Tel.: +49 6151 6290 817
This Privacy Notice informs you about the scope of our processing of your personal data (referred to simply as “data” below).
1. Data processing
We process data as part of the operation of our website. Data processing here also includes disclosure by transmission.
An adequacy decision by the EU Commission, the EU-US Privacy Shield, is in place for data transmissions to the US. Under this decision, the Commission has certified that the guarantees for the transmission of data to the US based on the EU-US Privacy Shield comply with EU data protection standards. Where we transmit data to the US, we have identified the participation of our service providers in the EU-US Privacy Shield.
The specific data, processing purposes, legal bases, recipients and transmissions to third countries are listed below:
a) Log file
We log your visit to our website. In doing so, the following data are processed: the name of the website accessed, the date and time of access, the volume of data transmitted, the browser type and version, the operating system you are using, the referrer URL (the website you visited prior to visiting our website), your IP address and the requesting provider. This is necessary to ensure the security of the website. We process the data accordingly on the basis of our legitimate interests in accordance with Article 6 Paragraph 1 f) GDPR. The log file is erased after seven days unless it is required to clarify or to prove specific violations that have been identified within the retention period.
As part of hosting, all data to be processed in connection with the operation of this website are stored. This is necessary to facilitate the operation of the website. We process the data accordingly on the basis of our legitimate interests in accordance with Article 6 Paragraph 1 f) GDPR. In providing our website, we use the services of web hosting providers to whom we submit the above data.
c) Contacting us
If you contact us, your data (name, contact details, if provided by you) and your message will be processed solely for the purpose of processing and dealing with your request. We process these data on the basis of Article 6 Paragraph 1 b) GDPR or Article 6 Paragraph 1 f) GDPR in order to handle your request
d) Customer account
If you open a customer account, you are consenting to your user-related data (name, address, email address, bank details) as well as your usage data (username, password) being stored. This allows us to identify you as a customer and gives you the option to manage your orders.
Your data are processed based on your consent pursuant to Article 6 Paragraph 1 a) GDPR.
We process your order data to execute the purchase contract. We process these data on the basis of Article 6 Paragraph 1 b) GDPR.
We transmit your address data to the company hired to carry out the delivery. Where necessary to execute the contract, we also provide your email address or telephone number to coordinate a delivery date (notification of dispatch) to the company hired to carry out the delivery.
We transmit your transaction data (name, date of order, payment method, date of dispatch and/or receipt, amount and payment recipient, bank details or credit card details) to the payment service provider responsible for processing the payment.
You can erase all cookies stored on your device and adjust the settings on common browsers to prevent the storage of cookies.
In that case, you may need to re-adjust some settings every time you visit this website and accept that this may impact some features.
2. Duration of data storage
We only store personal data for as long as it is necessary for the purposes for which they are processed or until you revoke your consent to their storage. Where statutory retention periods must be observed, the retention period for certain data may be up to ten years regardless of the purposes for processing.
3. Your rights as a data subject
Upon request, you will receive information about all personal data that we have stored about you free of charge at any time.
b) Rectification, erasure, restriction of processing (blocking), right to object
If you no longer consent to the storage of your personal data, or if these data are no longer correct, we will, upon receiving appropriate instructions, arrange for the erasure or blocking of your data or make the necessary corrections (to the extent permitted by applicable law). The same applies if we are only to process your data in future in a restricted manner.
c) Data portability
Upon request, we will provide you with your data in a standard, structured and machine-readable format so that you can, if you wish, transmit your data to another controller.
d) Right to lodge complaints
You have the right to lodge a complaint with the competent supervisory authority:
e) Right to revoke consent with future effect
You have the right to revoke any consent granted at any time with future effect. Your revocation does not affect the lawfulness of the processing prior to revocation.
Data where we are unable to identify the data subject, for example, if they have been anonymised for analytical purposes, are not covered by the above rights. Information, erasure, blocking, rectification or transfer to another company may be possible for these data if you provide us with additional information that permits identification.
g) Exercising your rights as a data subject
If you have any questions regarding the processing of your personal data, or if you would like to request information, rectification, blocking, if you would like to object or have your data erased, or if you wish to transfer your data to another company, please contact firstname.lastname@example.org.
4. Data security
We use SSL 256-bit encryption to ensure the security of the data transmitted to us. You can recognise encrypted connections by the “https://” URL prefix in the page link in your browser’s address bar. Unencrypted websites can be recognised by “http://”.
SSL encryption means that no data you transmit to our website, such as requests or logins, can be read by third parties.