Your wishlist is currently empty.
Your shopping cart is currently empty.

Data protection

It is important to us to handle your personal data with care. We are aware of our responsibility and thank you for your trust. Your data is protected by a range of technical and organizational measures against unauthorized access.
 

Our company participates in the Alliance for Cyber Security of the Federal Office for Information Security (BSI).

Webpräsenz der Allianz für Cyber-Sicherheit 
Your data is stored on a secure server in Germany (data center in Nuremberg). This server is integrated into the Backbone Europe infrastructure and equipped with modern technologies and energy-efficient hardware. The power supply is provided entirely from renewable energy.

Our email communication is handled via a German mail server (data center in Berlin), which complies with applicable consumer protection and security requirements. This includes, in particular, the implementation of the technical guideline “Secure Email Transport” (BSI TR-03108) issued by the Federal Office for Information Security (BSI). This server is also operated entirely using renewable energy. 


Privacy Policy

§ 1 Controller

The controller responsible for data processing on this website is:

OHB Thalheim e.K.
Owner: Guido Bernhardt
Hufelandstr. 24
09366 Stollberg
Germany

Phone: 0800 / 7467736
E-mail: datenschutz@underwear-shopping.de


§ 2 General Information on Data Processing

We process personal data exclusively in accordance with the applicable legal provisions, in particular the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Personal data means any information relating to an identified or identifiable natural person, such as name, address, e-mail address or IP address.


§ 3 Hosting

Our website is hosted by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany.

The hosting provider processes personal data (e.g. IP addresses, access times and browser information) in order to ensure the secure and stable operation of the website.

Legal basis:
Art. 6 para. 1 lit. f GDPR

Legitimate interest:
Secure operation, technical stability and protection of the website against misuse.

Server log files are generally deleted after no later than 7 days unless longer storage is required for security-related reasons.


§ 4 Data Processing for Contract Fulfillment

(1) Purpose of Processing

To process orders, we process the data provided during the ordering process (e.g. name, address, contact details and payment data).

When you contact us (e.g. by e-mail or contact form), we process your information in order to handle your request.

(2) Legal Basis

Art. 6 para. 1 lit. b GDPR

(3) Recipients

  • Shipping service providers
  • Payment service providers
  • Hosting providers

(4) Storage Period

  • Contract data: until expiration of statutory warranty periods
  • Tax and commercial law data: 10 years
  • Inquiries: until final processing has been completed

§ 5 Payment Services

For payment processing, personal data is transferred to the respective payment service provider depending on the selected payment method.

(1) Bank Transfer / Prepayment

If you choose payment by bank transfer / prepayment, payment processing is carried out directly via our bank account. Payment data will not be transferred to external payment service providers in this case.

(2) Cash on Delivery

If you choose cash on delivery, payment processing is carried out via the shipping provider. The data required for delivery (e.g. name and address) will be transmitted for this purpose.

Legal basis:
Art. 6 para. 1 lit. b GDPR

(3) PayPal (including payment methods offered via PayPal)

Payment processing is carried out by:

PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg

Depending on the selected payment method, the data required for payment processing will be transmitted to PayPal.

This includes in particular:

  • PayPal
  • Credit Card (Visa, Mastercard, American Express)
  • Apple Pay
  • Google Pay
  • Purchase on Invoice
  • Installment Payment

PayPal may transfer personal data to credit agencies or affiliated companies for payment processing and credit checks.

For invoice purchases or installment payments, processing may be carried out wholly or partially by external service providers (e.g. Ratepay GmbH, Berlin).

Further information:
PayPal Privacy Statement

Legal basis:
Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR

(4) WERO

If you choose the payment method WERO, payment processing is carried out via participating banks and payment service providers within the WERO system.

The data required for payment processing is processed and transmitted to the involved payment service providers.

Legal basis:
Art. 6 para. 1 lit. b GDPR


§ 6 Contact Form

If you contact us via a contact form, the data you provide will be processed for the purpose of handling your request.

Legal basis:
Art. 6 para. 1 lit. b GDPR and/or Art. 6 para. 1 lit. f GDPR

The data will be deleted once your request has been fully processed and no statutory retention obligations apply.


§ 7 Comments and Reviews

Comments

If you post comments, your information will be processed for publication purposes.

Legal basis:
Art. 6 para. 1 lit. f GDPR

You may request deletion at any time.

Customer Reviews (SHOPVOTE)

For displaying and collecting customer reviews, we cooperate with:

SHOPVOTE – Blickreif GmbH, Alter Messeplatz 2, 80339 Munich, Germany

The following data may in particular be processed:

  • E-mail address
  • Order number
  • Order date

To display reviews, content from SHOPVOTE may be loaded. In this process, technical data (e.g. IP address) may be transmitted to SHOPVOTE.

Legal basis:
Art. 6 para. 1 lit. f GDPR


§ 8 Cookies and Consent Management

Our website uses cookies and similar technologies.

We distinguish in particular between:

  • Technically necessary cookies
  • Statistics / analytics cookies
  • Marketing cookies

Non-essential cookies and similar technologies are only used after your explicit consent.

We use a consent management system to manage your consent preferences.

The system stores which consents you have given or withdrawn in order to ensure legally compliant control of cookies and external services.

You may change or revoke your consent at any time via the “Cookie Settings” on our website.

Legal basis:

  • Art. 6 para. 1 lit. a GDPR
  • Section 25 para. 1 TDDDG

Technically necessary cookies are used on the basis of:

  • Art. 6 para. 1 lit. f GDPR
  • Section 25 para. 2 TDDDG

You can disable cookies in your browser settings at any time. This may limit the functionality of the website.


§ 9 Google Analytics 4

Provided that you have given your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses cookies and similar technologies to analyze the use of our website.

The following data may in particular be processed:

  • Anonymized IP address
  • Device information
  • Browser information
  • User behavior
  • Visited pages
  • Traffic source
  • Interactions on the website

We use Google Analytics exclusively with activated IP anonymization.

Processing is carried out exclusively on the basis of your consent.

We have concluded a data processing agreement with Google.

Legal basis:

  • Art. 6 para. 1 lit. a GDPR
  • Section 25 para. 1 TDDDG

A transfer of personal data to the USA cannot be excluded.

Google relies on the Standard Contractual Clauses of the European Commission and, where applicable, the EU-U.S. Data Privacy Framework.

Further information:
Google Privacy Policy

You may revoke your consent at any time via the cookie settings.


§ 10 Google Tags / Conversion Tracking

Provided that you have given your consent, we use Google Tags to measure interactions and conversions.

Provider:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Cookies and similar technologies may be used to determine whether users reached our website via Google advertisements and subsequently performed certain actions.

Google may also use this information to create pseudonymous usage profiles.

Processing is carried out exclusively on the basis of your consent.

Legal basis:

  • Art. 6 para. 1 lit. a GDPR
  • Section 25 para. 1 TDDDG

Further information:
Google Privacy Policy


§ 11 Disclosure of Data

Personal data will only be disclosed if:

  • this is necessary for contract fulfillment,
  • we are legally obliged to do so,
  • or you have explicitly consented.

§ 12 Storage Period

Personal data is only stored for as long as necessary for the respective purpose or as required by statutory retention obligations.


§ 13 Your Rights

You have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to withdraw consent (Art. 7 para. 3 GDPR)
  • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

§ 14 Right to Object (Art. 21 GDPR)

You have the right to object at any time to the processing of your personal data if such processing is based on Art. 6 para. 1 lit. f GDPR.

In the case of direct marketing, you may object at any time without giving reasons.


§ 15 Supervisory Authority

Saxon Data Protection and Transparency Commissioner
Devrientstraße 5
01067 Dresden
Germany

Saxon Data Protection and Transparency Commissioner


Last updated: May 2026