1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about how we handle your personal data when you use our website. Personal data means all data that can be used to personally identify you.
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is [Shop Name]. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the lock symbol in your browser’s address bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
When you use our website purely for informational purposes, i.e., when you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which is technically necessary for us to display the website correctly:
-
The website visited
-
Date and time of access
-
Amount of data transmitted (in bytes)
-
Source/referrer from which you accessed the site
-
Browser used
-
Operating system used
-
IP address used (in anonymized form, where applicable)
Processing takes place in accordance with Art. 6 (1) lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. Data is neither disclosed nor used for other purposes. However, we reserve the right to check the server log files retrospectively if there are concrete indications of unlawful use.
3) COOKIES
To make your visit to our website attractive and enable the use of certain features, we use cookies on various pages. Cookies are small text files that are stored on your device. Some of the cookies we use are deleted after your browser session ends (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser the next time you visit (persistent cookies).
When cookies are set, they collect and process certain user information, such as browser and location data as well as IP addresses. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie. Some cookies help simplify the ordering process by storing settings (e.g., remembering items placed in a virtual shopping cart for a later visit).
If personal data is processed through cookies we set, processing takes place either in accordance with Art. 6 (1) lit. b GDPR (for contract execution) or in accordance with Art. 6 (1) lit. f GDPR (for our legitimate interest in providing the best possible website functionality and a user-friendly browsing experience).
In certain cases, we collaborate with advertising partners who help us make our website more interesting for you. For this purpose, third-party cookies from these partner companies may also be stored on your device when you visit our site. If we cooperate with such partners, you will be informed separately about the use of these cookies and the scope of data collected.
Please note: You can configure your browser to notify you when cookies are being set and decide individually whether to accept them, exclude cookies for specific cases, or disable them entirely. Each browser manages cookie settings differently. You can find instructions in your browser’s help menu at the following links:
-
Internet Explorer: Microsoft Support
-
Firefox: Mozilla Support
-
Chrome: Google Support
-
Safari: Apple Support
-
Opera: Opera Help
Please be aware that disabling cookies may limit the functionality of our website.
4) CONTACTING US
When you contact us (e.g., via contact form or email), personal data will be collected. The specific data collected depends on the contact form you use. This data is stored and used exclusively for the purpose of responding to your inquiry or establishing contact, including the related technical administration.
The legal basis for processing your data is our legitimate interest in responding to your request in accordance with Art. 6 (1) lit. f GDPR. If your inquiry aims to conclude a contract, the additional legal basis for processing is Art. 6 (1) lit. b GDPR.
Your data will be deleted once your inquiry has been fully resolved, provided there are no statutory retention requirements that require further storage.
5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING
In accordance with Art. 6 (1) lit. b GDPR, personal data will continue to be collected and processed when you provide it to us for the purpose of performing a contract or opening a customer account. The type of data collected can be found in the respective input forms.
You can delete your customer account at any time by sending a message to the controller mentioned above. We store and use the data you provide for contract processing. After the contract has been fully performed or your customer account has been deleted, your data will be blocked with respect to statutory retention periods in commercial and tax law and deleted after these periods expire, unless you have expressly consented to further use of your data, or we are legally permitted to retain the data for other purposes, which we will inform you about in this policy.
6) USE OF YOUR DATA FOR DIRECT MARKETING
6.1 Subscription to Our Email Newsletter
When you subscribe to our email newsletter, we will send you regular updates on our offers. The only mandatory information required is your email address. Any additional information you provide is voluntary and will be used to address you personally.
We use the so-called double opt-in procedure to send our newsletters. This means you will only receive the newsletter if you have expressly confirmed to us that you wish to receive it. We will then send you a confirmation email asking you to click a confirmation link to confirm your subscription.
By activating this confirmation link, you consent to our use of your personal data in accordance with Art. 6 (1) lit. a GDPR. When you register for the newsletter, we also store your IP address as provided by your internet service provider (ISP), as well as the date and time of registration, in order to trace any misuse of your email address.
The data we collect when you register for the newsletter will be used exclusively for sending promotional communications via our newsletter. You can unsubscribe at any time by clicking the unsubscribe link in the newsletter or by sending us a message. After you unsubscribe, your email address will be immediately deleted from our distribution list, unless you have expressly consented to further use of your data or we are legally permitted to continue using it.
6.2 Sending of Email Newsletters to Existing Customers
If you have provided us with your email address when purchasing goods or services, we may regularly send you offers for similar products or services from our range by email, even without your express consent.
This processing is based solely on our legitimate interest in personalized direct advertising in accordance with Art. 6 (1) lit. f GDPR. If you initially objected to this use of your email address, no such messages will be sent.
You may object at any time to the use of your email address for advertising purposes, with effect for the future, by contacting the controller listed above. You will only incur transmission costs according to the basic tariffs. Once we receive your objection, your email address will no longer be used for advertising purposes.
7) DATA PROCESSING FOR ORDER PROCESSING
7.1 General Information
We collect and process personal data as part of order fulfillment. This data will be passed on to the transport company responsible for delivery, provided this is necessary to deliver the goods.
Your payment data will also be shared with the financial institution handling the payment, where required for payment processing. If we use payment service providers, you will be informed separately below.
The legal basis for the transfer of data is Art. 6 (1) lit. b GDPR.
7.2 Use of Payment Service Providers
PayPal
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or—if available—“purchase on account” or “installment payment” via PayPal, your payment details will be passed on to:
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (“PayPal”).
The transfer takes place in accordance with Art. 6 (1) lit. b GDPR and only insofar as it is required for payment processing.
PayPal reserves the right to carry out a credit check for payment methods such as credit card via PayPal, direct debit via PayPal, or—if offered—purchase on account or installment payments. For this purpose, your payment data may be transmitted to credit agencies based on PayPal’s legitimate interest in assessing your creditworthiness in accordance with Art. 6 (1) lit. f GDPR.
The result of the credit check (including probability values, so-called “score values”) will be used by PayPal to decide whether the respective payment method is offered. These score values are based on scientifically recognized mathematical-statistical methods that may also use address data.
For further information, including details of the credit agencies used, please refer to PayPal’s privacy policy:
👉 https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You may object to PayPal’s processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if necessary for contractual payment handling.
SOFORT (Klarna Group)
If you select the payment method “SOFORT,” payment processing is carried out by:
SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (“SOFORT”), a company of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden).
We will pass on the information you provide during the ordering process, together with details about your order, to SOFORT in accordance with Art. 6 (1) lit. b GDPR.
The transfer of your data is made solely for the purpose of payment processing and only to the extent necessary for it.
Further information on SOFORT’s privacy policy can be found here:
👉 https://www.klarna.com/sofort/datenschutz
8) CONTACT FOR REVIEW REMINDERS
Custom Review Reminder (not sent via a customer review system)
We use your email address for a one-time reminder to submit a review of your order within the review system we employ, provided that you have expressly given us your consent to do so in accordance with Art. 6 (1) lit. a GDPR during or after placing your order.
You may withdraw your consent at any time by sending a message to the controller responsible for data processing.
9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS
9.1 Facebook Plugins with Shariff Solution
Please note that any additional customs clearance charges and/or import duties are not included in the price and must be borne by the customer.
Our website uses so-called social plugins (“plugins”) of the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”).
To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins but rather embedded into the page only via an HTML link. This type of integration ensures that when accessing a page of our website that contains such buttons, no direct connection is established with the servers of Facebook. Only when you click the button will a new browser window open, directing you to the Facebook page where you can (if necessary, after logging in) interact with the plugins there.
Facebook Inc., headquartered in the USA, is certified under the EU-U.S. Privacy Shield agreement, ensuring compliance with the data protection standards applicable in the EU.
For more details on the purpose and scope of data collection, further processing and use of the data by Facebook, as well as your related rights and settings to protect your privacy, please refer to Facebook’s Data Policy: https://www.facebook.com/policy.php
9.2 Google+ Plugins with Shariff Solution
Our website also uses so-called social plugins (“plugins”) of the social network Google+, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
To protect your data, these buttons are likewise embedded only as HTML links. This ensures that no connection is made to Google’s servers when you access a page of our site containing such buttons. Only when you click the button will a new browser window open and load the Google+ page, where you can interact with its plugins (if necessary, after logging in).
Google LLC, based in the USA, is certified under the EU-U.S. Privacy Shield, ensuring compliance with EU data protection standards.
Further information on Google’s data collection, processing, and your privacy rights can be found in Google’s Privacy Policy: https://www.google.com/intl/en/policies/privacy/
9.3 Instagram Plugins with Shariff Solution
Our website also integrates social plugins (“plugins”) of the online service Instagram, operated by Instagram LLC., 1601 Willow Rd, Menlo Park, CA 94025, USA (“Instagram”).
Again, for your data protection, these buttons are embedded only as HTML links rather than as full plugins. This prevents any automatic connection with Instagram’s servers when visiting our site. Only by clicking the button will a new browser window open, redirecting you to Instagram where you can (after logging in, if required) use the plugin features.
Instagram LLC, based in the USA, is certified under the EU-U.S. Privacy Shield, ensuring compliance with EU data protection standards.
Further details on the purpose and scope of Instagram’s data collection, use, and your privacy rights can be found in Instagram’s Privacy Policy: https://help.instagram.com/155833707900388/
10) ONLINE MARKETING
10.1 DoubleClick by Google
This website uses the online marketing tool DoubleClick by Google, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“DoubleClick”).
DoubleClick uses cookies to display ads relevant to users, improve campaign performance reports, or prevent users from seeing the same ads multiple times. Using a cookie ID, Google tracks which ads are displayed in which browser and can thus prevent them from being shown more than once. Processing is carried out on the basis of our legitimate interest in the optimal marketing of our website in accordance with Art. 6 (1) lit. f GDPR.
In addition, DoubleClick may use cookie IDs to record so-called conversions related to ad requests. This happens, for example, when a user sees a DoubleClick ad and later, with the same browser, visits the advertiser’s website and makes a purchase. According to Google, DoubleClick cookies do not contain personal information.
Because of the marketing tools used, your browser automatically establishes a direct connection with Google’s server. We have no influence over the scope and further use of the data collected by Google through this tool, and therefore inform you according to our knowledge: by integrating DoubleClick, Google receives the information that you have accessed the relevant part of our website or clicked on one of our ads. If you are registered with a Google service, Google can associate the visit with your account. Even if you are not registered with Google or are not logged in, it is possible that the provider will learn and store your IP address.
If you wish to object to participation in this tracking, you can deactivate cookies for conversion tracking by setting your browser to block cookies from the domain www.googleadservices.com (settings link). Please note that this setting will be deleted if you clear your cookies. Alternatively, you can visit the Digital Advertising Alliance at www.aboutads.info to learn more about cookie placement and manage your settings. Finally, you can configure your browser to notify you whenever cookies are set and decide individually whether to accept them, or exclude acceptance of cookies in certain cases or in general. If cookies are not accepted, the functionality of our website may be limited.
Google LLC, based in the USA, is certified under the EU-U.S. Privacy Shield agreement, ensuring compliance with EU data protection standards.
Further information about DoubleClick by Google’s privacy policy can be found here: https://www.google.de/policies/privacy/
10.2 Use of Google AdWords Conversion Tracking
This website uses the online advertising program “Google AdWords” and, within the framework of Google AdWords, the conversion tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
We use Google AdWords to draw attention to our attractive offers on external websites with the help of advertising tools (so-called Google AdWords). Based on the campaign data, we can measure how successful the individual advertising measures are. We pursue the legitimate interest of showing you advertisements that are of interest to you, making our website more appealing, and achieving a fair calculation of advertising costs.
The conversion tracking cookie is set when a user clicks on an ad placed by Google. Cookies are small text files stored on your computer system. These cookies usually expire after 30 days and are not intended for personal identification. If the user visits specific pages of this website and the cookie has not expired, Google and we can recognize that the user clicked on the ad and was redirected to that page.
Each Google AdWords customer receives a different cookie, so cookies cannot be tracked across the websites of other AdWords customers. The information collected using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers are informed of the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that personally identifies users.
If you do not wish to participate in tracking, you can block this use by disabling the Google Conversion Tracking cookie in your browser’s user settings. You will then not be included in the conversion tracking statistics.
We use Google AdWords based on our legitimate interest in targeted advertising in accordance with Art. 6 (1) lit. f GDPR.
Google LLC, based in the USA, is certified under the EU-U.S. Privacy Shield agreement, ensuring compliance with EU data protection standards.
For more information on Google’s privacy policies, please visit: https://www.google.de/policies/privacy/
You can permanently disable cookies for ad preferences by adjusting your browser settings or downloading and installing the browser plug-in available at this link: https://www.google.com/settings/ads/plugin?hl=en.
Please note that some functions of this website may not work or may only be partially usable if you disable the use of cookies.
11) WEB ANALYTICS SERVICES
Google (Universal) Analytics
This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses so-called “cookies,” text files stored on your computer, which enable an analysis of your use of the website. The information generated by the cookie about your use of this website (including the truncated IP address) is generally transmitted to and stored by Google on a server in the USA.
This website uses Google Analytics exclusively with the extension “_anonymizeIp()”, which ensures anonymization of the IP address by truncation and excludes direct personal reference. Within member states of the European Union or other contracting states of the European Economic Area Agreement, your IP address is shortened by Google before transmission. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. In such cases, processing is carried out in accordance with Art. 6 (1) lit. f GDPR, based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.
On our behalf, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide us with other services relating to website usage and internet usage. The IP address transmitted by your browser within the framework of Google Analytics will not be merged with other data from Google.
You may prevent the storage of cookies by selecting the appropriate settings in your browser software. However, please note that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting and processing the data generated by the cookie and related to your website usage (including your IP address) by downloading and installing the browser plug-in available here: https://tools.google.com/dlpage/gaoptout?hl=en.
Alternatively, especially on mobile devices, you can click the following link to set an opt-out cookie that will prevent Google Analytics from collecting data on this website in the future (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies, you must click the link again): Disable Google Analytics.
Google LLC, based in the USA, is certified under the EU-U.S. Privacy Shield agreement, ensuring compliance with EU data protection standards.
This website also uses Google Analytics for cross-device analysis of visitor flows conducted via a User ID. When you first access a page, you are assigned a unique, permanent, and anonymized ID, which is set across devices. This allows interaction data from different devices and sessions to be assigned to a single user. The User ID does not contain personal data and does not transmit such data to Google.
You may object to the collection and storage of data via the User ID at any time with effect for the future. To do so, you must deactivate Google Analytics on all systems you use, for example, in another browser or on your mobile device.
Deactivation can be carried out using a Google browser plug-in: https://tools.google.com/dlpage/gaoptout?hl=en.
Further information on Universal Analytics can be found here: https://support.google.com/analytics/answer/2838718?hl=en
12) RETARGETING / REMARKETING / REFERRAL ADVERTISING
Google AdWords Remarketing
Our website uses the functions of Google AdWords Remarketing, through which we advertise this website in Google search results as well as on third-party websites. The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
For this purpose, Google sets a cookie in your device’s browser that automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Processing is carried out on the basis of our legitimate interest in the optimal marketing of our website in accordance with Art. 6 (1) lit. f GDPR.
Any additional processing will only take place if you have given Google your consent to link your internet and app browsing history with your Google account, and to use information from your Google account to personalize the ads you view on the web. If you are logged into Google while visiting our website, Google uses your data together with Google Analytics data to create and define target audience lists for cross-device remarketing. In doing so, your personal data is temporarily linked by Google with Google Analytics data to form target groups.
You can permanently deactivate the setting of cookies for ad personalization by downloading and installing the browser plug-in available here:
https://www.google.com/settings/ads/onweb/
Alternatively, you can obtain information about the setting of cookies at the Digital Advertising Alliance website (www.aboutads.info) and adjust your settings there.
Google LLC, based in the USA, is certified under the EU-U.S. Privacy Shield agreement, ensuring compliance with EU data protection standards.
Further details and information about Google’s privacy policy regarding advertising can be found here:
https://www.google.com/policies/technologies/ads/
13) DATA SUBJECT RIGHTS
13.1 The applicable data protection law grants you the following rights concerning the processing of your personal data (data subject rights), which you may exercise against the controller responsible for data processing:
-
Right of access pursuant to Art. 15 GDPR: You have the right to obtain confirmation as to whether personal data concerning you is being processed, and if so, to receive information about such data and a copy thereof, along with certain supplementary details.
-
Right to rectification pursuant to Art. 16 GDPR: You have the right to request the correction of inaccurate personal data concerning you, and/or the completion of incomplete data stored by us, without undue delay.
-
Right to erasure (“right to be forgotten”) pursuant to Art. 17 GDPR: You have the right to request the erasure of your personal data when the requirements of Art. 17 (1) GDPR are met. However, this right does not apply where processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.
-
Right to restriction of processing pursuant to Art. 18 GDPR: You have the right to request restriction of processing of your personal data, provided one of the conditions set out in Art. 18 (1) GDPR is met (e.g., you contest the accuracy of the data, or the processing is unlawful but you oppose its erasure).
-
Right to be informed pursuant to Art. 19 GDPR: If you have asserted the right to rectification, erasure, or restriction of processing against the controller, they are obliged to notify all recipients to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed about those recipients.
-
Right to data portability pursuant to Art. 20 GDPR: You have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, or to request its transfer to another controller, where technically feasible.
-
Right to withdraw consent pursuant to Art. 7 (3) GDPR: You have the right to withdraw consent to processing of your data at any time with effect for the future. Upon withdrawal, we will immediately cease processing based on such consent. The withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
-
Right to lodge a complaint pursuant to Art. 77 GDPR: If you believe that the processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.
13.2 Right to Object
If your personal data is processed based on our overriding legitimate interest pursuant to Art. 6 (1) lit. f GDPR, you have the right, at any time, to object to such processing on grounds relating to your particular situation. This also applies to profiling based on these provisions.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or if processing serves the establishment, exercise, or defense of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to processing concerning such marketing. This also applies to profiling to the extent that it is related to direct marketing. If you object, your personal data will no longer be used for direct marketing purposes.
You may exercise your right to object by contacting us accordingly.
14) DURATION OF STORAGE OF PERSONAL DATA
The duration for which personal data is stored is determined by the respective legal retention period (e.g., retention periods under commercial and tax law). After the expiry of this period, the data will be routinely deleted, provided it is no longer required for the performance or initiation of a contract, and/or we have no legitimate interest in continued storage.