MISTELHAIN ® Copyright 2025
Privacy
1.Data protection at a glance
General information
The following information provides a simple overview of what happens to your
personal data when you visit this website. Personal data is any data that can be used
to identify you personally. Detailed information on the subject of data protection can
be found in our privacy policy listed below this text.
Data collection on this website
Who is responsible for the data collection on this website?
Data processing on this website is carried out by the website operator. You can find
his contact details in the imprint of this website.
How do we collect your information?
On the one hand, your data is collected when you provide it to us. This can be, for
example, data that you enter into a contact form.
Other data is collected automatically or with your consent when you visit the website
by our IT systems. This is mainly technical data (e.g. Internet browser, operating
system or time of page access). The collection of this data takes place automatically as
soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure that the website is provided without errors.
Other data may be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient and purpose of
your stored personal data at any time, free of charge. You also have the right to
request the correction or deletion of this data. If you have given consent to data
processing, you can revoke this consent at any time for the future. You also have the
right to request the restriction of the processing of your personal data in certain
circumstances. Furthermore, you have the right to lodge a complaint with the
competent supervisory authority. For this and other questions on the subject of data
protection, you can contact us at any time at the address given in the imprint.
Analytics and third-party tools
When you visit this website, your surfing behaviour can be statistically evaluated.
This is mainly done with so-called analysis programs.
Detailed information about these analysis programs can be found in the following
privacy policy.
2. Hosting and Content Delivery Networks (CDN)
We host the content of our website with the following providers: Hetzner
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen,
Germany (hereinafter referred to as Hetzner). Details can be found in Hetzner's
privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz
The use of Hetzner is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in
presenting our website as reliably as possible. If a corresponding consent has been
requested, the processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR
and § 25 (1) TTDSG, insofar as the consent includes the storage of cookies or access to
information in the user's end device (e.g. device fingerprinting) within the meaning
of the TTDSG. The consent can be revoked at any time.
Order processing
We have concluded an order processing agreement (DPA) with the above-mentioned
provider. This is a contract required by data protection law that ensures that it
processes the personal data of our website visitors only in accordance with our
instructions and in compliance with the GDPR.
Shop
In this web page you will find a link to our webshop. For the tools and third-party
policies that apply there, please refer to the privacy policy in the shop.
3. General information and mandatory information
Privacy
The operators of these pages take the protection of your personal data very seriously.
We treat your personal data confidentially and in accordance with the statutory data
protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data
that can be used to identify you personally. This privacy policy explains what data we
collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission on the Internet (e.g. when
communicating by e-mail) may have security gaps. It is not possible to completely
protect the data from access by third parties.
Note on the responsible body
The person responsible for data processing on this website is:
Mistelhain GmbH & Co. KG
Straubinger Strasse 81
93055 Regensburg
Germany
Phone: +49 (0) 941 784472-0
E-Mail: info(at)mistelhain.com
The controller is the natural or legal person who, alone or jointly with others, decides
on the purposes and means of the processing of personal data (e.g. names, e-mail
addresses, etc.).
Storage period
Unless a specific storage period has been specified in this privacy policy, your
personal data will remain with us until the purpose for which the data is processed no
longer applies. If you assert a justified request for erasure or revoke consent to data
processing, your data will be deleted, unless we have other legally permissible
grounds for storing your personal data (e.g. retention periods under tax or
commercial law); in the latter case, the deletion takes place after these reasons have
ceased to exist.
General information on the legal basis of data processing on this website
If you have consented to data processing, we process your personal data on the basis
of Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR, insofar as special categories of data are
processed in accordance with Art. 9 (1) GDPR. In the case of explicit consent to the
transfer of personal data to third countries, data processing is also carried out on the
basis of Art. 49 (1) (a) GDPR. If you have consented to the storage of cookies or access
to information in your device (e.g. via device fingerprinting), data processing will also
be carried out on the basis of Section 25 (1) TTDSG. The consent can be revoked at any
time. If your data is required for the performance of a contract or for the
implementation of pre-contractual measures, we process your data on the basis of
Art. 6 (1) (b) GDPR. Furthermore, we process your data if it is necessary to comply
with a legal obligation on the basis of Art. 6 (1) (c) GDPR. Data processing may also be
carried out on the basis of our legitimate interest in accordance with Art. 6 (1) (f)
GDPR.
Information on the relevant legal bases in each individual case is provided in the
following paragraphs of this data protection declaration.
Note on data transfer to the USA and other third countries
Among other things, we use tools from companies based in the USA or other third
countries that are not secure under data protection law. When these tools are active,
your personal data may be transferred to and processed in these third countries. We
would like to point out that in these countries no level of data protection comparable
to that of the EU can be guaranteed. For example, US companies are obliged to hand
over personal data to security authorities without you, as the data subject, being able
to take legal action against it. It cannot therefore be ruled out that US authorities (e.g.
intelligence services) process, evaluate and permanently store your data on US servers
for surveillance purposes. We have responded to this
processing activities.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can
revoke any consent you have already given at any time. The lawfulness of the data
processing carried out up to the time of revocation remains unaffected by the
revocation.
Right to object to data collection in special cases as well as to direct marketing (Art. 21
GDPR)
IF DATA PROCESSING ON THE BASIS OF ART. 6 PARA. 1 LIT. E OR F GDPR, YOU
HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA
AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS
ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE
LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS
PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR
PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE
GROUNDS FOR THE PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS
AND FREEDOMS, OR THE PROCESSING SERVES TO ASSERT, EXERCISE OR
DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT
MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE
PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF
SUCH MARKETING; THIS ALSO APPLIES TO PROFILING, INSOFAR AS IT IS
RELATED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL
DATA WILL THEN NO LONGER BE USED FOR THE PURPOSE OF DIRECT
MARKETING (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, the data subjects have the right to lodge a
complaint with a supervisory authority, in particular in the Member State of their
habitual residence, their place of work or the place of the alleged infringement. The
right of appeal exists without prejudice to other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your
consent or in fulfilment of a contract handed over to you or to a third party in a
common, machine-readable format. If you request the direct transfer of the data to
another controller, this will only be done to the extent that it is technically feasible.
Information, deletion and correction
Within the framework of the applicable legal provisions, you have the right to free
information about your stored personal data, its origin and recipients and the
purpose of the data processing at any time and, if necessary, a right to rectification or
deletion of this data. You can contact us at any time for this and other questions on
the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data.
You can contact us at any time for this. The right to restriction of processing exists in
the following cases: If you contest the accuracy of your personal data stored by us, we
usually need time to verify this. For the duration of the audit, you have the right to
request the restriction of the processing of your personal data.
If the processing of your personal data was/is unlawful, you can request the
restriction of data processing instead of deletion.
If we no longer need your personal data, but you need it to exercise, defend or assert
legal claims, you have the right to request the restriction of the processing of your
personal data instead of erasure.
If you have filed an objection in accordance with Art. 21 (1) GDPR, a balancing of your
interests and ours must be carried out. As long as it has not yet been determined
whose interests prevail, you have the right to request the restriction of the processing
of your personal data.
If you have restricted the processing of your personal data, this data may only be
processed with your consent or for the establishment, exercise or defence of legal
claims, or for the protection of the rights of another natural or legal person, or for
reasons of important public interest of the European Union or of a Member State.
SSL or TLS encryption
This site uses SSL or TLS encryption for security reasons and to protect the
transmission of confidential content, such as orders or inquiries that you send to us
as the site operator. You can recognize an encrypted connection by the fact that the
address bar of the browser changes from "http://" to "https://" and by the lock symbol
in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by
third parties.
Information, deletion and correction
Within the framework of the applicable legal provisions, you have the right to free
information about your stored personal data, its origin and recipients and the
purpose of the data processing at any time and, if necessary, a right to rectification or
deletion of this data. For this and other questions on the subject of personal data, you
can contact us at any time at the address given in the imprint.
4. Data collection on this website
Cookies
Our websites use so-called "cookies". Cookies are small text files and do not cause any
damage to your device. They are stored on your device either temporarily for the
duration of a session (session cookies) or permanently (persistent cookies). Session
cookies are automatically deleted at the end of your visit. Permanent cookies remain
stored on your device until you delete them yourself or until your web browser
automatically deletes them.
In some cases, cookies from third-party companies may also be stored on your device
when you enter our website (third-party cookies). These enable us or you to use
certain services of the third party company (e.g. cookies used to process payment
services).
Cookies have different functions. Many cookies are technically necessary because
certain website functions would not work without them (e.g. the shopping cart
function or the display of videos). Other cookies are used to evaluate user behaviour
or to display advertising.
Cookies that are necessary to carry out the electronic communication process
(necessary cookies) or to provide certain functions desired by you (functional cookies,
e.g. for the shopping cart function) or to optimize the website (e.g. cookies to
measure the web audience) are stored on the basis of Art. 6 (1) (f) GDPR, unless
another legal basis is specified. The website operator has a legitimate interest in the
storage of cookies for the technically error-free and optimised provision of its
services. If consent to the storage of cookies has been requested, the storage of the
cookies in question is carried out exclusively on the basis of this consent (Art. 6 para. 1
lit. a GDPR); consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and
only allow cookies in individual cases, exclude the acceptance of cookies for certain
cases or in general, and activate the automatic deletion of cookies when you close the
browser. If you disable cookies, the functionality of this website may be limited.
If cookies are used by third-party companies or for analysis purposes, we will inform
you separately about this within the framework of this data protection declaration
and, if necessary, ask for consent.
Cookie consent with Usercentrics
This website uses Usercentrics' cookie consent technology to obtain your consent to
the storage of certain cookies on your device or to the use of certain technologies and
to document them in compliance with data protection regulations. The provider of
this technology is Usercentrics GmbH, Rosental 4, 80331 Munich, Germany, website:
https://usercentrics.com/de/ (hereinafter referred to as "Usercentrics"). When you
enter our website, the following personal data will be transferred to Usercentrics:
Your consent(s) or the withdrawal of your consent(s)
Your IP address
Information about your browser
Information about your device
Time of your visit to the website
Furthermore, Usercentrics stores a cookie in your browser in order to be able to
assign you the consents you have given or their revocation. The data collected in this
way will be stored until you ask us to delete it, delete the Usercentrics cookie yourself
or the purpose for which the data is stored no longer applies. Mandatory statutory
retention obligations remain unaffected.
Usercentrics is used to obtain the legally required consents for the use of certain
technologies. The legal basis for this is Art. 6 para. 1 sentence 1 lit. c GDPR.
Order processing
We have concluded a contract processing agreement (DPA) with Usercentrics. This is
a contract required by data protection law that ensures that Usercentrics processes
the personal data of our website visitors only in accordance with our instructions and
in compliance with the GDPR.
If you contact us by e-mail, telephone or fax, your enquiry, including all personal data
resulting from it (name, enquiry), will be stored and processed by us for the purpose
of processing your request. We do not pass on this data without your consent. The
processing of this data is carried out on the basis of Art. 6 (1) (b) GDPR if your request
is related to the performance of a contract or is necessary for the implementation of
pre-contractual measures. In all other cases, the processing is based on our legitimate
interest in the effective processing of the enquiries addressed to us (Art. 6 para. 1 lit. f
GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR), if this has been requested;
consent can be revoked at any time.
The information you send us
Data sent by contact requests will remain with us until you ask us to delete it, revoke
your consent to its storage or the purpose for which it is stored no longer applies (e.g.
after your request has been processed). Mandatory statutory provisions – in
particular statutory retention periods – remain unaffected.
Server log files
The provider of the pages automatically collects and stores information in so-called
server log files, which your browser automatically transmits to us. This
are: browser type and browser version operating system used
Referrer URL
Hostname of the accessing computer
Time of the server request
IP address
This data is not merged with other data sources.
This data is collected on the basis of Art. 6 (1) (f) GDPR. The website operator has a
legitimate interest in the technically error-free presentation and optimisation of its
website – for this purpose, the server log files must be recorded.
Contact
If you send us enquiries via the contact form, your details from the enquiry form,
including the contact details you provide there, will be stored by us for the purpose of
processing the enquiry and in the event of follow-up questions. We do not pass on
this data without your consent.
The processing of this data is carried out on the basis of Art. 6 (1) (b) GDPR if your
request is related to the performance of a contract or is necessary for the
implementation of pre-contractual measures. In all other cases, the processing is
based on our legitimate interest in the effective processing of the enquiries addressed
to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR), if this
has been requested.
The data you enter in the contact form will remain with us until you ask us to delete it,
revoke your consent to the storage or the purpose for which the data is stored no
longer applies (e.g. after your enquiry has been processed). Mandatory statutory
provisions – in particular retention periods – remain unaffected.
Registration on this website
You can register on this website to use additional features on the site. We use the data
entered for this purpose only for the purpose of using the respective offer or service
for which you have registered. The mandatory information requested during
registration must be provided in full. Otherwise, we will refuse registration.
For important changes, such as in the scope of the offer or in the event of technically
necessary changes, we will use the e-mail address provided during registration to
inform you in this way.
The data entered during registration is processed for the purpose of executing the
user relationship established by the registration and, if necessary, for the initiation of
further contracts (Art. 6 para. 1 lit. b GDPR).
The data collected during registration will be stored by us for as long as you are
registered on this website and will then be deleted. Statutory retention periods
remain unaffected.
5. Social media
eRecht24 Safe Sharing Tool
The content on this website can be shared in social networks such as Facebook,
Twitter & Co. in compliance with data protection regulations. This site uses the
eRecht24 Safe Sharing Tool for this purpose. This tool establishes direct contact
between the networks and users only when the user actively clicks on one of these
buttons. Clicking on the button constitutes consent within the meaning of Art. 6
para. 1 lit. a GDPR and § 25 para. 1 TTDSG. This consent can be revoked at any time
with effect for the future.
This tool does not automatically transfer user data to the operators of these
platforms. If the user is logged in to one of the social networks, an information
window appears when using Meta's social media elements, in which the user can
confirm the text before sending.
Our users can share the content of this page on social networks in compliance with
data protection regulations, without complete surfing profiles being created by the
operators of the networks.
The Service is used to obtain the consents required by law for the use of certain
technologies. The legal basis for this is Art. 6 (1) (c) GDPR.
Social media elements with Shariff
You can usually recognize the social media elements by the respective social media
logos. In order to ensure data protection on this website, we only use these elements
together with the so-called "Shariff" solution. This application prevents the social
media elements integrated on this website from transmitting your personal data to
the respective provider as soon as you first enter the page.
Only when you activate the respective social media element by clicking on the
corresponding button will a direct connection to the provider's server be established
(consent). As soon as you activate the social media element, the respective provider
receives the information that you have visited this website with your IP address. If
you are logged in to your respective social media account (e.g. Facebook) at the same
time, the respective provider can assign the visit to this website to your user account
Activating the plugin constitutes consent within the meaning of Art. 6 para. 1 lit. a
GDPR and § 25 para. 1 TTDSG. You can revoke this consent at any time with effect for
the future. The Service is used to obtain the consents required by law for the use of
certain technologies. The legal basis for this is Art. 6 (1) (c) GDPR.
Facebook This website integrates elements of the social network Facebook. The
provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square,
Dublin 2, Ireland. However, according to Facebook, the data collected will also be
transferred to the USA and other third countries. An overview of the Facebook social
media elements can be found here:
https://developers.facebook.com/docs/plugins/?locale=de_DE
When the social media element is active, a direct connection is established between
your device and the Facebook server. Facebook thus receives the information that you
have visited this website with your IP address. If you click the Facebook "Like" button
while logged into your Facebook account, you can link the content of this website to
your Facebook profile. This allows Facebook to associate the visit to this website with
your user account. We would like to point out that we, as the provider of the pages,
have no knowledge of the content of the transmitted data or its use by Facebook. For
more information, please refer to Facebook's privacy policy at: https://de-
de.facebook.com/privacy/explanation
If consent has been obtained, the above-mentioned service is used on the basis of Art.
6 (1) (a) GDPR and § 25 TTDSG. The consent can be revoked at any time.
If no consent has been obtained, the use of the service is based on our legitimate
interest in the widest possible visibility in social media.
Insofar as personal data is collected on our website and forwarded to Facebook with
the help of the tool described here, we and Meta Platforms Ireland Limited, 4 Grand
Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this
data processing (Art. 26 GDPR). Joint responsibility is limited exclusively to the
collection of data and its disclosure to Facebook. The processing by Facebook after the
transfer is not part of the joint responsibility. Our joint obligations have been set out
in a joint processing agreement. The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for the provision of data protection
information when using the Facebook tool and for the implementation of the tool on
our website in a manner that is secure under data protection law. Facebook is
responsible for the data security of Facebook products. You can assert the rights of
data subjects (e.g. requests for information) regarding the data processed by
Facebook directly with Facebook. If you assert your rights as a data subject with us,
we are obliged to forward them to Facebook.
The data transfer to the USA is based on the standard contractual clauses of the EU
Commission.
Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum https://de-
de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php
6. Analytics Tools and Advertising
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider
is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4,
Ireland.
Google Analytics enables the website operator to analyse the behaviour of website
visitors. In doing so, the website operator receives various usage data, such as page
views, dwell time, operating systems used and origin of the user. This data is
summarized in a user ID and assigned to the respective end device of the website
visitor. Furthermore, we can use Google Analytics to, among other things: Her
Record mouse and scroll movements and clicks. In addition, Google Analytics uses
various modeling approaches to complement the collected data sets and uses machine
learning technologies in the
data analysis.
Google Analytics uses technologies that enable the recognition of the user for the
purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The
information collected by Google about the use of this website is usually transmitted to
a Google server in the USA and stored there.
The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a
GDPR and § 25 para. 1 TTDSG. The consent can be revoked at any time. The use of
this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and
§ 25 para. 1 TTDSG. The consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU
Commission. Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/
IP anonymization
We have activated the IP anonymization function on this website. As a result, your IP
address will be shortened by Google within member states of the European Union or
in other contracting states of the Agreement on the European Economic Area before
it is transmitted to the USA. Only in exceptional cases is the full IP address
transmitted to a Google server in the USA and shortened there. On behalf of the
operator of this website, Google will use this information to evaluate your use of the
website, to compile reports on website activity and to provide other services related to
website activity and internet use to the website operator. The IP address transmitted
by your browser as part of Google Analytics will not be merged with other data held by
Google.
Demographics on Google Analytics
This website uses the "demographic characteristics" function of Google Analytics to be
able to show website visitors relevant advertisements within the Google advertising
network. This allows reports to be generated that contain statements about the age,
gender and interests of the site visitors. This data comes from interest-based
advertising from Google as well as visitor data from third-party providers. This data
cannot be assigned to a specific person. You can deactivate this function at any time
via the ad settings in your Google account or generally prohibit the collection of your
data by Google Analytics as described in the section "Objection to data collection".
Order processing
We have concluded a contract processing agreement with Google and fully implement
the strict requirements of the German data protection authorities when using Google
Analytics.
This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc.,
555 West 18th Street, New York, New York 10011, USA.
When you visit one of our pages equipped with Vimeo videos, a connection to Vimeo's
servers is established. The Vimeo server is informed which of our pages you have
visited. Vimeo also obtains your IP address. However, we have set Vimeo in such a
way that Vimeo will not track your user activities and will not set cookies. The use of
Vimeo is in the interest of an appealing presentation of our online offers. This
constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. If a
corresponding consent has been requested, the processing is carried out exclusively
on the basis of Art. 6 (1) (a) GDPR; consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU
Commission and, according to Vimeo, on "legitimate business interests". Details can
be found here: https://vimeo.com/privacy Further information on the handling of
user data can be found in Vimeo's privacy policy at: https://vimeo.com/privacy