

page19image141144880

Cookie name AWSALBCORS

Page 19 of 29

page20image141137600
 

Server analytics.sitewit.com

 

Provider Kliken

Purpose This cookie is associated with Amazon Web Services. It is used to control the load balancer. This ensures an even load distribution so that our website always loads as

quickly and efficiently as possible.

Legal basis Legitimate interest

Storage period approx. 7 days

Type Configuration

 

Cookie name LAST_RESULT_ENTRY_KEY

Server www.youtube-nocookie.com

page20image141141136

Provider YouTube

page20image141140720

Purpose Saves the user settings when retrieving a Youtube video integrated on other websites.

Legal basis Consent

Storage period Session

Type Comfort

 

Cookie name PHPSESSID

Server www.audiolounge-pro.com

page20image141000912

Provider Website operator](#responsible-entity)

Purpose

We use the cookie "PHPSESSID" to manage the user session on our website. The purpose of this cookie is to provide a unique identifier for a user's session while they are visiting our website. This allows us to track the state of the session and ensure that the server can correctly identify the user to ensure smooth interaction with the website. The cookie usually contains a random string of characters that acts as a session ID. After the session ends, for example when the user closes the browser, the cookie is usually deleted.

Legal basis Legitimate interest

Storage period Session

Type Comfort

 

Cookie name __utma

Server audiolounge-pro.com, www.audiolounge-pro.com

page20image141002576

Provider Google Analytics

page20image141002992

Purpose This cookie is the tracking cookie of Google Analytics. This cookie stores a unique visitor ID, the date and time of the first visit, the start time of the active visit, as well as the

number of visitors a unique visitor has made to the website.

Legal basis Consent

Storage period approx. 24 months

Type Analytics

 

Cookie name __utmb

Server audiolounge-pro.com, www.audiolounge-pro.com

page20image141004448

Provider Google Analytics

page20image141004864

Page 20 of 29

page21image141032064
 

Purpose This cookie distinguishes between an ongoing and a new visit to the website. It measures which pages the site visitor calls up and is therefore essential for tracking.

 

Legal basis Consent

Storage period approx. 31 minutes

Type Analytics

 

Cookie name __utmc

Server audiolounge-pro.com, www.audiolounge-pro.com

page21image141025200

Provider Google Analytics

page21image141025616

Purpose This cookie is no longer used by Google Analytics. However, it is set so that Google Analytics still works in older browsers.

Legal basis Consent

Storage period Session

Type Analytics

 

Cookie name __utmt_a

Server audiolounge-pro.com

Provider Google Analytics

page21image141026864

Purpose The cookie is used to collect anonymous data about visitor behaviour on the website. It is used to track the number of visits and visitors to the website.

Legal basis Consent

Storage period approx. 11 minutes

Type Analytics

 

Cookie name __utmv

Server audiolounge-pro.com, www.audiolounge-pro.com

page21image141032272

Provider Google Analytics

page21image141027488

Purpose This cookie is used to pass values to a custom variable to Google Analytics.

Legal basis Consent

Storage period approx. 40 seconds

Type Analytics

 

Cookie name __utmz

Server audiolounge-pro.com, www.audiolounge-pro.com

page21image141029984

Provider Google Analytics

page21image141030400

Purpose This cookie is the visitor source cookie. It stores from which source the user arrived on the page.

Legal basis Consent

Storage period approx. 6 months

Type Analytics

 

Page 21 of 29

page22image140848928
 

Cookie name _fbp

 

Server .audiolounge-pro.com, .com

Provider Facebook Connect

page22image141022496

Purpose Facebook uses this cookie to display advertising products and to assign advertising clicks to a user.

Legal basis Consent

Storage period approx. 3 months

Type Marketing

 

Cookie name _swa_u

Server audiolounge-pro.com

Provider Website operator](#responsible-entity)

Purpose This cookie is used to track the user and aggregate the user's interactions under one ID.

Legal basis Consent

Storage period approx. 3 years

Type Analytics

 

Cookie name ckies_control-cookies-wildcard

Server www.audiolounge-pro.com

page22image140674896

Provider Jimstatic / Jimdo

page22image140675312

Purpose This cookie stores whether the cookie banner or the cookie notice regarding marketing cookies has been displayed correctly to you and we have opted you in regarding the use of

cookies on our website.

Legal basis Fulfilment of legal obligations

Storage period Session

Type Cookie banner

 

Cookie name ckies_cookielaw

Server www.audiolounge-pro.com

page22image140676768

Provider Jimstatic / Jimdo

page22image140677184

Purpose This cookie stores whether the cookie banner or the cookie notice regarding marketing cookies has been displayed correctly to you and we have opted you in regarding the use of

cookies on our website.

Legal basis Fulfilment of legal obligations

Storage period approx. 12 months

Type Cookie banner

 

Cookie name ckies_fb_analytics

Server www.audiolounge-pro.com

page22image140678640

Provider Jimstatic / Jimdo

page22image140679056

Purpose This cookie allows us to save individual comfort settings you have selected and to retain them for your current and future visits to the site.

Page 22 of 29

page23image140848304
 

Legal basis Consent

 

Storage period approx. 12 months

Type Configuration

 

Cookie name ckies_ga

Server www.audiolounge-pro.com

page23image140704176

Provider Website operator](#responsible-entity)

Purpose This cookie stores whether the cookie banner or the cookie notice regarding the Google Analytics cookies was displayed correctly and whether you have decided to use cookies

on our website.

Legal basis Fulfilment of legal obligations

Storage period approx. 12 months

Type Cookie banner

 

Cookie name ckies_google_maps

Server www.audiolounge-pro.com

page23image140705216

Provider Website operator](#responsible-entity)

Purpose This cookie stores whether the cookie banner or the cookie notice regarding Google Maps cookies was correctly displayed to you and we have decided regarding the use of cookies

on our website.

Legal basis Fulfilment of legal obligations

Storage period approx. 12 months

Type Cookie banner

 

Cookie name ckies_jimdo-cart-v1

Server www.audiolounge-pro.com

page23image140510016

Provider Jimstatic / Jimdo

page23image140510432

Purpose This cookie allows us to save individual comfort settings you have selected and to retain them for your current and future visits to the site.

Legal basis Consent

Storage period Session

Type Configuration

 

Cookie name ckies_jimdo_analytics

Server www.audiolounge-pro.com

page23image140511888

Provider Jimstatic / Jimdo

page23image140512304

Purpose This cookie stores whether the cookie banner or the cookie notice regarding marketing cookies has been displayed correctly to you and we have opted you in regarding the use of

cookies on our website.

Legal basis Fulfilment of legal obligations

Storage period approx. 12 months

Type Cookie banner

Page 23 of 29

page24image140847056
 

Cookie name ckies_phpsessionid

 

Server www.audiolounge-pro.com

page24image140849344

Provider Jimstatic / Jimdo

page24image140847680

Purpose This cookie allows us to save individual comfort settings you have selected and to retain them for your current and future visits to the site.

Legal basis Consent

Storage period Session

Type Configuration

 

Cookie name ckies_powr-v2

Server www.audiolounge-pro.com

page24image140845808

Provider Website operator](#responsible-entity)

Purpose This cookie stores whether the cookie banner has already been displayed to you and your decision regarding the use of cookies on our website.

Legal basis Fulfilment of legal obligations

Storage period approx. 12 months

Type Cookie banner

 

Cookie name ckies_powr_marketing

Server www.audiolounge-pro.com

page24image140852256

Provider Website operator](#responsible-entity)

Purpose This cookie stores whether the cookie banner has already been displayed to you and your decision regarding the use of cookies on our website.

Legal basis Fulfilment of legal obligations

Storage period approx. 12 months

Type Cookie banner

 

Cookie name ckies_stripe

Server www.audiolounge-pro.com

page24image140842064

Provider Jimstatic / Jimdo

page24image140607488

Purpose This cookie allows us to save individual comfort settings you have selected and to retain them for your current and future visits to the site.

Legal basis Consent

Storage period Session

Type Configuration

 

Cookie name ckies_youtu

Server www.audiolounge-pro.com

page24image140608944

Provider Website operator](#responsible-entity)

Purpose This cookie stores whether the cookie banner or cookie notice has been correctly displayed to you and we have opted you in regarding the use of cookies on our website.

 

Page 24 of 29

page25image140538464
 

Legal basis Fulfilment of legal obligations

 

Storage period approx. 12 months

Type Cookie banner

 

Cookie name ec-*-session

Server www.audiolounge-pro.com

page25image140539296

Provider Website operator](#responsible-entity)

Purpose This cookie is used to save the customer's individual session in our shop system.

Legal basis Contract performance

Storage period Session

Type Configuration

 

Cookie name nextId

Server www.youtube-nocookie.com

page25image140841232

Provider YouTube

page25image140846848

Purpose This cookie is used to assign a unique ID to the user. This allows data about the behaviour of the website visitor to be collected and used to compile statistics about which YouTube

videos have been viewed by the site visitor on different websites.

Legal basis Consent

Storage period Session

Type Marketing

 

Cookie name requests

Server www.youtube-nocookie.com

page25image140846640

Provider YouTube

page25image140843104

Purpose We embed videos from our official YouTube channel in YouTube's private use mode. This mode may set cookies on your computer when you click on the YouTube video player, but

YouTube does not store personally identifiable cookie information for the playback of embedded videos in private mode.

Legal basis Consent

Storage period Session

Type Configuration

 

Cookie name sc_anonymous_id

Server .soundcloud.com

Provider Soundcloud

page25image140468560

Purpose This cookie assigns an ID to a page user when visiting subpages with embedded music files from Soundcloud in order to be able to play the music.

Legal basis Consent

Storage period approx. 10 years

Type Configuration

 

Page 25 of 29

page26image140306800

Cookie name utmt_b

page26image140307632

Server www.audiolounge-pro.com

page26image140307840 page26image140308048

Provider Google Analytics

page26image140308256 page26image140308464

Purpose This cookie allows us to save individual comfort settings you have selected and to retain them for your current and future visits to the site.

page26image140308672

Legal basis Consent

page26image140308880

Storage period approx. 11 minutes

page26image140309088

Type Configuration

page26image140309296

Possibility of objection, revocation of consent and deletion

You can set your browser according to your wishes so that the setting of cookies is generally prevented. You can then decide on a case-by-case basis whether to accept cookies or accept cookies in principle. Cookies can be used for various purposes, e.g. to recognise that your access device is already connected to our website (permanent cookies) or to save recently viewed offers (session cookies). If you have expressly given us permission to process your personal data, you can revoke this consent at any time. Please note that the legality of the processing carried out on the basis of the consent up to the revocation is not affected by this.

Data security and data protection, communication by e-mail

Your personal data is protected by technical and organisational measures during collection, storage and processing so that it is not accessible to third parties. In the case of unencrypted communication by e-mail, we cannot guarantee complete data security on the transmission path to our IT systems, so we recommend encrypted communication or the postal service for information requiring a high level of confidentiality.

Duration of data storage and rights of the data subject Duration of storage

We store personal data only to the extent and for as long as necessary to fulfil the purposes for which the personal data was collected, we have a legitimate overriding interest in retaining the data or are legally obliged to do so.

Right to information

You have the right to request confirmation as to whether we are processing personal data about you. If this is the case, you have the right to information on the data specified in 25 ff. FADP or Art. 15 para. 1 GDPR, insofar as the information cannot be refused, restricted or postponed by the owner of the data collection (cf. Art. 26 f. FADP or Art. 15 para. 4 GDPR). We will also be happy to provide you with a copy of the data.

Right of rectification

Pursuant to Art. 32 (1) FADP or Art. 16 GDPR, you have the right to demand that incorrect personal data (e.g. address, name, etc.) be corrected, provided that there is no legal obligation to the contrary. You can also request that the data stored by us be completed

Page 26 of 29

page27image140139008

at any time. A corresponding adjustment will be made immediately.

Right to erasure

Pursuant to Article 17 (1) of the GDPR, you have the right to have us delete the personal data we have collected about you if

the data is either no longer required;
the legal basis for processing has ceased to exist without replacement due to the revocation of your consent; there are no longer any legitimate reasons for processing the data;
Your data is being processed unlawfully;
a legal obligation requires this.

Pursuant to Article 17 (3) of the GDPR, this right does not exist if

the processing is necessary for the exercise of the right to freedom of expression and information; Your data has been collected on the basis of a legal obligation;
processing is necessary for reasons of public interest;
the data is necessary for the assertion, exercise or defence of legal claims.

Right to restrict processing

According to Art. 18 (1) GDPR, you have the right to request the restriction of the processing of your personal data in individual cases.

This is the case when

the accuracy of the personal data is disputed by you;
the processing is unlawful and you do not consent to its deletion;
the data is no longer required for the purpose of processing, but the collected data is used for the assertion, exercise or defence of legal claims;
an objection to the processing has been lodged pursuant to Art. 21 (1) GDPR and it is still unclear which interests prevail.

Right of withdrawal

If you have given us express consent to process your personal data (Art. 6 para. 6 FADP and Art. 31 para. 1 FADP; Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR), you may revoke this consent at any time. Please note that the lawfulness of the processing carried out on the basis of the consent up to the revocation is not affected by this. Information for which we are legally obliged to retain data will be deleted after expiry of the deadline.

Right to object

In accordance with Art. 21 of the GDPR, you have the right to object at any time to the processing of personal data relating to you that has been collected on the basis of Art. 6 (1) f of the GDPR (in the context of a legitimate interest). If you have given us express consent to process your personal data (Art. 6 para. 6 FADP and Art. 31 para. 1 FADP), you may revoke this consent at any time. Please note that the lawfulness of the processing carried out on the basis of the consent up to the revocation is not affected by this. You only have this right if there are special circumstances that speak against the storage and processing. Information for which we are legally obliged to store data will be deleted after expiry of the deadline.

Page 27 of 29

page28image140246048

How do you exercise your rights?

You can exercise your rights at any time by contacting us using the contact details below:

Audiolounge Bannwart Arkadenweg 5a
8600 Dübendorf Switzerland

E-mail: info@audiolounge-pro.com Tel: §41765612028

Right to data portability

Pursuant to Article 20 of the GDPR, you have a right to the transfer of personal data relating to you. We will provide the data in a structured, common and machine-readable format. The data can be sent either to you or to a person responsible named by you.

We will provide you with the following data upon request:

Data collected on the basis of consent (Art. 31 para. 1 FADP as well as Art. 6 para. 1 let. a GDPR);
Data that we have received from you in the context of existing contracts (Art. 31 para. 2 let. a FADP as well as Art. 6 para. 1 let. b GDPR and Art. 9 para. 2 let. a GDPR);
Data that has been processed as part of an automated procedure.

We will transfer the personal data directly to a responsible person of your choice as far as this is technically feasible. Please note that we are not permitted to transfer data that interferes with the overriding interests of third parties, or only to a limited extent, pursuant to Art. 26 (1) b FADP or Art. 20 (4) GDPR.

Notifications to the FDPIC and possibility to file a complaint

Pursuant to Art. 49 FADP, data subjects may file a report with the supervisory authority if there are sufficient indications that a data processing operation could violate data protection regulations. The supervisory authority for data protection in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).

For further information, please consult the contact form of the FDPIC:

https://www.edoeb.admin.ch/edoeb/de/home/deredoeb/kontakt.html

If you suspect that your data is being processed illegally on our website, you can seek clarification of the issue in court in accordance with Art. 32 FADP. As a rule, a lawsuit in accordance with Art. 28 ff. CC should be sought. If you are affected by the processing of data by federal bodies, the procedure is in accordance with Art. 41 FADP. In this case, you can also contact the FDPIC (see the reference to the contact form above).

Right of appeal to the supervisory authority pursuant to Art. 77 para. 1 GDPR

If you suspect that your data is being processed illegally on our site, you can of course have the issue clarified by the courts at any time. In addition, any other legal option is open to you. Irrespective of this, you have the option of contacting a supervisory

page28image140246464 page28image140246672

Page 28 of 29

page29image140080544

authority in accordance with Article 77 (1) of the GDPR. The right of appeal pursuant to Art. 77 GDPR is available to you in the EU Member State of your place of residence, your place of work and/or the place of the alleged infringement, i.e. you can choose the supervisory authority to which you turn from the above-mentioned places. The supervisory authority to which the complaint has been submitted will then inform you of the status and outcome of your submission, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.

page29image140080960

Page 29 of 29

We're social!

Connect with the Audiolounge community