(Version 1.0, as of 29 October 2025)
Welcome to the data protection section of MAG Cosmetics GmbH. We are delighted that you are interested in our company. In the following data protection information, we would like to provide you with detailed information about when we collect which data and how it is processed.
The responsible party in accordance with Art. 4 (7) of the EU General Data Protection Regulation (GDPR) is:
MAG Cosmetics GmbH
Rötestraße 7
74321 Bietigheim-Bissingen
Managing Director:
Dr Silke Granzow
Telephone (0 71 42) 78 98 7-0
Fax (0 71 42) 78 98 7-111
info@mag-cosmetics.de
You can contact our data protection officer at:
Gesellschaft für Personaldienstleistungen mbH
Pestalozzistraße 27
34119 Kassel
Telephone: +49 561 220774 - 0
Email: datenschutz@gfp24.de
Website: https://www.gfp24.de
The following information provides you with transparent details on the type and scope of personal data processing
that takes place when you
The legal basis for our data protection is formed in particular by the provisions of the General Data Protection Regulation (GDPR) and the supplementary provisions of the Federal Data Protection Act (BDSG) and the Telecommunications and Digital Services Data Protection Act (TDDDG).
In cases where we obtain your consent for the processing of personal data, Article 6(1)(a) GDPR serves as the legal basis.
When processing personal data that is necessary for the performance of a contract concluded between you and us, Art. 6 (1) lit. b GDPR serves as the legal basis. This also applies to processing operations that are necessary for the implementation of pre-contractual measures.
In the event that the processing of personal data is necessary to fulfil a legal obligation to which we are subject, Art. 6 (1) lit. c GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) lit. d GDPR is the legal basis.
In the event that the processing of personal data is necessary to safeguard a legitimate interest of our company or a third party and your interests, fundamental rights and freedoms do not outweigh the former interest, Art. 6 para. 1 lit. f GDPR is the legal basis for the processing.
If cookies or similar technologies are used for data processing, these are stored or accessed on the user's end device (e.g. device fingerprinting) in accordance with Section 25 (1) TDDDG in conjunction with Article 6 (1) (a) GDPR.
If the use of cookies is absolutely necessary, this is done on the basis of Section 25 (2) sentence 2 TDDDG.
If, in the course of our processing, we transfer your personal data to other parties or disclose it to them, this will only be done on the basis of one of the legal grounds mentioned above. The recipients of this data may include, for example, payment service providers in the context of contract fulfilment. In cases where we are required to do so by law or court order, we must transfer your data to authorities entitled to receive such information.
If external service providers support us in processing your data (e.g. data analysis), this is done within the framework of order processing in accordance with Art. 28 GDPR. In doing so, we only conclude corresponding contracts with service providers who offer sufficient guarantees that appropriate technical and organisational measures are in place to ensure the protection of your data.
Data will only be transferred to third countries (outside the European Union or the European Economic Area) in accordance with the statutory provisions. Subject to express consent or transfer required by contract or law, we only process or allow the data to be processed in third countries with a recognised level of data protection (e.g. adequacy decision of the European Commission pursuant to Art. 45 (1) sentence 3 GDPR for the ‘EU-US Data Privacy Framework’ https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en) or in accordance with Art. 44 ff. GDPR on the basis of special guarantees, such as contractual obligations through so-called standard protection clauses of the EU Commission (information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
As soon as the respective purpose for storage no longer applies, we will delete or block your personal data. Furthermore, your personal data will only be stored if specific statutory retention periods (in particular commercial and tax law retention obligations) at national or European level prevent deletion.
Our privacy policy is based on terms used and defined in the GDPR. To ensure that our privacy policy is easy to read and understand, we would like to explain the most important terms in advance.
‘Personal data’ is any information relating to an identified or identifiable natural person (hereinafter referred to as ‘data subject’). A natural person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
‘Processing’ means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or other forms of provision, alignment or combination, restriction, erasure or destruction.
The ‘responsible party’ is the natural or legal person, authority, institution or other body that, alone or jointly with others, decides on the purposes and means of processing personal data. If the purposes and means of such processing are prescribed by Union law or the law of the Member States, the responsible party or the specific criteria for their designation may be provided for by Union law or the law of the Member States.
‘Pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
A ‘processor’ is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.
‘Recipients’ means any natural or legal person, public authority, agency or another body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
A ‘third party’ is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or processor, are authorised to process personal data.
‘Consent’ means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
‘Profiling’ means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
The processing of personal data gives you, as a data subject, certain rights that you can exercise at any time.
These are:
• Right to withdraw a declaration of consent under data protection law in accordance with Art. 7(3) GDPR
• Right to information about your personal data stored by us in accordance with Art. 15 GDPR
• Right to correction of incorrect data or completion of incomplete data in accordance with Art. 16 GDPR
• Right to deletion of your data stored by us in accordance with Art. 17 GDPR
• Right to restriction of processing of your data in accordance with Art. 18 GDPR
• Right to data portability in accordance with Art. 20 GDPR
• Right to object in accordance with Art. 21 GDPR
• Automated individual decision-making, including profiling, in accordance with Art. 22 GDPR.
You have the right to find out from us whether and, if so, which personal data we process about you, and to request copies of your personal data from us. Please note that your right to information may be restricted under certain circumstances in accordance with legal regulations.
If the information concerning you is no longer accurate, you have the right to request the immediate rectification of inaccurate personal data concerning you and, where applicable, the completion of incomplete personal data.
In accordance with legal requirements, you have the right to request that data concerning you be erased immediately, e.g. if the data is no longer required for the purposes pursued and the legal retention and archiving regulations do not prevent erasure.
Right to restriction of processing
Within the framework of the provisions of Art. 18 GDPR, you have the right to request a restriction on the processing of data concerning you, e.g. if you have lodged an objection to the processing, for the duration of the examination of whether the objection can be upheld.
Within the framework of the provisions of Art. 18 GDPR, you have the right to request a restriction on the processing of data concerning you, e.g. if you have lodged an objection to the processing, for the duration of the examination of whether the objection can be upheld.
You have the right to have data that you have provided to us handed over to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done if it is technically feasible.
If the processing of your personal data is based on consent given to us, you have the right to revoke this consent at any time. The revocation does not affect the legality of the processing carried out on the basis of the consent until the revocation.
You can send your revocation informally to [name of company, address, email address]. We would like to point out that your objection may also be made in further procedures or may have to be made for technical reasons. Further information on this can be found in the services described.
Under the conditions of Article 21(1) GDPR, data processing based on Article 6(1)(e) or (f) GDPR may be objected to for reasons arising from your particular situation. This also applies to profiling based on these provisions. If you exercise your right to object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Please send your objection informally to [name of company, address, email address]. We would like to point out that your objection may also be made in further proceedings or may be necessary for technical reasons. Further information on this can be found in the services described.
Under the conditions of Article 21(1) GDPR, data processing based on Article 6(1)(e) or (f) GDPR may be objected to for reasons arising from your particular situation. This also applies to profiling based on these provisions. If you exercise your right to object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Please send your objection informally to [name of company, address, email address]. We would like to point out that your objection may also be made in further proceedings or may be necessary for technical reasons. Further information on this can be found in the services described.
In accordance with Art. 77 GDPR, you have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data is not lawful. The address of the supervisory authority responsible for our company is:
The State Commissioner for Data Protection and
Freedom of Information Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Tel.: 0711/615541-0
Email: poststelle@lfdi.bwl.de
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
When using the website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. When you view our website, we collect the data listed below. This data is technically necessary to display our website to you and to ensure the stability and security of the display. The legal basis for storing information in the form of cookies or in the server log file on your end device or for accessing this information on your end device is Section 25 (2) No. 2 TDDDG. The associated data processing is based on Art. 6 (1) lit. f GDPR:
• IP address
• Date and time of the request
• Time zone difference to Greenwich Mean Time (GMT)
• Content of the request (specific page)
• Access status / HTTP status code
• Amount of data transferred in each case
• Website from which the request originates
• Browser
• Operating system and its interface
This data is temporarily stored in our system's log files for a maximum of 30 days. Storage beyond this period is possible, but in this case the IP addresses are partially deleted or anonymised so that it is no longer possible to identify the requesting client.
In addition to the aforementioned data, cookies are stored on your device (e.g. PC, laptop, smartphone) when you use our website. Cookies are small text files that are stored on your device and assigned to the browser you are using, and through which certain information flows to the entity that sets the cookie (in this case, us). Cookies cannot execute programms or transfer malware to your device. They serve to make the online offering more user-friendly and effective overall.
This website uses the following types of cookies, the scope and functionality of which are explained below:
Transient cookies are automatically deleted when you close your browser. These include, in particular, session cookies. These store a so-called session ID, which can be used to assign various requests from your browser to the shared session. This allows your computer to be recognised when you return to our website. Session cookies are deleted when you log out or close your browser.
Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. You can delete cookies at any time in your browser's security settings.
We use cookies on our website that are generated by us as the website operator and are necessary for the full functionality and presentation of our website. The legal basis for storing information in the form of cookies on your end device or accessing this information on your end device is Section 25 (2) No. 2 TDDDG. We use these cookies on the basis of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR to ensure the provision of our online services.
If, in addition to the cookies set by us as the controller, cookies offered by other providers are also used, processing is based on your consent in accordance with Art. 6 (1) lit. a and Section 25 (1) TDDDG (storage of cookies or access to information in a terminal device (e.g. via device fingerprinting). Further information on the use of and cooperation with external service providers can be found in the data protection information for the respective online offerings.
You can configure your browsers settings according to your preferences and, for example, refuse to accept cookies from external providers or even all cookies. However, we would like to point out that this may mean that you will not be able to use all the functions of this website. If you have agreed to accept cookies and would like to revoke this consent in future, you can delete the stored cookies in the settings of your browser.
Web browsers can be set to notify you when cookies are set or to reject or deactivate cookies in general or in part. By deactivating and deleting all cookies, you can also revoke any consent you have previously given. If you deactivate or restrict cookies using your browser, various functions on our website may not be available to you. You can delete stored cookies at any time using your web browser, including automatically.
You can find out more about these options for the most commonly used browsers via the following links:
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-informationen-websites-auf-ihrem-computer
Google Chrome: https://support.google.com/chrome/bin/answer.py?hl=de&answer=95647
Apple Safari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
Microsoft Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Microsoft Edge: https://support.microsoft.com/de-de/help/4027947/microsoft-edge-delete-cookies
Opera: https://help.opera.com/de/latest/web-preferences/
If no restrictions have been made to the cookie settings, cookies that enable and ensure the necessary technical functions will remain on your device until you close your browser; other cookies may remain on your device for longer. The exact cookie durations are displayed [in the consent banner / under cookie settings / for the respective services used].
Our website uses TLS encryption (formerly SSL) for security and protection during the transmission of confidential content. Orders or contact enquiries that you send to us are therefore encrypted during transmission. Depending on your browser type, you can recognise this either by the padlock symbol and/or the https protocol in the address bar.
We host our website externally. The personal data collected on this website is stored on the servers of the host/hosts. This may include all information relating to users of our online services that is generated in the course of use and communication, such as content data (e.g. entries in online forms); usage data (e.g. websites visited, access times); meta/communication data (e.g. device information, IP addresses).
We collect the aforementioned data in order to ensure the secure, fast and efficient provision of our online services. The legal basis for storing information in the form of cookies on your end device or accessing this information on your end device is Section 25 (2) No. 2 TDDDG. The associated processing of your data is carried out in accordance with Art. 6 (1) lit. f GDPR on the basis of our legitimate interest in the correct presentation and functionality of our website.
We have also concluded a contract for commissioned data processing (AV). This contract regulates the scope, type and purpose of the access options of the above-mentioned provider(s) to the data. The access options are limited to the access necessary to fulfil the hosting services and in compliance with the GDPR.
We use a consent management platform (CMP) to ensure that consent to store information on users' end devices or to access such information (e.g. cookies) is obtained and managed in accordance with data protection regulations.
This tool helps us to comply with legal requirements (in particular under the GDPR and TDDDG) by informing you about the technologies used when you first visit our website, offering you choices and documenting your preferences.
The following categories of personal data are processed when using the CMP:
• Your selection (consents and revocations)
• Time of consent
• Technical information (e.g. IP address in abbreviated/anonymised form, browser type, operating system)
• Possibly unique cookie IDs to recognise your preferences on subsequent visits
The consent data is usually stored locally in your browser (via cookie or local storage) and logged on the providers' servers in order to fulfil the obligation to provide evidence in accordance with Art. 7(1) GDPR.
The CMP provider necessarily obtains knowledge of the above-mentioned data to the extent necessary for the provision of consent management. When selecting the provider, we ensure an appropriate level of data protection and, where necessary, have concluded a data processing agreement in accordance with Art. 28 GDPR. The data will not be disclosed to other third parties. If data processing takes place in part in third countries, an adequate level of data protection is ensured by appropriate safeguards such as EU standard contractual clauses.
The legal basis is the fulfilment of legal obligations in accordance with Art. 6(1)(c) GDPR in conjunction with Art. 7 GDPR and § 25 TTDDG. We also have a legitimate interest in the legally compliant management of consents (Art. 6(1)(f) GDPR).
Your consent decision will be stored for as long as is necessary to fulfil the documentation requirements or until you delete the stored data in your browser.
You can assert your rights (information, correction, deletion, etc.) both against us and against the CMP provider. Please note that we do not have full access to the data stored by the provider.
When you contact us by email and/or telephone, we store the personal data you provide (your email address, your name if applicable, your telephone number and the content of your message) in order to process your enquiry. We do not pass on this data without your consent.
Data processing is carried out on the basis of Art. 6 (1) lit. b GDPR, provided that your enquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, we process your data on the basis of your consent in accordance with Art. 6 (1) (a) GDPR and/or on the basis of our legitimate interests in accordance with Art. 6 (1) (f) GDPR. Our legitimate interest lies in particular in the effective processing of your request.
The data you send us via contact requests will remain with us until you request us to delete it, revoke your consent to its storage, or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions – in particular statutory retention periods – remain unaffected.
We use various tools for online meetings. We use these tools to enable efficient communication regardless of location.
When using these tools, personal data is processed, in particular to enable participation in meetings, organise communication and document results. In some cases, processing also takes place outside the EU/EEA. When selecting providers, we ensure that appropriate data protection standards are in place and, where necessary, we have concluded data processing agreements and implemented appropriate safeguards such as EU standard contractual clauses.
The following categories of personal data may be processed in the course of use:
User information: Name (freely selectable), email address, telephone number (optional), department, profile picture (optional)
Meeting metadata: Topic, description, date, time, duration, participant IP addresses, device/hardware information
Content data: Text, audio and video data, screen transmissions, uploaded files, chat messages
Recordings (optional): video and audio recordings, chat logs, survey results
Telephone dial-in (optional): telephone number, country code, start and end time, additional connection data if applicable
Recordings will only be made after explicit notification and with your consent. You can deactivate the microphone, camera and chat functions at any time.
We do not disclose personal data processed in connection with participation in online meetings to third parties unless such disclosure is necessary for the purpose of the meeting (e.g. to share content with other participants) or required by law.
The respective providers of the tools necessarily become aware of the aforementioned data to the extent that this is provided for in the context of order processing agreements. In addition, data may be transferred to third countries if this is technically necessary in connection with the use of the services.
When using the video conferencing tools we employ, it cannot be ruled out that personal data may also be transferred to servers of service providers in third countries (outside the EU/EEA) and processed there. In such cases, we ensure that the recipient either has an adequate level of data protection (e.g. through an adequacy decision by the EU Commission) or that suitable safeguards are in place, such as, in particular, the conclusion of EU standard contractual clauses in accordance with Art. 46(2)(c) GDPR.
If you would like more detailed information about the safeguards used or would like to receive a copy of the standard contractual clauses, you can contact us at any time (see above for contact details).
• Performance of contracts or pre-contractual measures (Art. 6(1)(b) GDPR)
• Legitimate interests in efficient communication (Art. 6(1)(f) GDPR)
• Consent, where necessary (Art. 6(1)(a) GDPR)
• In the context of employment, § 26 BDSG (Federal Data Protection Act) where applicable
The data collected will generally be deleted as soon as the purpose of processing no longer applies and there are no legal retention obligations to the contrary.
There will be no recording of the ‘online meetings’. If we do wish to record individual meetings, we will inform you in advance and obtain your consent.
You can assert your rights (information, correction, deletion, etc.) both against us and against the respective provider. Please note that we do not have full access to the data stored by the provider.
Microsoft Teams
Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA
Privacy policy: https://privacy.microsoft.com/de-de/privacystatement
Further information: https://www.microsoft.com/de-de/trust-center/privacy/customer-data-definitions
Microsoft is certified under the EU-US Data Privacy Framework: Data Privacy Framework
TeamViewer
Provider: TeamViewer Germany GmbH, Jahnstr. 30, 73037 Göppingen, Germany
Privacy policy: https://www.teamviewer.com/de/datenschutzerklaerung/
We use the information you provide within the framework of the whistleblower system for purposes including the verification and documentation of reports, for internal investigations (including disclosure to external lawyers, auditors or other professionals who are bound by professional secrecy, as well as to affected group companies) and, if necessary, for disclosure to government agencies (such as the police, public prosecutor's office or courts).
We guarantee all whistleblowers confidential treatment.
The legal basis is the fulfilment of legal obligations pursuant to Art. 6 (1) (c) GDPR.
We provide you with free internet access in the form of Wi-Fi access (‘guest Wi-Fi’) in our business premises. Below, we provide information about the personal data collected in this context.
Data processing is carried out for the purpose of providing guest Wi-Fi and ensuring smooth use by our guests. Processing is necessary for the performance of a contract (provision of internet access via guest Wi-Fi) in accordance with Art. 6(1)(b) of the GDPR.
Furthermore, we process your data to protect our legitimate interests pursuant to Art. 6 (1) lit. f GDPR. Our legitimate interests lie in ensuring the security of our information technology systems and in defending against liability claims in the event of non-compliant use of the guest Wi-Fi.
When using our guest Wi-Fi, the MAC address and the hostname of your device are stored in this context. In addition, each device is assigned its own IP address.
The data is provided to us directly by our guests when they register for the guest Wi-Fi.
We do not share your personal data with third parties. Your data will only be disclosed or transferred insofar as this is necessary for the performance of a contract, is based on a legal requirement, there is a legitimate interest, or you have given your prior consent.
If external service providers (e.g., IT service providers) assist us in processing your data, this is done within the framework of data processing agreements in accordance with Art. 28 GDPR. We only conclude such agreements with service providers who offer sufficient guarantees that appropriate technical and organizational measures are in place to ensure the protection of your data.
No data is transferred to third countries, nor is such a transfer intended.
We regularly delete the data, but no later than after 30 days, unless a longer storage period is required by law or is necessary for the establishment, exercise, or defense of legal claims.
The provision of personal data concerning the data subject is technically required for the use of the guest Wi-Fi. Without this data, you will not be able to use our guest Wi-Fi.
The following information explains how we handle your data when you contact us, when contract negotiations take place, and/or when a contractual relationship exists with us.
Data processing is carried out for the purpose of contract performance. The processing of your data is necessary pursuant to Art. 6(1)(b) GDPR for the initiation and fulfillment of contracts.
Furthermore, the processing of your personal data may be necessary on the basis of Art. 6(1)(f) GDPR in order to safeguard our legitimate interests. Our legitimate interests include avoiding financial losses through credit checks, asserting legal claims and avoiding legal disadvantages (e.g., in cases of insolvency), preventing risks and liability claims, minimizing legal risks, and preventing criminal offenses.
We process the following categories of data:
Master and contact data: title, first and last name, department and position within the company, address, email address, telephone number, fax number, date of birth, purchase history, contract data, and billing data.
The data from the above-mentioned categories has been provided to us directly by our customers and prospective clients.
We do not share your personal data with third parties. Exceptions apply to our service partners if this is necessary for the performance of the contract, such as banks for the collection of direct debits, etc.
The data stored about you will be deleted after fulfillment of the contract, unless statutory retention obligations apply. Such obligations may arise, for example, under commercial and tax law. In such cases, the data will be deleted after ten years in accordance with legal requirements, unless longer retention periods are prescribed or required for legitimate reasons.
If you withdraw your consent to the use of your data, it will be deleted immediately, unless the above-mentioned reasons prevent deletion.
You have the right to object to the processing of your data. You may object to the use of your data at any time with effect for the future.
The provision of personal data is contractually required or necessary for the conclusion of a contract. If the required personal data is not provided, this would result in our inability to enter into a business relationship with you.
private label
hair competence
made in germany