Data Protection
PRIVACY POLICY
§ 1 General
We process your personal data (e.g. title, name, address, email address, telephone number, bank details, credit card number) solely in accordance with the provisions of German data protection law and the data protection law of the European Union (EU). The following provisions inform you not only about the purposes of processing, recipients, legal bases and retention periods, but also about your rights and the data controller responsible for processing your data. This privacy policy applies only to our websites. If you are redirected to other websites via links on our pages, please check those sites for information on how they handle your data.
§ 2 Data processing for the fulfilment of a contract
(1) Purpose of processing
The personal data you provide to us during the ordering process is necessary for the conclusion of a contract with us. You are not obliged to provide your personal data. However, without your address, we cannot send you the goods.
For some payment methods, we require the necessary payment details in order to pass them on to a payment service provider commissioned by us. The processing of the data you enter during the ordering process is therefore carried out for the purpose of fulfilling the contract.
If you send us an enquiry by email, via a contact form, etc. prior to the conclusion of the contract, we process the data received in this way to carry out pre-contractual measures and, for example, to answer your questions about our products.
If you open a customer account, your data (in particular your name, address, payment method, email address and password) will be processed for the purposes of registration and setting up a customer login. The stored data enables you to shop with us more quickly and view your past orders at any time. You can delete your account by sending us a message or using the delete function.
(2) Legal basis
The legal basis for this processing is Article 6(1)(b) of the GDPR.
(3) Categories of recipients
Payment service providers, delivery service providers, hosting providers, where applicable, the merchandise management system, and, where applicable, suppliers (drop shipping).
(4) Retention period
We store the data required for contract fulfilment until the expiry of the statutory warranty periods and, where applicable, contractual guarantee periods.
We retain the data required under commercial and tax law for the periods specified by law, typically ten years (see Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO)).
Data processed for the purpose of carrying out pre-contractual measures is deleted as soon as the measures have been carried out and it is clear that a contract will not be concluded.
§ 3 Comments
(1) Purpose of processing
You have the option to post a comment. Your data (e.g. name/pseudonym, email address, website) will then be processed solely for the purpose of publishing your comment.
(2) Legal basis
The legal basis for this processing is Article 6(1)(f) of the GDPR.
(3) Legitimate interest
Our legitimate interest is the public exchange of user opinions on specific topics and products. Publication serves, amongst other things, to promote transparency and the formation of opinions. Your interest in data protection is safeguarded, as you can post your comment under a pseudonym.
(4) Retention period
No specific retention period is envisaged. You may request the deletion of your comment at any time.
(5) RIGHT TO OBJECT
You have the right to object at any time, on grounds relating to your particular situation, to the processing of data carried out on the basis of Article 6(1)(f) of the GDPR which does not serve the purposes of direct marketing.
In the case of direct marketing, however, you may object to the processing at any time without giving reasons.
§ 4 Shop Review
(1) Purpose of processing
If you decide to review our service, we will process your email address, order number and order date in order to send you a request for review confirmation and a final review request, as well as to associate your review with your order and prevent review abuse.
(2) Legal basis
This processing is carried out on the basis of our legitimate interests in improving our services and preventing misuse of reviews in accordance with Article 6(1)(f) of the GDPR.
(3) Recipients Reviews.io
(4) Retention period
Your data will be stored for as long as the shop review is displayed on our website.
§ 5 Further information
(1) Purpose of processing
If you decide to review our service, we will process your email address, order number and order date in order to send you a request to confirm your review and a final review request, as well as to attribute your review and prevent review abuse.
(2) Legal basis
This processing is carried out on the basis of our legitimate interests in improving our services and preventing review abuse, in accordance with Article 6(1)(f) of the GDPR.
(3) Recipients
reviews.io
(4) Retention period
Your data will be stored for as long as the shop review is displayed on our website.
§ 6 PayPal Transactions
Please note that all PayPal transactions are subject to the PayPal Privacy Policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
§ 7 Information on cookies
(1) Purpose of processing
Technically necessary cookies are used on this website. These are small text files that are stored on your computer system by your internet browser. These cookies enable you, for example, to add multiple products to a shopping basket.
(2) Legal basis
The legal basis for this processing is Article 6(1)(f) of the GDPR.
(3) Legitimate interest
Our legitimate interest is to ensure the functionality of our website. The user data collected via technically necessary cookies is not used to create user profiles. This safeguards your interest in data protection.
(4) Retention period
Technically necessary cookies are usually deleted when you close your browser. Persistent cookies have varying lifespans, ranging from a few minutes to several years.
(5) RIGHT TO OBJECT
If you do not wish these cookies to be stored, please disable the acceptance of these cookies in your web browser. However, this may result in some features of our website not functioning properly. You can also delete persistently stored cookies at any time via your browser.
§ 8 Web advertising service with Google AdSense
(1) Purpose of processing
Google AdSense, a web advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”), is used on these pages to display advertisements (text adverts, banners, etc.). To this end, your browser stores cookies (small text files) on your hard drive. These cookies are used by Google to personalise content and adverts, to provide social media features and to analyse traffic to our website. Device identifiers are used in apps. In addition, information about your use of our website is shared with partners for social media, advertising and analytics. These partners combine this information with other data that you have provided to them or that they have collected in the course of your use of their services.
(2) Legal basis
The legal basis for this processing is Article 6(1)(a) of the GDPR.
(3) Categories of recipients
Google LLC and its partner companies.
(4) Transfer to a third country
Google Ireland Limited is an affiliate of Google LLC. Google LLC is based in the USA (1600 Amphitheatre Parkway, Mountain View, CA 94043). The basis for the transfer of personal data from the EU to the USA is the EU-US Privacy Shield.
(5) Retention period
Your personal data will only be stored for as long as you have consented to its processing.
(6) Withdrawal of consent
You may withdraw your consent at any time by contacting the data controller.
§ 9 Your rights as a data subject
(1) Purpose of processing
Technically necessary cookies are used on this website. These are small text files that are stored on your computer system by your internet browser. These cookies enable you, for example, to add multiple products to a shopping basket.
(2) Legal basis
The legal basis for this processing is Article 6(1)(f) of the GDPR.
(3) Legitimate interest
Our legitimate interest is to ensure the functionality of our website. The user data collected via technically necessary cookies is not used to create user profiles. This safeguards your interest in data protection.
(4) Retention period
Technically necessary cookies are usually deleted when you close your browser. Persistent cookies have varying lifespans, ranging from a few minutes to several years.
(5) RIGHT TO OBJECT
If you do not wish these cookies to be stored, please disable the acceptance of these cookies in your web browser. However, this may result in some features of our website not functioning properly. You can also delete persistently stored cookies at any time via your browser.
§ 8 Your rights as a data subject
If your personal data is being processed, you are a data subject within the meaning of the GDPR and you are entitled to the following rights vis-à-vis us as the data controller:
1. Right of access
You may, pursuant to Article 15 of the GDPR, request access to your personal data processed by us.
2. Right to rectification
If the information concerning you is no longer accurate, you may request rectification in accordance with Article 16 of the GDPR. If your data is incomplete, you may request that it be completed.
3. Right to erasure
: You may request the erasure of your personal data under the conditions set out in Article 17 of the GDPR.
4. Right to restriction of processing
: You have the right, in accordance with the provisions of Article 18 of the GDPR, to request a restriction on the processing of the data concerning you.
5. Right to data portability
Under Article 20 of the GDPR, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another controller.
6. Right to withdraw consent
to data processing
Under Article 7(3) of the GDPR, you have the right to withdraw your consent to data processing at any time. This does not affect the lawfulness of processing carried out on the basis of your consent prior to its withdrawal.
7. Right to lodge a complaint with a supervisory authority
If you consider that the processing of your personal data infringes the GDPR, you have the right, under Article 77 of the GDPR, to lodge a complaint with a supervisory authority (in particular in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred).
Please also note your right to object under Article 21 of the GDPR:
a) General:
a reasoned objection is required
If the processing of your personal data is carried out
- to safeguard our overriding legitimate interests (legal basis under Article 6(1)(f) of the GDPR) or
- in the public interest (legal basis under Article 6(1)(e) of the GDPR),
you have the right to object to the processing at any time on grounds relating to your particular situation; this also applies to profiling based on the provisions of the GDPR.
In the event of an objection, we will no longer process the personal data concerning you, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
b) Special case of direct marketing:
a simple objection is sufficient
If your personal data is processed for the purposes of direct marketing, you have the right to object to this processing at any time and without giving reasons; this also applies to profiling insofar as it is related to such direct marketing.
If you object to processing for the purposes of direct marketing, the personal data concerning you will no longer be processed for these purposes.
Data
controller:
aYoh GmbH
Plauener
Straße
163–165
13053 Berlin
Telephone: +493027581630
nihao@ayoh.de