Privacybeleid
1 Information on the collection of personal data
(1) In the following, we inform you about the collection of personal data when using our website. Personal data is any data that can be associated with you personally, e.g. name, address, e-mail address, user behaviour.
(2) If you contact us by e-mail or via a contact form, the data you provide (your e-mail address, your name and, if applicable, your telephone number) will be stored by us in order to answer your questions. We delete the data created in this context after the storage is no longer necessary or limit the processing if there are legal retention obligations. The legal basis for this is our legitimate interest within the meaning of Section 6(1)(f) of the Data Protection Act (DSG) to answer your enquiry and, if your enquiry serves to conclude a contract, Section 6(1)(b) of the DSG.
(3) If we use commissioned service providers for individual functions of our offer or wish to use your data for advertising purposes, we will inform you in detail about the respective procedures below. In doing so, we will also specify the criteria for the storage period.
2 Your rights
(1) You have the following rights against us regarding your personal data:
- Right to information (art. 15 DS-GVO),
- Right to rectification (art. 16 DS-GVO) or erasure (art. 17 DS-GVO),
- Right to restriction of processing (art. 18 DS-GVO),
- Right to withdraw consent (art. 7(3) DS-GVO).
- Right to object to processing (see par. 3).
- Right to information (art. 19 DS-GVO),
- Right to data portability (art. 20 DS-GVO).
(2) You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data by us (Art. 77 DS-GVO).
(3) When processing personal data for the performance of tasks in the public interest (Art. 6 (1) sentence 1 lit. e DS-GVO) or for the protection of legitimate interests (Art. 6 (1) sentence 1 lit. f DS-GVO), you may object to the processing of personal data concerning you at any time with effect for the future. In the event of an objection, we must refrain from further processing your data for the aforementioned purposes unless
- there are compelling legitimate grounds for the processing which override your interests, rights and freedoms; or
- the processing is necessary for the establishment, exercise or defence of legal claims.
You may object to the use of your data for direct marketing at any time with effect for the future; this also applies to profiling insofar as it relates to such direct marketing. In the event of an objection, we must refrain from further processing of your data for direct marketing purposes.
(4) To exercise your rights (with the exception of the right to lodge a complaint with a data protection supervisory authority), please contact the office mentioned in § 1(2).
3 Collection of personal data when you visit our website
(1) If you use our website for purely informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you call up our website, we collect the following data, which is technically necessary to display our website to you and to ensure its stability and security (legal basis is Art. 6 para. 1 lit. f DS-GVO):
- IP address
- Date and time of the request
- Time zone difference from Greenwich Mean Time (GMT)
- Request content (specific page)
- Access status/HTTP status code
- Amount of data transferred
- Website from which the request originated
- Browser
- Operating system and its interface
- Language and version of the browser software.
(2) In addition to the above-mentioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard disk in connection with the browser you use and through which the entity setting the cookie (in this case, us) receives certain information. Cookies cannot run programmes or transfer viruses to your computer. They serve to make the internet offer more user-friendly and effective in general (legal basis is Art. 6 para. 1 lit. f DS-GVO).
You can manage cookie settings in your browser and, among other things, refuse to accept cookies in general or for our website and delete cookies already placed. More information on this can be found in your browser's help menu.
(3) Use of cookies:
(a) This website uses the following types of cookies, the scope and functionality of which are explained below:
- Temporary cookies (for this purpose b).
- Persistent cookies (c).
(b) Persistent cookies are automatically deleted when you close the browser. These include, in particular, session cookies. These store a so-called session ID, which makes it possible to assign different requests from your browser to the common session. This allows your computer to be recognised when you revisit our website. Session cookies are deleted when you log out or close the browser.
(c) Persistent cookies are automatically deleted after a certain time, which may vary depending on the cookie. You can delete cookies at any time via your browser's security settings.
(d) You can adjust your browser settings to suit your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all the features of this website.
(e) We use cookies to identify you on subsequent visits if you have an account with us. Otherwise, you would have to log in again each time you visit.
4 Use of our online shop
(1) If you wish to place an order in our online shop, it is necessary that you provide us with the personal data we need to process your order and conclude the contract. Mandatory information required to process the contract is marked separately, other information is voluntary. We process the data you provide to process your order. To this end, we may transfer your payment details to our house bank. The legal basis for this is Article 6 para. 1 S. 1 lit. b DS-GVO.
On this basis, your payment data are also passed on to the respective payment service provider, depending on the payment method you have chosen. The payment service provider is responsible for your payment data. Information in particular on the responsible body of the payment service providers, the contact details of the payment service providers' data protection officers and the categories of personal data processed by the payment service providers can be found at the following internet address.
For payments via PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg): https://www.paypal.com/de/webapps/mpp/ua/privacy-full
For payments by direct bank transfer: Klarna Bank AB (publ) Sveavägen 46 111 34Stockholm Sweden): https://www.klarna.com/sofort/datenschutz/
(2) Under commercial and tax law, we are obliged to retain your address, payment and order data for a period of ten years. After two years, however, we restrict processing, i.e. your data is only used to comply with legal obligations.
(3) To prevent unauthorised access by third parties to your personal data, especially financial data, the order process is encrypted using TLS technology.
5 Use of Google Analytics
(1) This website uses Google Analytics, a web analytics service provided by Google Inc ("Google"). Google Analytics uses "cookies" (text files placed on your computer) to help the website analyse how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, in case IP anonymisation is activated on this website, your IP address will be pre-shortened by Google within the member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be forwarded to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to analyse your use of the website, to compile reports on website activity for the website operators and to provide other services associated with website and internet use.
(2) The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
(3) You may refuse the use of cookies by selecting the appropriate settings in your browser; however, please note that in this case you may not be able to use all the features of this website. You can also prevent the collection and processing of data generated by the cookie and related to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
(4) This website uses Google Analytics with the extension "_anonymizeIp()". This means that IP addresses are processed in a shortened form so that a personal reference can be excluded. Insofar as the data collected about you has a personal reference, it is thus immediately excluded and the personal data are thus immediately deleted.
(5) We use Google Analytics to analyse and regularly improve the use of our website. The statistics obtained enable us to improve our offer and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the US, Google has joined the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is Art. 6 para. 1 p. 1 lit. f DS-GVO.
(6) Information about the third-party provider: Google LLC, 1600 Amphitheatre Parkway,
Mountain View, CA 94043 USA Terms of Use: http://www.google.com/analytics/terms/de.html, Privacy Policy Overview: http://www.google.com/intl/de/analytics/learn/privacy.html, and Privacy Policy: http://www.google.de/intl/de/policies/privacy. Google is subject to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
6 User-defined Facebook target groups
(1) The website also uses the remarketing function "Custom Audiences" of Facebook Inc ("Facebook"). This allows interest-based ads ("Facebook Ads") to be shown to users of the website when they visit Facebook's social network or visit other websites that also use the procedure. In this way, we aim to show you advertising of interest to you in order to make our website more interesting to you.
(2) Through the marketing tools used, your browser automatically establishes a direct connection to the Facebook server. We have no influence on the scope and further use of the data collected by Facebook through the use of this tool and therefore inform you as follows: Through the integration of Facebook Custom Audiences, Facebook receives the information that you have visited the corresponding web page of our website or clicked on one of our advertisements. If you are registered with a Facebook service, Facebook can attribute the visit to your account. Even if you are not registered with Facebook or do not log in, the provider may find out and store your IP address and other identifying characteristics.
(3) Deactivation of the "Facebook Custom Audiences" feature is possible for logged-in users at https://www.facebook.com/settings/?tab=ads#_möglich, such as [please add].
(4) The legal basis for processing your data is Art. 6 para. 1 p. 1 lit. f DS-GVO.
(5) Third-party information: Facebook Inc, 1601 S California Ave, Palo Alto, California 94304, USA; http://www.facebook.com/policy.php; Facebook is subject to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The same applies to Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
More information can be found here: http://www.facebook.com/policy.php
More information on Facebook's processing of data can be found at https://www.facebook.com/about/privacy.
7 Integration of YouTube videos
(1) We have integrated YouTube videos into our online offer, which are stored at http://www.YouTube.com and can be played directly from our website. These are all integrated in "extended data protection mode", i.e. no data about you as a user is transmitted to YouTube if you do not play the videos. Only when you play the videos will the data mentioned in point 2 be transferred. We have no influence on this data transfer. This allows us to show you suitable videos directly on our website and thus make our website more user-friendly. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the DSGVO.
(2) By visiting the website, YouTube receives the information that you have visited the corresponding subpage of our website. In addition, the data mentioned in §3 of this statement is provided. This occurs regardless of whether YouTube provides a user account with which you are logged in or no user account exists. If you are logged into Google, your data will be assigned directly to your account. If you do not want your data to be linked to your YouTube profile, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for advertising purposes, market research and/or the needs-based design of its website. In particular, this evaluation is carried out (including for users who are not logged in) to deliver needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles and should contact YouTube to exercise this right.
(3) More information on the purpose and scope of data collection and processing by YouTube can be found in its privacy policy. There you will also find more information about your rights and setting options to protect your privacy: https://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the US and has joined the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
8 Newsletter
(1) With your consent, you can subscribe to our newsletter, through which we inform you about our current interesting offers. The advertised goods and services are mentioned in the declaration of consent.
(2) We use the so-called double opt-in procedure to subscribe you to our newsletter. This means that after your registration, we will send you an e-mail to the e-mail address you provided in which we ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your data will be blocked and automatically deleted after one month. In addition, we store the IP addresses used by you and the times of registration and confirmation. The purpose of this procedure is to prove your registration and clear up any misuse of your personal data.
(3) The only mandatory information for sending the newsletter is your e-mail address. After your confirmation, we will store your e-mail address to send you the newsletter. The legal basis is Article 6 para. 1 S. 1 lit. a DS-GVO.
(4) You can withdraw your consent to receive the newsletter at any time and unsubscribe from the newsletter. You can notify the withdrawal by clicking on the link in each newsletter e-mail, by sending an e-mail to support@lefreya.com or by sending a message to the contact details listed in the imprint.
9 Retention period
Unless we expressly state otherwise, we retain personal data for as long as there are statutory retention periods. After the expiry of the legal retention periods, we will delete the data if we no longer need it to fulfil our contractual obligations towards you or if we cannot invoke a legitimate interest to keep it.