1 General information
1.1 What is personal data?
Personal data is information that discloses or may disclose the identity of the user. We adhere to the principle of
data avoidance. As far as possible, we refrain from collecting personal data.
1.2 Handling of personal data
Personal data is used exclusively for the establishment of the contract, content design, execution or processing of the contractual relationship (Art. 6 I b GDPR). Beyond this, personal data will only be processed if we have received your consent to do so (Art. 6 I a GDPR). They will not be passed on to third parties. The data will only be passed on to the shipping company commissioned with the delivery for the fulfilment of the contract, insofar as this is necessary for the delivery of ordered goods. In order to process payments, the necessary payment data will be passed on to the credit institution commissioned with the payment and, if applicable, to the commissioned and selected payment service provider. Your personal data will only be processed within the EU.
1.3 Usage data
General technical information is collected when you visit the website. This includes the IP address used, time, duration of the visit, browser type and, if applicable, the originating page. For technical reasons, this usage data is registered in a log file and can be used and stored for the purpose of analysing the statistics of this website. This usage data is not linked to your other personal data.
1.4 Registration data
Registration is required to make full use of the functions of our website. The registration data is collected through your corresponding entries and used for the specifically stated purpose in accordance with your consent (Art. 6 I a GDPR).
1.5 Duration of storage
We only store your personal data after the end of the purpose for which the data was collected for as long as this is required by law (in particular tax law).
2 Your rights
2.1 Information
You can request information from us as to whether we process your personal data and, if this is the case, you have a right to information about this personal data and to the further information specified in Art. 15 GDPR.
2.2 Right to rectification
You have the right to rectification of inaccurate personal data concerning you and may request the completion of incomplete personal data in accordance with Art. 16 GDPR.
2.3 Right to erasure
You have the right to obtain from us the erasure of personal data concerning you without undue delay. We are obliged to erase this data immediately, in particular if one of the following reasons applies
-Your personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
-You withdraw your consent on which the processing of your data was based and there is no other legal basis for the processing.
-Your data has been processed unlawfully.
The right to erasure does not apply if your personal data is required for the establishment, exercise or defence of our legal claims.
2.4 Right to restriction of processing
You have the right to demand that we restrict the processing of your personal data if -Your personal data are no longer necessary for the purposes for which they were collected or otherwise processed. -the processing is unlawful and you oppose the erasure and request the restriction of use instead
-we no longer need the data, but you need it for the establishment, exercise or defence of legal claims, you have objected to the processing of your data and it is not yet clear whether our legitimate grounds override your grounds.
2.5 Right to data portability
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you have the right to transmit those data to another controller without hindrance from us, where the processing is based on consent or on a contract and the processing is carried out by automated means.
2.6 Right of cancellation
If the processing of your personal data is based on consent, you have the right to withdraw this consent at any time.
2.7 General information and right of appeal
The exercise of your above rights is generally free of charge for you. You have the right to lodge complaints directly with the supervisory authority responsible for us, the state data protection officer.
3 Data security
3.1 Data security
All data on our website is protected by technical and organisational measures against loss, destruction, access, modification and dissemination.
3.2 Sessions and cookies
To operate the website, we may use cookies or server-side sessions in which data can be stored. Cookies are also used, for example, to greet you personally with your member name. Cookies are files that are stored on your hard drive by a website in order to automatically recognise this computer the next time you visit the website and thus adapt the use of the website to you. Some of the cookies used are deleted again at the end of the browser session. These are so-called session cookies. Other cookies remain on your end device and enable the browser to be recognised when you visit our website at a later date (persistent cookies). You can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. Please note that you may not be able to use some functions of this website if cookies are deactivated. We ensure that no personal data is taken from sessions or through cookies and that cookies are only used if this is necessary for the website. Thus, the balancing of interests shows that there are no overriding interests on your part (Art. 6 I f GDPR).
4. newsletter
If you subscribe to our newsletter, we will use the data required for this or separately provided by you to send you our e-mail newsletter on a regular basis. Unsubscribing from the newsletter is possible at any time and can be done either by sending us a message via the contact options provided in the legal notice or via the link provided for this purpose in the newsletter. We use the services of the third-party provider Mailchimp for our newsletter (see 5.3).
4.1 Consent to the receipt of advertising newsletters by email
Purpose of data processing/legal basis: You have the option of subscribing to one of our newsletters via various channels (this website, competition pages, promotions, in writing at an event). The legal basis for data processing in the context of sending newsletters is your consent in accordance with Art. 6 para. 1 a) GDPR. The purpose of data processing in the context of ordering the newsletter is to inform newsletter subscribers about goods, competitions, promotions, surveys and services. After submitting the order form, you will receive an email from us with a confirmation link (double opt-in procedure). If you click on the link contained therein within 7 days, you are registered for the respective newsletter.
By confirming your registration, you confirm your consent to the processing of your data for the purposes stated in the declaration of consent. Unfortunately, we cannot send you a newsletter without your consent or activation of the confirmation link.
If you register for the free newsletter, you agree that Grafschaft Manufaktur GmbH may process your e-mail address and the country in which you live as mandatory information in order to be able to send you the newsletter relevant to your country by e-mail and to inform you in this newsletter about goods, competitions, promotions, surveys and services of Grafschaft Manufaktur GmbH. You also agree that we may store the information about where you started the newsletter order process (for example, from the contact form, a competition form or directly from the newsletter registration page) in order to optimise the newsletter order options. If you voluntarily provide optional information about yourself when registering (title, first name, surname), you consent to us using this data to add a personalised salutation to your newsletter.
You can revoke your consent to receive the newsletter at any time with effect for the future by clicking on the corresponding unsubscribe link in one of the newsletters or by sending an email to newsletter@grafschaft-manufaktur.de. You will then no longer receive newsletters.
Recipients/categories of recipients: The data collected as part of the newsletter order is generally only accessed by the department within Grafschaft Manufaktur GmbH that is responsible for processing and supporting the newsletter dispatch. If external processors are used to send the newsletter, they are contractually obliged in accordance with Art. 28 GDPR and have been checked accordingly to ensure that suitable organisational and technical security measures are in place.
Storage period/criteria for determining the storage period: If you revoke your consent to receive one or more different newsletters, the data in your subscriber profile will be blocked immediately and then deleted. As a result, you will no longer receive any personalised advertising (e.g. personalised newsletters, info mails, etc.).
5 Third-party services
5.1 Google Analytics
This website uses Google Analytics, a web analysis service from Google, operated by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”) and collects and stores data via this web analysis service, from which user profiles are created using pseudonyms. The usage profiles created in this way are used to evaluate visitor behavior in order to design and improve the offer presented on this website in line with requirements. Google Analytics uses so-called “cookies”, small text files which are stored on your computer and which enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there.
However, if IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The user profiles kept under a pseudonym are also not merged with the personal data about the user without the express and separately declared consent of the user. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of the data generated by the cookie and related to your use of the website data (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de). You can view Google’s privacy policy at http://www.google.de/intl/de/policies/privacy/. You can find more information on terms of use and data protection at http://www.google.com/analytics/terms/de.html or at http://www.google.com/intl/de/analytics/privacyoverview.html. Please note that on this website Google Analytics has been extended by the code “anonymizeIp” in order to ensure an anonymized collection of IP addresses (so-called IP masking).
5.2 Social media links and social sharing
We have our own social media pages for the third-party providers that can be reached via links from this website. Using the links will take you to the respective websites of the third-party providers (e.g. Facebook, Twitter, Google+) and you can also share our content. As soon as you have accessed the third-party provider’s page, you are in the area of responsibility of the respective third-party provider, so that their privacy policy or their declarations on the use of data also apply. We have no influence on this, but we recommend that you log out of the respective third-party provider before using a corresponding link to avoid unnecessary data transfer, so that usage profiles cannot be created by the third-party provider simply by using the link.
5.3 Use of MailChimp
Our email communication is processed using “MailChimp”, a platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. Your email address and the other data described in this notice will be stored on MailChimp’s servers in the USA. MailChimp uses this information to send and analyze the emails on our behalf. Furthermore, MailChimp may, according to its own information, use this data to optimize or improve its own services, e.g. for the technical optimization of the dispatch and presentation of the newsletter or for economic purposes in order to determine from which countries the recipients come. MailChimp does not use the data of our mail recipients to write to them itself or to pass it on to third parties. MailChimp is certified under the US-EU data protection agreement “Privacy Shield” and thus undertakes to comply with EU data protection regulations. Furthermore, we have concluded a “Data Processing Agreement” with MailChimp. This is a contract in which MailChimp undertakes to protect the data of our users, to process it on our behalf in accordance with its data protection regulations and, in particular, not to pass it on to third parties. You can view MailChimp’s privacy policy at https://mailchimp.com/legal/privacy/.
6 Affiliate links and advertising
We place affiliate and advertising links or banners to certain third-party providers on our website. With these links/banners, we generate income (reimbursement of advertising costs) if purchases are made from the respective third-party provider via this link/banner or if their site is accessed. The third-party provider may use cookies in order to identify the origin of the orders or visits. However, this has no effect on the use of our website and in particular does not constitute an obligation to purchase. Legal affiliate and advertising links or banners are only intended to facilitate your purchase. In addition, the respective data protection provisions of the third-party providers apply.
7. competitions
Purpose of data processing/legal basis: You have the opportunity to take part in various competitions on our website, from our newsletter. Unless otherwise specified in the special data protection principles of the respective competition or unless you have given us further express consent, the personal data you provide to us as part of your participation in the competition will be used exclusively for the purpose of processing the competition (determining the winner, notifying the winner, sending the prize). If necessary, the winners will be announced anonymously on Instagram or Facebook (e.g. “Peter L. from Munich won”). The legal basis for data processing in the context of competitions is generally Art. 6 para. 1 b) EU GDPR in the event of your participation. In the event of a declaration of consent going beyond this in the context of a competition, Art. 6 para. 1 a) GDPR is the legal basis for data processing based on consent. If you have given your consent in the context of a competition, you have the option of withdrawing this consent at any time with effect for the future. In these cases, further details are regulated in the special data protection principles of the competition concerned.
Recipients/categories of recipients: The data collected in the context of competitions are generally only accessed by the department within Grafschaft Dienstleistungen that carried out the specific competition. Data will only be passed on to third parties if this is absolutely necessary for the execution of the competition or the sending of the prize (e.g. prize dispatch by the sponsor of a competition) or if you have given us your express consent to do so.
Storage period/criteria for determining the storage period: After the end of the competition and the announcement of the winners, the participants’ data will be deleted. In the case of non-cash prizes, the winners’ data will be stored for one year after the winners are announced in order to be able to process the prize if necessary.
8. contacting us
To contact us regarding data protection, you are welcome to use the following contact options. Controller within the meaning of the GDPR:
Grafschaft Manufaktur GmbH
Alolfstr. 15
61350 Bad Homburg v.d.H.
E-mail: kontakt@grafschaft-manufaktur.de