Wish list

Print

Do you need progressive lenses, distance spectacles or are computer spectacles the better solution?

Spectacles consultant

Do you need progressive lenses, distance spectacles or are computer spectacles the better solution?

You can attach your wish list directly to your appointment booking.

Privacy Policy

Preamble

Data protection and information security are part of our corporate policy. Rodenstock takes the protection of your personal data very seriously and is committed to treating it confidentially and in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. In the following, we would therefore like to inform you which of your personal data we collect when you visit our website and for what purposes it is used. The terms used are not gender specific.

1. Responsible body and data protection officer
Responsible for the processing of personal data on the website is:

Rodenstock GmbH
Elsenheimerstrasse 33
D - 80687 Munich
Tel.: 089-7202-0
E-Mail: info@rodenstock.com

If you have any questions regarding the processing of your personal data, as well as your rights regarding data protection, please contact:

Rodenstock GmbH
- Data Protection Officer -
Elsenheimerstrasse 33
D - 80687 Munich
Tel.: 089-7202-0
E-Mail: privacy@rodenstock.com

2. Hosting 
We have commissioned SpaceNet AG, Joseph-Dollinger-Bogen 14, 80807 Munich, Germany to host our website. We have concluded the data processing agreement required under data protection law with SpaceNet in accordance with Art. 28 GDPR. According to this agreement, SpaceNet is obligated to ensure the necessary protection of your data and to process it exclusively on our behalf and in accordance with our instructions, in compliance with the applicable data protection regulations. Further information about SpaceNet can be found on the website: https://www.space.net/.  

3. The nature and purposes of and the legal basis for data processing
We process personal data that we collect about you in the course of using our website or our business relationship, e.g. your contacting us.

a) Access data 
Each time you use our website, we collect the access data that your browser automatically transmits to enable you to visit the website. The access data includes in particular:
• Client IP address of the requesting device
• Date and time of the request - address of the website accessed and the requesting website
• Details of the browser and operating system used
• Online identifiers (e.g. device identifiers, session IDs)

The data processing of this access data is necessary to enable the visit of the website and to ensure the permanent functionality and security of our systems. The access data is also temporarily stored in internal log files for the purposes described above in order to compile statistical information on the use of our website, to further develop our website with regard to the usage habits of our visitors (e.g. if the proportion of mobile devices used to access the pages increases) and to generally maintain our website administratively. The legal basis is Art. 6 para. 1 lit. b GDPR, if the page is accessed in the course of initiating or executing a contract, and otherwise Art. 6 para. 1 lit. f GDPR based on our legitimate interest in enabling the website to be accessed and ensuring the long-term functionality and security of our systems. 

The information stored in the log files does not allow any direct inference to your Person. The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended. 

Log file information is stored for a maximum of 7 days and then deleted or anonymized. Data whose further storage is required for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.

b) Contacting us / contact forms
You have various options for contacting us. These include the contact form and contacting us by e-mail. In this context, we process your data, such as your first and last name, your e-mail address and the content of your message,  exclusively for the purpose of communicating with you. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as your details are required to answer your inquiry or to initiate or execute a contract, and otherwise Art. 6 para. 1 lit. f GDPR due to our legitimate interest in you contacting us and us being able to answer your inquiry. We process the personal data received from you for contacting us only until we have conclusively answered your enquiry. Beyond that, we only store personal data for the assertion of or defense against legal claims or as long as there are legal obligations to store it. 

c) Registration 
As part of the registration process for optician, we collect and process the following data: customer number, invoice number, Email address and password. When you register for our services, we collect and process your customer number and invoice number to verify your identity and create a secure account. This processing is necessary  under Article 6 para. 1 lit. b GDPR (to provide our services) and for our legitimate interests in ensuring secure authentication (Article 6 para. 1 lit. f GDPR).  
We do not sell or share your data with third parties for marketing purposes. Your data is processed exclusively within our company and stored in compliance with GDPR. If any third-party service providers are involved (e.g., for hosting), they operate under strict data processing agreements ensuring compliance with GDPR.
We use Keycloak as our identity provider for authentication and user management. Keycloak is managed by Rodenstock GmbH and operates within our controlled infrastructure to ensure the security of your login credentials and personal information.

d) Integrated third-party services
Insofar as we integrate services of other providers (third parties) in the context of the use of our website in order to offer you certain content or functions (e.g. the playing of videos) and we process personal data in the process, this is done on the basis of Article 6 para. 1 lit. b and f GDPR. Such data processing is then necessary in order to implement the functions you have selected or to safeguard our legitimate interest in an optimal functional scope of the website. Insofar as cookies may be used within the scope of these third-party services, the explanations under point 2 lit. e apply. Please also refer to the data protection declaration of the respective provider with regard to the third-party services.

Services of other providers that we integrate or to which we refer are provided by the respective third parties. As a matter of principle, we have no influence on the content and function of the third-party services and are not responsible for the processing of your personal data by their providers, unless the third-party services are designed entirely on our behalf and then integrated by us under our own responsibility. Insofar as the integration of a third-party service leads to us establishing joint processes with its provider, we will stipulate with this provider in an agreement on joint responsibility pursuant to Art. 26 of the GDPR how the respective tasks and responsibilities for the processing of personal data are structured and who fulfils which data protection obligations.

Unless otherwise stated, profiles on social media are only included in our online offer as a link to the corresponding third-party services. After clicking on the integrated text/image link, you will be redirected to the offer of the respective social media provider. After the redirection, personal data may be collected directly by the third-party provider. If you log into your user account of the respective social media provider during this process, the provider may be able to assign the collected information of the specific visit to your personal user account. If you would like to prevent the collected information from being directly assigned to your user account, you must log out before clicking on the integrated text/image link. For information on how your personal data is handled when you use these websites, please refer to the respective privacy policies of the providers you use. 

e) Cookies and comparable technologies
In order to improve our website, we use cookies and comparable technologies that serve to communicate with your terminal device and exchange stored information (hereinafter collectively referred to as "cookies"). These cookies are primarily used to make the functions of our website usable. Accordingly, technically necessary cookies may be used by us to ensure the proper and secure operation of the website. The data processing is then carried out on the basis of Article 6 para. 1 lit. b GDPR for the execution of the contract (e.g. during registration) and in accordance with Art. 6 para. 1 lit. f GDPR, as it is necessary to implement the functions you have selected or to safeguard our legitimate interest in the functionality of the website.

If we also use cookies to analyze the use of the website and to target it to your interests and, if applicable, to provide you with interest-based content and advertisements, this will be done exclusively on the basis of your voluntary consent in accordance with Article 6 para. 1 a GDPR. You then have the option of accepting or rejecting individual or all cookies separately in our cookie consent solution by placing a tick next to the respective cookie or removing it and then clicking on "Save your settings". You can revoke your consent at any time with effect for the future.

If you do not wish to use cookies altogether, you can also prevent their storage by making the appropriate settings on your terminal device. You can delete stored cookies at any time in the system settings of your terminal device. Please note that blocking certain types of cookies can lead to impaired use of our website and the services we offer.

f) Analyse-Tools
Google Analytics [GA4]
We use Google Analytics, a web analysis service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (”Google”), on the basis of Art. 6 para. 1 lit. a GDPR for the purposes of analyzing, optimizing and economically operating our online offer. Google wills use this information on our behalf to evaluate the use of our website, to compile reports on website activity and to provide us with other services relating to website and internet use. We have added the code ”anonymizeIP“ to google analytics on our website. This means that user’s IP address is shortened within the EU or in other signatory states to the Agreement on the European Economic Area. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. 

You can prevent cookies from being stored by selecting the appropriate settings in your browser. You can also prevent the data generated by cookies about your use of the website from being passed to google, and the processing of these data by google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de

Further information about the use of data by Google and your opt-out options can be found here:

https://policies.google.com/technologies/partner-sites?hl=de 

Google Tag Manager
Our website uses Google Tag Manager. Google Tag Manager is a solution from Google Ireland Limited (” Google“), Gordon House, Barrow Street, Dublin 4, Ireland, that allows us to manage our website tags through a single interface (e.g. to integrate Google analytics 4 into our online offering).
The Taga Manager itself (which implements the tags) does not process any personal data of the users. The Google Tag Manager triggers other tags (cookies and pixels), which in turn may collect data under certain circumstances. We hereby draw your attention to this fact separately. If a user has disabled cookies at domain or cookie level, this will remain in a place for all tracking tags implemented with Google Tag Manager. The legal basis for the processing is your consent pursuant to Art. 6 para. 1 lit. a GDPR.

4. Disclosure of personal data to third parties and processors
As a matter of principle, we do not pass on any personal data to third parties without your consent. If, while processing, we nevertheless disclose your data to third parties, transmit it to them or otherwise grant them access to the data, this is also done exclusively on the basis of one of the aforementioned legal grounds. We transmit data to payment service providers, for example, if this is necessary for the performance of the contract. If we are obliged to do so by law or by court order, we must transfer your data to bodies entitled to receive information.

We use service providers to process your data in certain cases. If data is passed on within the scope of such commissioned processing, this is done based on Art. 28 GDPR.

5. Data transfer to third countries
The GDPR ensures an equally high level of data protection within the European Union. When selecting our service providers and cooperation partners, we therefore rely on European partners wherever possible if your personal data is to be processed. If we process data in a third country (i.e. outside the European Union or outside the European Economic Area) or the processing takes place in the context of the use of third-party services or the disclosure or transfer of data to other persons, bodies or companies, the transfer only takes place if the third country has been confirmed by the EU Commission as having an adequate level of data protection, an adequate level of data protection for your data has been guaranteed by contractual agreements with the data recipient (copy available on request) or we have been given your consent to do so or we are legally obliged to do so under applicable law.

6. Data storage
As a matter of principle, we only store personal data for as long as they are necessary for the purposes described in the section "Type and purposes as well as legal basis of data processing", this is necessary for the provision of our services to you, or we have a legitimate interest in the continued storage. In addition, we are subject to various storage and documentation obligations. Please note that retention periods vary from country to country and are determined in accordance with local legal and professional retention periods. Under certain circumstances, your data must also be retained for longer, e.g. if this is ordered by the authorities or a court.

Your registration data will be stored for as long as necessary to fulfill our contractual obligations or as required by applicable legal retention periods. If you request account deletion, we will securely erase your personal data unless legal obligations require continued storage.

7. Your rights
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
•    Right of objection: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. If the personal data concerning you are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.

  • Right of revocation for consents: You have the right to revoke any consent you have given at any time.
  • Right to information: You have the right to receive information about the data we have stored about you.
  • Right of correction and deletion: You can demand that we correct incorrect data and - insofar as the legal requirements are met - delete your data.
  • Restriction of processing: You can request us - provided the legal requirements are met - to restrict the processing of your data.
  • Data portability: If you have provided us with data on the basis of a contract or consent, you may, if the legal requirements are met, request that you receive the data you have provided in a structured, common and machine-readable format or that we transfer it to another responsible party.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular a supervisory authority in the Member State where you usually reside, the supervisory authority of your place of work or the place of the alleged infringement, in accordance with Article 77 of the GDPR, if you consider that the processing of personal data concerning you infringes the GDPR.

8. Data security
We take appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, use or alteration and against unauthorized disclosure or access. These are adapted to the current state of the art in each case. To secure the personal data you provide on our website, we use Transport Layer Security (TLS), which encrypts the information you enter.


9. Up-to-dateness and amendment of this privacy policy
Our privacy policy and also the descriptions in our cookie consent solution may change from time to time. This also includes further developments due to changes in our business as well as adjustments due to a changed legal situation and / or due to the implementation of new technologies or services on the website. Appropriate updates to the privacy policy will be published by us on this page.

Version: March 2025