Data protection
Data protection
1. General scope of data processing
Data protection is of great importance in our society. We comply with the General Data Protection Regulation (GDPR), which regulates the processing of personal data uniformly for the entire European Union, and other national data protection laws of the member states as well as other data protection regulations. We generally only collect, process and use personal data to the extent that this is necessary to provide a functional website and to present our offers and provide our services.
As a user, you can generally visit our websites without providing any personal information. Personal data is only collected and used to the extent necessary to provide a functional website and our content and services. Your personal data is generally only collected and used with your consent. An exception applies in cases where prior consent cannot be obtained for actual reasons or where the collection and processing of data is permitted by law.
For security reasons, we use an SSL certificate on our website to provide secure connections by encrypting all incoming and outgoing data traffic. You can recognize the encryption by the lock symbol in your browser line and the fact that "https://" is displayed there.
2. Name and address of the person responsible for data processing
The controller within the meaning of the GDPR is:
Sandra Brix
Ringstr. 196a
22145 Hamburg
Phone: +49 (0) 1520-6106688
Email: info@melavastra.com
- Definitions
The terms used in this privacy policy correspond to those in Article 4 of the GDPR. For the purposes of this Regulation, the following terms shall apply:
“personal data” – any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
“data subject” – any identified or identifiable natural person whose personal data is processed by the controller.
“Processing” – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Restriction of processing” – the marking of stored personal data with the aim of limiting their future processing;
“profiling” – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
"controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
"recipient" means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be considered recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules and in accordance with the purposes of the processing;
“third party” – a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons authorised to process personal data under the direct authority of the controller or processor;
“Consent” - any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data concerning him or her.
- General legal bases for the processing of personal data
If we obtain consent from the data subject for processing personal data, Art. 6 (1) (a) of the EU General Data Protection Regulation (GDPR) is the legal basis for the processing of personal data.
When processing personal data that is necessary to fulfill a contract to which the data subject is a party, Art. 6 (1) (b) GDPR is the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
If the processing of personal data is necessary to fulfill a legal obligation to which we are subject, Art. 6 (1) (c) GDPR is the legal basis.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) (d) GDPR is the legal basis.
If the necessary processing serves to safeguard our legitimate interests or those of a third party and the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 6 (1) (f) GDPR is the legal basis for the processing.
- Data deletion and storage period
Your personal data stored by us will be deleted or blocked as soon as the purpose for storing it no longer applies. Storage may also take place if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which we are subject, e.g. due to retention and documentation obligations under tax and commercial law. The data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the conclusion or fulfillment of a contract.
- Collection of technical access data , server log files
Every time you access our website, our web server automatically records data and information from the computer system of the computer you are using to access it. The following data is collected:
- Country
- country
- Federal State
- City
The data is temporarily stored in the log files of the web server we use. This data is not stored together with your other personal data. We cannot assign your data to specific people. We only use this technical log data for statistical purposes and to optimize our website and its security. The legal basis for the temporary storage of the data and log files is Art. 6 Para. 1 lit. f GDPR.
The temporary storage of the IP address by our web server is necessary to enable the delivery of the web pages accessed to your computer. For this purpose, the IP address of the accessing computer must be stored for the duration of the session. The data is stored in log files to ensure the functionality of the website. In addition, we use the data to optimize the website and to ensure the security of our information technology systems. The data is not evaluated for marketing purposes in this context. Our legitimate interest in data processing in accordance with Art. 6 (1) (f) GDPR also lies in the above purposes.
The stored data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. The collection of data to provide the website and the storage of data in log files is essential for the operation of the website. There is therefore no possibility for you to object or remove the data.
- Use of cookies
We use "cookies" on our website. "Cookies" are text files that are stored in the Internet browser or by the Internet browser on the computer system that is accessing the website. When you access a website, a cookie may be stored on the operating system of the computer you are using. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is accessed again.
The purpose of using cookies is to simplify the use of websites for you. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after a page change, e.g. log-in information, contents of the shopping cart, adoption of language settings, remembering search terms. The user data collected by technically necessary cookies is not used to create user profiles. The data processed by cookies is required for the purposes mentioned to protect our legitimate interests in a customer-friendly website design in accordance with Art. 6 Para. 1 Clause 1 Letter f of GDPR.
Cookies are stored on your computer and transmitted from it to our website. Therefore, as a user, you have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your Internet browser. Cookies that have already been stored can be deleted at any time. Depending on the browser, this may also be done automatically. You can find setting options for your browser on the website of the respective provider of your browser.
If cookies are deactivated for our website, it may no longer be possible to use all the website's functions to their full extent. The transmission of Flash cookies cannot be prevented via the browser settings, but by changing the Flash Player settings.
- Newsletter
If you have the option of subscribing to a free newsletter on our website, the following applies: When you register for the newsletter, the data from the input mask is sent to us. The data requested in the input mask then includes your first and last name and your email address so that we can send the newsletter to you personally at your email address. Your consent to the processing of the data is obtained as part of the registration process and reference is made to this data protection declaration. In addition, the IP address of the computer accessing the service and the date and time of registration are also collected when you register in order to prevent misuse of the services or the email address used or to be able to trace them in the event of a complaint. Our legitimate interest in data processing in accordance with Art. 6 Paragraph 1 Letter f of GDPR also lies in the above purposes.
If you purchase goods or services on our website and provide your email address, we may subsequently use this to send you a newsletter. In such a case, the newsletter will only be used to send direct advertising for our own similar goods or services. No data will be passed on to third parties in connection with data processing for sending newsletters. The data will only be used to send the newsletter. The legal basis for processing the data after you have registered for the newsletter is Art. 6 Para. 1 lit. a GDPR if you have given your consent. The legal basis for sending the newsletter as a result of the sale of goods or services is Section 7 Para. 3 UWG.
Your data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. Your email address will therefore only be stored as long as the newsletter subscription is active, unless you have expressly consented to further use of your data. You can cancel your newsletter subscription at any time. There is a link for this purpose in every newsletter. This also makes it possible to revoke your consent to the storage of the personal data collected during the registration process.
- Customer registration
If you have the option of setting up a customer account on our website and registering by providing your personal data, the following applies: The data is entered into an input mask and transmitted to us and stored. The data is not passed on to third parties. The following data is collected as part of the registration process: your company/business name, your title Mr./Ms., your first and last name, your postal address, your email address, your telephone number, your personal login password. As part of the registration process, your consent to the processing of this data is expressly obtained. At the time of registration, the following data is also stored: the IP address of the accessing computer, the date and time of registration. Our legitimate interest in data processing in accordance with Art. 6 (1) lit. f GDPR also lies in the above purposes.
Your registration is required to fulfil a contract with you or to carry out pre-contractual measures. By registering, we can make the data you have entered available to you quickly and easily without you having to enter it again. If you have given your consent, the legal basis for processing the data is Art. 6 (1) (a) GDPR. If the registration serves to fulfil a contract between you and us or to carry out pre-contractual measures, the additional legal basis for processing the data is Art. 6 (1) (b) GDPR.
Your data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. This is the case during the registration process for the performance of a contract or for the implementation of pre-contractual measures if the data is no longer required for the implementation of the contract. Even after the contract has been concluded, it may be necessary to store the contractual partner's personal data in order to comply with contractual or legal obligations.
As a user, you have the option of canceling your registration at any time. You can have the data stored about you changed at any time. To change or delete your data, simply contact us using the contact details provided in the imprint. Ideally, you should send us an email. If the data is required to fulfill a contract or to carry out pre-contractual measures, early deletion of the data is only possible if there are no contractual or legal obligations that prevent deletion.
- Contact form and email contact
If there is a contact form on our website that you can use to contact us electronically, the following applies: If you make use of this option, the data entered in the input mask will be transmitted to us and saved. This data is used to process the contact: your first and last name, your email address. Minimum required information is marked. At the time the message is sent, the IP address of the computer accessing the message and the date and time of registration are also saved in order to prevent misuse of the contact form and to ensure the security of our information technology systems. Our legitimate interest in data processing in accordance with Art. 6 (1) (f) GDPR also lies in the above purposes.
We will obtain your consent to process the data before sending it and at the same time refer to this privacy policy. Alternatively, you can contact us by email. In this case, only the personal data you send in the email will be saved to process the contact. Under no circumstances will your data be passed on to third parties. Your data will only be used for the intended communication. The legal basis for processing the data if you have given your consent is Art. 6 (1) (a) GDPR. The legal basis for processing personal data that you have sent to us by email is Art. 6 (1) (f) GDPR. If the email contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR.
The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and those that were sent by email, this is the case when the respective communication with you has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified.
You have the option to revoke your consent to the processing of personal data at any time. If you have contacted us by email, you can object to the storage of your personal data at any time. The revocation can be made, for example, by sending a revocation email or by letter to our contact addresses shown in the imprint. All personal data that was stored in the course of contacting us will then be deleted.
- Data transfer to service partners
We only pass on your personal data to service partners who are involved in the contract processing, such as the shipping company commissioned with the delivery, the credit institution commissioned with payment matters, and in the case of dropshipping, the supplier/wholesaler. The extent of the data transfer to third parties is limited to the necessary minimum, namely your first and last name, your address and, if applicable, your delivery address. The legal basis is Art. 6 Para. 1 lit. b GDPR.
In the event that you have given us or, at your request, the service partner your express consent to do so, we will also pass on your email address, telephone number or date of birth for the purpose of coordinating a delivery date with the shipping company or a required identity and credit check with the payment service provider. If you do not give us your consent in this regard, a prior agreement on a delivery date or a delivery notification or a "purchase on account" or "purchase by direct debit" or "installment purchase" is not possible. The legal basis for this is Art. 6 Para. 1 lit. a GDPR.
You can of course revoke your consent to us or to the respective service partner at any time with future effect. However, the respective service partner may still be entitled to process your personal data if this is necessary for the contractual execution of the contract.
We work in particular with the following service providers:
- a) Service providers
Shopify
We use Shopify as our e-commerce platform, a service provided by Shopify Inc., 150 Elgin St., 8th Fl, Ottawa, ON K2P 1L4, Canada. Shopify stores the personal data arising during the purchase process on foreign servers and in the USA, and for data from the EEA and Switzerland primarily in Ireland by Shopify International Limited, 2nd Floor 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32 Ireland.
If we offer Shopify payment options and you use them to complete your purchase, Shopify may store your credit card information. During the ordering process, your personal data is transmitted over the Internet in encrypted form using PCI-DSS (Payment Card Industry Data Security Standard). Your purchase processing data is only stored for as long as it is necessary to complete the transaction. After that, your purchase transaction data is deleted. For more information, see Shopify's Terms and Conditions at http://www.shopify.com/legal/terms and Shopify's Privacy Policy at http://www.shopify.com/legal/privacy .
Google Analytics
We use Google Analytics, a web analytics service Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). Google Analytics uses "cookies" which are stored on your computer and which enable an analysis of your use of the website. The information generated by the cookie about your use of this website (including the anonymized, i.e. shortened IP address) is usually also transferred to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 in the USA and stored there.
IP anonymization "_anonymizeIp()" is activated on our website. This option means that your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. This means that your IP address cannot be personalized. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
On our behalf, Google will use this information to evaluate your use of our website, to compile reports on website activity and to provide us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
For the processing described above, in particular the use of Google Analytics cookies to read information on the device you are using, you must have given us your express consent in accordance with Art. 6 Paragraph 1 Letter a) of GDPR. For the consent, we use a so-called “cookie consent tool”, which appears when you visit our website. “Cookie Consent Tool” you can give us your consent to use Google Analytics or exercise your right to refuse consent by deactivating the service for your website. You can revoke your consent at any time with effect for the future using the "Cookie Consent Tool". We have concluded a data processing agreement with Google for the use of Google Analytics. This agreement obliges Google to protect the data of our website visitors within the framework of standard contractual clauses and not to pass it on to third parties. Information on the general terms and conditions
For the transfer of data from the EU to the USA, Google relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European data protection level in the USA, see https://policies.google.com/privacy/frameworks .
You can find more information about Google Analytics here: https://policies.google.com/privacy
- b) Shipping service provider:
DHL
In the event that shipping is carried out via DHL, we will pass on your data to Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn.
- c) Payment service providers
PayPal
When paying via PayPal, credit card via PayPal, direct debit via PayPal or "purchase on account" via PayPal, we pass your payment data on to PayPal (Europe) S.à rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or "purchase on account" via PayPal. PayPal uses the result of the credit check in relation to the statistical probability of default for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, these are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of the score values. Further information on data protection can be found in the PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full .
Klarna
If you choose the payment method "Klarna purchase on account" or (if offered) the payment method "Klarna installment purchase", the payment will be processed via Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). If you have given your consent, your personal data (first and last name, street, house number, postcode, city, gender, email address, telephone number and IP address) as well as data related to the order (e.g. article, delivery method, invoice amount) will be passed on to Klarna for the purpose of identity and credit checks.
In order to check your creditworthiness, your data may be forwarded to credit agencies. You can find out which ones these are at the following link: https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies . As part of the decision on the establishment, implementation or termination of the contractual relationship, Klarna collects and uses information on the buyer's previous payment behavior and probability values for this behavior in the future, in addition to an address check. The calculation of these score values by Klarna is carried out on the basis of a scientifically recognized mathematical statistical procedure. Klarna will also use your address data, among other things, for this purpose. If this calculation shows that you are not creditworthy, Klarna will inform you of this immediately. Your personal data will be processed in accordance with Klarna's applicable data protection provisions for data subjects based in Germany https://cdn.klarna.com/1.0/shared/content/policy/data/de_de/data_protection.pdf
or for data subjects based in Austria https://cdn.klarna.com/1.0/shared/content/policy/data/de_at/data_protection.pdf
processed.
- Social Media Plug-ins
We use buttons (“plugins”) from social networks on our website so that you can interact with and through us. These plugins enable different functions that are specified by the different social networks.
The legal basis for the use of social media plugins in relation to the processing of personal data is Art. 6 Para. 1 f GDPR, whereby our legitimate interest lies in the provision of interaction options for the purpose of direct advertising (Recital 47 GDPR) and in the needs-based design of our Internet services for interaction with social networks to which you belong.
YouTube
We use functions of the YouTube service operated by Google, which is operated by YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. When you visit one of our pages with a YouTube plug-in, a connection is established to the YouTube servers. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you allow YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account. For more information on how user data is handled, see YouTube's privacy policy at: https://www.google.de/intl/de/policies/privacy .
- Rights of the data subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
Right to information (Art. 15 GDPR) - You can request confirmation from us as the controller as to whether personal data concerning you is being processed by us.
In the event of processing, you can request the following information from us: the purposes for which the personal data are processed; the categories of personal data that are processed; the recipients or categories of recipients to whom the personal data concerning you have been or will be disclosed; the planned duration of storage of the personal data concerning you or, if specific information is not possible, criteria for determining the storage period; the existence of a right to rectification or erasure of the personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing; the existence of a right to lodge a complaint with a supervisory authority; all available information about the origin of the data if the personal data are not collected from the data subject; the existence of automated decision-making, including profiling, in accordance with Art. 22 (1) and (4) GDPR and - at least in these cases - meaningful information about the logic involved and the scope and intended effects of such processing for the data subject. You also have the right to request information as to whether the personal data concerning you will be transferred to a third country or to an international organization. In this context, you can request to be informed of the appropriate guarantees in accordance with Art. 46 GDPR in connection with the transfer.
Right to rectification (Article 16 GDPR) - You have the right to have your personal data rectified and/or completed without delay by the controller if the personal data concerning you that are processed are incorrect or incomplete.
Right to erasure (Art. 17 GDPR) - You can request that we, as the controller, delete the personal data concerning you immediately. In this case, we are obliged to delete this data immediately if one of the following reasons applies: (1) The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed. (2) You withdraw your consent on which the processing was based in accordance with Art. 6 Para. 1 lit. a or Art. 9 Para. 2 lit. a GDPR, and there is no other legal basis for the processing. (3) You object to the processing in accordance with Art. 21 Para. 1 GDPR and there are no overriding legitimate reasons for the processing, or you object to the processing in accordance with Art. 21 Para. 2 GDPR. (4) The personal data concerning you have been processed unlawfully. (5) The deletion of the personal data concerning you is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the controller is subject. (6) The personal data concerning you were collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.
If we have made the personal data concerning you public and are obliged to delete it pursuant to Art. 17 Para. 1 GDPR, we will take appropriate measures, including technical ones, taking into account the available technology and the implementation costs, to inform data controllers which process the personal data that you, as the data subject, have requested that we delete all links to these personal data or copies or replications of these personal data.
The right to erasure does not apply if processing is necessary (1) to exercise the right to freedom of expression and information; (2) to fulfill a legal obligation which requires processing by Union or Member State law to which the controller is subject, or to perform a task carried out in the public interest or in the exercise of official authority vested in the controller; (3) for reasons of public interest in the area of public health pursuant to Art. 9 (2)(h) and (i) and Art. 9 (3) GDPR; (4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Art. 89 (1) GDPR, insofar as the right referred to in section (a) is likely to make the achievement of the objectives of this processing impossible or seriously compromises it, or (5) to assert, exercise or defend legal claims.
Right to restriction of processing (Art. 18 GDPR) - Under the following conditions, you can request the restriction of the processing of personal data concerning you: if you contest the accuracy of the personal data concerning you for a period that enables the controller to verify the accuracy of the personal data; the processing is unlawful and you refuse to delete the personal data and instead request the restriction of the use of the personal data; the controller no longer needs the personal data for the purposes of processing, but you need them to assert, exercise or defend legal claims, or if you have objected to the processing pursuant to Art. 21 Para. 1 GDPR and it has not yet been determined whether the legitimate reasons of the controller outweigh your reasons.
If the processing of personal data concerning you has been restricted, these data may - with the exception of storage - only be processed with your consent or for the establishment, exercise or defence of legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the Union or a Member State. If the restriction of processing has been restricted in accordance with the above-mentioned conditions, you will be informed by the controller before the restriction is lifted.
Right to information (Art. 19 GDPR) - If you have asserted your right to rectification, erasure or restriction of processing vis-à-vis the responsible party, this party is obliged to inform all recipients to whom the personal data concerning you was disclosed of said rectification, erasure or restriction of processing, unless doing so should prove impossible or involve disproportionate expenditure. You have the right to be informed by the responsible party of these recipients.
Right to data portability (Art. 29 GDPR) - You have the right to receive the personal data concerning you that you have made available to the controller in a structured, common and machine-readable format. In addition, you have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was made available, provided that (1) the processing is based on consent in accordance with Art. 6 Para. 1 lit. a GDPR or Art. 9 Para. 2 lit. a GDPR or on a contract in accordance with Art. 6 Para. 1 lit. b GDPR and (2) the processing is carried out using automated procedures.
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. This must not affect the freedoms and rights of other persons. The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
- Right to object
You have the right to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 (1) (e) or (f) GDPR, for reasons related to your particular situation; this also applies to profiling based on these provisions.
If you exercise your right to object, we will no longer process the personal data concerning you unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such advertising; this also applies to profiling insofar as it is associated with such direct marketing. If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.
In connection with the use of information society services, you have the option of exercising your right of objection by means of automated procedures that use technical specifications, regardless of Directive 2002/58/EC.
- Right to revoke the declaration of consent under data protection law
You have the right to revoke your consent to data protection at any time. The revocation of the consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.
- Automated decision-making in individual cases including profiling
You have the right not to be subjected to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you. This shall not apply if (1) the decision is necessary for entering into or fulfilling a contract between you and the controller, (2) is permitted by Union or Member State law to which the controller is subject, and this law contains appropriate measures to safeguard your rights and freedoms as well as your legitimate interests, or (3) is made with your explicit consent.
However, these decisions must not be based on special categories of personal data pursuant to Art. 9 (1) GDPR, unless Art. 9 (2)(a) or (g) applies and appropriate measures to protect your rights and freedoms as well as your legitimate interests have been taken. With regard to the cases referred to in (1) and (3), the controller shall take appropriate measures to safeguard your rights and freedoms as well as your legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
- Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority to which the complaint was submitted shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR.
- Further data protection information
If you have any further questions regarding data protection, please feel free to contact us. You can find our contact details above under the information on the person responsible for this data protection declaration or in our legal notice.
This privacy policy is provided by RA Kai Harzheim, Hamburg – www.shopabsicherung.de
As of 09.06.2020