DATA PRIVACY POLICY
Sect. 1 General
We will process your personal data (e.g. title, name, address, e-mail address, phone number, bank details, credit card number) solely in accordance with the provisions of the German data protection law and the data protection law of the European Union (EU). The following provisions will inform you, besides the information about the processing purposes, recipients, legal bases and storage periods, also about your rights and the controller for your data processing. This privacy policy applies only to our websites. If you are directed to other sites via links on our pages, please familiarise yourself with the respective use of your data there.
Sect. 2 Data processing for the performance of contracts
(1) Purpose of data processing
Your personal data you provide us during the ordering process are necessary for the conclusion of a contract with us. You are not obliged to provide your personal data. However, we would not be able to send you the goods without your address. For some payment methods we ask for the necessary payment data in order to pass them on to a payment service provider commissioned by us. Hence, the processing of your data collected during the ordering process is soley for the purpose of contract performance.
If you send us a request by e-mail or by using the contact form, etc. before concluding the contract, we process the obtained data to carry out pre-contractual measures and answer your questions about e.g. our products.
(2) Legal basis
The legal basis for such processing is set out in Article 6 (1) (b) of the GDPR.
(3) Recipient categories
Payment service provider, shipping service provider, hosting provider, if necessary merchandise management system, suppliers if necessary (drop-shipping).
(4) Duration of Storage
We store the data required for contract execution until the statutory warranty and, if applicable, contractual warranty periods expire.
We store the data required under commercial and tax law for the statutory periods, generally ten years (cf. § 257 German Commercial Code (HGB), § 147 Regulation of Taxation (AO)).
The data processed for the execution of pre-contractual measures will be deleted as soon as the measures have been carried out and the contract cannot be concluded.
Sect. 3 Comments
(1) Purpose of data processing
Adding comments is possible. Your personal data (e.g. name/pseudonym, email address, website) collected in this scope will be solely processed for the purpose of publishing your comments.
(2) Legal basis
The legal basis for such processing is set out in Article 6 (1) (f) of the GDPR.
(3) Legitimate interest
Our legitimate interest is the public exchange of user opinions on specific topics and products. The publication serves, among other things, the purpose of transparency and opinion-forming. Your interest in data protection is preserved, as you can publish your comment under a pseudonym.
(4) Duration of Storage
There is no provision for a certain storage period. You may request the deletion of your comment at any time.
(5) Right of objection
You have the right to object at any time to the processing of data which was performed according to Article 6 (1)(f) of GDPR and which does not serve direct marketing for reasons arising from your particular situation.
In the case of direct marketing, however, you may object to the processing at any time without stating any reasons.
Sect. 4 More information on the storage and transfer of personal data
For payment transactions, order processing and delivery of goods, we pass on your personal data to the minimum needed to service providers (third parties), if this is necessary for the execution and processing of the contract (see point sect. 2).
In the following, you will receive a detailed overview of all those involved, who come into contact with your data except us during order processing (see point sect. 2 (3) Recipient categories)
(1) Use of payment service provider
In addition to the bank transfer, we only use paypal as an external payment service provider. Please note that the offered methods of payment direct debit and credit card are also part of the service of paypal and are not handled directly by us. The data protection on paypal is listed below in a separate item.
(2) Edv-based data processing during order processing
a. Processing purpose
Your personal data, which you make available to us in the ordering process, are required for a contract with us and the processing of your data is therefore for the purpose of the contract (see point sect 2 ).
b. Legal basis
The legal basis for such processing is set out in Article 6 (1) (b) of the GDPR.
c. Duration of Storage
The storage period is based on the criteria mentioned in sect. 2 (4)
d. Recipient categories
Use of hosting provider and special service providers for data processing
Except on our own computer systems, the electronic data processing is carried out by the following listed service providers. The transfer of your data takes place only as far as this is necessary for the processing of the order and for parts of the data processing and financial accounting.
Webgo GmbH
The online shop was created with the software Gambio and is hosted by the company webgo GmbH (https://www.webgo.de/) on servers in Hamburg (Germany) and thus all data are subject to German data protection laws.
Webgo GmbH
Wandsbecker Zollstrasse 95
22041 Hamburg
Germany
Your personal data will be processed and stored in databases after being transmitted to these servers.
Details on data protection at "webgo" and the privacy policy of "webgo" are available on the website of "webgo" under webgo.de.
A contract for processing data has been concluded with Webgo GmbH, which, e.g. specifies that all user data may not be shared without consent and may not be stored in third countries on other servers outside the EU.
"Easybill" GmbH
Further data processing for order processing is carried out by "easybill" GmbH. The personal data is used here for billing and invoicing, also the storage and part of the financial accounting (evaluation of orders) via the cloud-based software of the service provider.
easybill GmbH
Düsselstr. 21
41564 Kaarst
Germany
Name, address and, if applicable, further personal data are only used in accordance with Article 6 (1) (b) of the GDPR for the processing of online orders to easybill and in accordance with Article 6 (1) (c) of the GDPR for financial accounting and storage of data.
Details on data protection at "easybill" and the privacy policy of "easybill" are available on the website of "easybill" under easybill.de.
Also with the company easybill GmbH a contract was concluded, which regulates the rights and obligations of the parties in connection with the processing of personal data according to GDPR.
(3) Disclosure of data to shipping service provider
For shipping we offer according to delivery country and article weight different shipping services.
In order to be able to send the goods ordered by you, your personal data such as name and address will be transmitted to the shipping service provider.
b. Legal basis
The legal basis for such processing is set out in Article 6 (1) (b) of the GDPR.
c. Shipping service
In the following all listed shipping service providers are listed with their address and reference to their privacy policy.
Deutsche Post (German postal service)
By choosing the shipping method merchandise post (“International priority”) your personal data such as name and address will transmissed to Deutsche Post AG.
Operator of the dispatch goods merchandise post office is the :
Deutsche Post AG
Charles-de-Gaulle-Straße 20
53113 Bonn
Germany
The handling and protection of data by Deutsche Post can be found in the privacy policy of Deutsche Post:
https://www.deutschepost.de//datenschutz.html
DHL PAKET
By choosing the shipping method DHL Paket your personal data such as name and address will transmissed to DHL Paket GmbH.
Operator of the DHL shipping service is:
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
The handling and protection of data by DHL can be viewed in the privacy policy of DHL Paket GmbH:
https://www.dhl.de/datenschutz
Sect. 5 PayPal-transactions
Please note that all PayPal transactions are subject to the PayPal Privacy Policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Sect. 6 Information about cookies
(1) Purpose of data processing
This website uses technically necessary cookies. These are small text files that are stored in or by your Internet browser on your computer system. These cookies enable, for example, the inserting of several products in a shopping basket.
(2) Legal basis
The legal basis for such processing is set out in Article 6 (1) (f) of the GDPR.
(3) Legitimate interest
Our legitimate interest is the functionality of our website. The user data collected by technically necessary cookies are not used to create user profiles. This preserves your interest in data protection.
(4) Duration of Storage
The technically necessary cookies are usually deleted when the browser is closed. Persistent cookies have different validity period from a few minutes to several years.
(5) Right of objection
If you do not wish these cookies to be stored, please deactivate the use of cookies in your Internet browser. However, this may cause a functional limitation of our website. You can also delete persistent cookies at any time by changing your browser settings.
Sect. 7 Newsletter
(1) Purpose of data processing
When registering for the newsletter, your e-mail address will be used for advertising purposes, i.e. the newsletter will inform you in particular about products from our product range. For statistical purposes we may evaluate which links are viewed in the newsletter. However, it is not recognizable for us, which concrete person has accessed the links. You have expressly given the following consent separately or, as the case may be, in the course of the ordering process:
The registration was made after entering the email address in the registration form for the newsletter by marking the button next to the text field:
subscribe (You can withdraw your consent to the newsletter at any time)
After entering the security code you have received an activation link via email.
(2) Legal basis
The legal basis for such processing is set out in Article 6 (1) (a) of the GDPR.
(3) Recipient categories
if necessary: newsletter provider
(4) Duration of Storage
Your e-mail address will only be stored for the respective duration of your registration.
(5) Right of revocation
You may revoke your consent at any time with effect for the future. If you no longer wish to receive the newsletter, you may unsubscribe as follows:
The registration will be removed after entering the email address in the registration form for the newsletter by marking the button next to the text field:
unsubscribe (Unsubscribe from the newsletter)
After entering the security code your email adress will be deleted from the newsletter.
Sect. 8 Your rights as a data subject
If your personal data is being processed, you are the ‘data subject’ in terms of GDPR and you have the following rights towards us, the controller:
1. Right to information
You may request us to provide information about your personal data processed by us under Article 15 of the GDPR.
2. Right to rectification
If your personal data provided to us is not up to date or not accurate you have the right to ask for modifications to your personal data under Article 16 of the GDPR. You also have the right to request us to complete an incomplete data.
3. Right to erasure
You have the right to have your personal data erased and ask for deletion of your data under Article 17 of the GDPR.
4. Right to restriction of processing
You have the right to restrict the processing your personal data under Article 18 of the GDPR.
5. Right to data portability
You have the right referred to in Article 20 of the GDPR to receive your personal data provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.
6. Right to revoke the consent given under data protection law
You have the right referred to in paragraph 3 of Article 7 to withdraw your given consent based on the data protection provisions at any time. This does not affect the lawfulness of the processing based on consent before its withdrawal.
7. Right to lodge a complaint with a supervisory authority
If you consider that the processing of personal data relating to you infringes the GDPR, you have the right referring to in Article 77 of the GDPR to complain to the supervisory authority against the processing of your personal data (in particular in the Member State of your habitual residence, place of work or place of the alleged infringement ).
Please also note your right of objection under Article 21 GDPR:
a) In general: reasoned objection required
If the processing of personal data concerning you takes place in order
- to perform our overriding legitimate interest (legal basis: Article 6 (1f) GDPR)
or
- to safeguard the public interest (legal basis: Article 6 (1e) GDPR),
you are entitled to object to the processing at any time for reasons arising from your particular situation; this also applies to profiling based on the provisions of the GDPR.
In the event of objection, we will no longer process the personal data concerning you unless we can prove compelling grounds for processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims;
b) Special case of direct marketing: simple objection is sufficient
If the personal data concerning you are processed for the purpose of direct marketing, you have the right to object at any time to the processing and without stating reasons; this includes profiling to the extent that it is related to such direct marketing.
If you object to the processing for direct marketing purposes, the personal data concerning you will no longer be processed for these purposes.
Responsible for data processing:
Johann Frisch
Wittelsbacherstr.,, 13
93462 Lam / Germany
Phone: +499943905070
service@archtopbaer.eu