Privacy
Data Protection
Personal data (hereinafter mostly referred to as "data") is processed by us only to the extent necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered there.
According to Article 4(1) of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as "GDPR"), "processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
With the following privacy policy, we inform you in particular about the type, scope, purpose, duration and legal basis of the processing of personal data, insofar as we decide either alone or together with others on the purposes and means of processing. In addition, we inform you below about the third-party components we use for optimization purposes and to increase the quality of use, insofar as third parties process data on their own responsibility.
Information about us as the controller
The responsible provider of this website in terms of data protection law is
Schagerl Music GmbH Hörsdorf 7 | 3240 Mank | AUSTRIA
+43 2755 2302 -0
musicstore@schagerl.com
Schagerl Music GmbH Hörsdorf 7 | 3240 Mank | AUSTRIA
+43 2755 2302 -0
musicstore@schagerl.com
Your data stored online or at our location in Mank will be used by SCHAGERL Music GmbH for the following purposes:
1) Order processing
- To process the orders placed by you in the area of goods delivery and repair (name including title, your e-mail address, your address, any different delivery or collection address, your payment data, if applicable the customer number for our bonus points program)
- To create a customer account that you can log into with your e-mail address and password
- For unambiguous identification (date of birth, if provided)
- For the purpose of customer management (digital recording of analog reported customer data)
- For the processing of warranty claims 2) Communication with customers:
- To contact you for the purpose of responding to your inquiries (your name including title, your e-mail address, your address, your telephone number)
- To respond to repair requests (your name including title, address, e-mail address, telephone number)
- To process instrument registration (your name including title, your e-mail address, your address, your telephone number)
- If you subscribe to a newsletter, we will use your e-mail address for our own advertising purposes until you unsubscribe
- To contact you in the context of customer satisfaction surveys (telephone number, e-mail address)
- To process the orders placed by you in the area of goods delivery and repair (name including title, your e-mail address, your address, any different delivery or collection address, your payment data, if applicable the customer number for our bonus points program)
- To create a customer account that you can log into with your e-mail address and password
- For unambiguous identification (date of birth, if provided)
- For the purpose of customer management (digital recording of analog reported customer data)
- For the processing of warranty claims 2) Communication with customers:
- To contact you for the purpose of responding to your inquiries (your name including title, your e-mail address, your address, your telephone number)
- To respond to repair requests (your name including title, address, e-mail address, telephone number)
- To process instrument registration (your name including title, your e-mail address, your address, your telephone number)
- If you subscribe to a newsletter, we will use your e-mail address for our own advertising purposes until you unsubscribe
- To contact you in the context of customer satisfaction surveys (telephone number, e-mail address)
3) Other purposes:
- To contact you when participating in any competitions
- To contact you when participating in any competitions
Rights of users and data subjects
With regard to the data processing described in more detail below, users and data subjects have the right
- to confirmation as to whether data concerning them is being processed, to information about the processed data, to further information about the data processing and
- to copies of the data (see also Art. 15 GDPR); to rectification or completion of incorrect or incomplete data (see also Art. 16 GDPR);
- to the immediate erasure of the data concerning them (see also Art. 17 GDPR) or, alternatively, if further processing is required in accordance with Art. 17 para. 3 GDPR, to the restriction of processing in accordance with Art. 18 GDPR;
- to receive the data concerning them and provided by them and to transmit this data to other providers/controllers (cf. also Art. 20 GDPR)
- to lodge a complaint with the supervisory authority if they are of the opinion that the data concerning them is being processed by the provider in breach of data protection regulations (see also Art. 77 GDPR).
- to confirmation as to whether data concerning them is being processed, to information about the processed data, to further information about the data processing and
- to copies of the data (see also Art. 15 GDPR); to rectification or completion of incorrect or incomplete data (see also Art. 16 GDPR);
- to the immediate erasure of the data concerning them (see also Art. 17 GDPR) or, alternatively, if further processing is required in accordance with Art. 17 para. 3 GDPR, to the restriction of processing in accordance with Art. 18 GDPR;
- to receive the data concerning them and provided by them and to transmit this data to other providers/controllers (cf. also Art. 20 GDPR)
- to lodge a complaint with the supervisory authority if they are of the opinion that the data concerning them is being processed by the provider in breach of data protection regulations (see also Art. 77 GDPR).
In addition, the provider is obliged to inform all recipients to whom data has been disclosed by the provider of any rectification or erasure of data or restriction of processing carried out on the basis of Articles 16, 17 (1), 18 GDPR. However, this obligation does not apply if this notification is impossible or involves a disproportionate effort. Notwithstanding this, the user has a right to information about these recipients.
In accordance with Art. 21 GDPR, users and data subjects also have the right to object to the future processing of data concerning them, provided that the data is processed by the provider in accordance with Art. 6 para. 1 lit. f) GDPR. In particular, an objection to data processing for the purpose of direct advertising is permitted.
Server data
Cookies
Google Analytics
Using Facebook Social Plugins
For technical reasons, in particular to ensure a secure and stable Internet presence, data is transmitted to us or to our web space provider by your Internet browser. With these so-called server log files, the type and version of your Internet browser, the operating system, the website from which you have switched to our Internet presence (referrer URL), the website(s) of our Internet presence that you visit, the date and time of the respective access and the IP address of the Internet connection from which the use of our Internet presence takes place are collected, among other things.
The data collected in this way is stored temporarily, but not together with other data about you. This storage takes place on the legal basis of Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality and security of our website.
The data will be deleted after seven days at the latest, unless further storage is required for evidence purposes. Otherwise, the data is excluded from deletion in whole or in part until an incident has been finally clarified.
Cookies
a) Session cookies/session cookies
We use so-called cookies on our website. Cookies are small text files or other storage technologies that are placed and stored on your end device by the Internet browser you use. These cookies are used to process certain information about you, such as your browser or location data or your IP address, on an individual basis. This processing makes our website more user-friendly, effective and secure, as the processing enables, for example, the reproduction of our website in different languages or the offer of a shopping cart function. The legal basis for this processing is Art. 6 para. 1 lit. b.) GDPR, insofar as these cookies are processed for contract initiation or contract processing. If the processing does not serve to initiate or process a contract, our legitimate interest lies in improving the functionality of our website. The legal basis in this case is Art. 6 para. 1 lit. f) GDPR. These session cookies are deleted when you close your Internet browser.
We use so-called cookies on our website. Cookies are small text files or other storage technologies that are placed and stored on your end device by the Internet browser you use. These cookies are used to process certain information about you, such as your browser or location data or your IP address, on an individual basis. This processing makes our website more user-friendly, effective and secure, as the processing enables, for example, the reproduction of our website in different languages or the offer of a shopping cart function. The legal basis for this processing is Art. 6 para. 1 lit. b.) GDPR, insofar as these cookies are processed for contract initiation or contract processing. If the processing does not serve to initiate or process a contract, our legitimate interest lies in improving the functionality of our website. The legal basis in this case is Art. 6 para. 1 lit. f) GDPR. These session cookies are deleted when you close your Internet browser.
b) Third-party cookies
Our website may also use cookies from partner companies with whom we cooperate for the purposes of advertising, analysis or the functionalities of our website. Please refer to the following information for details, in particular the purposes and legal basis for processing such third-party cookies.
Our website may also use cookies from partner companies with whom we cooperate for the purposes of advertising, analysis or the functionalities of our website. Please refer to the following information for details, in particular the purposes and legal basis for processing such third-party cookies.
c) Removal option
You can prevent or restrict the installation of cookies by changing the settings of your Internet browser. You can also delete cookies that have already been saved at any time. However, the steps and measures required for this depend on the specific Internet browser you are using. If you have any questions, please use the help function or documentation of your Internet browser or contact its manufacturer or support. In the case of so-called Flash cookies, however, processing cannot be prevented via the browser settings. Instead, you must change the settings of your Flash player. The steps and measures required for this also depend on the specific Flash player you are using. If you have any questions, please also use the help function or documentation of your Flash player or contact the manufacturer or user support. However, if you prevent or restrict the installation of cookies, this may mean that not all functions of our website can be used to their full extent.
You can prevent or restrict the installation of cookies by changing the settings of your Internet browser. You can also delete cookies that have already been saved at any time. However, the steps and measures required for this depend on the specific Internet browser you are using. If you have any questions, please use the help function or documentation of your Internet browser or contact its manufacturer or support. In the case of so-called Flash cookies, however, processing cannot be prevented via the browser settings. Instead, you must change the settings of your Flash player. The steps and measures required for this also depend on the specific Flash player you are using. If you have any questions, please also use the help function or documentation of your Flash player or contact the manufacturer or user support. However, if you prevent or restrict the installation of cookies, this may mean that not all functions of our website can be used to their full extent.
Contact requests / contact option
If you contact us via contact form or e-mail, the data you provide will be used to process your request. The provision of the data is necessary for processing and answering your inquiry - without the provision of this data, we cannot answer your inquiry or can only answer it to a limited extent.
The legal basis for this processing is Art. 6 para. 1 lit. b) GDPR.
Your data will be deleted if your request has been finally answered and the deletion does not conflict with any statutory retention obligations, such as in the case of any subsequent contract processing.
Instrument registration function
If you register your instrument with us via our website, we will collect and store the data you enter during registration (e.g. your name, address or e-mail address) exclusively for pre-contractual services, for contract fulfillment or for the purpose of customer care (e.g. to extend the warranty of your instrument).
Registration is required for the provision of certain content and services on our website. As part of the further registration process, your consent to this processing is obtained and reference is made to this privacy policy. The data collected by us will be used exclusively for the provision of the customer account.
You can revoke your consent to the opening and maintenance of the customer account at any time with effect for the future in accordance with Art. 7 para. 3 GDPR. All you have to do is inform us of your revocation.
The data collected in this respect will be deleted as soon as processing is no longer necessary. However, we must comply with retention periods under tax and commercial law.
Brevo
We use the "Brevo" service of Sendinblue GmbH (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin) for the administration, design and dispatch of our newsletter.
We will add the data you enter when registering for the newsletter (e.g. your name, address or e-mail address) to our contact list at Brevo and collect and store it exclusively for pre-contractual services or for the purpose of customer care. As part of the registration process, your consent to this processing is obtained and reference is made to this privacy policy. The data collected by us will be used with the help of Brevo exclusively for the administration and dispatch of our newsletter.
If you consent to this processing of your data for the purpose of receiving the newsletter, Art. 6 para. 1 lit. a) GDPR is the legal basis for the processing.
You can revoke your consent to receive our newsletter at any time with effect for the future in accordance with Art. 7 para. 3 GDPR. All you have to do is inform us of your revocation (unsubscribe from the newsletter).
Google Maps
We use Google Maps on our website to display our location and to provide directions. This is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google" - the controller for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
By means of certification in accordance with the EU-US Privacy Shield ( https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Activeversichert
Google guarantees that it will follow EU data protection regulations when processing data in the USA. If you call up the Google Maps component integrated into our website, Google stores a cookie on your end device via your Internet browser. Your user settings and data are processed in order to display our location and create directions. We cannot rule out the possibility that Google uses servers in the USA. The connection to Google established in this way enables Google to determine from which website your request has been sent and to which IP address the directions are to be sent. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in optimizing the functionality of our website.
By means of certification in accordance with the EU-US Privacy Shield ( https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Activeversichert
Google guarantees that it will follow EU data protection regulations when processing data in the USA. If you call up the Google Maps component integrated into our website, Google stores a cookie on your end device via your Internet browser. Your user settings and data are processed in order to display our location and create directions. We cannot rule out the possibility that Google uses servers in the USA. The connection to Google established in this way enables Google to determine from which website your request has been sent and to which IP address the directions are to be sent. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in optimizing the functionality of our website.
If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your Internet browser. Details on this can be found above under "Cookies".
In addition, the use of Google Maps and the information obtained via Google Maps is governed by the Google Terms of Use
https://policies.google.com/terms?gl=DE&hl=de and the Terms and Conditions for Google Maps https://www.google.com/intl/de_de/help/terms_maps.html.
In addition, Google offers at
https://adssettings.google.com/authenticated
https://policies.google.com/privacy
for further information.
https://policies.google.com/terms?gl=DE&hl=de and the Terms and Conditions for Google Maps https://www.google.com/intl/de_de/help/terms_maps.html.
In addition, Google offers at
https://adssettings.google.com/authenticated
https://policies.google.com/privacy
for further information.
If you have given your consent, we also use Google Analytics 4 on our website to analyze your use of the website. This is a web analysis service provided by Google LLC. - The controller for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). We use the data collected in this way to optimize our website and our advertising measures.
Google Analytics uses cookies (text files) to help us analyze how you use our website. During your visit to the website, your user behavior is recorded in the form of "events". Such events can be, for example: page views, first visit to the website, start of the session, web pages visited, language settings, use of the pages (e.g. duration of the visit and "scroll depth"), clicking on external links, performing searches on our website, downloading files, advertisements viewed or clicked on). We also record Your approximate location (region), date and time of the visit, your IP address (in abbreviated form), technical information such as your browser, your internet provider, the end device you are using, the website from which you switched to our website ("referrer URL") or via which advertising medium you came to this website) and a randomly generated user ID.
T
The information collected using cookies as described above is usually transferred to a Google server in the USA and stored there. Google Analytics 4 anonymizes the IP addresses by default. This means that your IP address is already truncated by Google within member states of the EU or in other signatory states to the EEA Agreement and thus anonymized. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. However, no personal data such as name, address or contact details are transmitted to Google Analytics. According to Google, the IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Recipients of the data may be
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as processor pursuant to Art. 28 GDPR)
- Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA - Alphabet Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA Google will use this information for the purpose of evaluating your use of the website and compiling reports on website activity in order to analyze the use of our website for us.
- Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA - Alphabet Inc, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA Google will use this information for the purpose of evaluating your use of the website and compiling reports on website activity in order to analyze the use of our website for us.
An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA. Service providers used from the USA are generally certified under the EU-U.S. Data Privacy Framework. Further information can be found here. If the service providers used are not certified under the DPF, standard contractual clauses have been concluded as a suitable guarantee.
Google Analytics stores cookies in your web browser for a period of two years since your last visit. Such cookies contain a randomly generated user ID with which you can be recognized on future website visits. The data collected is stored together with the randomly generated user ID, which makes it possible to analyze user profiles. This user-related data is automatically deleted after 14 months. Other data remains stored in aggregated form indefinitely.
The legal basis for this data processing is your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
You can revoke your consent for the future by making a change to your selection in the cookie settings HERE. For the past, the legality of the processing carried out on the basis of the consent remains intact. Alternatively, you can prevent the storage of cookies by installing the browser add-on to deactivate Google Analytics or by rejecting cookies via the cookie settings dialog. However, rejecting all cookies may restrict the functionality of our website.
You can find more information on the terms of use of Google Analytics and on data protection at Google at https://marketingplatform.google.com/about/analytics/terms/de/ and at
https://policies.google.com/?hl=de.
https://policies.google.com/?hl=de.
Google Tag Manager
We also use a service called Google Tag Manager from "Google" on our website. "Google" is a group of companies consisting of Google Ireland Ltd (provider of the service), Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA and other affiliated companies of Google LLC.
Google Tag Manager is an auxiliary service and does not itself collect any personal data. It triggers the loading of other components that may collect data. Google Tag Manager does not access this data. You can find more information about Google Tag Manager at https://www.google.de/tagmanager/use-policy.html.
Google reCAPTCHA
We also use a service called Google ReCAPTCHA from "Google" on our website. "Google" is a group of companies consisting of Google Ireland Ltd (provider of the service), Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA and other affiliated companies of Google LLC.
The use of Google ReCAPTCHA is intended to prevent machines, computer programs or malware (usually bots) from accessing our website in order to participate in registrations or comment functions.
Further information on Google ReCAPTCHA can be found in Google's privacy policy. Please note that due to American laws, American authorities could possibly gain access to personal data that is inevitably exchanged with Google due to the Internet protocol when this service is integrated.
Google Fonts
We also use Google Fonts on our website. These are Google fonts from Google Inc. that are made available to users free of charge - the controller for users in the EU/EEA and Switzerland is Google Ireland Limited, Google Building Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google").
Google Fonts enables us to use web-optimized fonts on our website, which we do not have to upload to our own server beforehand. This ensures a uniform and attractive display on different devices.
When you visit our website, the corresponding fonts are loaded via a Google server. With the request for reloading, data is transmitted to the Google server - Google recognizes that your IP address is visiting the website. Google Fonts stores CSS and font requests with Google.
Google stores requests for CSS assets for one day on its servers, most of which are located outside the EU. This allows the fonts to be used with the help of a Google stylesheet (a format template that can be used to easily change the design or font of a website, for example). The fonts files are stored by Google for one year in order to improve the loading time of the website.
With every Google Fonts request, information such as IP address, language settings, browser name, browser version and screen resolution of the browser are automatically transmitted to the Google servers. Unfortunately, Google does not clearly communicate whether this data is stored.
The data that Google stores for one day or one year cannot simply be deleted because the data is automatically transmitted to Google when the page is accessed. To request deletion of the data before the end of storage, please contact Google support at https://support.google.com/?hl=de&tid=231717121089.
In this case, you can only prevent data storage if you do not visit our website.
If you give your consent to the use of Google Fonts, this forms the legal basis for data processing within the meaning of Art. 6 para. 1 lit. a GDPR. Our legitimate interest lies in optimizing the functionality of our website (Art. 6 para. 1 lit. f GDPR).
For more information on data processing at Google Fonts, visit
https://www.google.com/intl/de/policies/privacy/ and
https://developers.google.com/fonts/faq?tid=231717121089.
Unfortunately, Google does not provide any detailed information on data storage there. Please note that due to American laws, American authorities could possibly gain access to personal data that is inevitably exchanged with Google due to the Internet Protocol when this service is integrated.
https://www.google.com/intl/de/policies/privacy/ and
https://developers.google.com/fonts/faq?tid=231717121089.
Unfortunately, Google does not provide any detailed information on data storage there. Please note that due to American laws, American authorities could possibly gain access to personal data that is inevitably exchanged with Google due to the Internet Protocol when this service is integrated.
Using Facebook Social Plugins
We use the plug-in of the social network Facebook on our website. Facebook is an internet service of Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA. In the EU, this service is in turn operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, hereinafter both referred to as "Facebook".
Certification in accordance with the EU-US Privacy Shield ("EU-US Privacy Shield")
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active,
Facebook guarantees that it will follow the EU's data protection regulations when processing data in the USA. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website. Facebook provides further information about the possible plug-ins and their respective functions at https://developers.facebook.com/docs/plugins/ for you.
If the plug-in is stored on one of the pages you visit on our website, your internet browser will download a representation of the plug-in from the Facebook servers in the USA. For technical reasons, it is necessary for Facebook to process your IP address. The date and time of your visit to our website are also recorded. If you are logged in to Facebook while you visit one of our plugged-in websites, the information collected by the plug-in about your specific visit will be recognized by Facebook. Facebook may assign the information collected in this way to your personal user account there. If you use the Facebook "Like" button, for example, this information will be stored in your Facebook user account and may be published via the Facebook platform. If you wish to prevent this, you must either log out of Facebook before visiting our website or use an add-on for your internet browser to prevent the Facebook plug-in from loading.
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active,
Facebook guarantees that it will follow the EU's data protection regulations when processing data in the USA. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website. Facebook provides further information about the possible plug-ins and their respective functions at https://developers.facebook.com/docs/plugins/ for you.
If the plug-in is stored on one of the pages you visit on our website, your internet browser will download a representation of the plug-in from the Facebook servers in the USA. For technical reasons, it is necessary for Facebook to process your IP address. The date and time of your visit to our website are also recorded. If you are logged in to Facebook while you visit one of our plugged-in websites, the information collected by the plug-in about your specific visit will be recognized by Facebook. Facebook may assign the information collected in this way to your personal user account there. If you use the Facebook "Like" button, for example, this information will be stored in your Facebook user account and may be published via the Facebook platform. If you wish to prevent this, you must either log out of Facebook before visiting our website or use an add-on for your internet browser to prevent the Facebook plug-in from loading.
Further information about the collection and use of data as well as your rights and protection options in this regard can be found on Facebook at
https://www.facebook.com/policy.php
in the data protection information available at.
Stripe
Our website enables the processing of payment transactions in the online store via the payment service provider "Stripe" (Stripe Inc. 510, Townsend St., San Francisco, CA 94103) - responsible for customers within the EU is Stripe Payments Europe, Limited (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).
When you use this payment method, we pass on the following data to Stripe, insofar as this is necessary for the respective fulfillment of the contract: Name of the cardholder, telephone number, e-mail address, customer number, order number, payment method (i.e. credit card, debit card or account number including bank sort code), in each case with validity period and any verification number, your billing or alternative delivery address, in some cases also your transaction history. This data is required for authentication purposes, without being required by law or contract. Furthermore, Stripe may collect technical data about your device (such as IP address), name, address, telephone number and your country for fraud prevention, financial reporting and to be able to offer its own services in full. However, payment via Stripe is not possible without the transmission of your personal data. The alternative is to select a different payment method.
The processing is necessary for the performance of a contract to which you are a party (see Art. 6 para. 1 lit. b GDPR). The use of the service also requires your consent (Art. 6 para. 1 lit. a GDPR), insofar as the use of cookies is necessary.
The data collected will be stored until the completion of payment processing, which also includes the necessary period for processing refunds, collections and fraud prevention.
Further information can be found at https://stripe.com/at/privacy. Information on objection and removal options vis-à-vis Stripe can be found at: https://stripe.com/privacy-center/legal
PayPal
Our website enables the processing of payment transactions in the online store via the payment service provider "PayPal" (Paypal Europe S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg).
When you use this payment method, we pass on the following data to PayPal, insofar as this is necessary for the respective fulfillment of the contract: Name of the cardholder, e-mail address, telephone number, customer number, order number, payment method (i.e. credit card, debit card or account number including bank sort code), in each case with validity period and any verification number, your billing or alternative delivery address and, in some cases, your transaction history. This data is required for authentication purposes without being required by law or contract. However, payment via PayPal cannot be carried out without the transmission of your personal data. The alternative is to select a different payment method. The processing is necessary for the performance of a contract to which you are a party (see Art. 6 para. 1 lit. b GDPR). The use of the service also requires your consent (Art. 6 para. 1 lit. a GDPR), insofar as the use of cookies is necessary.
The data collected will be stored until the completion of payment processing, which also includes the necessary period for processing refunds, collections and fraud prevention.
Trusted Shops
If you have given your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, Trusted Shops widgets are integrated on this website to display the Trusted Shops services (e.g. seal of approval, collected reviews) and to offer Trusted Shops products to buyers after an order. The Trustbadge and the services advertised with it are an offer from Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne ("Trusted Shops"), with whom we are jointly responsible under data protection law in accordance with Art. 26 GDPR. In the context of this data protection information, we inform you below about the essential contents of the contract in accordance with Art. 26 para. 2 GDPR.
Within the framework of the joint responsibility existing between us and Trusted Shops, please contact Trusted Shops in the event of data protection issues and to assert your rights using the contact options provided in the data protection information. Irrespective of this, you can always contact the controller of your choice. If necessary, your request will then be forwarded to the other responsible party for answering.
Within the framework of the joint responsibility existing between us and Trusted Shops, please contact Trusted Shops in the event of data protection issues and to assert your rights using the contact options provided in the data protection information. Irrespective of this, you can always contact the controller of your choice. If necessary, your request will then be forwarded to the other responsible party for answering.
1. data processing when integrating the Trustbadge / other widgets
The trust badge is provided by a US CDN provider (content delivery network). An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA. Service providers used from the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information can be found here. If the service providers used are not certified under the DPF, standard contractual clauses have been concluded as a suitable guarantee. When the Trustbadge is accessed, the web server automatically saves a so-called server log file, which also contains your IP address, the date and time of access, the amount of data transferred and the requesting provider (access data) and documents the access. The IP address is anonymized immediately after collection so that the stored data cannot be assigned to your person. The anonymized data is used in particular for statistical purposes and for error analysis.
The trust badge is provided by a US CDN provider (content delivery network). An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA. Service providers used from the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF). Further information can be found here. If the service providers used are not certified under the DPF, standard contractual clauses have been concluded as a suitable guarantee. When the Trustbadge is accessed, the web server automatically saves a so-called server log file, which also contains your IP address, the date and time of access, the amount of data transferred and the requesting provider (access data) and documents the access. The IP address is anonymized immediately after collection so that the stored data cannot be assigned to your person. The anonymized data is used in particular for statistical purposes and for error analysis.
2. data processing after order completion
If you have given your consent, the Trustbadge accesses the order information stored in your end device (order total, order number, product purchased if applicable) and e-mail address after the order has been completed and your e-mail address is hashed using a cryptological one-way function. The hash value is then transmitted to Trusted Shops with the order information in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. This serves to check whether you are already registered for Trusted Shops services. If this is the case, further processing will take place in accordance with the contractual agreement concluded between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then be given the opportunity to register manually for the use of the services or to complete the protection as part of your existing user contract.
If you have given your consent, the Trustbadge accesses the order information stored in your end device (order total, order number, product purchased if applicable) and e-mail address after the order has been completed and your e-mail address is hashed using a cryptological one-way function. The hash value is then transmitted to Trusted Shops with the order information in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR. This serves to check whether you are already registered for Trusted Shops services. If this is the case, further processing will take place in accordance with the contractual agreement concluded between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then be given the opportunity to register manually for the use of the services or to complete the protection as part of your existing user contract.
For this purpose, the Trustbadge accesses the following information, which is stored in the end device you are using, after you have completed your order: Order total, order number and e-mail address. This is necessary so that we can offer you buyer protection. The data will only be transmitted to Trusted Shops if you actively decide to take out buyer protection by clicking on the correspondingly labeled button in the so-called Trustcard. If you decide to use the services, the further processing is based on the contractual agreement with Trusted Shops in accordance with Art. 6 para. 1 lit. b GDPR in order to complete your registration for buyer protection and to secure the order and, if necessary, to be able to send you evaluation invitations by e-mail afterwards.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Art. 6 para. 1 lit. f GDPR for the purpose of ensuring trouble-free operation. Processing may take place in third countries (USA and Israel).
An adequate level of data protection is ensured in each case by an adequacy decision of the EU Commission, which can be accessed here for the USA and here for Israel. Service providers used from the USA are generally certified under the EU-U.S. Data Privacy Framework. Further information is available here. If the service providers used are not certified under the DPF, standard contractual clauses have been concluded as a suitable guarantee.
YouTube
We use YouTube on our website. This is a video portal of YouTube LLC, 901 Cherry Ave, 94066 San Bruno, CA, USA, hereinafter referred to as "YouTube".
YouTube is a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA, hereinafter referred to as "Google".
Through certification in accordance with the EU-US Privacy Shield ("EU-US Privacy Shield")
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google, and therefore also its subsidiary YouTube, guarantees that the data protection requirements of the EU will also be complied with when processing data in the USA.
We use YouTube in connection with the "extended data protection mode" function in order to be able to show you videos. The legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in improving the quality of our website. According to YouTube, the "Enhanced Privacy Mode" function means that the data described in more detail below is only transmitted to the YouTube server when you actually start a video.
Without this "enhanced data protection", a connection to the YouTube server in the USA is established as soon as you call up one of our Internet pages on which a YouTube video is embedded.
This connection is necessary in order to be able to display the respective video on our website via your Internet browser. In the course of this, YouTube will at least record and process your IP address, the date and time and the website you have visited. In addition, a connection is established to Google's "DoubleClick" advertising network.
If you are logged in to YouTube at the same time, YouTube will assign the connection information to your YouTube account. If you wish to prevent this, you must either log out of YouTube before visiting our website or make the appropriate settings in your YouTube user account.
For the purpose of functionality and analysis of user behavior, YouTube permanently stores cookies on your end device via your Internet browser. If you do not agree to this processing, you have the option of preventing the storage of cookies by changing the settings in your Internet browser. You can find more information on this above under "Cookies".
Google provides further information on the collection and use of data as well as your rights and protection options in this regard in the data protection information available at https://policies.google.com/privacy.
Created on the basis of a sample data protection declaration from the law firm Weiß & Partner (revised).