The persons responsible for data processing or his representative pursuant to Art. 27 (1) GDPR are
Franziska Kuntze, Andreas Gerth
Onkel-Tom-Strasse 3
14169 Berlin
GERMANY
Thank you for your interest in our website and online shop. The protection of your privacy is very important to us. Below we inform you in detail about the handling of your data.
Your data is processed on the basis of the GDPR and in accordance with § 96 Para. 3 TKG (German Telecommunications Law).
1. Access data and hosting
You can visit our web pages without providing any personal information. Each time you call up our website, the web server only automatically saves a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of the call, the amount of data transferred and the requesting provider (access data) and documents the call.
This access data is evaluated solely for the purpose of ensuring trouble-free operation of the site and improving our services. In accordance with Art. 6 Para. 1 S. 1 lit. f GDPR, this serves to protect our legitimate interests in the correct presentation of our offer, which outweigh our interests in the context of a balancing of interests. All access data will be deleted at the latest seven days after the end of your visit to our website.
Hosting services provided by a third party provider
As part of a processing operation on our behalf, a third party provider provides hosting and website display services on our behalf. All data collected in the course of using this website or in forms provided for this purpose in the online shop as described below are processed on its servers. Processing on other servers only takes place within the framework explained here.
This service provider is located within a country of the European Union or the European Economic Area.
2. Data collection and use for contract processing, contacting and opening a customer account
We collect personal data if you voluntarily provide it to us in the context of your order or when contacting us (e.g. via contact form or eMail). Mandatory fields are marked as such, as we need the data in these cases to process the contract or to process your contact and you cannot send the order or contact without providing it. Which data is collected can be seen from the respective input forms. We use the data you provide to process the contract and your enquiries in accordance with Art. 6 Para. 1 S. 1 lit. b GDPR.
If you have given your consent in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR by deciding to open a customer account, we will use your data for the purpose of opening a customer account. Further information on the processing of your data, in particular on the transfer to our service providers for the purpose of order, payment and shipping processing, can be found in the following sections of this data protection declaration.
After complete processing of the contract or deletion of your customer account, your data will be restricted for further processing and deleted after expiry of the retention periods under tax and commercial law in accordance with Art. 6 (1) sentence 1 lit. c DSGVO, unless you have expressly consented to further use of your data in accordance with Art. 6 (1) sentence 1 lit. a GDPR or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration. The deletion of your customer account is possible at any time and can be done either by sending a message to the contact option described in this privacy policy or via a function provided for this purpose in the customer account.
3. Data transfer
In order to fulfil the contract in accordance with Art. 6 para. 1 p. 1 lit. b GDPR, we pass on your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the ordering process, we pass on the payment data collected for this purpose to the credit institution commissioned with the payment and, if applicable, to payment service providers commissioned by us or to the selected payment service. In some cases, the selected payment service providers also collect this data themselves if you create an account with them. In this case, you must register with the payment service provider with your access data during the ordering process. In this respect, the data protection declaration of the respective payment service provider applies.
Data transfer to shipping service providers
If you have given us your express consent during or after your order, we will pass on your eMail address to the selected shipping service provider in accordance with Art. 6 Para. 1 Sentence 1 lit. a GDPR so that the shipping service provider can contact you before delivery for the purpose of delivery notification or coordination.
You can revoke your consent at any time by sending a message to the contact option described below or directly to the shipping service provider at the contact address listed below. After revocation, we will delete your data provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.
Deutsche Post AG
Charles-de-Gaulle-Strasse 20
53113 Bonn
GERMANY
4. eMail Newsletter
eMail advertising with newsletter registration
If you register for our newsletter, we will use the data required for this purpose or separately provided by you to send you our eMail newsletter on a regular basis based on your consent in accordance with Art. 6 Para. 1 Sentence 1 lit. a GDPR.
Unsubscribing from the newsletter is possible at any time and can be done either by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After unsubscribing, we will delete your eMail address from the list of recipients, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.
The newsletter is sent as part of processing on our behalf by a service provider to whom we pass on your eMail address for this purpose. This service provider is located within a country of the European Union or the European Economic Area.
5. Integration of the Trusted Shops Trustbadge
The Trusted Shops Trustbadge is integrated on this website in order to display our Trusted Shops seal of approval and any ratings collected, as well as to offer Trusted Shops products to buyers after they have placed an order.
This serves to protect our legitimate interests in optimal marketing by enabling secure shopping in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR, which prevail in the context of a balancing of interests. The trust badge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany. The Trustbadge is provided by a CDN provider (Content Delivery Network) within the framework of order processing. Trusted Shops GmbH also uses service providers from the USA. An appropriate level of data protection is ensured. Further information on the data protection of Trusted Shops GmbH can be found here.
When the Trustbadge is called up, the web server automatically saves a so-called server log file, which also contains your IP address, the date and time of the call-up, the amount of data transferred and the requesting provider (access data) and documents the call-up. Individual access data are stored in a security database for the analysis of security anomalies. The log files are automatically deleted 90 days after creation at the latest.
Further personal data is transferred to Trusted Shops GmbH if you decide to use Trusted Shops products after completing an order or if you have already registered to use them. The contractual agreement between you and Trusted Shops applies. For this purpose, personal data is automatically collected from the order data. Whether you as a buyer are already registered for product use is automatically checked using a neutral parameter, the eMail address hashed by cryptological one-way function. The eMail address is converted into this hash value, which cannot be decrypted by Trusted Shops, before it is transmitted. After checking for a match, the parameter is automatically deleted.
This is necessary for the fulfilment of our and Trusted Shops’ overriding legitimate interests in the provision of the buyer protection linked to the specific order in each case and the transactional evaluation services in accordance with Art. 6 para. 1 p. 1 lit. f GDPR. Further details, including the objection, can be found in the Trusted Shops privacy policy linked above and in the Trustbadge.
6. Cookies and Web analysis
In order to make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages.
In addition to the requirements of the GDPR, the processing of personal cookies is based on Section 96 (3) of the German Telecommunications Act (TKG).
Cookies are small text files that are automatically stored on your terminal device. Some of the cookies we use are deleted at the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognise your browser on your next visit (persistent cookies).
This serves to protect our legitimate interests in an optimised presentation of our offer, which outweigh our interests in the context of a balancing of interests in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR.
Furthermore, we use cookies for market research and for suitable product advertisements. You can find more information on this in the notes for the respective tool below.
The duration of storage can be found in the overview in the cookie settings of your web browser. You can set your browser in such a way that you are informed about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general.
If you do not accept cookies, however, the functionality of our website may be limited. Below you will find information on the cookies we use and how to set them in your browser.
How can I configure the cookie settings of my browser?
Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. This can be found for the respective browsers under the following links:
Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
What types of cookies are used?
a) Necessary cookies
These cookies are necessary to enable the operation of our website. These include, for example, cookies that enable you to log in to the customer area or to place something in the shopping basket.
b) Analytical / Performance cookies
These cookies allow us to collect anonymous data about the usage behaviour of our visitors. We then analyse this data in order to improve the functionality of the website, for example, and to show you interesting offers.
c) Functional cookies
These cookies are used for certain functionalities of our website, e.g. to suggest a better navigation flow on our website, to show you personalised and relevant information (e.g. “interest-based advertisements”).
d) Targeting cookies
These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to tailor our website and the advertisements you are shown to your interests.
e) Third party cookies
These cookies, from some of our advertising partners, help to make the website and our website more interesting for you. Therefore, when you visit our website, cookies from partner companies are also stored on your hard drive. These are temporary cookies that are automatically deleted after the specified time. Cookies from partner companies are usually deleted after a few days or up to 24 months, in individual cases after several years. The cookies of our partner companies also do not contain any personal data. Data is only collected under a user ID pseudonym. This pseudonymous data is never merged with your personal data.
Use of Google (Universal) Analytics for web analysis
This website uses Google (Universal) Analytics for website analysis. The web analytics service is offered by Google Ireland Limited, a company registered and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, IRELAND (www.google.de). This serves to protect our legitimate interests in an optimised presentation of our offer, which outweigh our interests in the context of a balancing of interests pursuant to Art. 6 (1) p. 1 lit. f GDPR. Google (Universal) Analytics uses methods that enable an analysis of your use of the website, such as cookies. The automatically collected information about your use of this website is usually transferred to a Google server in the USA and stored there. By activating IP anonymisation on this website, the IP address is shortened before transmission within the Member States of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The anonymised IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. After the end of the purpose and the end of the use of Google Analytics by us, the data collected in this context will be deleted.
Insofar as information is transferred to Google servers in the USA and stored there, the US American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has determined an adequate level of data protection for companies certified under the Privacy Shield.
You can prevent the collection of the data generated by the cookie and related to your use of the website (incl. your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de
As an alternative to the browser plug-in, you can click this link to prevent Google Analytics from collecting data on this website in the future. This will place an opt-out cookie on your terminal device. If you delete your cookies, you must click the link again.
7. Online marketing
Google Ads Remarketing
We use Google Ads to advertise this website in Google search results and on third-party websites. For this purpose, the so-called remarketing cookie is set by Google when you visit our website, which automatically enables interest-based advertising by means of a pseudonymous CookieID and on the basis of the pages you have visited. This serves to protect our legitimate interests in the optimal marketing of our website, which outweigh our interests in the context of a balancing of interests in accordance with Art. 6 para. 1 p. 1 lit. f GDPR. After the end of the purpose and the end of the use of Google Ads Remarketing by us, the data collected in this context will be deleted.
Further data processing will only take place if you have consented to Google linking your web and app browsing history to your Google Account and using information from your Google Account to personalise the ads you see on the web. In this case, if they are logged into Google while visiting our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. For this purpose, your personal data will be temporarily linked by Google with Google Analytics data in order to form target groups.
Google Ads is an offer of Google Ireland Limited, a company incorporated and operated under the laws of Ireland, with its registered office at Gordon House, Barrow Street, Dublin 4, IRELAND (www.google.de).
Insofar as information is transferred to Google servers in the USA and stored there, the US American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has determined an adequate level of data protection for companies certified under the Privacy Shield.
You can deactivate the remarketing cookie via this link . In addition, you can obtain information from the Digital Advertising Alliance about the setting of cookies and make settings in this regard.
Google Maps
This website uses Google Maps to visually display geographical information. Google Maps is a service provided by Google Ireland Limited, a company registered and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, IRELAND (www.google.de). This serves to protect our legitimate interests in an optimised presentation of our offer and easy accessibility of our locations, which outweigh our interests in the context of a balancing of interests, in accordance with Art. 6 Para. 1 S. 1 lit. f) GDPR.
When using Google Maps, Google transmits or processes data on the use of the Maps functions by website visitors, which may include in particular the IP address and location data. We have no influence on this data processing. Insofar as information is transferred to Google servers in the USA and stored there, the US American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has determined an adequate level of data protection for companies certified under the Privacy Shield.
To deactivate the Google Maps service and thus prevent data transmission to Google, you must deactivate the Java Script function in your browser. In this case, Google Maps cannot be used or can only be used to a limited extent.
Further information on data processing by Google can be found in Google’s privacy policy. The terms of use for Google Maps contain detailed information on the map service.
Data processing is carried out on the basis of an agreement between jointly responsible parties in accordance with Art. 26 GDPR, which you can view here.
Google Fonts
The script code “Google Fonts” is integrated on this website. Google Fonts is a service provided by Google Ireland Limited, a company incorporated and operated under the laws of Ireland, with its registered office at Gordon House, Barrow Street, Dublin 4, IRELAND (www.google.de). This serves to protect our legitimate interests in a uniform presentation of the content on our website, which outweigh our interests in the context of a balancing of interests, in accordance with Art. 6 Para. 1 lit. f) GDPR. In this context, a connection is established between the browser you are using and Google’s servers. This enables Google to know that our website has been accessed via your IP address.
Insofar as information is transferred to Google servers in the USA and stored there, the US American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has determined an adequate level of data protection for companies certified under the Privacy Shield. Further information on data processing by Google can be found in Google’s privacy policy.
8. Social Media
Use of social plugins from Facebook, Instagram, Pinterest
So-called social plugins (“plugins”) from social networks are used on our website.
When you access a page of our website that contains such a plugin, your browser establishes a direct connection to the servers of the respective social network. The content of the plugin is transmitted directly to your browser by the respective provider and integrated into the page. By integrating the plugins, the providers receive the information that your browser has accessed the corresponding page of our website, even if you do not have a profile or are not currently logged in. This information (including your IP address) is transmitted by your browser directly to a server of the respective provider (possibly in the USA) and stored there. If you are logged in to one of the services, the providers can directly assign your visit to our website to your profile in the respective social network. If you interact with the plugins, for example by clicking the “Like” or “Share” button, the corresponding information is also transmitted directly to a server of the providers and stored there. The information is also published on the social network and displayed there to your contacts. This serves to protect our legitimate interests in optimal marketing of our offer, which outweigh our interests in the context of a balancing of interests pursuant to Art. 6 para. 1 p. 1 lit. f GDPR.
YouTube Video Plugins
Content from third party providers is integrated on this website. This content is provided by Google (“Provider”). YouTube is a service provided by Google Ireland Limited, a company incorporated and operated under the laws of Ireland with its registered office at Gordon House, Barrow Street, Dublin 4, IRELAND (www.google.de).
For videos from YouTube that are embedded on our site, the extended data protection setting is activated. This means that no information from website visitors is collected and stored by YouTube unless they play the video. The integration of the videos serves to protect our legitimate interests in the optimal marketing of our offer, which prevail in the context of a balancing of interests, in accordance with Art. 6 para. 1 p. 1 lit. f GDPR.
If you do not want the social networks to directly assign the data collected via our website to your profile in the respective service, you must log out of the corresponding service before visiting our website. You can also completely prevent the loading of the plugins with add-ons for your browser, e.g. with the script blocker “NoScript“.
Our online presence on Facebook, Youtube, Instagram, Pinterest
Our presence on social networks and platforms serves to improve active communication with our customers and interested parties. We provide information there about our products and ongoing special promotions.
When visiting our online presences on social media, your data may be automatically collected and stored for market research and advertising purposes. So-called usage profiles are created from this data using pseudonyms. These can be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. Cookies are generally used on your terminal device for this purpose. Visitor behaviour and user interests are stored in these cookies. This serves according to Art. 6 Para. 1 lit. f. GDPR, this serves to protect our legitimate interests in an optimised presentation of our offer and effective communication with customers and interested parties, which prevail in the context of a balancing of interests. If you are asked by the respective social media platform operators for consent (agreement) to data processing, e.g. by means of a checkbox, the legal basis for data processing is Art. 6 (1) lit. a GDPR.
Insofar as the aforementioned social media platforms have their headquarters in the USA, the following applies: For the USA, there is an adequacy decision of the European Commission. This goes back to the EU-US Privacy Shield. A current certificate for the respective company can be viewed here.
For detailed information on the processing and use of data by the providers on their sites, as well as a contact option and your rights and setting options in this regard to protect your privacy, in particular opt-out options, please refer to the data protection notices of the providers linked below. Should you still require assistance in this regard, you can contact us.
Facebook: https://www.facebook.com/about/privacy/
The data processing takes place on the basis of an agreement between jointly responsible persons pursuant to Art. 26 GDPR, which you can view here.
Further information on data processing in the context of visiting a Facebook fan page (information on Insights data) can be found here.
Google/ YouTube: https://policies.google.com/privacy?hl=de
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://about.pinterest.com/de/privacy-policy
Option to object (Opt-Out):
Facebook: https://www.facebook.com/settings?tab=ads
Google/ YouTube: https://adssettings.google.com/authenticated?hl=de
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://www.pinterest.de/settings
9. Sending rating reminders by eMail
Rating reminder by Trusted Shops
If you have given us your express consent to this during or after your order in accordance with Art. 6 (1) p. 1 lit. a GDPR, we will transmit your eMail address to Trusted Shops GmbH, Subbelrather Str. 15c, 50823 Cologne, Germany (www.trustedshops.de), so that they can send you a rating reminder by eMail.
This consent can be revoked at any time by sending a message to the contact option described below or directly to Trusted Shops.
If you have given us your express consent to this during or after your order in accordance with Art. 6 (1) sentence 1 lit. a GDPR, we will use your eMail address as a reminder to submit a rating of your order via the rating system we use. This consent can be revoked at any time by sending a message to the contact option described below.
10. Contact options and your rights
As a data subject, you have the following rights:
- pursuant to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;
- pursuant to Art. 16 GDPR, the right to demand the correction of incorrect or incomplete personal data stored by us without delay;
- in accordance with Article 17 of the GDPR, the right to request the erasure of your personal data stored by us, unless further processing is necessary for the exercise of the right to freedom of expression;
- for the exercise of the right to freedom of expression and information;
- to comply with a legal obligation;
- for reasons of public interest or
- the assertion, exercise or defence of legal claims;
- in accordance with Art. 18 GDPR, the right to request the restriction of the processing of your personal data, insofar as
- the accuracy of the data is disputed by you;
- the processing is unlawful, but you object to its erasure;
- we no longer need the data, but you need them to assert, exercise or defend legal claims, or
- you have objected to the processing in accordance with Art. 21 GDPR;
- pursuant to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transferred to another controller;
- pursuant to Art. 77 GDPR, the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.
If you have any questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data, as well as revocation of consent given or objection to a specific use of data, please contact us directly using the contact details in our imprint.
Right of objection After you have exercised your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves the assertion, exercise or defence of legal claims. This does not apply if the processing is for direct marketing purposes. Then we will not further process your personal data for this purpose. |