Privacy policy

Privacy policy

Status: September 2022

 

Table of contents

I. Name and address of the controller
II. Contact details of the data protection officer
III. General information on data processing
IV. Rights of the data subject
V. Provision of the website and creation of log files
VI. Use of cookies
VII. Webshop
VIII. Payment options
IX. Shipping service provider
X. Newsletter
XI. Email contact
XII. Contact form
XIII. Application by mail
XIV. Hosting
XV. Company presences in social networks
XVI. Company presences in business-oriented networks
XVII. Geotargeting
XIII. Content Delivery Networks
XIX. Plugins used

 

I. Name and address of the controller

The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the Member States as well as other data protection provisions is the:

Senic GmbH
Pfuelstr. 5
10997 Berlin
Germany
+49 30 83794444
hi@museblocks.com
https://museblocks.com/

II. Contact details of the data protection officer

The data protection officer of the controller is:

DataCo GmbH
Dachauer Street 65
80335 Munich
Germany
+49 89 7400 45840
www.dataguard.de


III. General information on data processing

1. Scope of the processing of personal data

As a matter of principle, we only process personal data of our users insofar as this is necessary for the provision of a functional website as well as our contents and services. The processing of personal data of our users is regularly only carried out after the consent of the user. An exception applies in those cases in which obtaining prior consent is not possible for actual reasons and the processing of the data is required by legal regulations.

 

2. Legal basis for the processing of personal data

Insofar as we obtain the consent of the data subject for processing operations involving personal data, Article 6 (1) (a) GDPR serves as the legal basis.

When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Article 6 (1) (b) GDPR serves as the legal basis. This also applies to processing operations that are necessary for the implementation of pre-contractual measures.

Insofar as the processing of personal data is necessary for the fulfilment of a legal obligation to which our company is subject, Art. 6 (1)(c) GDPR serves as the legal basis.

In the event that vital interests of the data subject or another natural person make it necessary to process personal data, Article 6 (1) (d) GDPR serves as the legal basis.

If the processing is necessary to protect a legitimate interest of our company or a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the first-mentioned interest, Article 6 (1) (f) GDPR serves as the legal basis for the processing.

 

3. Data deletion and storage period

The personal data of the data subject shall be deleted or blocked as soon as the purpose of the storage ceases to apply. Storage may also take place if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a necessity for the continued storage of the data for the conclusion or fulfilment of a contract.

 

IV. Rights of the data subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

 

1. Right of access by the data subject

    You may request confirmation from the controller as to whether personal data concerning you are being processed by him.

    If there is such processing, you can request information from the controller about the following:

    • The purposes for which the personal data are processed;
    • The categories of personal data which are processed;
    • The recipients or categories of recipients to whom the personal data concerning you have been or will be disclosed;
    • The planned duration of the storage of the personal data relating to you or, if specific information on this is not possible, criteria for determining the storage duration;
    • The existence of a right to rectify or erase personal data concerning you, a right to have processing restricted by the controller or a right to object to such processing;
    • The existence of a right of appeal to a supervisory authority;
    • Any available information on the origin of the data if the personal data are not collected from the data subject;
    • The existence of automated decision-making, including profiling, pursuant to Article 22(1) and (4) of the GDPR and, at least in these cases, - meaningful information about the logic involved and the scope and intended effects of such processing for the data subject.

    You have the right to request information on whether personal data concerning you is transferred to a third country or to an international organisation. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 of the GDPR in connection with the transfer.

     

    2. Right of rectification

      You have a right of rectification and/or completion vis-à-vis the controller if the personal data processed concerning you are inaccurate or incomplete. The controller shall rectify the data without undue delay.

       

      3. Right to restriction of processing

        You may request the restriction of the processing of personal data concerning you under the following conditions:

        • If you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
        • The processing is unlawful and you refuse to erase the personal data and instead request the restriction of the use of the personal data;
        • The controller no longer needs the personal data for the purposes of processing, but you need them for the assertion, exercise or defence of legal claims, or
        • If you have objected to the processing pursuant to Art. 21 (1) GDPR and it has not yet been determined whether the legitimate grounds of the controller outweigh your grounds.

        Where the processing of personal data relating to you has been restricted, those data may be processed, with the exception of their storage, only with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of substantial public interest of the Union or of a Member State.

        If the restriction of processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.

         

        4. Right to erasure

        a) Obligation to delete

          You may request the controller to erase the personal data concerning you with undue delay and the controller is obliged to erase this data without delay if one of the following reasons applies:

          • The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
          • You revoke your consent on which the processing was based pursuant to Art. 6 (1) (a) or Art. 9 (2) (a) GDPR and there is no other legal basis for the processing.
          • You object to the processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21 (2) GDPR.
          • The personal data concerning you has been processed unlawfully.
          • The deletion of the personal data concerning you is necessary for compliance with a legal obligation under Union or Member State law to which the controller is subject.
          • The personal data concerning you was collected in relation to information society services offered pursuant to Art. 8 (1) GDPR.

           

          b) Information to third parties

            If the controller has made the personal data concerning you public and is obliged to erase it pursuant to Article 17(1) of the GDPR, it shall take reasonable steps, including technical measures, having regard to the available technology and the cost of implementation, to inform data controllers which process the personal data that you, as the data subject, have requested that they erase all links to, or copies or replications of, that personal data.

             

            c) Exceptions

              The right to erasure does not exist insofar as the processing is necessary

              • to exercise the right to freedom of expression and information.
              • for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
              • for reasons of public interest in the area of public health pursuant to Art. 9 (2) (h) and (i) and Art. 9 (3) GDPR;
              • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Article 89(1) of the GDPR, where the right referred to in section a) is likely to render impossible or seriously prejudice the achievement of the purposes of such processing, or
              • for the assertion, exercise or defence of legal claims.

               

              5. Right to information

                If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data concerning you have been disclosed, unless this proves impossible or involves a disproportionate effort.

                You have the right to be informed of these recipients by the controller.

                 

                6. Right to data portability

                  You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data has been provided, provided that

                  1. the processing is based on consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and
                  2. the processing is carried out with the aid of automated procedures.

                  In exercising this right, you also have the right to have the personal data concerning you transferred directly from one controller to another controller, insofar as this is technically feasible. This must not affect the freedoms and rights of other persons.

                  The right to data portability shall not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

                   

                  7. Right of objection

                    You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data relating to you which is carried out on the basis of Article 6 (1) (e) or (f) GDPR; this also applies to profiling based on these provisions.

                    The controller shall no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.

                    If the personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling, insofar as it is related to such direct marketing.

                    If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.

                    You have the possibility, in connection with the use of information society services, notwithstanding Directive 2002/58/EC, to exercise your right to object by means of automated procedures using technical specifications.

                     

                    8. Right to revoke the declaration of consent under data protection law

                      You have the right to revoke your declaration of consent under data protection law at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

                       

                      9. Automated decision in individual cases including profiling

                        You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision

                        1. is necessary for the conclusion or performance of a contract between you and the responsible person,
                        2. is authorised by legislation of the Union or the Member States to which the controller is subject, and that legislation contains adequate measures to safeguard your rights and freedoms and your legitimate interests, or
                        3. is done with your express consent.

                        However, these decisions must not be based on special categories of personal data pursuant to Art. 9(1) of the GDPR, unless Art. 9(2)(a) or (b) of the GDPR applies and appropriate measures have been taken to protect the rights and freedoms and your legitimate interests.

                        With regard to the cases referred to in a. and c. above, the controller shall take reasonable steps to safeguard the rights and freedoms of, and your legitimate interests, including at least the right to obtain the intervention of a person on the part of the controller, to express his or her point of view and to contest the decision.

                         

                        10. Right to complain to a supervisory authority

                          Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in the Member State of your residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

                          The supervisory authority to which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 GDPR.

                          A list of the supervisory authorities with local jurisdiction in Germany can be found on the website of the Federal Commissioner for Data Protection at the following link: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html

                           

                          V. Provision of the website and creation of log files

                          1. Description and scope of data processing

                            Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer.

                            The following data is collected:

                            • Information about the browser type and version used.
                            • The operating system of the user
                            • Device type
                            • Location data
                            • The IP address of the user
                            • Date and time of access
                            • Websites from which the user's system accesses our website.
                            • Websites that are accessed by the user's system via our website.

                            This data is stored in the log files of our system. This data is not stored together with other personal data of the user.

                             

                            2. Purpose of the data processing

                              The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session.

                              The storage in log files is done to ensure the functionality of the website. In addition, we use the data to optimise the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context.

                              These purposes are also our legitimate interest in data processing according to Art. 6 (1) (f) GDPR.

                               

                              3. Legal basis for the data processing

                                The legal basis for the temporary storage of the data and the log files is Art. 6 (1) (f) GDPR.

                                 

                                4. Duration of the storage

                                  The data shall be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.

                                  In the case of storage of the data in log files, this is the case after seven days at the latest . Storage beyond this period is possible. In this case, the IP addresses of the users are deleted or alienated so that an assignment of the calling client is no longer possible.

                                   

                                  5. Possibility of objection and removal

                                    The collection of data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. The user can object to this. Whether the objection is successful is to be determined within the framework of a balancing of interests.

                                     

                                    VI. Use of cookies

                                    1. Description and scope of data processing

                                      Our website uses cookies. Cookies are text files that are stored in the internet browser or by the internet browser on the user's computer system. When a user calls up a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again.

                                      We use cookies to make our website more user-friendly. Some elements of our website require that the calling browser can be identified even after a page change.

                                      The following data is stored and transmitted in the cookies:

                                      • Language settings
                                      • Article in shopping cart

                                      We also use cookies on our website that enable an analysis of the user's surfing behaviour.

                                      The following data can be transmitted in this way:

                                      • Search terms entered
                                      • Frequency of page views
                                      • Use of website functions

                                      The user data collected in this way is pseudonymised by technical precautions. Therefore, it is no longer possible to assign the data to the calling user without the inclusion of additional information. The data is not stored together with other personal data of the users.

                                       

                                      2. Purpose of the data processing

                                        The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognised even after a page change.

                                        We need cookies for the following applications:

                                        • Shopping cart
                                        • Adoption of language settings
                                        • Remembering search terms

                                        The user data collected through technically necessary cookies are not used to create user profiles.

                                        Analysis cookies are used to improve the quality of our website and its content. Through the analysis cookies, we learn how the website is used and can thus constantly optimise our offer.

                                         

                                        3. Legal basis for the data processing

                                          The provisions of the Telecommunications Telemedia Data Protection Act (TTDSG) are relevant for the storage of information in the end user's terminal equipment and/or access to information already stored in the end user's terminal equipment. If the setting and reading of cookies is technically necessary, this is done to ensure the functionality of our website. In this case, the storage of and access to cookies on your terminal equipment is carried out on the basis of § 25 (2) (2) TTDSG. This storage of and access to the information in your terminal equipment serves to facilitate your use of our website and to be able to offer you our services as you have requested. Some functions of our website also do not work without the use of these cookies and could therefore not be offered. The cookies are generally deleted after the session ends (e.g. logging out or closing the browser) or after the expiry of a specified duration. Information on different storage periods for cookies can be found in the following sections of this data protection declaration.

                                          Insofar as cookies are used that are not technically necessary, this is done on the basis of your express consent, which you can give via the cookie banner. The basis for storing and accessing information in this case is § 25 (1) TTDSG in conjunction with. Art. 6 (1) (a) and Art. 7 GDPR. You can revoke your consent at any time with effect for the future or subsequently grant it again by configuring your settings for cookies accordingly. Alternatively, you can prevent the storage of cookies by making the appropriate settings in your browser software. Please note that the browser settings you make only affect the browser you are using. If personal data is processed following the storage of and access to the information on your terminal equipment, the provisions of the GDPR are relevant. Information on this can be found in the following sections of this privacy policy.

                                           

                                          4. Duration of storage, possibility of objection and elimination

                                            The user has the possibility to revoke his consent to the processing of personal data at any time.

                                            Cookies are stored on the user's computer and transmitted from it to our site. Therefore, you as a user also have full control over the use of cookies. By changing the settings in your internet browser, you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all functions of the website to their full extent.

                                            The transmission of Flash cookies cannot be prevented via the settings of the browser, but by changing the settings of the Flash Player.

                                            If you use a Safari browser from version 12.1, cookies are automatically deleted after seven days. This also applies to opt-out cookies, which are set to prevent tracking measures.

                                             

                                            VII. Webshop

                                            We offer a webshop on our website. For this purpose, we use the Software as a Service (SaaS) rental shop system of a service provider commissioned by us.

                                            The name of our rental shop system and the name and address of the service provider are:

                                            Shopify of the provider Shopify International Limited, 1-2 Haddington Road, D04 XN32, Dublin, Ireland (hereinafter referred to as Shopify).

                                            You can find more information in the provider's privacy policy:
                                            https://www.shopify.de/legal/datenschutz

                                            The servers automatically collect and store information in so-called server log files, which your browser automatically transmits when you visit the website. The information stored is:

                                            • Browser type and version
                                            • Operating system used
                                            • Referrer URL
                                            • Host name of the accessing computer
                                            • Date and time of the server request
                                            • IP address

                                            This data is not merged with other data sources. The collection of this data is based on Art. 6 (1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website - for this purpose, the server log files must be collected.

                                            We have concluded an order processing contract with the relevant service provider, in which we oblige the relevant service provider to protect user data and not to disclose it to third parties.

                                            The server of the webshop is located in Canada. An adequacy decision of the European Commission exists for the transfer of your personal data to Canada. 

                                             

                                            VIII. Payment options

                                            1. Description and scope of data processing

                                              We offer our customers various payment options for processing their orders. For this purpose, we forward customers to the platform of the corresponding payment service provider depending on the payment option. After completion of the payment process, we receive the customers' payment data from the payment service providers or our house bank and process them in our systems for the purposes of invoicing and accounting.

                                               

                                              Payment by GiroPay

                                              It is possible to process the payment transaction with the payment service provider GiroPay.

                                              Based on online banking with PIN and TAN, GiroPay enables payment by online transfer. All you need to pay with GiroPay is an online banking current account at a participating bank or savings bank. After successful payment, the merchant receives a payment guarantee from the buyer's bank and can thus send you goods or services.

                                              When paying via GiroPay, your payment data will be transmitted to GiroPay GmbH, An der Welle 4, 60322 Frankfurt/Main, as part of the payment processing.

                                              In principle, GiroPay GmbH does not process any transaction data of the users. Transaction data is data that is required to carry out the payment initiated by the user.

                                              When users of the GiroPay services initiate a payment, GiroPay GmbH does not collect any transaction data in connection with this payment. In particular, GiroPay GmbH does not collect information on whether the user has initiated a payment, nor on the amount and the purpose of this payment. This information is generally only collected and further processed by the user's account-holding institution. The user's account-holding institution is the data controller in the sense of the GDPR with regard to data processing within the scope of the payment transaction.

                                              Only in individual cases and only at the request of the user does GiroPay GmbH collect transaction data to process queries about a payment made by the user (payment research) or in the event of user queries about technical problems.

                                              For more information on GiroPay's privacy policy, please click here:
                                              https://www.GiroPay.de/rechtliches/datenschutzerklaerung/

                                               

                                              Payment via Klarna

                                              It is possible to process the payment transaction with the payment service provider Klarna.

                                              Klarna is a payment service provider that enables purchase on account or payment by instalments.

                                              The European operating company of Klarna is Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden.

                                              If you select "purchase on account" or "purchase by instalment" as a payment option during the transaction via Klarna, your personal data will be automatically transmitted to Klarna. The personal data transmitted to Klarna is in particular the following

                                              • First name
                                              • Last name
                                              • Address
                                              • Date of birth
                                              • Gender
                                              • Email address
                                              • IP address
                                              • Telephone/mobile phone number
                                              • Bank details
                                              • Credit card number incl. expiry date and CVC code
                                              • Number of articles
                                              • Article number
                                              • Data on goods and/or services
                                              • Transaction amount and tax levies

                                              The purpose of the transmission of the data is in particular identity verification, payment administration and fraud prevention. The personal data exchanged between Klarna and us may be transmitted by Klarna to credit agencies.

                                              This transfer is for the purpose of checking identity and creditworthiness. Klarna may also pass on personal data to affiliated companies (Klarna Group) and service providers or subcontractors, insofar as this is necessary to fulfil contractual obligations or the data is to be processed on behalf.

                                              For more information on the processing of your data by Klarna, please refer to Klarna's privacy policy at:
                                              https://pay.amazon.com/de/help/201751600
                                              https://www.klarna.com/de/datenschutz/ can be accessed.

                                               

                                              Payment by credit card

                                              It is possible to complete the payment process by credit card.

                                              If you have selected payment by credit card, payment data will be passed on to payment service providers for payment processing. All payment service providers comply with the specifications of the "Payment Card Industry (PCI) Data Security Standards" and have been certified by an independent PCI Qualified Security Assessor.

                                              Within the framework of payment by credit card, the following data are regularly transmitted:

                                              • Purchase amount
                                              • Date and time of purchase
                                              • First name and surname
                                              • Address
                                              • Email address
                                              • Credit card number
                                              • Period of validity of the credit card
                                              • Security code (CVC)
                                              • IP address
                                              • Telephone number / mobile phone number

                                              Payment data is passed on to the following payment service providers:

                                              • Stripe Inc, 510 Townsend Street San Francisco, CA 94103, USA
                                              • Shopify Pay
                                              • Google Pay

                                              You can find more information on the data protection guidelines as well as revocation and removal options vis-à-vis the payment service providers here:

                                              Stripe: https://stripe.com/de/privacy 
                                              Shopify Pay: https://www.shopify.de/legal/datenschutz 
                                              Google Pay: https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice 
                                              Payment via PayPal

                                              It is possible to process the payment transaction with the payment service provider PayPal. In addition to a direct payment method, PayPal also offers purchase on account, direct debit, credit card and payment by instalment.

                                              The European operating company of PayPal is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg.

                                              If you choose PayPal as your payment method, your data required for the payment process will automatically be transmitted to PayPal.

                                              This involved the following data in particular:

                                              • Name
                                              • Address
                                              • Email address
                                              • Telephone / mobile phone number
                                              • IP address
                                              • Bank details
                                              • Card number
                                              • Validity date and CVC code
                                              • Number of articles
                                              • Article number
                                              • Data on goods and services
                                              • Transaction amount and tax levies
                                              • Information on previous purchasing behaviour

                                              The data transmitted to PayPal may be transferred by PayPal to credit agencies. The purpose of this transmission is to check identity and creditworthiness.

                                              PayPal may also share your data with third parties to the extent necessary to fulfil its contractual obligations or to process the data on its behalf. When transferring your personal data within companies affiliated with PayPal, the Binding Corporate Rules approved by the relevant supervisory authorities apply. You can find them here:
                                              https://www.paypal.com/de/webapps/mpp/ua/bcr
                                              Other data transfers may be based on contractual protections. For more information, please contact PayPal.

                                              All PayPal transactions are subject to PayPal's privacy policy. You can find this at:
                                              https://www.paypal.com/de/webapps/mpp/ua/privacy-full/.

                                               

                                              Payment by instant bank transfer

                                              There is the possibility of payment by instant bank transfer. In this case, the data will be collected by Sofort GmbH, Theresienhöhe 12, 80339 Munich.

                                              The data controller does not collect or store the data itself.

                                              By issuing an instant bank transfer, you instruct Sofort GmbH to carry out automated checks,

                                              whether your account covers the amount to be transferred (account coverage check), and any instant transfers made from your account in the last 30 days have been successfully completed,

                                              and, after positive verification, to transmit the transfer order approved by you to your bank in electronic form and to inform us, as the payee selected by you (online provider), about the successful setting of the transfer.

                                              For this purpose, Sofort GmbH requires the IBAN as well as PIN and TAN of your online banking account. During the ordering process you will be automatically redirected to the secure payment form of Sofort GmbH.

                                              Immediately afterwards you will receive the confirmation of the transaction. We will then receive the transfer credit directly.

                                              Anyone who has an activated online banking account with PIN/TAN procedure can use instant bank transfer as a payment method.

                                              Please note that a few banks do not yet support payment by Sofortüberweisung.

                                              You can find more information on this via the following link:
                                              https://www.klarna.com/sofort/.

                                              For more information on the stored data, please visit https://www.klarna.com/sofort/#cq-0.

                                               

                                              Payment in advance

                                              If you have chosen payment in advance, we will not process any data other than the data transmitted by your bank. This data is only used to check the receipt of payment.

                                               

                                              2. Purpose of the data processing

                                                The transmission of payment data to payment service providers serves to process the payment, e.g., when you purchase a product and/or use a service.

                                                 

                                                3. Legal basis for the data processing

                                                  The legal basis for the data processing is Art. 6 (1) (b) GDPR, as the processing of the data is necessary for the execution of the concluded purchase contract.

                                                   

                                                  4. Duration of the storage

                                                    All payment data as well as data on possible chargebacks will only be stored for as long as they are needed for payment processing and possible processing of chargebacks and debt collection as well as for combating misuse.

                                                    Furthermore, payment data may be stored beyond this if and as long as this is necessary to comply with statutory retention periods or to prosecute a specific case of misuse.

                                                    Your personal data will be deleted upon expiry of the statutory retention obligations, i.e. after 10 years at the latest.

                                                     

                                                    5. Possibility of objection and removal

                                                      You can object to the processing of your payment data at any time by notifying the responsible person or the payment service provider used. However, the payment service provider used may still be entitled to process your payment data if and as long as this is necessary for the contractual processing of payments.

                                                       

                                                      IX. Shipping service provider

                                                      1. Description and scope of data processing

                                                        If you order products or services on our website for which a shipping service provider is used for delivery, you will receive your order and shipping confirmation via your email address as well as, depending on the respective shipping service provider, the notification that your shipment has arrived and/or the notification for the package announcement as well as possible delivery options.

                                                        The data will be transmitted to the following service providers:

                                                        • DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany
                                                        • ISN GmbH

                                                        The data transmitted are regularly:

                                                        • Name
                                                        • Address
                                                        • Email address

                                                         

                                                        2. Purpose of the data processing

                                                          The purpose of processing the personal data is to enable shipping service providers to inform recipients about the progress of the shipment by email and thus increase the likelihood of a successful delivery.

                                                           

                                                          3. Legal basis for the data processing

                                                            The legal basis for the transmission of the email address to the respective shipping service provider as well as its use is consent pursuant to Art. 6 (1) (a) GDPR.

                                                            The legal basis for the transmission of your address data (first name, last name, address) to the respective shipping service provider is Art. 6 (1) (b) GDPR, as the processing of the data is necessary for the processing of the concluded purchase contract. 

                                                             

                                                            4. Duration of the storage

                                                              The transmitted data will be deleted from the respective shipping service provider once the package has been delivered.

                                                               

                                                              5. Possibility of objection and removal

                                                                The notification service by the dispatch service provider can be cancelled by the user concerned at any time. For this purpose, a corresponding opt-out link is included in every email.

                                                                 

                                                                X. Newsletter

                                                                1. Description and scope of data processing

                                                                  It is possible to subscribe to a free newsletter. When registering for the newsletter, the following data is transmitted to us from the input mask:

                                                                  • Email address

                                                                  For the processing of the data, your consent is obtained during the registration process and reference is made to this privacy policy.

                                                                  If you purchase goods or services on our website and enter your email address, this may subsequently be used by us to send you a newsletter. In such a case, only direct advertising for our own similar goods or services will be sent via the newsletter.

                                                                  No data is passed on to third parties in connection with the data processing for sending newsletters. The data is used exclusively for sending the newsletter.

                                                                   

                                                                  2. Purpose of the data processing

                                                                    The collection of the user's email address is used to deliver the newsletter.

                                                                    The collection of other personal data during the registration process serves to prevent misuse of the services or the email address used.

                                                                     

                                                                    3. Legal basis for the data processing

                                                                      The legal basis for the processing of the data after registration for the newsletter by the user is the following In the event of the user's consent, Art. 6 (1) (a) GDPR.

                                                                       

                                                                      4. Duration of the storage

                                                                        The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. The user's email address is therefore stored for as long as the subscription to the newsletter is active.

                                                                        The other personal data collected during the registration process is usually deleted after a period of seven days. deleted after a period of seven days.

                                                                         

                                                                        5. Possibility of objection and removal

                                                                          The subscription to the newsletter can be cancelled by the user concerned at any time. For this purpose, a corresponding link can be found in each newsletter.

                                                                          This also enables the revocation of consent to the storage of personal data collected during the registration process.

                                                                           

                                                                          XI. Email contact

                                                                          1. Description and scope of data processing

                                                                            On our website, it is possible to contact us via the email address provided. In this case, the user's personal data transmitted with the email will be stored.

                                                                            The data is used exclusively for processing the conversation.

                                                                             

                                                                            2. Purpose of the data processing

                                                                              In the case of contact by email, this also constitutes the necessary legitimate interest in processing the data.

                                                                               

                                                                              3. Legal basis for the data processing

                                                                                The legal basis for the processing of data transmitted in the course of sending an email is Art. 6 (1) (f) GDPR. Our legitimate interest is to optimally answer your enquiry that you send by email. If the email contact aims at the conclusion of a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

                                                                                 

                                                                                4. Duration of the storage

                                                                                  The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by email, this is the case when the respective conversation with the user has ended. The conversation is terminated when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

                                                                                  The additional personal data collected during the sending process will be deleted at the latest after a period of seven days. after a period of seven days at the latest.

                                                                                   

                                                                                  5. Possibility of objection and removal

                                                                                    If the user contacts us by email, he or she can object to the storage of his or her personal data at any time. In such a case, the conversation cannot be continued.

                                                                                    All personal data stored in the course of contacting us will be deleted in this case.

                                                                                     

                                                                                    XII Contact form

                                                                                    1. Description and scope of data processing

                                                                                      Our website contains a contact form that can be used for electronic contact. If a user uses this option, the data entered in the input mask is transmitted to us and stored.

                                                                                      The following data is stored at the time the message is sent:

                                                                                      • Email address
                                                                                      • Name
                                                                                      • First name
                                                                                      • IP address of the calling computer
                                                                                      • Date and time of registration
                                                                                      • Other data transmitted by the user as a message.

                                                                                      Alternatively, it is possible to contact us via the email address provided. In this case, the user's personal data transmitted with the email will be stored.

                                                                                      The data is used exclusively for processing the conversation.

                                                                                       

                                                                                      2. Purpose of the data processing

                                                                                        The processing of the personal data from the input mask serves us solely to process the contact. In the case of contact via the contact form, this also constitutes the necessary legitimate interest in processing the data.

                                                                                        The other personal data processed during the submission process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.

                                                                                         

                                                                                        3. Legal basis for the data processing

                                                                                          The legal basis for processing the data transmitted in the course of sending the contact form is Art. 6 (1) (f) GDPR. Our legitimate interest is to optimally answer your enquiry that you send to us via the contact form. If the purpose of contacting you via the contact form is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

                                                                                           

                                                                                          4. Duration of the storage

                                                                                            The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and those sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when the circumstances indicate that the matter in question has been conclusively clarified.

                                                                                            The additional personal data collected during the sending process will be deleted at the latest after a period of thirty days. deleted after a period of thirty days at the latest.

                                                                                             

                                                                                            5. Possibility of objection and removal

                                                                                              If the user contacts us via the contact form, he or she can object to the storage of his or her personal data at any time. In such a case, the conversation cannot be continued.

                                                                                              All personal data stored in the course of contacting us will be deleted in this case.

                                                                                               

                                                                                              XIII. Application by email

                                                                                              1. Scope of the processing of personal data

                                                                                                You can send us your application by email. We will collect your email address and the data you provide in the email:

                                                                                                • Salutation
                                                                                                • First name
                                                                                                • Name
                                                                                                • Email address
                                                                                                • Curriculum vitae
                                                                                                • Voluntary information of the applicant

                                                                                                 

                                                                                                2. Purpose of the data processing

                                                                                                  The processing of personal data from your application email is solely for the purpose of processing your application.

                                                                                                   

                                                                                                  3. Legal basis for the data processing

                                                                                                    The legal basis for the processing of your data is the initiation of a contract at the request of the data subject, Art. 6 (1) (b) GDPR and § 26 (1) BDSG.

                                                                                                     

                                                                                                    4. Duration of the storage

                                                                                                      After completion of the application process, the data will be stored for up to six months. Your data will be deleted after the six months at the latest. In the event of a legal obligation, the data will be stored within the framework of the applicable provisions.

                                                                                                      5. Possibility of opposition

                                                                                                        The applicant has the possibility to object to the processing of personal data at any time. In such a case, the application can no longer be considered.

                                                                                                        All personal data stored in the course of electronic applications will be deleted in this case.

                                                                                                         

                                                                                                        XIV. Hosting


                                                                                                        The website is hosted on servers of a service provider commissioned by us.

                                                                                                        Our service provider is:

                                                                                                         

                                                                                                        Shopify

                                                                                                        The servers automatically collect and store information in so-called server log files, which your browser automatically transmits when you visit the website. The information stored is:

                                                                                                        • Browser type and version
                                                                                                        • Operating system used
                                                                                                        • Referrer URL
                                                                                                        • Host name of the accessing computer
                                                                                                        • Date and time of the server request
                                                                                                        • IP address

                                                                                                        This data is not merged with other data sources. The collection of this data is based on Art. 6 (1) (f) GDPR. Our legitimate interest for processing this data is to present our website without errors and to optimise its functions.

                                                                                                        We have concluded an order processing contract with the relevant service provider, in which we oblige the relevant service provider to protect user data and not to disclose it to third parties.

                                                                                                        The website server is located in Canada. The transfer of your personal data to Canada is subject to an adequacy decision by the European Commission. 

                                                                                                         

                                                                                                        XV. Company presences in social networks

                                                                                                        Instagram:

                                                                                                        Instagram, Part of Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour, Dublin 2 Ireland


                                                                                                        On our company page, we provide information and offer Instagram users the opportunity to communicate. If you carry out an action on our Instagram company page (e.g., comments, posts, likes, etc.), it may be that you make personal data (e.g., clear name or photo of your user profile) public. However, as we generally or to a large extent have no influence on the processing of your personal data by Instagram, the company jointly responsible for the Senic GmbH corporate presence, we cannot provide any binding information on the purpose and scope of the processing of your data.

                                                                                                        Our corporate presence in social networks is used for communication and information exchange with (potential) customers. In particular, we use the corporate presence for:

                                                                                                        • Exhibiting and selling products

                                                                                                        In doing so, the publications about the company's presence can contain the following contents:

                                                                                                        • Information about products
                                                                                                        • Raffles
                                                                                                        • Advertising
                                                                                                        • Customer contact

                                                                                                        Every user is free to publish personal data through activities.

                                                                                                        Insofar as we process your personal data to evaluate your online behaviour, offer you competitions or conduct lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 (1) (a), Art. 7 GDPR. The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) (f) GDPR. Our legitimate interest here is to answer your enquiry in the best possible way or to be able to provide the requested information. If the aim of contacting you is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

                                                                                                        The data generated by the company website is not stored in our own systems.


                                                                                                        You can object at any time to the processing of your personal data that we collect in the course of your use of our Instagram corporate presence and assert your data subject rights as set out in IV. of this data protection declaration. To do so, send us an informal email to hi@museblocks.com. You can find more information about the processing of your personal data by Instagram and the corresponding objection options here:

                                                                                                        Instagram: https://help.instagram.com/519522125107875

                                                                                                         

                                                                                                        Twitter:

                                                                                                        Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland

                                                                                                        To ensure appropriate safeguards for the protection of the transfer and processing of personal data outside the EU, so-called standard contractual clauses (Art. 46 (2) (c) GDPR) have been concluded with Twitter.


                                                                                                        On our company website, we provide information and offer Twitter users the opportunity to communicate. If you carry out an action on our Twitter company website (e.g. comments, posts, likes, etc.), it may be that you make personal data (e.g. clear name or photo of your user profile) public. However, as we generally or to a large extent have no influence on the processing of your personal data by Twitter, the company jointly responsible for the Senic GmbH corporate presence, we cannot provide any binding information on the purpose and scope of the processing of your data.

                                                                                                        Our corporate presence in social networks is used for communication and information exchange with (potential) customers. In particular, we use the corporate presence for:

                                                                                                        • Exhibiting and selling products

                                                                                                        In doing so, the publications about the company's presence can contain the following contents:

                                                                                                        • Information about products
                                                                                                        • Raffles
                                                                                                        • Advertising
                                                                                                        • Customer contact

                                                                                                        Every user is free to publish personal data through activities.

                                                                                                        Insofar as we process your personal data in order to evaluate your online behaviour, offer you competitions or conduct lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 (1) (a), Art. 7 GDPR. The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) (f) GDPR. Our legitimate interest here is to answer your enquiry in the best possible way or to be able to provide the requested information. If the aim of contacting you is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

                                                                                                        The data generated by the company website is not stored in our own systems.

                                                                                                        For the processing of your personal data in third countries, we have provided appropriate safeguards in the form of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR. We have concluded these standard contractual clauses with the above-mentioned social network providers. A copy of the standard contractual clauses can be requested from us.


                                                                                                        You can object at any time to the processing of your personal data that we collect in the course of your use of our Twitter corporate presence and assert your data subject rights as set out in IV. of this data protection declaration. To do so, send us an informal email to hi@museblocks.com. \n You can find more information about the processing of your personal data by Twitter and the corresponding objection options here:

                                                                                                        Twitter: https://twitter.com/de/privacy

                                                                                                         

                                                                                                        YouTube:

                                                                                                        YouTube LLC, 901 Cherry Ave, San Bruno, CA 94066, United States

                                                                                                        To ensure appropriate guarantees for the protection of the transfer and processing of personal data outside the EU, so-called standard contractual clauses (Art. 46 (2) (c) GDPR) have been concluded with Google.


                                                                                                        On our company page, we provide information and offer YouTube users the opportunity to communicate. If you carry out an action on our YouTube corporate site (e.g. comments, posts, likes, etc.), it may be that you make personal data (e.g. real name or photo of your user profile) public. However, as we generally or to a large extent have no influence on the processing of your personal data by YouTube, the company jointly responsible for the Senic GmbH corporate presence, we cannot provide any binding information on the purpose and scope of the processing of your data.

                                                                                                        Our corporate presence in social networks is used for communication and information exchange with (potential) customers. In particular, we use the corporate presence for:

                                                                                                        • Exhibiting and selling products

                                                                                                        In doing so, the publications about the company's presence can contain the following contents:

                                                                                                        • Information about products
                                                                                                        • Raffles
                                                                                                        • Advertising
                                                                                                        • Customer contact

                                                                                                        Every user is free to publish personal data through activities.

                                                                                                        Insofar as we process your personal data in order to evaluate your online behaviour, offer you competitions or conduct lead campaigns, this is done on the basis of your express declaration of consent, Art. 6 (1) (a), Art. 7 GDPR. The legal basis for processing personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) (f) GDPR. Our legitimate interest here is to answer your enquiry in the best possible way or to be able to provide the requested information. If the aim of contacting you is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

                                                                                                        The data generated by the company website is not stored in our own systems.

                                                                                                        For the processing of your personal data in third countries, we have provided appropriate safeguards in the form of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR. We have concluded these standard contractual clauses with the above-mentioned social network providers. A copy of the standard contractual clauses can be requested from us.


                                                                                                        You can object at any time to the processing of your personal data that we collect in the course of your use of our YouTube corporate presence and assert your data subject rights as stated under IV. of this data protection declaration. To do so, send us an email to hi@museblocks.com. You can find more information about the processing of your personal data by YouTube and the corresponding objection options here:

                                                                                                        YouTube: https://policies.google.com/privacy?gl=DE&hl=de

                                                                                                         

                                                                                                        XVI. company presences in business-oriented networks

                                                                                                        1. Scope of data processing

                                                                                                          We use the possibility of company presences on professional networks. We maintain a company presence on the following professional networks:

                                                                                                          LinkedIn:

                                                                                                          LinkedIn, Unlimited Company Wilton Place, Dublin 2, Ireland

                                                                                                          To ensure appropriate guarantees for the protection of the transfer and processing of personal data outside the EU, so-called standard contractual clauses (Art. 46 (2) (c) GDPR) have been concluded with LinkedIn. A copy of the standard contractual clauses can be requested from us.

                                                                                                          On our site, we provide information and offer users the opportunity to communicate.

                                                                                                          The company website is used for applications, information/PR and active sourcing.

                                                                                                          We do not have any information on the processing of your personal data by the companies jointly responsible for the corporate presence. You can find more information on this in the privacy policy of:

                                                                                                          LinkedIn:

                                                                                                          https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv

                                                                                                          If you carry out an action on our company website (e.g., comments, posts, likes, etc.), you may make personal data (e.g. clear name or photo of your user profile) public.

                                                                                                           

                                                                                                          2. Legal basis for the data processing

                                                                                                            The legal basis for the processing of personal data for the purpose of communicating with customers and interested parties is Art. 6 (1) (f) GDPR. Our legitimate interest here is to answer your enquiry in the best possible way or to be able to provide the requested information. If the aim of contacting you is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

                                                                                                             

                                                                                                            3. Purpose of the data processing

                                                                                                              Our company website serves to inform users about our services. In doing so, every user is free to publish personal data through activities.

                                                                                                               

                                                                                                              4. Duration of the storage

                                                                                                                We store your activities and personal data published via our corporate website until you object to the processing. In addition, we comply with the statutory retention periods.

                                                                                                                 

                                                                                                                5. Possibility of objection and removal

                                                                                                                  You can object at any time to the processing of your personal data that we collect in the course of your use of our company website and assert your data subject rights as stated under IV. of this data protection declaration. To do so, send us an informal email to the email address stated in this data protection declaration.

                                                                                                                  You can find more information on objection and removal options here:

                                                                                                                  LinkedIn:

                                                                                                                  https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv

                                                                                                                   

                                                                                                                  XIX Plugins used

                                                                                                                  We use plugins for various purposes. The plugins used are listed below:


                                                                                                                  Service

                                                                                                                  Provider

                                                                                                                  Third country transfer (country)

                                                                                                                  Purpose of the data processing

                                                                                                                  Legal basis of the data processing

                                                                                                                  Information on data protection and appropriate safeguards for third country transfers

                                                                                                                  MailChimp

                                                                                                                  The Rocket Science Group, LLC

                                                                                                                  512 Means Street, Suite 404, Atlanta, GA 30318, USA

                                                                                                                  Newsletter dispatch

                                                                                                                  Art. 6 (1) (a) GDPR

                                                                                                                  https://MailChimp.com/legal/privacy/

                                                                                                                  https://mailchimp.com/de/legal/data-processing-addendum/

                                                                                                                  https://mailchimp.com/de/help/mailchimp-european-data-transfers/


                                                                                                                  Name

                                                                                                                  Provider

                                                                                                                  Category

                                                                                                                  Type

                                                                                                                  Retention

                                                                                                                  Source

                                                                                                                  Function

                                                                                                                  _orig_referrer

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Tracks landing pages.

                                                                                                                  _y

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  1 year(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics.

                                                                                                                  _s

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  30 minute(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics.

                                                                                                                  _shopify_y

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  1 year(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics.

                                                                                                                  _shopify_s

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  30 minute(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics.

                                                                                                                  VISITOR_INFO1_LIVE

                                                                                                                  Google

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  180 day(s)

                                                                                                                  Detected

                                                                                                                  A cookie that YouTubes sets that measures your bandwidth to determine whether you get the new player interface or the old.

                                                                                                                  _shopify_sa_t

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  30 minute(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics relating to marketing & referrals.

                                                                                                                  _landing_page

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Tracks landing pages.

                                                                                                                  _shopify_sa_p

                                                                                                                  Shopify

                                                                                                                  Functionality

                                                                                                                  3rd party

                                                                                                                  30 minute(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics relating to marketing & referrals.

                                                                                                                  secure_customer_sig

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  1 year(s)

                                                                                                                  Detected

                                                                                                                  Used in connection with customer login.

                                                                                                                  keep_alive

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  30 minute(s)

                                                                                                                  Detected

                                                                                                                  Used in connection with buyer localization.

                                                                                                                  localization

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  1 year(s)

                                                                                                                  Detected

                                                                                                                  Shopify store localization

                                                                                                                  _shopify_tm

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  3rd party

                                                                                                                  30 minute(s)

                                                                                                                  Detected

                                                                                                                  Used for managing customer privacy settings.

                                                                                                                  _shopify_tw

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  3rd party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Used for managing customer privacy settings.

                                                                                                                  shopify_pay_redirect

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  60 minute(s)

                                                                                                                  Detected

                                                                                                                  The cookie is necessary for the secure checkout and payment function on the website. This function is provided by shopify.com.

                                                                                                                  _shopify_m

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  3rd party

                                                                                                                  1 year(s)

                                                                                                                  Detected

                                                                                                                  Used for managing customer privacy settings.

                                                                                                                  cart_currency

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  The cookie is necessary for the secure checkout and payment function on the website. This function is provided by shopify.com.

                                                                                                                  cart

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Necessary for the shopping cart functionality on the website.

                                                                                                                  cart_ts

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Used in connection with checkout.

                                                                                                                  cart_ver

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Used in connection with shopping cart.

                                                                                                                  _tracking_consent

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  3rd party

                                                                                                                  1 year(s)

                                                                                                                  Detected

                                                                                                                  Tracking preferences.

                                                                                                                  cart_sig

                                                                                                                  Shopify

                                                                                                                  Strictly necessary

                                                                                                                  1st party

                                                                                                                  14 day(s)

                                                                                                                  Detected

                                                                                                                  Shopify analytics.

                                                                                                                  _dd_s

                                                                                                                  Shopify

                                                                                                                  Unclassified

                                                                                                                  1st party

                                                                                                                  15 minute(s)

                                                                                                                  Detected

                                                                                                                  Cookie used to group all events generated from a unique user session across multiple pages. It contains the current session ID, whether the session is excluded due to sampling, and the expiration date of the session. The cookie is extended for an extra 15 minutes every time the user interacts with the website, up to the maximum user session duration (4 hours).



                                                                                                                  1. Duration of storage

                                                                                                                  Your personal information will be retained for as long as is necessary to fulfil the purposes described in this privacy policy or as required by law, for example for tax and accounting purposes.

                                                                                                                   

                                                                                                                    2. Transfer to third countries

                                                                                                                    When using plugins marked with third country transfer or USA, personal data may be transferred to servers in third countries outside the EU, such as the USA. The legal basis for this transfer is consent according to Art. 6 (1) (a) GDPR. The United States of America does not offer an adequate level of data protection based on a decision of the European Union. The main risk of the transfer lies in the obligation of the plug-in providers to make user data accessible to American authorities under certain circumstances. An order processing agreement with standard contractual clauses is currently in place with all providers in order to make the third-country transfer as data protection-friendly and secure as possible. Adjustments to the ECJ ruling of 16.07.2020 (Schrems II, ref. C-311/18) including additional security measures are currently being sought by us. A copy of the standard contractual clauses can be requested by sending us an informal email. 

                                                                                                                     

                                                                                                                    3. Possibility of revocation and removal

                                                                                                                    You have the right to revoke your declaration of consent under data protection law at any time. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

                                                                                                                    You can prevent the collection as well as the processing of your personal data by the respective providers by preventing the storage of third-party cookies on your computer, using the "Do Not Track" function of a supporting browser, deactivating the execution of script code in your browser or installing a script blocker such as NoScript (https://noscript.net/) or Ghostery (https://www.ghostery.com) in your browser.


                                                                                                                    This privacy policy was created with the support of DataGuard.