Section 1: Introduction and general information

Text modules Summary
Data Protection Information Simple and concise
About us and our website
We, BSH domácí spotřebiče s.r.o., se sídlem Radlická 350/107c, 15800 Praha, operate this website. Please use the contact information provided on the Company Information page to contact us.
Our contact information can be found on the Company Information page
Our guiding principles
We take protecting your information very seriously. Your data is therefore processed with great care and in strict compliance with applicable data protection law. Organisational and technical security measures have been taken to protect all of our websites against the risks present in processing personal data. Our partners who support us in the provision of this website must comply with these provisions as well.


What we log as standard
You can use all the areas of our website that are not access-protected without disclosing your identity. We log every use of our website as standard in order to prevent attacks, remedy faults and investigate security incidents. You can find more about our log data in the section "How we process your data".
We and our partners employ the latest technical safeguards to protect your data
Which permissions do we have to process your data
We respect your privacy. Consequently, we only process your data when we are permitted to do so. You will find a summary of the relevant statutory authorisations, on which we base the data processing, at the end of this information Of course you can also give us permission to process your data by opting in to the corresponding data processing on our website. In other cases, we process your data because we are permitted to do so by law. If, for example, you place an order through our website, we are permitted to process your data in order to fulfil that contract. The same applies when you make use of other services on our website that require your data to be processed. We are also permitted to process your data when we have a legitimate interest in doing so. One example of this is the log data that we collect in order to ensure that e.g. our website can be operated without defects(indcluding the technical provision of the website). In any case, we will inform you. In any case, we will inform you about the corresponding processing of your personal data and, of course, your interests will always be taken into account in any such processing. In case that you have questions to your personal data, you can find your rights regarding the processing of your personal data in the latter section of this Data Protection Information.

The permissions we make use of, and when, are outlined in the following section. You can find more detailed information on how your data is collected, processed and used on our website (i.e. the type, scope and purpose of data processing) in the same section.

What else you should know:
Users below the age of 16 should only transmit personal data to us with the consent of their parent or legal guardian. The data protection law that applies may result in different age limits in this regard.

Our website may contain links to websites, which are not provided by us. We have no influence over how your data is processed on these websites or their compliance with provisions on data protection. Please note any Data Protection Information they provide.
We only process your data when we are permitted to do so

Section 2: Data processing on the website

How we process your data (Presentation of the website, logs, cookies, tracking, etc.) In this section we describe which data we process during the use of our website including the services offered there and for which purposes this data is used.
Presentation of the website, log data
In order to display the website on your internet browser, we use various technical devices to ensure that all content (text, images, video, etc.) is always up to date. To ensure that your user experience, in particular the loading speed of the website, is improved at all times, we also use technical service providers who enable us to provide the content required for the presentation of the website (so-called "Content Delivery Networks" or CDN). These technical CDN service providers act on our behalf and are bound to our instructions by corresponding agreements. The data collected in this way will only be used to display the contents of the website in your internet browser and will be deleted immediately after intermediate storage within the scope of delivery.

For technical reasons, each time your internet browser accesses our website it automatically sends information to our web server (i.e. log data). We store some of this information in log files, such as:

• date of the access
• time of the access
• URL of the website
• version of the HTTP protocol used.
• files accessed
• volume of data transferred
• internet browser type and version
• type of the operating system
• IP address (anonymised)

The aforementioned log data does not contain personal data. We only analyse log data event-driven when required, especially in order to remedy faults in the operation of our website or clarify security incidents. We store this log data indefinitely.

In addition, it may be necessary for us to collect the full IP address of the device as well as log data in order to remedy faults or preserve evidence relating to security incidents. We delete this data once the fault has been remedied or the security incident has been clarified in full, or if the original purpose of the processing no longer exists due to other factors. In the event of a security incident, we will transmit log data to the investigating authorities on a case-by-case basis, to the extent permitted and necessary.

We store such log data separately from other data collected that relates to the use of our website.
The data specified here are necessary to provide the website including the services offered there and to enable safe use ot the website and its services.
Registering on our website
You can register on our website to use different services. We collect and process the following details as part of the registration process:

Required details:
• Title
• First and last name
• Full postal address
• Telephone number
• E-mail address
• Password

Optional details:
• Mobile phone number
• Date of birth
• What made you find us
• Consent to receiving advertising and possibility to revoke.

We store registered users' data until the user deletes their account. Registered users can delete their accounts at any time via the settings of their user account. The user account also allows users to change or delete specific information provided at the time of registration at any time.


Comfort registration (Social Sign-On Option)
For the registration on our website you can also use the comfort registration (or Social Sign-On Option). This is available for various social networks. To register, you will be redirected to the website of the relevant social network, where you can register with your access data. This links your Social Network user account to the user account on our website. When linking, we automatically receive the data required for registration from your social network. You can find out which data is transferred from your social network to us from the data protection information and terms of use of the relevant social network. We store and process only your name and email address from this data for the provision of our services.

By linking the two user accounts, you no longer have to log-in additionally on our website if you have already registered in your social network. To provide this, a corresponding cookie is set in the Internet browser and used at your next visit of our website for the purpose of signing in to your account.

We use the data stored in the context of the comfort registration exclusively for the provision of the services of our website, in particular the Social Sign-On option. We store the data of registered users until the user account is deleted. Registered user can delete their accounts at any time via the settings of the user account. The user account also provides the option of changing or deleting certain data entered during registration at any time.
Registered users can access additional services and offers
Purchasing on our website
You can also use our website to access services requiring payment (e.g. orders in the accessories store, book a repair). We collect and process the following order information when services are ordered:

Required information:
• Title
• First and last name
• Full postal address
• Telephone number
• E-mail address
• Billing information
(depending on the payment type allowed by us and chosen by the user)

Optional information:
• Landline phone number
• Mobile phone number

As a registered user, you also benefit from the fact that the time and scope of all purchases (display of the history of purchases made in the user account) is displayed for you in your customer account, so that you can track your orders directly there.
We use state-of-the-art encryption techniques (e.g. SSL) via HTTPS to guarantee the security of your data during transmission.
When you place an order, we use your information for the sole purpose of processing that order and to display the history of purchases. We store order information at least until the expiry of the statutory retention periods. We store data provided when registering until the user deletes their account.
Your data is also secured by state-of-the-art encryption techniques when you make a purchase
Contacting us
If you contact us outside of a concrete contractual relationship (e.g. for an order) or a registration, we provide various, also purely technical contact possibilities via our websites, including the possibility to contact us e.g. via (automated) chat.

In order to be able to process your specific request when making such contact, we may ask you to provide personal data. This includes, for example, your name and email address and other information such as the subject of your request and your message. Optional postal address and/or telephone number can be given. We collect the information requested in order to be able to deal with your request in an appropriate way.

The personal data transmitted to us in this way are used exclusively for the purpose for which you provide them to us when contacting us - in particular the processing of your request. The data will not be used for other purposes or passed on to third parties without your express consent. Excluded from this are - insofar as it is necessary to fulfil your request - the persons and companies (e.g. local service company) involved in carrying out the communication and answering the request. If there are no legal storage obligations, your personal data will be deleted after the request has been processed.
If you contact us, we will only use your data to process your request.
Book a repair (online and via phone)
On our website or via phone you can arrange a repair appointment with a service technician directly. For this we generally need information about your household appliance, a problem description, your address and other contact details (see also section “Purchasing on our website” above). The specific data we collect for this purpose is determined by the booking process. Please be also aware of the notes regarding the costs of such appointment, which is stated on the relevant subpage, where you can arrange the repair appointment.
As part of the booking process, we check the correct spelling of your address entry via the Google Maps database to avoid any mis-entries or other mistakes. We do not transfer your personal data in this context.
We store your information as long as necessary for the execution of the contract and for fulfilling of legal retention periods.
Google Maps is a service provided by Google LLC (formerly Google Inc.), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA („Google“). You can find details on how personal data is processed when Google Maps is used via the following link: https://policies.google.com/privacy.
You can arrange a repair appointment with us via the website; the technology we use makes it easier for you to enter your address.
Using our website as a business partner
On our website we provide our business partners with different services and information to facilitate commercial relationships. In addition to product information and marketing materials, our partners receive access to a comprehensive range of collaboration and/or order processing services through our website.

Access to the specific areas of content on our website is restricted to registered business partners. As a general rule, registration for the Business Partner Portal takes place via our partner website www.tradeplace.com. In some countries, it is possible to register on our general website directly. Access to the Busniess Partner content on our website requires an existing commercial relationship with us.

When using our website as a business partner, we only process the partner master data, including the history of previous commercial relationships as well as personal data in content that you make available to us via the services (e.g. via Teamspace).

If you take advantage of our home delivery option, we also process the delivery address of the respective end customer (first and last name, full postal address, telephone number). We do not delete business partner data and transactional data during an ongoing commercial relationship.
It goes without saying that we will provide you with information about the data we hold about you on request. We will also be happy to correct inaccurate information or delete information we hold about you on request, provided that said deletion is not prohibited under the terms of our legal obligations to retain certain information. To request this, please use the contact information provided at the end of this Data Protection Information.
Content and services on this website support our commercial relationships with our business partners
Newsletter
Our website provides the option of subscribing to our newsletter. We use a double opt-in process to verify whether the owner of an e-mail address has actually registered to receive the newsletter. The newsletter is only successfully subscribed to if the owner of the e-mail address has expressly confirmed the activation of the newsletter by clicking on the link in the confirmation e-mail. We log the completion of the individual stages of the double opt-in process for evidence purposes.
As part of our newsletter campaigns, we use analysis tools to tailor our newsletter to your needs, for advertising purposes and for market research. For this purpose, we collect and process data about your use of our email newsletter. When you open an email newsletter from us, a file contained in the email (so-called web beacon) connects to our servers. This enables us to determine whether an email newsletter has been opened and, if so, which content has been clicked. In addition, we collect technical information about your end device with which the contents of the email newsletter are retrieved (e.g. time of retrieval, browser type and operating system). We use this data exclusively for statistical analysis of our newsletter campaigns.
If you subscribe to receive our newsletter, and therefore consent to it being sent to you, your details are solely used in order to send you the newsletter and analyse your use of the email newsletter. You can withdraw this consent at any time. The relevant link is included in each copy of our newsletter. We will make a note of the fact that you have unsubscribed from the newsletter in our database.

Participation in raffles/contests
When you register for a raffle/contest, we store and use the information you provide in order to run the raffle/contest and complete any follow-ups. The data we collect for this purpose depends on the registration form on the event page in question.
Your information is deleted once it is no longer required to run the raffle/contest or complete any follow-ups.

Participation in surveys/reviews
We conduct surveys on our website. In general, these surveys are carried out anonymously. If we as an exception do collect your data in the course of a survey, the information you provide will be stored and used by us for the purpose of conducting and following up the survey. Which data we collect for this purpose results from the survey itself. Your data will be deleted as soon as they are no longer required for the survey and follow-up.

You can also create reviews for some products on our website. The data we collect for this purpose can be found on the form provided for this purpose. In this case, special regulations apply, which will be announced to you separately in the course of the submission of the evaluation. For the management of reviews we use a service provider.
We use a double opt-in process to protect your e-mail address against misuse by third parties

Participation in events
When you register for an event, we store and use the information you provide in order to run the event and complete any follow-ups. The data we collect for this purpose depends on the registration form on the event page in question. Your information is deleted once it is no longer required to run the event or complete any follow-ups.
Some events require to pay the participation fee directly or are completely or partially supervised and carried out by our partners. In such a case you may be redirected to the website of the respective partner. In this case, the relevant payment details (last name, first name, postal address, number of participants, means of payment) are transmitted to our partner to carry out the event/payment process, provided you have already provided it.
Your details stay in good hands if you participate in one of our exciting events
Our Social Media Pages
The protection of your privacy when processing personal data is important to us. We process personal data transmitted to us, which is collected during your visit to our respective social media page (e.g. Facebook Fanpage, Instagram/Pinterest Page), confidentially and only in accordance with the statutory provisions.
Responsible for the processing of your data via our social media site is the respective operator of the social media site (see examples below) together with us. As far as the processing of these data takes place within our area of responsibility, we are available to you in all questions concerning data protection and the exercise of your rights in accordance with the information in this data protection information.
Data processing by the Social Media Service
The social media service processes your personal data as soon as you use our respective social media site. Processing is linked, for example, to the following usage processes:

• View a page or post or video from a page
• Subscribe or unsubscribe to a page
• Mark a page or post with "I like" or "I don't like anymore" or similar functions
• Recommend a page in a post or comment
• Comment on, share or respond to a page post (including the type of response)
• Hide a page contribution or report as spam
• From another site, click on the social media provider or from a Web page outside the social media provider on a link that leads to the page.
• Move the mouse over the name or profile picture of a page to see a preview of the page contents.
• Use functions of the social media provider, such as the website, phone number, "plan route" button or any other button on a page.
• The information whether the login is made via a computer or a mobile device.

You can find out which personal data is collected by the social media provider, how it is processed and which data protection rights you have vis-à-vis the social media provider in the following data protection guidelines of the social media provider. We have no influence on the data processing by the social media provider.
Data processing by us
On the website provided by us via the social media provider, the social media provider grants us access to the following data categories:

• The social media provider grants us access to statistical analyses that provide information about the use of our social media website. The analyses visible to us do not allow us to individually analyze the usage behavior of individuals. We can only view aggregated data (such as number of hits, likes, followers, region of origin, age group, gender, etc.) that tells us about our audience and the use of our social media site. The data of the respective user on which the analyses are based are not transmitted to us.
• We can set the target group to be reached for the social media website or for individual published articles. The setting is based on general parameters (e.g. age group, language, region, interests) that can be used to align our content with specific groups. It is not possible for us to address or identify individual persons on the basis of the data provided to us by the social media provider.
• If you contact us directly via the social media provider or interact with us in any other way and consciously transmit personal data (e.g. direct networking with our social media website), we store and process this personal data for the purposes for which you transmitted it to us.
• We process this data exclusively for the purpose of making content on our social media website known to the target group and to better understand and optimise the use of our social media website.

In addition, we cannot influence the data processing (for the provision of this data upstream) by the social media provider.
Which personal data is collected from the respective social media provider in detail, how these are processed and which data protection rights you have vis-à-vis the respective social media provider, please refer to the following data protection guidelines of the respective social media provider:

a) Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA; http://www.facebook.com/policy.php;
b) Twitter, Inc., 1355 Market St, Suite 900, San Francisco, California 94103, USA; https://twitter.com/privacy.
c) Instagram, provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, https://help.instagram.com/519522125107875
d) Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland, https://policy.pinterest.com/en/privacy-policy
e) Snapchat for countries of the European Union (EU), the European Economic Area (EEA) and Switzerland: SNAP GROUP LIMITED 7-11 Lexington Street, London, United Kingdom, W1F 9AF and for all other countries: SNAP Inc, 2772 Donald Douglas, Loop North Santa Monica, CA 90405 United States, USA.
f) LinkedIn for countries of the European Union (EU), the European Economic Area (EEA) and Switzerland: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland and for all other countries: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
g) Xing SE, Dammtorstrasse 30, 20354 Hamburg, Germany, https://privacy.xing.com/en/privacy-policy
Privacy information when you use one of our social media sites.
Cookies, Analytics, Marketing and Tracking
1. Analytics
Analytics refers to the process of collecting, processing, and analysing data to gain insights and make decisions. For us, it's like examining patterns and trends to better understand how our products and services are used by you. This insight allow us to make our products and services more user-friendly. It also enables us to identify areas for improvement and innovation in our products and services. Our websites integrate with analytics platforms (e.g., Adobe Analytics). These platforms provide JavaScript code that is added to the website. This code interacts with cookies or similar technologies to collect data when users interact with our website. As users navigate the website, the analytics code collects data from the cookies/pixels. This data we collect includes information on page views, clicks, time spent on pages, and other relevant metrics.
Analytics platforms aggregate the collected data, providing us with insights into user behaviour and website performance. This aggregated data is used for understanding audience demographics, popular content, and areas that may need improvement.


2. Marketing and Tracking (including Re-Marketing)
We may collect and use your personal data to send you relevant marketing communications. These communications could include product updates, promotional offers, and newsletters. You can easily manage your communication preferences and opt out if desired.
We also carry out digital marketing activities including retargeting. Retargeting, also known as remarketing, means showing targeting ads to users who have previously interacted with Our website or digital content but did not complete a desired action, such as making a purchase.
When a user visits our website and takes specific actions (e.g., views a product, adds an item to the cart), a tracking pixel or cookie is placed on their device. This allows us to show targeted ads to these users as they browse other websites or social media platforms, encouraging them to return to our website.
Please see Section XII for more information on the providers including information about the specific usage and additional information on provider-specific data protection aspects.


3. Cookies and similar Technologies
When you visit our website cookies or a so-called pixel-code/web beacon as well as similar technologies can be used by us. These technologies will allow us to interact with your browsing device as follows:
• Cookies are small text files that are stored in a special memory area of your browser which enable us to identify you when you revisit our website.
• Web beacons are tiny graphic files that contain a unique identifier that allows us to recognize user activity such as how often you have visited our website.
• We may also use direct server side solutions and similar technologies to measure the usage of our websites as well as the reach of our advertisements.
• Cookies and similar technology may be used for a variety of reasons such as making the website work or show you personalized content and advertisement.

We use the following types of cookies on our website
• Functional Cookies and Technologies (necessary to make the website available, secure and work properly)
• Analytics Cookies/Similar Technologies
• Marketing Cookies/Similar Technologies
• Third Party Cookies/Similar Technologies

For more information on specific cookies and similar technology we use on a specific website please see the cookie banner/notice. Functional Cookies will be used by us even you decline other types of cookies, as these are necessary for the use of the websites. All other Cookies as well as similar technologies will only be used, if you accept the relevant category of cookie within the cookie banner/notice and you can modify this choice at any time.


4. Profiling (based on Permission)
We offer you the option to enable profiling, which allows us to personalize your experience and provide you with tailored content. We want to ensure transparency and give you control over how your personal data is used. Profiling involves the automated processing of your personal data to analyse and predict your characteristics, preferences, behaviour, or interests.
By enabling profiling, we can better understand your needs and deliver a more customized experience based on such information and to enhance your experience on our website. This includes personalizing recommendations, delivering targeted advertisements, and improving our services based on your preferences.
To create your profile, we may collect and analyse various types of data, such as your browsing history, search queries, location information, and demographic details. You can find a comprehensive list of the data categories we utilize if you agreed in profiling in Section XIV, located at the end of this document. Rest assured that we handle your data with utmost care and in accordance with applicable data protection laws.
Our profiling activities are based on your consent, which you can freely give or withdraw at any time. We also rely on our legitimate interests in providing you with a tailored and relevant experience. You have the right to control your data and profiling preferences. You can choose to enable or disable profiling through your account settings or privacy preferences. Additionally, you can exercise your data protection rights, including the right to access, rectify, or delete your personal data at any time.
We may share your data with trusted third parties for profiling purposes. However, we only do so with your explicit consent or when necessary to provide our services. We ensure that appropriate safeguards are in place to protect your data when shared with these parties.
Please see Section XII for more information on the providers including information about the specific usage and additional information on provider-specific data protection aspects.


5. Cookie Handling, Tools and their providers
Once you have chosen which cookies you accept/decline, you can always revisit the privacy settings in the cookie banner/notice by clicking on the check mark located on the bottom left-hand side of our website and accommodate the changes. You also can delete the cookies set manually via the respective setting in your browser.
You can find a comprehensive list of the marketing and analytics tools we utilize in Section XII, located at the end of this document. This section not only provides the names of the tools but also describes the type of data processing conducted by each respective tool or provider.


6. Legal Basis for data handling
All processing described above, in particular the setting of pixels and cookies for reading out information on the end device used, will only be carried out if you have given us your consent to do so. You can revoke your consent at any time with effect for the future by as described in “Cookie Handling” above. Alternatively, you can use the deactivation page for EU consumers at: http://www.aboutads.info/choices or http://www.youronlinechoices.eu/

We base the above data processing operations in GDPR regions on:
a) Your consent pursuant to Art. 6 para. 1 lit. a) GDPR:
• Cookies for recording usage behaviour
• Web Analytics & Marketing via Cookies and/or similar technologies
• Profiling

b) a legal permit in accordance with Art. 6 para. 1 lit. b) GDPR:
• Registration on our website
• Comfort registration (Social Sign-On Option)

c) a legal permit in accordance with Art. 6 para. 1 lit. f) GDPR:
• Technical cookies, which are necessary for the provision of the website
• Interactive Digital Assistants
• Technical providing for the presentation of the website (e.g. Content Delivery Networks, security functions)
• Additional website functions (e.g. product videos)
• log data
• Session cookies and persistent cookies for convenience features


List of the Third party providers and their use
• Facebook and Instagram including WhatsApp and Facebook messenger is provided by the following entities:
o for countries in the European region: Meta Platforms Ireland Limited, Merrion Road Dublin 4 D04 X2K5, Ireland
o for other countries: Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025,USA;
http://www.facebook.com/policy.php;
https://help.instagram.com/519522125107875

Meta is providing the following services:
o as social media provider
o providing chat functionality via WhatsApp and Facebook Messenger
o Facebook Pixels and Custom Audiences, where For Facebook Pixels and Custom Audiences, Facebook processes your data under a joint responsibility with us, in accordance with the contract we concluded with Facebook on our joint responsibility. We do not have access to your individual tracking data processed by Facebook as Facebook provides us with aggregated data only. We may share this aggregated data with third parties, e.g. cooperation partner for marketing purposes.The essence of this contract is available here:
https://www.facebook.com/legal/controller_addendum.
o You can find information about Facebook ads and Facebook pixels with the following links:
https://www.facebook.com/policy and https://www.facebook.com/business/help/651294705016616
o To permanently prevent the collection of usage data, please use the following link:
https://www.facebook.com/policies/cookies/
As a registered Facebook user, you can also set what types of ads are displayed to you within Facebook, use the following link:
https://www.facebook.com/settings/?tab=ads

• X Corp, formerly Twitter, as social media provider is provided by the following entities:
o for countries of the European Union, EFTA States, or the United Kingdom: Twitter International Unlimited Company, One Cumberland Place, Fenian Street Dublin 2, D02 AX07 IRELAND and
o for all other countries: X Corp.
1355 Market St, Suite 900, San Francisco, California 94103, USA; https://twitter.com/privacy.

• Pinterest as an online marketing tool is provided as follows:
Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland, https://policy.pinterest.com/en/privacy-policy. The Pinterest Tag help us analyse use of our website and to track the effectiveness of our advertising campaigns (Conversion Tracking). We also use the Pinterest Tag to create audiences and show you personalized advertising based on your interest in our products (retargeting). For this purpose, Pinterest Europe processes data, which the service collects from pixels, cookies and similar technologies on our website.
If you have a Pinterest account and have allowed Pinterest Europe to do so in your account’s privacy settings, Pinterest Europe may also link the information collected about your visit to us with your Pinterest account and use it for showing you the targeted advertisements. You may see and change the privacy settings, especially for personalisation, in your Pinterest account at any time. For more information please see https://help.pinterest.com/en/article/edit-personalization-settings.
If you have not agreed to the use of the Pinterest Tag, Pinterest Europe will only show you general Pinterest Ads which have not been created based on the data collected about you.
This collection and transmission of activity data within the scope of the Pinterest Tag is carried out by us and Pinterest Europe as joint controllers within the meaning of Article 26 GDPR. We have an agreement with Pinterest Europe concerning this processing as joint controllers. This agreement defines the division between us and Pinterest Europe of the duties under data protection law. In this agreement, we and Pinterest Europe have agreed, among other things, that we are responsible for providing you pursuant to Articles 13 and 14 GDPR with all information about our joint processing of your personal data and that Pinterest Europe is responsible for facilitating the exercise of rights of data subjects pursuant to Articles 15 to 20 GDPR. You may see more information on this agreement below.
Responsibilities of us and Pinterest Europe under the Joint Controllership Agreement
Obligation under GDPR Pinterest Europe WE
Article 6: Requirement of legal basis for Joint Processing [x] (regarding Pinterest Europe’s processing) [X] (regarding our own processing )
Articles 13,14: Providing information on Joint Processing of Personal Data [X]
Article 26(2): Making available the essence of this JCA [X]
Articles 15-20: Rights of the Data Subject with regard to the Personal Data stored by Pinterest Europe after the Joint Processing [X]
Article 21: Right to object insofar as the Joint Processing is based on Article 6(1)(f) [X]
(regarding Pinterest Europe’s processing)
[X] (regarding our own processing)
Article 32: Security of the Joint Processing [X] (regarding the security of the Ad Data Features) [X] (regarding the correct technical implementation and configuration of BSH’s use of the Ad Data Feature)
Articles 33, 34: Personal Data Breaches concerning the Joint Processing [X] (insofar as a Personal Data Breach concerns Pinterest Europe’s obligations under the Joint Controller Addendum) [X] (insofar as a Personal Data Breach concerns BSH’s obligations under the Joint Controller Addendum)
Pinterest Europe is responsible as sole controller for the processing of activity data subsequent to their transmission. You can find more information on how Pinterest Europe processes Personal Data, including the legal basis Pinterest Europe relies on and the ways to exercise Data Subject rights against Pinterest Europe, in Pinterest Europe’s Privacy Policy at
o https://policy.pinterest.com/privacy-policy#section-residents-of-the-eea
o In addition, you can find out more about the Pinterest Tag at
https://help.pinterest.com/en/business/article/pinterest-tag-parameters-and-cookies.

• Adobe is providing several services which are used or can be used via our websites. These services are provided by Adobe Systems Software Ireland Ltd., 4-6 Riverwalk, Citywest Business Park, Dublin 24, Ireland ("Adobe”). You can find additional information about how Adobe Analytics cookies work and the opt-out option via the following link: http://www.adobe.com/privacy/opt-out.html.
We use the following services:

• for web analytics we use Adobe Audience Manager und Adobe Tracking being part of the Adobe Marketing Cloud: The information relating to your use of our website is transferred to Adobe servers, analyzed and solely returned to us as cumulative data. This data allows us to identify trends in how the website is generally used. We do not conflate the resultant usage profiles with your name or any other details that could disclose your identity, such as your e-mail address. The usage data is stored by the service used for a maximum duration of 37 months from the date on which it was collected.

• for A/B testing we use Adobe Test & Target: Adobe Test & Target works on the basis of A/B tests. This means that the person using our website is shown a different version of the website from the original (e.g. with altered design and content). Comparing both versions provides us with information about which version of our website is preferred by users. When Adobe Test & Target is used, the only information relating to you that is processed cannot be used to identify you. IP anonymisation is also activated, meaning that your IP address is shortened before Adobe Test & Target carries out any further processing. We do not conflate the usage profiles resulting from this with your name or any other details that could disclose your identity, such as your e-mail address. The usage data is stored by the service used for a maximum duration of 37 months from the date on which it was collected. You can also use the following link if you wish to prevent your usage data being collected: http://bsh.tt.omtrdc.net/optout.

• Google is providing several services which are used or can be used via our websites. These services are provided via several brands or tools, which we describe in more detail below. In general these services are provided by the following entities:
o for countries of the European Union (EU), the European Economic Area (EEA) and Switzerland: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
o for other countries including UK: Google LLC (formerly Google Inc.), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
You can find general information on how personal data is processed when Google tools are used via the following link https://policies.google.com/privacy. Opt-out: To permanently prevent the collection of usage data, Google offers a plugin for various Internet browsers: http://www.google.com/settings/ads/plugin. To disable only interest-based ads, you can block the use of third party cookies or cookies from the "www.googleadservices.com" domain or disable interest-based ads using this link at https://support.google.com/ads/answer/2662922?hl=en-GB.
We are using the following Google tools in the following specific way:

• YouTube for the presentation of videos on our websites. If you declined the use of cookies via the cookie banner, you may be ask to consent separately for consent before the display of such videos on our website. Only if you consented, any possible data transfer will start.

• YouTube as social media provider, where we present videos on different YouTube Channels. Please see the privacy information stated above when using such channels.

• Google reCAPTCHA: In order to protect your website interactions, such as logins or registrations, it performs risk assessments on website users, we use Google reCAPTCHA for these purposes. These assessments use cookies and collect personal information. However, Google may only set cookies and use personal information with users' prior consent, which can be given via the Cookie Layer.

• Google Maps as service for location and mapping services, whereby only such data is used, you provide in using that service. A proximate location is used to show e.g. partners near your location or verify the postal code for service requests.

• Google GA4 Technology is used by us (only if you gave your cookie consent), to implement server side tracking as similar technology to cookies. In using that tool, we do not send usage data or similar data to Google, but use the tool to send information of the website use to our servers. This data is processed by us and does not allow any individual identification of you or your device, you use the website/service from.

• Google Tag Manager (GTM) is a tool used by us enabling us to manage and deploy marketing tags on websites without code modification. Tags include analytics and tracking codes, providing insights into website performance and user behaviour. While GTM itself doesn't set cookies, tags deployed through it may use cookies for tracking.

• Google Ads & Remarketing
We use online marketing tools from Google on our own responsibility. The cookies used in this service generally lose their validity after 30 days and are not intended to identify you personally. Google merely provides us with statistical evaluations. Google processes your information in accordance with Google's data usage policy.
Opt-out: To permanently prevent the collection of usage data, Google offers a plugin for various Internet browsers: http://www.google.com/settings/ads/plugin.
To disable interest-based ads, you can block the use of third party cookies or cookies from the "www.googleadservices.com" domain or disable interest-based ads using this link at
https://adssettings.google.com/authenticated?hl=en_GB
Interest ads can also be deactivated via the link http://www.aboutads.info/choices if the provider has joined the self-regulatory campaign "About Ads".

• Google Ad Server
We use online marketing tool (formerly DoubleClick) of Google. The usage data will be deleted after 540 days from the time of collection. For more information about DoubleClick, please visit
https://support.google.com/admanager/answer/6022000?hl=en,
We use online marketing tools from Google on our own responsibility. To this end, we have agreed with Google in a data protection agreement that our customers' data may only be processed on the basis of our instructions, may not be passed on to third parties and must be sufficiently technically protected.


• Medallia Experience Orchestration is an online (re-)marketing platform provided by Medallia, Inc., 6220 Stoneridge Mall Rd, Floor 2, Pleasanton, CA 9458, USA. We use this service for our website as a marketing tool to display personalized information to you on our websites, as well as on websites of other providers, about our products that may have interested you while using our website. Medallia provides us with statistical analysis for this purpose. This service also provides us with cross-device and cross-context usage profiles (data) to help us learn more about our website users. We do not use this data to identify you personally.
Medallia processes this data on our behalf within the framework of a data protection agreement, in which we have agreed that our customers' data may only be processed on our instructions, may not be passed on to third parties and must be sufficiently technically protected. For detailed information on the cookies we use and the purposes for which we use them, refer to our cookie consent preference centre. These preferences can be updated at any time and you can also deactivate tracking in making a new choice by modifying your choice there. Most internet browsers are configured to automatically accept cookies. These settings can be modified to selectively accept, block cookies, or alert you when cookies are being sent to your device. You may also refer to your browser’s documentation or visit www.allaboutcookies.org for ways to manage cookies. Additional information on Medallia and its data handling can be found with the following link: https://www.medallia.com/privacy-policy/.


• ChannelSight for conversion tracking purposes the provider of the service is ChannelSight Ltd., Suite 3, Anglesea House, Carysfort Ave., Blackrock, Co. Dublin, Ireland (www.channelsight.com). You can purchase a large number of our products directly via the corresponding hyperlinks (e.g. a button “Buy Online”) to cooperating dealers' online stores (e.g. the function "Visit retailer shop"). If you follow the respective hyperlink to the chosen product page in the dealer's online store, we use JavaScript code and cookies (i.e. conversion tracking) to log that you clicked on the hyperlink and whether or not you purchase the product in the dealer's online store. The usage data collected in this way is used to measure the attractiveness of the "Visit retailer shop" function and, where applicable, for commission settlement purposes with the dealer's online store (i.e. affiliate marketing). Sometimes dealers' online stores pay us a commission when we successfully redirect prospective buyers and customers to them. The information relating to your use of the "Go to dealer's website" function is transmitted to ChannelSight servers, analysed and returned to us, to allow us to evaluate trends relating to use of the "Visit retailers shop" function. Please note that the aforementioned tracking is directly connected to the "Visit retailer shop" function, where we will you inform directly of the intended use of data. By using the "Visit retailer shop" button on our website, you give your consent for the inter-website recording of your website use and the analysis by us for the indicated purposes, and in particular to the associated data collection by ChannelSight and the retailer, as well as the transfer of data from ChannelSight and the retailer to us. The usage data is deleted once it is no longer required for commission settlement and analysis.
Opt-out: To prevent the collection of usage data via Channelsight, please use the Channelsight opt-out Web site with the following link:
https://www.channelsight.com/privacypolicy/


• We use Mouseflow to improve our website and the services it offers. Mouseflow is provided by Mouseflow ApS, Flaesketorvet 68, 1711 Copenhagen, Denmark. On our websites we record the mouse movements and clicks of randomly selected users of our website, whereas your IP address is anonymized. We do not conflate the resultant usage profiles with your name or any other details that could disclose your identity, such as your e-mail address.. The usage data is deleted three months after the date on which it is collected. Opt-out: Please use Mouseflow's opt-out website via the following link if you wish to prevent this usage data being collected: https://mouseflow.com/opt-out/
Social networks and similar networks and services
Content from our website can be shared on social networks using integrated social media buttons. All social media buttons that facilitate the sharing of content are integrated using simple hyperlinks rather than social plugins developed by social network providers. This ensures that your details are not automatically transmitted to social network servers as soon as you access our website. In addition, when you share content from our website we only transmit the information to the social network that is required to share the relevant content (e.g. the link to the content you want to share). We do not transfer personal data in this context.
At the same time, simple links to our websites on social networks can be found as well. If you follow a link from our website to a social network, or if you log in to your social network in order to share content from our website, your data is processed by the provider of the social network in question.
If you are registered and signed in in other networks or services that require registration while using our website or individual functions (e.g. Vimeo, YouTube), the respective network/service may collect information about your use or adopt settings, such as videos played/playing status. However, this data is collected solely by the respective network/service in its own data protection responsibility and processed by the respective provider.
For information about the purpose and scope of data collection, further processing and use by the respective network provider, as well as your associated rights and settings options for protecting your privacy, please refer to the Data Protection Information made available at the website of the respective provider.

Dealer search using Google Maps
One feature available to you as a user of our website is a map showing cooperating dealers in your area. We use Google Maps to display this map. Google Maps is a service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. You can find details on how personal data is processed when Google Maps is used via the following link: https://policies.google.com/privacy

If you wish to display cooperating dealers in your area, you will need to specify a location, either by entering your location manually or having it determined by the geolocation function on your internet browser automatically. Personal data is not processed if you enter this information manually, provided you do not specify your home address. Automatic location identification using the geolocation function on an internet browser requires your IP address to be processed. We are permitted to process your information in this context with your consent, which your internet browser requests when you access the map. We do not store your IP address in this context.
Share content from our website on social networks without compromising your data
Cases where we transmit your data
We work together with a number of service providers to implement and operate our website. We have chosen these service providers carefully and concluded a data protection agreement with each individual service provider to keep your information safe.

The service providers we use to implement and operate our website are:

• Service provider for hosting services including associated technical services (e.g. performance control and measurement, content delivery networks)
• Service provider for the provision of additional functionalities for our website (e.g. product videos, flip catalogue Issu)
• Service provider for programming services
• Service provider for sales and marketing services
• Service provider for hotline services

We only transmit your data to other recipients where necessary to fulfil a contract with you, where we or the recipient has a legitimate interest in the disclosure of your data, or where you have given your consent to that transmission. In such cases, your data will be processed in accordance with the data protection regulations of the recipient of your data concerned. These recipients include service providers and other companies within our corporate group. Furthermore, data may be transmitted to other recipients in the event that we are obliged to do so due to legal provisions or enforceable administrative or court orders.
Other recipients of your data are:

• Forwarding agents for delivering/collecting products
• Payment processing service providers
• Receivables management service providers
All service providers who process your data in conjunction with our website are carefully selected and obliged to meet data protection standards
Your point of contact for all questions relating to data protection
If you have any questions relating to data protection or exercising your rights, you can use the following contact information to get in touch with our data protection officer directly:

BSH Hausgeräte GmbH
Data Protection Officer
Carl-Wery-Str. 34
81739 Munich, Germany

Data-Protection-CZ@bshg.com

Changes to this Data Protection Information
This Data Protection Information reflects the current state of data processing on our website. In the event of changes to data processing, this Data Protection Information will be updated accordingly. We always provide the latest version of this Data Protection Information on our website so that you can find out about the scope of data processing on our website.
Please do not hesitate to contact our data protection officer if you have questions relating to data protection

Section 3: User rights

Supplementary information according to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of individuals with regard to the processing of personal data, on the free movement of such data and repealing Directive 95/46/EC (GDPR)
Legal basis for data processing
We base the above data processing operations on

• a legal permit in accordance with Art. 6 para. 1 lit. b of Regulation (EU) 2016/679:
– Registration on our website
– Shopping on our website
– Comfort registration (Social Sign-On Option)
– Arrange an online repair appointment
– Participation in raffles/contests
– Participation in surveys, reviews
– Participation in events
– Use our website as a business partner

• a legal permit in accordance with Art. 6 para. 1 lit. f of Regulation (EU) 2016/679:
– Technical providing for the presentation of the website (e.g. Content Delivery Networks)
– Additional website functions (e.g. product videos, Issu flip catalogue)
– log data
– Contact us
– Arrange an online repair appointment (data processing for address verification)
– Use our website as Business Partner (Home-Delivery Option)
– Session cookies and persistent cookies for convenience features
– Session-based Statistics

• Your consent pursuant to Article 6(1)(a) of Regulation (EU) 2016/679:
– Dealer search with Google Maps
– Newsletter
– Persistent cookies for recording usage behavior
– Web Analysis & Marketing
- Adobe Analytics
- Adobe Test & Target
- Channel Sight
- mouse flow
- DoubleClick
- Facebook Pixels and Custom Audiences
- Google Ads & Remarketing
- Oracle BlueKai
- Nielsen Marketing Cloud
Your rights
If you have any questions about your personal data, you will find a description of your rights below:

Unsubscribe from receiving promotional communications
If you wish to revoke your consent to receive electronic advertising, you can use the unsubscribe link located in the footer of the relevant e-mail or send an e-mail to mdo-marketing@bshg.com with the subject "Unsubscribe to receive electronic advertising", stating your first and last name and e-mail address.

If you wish to communicate your objection to the receipt of electronic advertising and/or postal advertising from the FOR US SHOP, please write an e-mail to aktion@fuer-uns-shop.de with the subject "Unsubscribe FOR US" or a letter with the subject "Unsubscribe FOR US" to Agentur Günther Huinink, Gebsattelstr. 11, 81541 München, stating your first and last name and your postal address.

Exercise of your data protection rights
Please use the following contact channels for your requests:
I. Consumers: Please use the Consumer Data Request Webform on https://datarequest.bsh-group.com/
II. Dealer/supplier/service providers and its employees: Please contact our local sales or procurement department
III. Our employees: Please contact the local HR department

• Your right to information about your data: We will provide you with information about the data we hold about you on request.
• Your right to correct and complete your data: We will correct inaccurate information about you if you notify us accordingly. We will complete incomplete data if you notify us accordingly, provided this data is necessary for the intended purpose of processing your data.
• Your right to delete your data: We will delete the information we hold about you on request. However, some data will only be deleted subject to a defined period of retention, for example because we are required to retain the data by law in some cases, or because we require the data to fulfil our contractual obligations to you.
• Your right to have your data blocked: In certain legally determined cases, we will block your data if you would like us to do so. Blocked data is only further processed to a very limited extent.
• Your right to withdraw consent: You can withdraw consent given for your data to be processed with effect for the future at any time. The legality of processing your data remains unaffected by this up to the point at which your consent is withdrawn.
• Your right to object to the processing of your data: You can object to the processing of your data with effect for the future at any time, if we are processing your data on the basis of one of the legal justifications set out in article 6(1e or 1f) of Regulation (EU) 2016/679. In the event that you object we will cease processing your data, provided that there are no compelling and legitimate grounds for further processing. The processing of your data for the purposes of direct marketing never constitutes compelling and legitimate grounds for us.
• Your right to data portability: At your request, we can make certain information available to you in a structured, commonly used and machine-readable format.
• Your right to appeal to a regulatory authority: You can lodge an appeal pertaining to data protection with a data protection authority. To do so, contact the data protection authority responsible for your place of residence or the data protection authority under whose jurisdiction we fall (named below).

Úřad pro ochranu osobních údajů, https://www.uoou.cz
To ensure complete control over your information, you have a comprehensive set of rights that you can use to manage how we process your data
Transmission to recipients outside the EEA
We also transmit personal data to recipients based outside of the EEA, in so-called third countries. In this case, we ensure ‒ before any data is shared ‒ that either an appropriate level of data protection is maintained by the recipient (e.g. on the basis of an adequacy decision made by the EU Commission for the respective country or the agreement of standard EU contractual clauses between the European Union and the recipient) or that you have given your consent to said sharing.
We are happy to provide you with an overview of the recipients in third countries and a copy of the specific provisions agreed to ensure an appropriate level of data protection. To request this, please use the contact information provided in the Section “Your point of contact for all questions relating to data protection” this Data Protection Information above.
We only transmit your data to recipients outside the EU when data protection is guaranteed

Valid from: 01.01.2023
Version: DPI_1.1.1c EN_DE