Privacy Policy Birkenstock Web Shop

Thank you for your interest in our web shop. The protection of your privacy is very important to us. Below please find detailed information on how your data will be handled.

This Privacy Policy is designed to give you a clear overview of how we handle personal data.

  1. Who is the controller of my data and who is the data protection officer?
  2. Which categories of data are we processing and where do they come from?
  3. On what legal basis will my data be processed?
  4. For which purposes will we process your data?
  5. With whom will my data be shared?
  6. Will my data be transferred to a third country?
  7. How long will my data be stored?
  8. Which data protection rights may I assert as data subject?
  9. The data protection supervisory authority responsible for us
  10. How are my data protected?
  11. Relevant legal texts





1. WHO IS THE CONTROLLER OF MY DATA AND WHO IS THE DATA PROTECTION OFFICER?

The Controller within the meaning of Art. 4(7) General Data Protection Regulation (GDPR) is:
Birkenstock digital GmbH,
BIRKENSTOCK Campus,
53577 Neustadt (Wied), Germany
https://birkenstock-privacy.bytemine.net/enquiry/

Please find here the contact details of our data protection officer:
BIRKENSTOCK GmbH & Co. KG Services
Data Protection Officer
BIRKENSTOCK Campus
53577 Neustadt/Wied, Germany
https://birkenstock-privacy.bytemine.net/enquiry/





2. WHICH CATEGORIES OF DATA ARE WE PROCESSING AND WHERE DO THEY COME FROM?

Personal data are information referring to an identified or identifiable natural person (hereinafter referred to as “Data”). By using our web shop, we process the following categories of data in particular:

Data that you make available to us: When you place an order, contact us (e.g., via contact form or email) or when you open a customer account, you provide us with data. The exact data that you provide are shown in the respective data entry forms. For example, the following data may be included: Your name, email address, telephone number, your other contact information including your address or account number.

The relevant data entry form will tell you whether you are contractually or legally obligated to provide us with the relevant data or what consequences it may have if you do not provide us with the data.

Data we collect about you: We may also collect information about you from third parties, for example as part of a credit check, if you wish to pay on account. If you visit our website, we may also store access data in server log files.

Cookies: In order to make your visit to our website efficient and to enable the use of certain functions, we use cookies on various pages, including to create user profiles by using pseudonyms. For more information about the categories of personal data we collect, please see our Cookie Policy.

You can change your cookie preferences here at any time

Special categories of personal data: We do not collect and process any special categories of personal data.1





3. ON WHAT LEGAL BASIS WILL MY DATA BE PROCESSED?

We process your data only in accordance with the relevant statutory provisions and only if permissible by an applicable legal regulation (in particular from the GDPR). Should we wish to process your data for purposes other than those originally collected, we will ensure that we have a sufficient legal basis to do so. In particular, we will base processing of your data on the following legal basis. Please note that these examples are only intended to make the legal basis more transparent and are not an exhaustive list.

Consent (Art. 6(1)(a), Art. 7 GDPR): We will only process certain data if you have given us your express and voluntary consent in advance. You have the right to revoke your consent at any time with effect for the future.

Performance of a contract / precontractual measures (Art. 6(1)(b) GDPR): In the course of the performance or initiation of your sales contract or any other contract with us, we must process certain data.

Compliance with a legal obligation (Art. 6(1)(c) GDPR): We need to process some of your data in order to comply with legal obligations to which we are subject.

Protection of legitimate interests (Art. 6(1)(f) GDPR): We also process some of your data to protect our legitimate interests or the legitimate interests of third parties, unless your interests are overriding in individual cases.





4. FOR WHICH PURPOSES WILL WE PROCESS YOUR DATA?

Among other things, we will process your data for the following purposes:

Contract-related processing purposes

Opening of a customer account: To open a customer account, you must first register with us. In the course of registration, we process certain of your data, such as your name, your address, or your bank account details. The respective data entry forms will show which data we collect.

Data collection and use for contract performance: We collect and process personal data voluntarily provided to us when placing your order or registering or maintaining your customer account. The respective data entry forms will show which data we collect. We use the data provided by you to meet our contractual obligations towards you and to process your inquiries.

Data processing on the basis of consents

Use of your data for advertising purposes:
In addition to processing your data to process your purchases in our web shop, we may also use your data to communicate with you about your orders, certain products or marketing campaigns and to recommend products or services that might be of interest to you. You may revoke your consent to the use of your personal data for advertising purposes at any time in whole or for individual measures with effect for the future. You may contact us at privacy@birkenstock.com or at the address shown in Section 1 of this Privacy Policy.

Newsletter:
If you register to receive our newsletter, we will use the data required or separately communicated by you to send you our email newsletter on a regular basis. For this purpose, we are working with a partner (see Section 6 of this Privacy Policy below for more information about our collaboration). By registering for the newsletter, you agree to the necessary data processing. You may also revoke this consent at any time with effect for the future by contacting us at privacy@birkenstock.com, or at the address shown in Section 1 of this Privacy Policy, or by clicking on the objection link attached to each newsletter.

Use of Google Analytics for web analysis purposes
This website uses Google Analytics, a web analysis service of Google Inc. (www.google.de). Google Analytics uses cookies ‒ text files that are stored on your computer and that enable an analysis of your use of the website. The information about your use of this website, which is generated by the cookie, is usually sent to a Google server in the USA and stored there. If IP anonymisation is activated on this website, Google will first abbreviate your IP address in Member States of the European Union or other Contracting States to the Agreement on the European Economic Area. The full IP address will only be transmitted to and abbreviated on a Google server in the USA in exceptional cases. IP anonymisation is active on this website. By order of the operator of this website, Google will use this information to analyse your use of the website, to compile reports about the website activities and to perform other services related to the use of the website and of the Internet in general for the website operator. The IP addresses sent by your browser within the scope of Google Analytics will not be associated with other data of Google. You can prevent the storage of cookies by configuring your browser software accordingly; in this case, however, you may not be able to use all functions of this website.

Moreover, you can prevent the collection of data concerning your use of the website (including your IP address), which are generated by the cookie, and the processing of these data by Google by downloading and installing the browser plugin that is available under this link.

Use of AddThis for advertising analysis purposes
On this website, data are collected and stored by AddThis, 8000 Westpark Dr. Suite 625, McLean, VA 22102, USA. From these data, usage profiles are created using pseudonyms. These usage profiles are used to analyse visitor behaviour and are used to improve our website, goods and services. Cookies may be used for this purpose. Cookies are little text files that are stored locally on your computer and that enable the recognition the next time our website is visited. Without your separate express consent, the pseudonymised usage profile will not be associated with personal data of the bearer of the pseudonym. Here you can object to the collection and storage of data for web analysis purposes at any time with effect for the future.

Use of Webtrekk for marketing and optimisation purposes
On this website, technologies of Webtrekk GmbH www.webtrekk.com are used to collect and store data for marketing and optimisation purposes. From these data, usage profiles may be created under a pseudonym. Cookies may be used for this purpose. Cookies are little text files that are stored in the cache of the site visitor's Internet browser. The cookies enable the recognition of the Internet browser.

Without the express consent of the subject, the data collected with Webtrekk technologies will not be used for personally identifying the visitor to this Web site and will not be associated with the personal data via the pseudonym. The data collection and storage may be objected to here at any time with effect for the future.

USE OF PLUGINS AND REMARKETING FUNCTIONS

In addition, our web shop contains various plugins and remarketing functions of individual providers. Processing of your data in connection with the use of these plugins and remarketing functions is the sole responsibility of the respective providers. Our web shop contains the following plugins and remarketing functions:

Facebook Social Plugins:
Our website uses social plugins (“Plugins”) of the social network Facebook, which is operated by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). The plugins are marked with a Facebook logo or the addition “Facebook Social Plug-in” or “Facebook Social Plugin.” An overview of the Facebook plugins and their appearance can be found here.

When you access a page of our website that contains such a plugin, your browser will establish a direct connection to Facebook servers. The content of the plugin is transmitted directly from Facebook to your browser and integrated into the page. By means of this integration, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged in to Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there. If you are logged in to Facebook, Facebook is able to associate your visit to our website with your Facebook profile.

If you interact with the plugins, for example by clicking the “Like” button or leaving a comment, this information is also transmitted directly to a Facebook server and stored there. The information will also be published on your Facebook profile and displayed to your Facebook friends. The purpose and scope of data collection and the processing and use of the data by Facebook as well as your rights and settings options to protect your privacy can be found in the Facebook Data Policy.

Facebook Remarketing: In part, we use the remarketing function of Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”) on our website. This feature enables us to target visitors to our site with advertising by delivering personalized, interest-based Facebook ads to them when they visit the Facebook social network.

For this purpose, remarketing tags from Facebook are integrated on our website. Your browser uses these tags to establish a direct connection to the Facebook servers when you visit the website. This provides Facebook with the information which of our web pages you have visited. Facebook is able to associate this information with your personal Facebook profile. This information allows for the display of personalized, interest-based Facebook advertisements.

You have the opportunity to object to the aforementioned data processing by our web shop here.

The purpose and scope of data collection and the processing and use of the data by Facebook as well as your rights and settings options to protect your privacy can be found in the Facebook Data Policy. If you do not want Facebook to associate the collected information directly with your Facebook profile, you may disable the feature here. You must be logged in to Facebook to do so.

Rocket Fuel remarketing function:
We also use the services of Rocket Fuel Inc., San Francisco, USA (www.rocketfuel.com) to collect statistical data about website use and to optimize our offering accordingly. For more information on the use and processing of the data, please see the Privacy Policy of Rocket Fuel Inc. at rocketfuel.com/privacy/.

You may also object to this data collection and storage at any time with effect for the future on the following page in the "Opt Out" section: rocketfuel.com/opt-out/.

Twitter Plugins:
Our website uses social plugins (“Plugins”) of the microblogging service Twitter, which is operated by Twitter Inc, 1355 Market St, Suite 900, San Francisco, CA 94103, USA (“Twitter”). The plugins are marked with a Twitter logo, for example in the form of a blue “Twitter bird.” An overview of the functions of the Twitter plugins and their appearance can be found at https://twitter.com/about/resources/buttons.

When you access a page of our website that contains such a plugin, your browser will establish a direct connection to Twitter's servers. The content of the plugin is transmitted directly from Twitter to your browser and integrated into the page. The integration provides Twitter with the information that your browser has accessed the corresponding page of our website, even if you do not have a Twitter profile or are not currently logged in to Twitter. This information (including your IP address) is transmitted directly from your browser to a Twitter server in the USA and stored there.

If you are logged in to Twitter, Twitter is able to associate your visit to our website with your Twitter account. If you interact with the plugins, for example by clicking the “Twitter” button, the corresponding information is also transmitted directly to a Twitter server and stored there. The information will also be published on your Twitter account and displayed to your contacts.

The purpose and scope of data collection and the processing and use of the data by Twitter and your rights and settings options to protect your privacy can be found in the Twitter Privacy Policy at https://twitter.com/privacy. If you do not want Twitter to associate the data collected via our website directly with your Twitter account, you must log out of Twitter before visiting our website. You may also entirely prevent the Twitter plugins from loading with add-ons for your browser, e.g., with the "NoScript" script blocker (http://noscript.net/).

Pinterest:
The “Pin it” button plugin from Pinterest (Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA) is also used on this website. When you visit this website, the plugin establishes a direct connection between your browser and the Pinterest server. Pinterest may obtain the information that you have visited this website using your IP address. If you click the “Pin it” button while logged in to Pinterest with your Pinterest account, you may share content on this website with the Pinterest network. This allows Pinterest to associate the visit of these pages with your user account. We would like to point out that, as the provider of the web pages, we have no knowledge of the content of the data transmitted or of their use by Pinterest. The Pinterest Privacy policy is available at https://policy.pinterest.com/en/privacy-policy/.

You may change the settings for saving your data by Pinterest under the following link even if you do not have your own Pinterest account: https://help.pinterest.com/en/articles/personalization-and-data.

Personal product recommendations by email: As a customer of our web shop, we will use your personal data at irregular intervals to improve your personal shopping experience and our service, in order to email you interesting offers irrespective of your subscription to the newsletter. This serves to draw your attention to items from our range of products that are of special interest to you and that might interest you on the basis of products that you have purchased from us in the past. If you no longer wish to receive personal product recommendations, you may revoke the declaration of consent to use your personal data for personal product recommendations at any time with effect for the future. To do so, you may contact us at privacy@birkenstock.com, or at the address shown in Section 1 of this Privacy Policy, or by clicking on the appropriate link in any email with product recommendations.

Data processing for compliance with legal obligations

We are subject to certain legal obligations when operating the web shop. This includes, among others, the obligation to ensure the security of your data when using the web shop. For this purpose, we may process your data as part of measures to ensure data security.

Data processing on the basis of legitimate interests

Storage of access data in server log files: When you visit our web shop, we may store access data in server log files, such as the name of the requested file, date and time of access, the transferred data volume, and the requesting provider. We use these data exclusively to ensure an efficient operation of the site and to improve our offering.





5. WITH WHOM WILL MY DATA BE SHARED?

We will always take appropriate steps to ensure that your data will be processed, protected, and transmitted in accordance with the applicable legal requirements. In addition, we may transfer further data to third parties as part of the use of cookies and tracking functions on our website. For more information, please consult our Cookie Policy.

In particular, we transmit your data to the following parties for the purposes stated below:

Shipping
Within the scope of contract performance, we transfer your data to the shipping company entrusted with shipping, to the extent necessary for the delivery of the products you ordered.

Credit assessment
We transmit your data (name, address and, if applicable, date of birth) to infoscore Consumer Data GmbH, Rheinstr. 99, 76532 Baden-Baden, Germany for the purpose of credit assessment, obtaining information for assessing the risk of non-payment on the basis of mathematical-statistical procedures using address data and for verifying your address (check for deliverability). The legal basis for these transfers is Article 6(1)(b) and Article 6(1)(f) GDPR. Transmission on the basis of these provisions may only take place where necessary to safeguard the legitimate interests of our company or of third parties and if it does not outweigh the interests of the fundamental rights and freedoms of the data subject requiring the protection of personal data. Detailed information on ICD within the meaning of Article 14 General Data Protection Regulation (“GDPR”), i.e., information on the business purpose, data storage purposes, data recipients, the right to self-disclosure, the right to erasure or rectification etc. can be found in the Annex or under the following link.

Newsletter and personal product recommendations
Our London-based partner company,
     salesforce.com EMEA Limited, Floor 26 Salesforce Tower, 110 Bishopsgate, London, EC2N 4AY, United Kingdom,
is responsible for the technical handling of sending the newsletter and the personal product recommendations by email. Our partner processes your data exclusively according to our instructions. We have contractually ensured that our partner complies with all data protection regulations. The scope of the transmitted data is limited to the required minimum.





6. WILL MY DATA BE TRANSFERRED TO A THIRD COUNTRY?

If we transfer personal data to service providers and affiliated companies outside the European Economic Area (EEA), the transfer will only take place if the EU Commission has confirmed an adequate level of data protection to the third country (Art. 45(1) GDPR) or if other appropriate data protection guarantees within the meaning of Art. 47 GDPR exist (e.g., binding corporate rules in accordance with Art. 46(2)(b), Art. 47 GDPR, standard data protection clauses issued by the EU Commission in accordance with Art. 46(2)(c)). For more information, please see the contact details provided in Section 1 of this Privacy Policy.





7. HOW LONG WILL MY DATA BE STORED?

In accordance with Art. 17 GDPR, your data will be stored for as long as we are legally obligated to do so or as long as we need your data for the purposes stated under Section 4. Your data will then be deleted in order to comply with the principle of data minimization.

For example, after complete performance of the contract or erasure of your customer account, your data will be blocked for further use and erased after the expiry of statutory retention periods, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this scope, which is permitted by law and about which we will notify you. Deletion of your customer account is possible at any time either via a message to our Customer Service department or via a function provided in the customer account.





8. WHICH DATA PROTECTION RIGHTS MAY I ASSERT AS DATA SUBJECT?

You may assert a number of different rights to which data subjects are entitled. To do so, please contact us using the contact details given in Section 1 of this Privacy Policy.

Right of access
You may request information about the personal data stored about you (Art. 15 GDPR). This information includes the categories of data processed by us, the purposes of the processing, the origin of the data where we have not collected them directly from you, and, if applicable, the recipients to whom we have transmitted your data. You may receive from us a free copy of your data, which are the subject matter of the agreement. If you are interested in further copies, we reserve the right to invoice you for any additional copies.

Right to rectification and erasure
You may request the rectification of inaccurate personal data and the completion of incomplete personal data concerning you. (Art. 16 GDPR). In addition, you may also request the erasure of your data under the conditions of Art. 17 GDPR. This may be the case, for example, if

  • the data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • you withdraw consent on which the processing is based and where there is no other legal ground for the processing;
  • you object to the processing of your data and there are no overriding legitimate grounds for the processing or you object to the processing of your data for direct marketing purposes;
  • the data have been unlawfully processed

unless processing is necessary,

  • to ensure compliance with a legal obligation that requires us to process your data;
  • especially with regard to legal retention periods;
  • to assert, exercise, or defend legal claims.

Right to restriction of processing
You may also have the right to restrict the processing of your data, i.e., to mark the stored personal data with the aim of restricting their future processing. For this purpose, one of the conditions specified in Art. 18 GDPR must be met, i.e.,

  • you contest the accuracy of the data for a period enabling us to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of your personal data and request the restriction of their use;
  • we no longer need your personal data, but they are required by you for the establishment, exercise, or defense of legal claims;
  • you have objected to processing pending the verification whether our legitimate grounds override yours.

Right to data portability
Finally, you may also have a right to receive the personal data concerning you, which you have provided to us in a structured, commonly used, and machine-readable format. You may transfer these data to another controller without hindrance. You may also request that we transmit your data directly to another controller, where technically feasible (Art. 20 GDPR).

Right to object
You may object to processing of your personal data at any time on grounds relating to your particular situation, provided that the data processing is based on your consent or on our legitimate interests or those of a third party. In this case, we will no longer process your data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise, or defense of legal claims s. If we process your data for direct marketing purposes, you may object to the processing at any time (Art. 21 GDPR). Your right to revoke your consent to the processing remains freely revocable at any time, regardless of your right of objection.

Right of lodging a complaint with a data protection authority
We are committed to working with you to achieve a fair resolution to any privacy concerns.

You have the right of lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data by us is in breach of applicable data protection law.





9. The data protection supervisory authority responsible for us is:

BAVARIAN DATA PROTECTION AUTHORITY, GERMANY.





10. HOW ARE MY DATA PROTECTED?

We have taken appropriate technical and organizational security measures to ensure the protection of your data. We have developed an internal security concept for this purpose.





11. RELEVANT LEGAL TEXTS

The provisions of the GDPR are available at:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679


Last update: 25.05.2018

Changes to this Privacy Policy:
We regularly review this Privacy Policy and may occasionally update it to keep it up-to-date.



1 In accordance with Art. 9(1) GDPR, special categories of personal data are data revealing your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.