Protecting your data and your privacy are very important to us.

PRIVACY NOTICE

We at STORZ & BICKEL (herewith "STORZ & BICKEL", "us" or "we") would like to use this privacy notice to inform you of how we use your personal data. This privacy notice applies to the collection, processing, and use of personal data when visiting our websites available at https://www.storz-bickel.com/ and https://www.vapormed.com/ as well as any other website that links to this privacy notice ("Websites"), within the framework of the WebApp offered by STORZ & BICKEL, and when you contact us by mail, e-mail or telephone. We collect, process, and use personal data for purposes such as completing orders, offering services, and carrying out and further improving the contents and functions of our products and websites. We also collect, process, and use such data for the purposes of advertising and market research, if you have consented to such uses.

If you specifically consent to this privacy notice (for instance by clicking a check box on a website referring to this privacy notice), you consent for the responsible party to use the data collected on their websites for the purpose of advertising and market research on those websites.


§ 1 Contact information

This privacy notice applies to data processing by:

STORZ & BICKEL GmbH
In Grubenäcker 5–9
78532 Tuttlingen
Germany

STORZ & BICKEL America Inc.
1078 60th St
CA 94608 Oakland
California

You are welcome to submit questions on data privacy to privacy@storz-bickel.com at any time.

The data protection officer is:

BEHR CONSULTING
Jürgen Behr
Langesteige 5
78736 Epfendorf
Germany


§ 2 Collecting and saving personal data

Visiting our Websites: When you visit our Websites, we automatically collect certain technical information, such as your IP address, information about your device and browser, time and date of access, the website you are visiting us from.

Contacting us and S&B Customer Feedback: If you contact us via our contact form, feedback form or e-mail, we collect your email-address, name and title, the information provided by you to contact us and (optional) your phone number. If you contact us via phone, we are collecting your phone number and the information provided by you to contact us. If you contact us via mail, we are collecting your name and title, address, and the information provided by you to contact us. If you contact us about repairs and guarantees, we will also need some specific information about your product and the sale.

Chatbot: We provide a chatbot on our website to answer your inquiries quickly and efficiently. When using the chatbot, the information you enter as well as technical data, such as the IP address and the timestamp, will be processed.

Registering a customer account: When you register a customer account, we collect your name, date of birth, county of residence, e-mail, and (optional) gender.

Purchasing a product on our Websites: When you purchase a product from us, we collect your name, salutation, e-mail, phone number, address (and, if applicable, deviating delivery address), date of birth, and payment information.

Newsletter: When you subscribe to our Newsletter, we collect your name, email and some tracking information, such as the open and click rates.

Newsletter: Registering your product: When you register a product you have bought, we collect your registered customer account, rating, the model and serial number of the registered product and the date of the registration.

Product Reviews: When you review a product on our Websites, we collect your username, the rating and the contents of the comment on the product.

S&B Points: When you are collecting our S&B points, we are collecting your registered customer account, your orders, friends you have invited to use our products, and product reviews.

Invite Friends: When you use the “Invite friends” function, we collect your registered customer account, the invited friend, and purchases made by your invited friend.

Wishlist: When you use our wishlist function, we collect your registered customer account, the product(s) placed on the wishlist, and the time of adding the product to the wishlist.

Store Locator (Google Maps): When you user the store locator function, we partner with Google Maps, which will collect your IP address and geolocation, as well as cookies and session data.

Employment Application: If you apply to a job advertisement or send in a prospective application, your application information and associated personal data will be used in a regulated application process. Data will only be collected and processed as part of applicant management and will never be transmitted to third parties.

Social media: When you interact with one of our pages on social media, we will collect your “likes”, “shares” and comments to our social media contents as well as any information you choose to provide.

In most of the times, we will collect personal information from you directly, e.g. when you are using the services offered, such as the possibility of contacting us by e-mail.

In some cases, we may also collect data from third parties, e.g.,

  • when a friend sends you an invitation to our Websites (your e-mail-address),
  • from our business partners (only with your consent), such as service providers for Analytics, Emails and Ad-Networks,
  • or from social networks (Facebook, Instagram, X and TikTok).
  • We may use the personal information we collect for the following purposes:

  • Processing your orders, including sending you goods you have purchased;
  • Providing services to you, i.e. our Apps;
  • Account and contract management (including customer support);
  • Update information;
  • Communicate with you, including via email, text message, social media and/or telephone;
  • Review our business performance and improve our Services, including by recognizing an individual and remembering their information when they return to our Services and analyzing our customer-base;
  • Process payment for our products and services;
  • Maintain and service our Website;
  • Test, enhance, update, understand, and monitor our products and services including how they are used, or diagnose or fix technology problems;
  • Help maintain the safety, security and integrity of our property, goods, services, Apps and Website, technology assets and business;
  • Enforce our Terms & Conditions, resolve disputes, carry out our obligations and enforce our rights, and protect our business interests and the interests and rights of third parties;
  • Prevent, investigate or provide notice of fraud or unlawful or criminal activity; and
  • Comply with legal obligations.
  • Anonymize and Aggregate your data, for example to use it for product development, statistics, and the like.

We process your personal information in accordance with applicable law. We have below described the legal bases that may apply to our processing operations in light of the GDPR in a general way.

 

(1) Performance of Contract

We may process your personal information to fulfill contractual or quasi-contractual obligations, or to enter into or to end an agreement with you, in which case the legal basis for the processing is Art. 6 (1) lit. b GDPR.

 

(2) Compliance with Legal Obligations

To the extent that we are subject to legal obligations, we may process your personal information for in fulfilment of such legal obligations based on Art. 6 (1) lit. c GDPR.

 

(3) Based on Our Legitimate Interests

We also process your personal information to protect our legitimate interests, except where your interests or fundamental rights and freedoms, which require the protection of your personal information prevail. In such cases, the legal basis for the processing is Art. 6 (1) lit. f GDPR.

 

(4) Based on Your Consent

If you have given us separate consent to process your personal information, we will process your personal information within and on the basis of this consent. Consents may, for example, relate to the transfer of data to other companies, the evaluation of your personal information for targeted advertising activities or sending of communication. Where we justify the processing based on your consent, the legal basis is Art. 6 (1) lit. a GDPR.


Consent is always freely given. Refusing or revoking your consent will not have any negative consequences for you.

 

There is neither a contractual nor a legal obligation to provide us with your personal information for the use of our Websites. However, if you wish to contact us, register to our Newsletter or one of our Websites or want to purchase products or receive services from us, certain information may be required to enable us to process your request.

STORZ & BICKEL does not use automated decision-making procedures, including profiling, unless we have explicitly informed you of them.


§ 3 Transmission of data

Your personal data is never transmitted to third parties for reasons other than the following. We only transmit your personal data to third parties if:

  • you have expressly granted your consent to transmission according to Art. 6 para. 1 clause 1 GDPR,
  • transmission under Art. 6 para. 1 clause 1 GDPR is necessary to assert, exercise, or defend against legal claims, and there is no reason to assume that you would have an outweighing protected interest in not transmitting your data,
  • if we have a legal obligation to provide data under Art. 6 para. 1 clause 1 GDPR, and
  • if this is legally permitted and necessary under Art. 6 para. 1 clause 1 GDPR to carry out contractual relationships (such as to fulfill an agreement in case of customer orders, transmission of address data to transportation service providers).

§ 4 Cookies

On our Website, we will use cookies and other tracking technologies such as pixels and Local Storage Objects (LSOs) like HTML5 (together "Cookies").


§ 5 Security & encryption

For security reasons and to protect the transmission of confidential information that you send to us as the Website provider, we use SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us usually cannot be read by third parties.


§ 6 Rights of data subjects

(1) You have the right to obtain confirmation from us as to whether or not personal information concerning you is being processed by us. Where that is the case, you have a right to access the personal information and obtain further information, in accordance with Art. 15 GDPR;

 

(2) You may have the right to obtain the rectification of inaccurate personal information concerning you without undue delay, in accordance with Art. 16 GDPR;

 

(3) You may have the right to request that your personal data saved by us be deleted in accordance with Art. 17 GDPR unless processing is necessary to carry out a right to free expression and information, to fulfill a legal obligation, based on the public interest, or to assert, exercise, or defend against legal claims;

 

(4) You may have the right to request the restricted processing of your personal data according to Art. 18 GDPR if you dispute the correctness of your data, if processing is illegal, but if you reject deletion of data, and if we no longer need the data, but you require the data to assert, exercise, or defend against legal claims or you have objected to processing in accordance with Art. 21 GDPR;

 

(5) You have the right to obtain information about the recipients of data to whom the rectification, erasure, or restriction of processing has been communicated, in accordance with Art. 19 GDPR;

 

(6) You have the right to receive the personal information you have provided to us in a structured, accessible, and machine-readable format or to request it be transmitted to another responsible entity in accordance with Art. 20 GDPR;

 

(7) You have the right according to Art. 7 para. 3 GDPR to revoke any consent you have granted to us at any time. If you do so, we will no longer be able to carry out data processing based on this consent in the future and

 

(8) You have the right to submit complaints with a supervising authority in accordance with Art. 77 GDPR. Typically, you can contact the supervising authority for your place of residence or your workplace, or our jurisdiction.


§ 7 Right to object

To exercise Your GDPR Data Subject Rights, you can contact us without any formality by post or e-mail at the points of contact listed in section §1 Contact information.

RIGHT TO OBJECT PURSUANT TO ARTICLE 21 GDPR


OBJECTION ON GROUNDS OF YOUR PARTICULAR SITUATION

ACCORDING TO ARTICLE 21 (1) GDPR, YOU HAVE THE RIGHT TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, AT ANY TIME, TO PROCESSING OF PERSONAL INFORMATION CONCERNING YOU WHICH IS BASED ON OUR LEGITIMATE INTERESTS, INCLUDING PROFILING (E.G., CREDIT RATING). WE SHALL NO LONGER PROCESS THE PERSONAL INFORMATION UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE THE INTERESTS, RIGHTS, AND FREEDOMS OF YOU, OR FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.


OBJECTION AGAINST DIRECT MARKETING

ACCORDING TO ARTICLE 21 (2) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO PROCESSING OF PERSONAL INFORMATION CONCERNING YOU FOR PURPOSES OF DIRECT MARKETING, WHICH INCLUDES PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT TO THE PROCESSING FOR DIRECT MARKETING PURPOSES, YOUR PERSONAL INFORMATION WILL NO LONGER BE PROCESSED FOR SUCH PURPOSES.


CONTACT
YOU CAN SEND YOUR OBJECTION INFORMALLY BY POST OR E-MAIL ADDRESSED TO:

STORZ & BICKEL GmbH
In Grubenäcker 5–9
78532 Tuttlingen
Germany
Email: privacy@storz-bickel.com


§ 8 Retention periods

All data required for typical business transactions (such as orders, repairs, and processing guarantee claims) such as correspondence and commercial issues with customer data is archived before it may be destroyed in accordance with commercial and tax law regulations (HGB - German Commercial Code and Tax Code). Longer retention periods from the Medical Device Regulation (MDR) and country-specific requirements in permitted markets apply to information relevant to our medical products (Vapormed brand). Application documents are archived until the end of the application process, and for a maximum of six months, then deleted in accordance with data privacy law. Please contact privacy@storz-bickel.com for further information.


§ 9 Social media

We operate the channels and pages listed on the below mentioned social media platforms. If you interact with us through social media networks, such as when you "like" us on Facebook or follow us or share our content on X, Instagram or TikTok, we may receive some information about you that you permitted the respective social network to share with us. The data we receive is dependent upon your individual privacy settings with the social network, and may include your profile information, profile picture, gender, username, user ID associated with your social media account, age range, language, country, and any other information you permit the social network to share with us. You should always review and, if necessary, adjust your privacy settings on social media networks before sharing information and/or linking or connecting them to other services.

If your personal data is processed in the course of your use of our social media channels and pages, you have the rights listed above. Please contact privacy@storz-bickel.com if you have any questions, comments, and requests regarding the exercise of your rights.


a) Purposes and Legal Basis for Data Processing

 

We operate the below mentioned social media profiles to target the public, promote our products and for other marketing purposes, staff recruitment and communication directly with our customers.

 

Therefore, we may process your personal information following your interaction with the content of our social media profiles to fulfill contractual or quasi-contractual obligations, or to enter into or to end an agreement with you, in which case the legal basis for the processing is Art. 6 (1) lit. b GDPR.

 

We also process your personal information to protect or pursue our legitimate interests, except where your interests or fundamental rights and freedoms, which require the protection of your personal information prevail. In such cases, the legal basis for the processing is Art. 6 (1) lit. f GDPR.

 

b) Facebook

 

We use the services of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland "Facebook"). When you use interactive functions (e.g., commenting and sharing content) on our Facebook page, we may process personal data that you provide to us.

 

Processing by Meta Platforms

When you visit our Facebook page, Facebook will collect, among other things, your IP address, as well as other information stored on your PC or mobile device via cookies. Facebook then subsequently processes this information to provide us with anonymized statistical information about the use of the Facebook page. Please read the privacy notice of Facebook for more information on the processing activities, how you can exercise your rights under privacy law and how to contact Facebook, available under the following link: https://www.facebook.com/privacy/center/.

If you wish to prevent or restrain the processing activities by Facebook, you should first log out of Facebook or disable the "keep me logged in" function, delete the cookies stored on your device and close and restart your browser. This will delete any information that can be used to directly identify you and enable you to use Facebook without sharing your Facebook ID. If you want to find out how to manage or delete information stored about you, visit the following Facebook support page: https://www.facebook.com/privacy/center/.

Please note that the data collected about you is processed by Meta Platforms Ltd. and may be transferred to countries outside the EEA. Please review the Meta privacy policy in order to understand how your personal data is used. This policy also provides contact details for Meta, as well as information about the available settings for ad preferences. You can find the privacy policy under the following link: https://mbasic.facebook.com/privacy/policy/printable/.

Facebook Page Insights

Facebook processes with the function "Page Insights" information of its page visitors' personal data for its own purposes. This processing is carried out regardless of whether page visitors are logged into Facebook and whether they are members of the Facebook network. Page Insights are aggregated statistics that are created as a result of certain "events" logged by Facebook servers when people interact with pages and the content associated with them. We have not switched off the "Page Insights" and therefore regularly view the aggregated statistics to understand the impact of our Facebook page and provide for more efficient strategies. Please read carefully the notice provided by Facebook about Page Insights Data for more information, available under the following link: https://www.facebook.com/legal/terms/information_about_page_insights_data.

Processing by Us

If you comment, share, or otherwise react to any of the posts of our Facebook page, we process your personal data. This includes your Facebook user data (especially your username, profile URL, profile picture), the content of the comments you have made, and the related metadata (i.e., the time at which you posted your comment). If you click the "Like" button to follow our page, we will also process this information. Your data will remain accessible to us through the page until the user's account for the relevant data, such as single comment, is deleted.

We may store the aforementioned data if and as long as it is necessary for legal proceedings or to fulfill statutory retention obligations.


c) Instagram

 

We also use the technical platform and services provided by Instagram, owned by the Meta conglomerate ("Meta").

Processing by Meta Platforms

When you visit our Instagram page, Meta will collect, among other things, your IP address, as well as other information stored on your PC or mobile device via cookies. Meta then subsequently processes this information to provide us with anonymized statistical information about the use of the Instagram page. Please note that the data collected about you is processed by Meta Platforms Ltd. and may be transferred to countries outside the EEA. Please read the privacy notice of Meta for more information on the processing activities, to understand how you can use your rights under privacy law and how to contact Facebook, available under the following link: https://help.instagram.com/155833707900388.

Instagram Insights

Meta processes a range of its page visitors' personal data for its own purposes. This processing is carried out regardless of whether page visitors are logged into Instagram and whether they are members of Instagram. Page Insights are aggregated, anonymized statistics. Page operators do not have access to the personal data processed in this context; they can only access the aggregated, anonymized Page Insights. You can find more information under the following link: https://help.instagram.com/788388387972460.


d) X (Twitter)

We use the microblogging service provided by Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07 Ireland. On our Twitter profile, you can react to our posts, comment or interact with us via the direct message option. If you wish to restrict the processing of your data, use the general settings or the tab "Privacy and Safety" of your Twitter account. You can also restrict Twitter's access to your personal data on your mobile phone by changing the relevant settings.

Processing by Twitter

We have no influence over the processing activities conducted by Twitter. Please find additional information about the processing activities in the Twitter privacy policy, available under the following link: https://twitter.com/en/privacy.


e) TikTok

We also use the technical platform and services provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

Processing by TikTok

We have no influence on the processing activities conducted by TikTok. Please find additional information about the processing activities in the TikTok privacy policy, available under the following link: https://www.tiktok.com/legal/page/eea/privacy-policy/en.


§ 10 Updates and changes to this privacy notice

This privacy notice is the current valid version and was last updated in March 2026.
We may need to update this privacy and cookie notice periodically due to further developments of our website and services, or due to changed legal or official regulations. When we change these Notices in a material way, we will adjust the “last updated” date at the end of this Notice. Changes to these Notices are effective when they are posted on the Websites and Apps.

You can always access and print out the current version at the website storz-bickel.com/privacy.


§ 11 Precedence of the German version of the privacy notice

This privacy notice is made available on our homepage in several languages. We specifically point out that exclusively the German privacy notice is relevant for any legal effects. Please take note of the precedence of the German privacy notice, especially in the event of deviations between the different language versions, as well as in any other cases of doubt.