Privacy Policies
Privacy Policy
1) Introduction and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.
1.2 The controller for data processing on this website in the sense of the General Data Protection Regulation (GDPR) is Arkanum Editions GbR, Freistraße 6, 36251 Ludwigsau, Germany, Tel.: +4917664461321, E-Mail: info@arkanum-editions.de. The controller for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
2) Data Collection When Visiting Our Website
2.1 When using our website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you reached the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
Processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. No further disclosure or other use of the data takes place. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.
3) Hosting & Content Delivery Network
3.1 Shopify
For hosting our website and displaying page content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")
Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada
All data collected on our website is processed on the servers of the provider. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
When data is transferred to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
3.2 Cloudflare
We use a Content Delivery Network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service enables us to deliver large media files such as graphics, page content or scripts faster via a network of regionally distributed servers. Processing is carried out to protect our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.
4) Cookies
In order to make visiting our website attractive and enable the use of certain functions, we use cookies, which are small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device for a longer period and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of the cookie settings of your web browser.
If personal data is also processed by individual cookies used by us, the processing is carried out either in accordance with Art. 6 Para. 1 lit. b GDPR for the execution of the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the event of a granted consent, or in accordance with Art. 6 Para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the website visit.
You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or exclude the acceptance of cookies for certain cases or generally.
Please note that if cookies are not accepted, the functionality of our website may be limited.
5) Contact
When contacting us (e.g. via contact form or e-mail), personal data is processed - exclusively for the purpose of processing and responding to your request and only to the extent necessary for this purpose.
The legal basis for the processing of this data is our legitimate interest in responding to your request in accordance with Art. 6 Para. 1 lit. f GDPR. If your contact aims at concluding a contract, the additional legal basis for the processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted if it can be inferred from the circumstances that the matter concerned has been conclusively clarified and provided that there are no legal retention obligations to the contrary.
6) Comment Function
When using the comment function on this website, in addition to your comment, information about the time of creation of the comment and the commenter name you chose are stored and published on this website. Furthermore, your IP address is logged and stored. This storage of the IP address is for security reasons and in case the data subject infringes the rights of third parties or posts illegal content through a comment. We need your email address to contact you if a third party complains that your published content is illegal.
Legal bases for storing your data are Art. 6 para. 1 lit. b and f GDPR. We reserve the right to delete comments if they are deemed illegal by third parties.
7) Data Processing When Opening a Customer Account
In accordance with Art. 6 para. 1 lit. b GDPR, personal data will continue to be collected and processed to the extent necessary if you provide us with this data when opening a customer account. The data required for opening an account can be found in the input mask of the corresponding form on our website.
Your customer account can be deleted at any time by sending a message to the controller's address mentioned above. After your customer account has been deleted, your data will be deleted, provided that all contracts concluded through it have been fully processed, no legal retention periods prevent deletion, and we no longer have a legitimate interest in further storage.
8) Use of Customer Data for Direct Marketing
8.1 Subscription to our e-mail newsletter
If you subscribe to our e-mail newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your e-mail address. The provision of further data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure, which ensures that you will only receive newsletters if you have explicitly confirmed your consent to receive newsletters by clicking on a verification link sent to the e-mail address provided.
By activating the confirmation link, you give us your consent for the use of your personal data in accordance with Art. 6 Para. 1 lit. a GDPR. In doing so, we store your IP address entered by the Internet service provider (ISP) as well as the date and time of registration in order to be able to trace a possible misuse of your e-mail address at a later date. The data collected by us when you register for the newsletter will be used strictly for the intended purpose.
You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the controller mentioned at the beginning. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this declaration.
8.2 GoDaddy
Our email newsletters are sent via this provider: Go Daddy Operating Co LLC, 14455 North Hayden Road, Suite 226, Scottsdale, AZ 85260, USA
Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided during newsletter registration to this provider in accordance with Art. 6 Para. 1 lit. f GDPR, so that they can take over the newsletter dispatch on our behalf.
Subject to your express consent in accordance with Art. 6 Para. 1 lit. a GDPR, the provider also carries out a statistical success evaluation of newsletter campaigns using web beacons or tracking pixels in the sent e-mails, which can measure opening rates and specific interactions with the content of the newsletter. Device information (e.g. time of access, IP address, browser type and operating system) is also collected and evaluated, but not merged with other data records.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider, which protects the data of our website visitors and prohibits disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.
8.3 Klaviyo
Our email newsletters are sent via this provider: Klaviyo, Inc., 125 Summer St., Ste 600, Boston, MA 02110, USA
Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided during newsletter registration to this provider in accordance with Art. 6 Para. 1 lit. f GDPR, so that they can take over the newsletter dispatch on our behalf.
Subject to your express consent in accordance with Art. 6 Para. 1 lit. a GDPR, the provider also carries out a statistical success evaluation of newsletter campaigns using web beacons or tracking pixels in the sent e-mails, which can measure opening rates and specific interactions with the content of the newsletter. Device information (e.g. time of access, IP address, browser type and operating system) is also collected and evaluated, but not merged with other data records.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider, which protects the data of our website visitors and prohibits disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which, based on an adequacy decision by the European Commission, ensures compliance with the European level of data protection.
9) Data Processing for Order Processing
9.1 To the extent necessary for the fulfillment of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Para. 1 lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact data you provided when ordering to inform you personally within the scope of our legal information obligations in accordance with Art. 6 Para. 1 lit. c GDPR. Your contact data will be used strictly for the intended purpose for notifications about updates owed by us and processed by us for this purpose only to the extent necessary for the respective information.
To process your order, we also work with the following service provider(s) who assist us wholly or partially in the execution of concluded contracts. Certain personal data will be transferred to these service providers in accordance with the following information.
9.2 Disclosure of personal data to shipping service providers
- Deutsche Post
We use the following provider as a transport service provider: Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany
We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 Para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent for this in the order process. Otherwise, for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b GDPR, we will only pass on the recipient's name and the delivery address to the provider. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or to announce the delivery in advance.
The consent can be revoked at any time with effect for the future towards the above-mentioned controller or towards the provider.
- DHL
We use the following provider as a transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany
We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 Para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent for this in the order process. Otherwise, for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b GDPR, we will only pass on the recipient's name and the delivery address to the provider. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or to announce the delivery in advance.
The consent can be revoked at any time with effect for the future towards the above-mentioned controller or towards the provider.
- DHL Express
We use the following provider as a transport service provider: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany
We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 Para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent for this in the order process. Otherwise, for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b GDPR, we will only pass on the recipient's name and the delivery address to the provider. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or to announce the delivery in advance.
The consent can be revoked at any time with effect for the future towards the above-mentioned controller or towards the provider.
- DHL Express Austria
We use the following provider as a transport service provider: DHL Express (Austria) GmbH, Am Europlatz 2 (Objekt G), 1120 Vienna
We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 Para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent for this in the order process. Otherwise, for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b GDPR, we will only pass on the recipient's name and the delivery address to the provider. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or to announce the delivery in advance.
The consent can be revoked at any time with effect for the future towards the above-mentioned controller or towards the provider.
- DHL Freight
We use the following provider as a transport service provider: DHL Freight GmbH, Godesberger Allee 102-104, 53175 Bonn, Germany
We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 Para. 1 lit. a GDPR before the delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent for this in the order process. Otherwise, for the purpose of delivery in accordance with Art. 6 Para. 1 lit. b GDPR, we will only pass on the recipient's name and the delivery address to the provider. The transfer will only take place to the extent necessary for the delivery of the goods. In this case, it is not possible to coordinate the delivery date with the provider or to announce the delivery in advance.
Consent can be revoked at any time with future effect from the controller designated above or from the provider.
9.3 Use of payment service providers
- Amazon Pay
This website offers one or more online payment methods from the following provider: Amazon Payments Europe s.c.a., 38 avenue J.F. Kennedy, L-1855 Luxembourg
If you select a payment method from this provider that requires you to pay in advance (e.g., credit card payment), your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the ordering process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- BLIK
This website offers one or more online payment methods from the following provider: Polski Standard Płatności Sp. z o.o., Czerniakowska 87a, 00-718 Warsaw, Poland
To process your payment, the payment data communicated during the order process (including name, address, bank and payment card information, currency and transaction number) and information about the content of your order will be transmitted to the provider in accordance with Art. 6 para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- EPS transfer
This website offers one or more online payment methods from the following provider: PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria
If you select a payment method from this provider that requires you to pay in advance (e.g., credit card payment), your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the ordering process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- Google Pay
If you choose the "Google Pay" payment method from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), payment will be processed via the "Google Pay" application on your mobile device running at least Android 4.4 ("KitKat") and equipped with NFC functionality, by charging a payment card stored with Google Pay or a verified payment system there (e.g. PayPal). To authorize a payment via Google Pay exceeding €25, you must first unlock your mobile device using the established verification method (e.g. facial recognition, password, fingerprint or pattern).
For the purpose of payment processing, the information you provided during the order process, along with information about your order, will be transmitted to Google. Google then transmits your payment information stored in Google Pay in the form of a uniquely assigned transaction number to the originating website, which verifies the completed payment. This transaction number contains no information about the real payment data of your payment methods stored in Google Pay, but is created and transmitted as a uniquely valid numerical token. For all transactions via Google Pay, Google acts merely as an intermediary for processing the payment. The transaction is carried out exclusively between the user and the originating website by charging the payment method stored with Google Pay.
If personal data is processed during the described transmissions, the processing is exclusively for the purpose of payment processing in accordance with Art. 6 para. 1 lit. b GDPR.
Google reserves the right to collect, store, and evaluate certain process-specific information for every transaction made via Google Pay. This includes the date, time, and amount of the transaction, merchant location and description, a description of the goods or services purchased provided by the merchant, photos you have attached to the transaction, the name and email address of the seller and buyer or sender and recipient, the payment method used, your description of the reason for the transaction, and, if applicable, the offer associated with the transaction.
According to Google, this processing is carried out exclusively in accordance with Art. 6 Para. 1 lit. f GDPR, based on the legitimate interest in proper accounting, verification of transaction data, and optimization and maintenance of the Google Pay service.
Google also reserves the right to combine the processed transaction data with other information collected and stored by Google when using other Google services.
The Google Pay terms of use can be found here:
https://payments.google.com
Further information on data protection at Google Pay can be found at the following internet address:
https://payments.google.com
- iDeal
This website offers one or more online payment methods from the following provider: Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands
If you select a payment method from this provider that requires you to pay in advance (e.g., credit card payment), your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the ordering process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- Klarna
This website offers one or more online payment methods from the following provider: Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden
If you select a payment method from this provider that requires you to pay in advance (e.g., credit card payment), your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the ordering process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
If you choose a payment method where the provider makes an advance payment (e.g., purchase on account or installment payment or direct debit), you will also be asked to provide certain personal data during the order process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable, data on an alternative payment method).
To safeguard our legitimate interest in determining our customers' creditworthiness, we forward this data to the provider in accordance with Art. 6 Para. 1 lit. f GDPR for the purpose of a credit check. Based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experiences), the provider checks whether the payment option you selected can be granted in view of payment and/or default risks.
In addition to internal provider criteria, identity and creditworthiness information from the following credit agencies may be included in the decision-making process for application review, in accordance with Art. 6 Para. 1 lit. f GDPR:
https://cdn.klarna.com
The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things but not exclusively, address data.
You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.
- PayPal
This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
If you select a payment method from the provider that requires you to pay in advance, your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the order process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
If you choose a payment method where we make an advance payment, you will also be asked to provide certain personal data during the order process (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable, data on an alternative payment method).
In such cases, to safeguard our legitimate interest in determining your creditworthiness, we forward this data to the provider in accordance with Art. 6 Para. 1 lit. f GDPR for the purpose of a credit check. Based on the personal data you provide and other data (such as shopping cart, invoice amount, order history, payment experiences), the provider checks whether the payment option you selected can be granted in view of payment and/or default risks.
The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things but not exclusively, address data.
You can object to this processing of your data at any time by sending us a message or by contacting the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.
- Shopify Payments
This website offers one or more online payment methods from the following provider: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
If you select a payment method from this provider that requires you to pay in advance (e.g., credit card payment), your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the ordering process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
- Sofortüberweisung (Instant Bank Transfer)
This website offers one or more online payment methods from the following provider: Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden
If you select a payment method from this provider that requires you to pay in advance (e.g., credit card payment), your payment data (including name, address, bank and payment card information, currency, and transaction number) as well as information about the content of your order, communicated during the ordering process, will be transmitted to this provider in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, the transmission of your data is exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
10) Web Analytics Services
Shopify Analytics
This website uses the web analysis service of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Data is also transferred to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada
Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading out end-device and browser information), the service collects and stores pseudonymized visitor data, including information about the end device used such as the IP address and browser information, to analyze user behavior on our website for statistical purposes and to create pseudonymized usage profiles. This allows for the analysis of movement patterns (so-called heatmaps), which show the duration of page visits and interactions with page content (e.g., text entries, scrolling, clicks, and mouse-overs). Pseudonymization generally precludes direct personal identification. No merging with clear data collected in other ways about your person takes place.
All processing described above, in particular the reading or storing of information on the end device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service in the "Cookie-Consent-Tool" provided on the website.
We have concluded a data processing agreement with the provider, which protects the data of our site visitors and prohibits disclosure to third parties.
In the case of data transfer to Canada, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
11) Retargeting/Remarketing and Conversion Tracking
Meta Pixel with Enhanced Matching
Within our online offering, we use the "Meta Pixel" service from the following provider in enhanced matching mode: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland ("Meta")
If a user clicks on an advertisement placed by us on Facebook or Instagram, the URL of our linked page is extended by a parameter using "Meta Pixel". This URL parameter is then entered into the user's browser by a cookie that our linked page itself sets after the redirection. In addition, this cookie collects specific customer data such as the email address, which we collect on our website linked to the Facebook or Instagram advertisement during processes such as purchases, account logins, or registrations (enhanced matching). The cookie is then read and enables the transmission of data, including specific customer data, to Meta.
We use "Meta Pixel" with enhanced matching to make our advertisements (so-called "Ads") on Facebook and/or Instagram more effective and to ensure that they match the interests of users or have certain characteristics (e.g., interests in certain topics or products, which are determined based on the visited websites) that we transmit to Meta (so-called "Custom Audiences").
Furthermore, we analyze the effectiveness of our advertisements by tracking whether users were redirected to our website after clicking on an advertisement (conversion). Compared to the standard version of "Meta Pixel", the enhanced matching feature helps us better measure the effectiveness of our advertising campaigns by capturing more attributed conversions.
All transmitted data is stored and processed by Meta, so that an assignment to the respective user profile is possible and Meta can use the data for its own advertising purposes in accordance with Meta's data usage policies (https://www.facebook.com
All processing described above, in particular the setting of cookies for reading information on the end device used, will only be carried out if you have given us your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your given consent at any time with effect for the future by deactivating this service in the "Cookie-Consent-Tool" provided on the website.
We have concluded a data processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorized disclosure to third parties.
The information generated by Meta is generally transmitted to a Meta server and stored there; in this context, it may also be transmitted to Meta Platforms Inc. servers in the USA.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with European data protection standards based on an adequacy decision of the European Commission.
12) Page functionalities
Endereco
To enable real-time verification of certain inputs in the address form of our webshop's order process for input errors, we use the services of the following provider: Endereco UG, Balthasar-Neumann-Straße 4b, 97236 Randersacker, Germany
The provider validates the entered address, verifies the spelling, and adds any missing data. In the case of ambiguous addresses, correct alternative suggestions are displayed. For this purpose, the address data you enter is transmitted to the provider, stored there, and evaluated.
This processing is carried out in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in the proper collection of the customer's correct address data for the diligent fulfillment of our contractual delivery obligations and to prevent problems with contract performance.
The provider processes the affected data separately and does not merge it with other data records, and deletes it as soon as its status or correctness has been confirmed, but no later than after 30 days.
13) Rights of the data subject
13.1 The applicable data protection law grants you, the data subject, the following rights (rights of access and intervention) with regard to the processing of your personal data by the controller, with reference to the legal basis for the respective exercise conditions:
- Right to information pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to notification pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw consent given pursuant to Art. 7 (3) GDPR;
- Right to lodge a complaint pursuant to Art. 77 GDPR.
13.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA WITHIN THE FRAMEWORK OF A BALANCING OF INTERESTS ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENCE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.
14) Duration of storage of personal data
The duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and - if applicable - additionally by the respective statutory retention period (e.g., commercial and tax retention periods).
When processing personal data on the basis of explicit consent pursuant to Art. 6 (1) (a) GDPR, the data concerned will be stored until you withdraw your consent.
If statutory retention periods exist for data processed within the scope of legal or quasi-legal obligations on the basis of Art. 6 (1) (b) GDPR, these data will be routinely deleted after the retention periods have expired, provided they are no longer required for contract fulfillment or contract initiation and/or there is no longer a legitimate interest on our part in continued storage.
When processing personal data on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right to object pursuant to Art. 21 (1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defence of legal claims.
When processing personal data for the purpose of direct marketing on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right to object pursuant to Art. 21 (2) GDPR.
Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will otherwise be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.
