Privacy policy
Privacy Policy
1. Introduction and Controller
1.1 General Information
We thank you for visiting our website and for your interest in our company. In the following, we inform you about how we handle your personal data when using our website. Personal data is any information that enables the identification of your person.
1.2 Controller under GDPR
The controller for the processing of personal data on this website in accordance with the General Data Protection Regulation (GDPR) is:
TFK DermaCare GmbH Landstrasse 117 9490 Vaduz Liechtenstein Phone: +41 78 208 93 33 Email: support@tederm.li
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
1.3 EU Representative
A representative in the European Union has been appointed and can be contacted as follows: TFK DermaCare GmbH, Mathias Koch, Landstrasse 117, 9490 Vaduz
2. Data Collection When Visiting Our Website
2.1 Server Log Files
When using our website purely for information purposes - that is, without registration or otherwise transmitting information - we only collect data that your web browser automatically transmits to our server (so-called “server log files”). When you access our website, the following technically necessary data is collected:
- Website visited
- Date and time of access
- Amount of data transferred in bytes
- Source/reference from which you reached the page
- Web browser used
- Operating system used
- IP address (if applicable, in anonymized form)
Data processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR based on our legitimate interest in optimizing the stability and functionality of our website. The data is not passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of unlawful use.
2.2 SSL/TLS Encryption
For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries), our website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string “https://” and the lock symbol in your browser line.
3. Hosting & Content Delivery Network
3.1 Amazon Web Services
For hosting our website and providing content, we use the services of Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.
All data collected on our website is processed on the servers of this provider. A data processing agreement has been concluded with the provider, which ensures the protection of the data of our website visitors and excludes unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
3.2 Shopify
For hosting our website and displaying content, we use the platform of Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (“Shopify”).
Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada.
All data collected on our website is processed on the servers of this provider. A data processing agreement has been concluded with the provider, which ensures the protection of the data of our website visitors and excludes unauthorized disclosure to third parties.
For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
3.3 AWS-CloudFront
We use a Content Delivery Network (CDN) from Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA.
This service enables us to provide extensive media files such as graphics, content, or scripts more quickly via a network of regionally distributed servers. The processing is carried out to safeguard our legitimate interest in optimizing the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR. A data processing agreement has been concluded with the provider, which ensures the protection of the data of our website visitors and excludes unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
3.4 Shopify CDN
We use a Content Delivery Network (CDN) from Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (“Shopify”).
Data may also be transferred to: - Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada - Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service enables us to provide extensive media files such as graphics, content, or scripts more quickly via a network of regionally distributed servers. The processing is carried out to safeguard our legitimate interest in optimizing the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR. A data processing agreement has been concluded with the provider, which ensures the protection of the data of our website visitors and excludes unauthorized disclosure to third parties.
For data transfers to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission. For data transfers to the USA, the data recipient has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
4. Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies - small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called “session cookies”), while others remain on your device for longer and enable the storage of page settings (so-called “persistent cookies”). In the latter case, you can view the storage duration in the cookie settings overview of your web browser.
If personal data is also processed by individual cookies we use, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR for contract fulfillment, in accordance with Art. 6 para. 1 lit. a GDPR if consent has been given, or in accordance with Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the optimal functionality of the website and a user-friendly and efficient design of the website visit.
You can configure your browser to be informed about the setting of cookies and decide individually about their acceptance, or to exclude the acceptance of cookies for certain cases or in general.
Please note that the functionality of our website may be restricted if cookies are not accepted.
5. Contact
5.1 Judge.me
For review reminders, we use the services of Judge.me Ltd., c/o Buckworths, 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB, United Kingdom.
Exclusively on the basis of your express consent in accordance with Art. 6 para. 1 lit. a GDPR, we transmit your email address and, if applicable, other customer data to this provider so that they can contact you with a review reminder by email.
You can withdraw your consent at any time with effect for the future to us or to the provider.
A data processing agreement has been concluded with the provider, which ensures the protection of the data of our website visitors and excludes unauthorized disclosure to third parties.
For data transfers to the provider’s location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
5.2 Contact Form
If you send us inquiries via our contact form, your information from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing your inquiry and for possible follow-up questions. The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us in accordance with Art. 6 para. 1 lit. f GDPR or on your consent in accordance with Art. 6 para. 1 lit. a GDPR if this has been requested.
The data you enter in the contact form will remain with us until you request deletion, withdraw your consent to storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
6. Data Processing When Concluding a Contract
6.1 Processing of Customer Data
We collect, process, and use personal data only to the extent necessary for the establishment, content design, or modification of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures. We collect, process, and use personal data about the use of our website (usage data) only to the extent necessary to enable the user to use the service or to bill them.
The collected customer data is deleted after completion of the order or termination of the business relationship. Statutory retention periods remain unaffected.
6.2 Transfer of Data to Shipping Service Providers
If you have given us your express consent in accordance with Art. 6 para. 1 lit. a GDPR as part of your order, we will transmit your email address to the selected shipping service provider so that they can inform you by email about the shipping status of your order before delivery of the goods.
You can withdraw your consent at any time with effect for the future to us or to the shipping service provider.
7. Payment Service Providers
7.1 Shopify Payments (Stripe)
When selecting a payment method offered via the “Shopify Payments” payment service, payment processing is carried out by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe may use other payment services for payment processing.
Data processing serves payment processing and is carried out on the basis of Art. 6 para. 1 lit. b GDPR (contract fulfillment). Transmitted data may include inventory data (e.g., name, address), payment data (e.g., bank details, credit card numbers), and order data (e.g., invoice number, invoice amount).
For data transfers to third countries, a data processing agreement in accordance with Art. 28 GDPR has been concluded with the payment service provider and, if applicable, standard contractual clauses of the European Commission have been agreed.
Further information on “Shopify Payments” can be found at: https://www.shopify.com/legal/terms-payments-de
7.2 PayPal
When selecting a payment method offered via PayPal, payment processing is carried out via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
Data processing serves payment processing and is carried out on the basis of Art. 6 para. 1 lit. b GDPR (contract fulfillment). Transmitted data may include inventory data (e.g., name, address), payment data (e.g., bank details, credit card numbers), and order data (e.g., invoice number, invoice amount).
Further information on PayPal can be found in the privacy policy at: https://www.paypal.com/de/legalhub/privacy-full
8. Web Analysis and Advertising
8.1 Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
Google Analytics uses cookies that enable an analysis of your use of the website. The information generated by cookies about your use of this website is usually transmitted to a Google server in the USA and stored there.
IP anonymization is activated on this website, so that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission.
The use of Google Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TTDSG. You can withdraw your consent at any time with effect for the future.
For data transfers to the USA, Google has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
Further information on Google Analytics can be found at: https://policies.google.com/privacy
8.2 Google Ads and Conversion Tracking
This website uses Google Ads, an online advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
As part of Google Ads, we use conversion tracking. When you click on an ad placed by Google, a cookie for conversion tracking is set. These cookies expire after 30 days and are not used for personal identification.
The use of Google Ads is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TTDSG. You can withdraw your consent at any time with effect for the future.
For data transfers to the USA, Google has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
Further information on Google Ads can be found at: https://policies.google.com/privacy
8.3 Meta Pixel (Facebook Pixel)
This website uses the Meta Pixel (formerly Facebook Pixel) from Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Meta”).
With the Meta Pixel, we can target visitors to our website as an audience for the display of advertisements (so-called “Facebook Ads”). The Meta Pixel enables us to track the effectiveness of our Facebook advertisements for statistical and market research purposes.
The use of the Meta Pixel is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TTDSG. You can withdraw your consent at any time with effect for the future.
For data transfers to the USA, Meta has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
Further information on Meta and Facebook Ads can be found at: https://www.facebook.com/privacy/explanation
8.4 TikTok Pixel
This website uses the TikTok Pixel from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.
With the TikTok Pixel, we can target visitors to our website as an audience for the display of advertisements on TikTok. The TikTok Pixel enables us to track the effectiveness of our TikTok advertisements.
The use of the TikTok Pixel is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TTDSG. You can withdraw your consent at any time with effect for the future.
For data transfers to the USA, TikTok has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision by the European Commission.
Further information can be found in TikTok’s privacy policy: https://www.tiktok.com/legal/privacy-policy
9. Your Rights as a Data Subject
9.1 Right of Access
You have the right to request confirmation from us as to whether personal data concerning you is being processed. If such processing is taking place, you can request information about this personal data and further information in accordance with Art. 15 GDPR.
9.2 Right to Rectification
You have the right to request the immediate rectification of incorrect personal data concerning you in accordance with Art. 16 GDPR. Taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data.
9.3 Right to Erasure
You have the right to request the immediate erasure of personal data concerning you in accordance with Art. 17 GDPR, provided that one of the legally prescribed reasons applies.
9.4 Right to Restriction of Processing
You have the right to request the restriction of the processing of your personal data in accordance with Art. 18 GDPR if one of the legal requirements is met.
9.5 Right to Data Portability
You have the right, in accordance with Art. 20 GDPR, to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us.
9.6 Right to Object
You have the right, in accordance with Art. 21 GDPR, to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6 para. 1 lit. e or f GDPR.
9.7 Withdrawal of Consent
You have the right to withdraw your given consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal.
9.8 Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data by us.
10. Data Security
We employ technical and organizational security measures to protect your data managed by us against accidental or intentional manipulation, loss, destruction, or against access by unauthorized persons. Our security measures are continuously improved in line with technological developments.
11. Validity and Amendment of this Privacy Policy
This privacy policy is currently valid. Due to the further development of our website and offers or due to changed legal or official requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed and printed out by you at any time on the website.




