Privacy policy
Data controller:
Bernd Lange
Markgrafenstrasse 125/6
79211 Denzlingen
Email: info@womomatratze.de
Phone: 01714906059
We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information on how we handle your data.
1. Access data and Hosting
You can visit our websites without providing any personal information. Each time a webpage is accessed, the web server automatically stores certain information in a server log file, such as the name of the requested file, your IP address, date and time of access, amount of data transferred, and the requesting provider (access data). This access data is evaluated solely for the purpose of ensuring the smooth operation of the site and improving our services. This serves to safeguard our legitimate interests, which outweigh any other interests, in presenting our offerings correctly in accordance with Art. 6 para. 1 lit. f GDPR.
2. Data processing for contract processing and contacting
2.1 Data processing for contract processing
For the purpose of contract processing (including inquiries and processing of any existing warranty and liability claims as well as any legal obligation to update) pursuant to Art. 6 para. 1 lit. b GDPR, we collect personal data when you voluntarily provide it to us during your order. Mandatory fields are marked as such because in these cases we need the data to process the contract and cannot complete the order without it. The types of data collected are apparent from the respective input forms.
For more information on the processing of your data, especially regarding its transfer to our service providers for the purpose of order processing, payment, and shipping, please refer to the following sections of this privacy policy. After complete processing of the contract, your data will be restricted for further processing and deleted after the expiration of the tax and commercial retention periods pursuant to Art. 6 para. 1 lit. c GDPR, unless you have expressly consented to further use of your data pursuant to Art. 6 para. 1 lit. a GDPR or we reserve the right to use data beyond that which is legally permitted and about which we inform you in this statement.
2.2 Customer account
If you have given your consent pursuant to Art. 6 para. 1 lit. a GDPR by choosing to open a customer account, we use your data for the purpose of opening a customer account and storing your data for further future orders on our website. Deleting your customer account is possible at any time and can be done either by sending a message to the contact information described in this privacy policy or via a designated function in the customer account. After deleting your customer account, your data will be deleted unless you have expressly consented to further use of your data pursuant to Art. 6 para. 1 lit. a GDPR or we reserve the right to use data beyond that which is legally permitted and about which we inform you in this statement.
2.3 Contact
As part of customer communication, we collect personal data to process your inquiries pursuant to Art. 6 para. 1 lit. b GDPR if you voluntarily provide it to us when contacting us (e.g., via contact form or email). Mandatory fields are marked as such because in these cases we need the data to process your contact request. The types of data collected are apparent from the respective input forms. After completing your request, your data will be deleted unless you have expressly consented to further use of your data pursuant to Art. 6 para. 1 lit. a GDPR or we reserve the right to use data beyond that which is legally permitted and about which we inform you in this statement.
3. Data processing for shipping
For the purpose of contract fulfillment pursuant to Art. 6 para. 1 lit. b GDPR, we pass on your data to the shipping service provider commissioned with the delivery, to the extent necessary for the delivery of ordered goods.
The same applies to the transfer of data to our manufacturers or wholesalers in cases where they handle the shipping for us (drop shipping). These are considered shipping service providers within the meaning of this privacy policy.
Data transfer to shipping service providers for the purpose of shipping notification
If you have given us your express consent during or after your order, we will, based on this, pursuant to Art. 6 para. 1 lit. a GDPR, forward your email address and telephone number to the selected shipping service provider so that they can contact you for the purpose of delivery notification or coordination.
You can revoke your consent at any time by sending a message to the contact information described in this privacy policy or directly to the shipping service provider at the contact address listed below. After revocation, we will delete the data you provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use data beyond that which is legally permitted and about which we inform you in this statement.
General Logistics Systems Germany GmbH & Co. OHG
GLS Germany-Straße 1 - 7
DE-36286 Neuenstein
Germany
4. Data processing for payment processing
In processing payments in our online shop, we collaborate with the following partners: technical service providers, banks, payment service providers.
4.1 Data processing for transaction processing
Depending on the selected payment method, we provide the necessary data for processing the payment transaction to our technical service providers, who act as data processors for us, or to the designated banks or the selected payment service provider, as far as necessary for payment processing. This is for the fulfillment of the contract in accordance with Art. 6 para. 1 lit. b GDPR. In some cases, the payment service providers collect the necessary payment transaction data themselves, for example, on their own website or through a technical integration in the ordering process. The privacy policy of the respective payment service provider applies in these cases.
For questions regarding our partners for payment processing and the basis of our collaboration with them, please contact the contact information described in this privacy policy.
4.2 Data processing for fraud prevention and optimization of our payment processes
If necessary, we provide our service providers with additional data, which they use together with the data necessary for payment processing as our data processors for the purpose of fraud prevention and optimization of our payment processes (e.g., invoicing, processing of disputed payments, support for accounting). This serves, according to Art. 6 para. 1 lit. f GDPR, to safeguard our legitimate interests in preventing fraud and ensuring efficient payment management through a balance of interests.
5. Cookies and other technologies
General information
To make your visit to our website attractive and to enable the use of certain functions, we use technologies including so-called cookies on various pages. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e., after closing your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies).
Privacy protection on end devices
When using our online offering, we use technologies that are absolutely necessary to provide the expressly desired telemedia service. The storage of information on your device or access to information already stored on your device does not require consent in this regard.
For non-essential functions, the storage of information on your device or access to information already stored on your device requires your consent. We would like to point out that if you do not give your consent, certain parts of the website may not be fully functional. Your consents remain valid until you adjust or reset the respective settings on your device.
Subsequent data processing through cookies and other technologies
We use such technologies that are necessary for the use of certain functions of our website (e.g., shopping cart function). Through these technologies, IP address, time of visit, device and browser information, and information about your use of our website (e.g., information about the contents of the shopping cart) are collected and processed. This serves, within the framework of a balance of interests, our legitimate interests in an optimized presentation of our offer in accordance with Art. 6 para. 1 lit. f GDPR.
The cookie settings for your browser can be found at the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
If you have consented to the use of the technologies in accordance with Art. 6 para. 1 S. 1 lit. a GDPR, you can revoke your consent at any time by sending a message to the contact information described in the privacy policy.
6. Social Media
6.1 Social Buttons from Facebook (by Meta), Instagram (by Meta)
Social buttons from social networks are used on our website. These are merely embedded as HTML links in the page, so no connection is made to the servers of the respective provider when our website is accessed. Clicking on one of the buttons opens the website of the respective social network in a new window of your browser. There, you can, for example, click on the like or share button.
6.2 Our online presence on Facebook (by Meta), Instagram (by Meta), Youtube
If you have given your consent pursuant to Art. 6 para. 1 S. 1 lit. a GDPR to the respective social media operator, your data will be automatically collected and stored for market research and advertising purposes when you visit our online presences on the social media platforms mentioned above, from which usage profiles are created using pseudonyms. These profiles can be used, for example, to display advertisements within and outside the platforms that presumably correspond to your interests. Cookies are usually used for this purpose. For detailed information on the processing and use of data by the respective social media operator, as well as a contact option and your related rights and privacy settings, please refer to the privacy notices linked below. If you still need assistance in this regard, you can contact us.
Facebook (by Meta) is provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland about your use of our online presence on Facebook (by Meta) is usually transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. Data processing in the context of visiting a Facebook (by Meta) fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. Further information (Insights data information) can be found here.
Our service providers are located and/or use servers in the following countries, for which the European Commission has established an adequate level of data protection by decision: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
There is a European Commission decision on an adequate level of data protection for the USA as a basis for third-country transfers, provided that the respective service provider is certified. Certification exists.
Our service providers are located and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
There is no adequacy decision by the European Commission for these countries. Our cooperation with them is based on these safeguards: Standard Contractual Clauses of the European Commission.
Instagram (by Meta) is provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland about your use of our online presence on Instagram is usually transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Menlo Park, California 94025, USA and stored there. Data processing in the context of visiting an Instagram (by Meta) fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. Further information (Insights data information) can be found here.
Our service providers are located and/or use servers in the following countries, for which the European Commission has established an adequate level of data protection by decision: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.
There is a European Commission decision on an adequate level of data protection for the USA as a basis for third-country transfers, provided that the respective service provider is certified. Certification exists.
Our service providers are located and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
For these countries, there is no adequacy decision by the European Commission. Our cooperation with them is based on these safeguards: Standard Contractual Clauses of the European Commission.
YouTube is provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information automatically collected by Google about your use of our online presence on YouTube is usually transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there.
Our service providers are located and/or use servers in countries outside the EU and EEA, for which the European Commission has established an adequate level of data protection.
Our service providers are located and/or use servers in countries outside the EU and EEA. For these countries, there is no adequacy decision by the European Commission. Our cooperation with them is based on Standard Contractual Clauses of the European Commission.
7. Contact Options and Your Rights
7.1 Your Rights
As a data subject, you have the following rights:
- according to Art. 15 GDPR, the right to obtain information about your personal data processed by us to the extent specified therein;
- according to Art. 16 GDPR, the right to demand without delay the correction of incorrect or completion of your personal data stored by us;
- according to Art. 17 GDPR, the right to demand the deletion of your personal data stored by us, unless
- exercising the right to freedom of expression and information;
- to fulfill a legal obligation;
- for reasons of public interest or
- for the assertion, exercise or defense of legal claims is required;
- according to Art. 18 GDPR, the right to request the restriction of processing of your personal data, to the extent that
- the accuracy of the data is contested by you;
- the processing is unlawful, but you oppose the erasure of the data;
- we no longer need the data, but you require it for the establishment, exercise, or defense of legal claims, or
- you have objected to processing pursuant to Art. 21 GDPR;
- according to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format, or to request the transmission of this data to another controller;
- according to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority at your habitual residence or place of work, or our company headquarters for this purpose.
|
Right to Object To the extent that we process personal data in the context of our overriding legitimate interests as explained above, you have the right to object to this processing for reasons arising from your particular situation, with effect for the future. If the processing is carried out for purposes of direct marketing, you can exercise this right at any time as described above. If processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation. Upon exercising your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims. This does not apply if the processing is for direct marketing purposes. In that case, we will no longer process your personal data for this purpose. |
7.2 Contact Options
If you have any questions about the collection, processing, or use of your personal data, or for inquiries, correction, restriction, or deletion of data, as well as the revocation of granted consents or objection to a specific use of data, please contact us directly using the contact details provided in our legal notice.
Privacy Policy created with the Trusted Shops Legal Text Generator