Produced in Germany

PRIVACY POLICY

Privacy policy

 

1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
MOECK & MOECK GmbH
Waidmannstraße 12 d
22769 Hamburg
Germany
E-mail: vet@moeckundmoeckshop.de
Phone: +49 40 4111 4111

 

2. General Information

The protection of your personal data is important to us. We process personal data exclusively in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR), applicable national data protection laws and other relevant legal requirements.
Personal data means any information relating to an identified or identifiable natural person.

This includes, for example:

  • Name
  • Address
  • E-mail address
  • Telephone number
  • Customer number
  • Order information
  • Payment information
  • IP address
  • Usage data

Personal data is generally processed only where a legal basis exists or where you have provided your consent.

 

3. Hosting

Our online shop is hosted by:
Neue Medien Münnich GmbH (ALL-INKL.COM)
Hauptstraße 68
02742 Friedersdorf
Germany

As part of the hosting services, technical connection data, server log files and other data necessary for the secure operation of the website are processed.
The processing is carried out for the purpose of providing a stable, secure and efficient online shop.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interests).

A Data Processing Agreement (DPA) has been concluded with the hosting provider pursuant to Art. 28 GDPR.
Data processing takes place exclusively within the European Union.

 

4. Server Log Files

Whenever our online shop is accessed, certain information is automatically collected by the server.
This may include:

  • IP address
  • Date and time of access
  • Browser type and version
  • Operating system
  • Referrer URL
  • Visited pages and files
  • Access status
  • Internet service provider

The processing of this data is required to:

  • Ensure the functionality of the website
  • Maintain system security
  • Detect and prevent misuse
  • Investigate technical issues
  • Protect against cyberattacks

The data is not used to identify individual visitors.

Legal basis: Art. 6 (1) (f) GDPR.

 

5. Cookies

Our online shop uses cookies and comparable technologies.
Cookies are small text files that are stored on your device and contain information relating to your use of the website.
We use different categories of cookies.

 

Necessary Cookies

Necessary cookies are essential for the operation of the online shop.
These include:

  • Shopping cart functionality
  • Login functionality
  • Language settings
  • Session management
  • Security functions
  • Storage of privacy preferences

Without these cookies the website cannot function properly.

Legal basis: Sec. 25 (2) TDDDG, Art. 6 (1) (f) GDPR

 

Analytics Cookies

Analytics cookies allow us to understand how visitors use our website.
These cookies are activated only after your consent.

Legal basis: Sec. 25 (1) TDDDG, Art. 6 (1) (a) GDPR

 

Marketing Cookies

Marketing cookies help us measure and improve advertising campaigns.
They are activated only after your consent.

Legal basis: Sec. 25 (1) TDDDG, Art. 6 (1) (a) GDPR

 

6. Consent Management (oil.js)

We use the consent management platform oil.js to obtain, manage and document user consent regarding cookies and external services.
The following information may be processed:

  • Consent status
  • Date and time of consent
  • Browser information
  • Device information
  • Pseudonymous identifiers
  • Language settings

The processing is necessary to document compliance with legal obligations and to manage consent preferences.

Legal basis: Art. 6 (1) (c) GDPR

 

7. Customer Account

Customers may create a customer account.
The following categories of personal data may be processed:

  • Name
  • Postal address
  • E-mail address
  • Telephone number
  • Login credentials
  • Delivery addresses
  • Order history
  • Customer profile information

Customer account data is used for:

  • Account management
  • Order history management
  • Faster checkout procedures
  • Customer support

Legal basis: Art. 6 (1) (b) GDPR

Customers may request the deletion of their account at any time, subject to applicable legal retention requirements.

 

8. Registration and Login

Certain functionalities require user registration.
During registration and login, the following information may be processed:

  • Name
  • E-mail address
  • Password
  • Customer identification data

Passwords are stored in encrypted form and are never stored in plain text.
The processing serves the establishment and management of the customer relationship.

Legal basis: Art. 6 (1) (b) GDPR

 

9. Orders and Contract Performance

To process orders and fulfil contractual obligations, we process personal data including:

  • Name
  • Billing address
  • Delivery address
  • E-mail address
  • Telephone number
  • Order details
  • Contract information
  • Communication data

The processing serves:

  • Order processing
  • Contract performance
  • Delivery of goods
  • Customer communication
  • Invoicing
  • Legal obligations

Legal basis: Art. 6 (1) (b) GDPR

Order-related information may be retained beyond contract performance where required by statutory retention obligations.

 

10. Purchase on Invoice

Where payment by invoice is offered, we process the personal data necessary for:

  • Invoicing
  • Order administration
  • Payment processing
  • Receivables management
  • Contract fulfilment

This may include:

  • Customer master data
  • Contact information
  • Order data
  • Invoice information
  • Contractual information

Legal basis: Art. 6 (1) (b) GDPR

Personal data is retained only for as long as necessary for contract fulfilment or compliance with statutory retention requirements.

 

11. Financing and Hire Purchase via abcfinance

For selected products, we offer financing and hire purchase solutions through our financing partner:
abcfinance GmbH
Kamekestraße 2–8
50672 Cologne
Germany
If you choose financing or hire purchase, personal data required for the assessment, administration and execution of the financing agreement may be transferred to abcfinance. This may include personal details, identification data, contact information, financial information, creditworthiness data and contract-related information. 
The purposes of processing include:

  • assessment of financing requests,
  • execution of financing agreements,
  • identity verification,
  • fraud prevention,
  • risk assessment,
  • legal and regulatory compliance,
  • contract administration.

The legal basis for this processing is: Art. 6 (1) (b) GDPR (contractual necessity), Art. 6 (1) (f) GDPR (legitimate interests in risk assessment and fraud prevention). 

Further information on the processing of personal data by abcfinance can be obtained directly from abcfinance's privacy information. 

 

12. Credit Checks and Scoring

Where financing solutions are requested, abcfinance may carry out creditworthiness assessments and scoring procedures. These assessments are intended to evaluate payment reliability and financing risks. 
For this purpose, information may be obtained from credit reference agencies and other legally permissible sources. According to abcfinance, this may include information from credit agencies such as Creditreform Boniversum. 

The following categories of data may be processed:

  • Identification data
  • Contact information
  • Financial information
  • Creditworthiness information
  • Scoring values
  • Contract-related information

The legal basis for such processing is: Art. 6 (1) (b) GDPR, Art. 6 (1) (f) GDPR. 

 

13. Automated Decision-Making

As part of financing applications, automated decision-making and scoring procedures may be used by abcfinance. These procedures help assess whether contractual payment obligations are likely to be fulfilled. 
The assessment may take into account:

  • creditworthiness data,
  • financial information,
  • payment history,
  • scoring values,
  • information obtained from credit agencies,
  • other financing-related information.

The results of these procedures may be used by abcfinance when deciding whether financing products can be offered. 

In connection with automated decisions, you have the right to obtain human intervention, to express your point of view and to contest the decision (Art. 22 (3) GDPR). To exercise these rights, please contact abcfinance or us at vet@moeckundmoeckshop.de.

 

14. Shipping Providers (DPD and UPS)

To deliver ordered products, we transfer the information required for shipment to the relevant shipping provider.

Regular deliveries are handled by:
DPD Deutschland GmbH

In individual cases deliveries may be handled by:
UPS Deutschland S.à r.l. & Co. OHG

The transmitted data may include:

  • Name
  • Delivery address
  • Order information
  • Telephone number (where required)
  • E-mail address (where required)

Data is transferred solely for the purpose of carrying out the delivery.

Legal basis: Art. 6 (1) (b) GDPR

 

15. Shipping Notifications and Tracking Information

To keep customers informed about the delivery status of their orders, we may send shipping notifications and tracking information.

This may include:

  • shipment confirmation,
  • shipment tracking details,
  • estimated delivery information,
  • delivery notifications,
  • delivery status updates.

For this purpose, the following information may be processed:

  • E-mail address,
  • order number,
  • shipment number,
  • delivery status information.

The processing is necessary for contract performance under Art. 6 (1) (b) GDPR.

 

16. Contact by E-mail

If you contact us by e-mail, we process the information you provide in order to handle and respond to your inquiry.
This may include:

  • Name,
  • E-mail address,
  • Telephone number,
  • Company information,
  • Subject matter of the request,
  • Content of the communication.

The processing serves customer communication and the handling of requests.

Legal basis: Art. 6 (1) (b) GDPR, Art. 6 (1) (f) GDPR.

Data is deleted when the inquiry has been fully processed unless statutory retention obligations require longer storage.

 

17. Google Analytics

Subject to your consent, we use Google Analytics.

Provider

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google Analytics allows us to analyse visitor behaviour within our online shop and better understand how users interact with our services.

The processed information may include:

  • truncated IP address,
  • browser information,
  • device information,
  • session information,
  • interaction data,
  • click paths,
  • duration of visits,
  • navigation behaviour.

We use Google Analytics 4. IP addresses are not logged and not permanently stored.

The processing takes place only after your explicit consent.

Legal basis: Sec. 25 (1) TDDDG, Art. 6 (1) (a) GDPR.

You may withdraw your consent at any time with future effect.

 

18. Meta Pixel

Subject to your consent, we use Meta Pixel.

Provider

Meta Platforms Ireland Limited
4 Grand Canal Square
Grand Canal Harbour
Dublin 2
Ireland

Meta Pixel enables us to analyse the effectiveness of advertising campaigns and improve our marketing activities.

The following information may be processed:

  • IP address,
  • browser information,
  • device information,
  • visited pages,
  • user interactions,
  • advertising-related data.

The processing helps us:

  • measure campaign performance,
  • optimise advertising efforts,
  • analyse user interactions,
  • improve website content.

The service is activated only after your consent.

Legal basis: Sec. 25 (1) TDDDG, Art. 6 (1) (a) GDPR.

 

19. Data Sharing

Personal data will only be disclosed where necessary and legally permissible.
Data may be shared, for example:

  • with processors acting on our behalf,
  • with shipping providers,
  • with financing providers,
  • with IT service providers,
  • due to legal obligations,
  • where consent has been provided.

Personal data will not be disclosed beyond these purposes unless another legal basis exists.

 

20. Categories of Recipients

Depending on the processing activity, personal data may be transferred to the following categories of recipients:

 

Hosting and IT Service Providers

  • Hosting providers

  • Technical service providers
  • System administrators
  • Security service providers

 

Shipping and Logistics Providers

  • DPD

  • UPS

 

Financing and Credit Assessment Providers

  • abcfinance GmbH

  • Credit agencies involved in financing procedures

 

Professional Advisors

  • Tax advisors

  • Auditors
  • Legal advisors

 

Public Authorities

  • Tax authorities

  • Regulatory authorities
  • Law enforcement authorities
  • Other legally authorised public bodies

Any transfer of personal data is limited to what is necessary for the respective purpose.

 

21. International Data Transfers

Certain services used within our online shop may involve the transfer of personal data to countries outside the European Union (EU) or the European Economic Area (EEA).

This may apply in particular to:

  • Google Analytics
  • Meta Pixel
  • Services provided by Google companies
  • Services provided by Meta companies

In such cases, personal data may be transferred to and processed on servers located outside the EU, including the United States.
Where such transfers take place, they are carried out only in accordance with the requirements of Articles 44 et seq. GDPR.

Appropriate safeguards may include:

  • Adequacy decisions issued by the European Commission
  • Standard Contractual Clauses (SCCs)
  • Additional technical and organizational protection measures
  • Other legally recognized transfer mechanisms

Google and Meta are certified under the EU-US Data Privacy Framework (DPF).
By adequacy decision of 10 July 2023, the European Commission determined that DPF-certified US companies ensure an adequate level of data protection (Art. 45 GDPR).
Standard Contractual Clauses may additionally be agreed as a supplementary safeguard.

We take reasonable steps to ensure that an adequate level of data protection is maintained whenever personal data is transferred internationally.
Further information regarding international data transfers is provided within the relevant service descriptions where applicable.

 

22. Retention Periods

We store personal data only for as long as necessary to fulfill the purposes for which the data was collected.
Following this period, personal data will be deleted unless statutory retention obligations require continued storage.

Retention periods depend on factors such as:

  • Nature of the contractual relationship
  • Legal obligations
  • Tax regulations
  • Commercial regulations
  • Warranty periods
  • Limitation periods under applicable law

 

Contract and Order Data

Contract-related documentation may be stored for up to ten years where required by commercial and tax legislation.

 

Accounting and Invoice Data

Invoice and accounting records may be retained for statutory retention periods.

 

Customer Accounts

Customer account data is generally retained as long as the customer account remains active.
Upon a valid deletion request, account data will be deleted unless legal obligations require continued storage.

 

Communication Data

Correspondence data may be retained for the duration necessary to process inquiries and comply with legal obligations.

 

Log Data

Technical server log files are generally deleted after 7 days, unless a security-relevant incident requires longer retention.

 

23. SSL/TLS Encryption

Our online shop uses SSL/TLS encryption technology to secure the transmission of confidential information.
Encrypted connections are typically indicated by:

  • a padlock symbol in your web browser,
  • the use of “https://” in the address bar.

SSL/TLS encryption helps protect:

  • login credentials,
  • customer account information,
  • order information,
  • payment-related information,
  • communication submitted through our website.

The encryption reduces the risk of unauthorized access, disclosure or manipulation of transmitted data.

 

24. Data Security

We implement appropriate technical and organizational measures to protect personal data against:

  • accidental loss,
  • destruction,
  • unauthorized access,
  • unauthorized disclosure,
  • manipulation,
  • unlawful processing.

Security measures may include:

  • access control systems,
  • authorization concepts,
  • encrypted communications,
  • regular data backups,
  • malware protection,
  • secure hosting environments,
  • regular security updates.

These measures are continuously reviewed and updated in accordance with technological developments and current security requirements.
Despite all reasonable precautions, complete security of data transmissions via the Internet cannot be guaranteed.

 

25. Data Subject Rights

Under the GDPR, you have the following rights concerning your personal data.

Right of Access

You have the right to obtain confirmation as to whether personal data concerning you is being processed and, where that is the case, access to such data.

Legal basis: Art. 15 GDPR

Right to Rectification

You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.

Legal basis: Art. 16 GDPR

Right to Erasure

You have the right to request the deletion of personal data where the legal requirements are fulfilled.

Legal basis: Art. 17 GDPR

Right to Restriction of Processing

You may request the restriction of the processing of your personal data in certain circumstances.

Legal basis: Art. 18 GDPR

Right to Data Portability

You have the right to receive personal data concerning you in a structured, commonly used and machine-readable format or to request its transfer to another controller.

Legal basis: Art. 20 GDPR

Right to Object

You have the right to object to the processing of your personal data under certain circumstances.

Legal basis: Art. 21 GDPR

Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time with future effect.
Such withdrawal will not affect the lawfulness of processing carried out before the withdrawal.

 

26. Right to Lodge a Complaint

If you believe that the processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with a competent supervisory authority.
You may lodge your complaint with:

  • the supervisory authority at your place of residence,
  • the supervisory authority at your place of work,
  • or the supervisory authority responsible for the location of the alleged infringement.

Legal basis: Art. 77 GDPR

 

27. Right to Object

Where personal data is processed on the basis of Art. 6 (1) (e) or Art. 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
If you object, we will no longer process your personal data unless:

  • we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or
  • the processing serves the establishment, exercise or defense of legal claims.

 

Direct Marketing

Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time.
In this case, personal data will no longer be processed for direct marketing purposes.

 

28. Newsletter

You may subscribe to our newsletter.
For sending the newsletter, we process your e-mail address.

Subscription uses a double opt-in procedure: after signing up, you will receive an e-mail containing a confirmation link.
Your e-mail address is added to the mailing list only after confirmation.
We log the subscription and the confirmation in order to be able to demonstrate consent.

Legal basis: Art. 6 (1) (a) GDPR (consent).

You may unsubscribe at any time via the unsubscribe link contained in every newsletter e-mail, in your customer account, or by e-mail to vet@moeckundmoeckshop.de.
Unsubscribing withdraws your consent with future effect.

Your e-mail address will be removed from the mailing list after unsubscribing, unless statutory documentation obligations require further storage.

 

29. Updates to this Privacy Policy

We reserve the right to amend this Privacy Policy whenever necessary.
Updates may become necessary due to:

  • changes in applicable legislation,
  • changes in regulatory requirements,
  • technical developments,
  • introduction of new services,
  • modifications of our business processes.

The version published on the website at the time of your visit shall apply.
We therefore recommend reviewing this Privacy Policy regularly to stay informed about current data protection practices.

 

Status: July 2026