Privacy Policy
privacy policy
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide the data has no consequences. This only applies if no other information is provided in the subsequent processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.
contact
responsible person
Please contact us if you wish. The person responsible for data processing is: Julian Ostler, Hauptstr. 17, 87772 Pfaffenhausen Germany, +491749507309, info@essheept.de
customer's initiative contact via email
If you initiate business contact with us by email, we will only collect your personal data (name, email address, message text) to the extent you provide it. The data processing serves to process and answer your contact request.
If the contact is for the implementation of pre-contractual measures (e.g. advice in the event of interest in purchasing, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 (1) (b) GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in processing and answering your request. In this case, you have the right to object at any time to the processing of personal data concerning you based on Art. 6 (1) (f) GDPR, for reasons arising from your particular situation.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
Collection and processing when using the contact form
When you use the contact form, we only collect your personal data (name, email address, message text) to the extent you provide it. The data processing serves the purpose of establishing contact.
If the contact is for the implementation of pre-contractual measures (e.g. advice in the event of interest in purchasing, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 (1) (b) GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in processing and answering your request. In this case, you have the right to object at any time to the processing of personal data concerning you based on Art. 6 (1) (f) GDPR, for reasons arising from your particular situation.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
orders
reviews Advertising
Data collection when writing a comment or review
When you comment on/rate an article or post, we only collect your personal data (name, email address, comment text) to the extent you provide it. The processing serves the purpose of enabling a comment/rate and displaying comments/rates.
By submitting the comment/review, you consent to the processing of the transmitted data. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the legality of the processing carried out on the basis of the consent until the revocation. Your personal data will then be deleted.
When your comment/review is published, the name and email address you provided published.
We use your email address, regardless of the contract processing, exclusively for our own advertising purposes to send newsletters, provided that you have expressly consented to this. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until the revocation. You can unsubscribe from the newsletter at any time by using the corresponding link in the newsletter or by notifying us. Your email address will then be removed from the mailing list.
Use of the email address for sending direct advertising
We use your email address, which we received as part of the sale of a product or service, to electronically send advertising for our own products or services that are similar to those you have already purchased from us, provided you have not objected to this use. The provision of the email address is necessary for the conclusion of the contract. Failure to provide it means that no contract can be concluded. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in direct advertising. You can object to this use of your email address at any time by notifying us. The contact details for exercising your right of objection can be found in the imprint. You can also use the link provided in the advertising email. There are no costs for this other than the transmission costs according to the basic rates.
Using Klaviyo
We use the service of Klaviyo Inc. (125 Summer St Floor 7, Boston, MA 02111, USA; “Klaviyo”) to send the newsletter. as part of order processing.
We pass on the information you provide when registering for the newsletter (email address, first and last name if applicable) to Klaviyo. The data processing serves the purpose of sending the newsletter and its statistical evaluation.
In order to evaluate newsletter campaigns, the newsletters sent contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any integrated links. In this context, we collect your personal data such as IP address, browser type and device, and the time. User profiles can be created from this data under a pseudonym. The data collected is not used to identify you personally. The data collected is only used to statistical analysis to improve newsletter campaigns.
Your data is usually transferred to Klaviyo servers in the USA and stored there. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Klaviyo has certified itself according to the TADPF and is therefore committed to complying with European data protection principles.
Your personal data is processed on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in a targeted, promotionally effective and user-friendly newsletter system. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
For more information about privacy at Klaviyo, please visit https://www.klaviyo.com/legal/privacy-notice as well as under https://www.klaviyo.com/legal/data-processing-agreement.
shipping service providers inventory management
Passing on the email address to shipping companies to inform them about the shipping status
We will pass on your email address to the transport company as part of the contract processing, provided that you have expressly consented to this during the ordering process. The purpose of the transfer is to inform you of the shipping status by email. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time by notifying us or the transport company, without affecting the legality of the processing carried out on the basis of the consent until the revocation.
use of an external inventory management system
We use a merchandise management system to process the contract as part of order processing. For this purpose, your personal data collected as part of the order will be sent to
Sufio sro, Bottova 1, 81109 Bratislava, Slovakia
transmitted.
The processing of your personal data serves the purpose of fulfilling the contract concluded with you and is carried out on the basis of Art. 6 (1) (b) GDPR.
payment service providers credit report
Using PayPal Express
We use the PayPal Express payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. In order to integrate this payment service, PayPal must collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you visit the website.Cookies can also be used for this purpose. The cookies enable your browser to be recognized.
The processing of your personal data is based on Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest on a customer-oriented offer of different payment methods. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
By selecting and using PayPal Express, the data required for payment processing will be transmitted to PayPal in order to be able to fulfil the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 Paragraph 1 Letter b of GDPR. Further information on data processing when using the PayPal Express payment service can be found in the associated data protection declaration at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS.
Using PayPal Check-Out
We use the PayPal Check-Out payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the payment service. By selecting and using payment via PayPal, credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, the data required for payment processing will be transmitted to PayPal in order to be able to fulfill the contract with you with the selected payment method. This processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.
Cookies may be stored here that enable your browser to be recognized. The resulting data processing is based on Art. 6 (1) (f) GDPR due to our overriding legitimate interest in offering a customer-oriented range of different payment methods. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
Credit card via PayPal, direct debit via PayPal & "Pay later" via PayPal
For individual payment methods such as credit card via PayPal, direct debit via PayPal or “Pay later” via PayPal, PayPal reserves the right to obtain a credit report based on mathematical-statistical procedures using credit agencies. To do this, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received on the statistical probability of a payment default to make a balanced decision about the establishment, implementation or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes, among other things, address data. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protection against payment default if PayPal makes advance payments.
You have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time by notifying PayPal, for reasons arising from your particular situation. The provision of data is necessary for the conclusion of the contract with the payment method you have requested. Failure to provide the data means that the contract cannot be concluded with the payment method you have selected.
third-party providers
When paying using a third-party payment method, the data required for payment processing is transmitted to PayPal. This processing is carried out on the basis of Art. 6 (1) (b) GDPR. To carry out this payment method, the data may then be passed on by PayPal to the respective provider. This processing is carried out on the basis of Art. 6 (1) (b) GDPR. Local third-party providers can be, for example:
purchase on account via PayPal
When paying using the payment method purchase on account, the data required for payment processing is first sent to PayPal. To carry out this payment method, the data is then sent by PayPal to Ratepay GmbH (Franklinstraße 28-29, 10587 Berlin; "Ratepay") in order to be able to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR. Ratepay may carry out a credit check on the basis of mathematical-statistical procedures (probability or score values) using credit agencies according to the process already described above. The data processing serves the purpose of credit checks for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protecting against payment default if Ratepay You can find further information on data protection and which credit agencies use Ratpay at https://www.ratepay.com/legal-payment-dataprivacy/ and https://www.ratepay.com/legal-payment-creditagencies/.
Further information on data processing when using PayPal can be found in the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Data collection and processing during credit checks
If we make advance payments, e.g. when paying by invoice or direct debit, we reserve the right to obtain a credit report based on mathematical-statistical procedures using the Klarna Bank AB (publ), Chausseestrasse 117, 10115 Berlin To do so, we transmit the personal data required for a credit check to them and use the information received on the statistical probability of a payment default to make a balanced decision about the establishment, implementation or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes, among other things, address data. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protection against payment default when we make advance payments. You have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time by notifying us, for reasons arising from your particular situation. The provision of data is necessary for the conclusion of the contract with the payment method you have requested. Failure to provide the data means that the contract cannot be concluded with the payment method you have selected.
cookies
Our website uses cookies. Cookies are small text files that are stored in the Internet browser or by the Internet browser on a user's computer system. When a user visits a website, a cookie can be stored on the user's operating system. This cookie contains a characteristic string that enables the browser to be uniquely identified when the website is visited again.
analysis advertising tracking
Using Shopify Statistics
We use the statistics and analysis functions of Shopify International Ltd. (Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") as part of order processing. Shopify is an affiliate of Shopify Inc. (151 O'Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada).
The data processing serves the purpose of analyzing this website and its visitors. For this purpose, data is stored for marketing and optimization purposes and made available in reports, analyses and statistics. The following device information is collected and processed, among others: information about the web browser, IP address, time zone and some of the cookies installed on your device. When you navigate the website, information about the websites or products accessed, the referrer URL (website through which you accessed our website) and information about how you interact with the website is also collected. Technologies such as cookies as well as web beacons, tags and pixels (electronic files for collecting information about how you navigate the website) are used for this.
Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. For Canada, there is an adequacy decision of the EU Commission. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified according to the TADPF. This data transfer is based on contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.
The use of cookies or similar technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Art. 6 Paragraph 1 Letter a of GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Paragraph 1 Letter a of GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until the revocation.
You can find more information about data protection at Shopify at https://www.shopify.com/de/legal/datenschutz, Information on the order processing contract at https://www.shopify.com/de/legal/dpa and information about the cookies used at https://www.shopify.com/de/legal/cookies.
Use of Google Fonts
We use Google Fonts from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The data processing serves the purpose of uniform display of fonts on our website. In order to load the fonts, a connection is established to Google servers when the page is accessed. Cookies may be used for this purpose. Your IP address and information about the browser you use are processed and sent to Google. This data is not linked to your Google account.
Your data may be transferred to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is therefore committed to complying with European data protection principles.
The use of cookies or similar technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Art. 6 Paragraph 1 Letter a of GDPR.Your personal data will be processed with your consent on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Further information on data processing and data protection can be found at https://www.google.de/intl/de/policies/ as well as under https://developers.google.com/fonts/faq.
Rights of data subjects and storage period
duration of storage
After the contract has been fully processed, the data will initially be stored for the duration of the warranty period, then taking into account statutory retention periods, in particular those under tax and commercial law, and then deleted after the deadline has expired, unless you have consented to further processing and use.
rights of the data subject
If the legal requirements are met, you have the following rights under Art. 15 to 20 GDPR: Right to information, to rectification, to erasure, to restriction of processing, to data portability.
Furthermore, according to Art. 21 Para. 1 GDPR, you have the right to object to processing based on Art. 6 Para. 1 f GDPR and to processing for direct marketing purposes.
right to lodge a complaint with the supervisory authority
According to Art. 77 GDPR, you have the right to complain to the supervisory authority if you believe that the processing of your personal data is not lawful.
You can lodge a complaint with the supervisory authority responsible for us, which you can reach using the following contact details:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Tel.: +49 981 1800930
Fax: +49 981 180093800
E-mail: poststelle@lda.bayern.de
right of objection
If the personal data processing listed here is based on our legitimate interest in accordance with Art. 6 (1) (f) GDPR, you have the right to object to this processing at any time with effect for the future for reasons arising from your particular situation.
Once you have objected, the processing of the data in question will be stopped unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.
If the personal data is processed for direct marketing purposes, you can object to this processing at any time by notifying us. After the objection has been made, we will stop processing the data concerned for direct marketing purposes.
last update: October 22, 2024
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide the data has no consequences. This only applies if no other information is provided in the subsequent processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.
server log files
You can visit our websites without providing any personal information.
Every time you access our website, usage data is transmitted to us or our web host/IT service provider through your Internet browser and stored in protocol data (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred and the requesting provider.
The processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in ensuring the trouble-free operation of our website and improving our offering.
Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. For Canada, there is an adequacy decision of the EU Commission. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified according to the TADPF. This data transfer is based on contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.The processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in ensuring the trouble-free operation of our website and improving our offering.
contact
responsible person
Please contact us if you wish. The person responsible for data processing is: Julian Ostler, Hauptstr. 17, 87772 Pfaffenhausen Germany, +491749507309, info@essheept.de
customer's initiative contact via email
If you initiate business contact with us by email, we will only collect your personal data (name, email address, message text) to the extent you provide it. The data processing serves to process and answer your contact request.
If the contact is for the implementation of pre-contractual measures (e.g. advice in the event of interest in purchasing, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 (1) (b) GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in processing and answering your request. In this case, you have the right to object at any time to the processing of personal data concerning you based on Art. 6 (1) (f) GDPR, for reasons arising from your particular situation.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
Collection and processing when using the contact form
When you use the contact form, we only collect your personal data (name, email address, message text) to the extent you provide it. The data processing serves the purpose of establishing contact.
If the contact is for the implementation of pre-contractual measures (e.g. advice in the event of interest in purchasing, preparation of an offer) or concerns a contract already concluded between you and us, this data processing is carried out on the basis of Art. 6 (1) (b) GDPR.
If contact is made for other reasons, this data processing is carried out on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in processing and answering your request. In this case, you have the right to object at any time to the processing of personal data concerning you based on Art. 6 (1) (f) GDPR, for reasons arising from your particular situation.
We only use your email address to process your request. Your data will then be deleted in compliance with statutory retention periods unless you have consented to further processing and use.
orders
Collection, processing and transfer of personal data when placing orders
When you place an order, we only collect and process your personal data to the extent that this is necessary to fulfil and process your order and to process your enquiries. The provision of the data is necessary for the conclusion of the contract. Failure to provide the data means that no contract can be concluded. The processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR and is necessary for the fulfilment of a contract with you.
Your data will be passed on to, for example, shipping companies, dropshipping or fulfillment providers, payment service providers, service providers for order processing and IT service providers. In all cases, we strictly adhere to the legal requirements. The scope of data transmission is limited to a minimum.
Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. For Canada, there is an adequacy decision of the EU Commission. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified according to the TADPF. This data transfer is based on contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.reviews Advertising
Data collection when writing a comment or review
When you comment on/rate an article or post, we only collect your personal data (name, email address, comment text) to the extent you provide it. The processing serves the purpose of enabling a comment/rate and displaying comments/rates.
By submitting the comment/review, you consent to the processing of the transmitted data. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the legality of the processing carried out on the basis of the consent until the revocation. Your personal data will then be deleted.
When your comment/review is published, the name and email address you provided published.
review reminder
After your order, we would like to ask you to rate your purchase with us.
For this purpose, we use your personal data (name, email address, order information) independently of the contract processing to send you a review reminder by email after you have placed an order, provided that you have expressly consented to this.
The processing is carried out on the basis of Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time by using the corresponding link in the email or by notifying us, without affecting the legality of the processing carried out on the basis of the consent until the revocation.
Use of the email address for sending newslettersAfter your order, we would like to ask you to rate your purchase with us.
For this purpose, we use your personal data (name, email address, order information) independently of the contract processing to send you a review reminder by email after you have placed an order, provided that you have expressly consented to this.
The processing is carried out on the basis of Art. 6 (1) (a) GDPR with your consent. You can revoke your consent at any time by using the corresponding link in the email or by notifying us, without affecting the legality of the processing carried out on the basis of the consent until the revocation.
We use your email address, regardless of the contract processing, exclusively for our own advertising purposes to send newsletters, provided that you have expressly consented to this. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until the revocation. You can unsubscribe from the newsletter at any time by using the corresponding link in the newsletter or by notifying us. Your email address will then be removed from the mailing list.
Use of the email address for sending direct advertising
We use your email address, which we received as part of the sale of a product or service, to electronically send advertising for our own products or services that are similar to those you have already purchased from us, provided you have not objected to this use. The provision of the email address is necessary for the conclusion of the contract. Failure to provide it means that no contract can be concluded. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in direct advertising. You can object to this use of your email address at any time by notifying us. The contact details for exercising your right of objection can be found in the imprint. You can also use the link provided in the advertising email. There are no costs for this other than the transmission costs according to the basic rates.
Using Klaviyo
We use the service of Klaviyo Inc. (125 Summer St Floor 7, Boston, MA 02111, USA; “Klaviyo”) to send the newsletter. as part of order processing.
We pass on the information you provide when registering for the newsletter (email address, first and last name if applicable) to Klaviyo. The data processing serves the purpose of sending the newsletter and its statistical evaluation.
In order to evaluate newsletter campaigns, the newsletters sent contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any integrated links. In this context, we collect your personal data such as IP address, browser type and device, and the time. User profiles can be created from this data under a pseudonym. The data collected is not used to identify you personally. The data collected is only used to statistical analysis to improve newsletter campaigns.
Your data is usually transferred to Klaviyo servers in the USA and stored there. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Klaviyo has certified itself according to the TADPF and is therefore committed to complying with European data protection principles.
Your personal data is processed on the basis of Art. 6 (1) (f) GDPR due to our overriding legitimate interest in a targeted, promotionally effective and user-friendly newsletter system. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
For more information about privacy at Klaviyo, please visit https://www.klaviyo.com/legal/privacy-notice as well as under https://www.klaviyo.com/legal/data-processing-agreement.
shipping service providers inventory management
Passing on the email address to shipping companies to inform them about the shipping status
We will pass on your email address to the transport company as part of the contract processing, provided that you have expressly consented to this during the ordering process. The purpose of the transfer is to inform you of the shipping status by email. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time by notifying us or the transport company, without affecting the legality of the processing carried out on the basis of the consent until the revocation.
use of an external inventory management system
We use a merchandise management system to process the contract as part of order processing. For this purpose, your personal data collected as part of the order will be sent to
Sufio sro, Bottova 1, 81109 Bratislava, Slovakia
transmitted.
The processing of your personal data serves the purpose of fulfilling the contract concluded with you and is carried out on the basis of Art. 6 (1) (b) GDPR.
payment service providers credit report
Using PayPal Express
We use the PayPal Express payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. In order to integrate this payment service, PayPal must collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you visit the website.Cookies can also be used for this purpose. The cookies enable your browser to be recognized.
The processing of your personal data is based on Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest on a customer-oriented offer of different payment methods. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
By selecting and using PayPal Express, the data required for payment processing will be transmitted to PayPal in order to be able to fulfil the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 Paragraph 1 Letter b of GDPR. Further information on data processing when using the PayPal Express payment service can be found in the associated data protection declaration at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS.
Using PayPal Check-Out
We use the PayPal Check-Out payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the payment service. By selecting and using payment via PayPal, credit card via PayPal, direct debit via PayPal or "Pay later" via PayPal, the data required for payment processing will be transmitted to PayPal in order to be able to fulfill the contract with you with the selected payment method. This processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.
Cookies may be stored here that enable your browser to be recognized. The resulting data processing is based on Art. 6 (1) (f) GDPR due to our overriding legitimate interest in offering a customer-oriented range of different payment methods. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
Credit card via PayPal, direct debit via PayPal & "Pay later" via PayPal
For individual payment methods such as credit card via PayPal, direct debit via PayPal or “Pay later” via PayPal, PayPal reserves the right to obtain a credit report based on mathematical-statistical procedures using credit agencies. To do this, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received on the statistical probability of a payment default to make a balanced decision about the establishment, implementation or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes, among other things, address data. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protection against payment default if PayPal makes advance payments.
You have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time by notifying PayPal, for reasons arising from your particular situation. The provision of data is necessary for the conclusion of the contract with the payment method you have requested. Failure to provide the data means that the contract cannot be concluded with the payment method you have selected.
third-party providers
When paying using a third-party payment method, the data required for payment processing is transmitted to PayPal. This processing is carried out on the basis of Art. 6 (1) (b) GDPR. To carry out this payment method, the data may then be passed on by PayPal to the respective provider. This processing is carried out on the basis of Art. 6 (1) (b) GDPR. Local third-party providers can be, for example:
- Apple Pay (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
- Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)
- giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main)
purchase on account via PayPal
When paying using the payment method purchase on account, the data required for payment processing is first sent to PayPal. To carry out this payment method, the data is then sent by PayPal to Ratepay GmbH (Franklinstraße 28-29, 10587 Berlin; "Ratepay") in order to be able to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR. Ratepay may carry out a credit check on the basis of mathematical-statistical procedures (probability or score values) using credit agencies according to the process already described above. The data processing serves the purpose of credit checks for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protecting against payment default if Ratepay You can find further information on data protection and which credit agencies use Ratpay at https://www.ratepay.com/legal-payment-dataprivacy/ and https://www.ratepay.com/legal-payment-creditagencies/.
Further information on data processing when using PayPal can be found in the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Data collection and processing during credit checks
If we make advance payments, e.g. when paying by invoice or direct debit, we reserve the right to obtain a credit report based on mathematical-statistical procedures using the Klarna Bank AB (publ), Chausseestrasse 117, 10115 Berlin To do so, we transmit the personal data required for a credit check to them and use the information received on the statistical probability of a payment default to make a balanced decision about the establishment, implementation or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes, among other things, address data. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in protection against payment default when we make advance payments. You have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time by notifying us, for reasons arising from your particular situation. The provision of data is necessary for the conclusion of the contract with the payment method you have requested. Failure to provide the data means that the contract cannot be concluded with the payment method you have selected.
Using Klarna payment options
We use the payment service of Klarna Bank AB (publ) (Sveavägen 46, 111 34 Stockholm, Sweden; “Klarna”) on our website. By selecting and using payment via Klarna, the data required for payment processing will be transmitted to Klarna in order to be able to fulfill the contract with you using the selected payment method. This processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.
Cookies may be stored here that enable your browser to be recognized. The resulting data processing is based on Art. 6 (1) (f) GDPR due to our overriding legitimate interest in offering a customer-oriented range of different payment methods. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
Cookies may be stored here that enable your browser to be recognized. The resulting data processing is based on Art. 6 (1) (f) GDPR due to our overriding legitimate interest in offering a customer-oriented range of different payment methods. You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
“Pay Later” (invoice), “Pay Now” (payment by direct debit, credit card, instant transfer), “Financing” (installment purchase)
For individual payment methods such as “Pay Later” (invoice), “Pay Now” (payment by direct debit, credit card, instant bank transfer), “Financing” (installment purchase), Klarna reserves the right to obtain a credit report based on mathematical-statistical procedures using credit agencies.
For this purpose Klarna the personal data required for a credit check, such as first and last name, address, gender, email address, IP address and data related to the order for the purpose of identity and credit check to a credit agency and uses the information received on the statistical probability of a payment default for a balanced decision on the establishment, implementation or termination of the contractual relationship. The credit report may contain probability values (score values) that are calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes, among other things, address data. Your legitimate interests are taken into account in accordance with the statutory provisions. The data processing serves the purpose of the credit check for the initiation of a contract. The processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR from our overriding legitimate interest in protection against payment default if Klarna makes an advance payment. You have the right to object to this processing of personal data concerning you based on Art. 6 (1) (f) GDPR at any time by notifying Klarna, for reasons arising from your particular situation. The provision of data is necessary for the conclusion of the contract with the payment method you have requested. Failure to provide the data means that the contract cannot be concluded with the payment method you have selected.
For further information, in particular to which credit agencies Klarna passes on your personal data, please see for Germany at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies and for Austria under https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/credit_rating_agencies.
General information about Klarna for Germany can be found at: https://www.klarna.com/de/ and for Austria under https://www.klarna.com/at/Your personal data will be processed by Klarna in accordance with the applicable data protection regulations and as set out in Klarna's privacy policy for Germany at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy and for Austria under https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy treated.
cookies
Our website uses cookies. Cookies are small text files that are stored in the Internet browser or by the Internet browser on a user's computer system. When a user visits a website, a cookie can be stored on the user's operating system. This cookie contains a characteristic string that enables the browser to be uniquely identified when the website is visited again.
Cookies are stored on your computer. You therefore have full control over the use of cookies. By selecting the appropriate technical settings in your Internet browser, you can be notified before cookies are set and decide individually whether to accept them, as well as prevent the cookies from being stored and the data they contain from being transmitted. Cookies that have already been stored can be deleted at any time. However, we would like to point out that you may then not be able to use all of the functions of this website to their full extent.
The links below will tell you how to manage (including deactivate) cookies in the most important browsers:
Chrome: https://support.google.com/accounts/answer/61416?hl=de
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Technically necessary cookies
Unless otherwise stated in the privacy policy below, we only use these technically necessary cookies for the purpose of making our service more user-friendly, effective and secure. Cookies also enable our systems to recognize your browser even after you change pages and to offer you services. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after you change pages.
The use of cookies or similar technologies is based on Section 25 Paragraph 2 TDDDG. The processing of your personal data is based on Art. 6 Paragraph 1 Letter f GDPR due to our overriding legitimate interest to ensure the optimal functionality of the website and a user-friendly and effective design of our offering.
You have the right to object to the processing of personal data concerning you at any time for reasons related to your particular situation.
analysis advertising tracking
Using Shopify Statistics
We use the statistics and analysis functions of Shopify International Ltd. (Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") as part of order processing. Shopify is an affiliate of Shopify Inc. (151 O'Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada).
The data processing serves the purpose of analyzing this website and its visitors. For this purpose, data is stored for marketing and optimization purposes and made available in reports, analyses and statistics. The following device information is collected and processed, among others: information about the web browser, IP address, time zone and some of the cookies installed on your device. When you navigate the website, information about the websites or products accessed, the referrer URL (website through which you accessed our website) and information about how you interact with the website is also collected. Technologies such as cookies as well as web beacons, tags and pixels (electronic files for collecting information about how you navigate the website) are used for this.
Your data may be transferred to third countries outside the EU, in particular to Canada and the USA, and processed there. For Canada, there is an adequacy decision of the EU Commission. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified according to the TADPF. This data transfer is based on contractual obligations that are comparable to those of the EU Commission's standard contractual clauses.
The use of cookies or similar technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Art. 6 Paragraph 1 Letter a of GDPR. The processing of your personal data takes place with your consent on the basis of Art. 6 Paragraph 1 Letter a of GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until the revocation.
You can find more information about data protection at Shopify at https://www.shopify.com/de/legal/datenschutz, Information on the order processing contract at https://www.shopify.com/de/legal/dpa and information about the cookies used at https://www.shopify.com/de/legal/cookies.
Using the Meta Pixel
We use the meta pixel of Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; "Meta") on our website.
Meta and we are jointly responsible for the collection of your data when integrating the service and the transmission of this data to Meta. The basis for this is an agreement between us and Meta on the joint processing of personal data, in which the respective responsibilities are specified. The agreement is available at https://de-de.facebook.com/legal/terms/businesstools We are then responsible in particular for fulfilling the information obligations pursuant to Art. 13, 14 GDPR, for compliance with the security requirements of Art. 32 GDPR with regard to the correct technical implementation and configuration of the service, and for compliance with the obligations pursuant to Art.33, 34 GDPR, insofar as a breach of the protection of personal data affects our obligations under the joint processing agreement. Meta is responsible for enabling the rights of the data subject in accordance with Art. 15 - 20 GDPR, for complying with the security requirements of Art. 32 GDPR with regard to the security of the service and for complying with the obligations under Art. 33, 34 GDPR, insofar as a breach of the protection of personal data affects Meta's obligations under the joint processing agreement.
The purpose of the application is to target website visitors with interest-based advertising on the social networks Facebook and Instagram. For this purpose, the Meta remarketing tag has been implemented on the website. This tag establishes a direct connection to the Meta servers when you visit the website. This transmits to the Meta server which of our pages you have visited. Meta assigns this information to your personal Facebook and/or Instagram user account. When you visit the social networks Facebook or Instagram, you will then be shown personalized, interest-based ads.
The application also serves the purpose of creating conversion statistics. This tells us the total number of users who clicked on one of our ads and were redirected to a page with a conversion tracking tag, as well as what actions were taken after being redirected to this website. However, we do not receive any information that can be used to personally identify users.
Your data may be transferred to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Meta has certified itself according to the TADPF and therefore obliged to comply with European data protection principles.
Your personal data will be processed with your consent on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
You can deactivate the “Custom Audiences” remarketing function here. For more information about the collection and use of data by Meta, your rights in this regard and options for protecting your privacy, please see Meta’s privacy policy at https://www.facebook.com/about/privacy/.
You can deactivate the “Custom Audiences” remarketing function here. For more information about the collection and use of data by Meta, your rights in this regard and options for protecting your privacy, please see Meta’s privacy policy at https://www.facebook.com/about/privacy/.
Use of Google Fonts
We use Google Fonts from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The data processing serves the purpose of uniform display of fonts on our website. In order to load the fonts, a connection is established to Google servers when the page is accessed. Cookies may be used for this purpose. Your IP address and information about the browser you use are processed and sent to Google. This data is not linked to your Google account.
Your data may be transferred to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is therefore committed to complying with European data protection principles.
The use of cookies or similar technologies takes place with your consent on the basis of Section 25 Paragraph 1 Sentence 1 TDDDG in conjunction with Art. 6 Paragraph 1 Letter a of GDPR.Your personal data will be processed with your consent on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of your consent until the revocation.
Further information on data processing and data protection can be found at https://www.google.de/intl/de/policies/ as well as under https://developers.google.com/fonts/faq.
Rights of data subjects and storage period
duration of storage
After the contract has been fully processed, the data will initially be stored for the duration of the warranty period, then taking into account statutory retention periods, in particular those under tax and commercial law, and then deleted after the deadline has expired, unless you have consented to further processing and use.
rights of the data subject
If the legal requirements are met, you have the following rights under Art. 15 to 20 GDPR: Right to information, to rectification, to erasure, to restriction of processing, to data portability.
Furthermore, according to Art. 21 Para. 1 GDPR, you have the right to object to processing based on Art. 6 Para. 1 f GDPR and to processing for direct marketing purposes.
right to lodge a complaint with the supervisory authority
According to Art. 77 GDPR, you have the right to complain to the supervisory authority if you believe that the processing of your personal data is not lawful.
You can lodge a complaint with the supervisory authority responsible for us, which you can reach using the following contact details:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Tel.: +49 981 1800930
Fax: +49 981 180093800
E-mail: poststelle@lda.bayern.de
right of objection
If the personal data processing listed here is based on our legitimate interest in accordance with Art. 6 (1) (f) GDPR, you have the right to object to this processing at any time with effect for the future for reasons arising from your particular situation.
Once you have objected, the processing of the data in question will be stopped unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.
If the personal data is processed for direct marketing purposes, you can object to this processing at any time by notifying us. After the objection has been made, we will stop processing the data concerned for direct marketing purposes.
last update: October 22, 2024