Privacy policy

Data protection

 

The protection of your personal data is very important to us. We want you to know at all times whether, when and to what extent we process your personal data (hereinafter referred to as ‘data’) when you visit our websites and use our Internet services, which web analysis, remarketing and retargeting tools, cookies, social media and other services we use, and we want to inform you about your rights.

Processing of personal data

According to the European General Data Protection Regulation (GDPR), personal data is any information relating to an identified or identifiable natural person (data subject). A natural person is identifiable if they can be identified directly or indirectly, in particular by association with an identifier (such as name, address, telephone number, email address, IP address, location data or special characteristics such as genetic, economic and social identity of that natural person).

Processing means any operation or set of operations which is performed on data, whether or not by automated means. This includes, in particular, the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

It is generally not necessary for you to provide data in order to use our website. In certain cases, however, we need your name and address as well as other information so that we can provide the services you require.

The same applies, for example, to the sending of information material and ordered goods or to the answering of individual questions. Where this is necessary, we will point this out to you accordingly. Beyond that, we only process data that you voluntarily provide to us and, if applicable, data that we automatically collect when you visit our website (e.g. IP address and the names of the pages you visit, the browser and operating system you use, date and time of access, search engines used, names of downloaded files).

If you make use of services, we generally only collect the data we need to provide those services. If we ask you for further data, this is voluntary information.

Your data is processed for the purpose of providing the requested service, safeguarding our own legitimate business interests, fulfilling a legal obligation or on the basis of your consent.

If we obtain your consent for the processing of personal data, this consent constitutes the legal basis for the processing of your data in accordance with Art. 6 (1) (a) GDPR.

When processing personal data that is necessary to perform the requested service, we refer to Art. 6 (1) (b) GDPR as the legal basis.

Insofar as the processing of personal data is necessary to fulfil a legal obligation to which we are subject, Art. 6 (1) (c) GDPR serves as the legal basis.

If processing is necessary to safeguard a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 6 para. 1 sentence 1 lit. f GDPR forms the legal basis for processing.

We only store your data until the purpose has been fulfilled and there are no other legal storage obligations (e.g. commercial or tax law storage obligations).

If you have given us your consent, we will store your data until you revoke your consent, provided that there is no other legal basis for the processing of your data and no statutory retention periods prevent its deletion.

In addition, in individual cases, e.g. for evidence purposes, longer storage may be appropriate to defend/enforce civil or public law claims.

Protection of your personal data

We appreciate your interest in our company and our products and services, and want you to feel secure about the protection of your data when visiting our website. We take the protection of your data very seriously. Compliance with the provisions of the GDPR and the Federal Data Protection Act in its current version is a matter of course for us.

We have taken technical and organisational measures to ensure that data protection regulations are observed both by us and by the external service providers we commission. Our employees and the service providers we commission are obliged by us to maintain confidentiality and to comply with the provisions of the GDPR and the Federal Data Protection Act in its currently valid version.

As part of our information obligations, we want to make this privacy policy as transparent as possible. To this end, we describe below the purpose limitation of the processing of your data and the use of cookies or tracking/analysis tools.

Purpose limitation of the processing of personal data

We process the data you provide in accordance with the principles of data minimisation and purpose limitation. The principle of purpose limitation states that data may only be collected and processed for specified, explicit and legitimate purposes. Further processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes is not considered incompatible with the original purposes.

We generally process your data for the purpose of responding to your enquiries, processing your orders or providing you with access to specific information or offers. In order to maintain customer relationships, it may also be necessary for us or a service provider commissioned by us to use this data to inform you about product offers or to conduct online surveys in order to better meet the tasks and requirements of our customers.

We will only process the data you provide online for the purposes communicated to you.

Your data will only be passed on in exceptional cases
- to external service providers (processors) working on our behalf, if this is necessary for the purpose of fulfilling the contractual relationship,
- to government institutions and authorities, if we are legally obliged to do so, or 
- if you consent to this.

We conclude the relevant agreements with the processors for order processing on the basis of Art. 28 GDPR. The service companies commissioned by us are obliged by us to maintain confidentiality and to comply with the provisions of the GDPR and the BDSG. The data passed on may only be used by our service providers to fulfil their tasks. Any other use of the information is not permitted and does not occur at any of the service providers we commission.

Data is only collected and transmitted to government institutions and authorities entitled to receive such information within the framework of the relevant laws or if we are obliged to do so by a court decision.

Beyond that, we do not pass on any data to third parties unless you have expressly consented to this.

We naturally respect your decision if you do not wish to provide us with your data to support our customer relationship (in particular for direct marketing or market research purposes). We will not sell your data to third parties or market it in any other way unless you have given us your consent to do so.

If, in the context of using third-party services, data is disclosed or transferred to third parties in a third country, i.e. outside the European Union (EU) or the European Economic Area (EEA), and data is further processed, this will only be done on the basis of your consent, a legal obligation, our legitimate interests or if it is necessary for the fulfilment of our (pre)contractual obligations. Subject to legal or contractual permissions, we only process or have the data processed in a third country if the special requirements of Art. 44 ff. GDPR are met.

Encryption

This website uses TLS encryption for security reasons and to protect the transmission of confidential content, such as enquiries that you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of the browser changes from ‘http://’ to ‘https://’ and by the lock symbol in your browser line. If TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

Browser type and browser version
Operating system used
Referrer URL
Host name of the accessing computer
Time of the server request

This data is not merged with other data sources. Storage is limited in time and only takes place to ward off hackers, taking into account the company's interest in protection and the personal rights of users. We reserve the right to check this data retrospectively if we become aware of specific indications of illegal use.

Cookies

This website and some of the web analysis, remarketing and retargeting tools we use sometimes employ cookies. Cookies serve to make our offering more user-friendly, effective and secure. Cookies are small text files that are stored on your computer and saved by your browser. Cookies do not cause any damage to your computer and do not contain viruses.

Other cookies remain on your device and enable your browser to be recognised on your next visit (so-called persistent cookies). If cookies are set, they process certain user information such as browser and location data as well as IP address values to an individual extent. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.

Apart from the Internet Protocol address, no personal data of the user is stored. This information is used to automatically recognise you on your next visit to our websites and to make navigation easier for you. Cookies allow us, for example, to tailor a website to your interests or to store your password so that you do not have to re-enter it each time.

Necessary cookies help to make a website usable by enabling basic functions such as page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Convenience cookies make it easier for you to use our websites. They enable a website to remember information that affects the way a website behaves or looks, such as your preferred language or the region you are in.

Statistics cookies collect anonymised data for statistics and analysis. They thus help us to further improve our website and optimise its content.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when you close your browser.

Please refer to your browser manufacturer's instructions for details on how this works. Deactivating cookies may restrict the functionality of this website.

In addition, when you start our websites, you can decide for yourself which categories you want to allow in the cookie settings.

Cookies that are necessary for the technically error-free and optimised provision of our services (‘technically necessary cookies’) are stored on the basis of our legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR. Cookies that are not technically necessary are only set after you have given your consent (based on the legal basis of Art. 6 para. 1 sentence 1 lit. a GDPR).

You can adjust your cookie settings and revoke any consent you have already given at any time here:

Open configuration menue

 

Contact form
If you use our contact form to get in touch with us, we will ask you for personal information. In order for us to respond to your enquiry, you must provide a valid email address and your name. Further personal details are optional. Your details will be processed via email.

The contact form is sent using end-to-end encryption.
The information you provide in the enquiry form, including the contact details you provide there, will be stored and processed on our servers for the purpose of processing the enquiry and in case of follow-up questions.

Data processing for the purpose of contacting us is based on your voluntary consent. By clicking on the ‘Send’ button, you consent to the processing of your contact information for the above-mentioned purposes. If you do not agree, you must cancel the process. The contact form will then not be sent and your data will not be processed.

The data entered in the contact form is therefore processed exclusively on the basis of your consent (Art. 6 (1) (a) GDPR). You can revoke this consent at any time with effect for the future. To do so, please send us an email to support[at]cinecitta.de.

We only use your data to the extent necessary to process your enquiries and for further correspondence with you. The data collected by us for the use of the contact form is stored by us for the purpose of processing the enquiry and in the event of follow-up questions, and is deleted in accordance with data protection regulations after your enquiry has been dealt with, unless there is another legal obligation to retain it. We do not pass this data on to third parties without your consent. 

Newsletter

If you would like to receive the newsletter offered on the website, we require your email address. No further data will be collected. We will use your email address exclusively for sending the requested information and will not pass it on to third parties. By entering your email address and clicking the ‘Subscribe’ button, you consent to the storage of your email address and its use for sending our newsletter. The legal basis is your consent in accordance with Art. 6 (1) (a) GDPR. We have logged your consent and are obliged to keep its content available for retrieval at any time.

You can revoke your consent to the storage of your email address and its use for sending the newsletter at any time with future effect, for example by clicking on the ‘Unsubscribe newsletter’ link provided in each newsletter or by sending an email to support[at]cinecitta.de. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until revocation.

If you register for an email newsletter, the personal data and information you provide and transmit to us will be electronically recorded and stored by us. The purpose of this processing is initially to carry out the so-called double opt-in procedure, with which you can consent to the regular sending of the email newsletter. This means that after you have submitted your data and information, we will send an email to the email address you have provided and ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration, your data will be deleted.

After your confirmation, we will store your IP address and the time of confirmation. The purpose of this procedure is to verify your registration for the email newsletter and, if necessary, to detect and prevent any misuse of your personal data. The legal basis for this is Art. 6 (1) (f) GDPR.

Please note that we evaluate the behaviour of the readers of our email newsletter. For this evaluation, the emails sent contain so-called web beacons or tracking pixels. These web beacons or tracking pixels are single-pixel image files stored on our website. For the evaluation, we link the web beacons or tracking pixels to your email address and an individual ID.

We use the data obtained in this way to create a user profile in order to tailor the newsletter to your individual interests. When you read the newsletter, we record which links you click on in the newsletter and use this to deduce your personal interests. We link this data to the actions you take on our websites. The purpose of this processing is to improve the quality of the newsletter and optimise our offers. The legal basis is Art. 6 (1) (f) GDPR.

This tracking does not take place if you have disabled the display of images in your email programme by default. In this case, the newsletter will not be displayed in full and you may not be able to use all functions. As soon as you display the images, the tracking described above will be activated.

The data collected during registration (e-mail address and voluntary information) will be deleted as soon as it is no longer required for the purpose for which it was collected. This is the case after you unsubscribe from the newsletter or revoke your consent.

The data and information stored via the tracking function will be stored for as long as you are subscribed to the newsletter. After you unsubscribe or revoke your consent, we store your data purely for statistical and anonymous purposes.

Competition

If you take part in a competition organised by the controller, we require further data from you in addition to your email address (e.g. first and last name, address details, date of birth). This data will be processed for verification, communication and information purposes. This data will not be passed on to third parties or processed for other purposes without your express consent. Your rights remain unaffected (see Rights of data subjects).

Further information can be found in the terms and conditions of participation for the respective competition.

Online shop

 

We process your personal data collected during the ordering process exclusively for the purpose of establishing, executing and processing the purchase contracts concluded with us in our online shop. The legal basis for processing is Art. 6 (1) (a) and (b) GDPR.

 

Customer account

On the website, you have the option of setting up a personal customer account for the online shop (hereinafter referred to as ‘customer account’). You can store your personal information in your customer account and use it to conveniently shop in our online shop. In addition, we offer you certain convenience features such as the display of your purchase history. To set up your personal customer account, we need your first and last name, your email address and your postal address. We also need you to choose a password to set up your customer account. The email address you provide also serves as your login ID for the customer account. After successful registration, you will automatically receive a confirmation email. In the personal area of your customer account, you can update your data at any time and add further information on a voluntary basis.

 

Use of the online shop

We use your data exclusively to the extent necessary for the establishment, execution and processing of the purchase contracts concluded with us in our online shop. Beyond this, we only process your personal data if you have given your express consent. The legal basis for processing is Art. 6 (1) (a) and (b) GDPR. There are two options available to you for ordering from our online shop:

 

Orders with a customer account

The information stored in your customer account is stored in the central customer database of the controller (see below). During the ordering process, you will be asked to log in to your customer account with your email address and password. Your delivery and billing addresses are already automatically pre-filled in your customer account. During the ordering process, you have the option of changing or adding to this information (e.g. specifying a different delivery or billing address).

 

Guest orders

Of course, you can also use our online shop without an existing customer account. In this case, you can enter the information required to process your order in the order form provided during the ordering process and send it directly to us by clicking on the ‘Continue’ button in the order form.

 

Use of logistics providers

If necessary, we will provide your data to logistics providers for the purpose of shipping, who will process this data on our behalf and in compliance with these data protection regulations and the necessary security measures.

 

Collection of outstanding debts

We also use your data to collect outstanding debts. We hereby commission debt collection agencies to process your data on our behalf and in compliance with these data protection provisions and the necessary security measures.

 

Use of web analysis, remarketing and retargeting tools

We use various tools or plugins for web analysis, remarketing and retargeting for the purpose of optimising our online presence and providing you with more targeted offers. This involves the use of cookies, the forwarding of IP addresses in anonymised form, or the collection and evaluation of various types of data. This includes, for example, the number of website visitors, abandonments during the purchase process, conversion rates, visit duration, average page load time, and visitor origin.

In cross-device remarketing, when you visit our websites from multiple devices (e.g. computer, tablet, mobile phone), data is stored by the respective tool provider so that cross-device analyses can be carried out. A random user ID is assigned and stored. This user ID then represents an individual user.

The following tools are used on our website:

Google Analytics
Google Remarketing or cross-device remarketing
Meta Pixel

In the detailed descriptions, you can see how these tools/plugins work and what specific benefits they have for you.

 

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, or, if the service is provided in the European Union (EU), Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (‘Google’).

Google Analytics uses cookies (see above). The information generated by the cookie about your use of this website (including your IP address) is usually transferred to a Google server in the USA and stored there. Google will use this information to evaluate your use of the website, to compile reports on website activity for us and to provide other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will never associate your IP address with other data from Google.

 

We would like to point out that we use Google Analytics with the extension ‘_anonymizeIp()’ so that your IP address is only processed in truncated form in order to exclude direct personal references.

 

If consent to set or store cookies has been requested and granted, processing will be carried out exclusively on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by clicking on cookie settings. An opt-out cookie will then be set to prevent your data from being collected on future visits to this website.

Open configuration menue

You can object to the collection and use of information by Google at any time with future effect by installing the deactivation add-on provided by Google (https://tools.google.com/dlpage/gaoptout?hl=de).

 

For more information on how Google Analytics handles user data, please refer to Google's privacy policy: support.google.com/analytics/answer/6004245

Google's terms of use can be found at policies.google.com/terms.

 

Google Remarketing or Cross-Device Remarketing

As an extension of Google Analytics, this website also uses Google Remarketing or Cross-Device Remarketing. This is a feature of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, or, if the service is provided in the European Union (EU), Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland, for the placement of interest-based online advertising. This serves our legitimate interests in pursuing our business purposes in the form of targeted advertising for our services. Cookies are used for this purpose, which enable us to tailor our ad content specifically to your interests based on your previous visits to this website and your demographic data (only for cross-device remarketing). For this purpose, a user list is created, which is a list of website visitors, i.e. multiple cookie IDs.

 

This allows Google to detect your previous visit to our website. According to Google, the data collected in the context of remarketing is not merged with your personal data that may be stored by Google. In particular, according to Google, pseudonymisation is used in remarketing.

 

If you do not want this, you can deactivate the use of cookies by adjusting your browser software settings and installing the deactivation add-on provided by Google (https://tools.google.com/dlpage/gaoptout?hl=de).

 

Furthermore, you can use the Ads Preferences Manager (https://www.google.com/settings/ads/?hl=de) to deactivate Google Analytics for display advertising and specify which types of ads are displayed to you in the Google Display Network.

 

If consent to set or store cookies has been requested and granted, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by clicking on Cookie Settings. An opt-out cookie will then be set to prevent your data from being collected on future visits to this website.

Open configuration menue

 

Further information on data protection at Google can be found here:
www.google.com/intl/de/policies/privacy and
services.google.com/sitestats/de.html.


   Meta Pixel


With your consent, we use the so-called ‘Meta Pixel’ from the social network Meta, which is operated by Meta Inc., 1601 Willow Road 94025 Menlo Park, CA 94025, USA, or, if you are based in the EU, Meta Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (‘Meta’).

With the help of Meta Pixel, Meta is able to identify visitors to our online offering as a target group for the display of advertisements (so-called ‘Meta Ads’). Accordingly, our purpose in using Meta Pixel is to display the Meta Ads we place only to those Meta users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products, determined on the basis of the websites visited) that we transmit to Meta (so-called ‘Custom Audiences’). In this way, we also want to ensure that our Meta Ads correspond to the potential interests of users and do not appear intrusive. With the ‘Conversion’ tool from Meta Pixel, we can also track your actions after you have seen or clicked on a Meta ad. This serves to monitor and analyse the effectiveness of our Meta advertisements for statistical purposes and for market research purposes.

The Meta Pixel automatically establishes a direct connection between your browser and Meta's server. We have no influence on the scope and further use of the data collected by Meta through the use of this tool and therefore inform you according to our state of knowledge:

By integrating the Meta pixel, Meta receives the information that you have clicked on one of our advertisements or visited the corresponding page of our website. If you are registered with a Meta service, Meta can assign the visit to your account. Meta may use this information for advertising, market research and the needs-based design of Meta pages. To this end, Meta and its partners create usage, interest and relationship profiles, e.g. to evaluate your use of our website with regard to the advertisements displayed to you on Meta, to inform other Meta users about your activities on our website and to provide other services related to the use of Meta. Cookies may also be stored on your PC for this purpose.

If you are registered with Meta, you can set which types of advertisements are displayed to you within Meta by visiting the page set up by Meta and following the instructions on the settings for usage-based advertising: www.facebook.com/settings. The settings are platform-independent, i.e. they are applied to all devices, such as desktop computers or mobile devices.

Even if you are not registered with Meta or have not logged in, it is possible that the provider may obtain and store your IP address and other identifying characteristics.

For the purpose and scope of data collection and the further processing and use of data by Meta, as well as your rights in this regard and setting options for protecting your privacy, please refer to Meta's privacy policy.
Further information can be found in Meta's privacy policy at de-de.facebook.com/privacy/explanation.

If you have given us your consent, your consent is the legal basis for the use of Meta Pixel (Art. 6 (1) (a) GDPR).
You can revoke your consent at any time with effect for the future. If you wish to deactivate Meta Pixel tracking or revoke your consent, please click on ‘Decline’ under the ‘Cookie Settings’ button for the Meta Pixel service.

Open configuration menue

Security

We have taken technical and organisational security measures in accordance with legal requirements to protect your data from loss, destruction, manipulation and unauthorised access. These security measures include, in particular, the encrypted transmission of data between your browser and our server. All our employees and all persons involved in data processing are obliged to comply with the General Data Protection Regulation, the Federal Data Protection Act in its currently valid version and other data protection-related laws, as well as to treat data confidentially.

Furthermore, we conclude the relevant agreements on order processing with the external service providers working on our behalf.

Our security measures are regularly reviewed and continuously revised in line with technological developments.

Rights of data subjects

 

Right to information

You can obtain information about your data processed by us at any time in accordance with Art. 15 GDPR. In particular, you can request information about the purposes of the processing, the categories of data processed, categories of possible recipients and the planned storage period. Please send your request for information to support[at]cinecitta.de.

 

Right to rectification

Pursuant to Art. 16 GDPR, you have the right to have inaccurate personal data concerning you rectified or incomplete personal data completed at any time. If you have registered via our website, you can of course make the changes yourself. Alternatively, you can contact our service centre or write to the person responsible (see below).

 

Right to erasure

We will erase your personal data in accordance with Art. 17 GDPR

  • if you withdraw your consent to lawful processing and there are no other legal grounds for storage.
  • if you object to the processing. As long as the objection remains valid and the matter has not been clarified, your data will be blocked. You can withdraw your objection by giving your written consent.
  • if it is no longer required for the purposes for which it was collected or otherwise processed.
  • if the processing is inadmissible for other legal reasons

To do so, please contact our support team or write to the controller (see below).

 

Right to restriction of processing

Under Article 18 of the GDPR, you have the right to have the processing of your personal data restricted if

 

  • You contest the accuracy of your personal data, for a period enabling us to verify its accuracy.
  • the processing is unlawful, but you refuse to have your personal data deleted and instead of deletion you request a restriction on its use.
  • we no longer need your personal data for the purposes, but you need it to assert, exercise or defend legal claims.
  • you have objected to the processing, but it is not yet clear whether our legitimate reasons outweigh your reasons.
  • You can revoke the restriction by giving your written consent. To do so, please contact our service centre or write to the controller (see below).

 

Right to data portability

Under Article 20 of the GDPR, you have the right to receive the data concerning you in a commonly used, structured and machine-readable format (data portability). In addition, under certain conditions, you can request that your data be transferred directly from one controller to another, where technically feasible.

To exercise this right, please contact the controller in writing (see below).

 

Right to object

You have the right to object to the use of your data for the above-mentioned purposes at any time (Art. 21 GDPR). This is possible if the objection is directed against direct marketing or if there are reasons for this arising from your particular situation. In the case of an objection to direct marketing, you have a general right of objection, which we will implement without you having to specify a particular situation.

To exercise your right of objection, please write to support[at]cinecitta.de

Right to lodge a complaint with a supervisory authority

We would also like to point out that, without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of data relating to you infringes the General Data Protection Regulation.

A list of supervisory authorities (for the non-public sector) with addresses can be found at:

www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

Third-party services

Payment via PayPal

PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

 

All data required for payment processing is transmitted securely using the SSL protocol. PayPal may transfer, process and store personal data outside the EU. By using PayPal, you agree to PayPal's privacy policy. Your data is transferred to PayPal on the basis of Art. 6 (1) (b) GDPR (processing for the performance of a contract).

 

When paying via PayPal, credit card via PayPal, direct debit via PayPal or – if offered – ‘purchase on account’ via PayPal, we pass on your payment details to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter ‘PayPal’) for the purpose of payment processing. This transfer is necessary to process your order using the payment method you have selected, in particular to confirm your identity, to administer your payment and the customer relationship. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or, if offered, ‘purchase on account’ via PayPal. PayPal uses the result of the credit check in relation to the statistical probability of payment default to decide whether to provide the respective payment method. The credit check may contain probability values (so-called score values). Insofar as score values are included in the result of the credit check, these are based on a scientifically recognised mathematical-statistical procedure. Address data, among other things, is included in the calculation of the score values. For further information on data protection, including the credit agencies used, please refer to PayPal's privacy policy:

www.paypal.com/de/webapps/mpp/ua/privacy-full

Payment via instant transfer

SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany

If you choose to pay via the online payment service provider Sofortüberweisung during the ordering process, your contact details will be transmitted to Sofortüberweisung as part of the order you have placed. Sofortüberweisung is a service offered by SOFORT GmbH, a company of the Klarna Group, based at Theresienhöhe 12, 80339 Munich, Germany. Sofortüberweisung acts as an online payment service provider, enabling cashless payment for products and services on the Internet.

The data transmitted to Sofortüberweisung usually includes your first name, last name, address, telephone number, email address, IP address or other data required for order processing and related to the order, such as the number of items, item number, invoice amount and taxes as a percentage, and invoice information.

This transmission is necessary to process your order with the payment method you have selected, in particular to confirm your identity, to administer your payment and the customer relationship.

Please note, however, that data from Sofortüberweisung may also be passed on to service providers, subcontractors or other affiliated companies, insofar as this is necessary to fulfil the contractual obligations arising from your order or if the data is to be processed on behalf of Sofortüberweisung.

Furthermore, the data transmitted to Sofortüberweisung may be transmitted by Sofortüberweisung to credit agencies for identity and credit checks in relation to the order you have placed. The transmission of your data to Sofort GmbH is based on Art. 6 (1) (b) GDPR (processing for the performance of a contract). Information on Sofortüberweisung's data protection principles when processing your data can be found in the data protection information displayed during the Sofortüberweisung payment process.

If you have any further questions about the use of your data, you can contact Sofortüberweisung by email ([email protected]) or in writing (SOFORT GmbH, Data Protection, Theresienhöhe 12, 80339 Munich). Further details on payment with Sofortüberweisung can be found at the following links: www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/.

Payment via Amazon Payments

Amazon Payments Europe s.c.a., 5 Rue Plaetis, L-2338 Luxembourg

All data required for payment processing is used by Amazon Payments exclusively for the execution of payments and is transmitted securely using the “SSL” procedure. The transfer of your data to Amazon Payments is based on Art. 6 (1) (b) GDPR (processing for the performance of a contract). Amazon Payments is PCI DSS certified. Amazon Payments may transfer, process, and store personal data outside the EU. By using Amazon Payments, you agree to the privacy policy, which you can view at the following link:

pay.amazon.com/de/help/201751600

 

Payment by Visa or Mastercard

Datatrans AG, Kreuzbühlstrasse 26, CH-8008 Zurich, Switzerland

Concardis GmbH, Helfmann-Park 7, 65760 Eschborn, Germany

 

All data required for payment processing is used by Datatrans AG exclusively for the execution of payments and is transmitted securely using the “SSL” procedure. The transmission of your data is based on Art. 6 (1) (b) GDPR (processing for the performance of a contract).

 

Use of Google Maps

This website uses Google Maps, a map service provided by Google LLC (‘Google’), 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, or, if the service is provided in the European Union (EU), Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (‘Google’).

 

Google Maps is a web service for displaying interactive (land) maps to visually represent geographical information. By using this service, our location is displayed to you and any journey to us is made easier.

 

As soon as you access the subpages in which the Google Maps map is integrated, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there. This may also involve transmission to Google LLC. servers in the USA. This occurs regardless of whether Google provides a user account that you are logged in to or whether a user account exists. If you are logged in to Google, your data will be directly associated with your account. If you do not want your data to be associated with your Google profile, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates them

.The collection, storage and evaluation are carried out in accordance with Art. 6 (1) (f) GDPR on the basis of Google's legitimate interest in displaying personalised advertising, market research and/or the needs-based design of Google websites. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right.

 

If consent to set or store cookies has been requested and granted, processing is carried out exclusively on the basis of Art. 6 para. 1 sentence 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by clicking on cookie settings. An opt-out cookie will then be set to prevent your data from being collected on future visits to this website.

Open configuration menue

Further information on Google's data protection policy can be found at:

www.google.de/intl/de/policies/privacy/

 

The terms of use for Google Maps can be found at:

www.google.de/intl/de/policies/terms/regional.html and

https://www.google.com/intl/de_de/help/terms_maps.html

 

Google Tag Manager

We use Google Tag Manager on our websites. Google Tag Manager is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, or, if the service is provided in the European Union (EU), Google Ireland Limited, Google Building Gordon House, Barrow St, Dublin 4, Ireland, (‘Google’). Google Tag Manager enables us as marketers to manage website tags via an interface. The Google Tag Manager tool, which implements the tags, is a cookie-free domain and does not itself collect any personal data. Google Tag Manager triggers other tags, which in turn may collect data. Google Tag Manager does not access this data. If deactivation has been carried out at domain or cookie level, this remains in place for all tracking tags implemented with Google Tag Manager.

Further information on data protection can be found on the following Google websites:

Privacy policy: policies.google.com/privacy

Google Tag Manager FAQ: www.google.com/intl/de/tagmanager/faq.html

Google Tag Manager Terms of Service: www.google.com/intl/de/tagmanager/use-policy.html

 

Social media

Our website contains links to the social networks (social media) Facebook, Instagram, TikTok and YouTube.

 

Meta

Our website contains links to the social networks ‘Facebook’ and “Instagram”. These are operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (‘Facebook’).

You can recognize the (image) link by the button with the Facebook logo (small ‘f’); the links to Instagram are marked with an Instagram logo, for example in the form of an ‘Instagram camera’.

After clicking on the respective integrated button, you will be redirected to our Facebook or Instagram page.

This also informs Meta that you have visited our site.

Data may be transferred to the USA in this process.

For further information, in particular the exact purpose and scope of data collection by Facebook, please visit de-de.facebook.com/policy.php or http://instagram.com/about/legal/privacy/.

TikTok

Our website contains a link to TikTok (the link to TikTok is marked with a logo in the form of a musical note).

Please carefully consider what personal data you share with us via TikTok (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland). We would like to point out that you use TikTok and its functions at your own risk. This applies in particular to the interactive functions (e.g. commenting, sharing, rating). In your own interest, please carefully consider what information you wish to disclose and share with other users. We expressly point out that TikTok stores the data of users of its services (e.g. personal information, IP address, etc.) and may also use this data for business purposes. For more information on TikTok's data processing, please refer to TikTok's privacy policy at www.tiktok.com/legal/privacy-policy-eea.

YouTube

Our websites use links to YouTube and videos from YouTube, which is represented by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, or, if the service is provided in the European Economic Area and Switzerland, by Google Ireland Limited, based at Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as ‘Google’).

When you click on the link, a connection to our YouTube page is established. This also informs YouTube that you have visited our site.

The data collected by Google may be transferred by Google to countries outside the EU, in particular the USA.

By embedding YouTube videos on our website, we aim to present various videos on our website so that you can view them directly on our website.

The legal basis for the processing of personal data described here is Art. 6 (1) (f) GDPR. Our legitimate interest in this lies in the great benefits offered by YouTube. By embedding external videos, we reduce the load on our servers and can use the corresponding resources elsewhere. Among other things, this can increase the stability of our servers. YouTube and Google also have a legitimate interest in the (personal) data collected in order to improve their own services.

If consent to set or store cookies has been requested and granted, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by clicking on cookie settings. An opt-out cookie will then be set to prevent your data from being collected on future visits to this website.

For more information, please refer to the privacy policy of YouTube or Google, which you can access here: www.google.com/policies/privacy/

Information on Google's privacy settings can be found at privacy.google.com/take-control.html

Responsible party

This website and the shops integrated therein are operated by

 

CINECITTA' Multiplexkino GmbH & Co. KG

Gewerbemuseumsplatz 3

90403 Nuremberg, Germany

Phone: +49 (0)911/20 666 - 0

Fax: +49 (0)911/20 666 - 12

Email: support[at]cinecitta.de

 

as the controller of data processing.

External data protection officer

 

CINECITTA' Multiplexkino GmbH & Co. KG has appointed the following person as its group data protection officer:

 

Attorney Thomas P. Costard

Costard Law Firm

Lina-Ammon-Straße 9

90471 Nuremberg

Phone: 0911 / 790 30 34

Fax: 0911 / 790 30 35

Email: info[at]it-rechtsberater.de

Website: www.it-rechtsberater.de

Further questions about data protection

 

If you have any further questions that this privacy policy has not been able to answer, or if you would like more detailed information on a particular point, we will be happy to answer your questions at any time. Please contact our external data protection officer.

Changes to the privacy policy

 

We reserve the right to update this privacy policy from time to time.

 

As of June 2025.