1) Information about the collection of personal data and contact details of the person responsible
1.1 We are pleased that you are visiting our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data are all data with which you can be personally identified.
1.2 Responsible for data processing on this website in terms of the General Data Protection Regulation (GDPR) is SENAVE UG (limited liability), Moldauweg 14, 21109 Hamburg, Germany, Tel .: 015901372343, email: firstname.lastname@example.org. The person responsible for the processing of personal data is the natural or legal person who, alone or together with others, decides on the purposes and means of processing personal data.
1.3 For security reasons and to protect the transfer of personal data and other confidential content (e.g. orders or inquiries to the person responsible), this website uses an SSL or. TLS encryption. You can recognize an encrypted connection by the string "https: //" and the lock symbol in your browser line.
2) Data collection when visiting our website
When using our website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to show you the website:
- Our website visited
- Date and time at the time of access
- Amount of data sent in bytes
- Source / reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if necessary: in anonymous form)
Processing takes place in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are specific indications of illegal use.
Hosting through Shopify
We use the shop system of the service provider Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify"), for the purpose of hosting and displaying the online shop on the basis of a Processing on our behalf. All data collected on our website is processed on Shopify's servers. As part of the aforementioned Shopify services, data can also be processed as part of further processing on behalf of Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc .or Shopify (USA) Inc. In the event of data being transmitted to Shopify Inc. in Canada, the adequacy decision of the European Commission guarantees the appropriate level of data protection. Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc. and Shopify (USA) Inc. in the USA are certified for the us-European data protection convention "Privacy Shield", which ensures compliance with the data protection level applicable in the EU guaranteed.
You can find further information on Shopify's data protection at the following website: https://www.shopify.de/legal/datenschutz
Further processing on servers other than those mentioned by Shopify will only take place within the framework communicated below.
In order to make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your device and enable you to recognize your browser the next time you visit (so-called persistent cookies). If cookies are set, they collect and process certain user information such as browser and location data as well as IP address values to the individual extent. Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie. The duration of the respective cookie storage can be found in the overview of the cookie settings of your web browser.
Some of the cookies are used to simplify the ordering process by saving settings (e.g. remembering the content of a virtual shopping cart for a later visit to the website). If personal data is also processed by individual cookies we use, the processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR either to implement the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the case of a given consent or according to Art. 6 Para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.
Please note that you can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. Every browser differs in the way it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browser under the following links:
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Please note that the functionality of our website may be restricted if cookies are not accepted.
5) Contact us
When contacting us (e.g. via contact form or email), personal data is collected. The respective contact form shows which data is collected in the case of a contact form. This data is stored and used exclusively for the purpose of answering your request or for contacting you and the associated technical administration. The legal basis for processing this data is our legitimate interest in answering your request in accordance with Art. 6 Para. 1 lit. f GDPR. If your contact is aimed at the conclusion of a contract, then an additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after your request has been processed. This is the case if it can be inferred from the circumstances that the matter in question has been finally clarified and provided that there are no statutory retention requirements.
6) Data processing when opening a customer account and for contract processing
According to Art. 6 Para. 1 lit. b GDPR, personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. It is possible to delete your customer account at any time and can send a message to the above. Address of the person responsible. We save and use the data you provide for contract processing. After completion of the contract or deletion of your customer account, your data will be blocked with due regard to tax and commercial law retention periods and deleted after the expiry of these deadlines, unless you have expressly consented to further use of your data or a legally permitted further data use on our part is reserved has been.
7) Use of your data for direct advertising
7.1 Sign up for our email newsletter
If you register for our e-mail newsletter, we will send you regular information about our offers. The only mandatory information for sending the newsletter is your email address. The provision of further data is voluntary and is used to address you personally. We use the so-called double opt-in procedure to send the newsletter. This means that we will only send you an e-mail newsletter if you have expressly confirmed to us that you consent to receiving the newsletter. We will then send you a confirmation e-mail asking you to click the corresponding link to confirm that you want to receive the newsletter in the future.
By activating the confirmation link, you give us your consent to the use of your personal data in accordance with Art. 6 Para. 1 lit. a GDPR. When registering for the newsletter, we save your IP address entered by the Internet service provider (ISP) as well as the date and time of registration in order to be able to trace a possible misuse of your email address at a later date. The data collected by us when registering for the newsletter will only be used for advertising purposes in the form of the newsletter. You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a message to the person named above. After unsubscribing, your email address will be deleted from our newsletter mailing list immediately, unless you have expressly consented to further use of your data or we reserve the right to use the data beyond this, which is permitted by law and about which we inform you in this declaration.
7.2 Sending the e-mail newsletter to existing customers
If you have provided us with your e-mail address when purchasing goods or services, we reserve the right to send you regular offers from our range of goods or services similar to those already purchased by e-mail. We do not have to obtain any separate consent from you for this in accordance with Section 7 (3) UWG. In this respect, data processing is based solely on our legitimate interest in personalized direct advertising in accordance with Art. 6 Para. 1 lit. f GDPR. If you have initially objected to the use of your email address for this purpose, we will not send an email. You are entitled to object to the use of your email address for the aforementioned advertising purpose at any time with future effect by notifying the person responsible at the beginning. For this, you only incur transmission costs according to the basic tariffs. After receipt of your objection, the use of your email address for advertising purposes will be stopped immediately.
8) Data processing for order processing
8.1 In order to process your order, we work with the following service provider (s), who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
The personal data collected by us will be passed on to the transport company commissioned with the delivery as far as this is necessary for the delivery of the goods. We pass on your payment data to the commissioned credit institution as part of the payment processing, if this is necessary for the payment processing. If payment service providers are used, we will inform you explicitly below. The legal basis for the transfer of the data is Art. 6 Para. 1 lit. b GDPR.
8.2 Use of special service providers for order processing and processing
- DHL fulfillment
The order is processed by the service provider DHL Home Delivery GmbH, Sträßchensweg 10, 53113 Bonn as part of the "Dispatch by DHL Fulfillment". Your personal data will only be used for the purpose of processing the online order in accordance with Art. 6 Para. 1 lit. b GDPR passed on to DHL Fulfillment.
8.3 Use of payment service providers (payment services)
When paying via PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "installment payment" via PayPal, we pass your payment details on to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"). The transfer takes place in accordance with Art. 6 Para. 1 lit. b GDPR and only to the extent that this is necessary for payment processing.
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Shopify Payments
We use the payment service provider "Shopify Payments", 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2. If you choose a payment method offered by the payment service provider Shopify Payments, the payment will be processed by the technical service provider Stripe Payments Europe Ltd. , 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we provided the information you provided during the ordering process together with the information about your order (name, address, account number, bank code, possibly credit card number, invoice amount, currency and transaction number) according to Art. 6 Para. 1 lit. b Pass on GDPR. Your data will only be passed on for the purpose of payment processing with Stripe Payments Europe Ltd. and only to the extent that it is necessary for this. You can find more information on Shopify Payments' data protection at the following Internet address: https://www.shopify.com/legal/privacy.
Data protection information on Stripe Payments Europe Ltd. can be found here: https://stripe.com/de/privacy
9) Use of rating and test seal graphics
Trusted Shops Trustbadge
To display our Trusted Shops seal of approval and to offer the Trusted Shops membership for buyers after placing an order, the Trusted Shops Trustbadge is integrated on this website.
This serves to safeguard our legitimate interests in the optimal marketing of our offer, which predominate in the context of a balancing of interests, Art. 6 para. 1 lit. f GDPR. The Trustbadge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str.15C, 50823 Cologne.
When the Trustbadge is called up, the web server automatically saves a so-called server log file, which e.g. Contains your IP address, date and time of access, amount of data transferred and the requesting provider (access data) and documents the access. This access data is not evaluated and is automatically overwritten at the latest seven days after the end of your visit to the site.
Further personal data will only be transferred to Trusted Shops if you decide to use Trusted Shops products after completing an order or if you have already registered for use. In this case, the contractual agreement between you and Trusted Shops applies.
10) Use of social media: videos
Use of YouTube videos
This website uses the YouTube embedding function to display and play back videos from the provider "YouTube", which belongs to Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
Regardless of whether the embedded videos are played back, a connection to the Google network is established each time this website is accessed, which may trigger further data processing operations without our influence.
In the event of the transfer of personal data to Google LLC. based in the United States, Google LLC. certified for the us-European data protection convention "Privacy Shield", which guarantees compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/list
Further information on data protection at "YouTube" can be found in the provider's data protection declaration at: https://www.google.de/intl/de/policies/privacy
As far as legally required, we have your consent to the processing of your data as described above in accordance with Art. a GDPR obtained. You can revoke your consent at any time with future effect. In order to exercise your revocation, please follow the option described above to make an objection.
11) Tools and other
Shopsync for Shopify
This website uses the Shopify app "Shopsync" from ShopSync LLC, PO Box 252, Jefferson City, TN 37760, USA.
With the help of ShopSync, the newsletter service "Mailchimp" is synchronized with our Shopify account in such a way that updates in e-mail lists from Mailchimp (such as a successful opt-out of a newsletter recipient) are automatically stored on Shopify and, on the other hand New contact data generated via contracts on Shopify are automatically transferred to Mailchimp's email lists.
In the former case, data is processed in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in the effective and cross-system maintenance of the files of addressees and the efficient consideration of legally significant changes in status.
In the second case, only on the basis of the user's express consent in accordance with Art. 6 Para. 1 lit. a DSGVO after a contract has been concluded on Shopify for inclusion in the Mailchimp list, its first and last name, address and email address together with transaction-related information (purchase amount, time and date of purchase) transmitted to Mailchimp by ShopSync.
ShopSync does not save or store data transmitted in this way after synchronization. All information synchronized between Shopify and Mailchimp is transmitted via SSL (Secure Socket Layer) technology, and all transmitted information remains encrypted during the synchronization process.
The synchronization process requires the transfer of information over a secure connection to servers hosted by Amazon Web Services in the United States. Amazon Web Services based in the USA is certified for the US-European data protection agreement “Privacy Shield”, which guarantees compliance with the data protection level applicable in the EU. A current certificate can be viewed here: https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4
Further data protection information on ShopSync can be found here: https://shopsync.io/privacy-policy
12) Rights of the data subject
12.1 The applicable data protection law grants you comprehensive data protection rights (information and intervention rights) to the person responsible with regard to the processing of your personal data, about which we will inform you below:
- Right to information according to Art. 15 GDPR: In particular, you have a right to information about your personal data processed by us, the processing purposes, the categories of processed personal data, the recipients or categories of recipients to whom your data has been or will be disclosed planned storage period or the criteria for determining the storage period, the existence of a right to correction, deletion, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if we have not collected it from you, the existence of automated decision-making, including profiling and, if necessary, meaningful information about the logic involved and the scope that affects you and the intended effects of such processing, as well as your right to be informed about the guarantees according to Art. 46 GDPR when your data is forwarded to Third countries exist;
- Right to correction in accordance with Art. 16 GDPR: You have the right to immediate correction of incorrect data concerning you and / or completion of your incomplete data stored by us;
- Right to deletion in accordance with Art. 17 GDPR: You have the right to request the deletion of your personal data if the requirements of Art. 17 Para. 1 GDPR are met. However, this right does not exist in particular if the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
- Right to restriction of processing in accordance with Art. 18 GDPR: You have the right to request the restriction of the processing of your personal data as long as the correctness of your data, which you disputed, is checked, if you refuse to delete your data due to unauthorized data processing and instead request the restriction of the processing of your data if you need your data for the establishment, exercise or defense of legal claims, after we no longer need this data after the purpose has been achieved or if you have objected to reasons of your particular situation, as long as it is not certain whether ours legitimate reasons prevail;
-Right to be informed in accordance with Art. 19 GDPR: If you have asserted the right to correction, deletion or restriction of processing against the person responsible, he is obliged to make this correction or deletion of the data to all recipients to whom the personal data concerning you have been disclosed or to restrict processing, unless this proves to be impossible or involves a disproportionate effort. You have the right to be informed about these recipients.
- Right to data portability in accordance with Art. 20 GDPR: You have the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another person responsible, insofar as this is technically feasible ;
- Right to revoke consent given in accordance with Art. 7 Para. 3 GDPR: You have the right to revoke your consent to the processing of data at any time with future effect. In the event of revocation, we will delete the data concerned immediately, unless further processing can be based on a legal basis for processing without consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal;
- Right to lodge a complaint in accordance with Art. 77 GDPR: If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, especially in the Member State of your whereabouts, your place of work or the place of the alleged violation.
12.2 RIGHT TO OBJECT
WHEN WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR PRINCIPLE OF INTERESTED LEGAL INTEREST, YOU HAVE THE RIGHT TO MAKE ANY RIGHT, FOR REASONS THAT ARE A SPECIFIC LOCATION.
If you exercise your right to object, we will stop processing the data concerned. PROCESSING IS SUBJECT TO BE PROVIDED IF WE CAN PROVIDE OBLIGATORY PROTECTED REASONS FOR THE PROCESSING, WHICH EXERCISE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND BASIC FREEDOMS, OR IF THE PROCESSING OF PUBLICITY OR PEDICTION.
IF YOUR PERSONAL DATA IS PROCESSED BY US TO OPERATE DIRECT ADVERTISEMENT, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO PROCESS PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING. YOU CAN EXERCISE THE CONTRADICTION AS DESCRIBED ABOVE.
If you use your right to object, we will stop processing the data concerned for direct marketing purposes.
13) Duration of storage of personal data
The duration of the storage of personal data is measured on the basis of the respective legal basis, the purpose of processing and - if relevant - also on the basis of the respective legal retention period (e.g. retention periods under commercial and tax law).
When processing personal data based on an express consent in accordance with Art. 6 Para. 1 lit. a DSGVO, this data is stored until the data subject withdraws their consent.
Are there statutory retention periods for data that is part of legal or similar legal obligations on the basis of Art. 6 para. 1 lit. b GDPR are processed, this data will be routinely deleted after the retention periods have expired, provided that they are no longer required for contract fulfillment or contract initiation and / or if we do not have a legitimate interest in further storage.
When processing personal data on the basis of Art. 6 Para. 1 lit. f GDPR, this data is stored until the data subject exercises his right to object pursuant to Art. 21 Para. 1 GDPR, unless we can demonstrate compelling legitimate reasons for the processing that outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims.
When processing personal data for the purpose of direct advertising on the basis of Art. 6 Para. 1 lit. f GDPR, this data is stored until the data subject exercises his right to object pursuant to Art. 21 Para. 2 GDPR.
Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.