Privacy Policy
PRIVACY POLICY
1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1
We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about how we handle your personal data when you use our website. Personal data is all data that can be used to personally identify you.
1.2
The controller responsible for data processing on this website within the meaning of the GDPR is Shop Name.
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
1.3
For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string “https://” and the lock symbol in your browser bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
When you visit our website for informational purposes only, meaning you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to our server (so-called server log files).
When you access our website, we collect the following data, which is technically necessary for us to display the website:
-
The website visited
-
Date and time of access
-
Amount of data sent in bytes
-
Source/referral from which you accessed the site
-
Browser used
-
Operating system used
-
IP address used (possibly in anonymized form)
Processing is carried out pursuant to Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not transferred or used for other purposes.
However, we reserve the right to check the server log files retrospectively if there are concrete indications of unlawful use.
3) COOKIES
To make your visit to our website attractive and to enable the use of certain functions, we use cookies. These are small text files stored on your device.
Some cookies are deleted when you close your browser (session cookies). Others remain stored and allow us or our partner companies (third-party cookies) to recognize your browser during your next visit (persistent cookies).
If cookies process personal data, such processing occurs based on Art. 6(1)(b) GDPR (contract performance) or Art. 6(1)(f) GDPR (legitimate interest in optimal functionality and user-friendly website design).
We may cooperate with advertising partners who also store cookies on your device. You will be informed separately if this is the case.
Your browser allows you to control cookie settings. Instructions for major browsers:
-
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
-
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
-
Chrome: https://support.google.com/chrome/answer/95647?hl=de
-
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
If cookies are not accepted, functionality of the website may be limited.
4) CONTACTING US
When contacting us (e.g. via contact form or email), personal data is collected. The data collected is visible in the respective form.
The data is used exclusively to respond to your inquiry and for technical administration. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in handling your request). If the contact aims at contract conclusion, Art. 6(1)(b) GDPR applies additionally.
Data is deleted once your request is fully resolved, unless legal retention obligations prevent deletion.
5) DATA PROCESSING FOR CUSTOMER ACCOUNT CREATION AND CONTRACT PROCESSING
According to Art. 6(1)(b) GDPR, personal data is collected when you provide it for contract execution or customer account creation.
You may request deletion of your account at any time. After full contract processing, your data will be restricted and deleted after statutory retention periods unless you consent to further use.
6) USE OF YOUR DATA FOR DIRECT MARKETING
6.1 Newsletter Subscription
If you register for our email newsletter, we send you regular updates on our offers. Required data: email address only. Additional data is voluntary.
We use the double opt-in method. After signing up, you must confirm via a verification link.
We store your IP address and the time of registration to prevent misuse. You may unsubscribe at any time via the link in the newsletter.
6.2 Newsletter to Existing Customers
If you provided your email address during a purchase, we may send you offers for similar products without separate consent, based on Art. 6(1)(f) GDPR. You may object at any time.
7) DATA PROCESSING FOR ORDER FULFILLMENT
7.1
Personal data is transferred to the delivery company where necessary for shipping, and to the payment provider where necessary for payment processing. Legal basis: Art. 6(1)(b) GDPR.
7.2 Use of Payment Providers
PayPal
If you pay via PayPal services, your data is transferred to PayPal (Europe) S.a.r.l. et Cie, S.C.A., Luxembourg. PayPal may conduct credit checks for certain payment methods. Details: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
SOFORT (Klarna Group)
Data required for payment processing is transferred to SOFORT GmbH, Theresienhöhe 12, 80339 Munich. Privacy info: https://www.klarna.com/sofort/datenschutz
8) REVIEW REMINDERS
We may send you a one-time reminder to review your purchase if you consented under Art. 6(1)(a) GDPR. You may revoke consent at any time.
9) SOCIAL MEDIA PLUGINS (SHARIFF SOLUTION)
9.1 Facebook
Using a Shariff link prevents automatic data transfer to Facebook Inc., Menlo Park, USA. Privacy info: https://www.facebook.com/policy.php
9.2 Google+
Same Shariff method. Privacy info: https://www.google.com/intl/de/policies/privacy/
9.3 Instagram
Shariff protection used. Privacy info: https://help.instagram.com/155833707900388/
10) ONLINE MARKETING
10.1 DoubleClick by Google
Used for ad optimization. Cookies may track ad interactions. Info: https://www.google.de/policies/privacy/
10.2 Google AdWords Conversion Tracking
Cookie-based tracking to measure ad performance. Info: https://www.google.de/policies/privacy/
11) WEB ANALYTICS
Google (Universal) Analytics
This website uses Google Analytics with IP anonymization (“_anonymizeIp()”). Data may be transferred to the USA. Opt-out plugin:
https://tools.google.com/dlpage/gaoptout?hl=de
User-ID functionality is enabled for cross-device analysis.
12) RETARGETING / REMARKETING
Facebook Pixel
Used for conversion tracking if you consent (Art. 6(1)(a) GDPR). Details: https://www.facebook.com/about/privacy/
Google AdWords Remarketing
Used to display interest-based advertising. Info:
https://www.google.com/settings/ads/onweb/
13) RIGHTS OF THE DATA SUBJECT
13.1
Applicable data protection law grants you extensive rights regarding the processing of your personal data by the controller (rights of access and intervention), as described below:
-
Right of access (Art. 15 GDPR): You have the right to obtain information about your personal data processed by us, the purposes of processing, categories of personal data, recipients or categories of recipients to whom your data has been or will be disclosed, the planned storage period or the criteria for determining this period, the existence of rights to rectification, erasure, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if not collected by us, the existence of automated decision-making including profiling, and any meaningful information about the logic involved and the intended effects on you. You also have the right to be informed about safeguards under Art. 46 GDPR for transfers to third countries.
-
Right to rectification (Art. 16 GDPR): You have the right to request immediate correction of inaccurate data or completion of incomplete data stored by us.
-
Right to erasure (Art. 17 GDPR): You may request the deletion of your personal data where the conditions of Art. 17(1) GDPR are met. This right does not apply where processing is necessary for freedom of expression, legal obligations, public interest, or the assertion, exercise, or defense of legal claims.
-
Right to restriction of processing (Art. 18 GDPR): You may request the restriction of processing while the accuracy of disputed data is verified, when you object to deletion due to unlawful processing, when data is needed for legal claims, or when you have objected to processing based on special circumstances and it is not yet determined whether our legitimate interests override yours.
-
Right to notification (Art. 19 GDPR): If you have exercised your rights to rectification, erasure, or restriction, the controller must inform all recipients of your data of such corrections, deletions, or restrictions unless impossible or disproportionate. You have the right to be informed about these recipients.
-
Right to data portability (Art. 20 GDPR): You may receive the personal data you provided in a structured, commonly used, and machine-readable format or request its transfer to another controller, where technically feasible.
-
Right to withdraw consent (Art. 7(3) GDPR): You may withdraw previously given consent at any time. Upon withdrawal, your data will be deleted unless processing is based on another legal ground. Withdrawal does not affect the lawfulness of processing before withdrawal.
-
Right to lodge a complaint (Art. 77 GDPR): If you believe that processing of your personal data violates the GDPR, you may lodge a complaint with a supervisory authority in your member state of residence, work, or alleged infringement.
13.2 RIGHT TO OBJECT
If we process your personal data based on our legitimate interest, you have the right to object at any time for reasons arising from your particular situation, with effect for the future.
If you exercise your right to object, we will stop processing the relevant data. Further processing is possible only if we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or if processing is necessary for asserting, exercising, or defending legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your data for such marketing. Exercising this right will stop the processing for direct marketing purposes.
14) DURATION OF STORAGE OF PERSONAL DATA
The duration of storage of personal data is determined by the respective statutory retention periods (e.g., commercial and tax retention obligations). After the expiration of these periods, the corresponding data is routinely deleted, unless it is still required for contract fulfillment or initiation and/or we have a legitimate interest in continued storage.