Data Protection Declaration SmartDevice-App

We, Liebherr-Hausgeräte GmbH, are pleased that you are using our SmartDevice-App (hereinafter also referred to collectively as “app”) and that you have thereby expressed an interest in the Liebherr Group.

We attach great importance to the protection and security of your personal data. Therefore, we consider it vital to inform you in the following about which of your personal data we process for what purpose and what rights you have in respect of your personal data.

Our app allows you to manage and use compatible Liebherr appliances via a mobile device. Depending on the appliance type, you can connect appliances to the app, manage settings, view status information, and display notifications or alerts. The app also offers numerous other features, such as storage tips and wine-related functions.

General information

What is personal data and what does processing mean?

–     “Personal data” (hereinafter also referred to as “data”) are all the details that make a statement about a natural person. Personal data are not just details that allow a direct conclusion to be drawn about a certain person (such as the name or e-mail address of a person), but also information with which with suitable additional knowledge a connection can be made with a certain person.

–     “Processing” means any action taken with your personal data (such as collection, recording, organisation, structuring, storage, use or erasure of data).

Who is the controller for the processing of your data?

The controller for the processing of your data is:

Liebherr-Hausgeräte GmbH

Memminger Straße 77-79

88416 Ochsenhausen

Germany

Phone: +49 7352 928-0

Email: privacy.appliances@liebherr.com

How can you reach our data protection officer?

Our data protection officer can be reached at the following contact details:

Group Data Protection EU/EEA

Liebherr-IT Services GmbH

St. Vitus 1

88457 Kirchdorf an der Iller

Germany

Email: datenschutz@liebherr.com

What rights do you have as a data subject?

As a data subject, you have the right, within the legal scope, to:

–     Information about your data;

–     Rectification of inaccurate data and completion of incomplete data;

–     Erasure of your data, particularly if (1) they are no longer necessary for the purposes stated in this Data Protection Declaration, (2) you have withdrawn your consent and there is no other legal ground for the processing, (3) your data have been unlawfully processed, or (4) you have objected to the processing and there are no overriding legitimate grounds for the processing;

–     Restriction of the processing of your data, particularly if the accuracy of the data is contested by you or the processing of your data is unlawful and instead of deletion you demand restriction of use;

–     Object to processing of your data based on legitimate interests, on grounds relating to your particular situation, or, without specific justification, to processing of your data carried out for direct marketing purposes; unless it is an objection to direct marketing, we ask that you explain the reasons why we should not process your data as we may do, when you lodge an objection. In the event of your reasoned objection, we will examine the merits of the case and cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims;

–     Receive your data in a structured, commonly used and machine-readable format and to have your data transmitted from us directly to another controller;

–     Withdraw consent, if you have given us consent for processing. Please note that the lawfulness of processing based on consent before its withdrawal will not be affected by your withdrawal.

If you assert any of the above-stated rights, please understand that we may require you to provide evidence showing that you are the person you claim to be.

Furthermore, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your data infringes the GDPR.

Links to other websites

Our app may contain links to and from websites of other providers not affiliated with us (“third parties”). After clicking on the link, we no longer have any influence on the processing of any data transmitted to the third party when the link is clicked (such as the IP address or the URL on which the link is located), as the behaviour of third parties is naturally beyond our control. Therefore, we cannot assume any responsibility for the processing of such data by third parties.

Links to social networks and messenger services

Our app may contain links to share content from our app on various social networks and/or messenger services. The established links do not result in any data being transmitted to providers of social networks or messenger services while you are using our app. Only when you click on one of the links to share content from our app will data (such as your IP address or the URL on which the link is located) be transmitted to the respective provider of the social network or messenger service. We have no influence on further data processing by the respective provider of the social network or messenger service.

Data processing

Download and use of the app (log files)

Every time you download, open, or use our app, your device (smartphone or similar) automatically sends information to our web servers, which we store in what are known as log files.

What data do we process and for what purposes?

We process the following data:

–     Your (external) IP address

–     Date and time of access

–     Domain name of your internet access provider

–     The type and version of browser you are using and the operating system you are using

–     URL (address on the internet) you were on at the time of the access

–     The files you retrieve (type of access, name of the retrieved file, URL of the retrieved file, success of the retrieval)

–     The amount of data transmitted to you

–     If applicable, date and time of submission when using web forms

These data are in principle processed by us solely for the purpose of ensuring stability as well as network and information security.

Processing for other purposes may only be considered if the necessary legal requirements pursuant to Article 6 para. 4 GDPR are met. In that case, we will of course comply with any information obligations pursuant to Article 13 para. 3 GDPR and Article 14 para. 4 GDPR.

On what legal basis do we process your data?

The processing of your data is carried out for purposes of legitimate interests pursuant to Article 6 para. 1 point f GDPR.

Our legitimate interests pursued are the improvement and maintenance of the stability or functionality and the security of our app.

You have the right to object, on grounds relating to your particular situation, at any time to processing based on Article 6 para. 1 point f GDPR.

Account registration/authentication & communication

Use of the app requires the registration of a user account. Users then log in and authenticate themselves using this account, and these data is processed for the purpose of communicating with you.

What data do we process and for what purposes?

When you register and authenticate within the app using a MyLiebherr account without using an existing account with Apple Inc., Google Ireland Limited, or Microsoft Ireland Operations Limited, we process the following data:

–     The information you provided during registration/authentication

–     User Principal Name (UPN)

–     Email address

–     Log data, such as the registration date and the date and time of the last successful login

When you register and authenticate within the app using an existing account with Apple Inc., Google Ireland Limited, or Microsoft Ireland Operations Limited (known as “External Login”), we also process the following data:

–     External login identifier (known as identifier), external login provider and your email address

Note:

–      If you register or authenticate using an external login from Google Ireland Limited, Google Ireland Limited also provides us with your last name, first name, Google ID, profile URL, and email address. We do not process this data for any purpose.

–      If you register or authenticate using an external login from Microsoft Ireland Operations Limited, Microsoft Ireland Operations Limited will also provide us with your last name and first name. We do not process this data for any purpose.

–      If you register or authenticate using an external login provided by Apple Inc., Apple Inc. also transmits your last name, first name, email address, or proxy email to us. We do not process this data for any purpose.

Please note that we have no influence over the processing of your personal data by Google Ireland Limited, Microsoft Ireland Operations Limited, and Apple Inc. The data transmitted in this context may be stored and processed by Google Ireland Limited, Microsoft Ireland Operations Limited, and Apple Inc.—including for their own purposes—outside the EU or the EEA and thus in a third country, specifically in the United States.

Under the GDPR, additional conditions must be met for data transfers to a third country to ensure that the level of data protection guaranteed in the EU is not undermined.

In the case of Google LLC and Microsoft Corporation, data transfers to the United States are based on the European Commission’s Adequacy Decision of July 10, 2023. According to this adequacy decision, the United States ensures an adequate level of protection within the meaning of Article 45 of the GDPR for personal data transferred from the EU to organizations in the United States that are certified under the “EU-U. S. Data Privacy Framework” (hereinafter “DPF”) and are listed on the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list) maintained by the U.S. Department of Commerce and made publicly available.

Google LLC and Microsoft Corporation are each certified under the DPF and listed on the “Data Privacy Framework List.”

In the case of Apple Inc., the transfer of data to the U.S. is subject to appropriate safeguards pursuant to Article 46(1) of the GDPR, which consist of Apple’s use of standard data protection clauses or standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR.

For more information on how Google Ireland Limited, Microsoft Ireland Operations Limited, and Apple Inc. process your personal data, please refer to the respective privacy policies of these providers.

These data are in principle processed by us solely for the following purposes:

–     Registration of a MyLiebherr-account to use the app, either via a double opt-in process or through an external login account

–     Centralized authentication mechanism for using the app

–     Centralized management of user data for the MyLiebherr-account

–     Notifications about promotions, new features, or changes related to the use of app, as well as the provision of support services

Processing for other purposes may only be considered if the necessary legal requirements pursuant to Article 6 para. 4 GDPR are met. In that case, we will of course comply with any information obligations pursuant to Article 13 para. 3 GDPR and Article 14 para. 4 GDPR.

On what legal basis do we process your data?

The processing of your data is carried out for the performance of a contract or in order to take steps prior to entering into a contract pursuant to Article 6 para. 1 point b GDPR and for purposes of legitimate interests pursuant to Article 6 para. 1 point f GDPR.

Our legitimate interests pursued are customer care and retention, as well as improving our offerings.

You have the right to object, on grounds relating to your particular situation, at any time to processing based on Article 6 para. 1 point f GDPR.

Use and provision of the app

When using the app, personal data—depending on the connected device and the features used—is displayed and processed within the app, including, in particular, device status, settings, alerts, and maintenance notifications. The app is thus used to provide and manage these features, as well as to facilitate communication between the connected device, the backend systems in use, and the mobile device.

In addition, you can specify your preferences regarding content and features within the app. If and to the extent that you have provided this information, it will be used to display content, information, and notifications within the app in accordance with your settings (app preferences) and selected topics.

In addition, when using the app, you can add and manage different wines in the “Wine” section and enter details, ratings, and notes about them. This information is used to provide you with the relevant content within the app and to associate it with your user account. If you use the search function or the label scan, the information you enter or submit will be processed to display the corresponding wine information within the app. To retrieve this wine information, we use the service provider Vivino ApS, Njalsgade 21G, 5, 2100 Copenhagen, Denmark. To this end, we have concluded a data processing agreement with Vivino ApS in accordance with Article 28 GDPR. Vivino ApS will accordingly process the data collected on our behalf for the specific purpose of providing the requested wine information and reporting it back to us.

What data do we process and for what purposes?

–     The serial number of your Liebherr refrigerator and/or freezer

–     Additional appliance information, such as the model of your Liebherr refrigerator and/or freezer

–     The appliance data for your Liebherr refrigerator and/or freezer

–     The sensor data for your Liebherr refrigerator and/or freezer

–     The technical configuration of your Liebherr refrigerator and/or freezer

–     Usage data for your Liebherr refrigerator and/or freezer

–     Selected preferences and settings, if applicable

–     Request ID, if applicable (when using the wine inventory feature)

–     Information, ratings, and notes about your wines, if applicable

–     Activation and use of SabbathMode, if applicable

These data are in principle processed by us solely for the purpose of properly providing the app's features, as well as for error analysis and improving the app.

Processing for other purposes may only be considered if the necessary legal requirements pursuant to Article 6 para. 4 GDPR are met. In that case, we will of course comply with any information obligations pursuant to Article 13 para. 3 GDPR and Article 14 para. 4 GDPR.

On what legal basis do we process your data?

The processing of your data is carried out for the performance of a contract or in order to take steps prior to entering into a contract pursuant to Article 6 para. 1 point b GDPR. To the extent that the data is used for error analysis and to improve the app, the processing is carried out to safeguard legitimate interests in accordance with Article 6 para 1 point f GDPR. The processing of your information regarding the wines for the purpose of error analysis and optimizing functionality is based on your consent pursuant to Article 6 para 1 point a GDPR.

The processing of personal data in connection with the activation and use of SabbathMode is based on your consent pursuant to Article 6 para 1 point a GDPR. To the extent that the use of SabbathMode may reveal special categories of personal data, your consent expressly covers the processing of such data as well, thereby also fulfilling the specific requirements under Article 9 para 2 point a GDPR.

We use special categories of personal data processed in connection with the use of SabbathMode exclusively to provide this feature. We do not use this data for any other purposes, in particular not for profiling, analyzing user behavior, or marketing purposes.

Our legitimate interests pursued are conducting error analyses to ensure the app operates without disruption, as well as further developing and optimizing the app.

You have the right to withdraw given consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

You have the right to object, on grounds relating to your particular situation, at any time to processing based on Article 6 para. 1 point f GDPR.

Analysis of appliance data

When using the app and connecting compatible devices to the SmartDevice Cloud, device data is processed and analyzed in the Liebherr Analytics platform. This includes, in particular, current device settings, changes to device settings, status information, technical device data, and usage and sensor data from the connected device. This processing is carried out to provide services, analyze potential error patterns, determine energy consumption, and generate statistical analyses of the usage and functionality of the connected devices. If anomalies or potential malfunctions are detected during these analyses, corresponding alerts or notifications may be displayed within the app.

What data do we process and for what purposes?

We process the following data:

–     The serial number of your Liebherr refrigerator and/or freezer

–     Additional appliance information, such as the model of your Liebherr refrigerator and/or freezer

–     The appliance data for your Liebherr refrigerator and/or freezer

–     The sensor data for your Liebherr refrigerator and/or freezer

–     The technical configuration of your Liebherr refrigerator and/or freezer

–     Usage data for your Liebherr refrigerator and/or freezer

–     Your (external) IP address

These data are in principle processed by us solely for the purpose of analyzing the operation and use of connected devices, for error detection and analysis, for providing services, for determining device-related information (e.g., usage or status information), and for generating statistical analyses.

Processing for other purposes may only be considered if the necessary legal requirements pursuant to Article 6 para. 4 GDPR are met. In that case, we will of course comply with any information obligations pursuant to Article 13 para. 3 GDPR and Article 14 para. 4 GDPR.

On what legal basis do we process your data?

The processing of your data is carried out for the performance of a contract or in order to take steps prior to entering into a contract pursuant to Article 6 para. 1 point b GDPR.

Use of cookies and other technologies

A. General

In providing our app, we use cookies and other technologies. In the following notes we provide you – as a user of our app – with additional information on data processing via the use of cookies and other technologies.

I. What are cookies and other technologies?

Cookies and other technologies are small text files that a web server or app can store and read on your device (computer, smartphone, or similar) via the web browser or apps you use. Cookies and other technologies contain unique alphanumeric strings that allow the web browser or app you are using to be identified and may also contain information about user-specific settings.

The aforementioned cookies and other technologies are hereinafter collectively referred to as “technologies”.

We distinguish between essential cookies on the one hand and optional cookies on the other:

–Essential technologies are those that are technically necessary for the functionality of our app and IT systems, as well as for ensuring their security and stability. We also classify as part of this category technologies that store certain settings you have configured, options you have selected, or information you have entered—at most until you close the app—in order to provide the functionality you have requested (e.g., login status). Your consent is not required for the storage or retrieval of essential technologies. Therefore, you cannot manage essential technologies via the settings of the consent management service we use; instead, you can only manage them through your device’s settings, where you can delete stored technologies or block the storage of technologies.

–Optional technologies are those that are not required for the functionality or for ensuring the security and stability of our app and IT systems, but rather serve analytical or marketing purposes. For example, these technologies may collect information about how you use our app to generate anonymized statistics, which enables us to analyze usage and thereby optimize our app. In addition, we also classify as part of this category technologies that store certain settings you have configured, options you have selected, or information you have entered beyond the point at which you close the app, in order to make the features you have requested and desired available over the long term (e.g., login status via the “Remember my email address” option, wish list, comparison list, etc.). Your prior consent is generally required for the storage or reading of optional technologies. Through the settings of the consent management service we use, you can consent to the use of optional technologies and revoke any consent you have given at any time with future effect.

Both essential and optional technologies may be so-called “session technologies” or “persistent technologies”, which differ in their intended lifetime or functional life:

–     Session technologies are stored on your terminal equipment and are automatically deleted when you close the app.

–     Persistent technologies (or permanent technologies) are stored on your terminal equipment and are not automatically deleted when you close the app, but remain on your terminal equipment for a predefined period of time.

Note: You can generally delete the data stored by these technologies yourself through your device settings. For details, please refer to your device’s user manual.

B. Use of technologies in our app

I. Essential technologies

1. Which essential technologies are used for what purpose and for how long?

–     Consent management

Purpose:Obtaining and managing consent and storing information about consent decisions
Service provider: Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany
Functional life: Unlimited

In order for you to manage the use of optional technologies in our app, we have implemented a consent management service. Via the consent management service, the first time you access our app, you will be presented with a previously defined query (“Cookies and other technologies”), which allows you to accept or decline the use of optional technologies by clicking the appropriate button. In addition, clicking “settings” will take you to the consent management service settings, where you will find, among other things, a simplified list of technologies classified by type. Using the consent management service, you can, among other things, learn about the purposes of the technologies we use, the data processed in each case, and any data recipients; and, in the case of optional technologies, you can give or withdraw your consent at any time by selecting or deselecting the relevant box.

Please note that essential technologies are already stored upon accessing our app and that the relevant box is preselected. It is not possible to deselect essential technologies via the consent management service. The functionality of the consent management service itself requires the use of certain technologies.

Service provider information:

Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany

Website:

https://usercentrics.com/

General Terms and Conditions:

https://usercentrics.com/terms-and-conditions/

Privacy Policy:

https://usercentrics.com/privacy-policy/

–     AppsFlyer (fraud prevention)

Purpose:To ensure the stability, security, and fraud prevention of our campaigns
Service provider: AppsFlyer Ltd., 14 Maskit St., POB 12371, Herzliya, Israel
Functional life: Until objective is achieved

We use the services of AppsFlyer Ltd., 14 Maskit St., Herzliya, Israel (“AppsFlyer”); parent company: AppsFlyer Inc., 111 New Montgomery St., Ste. 400, San Francisco, CA, 94105-3616 United States (hereinafter collectively “AppsFlyer”), with the “IP anonymization” feature (also known as the “IP masking method”), to ensure protection against fraud in our campaigns (“AppsFlyer Fraud Prevention”).

In doing so, certain information regarding the devices used by users, their online behavior, and the page content they access is collected, processed, and used. AppsFlyer uses this data on our behalf to detect and prevent instances of so-called “mobile fraud,” i.e., manipulative and fraudulent activities related to our marketing efforts. Based on the data collected and subsequently aggregated, AppsFlyer can identify for us whether certain actions related to our app (e.g., download or installation) were caused by manipulation.

To this end, we have concluded a data processing agreement with AppsFlyer in accordance with Article 28 GDPR and the EU standard contractual clauses. Accordingly, AppsFlyer will process the collected data (data regarding your device or web browser, IP addresses, and your app activity) on our behalf for specific purposes: to analyze your use of our app on our behalf, to compile reports on app activity, and to provide us with other services related to the use of our app and internet usage.

The data collected through AppsFlyer may be stored and processed in the United States or in any other country where AppsFlyer or its subprocessors maintain facilities. However, the IP masking method we use ensures that, before transmission to an AppsFlyer server in the United States and storage there, the IP address is truncated while still within EU member states or other EEA member states, so that no complete IP address is transmitted, thereby preventing or significantly hindering the identification of an individual.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

AppsFlyer is certified under the DPF and included in the Data Privacy Framework List.

You may object to AppsFlyer’s collection and storage of data at any time, effective for the future, by following the instructions at https://www.appsflyer.com/optout. Alternatively, you may opt out of the use of AppsFlyer technology by sending us an email to privacy.appliances@liebherr.com and notifying us of your withdrawal in writing.

Service provider information:

AppsFlyer Ltd., 14 Maskit St., Herzliya, Israel, parent company: AppsFlyer Inc. 111 New Montgomery St Ste 400 San Francisco, CA, 94105-3616 United States

Website:

https://www.appsflyer.com

Privacy Policy:

https://www.appsflyer.com/services-privacy-policy

–     Firebase Cloud Messaging (FCM) –Silent Messages

Purpose:Technical communications between system and app
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irleand
Functional life: Until objective is achieved

We use the Firebase Cloud Messaging service (hereinafter “FCM”), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter collectively “Google”), to transmit signals from your device in the form of background messages or updates to your mobile device. To this end, we have concluded a data processing agreement with Google in accordance with Article 28 GDPR.

FCM is a cross-platform service for technical communication between our backend system and the SmartDevice app you use. The service enables us to trnsmit information about status updates from your connected devices to the SmartDevice app in real time. This is done using so-called data messages (“silent messages”). These are processed in the background of the app and serve exclusively for the technical synchronization of data between the backend and the end device, without triggering a visible notification.

As part of the use of Firebase Cloud Messaging, the end device is assigned a pseudonymous identifier (known as an FCM token), which is used to address messages. FCM is used exclusively to ensure the functionality of our app, in particular to transmit status information (e.g., changes to device settings) and to synchronize data between the device, the cloud, and the app.

The data collected as part of FCM may be stored and processed in the United States or in any other country where Google or Google’s subprocessors maintain facilities.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

Google is certified under the DPF and is listed on the “Data Privacy Framework List.”

Service provider information:

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Website:

https://firebase.google.com/products/cloud-messaging

Privacy Policy:

https://policies.google.com/privacy

2. On which legal basis are essential technologiesused?

In order to be able to demonstrate that – or whether – you have consented to the use of optional technologies requiring your consent, we store the information about your consent, whether given or not, in order to fulfil our legal obligation to provide evidence in accordance with Article 6 para. 1 point c and Article 6 para. 3 point a GDPR in conjunction with Article 7 para. 1 GDPR.

Furthermore, we use essential technologies for the purposes of legitimate interests in accordance with Article 6 para. 1 point f GDPR.

Our legitimate interests pursued are:

–     Ensuring the security and stability of our app and information technology systems, for example by protecting against attacks in the form of targeted server overloads (Denial of Service attacks) or by using optimal load distribution on servers

–     Detection and prevention of campaign fraud

–     Establishment, exercise or defence of legal claims

–     Providing and guaranteeing the proper functionalities of our app

3. How can I object to the use of essential technologies?

You can exercise your right to object by means of the blocking options described below under “Deletion/Blocking of technologies” (cf. Article 21 para. 5 GDPR), i.e. by blocking essential technologies via your app settings.

Please note that if you delete without blocking, essential technologies will be used once again when you access our app at a later date. Please also note that deactivating or deleting or blocking essential technologies may affect the performance and functionality of our app and may cause certain features and functions to be unavailable.

II. Optional technologies

Using the following information, we would like to enable you to make a well-founded decision for or against the use of optional technologies and the associated data processing.

1. Which optional cookies are used for what purpose and for how long?

–     Google Analytics

Purpose:Web analysis
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irleand
Functional life: Up to 2 years

Subject to your consent, we use app analytics technologies to analyze how our app is used so that we can continuously improve it. The anonymized user statistics we collect (e.g., the number and location of app users) allow us to optimize our app and make it more engaging, for example, by placing frequently accessed information or topics on our app in a way that meets user needs.

For app analysis we use “Google Analytics”, an app analysis service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter collectively “Google”), with the “IP anonymization” extension (also called “IP masking method”). To this end, we have concluded a data processing agreement with Google in accordance with Article 28 GDPR. Google will accordingly process the data collected (data about your device or web browser, IP addresses, and your website or app activity) on our behalf for the purposes of analyzing your use of our app, compiling reports on app activity, and providing us with other services related to the use of our app and internet usage.

Data collected within the context of Google Analytics may be stored and processed by Google or subprocessors of Google outside the EU or the EEA and thus in a third country, in particular in the USA. The IP masking method that we use ensures that before the IP address is transferred to a Google server in the USA and stored there, it is shortened within EU member states or in other EEA member states so that no IP address is transferred in its entirety, thereby preventing or considerably complicating identification of a person. Only in exceptional cases will the complete, i.e. entire, IP address be transferred to a Google server in the USA and only shortened there.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

Google is certified under the DPF and included in the Data Privacy Framework List.

Service provider information:

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Google Ads Data Processing Terms:

https://privacy.google.com/businesses/processorterms/

Terms of Service:

https://marketingplatform.google.com/about/analytics/terms/us/

Overview of data usage in Google Analytics:

https://support.google.com/analytics/answer/6004245?hl=en

Privacy Policy:

https://policies.google.com/privacy

Technical explanation of “IP Anonymization (or IP masking) in Google Analytics”

https://support.google.com/analytics/answer/2763052?hl=en

Additional note:

If you wish to deactivate Google Analytics across all websites, you can download and install the “Google Analytics Opt-out Browser Add-on” at https://tools.google.com/dlpage/gaoptout?hl=en. This option only disables web analysis as long as you are using a web browser for which you have installed the add-on.

–     Google Firebase Crashlytics

Purpose:Error reports
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irleand
Functional life: Up to 2 years

We have integrated Google Firebase Crashlytics into the app to analyze and resolve errors. The reporting is used to ensure the app’s stability and to improve it. This involves collecting information about the device being used and app usage (e.g., timestamps indicating when the app was launched and when the crash occurred), which enables us to diagnose and resolve issues. The data is stored in an anonymized form. This personal data is not combined with your other profile information. The retention period for the data collected in this manner can be found in the provider’s privacy policy.

For error troubleshooting, we use “Google Firebase Crashlytics”, an app analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter collectively referred to as “Google”), with the “IP anonymization” feature (also known as the “IP masking method”). To this end, we have concluded a data processing agreement with Google in accordance with Article 28 GDPR. Google will accordingly process the data collected (data about your device or web browser, IP addresses, and your website or app activity) on our behalf for the purposes of analyzing your use of our app, compiling reports on app activity, and providing us with other services related to the use of our app and internet usage.

Data collected within the context of Google Firebase Crashlytics be stored and processed by Google or subprocessors of Google outside the EU or the EEA and thus in a third country, in particular in the USA. The IP masking method that we use ensures that before the IP address is transferred to a Google server in the USA and stored there, it is shortened within EU member states or in other EEA member states so that no IP address is transferred in its entirety, thereby preventing or considerably complicating identification of a person. Only in exceptional cases will the complete, i.e. entire, IP address be transferred to a Google server in the USA and only shortened there.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

Google is certified under the DPF and included in the Data Privacy Framework List.

Service provider information:

Google Ireland Limited, Gordon House, 44-47 Barrow Street Dublin 4 D, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Website:

https://firebase.google.com

Privacy Policy:

https://firebase.google.com/support/privacy/

–     AppsFlyer (Marketing & Re-Targeting)

Purpose:Marketing
Service provider: AppsFlyer Ltd., 14 Maskit St., POB 12371, Herzliya, Israel
Functional life: Until objective is achieved

We use the services of the provider AppsFlyer Ltd, 14 Maskit St, Herzliya, Israel ("AppsFlyer"); parent company: AppsFlyer Inc. 111 New Montgomery St Ste 400 San Francisco, CA, 94105-3616 United States (hereinafter collectively "AppsFlyer"), with the enhancement of "IP anonymisation" (also referred to as "IP masking method"), to carry out further advertising of our products ("AppsFlyerMarketing & Re-Targeting"). For this purpose, we have concluded a data processing addendum with AppsFlyer in accordance with Article 28 of the GDPR and the EU standard contractual clauses. Accordingly, AppsFlyer will process the collected data (data on your terminal device or your web browser, IP addresses and your app activities) on our behalf for the purpose of evaluating your use of our app for us, compiling reports on app activities and providing us with other services related to the use of our app and internet usage.

This involves the collection, processing and use of certain information about the devices used by users, your online usage behaviour and page content accessed. AppsFlyer uses this data on our behalf to evaluate and understand the performance of our marketing measures and channels, and how you use and interact with the app.

Data collected through AppsFlyer may be stored and processed by AppsFlyer or subprocessors of AppsFlyer outside the EU or the EEA and thus in third country, particular in the USA. The IP masking method that we use ensures that before the IP address is transferred to a AppsFlyer server in the USA and stored there, it is shortened within EU member states or in other EEA member states so that no IP address is transferred in its entirety, thereby preventing or considerably complicating identification of a person. Only in exceptional cases will the complete, i.e. entire, IP address be transferred to a Google server in the USA and only shortened there.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

AppsFlyer is certified under the DPF and included in the Data Privacy Framework List.

You can object to the collection and storage of data by AppsFlyer at any time with effect for the future by following the instructions at https://www.appsflyer.com/optout. Alternatively, you can stop the use of AppsFlyer technology by sending us a message to privacy.appliances@liebherr.comand informing us of your revocation.

Information about the service provider:
AppsFlyer Ltd., 14 Maskit St., Herzliya, Israel; parent company: AppsFlyer Inc. 111 New Montgomery St Ste 400 San Francisco, CA, 94105-3616 United States

Website:
https://www.appsflyer.com

Privacy Policy:
https://www.appsflyer.com/services-privacy-policy

-         Push notifications

Purpose:Sending push notifications and, where applicable, analyzing usage and behavioral data to personalize push notifications
Service provider: Depending on the end device's operating system:

iOS:

Apple Distribution International Limited,

Hollyhill Industrial Estate, Hollyhill, Cork, Ireland

Android:

Google Ireland Limited,

Gordon House, Barrow Street,

Dublin 4, Ireland

If consent has been given for personalization, additionally:

Urban Airship Germany GmbH, Thurn-und-Taxis-Platz 6, 60313 Frankfurt, Germany

Functional life: Unlimited

Subject to your consent to receive push notifications and the technical capabilities of your terminal equipment, we will use push notifications to inform you about updates, various functions or specific news about our app, even if the app is not open and/or your terminal equipment is locked. To do this, we use the technology of your terminal equipment, so that your consent is given by allowing notifications via the applicable system settings of your terminal equipment. When you grant the relevant permission through the applicable system settings of your terminal equipment, your terminal equipment registers with the respective push service (Apple Notification Service or Firebase Cloud Messaging), which assigns a pseudonymised unique ID in the form of a so-called push token to your terminal equipment and to our app installed on it. With the help of this push token, the respective push service can unambiguously recognise your terminal equipment and our app installed on this terminal equipment and thus address it precisely, which is necessary for the proper sending and receiving of push notifications.

You can withdraw your given consent to receive push notifications at any time with effect for the future and thus prevent the further receipt of push notifications by revoking the relevant permission through the applicable system settings of your terminal equipment. When the relevant permission is revoked, the push token will also be deleted upon the next launch of our app.

Given that the reception of push notifications relies on the technology of your terminal equipment, we use the services detailed hereafter depending on the operating system of the terminal equipment:

-         Apple Push Notification Service

If your terminal equipment is running the operating system “iOS”, push notifications are sent and received via the “Apple Push Notification Service”, a service provided by Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland; parent company: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA (hereinafter collectively “Apple”).

Data transmitted/transferred to Apple within the context of the Apple Push Notification Service may be stored and processed by Apple outside the EU or the EEA and thus in a third country, in particular in the USA.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer of data to the USA takes place subject to appropriate safeguards pursuant to Article 46 para. 1 GDPR, which consist of Apple’s making use of standard data protection clauses or standard contractual clauses adopted by the European Commission pursuant to Article 46 para. 2 point c GDPR.

Service provider information:

Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland; parent company: Apple Inc., Infinite Loop, Cupertino, CA 95014, USA

Website:

https://developer.apple.com/notifications/

Privacy Policy:

https://www.apple.com/legal/privacy/en-ww/

Standard Contractual Clauses:

If you would like a copy of Apple’s standard contractual clauses, please contact https://apple.com/de/privacy/contact/.

-         Firebase Cloud Messaging

If your terminal equipment is running the operating system “Android”, push notifications are sent and received via “Firebase Cloud Messaging”, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter collectively “Google”).

Data transmitted/transferred to Google within the context of Firebase Cloud Messaging may be stored and processed by Google outside the EU or the EEA and thus in a third country, in particular in the USA.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

Google is certified under the DPF and included in the Data Privacy Framework List.

Service provider information:

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Website:

https://firebase.google.com/products/cloud-messaging

Privacy Policy:

https://policies.google.com/privacy

Subject to your supplementary consent to personalise push notifications, we additionally also collect and analyse your use of our app to personalise push notifications. This means that we track your interactions with our app and the push notifications received through it (e.g. opening behaviour) and collect and analyse your usage and behavioural data in this regard in order to send you targeted, personalised advertising based on your presumed interests using electronic mail in the form of push notifications. In doing so, usage and behavioural data are also stored in recipient profiles. The analysis of your usage and behavioural data and the storage of the analysis results also enable us to measure the success of our advertising campaigns and to design them to meet demand and suit our target groups.

You can withdraw your given consent to personalise push notifications at any time with effect for the future and thus prevent the further collection and analysis of your data by deselecting the corresponding service under “Analysis” in the settings of the consent management service.

If you have given your supplementary consent to the personalisation of push notifications, we use the following services in addition to the respective push service (Apple Notification Service or Firebase Cloud Messaging):

-         Airship

For the personalisation of our push notifications, including the necessary analysis of usage and behavioural data, we use “Airship”, an analysis service provided by Urban Airship Germany GmbH, Thurn-und-Taxis-Platz 6, 60313 Frankfurt, Germany; parent company: Airship Group, Inc., 1225 W. Burnside, Suite 401, Portland, OR 97209, USA (hereinafter collectively “Airship”). In this respect, we have concluded a data processing agreement with Airship in accordance with Article 28 GDPR.

Data collected within the context of the analysis may be stored and processed by Airship or subprocessors of Airship outside the EU or EEA, and thus in a third country, in particular in the USA.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

Airship Group, Inc. is certified under the DPF and included in the Data Privacy Framework List.

Service provider information:

Urban Airship Germany GmbH, Thurn-und-Taxis-Platz 6, 60313 Frankfurt, Germany; parent company: Airship Group, Inc., 1225 W. Burnside, Suite 401, Portland, OR 97209, USA

Website:

https://www.airship.com/

Privacy Policy:

https://www.airship.com/legal/privacy/

2. On which legal basis are optional technologies used?

We use optional technologies on the basis of the consent pursuant to Article 6 para. 1 point a in conjunction with Article 7 GDPR.

3. How can I withdraw the consent that I have given to the use of optional technologies?

When you (first) access our app, we request inter alia your consent for the use of optional technologies by means of a predefined query (“Cookies and other technologies”). You can withdraw the consent that you have given at any time with effect for the future and thereby prevent further collection of your data by deselecting optional technologies (app analysis, marketing) in the settings of the consent management service.

If and insofar as you do not consent or withdraw consent already given (further) data collection by means of optional technologies requiring consent and the associated data processing will cease. This presents no drawbacks when using the app, unless you also deactivate the technologies functions for essential technologies.

The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

As an alternative to withdrawing your consent, you can also make use of the options described below under “Deletion/Blocking of technologies” to delete or block technologies using the information provided there.

C. Deletion/Blocking of technologies

Technologies are stored on your device, so you have control over them. If you do not want us to recognize your device, you can at any time deactivate or delete technologies already stored on your device—either manually or automatically—and/or block the storage of technologies in the future by adjusting the relevant setting on your device, e.g., “do not accept technologies” or similar. Most apps can also be configured so that the storage of technologies is only accepted if you give your separate consent on a case-by-case basis. If you do not wish to accept the technologies of our service providers and partners, you should be able to find the setting “Block third-party technologies” or similar on your device. For details on the options described, please refer to the instructions provided by your device manufacturer. Please note that if you delete without blocking, any essential technologies will be used the next time and we may ask you once again for your consent to optional technologies when you access our app at a later date. Please also note that deactivating or deleting or blocking essential technologies may affect the performance and functionality of our app and may cause certain features and functions to be unavailable.

Please note that if you delete the app without blocking it, required technologies will be re-enabled, and we may ask for your consent again regarding optional technologies if you access our app at a later time. Please also note that deactivating, deleting, or blocking required technologies may impair the performance and functionality of our app and may result in certain features and functions becoming unavailable.

You can manage the settings for the use of optional technologies and the associated data processing at any time in the settings of the consent management service.

Integration of third-party services

In providing our app, we integrate various content and functional elements (hereinafter also referred to collectively as “services”) that are obtained from the web servers of their respective providers (hereinafter referred to as “third-party providers”). For the proper presentation and provision of the services, it is always necessary that your IP address is transmitted to the respective third-party provider. Although we endeavour to only integrate services where the respective third-party provider only uses the IP address to deliver the services, we have no influence on the further processing by third-party providers.

For data transfers requiring consent, we ask you—when you first open our app—via a preliminary prompt (“Cookies and Other Technologies”) to provide your consent, among other things, for the transfer of data to third-party providers or third countries associated with the use of other services. If you do not grant your consent via this initial prompt, third-party services requiring consent will be blocked in our app, and no data will be transferred to third-party providers or third countries. Instead, you can grant your consent separately for individual third-party services by clicking “Accept” in the respective blocker. If, in the future, you no longer wish to grant consent individually for each third-party service and would like to be able to load them without the respective blocker, you have the option to additionally select “Always Accept,” thereby consenting to the associated data transfers for all future third-party services you access in our app.

You can withdraw given consents at any time with effect for the future and thus prevent the further transmission of your data by deselecting the respective service under “Miscellaneous services (optional)” in the settings of the consent management service.

With this in mind, we use the services listed below:

–     YouTube videos

We integrate videos from “YouTube” on our app, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter collectively “Google”). For the integrated YouTube videos, the “privacy-enhanced mode” is turned on, so that no technologies for analysing user behaviour are used.

Subject to your consent, we transmit your data, including your IP address, to Google when you load a YouTube video. Data transmitted within this context may be stored and processed by Google, also for its own purposes, outside the EU or the EEA and thus in a third country, in particular in the USA. We have no influence on further data processing by Google.

For a data transfer to a third country, pursuant to the GDPR, additional conditions are to be complied with in order to ensure that the level of data protection guaranteed in the EU is not undermined. In this case, the data transfer to the USA takes place on the basis of the European Commission’s adequacy decision of 10 July 2023. According to this adequacy decision, the USA ensures an adequate level of protection within the meaning of Article 45 GDPR for personal data transferred from the EU to organisations in the USA that are certified under the “EU-U.S. Data Privacy Framework” (hereinafter “DPF”) and included in the “Data Privacy Framework List” (https://www.dataprivacyframework.gov/list), maintained and made publicly available by the U.S. Department of Commerce.

Google is certified under the DPF and included in the Data Privacy Framework List.

Third-party provider information:

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Website:

https://www.youtube.com

Privacy Policy:

https://policies.google.com/privacy

Data recipients

We may transmit your data to:

–     Other companies of the Liebherr Group, provided this is necessary to initiate, perform or terminate a contract, or for our part we have a legitimate interest in the transmission and your predominant legitimate interest is not opposed to this;

–     The providers of the functions and any other services you actively use;

–     Our service providers that we use in order to achieve the above-stated purposes;

–     The recipient or recipients you specify;

–     Courts of law, courts of arbitration, authorities or legal advisers, if this is necessary to comply with current law or for the establishment, exercise or defence of legal claims.

Data transfers to third countries

The transfer of data to bodies in countries outside the European Union or the European Economic Area (so-called third countries) or to international organisations is only permissible (1) if you have given us your consent or (2) if the European Commission has decided that an adequate level of protection exists in a third country (Article 45 GDPR). If the Commission has not made such a decision, we may only transfer your data to recipients located in a third country if appropriate safeguards are in place (e.g., standard data protection clauses adopted by the Commission or the supervisory authority following a specific procedure) and the enforcement of your data subject rights is ensured or the transfer is permissible in individual cases on the grounds of other legal bases (Article 49 GDPR).

Where we transfer your data to third countries, we will inform you of the respective details of the transfer at the relevant points in this data protection declaration.

Data erasure and storage period

We will process your data as long as this is necessary for the respective purpose, unless you have effectively objected to the processing of your data or effectively withdrawn any consent you may have given.

Insofar as statutory retention obligations exist, we will be bound to store the data in question for the duration of the retention obligation. Upon expiry of the retention obligation, we will check whether there is any further necessity for the processing. If there is no longer such a necessity, your data will be deleted.

Data security

We use technical and organisational security measures to ensure that your data is protected against loss, inaccurate alteration or unauthorised access by third parties. Moreover, for our part in every case, only authorised persons have access to your data, and this only insofar as it is necessary within the scope of the above-stated purposes. The transmission of all data is encrypted.

As of:July 2026