Skip to content

Privacy policy

This translation is provided for ease of understanding. The German version is the authoritative one. This site works without an account, without registration and without ad networks. Whatever data does arise is set out here — in full, and in the order in which it happens.

01Controller

The controller for the data processing on this website within the meaning of the GDPR is:

CIO LENA GmbHChristinenstr. 1540880 RatingenDeutschlandinfo@ciolena.de02102-5655080

No data protection officer has been appointed; the conditions of § 38 BDSG (Section 38 of the German Federal Data Protection Act) are not met.

02First things first

  • There is no account and no registration.
  • There is no Google Analytics, no Facebook pixel and no ad network.
  • Fonts and scripts are held on our own server, not at Google.
  • There is no cookie banner, because there is nothing that would need consent.
  • The saved list and the packing list stay in the browser and are not uploaded anywhere.
  • Product images come from Amazon servers — that is the one point at which data goes to another company simply by opening a page. More on that below.

03Opening the site: server logs

When a page is opened, the browser transmits technical data to the host's server, which stores it in log files:

  • the address requested
  • the date and time of the request
  • the amount of data transferred and a message on whether the request succeeded
  • browser type and version, operating system
  • the page visited before (referrer)
  • IP address

This data is not merged with other data sources and serves the secure, trouble-free operation of the site. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in being able to deliver the site and fend off attacks.

The host deletes the logs itself after a short time; the operator does not evaluate them.

04Hosting

The site is held by a service provider that makes it technically available:

Hostinger International Ltd.61 Lordou Vironos Street, 6023 Larnaca, Zypern

A data processing agreement pursuant to Art. 28 GDPR is in place with the host. The host processes the data named above solely on instruction and for the operation of the site.

05Product images from Amazon

The images of the products presented here are not held on our own server; they are loaded directly from Amazon servers when displayed (m.media-amazon.com and images-eu.ssl-images-amazon.com).

This means: as soon as a page with product images is opened, Amazon learns the visitor's IP address, the browser type and the address of the page opened. This happens automatically as the page loads — not only when a product is clicked. Whether Amazon links this data to an account held there is beyond the operator's knowledge.

The reason for embedding them this way is the terms of participation of the Amazon partner programme: product images may only be embedded the way Amazon delivers them, so that they stay current and follow any changes in price or packaging.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in presenting the products and in keeping to the programme terms, without which the site would lose its funding.

Amazon also processes data in the United States. Amazon Europe Core S.à r.l. and Amazon.com Inc. base the transfer on the standard contractual clauses of the EU Commission. Further details in Amazon's privacy notice: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010

Anyone who wants to avoid this can block the loading of external images in the browser or through an extension. The site then remains fully usable; an empty area appears where the images would be.

06Redirect to Amazon (partner links)

Every click on a product leads first to the file go.php on our own server and from there straight on to Amazon. The address at Amazon contains the operator's partner tag, by which Amazon attributes an order to the recommendation.

What go.php writes down in the process: the short code of the product, its category, the Amazon marketplace and the time. What go.php expressly does not write down: IP address, browser identifier and any detail by which an individual visitor could be recognised again.

As soon as the redirect arrives at Amazon, Amazon's terms apply. Amazon usually sets a cookie there in order to attribute the recommendation to a later order. The operator has no influence over this.

The legal basis for our own counting is Art. 6(1)(f) GDPR — the legitimate interest in knowing which recommendations are taken up.

07Our own reach measurement

Besides the redirects, the site counts how often an item is put on the saved list, taken off again, and opened on Amazon from there. These events go to the file track.php on our own server.

Only the following are stored: the type of event, the short code of the product, its category, the language of the page, the marketplace, a quantity and the time.

Added to this is a random session identifier, which is held in the browser's session storage and disappears when the tab is closed. Its sole purpose is to tell apart several events from one visit, and it allows no conclusion about a person.

Neither IP address nor browser identifier nor any permanent identifier is stored. No merging across several visits takes place, and it would not be possible with this data either.

Because there is no person inside these counts, there is no deadline by which they would have to be deleted — they are kept as totals.

The legal basis is Art. 6(1)(f) GDPR. Since no identifier that outlasts the session is stored on the device, the measurement needs no consent under § 25 TDDDG (Section 25 of the German Telecommunications and Digital Services Data Protection Act).

08What is stored in the browser

The site puts a few details in the browser's local storage. These are not cookies: they are not sent along when a page is opened and they do not leave the device.

  • Saved list — which items have been saved, with quantity and the price at the time of saving
  • Packing list — which lines have been ticked off
  • Chosen festival — for the packing list and the rule check of the saved list
  • Session identifier — only in session storage, disappears with the tab

One exception to “does not leave the device”: the session identifier is passed along with the counting events described in the previous section.

There is one cookie after all, and it should not be swept under the carpet here: the language choice. Switching the language at the top right stores it as the cookie “fc_locale” with a lifetime of one year. It holds nothing but the language code — “de”, “en”, “fr” or “nl” — and is sent with every request so the server can serve the right language version straight away instead of sending you to the front page first.

All of these details are needed for functions that are expressly wanted: whoever puts something on the saved list wants to find it there again, and whoever switches to French does not want to land on German on the next visit. Under § 25 Abs. 2 Nr. 2 TDDDG, no consent is required for this. That is also why there is no cookie banner on this site — there is nothing for it to ask about.

Everything can be deleted at any time: through the “Clear list” button, or “Reset” on the packing list, or by deleting the website data in the browser.

09Getting in touch

If you write an email, your details are stored in order to handle the enquiry. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR where there is a connection to a contract.

The messages are deleted as soon as they are no longer needed and no statutory retention obligation stands in the way.

10Rights of data subjects

The following rights exist vis-à-vis the controller:

  • access to the personal data stored (Art. 15 GDPR)
  • rectification of incorrect data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing based on a legitimate interest (Art. 21 GDPR)

A note in the interest of honesty: the site stores nothing that could be assigned to a person. A request for access to your data will therefore, as a rule, show that none is held here — unless you have written an email.

An informal message to the address given above is enough for any of these rights.

11Complaint to a supervisory authority

Independently of this, Art. 77 GDPR gives you the right to lodge a complaint with a data protection supervisory authority. The authority responsible is the one at your place of residence or work, or at the seat of the controller:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4, 40213 Düsseldorfhttps://www.ldi.nrw.de/

12Encryption

The site is delivered exclusively over HTTPS. Requests over HTTP are redirected to the encrypted connection.

13Changes

If something about the site changes, this policy changes with it. The version available here applies in each case; the date beneath it shows how current it is.

Last updated: 09 August 2026