Privacy policy

This website is operated by Lithos Natural GmbH (FN 461725h), hereinafter “we”, “us” and “LITHOS”, based in Ennsdorf. In this privacy policy, we as the data controller according to Art. 4 Para. 7 EU GDPR describe what data we collect when you visit our website and for what purpose we process this data. All relevant contact details can be found in point 10 of this privacy policy.

Since the protection of your personal data is of particular concern to us, we adhere strictly to the legal requirements of the Data Protection Act and the EU GDPR when collecting and processing your personal data.

In the following we will inform you in detail about the scope and purpose of our data processing as well as about your rights as the data subject. Therefore, please read our privacy policy carefully before you continue to use our website and, if necessary, give your consent to the data processing.

  1. Personal data

In principle, our website can be used without providing any personal data. However, there may be different regulations for the use of individual services, which we will point out to you separately.

Apart from the cookies described in detail below, we only collect and store the data that you provide to us yourself by entering it into our input masks or by actively interacting with our website in any other way.

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, your name, your address, your telephone number or your date of birth.

  1. Use of cookies

a) If you only use our website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you would like to visit our website, we collect the data listed below, which is technically necessary for us to display the website to you and to guarantee its stability and security in accordance with Art. 6 Para. 1 Clause 1 Item f EU GDPR:

IP address
Date and time of the request
Time zone difference to Greenwich Mean Time (GMT)
Content of the request
Access status / http status code
Amount of data transferred in each case
Website from which the request originates
Browser used
Operating system and its interface
Browser software language and version

b) In addition to the aforementioned data, cookies are stored on your computer when you use our website; these are small text files that are stored on your hard drive and assigned to the browser you are using and through which certain information is transmitted to the place that sets the cookie (in this case, by us). According to the current state of the art, cookies cannot run programmes or transfer data to your computer, but can only serve to make the Internet offer more user-friendly and effective.

c) Our website(s) use the following types of cookies, the scope and functionality of which are explained below:

Transient cookies

Transient cookies are automatically deleted when you close your browser. These include, in particular, session cookies, which store a so-called session ID with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognized when you return to our website. These session cookies are deleted when you log out or close the browser.

Persistent cookies

Persistent cookies are automatically deleted after a specified period, which can vary depending on the cookie. However, you can delete the cookies yourself at any time in your browser settings.

d) You can change your browser settings so that, for example, you refuse to accept third-party cookies or all cookies. In this case, however, we must point out that you may no longer be able to use all the functions of our website.

e) We also use cookies to identify you for subsequent visits if you have an account with us – otherwise you will have to log in again upon each visit.

f) The Flash cookies we use are not recorded by your browser, but by your Flash plug-in. We also use HTML5 storage objects that are stored on your end device. These objects store the required data regardless of the browser you use and do not have an automatic expiry date. You can prevent the processing of Flash cookies by installing the appropriate add-ons in your browser or by browsing in private mode.

   3. Collection and processing of personal data

Personal data that goes beyond the information stored by cookies will only be processed by us if you provide it to us voluntarily, for example if you register with us, enter into a contractual relationship with us or otherwise contact us. This data only includes contact details and information about the inquiries with which you approach us.

We use the personal data you provide exclusively within the extent to which it is required and/or permitted by law in order to fulfil the respective purpose of processing (e.g. registration, sending the newsletter, processing an order, sending information material and advertising, processing a competition, answering a question, enabling access to certain information) in particular pursuant to Art. 6 EU-GDPR (e.g. the sending of advertising and information material to existing customers).

The purpose of processing your data is the operation of our website and the targeted provision of company-specific information, including the presentation of our range of goods and services (marketing). Any further use of your data will only take place if you have previously provided your express consent. You can revoke your consent at any time for the future, as explained in detail below.

  1. Storage duration

We store data that you have made available to us exclusively for customer service or for marketing and information purposes for a period of three years after our last contact. However, if you wish, we will delete your data before this period expires, provided that there is no legal obstacle to this.

In the event of a contract initiation or conclusion, we process your personal data after the contract has been completed in full until the guarantee, warranty, statute of limitations and statutory retention periods applicable to us have expired, and also until the end of any legal disputes in which the data is needed as evidence.

  1. Newsletter

You have the option of subscribing to our free newsletter. With this newsletter, you will receive all the latest news and information about our company as well as customized advertising at regular intervals. In order to receive our newsletter, you need a valid email address.

We check the email address you enter in our registration mask to see whether you actually want to receive newsletters. We do so by sending you an email to the e-mail address you provided, the receipt of which you can then confirm by clicking on the link provided. After confirming the email address, you are registered for our newsletter (double opt-in).

When you first register for the newsletter, we save your IP address, the date and time of your registration. This is done for security reasons, in the event that a third party misuses your email address and subscribes to our newsletter without your knowledge. We do not collect or process any further data for the newsletter subscription; the data is used exclusively for subscribing to the newsletter.

Unless you object to this, we will transmit your data within our group for the purpose of analysis and for the transmission of information for advertising purposes. Within the group of companies, your data that you have made available to us in order to receive the newsletter will be compared with data that we may collect elsewhere (e.g. when purchasing goods or booking a service).

Your data for registering for the newsletter will not be passed on to third parties who do not belong to the group of companies. You can unsubscribe from our newsletter at any time. You will find the details on how to unsubscribe in the confirmation email and in each individual newsletter.

  1. Tools and applications used

a) We use Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. This service uses so-called “cookies” (see above). The information generated by cookies about your use of this website is usually transmitted to a Google server and stored there.

On our behalf, Google uses this information to evaluate your use of our website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

The storage of the cookies required by Google Analytics can be prevented by setting your browser software accordingly; however, this may lead to you being unable to fully use all functions of this website. You can prevent the data generated by the cookie and related to your use of the website (Including your IP address) from being collected and processed by Google by downloading and installing the browser plug-in available under the following link:

If you would like more information about the type, scope and purpose of the data collected by Google, we recommend that you read their privacy policy.

b) We also place links to other websites on our website; this is for informational purposes only. These websites are not under our control and therefore do not fall under the terms of this privacy policy. If you activate a link, it is possible that the operator of this website may collect data about you and process it in accordance with their data protection declaration, which may differ from ours.

c) Our website also offers the option of interacting with various social networks via plugins. These are:

Facebook, operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

Twitter, operated by Twitter Inc., 795 Folsom Street, Suite 600, San Francisco, CA 94107, USA

Google+, operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

LinkedIn, operated by LinkedIn Inc., 2029 Stierlin Court, Mountain View, CA 94043, USA

Youtube, operated by Youtube LLC, 901 Cherry Avenue, San Bruno, CA 94066 USA

XING, operated by XING SE, Dammtorstraße 30, 20354 Hamburg, Germany

If you click on a plugin of one of these social networks, it will be activated and a connection to the respective server of this network will be established. We have no influence on the scope and content of the data that is transmitted to the respective operator of this social network when you click on the plugin.

If you want to find out more about the type, scope and purpose of the data collected by the operators of these social networks, we recommend that you read the data protection regulations of the respective social network.

  1. Data transmission

A transfer of your data to third parties does not take place unless we are legally obliged to do so, the data transfer is necessary to carry out a contractual relationship concluded between us or you have previously provided your express consent to the transfer of your data. External processors or other cooperation partners only receive your data if this is necessary for the execution of the contract or if we have a legitimate interest in it. If one of our processors comes into contact with your personal data, we ensure that they comply with the provisions of the data protection laws In the same way as we do.

Your personal data will not be sold by us to third parties outside the group or marketed in any other way.

If our contractual partners or processors are based in a third country, i.e. a country outside the European Economic Area (EEA), we will inform you about the consequences of this circumstance in the description of the offer.

  1. Security

We use numerous technical and organizational security measures to protect your data against manipulation, loss, destruction and access by third parties. Our security measures are constantly being improved in line with technological developments on the Internet.

  1. Your rights

In accordance with the General Data Protection Regulation and the Data Protection Act, you as the data subject are entitled to the following rights and legal remedies:

Right to information (Article 15 EU GDPR)

As the data subject, you have the right to request information as to whether and, if so, which personal data is being processed about you. For your own protection – so that no third party receives information about your data – it may be necessary for us to verify your identity in a suitable form.

Right to rectification (Article 16) and erasure (Article 17 EU GDPR)

You have the right to immediately request the correction of incorrect personal data concerning you or – taking into account the purposes of data processing – the completion of incomplete personal data and the deletion of your data, provided that the criteria of Art. 17 EU GDPR are met.

Right to restriction of processing (Article 18 EU GDPR)

Under the legal requirements, you have the right to restrict the processing of all personal data collected. From the moment of the request for restriction, this data will only be processed with individual consent or to assert and enforce legal claims.

Right to data portability (Art. 20 EU GDPR)

You can request the unimpeded and unrestricted transfer of collected personal data to a third party.

Right to object (Art. 21 EU GDPR)

For reasons arising from your particular situation, you can object at any time to the processing of your personal data that is necessary to protect our legitimate interests or those of a third party. Your data will no longer be processed after the objection, unless there are compelling legitimate reasons for processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims. You can object to data processing for the purpose of direct advertising at any time with effect for the future.

Revocation of consent

If you have separately provided your consent to the processing of your data, you can revoke this at any time. Such a revocation affects the admissibility of the processing of your personal data after you have exerted it against us.

If you take action to enforce your above-mentioned rights under the GDPR, LITHOS must comment on the action requested or comply with the application immediately, but no later than one month after receipt of your application.

We will respond to all reasonable inquiries within the legal framework free of charge and as quickly as possible.

The data protection authority is responsible for requests relating to violations of the right to information, violation of the right to secrecy, rectification or erasure.