exocad Partner
Secure SSL connection
Tel: +49 (0) 7123 9595 146
Easy shopping

Privacy Policy

Last updated: 8 August 2026

Thank you for your interest in our website Dentoo. Protecting your personal data is important to us. Below we inform you, in accordance with the General Data Protection Regulation (GDPR), about the nature, scope and purpose of the processing of personal data.

1. Controller

PayFactory GmbH
– Brand: Dentoo –
Nürtinger Str. 6/4
72555 Metzingen
Germany

Phone: +49 (0)7123 9595 130
Fax: +49 (0)7123 959 7405
Email: info@dentoo.de

2. General Information on Data Processing

Personal data means any information relating to an identified or identifiable natural person. We process personal data exclusively in accordance with the applicable data protection legislation.

Where we obtain your consent for individual processing operations, Art. 6(1)(a) GDPR is the legal basis. Where processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract, Art. 6(1)(b) GDPR is the legal basis. Where processing is necessary for compliance with a legal obligation, it takes place on the basis of Art. 6(1)(c) GDPR. Where processing serves our legitimate interests or those of a third party, Art. 6(1)(f) GDPR is the legal basis, unless the interests or fundamental rights and freedoms of the data subject override those interests.

3. SSL / TLS Encryption

For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the string “https://” and the padlock symbol in your browser bar.

4. Data Collected When Visiting Our Website

When you use our website for information purposes only, server log data is processed automatically. This may include in particular:

  • pages visited and files retrieved,
  • date and time of access,
  • volume of data transferred,
  • referrer URL,
  • browser type and browser version,
  • operating system,
  • IP address, shortened or anonymised where applicable,
  • HTTP status code and technical error messages.

This processing serves the secure, stable and error-free provision of the website and the prevention of abusive access.

Legal basis: Art. 6(1)(f) GDPR.

5. Cookies and Consent Management

Our website uses cookies and comparable technologies. Cookies are small text files that are stored on your device or that access information already stored on your device.

Strictly necessary cookies and comparable access operations are used to the extent required to provide the digital service you have expressly requested. In these cases, the storage of information on your device or access to information already stored there takes place on the basis of Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). The subsequent processing of personal data takes place, depending on the purpose, on the basis of Art. 6(1)(b) or (f) GDPR.

Cookies and comparable technologies used for analytics, reach measurement, marketing, remarketing or external media are only used with your prior consent. The legal bases are Section 25(1) TDDDG for the storage of, or access to, information on your device and Art. 6(1)(a) GDPR for the subsequent processing of personal data.

You may withdraw a consent you have given at any time with effect for the future, or change your selection, via the privacy or cookie settings available on the website. The lawfulness of processing carried out up to the withdrawal remains unaffected.

In addition to cookies, we use your browser’s local storage in individual cases. Following your consent, the Dia chat assistant stores the current chat session and the conversation history there so that the conversation is not interrupted when you move to another page. This information remains on your device and is removed when the chat ends.

6. Contacting Us

If you contact us by email or via a contact form, we process the data you provide – in particular your name, contact details, the content of your message and any attachments – in order to deal with your enquiry.

Legal basis:
Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries;
Art. 6(1)(f) GDPR for all other enquiries.

7. Customer Account and Order Processing

When you register a customer account, place an order and during the performance of the contract, we process in particular master data, contact data, delivery, invoicing, order, contract and payment data, to the extent necessary for the performance of the contract.

Legal basis: Art. 6(1)(b) GDPR. Where retention obligations under commercial or tax law apply, processing additionally takes place on the basis of Art. 6(1)(c) GDPR.

8. Payment Service Providers

Depending on the payment method chosen, we transmit the data required for payment processing to the respective payment service provider. The payment service provider may process the data under its own data protection responsibility.

PayPal

PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
PayPal Privacy Statement

Ingenico / Worldline

Ingenico ePayments / Worldline
Daniel-Goldbach-Str. 17–19
40880 Ratingen, Germany

SEPA Direct Debit

If you choose SEPA direct debit, we process in particular the account holder’s name, the IBAN, the BIC where applicable, the mandate reference, the creditor identifier, invoice and due dates, collection amounts and status and return information from the bank. The processing serves to create and administer the direct debit mandate, to provide the pre-notification, to submit the direct debit, to record incoming payments and to handle returned direct debits.

For processing purposes, the required data may be transmitted to our account-holding bank, to the payment service providers involved, to clearing houses and to the payer’s bank.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR where statutory evidence and retention obligations apply.

9. Credit Assessment

Where certain payment methods are selected, or where there is a legitimate risk of default, we reserve the right to carry out a credit assessment to the extent permitted by law. For this purpose, the necessary identification and contract data may be transmitted to credit agencies.

  • SCHUFA Holding AG, Wiesbaden, Germany
  • Creditreform, Neuss, Germany

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in avoiding payment defaults and economic risks.

10. Newsletter

When you subscribe to our newsletter, we generally use the double opt-in procedure. In doing so, we process your email address, the time of subscription and confirmation, and technical evidence data. You can unsubscribe at any time using the unsubscribe link in the newsletter.

Legal basis: Art. 6(1)(a) GDPR. The logging of the record of consent takes place on the basis of Art. 6(1)(c) in conjunction with Art. 7(1) GDPR, or on the basis of Art. 6(1)(f) GDPR.

11. Web Analytics with Google Analytics 4

Following your consent, this website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited. Google Analytics serves to analyse the use of our website and to improve our offering. In this context, information about the pages visited, interactions, approximate location, browser, device, referrer, session duration and technical identifiers may be processed.

Google Analytics is only activated in accordance with your consent decision. Where cookies or comparable identifiers are stored or read, this takes place on the basis of Section 25(1) TDDDG. Any further processing takes place on the basis of Art. 6(1)(a) GDPR.

A transfer to Google LLC in the USA cannot be ruled out. Further information on transfers to third countries can be found in section 20.

Google Privacy Policy

12. Google reCAPTCHA

To protect our forms against misuse, spam and automated entries, we may use Google reCAPTCHA provided by Google Ireland Limited. The service is only activated following your consent. In this context, technical data, interactions with the website, IP address, browser and device data and other information required for risk assessment may be processed.

Legal bases: Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

A transfer to Google LLC in the USA cannot be ruled out. Further information on transfers to third countries can be found in section 20.

13. Google Maps

To display locations, we may integrate Google Maps provided by Google Ireland Limited. The service is only loaded following your consent. When it is called up, your IP address, browser and device data, location data and information about the page visited may in particular be processed.

Legal bases: Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

A transfer to Google LLC in the USA cannot be ruled out. Further information on transfers to third countries can be found in section 20.

14. YouTube

We may embed videos from the YouTube service provided by Google Ireland Limited. Where possible, the videos are embedded in extended data protection mode and are only loaded or played following your consent. In this context, IP address, browser and device data, the page visited and information about playback may in particular be processed.

Legal bases: Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

A transfer to Google LLC in the USA cannot be ruled out. Further information on transfers to third countries can be found in section 20.

15. Error and Stability Monitoring with Sentry

To detect, analyse and remedy technical errors we use the Sentry service provided by Functional Software, Inc. According to our configuration, application data is processed in the European data region. If a technical error occurs in your browser or while you are using our services, the error message, the time of the error, the page visited, technical process and log data as well as details of your browser, operating system and device may in particular be transmitted to Sentry. Depending on the type of error, the IP address may also be processed for technical reasons.

Sentry serves exclusively the purposes of error diagnosis, security and stability of our services. Under the current configuration, Sentry does not set any analytics or marketing cookies for this purpose. Wherever possible, we configure Sentry in such a way that no unnecessary personal content, form entries or payment data is transmitted in error reports.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and error-free operation of our website and applications.

Access by the US provider or by sub-processors engaged by it cannot be entirely ruled out. Further information on transfers to third countries can be found in section 20.

Sentry Privacy Policy

16. Google Ads – Conversion Tracking and Remarketing

Following your consent, this website uses Google Ads provided by Google Ireland Limited to measure the success of our advertisements and for remarketing purposes. Conversion tracking makes it possible to evaluate whether you carried out a particular action, such as placing an order or submitting an enquiry, after clicking on an advertisement. Remarketing makes it possible to build audiences in order to display interest-based advertising to you on other websites.

In this context, advertising and click identifiers, pages visited, referrer, conversion events, approximate location, IP address and browser and device data may in particular be processed. Depending on your consent and the technical configuration, cookies or identifiers such as _gcl_au and other Google advertising cookies may be used.

Google Ads is controlled via our consent management. Ad storage, the transmission of ad user data and personalised advertising are handled in accordance with your consent decision. Without the required consent, the marketing functions concerned are not activated.

Legal bases: Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

A transfer to Google LLC in the USA may take place. Further information on transfers to third countries can be found in section 20.

Google Privacy Policy

17. HubSpot – CRM, Forms and Marketing Analytics

We use HubSpot provided by HubSpot Ireland Limited as a customer relationship and marketing platform. HubSpot may be used to manage customer and prospect contacts, to process enquiries, to document communication, to evaluate forms and – subject to consent – to analyse the use of our website.

If you submit a form or contact us, your master and contact data, the content of your enquiry, company data, communication data and technical evidence data may in particular be processed in HubSpot. Where this processing is necessary in order to deal with an enquiry or to perform a contract, it takes place on the basis of Art. 6(1)(b) GDPR; for general customer relationship and organisational purposes it takes place on the basis of Art. 6(1)(f) GDPR.

HubSpot’s tracking and analytics functions are only activated following your consent. In this context, cookies or identifiers such as __hstc, hubspotutk, __hssc and __hssrc may be used and information about page views, sessions, referrer, browser and device may be processed.

Legal bases for tracking and analytics: Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

A transfer to HubSpot, Inc. in the USA may take place. Further information on transfers to third countries can be found in section 20.

HubSpot Privacy Policy

18. Meta Pixel

Following your consent, this website uses the Meta Pixel provided by Meta Platforms Ireland Limited. The Meta Pixel serves to measure the reach and success of our advertising and for remarketing purposes. It makes it possible to track whether visitors call up certain pages or carry out certain actions after viewing or clicking on a Meta advertisement. In addition, audiences can be built for interest-based advertising.

In this context, page views, interactions, conversion events, referrer, IP address, browser and device data and identifiers may in particular be processed. Depending on your consent and the technical configuration, the cookie _fbp may be used.

Legal bases: Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

With regard to the collection of data on our website and its transmission to Meta Platforms Ireland Limited, we and Meta are joint controllers within the meaning of Art. 26 GDPR to the extent provided for by law. The joint controllership relates in principle to the collection and transmission of the data by the Meta Pixel. Meta is generally solely responsible for the subsequent processing by Meta.

The allocation of data protection obligations follows from the controller addendum provided by Meta. Data subject rights may in principle be asserted against either joint controller. Under the agreement, Meta assumes responsibility in particular for handling data subject requests concerning the data processed by Meta after transmission.

A transfer to Meta Platforms, Inc. in the USA may take place. Further information on transfers to third countries can be found in section 20.

Meta Privacy Policy
Controller Addendum

19. Dia Chat Assistant and Live Chat with 3CX

Dia – AI-Powered Chat Assistant

Enquiries submitted through our chat window are first handled by “Dia”, an AI-powered assistant that we operate ourselves. Dia answers questions about products, prices and services and hands the conversation over to a member of our team if you request it or if your enquiry is more complex.

The chat only starts once you have entered your name and email address in the preceding form and expressly consented to the processing of this information for the chat. The data processed includes your chat messages and the conversation history so far, the language of the shop you are using, a technical session identifier, and the name and email address from the form. In addition, the usual server log data described in section 4 is generated.

Processing takes place on a server operated by us. Your browser does not communicate directly with the AI system: your message is passed from our shop server to our AI service, which searches a curated knowledge base covering our product range and generates the answer using a locally operated language model. Your name and email address are not passed to the language model; they remain within our shop system and are used solely to associate your enquiry and to forward it to our service team.

If the locally operated language model is temporarily unavailable, your enquiry is processed instead via Nebius AI Studio, a service provided by Nebius B.V., Netherlands. We have concluded a data processing agreement with this provider in accordance with Art. 28 GDPR; processing takes place in the region we have selected within the European Union. Only the content of the conversation and the related product context are transmitted – not your name or email address. The “zero data retention” setting is enabled for our account: the provider neither stores your inputs and the replies nor uses them to train AI models. Should a transfer to a third country occur in an individual case, it takes place on the basis of the European Commission’s standard contractual clauses; further information can be found in section 20.

On our AI server we store technical metadata for each chat: the session identifier, the language model used, whether the chat was handed over to a member of staff, the length of the enquiry and the reply, and the time and duration of the response. We delete this metadata after 90 days. During the chat, the conversation history is additionally held in your browser’s local storage and removed there when the chat ends.

In addition, we store the conversation histories in order to improve Dia. They show us which questions are asked frequently and where answers were incomplete or incorrect, and we then extend our knowledge base and the instructions given to the assistant. This evaluation is carried out by our staff; your chat content is not used for automated training of AI models. Before storage, we automatically remove recognisable contact details such as email addresses and telephone numbers. We delete the conversation histories after six months at the latest.

Legal basis for this evaluation: Art. 6(1)(f) GDPR. Our legitimate interest lies in improving our advisory services. You may object to this evaluation at any time; the contact details for doing so can be found in section 23.

When you end the chat or ask to be connected to a member of staff, Dia summarises the conversation. This summary is sent by email to our service team together with the conversation history and your name and email address, so that you do not have to explain your enquiry again. We delete these messages once your enquiry has been dealt with conclusively, unless statutory retention obligations apply; if the contact leads to an order or a contract, the retention periods under German commercial and tax law of up to ten years apply. When the conversation is handed over to the live chat, your name and email address are pre-filled in its form; you confirm the privacy notice shown there separately yourself.

Dia does not take automated decisions within the meaning of Art. 22 GDPR. The answers are generated automatically and may be incomplete or incorrect; binding information is provided by our staff. Please do not enter any special categories of personal data within the meaning of Art. 9 GDPR in the chat, in particular no patient or health data.

Legal bases:
Art. 6(1)(a) GDPR for the processing of the information you provide in the chat on the basis of your consent;
Section 25(1) TDDDG for storing the conversation history in the local storage of your device;
Art. 6(1)(b) GDPR where the chat serves to initiate or perform a contract;
Art. 6(1)(f) GDPR for technical logging to ensure stable operation and to protect against misuse.

You may withdraw your consent at any time with effect for the future by ending the chat; to have information already transmitted deleted, a message to the contact details given in section 23 is sufficient.

Live Chat with 3CX

For direct communication we offer a live chat based on the 3CX software. The chat widget is provided via a server instance operated or controlled by us. The script required to display it is delivered from our own infrastructure.

When the chat function is loaded, connection and server log data may be processed. The content of the chat, contact details you enter and other voluntary information are only processed once you actively use the chat function and confirm the privacy notice displayed there.

The processing serves to answer your enquiry, for customer communication and, where applicable, to take steps prior to entering into a contract or to perform a contract.

Legal basis:
Art. 6(1)(f) GDPR for the technical provision and general communication;
Art. 6(1)(b) GDPR for pre-contractual or contractual enquiries;
Art. 6(1)(a) GDPR where consent is expressly obtained for certain optional processing operations.

Chat data is only stored for as long as is necessary to deal with the enquiry, to document the communication and to comply with statutory retention obligations.

Dia in Your Customer Account

Once you’re logged into your customer account, you can ask our AI assistant, Dia, questions about your own transactions—such as invoices, open items, payments, orders, and shipments. Before providing such information for the first time, we’ll also ask for your customer number; it will be used solely to verify your logged-in account and will not be stored. Dia only accesses data associated with your account. The legal basis is Article 6(1)(b) of the GDPR (performance of the contract). We delete chat histories in which such information was provided after 30 days; the remaining histories are deleted after six months at the latest.

20. Transfers to Third Countries

In the case of individual services, personal data may be transferred to recipients outside the European Union and the European Economic Area, in particular to the USA.

Where the respective US recipient is effectively certified under the EU-U.S. Data Privacy Framework and the specific transfer is covered by that certification, the transfer may be based on the European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework. Otherwise, we use appropriate safeguards within the meaning of Art. 44 et seq. GDPR where necessary, in particular the European Commission’s standard contractual clauses and, where applicable, supplementary protective measures.

Even where safeguards are in place, processing in a third country may involve a residual risk that authorities there access data under national law and that European data subject rights cannot be enforced to the same extent.

21. Rights of Data Subjects

Within the scope of the statutory requirements, you have in particular the following rights:

  • access under Art. 15 GDPR,
  • rectification under Art. 16 GDPR,
  • erasure under Art. 17 GDPR,
  • restriction of processing under Art. 18 GDPR,
  • data portability under Art. 20 GDPR,
  • objection to processing based on Art. 6(1)(e) or (f) GDPR under Art. 21 GDPR,
  • withdrawal of consent given, with effect for the future, under Art. 7(3) GDPR,
  • lodging a complaint with a data protection supervisory authority under Art. 77 GDPR.

In the case of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing. This also applies to profiling to the extent that it is related to such direct marketing.

22. Retention Period

Personal data is only stored for as long as is necessary to fulfil the respective purposes. In addition, we store data where statutory retention, evidence or limitation periods apply. Once the purpose ceases to apply or the respective periods expire, the data is deleted or anonymised, unless there is another legal basis for the processing.

The specific retention period depends in particular on the nature of the enquiry, the contractual relationship, statutory retention obligations under commercial and tax law, the duration of any consent given, and the settings and retention rules of the services used.

For the chat assistant in detail: technical metadata relating to the use of the chat is deleted after 90 days, and the conversation histories evaluated for improvement purposes after six months at the latest. Summaries and conversation histories that reach us by email are deleted once your enquiry has been dealt with conclusively, unless statutory retention obligations apply.

23. Data Protection Contact

If you have any questions about the processing of your personal data or wish to exercise your rights, please contact:

info@dentoo.de