PRIVACY POLICY BIRKENSTOCK WEBSHOP
Thank you for your interest in our webshop (www.birkenstock.com) (hereinafter referred to as "webshop" or "website").This Privacy Policy is intended to provide you with a clear overview of how we process your personal data.
1. WHO IS RESPONSIBLE FOR THE PROCESSING OF MY DATA AND WHO IS THE DATA PROTECTION OFFICER?
The controller for data processing within the meaning of Art. 4 No. 7 of the General Data Protection Regulation ("GDPR") is:
Birkenstock digital GmbH
Burg Ockenfels
53545 Linz am Rhein
You can contact our data protection officer at:
Birkenstock digital GmbH
Data Protection Officer
Burg Ockenfels
53545 Linz am Rhein
dpo@birkenstock.com
For general questions about data protection or data subject enquiries, please contact us via our online form.
Birkenstock digital GmbH
Burg Ockenfels
53545 Linz am Rhein
You can contact our data protection officer at:
Birkenstock digital GmbH
Data Protection Officer
Burg Ockenfels
53545 Linz am Rhein
dpo@birkenstock.com
For general questions about data protection or data subject enquiries, please contact us via our online form.
2. WHAT IS THE SUBJECT OF DATA PROTECTION?
Data protection law regulates the handling of personal data. Personal data is information relating to an identified or identifiable natural person (hereinafter "data").
3. WHAT CATEGORIES OF DATA DO WE PROCESS?
Through your use of our webshop, we process the following categories of data in particular:
Data you provide us: You provide us with data as part of your order, when contacting us (e.g. via contact form or e-mail) or when opening a customer account. The exact data you provide us can be seen in the respective input forms. For example, this may include the following data: your name, email address, telephone number, other contact details including your address or payment details.
You can see from the input form whether you are obliged to provide us with the relevant data. Further information can also be found under Section 5 of this Privacy Policy.
If you visit our website, we may also store access data in so-called log files. Access data includes:
If you place an order in our webshop, access data will also be stored in log files. Access data includes:
Information we collect from third parties: If you order from our webshop, we may also collect data about you from third parties, such as credit agencies and payment service providers.
Cookies: order to make visiting our website attractive and to enable the use of certain functions, we use so-called cookies or similar technologies on our website, including for advertising and analysis purposes. For more information, see Section 5 below as well as in our Cookie settings. You can change your cookie preferences there at any time.
Data you provide us: You provide us with data as part of your order, when contacting us (e.g. via contact form or e-mail) or when opening a customer account. The exact data you provide us can be seen in the respective input forms. For example, this may include the following data: your name, email address, telephone number, other contact details including your address or payment details.
You can see from the input form whether you are obliged to provide us with the relevant data. Further information can also be found under Section 5 of this Privacy Policy.
If you visit our website, we may also store access data in so-called log files. Access data includes:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Server Request Time
- IP address
If you place an order in our webshop, access data will also be stored in log files. Access data includes:
- Caching Information
- IP address, country of IP address, IP address blocking status
- Information about your device type
- Information about your device's request to our system
- Information about our system's response to your device
- Timestamp
- Security-related information of the firewall
- Unique identifier
Information we collect from third parties: If you order from our webshop, we may also collect data about you from third parties, such as credit agencies and payment service providers.
Cookies: order to make visiting our website attractive and to enable the use of certain functions, we use so-called cookies or similar technologies on our website, including for advertising and analysis purposes. For more information, see Section 5 below as well as in our Cookie settings. You can change your cookie preferences there at any time.
4. WHAT ARE THE LEGAL BASES FOR PROCESSING MY DATA?
As a so-called controller of your data, we need a legal basis to process your data lawfully (Art. 6 para. 1 GDPR). If:
- If you have given us your consent to process your data for one or more specific purposes, the legal basis is Art. 6 para. 1 sent. 1 let. a) GDPR;
- the processing is necessary for the performance of a contract to which you are a party or for the implementation of pre-contractual measures taken at your request, Art. 6 para. 1 sent. 1 let. b) GDPR;
- the processing is necessary for compliance with a legal obligation to which we are subject, Art. 6 para. 1 sent. 1 let. c) GDPR;
- the processing is necessary to safeguard our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms that require the protection of personal data prevail, the legal basis is Art. 6 para. 1 sent. 1 let. f) GDPR.
- data in connection with employment relationships, e.g. for job applications, recruitment, the implementation and termination of employment relationships, the legal basis for this is Art. 88 para. 1 GDPR in conjunction with § 26 para. 1 sent. 1 or 3 of the German Federal Data Protection Act (“BDSG”) or other applicable country-specific laws.
5. FOR WHAT PURPOSES WILL MY DATA BE PROCESSED?
Your data can be processed by us for the following purposes:
5.1. Contract-related processing purposes
Opening a customer account: To open a customer account, you must first register with us. As part of the registration process, we process certain data about you, such as: Your name, address or bank details. The data we collect can be seen from the respective input masks.
Performance of a contract: We process data that you provide to us when you place an order or when registering or maintaining your customer account. The data we collect can be seen from the respective input masks. We use the information you provide to fulfill our contractual obligations to you (e.g. to process and ship your order) and to process your requests.
Legal basis: Art. 6 para. 1 sent. 1 let. b) GDPR
In certain cases, we might be obliged to retain certain data (e.g. business correspondence and receipts) for a period of time required by law. This data may only be deleted – even in the case of a request for deletion – after the expiry of the statutory retention periods.
Legal basis: Art. 6 para. 1 sent. 1 let. c) GDPR in connection with, in particular, § 257 para. 4 German Commercial Code (“HGB”) or other applicable statutory retention obligations
5.2. Advertising purposes
In addition to processing your information to process your purchases on our online store, we may also use your information to communicate with you about your orders, specific products, or marketing campaigns, and to recommend products or services that may be of interest to you. This communication can be via email, SMS, WhatsApp or other messaging services. If you have consented to receive such communications from us, you can withdraw your consent to the use of your data for advertising purposes at any time, either in whole or for individual measures, with effect for the future. You can also object to advertising communications that you receive from us without your consent at any time with effect for the future. You can contact us at privacy@birkenstock.com or under the address stated in section 1 of this Privacy Policy.
Legal basis: Art. 6 para. 1 sent. 1 let. a) GDPR or Art. 6 para. 1 sent. 1 let. f) GDPR
5.3. Newsletter
If you subscribe to our newsletter, we will use the data you provide to send you our newsletter on a regular basis. The newsletter can be sent by e-mail, SMS, WhatsApp or other messaging services. By subscribing to the newsletter, you agree to the necessary data processing. You can revoke this consent at any time with effect for the future by contacting us at privacy@birkenstock.com, under the address set out in section 1 of this Privacy Policy, or click on the revocation link that can be found in each newsletter.
Legal basis: Art. 6 para. 1 sent. 1 let. a) GDPR
5.4. Credit Assessment
If you decide to purchase on account, we have a legitimate interest in being able to assess the associated economic risks before concluding the contract. If you have selected the payment method "purchase on account", we will therefore transmit your data (name, address and, if applicable, date of birth) to a financial service provider for the purpose of a credit assessment, to assess the risk of non-payment on the basis of mathematical-statistical methods using address data, and to verify your address (check for deliverability).
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.5. Fraud prevention
We have a legitimate interest in preventing fraud when our goods are ordered. Therefore, we carry out a fraud check on orders and transmit your order data to our designated service providers for this purpose. If an order is determined to be risky as a result of the review, your order may be cancelled.
If you make a purchase on account or pay via PayPal, we transmit your order data (name, address, gender, date of birth, shopping cart value, time of order, IP address, means of payment) to a service provider based in Germany for fraud prevention purposes.
If you select credit card as your payment method, we will transmit your order information to a service provider based in the United States. This service provider's fraud screening uses probability values that detect orders that pose a risk of fraud to us. Further information on how our service provider processes personal data can be obtained from us at any time under the contact details stated in section 1 of this Privacy Policy. If you do not agree to the transmission of data to this service provider, please use a different method of payment.
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.6. Payment Service Providers
Depending on the payment method you choose, our payment service providers collect information from you so that they can associate your order details with your payment and process the payment for you. We cannot view your payment-related information, such as credit card details.
Insofar as we transmit data to payment service providers for the purpose of making the payment, this is done to perform our contract with you.
Legal basis: Art. 6 para. 1 sent. 1 let. b) GDPR
5.7. Management of Claims
If there are outstanding claims from your orders, we will contact you by e-mail with a new payment request. If you do not comply with this request despite the existence of a justified claim, we can hand over the assertion of the claim to our debt collection service provider, to whom we will hand over your order and contact details for this purpose.
Legal basis: Art. 6 para. 1 sent. 1 let. b) GDPR
5.8. Cookies
We use cookies on our website. You can find more information about this and your setting options in our Cookie settings.
Legal basis: Art. 6 para. 1 sent. 1 let. a) GDPR or Art. 6 para. 1 sent. 1 let. f) GDPR
5.9. Log Files
If you visit our website, certain access data can be stored by us in so-called log files. This serves our legitimate interest in providing you a functioning website.
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.10. Live Chat
We use live chat software from Enterprise Bot GmbH, Soodmattenstr. 4, 8134 Adliswil, Switzerland. You can use the live chat like a contact form to chat with our staff in near real-time. When using the live chat, the following data in particular will be processed: your name, your e-mail address, if applicable. Your order number, your entries in the chat window (e.g. your shoe size), usage data (e.g. chat duration, number of interactions).
Depending on the course of the conversation with our employees, further data may be processed in the live chat, which is entered by you. The nature of this data depends on your request or the concern you are describing to us. The processing of this data serves to provide you with a quick and efficient contact option and, thus, to improve our customer service. As long as we do not transfer it to a contact person in the course of communication with our live chat, your data will remain pseudonymous, i.e., we will not personally assign it to you as a visitor of our website. As soon as a handover to a contact person of ours takes place, an individualization of the chat process is carried out in order to personally process your request. In order to continuously improve the functionality of the live chat and to enable statistical surveys, your data may be evaluated pseudonymously or anonymously. The history of the chats is temporarily saved. This serves the purpose of sparing you extensive explanations of the history of your request, as well as the constant quality control of our chat offer. The storage of chat data also serves the purpose of ensuring the security of our IT systems.
This is a legitimate interest of ours. You can find more information about live chat and data processing by Enterprise Bot here: https://get.enterprisebot.ai/legal/dpa
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.11. Customer Reviews
Depending on the region of the web shop, you may have the possibility to submit customer reviews of our products. Customer reviews help us better understand and improve our products, while also helping other customers choose products. We process the data of you that you enter when submitting the review. Reviews are published anonymously on our website, containing only the first name and the first letter of the customer's last name.
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.12. Product Safety
According to the EU General Product Safety Regulation ("GPSR"), we are obliged to maintain a register of complaints in which we document complaints and information received about accidents affecting the safety of our products. In it, we also document product recalls and any corrective actions. In this register of complaints, we only store your data that is necessary for the investigation and only for as long as it is necessary for the purpose of the investigation (maximum five years according to the GPSR).
In the event of a product safety recall or safety warning, we must also be able to contact you and notify you of this. For this purpose, we use the data you have provided to us in your customer account or in a contact form for product safety.
Legal basis: Art. 6 para. 1 sent. 1 let. c) GDPR in conjunction with Art. 9 para. 11 and 12, respectively Art. 35 para. 1 and 2 GPSR
5.13. Job Applications
We process your data when you apply for a job or a freelancer position (e.g., your name, address, data included in your cover letter or CV). The data is processed to decide if a contract with you will be concluded, or, if you already have a contract with us, to perform our obligations under the contract or terminate the contract.
If we have decided not to hire you or if your employment with us has ended, your data will be stored to enable us to defend ourselves against potential claims based on applicable laws regarding equal treatment.
Legal basis when you apply and during your employment: Art. 6 para. 1 sent. 1 let. b) GDPR as well as applicable country-specific legal bases, such as Art. 88 para. 1 GDPR in conjunction with § 26 para. 1 sent. 1 BDSG
Legal basis if we have decided to not hire you, or if your employment with us has ended: Art. 6 para. 1 sent. 1 let. f) GDPR
5.14. Data Subjet Requests
When you contact us to make use of your data subject rights, we process your name, email address and any additional information you provide us in your request, as well as personal data provided to verify your identity as legitimate data subject if needed.
The data provided in your request is processed for the purpose of responding to you, as well as ensuring our compliance with the GDPR by helping you as data subject exercise your rights as set out in the GDPR. This is also a legitimate interest of ours.
If we process additional data of yours to verify your identity, this is done to prevent cases of fraud, which is a legitimate interest of ours.
Legal basis for processing the data in your request is Art. 6 para. 1 sent. 1 let. c) in connection with Art. 12 GDPR, as well as Art. 6 para. 1 sent. 1 let. f) GDPR
Legal basis for verifying your identity: Art. 6 para. 1 sent. 1 let. f) GDPR
5.1. Contract-related processing purposes
Opening a customer account: To open a customer account, you must first register with us. As part of the registration process, we process certain data about you, such as: Your name, address or bank details. The data we collect can be seen from the respective input masks.
Performance of a contract: We process data that you provide to us when you place an order or when registering or maintaining your customer account. The data we collect can be seen from the respective input masks. We use the information you provide to fulfill our contractual obligations to you (e.g. to process and ship your order) and to process your requests.
Legal basis: Art. 6 para. 1 sent. 1 let. b) GDPR
In certain cases, we might be obliged to retain certain data (e.g. business correspondence and receipts) for a period of time required by law. This data may only be deleted – even in the case of a request for deletion – after the expiry of the statutory retention periods.
Legal basis: Art. 6 para. 1 sent. 1 let. c) GDPR in connection with, in particular, § 257 para. 4 German Commercial Code (“HGB”) or other applicable statutory retention obligations
5.2. Advertising purposes
In addition to processing your information to process your purchases on our online store, we may also use your information to communicate with you about your orders, specific products, or marketing campaigns, and to recommend products or services that may be of interest to you. This communication can be via email, SMS, WhatsApp or other messaging services. If you have consented to receive such communications from us, you can withdraw your consent to the use of your data for advertising purposes at any time, either in whole or for individual measures, with effect for the future. You can also object to advertising communications that you receive from us without your consent at any time with effect for the future. You can contact us at privacy@birkenstock.com or under the address stated in section 1 of this Privacy Policy.
Legal basis: Art. 6 para. 1 sent. 1 let. a) GDPR or Art. 6 para. 1 sent. 1 let. f) GDPR
5.3. Newsletter
If you subscribe to our newsletter, we will use the data you provide to send you our newsletter on a regular basis. The newsletter can be sent by e-mail, SMS, WhatsApp or other messaging services. By subscribing to the newsletter, you agree to the necessary data processing. You can revoke this consent at any time with effect for the future by contacting us at privacy@birkenstock.com, under the address set out in section 1 of this Privacy Policy, or click on the revocation link that can be found in each newsletter.
Legal basis: Art. 6 para. 1 sent. 1 let. a) GDPR
5.4. Credit Assessment
If you decide to purchase on account, we have a legitimate interest in being able to assess the associated economic risks before concluding the contract. If you have selected the payment method "purchase on account", we will therefore transmit your data (name, address and, if applicable, date of birth) to a financial service provider for the purpose of a credit assessment, to assess the risk of non-payment on the basis of mathematical-statistical methods using address data, and to verify your address (check for deliverability).
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.5. Fraud prevention
We have a legitimate interest in preventing fraud when our goods are ordered. Therefore, we carry out a fraud check on orders and transmit your order data to our designated service providers for this purpose. If an order is determined to be risky as a result of the review, your order may be cancelled.
If you make a purchase on account or pay via PayPal, we transmit your order data (name, address, gender, date of birth, shopping cart value, time of order, IP address, means of payment) to a service provider based in Germany for fraud prevention purposes.
If you select credit card as your payment method, we will transmit your order information to a service provider based in the United States. This service provider's fraud screening uses probability values that detect orders that pose a risk of fraud to us. Further information on how our service provider processes personal data can be obtained from us at any time under the contact details stated in section 1 of this Privacy Policy. If you do not agree to the transmission of data to this service provider, please use a different method of payment.
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.6. Payment Service Providers
Depending on the payment method you choose, our payment service providers collect information from you so that they can associate your order details with your payment and process the payment for you. We cannot view your payment-related information, such as credit card details.
Insofar as we transmit data to payment service providers for the purpose of making the payment, this is done to perform our contract with you.
Legal basis: Art. 6 para. 1 sent. 1 let. b) GDPR
5.7. Management of Claims
If there are outstanding claims from your orders, we will contact you by e-mail with a new payment request. If you do not comply with this request despite the existence of a justified claim, we can hand over the assertion of the claim to our debt collection service provider, to whom we will hand over your order and contact details for this purpose.
Legal basis: Art. 6 para. 1 sent. 1 let. b) GDPR
5.8. Cookies
We use cookies on our website. You can find more information about this and your setting options in our Cookie settings.
Legal basis: Art. 6 para. 1 sent. 1 let. a) GDPR or Art. 6 para. 1 sent. 1 let. f) GDPR
5.9. Log Files
If you visit our website, certain access data can be stored by us in so-called log files. This serves our legitimate interest in providing you a functioning website.
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.10. Live Chat
We use live chat software from Enterprise Bot GmbH, Soodmattenstr. 4, 8134 Adliswil, Switzerland. You can use the live chat like a contact form to chat with our staff in near real-time. When using the live chat, the following data in particular will be processed: your name, your e-mail address, if applicable. Your order number, your entries in the chat window (e.g. your shoe size), usage data (e.g. chat duration, number of interactions).
Depending on the course of the conversation with our employees, further data may be processed in the live chat, which is entered by you. The nature of this data depends on your request or the concern you are describing to us. The processing of this data serves to provide you with a quick and efficient contact option and, thus, to improve our customer service. As long as we do not transfer it to a contact person in the course of communication with our live chat, your data will remain pseudonymous, i.e., we will not personally assign it to you as a visitor of our website. As soon as a handover to a contact person of ours takes place, an individualization of the chat process is carried out in order to personally process your request. In order to continuously improve the functionality of the live chat and to enable statistical surveys, your data may be evaluated pseudonymously or anonymously. The history of the chats is temporarily saved. This serves the purpose of sparing you extensive explanations of the history of your request, as well as the constant quality control of our chat offer. The storage of chat data also serves the purpose of ensuring the security of our IT systems.
This is a legitimate interest of ours. You can find more information about live chat and data processing by Enterprise Bot here: https://get.enterprisebot.ai/legal/dpa
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.11. Customer Reviews
Depending on the region of the web shop, you may have the possibility to submit customer reviews of our products. Customer reviews help us better understand and improve our products, while also helping other customers choose products. We process the data of you that you enter when submitting the review. Reviews are published anonymously on our website, containing only the first name and the first letter of the customer's last name.
Legal basis: Art. 6 para. 1 sent. 1 let. f) GDPR
5.12. Product Safety
According to the EU General Product Safety Regulation ("GPSR"), we are obliged to maintain a register of complaints in which we document complaints and information received about accidents affecting the safety of our products. In it, we also document product recalls and any corrective actions. In this register of complaints, we only store your data that is necessary for the investigation and only for as long as it is necessary for the purpose of the investigation (maximum five years according to the GPSR).
In the event of a product safety recall or safety warning, we must also be able to contact you and notify you of this. For this purpose, we use the data you have provided to us in your customer account or in a contact form for product safety.
Legal basis: Art. 6 para. 1 sent. 1 let. c) GDPR in conjunction with Art. 9 para. 11 and 12, respectively Art. 35 para. 1 and 2 GPSR
5.13. Job Applications
We process your data when you apply for a job or a freelancer position (e.g., your name, address, data included in your cover letter or CV). The data is processed to decide if a contract with you will be concluded, or, if you already have a contract with us, to perform our obligations under the contract or terminate the contract.
If we have decided not to hire you or if your employment with us has ended, your data will be stored to enable us to defend ourselves against potential claims based on applicable laws regarding equal treatment.
Legal basis when you apply and during your employment: Art. 6 para. 1 sent. 1 let. b) GDPR as well as applicable country-specific legal bases, such as Art. 88 para. 1 GDPR in conjunction with § 26 para. 1 sent. 1 BDSG
Legal basis if we have decided to not hire you, or if your employment with us has ended: Art. 6 para. 1 sent. 1 let. f) GDPR
5.14. Data Subjet Requests
When you contact us to make use of your data subject rights, we process your name, email address and any additional information you provide us in your request, as well as personal data provided to verify your identity as legitimate data subject if needed.
The data provided in your request is processed for the purpose of responding to you, as well as ensuring our compliance with the GDPR by helping you as data subject exercise your rights as set out in the GDPR. This is also a legitimate interest of ours.
If we process additional data of yours to verify your identity, this is done to prevent cases of fraud, which is a legitimate interest of ours.
Legal basis for processing the data in your request is Art. 6 para. 1 sent. 1 let. c) in connection with Art. 12 GDPR, as well as Art. 6 para. 1 sent. 1 let. f) GDPR
Legal basis for verifying your identity: Art. 6 para. 1 sent. 1 let. f) GDPR
6. WHO CAN MY DATA BE SHARED WITH?
We transmit your data to the following bodies for the purposes mentioned in each case:
6.1. Contract-related processing purposes and general administration
When you open a customer account, your data will be stored in our customer database, which is hosted by salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany.
As part of the fulfilment of your order and for the purpose of parcel delivery, we pass on your data to shipping or transport companies commissioned with the delivery, insofar as this is necessary for the delivery of your ordered goods.
If you contact us, your data may be processed by us by using office and customer management software solutions that we use for our daily work, in particular software from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
6.2. Newsletters, personal product recommendations and surveys
Services of salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany, are used for the technical processing of the newsletter dispatch, personal product recommendations, as well as personalized messages by e-mail based on user behavior.
We use the services of SaaS.group Zenloop GmbH, Attillastsraße 18, 12529 Schönefeld, Germany, to conduct customer satisfaction surveys to obtain customer feedback, e.g. on the visibility of our brand and products.
6.3. Credit Assessment
If you have selected the payment method "purchase on account", and where applicable, we will transmit your data (name, address and, if applicable, date of birth) to the financial service provider Creditreform Koblenz Brodmerkel KG, Rizzastr. 49, 56068 Koblenz, Germany, for the purpose of a credit assessment, for assessing the risk of non-payment on the basis of mathematical-statistical procedures using address data, and for verifying your address (check for deliverability).
6.4. Fraud Prevention
To prevent fraud, we transmit your order data to our designated service providers. If an order is determined to be risky as a result of the review, your order may be cancelled.
If you make a purchase on account or pay via PayPal, we transmit your order data (name, address, gender, date of birth, shopping cart value, time of order, IP address, means of payment) to a service provider based in Germany for fraud prevention purposes. If you select credit card as your payment method, we will transmit your order information to a service provider based in the United States.
6.5. Payment Service Providers
Depending on the available payment method you choose, our payment service providers collect information from you so that they can associate your order details with your payment and process the payment for you.
6.6. Claim Management
If there are outstanding claims from your orders, we will contact you by e-mail with a new request for payment. If you do not comply with this request despite the existence of a justified claim, we can hand over the assertion of the claim to our debt collection service provider, to whom we will hand over your order and contact details for this purpose.
6.7. Cookies
We use cookies on our website. Some of these cookies are provided by third parties whose services we use (e.g., maps for locating stores, or marketing analytics). When using such a service, the provider may also be the recipient of the information collected through a cookie. You can find more information about your setting options in our Cookie settings.
6.8. Log files
When log files are stored upon visiting our website, this is done by service providers whose services we use for the provision of our website. These are Akamai Technologies, Waterpark Place, 88 Queens Quay W, Toronto, ON M5J 0B8, Canada and salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany.
6.9. Live Chat
We use live chat software from Enterprise Bot GmbH, Soodmattenstr. 4, 8134 Adliswil, Switzerland.
6.10. Customer Reviews
To offer the possibility of writing customer reviews of our products, we use the services of Yotpo Ltd., 35 HaMasger St, Tel Aviv, Israel, that processes your data in such case. Reviews are published anonymously on our website, containing only the first name and the first letter of the customer's last name.
6.1. Contract-related processing purposes and general administration
When you open a customer account, your data will be stored in our customer database, which is hosted by salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany.
As part of the fulfilment of your order and for the purpose of parcel delivery, we pass on your data to shipping or transport companies commissioned with the delivery, insofar as this is necessary for the delivery of your ordered goods.
If you contact us, your data may be processed by us by using office and customer management software solutions that we use for our daily work, in particular software from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
6.2. Newsletters, personal product recommendations and surveys
Services of salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany, are used for the technical processing of the newsletter dispatch, personal product recommendations, as well as personalized messages by e-mail based on user behavior.
We use the services of SaaS.group Zenloop GmbH, Attillastsraße 18, 12529 Schönefeld, Germany, to conduct customer satisfaction surveys to obtain customer feedback, e.g. on the visibility of our brand and products.
6.3. Credit Assessment
If you have selected the payment method "purchase on account", and where applicable, we will transmit your data (name, address and, if applicable, date of birth) to the financial service provider Creditreform Koblenz Brodmerkel KG, Rizzastr. 49, 56068 Koblenz, Germany, for the purpose of a credit assessment, for assessing the risk of non-payment on the basis of mathematical-statistical procedures using address data, and for verifying your address (check for deliverability).
6.4. Fraud Prevention
To prevent fraud, we transmit your order data to our designated service providers. If an order is determined to be risky as a result of the review, your order may be cancelled.
If you make a purchase on account or pay via PayPal, we transmit your order data (name, address, gender, date of birth, shopping cart value, time of order, IP address, means of payment) to a service provider based in Germany for fraud prevention purposes. If you select credit card as your payment method, we will transmit your order information to a service provider based in the United States.
6.5. Payment Service Providers
Depending on the available payment method you choose, our payment service providers collect information from you so that they can associate your order details with your payment and process the payment for you.
Payment | Payment method | Data protection information of the providers |
---|---|---|
Adyen N.V., Simon Carmiggelstraat 6-50, 1011 DJ Amsterdam, Netherlands | Credit card (Visa, MasterCard, American Express, Diners Club) | https://www.adyen.com/policies-and-disclaimer/privacy-policy |
Apple Inc., 1 Infinite Loop Cupertino, California, United States of America | ApplePay | https://support.apple.com/en-us/HT203027 |
Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden | Paynow (instant bank transfer), Paylater (purchase on account) | https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy |
PayPal (Europe), S.à.r.l. et Cie, S.C.A, 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg | PayPal, PayPal Express | https://www.paypal.com/de/webapps/mpp/ua/privacy-full |
6.6. Claim Management
If there are outstanding claims from your orders, we will contact you by e-mail with a new request for payment. If you do not comply with this request despite the existence of a justified claim, we can hand over the assertion of the claim to our debt collection service provider, to whom we will hand over your order and contact details for this purpose.
6.7. Cookies
We use cookies on our website. Some of these cookies are provided by third parties whose services we use (e.g., maps for locating stores, or marketing analytics). When using such a service, the provider may also be the recipient of the information collected through a cookie. You can find more information about your setting options in our Cookie settings.
6.8. Log files
When log files are stored upon visiting our website, this is done by service providers whose services we use for the provision of our website. These are Akamai Technologies, Waterpark Place, 88 Queens Quay W, Toronto, ON M5J 0B8, Canada and salesforce.com Germany GmbH, Erika-Mann-Str. 31, 80636 München, Germany.
6.9. Live Chat
We use live chat software from Enterprise Bot GmbH, Soodmattenstr. 4, 8134 Adliswil, Switzerland.
6.10. Customer Reviews
To offer the possibility of writing customer reviews of our products, we use the services of Yotpo Ltd., 35 HaMasger St, Tel Aviv, Israel, that processes your data in such case. Reviews are published anonymously on our website, containing only the first name and the first letter of the customer's last name.
7. WILL MY DATA BE TRANSFERRED TO A THIRD COUNTRY?
Some of our service providers and group companies that might receive information of yours from us are based outside the European Union (EU). These countries may not have a level of data protection comparable to the GDPR. If a recipient of your data is based outside the EU, there are basically two possibilities to ensure that an adequate level of protection for your data is also provided outside the EU:
- If a recipient is located in a country for which the European Commission has determined an adequate level of data protection, we rely on this adequacy decision of the EU Commission. The EU Commission offers an overview of the countries for which adequacy decisions have been issued, which you can access here.
- If a recipient is not located in a country that the EU Commission has deemed to provide an adequate level of data protection, we will either enter into a contract with that recipient in which we agree on rules to ensure that the recipient adequately protects your personal data (EU Standard Contractual Clauses developed by the EU Commission), or we will rely on binding corporate rules of a group of companies or a company, approved by a supervisory authority. You can request further information by contacting us under the contact details provided in Section 1 of this Privacy Policy.
8. HOW LONG WILL MY DATA BE STORED?
Your data will be stored in accordance with Art. 5 para. 1 let. e) GDPR for as long as we are legally obliged to do so or as long as we use your data for the purposes stated in Section 5. Subsequently, the processing of your data will be restricted or your data will be deleted.
If you need more information regarding our retention periods, feel free to contact us anytime at the address stated in Section 1 of this Privacy Policy.
If you need more information regarding our retention periods, feel free to contact us anytime at the address stated in Section 1 of this Privacy Policy.
9. WHAT DATA PROTECTION RIGHTS DO I HAVE AS A DATA SUBJECT?
When we process your data, you have the following rights under the GDPR:
- Right to information: You have the right to receive information about the processing of your personal data by us (Art. 13 and 14 GDPR).
- Right of access: You have the right to obtain confirmation as to whether or not we are processing your personal data and, where that is the case, to obtain access to the personal data (Art. 15 GDPR).
- Right to rectification: You have the right to request the rectification of inaccurate or incomplete personal data concerning you (Art. 16 GDPR).
- Right to erasure ("right to be forgotten"): Under certain circumstances, you have the right to request the erasure of personal data concerning you (Art. 17 GDPR).
- Right to restriction: Under certain circumstances, you have the right to request the restriction of processing (Art. 18 GDPR).
- Right to data portability: Under certain conditions, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and the right to transmit this data to another controller or to have them transmitted to us (Art. 20 GDPR).
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR (Art. 77 GDPR).
- Right to withdraw consent: If the processing of your personal data is based on your consent (Art. 6 para. 1 sent. 1 let. a) GDPR or Art. 9 para. 2 let. a) GDPR), you have the right to withdraw your consent at any time (Art. 7 para. 3 GDPR). The revocation has no effect on the legality of the data processing carried out until the revocation.
- Right against a decision based on automated processing: You have the right not to be subject to a decision based solely on automated processing - including profiling - which produces legal effects concerning you or similarly significantly affects you (Art. 22 para. 1 GDPR).
Right to object: Under certain circumstances, you have the right to object to the processing of personal data concerning you (Art. 21 GDPR). You have this right to object in particular in cases in which we process your personal data on the legal basis of Art. 6 para. 1 set. 1 let. f) GDPR.
10. ARE THERE AUTOMATED INDIVIDUAL DECISIONS OR MEASURES FOR PROFILING?
We do not use automated processing of data (Art. 22 GDPR) to make decisions concerning you – including profiling – that have legal effects on you or similarly significantly impair you.
Date of update: 17.02.2025
Version: 1.4