Privacy Policy on Our Website

We appreciate your visit to our website and your interest in our company. We take the utmost care when handling your data. The following information provides a concise and straightforward overview of what happens to your data when you visit our website. Your data is processed in accordance with the relevant legal provisions.

Data Controller

The data controller within the meaning of the General Data Protection Regulation and other national data protection laws of the EU member states, as well as other data protection regulations, is:

Braun Animal Health Center in Lahr, LLC
1 Johann-Sebastian-Bach Street
77933 Lahr
Contact for Questions Regarding Data Protection

If you have any questions regarding data protection, please feel free to contact us at: info@tgz-lahr.de

Validity and Changes to the Privacy Policy

This Privacy Policy is valid and is dated April 23, 2025.

As we continue to develop our website or implement new technologies and features, it may become necessary to amend this Privacy Policy. We reserve the right to make such changes at any time.

Data Protection Rights and Information on the Right to Object

Your rights to access, rectification, restriction, erasure, data portability, and to file a complaint with the competent supervisory authority

Every data subject has the right of access under Article 15 of the GDPR, the right to rectification under Article 16 of the GDPR, the right to erasure under Article 17 of the GDPR, the right to restriction of processing under Article 18 of the GDPR, the right to object under Article 21 of the GDPR, and the right to data portability under Article 20 of the GDPR.

With regard to the right of access and the right to erasure, the restrictions set forth in Sections 34 and 35 of the BDSG apply.

You may revoke your consent to the processing of personal data at any time. This also applies to the revocation of consents that were granted to us prior to the General Data Protection Regulation taking effect, i.e., before May 25, 2018. Please note that the revocation takes effect only for the future. Processing that took place prior to the revocation is not affected.

In addition, you have the right to file a complaint with a competent data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG). A list of supervisory authorities (for the private sector) with their addresses can be found at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html

Information on the Right to Object Under Article 21 of the GDPR

Right to Object on a Case-by-Case Basis and Recipient of the Request

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out pursuant to Article 6(1)(f) of the GDPR (data processing based on a balancing of interests); this also applies to profiling based on this provision within the meaning of Article 4(4) of the GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

The objection may be submitted in any form, with the subject line “Objection,” and must include your name, address, or other identifying information, to the contact information provided in the legal notice.

General Information

Routine Deletion of Data

As a general rule, we store your data only for the period necessary to fulfill the purpose of storage, or to the extent required by European directives and regulations or by other legislative bodies in laws or regulations to which we are subject.

In Germany, there is a specific requirement to retain records for 6 years in accordance with Section 257(1) of the German Commercial Code (HGB) (in particular, ledgers, inventories, opening balance sheets, annual financial statements, business correspondence, and accounting documents). Pursuant to Section 147(1), (3) of the German Fiscal Code (Abgabenordnung), records must be retained for 10 years in the case of books, records, management reports, accounting documents, and documents relevant to taxation, and for 6 years in the case of commercial and business correspondence in particular.

If the purpose of storage no longer applies or if a legally required retention period expires, your personal data will be routinely deleted in accordance with legal requirements.

Please also refer to the specific details regarding the retention and deletion periods for each data processing activity in this Privacy Policy.

Data Security

We implement technical and organizational security measures to protect your personal data against misuse, loss, destruction, or unauthorized access. The security measures in place (such as encryption methods, firewalls, and antivirus protection, as well as backup and recovery procedures) reflect the current state of the art and are continuously updated.

We would like to point out, however, that there is always a certain residual risk associated with communication over the Internet, which depends on the user’s specific behavior and over which we therefore have no control.

Data Processing by External Service Providers

Our website uses third-party tools and plug-ins in the context of data processing on behalf of others. We have duly entered into data processing agreements with all data processors used, which ensure an adequate level of data protection.

For more information about the data processing carried out by the data processors we use, please refer to the relevant section on the third-party tool in this Privacy Policy.

Data Transfer to Third Countries

When you visit our website, personal data may be transferred to servers in third countries outside the European Union due to the integration of certain plug-ins and tools. Details regarding these potential data transfers, including the applicable legal bases, can be found in the section on the respective third-party tool in this Privacy Policy.

Scope (External Links)

The privacy policy provided here applies exclusively to visits to our own website.

In some sections of our website, there are links to external third-party websites. These websites are the responsibility of their respective operators. If you notice that any links on our website lead to pages whose content violates applicable law, please notify us using the email address provided in the legal notice.

We will then promptly remove these links from our website. The providers assume no liability for the timeliness, accuracy, completeness, or quality of the information provided.

Hosting

Use of an External Hosting Provider

We use an external service provider to host our website.

Provider:
WebExperten Online Marketing, LLC
50 Karmarschstraße
30159 Hanover
Germany

Purpose: To ensure the reliable availability and display of our website.

Legal basis:

Our use of a web hosting provider is based on our legitimate interest in ensuring that our website is as reliable as possible in terms of accessibility and display, in accordance with Article 6(1)(f) of the GDPR.

Objection / Opt-Out:

Information regarding your right to object under Article 21 of the GDPR can be found in the “Data Protection Rights” section above.

Data Processing:

We have entered into a data processing agreement (DPA) with our hosting provider that ensures that the personal data of our website visitors is processed only in accordance with our instructions and in compliance with the GDPR.

SSL or TLS encryption:

To protect the security of your data during transmission, we use SSL or TLS encryption via HTTPS.

Server Log Files:

When you access our website, technical data regarding your visit is automatically collected. This information (known as server log files) includes, for example: the type of web browser, the operating system used, the domain name of your Internet service provider, your IP address, and similar details.

Purpose:

To ensure that users can connect to the website without any problems, that our website functions smoothly, and to guarantee system security and stability. We also reserve the right to review server log files retroactively if there are specific indications of unlawful use.

Legal basis:

The legal basis for collecting server log files is our legitimate interest in ensuring the error-free and secure operation of our website, in accordance with Article 6(1)(f) of the GDPR.

Providing your data is voluntary or required:

The provision of server log files is not required by law or by contract. However, without the collection of log files, the proper functioning of our website cannot be guaranteed.

Retention period:

The log data is deleted as soon as it is no longer necessary for the purpose for which it was collected. For data used to provide the website, this is generally the case once the respective session has ended.

Cookies

Cookies are pieces of information that are transmitted from our web server or third-party web servers to users’ web browsers and stored there for later retrieval. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or your web browser deletes them automatically.

If you agree, third-party cookies may also be stored on your device. These enable us or you to use certain services provided by the third party (e.g., measuring reach and analyzing usage patterns on our website, etc.).

Cookies can be used for various purposes. A distinction is made between technically necessary cookies, without which the website would not function (e.g., session cookies or the cookie that stores your consent preferences), And technically non-essential cookies, which help the website operator analyze user behavior on the website or are used for marketing purposes.

Technically necessary cookies are stored based on our legitimate interest, in accordance with Article 6(1)(f) of the GDPR and Section 25(2) of the TTDSG. The website operator has a legitimate interest in using cookies to ensure the technically flawless and optimized operation of its website.

The use of cookies that are not technically necessary requires your explicit consent. In these cases, the legal basis for this processing is therefore your consent, in accordance with Art. 6(1)(a) of the GDPR and §25(1) of the TTDSG. You may revoke your consent at any time.

You have the option to configure your browser with privacy in mind. These settings allow you, for example, to accept cookies only in specific cases or to block them entirely, as well as to automatically delete all cookies set during the browsing session when you close your browser. If you disable cookies entirely, some features of the website may not function properly.

If third-party cookies are used or if cookies are used for purposes other than those technically necessary, you can find specific details about this in this Privacy Policy.

Borlabs Cookie

Provider: Borlabs – Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg, Germany.

Purpose:

Borlabs Cookie is used to obtain consent from website users to store certain cookies and use certain third-party tools, and to document this consent in compliance with data protection regulations.

Type of data processing:

The first time you visit the website, you will be asked to specify your cookie preferences in the Borlabs Consent Manager. A cookie will then be set in your browser to store your cookie preferences for your continued browsing on our site. No personal data is shared with Borlabs during this process.

Legal basis:

Obtaining the legally required consent for the use of cookies in accordance with Article 6(1)(c) of the GDPR and Section 25(2)(2) of the TTDSG.

Providing your data is voluntary or required:

Obtaining your cookie preferences is required by law.

Retention period:

The collected data will be stored until you request that we delete it, delete the Borlabs cookie yourself, or the purpose for storing the data no longer applies.

No data processing on behalf of a client:

No personal data is transmitted to Borlabs. According to its own statements, Borlabs is therefore not a data processor. For more information: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.

Privacy Policy Information for Third-Party Providers: https://de.borlabs.io/datenschutz/.

Data Processing on the Website

Contact Requests via Email and Phone

Purpose: Processing the inquiry.

Type of data processing:

Inquiries received by email or phone, including any personal data contained therein, are stored and processed for the purpose of handling the inquiry. The data will not be disclosed to third parties without your consent.

Legal basis:

Your inquiry will be processed based on our legitimate interest in pursuing our business interests in accordance with Article 6(1)(f) of the GDPR. If you contact us to request a quote, the processing is carried out for the purpose of taking steps prior to entering into a contract in accordance with Article 6(1)(b) of the GDPR.

Objection / Opt-Out:

Information regarding your right to object under Article 21 of the GDPR can be found in the “Data Protection Rights” section above.

Providing your data is voluntary or required:

Providing your data is not required by law or by contract. However, we cannot process your request without this information.

Retention period:

Your data will be deleted no later than 6 months after your request has been processed. If a contractual relationship is established, we are subject to the statutory retention periods and will delete your data after six or ten years.

Implementation of a CRM system:

The personal data contained in your inquiry may be stored in our customer relationship management system (“CRM system”). For more information about the CRM system we use, please see the “Third-Party Tools” section.

Newsletter Distribution

Purpose: Sending a newsletter for marketing purposes.

Type of data processing:

We offer a newsletter on our website. If you decide to subscribe, your data will be used exclusively to send you the newsletter you subscribed to via email and, to the extent you have provided additional consent, to analyze how you use the newsletter and any content linked within it. To receive the newsletter, you are only required to provide a valid email address. All other information requested is voluntary.

Legal basis:

Data processing is based on your consent to receive the newsletter in accordance with Article 6(1)(a) of the GDPR. This consent is obtained when you subscribe to the newsletter.

Objection / Opt-Out:

You may revoke your consent to receive the newsletter and to the storage of your data at any time. Each newsletter email contains a link for this purpose. You may also revoke your consent using the other contact options listed on the website.

Providing your data is voluntary or required:

Providing your data is voluntary and based on your consent. However, without your consent, you will not be able to receive our newsletter.

Retention period:

In this context, your data will only be processed as long as we have your consent to do so.

Use of a newsletter tool:

To ensure efficient newsletter distribution, we use a third-party newsletter tool. For more information about the newsletter tool we use, see the “Third-Party Tools” section.

Third-Party Tools

Klaviyo

Provider: Klaviyo – Klaviyo, Inc., 125 Summer Street, 6th Floor, Boston, Massachusetts, 02110, USA.

Purpose: Efficient newsletter email marketing.

Type of data processing:

We offer a newsletter that keeps you informed about the latest news. Subscription to our newsletter is, of course, voluntary. As part of your subscription, we and our service provider klaviyo—which we use to send the newsletter—process the data you provide. The only required information is your email address; all other information is voluntary. Sign-up is done via the so-called double opt-in process. klaviyo allows us to analyze our newsletter campaigns. To do this, so-called web beacons are embedded in the emails; when you open the email, these establish a connection to klaviyo’s servers and transmit technical information (e.g., time of access, IP address, browser type, and operating system). These servers may be located in the United States.

Legal basis:

Receiving our newsletter requires your consent. We will ask for your consent when you sign up for the newsletter. The legal basis is therefore Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of cookies or device fingerprinting (access to information on your device) as defined by the TDDDG. This consent may be revoked at any time.

Objection / Opt-Out:

Information regarding your right to object under Article 21 of the GDPR can be found in the section on Data Subject Rights. You can unsubscribe from our newsletter at any time. To unsubscribe, simply click the link provided in the footer of each newsletter email.

Providing your data is voluntary or required:

Providing your information is voluntary. However, without your consent, we cannot send you our newsletter.

Retention period:

Your data will continue to be processed until you revoke your consent and unsubscribe from our newsletter.

Privacy Policy Information for Third-Party Providers:

Privacy Center: https://www.klaviyo.com/legal/privacy

Information on email marketing: https://www.klaviyo.com/email-marketing

Transfer to a Third Country:
Data processing also takes place outside the EU, specifically in the United States. Safeguards are in place in the form of standard contractual clauses, in accordance with Article 46(2)(c) of the GDPR.

In addition, the company participates in the data protection agreement between the EU and the U.S., known as the “EU-U.S. Data Privacy Framework (DPF),” and is certified under this framework. By participating in the DPF, the company commits to ensuring a level of data protection comparable to that of the GDPR.

Data Processing Addendum / Data Processing on Behalf of a Client:

By accepting Klaviyo’s Terms of Service, we have also entered into a Data Processing Agreement (DPA) that ensures the personal data of our website visitors is processed only in accordance with our instructions and in compliance with the GDPR.

Google Analytics

Provider: Google – Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose:

Analysis of website visitors’ behavior by evaluating metrics such as page views, time spent on the site, operating system, etc., to optimize the website.

Type of processing:

Google Analytics helps us analyze traffic to our website. To make this work, a tracking code provided by Google Analytics and integrated via Google Tag Manager is implemented on our website. If you consent to tracking by Google Analytics, a cookie will be placed on your device that assigns a unique identifier (tracking ID) to your device. This cookie is linked to Google Analytics. It records the browsing behavior of our website visitors, and the resulting statistics may provide insight into which target groups are drawn to our website.

Legal basis:

The use of Google Analytics requires your consent. This consent was requested via our Cookie Consent Tool. The legal basis is therefore Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. You may withdraw this consent at any time.

Objection / Opt-Out:

Information regarding your right to object under Article 21 of the GDPR can be found in the section on Data Subject Rights. In the footer area of the website, you can resubmit your cookie preferences. Another way to opt out is to manually delete the website’s cookies in your browser settings or to follow the opt-out link below. Google also provides a browser plug-in for permanent opt-out: https://tools.google.com/dlpage/gaoptout?hl=de.

Providing your data is voluntary or required:

Providing your information is voluntary.

Privacy Policy Information for Third-Party Providers:

Privacy Information for Google Analytics: https://support.google.com/analytics/answer/6004245?hl=de.

Information on how Google Analytics works: https://marketingplatform.google.com/about/analytics/terms/de/.

Google’s Privacy Policy: https://policies.google.com/privacy.

Third-Country Transfer:
Data processing also takes place outside the EU, specifically in the United States. Safeguards are in place in the form of standard contractual clauses, in accordance with Article 46(2)(c) of the GDPR. The standard contractual clauses and further information regarding the GDPR and Google can be viewed here: https://privacy.google.com/businesses/controllerterms/mccs/.

In addition, the company participates in the data protection agreement between the EU and the U.S., known as the “EU-U.S. Data Privacy Framework (DPF),” and is certified under this framework. By participating in the DPF, the company commits to ensuring a level of data protection comparable to that of the GDPR.

IP anonymization enabled:

For data protection reasons, we have enabled the IP anonymization feature. This ensures that no full IP addresses of visitors within the European Economic Area (EEA) are stored or transmitted in their entirety to the United States. However, the transmission of untruncated IP addresses to servers in the United States cannot be completely ruled out and may occur in exceptional cases.

Retention period: 14 months:

We have configured Google Analytics so that stored data at the user and event levels is automatically deleted after 14 months. For more information on the tool’s data retention period, click here:
https://support.google.com/analytics/answer/7667196?hl=de.

Google Ads Data Processing Terms:

We have entered into a direct customer agreement with Google for the use of Google Analytics by accepting the “Data Processing Addendum” in the Google Analytics settings. This should be regarded as a Data Processing Addendum (DPA).

Google Maps

Provider: Google – Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose:To improve the discoverability of our website.

Type of data processing:

We have integrated the online map service Google Maps into our website. This helps visitors find their way around and makes it easier for us to be found in Google Search. If you agree to the display of Google Maps on our website, data will be transmitted to Google and at least one cookie will be set. This cookie then stores data about your user behavior, which Google uses to improve its own services and, if applicable, to display individualized, personalized ads.

Legal basis:

The display of Google Maps content requires your consent. This consent was requested via our Cookie Consent Tool. The legal basis is therefore Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG.

Objection / Opt-Out:

Information about your right to object under Article 21 of the GDPR can be found in the “Data Subject Rights” section. In the footer of the website, you can resubmit your cookie preferences. Another way to opt out is to manually delete the website’s cookies in your browser settings.

Providing your data is voluntary or required:

Providing your information is voluntary.

Retention period:

According to Google, the NID cookie set by Google Maps in your browser is valid for 6 months. We cannot guarantee this information, as changes to the validity period of Google cookies can never be ruled out.

Privacy Policy Information for Third-Party Providers:

Google’s Privacy Policy: https://policies.google.com/privacy?hl=de.

Third-Country Transfer:

Data processing also takes place outside the EU, specifically in the United States. Safeguards are in place in the form of standard contractual clauses, in accordance with Article 46(2)(c) of the GDPR. Google’s standard contractual clauses can be viewed here:
https://business.safety.google/controllerterms/.

In addition, the company participates in the data protection agreement between the EU and the U.S., known as the “EU-U.S. Data Privacy Framework (DPF),” and is certified under this framework. By participating in the DPF, the company commits to ensuring a level of data protection comparable to that of the GDPR.

As of August 2025