Data Protection Declaration
Unless stated otherwise below, the provision of your personal data is neither legally nor contractually obligatory, nor required for conclusion of a contract. You are not obliged to provide your data. Not providing it will have no consequences. This only applies insofar as the processing procedures below do not state otherwise. “Personal data” is any information relating to an identified or identifiable natural person.
Server log files
You can use our websites without submitting personal data. Every time our website is accessed, user data is transferred to us or our web host/IT service provider by your internet browser and stored in server log files. Stored data may include the name of the page accessed, date and time of access, IP address, amount of data transferred and the requesting provider. Processing is based on Article 6(1)(f) GDPR due to our legitimate interests in ensuring the smooth operation of our website and improving our services.
Contact
Controller
Contact us at any time. Controller for data processing is: Thomas Merk, Weinstraße 1C, 82140 Olching, Germany, Phone: +49 151 28955773, Email: tom@secretofeden.de
Proactive contact by e-mail
If you proactively contact us by e-mail, we collect your personal data (name, e-mail address, message text) only to the extent you provide it. The purpose is to handle and respond to your request. If the initial contact serves to implement pre-contractual measures (e.g. advice, quote) or concerns a contract already concluded with us, processing takes place on the basis of Article 6(1)(b) GDPR. Otherwise, processing occurs on the basis of Article 6(1)(f) GDPR (our overriding legitimate interest in handling and responding to your request). In that case, on grounds relating to your particular situation, you have the right to object at any time to such processing under Article 6(1)(f) GDPR. We will only use your e-mail address to process your request and will then delete your data in compliance with statutory retention periods, unless you have consented to further processing and use.
Use of address validation from Google Maps API
We use address validation from Google Ireland Limited (Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland; “Google”). The purpose is to check your entries in our address forms in real time for input/spelling errors and to complete missing data. Your entered address data is transmitted to Google, stored and analysed there. Information transmitted may include: postal addresses (country, city, postcode, street, house number), e-mail address, phone number. Data may also be transferred to the USA. For the USA, an EU adequacy decision exists (Trans-Atlantic Data Privacy Framework, “TADPF”); Google is certified. Processing is based on Article 6(1)(f) GDPR (overriding legitimate interest in a correct data basis for fulfilment of our contractual obligations). You may object at any time on grounds relating to your particular situation. Data is processed separately by Google (not merged with other data) and deleted after the status of the entered data has been determined, at the latest after 30 days. More info: Google Maps Platform Terms of Service, Google Privacy Policy.
WhatsApp Business
If you communicate with us via WhatsApp, we use WhatsApp Business provided by WhatsApp Ireland Limited (4 Grand Canal Square, Dublin 2, Ireland). Outside the EEA: WhatsApp Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. We process your WhatsApp-registered mobile number, your name (if provided) and any additional data you send, solely to handle your request. The device we use stores only contacts who have reached out to us via WhatsApp. No disclosure of personal data to WhatsApp occurs unless you have already consented to this toward WhatsApp. WhatsApp transfers data to servers of Meta Platforms Inc. in the USA (TADPF certification). Legal bases: Article 6(1)(b) GDPR (pre-contractual/contractual requests) or Article 6(1)(f) GDPR (legitimate interest in quick communication; right to object). Further information: Terms, Privacy.
Customer account & orders
Customer account
When you open a customer account, we process your personal data as specified there to improve your shopping experience and simplify order processing. Legal basis: Article 6(1)(a) GDPR (consent). You can withdraw your consent at any time; your account will then be deleted.
Collection, processing and transfer of personal data in orders
We process your data only as necessary to fulfil and handle your order and queries (Article 6(1)(b) GDPR). Provision is required to conclude a contract. Data may be shared with shipping companies, dropshipping/fulfilment providers, payment service providers, order-processing providers and IT service providers — strictly limited to what is necessary and in compliance with law.
Reviews & advertising
Use of the Trusted Shops rating system (Trustbadge)
We use the rating system of Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne, Germany (‘Trusted Shops') on our website. Trusted Shops and we are jointly responsible for the collection of your data when using the service and the transmission of this data to Trusted Shops. The basis for this is an agreement between us and Trusted Shops on the joint processing of personal data. Accordingly, we and Trusted Shops are equally responsible for the fulfilment of the obligations under the GDPR, in particular for the fulfilment of the information obligations pursuant to Art. 13, 14 GDPR and for the granting of the rights of data subjects pursuant to Art. 15 - 21 GDPR. You can find more information on this at FAQ on Trusted Shops Data Protection. Trusted Shops enables us to obtain customer reviews and display them on our website via the ‘Trustbadge' in order to provide you with an insight into the quality of our services. After placing an order, you can receive an invitation to submit a review from us or Trusted Shops and then submit a review. The following data will be processed by us or Trusted Shops: E-mail address, order information (order total, order number, product purchased if applicable). This data may also be used for the purpose of verifying your rating. When you visit our website and display the Trustbadge, the following data is also processed by us or Trusted Shops: Your IP address, date and time of access, amount of data transferred and the requesting provider. The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR with your consent, provided that you have expressly consented to the transfer of your data and the receipt of the evaluation request. You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. Further information on data protection at Trusted Shops can be found at: Trusted Shops privacy.
Review reminder
With your consent (Article 6(1)(a) GDPR) we may send you a one-off review reminder by e-mail after your order. You can withdraw your consent at any time via the link in the e-mail or by contacting us.
Newsletters
With your consent (Article 6(1)(a) GDPR) we use your e-mail address to send newsletters. You can unsubscribe at any time via the link in the newsletter or by contacting us. We may store your e-mail in a blacklist to prevent future sends based on Article 6(1)(f) GDPR (legitimate interest); you have the right to object.
Direct marketing by e-mail
We may use your e-mail address obtained in connection with a purchase for electronic marketing of our own similar goods/services unless you have objected (Article 6(1)(f) GDPR). You can object at any time using the contact details in the imprint or via the link in the marketing e-mail.
Availability notifications
On request, we send a one-time e-mail when an item becomes available (Article 6(1)(a) GDPR; you can withdraw your consent at any time).
Merchandise management
For contractual processing we use a merchandise management system (order processing). Personal data collected during ordering is transmitted to Pickware GmbH, Goebelstr. 21, 64293 Darmstadt (Article 6(1)(b) GDPR).
Cookies
Our website uses cookies. Cookies are small text files stored by the browser on your device and allow unique identification of the browser. You can choose to be notified before cookies are set, accept cookies in individual cases, prevent storage and delete stored cookies at any time. Guidance:
Technically necessary cookies
Unless otherwise stated below, we only use technically necessary cookies to make our offering more user-friendly, effective and secure. Some functions cannot be provided without cookies (browser recognition). The use of cookies or comparable technologies is based on Art. 25(2) TDDDG. Processing of personal data is based on Article 6(1)(f) GDPR (our legitimate interest in optimal functionality and a user-friendly design). You have the right to object at any time on grounds relating to your particular situation.
Use of the Shopware Cookie Consent Manager
We use the Cookie Consent Manager from shopware AG (Ebbinghoff 10, D-48624 Schöppingen; “Shopware”) to obtain and document consents (Article 6(1)(c) GDPR). Cookies may be used and user information incl. IP address transmitted to Shopware. No disclosure to other third parties. More info: Shopware Privacy Policy.
Analysis & advertising tracking
Use of Google Analytics 4 (incl. Google Signals)
We use Google Analytics 4 (Google Ireland Limited) to analyse this website and its visitors for marketing and advertising purposes. Data collected may include: IP address (shortened within the EU/EEA), date/time, click paths, device and browser info, pages visited, referrer URL, location data, purchase activity. Google may combine this with other Google data (e.g. search history, accounts, cross-device usage). Google uses cookies, browser storage and pixels. Use only with your consent (Art. 25(1) sentence 1 TDDDG in conjunction with Article 6(1)(a) GDPR). You can withdraw your consent at any time.
We also use Google Signals for cross-device tracking, if you enabled “personalised advertising” in your Google account and linked your devices. Reports available to us contain only aggregated data. You can disable personalised ads in your Google account to prevent cross-device collection. More info: Control your ad experience, [UA] Activate Google signals [Legacy].
Information generated about your use of this website is usually transferred to a Google server in the USA and stored there (TADPF in place). Further info: Partner sites, Google Privacy Policy.
Use of shopware Analytics
We use “shopware Analytics” by shopware AG. Shopware and we are joint controllers; shopware is responsible in particular for data subject rights (Articles 15–21 GDPR). Data processed may include: customer group, pages visited, click paths, date/time, device info (resolution, density, OS), referrer URL, browser info, locale, search queries, time zone. Cookies or comparable technologies are used. Use only with consent (Art. 25(1) sentence 1 TDDDG in conjunction with Article 6(1)(a) GDPR). More info: shopware Analytics docs.
Use of Google Ads conversion tracking
We use Google Ads (conversion tracking). After clicking our Google ad, a conversion cookie (limited validity, no personal data) is set to compile anonymous conversion statistics. Data may be transmitted to Google LLC in the USA (TADPF). Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: Google Privacy.
Use of Google AdSense
We use Google AdSense (Google Ireland Limited) to rent ad space and serve interest-based ads. Google uses cookies; data may be transferred to the USA (TADPF). Google may pass data to third parties where required by law or for processing on its behalf. According to Google, your IP address will not be merged with other Google data. Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: Technologies & ads, Privacy.
Plug-ins
Use of social plug-ins
Social plug-ins are integrated only with your explicit consent. Your IP address and information about which of our pages you visited are transmitted to the provider’s servers (even without registration/login). If you are logged in to a social network, the information may be assigned to your profile. Legal basis: Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR (consent).
Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland)
Joint control with Meta per the Controller Addendum. Possible transfer to the USA (TADPF). Info: Facebook Privacy Policy.
Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland)
Help & privacy: Instagram Data Policy. Possible transfer to the USA (TADPF).
Use of Google reCAPTCHA
We use Google reCAPTCHA (Google Ireland Limited) to distinguish human input from automated processing. Your input, IP address and any other data required by Google for reCAPTCHA are transmitted to Google (processing within the EU and potentially in the USA; TADPF). Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: reCAPTCHA, Privacy.
Use of Google Maps
We embed Google Maps (Google Ireland Limited) to display interactive maps. Google collects, processes and uses data of visitors to pages with embedded maps; possible transfer to the USA (TADPF). Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: Google Privacy Policy.
Use of YouTube
We embed YouTube videos (Google Ireland Limited) using the “enhanced privacy mode”. Only when you play a video is information transmitted to YouTube (possible transfer to the USA; TADPF). Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: YouTube Privacy Policy.
Using Vimeo
We embed videos from Vimeo Inc., 555 West 18th Street, New York, NY 10011, USA. When accessing such pages, your IP address and the pages visited are transmitted to Vimeo; if logged in, assignment to your account is possible. Possible transfer to the USA (TADPF). Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: Vimeo Privacy Policy.
Use of Adobe Fonts
We use Adobe Fonts (Adobe Systems Software Ireland Limited) for consistent font display. When the page is accessed, a connection to Adobe servers is established; your IP address and browser/OS information are processed. Possible transfers to the USA (TADPF) and to India (no adequacy decision). Use only with consent (Art. 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Info: Adobe Privacy, Adobe Fonts privacy.
Data subject rights & storage duration
Duration of storage
After contractual processing has been completed, data is first stored for the duration of the warranty period, then according to statutory retention periods (especially tax and commercial law), and deleted after expiry unless you have consented to further processing.
Rights of the data subject
Where the legal requirements are met, you have the rights under Articles 15–20 GDPR: access, rectification, erasure, restriction of processing, data portability. You also have the right to object to processing based on Article 6(1)(f) GDPR, and to processing for direct marketing (Article 21(1) GDPR).
Right to complain to a supervisory authority
You have the right to complain to a supervisory authority under Article 77 GDPR. For us, the competent authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Tel.: +49 981 1800930
Fax: +49 981 180093800
Email: poststelle@lda.bayern.de
Right to object
Where processing is based on our legitimate interests under Article 6(1)(f) GDPR, you have the right, on grounds relating to your particular situation, to object at any time with effect for the future. We will then no longer process the personal data unless we can demonstrate compelling legitimate grounds or the processing is for the establishment, exercise or defence of legal claims. If personal data is processed for direct advertising, you can object at any time; we will then no longer process the data for this purpose.
Last update: 22.10.2024