Privacy Policy

Privacy Policy

We are very pleased about your interest in our company. Data protection has a particularly high priority for the management of Luvonio GmbH. The use of the internet pages of Luvonio GmbH is generally possible without providing any personal data. However, if a data subject wishes to use special services provided by our company via our website, processing of personal data may become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject. The processing of personal data, such as the name, address, email address, or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to Luvonio GmbH. By means of this privacy policy, our company would like to inform the public about the nature, scope, and purpose of the personal data we collect, use, and process. Furthermore, data subjects are informed of their rights under this privacy policy. As the controller, Luvonio GmbH has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, internet-based data transmissions may have security gaps, so absolute protection cannot be guaranteed. For this reason, any data subject is free to transfer personal data to us via alternative means, e.g., by telephone.

1. Definitions

This privacy policy is based on the terms used by the European legislator when adopting the General Data Protection Regulation (GDPR). Our aim is to ensure that this policy is easy to read and understand for the general public as well as our customers and business partners. To achieve this, we explain the terminology used as follows:

a) Personal data – any information relating to an identified or identifiable natural person (“data subject”).

b) Data subject – any identified or identifiable natural person whose personal data is processed.

c) Processing – any operation or set of operations performed on personal data, whether or not by automated means.

d) Restriction of processing – marking of stored personal data with the aim of limiting its processing in the future.

e) Profiling – any automated processing of personal data to evaluate certain personal aspects.

f) Pseudonymization – processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information.

g) Controller or data controller – the natural or legal person that determines the purposes and means of the processing of personal data.

h) Processor – a natural or legal person that processes personal data on behalf of the controller.

i) Recipient – a natural or legal person to whom personal data is disclosed.

j) Third party – a person or entity other than the data subject, controller, processor, or persons who are authorized to process personal data under the direct authority of the controller or processor.

k) Consent – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes.

2. Name and Address of the Controller

Controller within the meaning of the GDPR and other applicable data protection laws is:


Luvonio GmbH

Rathausgasse 17, 12529 Schönefeld, Germany

Phone: +49 1525 1492029

Email: info@luvonio.com

Website: www.luvonio.com


3. Cookies

The websites of Luvonio GmbH use cookies. Cookies are text files that are stored on a computer system via an internet browser. Many websites and servers use cookies. Many cookies contain a so-called cookie ID – a unique identifier. This enables visited websites and servers to distinguish the data subject’s individual browser from other internet browsers. By using cookies, Luvonio GmbH can provide more user-friendly services. For example, a user who allows cookies does not have to re-enter access data each time. Cookies can also remember the contents of a shopping cart. You can prevent cookies from being set via your browser settings and delete existing cookies at any time. However, if cookies are deactivated, some website features may not function fully.

4. Collection of General Data and Information

Each time the Luvonio GmbH website is accessed, a series of general data and information is collected and stored in the server log files. This may include: Browser types and versions Operating system used The website from which access was referred Sub-pages visited Date and time of access Internet Protocol (IP) address Internet service provider Other similar data related to IT security Luvonio GmbH does not draw conclusions about the data subject from this information. This data is used to ensure correct website content delivery, optimize the website and advertising, guarantee IT system stability, and provide necessary information in the event of cyberattacks. The anonymized data is evaluated statistically and stored separately from personal data. 

5. Registration on Our Website

Data subjects have the possibility to register on the controller’s website by providing personal data. Which personal data are transmitted to the controller is determined by the respective input form used for registration. The entered personal data are collected and stored exclusively for internal use by the controller and for the data subject’s own purposes. The controller may initiate transfer to one or more processors (e.g., parcel services) who also use the personal data exclusively for internal purposes attributed to the controller. Upon registration, the IP address assigned by the internet service provider (ISP), date, and time of registration are also stored. This is necessary to prevent misuse of our services and to investigate criminal offenses where applicable. Hence, the storage of this data is necessary to safeguard the controller. The registration of the data subject, voluntarily providing personal data, enables the controller to offer contents or services that may only be offered to registered users. Registered persons may at any time request the modification or deletion of their stored personal data. Upon request, the controller will inform any data subject of the personal data stored about them and will correct or delete such data, unless statutory retention requirements prevent this. The entirety of the controller’s employees is available to the data subject as contact persons.

6. Subscription to Our Newsletter

Users have the option to subscribe to the newsletter of Luvonio GmbH via the website. The input form used for this purpose determines which personal data is transmitted. Luvonio GmbH regularly informs customers and business partners about offers by means of a newsletter. The newsletter can only be received if: The data subject has a valid email address and The data subject registers for newsletter delivery. A confirmation email will be sent to the provided email address using the double opt-in procedure to verify the registration. During newsletter registration, we also store the IP address and the date and time of registration. This is necessary for legal security, particularly to trace potential misuse of the email address. The personal data collected will only be used for sending the newsletter. Subscribers may also be informed via email if necessary for the newsletter service (e.g., changes in the offer or technical updates). No data is passed on to third parties. The subscription can be canceled at any time. Each newsletter contains a corresponding unsubscribe link. Alternatively, users may unsubscribe via the website or by contacting the controller directly.

7. Newsletter Tracking

The newsletters of Luvonio GmbH contain so-called tracking pixels. These are miniature graphics embedded in HTML emails to enable log file recording and analysis. This allows a statistical analysis of marketing campaign success. Luvonio GmbH can see whether and when a newsletter was opened and which links were clicked. These personal data are stored and analyzed to optimize the newsletter and align it with the data subject's interests. These data are not shared with third parties. The data subject may revoke consent to this tracking at any time. Unsubscribing from the newsletter is interpreted as revocation.

8. Contact Option via the Website

The website of Luvonio GmbH contains information enabling electronic contact with our company, including a general email address. If a data subject contacts the controller via email or a contact form, the transmitted personal data is automatically stored. Such voluntarily provided personal data is stored for processing the request or contacting the data subject. It is not shared with third parties.

9. Comment Function in the Blog on the Website

Luvonio GmbH offers users the opportunity to leave comments on blog posts. If a data subject leaves a comment, the chosen username (pseudonym), timestamp, and IP address are stored and published. The IP address is stored for security and legal protection in case the comment infringes third-party rights or contains unlawful content. These data are not passed on to third parties unless legally required or for legal defense purposes.

10. Subscription to Blog Comments

Users may subscribe to blog comments following their own. If a data subject chooses to subscribe, a confirmation email using the double opt-in method will be sent to verify ownership of the provided email address. Subscriptions to comments can be canceled at any time.

11. Routine Erasure and Blocking of Personal Data

The controller processes and stores personal data only for the period necessary to achieve the purpose of storage or as required by the European legislator or other lawmakers. Once the storage purpose no longer applies or a legally mandated storage period expires, the personal data is routinely blocked or deleted in accordance with legal requirements.

12. Rights of the Data Subject

a) Right to confirmation Every data subject has the right to obtain confirmation from the controller as to whether personal data concerning them is being processed.

b) Right of access Data subjects have the right to obtain free information about their stored personal data and a copy of this information. This includes: Purposes of processing Categories of personal data processed Recipients or categories of recipients to whom data have been disclosed or will be Planned storage duration or criteria for determining it Existence of the right to rectification, erasure, restriction, or objection Right to lodge a complaint with a supervisory authority Source of data if not collected from the data subject Existence of automated decision-making including profiling and meaningful information about the logic involved and consequences If data is transferred to a third country or international organization, the data subject has the right to be informed of appropriate safeguards.

c) Right to rectification Data subjects have the right to request the rectification of inaccurate personal data and to have incomplete data completed.

d) Right to erasure ("right to be forgotten") The data subject has the right to request erasure of their data without undue delay if one of the following applies: The data is no longer needed Consent is withdrawn and there is no other legal basis Objection is made under Art. 21(1) or (2) GDPR The data has been unlawfully processed Erasure is required to comply with legal obligations The data was collected in relation to the offer of information society services If Luvonio GmbH has made personal data public and is obliged to delete it, we will inform other controllers processing the data of the deletion request.

e) Right to restriction of processing Data subjects may request the restriction of processing if: The accuracy of the data is contested Processing is unlawful but erasure is refused The controller no longer needs the data, but the data subject requires it for legal claims Objection has been made under Art. 21(1) GDPR and the outcome is pending

f) Right to data portability Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible.

g) Right to object Data subjects may object at any time to processing based on Art. 6(1)(e) or (f) GDPR, including profiling. If an objection is made, we will no longer process the data unless compelling legitimate grounds override the data subject’s interests, rights, and freedoms, or the processing serves legal claims. If personal data is used for direct marketing, the data subject can object at any time. In such cases, the data will no longer be used for that purpose.

h) Automated decisions including profiling Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, unless: It is necessary for entering or performing a contract It is authorized by law It is based on explicit consent In such cases, Luvonio GmbH ensures appropriate safeguards including the right to human intervention, to express a point of view, and to contest the decision.

i) Right to withdraw consent Data subjects have the right to withdraw consent to the processing of personal data at any time.

13. Data Protection for Applications and in the Application Process

The controller collects and processes personal data of applicants for the purpose of managing the application process. This may also occur electronically, especially if applications are submitted via email or web forms. If an employment contract is concluded, the data will be stored for the purpose of employment. If no contract is concluded, the application data will be deleted two months after rejection unless other legitimate interests (e.g. burden of proof under the AGG) justify retention.

14. Use of Affilinet

The controller has integrated components of Affilinet, a German affiliate network, on this website. Affiliate marketing allows commercial websites to place advertisements on third-party websites in return for commissions. Affilinet is operated by affilinet GmbH, Sapporobogen 6–8, 80637 Munich, Germany. Affilinet places a cookie on the data subject’s device. It stores the affiliate’s ID and visitor/order identifiers but no personal data. The purpose is to track commission payments. You can prevent cookie storage via browser settings and delete cookies at any time. For more information, please visit: https://www.affili.net/de/footeritem/datenschutz

15. Use of Facebook

This website integrates components of Facebook, a social networking platform operated by Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. For users in the EU, the responsible entity is Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland. When accessing a page with a Facebook plugin, your browser connects to Facebook’s servers and downloads the plugin content. Facebook is thus informed of which specific pages you visited. If you are logged into Facebook during the visit, Facebook assigns this visit to your user account. If you click on a plugin (e.g. “Like”) or post a comment, Facebook links this information to your account and stores it. If you do not want Facebook to collect data via our website, log out of your Facebook account before visiting. Facebook’s privacy policy is available at: https://www.facebook.com/about/privacy/

16. Use of Amazon Affiliate Program

This website integrates components of the Amazon Affiliate Program. These components are designed to allow the operator to earn advertising fees by placing advertisements and links to various Amazon sites (including Amazon.co.uk, Amazon.de, Amazon.fr, etc.). The provider is Amazon EU S.à.r.l., 5 Rue Plaetis, L-2338 Luxembourg. Amazon sets a cookie on the data subject’s device to track the origin of orders. The cookie stores the affiliate ID and order tracking numbers but does not collect personal data directly. The purpose is to allocate sales and commissions accurately. You can prevent cookies from being set at any time via your browser settings. Already set cookies can be deleted. For Amazon's privacy policy, visit: https://www.amazon.de/gp/help/customer/display.html?nodeId=3312401

17. Use of Google AdSense This website uses Google AdSense, a service for embedding advertisements. AdSense uses an algorithm to display context-sensitive and interest-based ads on third-party websites. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. Google AdSense uses cookies and tracking pixels to enable ad analysis and performance evaluation. By visiting the website, data such as the user’s IP address and browsing behavior are transmitted to Google and may be stored in the USA. The data helps Google understand the origin of visitors and assign advertising and commissions. You can prevent cookies via your browser settings. Further details: https://www.google.de/intl/de/adsense/start/

18. Use of Google Analytics (with Anonymization Function) This website uses Google Analytics (with IP anonymization). Google Analytics collects, analyzes, and reports on website usage data, such as which pages are visited and how often. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. To ensure GDPR compliance, we use the anonymization extension _gat._anonymizeIp, which shortens IP addresses within the EU or EEA. Google Analytics uses cookies to track and evaluate behavior, including: Time of access Location from which access occurred Frequency of visits IP address (anonymized) The data may be transmitted and stored in the USA. You can prevent tracking with browser settings or by installing this opt-out plugin: https://tools.google.com/dlpage/gaoptout Privacy policy and terms: https://www.google.de/intl/de/policies/privacy/ http://www.google.com/analytics/terms/de.html

19. Use of Google Remarketing This website uses Google Remarketing services. This allows advertising to be shown to users who previously visited the site, based on their interests. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. Google Remarketing places a cookie to recognize users across websites that are part of the Google advertising network. This allows ads tailored to the user’s behavior to be shown. Data such as IP addresses and browsing behavior may be collected and transferred to Google in the USA. Users can opt out by adjusting ad preferences here: www.google.de/settings/ads More info: https://www.google.de/intl/de/policies/privacy/

20. Use of Google+

This website integrates the Google+ button, a social network feature from Google. Users can share content, upload media, and connect via the Google+ platform. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. When you visit a page with a Google+ component, your browser loads this component from Google. Google learns which specific page you visited. If you're logged in to Google+ during the visit and click the Google+1 button, that interaction is linked to your Google+ account. The recommendation may appear along with your profile name and picture in Google services (search, account, ads). If you want to avoid data transmission to Google, log out of your Google+ account before visiting the website. More information: https://www.google.de/intl/de/policies/privacy/ https://developers.google.com/+/web/buttons-policy

21. Use of Google Ads (formerly AdWords)

This website uses Google Ads, a service that enables advertisements in Google search results and across the Google Display Network. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. Google Ads allows advertisers to define keywords so that ads are shown when users search for those terms. If a user clicks a Google ad and lands on our site, a conversion cookie is placed on their system. This cookie loses validity after 30 days and does not personally identify the user. The cookie helps determine whether a user who clicked an ad made a purchase or completed another action. The data collected is used by Google to compile statistics on ad performance. We and other advertisers do not receive personally identifiable information. Users can block cookies via their browser settings and delete existing cookies. To manage ad preferences, visit: www.google.de/settings/ads Privacy policy: https://www.google.de/intl/de/policies/privacy/

22. Use of Instagram

This website includes components from Instagram, a visual platform for sharing photos and videos. Provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. When a user accesses a page containing an Instagram button, their browser automatically connects to Instagram servers to display the button. Instagram is thus informed of the specific page visited. If the user is logged in to Instagram, Instagram links this visit to their user account. If the Instagram button is clicked, the corresponding data is assigned to their personal profile and stored by Instagram. To prevent this, users must log out of Instagram before visiting the site. Privacy details: https://help.instagram.com/155833707900388 https://www.instagram.com/about/legal/privacy/

23. Use of LinkedIn

This website integrates components from LinkedIn, a business-oriented social network. Provider: LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. For EU data protection matters: LinkedIn Ireland, Wilton Plaza, Dublin 2, Ireland. When a LinkedIn plugin is present on a page, the browser loads content directly from LinkedIn. This informs LinkedIn of the specific page visited. If the user is logged in, LinkedIn can associate the visit with the user's LinkedIn profile. If a plugin (e.g. Share button) is used, LinkedIn stores that information. To opt out, users must log out of LinkedIn before accessing the website. Manage preferences: https://www.linkedin.com/psettings/guest-controls Privacy policy: https://www.linkedin.com/legal/privacy-policy Cookies: https://www.linkedin.com/legal/cookie-policy

24. Use of Pinterest

This website integrates components from Pinterest, a social network used to share images and ideas via “pins.” Provider: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. When a page with a Pinterest button is visited, the browser connects to Pinterest servers, which then receive information about which page is accessed. If the user is logged in to Pinterest, that data is assigned to their account. Clicking the Pinterest button links this action to their profile. To prevent this, users should log out of Pinterest before visiting. Privacy policy: https://about.pinterest.com/privacy-policy

25. Use of Tumblr

This website integrates components from Tumblr, a blogging platform that allows users to publish and share various forms of content. Provider: Oath (EMEA) Limited, 5–7 Point Square, North Wall Quay, Dublin 1, Ireland. When a page with a Tumblr button is accessed, the browser loads content from Tumblr. Tumblr is then informed which page was visited. If the user is logged in to Tumblr, that visit is linked to their account. Clicking a Tumblr button also links that interaction to their profile. To prevent this, log out of Tumblr before visiting the site. More information: https://www.tumblr.com/buttons Privacy policy: https://www.tumblr.com/policy/en/privacy

26. Use of X (formerly Twitter)

This website integrates components of the Twitter platform, a public microblogging service that allows users to post short messages (“tweets”). Provider: Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland. Each time a page with a Twitter component is accessed, the browser downloads data from Twitter. Twitter is informed of which page was visited. If the data subject is logged into Twitter, Twitter associates the visit with their Twitter account. Clicking a Twitter button (e.g. retweet or follow) also links that action to the user's account. If the data subject does not wish for this to happen, they should log out of Twitter before visiting the website. More information: Buttons: https://about.twitter.com/de/resources/buttons Privacy: https://twitter.com/privacy?lang=de

27. Use of Xing

This website includes components of Xing, a professional social networking platform. Provider: XING SE, Dammtorstraße 30, 20354 Hamburg, Germany. When a Xing plugin is integrated, the browser connects to Xing servers. Xing is then informed which specific page was visited. If the user is logged into Xing, this visit is linked to their Xing profile. Clicking a plugin (e.g. the "Share" button) also links this information to their profile. To prevent tracking, users should log out of Xing before visiting the site. Privacy: https://www.xing.com/privacy Data protection for the Share button: https://www.xing.com/app/share?op=data_protection

28. Use of YouTube

This website integrates components of YouTube, a platform for uploading and sharing videos. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Ireland. When a user accesses a page with a YouTube video, the browser connects to YouTube and loads the video component. YouTube and Google are informed which page was visited. If the user is logged into YouTube, this visit is linked to their account. To avoid this, users should log out before accessing pages with YouTube videos. More information: https://www.youtube.com/yt/about/de/ https://www.google.de/intl/de/policies/privacy/

29. Use of Belboon

This website integrates components from Belboon, a German affiliate marketing network. Provider: belboon GmbH, Weinmeisterstr. 12-14, 10178 Berlin, Germany. Belboon places a cookie on the user’s system, which stores only the affiliate ID and reference ID of the visitor and clicked advertisement. No personal data is collected. Purpose: Tracking for commission payment between merchants and affiliates. Users can block or delete Belboon cookies via their browser settings. Privacy policy: https://www.belboon.com/de/ueber-uns/datenschutz/

30. Payment Method: PayPal

This website offers PayPal as a payment method. Provider: PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. When a user selects PayPal, personal data is automatically transmitted to PayPal for payment processing. These data typically include: Name, address, email, IP address, telephone number Order-related data necessary to complete the transaction This data transfer serves fraud prevention and payment processing. PayPal may transmit data to credit agencies for identity and credit checks. Data may also be passed to subcontractors or affiliated companies if required. Consent can be withdrawn at any time, though it does not affect data required for contractual processing. PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

31. Payment Method: Sofortüberweisung (Klarna)

This website offers "Sofortüberweisung" (now Klarna Instant Bank Transfer) as a payment method. Provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden. When this payment method is selected, personal data is automatically transferred to Klarna. This includes: Name, address, email address, IP address, phone number, mobile number Banking and transaction-related data, including PIN and TAN (sent securely to Klarna) Purpose: secure payment processing and fraud prevention. Klarna may transmit this data to credit agencies for identity and credit checks and may share it with affiliated companies or processors as necessary. Consent can be withdrawn at any time. However, this does not affect the lawfulness of processing required for contract fulfillment. Privacy policy: https://www.klarna.com/sofort/datenschutz/

32. Legal Basis for Processing

Processing of personal data is based on the following legal grounds under Article 6 GDPR: Art. 6(1)(a): Consent Art. 6(1)(b): Performance of a contract Art. 6(1)(c): Legal obligation (e.g. tax compliance) Art. 6(1)(d): Protection of vital interests Art. 6(1)(f): Legitimate interest (e.g. business operations), unless overridden by the data subject’s rights and freedoms The European legislator explicitly recognizes such legitimate interest where the data subject is a customer of the controller (Recital 47 GDPR).

33. Legitimate Interests Pursued by the Controller or a Third Party

If processing is based on Art. 6(1)(f) GDPR, our legitimate interest is the conduct of our business activities for the benefit of our employees and shareholders.

34. Storage Duration of Personal Data

The retention period is based on statutory requirements. After expiration of such a period, the data will be routinely deleted unless still needed for contract performance or initiation.

35. Legal or Contractual Requirement to Provide Personal Data; Necessity for Contract Conclusion; Obligation of the Data Subject; Consequences of Non-Disclosure We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or contractual obligations (e.g. information about a contracting party). In some cases, the conclusion of a contract may require the data subject to provide personal data. If such data is not provided, a contract with the data subject cannot be concluded. Before providing personal data, the data subject may contact our staff for clarification about whether the provision is legally or contractually required, whether it is necessary for the conclusion of a contract, and what the consequences of non-provision would be.

36. Existence of Automated Decision-Making

As a responsible company, we do not use automatic decision-making or profiling.