**PRIVACY POLICY**

**1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER**

**1.1** We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data are all data with which you can be personally identified.

**1.2** The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is [Shop Name]. The controller for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

**1.3** For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the lock symbol in your browser line.

**2) DATA COLLECTION WHEN VISITING OUR WEBSITE**

When using our website for informational purposes only, i.e., if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which are technically necessary for us to display the website to you:

– Our visited website
– Date and time at the moment of access
– Amount of data sent in bytes
– Source/reference from which you reached the page
– Used browser
– Used operating system
– Used IP address (if applicable: in anonymized form)

Processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or otherwise used. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.

**3) COOKIES**

To make the visit to our website attractive and to enable the use of certain functions, we use cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and enable us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). If cookies are set, they collect and process specific user information such as browser and location data as well as IP address values to an individual extent. Persistent cookies are automatically deleted after a specified period, which can vary depending on the cookie.

In some cases, cookies serve to simplify the ordering process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). If personal data are also processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6(1)(b) GDPR either for the performance of the contract or in accordance with Art. 6(1)(f) GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the page visit.

We may work with advertising partners who help us make our internet offer more interesting for you. For this purpose, cookies from partner companies are also stored on your hard drive (third-party cookies) when you visit our website. If we cooperate with the aforementioned advertising partners, you will be informed individually and separately about the use of such cookies and the scope of the information collected within the following paragraphs.

Please note that you can set your browser to inform you about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general. Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers under the following links:

– Internet Explorer: [https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies](https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies)
– Firefox: [https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen](https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen)
– Chrome: [https://support.google.com/chrome/answer/95647?hl=de&hlrm=en](https://support.google.com/chrome/answer/95647?hl=de&hlrm=en)
– Safari: [https://support.apple.com/kb/ph21411?locale=de_DE](https://support.apple.com/kb/ph21411?locale=de_DE)
– Opera: [https://help.opera.com/en/latest/web-preferences/#cookies](https://help.opera.com/en/latest/web-preferences/#cookies)

Please note that if you do not accept cookies, the functionality of our website may be limited.

**4) CONTACTING US**

When contacting us (e.g., via contact form or email), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. These data are stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6(1)(f) GDPR. If your contact aims at concluding a contract, then an additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted after final processing of your inquiry if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention obligations to the contrary.

**5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING**

**In accordance with Art. 6(1)(b) GDPR, personal data will continue to be collected and processed if you provide it to us for the performance of a contract or when opening a customer account. The data collected can be seen from the respective input forms. You can delete your customer account at any time by sending a message to the above-mentioned address of the controller. We store and use the data you provide for contract processing. After the complete processing of the contract or deletion of your customer account, your data will be blocked considering tax and commercial law retention periods and deleted after these periods, unless you have expressly consented to further use of your data or a legally permitted further data use has been reserved by our side, about which we inform you accordingly below.

**6) USE OF YOUR DATA FOR DIRECT ADVERTISING**

**6.1** Subscription to our email newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. The provision of any further data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an email newsletter if you have expressly confirmed that you consent to the receipt of newsletters. We will then send you a confirmation email asking you to confirm that you wish to receive the newsletter by clicking on a corresponding link.

By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6(1)(a) GDPR. When registering for the newsletter, we store your IP address entered by the Internet service provider (ISP) as well as the date and time of registration to trace any possible misuse of your email address at a later date. The data collected by us when registering for the newsletter will be used exclusively for the purposes of advertising communication via the newsletter. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a message to the controller mentioned at the beginning. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.

**6.2** Sending the email newsletter to existing customers

If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range by email. For this, we do not need to obtain separate consent from you. Data processing is carried out solely on the basis of our legitimate interest in personalized direct advertising in accordance with Art. 6(1)(f) GDPR. If you initially objected to the use of your email address for this purpose, we will not send emails. You are entitled to object to the use of your email address for the aforementioned advertising purposes at any time with effect for the future by notifying the controller mentioned at the beginning. The only costs you will incur are the transmission costs according to the basic rates.

**in accordance with the basic rates. Upon receipt of your objection, the use of your email address for advertising purposes will be immediately discontinued.**

**7) DATA PROCESSING FOR ORDER HANDLING**

**7.1** The personal data collected by us will be passed on to the transport company commissioned with the delivery as part of the contract processing, to the extent that this is necessary for the delivery of the goods. Your payment data will be passed on to the credit institution commissioned with the payment processing as part of the payment processing, to the extent that this is necessary for the payment processing. If payment service providers are used, we will explicitly inform you of this below. The legal basis for the transfer of data is Art. 6(1)(b) GDPR.

**7.2** Use of payment service providers (payment services) – PayPal

When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – “purchase on account” or “installment payment” via PayPal, we pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”), as part of the payment processing. The transfer takes place in accordance with Art. 6(1)(b) GDPR and only insofar as this is necessary for the payment processing.

PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – “purchase on account” or “installment payment” via PayPal. For this purpose, your payment data may be passed on to credit agencies based on PayPal’s legitimate interest in determining your solvency in accordance with Art. 6(1)(f) GDPR. The result of the credit check with regard to the statistical probability of non-payment is used by PayPal for the purpose of deciding on the provision of the respective payment method. The credit check may contain probability values (so-called score values). Insofar as score values are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data is included in the calculation of the score values, among other things.

For further data protection information, including information on the credit agencies used, please refer to PayPal’s privacy policy: [https://www.paypal.com/de/webapps/mpp/ua/privacy-full](https://www.paypal.com/de/webapps/mpp/ua/privacy-full)

You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.

**- SOFORT**

If you choose the “SOFORT” payment method, the payment will be processed by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “SOFORT”), to whom we will pass on your information provided during the order process together with the information about your order in accordance with Art. 6(1)(b) GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). The transfer of your data takes place exclusively for the purpose of payment processing with the payment service provider SOFORT and only insofar as it is necessary for this purpose.

For further information on SOFORT’s privacy policy, please refer to the following Internet address: [https://www.klarna.com/sofort/datenschutz](https://www.klarna.com/sofort/datenschutz)

**8) CONTACT FOR RATING REMINDERS**

**Own rating reminder (no dispatch by a customer rating system)**

We use your email address to remind you once to submit a rating of your order for the rating system we use, provided that you have given us your explicit consent to do so during or after your order in accordance with Art. 6(1)(a) GDPR.

You can withdraw your consent at any time by sending a message to the controller responsible for data processing.

**9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS**

**9.1** Facebook plugins with Shariff solution

Special additional customs clearance costs and/or import duties are not included in the price and are the responsibility of the customer.

On our website, we use so-called social plugins (“plugins”) from the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”).

To increase the protection of your data when you visit our website, these buttons are not fully integrated as plugins but only embedded in the page using an HTML link. This type of embedding ensures that when you call up a page on our website that contains such buttons, no connection is made to Facebook’s servers. If you click the button, a new browser window opens and calls up the Facebook page where you can interact with the plugins there (if necessary, after entering your login data).

Facebook Inc. based in the USA is certified for the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

For the purpose and scope of data collection and further processing and use of the data by Facebook, as well as your rights and setting options to protect your privacy, please refer to Facebook’s privacy policy: [https://www.facebook.com/policy.php](https://www.facebook.com/policy.php).

**9.2 Google+ Plugins with Shariff Solution**

On our website, we use so-called social plugins (“plugins”) from the social network Google+, which is operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

To increase the protection of your data when you visit our website, these buttons are not fully integrated as plugins but only embedded in the page using an HTML link. This type of embedding ensures that when you call up a page on our website that contains such buttons, no connection is made to Google’s servers. If you click the button, a new browser window opens and calls up the Google+ page where you can interact with the plugins there (if necessary, after entering your login data).

Google LLC based in the USA is certified for the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

For the purpose and scope of data collection and further processing and use of the data by Google, as well as your rights and setting options to protect your privacy, please refer to Google’s privacy policy: [https://www.google.com/intl/de/policies/privacy/](https://www.google.com/intl/de/policies/privacy/).

**9.3 Instagram Plugin with Shariff Solution**

On our website, we use so-called social plugins (“plugins”) from the online service Instagram, which is operated by Instagram LLC., 1601 Willow Rd, Menlo Park, CA 94025, USA (“Instagram”).

To increase the protection of your data when you visit our website, these buttons are not fully integrated as plugins but only embedded in the page using an HTML link. This type of embedding ensures that when you call up a page on our website that contains such buttons, no connection is made to Instagram’s servers. If you click the button, a new browser window opens and calls up the Instagram page where you can interact with the plugins there (if necessary, after entering your login data).

Instagram LLC based in the USA is certified for the US-European data protection agreement “Privacy Shield,” which ensures compliance with the data protection level applicable in the EU.

For the purpose and scope of data collection and further processing and use of the data by Instagram, as well as your rights and setting options to protect your privacy, please refer to Instagram’s privacy policy: [https://help.instagram.com/155833707900388/](https://help.instagram.com/155833707900388/).

**10) ONLINE MARKETING**

**10.1 DoubleClick by Google**

This website uses the online marketing tool DoubleClick by Google, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“DoubleClick”).

DoubleClick uses cookies to show relevant ads to users, improve campaign performance reports, or to prevent a user from seeing the same ads multiple times. Google uses a cookie ID to record which ads are displayed in which browser and can thus prevent them from being displayed multiple times. Processing is based on our legitimate interest in optimal marketing of our website in accordance with Art. 6(1)(f) GDPR.

Additionally, DoubleClick can use cookie IDs to track so-called conversions related to ad requests. This happens, for example, when a user sees a DoubleClick ad and later visits the advertiser’s website with the same browser and makes a purchase there. According to Google, DoubleClick cookies do not contain any personal information.

Due to the marketing tools used, your browser automatically establishes a direct connection to Google’s server.