Information according to § 5 DDG
Quality First GmbH
Werner-von-Siemens-Straße 8
25337 Elmshorn
Management:
André Rose, Nicolas Lother, Patrycja Nowakowska
Contact:
Contact us here
Tel.: (Only for private customers of our shop)
Email: service@morenutrition.de
dealers
retail@esn.com (for B2B retailers)
career
www.tqgg.de
We are a registered member:
Hotline for dealers:
This phone number is for dealer inquiries only.
dispute resolution
The European Commission provides a platform for online dispute resolution (OS): https://ec.europa.eu/consumers/odr
You can find our email address above in the imprint.
We are not willing or obliged to participate in dispute resolution proceedings before a consumer arbitration board.
We take data protection seriously
Protecting your privacy when processing personal data is important to us. For this reason, we only process personal data if this is sensible and economically relevant for the use of our services. In any case, we adhere to the provisions of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
Below you will find information about which data is processed in which form and by whom when you visit our shop at www.morenutrition.nl .
Table of contents:
1. Who is responsible for data processing and who can you contact?
2. Personal data
3. Visiting our website
3.1 General Use
3.1.1 Automatically saved data (server log files)
3.1.2 Cookies, tracking pixels and tools
3.1.3 Social media plugins (Facebook, Pinterest, Instagram, YouTube)
3.1.4 Consent Management
3.2 Online presence and service optimization
3.3 Tools and services for analysis, statistical collection and marketing
3.4 Contact form
3.5 Customer account
3.6 Shop and e-commerce
3.6.1. Purchase of goods
3.7. Direct marketing
3.7.1. Customer information
3.7.2. Newsletter
3.7.3. Service providers
3.7.4. Analysis
3.8. Evaluation requests
3.9 Economic analyses and market research
3.10 Payment service providers
3.11 Transport service providers
3.12 Security
4. Online presence on social media
5. Rights of the data subject
6. Changes to this Privacy Policy
1. Who is responsible for data processing and who can you contact?
Responsible is
Quality First GmbH
Werner-von-Siemens-Straße 8
25337 Elmshorn
Phone: +49 40/35674432
Email: service@morenutrition.de
The company data protection officer is
Nico Becker
Projekt 29 GmbH & Co. KG
Ostengasse 14
93047 Regensburg
E-Mail: anfragen@projekt29.de
Tel.: 0941-2986930
2. Personal data
Personal data is data about you that can be used to identify you. This includes, for example, your name, address, email address, location data, payment details and many other details. In principle, you do not have to disclose any personal data in order to visit our website. In some cases, however, we require this in order to be able to offer you the services you request on our website. If you use one of our services where this is required, we generally only collect the data that is necessary for this purpose and not without your consent.
3. Visiting our website
3.1 General Use
When you visit our website, our web servers store the IP address of your Internet service provider, the website from which you visit us, the web pages you visit on our site, and the date and duration of your visit. The processing of this information is absolutely necessary for the technical transmission of the websites, the convenient use of our services, and the secure operation of the server. Our legitimate interest arises from Art. 6 (1) (f) GDPR.
It is not possible to draw any direct conclusions about your identity from the information and we will not do so. The information is stored and automatically deleted once the aforementioned purposes have been achieved. The standard deletion periods are based on the criterion of necessity.
3.1.1 Automatically saved data (server log files)
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
This data will not be merged with other data sources. Processing is carried out in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website.
For reasons of technical security, in particular to prevent attempts to attack our web server, we store this data for a short time. We are unable to identify individuals based on this data. After seven days at the latest, the data is anonymized by shortening the IP address at domain level, so that it is no longer possible to establish a link to the individual user. The data is also processed in anonymized form for statistical purposes; it is not compared with other databases or passed on to third parties, even in extracts.
3.1.2 Cookies, tracking pixels and tools
When you visit our website, we may store information on your computer in the form of cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a character string by which websites and servers can be assigned to the specific Internet browser in which the cookie was stored. This enables the websites and servers visited to distinguish the individual browser of the data subject from other Internet browsers that contain other cookies. A specific Internet browser can be recognized and identified via the unique cookie ID. You can find an overview of the cookies we use here.
By using session cookies, the controller can provide users of this website with a user-friendly service that would not be possible without the setting of cookies. Without consent, we only use technically necessary cookies on the legal basis of legitimate interest in accordance with Art. 6 (1) (f) GDPR.
We only use personal cookies to improve our website or for marketing/advertising purposes with your consent. On your first visit, you can voluntarily consent to tracking or analysis via the cookie banner displayed. Your data may be passed on to partners or third-party providers. These cookies will only be stored if you explicitly consent to this; the legal basis is then your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
You can change your cookie settings here at any time.
3.1.3 Social Plugins from Facebook, Pinterest, Instagram and Youtube
Our website uses social buttons from social networks. These are simply integrated into the page as HTML links, so that when you visit our website, no connection is established with the servers of the respective provider. If you click on one of the buttons, the website of the respective social network opens in a new window in your browser. There you can, for example, press the Like or Share button.
3.1.4 Consent Management
Here you can manage, revoke or change your settings regarding the use of cookies:
https://morenutrition.de/pages/faq#uc-corner-modal-show or on the website www.morenutrition.nl click on “Cookie Settings” at the very bottom of the footer.
3.2 Online presence and service optimization
Shopify
We host our website at Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter “Shopify”).
Shopify is a tool for creating and hosting e-commerce websites. When you visit our website, Shopify records your IP address and information about the device you are using and your browser. Shopify also analyzes visitor numbers, visitor sources, and customer behavior, and compiles user statistics. When you make a purchase on our website, Shopify also records your name, email address, delivery and billing addresses, payment details, and other data related to the purchase (e.g. phone number, amount of sales made, etc.). Shopify stores cookies in your browser for analysis purposes.
For details, see Shopify’s privacy policy:
https://www.shopify.com/nl/juridisch/privacy .
The use of Shopify is based on Art. 6 Paragraph 1 Letter f of GDPR. We have a legitimate interest in presenting our website as reliably as possible. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 Paragraph . 1 lit. a GDPR and 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.
We have concluded a contract for order processing (AV) in accordance with Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law, which guarantees that the provider will only process the personal data of our website visitors in accordance with our instructions and in compliance with the DSGVO processed.
Usercentrics
This website uses the consent technology from Usercentrics to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, website:
https://usercentrics.com/ (hereinafter “Usercentrics”).
When you enter our website, the following personal data is transferred to Usercentrics:
Furthermore, Usercentrics stores a cookie in your browser in order to be able to assign the consent granted or its revocation to you. The data collected in this way is stored until you ask us to delete it, delete the Usercentrics cookie yourself or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected.
Usercentrics is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 (1) (c) GDPR.
We have concluded a contract for order processing (AV) in accordance with Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law, which guarantees that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
3.3 Tools and services for analysis, statistical collection and marketing
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager is a tool that helps us to implement tracking or statistics tools and other
technologies on our website. The Google Tag Manager itself does not create any
User profiles, does not save cookies and does not carry out any independent analyses. It is only used to manage and display the tools integrated through it. However, the Google Tag Manager records your IP address, which can also be transferred to Google's parent company in the United States.
The use of Google Tag Manager is based on Art. 6 (1) lit. f GDPR. The
Website operators have a legitimate interest in the quick and uncomplicated integration and management of various tools on their website. If a corresponding consent has been requested, the processing will be carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and 25 Para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.
Google Analytics (4)
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, length of stay, operating systems used and origin of the user. This data is summarized in a user ID and assigned to the respective device of the website visitor.
Furthermore, Google Analytics allows us to record your mouse and scroll movements and clicks, among other things. Google Analytics also uses various modeling approaches to supplement the collected data sets and uses machine learning technologies in data analysis.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there. The use of this service is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR and Section 25 Para. 1 TDDDG. The consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/ .
browser plugin
You can prevent Google from collecting and processing your data by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en . More information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
Google signals
We use Google Signals. When you visit our website, Google Analytics records your location, search history, YouTube history, and demographic data (visitor data), among other things. This data can be used for personalized advertising with the help of Google Signal. If you have a Google account, the visitor data from Google Signal is linked to your Google account and used for personalized advertising messages. The data is also used to create anonymized statistics on the user behavior of our users.
Google Analytics E-Commerce Measurement
This website uses the "E-Commerce Measurement" function of Google Analytics. With the help of E-Commerce Measurement, the website operator can analyze the purchasing behavior of website visitors in order to improve its online marketing campaigns. Information such as orders placed, average order values, shipping costs and the time from viewing to purchasing a product is recorded. This data can be summarized by Google under a transaction ID that is assigned to the respective user or their device.
Varify.io
We use Varify.io from Varify GmbH, Südliche Münchner Straße 55, 82031 Grünwald. Varify is a service that enables us to further develop our website and adapt it to requirements using so-called “A/B tests”.
For this purpose, we store cookies in your browser in order to be able to evaluate and analyze these "A/B tests". We have ensured that the cookies stored in your browser do not process any of your personal data and that no conclusions can be drawn about you. The cookies only record your interaction with the website by dividing you into a user group. The analysis and evaluation of the user group is carried out anonymously. Your IP address is processed briefly to display the cookie, but it is not stored.
The use of Varify.io is based on Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in A/B testing in order to optimize and improve the online offering. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and 25 Para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's end device (e.g. device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.
We have concluded a contract for order processing (AV) in accordance with Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law, which guarantees that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program from Google
Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites
when the user enters certain search terms into Google (keyword targeting). In addition, targeted advertisements can be displayed based on user data available to Google (e.g.
location data and interests) (target group targeting). We as website operators
We can evaluate this data quantitatively, for example by analyzing which search terms led to the display of our advertisements and how many advertisements led to corresponding clicks.
The use of this service is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR and 25 Para. 1 TDDDG. The consent can be revoked at any time. The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://policies.google.com/privacy/frameworks and
https://privacy.google.com/businesses/controllerterms/mccs/.
Google AdSense
This website uses Google AdSense, a service for integrating advertisements. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We use Google AdSense in "non-personalized" mode. In contrast to personalized mode, the advertisements are not based on your previous user behavior and no user profile is created of you. Instead, so-called "context information" is used when selecting the advertisement. The selected advertisements are then based on, for example, your location, the content of the website you are on or your current search terms. You can find out more about the differences between personalized and non-personalized targeting with Google AdSense at:
https://support.google.com/adsense/answer/9007336 .
Please note that even when using Google Adsense in non-personalized mode, cookies or similar recognition technologies (e.g. device fingerprinting) may be used. According to Google, these are used to combat fraud and abuse.
The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and 25 (1) TDDDG. The consent can be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/ .
You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in:
https://adssettings.google.com/authenticated .
You can find more information about Google’s advertising technologies here:
https://policies.google.com/technologies/ads and
https://www.google.de/intl/de/policies/privacy/ .
Microsoft Advertising
We use the technologies presented below from Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland ("Microsoft"). Data processing is carried out on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR. The information automatically collected by Microsoft technologies about your use of our website is usually transferred to a server of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA and stored there.
There is no adequacy decision from the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission.
Further information about data processing by Microsoft can be found in Microsoft's privacy policy https://privacy.microsoft.com/de-de/privacystatement
For advertising purposes in the Bing, Yahoo and MSN search results as well as on third-party websites, the so-called Microsoft Advertising Remarketing Cookie is set when you visit our website, which automatically enables interest-based advertising by collecting and processing data (IP address, time of visit, device and browser information as well as information about your use of our website) and by means of a pseudonymous CookieID and based on the pages you visit.
For website analysis and event tracking, we use Microsoft Advertising Universal Event Tracking (UET) to measure your subsequent usage behavior if you have accessed our website via a Microsoft Advertising ad, from which usage profiles are created using pseudonyms. Cookies can be used for this purpose and data (IP address, time of visit, device and browser information as well as information about your use of our website based on events specified by us, such as visiting a website or registering for a newsletter) can be collected, from which usage profiles are created using pseudonyms.
If a corresponding consent has been requested, the processing will be carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and 25 Para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.
TikTok Pixel
We use the TikTok Pixel on our website. The TikTok Pixel is a TikTok advertiser tool from the two providers:
The TikTok pixel is a JavaScript code snippet that enables us to understand and track the activities of visitors to our website. The TikTok pixel collects and processes information about the visitors to our website or the devices they use (so-called event data).
The event data collected via the TikTok pixel is used to target our advertisements and to improve ad delivery and for personalized advertising. For this purpose, the event data collected on our website using the TikTok pixel is transmitted to TikTok.
Some of this event data is information that is stored on the device you are using. Cookies are also used via the TikTok pixel to store information on the device you are using. Such storage of information by the TikTok pixel or access to information that is already stored on your device only takes place with your consent. The use of this service is based on your consent in accordance with Art. 6 (1) (a) GDPR and 25 (1) TDDDG. Consent can be revoked at any time.
This collection and transmission of event data is carried out by us and TikTok as joint controllers in accordance with Art. 26 GDPR. We have entered into an agreement with TikTok on processing as joint controllers, which sets out the distribution of data protection obligations between us and TikTok. In this agreement, we and TikTok have agreed, among other things,
Art. 15 to 20 GDPR with regard to the personal data stored by Tik Tok after the joint processing.
You can access the agreement between us and TikTok at https://ads.tiktok.com/i18n/official/article?aid=300871706948451871 .
TikTok is solely responsible for the processing of the transmitted event data following transmission. For more information on how TikTok processes personal data, including the legal basis on which TikTok relies and the options for exercising your rights vis-à-vis TikTok, please see TikTok's data policy at https://www.tiktok.com/legal/privacy-policy?lang=de-DE .
polyfill-fastly.net
A web service from the company The Financial Times Limited, 1 Southwark Bridge, SE1 9HL London, United Kingdom (hereinafter: polyfill-fastly.net) is loaded onto our website. We use this data to ensure the full functionality of our website. In this context, your browser may transmit personal data to polyfill-fastly.net. The legal basis for data processing is Art. 6 Para. 1 lit. f GDPR. The legitimate interest is that the website functions correctly. The data is deleted as soon as the purpose for which it was collected has been fulfilled. Further information on the handling of the transferred data can be found in the polyfill-fastly.net privacy policy: https://polyfill-fastly.net/docs/privacy-policy
Hyros
On our website we use the service “Hyros” from the provider Hyros, Inc., 13359 N Highway 183 Ste 406 # 2008, Austin, TX 78750 USA. By using Hyros we can see whether our advertisements were successful. We also receive statistical data to optimize the effectiveness of our advertisements.
The use is based on Art. 6 Paragraph 1 Letter a of GDPR (consent). Your consent is voluntary and can be revoked at any time.
When used, data may also be transferred to the USA. Hyros is certified according to the Data Privacy Framework Program and therefore meets the requirements of the EU adequacy decision. We have also concluded a contract for order processing with Hyros in accordance with Art. 28 GDPR.
3.4 Contact form
When you contact us (e.g. via contact form, email, telephone or via social media), the data sent by the person making the inquiry will be processed to the extent necessary to answer the contact inquiries and any requested measures and stored on our servers as part of data backup. We will use your data exclusively to process your request. Your data will be treated as strictly confidential. It will not be passed on to third parties.
Contact requests within the framework of contractual or pre-contractual relationships are answered to fulfill our contractual obligations or to answer (pre)contractual requests and otherwise on the basis of legitimate interests in answering the requests.
3.5 Customer account
Contractual partners can create an account within our online offering (e.g. customer or user account, "customer account" for short). If the registration of a customer account is required, contractual partners will be informed of this and of the information required for registration. Customer accounts are not public and cannot be indexed by search engines. As part of the registration and subsequent logins and use of the customer account, we save the customers' IP addresses along with the access times in order to be able to prove registration and prevent any misuse of the customer account.
If customers have terminated their customer account, the data relating to the customer account will be deleted, unless their retention is required for legal reasons. It is the customer's responsibility to back up their data when the customer account is terminated.
3.6 Shop and e-commerce
We process our customers' data to enable them to select, purchase or order the selected products, goods and associated services, as well as to pay for and deliver or execute them. If necessary to execute an order, we use service providers, in particular postal, forwarding and shipping companies, to carry out the delivery or execution for our customers. We use the services of banks and payment service providers to process payment transactions. The required information is marked as such in the order or comparable purchase process and includes the information required for delivery, provision and billing as well as contact information in order to be able to hold any consultation.
3.6.1. Purchase of goods
If you are already a customer of ours and you interrupt the process during a new order process or are unable to complete your purchase, we will remind you after a certain time by email or SMS of the items you have placed in your shopping cart so that you do not have to put them together again ("Abandoned Cart") or send you a message with the items you have viewed ("Abandoned Browse"). We use cookies for this purpose. For more information on the use of cookies, see section 3.1.2 ("Cookies, tracking pixels and tools").
The legal basis for sending notifications is Section 7 Paragraph 3 of the German Act Against Unfair Competition (UWG). You can object to the sending of notifications at any time, for example by contacting us via the corresponding link in the email you received.
3.7. Direct marketing
3.7.1. Customer information
Unless you have objected, we will use the email address and mobile phone number that you provided when purchasing goods or services to electronically send you advertising for our own goods or services that are similar to those that you have already purchased or used from us. For this purpose, we use your email address, mobile phone number, name and order history to send you information about products that may interest you based on your last orders. The legal basis for data processing is Art. 6 Para. 1 lit. F GDPR and Section 7 Para. 3 UWG.
You can object to this processing at any time in accordance with Art. 21 Para. 2 GDPR, for example by contacting us via the corresponding link in the email you received or by sending an email to service@morenutrition.de write.
3.7.2. Newsletter
On our website we offer the option of signing up for our newsletter. After registration, we will regularly inform you by email and SMS about news about our offers (e.g. promotions, new products, re-stocks and competitions).
Furthermore, after a certain period of time, you will be reminded by email and SMS of the items you have placed in your shopping cart and whose order you had to interrupt or whose purchase you were unable to complete.
A valid email address or mobile number is required to register for the newsletter. To verify your email address, you will first receive a registration email, which you must confirm using the link. To verify your mobile number, you will receive a registration SMS, which you must confirm using the link (double opt-in). If you subscribe to the newsletter on our website, we process personal data such as your email address and mobile number based on your consent. The legal basis for the processing is Art. 6 (1) subsection 1 lit. a GDPR.
You can unsubscribe from our newsletter at any time, for example by contacting us via the corresponding link in the email you received or by writing an email to service@morenutrition.de .
3.7.3. Service providers
We use Klaviyo to send customer information and newsletters. The provider is Klaviyo, Inc., 125 Summer St Floor 6, Boston, MA 02111, United States (hereinafter "Klaviyo"). Klaviyo offers marketing automation software for marketing services and products, including SEO and content creation, lead management, newsletters, email and SMS marketing and web analytics. Klaviyo uses cookies and other browser technologies to evaluate user behavior and identify users. This information is used, among other things, to compile reports on website activity and to provide customers with personalized communications (e.g. reminders of incomplete purchases, information about products customers have viewed, etc.). In addition, Klaviyo is used to store and transmit data entered in forms using cookies, including your IP address. In this case, your data will be passed on to Klaviyo, Inc.
The data you enter to subscribe to the newsletter (e.g. email address) will be stored on Klaviyo's servers in the United States .
The data you provide to us for the purpose of subscribing will be stored by us until you unsubscribe from us or the service provider and will be deleted from the mailing list after you unsubscribe. Data that we have stored for other purposes will remain unaffected.
3.7.4. Analysis
With the help of Klaviyo we can analyse our newsletter campaigns, among other things. If you have a
When you open an email sent by Klaviyo, a file contained in the email (so-called web beacon) connects to Klaviyo's servers in the USA. This makes it possible to determine whether a newsletter message has been opened and which links have been clicked. In addition, technical information is recorded (e.g. time of retrieval, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better tailor future newsletters to the interests of the recipients.
If you do not want Klaviyo to analyze your data, you must unsubscribe from the newsletter. We provide a link for this in every newsletter message. The data processing is carried out on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
The data you provide to us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data that we have stored for other purposes remains unaffected.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission.
Details can be found here: https://www.klaviyo.com/legal/dpa
After you unsubscribe from the newsletter distribution list, your email address will be stored by us or the
Newsletter service provider may store your data in a blacklist if this is necessary to prevent future
Mailings are required. The data from the blacklist is only used for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR). Storage in the blacklist is not time-limited. You can object to storage if your interests outweigh our legitimate interest.
For more information, please see Klaviyo’s privacy policy at:
https://www.klaviyo.com/legal/privacy-notice
We have concluded a contract for order processing (AV) in accordance with Art. 28 GDPR with the above-mentioned provider. This is a contract required by data protection law, which guarantees that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
3.8. Evaluation requests
If you have ordered a product in our shop, we will ask you by email and SMS about your satisfaction with your order, unless you have previously objected to this. To send you this request, we use the email address and mobile number you provided. We also process your name, your IP address and the IP geolocation used, as well as information about your order. The customer satisfaction survey and the data processing described are based on the legal basis of Section 7 (3) UWG in conjunction with Art. 6 (1) lit. f) GDPR. This processing is for direct advertising.
To evaluate your order, we use the service Trustpilot Trustpilot A/S, Pilestraede 58, 5th floor, DK-1112 Copenhagen, Denmark. For this purpose, we will pass on your name, email address and reference number to Trustpilot. The transfer of your data takes place in accordance with Art. Paragraph 1 lit. f GDPR and is based on our legitimate interest in continuously improving our services and products.
You can object to the processing and in particular the use of your e-mail address and mobile phone number for this purpose at any time in accordance with Art. 21 Para. 2 GDPR, without incurring any costs other than the transmission costs according to the basic rates.
3.9 Economic analyses and market research
For business reasons and in order to be able to identify market trends and the wishes of contractual partners and users, we analyze the data available to us on business transactions, contracts, inquiries, etc., whereby the group of persons affected may include contractual partners, interested parties, customers, visitors and users of our online offering.
The analyses are carried out for the purposes of business evaluations, marketing and market research (e.g. to determine customer groups with different characteristics). In doing so, we can take into account the profiles of registered users, if available, along with their information, e.g. on services used. The analyses serve us alone and are not disclosed externally, unless they are anonymous analyses with summarized, i.e. anonymized values. Furthermore, we take the privacy of the users into account and process the data for the analysis purposes as pseudonymously as possible and, if possible, anonymously (e.g. as summarized data).
Within the framework of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer the data subjects efficient and secure payment options and, in addition to banks and credit institutions, use other payment service providers (collectively "payment service providers").
The data processed by the payment service providers includes inventory data such as name and address, bank details such as account numbers or credit card numbers, passwords, TANs and checksums as well as contract, sum and recipient-related information. The information is required to carry out the transactions. However, the data entered is only processed and stored by the payment service providers. This means that we do not receive any account or credit card-related information, only information confirming or rejecting the payment. The payment service providers may transmit the data to credit agencies. This transmission is for the purpose of checking identity and creditworthiness. For this purpose, we refer to the terms and conditions and the data protection information of the payment service providers.
The terms and conditions and data protection notices of the respective payment service providers apply to payment transactions and can be accessed on the respective websites or transaction applications. We also refer to these for further information and to assert revocation, information and other rights of those affected.
3.11 Transport service providers
For the purpose of delivering ordered goods, we work with logistics service providers/transport companies and/or shipping partners to whom the following data is transmitted for the purpose of delivering the ordered goods or for the purpose of notifying the shipment: first name, last name, postal address and, if applicable, the email address and, if applicable, the telephone number. The legal basis for the processing is Art. 6 paragraph 1 letter b) GDPR.
3.12 Security
We have taken technical and administrative security precautions to protect your personal data against loss, destruction, manipulation and unauthorized access. All of our employees and service providers working for us (contract processors) are obliged to comply with the applicable data protection laws.
Whenever we collect and process personal data, it is encrypted before it is transmitted. This means that your data cannot be misused by third parties. Our security measures are subject to a continuous improvement process and our privacy statements are constantly being revised. Please ensure that you have the latest version.
4. Online presence on social media
If you have given your consent to this in accordance with Art. 6 Paragraph 1 Clause 1 Letter a of GDPR to the respective social media operator, when you visit our online presence on our social media channels, your data will be automatically collected and stored for market research and advertising purposes, from which usage profiles will be created using pseudonyms. These can be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. Cookies are usually used for this purpose. For detailed information on the processing and use of data by the respective social media operator, as well as a contact option and your rights and setting options to protect your privacy, please refer to the respective linked data protection notices of the providers on their websites. If you still need help with this, you can contact us.
5. Rights of the data subject
You have the right to information, correction, deletion or restriction of the processing of your stored data at any time, the right to object to the processing as well as the right to data portability and to lodge a complaint in accordance with the requirements of data protection law.
You can request information from us as to whether and to what extent we process your data.
If we process your data that is incomplete or incorrect, you can request that we correct or complete it at any time.
You can request that we delete your data if we process it unlawfully or if the processing disproportionately interferes with your legitimate interests in protection. Please note that there may be reasons that prevent immediate deletion, e.g. in the case of statutory retention periods.
Regardless of your exercise of your right to erasure, we will delete your data immediately and completely, unless there is a contractual or statutory obligation to retain the data in this regard.
You can request that we restrict the processing of your data if
- You contest the accuracy of the data for a period enabling us to verify the accuracy of the data.
- the processing of the data is unlawful, but you refuse to delete it and instead request a restriction on the use of the data,
- we no longer need the data for the intended purpose, but you still need this data to assert or defend legal claims, or
- You have objected to the processing of your data.
You can request that we provide you with the data you have provided to us in a structured, common and machine-readable format and that you can transmit this data to another responsible party without hindrance from us, provided that
- we process this data based on your consent which can be revoked or to fulfil a contract between us, and
- this processing is carried out using automated procedures.
If technically feasible, you can request that we transmit your data directly to another responsible party.
If we process your data based on legitimate interests, you can object to this data processing at any time; this would also apply to profiling based on these provisions. We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms or the processing serves to assert, exercise or defend legal claims. You can object to the processing of your data for the purpose of direct marketing at any time without giving reasons.
If you believe that we are violating German or European data protection law when processing your data, please contact us so that we can clarify any questions. You also have the right to contact the supervisory authority responsible for you, the relevant state data protection authority.
If you wish to assert one of the above-mentioned rights against us, please contact our data protection officer. In case of doubt, we may request additional information to confirm your identity.
6. Changes to this Privacy Policy
We reserve the right to change our privacy policy at any time if this should become necessary, for example due to new technologies. Please ensure that you have the latest version. If fundamental changes are made to this privacy policy, we will announce these on our website.