Privacy Policy of Leica Camera AG for the leica-camera.com website
Using the website leica-camera.com involves the processing of personal data (hereinafter simply “data”). Because the protection of our users’ privacy is important to us, we would like to inform you which personal data we collect when you use the website and the associated services as well as the purposes for which we process the data.
With a view to protecting the privacy of your end devices (computer or mobile device), we will also provide you with information about storage and access to information on your end device via cookies or similar technologies.
1. Controller / Contact Details
Leica Camera AG
Am Leitz-Park 5
35578 Wetzlar
Germany
Email: data-protection@leica-camera.com
Should you have any questions or suggestions regarding data protection or this Privacy Policy, or if you would like to contact us to assert your rights, please use the above-mentioned contact details when submitting your query.
2. Data Protection Officer
You can contact our data protection officer at: DPO@leica-camera.com.
3. Automated Data Processing
When accessing our website, your end device automatically transmits certain data for technical reasons, which is required to establish the connection and access the queried and embedded contents (e.g., shopping cart, texts, images, videos and product information as well as data provided for downloading). This comprises:
-
the IP address or device ID allocated to the respective end device
-
the type of end device in question
-
browser type/version
-
the operating system used
-
the visited website
-
the previously visited website (referrer URL)
the date and time of the server query
-
the HTTP status code
The collection and subsequent processing are intended to deliver the contents of our website and make the functions and services associated with our website available to you.
We store this data for the following purposes:
-
to ensure the security of our IT systems, e.g., to defend against specific attacks on our systems and to detect attack patterns
-
to ensure the proper operation of our IT systems, e.g., when faults occur which we can only resolve by storing the IP address
-
for law enforcement, hazard prevention or prosecution if there is specific evidence of crimes
The data is processed on the basis of our overriding legitimate interests specified above; Art. 6 para. 1(f) of the General Data Protection Regulation (GDPR).
We store this data for a period of 14 days. We then delete or anonymize this data, including the IP addresses.
The data is only stored for a longer period when there are specific indications to warrant a justified suspicion of unlawful use which necessitates an additional review and processing of the data for this reason.
4. Hosting
We use the services provided by Amazon Web Services EMEA S.a.r.l., 38 avenue John F. Kennedy, L-1855 (“AWS”) based in Luxembourg and Profihost GmbH, Expo Plaza 1, 30539 Hannover, Germany (“Profihost”) for the hosting and operation of our website. AWS and Profihost process your personal data on our behalf and exclusively in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
5. Data Processing When Visiting the Website and the Related Functions and Services
We process your personal data to provide the functions and services available when using the website and the associated functions and services.
When you use specific functions in connection with the website or define any settings such as search and filter functions, place products in the shopping cart or select a language, we will process the information you provided and the settings you defined in order to provide these functions.
The processing is required in order to provide you with the requested functions. The legal basis for the respective data processing is Art. 6 para. 1(b) GDPR.
6. Leica Account (General Account)
You can create an account in order to use additional functions of the website and associated services such as product registration.
6.1. Registration/Login
When registering your account, you must provide the following information:
-
country and language
-
your first and last name
-
your email address
-
your chosen password
You can also specify your preferred salutation (optional).
We process mandatory information:
-
to create and manage your account for you
-
to provide you with the functions and services associated with the account
-
to prevent and uncover cases of fraud in connection with the account
You will neither be able to create an account nor use the functions and services associated with the account if you do not provide this information. The legal basis for the processing is Art. 6 para. 1(b) GDPR. Processing is required to execute the contractual relationship with you.
We process the information you provide on a voluntary basis so that we can use your preferred salutation when responding to queries you submit. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.
We also process the data related to the login to authenticate your login. We have a legitimate interest in ensuring that only authorized persons have access to the respective account, Art. 6 para. 1(f) GDPR.
6.2. Using and Managing the Account
You can also provide additional information in your account. For example, you can supplement, amend and manage:
-
your profile (title, address, date of birth, (mobile) phone number, professional ties to photography and alternative [delivery] addresses)
-
your interests regarding specific topics, such as photography interests, Leica products and events as well as Leica Camera Stores and their events for which you would like to receive related information
-
information regarding products you use that were made by other companies
-
your preferences and consent settings for receiving advertising communication and the corresponding processing (item 19)
We process your personal data to manage your account for you, provide the full range of functions available with your account and store the consent settings you provide. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.
6.3. Product Registration
You can also register and manage your Leica products in your account to make it easier to retrieve firmware updates, instructions and supplemental information on your product.
To register a product, you have to:
-
select the product you wish to register (model designation)
-
enter the product’s serial number
Optionally, you can add the date of purchase and include a comment.
The processing of mandatory information is required to register the product. Moreover, we process this data, including the optional information provided, to provide you with a comprehensive overview of your camera and sport optics portfolio and to allow you to manage your account, Art. 6 para. 1(b) GDPR.
6.4. Erasing Your Data
We generally save your personal data for the duration of the usage relationship. The data is deleted when you delete your account.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
7. Leica Customer Account, Orders and Leica Akademie Events
If you submit an order to us or book tickets for a Leica Akademie event, we will process your data for the receipt and processing of your order or booking.
7.1. Ordering as a New Customer / Registering for or Booking Leica Akademie Events
To submit an order to us or book a ticket for a Leica Akademie event, you must first provide the following information:
-
your first and last name
-
your email address
Optionally, you can provide:
-
your title
-
your date of birth
-
your phone number
For orders and tickets for Leica Akademie events, you also need to provide your
-
address including country
-
alternate invoice address, if applicable
In addition, you have the option of providing your salutation, the name of your company and, if requested, the VAT ID (sales tax number).
If you wish to specify an alternate invoice address for orders and bookings, we also need the necessary information, i.e., the address including country and, for orders, the recipient’s name. You can also add the company and department.
If you wish to create a Leica customer account along with your order or booking, you must also select a password. However, you do not need an account to place the order.
7.2. Ordering as an Existing Customer
If you are already registered as a customer and log in to your Leica customer account to place an order, we use the information provided in your account to process the order.
7.3. Data Collection from a Third Party
Your personal data will be provided to us by the orderer in the event that you are the recipient of a product but did not place the order, or if tickets for a Leica Akademie event are for you but were booked by a third party.
7.4. Reservation and Pick-up (Click & Collect) in a Leica Store
You can also designate your order for pick-up at a Leica store. To do so, you must also select the Leica store at which you want to reserve and pick up your product.
For this purpose, we transfer the data provided during your reservation to the store you selected. This comprises:
-
your first and last name
-
your address
-
your email address
-
your phone number
-
your reservation data: product, price, quantity and item number
7.5. Transferring Data to Leica’s National Subsidiaries for Executing an Order/Booking
We pass on your personal data, which we process in connection with your order, to Leica’s national subsidiary responsible for the country in which you have placed your order or for holding the Leica Akademie event you have booked.
7.6. Using and Managing the Leica Customer Account
You can also provide additional information in your account and use the functions and services provided there. For example, you can:
-
supplement, amend and manage your delivery and invoice address and your preferred payment method
-
manage your e-shop vouchers
-
view your order history and the status of your current orders
7.7. Purposes and Legal Basis for Processing
To fulfill the contract, it is necessary to process mandatory information, including data collected for product orders or bookings concerning alternate delivery addresses and optional address supplements, as well as data required for reservations. We will also process the corresponding data related to your order or booking for this purpose. In particular, this includes invoice, product and booking data as well as the customer and order number. The above-mentioned data is also processed for managing returned items, contract terminations and withdrawals.
When you book tickets for a Leica Akademie event, the Leica national subsidiary responsible will process the contact data provided by you to communicate with you regarding the event (e.g., booking confirmations, event reminders, information on last-minute changes, and information materials).
The transfer of your data processed in connection with the order or booking to the relevant national subsidiary is necessary so that your order can be fully processed and delivered, or your Leica Akademie event can be booked and carried out.
The legal basis for this processing is Art. 6 para. 1(b) GDPR. We also have a legitimate business interest in maintaining an effective sales organization, Art. 6 para. 1(f) GDPR.
If you decide to sign up for a Leica customer account when placing an order, we process the above-mentioned data:
-
to create and manage your account for you
-
to provide you with the functions and services associated with the account
-
to prevent and uncover cases of fraud in connection with the account
The legal basis for the processing is Art. 6 para. 1(b) GDPR. Processing is required to execute the contractual relationship with you.
Your date of birth is processed to verify your legal capacity and this processing is based on our legitimate interest in verifying your legal capacity (Art. 6 para. 1(f) GDPR).
If recipients or participants in Leica Akademie events other than the customer are specified when ordering products or booking tickets, we will collect and process their data to execute the order or booking as instructed. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.
If you have provided your phone number, we will use it to ensure secure delivery (item 14) or, in the case of Leica Akademie events, to answer queries or inform you about last-minute changes. The data is processed on the basis of our legitimate interest in ensuring proper delivery and/or efficient preparation and implementation of the Leica Akademie event, Art. 6 para. 1(f) GDPR.
7.8. Erasing Your Data
Where the data is processed for the fulfillment and processing of orders or bookings and/or the provision of the account, the data is erased following the complete fulfillment of the contract and/or following the expiration of the statutory warranty obligations or contractual guarantee or, with respect to the Leica customer account, when you delete this account.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
8. Payment Processing
You have the option of choosing between several payment methods for orders and bookings of Leica Akademie events. We use the services provided by various payment service providers to process payments.
The respective service providers are responsible for processing your data and may forward your data to credit agencies in order to verify your identity and perform a credit check; they may also pass on your data to other third parties or service providers for their own purposes. Further information on the processing of your data can be found in the privacy policies issued by the various service providers, which are referenced below.
8.1. Payments via PayPal
“Direct to PayPal” is a service of PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg (“PayPal”). You can find the PayPal Privacy Statement at https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_en.
If you use the “Direct to PayPal” function, your data that is required for the forwarding to your PayPal account and the execution of the payment process is automatically transmitted to PayPal. This comprises:
-
your IP address
-
the total amount of your order and/or booking
-
reference to the PayPal account
If you have registered your PayPal account with us, your email address assigned to the PayPal account can also be accessed via PayPal. PayPal will then transmit the required data regarding your order and/or booking to us for processing. Therefore, PayPal provides us with the following data:
-
your first and last name
-
your invoice and/or delivery address, as needed
Moreover, PayPal will inform us whether the payment has been completed properly.
8.2. Payments via Google Pay
“Pay with Google Pay” is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). You can find Google’s Privacy Policy for Google Pay at https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=en.
When you use the “Pay with Google Pay” function, we will transfer the data required for forwarding to your Google Pay account to Google. This data includes:
-
your IP address
-
the date, time and amount of the transaction
-
the dealer’s location and description
-
a description of the purchased products and/or booked Leica Akademie events or test drives
-
your email address, as needed
When you make a payment via Google Pay, Google provides us with the following data:
-
your email address
-
information on the payment method
-
your first and last name
-
your delivery address
Moreover, Google will inform us whether the payment has been completed properly.
8.3. Payments via Credit Card, ONEY, and Apple Pay
If you choose to pay for your order or booking using a credit card, or, where available, via ONEY (Oney Bank S.A., RCS Lille Métropole 546 380 197; BP6 – 59895 Lille Cedex 9, France) or Apple Pay (Apple Inc., 1 Apple Park Way, Cupertino, CA 95014, USA), the relevant payments and any refunds will be processed by our payment services provider Adyen B.V., Simon Carmiggeltstraat 6–50, 1011 DJ Amsterdam, Netherlands (“Adyen”).
You can find further information on the processing of your data in Adyen’s Privacy Statement at https://www.adyen.com/policies-and-disclaimer/privacy-policy. You can find the Apple Pay privacy policy at https://www.apple.com/legal/privacy/data/en/apple-pay/.
Adyen collects and processes your payment data in order to process the payment. For this purpose, we automatically transmit the data required for your chosen payment method data to Adyen. For payments via ONEY and Apple Pay, this data comprises:
-
your salutation
-
your first and last name
-
your invoice and delivery address
-
your phone number
-
information on the product purchased
-
purchase price and currency
-
date and time of login
-
your IP address
If you have opted for payment via credit card, we will forward the following data to Adyen:
-
your IP address
-
purchase price
-
payment ID
-
your credit card data – this is encrypted during collection by Adyen so that we do not have access to this data at any time
-
your customer number
-
your email address
Adyen will inform us whether the payment has been completed properly.
8.4. Payments via Findomestic
If this payment type is offered as a payment method during the payment process, you can also make the payment via Findomestic (financing IT), a service of Findomestic Banca S.p.A. Firenze, Via Jacopo da Diacceto 48, 50129, Florence, Italy (“Findomestic”). You can find the Findomestic Privacy Policy at https://www.findomestic.it/servizi/privacy.shtml (only available in Italian).
We will transmit the following data to Findomestic:
-
your first and last name
-
your tax ID number
-
your email address
-
your date of birth
Findomestic will inform us whether the payment has been completed properly.
8.5. Payments via Scalapay (“Pay in 3 Installments”)
If this payment type is offered as a payment method during the payment process, you can also make the payment via Scalapay, a service of Scalapay S.r.l, Via Giuseppe Mazzini 9, 20123 Milan, Italy (“Scalapay”). You can find the Scalapay Privacy Policy at https://www.scalapay.com/privacy?country=EN.
In particular, we will transmit the following data to Scalapay:
-
your first and last name
-
your invoice and delivery address
-
information on the product purchased
-
purchase price and currency
-
your IP address
Scalapay will inform us whether the payment has been completed properly.
8.6. Purposes and Legal Basis
The data must be processed for the purpose of contract fulfillment, in particular payment processing, including the processing of any chargebacks, Art. 6 para. 1(b) GDPR.
8.7. Erasing Your Data
Data that is processed for the fulfillment and processing of orders and/or bookings (including for payment processing) is erased following the complete fulfillment of the contract or following the expiry of the statutory warranty obligations or contractual guarantee.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
9. Financing
If you have opted for purchase price financing when ordering, we will forward your:
-
first and last name
-
address including country
-
the purchase price details
to our financing partner, Novuna Personal Finance, which trades under the name Mitsubishi HC Capital UK PLC, Thorpe Road, Staines-upon-Thames, Surrey, TW18 3HP, United Kingdom (“Novuna”) in order to verify and process your financing application. The European Commission has adopted an adequacy decision for the United Kingdom in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection.
Novuna processes your data on its own responsibility and may forward your data to credit agencies in order to verify your identity and perform a credit check; it may also pass on your data to other third parties or service providers for its own purposes. Further information on the processing of your data is available in Novuna’s Privacy Policy at https://www.novuna.co.uk/privacy-policy/.
The data must be processed in order to execute the order in connection with the financing of the purchase price, Art. 6 para. 1(b) GDPR.
Data that is processed for the fulfillment and processing of orders is erased following the complete fulfillment of the contract or following the expiry of the statutory warranty obligations or contractual guarantee.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
10. Fraud Prevention
We analyze the information provided by our customers during the booking as well as the technical information transferred from your end device to protect ourselves against fraudulent bookings.
When doing so, we use the services provided by Adyen B.V., Simon Carmiggeltstraat 6 - 50, 1011 DJ Amsterdam, Netherlands (“Adyen”). Adyen processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
The processing is required to safeguard our legitimate interest in preventing and uncovering fraud, Art. 6 para. 1(f) GDPR.
We will erase this data following the complete fulfillment of the contract or following the expiry of the statutory warranty obligations or contractual guarantee. If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
11. Consultations (Speak to a Leica Expert) and Test Drive
You have the option of arranging a consultation with a Leica expert and/or participating in our test drive for various Leica systems.
11.1. Consultations (Speak to a Leica Expert), Including Consultation on the Test Drive
If you wish to book a personal consultation with a Leica expert, you must provide the following information:
-
your preferred time slot (date and time)
-
your first and last name
-
your email address
-
the type of contact preferred (via Microsoft Teams, by phone or in person at a Leica store)
-
your phone number (if you wish to be contacted by phone; otherwise, providing your phone number is optional)
-
the planned purpose of the consultation
-
your level of experience in photography
In addition, you can provide optional information on the camera or camera system you are currently using.
We use the Calendly service provided by Calendly LLC, 271 17th St NW Ste 1000, Atlanta, Georgia, 30363, USA (“Calendly”) for booking the appointment. Calendly processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
Your personal data is processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Calendly is certified in accordance with the EU-US Data Privacy Framework.
The processing of your personal data is required to book the personal consultation, Art. 6 para. 1(b) GDPR.
11.2. Forwarding Your Data to Leica’s National Subsidiaries and Leica Stores
We will forward the information required for booking and conducting your consultation to the relevant national subsidiary or Leica store responsible for carrying out the consultation. The transfer of data is required for booking and conducting the consultation, Art. 6 para. 1(b) GDPR.
11.3. Test Drive
When participating in a test drive, you can choose to have the desired Leica system delivered to you for a weekend test drive, or to take part in a test drive at a Leica store.
To participate in a test drive, you must book an appointment via Eventbrite, an event booking portal provided by Eventbrite, Inc, 535 Mission Street, 8th Floor, San Francisco, CA 94105, USA (“Eventbrite”).
Eventbrite processes your personal data in connection with the reservation on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR). Eventbrite also processes data at its own discretion, for example when you register with Eventbrite. Furthermore, Eventbrite evaluates your usage data on its own responsibility. You can find further information in the Eventbrite Privacy Policy at https://www.eventbrite.com/support/articles/en_US/Troubleshooting/eventbrite-privacy-policy?lg=en_US.
For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Eventbrite is certified in accordance with the EU-US Data Privacy Framework.
The following information is required for the reservation:
-
selected Leica system
-
your booked appointment for receiving the Leica system
-
your first and last name
-
your email address
-
your phone number
Moreover, we receive the confirmation from Eventbrite that your payment has been completed properly.
Following your reservation, we receive an order confirmation from Eventbrite containing the above-mentioned data to confirm your reservation.
The legal basis for the processing is Art. 6 para. 1(b) GDPR. The processing is required to fulfill the contractual relationship with you.
We will delete your personal data following the complete fulfillment of the contract.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
12. Conducting Consultations and Leica Akademie Events (Online)
If you book a phone or an on-site consultation, we will process your personal data to contact you and to conduct the consultation.
We use the following services for consultations and Leica Akademie events taking place online.
-
We use “Zoom” (only for Leica Akademie events). Zoom is a service provided by Zoom Video Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA (“Zoom, Inc.”). Information on the processing of your personal data by Zoom, Inc. is available at https://www.zoom.com/en/trust/privacy/privacy-statement/.
Your personal data is processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Zoom, Inc. is certified in accordance with the EU-US Data Privacy Framework.
-
We use Microsoft Teams, a service of Microsoft Ireland Operations Ltd., One Microsoft Court, South County Business Park, Leopardstown, Dublin 18, D18 DH6K, Ireland (“Microsoft”). Microsoft transfers personal data to the US – in particular to the Microsoft Corporation – and to other countries outside the European Economic Area that are not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. The Microsoft Corporation is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Microsoft will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
When using these services, we process the following data:
-
your first and last name
-
your email address
-
your password
-
your IP address
-
additional information on your end device
-
meeting ID and other login data, if applicable
-
start and end time of your participation
-
topic of the online meeting
Other data such as a profile image can be provided optionally.
If you use the chat or Q&A feature during the consultation, we will process the text you enter to display it during the consultation. The data from your end device’s microphone and, if applicable, the images from the video camera of your end device will be processed for the duration of the consultation in order to allow the playback of video and audio content. However, you can opt to disable the camera and/or microphone yourself at any time via the settings in the respective application.
Reports on online meetings (meeting metadata) and chat logs are kept for up to 30 days.
The legal basis for data processing to conduct a consultation, including via Microsoft Teams, is Art. 6 para. 1(b) GDPR.
13. Account Security and Troubleshooting
We also process technical data such as internal identifiers, the time of your registration or changes tied to your account. This processing is based on our legitimate interest in logging specific activities to ensure and track the security of your account.
We also process technical data, such as time stamps and activities, to identify and eliminate technical malfunctions or faults as well as to continuously improve the application. We have a legitimate interest in ensuring the functionality and security of our applications as well as continuously improving them.
The legal basis for processing is Art. 6 para. 1(f) GDPR.
14. Logistics Companies
We forward your address data to the respectively commissioned logistics company in order to deliver your order, Art. 6 para. 1(b) GDPR.
If you have provided us with your telephone number for this purpose, we will also transmit this number to the logistics company hired to transport your shipment. Providing the telephone number allows the logistics company to contact you to ensure delivery, for example, in cases where the delivery person cannot find the specified address or cannot immediately locate you. For this purpose, your telephone number is printed on the shipping label where it may be read by third parties, e.g., if the item is dropped off at a parcel shop or left with a neighbor. The data is processed on the basis of our legitimate interest in ensuring proper delivery, Art. 6 para. 1(f) GDPR.
15. Contact, Support, Service and Other Queries
15.1. Queries via Our Contact Form and Availability Notifications
If you submit a query regarding our products and services via our contact form (e.g., in case of questions regarding specific products, the Leica Akademie program or spare parts), or if you wish to be notified when specific products are in stock again, we process the data provided by you, for example:
-
your first and last name
-
your email address
-
the information required in order to process and respond to your request (e.g., information related to your request, the product name, item number and invoice numbers)
-
the time and date of your query, as well as further information you provide in your query
15.2. Ordering a printed copy of the instructions
If you wish to take advantage of our offer to receive a printed copy of the instructions by post, we will process the data you provide:
- your first name and surname,
- your email address
- your postal address,
- the product on which the desired manual is based or the corresponding product number, and
- the language in which you would like the manual to be provided.
The manual will then be produced for you by a service provider on our behalf and in accordance with our instructions, and a copy will be sent to you by post. The service provider will delete your data after the copy has been sent.
15.3. Support Queries and Other Queries
If you contact us via the contact data provided on our website, e.g., for support queries, or contact us via our general contact details provided under item 1, we will process:
-
your first and last name
-
the time and date of your query, as well as further information you provide in your query
Depending on the contact method chosen by you or the contact details you have provided, we also process:
-
your email address
-
your phone number
-
your address
15.4. Purposes and Legal Basis
For queries in connection with contracts, e.g., in connection with products and services or support queries, data is processed in order to initiate or execute the respective contractual relationship, Art. 6 para. 1(b) GDPR. We process information you provide voluntarily via our contact forms on the basis of our legitimate interest in the effective and proper processing of your queries, Art. 6 para. 1(f) GDPR.
For other queries, processing is based on our legitimate interest in receiving and processing your query, Art. 6 para. 1 (f) GDPR.
15.5. Erasing your Data
We store queries related to contracts for the duration of the contractual relationship, Art. 6 para. 1(b) GDPR. In all other cases, we delete your query three years after the expiration of the calendar year in which we completed the processing of your query.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
16. Shared Management of Customer Data and Analysis for Market Research Purposes
16.1. Shared Management of Customer Data
We process the data that we have collected in connection with your account (item 6), your orders and/or bookings and execution of Leica Akademie events (item 7), and your bookings of consultations (item 11) in our customer database for the purpose of managing our customer relationships. This enables us to manage your data and provide relevant, targeted answers to any questions.
If you are a Leica store customer, we also manage your data – which has been collected in the Leica store in connection with a purchase or an order – in our customer database for the aforementioned purposes. This data includes, without limitation:
-
your first and last name
-
your address
-
your email address
-
your phone number
-
your date of birth
-
country
-
the customer and invoice recipient, which may also be the Leica company or Leica store that places your order in the Leica store
-
name and address of the Leica store where you made your purchase, placed your order, or had a consultation
-
Leica’s national subsidiary responsible for the country in which you have placed your order or for holding the Leica Akademie event you booked
-
invoice number
-
product and item number or booking data
-
quantity
-
purchase date
-
purchase price and currency
If you also use our services offered on our website and have registered for a Leica account or Leica customer account, or have submitted orders, we will merge this data with your data that we have collected in connection with your account and your submitted orders in our customer database.
The associated processing is conducted on the basis of our legitimate interests in managing our customer relationships and the efficient design of our processes, Art. 6 para. 1(f) GDPR.
16.2. Data Processing for Market Research Purposes
We also process the data stored or merged in our customer database for statistical analysis and market research purposes. This allows us to better understand our customers’ interests and purchasing habits and adapt and optimize our advertising and sales activities accordingly. We anonymize your data before processing it for this purpose.
If anonymization is not possible in individual cases, we pseudonymize your data before processing it for the aforementioned purposes. We do not engage in individual profiling.
Processing is based on our legitimate economic interest in optimizing our advertising and sales activities, Art. 6 para. 1(f) GDPR.
Whenever your data is pseudonymized for statistical analysis purposes, it is deleted immediately after the analysis has been carried out.
17. Zoho Chat Function
We have embedded a live chat function on our website, which is provided by Zoho Corporation B.V, Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. Zoho processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
When you use the chat function, we will initially process:
-
your name
-
your email address
-
your phone number (optional)
-
the time and date of your query, as well as further information you voluntarily provide in relation to your query
If you have already contacted us via the chat function, have logged into your Leica account or have entered your name and contact data in an order or booking process, we will process this data in order to contact you in a personalized manner via the chat function.
For queries in connection with contracts, e.g., in connection with products and services or support queries, data is processed in order to initiate or execute the respective contractual relationship, Art. 6 para. 1(b) GDPR. In all other cases, we process your data based on our legitimate interest in the effective and proper processing of your query, Art. 6 para. 1(f) GDPR.
Zoho uses cookies and similar technologies. We use these cookies and similar technologies to assist in clearly identifying you as a visitor to our website and to analyze and track your personal behavior on our website. We use the data generated and collected on the basis of the cookies and similar technologies as well as other types of data (IP address, browser type, version and language) to evaluate and optimize the use of our website and the chat function.
Furthermore, these cookies and similar technologies assist us in identifying you as a user when you return to our website, thus allowing us to use the chat function in a targeted manner and personalize our communication with you.
We use cookies and similar technologies based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for analysis and optimization purposes as well as enabling personalized communication.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
We store queries related to contracts for the duration of the contractual relationship, Art. 6 para. 1(b) GDPR. In all other cases, we delete your query three years after the expiration of the calendar year in which we completed the processing of your query.
Data processed on the basis of your consent will be deleted when you withdraw your consent, or at an earlier point in time when the data we collected is no longer required for the purpose for which it was collected.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
18. reCAPTCHA
We use reCAPTCHA v2, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). reCAPTCHA v2 assists us in preventing the automatic, computer-controlled completion of registration forms and thus improper behavior on our website and in connection with our services. To this end, we use CAPTCHAs, i.e., tasks that can easily be solved by humans but not by bots (such as ticking a box and other tasks).
Google will collect your device and personal data when you access the registration screen on our website to subscribe to the newsletter. reCAPTCHA v2 tracks your interactions with our website, including mouse movements, keystrokes and time spent on the website. In addition, we will process your IP address, the referrer URL (the address of the previously visited website), information on your operating system and the settings on your end device, in particular your language settings and location-related data.
reCAPTCHA v2 uses this data to conduct a risk analysis and uses a probability value to calculate whether a human user or a bot is accessing our website. We receive this evaluation from Google in order for us to evaluate the corresponding interaction on our website.
Google deposits a cookie in your browser to provide the risk analysis. Additional information on cookies is available in item 22.
Please note that Google may share the aforementioned data on your use of the website (including the information generated by the cookie) within the Google group of companies and with other third parties. In this context, personal data is transferred to the US (in particular to Google LLC) and to other countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. In all other cases, Google will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
Additional information can be found in Google’s Privacy Policy at https://policies.google.com/privacy?hl=en.
The forwarding of data to Google and any storage of information on your end device or access to such information necessary for this are essential in order for us to provide you with your expressly requested telemedia service, i.e., the use of our website. Consent for this is therefore not required in accordance with the laws of the EU member states on the implementation of EU Directive 2002/58/EC governing the protection of your privacy and electronic communication, amended by EU Directive 2009/136/EC (for example, Section 25 para. 2 no. 1 of the German Telecommunications-Telemedia Data Protection Act (TTDSG)). The associated processing of personal data is based on our legitimate interest in protecting our users from spam, fraud and other improper behavior on our website and in connection with the services we offer, Art. 6 para. 1(f) GDPR.
19. Consent to Receiving Advertising Information and to Data Processing for Advertising Purposes, including Newsletter Tracking
19.1. Consent to Receiving Advertising Information and to Data Processing for Advertising Purposes
If you have given us your consent to receiving advertising information, we will use the information you have disclosed to us (including data that you may have saved in your account and that we may have received through your interactions with us) on the basis of your consent (Art. 6 para. 1(a) GDPR) to send you advertising information about Leica Camera products, services, events and advertising campaigns in accordance with your preferences – by email, telephone, push notification via Leica Camera mobile apps and social media (Facebook, Instagram and YouTube).
The consent is deemed to be granted to the Leica Camera Group*.
To enable us to adapt the communications to your interests and behavior and offer you an optimally personalized experience, we may analyze and combine more of your personal data. This can include the following data:
1. Data that you actively provided us with, e.g.:
-
name
-
date of birth
-
age
-
a further email address
-
mailing address
-
gender
-
telephone number
-
the data you have provided us with via social networks
-
personal interests, e.g., photography, professional imaging, hunting, nature observation
-
product registration
2. Data that we obtain through your interactions with us:
Data on your interactions, such as purchases in Leica Camera stores (POS) and Leica Camera online shops, Customer Care inquiries, your use of the digital Leica Camera channels such as social media, websites, emails, Leica Camera apps and your use of networked Leica Camera products. This data can include the following:
-
IP address
-
cookies
-
device information
-
information you have clicked on
-
location information
-
websites you have visited
-
Leica Camera apps you have used
-
your purchases (products)
-
your inquiries to Leica Camera Customer Care
The provision of this data is voluntary. However, without this data we are unable to provide you with the corresponding information.
19.2. Newsletter Tracking
Newsletters and other advertising information that we send you via email in accordance with your previously selected areas of interest contain web beacons. Web beacons are pixel-sized files which are downloaded from the server of the sender when the email is opened. Technical information about you is initially collected together with this request, such as:
-
delivery of the newsletter
-
browser information
-
information on the system used
-
IP address
-
time of retrieval
We also collect the following data about you:
-
location of retrieval, which we determine on the basis of your IP address
-
information on whether you have opened the email
-
information on which of the links in the email you have clicked on.
This information will be used for statistical purposes in order to bring about a technical improvement in the services on the basis of the technical data or the target groups and their reading behavior. Although this information can be assigned to the individual recipients for technical reasons, the analyses are merely for the purposes of recognizing the reading behavior of our users and adapting our content accordingly, improving it or sending different content in accordance with the interests of our users.
The legal basis for the processing of your data for the aforementioned purposes is the consent you have provided (Art. 6 para. 1(a) GDPR).
19.3. Forwarding of Your Data to Leica Camera Group Companies for Marketing Purposes
If it is necessary in order to fulfill the aforementioned purposes, the data specified above will be forwarded between the companies of the Leica Camera Group.
The legal basis for the transmitting of the data and its further processing by the companies of the Leica Camera Group is the consent you have provided (Art. 6 para. 1(a) GDPR).
If we forward your data to companies of the Leica Camera Group or other recipients outside the European Union or the European Economic Area for the purposes specified in item 19.3, it shall only be forwarded in harmony with the requirements of the GDPR:
Further information on third-country transfers within the Leica Camera Group and on how you can request additional information is available in item 30.
19.4. Forwarding Your Data to Facebook, Instagram and YouTube for Marketing Purposes
In order for us to send you advertising information, we process your email address, country and language and, if necessary, forward them to the following companies on the basis of your consent (Art. 6 para. 1(a) GDPR):
-
Facebook and Instagram
Information to Be Forwarded to Facebook
We want to ensure that the ads are only shown to users who are interested in our advertising information. This is why we use Facebook services to show you personalized advertising. For users outside the US and Canada, the operator of Facebook and Instagram is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For users in the US and Canada, the operator is Meta Platforms Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA.
If you have a Facebook profile, Meta Platforms Ireland Limited may match this data with the information Facebook has already stored about you. Where applicable, Meta Platforms Ireland Limited may also merge this data with other data.
Meta Platforms Ireland Limited may share your information within the Meta group of companies or with other third parties. In this context, personal data may be transferred to the US (in particular to Meta Platforms, Inc.) and to other countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Meta Platforms, Inc. is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Meta Platforms Ireland Limited will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
You can find general information on the further processing and use of your data by Meta Platforms Ireland Limited and your configuration options for protecting your privacy when using Facebook in the Facebook Privacy Policy available at https://www.facebook.com/about/privacy/.
Custom Audiences
We use the “Custom Audiences from File” process. If you have given your consent, we will transfer your email address or phone number that we have on file to Meta Platforms Ireland Limited in hashed form. Meta Platforms Ireland Limited will compare this information with the information stored in its databases in connection with the Facebook platform. If Meta Platforms Ireland Limited finds a match, it will deliver personalized advertising.
Information on how Meta Platforms Ireland Limited processes your personal data is available in the Meta Privacy Policy at https://www.facebook.com/about/privacy/.
-
YouTube
We also transfer the aforementioned data to YouTube. For users in the European Union, the European Economic Area or Switzerland, the operator of YouTube is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For users outside the European Economic Area and Switzerland, the operator is Google LLC, 1600 Amphitheatre Pkwy Mountain View, California 94043, USA.
If you have a Google account, Google can match this data with the information the company has already stored about you. Where applicable, Google will also merge this data with other data.
Google may share your information with other Google companies or other third parties. In this context, personal data may be transferred to the US (in particular to Google LLC) and to other countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Google LLC is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Google will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
You can find general information about the processing of your personal data by Google at: https://policies.google.com/privacy?hl=en
19.5. Right of Withdrawal
You can withdraw your consent with effect for the future, either in full or partially, at any time by sending an email to data-protection@leica-camera.com. The withdrawal of your consent does not affect the lawfulness of the processing performed on the basis of your consent prior to its withdrawal. Should you withdraw your consent, we will no longer use this data to send you advertising information.
You can also set your preferences in your Leica account under your profile and thereby change the communication channels through which you wish to receive advertising information.
19.6. Verification of Consent
We verify your consent using what is known as a double opt-in process: This means that we initially request the active confirmation of your consent via an email sent to the email address you provided. We use the information on the confirmation as well as the time and date of this confirmation to document and verify your consent.
The legal basis for processing your personal data for double-opt-in purposes or for the verification of your consent is Art. 6 para. 1(c) GDPR in conjunction with Art. 7 para. 1 sentence 3 GDPR. We are legally obliged to verify your consent.
19.7. Erasing Your Data
Your data is processed in this context until the purpose of the processing is no longer given or when you withdraw your consent. We store the data verifying your consent for a period of three years.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
20. Integration of Third-Party Content
We have also embedded content from third-party providers on our website. This content is loaded from the servers of the respective service provider, meaning that your end device transfers specific technically necessary data, including your IP address, to these third-party service providers. Using this data, the third-party service providers can track your surfing behavior and can process your IP address along with additional technical information (including browser type and version, operating system used, the previously visited website, the host name of the accessing device and the time of access, as well as additional information on the use of our online offering). Further information on the processing of your personal data by these third-party service providers is available in the respective privacy policies issued by the various service providers, which are referenced below.
We integrate this content on the basis of our legitimate interests in providing our users with the corresponding contents and functions and operating our website in a commercially viable manner, Art. 6 para. 1(f) GDPR.
The services we embed use cookies and similar technologies. The legal basis for the use of these cookies and similar technologies is your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers processing of your personal data for analysis and optimization purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options is available in item 22.
Specifically, we embed the following third-party contents:
20.1. YouTube
YouTube is a service provided for users in the European Economic Area and Switzerland by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and provided for other users by Google LLC, 1600 Amphitheatre Pkwy Mountain View, California 94043, USA.
When you access a (sub)page of our website on which a YouTube video is embedded, a connection with Google’s servers is established in order to load the video preview. During the process, Google collects, for example, information on which of our websites or (sub)pages you are currently visiting.
Google will share personal data within the Google group of companies and with other third parties. In this context, personal data is transferred to the US (in particular to Google LLC) and to other countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Google LLC is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Google will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
You can find the Google Privacy Policy here: https://policies.google.com/privacy?hl=en. Google’s Privacy Policy also contains information about the configuration options for your Google account. Please note that your Google account may be used for different Google services (e.g., Gmail, YouTube, Google Search) and that Google may combine personal data about the Google services you use according to your Google account settings.
20.2. Vimeo
We embed videos from Vimeo on our website. Vimeo is a service provided by Vimeo.com, Inc., 330 West 34th Street, 5th Floor, New York, New York 10001, USA (“Vimeo”).
Your personal data is processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Vimeo is certified in accordance with the EU-US Data Privacy Framework.
We have embedded the Vimeo player on some of the (sub)pages of our website to make it possible for you to access specific Vimeo videos. When you access one of these subpages, your browser will transfer your personal data, e.g., your IP address and the websites or (sub)pages you used to access the Vimeo player, to servers provided by Vimeo.
If you have a Vimeo account and remain logged in to it when you access the subpage, Vimeo will link the transferred information with your account.
You can find the Vimeo Privacy Policy here: https://vimeo.com/privacy. The policy also provides you with information about the configuration options for your Vimeo account. Please note that Vimeo will be able to assign your surfing behavior directly to your personal profile when you are logged in to your Vimeo account.
20.3. Google Maps
We use Google Maps, an online map service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, California 94043, USA (“Google”), to provide interactive maps on our website. Google collects your usage data, such as the referrer URL or the IP address, when you access our website. Google will also process data for its own purposes, such as the provision or improvement of the service, and is thus the controller for the data processing.
You can find the Google Privacy Policy at https://policies.google.com/privacy?hl=en.
Your personal data is processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Google is certified in accordance with the EU-US Data Privacy Framework.
21. Use of Content Published by You (User-Generated Content)
21.1. Data Processing in Connection with Published Content
In some cases, we may ask you to consent to our use of specific content (e.g., photos, audio and video recordings or posts) you have posted on social media platforms. In addition, you can choose to provide us with specific content on our website or as part of promotion campaigns (e.g., by uploading on our website or via specific platforms).
In these cases, we will process your personal data, including any content you have posted, for the purposes and within the scope as defined in the license agreement that you have accepted.
The legal basis for the processing is Art. 6 para. 1(b) GDPR. Processing is required to fulfill the contractual relationship with you.
21.2. Data Collection from a Third Party
If the aforementioned content includes personal data of third parties (such as names, photos, video and audio recordings), we will collect the data from the user who provided us with the content (e.g., via our websites) or who posted the content on social media platforms, or via the platforms themselves.
We will process this data for the purpose of promoting the products and services of the Leica Camera Group and for advertising its companies.
The legal basis for this processing of data of third parties is the consent provided by the third party to the relevant user, Art. 6 para. 1(a) GDPR.
21.3. Recipients
The aforementioned content is published for advertising purposes, including to promote the companies of the Leica Camera Group as well as their products and services. Content is primarily published
-
via the social media accounts of the Leica Camera Group, in particular on Facebook, Instagram, TikTok, Pinterest, YouTube, Vimeo and LinkedIn. Further information on the operators of social media platforms and the processing of your data can be found in item 25.
-
in TV advertising and in print media
-
on the websites of the Leica Camera Group
-
at trade fairs, exhibitions, in Leica stores and galleries
-
as part of online and offline marketing campaigns, competitions and web-based promotions, in print or electronic advertising (leaflets, banners, billboards, ads)
For these purposes, your data will be transferred to the respective operators and shared within the Leica Camera Group.
Additionally, we use service providers to collect, evaluate, manage, process and publish the content. These service providers process your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
If this entails transferring your personal data to a third country for which there is no adequacy decision by the European Commission under Art. 45 GDPR, the standard data protection clauses approved by the European Commission will be used in accordance with Art. 46 para. 2(c) GDPR. Further information on third-country transfers and how you can request additional information is available in item 30.
21.4. Erasing Your Data
We will erase your data in accordance with the provisions of the license agreement, or earlier if the purpose of the processing no longer applies – e.g., if the promotion has ended, the relevant content is no longer featured, or you revoke your consent. If you would like your content to be removed earlier or if you wish to revoke your consent to processing, please contact us at social@leica-camera.com or using the contact details provided in item 1.
If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
Please note that photos and audio recordings published online, including on social media, are accessible worldwide and can be found using search engines. Further use and/or modification by third parties cannot be ruled out, and it may not always be possible to completely erase the content from the internet.
22. Cookies and Similar Technologies
We use cookies to enhance the functionality of the website (strictly necessary cookies), to analyze your use of the website (functional cookies), to count visits and traffic sources, so that we can measure and enhance the performance of our website (performance cookies) and to show you advertisements tailored to your interests within and outside the Leica Camera website (cookies for marketing purposes).
Cookies are text files that contain information. They are saved on your end devices (computer or mobile device) when you visit our websites or use our online services. A general distinction can be made between two types of cookies, known as session and persistent cookies:
Session cookies are small information units containing a randomly generated identification number, which is known as the session ID. Using session IDs enables us to make information such as login data and shopping basket contents available upon the next visit as a personal setting, which also, for example, allows a login session to be continued. A session cookie also contains information on its origin and the retention period. These cookies cannot save any other data. When you log out of your customer account, the used session cookies are deleted.
Persistent cookies store information which may contain personal data from your browser. This can include the following: your IP address, your device type, the domain, browser type, language, operating system, country, time zone, previously visited websites or information about your interaction with our websites such as click behavior, purchases and preferences.
In accordance with the laws of the EU member states on the implementation of EU Directive 2002/58/EC governing the protection of your privacy and electronic communication, amended by EU Directive 2009/136/EC, the setting and reading of data from strictly necessary cookies does not require consent (see, for example, Section 25 para. 2 no. 1 of the German Telecommunications-Telemedia Data Protection Act (TTDSG)). The legal basis for the processing of your personal data, which is also associated with the above, is based on our legitimate interests (Art. 6 para. 1(f) GDPR). We have a legitimate interest in maintaining technical access to and the security and practical use of our website.
Your consent for us to set and read performance cookies forms the legal basis and extends to the processing of your personal data for analyzing how you interact with the website and for compiling performance reports (Art. 6 para. 1(a) GDPR).
Your consent for us to set and read functional cookies forms the legal basis and extends to the processing of your personal data for analyzing how you interact with the website and for providing specific website functions (Art. 6 para. 1(a) GDPR).
Your consent for us to set and read the cookies for marketing purposes forms the legal basis and extends to the processing of your personal data for analyzing your interests and for compiling a marketing profile (Art. 6 para. 1(a) GDPR).
Furthermore, we will forward your personal data on a case-by-case basis – for example as part of contract initiation if necessary – to other companies within the Leica Camera Group. In these cases, the transfer is based on our legitimate interests and the legal basis is Art. 6 para. 1(f) GDPR. We, and the other companies within the Leica Camera Group, have a legitimate interest in designing our work process efficiently and sharing business processes within the Leica Camera Group.
You can also view our website without cookies. Most internet browsers accept cookies automatically. You can prevent cookies being saved on your computer by choosing not to accept cookies in your browser settings. To find out how this works, please refer to the Help function of your browser. You can delete cookies that have been set on your end device at any time. However, if you do not accept cookies, the functionality of our offerings may be restricted.
22.1. How Can I Control the Use of Cookies, or Delete Them?
Strictly necessary cookies are always active and storing and accessing such cookie information does not require your consent. Performance and functional cookies and cookies for marketing purposes are set and read only after you have given your consent.
You can withdraw your consent for the use of performance cookies, functional cookies and cookies for marketing purposes and the associated processing of your data for the purposes described in the following with effect for the future at any time by making the corresponding changes to your cookie settings here . The withdrawal of your consent does not affect the lawfulness of the processing performed on the basis of your consent prior to its withdrawal.
Moreover, you can delete the cookies at any time yourself in your browser settings.
22.2. Contacts for Information on Data Transfer to Third Countries outside the EU or EEA
The use of cookies in part involves the transfer of your personal data to third countries outside the European Union (EU) / European Economic Area (EEA) (see the list of cookies in the cookie settings ) for which an adequacy decision from the European Commission does not exist (a list of safe third countries that provide an appropriate data protection level and for which an adequacy decision has therefore been issued by the European Commission is available at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en). Transferring data to unsafe third countries may be associated with risks to your personal data, in particular because access to your personal data by the respective authorities cannot be definitively excluded. If we transfer your personal data on the basis of your consent to other countries outside the EU/EEA, we will undertake measures to ensure that your data protection rights are safeguarded. These measures include the conclusion of standard data protection clauses between Leica and the respective service provider as well as additional security measures based on Art. 44 et seq. GDPR. Please consider this when giving your consent.
If you have any questions regarding these standard data protection clauses or wish to know more about the security measures applicable to the transfer of data to countries outside the EU or EEA, please contact us via the contact details provided in item 1.
23. Consent Management
In order to obtain, manage and document your consent in conformity with the law, we use OneTrust Consent Manager from our service provider OneTrust Technology Limited, 82 St John St, Farringdon, London EC1M 4JN, United Kingdom (UK) (“OneTrust”).
The European Commission has adopted an adequacy decision for the UK in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection.
On our behalf, OneTrust processes your IP address to ensure the technical provision of OneTrust Consent Manager, as well as your set cookie preferences, including the consent provided, rejected or withdrawn by you, for the purpose of lawful consent management. OneTrust stores necessary cookies on your end device in order to save your cookie preferences, including the status of your consent.
Furthermore, we process the aforementioned data and the time of your consent in conjunction with the unique cookie ID in order to verify that you have provided consent. The legal basis for this processing is Art. 6 para. 1(c) in conjunction with Art. 7 para. 1 GDPR.
We delete any information stored to verify your consent following conclusion of the statutory period of limitation, i.e., three years starting from the end of the year in which we received your withdrawal of consent. If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.
24. Analysis Tools and Marketing Services
24.1. Google Tag Manager
If you have given your consent, we will use Google Tag Manager. This service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), and is operated on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
Google Tag Manager is a service we use to embed other technologies and services such as Google Analytics on our website. In this case, Google Tag Manager is merely used for managing and delivering the technologies embedded by it (via tags). This means that Google Tag Manager itself does not create any user profiles, does not store any cookies and does not conduct any independent analyses.
However, Google Tag Manager does collect your IP address, which may also be transferred to Google’s parent company, Google LLC in the USA, and to countries outside the European Economic Area for which there is no adequacy decision by the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Google LLC is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Google will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
Your personal data will be stored for this purpose for a period of 14 days. After this period, the data is deleted and only aggregated statistics are retained.
We use Google Tag Manager based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.2. Google Analytics
If you have given us your consent, we will use Google Analytics, a web analysis service, to analyze the use of our website and adapt it to the needs of our users based on the resulting findings. This service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
Google Analytics stores cookies on your end device and uses them to collect pseudonymous data about your use of our website. In particular, this includes the number of visits to our website, the time spent on the website and how you interact with it (e.g., the pages you visit, the links you click, whether you search for something or download content, and whether you make a purchase or subscribe to our newsletter). We can track your interactions (known as events) with our website using tags, which are used to mark any interactions that we consider events to be tracked. Once a specific event has been assigned a tag, the tag is triggered as soon as you interact with the website in the relevant way, and the corresponding event data is sent to Google Analytics. Based on your IP address, Google Analytics also collects information on your geographic location (such as the city) and your end device (including the model and screen resolution).
We use Google Signals, a feature that enables cross-device and cross-browser tracking as part of Google Analytics. For this purpose, you will be assigned a unique identifier (user ID) that allows us to track and analyze your interactions with our website across multiple devices and browsers. Google Signals enables us to add the demographic information (e.g., age, gender, interests) provided by Google to your Google Analytics tracking profile. This allows us to improve our insights and statistics about our users’ interests and interactions.
Google uses this information to analyze your use of our website, to compile reports on the website activities, and to generate other analyses and evaluations relating to the use of our website and the internet. Google may also combine this information with other information about you, such as your search history, your personal account, usage data from other devices and other information that Google has stored about you. Google may also pass this information on to third parties if this is required by law (e.g., by government authorities) or when third parties process this data on behalf of Google.
The data will be stored for a period of 26 months.
a) Google Signals remarketing feature (personalized ads using Google Ads)
If you have agreed to the use of Google Analytics and of Google Ads remarketing (including the use of associated cookies and tags), we will use the remarketing feature to personalize ads via Google Ads. These features allow us to create target groups for our website users based on demographic data (age, gender, interests) and other aggregated tracking data provided to Google Analytics by Google Signals. The target groups are shared in Google Ads and allow us to create personalized marketing campaigns for the specified groups and target our adverts accordingly. Google uses this information to create detailed reports and custom models relating to the success of our marketing campaigns and our conversion rates (e.g., purchases). In addition, Google can use the information to make predictions about the cross-device behavior of our entire user base.
However, this only happens when you visit our website while also logged into a Google service with the “Ad personalization” option enabled in your Google account settings. We do not have access to personal data or usage profiles in your Google account at any time; they remain anonymous to us.
Additional information on Google Ads remarketing can be found in item 24.3.
b) Google Signals and Google Ads conversion tracking
If you have agreed to the use of Google Analytics and of Google Ads conversion tracking (including the use of associated cookies and tags), we will share the tracking data with Google Ads conversion tracking to optimize our marketing campaigns.
Google uses this information to create detailed reports and custom models relating to the success of our marketing campaigns and our conversion rates (e.g., purchases). In addition, Google can use the information to make predictions about the cross-device behavior of our entire user base.
Additional information on Google Ads conversion tracking can be found in item 24.4.
When using Google Analytics (including Google Signals and other supplementary features described above), personal data may be transferred to third countries (in particular to servers operated by Google LLC in the USA), as described in 24.1.
We use Google Analytics (including Google Signals and other supplementary features described above), and the corresponding cookies and tags based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here [Link auf Cookie-Einstellungen]. Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
If you do not wish your use of the website to be analyzed, you can also deactivate Google Analytics using a browser add-on. You can download the add-on here: https://tools.google.com/dlpage/gaoptout?hl=en.
You can also prevent the collection of your data by Google Analytics by clicking the following link. This sets an opt-out cookie that prevents the collection of your data during future visits to this website: Disable Google Analytics.
24.3. Google Ads Remarketing
If you have given us your consent, we will use the functions of Google Ads remarketing, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). This enables the advertising of our website in Google search results as well as on third-party websites. To do so, Google sets a cookie in your end device’s browser, which automatically allows interest-based advertising using a cookie ID and based on the websites you visited. Furthermore, Google will link your browsing history with your Google account and use information from your Google account to personalize ads you see on the web. If you are logged in to Google while visiting our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. To do this, Google will temporarily link your personal data to Google Analytics data to form target groups.
In addition, please note that Google may share the information on your use of the website generated by the cookies within the Google group of companies (in particular with Google LLC) and with other third parties. This may lead to a transfer of personal data to the US and to third countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Google LLC is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Google will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
Details on the data processing initiated by Google Ads remarketing and on how Google handles data collected from websites are available here: https://policies.google.com/technologies/partner-sites?hl=en. You can find general information about the processing of your personal data by Google at: https://policies.google.com/privacy?hl=en and https://policies.google.com/technologies/ads?hl=en.
The data saved by Google will be stored for a period of 14 months.
We use Google Ads remarketing and the corresponding cookies based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.4. Google Ads Conversion Tracking
If you have given your consent, we will use the functions of Google Ads conversion, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), to draw attention to our offers by using advertising media (Google Ads) on external websites. We can determine how successful the individual advertising measures are in relation to the data of the advertising campaigns. In doing so, we pursue our interest in displaying advertising which may be of interest to you, designing our website such that it increases your interest and achieving a fair calculation of advertising costs.
Google delivers these advertising media via an ad server. For this, Google Ads uses cookies which allow specific parameters to be measured in order to determine success, such as when the ads are displayed or the number of clicks by users. If you accessed our website via a Google advertisement, Google Ads will store a cookie on your end device. Along with this cookie, the unique cookie ID, the number of impressions per placement (frequency), last impression (relevant for post-view conversions) and opt-out information are generally stored as analysis values. In these statistics we can see the total number of users who clicked on one of our ads and were forwarded to a page with a conversion tracking tag. However, we receive no information which allows users to be identified personally.
You can find general information about the processing of your personal data by Google at: https://policies.google.com/privacy?hl=en and https://policies.google.com/technologies/ads?hl=en.
When Google Ads conversion is used, personal data may be transferred to third countries (in particular to servers operated by Google LLC in the USA), as described in 24.3.
We use Google Ads conversion and the corresponding cookies based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
Google Conversion Linker
If you have given your consent, we use the Google conversion linker in connection with Google Ads conversion tracking (item 24.4). This service ensures a higher degree of reliability for measuring click data, thereby allowing us to record conversions effectively. If you click our advertisements, the URL of the conversion page on our website will receive information on the click. When you execute an action that we have tagged as a conversion (e.g., by triggering a Google Ads conversion tracking tag, see item 24.4), this information will be used to link the conversion with the click through which you accessed our website. The conversion linker is used to automatically collect information regarding the click on the ad in the URLs of the conversion page and store it in dedicated cookies on our website.
You can find general information about the processing of your personal data by Google at: https://policies.google.com/privacy?hl=en and https://policies.google.com/technologies/ads?hl=en.
When Google Ads conversion is used, personal data may be transferred to third countries (in particular to servers operated by Google LLC in the USA), as described in 24.3.
We use Google conversion linker and the corresponding cookies and tags based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.5. Google Floodlight
If you have given your consent, we will use Google Floodlight, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (“Google”).
Your personal data is processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Google is certified in accordance with the EU-US Data Privacy Framework.
We use Google Floodlight for conversion tracking in connection with Google Ads conversion tracking and Google Analytics. This includes setting Google Floodlight tags on our website to measure the efficiency of our advertising campaigns with greater accuracy and allow us to determine specific conversions which we tagged (e.g., a purchase or access to our website) and the advertising channels (e.g., display or search displays) via which these conversions were generated. We can filter these evaluations and assess them according to specific criteria. Google Floodlight uses cookies and similar technologies to track conversions in order to identify you based on a unique cookie or user ID and to save your interactions (impressions, clicks and other activities) along with this ID. This makes it possible to track your interactions across multiple devices and assign them to a conversion.
We use Google Floodlight and the corresponding cookies and tags based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
You can find general information about the processing of your personal data by Google at: https://policies.google.com/privacy?hl=en and https://policies.google.com/technologies/ads?hl=en.
24.6. Google Optimize
If you have given your consent, we use Google Optimize, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), for A/B and multivariate tests (MVT). Google processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
Google Optimize analyzes the use of different variants of website design so that we can use these analyses to align our website with the needs of our users and adapt the website’s user friendliness. Google Optimize is a tool embedded in Google Analytics (see item 24.2) and uses cookies.
During the A&B and MVT tests, we do not evaluate your individual preferences; instead, we use statistical values to analyze how most of the website users react to a specific website design. Your personal data will be stored for this purpose for a period of 90 days. After this period, the data is deleted and only aggregated statistics are retained.
When using Google Optimize, personal data may be transferred to third countries (in particular to servers operated by Google LLC in the USA), as described in 24.1.
We use Google Optimize and the corresponding cookies based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options is available in item 22.
24.7. X Pixel
If you have given your consent, we will use the X Pixel of Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (“X”). In particular, if you have engaged with our tweets and ads on X, e.g., by clicking a link redirecting you to our website, the X Pixel enables us to track your interactions with our website across your devices and can connect several of your visits to our website.
Using the X Pixel , we record the time and date of your visit and the links you clicked. Furthermore, we receive aggregated metric reports about user behavior from X. This data helps us analyze our conversion rate and to understand user behavior on our website as well as tweet engagement, allowing us to optimize our website and our activities on X.
X will share your data within the X group and with other third parties. In this context, personal data may be transferred to the US (in particular to X Corp.) and to other third countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. X Corp. is certified in accordance with the EU-US Data Privacy Framework. In all other cases, X will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
Information on how X processes your personal data, including information on data transfers to third countries, can be found in the X Privacy Policy at https://twitter.com/en/privacy.
We use the X Pixel based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.8. Meta Pixel
Subject to your consent, our website uses the Meta Pixel remarketing function of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Meta”). The purpose of this function is to present interest-related advertising (“Facebook ads”) to visitors to this website during their visits to the Facebook social network, thereby optimizing our advertising campaigns. The Meta Pixel captures when you perform certain actions on our website or visit certain areas of our website. The Meta Pixel also collects usage data as well as technical data (such as URL, referrer URL, IP address, device and browser properties and time stamps). The Meta Pixel generates a checksum (hash value) from this information and transfers this hash value to Facebook. Where available, the Facebook cookie is also queried and your Facebook ID is transmitted. If you have a Facebook profile and log in there, the data transmitted by the pixel can be used to present targeted, personalized advertising on Facebook. Data from users who do not have a Facebook profile will be discarded, unused, by Meta Platforms Ireland Limited.
You can find further information on the processing of your personal data by Meta Platforms Ireland Limited in the Meta Privacy Policy at https://www.facebook.com/about/privacy.
Meta Platforms Ireland Limited may share your information within the Meta group of companies (in particular with Meta Platforms, Inc.) or with other third parties. In this context, personal data may be transferred to the US and to other third countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Meta Platforms, Inc. is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Meta Platforms Ireland Limited will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
As a Facebook user, you can revoke your consent from Meta Platforms Ireland Limited at any time by deactivating advertisements based on partner data in your Facebook settings under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.
We use the Meta Pixel based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.9. LinkedIn Insight Tag
This website uses the “Insight Tag” function by LinkedIn Ireland Unlimited, Wilton Plaza, Wilton Pl, Dublin, 2, Ireland (“LinkedIn”). The Insight Tag is a small JavaScript code section that is added to this website in order to enable detailed reports on advertising campaigns and obtain valuable information about you as a visitor to this website. We use the Insight Tag in order to track conversions, retarget website visitors and gain further information about you as a LinkedIn member when you view one of our ads. The Insight Tag enables LinkedIn to collect data such as the URL, referrer URL, IP address, device and browser properties, time stamp and page views during a visit to this website. LinkedIn encrypts this data, anonymizes it within seven days and deletes the anonymized data within 90 days. LinkedIn does not share any personal data with us; it only offers summarized reports on the target group for the website and the performance of ads. With the Insight Tag, LinkedIn also offers us the possibility of retargeting so that we can use the collected data to display targeted ads outside this website without you being identified.
In this context, LinkedIn may transfer personal data to the US (in particular to the LinkedIn Corporation) and to other countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. The LinkedIn Corporation is certified in accordance with the EU-US Data Privacy Framework. In all other cases, LinkedIn will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection. You can find relevant information at https://www.linkedin.com/help/linkedin/answer/62533?trk=microsites-frontend_legal_privacy-policy&lang=en.
As a member of LinkedIn, you can manage the use of your personal data for advertising purposes in your LinkedIn account settings.
Further information on the collection and use of data by LinkedIn as well as your rights in this connection and options for protecting your privacy can be found in the LinkedIn Privacy Policy at https://www.linkedin.com/legal/privacy-policy?trk=uno-reg-guest-home-privacy-policy.
We use the LinkedIn Insight Tag based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.10. TikTok Pixel
If you have consented, our website uses the TikTok Pixel from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland and TikTok Information Technologies UK Limited, 6th Floor, One London Wall, London, EC2Y 5EB, United Kingdom (collectively “TikTok”).
The European Commission has adopted an adequacy decision for the UK in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection.
TikTok and Leica share responsibility for the processing associated with the use of the TikTok Pixel. We have concluded an agreement with TikTok for this purpose which covers the joint responsibility for the processing; this agreement can be accessed at https://ads.tiktok.com/i18n/official/policy/jurisdiction-specific-terms (located under “Joint Controller Terms” and “Allocation of GDPR responsibilities”). Leica and TikTok each undertake to assume primary responsibility for fulfilling the obligations under the GDPR for the data processed by the respective party. In this case, TikTok assumes responsibility for fulfilling the rights of the data subjects (Art. 15–20 GDPR) for the data processed by TikTok.
TikTok uses cookies and similar technologies, such as the pixel, to assign a unique identifier to you, so that you are recognized the next time you visit our website. This involves collecting and transferring information on your visit to our website, the date and time of the visit, information on the browser you use and the device type, the screen resolution and your IP address to TikTok. TikTok may assign this information to your personal TikTok user account. By using this service, we can analyze who visits our website and address them through targeted advertising on TikTok, and we can evaluate the reach and effectiveness of our ads in order to optimize our advertising campaigns.
You can find further information on the processing of your data by TikTok in TikTok’s Privacy Policy at https://www.tiktok.com/legal/page/eea/privacy-policy/en.
In this context, TikTok may transfer personal data to the US and to other countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. In all other cases, TikTok will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection. You can find relevant information at https://www.linkedin.com/help/linkedin/answer/62533?trk=microsites-frontend_legal_privacy-policy&lang=en https://www.tiktok.com/legal/page/eea/privacy-policy/en#data-transfer.
We use the TikTok Pixel and the corresponding cookies and similar technologies based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.11. Taboola Pixel
This website uses Taboola Pixel provided by our partner Taboola Europe Limited, Aldgate House, 2nd Floor, 33 Aldgate High Street, London EC3N 1DL, United Kingdom.
The European Commission has adopted an adequacy decision for the UK in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection.
When you click an ad and are taken to our website, we can track your behavior on our website using the Taboola Pixel. The Taboola Pixel also allows us to display targeted advertising to you if you have already shown interest in specific products on our website. The Taboola Pixel uses a unique identifier to recognize and track you on our website. The information required for this purpose and information about your visit to our website, your browser and your end device are stored in cookies on your end device and sent to Taboola. In addition, Taboola uses the IP address, minus the last octet, to determine your approximate location. This results in pseudonymous profiles which are stored by Taboola for 13 months. We use Taboola Pixel to evaluate the effectiveness of our ads for statistical and market research purposes and to optimize future advertising campaigns.
You can find further information on data processing by Taboola at https://www.taboola.com/policies/privacy-policy.
Taboola can share your data within the Taboola group of companies or with other third parties. This may lead to a transfer of personal data to the US and to other third countries not covered by an EU adequacy decision. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. In all other cases, Taboola will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
We use the Taboola Pixel based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.12. Outbrain Pixel
This website uses the Outbrain Pixel from our partner, Outbrain UK Ltd, 5th Floor, The Place, 175 High Holborn, London, WC1V 7AA, United Kingdom (“Outbrain”), a technology of Outbrain Inc., 39 W 13th Street New York, NY 10011, USA.
The European Commission has adopted an adequacy decision for the UK in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection.
When you click on an ad and are taken to our website, we can track your behavior on our website using the Outbrain Pixel. In addition, the Outbrain Pixel allows us to send you targeted advertising if you have already shown an interest in certain products on our website. The Outbrain Pixel uses a unique identifier to recognize and track you on our website. Information about your visit to our website, your browser and your end device, as well as information required for this purpose, is collected in cookies stored on your end device and sent to Outbrain. In addition, Outbrain uses the IP address, minus the last octet, to get your approximate location. This produces pseudonymous profiles that Outbrain stores for 13 months. We use the Outbrain Pixel to evaluate the effectiveness of our ads for statistical and market research purposes and to optimize future advertising campaigns.
You can find further information on data processing by Outbrain at https://www.outbrain.com/privacy/.
Outbrain may share your information within the Outbrain group of companies (in particular, Outbrain, Inc.) or with other third parties. In this context, personal data may be transferred to the US and to other third countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Outbrain Inc. is certified in accordance with the EU-US Data Privacy Framework. In all other cases, Outbrain will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR to ensure an adequate level of data protection.
We use the Outbrain Pixel based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
24.13. Pixlee
We use the Pixlee analysis feature, a service provided by Pixlee Inc., 2443 Fillmore Street #380 – 18365, San Francisco, CA 94115, USA (“Pixlee”), on our website. Pixlee processes your personal data on our behalf (see Art. 4 no. 8 and Art. 28 GDPR).
Your personal data is processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. Pixlee is certified in accordance with the EU-US Data Privacy Framework.
We have integrated the Pixlee widget on our website to dynamically display photos and other content from our users. When you visit subpages of our website on which the Pixlee widget has been implemented and access the embedded photos and content, the cookies set by Pixlee enable us to track how you interact with the Pixlee widget and the embedded photos and content. This way, we are able to track how often these subpages are accessed, which photos and content our users click on, whether users zoom in using the lightbox view, how they navigate within the lightbox, what links they click and whether they have loaded additional content using the “Load more content” button. To this end, Pixlee assigns you a unique user ID that allows us to identify you when you visit the corresponding subpages again. Your user ID is stored for 30 days. After this period has expired, we will only retain aggregated, anonymized data.
Furthermore, the cookies set by Pixlee are used to display photos and content and enable navigation within the lightbox.
We use the Pixlee analysis function and the corresponding cookies based on your consent, Art. 6 para. 1(a) GDPR. This legal basis also covers the processing of your personal data for the aforementioned purposes.
You can withdraw your consent with effect for the future at any time by making the corresponding changes to your cookie settings here . Additional information on the use of cookies and similar technologies as well as on your withdrawal options can be found in item 22.
25. Our Social Media Presence
We operate pages or profiles on different social media platforms. In this context, personal data is processed as described below.
25.1. General Information
When you interact with us via our social media pages or our posts, we collect and process the data that you provide in this respect, which may include your user name and any profile photo. This is the case, for example, whenever you like, share or comment on a post or provide other content. This data is collected via the platform on which we maintain our social media presence. This data is regularly processed on the basis of our legitimate interest in making the corresponding functions available on our social media pages (Art. 6 para. 1(f) GDPR) and, if applicable, on the basis of your consent given to the operator of the respective social media platform (Art. 6 para. 1(a) GDPR) or your contractual relationship with the operator (Art. 6 para. 1(b) GDPR). Please also note that this content is published on our social media pages in line with your account settings and can be accessed by anyone worldwide.
We may also process data in order to receive and process inquiries or messages via our social media pages (Art. 6 para. 1(f) GDPR). For queries in connection with contracts, data will be processed for the initiation or execution of the respective contractual relationship with you (Art. 6 para. 1(b) GDPR) or with the company for which you work (Art. 6 para. 1(f) GDPR). The latter also constitutes our legitimate interest.
In addition, the operators collect and process your personal data under their own responsibility under data protection law when you visit our social media pages and/or interact with them or our posts.
25.2. Additional Processing of Data of Logged-In and Non-Logged-In Users
If you visit our social media presences and interact with our posts while logged in to the respective platform, for example when you like a post, the operators of the platforms will collect your personal data. Even if you are not logged in to the respective platform, the operators collect certain personal data, such as your IP address and other unique identifiers linked to your browser or device, when you access the site. In addition, the operators collect your pseudonymous usage data on how you interact with our social media presences and the content provided there (posts, videos, buttons, etc.).
25.3. Cookies and Similar Technologies
The operators of the respective platforms use cookies and similar technologies in order to determine, for example, if you (as the user) are already logged in to or registered on the respective platform or on any of the other products, apps and platforms of the operator. In particular, the operators of the respective platforms also use these technologies to track your usage behavior for the purpose of generating a profile for analysis and advertising purposes. Your usage behavior can also be tracked when you visit other websites and apps which embed products from the operator. For example, Meta Platforms can track your usage behavior when you visit a website which embeds the “Like” button or other Facebook or Meta technologies. Please also note that the respective operators share this data with third parties.
You can find further information in the operators’ cookie policies, which are referenced below.
25.4. Transfers to Third Countries
The respective operators of the platforms share your personal data within their groups of companies as well as with other third parties. In this context, personal data may be transferred to the US and to other third countries not covered by an adequacy decision of the European Commission. For data transferred to the US, the European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-US Data Privacy Framework, which serves as the basis for transferring data to certified companies and organizations located in the US. For example, Meta Platforms, Inc., Google LLC, Vimeo.com, Inc., and the LinkedIn Corporation are certified in accordance with the EU-US Data Privacy Framework. In all other cases, the respective operators will use the standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR, provided they cannot invoke exceptional circumstances pursuant to Art. 49 para. 1 GDPR. Additional information can be found in the operators’ privacy notices listed below.
Please note that your data may be combined across different platforms and services if they are operated by the same operator. For example, for users outside the US and Canada, the operator of both Facebook and Instagram is Meta Platforms Ireland Limited (formerly Facebook Ireland Ltd.). You can find further information in the operators’ privacy policies, which are referenced below.
25.5. Facebook
You can find our Facebook page at https://www.facebook.com/LeicaCamera/.
For users outside the US and Canada, the operator of Facebook is Meta Platforms Ireland Limited (formerly Facebook Ireland Ltd.), 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For users within the US and Canada, the operator of Facebook is Meta Platforms, Inc. (formerly Facebook, Inc.), 1601 Willow Road Menlo Park, CA 94025, USA.
Information on how Meta Platforms Ireland Limited processes your personal data is available in the Meta Privacy Policy at https://www.facebook.com/privacy/policy/ and at https://www.facebook.com/legal/terms/information_about_page_insights_data. The Privacy Policy also contains information about the configuration options for your Facebook account.
Meta Platforms Ireland Limited uses cookies and similar technologies. Related information is provided by Meta Platforms Ireland Limited in its Cookies Policy at https://www.facebook.com/policies/cookies/. To find out how you can manage existing information about you, visit https://www.facebook.com/about/basics.
Furthermore, we are jointly responsible with Meta Platforms Ireland Limited for the processing of Page Insights data when visiting our Facebook page. Meta Platforms Ireland Limited uses this Page Insights data to analyze user behavior on our Facebook page and provides this information to us in anonymized form. We can use Page Insights to conduct an anonymous evaluation of the reach, page views, time spent with (video) posts, actions (likes, comments, sharing of posts) and the age, gender and location of users (as specified in their respective Facebook profiles). The evaluation of reach can involve making settings or defining corresponding filters for selecting a time period, a specific post and the demographic groups (e.g., according to age and gender). Further information is provided by Meta Platforms Ireland Limited here: https://www.facebook.com/help/268680253165747.
Platforms Ireland Limited agrees, among other things, to assume primary responsibility pursuant to the GDPR for the processing of Page Insights data and to fulfill all obligations under the GDPR with respect to the processing of Page Insights data. For this purpose, we have entered into an agreement with Meta Platforms Ireland Limited regarding our joint responsibility for data protection in relation to data processing. The agreement is available here: https://www.facebook.com/legal/terms/page_controller_addendum. In this agreement, Meta
The processing serves our legitimate economic interests in the optimization and needs-based design of our Facebook page, Art. 6 para. 1(f) GDPR.
25.6. Instagram
You can find our Instagram page at: https://www.instagram.com/leica_camera/.
For users outside the US and Canada, the operator of Instagram is Meta Platforms Ireland Limited (formerly Facebook Ireland Ltd.), 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The operator of Instagram for users in the US and Canada is Meta Platforms, Inc. (formerly Facebook Inc.), 1601 Willow Road Menlo Park, CA 94025, USA.
Information on how Meta Platforms Ireland Limited processes your personal data is available in the Meta Privacy Policy at https://privacycenter.instagram.com/policy and at https://www.facebook.com/legal/terms/information_about_page_insights_data. The Privacy Policy also contains information about the configuration options for your Instagram account.
Meta Platforms Ireland Limited uses cookies and similar technologies. Related information is provided by Meta Platforms Ireland Limited in the Meta Cookies Policy available at https://privacycenter.instagram.com/policies/cookies/. To find out how you can manage existing information about you, visit https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect
Furthermore, we are jointly responsible with Meta Platforms Ireland Limited for the processing of Instagram Insights as part of operating our Instagram page. Meta Platforms Ireland Limited uses these Instagram Insights to analyze user behavior on our Instagram page and provides this information to us in a depersonalized form. We can use Instagram Insights to conduct an anonymous evaluation of the reach, page views, time spent with (video) posts, actions (likes, comments, sharing of posts), taking into account factors such as the age, gender and location of users (as specified in their respective Instagram profiles). The evaluation of reach can involve making settings or defining corresponding filters for selecting a time period, a specific post and the demographic groups (e.g., according to age and gender). Further information is provided by Meta Platforms Ireland Limited here: https://www.facebook.com/help/pages/insights.
For this purpose, we have entered into an agreement with Meta Platforms Ireland Limited regarding our joint responsibility for data protection, which you can access at the following link: https://www.facebook.com/legal/terms/page_controller_addendum. In this agreement, Meta Platforms Ireland Limited agrees, among other things, to assume primary responsibility pursuant to the GDPR for the processing of Instagram Insights and to fulfill all obligations under the GDPR with respect to this processing.
The processing serves our legitimate economic interests in the optimization and needs-based design of our Instagram page, Art. 6 para. 1(f) GDPR.
25.7. TikTok
Our TikTok profile is available at https://www.tiktok.com/@leica_camera_official.
For users within the European Economic Area, Switzerland and the United Kingdom, the operator of TikTok is, under joint responsibility, TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, 4 Lindsey Street, Barbican, London, EC1A 9HP, United Kingdom (collectively “TikTok”). You can find the TikTok Privacy Policy at https://www.tiktok.com/legal/page/eea/privacy-policy/en.
TikTok provides TikTok analytics for our TikTok profile. TikTok uses this analytics data to evaluate the behavior and interactions of users when they visit our TikTok profile and provides this information to us in a depersonalized form. We can use TikTok analytics to evaluate and filter the reach, follower development, profile and video views as well as the number of actions (likes, commenting, sharing of videos) within selected periods of time. Furthermore, we can use the analytics data to define individual filters for each of our videos. This allows us to evaluate and filter the number of accesses, actions (likes, commenting, sharing of videos), the average duration of the access and the share of users who watched the entire video for specific periods of time. This also includes information on where the users discovered our videos (e.g., on our profile or in the For You feed) and the region where our users come from.
TikTok analytics also provides additional filters and evaluation options with regard to our followers. This allows us to evaluate where our followers come from and when they are active and compare the development of the number of our followers over specific periods of time.
This information allows us to analyze and optimize the effectiveness of our TikTok activities. The associated processing serves our legitimate interests in optimizing our TikTok activities (Art. 6 para. 1(f) GDPR).
25.8. Pinterest
You can find our Pinterest page at: https://www.pinterest.de/leicacamera/.
For users outside the US, Pinterest is operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. For users in the US, the operator of Pinterest is Pinterest Inc. at 651 Brannan Street, San Francisco, CA 94107, USA. You can find the Pinterest Privacy Policy at https://policy.pinterest.com/en/privacy-policy. The policy also includes information on cookies and similar technologies used by Pinterest.
Pinterest provides us with depersonalized information and analyses regarding the use of our account. This information allows us to analyze and optimize the effectiveness of our Pinterest activities. The associated processing is based on our legitimate interests in optimizing our Pinterest activities (Art. 6 para. 1(f) GDPR).
25.9. YouTube
You can find our YouTube page at: https://www.youtube.com/channel/UCVmgQawOcdeA9v9o0aukV7A.
YouTube is a service provided for users in the European Economic Area and Switzerland by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and provided for other users by Google LLC, 1600 Amphitheatre Pkwy Mountain View, California 94043, USA. You can find the Google Privacy Policy here: https://policies.google.com/privacy?hl=en.
Please note that your Google account may be used for different Google services (e.g., Gmail, Google Search) and that YouTube and/or Google Ireland Limited may combine personal data about the Google services you use according to your Google account settings.
Google Ireland Limited uses cookies and similar technologies. Google provides information on the use of cookies and similar technologies at https://policies.google.com/technologies/cookies?hl=en.
We use YouTube Analytics. Through this function, Google Ireland Limited provides us with depersonalized and aggregated information on user interactions with our contents available on YouTube, as well as information on the use of the YouTube channels.
By using YouTube Analytics, we can analyze anonymous evaluations of the reach and popularity of YouTube videos with subscribers and non-subscribers of our YouTube channel, the views and play times of the individual YouTube videos and community posts, and the viewer loyalty based on “Like” or “Dislike” data and click rates. YouTube Analytics allows us to conduct these evaluations by target group (e.g., according to age and gender, region and languages) and compare the results with data and online activities outside of our own YouTube channels.
This information allows us to analyze and optimize the effectiveness of the YouTube activities. The associated processing serves our legitimate interests in optimizing our YouTube activities, Art. 6 para. 1(f) GDPR.
25.10. Vimeo
You can find our Vimeo page at https://vimeo.com/leicacamera .
Vimeo is a service provided by Vimeo.com, Inc., 330 West 34th Street, 5th Floor, New York, New York 10001, USA (“Vimeo”). Vimeo’s Privacy Policy is available at https://vimeo.com/privacy.
Vimeo uses cookies and similar technologies. Vimeo provides information on the use of cookies and similar technologies at https://vimeo.com/cookie_policy.
25.11. LinkedIn
You can find our LinkedIn account at: https://de.linkedin.com/company/leica-camera-ag.
For users residing in the European Economic Area and Switzerland, the operator of LinkedIn is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (“LinkedIn Ireland”). For all other users, the operator is LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, CA 94085, USA. You can find the LinkedIn Ireland Privacy Policy at: https://www.linkedin.com/legal/privacy-policy. It also contains information about the configuration options for your LinkedIn profile.
LinkedIn Ireland uses cookies and similar technologies. Related information is provided by LinkedIn Ireland at https://www.linkedin.com/legal/cookie-policy as well as in its Privacy Policy at https://www.linkedin.com/legal/privacy-policy.
We use Page Insights. Through this function, LinkedIn Ireland provides us with depersonalized information and analyses on the use of our company page and/or your interactions with our posts (e.g., clicks on user-defined buttons embedded in our posts). This information allows us to analyze and optimize the effectiveness of our LinkedIn activities. For this purpose, LinkedIn Ireland processes data that you provided to LinkedIn Ireland via the information in your profile in particular. This includes data on your job, country, sector, professional seniority, company size and employment status. LinkedIn Ireland will also process information on whether you are a follower of our LinkedIn company page. We can filter this information using the above-mentioned demographic criteria.
Furthermore, we are jointly responsible with LinkedIn Ireland for the processing of Page Insights data when visiting our LinkedIn company page. For this purpose, we have entered into an agreement with LinkedIn Ireland regarding our joint responsibility for data processing, which you can access here: https://legal.linkedin.com/pages-joint-controller-addendum. In this agreement, LinkedIn Ireland agrees, among other things, to assume primary responsibility pursuant to the GDPR for the processing of Page Insights data and to fulfill all obligations under the GDPR with respect to the processing of Page Insights data.
The processing serves our legitimate economic interests in the optimization and needs-based design of our LinkedIn company page, Art. 6 para. 1(f) GDPR.
25.12. X (Formerly Twitter)
You can find our X account at:
For users in the European Union, the European Economic Area, and the United Kingdom, X (formerly Twitter) is operated by Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 Ireland (“Twitter International”). For all other users, X is operated by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.
You can find the X Privacy Policy at: https://twitter.com/en/privacy. It also contains information about the configuration options for your X account.
Twitter International uses cookies and similar technologies. Related information is provided by Twitter International in its cookie guidelines https://help.x.com/en/rules-and-policies/x-cookies. To find out how you can manage existing information about you, visit https://help.x.com/en/managing-your-account, https://help.x.com/en/safety-and-security and https://x.com/settings/account/personalization.
We use the X Analytics feature. Through this function, Twitter International provides us with depersonalized information about your interactions with and use of our X profile.
We can use X Analytics to conduct an anonymous evaluation of the reach and interactions (likes, comments, retweeting of posts), taking into account specific factors such as location data specified by users in their X profile or in their tweets. The evaluation of reach can involve making settings or defining corresponding filters for selecting a time period, viewing a specific post, and prioritizing characteristics such as the followers’ location and interests. This information allows us to analyze and optimize the effectiveness of our activities on X. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.
26. Job Applications
Information on the processing of your data collected in connection with your job application can be found in the Privacy Policy for Applicants (only available in German).
27. Further Processing of Your Personal Data
We process the same data collected for the aforementioned purposes, as well as for the following purposes:
-
for law enforcement, hazard prevention or prosecution if there is specific evidence of crimes
-
to provide proof and assert, exercise or defend against claims
-
for internal administrative purposes, organization of our business and financial accounting
-
for complying with statutory obligations
Processing is based on our legitimate interests in maintaining our business activities, performing our tasks, asserting, exercising or defending against claims (Art. 6 para. 1(f) GDPR) or on a statutory obligation (Art. 6 para. 1(c) GDPR).
28. Disclosure of Your Data
You are neither contractually nor legally obliged to disclose your personal data. However, the provision of personal data is necessary so that:
-
you can register a Leica account or Leica customer account and use the corresponding services
-
we can receive and execute your orders and/or bookings and you can take advantage of our financing offers
You will not be able to conclude a contract if you do not provide your data.
Moreover, disclosing your data is required so that:
-
we can receive and process your contact, support and service inquiries and other queries
-
you can use the functions and services provided on our website
-
we can guarantee the security of our website and the services you use
-
you can use the community functions available on our social media presences
If you need to provide your data, we will alert you to this by designating the appropriate fields as mandatory during input. Additional data is provided on a voluntary basis. Where providing your data is mandatory, failing to do so will result in our being unable to provide the aforementioned functions and services to you.
In other cases, failing to provide your data may result in our not being able to provide the respective functions and services at all, or not to the usual extent.
29. Forwarding Your Data
Alongside the cases mentioned in this Privacy Policy, your personal data can only be forwarded without your prior consent in the following cases:
-
If it is necessary in order to clarify unlawful or improper use of our website and the associated functions and services or for the purpose of prosecution, your personal data will be forwarded to external advisors (e.g., attorneys), law enforcement authorities and, if necessary, to injured third parties. However, this only takes place if there are specific indications of unlawful or improper behavior. Your personal data may also be forwarded to these parties, including collection agencies, where this is required for asserting terms of use or contract terms or for asserting, enforcing or defending claims. Furthermore, we are legally obliged to provide information to certain public bodies upon request. These bodies are law enforcement authorities, authorities that pursue offenses that entail fines, and the financial authorities.
Your personal data can also be forwarded if we are subject to other claims from third parties that include access to your data. In particular, these can be claims of data subjects within the scope of the exercise of your rights in accordance with Chapter III GDPR.
-
The forwarding of this personal data is based on our legitimate interest in combating misuse, prosecuting criminal acts and asserting, exercising or defending against claims (Art. 6 para. 1(f) GDPR) or on a statutory obligation (Art. 6 para. 1(c) GDPR).
-
We rely on contractually bound third-party companies and external service providers, known as “processors” (see Art. 4 no. 8 and Art. 28 GDPR), for the provision of our website and the associated functions and services. In such cases, personal data is forwarded to these processors in order to enable further processing. The processors process personal data on our behalf and in accordance with our instructions.
In addition to the processors already named in this Privacy Policy, we deploy the following categories of processors:
-
IT service providers
-
Cloud service providers
-
Software service providers
-
Service providers for booking, managing and tracking events
-
Within the framework of administrative processes and the organization of our business, financial accounting and adherence to statutory obligations such as archiving, we disclose or forward your data to financial authorities, consultants (e.g., tax advisors or auditors) and payment service providers, postal and transport companies and similar bodies.
The forwarding of this data is based on our legitimate interest in maintaining our business activities, performing our tasks, asserting, exercising or defending against claims (Art. 6 para 1(f) GDPR) or on a statutory obligation (Art. 6 para 1(c) GDPR).
-
During the development of our business, it is possible that the structure of our company is altered through a change of legal structure or the foundation, acquisition or sale of subsidiaries, business units or components. For transactions of this nature, information is passed on together with the part of the company that is to be transferred. Each time that personal data is forwarded to third parties to the extent described above, we will ensure that this takes place in accordance with the relevant data protection laws.
The forwarding of personal data is justified by the fact that we have a legitimate interest in adapting our corporate structure to the economic and legal circumstances, Art. 6 para. 1(f) GDPR.
30. Transfers to Third Countries
We also process personal data in third countries or transfer this data to recipients in third countries. All countries outside the European Economic Area (EEA) are considered third countries. Please note that there is currently no adequacy decision by the European Commission certifying that these third countries generally have an adequate level of data protection.
When we transfer personal data to third countries, we guarantee that one of the following prerequisites is met:
-
There is an adequacy decision of the European Commission in accordance with Art. 45 GDPR, according to which there is an adequate level of data protection in a third country.
-
we have agreed standard data protection clauses approved by the European Commission pursuant to Art. 46 para. 2(c) GDPR and, to the extent necessary, have implemented supplemental measures in line with the criteria set forth by the Court of Justice of the European Union (decision on Schrems II)
-
other appropriate safeguards exist in the meaning of Art. 46 para. 1 GDPR which are appropriate for ensuring that an adequate level of data protection is in place
-
There is a derogation in accordance with Art. 49 GDPR; i.e., when you have consented to the transfer (Art. 49 para. 1(a) GDPR), the transfer is necessary for the performance of a contract with you (Art. 49 para. 1(b) GDPR) or for asserting, exercising or defending legal claims (Art. 49 para. 1(e) GDPR).
The following applies to data transfers to the Leica Camera Group:
-
Forwarding to recipients on the basis of an adequacy decision
On the basis of an adequacy decision by the European Commission (Art. 45 GDPR), we transfer your data to the following companies of the Leica Camera Group:
-
Leica Camera AG (Switzerland)
-
Leica Camera Japan Co., Ltd. (Japan)
-
Leica Camera Ltd. (United Kingdom)
-
Forwarding to recipients on the basis of standard data protection clauses as per Art. 46 para. 2(c) GDPR
Furthermore, we also transfer the aforementioned data to Leica Camera Group companies in third countries that are not currently covered by an adequacy decision of the European Commission according to which such third countries generally have an adequate level of data protection. We therefore use the European Commission’s standard data protection clauses as per Art. 46 para. 2(c) GDPR when defining the contractual relationships with Leica Camera Group companies in such third countries.
You can request additional information via the contact details listed under item 1. Here, you can also query information on the appropriate safeguards we have implemented to protect your personal data, including a copy of any concluded standard data protection clauses.
31. Erasing Your Data
Unless described otherwise in this Privacy Policy, we erase or anonymize your data as soon as it is no longer required for the purposes for which we collected or otherwise processed it in line with this Privacy Policy. We generally save your personal data on the website and the associated services for the duration of the usage or contractual relationship plus a period of 30 days during which we keep backup copies following erasure. Data processed on the basis of your consent will be deleted when you withdraw your consent, or at an earlier point in time when the data we collected is no longer required for the purpose for which it was collected.
Your data will only be stored beyond the period specified in this Privacy Policy in the following cases:
-
When we are obliged to do so for legal reasons, Art. 6 para. 1(c) GDPR. Where we are legally obliged to do so, we will store your data for the period prescribed by law. In particular, legal provisions on the storage of data can be derived from the retention periods stipulated in the German Commercial Code (HGB) or German Fiscal Code (AO). The retention period specified by these provisions is generally between six and ten years as of the end of the year during which the corresponding transaction was finalized, e.g., when we completed the processing of your query.
-
When the data is required for longer due to criminal proceedings or for asserting, exercising or defending legal claims. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR. In this case, your data is stored until the corresponding transaction is complete, plus the statutory period of limitation.
Should it be necessary to store data for legal reasons, its processing will be restricted. The data will then no longer be available for further use.
32. Your Rights
You have the rights described below in relation to the processing of your personal data. In addition to the options described above, you can assert your rights by sending a request by post or email to the addresses specified in item 1 above.
32.1. Right of access
You have the right to access the personal data concerning you that we process at any time upon request within the scope of Art. 15 GDPR as well as Section 34 of the German Federal Data Protection Act (BDSG).
32.2. Right to rectification
As stipulated in Art. 16 GDPR, you have the right to request that we rectify personal data about you where this data is inaccurate. Furthermore, you have the right to request the completion of incomplete personal data by us.
32.3. Right to erasure
In the circumstances described in Art. 17 GDPR and Sec. 35 BDSG, you have the right to request that we erase personal data concerning you.
32.4. Right to restriction of processing
You have the right to request that we restrict processing as per Art. 18 GDPR.
32.5. Right to data portability
You have the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format pursuant to Art. 20 GDPR.
32.6. Right to object
According to Art. 21 GDPR, you have the right to object to the processing of personal data concerning you based on Art. 6 para. 1(f) GDPR at any time on grounds relating to your particular situation. We will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing is for asserting, exercising or defending legal claims.
If we process your personal data for direct marketing purposes, you have the right to object to the processing of your personal data for these purposes, including any profiling, at any time. Following your objection, we will no longer process your personal data.
32.7. Right of withdrawal
You have the right to withdraw your consent at any time in accordance with Art. 7 para. 3 sentence 1 GDPR. Withdrawal of your consent does not affect the lawfulness of the processing performed on the basis of your consent prior to its withdrawal.
33. Right to Complain
You have the right to lodge a complaint with a supervisory authority of your choice if you believe that the processing of your data breaches applicable data protection law.
34. Data Processing When Exercising Your Rights
Lastly, we would like to point out that in the event that you exercise your rights as per Art. 7 para. 3 sentence 1 GDPR and Art. 15 to 22 GDPR, we will process the personal data provided by you for the purpose of implementing these rights and providing verification thereof as well as for the purpose of defending any legal positions.
In this context, we will store your data for three years as of the complete processing of your rights as a data subject. Your data will only be stored for a longer period where we still require this data for the purpose of legal defense. In this case, erasure will take place once the transaction is completed plus the statutory periods of limitation.
The legal basis for this processing for the purpose of implementation and for verifying that implementation was legally compliant is Art. 6 para. 1(c) GDPR in conjunction with Art. 7, para. 3 sentence 1 GDPR and Art. 15 to 22 GDPR as well as Sec. 34 para. 2 BDSG. If we process the personal data for purposes relating to legal defense, this also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.
You are neither contractually nor legally obliged to provide your personal data; however, we can reject your request to exercise your rights as a data subject as per Art. 12 para. 2 sentence 2 GDPR if you do not provide the data required to identify you uniquely (after being requested to do so, if applicable).
35. Links to Other Websites and Online Services
The websites and online services of the Leica Camera Group may contain links to websites or online services of other providers to which this Privacy Policy does not apply. If you click one of these links, you will automatically be directed to the linked external website or to the corresponding online service. You can recognize this, for example, by observing the input bar of your browser when the website address (URL) changes. Information on the processing of your personal data is available in the corresponding privacy policies for the respective websites and online services.
36. Changes to This Privacy Policy
The latest version of this Privacy Policy is available at any time at https://leica-camera.com/en-US/dataprotection.
Version: October 2025