Privacy policy

 

INTRODUCTION AND DEFINITIONS

  1. Introduction

The operation of our website http://www.andunion.com/de/ and http://www.andunion.com/en/ (hereinafter referred to as "website") involves the processing of personal data. We treat this data confidentially and process it in accordance with the applicable laws - in particular the Basic Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This Privacy Policy is designed to inform you about the personal data we collect from you, what we use it for, the legal basis for the usage and, where applicable, with whom we share it. They will also inform you of your rights in regard to the protection of your data.

Our Privacy Policy contain technical terms that are used in the GDPR and the BDSG. For your better understanding we would like to explain these terms in simple words in advance:

  • Personal data

"Personal data" means all information relating to an identified or identifiable person (Art. 4 No. 1 GDPR). Information relating to an identified person may, for example, be the name or the e-mail address. However, personal data also includes data for which the identity is not immediately apparent, but which can be determined by combining one's own information or that of others and thus finding out who it is. A person becomes identifiable, for example, by providing his or her address or bank details, date of birth or username, IP address and/or location data. Relevant here is all information that in any way allows a conclusion to be drawn about a person.

  • Processing

Art. 4 No. 2 GDPR is understood by "processing" to mean any operation involving personal data. This applies in particular to the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.

 

DATA CONTROLLER

  1. Controller

Responsible for the data processing is:

 

Company:                                 AND UNION GmbH ("we")

Legal representative:                 Henning Madea (Managing Director)

Address:                                   Lindwurmstrasse 114, 80337 Munich, Germany

Phone:                                      +49 (0)89 45 224 113

E-mail:                                      info@andunion.com

 

 

 

SCOPE OF PROCESSING

  1. Scope of processing: website

Regarding the website with the URL http://www.andunion.com/de/ and http://www.andunion.com/en/ we process the personal data of you listed in detail under points 5-12 below. We only process personal data that you actively provide on our website (e.g. by filling out forms) or that you automatically provide when using our services.

Your data will be processed exclusively by us and will not be sold, lent or passed on to third parties. If we use the help of external service providers to process your personal data, this is done within the framework of so-called order processing, in which we as the client are authorized to give instructions to our contractor. For the operation of our website we use external service providers for hosting, as well as for maintenance, care and further development. Should further external service providers be used for individual processing operations listed in sections 5-12, they will be named there.

We host our website with the external provider Shopify (Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland). Shopify acts for us within the framework of order processing. A data transfer to third countries does not take place and is not planned. We will provide information about exceptions to this principle in the processing operations described below.

 

THE PROCESSING OPERATIONS IN DETAIL

  1. Provision of website and server log files
    • Description of processing

Whenever you access the website, we automatically collect information that your browser transfers to our server. This concerns the following data:

 

  • your IP address
  • the browser software you use, as well as its version and language
  • the operating system you use
  • the website from which you have reached our website (so-called referrer)
  • the subpages you have called up on our website
  • the date and time of your visit to our website
  • your Internet Service Provider
  • amount of data transferred
  • country and place from which you visited our website
  • your length of stay on our website

 

These are also stored in the so-called log files of our system. The temporary storage of your IP address by the system is necessary in order to be able to deliver our website to the end device of a user. For this purpose, the user's IP address must remain stored for the duration of the session. However, your IP address is not recorded in our log files.

  • Purpose

Processing is carried out to enable the website to be accessed and to ensure its stability and security. Furthermore, the processing serves the statistical evaluation and improvement of our online offer.

  • Legal basis

The processing is necessary in order to safeguard the overriding legitimate interests of the controller (Art. 6 para. 1lit.f GDPR). Our legitimate interest lies in the purpose stated in item 5.2.

  • Storage period

The data will be erased as soon as they are no longer required for the purpose for which they were collected. In the case of the collection of data for the provision of the website, this is the case when the respective session is ended. The log files are deleted after 7 days.

  1. NEWSLETTER
    • Description of processing

We send out a newsletter at irregular intervals. With the newsletter we inform you about our products and promotions. You will only receive our newsletter if you actively subscribe to our mailing list. You can subscribe to it by filling out and sending a newsletter registration form on our website.

To subscribe to the newsletter, you only need to enter your e-mail address. All other details (such as your first name and surname) are voluntary and are used solely to personalize the e-mails.

We use the so-called double opt-in procedure for the execution and verification of newsletter registrations. A registration takes place in several steps. First you register for the newsletter on our website. You will then receive an e-mail from us to the e-mail address you have entered. With this e-mail we ask you to confirm that you have actually subscribed to the newsletter and wish to receive it. A confirmation is made by clicking on a confirmation link in the e-mail. Only after a successful confirmation will we add you to our newsletter distribution list and send you e-mails in the future. Within the scope of the double opt-in procedure, we save the date, time and your IP address both during registration and confirmation.

  • Purpose

The processing is done in order to offer the newsletter function and to send newsletter e-mails to subscribers. The collection and storage of date, time and IP addresses during newsletter registration serves the documentation of granted consent and protection against the misuse of e-mail addresses.

  • Legal basis

The processing of our subscriber newsletter is based on a consent pursuant to Art. 6 para. 1 a GDPR. Consent can be accessed on our website at any time under the newsletter subscriber form. Your consent is voluntary. The collection and storage of the date, time and IP address when registering for the newsletter is necessary to safeguard the predominant legitimate interests of the person responsible (Art. 6 para. 1 f GDPR). Our legitimate interest lies in the purpose stated in section 5. 2.

  • Storage period and withdrawal of consent

If you do not confirm your subscription to our newsletter within 24 hours of receiving the corresponding registration e-mail, your data will be automatically deleted. We process your personal data for the duration of your newsletter subscription. You can cancel your subscription to our newsletter at any time by withdrawing your consent.

A simple declaration (by e-mail to info@andunion.com, by post to And Union GmbH, Lindwurmstraße 114, 80337 Munich, Germany) is sufficient for this purpose. It is also possible to unsubscribe from the newsletter by clicking on the unsubscribe link in every newsletter e-mail or info@andunion.com or by clicking on the unsubscribe link here: https://manage.kmail-lists.com/subscriptions/unsubscribe?a=XwPZhQ&g=R6yLiu. If you withdraw your consent, no more newsletters will be sent to you and your personal data will be removed from our active mailing list. To enforce your revocation, we will add your e-mail address to our so-called blacklist in a restricted manner. In this way we can ensure that you will not receive any newsletters from us in the future and that your e-mail address will not be misused by third parties.

  • Recipient and transfer to third countries

For the administration of our newsletter distribution list and for sending e-mails we use the services of the newsletter provider Klavio. This takes place in the context of an order processing. Klaviyo is a service of Klaviyo, Inc, 225 Franklin St. Boston, Massachusetts 02110 (hereinafter referred to as "Klaviyo"). With your newsletter subscription, the data provided during the registration process is transferred to Klaviyo and processed on Klaviyo servers in the USA. Klaviyo is subject to the EU-US Privacy Shield. Further information on the EU-US Privacy Shield can be found at https://www.klaviyo.com/privacy/policy#certifications. For more information about Klaviyo’s privacy policy, please refer to the service provider's privacy policy at https://www.klaviyo.com/privacy/policy

  1. Contact form and contact by e-mail
    • Description of processing

We have provided a contact form on our website for making contact. In this form you are asked to enter your e-mail address, your name and a message, and optionally your telephone number. If you click on the "Send" button, the data will be transferred to us using SSL encryption (see section 13). The contact form can only be transferred if you accept our privacy policy by clicking the corresponding checkbox. You can also contact us using the e-mail addresses provided on the website. In this case, the personal data transferred with the e-mail will be processed by us.

  • Purpose

By providing a contact form on our website, we want to offer you a convenient way to contact us. The data transferred with and in the contact form or your e-mail are used exclusively for the purpose of processing and answering your request.

  • Legal basis

The processing is necessary in order to safeguard the overriding legitimate interests of the controller (Art. 6 para. 1 f GDPR). Our legitimate interest lies in the purpose stated in section 7. 2. If the e-mail contact is aimed at the conclusion or fulfilment of a contract, the data processing is carried out for the fulfilment of the contract (Art. 6 para. 1 b GDPR).

  • Storage period

The data will be deleted by us as soon as they are no longer necessary for the purpose of their collection. This is usually the case when the respective communication with you has ended. The communication is terminated when it is clear from the circumstances that your request has been finally clarified. If legal retention periods prevent deletion, the data will be deleted immediately after the legal retention period has expired.

  1. Cookies
    • Description of processing

A cookie is a small amount of information that’s downloaded to your computer or device when you visit certain websites. We use a number of different cookies on the Shopify website, including strictly necessary, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor. Read more about cookies (and other similar tracking technologies) and how we use the data collected through these technologies, in our Privacy Policy.

What cookies do we use and why?

Some cookies are necessary to allow you to browse our website, use its features, and access secure areas. The use of these cookies is essential for the website to work. For example, we use user-input cookies for the duration of a session to keep track of a user’s input when filling in forms that span several pages.

We also use functional cookies to remember choices you’ve made or information you’ve provided, such as your username, language, or the region you are in. This allows us to tailor your website experience specifically to your preferences. For example, authentication cookies are functional cookies that are used for the duration of a session (or persistent, if you agree to the “remember me” function) to allow users to authenticate themselves on subsequent visits or to gain access to authorized content across pages. The functional cookies we use include:

  • User-centric security cookies to detect authentication abuses for a limited persistent duration, like repeated failed login attempts. These cookies are set for the specific task of increasing the security of the service.
  • Multimedia content player session cookies (flash cookies) are used for the duration of a session to store technical data needed to play back video or audio content (e.g. image quality, network link speed, and buffering parameters).
  • Load balancing session cookies are used for the duration of the session to identify the same server in the pool in order for the load balancer to redirect user requests appropriately.
  • User interface customization persistent cookies are used to store a user’s preference regarding a service across web pages.

Shopify is dedicated to user experience and we use many tools to help us improve our website and our commerce platform. To this end, we use reporting and analytics cookies to collect information about how you use our website or our merchants’ storefronts, and how often. These cookies only gather information for statistical purposes and only use pseudonymous cookie identifiers that do not directly identify you. The performance cookies we use include:

  • First party analytics cookies - We use these cookies to estimate the number of unique visitors, to improve our websites and our merchants’ websites, and to detect the most searched for words in search engines that lead to a webpage. These cookies are not used to target you with online marketing. We use these cookies to learn how our websites and our merchants’ websites are performing and make relevant improvements to improve your browsing experience.
  • Third party analytics cookies - We also use Google Analytics and other third-party analytics providers listed below to help measure how users interact with our website content. These cookies “remember” what our users have done on previous pages and how they’ve interacted with the website. For more information on Google Analytics, visit Google’s information page. For instructions on how to opt out of Google Analytics, see below.

Advertising cookies are used on our website to tailor marketing to you and your interests and provide you with a more personalized service in the future. These cookies remember that you visited our website and we may share this information with third parties, such as advertisers. Although these cookies can track your device’s visits to our website and other sites, they typically cannot personally identify you. Without these cookies, the advertisements that you see may be less relevant and interesting to you. Read more about how companies use cookies to conduct targeted or retargeted advertising here. We do not set advertising cookies through our merchants’ storefronts ourselves, though merchants may choose to do so independently.

Finally, Social and Content cookies are placed by many social media plugins (for example the Facebook ’like’ button), and other tools meant to provide or improve the content on a website (for example services that allow the playing of video files, or that create comments sections). We integrate these modules into our platform to improve the experience of browsing and interacting with our websites. Please note that some of these third-party services place cookies that are also used for things like behavioral advertising, analytics, and/or market research.

Full list of current cookies:

3 August 2020

Cookie

Description

Duration

Type

 

Category: Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

1

__cfduid

The cookie is set by CloudFare. The cookie is used to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information.

4 weeks

Necessary

2

cart_currency

This is an essential cookie for the secure checkout and payment function on the website. This cookie is provided by shopify.com.

2 weeks

Necessary

3

_orig_referrer

This cookie is set by website built on Shopify platform and is used in association with shopping cart.

2 weeks

Necessary

4

secure_customer_sig

This cookie is set by websites built on Shopify platform and is used in connection with customer login.

20 years

Necessary

5

cart_sig

This cookie is set by Shopify and is used in connection with store checkout.

2 weeks

Necessary

6

pf.keys

Necessary for the payment function which is provided by Google.

Persistent

Necessary

 

 

 

 

 

 

Category: Preferences

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

7

KL_FORMS_MODAL

Tracks when someone subscribes (opts in) to a form.

1 year

Other

 

 

 

 

 

 

Category: Statistics

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

8

_ga

This cookie is installed by Google Analytics. The cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors.

2 years

Analytics

9

_gid

This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the website is doing. The data collected including the number visitors, the source where they have come from, and the pages visited in an anonymous form.

1 day

Analytics

10

_gat

This cookie is installed by Google Universal Analytics to throttle the request rate to limit the collection of data on high traffic sites.

1 minute

Performance

11

__kla_id

Tracks when someone clicks through a Klaviyo email to your website.

2 years

Other

12

collect

Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across de vices and marketing channels.

Per Session

Analytics

 

 

 

 

 

 

Category: Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third-party advertisers.

13

_shopify_y

This cookie is associated with Shopify's analytics suite.

1 year

Analytics

14

_landing_page

This cookie is set by website built on Shopify platform and is used to track landing pages.

2 weeks

Analytics

15

bab_locale

Used by Bablic to set current language code. 1 year. bab_original, Used by Bablic, which translates the website into different languages. 1 year.

1 year

Other

16

bab_original

Used by Bablic, which translates the website into different languages.

1 year

Other

17

_s

This cookie is associated with Shopify's analytics suite.

30 minutes

Analytics

18

_shopify_s

This cookie is associated with Shopify's analytics suite.

30 minutes

Analytics

19

_shopify_fs

This cookie is associated with Shopify's analytics suite.

1 year

Analytics

20

cart_ver

null

2 weeks

Other

21

_shopify_sa_t

This cookie is set by Shopify and is used for analytics relating marketing and referrals.

30 minutes

Analytics

22

_shopify_sa_p

This cookie is set by Shopify and is used for analytics relating marketing and referrals.

30 minutes

Analytics

23

YSC

This cookie is set by YouTube and is used to track the views of embedded videos.

 

Performance

24

VISITOR_INFO1_LIVE

This cookie is set by YouTube. Used to track the information of the embedded YouTube videos on a website.

5 months

Advertisement

25

_hulk_age_verifier

Age Gating - 18+ age check popup. Let user certify their age.

2 weeks

Other

26

_fbp

This cookie is set by Facebook to deliver advertisement when they are on Facebook or a digital platform powered by Facebook advertising after visiting this website.

2 months

Advertisement

27

GPS

This cookie is set by YouTube and registers a unique ID for tracking users based on their geographical location

30 minutes

Analytics

28

IDE

Used by Google DoubleClick and stores information about how the user uses the website and any other advertisement before visiting the website. This is used to present users with ads that are relevant to them according to the user profile.

1 year

Advertisement

29

fr

The cookie is set by Facebook to show relevant advertisements to the users and measure and improve the advertisements. The cookie also tracks the behavior of the user across the web on sites that have Facebook pixel or Facebook social plugin.

2 months

Advertisement

30

_secure_session_id

Keeps customer logged in for 1 day

1 day

Other

31

_y

This cookie is associated with Shopify's analytics suite.

1 year

Analytics

32

_orig_referrer

Stores visitors' navigation by registering landing pages - This allows the website to present relevant prod ucts and/or measure their advertisement efficiency on other websites.

2 weeks

Analytics

33

NID

Registers a unique ID that identifies a returning user's device. The ID is used for targeted ads.

6 months

Analytics

34

OTZ

This cookie is set to collect information on user behavior and navigation which is used to optimize the we bsite - The cookie also allows Google Ads and Google Analytics to compile information on visitors for marketing purposes.

1 month

Analytics

35

r/collect

This cookie is used to send data to Google Analytics about the visitor's device and behavior. It tracks the

visitor across devices and marketing channels.

Per Session

Analytics

36

recentlyViewedProducts

This cookie may collect the following information and store it against a user ID: Product codes from merch ant sites the visitor has browsed and other information relevant to shopping behavior on mainstream shopping sites. This information n is used to serve targeted adverts to the visitor.

Persistent

Analytics

37

v1/event.gif

Presents the user with relevant content and advertisement. The service is provided by third-party

advertisement hubs, which facilitate real-time bidding for advertisers.

Per Session

Analytics

38

yt-remote-cast-installed

Stores the user's video player preferences using embedded YouTube video

Per Session

Analytics

39

yt-remote-connected-devices

Stores the user's video player preferences using embedded YouTube video

Persistent

Analytics

40

yt-remote-device-id

Stores the user's video player preferences using embedded YouTube video

Persistent

Analytics

41

yt-remote-fast-check-period

Stores the user's video player preferences using embedded YouTube video

Persistent

Analytics

 

Please consult your web browser’s “Help” documentation or visit aboutcookies.org for more information about how to turn cookies on and off for your browser.

  • Purpose

We use cookies to make our website more user-friendly and to offer the functions described in section 8.1. You can find the exact purpose of the individual cookies in the settings of our cookie banner or cookie content tool.

  • Legal basis

The processing is necessary with regard to technically necessary cookies in order to safeguard the predominant legitimate interests of the controller (Art. 6 para. 1 f GDPR). Our legitimate interest lies in the purpose stated in item 8.2. In the case of processing with regard to all other - i.e. not technically necessary - cookies, the legal basis is consent (Art. 6 para. 1 a GDPR). Such consent is voluntary.

  • Storage period, withdrawal of consent

Cookies are automatically deleted at the end of a session or when the specified storage period expires. Since cookies are stored on your terminal device, you as a user have full control over the use of cookies. By changing the settings in your Internet browser, you can deactivate or restrict the transmission of cookies. Cookies already stored can be deleted. This can also be done automatically. If cookies for our website are deactivated, deleted or restricted, it is possible that individual functions of our website cannot be used or can only be used to a limited extent. You can withdraw any consent you may have given to the use of cookies at any time in the settings of the cookie banner or the cookie content tool with effect for the future.

 

8.5        Recipient and transfer to third countries

When using third-party cookies, data may be transferred to the corresponding providers of these third-party services. This may also involve a transfer to third countries outside the European Union or the European Economic Area. We provide information about the recipients of data and the transfer of data to third countries in the settings of the cookie banner/cookie content tool or in the corresponding section on the third party service or processing in these data protection provisions.

For more information on Shopify’s cookie policy, please visit: https://www.shopify.co.za/legal/cookies#:~:text=We%20use%20a%20number%20of,as%20login%20and%20region%20selection).

 

  1. Social networks
    • Description of processing

Our website does use so-called social media plugins.

You can share the information contained on our website via social media such as Facebook, Instagram and Twitter. This means that the data you provide with names and preferences will be visible to visitors to your personal pages. We advise you to read the data protection declaration of the respective social media providers carefully, as these apply to the processing of your personal data by these providers.

The logos of the social networks; Facebook, Twitter and Instagram displayed on our website are linked to the corresponding profiles of our company. This also applies to our Facebook fan page. If you click on one of the displayed logos, you will be forwarded to the external website of the respective social network.

However, our profiles within the social networks represent a data processing. If you are logged in to the respective social network when visiting such a profile, this information is assigned to your user account there. If you interact with our profile, e.g. "share", "link" or "retweet" a post, this information is also stored in your user account. Through the so-called "Insights" on our Facebook page, we have the possibility to obtain statistical data. These statistics are provided by Facebook. The "Insights" function is not available. We cannot decide to turn this function on or off. It is available to all Facebook fan page operators, regardless of whether you use the Insights function of Facebook or not. We are provided with data for a selectable period of time and for the following group of affected persons: Fans, subscribers, people reached and interacting. These are the following categories of personal information: Total number of page views, "likes me" information including source, page activity, post interactions, reach, post reach (divided into organic, viral and paid interactions), comments, shared content, responses, and demographic analysis, including country of origin, gender and age. Because of the Facebook Terms of Use - which every user must agree to in order to use Facebook - we are able to identify subscribers and fans of our site and view their profiles.

The social networks with which you communicate store your data using pseudonyms as user profiles and use them for advertising purposes and market research. For example, you may be shown advertisements within the social network and on other websites of third parties that correspond to your presumed interests. For this purpose, cookies are usually used, which the social network stores on your end device. You have the right to object to the creation of these user profiles, and to exercise this right you must contact the social networks directly.

  • Purpose

We maintain profiles on the aforementioned social networks for the purpose of up-to-date and supportive public relations and corporate communication with customers and interested parties.

We use the function "Facebook-Insights" to make our contributions on our Facebook fan page more attractive for our visitors. This enables us to use visitors' favorite visiting times for a time-optimized planning of our posts.

  • Legal basis

The legal basis for data processing within the framework of our profiles on social networks is the protection of our predominant legitimate interests (Art. 6 para. 1 f GDPR). Our legitimate interest lies in the purpose stated in section 9.2. If you are asked for consent by the respective operator of a social network, the legal basis is Art. 6 para. 1 a GDPR. The data processing with regard to our Facebook fan page is otherwise based on a joint controllership agreement in accordance with Art. 26 GDPR between us and Facebook, which you can view here: https://www.facebook.com/legal/terms/page_controller_addendum.

  • Recipient and transfer to third countries

The respective social networks are operated by the companies listed below. Further information on data protection with regard to our profile on the social networks can be found in the linked privacy policies:

 

 

 

  • Instagram: Instagram LLC, 1601 Willow Rd, Menlo Park, California 94025, USA; privacy policy: https://help.instagram.com/155833707900388/.

 

The social networks also process your personal data in the USA and have subjected themselves to the EU-US privacy shield. Further information on the EU-US Privacy Shield can be found at https://www.privacyshield.gov/EU-US-Framework.

  1. Google Analytics
    • Description of processing

Our website uses "Google Analytics", a web analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as "Google"). Google Analytics uses cookies (see item 8), which enable an analysis of your use of our offer. We use Google Analytics in the version offered, "Universal Analytics", which allows this analysis across devices by assigning the data to a pseudonymous user ID. The information generated by the cookie is usually transferred to a Google server in the USA and stored there. However, we use Google Analytics exclusively with IP anonymization. As a result, your IP address will be shortened by Google within member states of the European Union or in other signatory states of the Agreement on the European Economic Area before. Only in exceptional cases is the full IP address transferred to a Google server in the USA and shortened there. The IP address transferred by your browser within the framework of Google Analytics is not merged with other data from Google. The statistics created by Google Analytics record, in particular, how many users visit our website, from which country or location the access takes place, which sub-pages are called up and which links or search terms are used to reach our website. You can find the user conditions of Google Analytics at http://www.google.com/analytics/terms/de.html. An overview of data protection at Google Analytics is available at http://www.google.com/intl/de/analytics/learn/privacy.html. The Google data protection declaration can be viewed at http://www.google.de/intl/de/policies/privacy.

  • Purpose

The processing takes place in order to be able to evaluate the use of our website. The information thus obtained is used to improve our online presence and to design it in line with requirements.

  • Legal basis

The processing is based on a consent pursuant to Art. 6 para. 1 a GDPR. This is obtained by us via a cookie banner or cookie content tool. Such consent is voluntary.

  • Storage period and right of objection, withdrawal of consent

We have explained the storage period and your control and setting options for cookies in section 8. You can object to data processing by Google Analytics at any time by downloading and installing the browser add-on offered by Google at https://tools.google.com/dlpage/gaoptout?hl=de. Alternatively, you have the possibility to click on the following link. This will set an opt-out cookie on your end device, which will prevent the collection of your data during future visits to this website: Disable Google Analytics (LINK: "javascript:gaOptout()") The analysis data processed and stored with Google Analytics will be automatically deleted by us after 14 months. You can withdraw your consent with regard to https://www.google.com/settings/ads/anonymous at any time in the settings of the cookie banner or the cookie content tool with effect for the future.

  • Recipient and transfer to third countries

Google Analytics is a service provider for us within the scope of an order processing. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield. You can find further information on the EU-US Privacy Shield at https://www.privacyshield.gov/EU-US-Framework.

  1. Facebook Custom Audience
    • Description of processing

Our website uses the remarketing service "Facebook Custom Audience", which is operated by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook") in the "Facebook Pixel" variant. The "Facebook Pixel" enables us to place advertisements on the social network, which are targeted at those Facebook users who have shown interest in our offer - e.g. through an earlier visit to our website. With the help of the "Facebook Pixel" we can also track and evaluate the effectiveness and reach of our ads on Facebook by recording whether Facebook users interact with our ads on the social network by clicking on the ads and being redirected to our website. Therefore, when you visit our website, a connection to the Facebook servers is established and the "Facebook pixel" is embedded in our website. In addition, it is possible that Facebook may store a cookie (see above paragraph 8) on your end device. If you are logged in to Facebook or log in to Facebook later, your visit to our website will be assigned to your user account. The data collected about you using the "Facebook Pixel" is anonymous to us. They do not provide us with any conclusions about your person. However, on the part of Facebook a connection to your user profile is possible. Data processing by Facebook is carried out in accordance with the company's data policy, which can be found at https://www.facebook.com/policy.php.

  • Purpose

Processing is carried out in order to carry out targeted online advertising for our own offers and to evaluate their effectiveness and reach.

  • Legal basis

The processing is based on a consent pursuant to Art. 6 para. 1 a GDPR. This is obtained by us via a cookie banner or cookie content tool. Such consent is voluntary.

  • Storage period and right of objection, withdrawal of consent

We have explained the storage period and your control and setting options for cookies in section 8. You can object to the collection of data by the "Facebook Pixel" and the use of your data to display Facebook advertisements at any time. You can withdraw your consent with regard to https://www.facebook.com/settings/?tab=ads at any time in the settings of the cookie banner or the cookie content tool with effect for the future.

  • Recipient and transfer to third countries

Through the integration of the "Facebook Pixel", personal data may be transferred to Facebook. Facebook also processes your personal data in the USA and has submitted to the EU-US Privacy Shield. Further information on the EU-US Privacy Shield can be found at https://www.privacyshield.gov/EU-US-Framework.

  1. YOUTUBE VIDEOS

 

11.1 Description of processing

 

Our website uses services from "YouTube" a video platform operated by YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA (hereinafter referred to as "YouTube"). YouTube is represented by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. We use YouTube by embedding individual videos from the platform on our website as so-called iFrames so that they can be played directly on our website. The videos are embedded in the "extended privacy mode" offered on YouTube, i.e. no personal data will be transferred from you to Google as long as you do not play the videos. Only when a video is played will data be transferred to Google, over which we have no influence. If you play an embedded video on a subpage of our website, Google is informed which subpage you have visited and which video you have viewed. If necessary, your IP address is also transferred to Google. If you are logged in as YouTube or Google user, Google will assign this information to your user account. Google stores your data as user profiles and uses them for advertising purposes, for market research and/or for the design of Google websites according to your needs. You have a right of objection to the creation of these user profiles, and to exercise this right you must contact Google directly. You can find further information on data protection at Google at http://www.google.com/intl/de-DE/policies/privacy/.

 

11.2 Purpose

The processing takes places in order to be able to show you video content on our website.

 

11.3 Legal basis

The processing is necessary in order to safeguard the overriding legitimate interests of the controller (Art. 6 para. 1 f GDPR). Our legitimate interest lies in the purpose stated in item 11.2.

 

11.4 Recipient and transfer to third countries

By integrating YouTube, personal data may be transmitted to YouTube LLC or Google. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield. Further information on the EU-US Privacy Shield can be found at https://www.privacyshield.gov/EU-US-Framework.

 

AGE OF CONSENT

  1. We us an age gate application developed by Hulk Code Inc. an organization which develops applications and themes for Shopify users to determine legal age consent of our users. The website is not intended for use by persons under the age of 18 (or the legal age applicable for the consumption of the products in question). We do not knowingly collect personal information from anyone under the age of 18.
    • By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site. Once consent is provided, this information is stored as a cookie for two weeks. Once two weeks have lapsed, the information and consent will be required again.

SECURITY MEASURES

  1. In order to protect your personal data from unauthorized access, we have provided our website with an SSL or TLS certificate, where formularies are used. SSL stands for "Secure-Sockets-Layer" and TLS for "Transport Layer Security" and encrypts the communication of data between a website and the user's end device. You can recognize the active SSL or TLS encryption by a small lock logo, which is displayed on the far left in the address line of the browser.

 

YOUR RIGHTS

  1. Data subject rights

With regard to the data processing by our company described above, you are entitled to the following data subject rights:

  • Right of access (Art. 15 GDPR)

You have the right to ask us to confirm whether we are processing personal data concerning you. If this is the case, you have the right, under the conditions set out in Art. 15 GDPR, to access this personal data and the other information listed in Art. 15 GDPR.

  • Rectification (Art. 16 GDPR)

You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you and, where applicable, to have incomplete personal data completed, including by means of providing a supplementary statement. Erasure (Art. 17 GDPR)

You have the right to obtain from us the erasure of your personal data without undue delay, and we shall have the obligation to erase your personal data without undue delay where one of the following grounds under Art. 17 of the GDPR applies (e.g. if your data is no longer required for the purpose for which we were using it).Restriction of processing (Art. 18 GDPR)

You have the right to demand that we restrict the processing of your personal data, provided that one of the criteria specified under Art. 18 of the GDPR is met (e.g. if you dispute the accuracy of your personal data, its processing will be restricted for the period necessary for us to check its accuracy).Data portability (Art. 20 GDPR)

Subject to the criteria specified under Art. 20 of the GDPR, you have the right to be given your data in a structured, commonly used and machine-readable format. Withdrawal of consents (Art. 7 para. 3 GDPR)

You have the right to withdraw your previously provided consent for data processing. The withdrawal will take effect from the time you request it (i.e. it will have future effect but no retrospective affect). Complaints (Art. 77 GDPR)

If you believe that the processing of your personal data is in breach of the GDPR, you can complain to a supervisory authority. You can submit your complaint to a supervisory authority in the EU member state where you are habitually resident or work, or where the alleged breach took place. Restraint on automated decision-making/profiling (Art. 22 GDPR)

Decisions that have legal consequences for you or that could have a significant detrimental effect on you must not be based solely on the automated processing of personal data, including profiling. We do not apply any such processing or profiling to your personal data. Objection (Art. 21 GDPR)

Where we process your personal data on the basis of Art. 6 Par. 1f of the GDPR in pursuit of our overriding legitimate interests, you have the right subject to Art. 21 of the GDPR to object, provided your objection is based on grounds relating to your specific situation. Once you have objected, we will no longer process your personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims. Regardless of the aforementioned restrictions, and regardless of whether any special circumstances apply, you have the right to object at any time to the processing of your personal data for direct marketing purposes.

Status: August 2020