Privacy policy

General

As the operator of this website and as a company, we come into contact with your personal data. This refers to all data that says something about you and with which you can be identified. In this privacy policy, we would like to explain to you how, for what purpose, and on what legal basis we process your data.

The party responsible for data processing on this website and in our company is:

BLUSUN GmbH

Kreuzgasse 23

66954 Pirmasens

Germany

Phone: +49 (0)6331 289 93 56

Email: info@blusun.shoes

General Information

SSL or TLS Encryption

When you enter your data on websites, place online orders, or send emails over the internet, you must always expect that unauthorized third parties may access your data. There is no complete protection against such access. However, we do everything possible to protect your data and close security gaps as far as possible.

An important protection mechanism is the SSL or TLS encryption of our website, which ensures that data you transmit to us cannot be read by third parties. You can recognize the encryption by the lock icon before the entered internet address in your browser and by the fact that our internet address begins with https:// and not with http://.

Encrypted Payment Transactions

Payment data, such as account or credit card numbers, are particularly in need of protection. Therefore, payment transactions using the common payment methods are conducted exclusively via an encrypted SSL or TLS connection.

How long do we store your data?

In some parts of this privacy policy, we inform you about how long we or the companies that process your data on our behalf store your data. If this information is missing, we store your data until the purpose of data processing no longer applies, you object to the data processing, or you revoke your consent to the data processing.

In the event of an objection or revocation, we may continue to process your data if at least one of the following conditions is met:

  • We have compelling legitimate grounds for continuing the data processing that outweigh your interests, rights, and freedoms (only in the case of objection to data processing; if the objection is against direct marketing, we cannot provide any legitimate grounds).
  • The data processing is necessary to assert, exercise, or defend legal claims (does not apply if your objection is against direct marketing).
  • We are legally obliged to retain your data.

In this case, we delete your data as soon as the condition(s) no longer apply.

Data Transfer to the USA

We also use tools from companies on our website that transfer your data to the USA and store and possibly further process it there. The European Commission has adopted an adequacy decision for the EU-US Data Privacy Framework. This determines that the USA ensures an adequate level of protection for personal data from the EU that is transferred to US companies. This decision is based on new guarantees and measures introduced by the USA to meet data protection requirements. The adequacy decision includes, among other things, restrictions and guarantees regarding the access of US intelligence services to the data. Binding Guarantees have been introduced to limit the access of US intelligence services to the necessary and proportionate level required to protect national security. Additionally, increased oversight of the activities of US intelligence services has been established to ensure that the restrictions on surveillance activities are adhered to. Furthermore, an independent legal remedy process has been established to handle and resolve complaints from European citizens regarding access to their data. The EU-US data protection framework thus allows European companies to transfer data to certified US companies without having to introduce additional data protection guarantees. You can view a list of all certified companies at the following link: https://www.dataprivacyframework.gov/s/participant-search

A change in the decision of the European Commission cannot be ruled out.

Your Rights

Objection to Data Processing

IF YOU READ IN THIS PRIVACY POLICY THAT WE HAVE LEGITIMATE INTERESTS FOR PROCESSING YOUR DATA AND THEREFORE RELY ON ART. 6 PARA. 1 SENTENCE 1 LIT. F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THIS ACCORDING TO ART. 21 GDPR. THIS ALSO APPLIES TO PROFILING THAT IS BASED ON THE MENTIONED REGULATION. THE CONDITION IS THAT YOU PROVIDE REASONS FOR THE OBJECTION THAT ARISE FROM YOUR PARTICULAR SITUATION. NO REASON IS REQUIRED IF THE OBJECTION IS AGAINST THE USE OF YOUR DATA FOR DIRECT ADVERTISING.

THE CONSEQUENCE OF THE OBJECTION IS THAT WE MAY NO LONGER PROCESS YOUR DATA. THIS DOES NOT APPLY IF ONE OF THE FOLLOWING CONDITIONS IS MET:

  • WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS.
  • THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.

THE EXCEPTIONS DO NOT APPLY IF YOUR OBJECTION IS DIRECTED AGAINST DIRECT ADVERTISING OR AGAINST PROFILING RELATED TO IT.

Other Rights

Withdrawal of Your Consent to Data Processing

Many data processing operations are based on your consent. You give this, for example, by checking a box in online forms before submitting the form or by allowing certain cookies when you visit our website. You can withdraw your consent at any time without providing reasons (Art. 7 Para. 3 GDPR). From the time of withdrawal, we may no longer process your data. The only exception: we are legally obliged to retain the data for a certain period. Such retention periods exist, particularly in tax and commercial law.

Right to Complain to the Competent Supervisory Authority

If you believe that we are violating the General Data Protection Regulation (GDPR), you have the right to complain to a supervisory authority according to Art. 77 GDPR. You can contact a supervisory authority in the member state of your residence, workplace, or the place where the alleged violation occurred. The right to complain exists in addition to administrative or judicial remedies.

Right to Data Portability

Data that we process automatically based on your consent or in fulfillment of a contract must be handed over to you or a third party in a common machine-readable format if you request it. We can only transfer the data to another controller transferred, as far as this is technically possible.

Right to data access, deletion, and correction

According to Art. 15 GDPR, you have the right to receive information free of charge about which personal data we have stored about you, where the data comes from, to whom we transmit the data, and for what purpose it is stored. If the data is incorrect, you have the right to correction (Art. 16 GDPR), and under the conditions of Art. 17 GDPR, you may request that we delete the data.

Right to restriction of processing

In certain situations, you can request us to restrict the processing of your data according to Art. 18 GDPR. The data may then only be processed as follows, apart from storage:

  • with your consent
  • for the assertion, exercise, or defense of legal claims
  • to protect the rights of another natural or legal person
  • for reasons of important public interest of the European Union or a member state

The right to restrict processing exists in the following situations:

  • You have disputed the accuracy of your personal data stored with us, and we need time to verify this. The right exists for the duration of the verification.
  • The processing of your personal data is unlawful or was unlawful in the past. Here, the right exists as an alternative to the deletion of the data.
  • We no longer need your personal data, but you need it for the exercise, defense, or assertion of legal claims. Here, the right exists as an alternative to the deletion of the data.
  • You have objected according to Art. 21 para. 1 GDPR, and now your and our interests must be weighed against each other. The right exists as long as the result of the weighing is not yet determined.

Hosting and Content Delivery Networks (CDN)

External Hosting

Our website is hosted on a server of the following internet service provider (host):

Shopify International Limited
Victoria Buildings
1-2 Haddington Road
Dublin 4, D04 XN32, Ireland


How do we process your data?

The host stores all data from our website. This includes all personal data that is automatically collected or entered by you. This can include: your IP address, accessed pages, names, contact details and inquiries, as well as meta and communication data. In data processing, our host follows our instructions and processes the data only to the extent necessary to fulfill the service obligation to us.

On what legal basis do we process your data?

Since we address potential customers through our website and maintain contacts with existing customers, the data processing by our host serves the initiation and fulfillment of contracts and is therefore based on Art. 6 para. 1 lit. b) GDPR. Furthermore, it is our legitimate interest as a company to provide a professional internet offering that meets the necessary requirements for security, speed, and efficiency. In this respect, we also process your data on the basis of Art. 6 para. 1 lit. f) GDPR.

Data collection on this website

Use of cookies

Our website places cookies on your device. These are small text files with different purposes. Some cookies are technically necessary for the website to function at all (necessary cookies). Others are needed to perform certain actions or functions on the site (functional cookies). For example, it would not be possible to use the advantages of a shopping cart in an online shop without cookies. Other cookies are used to analyze user behavior or optimize advertising measures. If we use third-party services on our website, e.g., for processing payment transactions, these companies may also leave cookies on your device when you visit the website (so-called third-party cookies).

How do we process your data?

Session cookies are stored on your device only for the duration of a session. As soon as you close the browser, they disappear on their own. Permanent cookies, on the other hand, remain on your device unless you delete them yourself. This can, for example, lead to your user behavior being analyzed permanently. You can influence how your browser handles cookies through the settings:

  • Do you want to be informed when cookies are set?
  • Do you want to exclude cookies in general or for specific cases?
  • Do you want cookies to be automatically deleted when you close the browser?

If you disable or do not allow cookies, the functionality of the website may be limited.

If we use cookies from other companies or for analysis purposes, we will inform you about this within the framework of this privacy policy. We also ask for your consent in this regard when you visit our website.

On what legal basis do we process your data?

We have a legitimate interest in ensuring that our online offers can be used by visitors without technical problems and that all desired functions are available to them. The storage of necessary and functional cookies on your device is therefore based on Art. 6 para. 1 lit. f) GDPR. We use all other cookies based on Art. 6 para. 1 lit. a) GDPR, provided you give us your corresponding consent. You can revoke this consent at any time with effect for the future. If you have consented to the placement of necessary and functional cookies during the consent query, the storage of these cookies is also based solely on your consent.

Cookie Consent with the Legal Cockpit

What is the Legal Cockpit Cookie Tool?

Consent Management Platform (CMP) for obtaining and processing GDPR-compliant consents

Who processes your data?

Legalcore AG, Reinhardtstr. 7, 10117 Berlin


Where can you find more information about data protection at Legal Cockpit?

https://cockpit.legal/datenschutz/

How do we process your data?

We use the Legal Cockpit's Consent Management Platform to obtain your consent for storing cookies on your device in compliance with data protection regulations. When you visit our website and close the Legal Cockpit's cookie window with the consent query, the following data is transmitted to the company:

  • Your IP address
  • Information about your browser
  • Information about your device
  • The time of your visit to the website

Additionally, the Legal Cockpit stores a cookie in your browser to be able to assign the given consents or their revocation to your browser. All collected data is stored until the If cookies are no longer needed, you can delete the Legal Cockpit cookie or request us to delete the data. This does not apply if we are legally required to retain the data.

On what legal basis do we process your data?

We are legally required to obtain the consent of our website visitors for the use of certain cookies. To fulfill this obligation, we use Legal Cockpit. The legal basis for data processing is therefore Art. 6 para. 1 lit. c) GDPR.

Server Log Files

Server log files record all requests and accesses to our website and log error messages. They also include personal data, especially your IP address. However, this is anonymized by the provider after a short time, so we cannot associate the data with your person. The data is automatically transmitted by your browser to our provider.

How do we process your data?

Our provider stores the server log files to track activities on our website and identify errors. The files contain the following data:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address (possibly anonymized)

We do not combine this data with other data but use it only for statistical analysis and to improve our website.

On what legal basis do we process your data?

We have a legitimate interest in ensuring that our website runs error-free. It is also our legitimate interest to obtain an anonymized overview of the accesses to our website. Therefore, data processing is lawful in accordance with Art. 6 para. 1 lit. f) GDPR.

Contact Form

You can send us a message via the contact form on this website.

How do we process your data?

We store your message and the information from the form to process your inquiry, including follow-up questions. This also concerns the provided contact details. We do not share the data with other persons without your consent.

How long do we store your data?

We delete your data as soon as one of the following points occurs:

  • Your inquiry has been fully processed.
  • You request us to delete the data.
  • You revoke your consent to storage.

This does not apply if we are legally obliged to retain the data.

On what legal basis do we process your data?

If your inquiry is related to our contractual relationship or serves the implementation of pre-contractual measures, we process your data based on Art. 6 para. 1 lit. b) GDPR. In all other cases, it is our legitimate interest to effectively process inquiries directed to us. The legal basis for data processing is therefore Art. 6 para. 1 lit. f) GDPR. If you have consented to the storage of your data, Art. 6 para. 1 lit. a) GDPR is the legal basis. In this case, you can revoke your consent at any time with effect for the future.

Inquiry by Email, Phone, or Fax

You can send us a message via email or fax or call us.

How do we process your data?

We store your message as well as your self-provided contact details or the transmitted phone number to process your inquiry, including follow-up questions. We do not share the data without your consent. the data to other people.

How long do we store your data?

We delete your data as soon as one of the following occurs:

  • Your request has been fully processed.
  • You request us to delete the data.
  • You revoke your consent to storage.

This only does not apply if we are legally obliged to retain the data.

On what legal basis do we process your data?

If your request is related to our contractual relationship or serves the implementation of pre-contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b) GDPR. In all other cases, it is our legitimate interest to effectively process inquiries addressed to us. The legal basis for data processing is therefore Art. 6 para. 1 lit. f) GDPR. If you have consented to the storage of your data, Art. 6 para. 1 lit. a) GDPR is the legal basis. In this case, you can revoke your consent at any time with effect for the future.

Registration Function

To use certain functions or offers on our website, you must register. This requires providing your email address and possibly other personal data.

How do we process your data?

We store the data you provide during registration and use it to provide you with the function or offer you registered for. If there are changes regarding the offer or function, we use your email address to inform you. We also use your email address to possibly make you further contract offers.

How long do we store your data?

We delete your data as soon as one of the following occurs:

  • The purpose of data processing no longer applies.
  • You request us to delete the data.
  • You revoke your consent to storage.

This only does not apply if we are legally obliged to retain the data.

On what legal basis do we process your data?

We store and use your data to fulfill the usage relationship established during registration and possibly initiate further contracts. The legal basis is therefore Art. 6 para. 1 lit. b) GDPR.

Comment Function

You have the option to comment on content on our website via appropriate input fields. To use the comment function, you must provide your email address. It is also possible to subscribe to the comments of others.

How do we process your data?

When you leave comments on our website, we store the following data:

  • Your comment
  • Your email address
  • The time of the comment
  • Additional data you provide during the comment, e.g., your username
  • Your IP address

We store data that can identify you in order to take legal action against you if your comment is offensive, incites hatred, or is otherwise criminally relevant.

If you subscribe to comments, we will send you an email to verify that you are the owner of the specified email address. You can unsubscribe from receiving comments at any time via a link in this email.

How long do we store your data?

We store your comments and the associated data until the commented content is completely deleted or the comments are removed for legal reasons, e.g., because they violate Violations of penal regulations must be deleted.

If you have subscribed to comments and unsubscribe from the notification, all data provided as part of the subscription will be deleted. If we have stored your data for another reason, e.g., because you have subscribed to our newsletter, this data will not be affected by the deletion.

On what legal basis do we process your data?

By using the comment function, you consent to the storage of your data. The basis for data processing is thus Art. 6 para. 1 lit. a) GDPR. You can revoke your consent at any time by writing us an email in which you declare your revocation. From this point on, we may no longer process your data.

Trusted Shops

What is Trusted Shops?

Review platform

Who processes your data?

Trusted Shops AG, Colonius Carré, Subbelrather Straße 15c, 50823 Cologne

Has a joint responsibility agreement been concluded with Trusted Shops?

Yes

Where can you find more information about data protection at Trusted Shops?

https://www.trustedshops.com/de/legal/datenschutz[RRA[R1]

How do we process your data?

We use the services of Trusted Shops AG for this website.

If you have given us your consent in accordance with Article 6 paragraph 1 sentence 1 lit. a) GDPR, Trusted Shops widgets are used on this website to display Trusted Shops services (e.g., trustmarks, collected reviews) and to offer Trusted Shops products to buyers after an order.

The trust badge is provided by a US CDN provider. When the trust badge is accessed, access data such as IP address, date, time, data volume transferred, and requesting provider are stored in a server log file. The IP address is anonymized, and the data is used for statistical purposes and error analysis.

If you have given your consent, the trust badge accesses order information stored on your end device and your email address after order completion. Your email address is encrypted and transmitted to Trusted Shops along with the order information.

On what legal basis do we process your data?

If you have consented to the use of Trusted Shops widgets, Art. 6 para. 1 lit. a) GDPR is the sole legal basis. In this case, you can revoke your consent at any time with effect for the future.

Analysis Tools and Advertising

We use the following tools to analyze the behavior of our website visitors and to show you advertisements.

Google Tag Manager

What is Google Tag Manager?

Tag management system for integrating tracking codes and conversion pixels of Google Ireland Ltd.

Who processes your data?

Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Where can you find more information about data protection at Google Tag Manager?

https://policies.google.com/privacy

On what basis do we transfer your data to the USA?

Based on the adequacy decision of the European Commission and the corresponding certification of the company.

How do we process your data?

We use the Google Tag Manager. The tool helps us to integrate, manage, and deploy tracking codes and conversion pixels on our website. The Google Tag Manager itself does not create user profiles, place cookies on your device, or analyze your user behavior. However, it does capture your IP address and transmits it to Google's servers in the USA.

On what legal basis do we process your data?

We have a legitimate interest in the fast and uncomplicated integration and management of various tools on our website. Therefore, the use of the Google Tag Manager is lawful under Art. 6 para. 1 lit. f) GDPR. If you have consented to the transfer of your IP address, we process your data solely on the basis of Art. 6 para. 1 lit. a) GDPR. You can revoke your consent at any time with effect for the future.

Google Analytics

What is Google Analytics?

Tool for analyzing user behavior by Google Ireland Ltd.

Who processes your data?

Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Where can you find more information about data protection at Google Analytics?

https://support.google.com/analytics/answer/6004245?hl=de

On what basis do we transfer your data to the USA?

Based on the adequacy decision of the European Commission and the corresponding certification of the company.

How can you prevent data collection?

Among other things, with a browser plugin: https://tools.google.com/dlpage/gaoptout?hl=de

How do we process your data?

We are always interested in optimizing our web offering for the visitors of our website and placing advertisements optimally. Google Analytics helps us with this, a tool that analyzes user behavior and thus provides us with the necessary data basis for adjustments. Through the tool, we receive information about the origin of our visitors, their page views, and their dwell time on the pages as well as the operating system they use.

Standard processing

To collect the data, Google Analytics uses cookies, device fingerprinting, or other technologies to recognize users. The data is transmitted to Google's servers in the USA and combined into a profile with the IP address also collected, which can be assigned to you or your device.

You can prevent Google from processing your data by installing a browser plugin provided by Google itself: https://tools.google.com/dlpage/gaoptout?hl=de.

IP Anonymization

We have activated the "IP Anonymization" function within Google Analytics. For you, this means that Google shortens your IP address (from the EU or EEA) before transmission to the USA. Only in exceptional cases does Google transmit the full IP address to servers in the USA and only shortens them there.

E-Commerce Tracking

We use the "E-Commerce Tracking" function from Google Analytics. This allows us to analyze the purchasing behavior of our website visitors and improve our online marketing campaigns. In e-commerce tracking, for example, your orders, average order values, shipping costs, and the time from viewing to purchasing a product are recorded. Google can summarize the data under a transaction ID and assign it to you or your device.

How long do we store your data?

Data stored at user and event level linked with cookies, user identifiers (e.g., user IDs), or advertising IDs are deleted or anonymized by Google after 14 months according to their information (see https://support.google.com/analytics/answer/7667196?hl=de).

On what legal basis do we process your data?

As website operators, we have a legitimate interest in analyzing user behavior to optimize our web offering and the advertising placed there. Data processing is therefore lawful according to Art. 6 para. 1 lit. f) GDPR. In the event that you have consented to the storage of cookies or otherwise agreed to data processing by Google Analytics, Art. 6 para. 1 lit. a) GDPR is the sole legal basis. You can revoke your consent at any time with effect for the future.


Facebook Pixel

What is Facebook Pixel?

A tool for analyzing user behavior that measures the effectiveness of advertising on Facebook

Who processes your data?

Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland

Where can you find more information about data protection with Facebook Pixel?

https://de-de.facebook.com/about/privacy/

On what basis do we transfer your data to the USA?

Based on the adequacy decision of the European Commission and the corresponding certification of the company.

How can you prevent data processing?

If you have a Facebook account: Disable the "Custom Audiences" remarketing feature in the ad settings area (https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen).

If you do not have a Facebook account: Disable usage-based advertising from Facebook on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.

How do we process your data?

We use the Facebook Pixel on our website. The analysis tool helps us learn more about the behavior of our website visitors after they have clicked on one of our advertisements on Facebook. This allows us to measure how effective our Facebook advertising is and tailor future advertising measures to the insights gained. The data Facebook collects via the pixel is anonymous to us as the operators of this website. Therefore, we cannot identify you as a visitor. However, the data is stored and processed by Facebook. Thus, Facebook establishes a connection to your Facebook account via the pixel and uses the Data beyond that, to place ads within and outside the network itself (see Facebook Data Use Policy). In the course of storage and processing, Facebook also transmits the data to the USA and other third countries.

If you have a Facebook account, you can disable the remarketing function "Custom Audiences" in the ad settings area at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.

If you do not have a Facebook account, you can disable usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.

On what legal basis do we process your data?

As website operators, we have a legitimate interest in effective advertising measures in social networks. Therefore, data processing is lawful under Art. 6 Para. 1 lit. f) GDPR. In the event that you, for example, have agreed to the storage of cookies or have consented to data processing by Facebook in any other way, only Art. 6 Para. 1 lit. a) GDPR is the legal basis. You can revoke your consent at any time with effect for the future.

Pinterest Tag

What is Pinterest Tag?

Tool for analyzing user behavior

Who processes your data?

Pinterest Ireland Ltd. 2 Grand Canal Square Dublin 2, Ireland

Where can you find more information about data protection with Pinterest Tag?

https://policy.pinterest.com/de/privacy-policy

On what basis do we transfer your data to the USA?

Pinterest adheres to the standard contractual clauses of the European Commission (see https://policy.pinterest.com/de/privacy-policy)

How do we process your data?

We use Pinterest Tag on our website. Pinterest Tag is a tracking code or code snippet used by companies to track activities on their website and collect data on user behavior and campaign performance. For this purpose, the Pinterest Tag collects, among other things, a tag ID, your location, and the referrer URL. Action-specific data such as order value, order quantity, order number, category of purchased items, and video views can also be collected.

Pinterest Tag belongs to the globally operating company "Pinterest Inc.", so data transfer to the USA can also take place.

On what legal basis do we process your data?

As website operators, we have a legitimate interest in effective advertising measures in social networks. Therefore, data processing is lawful under Art. 6 Para. 1 lit. f) GDPR. In the event that you, for example, have agreed to the storage of cookies or have consented to data processing by Facebook in any other way, only Art. 6 Para. 1 lit. a) GDPR is the legal basis. You can revoke your consent at any time with effect for the future.

Plugins and Tools

Google Maps

What is Google Maps?

Map service of Google Ireland Ltd.

Who processes your data?

Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Where can you find more information about data protection at Google?

https://policies.google.com/privacy?hl=de

On what basis do we transfer your data to the USA?

Based on the adequacy decision of the European Commission and the corresponding certification of the company.

How do we process your data?

We use Google Maps on our website. To enable you to use all the functions of the map service, Google stores your IP address on one of its servers in the USA.

On what legal basis do we process your data?

The maps from Google Maps ensure that the locations specified on our website are easier for visitors to find. As a company, we have a legitimate interest in this. Therefore, the data processing is lawful according to Art. 6 para. 1 lit. f) GDPR.

If you have consented to the data processing, we process your data solely based on Art. 6 para. 1 lit. a) GDPR. You can revoke your consent at any time. From the time of revocation, we are no longer allowed to process your data.

eCommerce and Payment Providers

Customer and Contract Data

How do we process your data?

When we enter into a contract with you, we need certain personal data from you. We collect, process, and use this data only to the extent necessary to establish, structure, or change our legal relationship. If you can only use our services via our website or if the services are billed via the website, we also collect usage data if this is necessary to enable you to use our offer or to bill for the service you have used.

How long do we store your data?

We store your data until our legal relationship ends, unless we are legally obliged to keep the data longer.

On what legal basis do we process your data?

We store your data to fulfill the contract with you or to take pre-contractual measures. The basis of the data processing is therefore Art. 6 para. 1 lit. b) GDPR.

Data Transfer for Goods Shipment

How do we process your data?

If you order goods from us, we transfer your data to companies that we commission with the delivery and/or through which we process the payment. Only data necessary for the commissioned company to execute the specific order will be transmitted. If we want to share data beyond this, we will obtain your consent. We do not pass on your data for advertising purposes.

On what legal basis do we process your data?

We pass on your data to fulfill the contract we have concluded with you. The basis of the data processing is therefore Art. 6 para. 1 lit. b) GDPR.

Payment Services

To enable you to conveniently pay for your purchases on our website, we use the service of payment services, i.e., external companies that process payments for us. You can find out which ones specifically at the end of this section.

How do we process your data?

For the payment process, you must provide certain personal data, such as your name, account details, or credit card number. We pass these data on to the respective payment service. For the transaction itself, the respective contract and data protection provisions of the respective services.

On what legal basis do we process your data?

We share your data to fulfill the contract we have concluded with you. The basis for data processing is therefore Art. 6 para. 1 lit. b) GDPR. In addition, we have a legitimate interest in processing purchases as quickly, conveniently, and securely as possible. The legal basis is also Art. 6 para. 1 lit. f) GDPR. If you have consented to the sharing of your data, the data processing is based on Art. 6 para. 1 lit. a) GDPR. You can revoke your consent at any time with effect for the future.

Which payment services do we use?

PayPal

What is PayPal?

Online payment service

Who processes your data?

PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg

Where can you find more information about data protection at PayPal?

https://www.paypal.com/de/webapps/mpp/ua/privacy-full

On what basis do we transfer your data to the USA?

PayPal adheres to the standard contractual clauses of the European Commission (see https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full)

Apple Pay

What is Apple Pay?

Mobile payment service by Apple Inc.

Who processes your data?

Apple Inc., Infinite Loop, Cupertino, CA 95014, USA

Where can you find more information about data protection at Apple Pay?

https://www.apple.com/legal/privacy/de-ww/

On what basis do we transfer your data to the USA?

Apple Pay adheres to the standard contractual clauses of the European Commission (see https://www.apple.com/legal/privacy/de-ww/)

Google Pay

What is Google Pay?

Mobile payment system of the American company Google

Who processes your data?

Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Where can you find more information about data protection at Google Pay?

https://policies.google.com/privacy

On what basis do we transfer your data to the USA?

Based on the adequacy decision of the European Commission and the corresponding certification of the company.

Klarna

What is Klarna?

Payment service

Who processes your data?

Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden

Where can you find more information about data protection at Klarna?

https://www.klarna.com/de/datenschutz/

Data processing on Social Media

What is Social Media?

By Social Media, we mean the social networks on which we have created publicly accessible profiles. You can read which social networks these specifically are below.

Who processes your data?

The respective operating companies of the social networks. You can find the individual operators below for the respective networks.

How are your data processed?

The operators of social networks are generally able to collect and evaluate comprehensive data about the behavior of visitors and users of the network. We are not able to trace all processing operations in the social networks we use, which is why additional processing operations not listed here may be carried out by the operators of the social networks. You can find more information about this in the terms of use and privacy policies of the respective social networks.

Your data may be processed by visiting the website of the social network or our profile page there. Even when you visit a website that uses certain content from the network, such as like or share buttons, data can already be transferred to the operators of the social network. If you are a user of the social network and logged into your user account, your visit to our profile page can be assigned to your account by the operator of the social network. Even if you do not have a registered user account or are not logged in, the network operator may still collect your personal data, for example by capturing your IP address or setting cookies. With this data, operators can create user profiles tailored to your behavior and interests and display interest-based advertising to you within and outside the network. If you are a registered user of the network, interest-based advertising can also be displayed on all devices where you are or have been logged in.

On what legal basis are your data processed?

Our profiles on social networks are intended to ensure the most comprehensive presence of our company on the Internet. As a company, we have a legitimate interest in this. Data processing is therefore lawful according to Art. 6 para. 1 lit. f GDPR.

The data processing operations and analyses carried out by the operators of the social networks themselves may be based on other legal bases. These must be specified by the operators of the social networks.

Who is responsible for processing your data and how can you exercise your rights?

If you visit one of our profiles on social networks, we are jointly responsible with the operator of the respective network for the data processing operations triggered during this visit. You can generally exercise your rights both against us and the operator of the respective network.

Despite the joint responsibility with the operators of social networks, our influence on the data processing operations of the respective operator is limited and is primarily determined by the operator's specifications.

How long are your data stored?

If we collect data via our profiles on social networks, it will be deleted from our systems as soon as the purpose for its storage ceases to apply, you request us to delete it, or you revoke your consent to storage. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected.

We have no influence on how long the operators of social networks store your data, which they collect for their own purposes. You can obtain information about this directly from the operator of the respective social network, e.g., in the respective privacy policy.

Which social media do we use?

Facebook

What is Facebook?
A social network

Who processes your data?
Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland

Are your data transferred to third countries?
Yes, to the USA and also to other third countries

Where can you find more information about data protection on Facebook?
https://www.facebook.com/about/privacy/

Where can you adjust your advertising settings as a Facebook user?
As a registered Facebook user, you can adjust your advertising settings in your user account. Click on the following link and log in:
https://www.facebook.com/settings?tab=ads.

Instagram

What is Instagram?
A social network specialized in photos and videos

Who processes your data?
Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland

Are your data transferred to third countries?
Yes

Where can you find more information about data protection on Instagram?
https://help.instagram.com/519522125107875/?helpref=hc_fnav&bc[0]=Instagram-Hilfebereich&bc[1]=Richtlinien%20und%20Meldungen

Where can you adjust your privacy settings as a user?
As a registered Instagram user, you can adjust your privacy settings in your user account. Click on the following link and log in:
https://www.instagram.com/accounts/privacy_and_security/

Pinterest

What is Pinterest?

Visual search engine and online pinboard

Who processes your data?

Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland

Are your data transferred to third countries?

Yes

Where can you find more information about data protection on Pinterest?

https://policy.pinterest.com/de/privacy-policy

Where can you adjust your data protection settings as a user?

https://help.pinterest.com/de/article/edit-account-privacy

YouTube

What is YouTube?
A social network in the form of an online video portal

Who processes your data?
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

Are your data transferred to third countries?
Yes

Where can you find more information about data protection on YouTube?
https://policies.google.com/privacy?hl=de

Where can you adjust your data protection settings as a user?
https://policies.google.com/privacy?hl=de#infochoices