Privacy policy

General information about data handling

We are very pleased that you are interested in our website – and thus in our company. The protection of your private rights and freedoms is important to us; we only use your data for the purposes intended. Since it is important to us that you know at all times to what extent we collect, use and, if necessary, pass your data onto third parties, we will subsequently inform you in detail about the processing of your personal data (collected via our website).

In principle, you can use our pages without providing any data; if there are exceptions for selected services, we will explain these in the following chapters. We will not process data without a legal basis without your informed consent.

When processing personal data, we strictly adhere to the requirements of the EU Data Protection Regulation (GDPR) and, if necessary, other data protection regulations.

Name and address of the data controller

Active Nutrition International GmbH
Stefan Geisenberger, Craig Rosenthal
Zielstattstraße 42
81379 München

Tel: +49 (0) 89 50 200 72
Mail: info@active-nutrition-international.com

Data protection contact

Jonathan Stoklas

Mail: data_compliance@active-nutrition-international.com

Timeliness of the privacy policy

To ensure up-to-date data protection information in connection with the services of our website, we use the Cloud-Service by Cookiebox GmbH.

The rights of data subjects

Chapter III of the EU Data Protection Regulation (GDPR) provides for extensive rights for data subjects, which we will explain to you below with regard to the processing of your personal data:

1. The right to be informed
This specification applies in particular to the following data processing details:
  • The purpose of the processing operation
  • Categories of data
  • If necessary, recipient or categories of recipients
  • If necessary, the planned storage duration or the criteria for determining this duration
  • Information on the respective right to correction, deletion, restriction or objection
  • Existence of a right of appeal to a supervisory authority
  • If necessary, origin of the data (if not collected from you)
  • If necessary, existence of automated decision making including profiling, and including meaningful information about the logic involved, the scope and the expected effects
  • If necessary, (planned) transfer to a third country or international organisation
2. The right of rectification
If necessary, we will correct faulty data immediately if you inform us about the circumstance accordingly.
3. Right to deletion (right to be forgotten)
If the processing is no longer necessary and one of the following conditions is fulfilled:
  • Expiry of the purpose of processing
  • Withdrawal of your consent and the absence of any other legal basis for processing
  • Opposition to processing without an important reason to the contrary
  • Illegal processing
  • Required to fulfil a legal obligation
  • Data collection in accordance with Art. 8 para. 1 GDPR
  • As part of the deletion request, we may pass on your request to those third parties to whom your data was previously transferred.
4. The right to restriction of processing
Provided one of the following conditions is met:
  • You dispute the accuracy of your data (restriction may be made on our site for the duration of the verification)
  • In the event of unlawful processing and provided that the data is not to be deleted, deletion shall be replaced by restriction of processing
  • If the processing purposes expire, at the same time you need your data to assert, exercise or defend legal claims
  • After your objection pursuant to Art. 21 para. 1 GDPR and for the duration of the examination, whether our justified reasons outweigh yours.
5. The right to data portability
As long as it is technically possible and the rights and freedoms of other persons are not affected, we will – at your request – transfer your data to another recipient (data controller).
6. Right to object
If we collect personal data from you or have it collected and process it (on the basis of Art. 6 Para. 1(e) or (f) or Art. 9 Para. 2(a) GDPR), you have the right to object to data processing (including profiling) at any time (with effect for the future). In exceptional cases, the objection may be invalid, e.g. if we can prove compelling legitimate interests for processing that outweigh your interests, or processing serves to assert, exercise or defend legal claims. If we process your personal data for direct marketing purposes, you have the right to object to such processing at any time. This also applies to any profiling connected with such direct advertising. You also have the right to object to the processing of the data we hold about you, which is carried out by us for scientific or historical research purposes or for statistical purposes in accordance with Art. 89 para. 1 GDPR unless such processing is necessary to fulfil a task in the public interest.
7. Automated individual decision-making including profiling
If we collect personal data from you or have it collected and process it, you have the right not to be subject to decision based exclusively on automated processing – including profiling – which has a legal effect on you or significantly impairs you in a similar manner. Exceptions to this requirement apply if the decision to conclude or fulfil a contract between you and us is necessary or if you have expressly consented to the processing. In any event, we will take reasonable measures to protect your rights and freedoms and your legitimate interests, including at least the right on our part to obtain the intervention of a person to express our position and to challenge the decision.
8. Right to withdraw consent under the data protection laws
You have the right to revoke your consent to the processing of personal data at any time.
9. The right to file a legal complaint with a supervisory authority
A list of supervisory authorities in Germany can be found on the website of the Federal Commissioner for Data Protection or via the following link: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html

General information about data processing on the website

The following information applies to the data processing on our website in general. If there are exceptions or additions to this information, these are described in detail in the respective sections.

Information on data security

We secure your personal data processed by us against loss, destruction, access, modification or distribution of your data by unauthorised persons by appropriate technical and organisational measures. We have also implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all risks is not possible.

Legal basis for processing

We process personal data according to the specifications of the GDPR, depending on the type and purpose of processing, as follows:

Where allowed by law Specification of the GDPR
Informed consent Art. 6 para. 1(a)
In performance of a contract Art. 6 para. 1(b)
Implementation of pre-contractual measures Art. 6 para. 1(b)
Fulfilment of legal obligations Art. 6 para. 1(c)
Protection of vital interests Art. 6 para. 1(d)
Safeguarding our legitimate interest Art. 6 para. 1(f)
Our legitimate interest

Our legitimate interest, as defined in Article 6 para. 1(f) GDPR, is based on the performance of our business activities to maintain our operability and to safeguard the employment of our employees.

General deadlines for data deletion

After elimination of the storage purpose, the retention periods are generally at least six or ten years. As a rule, the deletion of data generally takes place without delay in accordance with our deletion plan, insofar as it does not preclude any obligation to retain data, the need to fulfil a contract or a legitimate interest.

Deletion or blocking of personal data

We store your personal data only for the period necessary to fulfill the intended purpose. After elimination of the purpose and after expiration of any existing retention periods, your data will be deleted immediately. If deletion is not possible, the data will be blocked instead.

Collection of general data and information

As soon as you visit our website, our web server collects some general data and technical information – as shown in the table below:

Used browser types and versions Correct presentation of the page content
Used operating system, visitor origin (referrer, e.g. Google), clicked subpages Optimization of our website content as well as our advertising
Date and time of access to the website and the visitor’s IP address and Internet service provider Ensuring the lasting functioning of our IT systems (for the operation of the website) and preventing misuse
Other data and security information in case of attacks Providing relevant information to law enforcement agencies in the event of a cyberattack
Obligation to provide personal data

Under certain conditions (eg due to legal or contractual regulations) you have the obligation to provide us with your personal data. Examples of such processing are as follows:

Type or purpose of processingNeed
Conclusion of a purchase contract (eg your address)Fulfillment of the contractual obligation (eg delivery of the goods to your address)

In the employment context (eg transfer of data to the tax office)

Fulfillment of legal requirements (eg tax regulations)

An infringement (ie the non-provision of the required data) would mean that the respective data processing and consequently the corresponding contract with you could not be closed. We will inform you on request in individual cases before collection of your data on whether the provision is required by law or contract or for the conclusion of the contract is necessary and what consequences for you would possibly arise from the refusal.

Information about specific data processing on the website

Depending on the processing, the purposes, legal basis and other information may vary. You will find the exact assignment of the information in the following chapter.
Contact form
The purpose of the processing operation Processing and, if necessary, answering the request of the form sender
Legal basis (in accordance with Art. 6/9 GDPR) – Performance of a contract (Art. 6 para. 1 (b))
– Safeguarding our legitimate interest (Art. 6 para. 1 (f))
if applicable, data receiver (when passing on) A transfer to third parties and / or to a third country does not take place.
if applicable, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) No data transfer to a third country takes place and is not planned.
Where known: Duration of data retention See General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity
There is no obligation.
Consequences of non-compliance (if the required data are not provided) None
if applicable, existence of automated decision making In this context, we refrain from purely automated decision making.
if applicable, origin of data (if not collected directly from the data subject) The data usually comes from the person concerned.
if applicable, categories of personal data (if not collected directly from the data subject) The data usually comes from the person concerned.
if applicable, change of purpose None
Newsletter
The purpose of the processing operation Providing information in the form of electronic circular mailings
Legal basis (in accordance with Art. 6/9 GDPR) – Informed consent (Article 6 (1) a)
– In the context of an existing customer relationship (§ 7 Abs. 3 UWG)
if applicable, data receiver (when passing on) or operator of the addon Mailchimp; Operator: The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA; https://mailchimp.com/legal/,
Sendinblue; Operator: Sendinblue SAS, 55 Rue d’Amsterdam, 75008 Paris, France, https://de.sendinblue.com/legal/privacypolicy/
if applicable, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) Data transfer to a third country does not take place and is not planned.
Where known: Duration of data retention See General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity
There is no obligation to provide personal information. The sending of newsletters takes place exclusively after registration via a double-opt-in procedure (voluntary and revocable informed consent in accordance with Article 6 paragraph 1 a DSGVO) or after a purchase contract has been successfully concluded and the e-mail address was given in this process (according to § 7 Abs. 3 UWG).
Consequences of non-compliance (if the required data are not provided) An infringement (ie the non-provision of the required data) would mean that the newsletter can not be delivered to you.
if applicable, Existence of automated decision-making In this context, we do not use automated decision making.
if applicable, Origin of data (if not collected directly from the data subject) The data comes from the person concerned.
if applicable, Categories of personal data (if not collected directly from the data subject) The data comes from the person concerned.
Cookies
On this website we use cookies. These are small text files that are stored or saved on your computer via your Internet browser (eg Google Chrome, Safari, Firefox, Edge). This cookie may contain a so-called cookie ID – a unique identifier consisting of a string that allows mapping of web pages and servers to the storing browser. At the same time, these cookies give us information that enables us to optimize our websites to meet the needs of our visitors. We use cookies partly only for the duration of your stay on the website. All cookies on our websites contain purely technical information, not personal data. Use of our offers is possible (even if not fully functional) without cookies. Most browsers are set to automatically accept cookies. However, you can disable the storage of cookies or set your browser to notify you when cookies are sent.
Application platform - active-nutrition-international - Jobapplication.hrworks.de
The purpose of the processing operation
Data type Purpose of the collection
E-mail address, Date of birth, Mobile number, Last name, POSTAL CODE, Street, No, Title, First name, Salutation, Country, Location, Application documentsData of applicants are processed for the purpose of selecting potential employees.
Legal basis (in accordance with Art. 6 GDPR) Implementation of pre-contractual measures, according to Art. 6 para. 1 b) DSGVO, § 26 para. 1 BDSG
The purpose of the processing operation
Legal basis (in accordance with Art. 9 GDPR) Art. 9 Abs. 2 lit. b, h DSGVO,
Durch die betroffene Person bereits veröffentlichte Daten, gemäß Art. 9 Abs. 2 e) DSGVO
If necessary, data receiver (when passing on) or operator of the addon Active Nutrition International GmbH,Zielstattstraße 42,81379 Munich, Germany
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) A data transfer to a third country does not take place and is not planned.
Where known: Duration of data retention See General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity The data (in the mandatory fields) must be provided as part of the underlying transaction.
Consequences of non-compliance (if the required data are not provided) Without the data provided, the described data processing cannot be carried out.
If necessary, Existence of automated decision-making In this context, we do not use automated decision making.
If necessary, Origin of data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, Categories of personal data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, change of purpose In principle, there is no change of purpose and is not planned.
Opt out
Privacy information (of the Addin)
Payment service provider - Unzer GmbH
The purpose of the processing operation
Data type Purpose of the collection
Identification data, contact details, Device-related data (e.g. IP address)Enabling a secure payment option
Legal basis (in accordance with Art. 6 GDPR) Safeguarding our legitimate interest (Art. 6 para. 1 f)
The purpose of the processing operation
Legal basis (in accordance with Art. 9 GDPR)
If necessary, data receiver (when passing on) or operator of the addon Paypal, if applicable - PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg,
If necessary SOFORT bank transfer, Klarna GmbH, Theresienhöhe 12, 80339 Munich, Germany
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees)
Where known: Duration of data retention See General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity There is no obligation.
Consequences of non-compliance (if the required data are not provided)
If necessary, Existence of automated decision-making In this context, we do not use automated decision making.
If necessary, Origin of data (if not collected directly from the data subject) The data usually comes from the person concerned.
If necessary, Categories of personal data (if not collected directly from the data subject) The data usually comes from the person concerned.
If necessary, change of purpose In principle, there is no change of purpose and is not planned.
Opt out
Privacy information (of the Addin)
Risk and credit assessment - Unzer GmbH
The purpose of the processing operation
Data type Purpose of the collection
Address data, Creditworthiness dataRisk and credit assessment
Legal basis (in accordance with Art. 6 GDPR) Interest, pursuant to Art. 6 para. 1) DSGVO; the legitimate interest is not to suffer payment defaults and therefore to be able to assess the risk of payment default when we make advance payments.
The purpose of the processing operation
Legal basis (in accordance with Art. 9 GDPR)
If necessary, data receiver (when passing on) or operator of the addon Our payment service provider may pass on or query your personal data to credit agencies (e.g. Schufa Holding AG, CRIF Bürgel GmbH, Arvato Infoscore GmbH, Universum Business GmbH, Bisnode D & B Austria GmbH) in order to carry out credit checks.
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees)
If known: Duration of data storage See General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity For the aforementioned payment methods, the provision of the relevant data is mandatory.
Consequences of non-compliance (if the required data are not provided) Without the data, the payment methods in question cannot be used.
If necessary, Existence of automated decision-making In this context, we do not use automated decision making.
If necessary, Origin of data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, Categories of personal data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, change of purpose In principle, there is no change of purpose and is not planned.
Opt out
Privacy information (of the Addin)
Customer account
The purpose of the processing operation
Data type Purpose of the collection
Last name, POSTAL CODE, Street, No, Title, First name, Salutation, Country, LocationHandling of complaints, Unique identification of the customer account, Product purchase processing, Delivery, Payment transactions
E-mail address, PasswordAuthentication, Independently resetting the password
Legal basis (in accordance with Art. 6 GDPR) Performance of a contract, according to Art. 6 para. 1 b) DSGVO
The purpose of the processing operation
Legal basis (in accordance with Art. 9 GDPR)
If necessary, data receiver (when passing on) or operator of the addon Parcel service,
Logistics service provider,
Payment service provider
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) As a matter of principle, no forwarding takes place and is not planned
If known: Duration of data storage See General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity Unless otherwise specified, the data (in the mandatory fields) must be provided as part of the underlying user agreement to create a customer account.
Consequences of non-compliance (if the required data are not provided) Die Anlage eines Kundenkontos ist in dem Fall nicht möglich.
If necessary, Existence of automated decision-making An automatic decision making process does not take place and is not planned
If necessary, Origin of data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, Categories of personal data (if not collected directly from the data subject) The data usually comes from the person concerned.
If necessary, change of purpose In principle, there is no change of purpose and is not planned.
Opt out
Privacy information (of the Addin)
Online shopping
The purpose of the processing operation
Data type Purpose of the collection
Age, E-mail address, Name, Title, Postal address, Phone number landline, Cell phone number, Information about products you have ordered, Order history, Details of your purchase, Payment details, Payment historyThe processing of your online purchase and delivery of the product to you according to your order.
Legal basis (in accordance with Art. 6 GDPR) Performance of a contract, according to Art. 6 para. 1 b) DSGVO
The purpose of the processing operation
Legal basis (in accordance with Art. 9 GDPR)
If necessary, data receiver (when passing on) or operator of the addon Payment service provider
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees)
If known: Duration of data storage As long as you shop with us. We store your personal data only until the above-mentioned purposes for which we collected or received your personal data have been fulfilled and until the respective legal retention obligations have expired.
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity Unless otherwise specified, the data (in the mandatory fields) must be provided as part of the underlying contract.
Consequences of non-compliance (if the required data are not provided) The purchase of products from our online store is not possible in that case.
If necessary, Existence of automated decision-making In this context, we do not use automated decision making.
If necessary, Origin of data (if not collected directly from the data subject) The data usually comes from the person concerned.
If necessary, Categories of personal data (if not collected directly from the data subject) The data usually comes from the person concerned.
If necessary, change of purpose In principle, there is no change of purpose and is not planned.
Opt out
Privacy information (of the Addin)
Sweepstakes, contests and raffles
The purpose of the processing operation
Data type Purpose of the collection
Data required for participation in the competition (e.g. name, title, postal address, e-mail address, landline or cell phone number, age, date of birth, gender, user-generated content or other personal data).The implementation of sweepstakes
Legal basis (in accordance with Art. 6 GDPR) Fulfillment of a contract or pre-contractual requests, according to Art. 6 para. 1 b) DSGVO.,
In cases where we intend to use your personal data for marketing purposes, we will explicitly inform you before we collect your personal data and process your personal data for marketing purposes only on the basis of your consent.
The purpose of the processing operation
Legal basis (in accordance with Art. 9 GDPR)
If necessary, data receiver (when passing on) or operator of the addon If applicable, sweepstake partner, cf. general information on transmission
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) A data transfer to a third country does not take place and is not planned.
If known: Duration of data storage We store your personal data only as long as it is necessary for the fulfillment of mutual obligations in connection with the competition, contest or prize draw. In addition, we store your personal data only for the assertion of or defense against legal claims or until the respective statutory retention obligations have expired.
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity Unless otherwise specified, the data (in the mandatory fields) must be provided as part of the underlying contract.
Consequences of non-compliance (if the required data are not provided)
If necessary, Existence of automated decision-making In this context, we do not use automated decision making.
If necessary, Origin of data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, Categories of personal data (if not collected directly from the data subject) The data comes from the data subject himself.
If necessary, change of purpose In principle, there is no change of purpose and is not planned.
Opt out
Privacy information (of the Addin)
Web tracking technologies – managed with Usercentrics
For the privacy-compliant management of all consent or opt-out required cookies, website and tracking technologies, we use the Consent Management Platform Usercentrics GmbH, Rosental 4, 80331 Munich, Germany, with whom we have integrated the following services: