Privacy policy
1) Introduction and contact details of the person responsible
1.1 We are pleased that you are visiting our website and thank you for your interest. Below we will inform you about how we handle your personal data when you use our website. Personal data is all data that can be used to identify you personally.
1.2 The person responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Rene Kiessling, My.Bali.nest, Schneeberger Straße 20, 08324 Bockau, Germany, Tel.: +49 (0)1742412103, E-Mail: info@mybalinest.comThe controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
2) Data collection when visiting our website
2.1 If you use our website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the website server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the time of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if necessary: in anonymous form)
The processing takes place in accordance with Article 6 Paragraph 1 Letter f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the person responsible), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://“ and the lock symbol in your browser bar.
3) Hosting & Content-Delivery-Network
3.1 Shopify
We use the system of the following provider to host our website and display the page content: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")
Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc. or Shopify (USA) Inc.
SAll data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
In the case of data transfer to Canada, an adequate level of data protection is guaranteed by an adequacy decision of the European Commission.
For the transfer of data to the USA, the provider refers to standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.
3.2 Cloudflare
We use a content delivery network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service enables us to deliver large media files such as graphics, page content or scripts more quickly via a network of regionally distributed servers. The processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 Paragraph 1 Letter f of GDPR. We have concluded a data processing agreement with the provider that ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
4) Cookies
In order to make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your end device. Some of these cookies are automatically deleted after closing the browser (so-called “session cookies”), some of these cookies remain on your end device for a longer period of time and enable page settings to be saved (so-called “persistent cookies”). In the latter case, you can find the storage period in the overview of the cookie settings in your web browser.
If personal data is also processed by individual cookies used by us, the processing takes place in accordance with Article 6 (1) (b) GDPR either for the execution of the contract, in accordance with Article 6 (1) (a) GDPR in the event that consent has been given or in accordance with Art. 6 (1) (f) GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.
You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general.
Please note that if cookies are not accepted, the functionality of our website may be restricted.
5) Contact
5.1 Shopify Inbox
This website uses the live chat system of the following provider: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada ("Shopify").
The processing of personal data transmitted via chat takes place either in accordance with Art. 6 Para. 1 lit. b GDPR, because it is necessary for the initiation or execution of the contract, or in accordance with Art. 6 Para. 1 lit. f GDPR due to our legitimate interest in the effective support of our site visitors.
Your data transmitted in this way will be deleted, subject to any conflicting statutory retention periods, once the matter in question has been conclusively clarified.
In addition, cookies can be used to collect and evaluate additional information for the purpose of creating pseudonymized user profiles. However, this information does not serve to identify you personally and is not merged with other data sets. If this information is personally identifiable, it is processed in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization purposes.
Cookies can be prevented by selecting the appropriate settings on your browser. However, this may limit the functionality of our website.
You can object to the collection and storage of data for the purpose of creating a pseudonymized user profile at any time with effect for the future.
Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc. or Shopify (USA) Inc.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
For the transfer of data to the USA, the provider refers to standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.
In the case of data transfer to Canada, an adequate level of data protection is guaranteed by an adequacy decision of the European Commission.
5.2 Trustpilot
For review reminders we use the services of the following provider: Trustpilot A/S, Pilestræde 58, 1112 Copenhagen, Denmark
Only on the basis of your express consent in accordance with Art. 6 (1) (a) GDPR will we transmit your email address and, if applicable, other customer data to the provider so that they can contact you by email with a review reminder.
You can revoke your consent at any time with effect for the future vis-à-vis us or the provider.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
5.3 When you contact us (e.g. via contact form or email), personal data will be processed exclusively for the purpose of processing and answering your request and only to the extent necessary for this purpose.
The legal basis for processing this data is our legitimate interest in answering your request in accordance with Art. 6 (1) (f) GDPR. If your contact is aimed at a contract, an additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention periods to the contrary.
6) comment function
As part of the comment function on this website, your comment, information about the time the comment was created and the name of the commentator you have chosen will be saved and published on this website. Furthermore, your IP address will be saved for security reasons in order to enable attribution to the author in the event of illegal comments. Your e-mail address will be saved so that you can be contacted if a third party should complain that your published content is illegal.
The legal basis for storing your data is Art. 6 (1) (b) and (f) GDPR. We reserve the right to delete comments if third parties object to them as being unlawful.
In addition, we analyze the effectiveness of our ads by tracking whether users were redirected to our website after clicking on an ad (conversion).
In accordance with Art. 6 (1) (b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can find out which data is required to open an account from the input mask of the corresponding form on our website.
One LDeletion of your customer account is possible at any time and can be done by sending a message to the above-mentioned address of the person responsible. After LIf your customer account is deleted, your data will be deleted provided that all contracts concluded through it have been fully processed, there are no statutory retention periods to the contrary and we have no legitimate interest in continuing to store the data.
8) Use of Customer Data for Direct Marketing
8.1 Registration for our email newsletter
If you register for our e-mail newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your e-mail address. Providing further data is voluntary and is used to be able to address you personally. We use the so-called double opt-in procedure to send the newsletter, which ensures that you only receive the newsletter if you have expressly confirmed your consent to receive the newsletter by clicking on a verification link sent to the email address provided
By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 Paragraph 1 Letter a of GDPR. We store your IP address entered by your Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your email address at a later date. The data we collect when you register for the newsletter is used strictly for the intended purpose.
You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a message to the person responsible named above. After unsubscribing, your email address will be immediately deleted from our newsletter mailing list unless you have expressly consented to further use of your data or we reserve the right to use the data in any other way that is permitted by law and about which we will inform you in this declaration.
8.2 Product availability notification by email
For items that are temporarily unavailable, you can opt-in to receive email notifications of stock availability. We will send you a one-time email message about the availability of the item you have selected. The only mandatory information for sending this notification is your e-mail address. Providing further data is voluntary and may be used to address you personally. We use the so-called double opt-in procedure for sending e-mails, which ensures that you only receive a notification if you have expressly confirmed your consent to this by clicking on a verification link sent to the e-mail address provided.
By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 Paragraph 1 Letter a of GDPR. We store your IP address entered by your Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your email address at a later date. The data we collect when you register for our email notification service for product availability is used strictly for the intended purpose.
You can unsubscribe from the availability notifications at any time by sending a corresponding message to the person responsible named above. After unsubscribing, your email address will be immediately deleted from our mailing list set up for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use the data in any other way that is permitted by law and about which we will inform you in this declaration.
8.3 Shopping cart reminders by email
In case you cancel your purchase with us before completing the order, you have the MPossibility to be reminded once by email of the contents of your virtual shopping cart.
The only mandatory information for sending this reminder is your e-mail address. Providing further data is voluntary and may be used to address you personally. We use the so-called double opt-in procedure for sending e-mails, which ensures that you only receive a notification if you have expressly confirmed your consent to this by clicking on a verification link sent to the e-mail address provided.
By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6 Paragraph 1 Letter a of GDPR to send a shopping cart reminder. We store your IP address entered by your Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your email address at a later date. The data we collect when you register for our email notification service is used strictly for the intended purpose.
You can unsubscribe from the shopping cart reminders at any time by sending a corresponding message to the person responsible named above. After unsubscribing, your email address will be immediately deleted from our mailing list set up for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use the data in any other way that is permitted by law and about which we will inform you in this declaration.
9) Data processing for order processing
9.1 To the extent necessary for the execution of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Paragraph 1 Letter b of GDPR.
If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we process the contact data you provide when ordering (name, address, e-mail address) in order to inform you within the scope of our legal information obligations in accordance with Art. 6 Para 1 lit. c GDPR via a suitable communication channel (e.g. by post or e-mail) about upcoming updates in the period stipulated by law. Your contact details will be used strictly earmarked for notifications about updates owed by us and will only be processed by us for this purpose to the extent that this is necessary for the information in question.
In order to process your order, we also work together with the following service provider(s), who support us in whole or in part in the implementation of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
9.2 Transfer of personal data to shipping service providers
- DHL
We use the following provider as a transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany
We will pass on your email address and/or telephone number to the provider in accordance with Art. 6 (1) (a) GDPR before delivery of the goods for the purpose of coordinating a delivery date or to notify the provider of the delivery, provided that you have given your express consent to this during the ordering process. Otherwise, we will only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 (1) (b) GDPR. The information will only be passed on if this is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with the provider or the delivery notification is not possible.
The consent can be revoked at any time with effect for the future vis-à-vis the above-mentioned person responsible or vis-à-vis the provider.
9.3 Use of payment service providers (payment services)
- Apple Pay
If you choose the "Apple Pay" payment method from Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment will be processed using the "Apple Pay" function of your device running iOS, watchOS or macOS by debiting a payment card stored with "Apple Pay". Apple Pay uses security features built into your device's hardware and software to protect your transactions. In order to release a payment, it is therefore necessary to enter a code previously defined by you and to verify it using the "Face ID" or "Touch ID" function of your device.
For the purpose of payment processing, the information you provide during the ordering process, along with the information about your order, will be sent to Apple in encrypted form. Apple then encrypts this data again with a developer-specific key before the data is sent to the payment service provider of the payment card stored in Apple Pay to carry out the payment. The encryption ensures that only the website through which the purchase was made can access the payment details. After payment is made, Apple will send your device account number and a transaction-specific dynamic security code to the originating website to confirm payment success.
If personal data is processed in the transmissions described, the processing is carried out exclusively for the purpose of payment processing in accordance with Article 6 (1) (b) GDPR.
Apple retains anonymized transaction information, including approximate purchase amount, date and time, and whether the transaction was successfully completed. The anonymization completely excludes any personal reference. Apple uses the anonymized data to improve Apple Pay and other Apple products and services.
When you use Apple Pay on iPhone or Apple Watch to complete a purchase made through Safari on Mac, the Mac and the authorization device communicate over an encrypted channel on Apple servers. Apple does not process or store any of this information in a format that can identify you. You can MYou can disable the ability to use Apple Pay on your Mac in your iPhone's settings. Go to Wallet & Apple Pay and uncheck Allow Payments on Mac.
Further information on data protection at Apple Pay can be found at the following internet address:https://support.apple.com/de-de/HT203027
- Google Pay
If you decide to use the “Google Pay” payment method from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”), payment will be processed using the “Google Pay” application on your device with at least Android 4.4 ("KitKat") operated mobile device with an NFC function by debiting a payment card stored with Google Pay or a payment system verified there (e.g. PayPal). To release a payment via Google Pay of more than €25, you must first unlock your mobile device using the verification measure set up (e.g. face recognition, password, fingerprint or pattern).
For the purpose of payment processing, the information you provide during the ordering process together with the information about your order will be passed on to Google. Google then transmits your payment information stored in Google Pay in the form of a unique transaction number to the source website, which is used to verify that the payment has been made. This transaction number does not contain any information about the real payment data of your means of payment stored with Google Pay, but is created and transmitted as a uniquely valid numeric token. For all transactions via Google Pay, Google only acts as an intermediary to process the payment process. The transaction is carried out exclusively in the relationship between the user and the source website by debiting the means of payment stored with Google Pay.
If personal data is processed in the transmissions described, the processing is carried out exclusively for the purpose of payment processing in accordance with Article 6 (1) (b) GDPR.
Google reserves the right to collect, store and evaluate certain process-specific information for every transaction made via Google Pay. This includes the date, time, and amount of the transaction, merchant location and description, a description provided by the merchant of the goods or services purchased, photographs you included with the transaction, the name and email addresses of the seller and buyer, or of the sender and recipient, the payment method used, your description of the reason for the transaction and, if applicable, the offer associated with the transaction.
According to Google, this processing takes place exclusively in accordance with Article 6 Paragraph 1 Letter f GDPR on the basis of the legitimate interest in proper accounting, the verification of transaction data and the optimization and functional maintenance of the Google Pay service.
Google also reserves the right to merge the processed transaction data with other information that is collected and stored by Google when using other Google services.
The Google Pay Terms of Use can be found here:
https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=de
Weitere Information on data protection at Google Pay can be found at the following internet address:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=de
- Klarna
One or more online payment methods from the following provider are available on this website: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden
If you select a payment method from the provider that requires you to pay in advance (such as credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent that it is necessary for this purpose.
If you select a payment method where the provider makes an advance payment (e.g. purchase on account, installment plan or direct debit), you will also be asked to provide certain personal data (first and last name, street, house number, postcode, city, date of birth, email address, telephone number, if applicable, data on an alternative payment method) during the ordering process.
In order to protect our legitimate interest in determining the solvency of our customers, we will forward this data to the provider for the purpose of a credit check in accordance with Art. 6 Paragraph 1 Letter f of GDPR. The provider will check on the basis of the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option you have selected can be granted with regard to payment and/or default risks.
In addition to provider-internal criteria in accordance with Art. 6 (1) (f) GDPR, identity and creditworthiness information from the following credit agencies may also be included in the decision-making process when reviewing the application:
https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies
The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical process. Among other things, but not exclusively, address data is included in the calculation of the score values.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Paypal
One or more online payment methods from the following provider are available on this website: PayPal (Europe) S.arl et Cie, S.CA, 22-24 Boulevard Royal, L-2449 Luxembourg
If you select a payment method from the provider that requires you to pay in advance, the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent that it is necessary for this purpose.
If you select a payment method for which we pay in advance, you will also be asked to provide certain personal information (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and if applicable, data on an alternative payment method) during the ordering process.
In order to protect our legitimate interest in determining your ability to pay in such cases, we will forward this data to the provider for the purpose of a credit check in accordance with Art. 6 Paragraph 1 Letter f of GDPR. The provider will check on the basis of the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option you have selected can be granted with regard to payment and/or default risks.
The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical process. Among other things, but not exclusively, address data is included in the calculation of the score values.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Shopify Payments
One or more online payment methods from the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
If you select a payment method from the provider that requires you to pay in advance (such as credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent that it is necessary for this purpose.
- IMMEDIATELY
One or more online payment methods from the following provider are available on this website: SOFORT GmbH, Theresienhöhe 12, 80339 München, Germany
If you select a payment method from the provider that requires you to pay in advance (such as credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) (b) GDPR. In this case, your data will be passed on exclusively for the purpose of processing the payment with the provider and only to the extent that it is necessary for this purpose.
10) Web Analytics Services
Google Tag Manager
In so far as special categories of personal data within the scope of the application process within the meaning of Art.
The Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and calibrating, controlling and linking them to conditions via a uniform user interface. The Google Tag Manager itself does not store or read information on user devices. The service also does not carry out any independent data analyses. However, when you access a page, the Google Tag Manager transmits your IP address to Google and may store it there. Transmission to Google LLC servers in the USA is also possible.
This processing will only be carried out if you have given us your express consent in accordance with Art. 6 Paragraph 1 Letter a of GDPR. Without this consent, Google Tag Manager will not be used during your visit to the website. You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
11) Retargeting/ Remarketing und Conversion-Tracking
11.1 Facebook Pixel for creating custom audiences
Within our online offering, we use the "Facebook Pixel" service from the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Facebook")
If a user clicks on an ad we have placed on Facebook, the URL of our linked page is extended by a parameter using "Facebook Pixel". This URL parameter is then entered into the user's browser after forwarding via a cookie that our linked page itself sets.
This enables Facebook to determine the visitors to our online offering as a target group for the display of advertisements (so-called "Facebook Ads"). Accordingly, we use the service to only display the Facebook ads placed by us to those Facebook users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products determined based on the websites visited) which we transmit to Facebook (so-called "custom audiences").
On the other hand, “Facebook Pixel” can be used to track whether users were redirected to our website after clicking on a Facebook ad and which actions they perform there (so-called “conversion tracking”).
The data collected is anonymous to us and does not allow us to draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes.
All of the processing described above, in particular the setting of cookies for reading information on the end device used, will only be carried out if you have given us your express consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the “Cookie Consent Tool” provided on the website.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
The information generated by Facebook is usually transmitted to a Facebook server and stored there; in this context, data may also be transmitted to Meta Platforms Inc. servers in the USA.
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
11.2 Google Ads Remarketing
This website uses retargeting technology from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
For this purpose, Google places a cookie in the browser of your device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. Further data processing only takes place if you have agreed to Google linking your internet and app browsing history with your Google account and using information from your Google account to personalize ads that you view on the web. In this case, if you are logged in to Google while visiting our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. For this purpose, Google will temporarily link your personal data with Google Analytics data to create target groups.As part of the use of Google Ads Remarketing, personal data may also be transmitted to the servers of Google LLC. come in the US.
All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your express consent in accordance with Art. 6 Paragraph 1 Letter a of GDPR. Without this consent, retargeting technology will not be used during your visit to the website.
You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.
11.3 Pinterest-Tag Conversion-Tracking
This website uses the conversion tracking technology of the following provider: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland
If you have accessed our website from an advertisement on the provider's domain, the success of the advertisement can be tracked using cookies and/or comparable technologies (tracking pixels, web beacons, pings or HTTP requests).
For this purpose, certain device and browser information, including your IP address where applicable, is read using tracking technology in order to record and evaluate user actions predefined by us (e.g. completed transactions, leads, search queries on the website, visits to product pages). This enables us to create statistics on user behavior on our website after being redirected from an advertisement, which we use to optimize our offering.
All processing described above, in particular the setting of cookies for reading information on the device used, will only be carried out if you have given us your express consent in accordance with Art. 6 Paragraph 1 Letter a of GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
11.4 Google Ads Conversion-Tracking
This website uses the online advertising program "Google Ads" and, as part of Google Ads, conversion tracking by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use Google Ads to draw attention to our attractive offers with the help of advertising material (so-called Google Adwords) on external websites. In relation to the data of the advertising campaigns, we can determine how successful the individual advertising measures are. We are pursuing the goal of showing you advertising that is of interest to you, making our website more interesting for you and achieving a fair calculation of the advertising costs incurred.
The cookie for conversion tracking is set when a user clicks on an Ads ad placed by Google. Cookies are small text files that are stored on your device. These cookies usually expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Cookies cannot therefore be tracked across the websites of Google Ads customers. The information obtained using the conversion cookie is used to create conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users. When using Google Ads, personal data may also be transferred to Google LLC's servers in the USA.
Details on the processing initiated by Google Ads Conversion Tracking and how Google handles data from websites can be found here:https://policies.google.com/technologies/partner-sites
All of the processing described above, in particular the setting of cookies for reading information on the end device used, will only be carried out if you have given us your express consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the “Cookie Consent Tool” provided on the website.
You can also permanently object to the setting of cookies by Google Ads conversion tracking by downloading and installing the Google browser plug-in available under the following link:
https://www.google.com/settings/ads/plugin?hl=de
Please note that certain functions of this website may not be available or may only be available to a limited extent if you have deactivated the use of cookies.
Google’s privacy policy can be viewed here:https://www.google.de/policies/privacy/
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
12) Site Functionalities
12.1 Instagram-Plugins
Our website uses plugins of the social network of the following providers: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland
In the event of a successful application, the data provided will be based on Art.
In order to increase the protection of your data when visiting our website, the plugins are initially deactivated using so-called “2-click” or “Shariff”Lsolution integrated into the page.
1 BDSG) for the purpose of carrying out the employment relationship.
Only when you activate the plug-ins and thereby give your consent to the data transfer in accordance with Art. 6 Paragraph 1 Letter a of GDPR will your browser establish a direct connection to the provider's servers. In this case, regardless of whether you log in to an existing user profile, a certain amount of information about the device you are using (including your IP address), your browser and your page history will be transmitted to the provider and may be further processed there.
If you are logged into an existing user profile on the provider's social network, information about interactions carried out via the plug-ins will also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation has no influence on the data that has already been transferred to the provider.
Data can also be transmitted: Meta Platforms Inc., USA
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
12.2 Pinterest-Plugins
Our website uses plugins of the social network of the following providers: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland
In the event of a successful application, the data provided will be based on Art.
In order to increase the protection of your data when visiting our website, the plugins are initially deactivated using so-called “2-click” or “Shariff”Lsolution integrated into the page.
1 BDSG) for the purpose of carrying out the employment relationship.
Only when you activate the plug-ins and thereby give your consent to the data transfer in accordance with Art. 6 Paragraph 1 Letter a of GDPR will your browser establish a direct connection to the provider's servers. In this case, regardless of whether you log in to an existing user profile, a certain amount of information about the device you are using (including your IP address), your browser and your page history will be transmitted to the provider and may be further processed there.
If you are logged into an existing user profile on the provider's social network, information about interactions carried out via the plug-ins will also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation has no influence on the data that has already been transferred to the provider.
Data may also be transferred to: Pinterest Inc., USA
We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
For the transfer of data to the USA, the provider refers to standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.
12.3 Youtube
This website uses plugins to display and play videos from the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
Data can also be transmitted to: Google LLC., USA
When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to the provider's servers in order to load the plugin. Certain information, including your IP address, is transmitted to the provider.
If the playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics and prevent abusive behavior.
If you are logged into a user account with the provider when you visit the site, your data will be assigned directly to your account when you click on a video. If you do not want this to be assigned to your account, you must log out before pressing the play button.
All of the aforementioned processing, in particular the setting of cookies for reading information on the device used, will only take place if you have given us your express consent in accordance with Art. 6 Paragraph 1 Letter a of GDPR. You can revoke your consent at any time with effect for the future by deactivating this service using the "Cookie Consent Tool" provided on the website.
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
12.4 Google Web Fonts
This site uses so-called web fonts from the following provider for the uniform display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland
When you visit a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly and establishes a direct connection to the provider's servers. Certain browser information, including your IP address, is transmitted to the provider.
Data may also be transmitted to: Google LLC, USA
The processing of personal data when establishing contact with the font provider will only be carried out if you have given us your express consent in accordance with Art. 6 Paragraph 1 Letter a of GDPR. You can revoke your consent at any time with effect for the future by deactivating this service using the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a standard font from your computer will be used.
For the optical design of the captcha window, the provider uses “Google Fonts”, i.e. fonts loaded from the Internet by Google.
12.5 Shopsync for Shopify
This website uses the Shopify app “Shopsync” from ShopSync LLC, PO Box 252, Jefferson City, TN 37760, USA.
With the help of ShopSync, the newsletter service “Mailchimp” is synchronized with our Shopify account in such a way that, on the one hand, updates in Mailchimp email lists (such as an opt-out by a newsletter recipient) are automatically stored on Shopify and, on the other hand, new contact data generated through contract conclusions on Shopify are automatically transferred to Mailchimp’s email lists.
In the first case, data is processed in accordance with Article 6 Paragraph 1 Letter f GDPR on the basis of our legitimate interest in the effective and cross-system maintenance of the files of advertising addressees and the efficient observance of legally significant status changes.
In the second case, the user's first and last name, address and e-mail address together with transaction-related information are only recorded on the basis of the user's express consent in accordance with Article 6 (1) (a) GDPR after a contract has been concluded on Shopify for inclusion in the Mailchimp list (purchase amount, time and date of purchase) transferred to Mailchimp by ShopSync.
Data transferred in this way is not stored or retained by ShopSync after synchronization. All information synced between Shopify and Mailchimp is transmitted over Secure Socket Layer (SSL) technology, and all information transmitted remains encrypted during the sync process.
The synchronization process requires information to be transmitted over a secure connection to servers hosted by Amazon Web Services in the United States.
Further data protection information about ShopSync can be found here:https://shopsync.io/privacy-policy
13) Tools and Miscellaneous
Cookie-Consent-Tool
This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies that require consent and cookie-based applications. The "Cookie-Consent-Tool" is displayed to users when the page is accessed in the form of an interactive user interface, on which consent can be given for certain cookies and/or cookie-based applications by ticking the box. By using the tool, all cookies/services that require consent are only loaded if the respective user gives their consent by ticking the box. This ensures that such cookies are only set on the respective end device of the user if consent has been given.
The tool sets technically necessary cookies to save your cookie preferences. Personal user data is generally not processed here.
If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is carried out in accordance with Article 6 (1) (f) GDPR on the basis of our legitimate interest in a legally compliant, user-specific and user-friendly consent management for cookies and therefore a legally compliant design of our website.
Another legal basis for processing is Art. 6 (1) (c) GDPR. As the person responsible, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.
Where necessary, we have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
Further information on the operator and the setting options of the cookie content tool can be found directly in the corresponding user interface on our website.
14) Rights of the data subject
14.1 The applicable data protection law grants you the following data subject rights (rights to information and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the legal basis stated for the respective conditions for exercising them:
- Right to information according to Art. 15 GDPR;
- Right to rectification according to Art. 16 GDPR;
- right to Lerasure pursuant to Art. 17 GDPR;
- Right to restriction of processing in accordance with Art. 18 GDPR;
- Right to information according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to revoke granted consent in accordance with Art. 7 Para. 3 GDPR;
- Right to complain according to Art. 77 GDPR.
14.2 RIGHT OF OBJECTION
IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF A BALANCING OF INTERESTS IN OUR PREVIOUS LEGITIMATE INTERESTS, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP THE PROCESSING OF THE DATA INVOLVED. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN PROVE COMPREHENSIVE REASONS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FUNDAMENTAL FREEDOMS, OR IF THE PROCESSING IS FOR THE CERTIFICATION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT ADVERTISING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING. YOU MAY OBJECT AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP THE PROCESSING OF THE DATA INVOLVED FOR DIRECT MARKETING PURPOSES.
15) Duration of storage of personal data
The duration of the storage of personal data is based on the respective legal basis, the processing purpose and - if relevant - also based on the respective statutory retention period (e.g. commercial and tax retention periods).
When processing personal data on the basis of an express consent in accordance with Article 6 Paragraph 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.
If there are statutory retention periods for data that are processed as part of legal or similar obligations on the basis of Article 6 (1) (b) GDPR, this data will be routinely deleted after the retention period has expired, provided that it is no longer required to fulfill or initiate a contract and/or we have no legitimate interest in further storage.
When processing personal data on the basis of Article 6 Paragraph 1 Letter f GDPR, this data will be stored until you exercise your right of objection in accordance with Article 21 Paragraph 1 GDPR, unless we can provide compelling reasons worthy of protection prove the processing that outweighs your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
When processing personal data for the purpose of direct advertising on the basis of Article 6 (1) (f) GDPR, this data will be stored until you exercise your right of objection under Article 21 (2) GDPR.
Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.