Data protection declaration
1. What personal information do we collect from you?
Personal data is any information relating to an identified or identifiable natural person given to us by you or that arises or is collected by us. This can include:
Registration data: When you order goods through our online shop, you can register and open a customer account. When you register, you must enter your name and contact information (e.g. your address, telephone number, e-mail address) and set a password.
Order data in the online shop: If you order goods through our online shop (using a customer account or as a guest), we process the data entered by you, the data about your person (in particular delivery addresses and payment data) as well as the information provided to you by us. We also collect information about the time, scope and, if necessary, the location of your order.
Other content data: If you use other services on our website, e.g., fill out contact forms, sign up for newsletters, participate in contests or post a comment on our blog, we process the content data you provide and the information we make available to you.
Usage data: We create user profiles under a pseudonym based on how you use our website, which we then use to track how our website is used.
Server log data: When you use our websites, data (such as your IP address, browser type and version, device type and operating system, the date and time of your visit as well as the pages you accessed and the files you requested) are temporarily stored in a log file on our servers.
2. What is the purspose and legal basis for processing your personal data and how long is it stored?
2.1 Your customer account
When you register for a personal customer account, we process the registration data to set up and manage your customer account and process future orders. As a registered customer, you have access to your personal customer account (using your email address and password created by you), in which you can view your order history and save and change your personal settings (e.g. password settings, newsletter settings, invoice and delivery settings).
The legal basis for processing is our legitimate interest according to Art. 6 (1) (f) GDPR to provide you with the service of a "customer account" as described above respectively for the purpose of performance of the user contract with you (Art. 6 (1) (b) GDPR).
This data will be deleted if the registration on our website or the customer account is cancelled or changed.
You may object to the processing of your data on the basis of Art. 6 (1) (f) GDPR unless we can prove compelling reasons for the processing to continue. However, we will not do this for a customer account. In this case, the following applies: The customer account must then be deleted and is no longer available to you. Please note that we may store the data concerning the orders that are visible in your customer account for a longer period of time (see 2.2).
2.2 Your orders
We use your order data (such as your name, address, e-mail address, delivery preferences and other information pertaining to your order) to process the order and to deliver the goods you ordered. In addition, depending on the payment method you have selected, either we or payment service providers commissioned by us (see Section 3.2.1) process the payment information required by the respective payment method. For example, we store IBAN and BIC ourselves, while payment service providers store your credit card number, Paypal account details, etc.).
The legal basis for processing is the conclusion and performance of the sales contract for the purchased goods, Art. 6 (1) (b) GDPR.
This data will be deleted when it is no longer required for contract management (including customer service and warranty), unless we are legally obliged to store it, e.g. due to the legal obligation to retain data for commercial or tax-based reasons.
2.3 Your enquiries
If you send us enquiries using a contact form, via e-mail or by phone, we will process the information you provide in order to answer your query as well as your IP address and the date/time of the enquiry to prevent misuse of the contact form.
The legal basis for processing is our legitimate interest (Art. 6 (1) (f) GDPR) to provide you with the “enquiries" service described above. If your enquiry concerns the initiation or performance (including customer service or warranty) of a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR.
You can object to the processing of your data on the basis of Art. 6 (1) (f) GDPR. We can then continue processing if there are compelling reasons for processing. This may be necessary in order to provide evidence for enquiries from you and past communication with you. If there are no such compelling reasons, we will stop communicating with you and delete the data that has been collected.
This data will be deleted when our communication with you has been terminated, i.e. when the relevant facts have been clarified and no further legitimate interests exist for storage or no further legal obligations exist for storage.
If you take part in one of our contests, we use your data (e.g. name, e-mail address) to carry out the contest, for information purposes and to send you a prize, if applicable.
The legal basis for the processing is the consent you have given when participating in the contest (Art. 6 (1) (a) GDPR). Your data will be deleted when the contest is over and the prizes have been distributed. Your data will be used for other purposes, e.g. advertising, only if you have explicitly given your consent.
2.5 Advertising and product development (Newsletters, etc.), right to object
We would also like to use the data you have entered or accrued when using the websites to inform you about our products and services (advertising) or to improve our offerings and services (product development).
On our website, you can subscribe to a free newsletter. The data collected during registration will be processed (the data displayed as mandatory fields are absolutely necessary for receipt of the newsletter, while voluntary data fields are only used for a more personal form of address and selecting the information displayed).
We will contact you by e-mail with information, special sales and offers for wardow.com services tailored to you and your interests on the basis of either your explicit consent or - if you purchase similar goods or services from us and store your e-mail address here - even without your extra consent. We process data about your usage behaviour after we have sent you e-mails (e.g. click behaviour).
We will contact you by telephone only with your express consent to provide you with information, special sales and offers for wardow.com services tailored to your personal interests or usage of our site.
We will contact you by post with advertisements in written form, even without your consent, to the extent permitted by law for wardow.com services.
You can object to the use of your personal data for purposes of advertising and product development as well as the establishment of contact for this purpose in whole or in part at any time or withdraw any consent you have given. Please use the corresponding options provided for you (e.g. the unsubscribe link in your personal customer account) or contact our data protection officer via e-mail or in writing (keyword: data protection) using the contact information specified under section 8.
The legal basis for processing is your consent (Art. 6 (1) (a) GDPR) and our legitimate interests (Art. 6 (1) (f) GDPR) in conjunction with § 7 (3) of the German Act against Unfair Competition (UCA), if applicable.
This data will be deleted or stored only in aggregated, anonymous form after your objection or withdrawal of any consents you have given or after cessation of use by us at the very latest. If necessary, we will store the data of your objection in order to prevent further contact with you.
2.6 Providing the best website and services
The processing of server log data is necessary for technical reasons in order to provide the websites and services and in order to ensure system security thereafter.
The legal basis for processing is our legitimate interest in providing the website and our services (Art. 6 (1) (f) GDPR). The processing is absolutely necessary for the use of our website, and there is no right to object.
This data will be deleted after 12 days at the very latest.
The server log data may then be analysed anonymously for statistical purposes and to improve the quality of our website. The server log data is not linked to your personal data, nor will it be merged with other personal data sources.
3. Data transfer
3.1 Data transfer to processors
In some cases, we employ service providers in compliance with legal requirements for order processing, i.e. on our behalf, in accordance with our instructions and under our control.
- technical service providers we use to provide the website, e.g. service providers for software maintenance, data centre operation and hosting
- technical service providers we use to provide functionalities, e.g. essential cookies for technical purposes.
- service providers for the practical implementation of advertising and marketing, e.g. service providers for e-mail and analytics cookies.
In these cases, we remain responsible for data processing; the transfer and processing of personal data to or by our processors rests on the legal basis that allows us to process the data in each case. A separate legal basis is not required.
3.2 Data transfer to third parties
In some cases, we also transfer your data to third parties, i.e. to partners with whom we cooperate outside of commissioned processing. Such partners provide their services and are as such the responsible parties. For the processing of your data by partners, only their data protection policy applies.
3.2.1 Payment service providers
To process your orders, we send payment information to payment service providers who then process the payment transactions associated with the orders. These include PayPal and your financial institution. The legal basis for the transmission is the performance of the contract with you, Art. 6 (1) (b) GDPR.
When you pay upon invoice, we also transmit data relevant to your order to RatePAY GmbH, to which we assign the invoice you are to pay. In order to determine whether or not to purchase the claim, the above mentioned companies will perform a credit check. The legal basis for the transmission of the data is your express consent provided during the ordering process (Art. 6 (1) (a) GDPR).
3.2.2 Buyer protection/ratings
The Trusted Shops Trustbadge is displayed on this website in order to show our Trusted Shops seal of approval, any ratings accumulated from users as well as to offer Trusted Shops products to buyers following an order.
This serves to protect our legitimate interests in the optimal marketing of our offer according to Art. 6 (1) (f) GDPR. The Trustbadge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Köln, Germany. Each time the Trustbadge is used, the web server automatically saves a so-called server log file, which contains your IP address, date and time of the request, volume of data transferred and the requesting provider (access data) and documents the request. This access data is not analysed and is automatically overwritten no later than seven days after the end of your website visit.
Other personal data is transferred to Trusted Shops only if you decide to use or have already registered to use Trusted Shops products after placing an order. In such a case, the contract between you and Trusted Shops applies.
For ratings via the rating service www.trustpilot.com the terms and conditions and data protection regulations of trustpilot.de, published at https://legal.trustpilot.com/for-reviewers/end-user-privacy-terms and https://legal.trustpilot.com/for-reviewers/end-user-terms-and-conditions apply. If you participate (prior registration required) in this rating system, your rating will be published according to the terms of trustpilot.de on our website and on the websites of trustpilot and its partners. For the purpose of using trustpilot.de we will pass on your e-mail address, name and internal booking number to Trustpilot A/S, Trommesalen 5, 3. sal, 1614 København, Denmark.
3.2.3 Logistics companies
For the transport of goods, we transfer your address and contact data, when necessary, to parcel delivery companies. The legal basis for the transmission is the performance of the contract with you, Art. 6 (1) (b) GDPR.
3.2.4 Social Networks
If you wish to share one of our websites on a social network (e.g. Facebook or Twitter) by clicking on one of our "Share" buttons, this information will be transferred to the social network. This assumes that you are logged in to the social network. The legal basis for the transmission is our legitimate interest in offering you the possibility of “sharing", Art. 6 (1) GDPR.
4. Cookies and web analysis tools
4.1 What are cookies?
In order to make our websites as user-friendly as possible and to increase the relevance of our advertising for the visitors to our websites, we and our partners use so-called "cookies". Cookies are small files that are stored on a visitor's hard drive. They allow information to be stored for a certain period of time and the visitor's computer to be identified. This is done in part using so-called tracking pixels, which are not stored on a visitor's hard drive but can help identify the computer in the same way as a cookie. In the following, the term "cookie" covers cookies in the technical sense as well as tracking pixels and similar technical methods.
4.2 Which cookies do we use, what is the legal basis of their use and how long are they stored?
We use three categories of cookies on our websites: (1) Essential cookies, without which the functionality of our websites would be limited, (2) optional performance cookies and (3) optional targeting or advertising cookies:
4.2.1 Essential cookies
These cookies are essential for you to move around our websites and use the functions. For example, they save the products you have placed in your basket as well as the progress of the ordering process. These cookies also allow you to easily search for retailers where you can purchase our products (e.g. by displaying a map of your area). These cookies do not collect any information about you for marketing purposes, nor do they store where you have been on the internet. Disabling this category of cookies would limit the functionality of all or part of the websites.
The legal basis for processing is our legitimate interests (Art. 6 (1) (f) GDPR).
These cookies are session-specific and expire after your visit to the website (session).
4.2.2 Performance cookies/ Google Analytics
Performance cookies collect information about how visitors use a website in general, such as which pages they visit most frequently and whether they receive error messages from websites. These cookies do not collect any data that can be used to identify visitors. All of the information collected with the help of these cookies serves exclusively to understand and improve the functionality of the website and the service it provides.
We use Google Analytics, a web analytics service provided by Google Inc. The information generated by the use of Google Analytics about your use of this website is transmitted to and stored by Google on servers in the United States. However, by activating the IP anonymisation on this website, Google will shorten your IP address beforehand within the area of the member states of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by the user's browser will not be merged with other Google data.
Google will use this information on our behalf to analyse your use of the website, to compile reports on website activities and provide additional services relating to website use and internet use to the website operator. Pseudonymous user profiles can be created from the processed data.
Users can prevent the storage of cookies by setting their browser software accordingly; Users may also prevent Google’s collection of the data generated by the cookie and related to their use of the online offer and Google’s processing of such data by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=en.
The legal basis for processing is our legitimate interests because we only use pseudonymised or anonymised data (Art. 6 (1) (f) GDPR).
The data collected on the basis of these cookies is made anonymous before analysis. You can deactivate or delete cookies and information stored therein at any time (see 4.2.4).
4.2.3 Targeting and advertising cookies
Targeting and advertising cookies are used to tailor advertising more specifically to you and your interests. They also serve to limit how often you see the same advert, to measure the effectiveness of an advertising campaign and understand people's behaviour after viewing an advert. These cookies are usually placed on the pages of advertising networks with the consent of the website operator (i.e. in this case us). They detect that a user has visited a website and pass this information on to other companies, e.g. advertising companies, or adjust the adverts accordingly. They are often linked to the functions of the website provided by this company. We use these cookies to connect with social networks that may then use the information about your visit to tailor adverts on other websites to you and to provide the advertising networks we use with information about your visit so that you can later be presented with precisely the adverts that could interest you based on your browsing behaviour. If a product is purchased later, this fact may be transmitted to such an advertising network.
We also include cookies on our website that are set by service providers on our behalf and enable us to track which products of ours you have already viewed so that we can recommend similar products to you.
The legal basis for the processing is the consent you have given in the context of the cookie banner displayed when our website is visited (Art. 6 (1) (a) GDPR).
You can deactivate or delete cookies and the information stored therein at any time (see the following information).
4.2.4 Deavtivation of analytics, targeting and advertising cookies
4.3 How do I disable cookies?
You can disable individual cookies using the links in the table above (opt-out options), provided that the cookie provider offers such a function. You can also prevent the use of any cookies by adjusting the cookie settings in your browser. However, we would like to point out that the functionality of our websites will be limited if you do so, since essential cookies will also be blocked.
If you go to the website www.youronlinechoices.com, you can read more information about cookies and the individual providers. There, you also have the opportunity to object to use-based online advertising by means of individual tools or all tools. To go directly to the preference manager, please click here: http://www.youronlinechoices.com/uk/your-ad-choices.
We use links to our other web presences on websites and third-party services, e.g. on social media channels like Facebook, Twitter or Youtube. The data processing of these other service providers on their websites is the sole responsibility of these third parties and their data protection policy applies.
We and our service providers employ technical and organisational security measures to protect your personal data against accidental or intentional manipulation, loss, destruction or against access by unauthorised persons. Our data processing and security measures are continually being improved with technological developments.
When your personal data is transmitted to us, it is encrypted with Secure Socket Layer (SSL). Personal data exchanged between you and us or other participating companies is generally transmitted via encrypted connections that correspond to the current state of the art.
Our employees and our service providers are, of course, bound to a confidentiality agreement.
7. Your rights to information, correction, blocking and deletion
Every natural person whose personal data we process has the following rights (i.e. depending on the respective conditions):
- If you have any questions regarding the processing of your personal data by us, we would be happy to provide you with information about your stored personal data at any time free of charge (Art. 15 GDPR).
- You have the right to correct inaccurate data and complete incomplete data (Art. 16 GDPR).
- You have a right to block/restrict the processing or delete your personal data that is no longer required or stored on the basis of legal obligations (Art. 17, 18 GDPR).
- You have the right to transfer the data in a structured, commonly used and machine-readable format, provided that you have provided us with the data on the basis of an agreement or a contract between us and you (Art. 20 GDPR).
- You have the right to object to the processing of your data for direct marketing purposes at any time (Art. 21 (2 and 3) GDPR).
- You have a right to object to processing of personal data on the basis of a legitimate interest, unless we can explain our compelling legitimate grounds (Art. 21 (1) GDPR). We have pointed out above in what cases such a right is available.
- If you have given your consent to data processing, you can withdraw this with effect for the future at any time, i.e. the legality of the data processing carried out up to the time of the revocation remains unaffected by your withdrawal of consent. After withdrawing your consent, you may no longer use our services.
Please contact us with your request in writing (keyword: data protection) or via e-mail using the contact information under section 8. We reserve the right to check your identity to ensure that your personal data is not disclosed to unauthorised persons.
You also have the right to file a complaint with a data protection authority.
8. Contact data
For all questions regarding data protection, please contact here:
Ansprechpartnerin: Alexandra Flieger
From time to time, it is necessary to change the content of this Privacy and Data Protection Policy. We therefore reserve the right to change it at any time. We will publish the amended version of the Privacy and Data Protection Policy here as well. If you visit us again, we kindly ask you to read the Privacy and Data Protection Policy again.
Last changed: May 2018