Thank you for visiting our online shop. Protection of your privacy is very important to us. Below you will find extensive information about how we handle your data.
1. Access data and hosting
You may visit our website without revealing any personal information. With every visit on the website, the web server stores automatically only a so-called server log file which contains e.g. the name of the requested file, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request.
These access data are analysed exclusively for the purpose of ensuring the smooth operation of the website and improving our offer. This serves according to art. 6 (1) 1 lit f GDPR the protection of our legitimate interests in the proper presentation of our offer that are overriding in the process of balancing of interests. All access data are deleted no later than seven days after the end of your visit on our website.
Third-party hosting services
Data are also processed by a third-party provider that we have engaged to render hosting and website presentation services on our behalf. This provider processes on its servers all data that are collected in the manner specified below when you visit our website or fill in forms made available for this purpose in our online shop. Data are processed on other servers only in the scope described herein.
This service provider is based in an EU or EEA member state.
2. Data collection and use for processing the contract and for opening a customer account
We collect personal data that you voluntarily submit to us when you place an order, contact us (e.g. via contact form or by e-mail) or open a customer account with us. Mandatory fields are marked as such because we absolutely need those data to perform the contract or process your contact request or open your customer account, and you would otherwise not be able to complete your order and/or create your customer account or send the contact request. It is evident in each input form what data are collected. We use the data that you disclose to us to perform the contract and process your enquiries according to art. 6 (1) 1 lit b GDPR. Upon completion of the contract or deletion of your customer account, any further processing of your data will be restricted, and your data will be deleted upon expiry of the retention period applicable under relevant regulations, unless you expressly consent to the further use of your data or we reserve the right to further use your personal data in the scope and manner permitted by law, of which we inform you in this notice. Your customer account can be deleted at any time. For this purpose you can send a message to the contact option specified below.
3. Transfer of data
the ordered goods according to art. 6 (1) 1 lit. b GDPR. Depending on the payment service provider you have selected during the ordering process, we disclose the payment details collected for order processing purposes to the bank commissioned to handle the payment and, as the case may be, to the payment service provider commissioned by us or to the selected payment service. Some of those data are collected by the selected payment service providers themselves if you open an account with them. In such a case, during the ordering process, you must register with your payment service provider using your access data. In this respect, the privacy notice of the relevant payment service provider applies.
Disclosure of data to a shipping provider
If, when or after placing your order, you have given your express consent to us doing so, we disclose your e-mail address to the selected shipping provider based on that consent according to art. 6 (1) 1 lit. a GDPR, in order to enable the shipping provider to contact you to advise you of the delivery or agree with you the delivery details.
You may revoke your consent at any time by sending a message to the contact option described below or by directly notifying the shipping provider at the contact address specified below. After you revoke your consent, we will delete the data disclosed for this purpose, unless you expressly consent to the further use of your data or we reserve the right to further use your personal data in the scope and manner permitted by the law, of which we inform you in this notice.
DHL Paket GmbH
Transfer of data to CloudFlare (Reverse Proxy)
In order to protect ourselves against attacks and harmful bots, and to improve our service, we have enlisted the services of CloudFlare Inc. (101 Townsend St, San Francisco, CA 94107 USA). To identify and ward off dangers and attacks, CloudFlare saves certain access data, which is usually deleted again after 4 hours, but no later than 3 days. Much of the data sent to and from our server is transferred via a CDN (content delivery network) provided by CloudFlare. CloudFlare is a member of the EU-US Privacy Shield. For more information, please visit Privacy Shield’s website or read the information provided by CloudFlare on their website:
EU-US Privacy Shield – https://www.privacyshield.gov/welcome
CloudFlare Privacy & Security Policy – https://www.cloudflare.com/security-policy/
5. Use of data for payment processing
In cases where we make deliveries before payment, e.g. in the case of a purchase on invoice, we will have to obtain information about your identity and creditworthiness using the services of specialised service providers (credit reference agencies) for the purpose of contract formation according to art. 22 (2) lit a GDPR. To this end, we will transfer your personal data needed for the credit assessment to the following company(ies):
arvato infoscore GmbH
76532 Baden-Baden Germany
Bebericher Str. 23
41063 Mönchengladbach Germany
In this process, we will apply appropriate measures to respect your rights, freedoms and legitimate interests. You can contact us via the contact option specified below to present your position and contest the decision.