Privacy & Cookies policy
With this privacy policy we inform you about our treatment of your personal data. We know that the protection of this data is important to you and we appreciate the trust you place in us. We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG)
1. Who controls the data processing and who can I contact?
Preview Brands International Ltd. operates this website ("Website").
Contact Details:
Preview Brands International Ltd.
1, Ferris Building
St.Lukes Street, Guardamangia,
PTA1020, Pieta
Malta
Phone: +35620106811
Email: nuvita@nuvitababy.com
2. For what purpose do we process your data and on what legal basis?
We process personal data in accordance with the provisions of the GDPR and the Federal Data Protection Act (BDSG) for the following purposes:
2.1 For the fulfillment of contractual and pre-contractual obligations (Article 6(1), sentence 1(b), GDPR)
The processing of personal data (Article 4 No. 2 GDPR) takes place to provide this website and market products, in particular to answer questions related to our business dealings and for all activities necessary for the operation and administration of the company.
Preview Brands International Ltd. processes personal information provided as a user when registering, for purchase purposes. Specifically, the following information is processed: name, e-mail address, address (invoice and, if applicable, different shipping address), order information, and telephone number.
2.2 Based on legitimate interests (Article 6 (1) sentence 1 (f) GDPR)
In addition, we process your data beyond the needs of the Web site and the actual performance of the contract to pursue legitimate interests of third parties or our own, particularly in the following cases:
- Answer your questions related or unrelated to a purchase;
- Advertising or market and opinion research, as long as they did not object to the use of the data;
- Claiming legal actions and defense in litigation;
- Ensure IT security and IT operations;
- Preventing crimes or investigating them;
- Business management and product development;
Our legitimate interest is to market our products optimally, further develop these products and our company, or protect our company from threats and enforce our rights.
2.3 Based on the user's consent (Article 6(1), sentence 1(a) of the General Data Protection Regulation)
To the extent that you have given us consent to process personal data for specific purposes (e.g. Evaluation or use of data for marketing purposes), the legality of this processing is based on your consent. A given consent can be withdrawn at any time. This also applies to the withdrawal of consents, which you provided to us before the GDPR was valid (before May 25, 2018). Please note that withdrawal only takes effect for the future. Processing that occurred before the withdrawal is not affected by a revocation.
2.4 For the fulfillment of a legal obligation (Article 6 (1) sentence 1 (c) GDPR)
In addition, we are subject to various legal obligations (e.g. money laundering law, tax laws), which require data processing.
3. Who gets my data?
Within the respective controlling company, the departments that need your personal data to fulfill our contractual and legal obligations obtain access to your data.
In addition, we transmit your data to the recipients expressly mentioned in this privacy policy.In addition, we transmit them to the following categories of recipients if this is necessary to fulfill a contractual relationship with you or to implement pre-contractual measures (Article 6 (1) sentence 1 GDPR) or to pursue legitimate interests (Article 6 (1) sentence 1 lit. f GDPR):
- IT service providers, particularly software as a service, hosting, storage, and cloud computing providers,
- Logistics service providers,
- Email marketing service providers and customer service providers,
- Marketing service providers, particularly Google Ads and WhatsApp advisory service providers,
- Payment service providers for the collection of their fees
To the extent that processing is required to pursue legitimate interests, such as the use of IT services, our legitimate interest is to outsource functions.
In addition, your personal data is forwarded or transmitted if required by law (Article 6 (1) sentence 1 (c) GDPR), or if you have consented (Article 6 (1
4. How long will my data be kept?
To the extent necessary, we process and store your personal data for the duration of our contractual relationship. Note that our contractual relationship is generally a continuing obligation.
When there is a contractual relationship or other civil law claim, the retention period is also governed by the statutory limitation periods.
The retention period for cookies depends on the individual case and is usually between 12 and 24 months.
5. Is the data transmitted to a third country or international organization?
Preview Brands International Ltd. itself does not transfer data to third countries (countries outside the European Economic Area - EEA). However, some of the recipients mentioned above will transfer personal data to third countries, but this will be done only on the basis of a decision by the EU Commission or, as indicated below, on the basis of standard data protection clauses of the EU Commission (available at https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2010:039:0005:0018:EN:PDF) or binding corporate rules.
6. Web site: log files
When you visit our Web site, the browser used on your device automatically sends information to the server that hosts our Web site. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until it is automatically deleted: IP address of the requesting computer, date and time of access, name and URL of the retrieved file, web page from which the access follows ("referrer URL"), if applicable, the search engine in use, the browser used and, if applicable, the operating system of the computer and the name of the access provider.
The legal basis for this type of data processing is Article 6, paragraph 1, sentence 1 lit. f GDPR. The legitimate interests we pursue are in particular:
- Ensure a smooth connection of the Web site,
- Ensure comfortable use of our Web site,
- billing,
- statistical evaluation using a pseudonym to optimize our Web site and offer quality and range,
- Evaluation of system safety and stability
- For further administrative purposes.
7. Marketing
7.1 Newsletters
Insofar as you have expressly consented in accordance with Art. 6 para. 1 sentence 1 (a) GDPR we use your e-mail address to inform you with our e-mail newsletter, our offers and special promotions. Your consent will be recorded.
The provision of an e-mail address is sufficient for receiving the newsletter.
You can revoke your consent at any time, e.g. via the link at the end of each e-mail. Alternatively, you can also send your withdrawal notice at any time by e-mail to nuvita@nuvitababy.com. In this case, your e-mail address will be removed from our e-mail distribution list and added to our black list. Withdrawal of consent is effective only for the futureand will have no effect on actions taken in the past.
Newsletter tracking
Please note that we evaluate the behavior of recipients of our e-mails using statistics with the use of pseudonyms. For this purpose, e-mails contain so-called web beacons or tracking pixels and links, which are each linked with a single ID. Therefore, we record the time the e-mail was opened and forwarded, as well as the click on links in it, the IP address (to determine the country of retrieval), and the e-mail program used. This data is not linked to your e-mail address or other personal data, so a direct personal relationship is excluded for us. Evaluation is based on aggregate usage statistics (delivery rate, open rate, click rate, number of redirects, number of clicks on links contained in the e-mail, e-mail programs used, opens and clicks by time of day and date, country of retrieval ). Only in case of cancellations or failed deliveries will we also receive information about your name and e-mail address. This is (also) in your best interest, so that we can immediately remove you from our e-mail distribution list or correct the delivery problem. The use of a pseudonym in the evaluation of usage behavior serves to verify the success of our email marketing and to continuously improve it. For these purposes, we have a legitimate interest in data processing. The legal basis is Art. 6 (1) sentence 1 (f) GDPR.
7.2 Existing customer advertising
To the extent that you have already ordered our paid products, we will inform you from time to time by e-mail about similar products and services from us, if you have not expressly refused this permission.
The legal basis for data processing is Art. 6 (1) sentence 1 (f) GDPR. We have a legitimate interest in direct marketing (Chapter 47 GDPR).
You can object to the use of your e-mail address for promotional purposes at any time at no additional cost, e.g., via the link at the end of each e-mail or by e-mail to nuvita@nuvitababy.com.
8. Cookies and similar technologies
We use cookies on our Web site that collect your information using pseudonyms. Cookies are small text files generated by a Web site and saved by your Internet browser when you visit the Web site on your hard drive. Depending on the cookie, different data is collected.
We use technically necessary cookies, functional cookies, web analytics cookies, and tracking cookies for advertising purposes on our Web site.
If you wish to prevent the use of cookies, you can generally do the following:
- You can delete existing cookies in your browser,
- you can prevent the storage of (third-party) cookies in your browser settings,
- you can use tools such as Ghostery (https://www.ghostery.com/de/) that block tracking tools,
- you can turn off personalized ads from vendors that are part of the About Ads self-regulatory campaign (http://www.aboutads.info/choices).
- you can use the opt-out features of the Network Advertising Initiative (http://optout.networkadvertising.org/) or the http://www.youronlinechoices.com/de/ page to prevent tracking.
Note that you may not be able to use all the features of our Web site if you block cookies.
8.1 Technically necessary cookies
Many of the cookies we use are technically necessary to enable you to use our website and the services offered on them ("session cookies"). These cookies allow, for example, the entry of goods into a shopping cart or login to the secure area. The legal basis for the processing is Art. 6 (1) sentence 1 (b) GDPR. The data will not be combined with other personal information and will not be used for promotional purposes. Session cookies are deleted at the end of the respective browser session, at the latest after seven days.
8.2 Functional cookies
We use temporary cookies to improve usability. These cookies are stored on your device for a set period of time, allowing them to be recognized when you access our site again and your likes and dislikes are set automatically. The legal basis for the processing is Art. 6 (1) sentence 1 (f) GDPR.
8.3 Web Analytics Cookies
We use cookies to create pseudonymized user profiles for the purpose of web analytics ("web analytics cookies"). These cookies allow us to recognize recurring users (device owners), analyze their behavior on our website, optimize our website, and measure their interaction. The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. a GDPR, i.e. your consent. We do not combine data with other personal information and do not use it for the targeted approach of individual users for advertising purposes.
8.3.1 Google Analytics with anonymization feature
For this web analysis, we use the Google Analytics service, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
Google Analytics uses cookies that are stored on your computer and that enable an analysis of your use of the Web site. The information generated by the cookie about your use of the Web site (browser type/version, operating system used, referring URL, host name of the accessing computer (IP address), date and time of the server request) is generally transferred to Google servers in the United States and stored there. On our website, we have extended Google Analytics with the code "anonymizeIp ()" to ensure anonymous collection of IP addresses (so-called IP masking). Google will then reduce your IP address by the last octet within member states of the European Union or other states that are signatories to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and shortened there. The transfer of information to a third country outside the EU is covered by a Commission adequacy decision (C / 2016/4176 of July 12, 2016 - http://data.europa.eu/eli/dec_impl/2016/1250/ oj under Article 45 of the GDPR, as Google has committed to the principles of the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework).
On our behalf, Google uses this information as a processor under Art. 28 GDPR to evaluate website usage, compile reports on website activity, and provide the website operator with additional services associated with website and Internet usage. The IP address transmitted by your browser in the context of Google Analytics is not merged with other Google data.
For more information about Google Analytics' Terms of Use and Privacy Policy, visit https://www.google.com/analytics/terms/gb.html und https://support.google.com/analytics/answer/6004245? hl=en.
8.3.2 Other cookies
We continually adapt our web data analysis to market needs. Therefore, the use of cookies is constantly changing. Through the cookie banner on our website, we provide information about other cookies used and the purpose of their use.
8.4 Tracking cookies for promotional purposes
We also use tracking cookies for the purpose of targeted, interest-based online advertising ("advertising cookies"). These cookies collect and store information about the use of our website in pseudonymous form. The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. a GDPR, i.e. your consent. You can revoke your consent at any time. The legal basis for processing carried out on the basis of your consent as long as the withdrawal remains unaffected.
We use the information to place advertisements in line with your interests on our website and on third-party websites (if they are part of our advertising network). You will benefit because you will be shown less advertising that does not reflect your interests. We also use the information to measure and optimize the success of our advertising campaigns.
In particular, we use the following tracking cookies (and tracking pixels) for promotional purposes.
8.4.1 Google ads with conversion tracking
This Web site uses the Google Ads online advertising service with conversion operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
We use the service to place ads on the results page of a Google search or a Web site in Google's advertising network using Google (so-called Google Ads). Our purpose is to draw your attention to our offerings. Conversion tracking allows us to measure the success of our individual advertising measures by certain parameters (e.g. Ad placement or user clicks).
When you click on an ad placed by Google, Google stores a conversion tracking cookie on your computer. These cookies usually expire after 30 days and are not intended to identify you personally. For this cookie, the cookie's unique ID, the number of ad impressions per placement (frequency), the last impression (relevant to post-display conversions), and opt-out information (marking that the user no longer wishes to be targeted) are usually stored as analytics values.
These cookies help Google recognize your browser. If you visit certain Web sites on a Google Ads client's Web site and the cookie has not yet expired, Google and the client may recognize that you clicked on the ad and were redirected to the Web site. A different cookie is assigned to each Google Ads client. Therefore, cookies cannot be tracked across Google Ads client Web sites. We do not collect or process personal data while using Google Ads. We receive statistical evaluations from Google only with the total number of users who clicked on an ad and were redirected to a Web site with a conversion tracking tag. Based on these evaluations we can recognize which of the advertising measures used are particularly effective. We do not receive any additional data from the use of advertising materials; in particular, we cannot identify users based on this information.
Due to the technologies used, your browser automatically establishes a direct connection to a Google server in the United States. The transfer of your information to a third country outside the EU is covered by a Commission adequacy decision under Article 45 GDPR, as Google has self-certified its adherence to the principles of the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). By integrating Google Ads with conversion tracking, Google receives information that you have called up on the corresponding website of our web presence or clicked on an ad from us. If you are registered with a Google service, Google may associate the data with your account. Even if you are not registered or logged in with Google, it is possible that Google may obtain and store your IP address.
More information about data processing in the context of Google Ads is available at http://www.google.com/intl/de/policies/privacy.
8.4.2 Other cookies
We continually adapt our online advertising to market needs. Therefore, the use of cookies for this purpose is constantly changing. Through the cookie banner on our website, we provide information about other cookies used and the purpose of their use.
8.5 HotJar
On our Web site, through the technologies provided by HotJar (HotJar Ltd., St Julian's Business Center, 3, Elia Zammit Street, St Julian's STJ 1000, Malta) with the analytics service "HotJar" visitor interaction data is collected and stored to optimize the 'user experience and for the improvement of customer satisfaction. For this, mouse clicks, mouse movements, and scrolling movements, as well as keyboard input, can be saved.
HotJar does not record this data on Web sites that do not use the HotJar system. Data collection and storage can be challenged at any time and you can opt out here: https://www.hotjar.com/opt-out. In some cases, opting out may result in a limitation of the functionality of our Web site.
8.6 LinkedIn
We have integrated components of LinkedIn Corporation on our Web site. LinkedIn is an Internet-based social network that allows users to connect to existing business contacts and make new business contacts.
The operating company of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court Mountain View, CA 94043, USA. The privacy policy outside the United States is administered by LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Whenever you visit our Web site, which has a LinkedIn component (LinkedIn plug-in), this component causes the browser used by the subject to download a corresponding representation of the LinkedIn component. More information about LinkedIn plug-ins can be found at https://developer.linkedin.com/plugins. As part of this technical process, LinkedIn learns about the specific lower site of our Web site visited by the data subject.
If the data subject is logged into LinkedIn at the same time, LinkedIn recognizes at each visit to our Web site by the data subject and during the entire duration of the respective stay on our Web site, which specific lower site of our Web site the data subject visits. This information is collected via the LinkedIn component and linked by LinkedIn to the data subject's LinkedIn account. If the data subject activates an integrated LinkedIn button on our Web site, LinkedIn assigns this information to the data subject's personal LinkedIn user account and saves this personal data.
LinkedIn always receives information via the LinkedIn component that the data subject has visited our Web site if the data subject is simultaneously logged into LinkedIn at the time of accessing our Web site; this happens regardless of whether the data subject clicks on the LinkedIn component or not. If the data subject does not wish to transmit this information to LinkedIn, LinkedIn can prevent him or her from logging out of their LinkedIn account before visiting our Web site.
At https://www.linkedin.com/psettings/guest-controls, LinkedIn provides the ability to opt out of receiving e-mail messages, text messages, and targeted ads, as well as to manage ad settings. LinkedIn also uses partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua, and Lotame, which may set cookies. Such cookies can be rejected at https://www.linkedin.com/legal/cookie-policy. LinkedIn's privacy policy is available at https://www.linkedin.com/legal/privacy-policy
8.7 Facebook
Il controller ha integrato componenti dell’azienda Facebook su questo sito Web. Facebook è un social network.
Un social network è un luogo di incontro sociale basato su Internet, una comunità online che in genere consente agli utenti di comunicare tra loro e interagire nello spazio virtuale. Un social network può fungere da piattaforma per lo scambio di opinioni ed esperienze o consente alla comunità di Internet di fornire informazioni personali o aziendali. Facebook consente agli utenti dei social network di creare profili privati, caricare foto e socializzare tramite richieste di amicizia.
La società operativa di Facebook è Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. Le persone responsabili del trattamento dei dati personali, se una persona interessata vive al di fuori degli Stati Uniti o del Canada, sono Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublino 2, Irlanda.
Ogni visita a una delle singole pagine di questo sito Web, gestita dal controller e su cui è stato integrato un componente di Facebook (plug-in di Facebook), il browser Internet sul sistema informatico della persona interessata automaticamente dai rispettivi Componente Facebook provoca il download di una rappresentazione del componente Facebook corrispondente di Facebook. Una panoramica di tutti i plug-in di Facebook è disponibile all’indirizzo https://developers.facebook.com/docs/plugins/?locale=en_US. Come parte di questo processo tecnico, Facebook riceve informazioni su quale parte inferiore specifica del nostro sito Web è visitata dall’interessato.
Se l’interessato viene contemporaneamente registrato su Facebook, Facebook riconosce ad ogni visita al nostro sito Web dall’interessato e durante l’intera durata del rispettivo soggiorno sul nostro sito Web, quale parte inferiore specifica del nostro sito Web visita l’interessato. Queste informazioni vengono raccolte attraverso il componente Facebook e assegnate da Facebook al rispettivo account Facebook dell’interessato. Se l’interessato attiva uno dei pulsanti di Facebook integrati nel nostro sito Web, ad esempio il pulsante “Mi piace”, o se l’interessato fa un commento, Facebook assegna queste informazioni all’account utente Facebook personale dell’interessato e le salva sui dati personali.
Facebook riceve sempre informazioni tramite il componente Facebook che l’interessato ha visitato il nostro sito Web se l’interessato ha effettuato l’accesso a Facebook contemporaneamente all’accesso al nostro sito Web; ciò accade indipendentemente dal fatto che la persona faccia clic o meno sul componente Facebook. Se tale trasferimento di tali informazioni su Facebook non è desiderato dall’interessato, può impedire il trasferimento disconnettendosi dal proprio account Facebook prima di collegarsi al nostro sito Web.La politica sui dati pubblicata da Facebook, disponibile all’indirizzo https://www.facebook.com/about/privacy/update?ref=old_policy fornisce informazioni sulla raccolta, l’elaborazione e l’uso dei dati personali da parte di Facebook. Spiega inoltre quali opzioni offre Facebook per proteggere la privacy dell’interessato.
Come membro di Facebook, puoi anche modificare le impostazioni del tuo account su https://www.facebook.com/ads/website_custom_audiences/ e disattivare la raccolta di dati tra dispositivi tramite Pubblico personalizzato. Per ulteriori informazioni sulla politica sulla privacy di Facebook, visitare: https://www.facebook.com/about/privacy/update?ref=old_policy.
L’uso della nostra pagina Facebook è generalmente possibile senza fornire informazioni personali. Nella misura in cui i dati personali (ad es. Nome, indirizzo o indirizzi e-mail) vengono raccolti sul nostro sito Web, ad esempio contattandoci direttamente tramite messaggio di Facebook, ciò viene sempre fatto su base volontaria. Questi dati non saranno divulgati a terzi senza il tuo esplicito consenso.
Gestiamo questo sito per attirare l’attenzione sui nostri servizi, eventi e altre promozioni e per contattarti come visitatore e utente di questa pagina Facebook e del nostro sito Web. Come operatore della pagina Facebook, non abbiamo alcun interesse nella raccolta e nell’ulteriore trattamento dei tuoi dati personali a fini di analisi o marketing. Ulteriori informazioni sulla nostra gestione dei dati personali sono disponibili nella nostra politica sulla privacy sul nostro sito Web. Il funzionamento di questa pagina Facebook, incluso il trattamento dei dati personali degli utenti, si basa sul nostro legittimo interesse per un’informazione tempestiva e di supporto e opportunità di interazione per e con i nostri utenti e visitatori. Art. 6 cpv. 1 lit. f DSGVO. Le informazioni che ci fornite volontariamente, elaboriamo anche sulla base del vostro consenso in conformità con. Arte. 6 cpv. 1 lit. un DSGVO.
Trattamento dei dati personali da parte di Facebook:
Nella sua sentenza del 05.06.2018, la Corte di giustizia europea (CGE) ha stabilito che il gestore di una pagina Facebook, insieme a
Facebook, è responsabile del trattamento dei dati personali.
Facebook elabora i dati degli utenti per i seguenti scopi:
- Advertising, analysis, creation of personalized advertising
- Creation of user profiles
- Market research
When you access this page, Facebook automatically saves information in a log file that your browser sends to Facebook. We expressly emphasize that we have no knowledge of the scope and content of the data collected by Facebook and its processing and use or, if necessary, transmission to third parties through Facebook.
For information about Facebook's privacy, please see Facebook's Privacy Policy at https://www.facebook.com/policy.php.
Facebook uses cookies for the storage and further processing of this information, i.e., small text files that are stored on the user's various terminals. If the user has a Facebook profile and is logged into it, the storage and analysis is also cross-device. Facebook's privacy policy contains additional information about data processing on Facebook: https://www.facebook.com/about/privacy/.
Facebook Inc., the U.S. parent company of Facebook Ireland Ltd. is subject to EU-US. Privacy Shield certifies that it is committed to complying with European privacy policies.
For more information on the status of Facebook's Privacy Shield, please visit https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active.
Transmission and further processing of users' personal data to third countries, such as the United States, as well as the possible associated risks to users cannot be excluded by us as site operators.
Statistical data
Statistical data on the different categories of visitors to the Facebook page are available to us in Facebook "Insights." These statistics are generated and provided by Facebook. On the generation and representation we have no influence as site operator.
We cannot disable this function or prevent the generation and processing of data. For a selectable period of time and for each of the Fan, Member, and Interactor groups, we receive the following data from Facebook on our Facebook page: total page views, likes, page activity, posts, coverage, video views, contribution interval , comments, shared content, replies, men and women sharing, city and town origin, language, views and clicks in the store, clicks on route planning, clicks on phone numbers. It also provides data on Facebook groups linked to our Facebook page. Due to the constant development of Facebook, the availability and preparation of data is changing, so we are looking for more details on the aforementioned Facebook privacy policy reference. We use this aggregate data to make our posts and activities on our Facebook page more interesting to users. For example, we use age and gender distribution for a personalized approach and users' preferred visit times for optimized time planning of our contributions.
Information about the type of devices visitors use helps us visually tailor articles. In accordance with Facebook's Terms of Use, to which each user has consented while creating a Facebook profile, we may identify subscribers and fans of the page and view their profiles and other shared information.
You can find the option to unsubscribe here: https://www.facebook.com/policies/cookies/ and here: http://www.youronlinechoices.com/de/praferenzmanagement/.
8.8 Monitoring Bing Ads conversions.
Our online services also use conversion tracking from Microsoft (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA). Microsoft Bing Ads places a cookie on your computer if you have accessed our Web site through a Microsoft Bing ad. Microsoft Bing and so we can recognize that someone clicked on an ad, was redirected to our Web site, and reached a previously determined landing page (conversion page). We only record the total number of users who clicked on a Bing ad and were then redirected to the conversion page. No personal information about the user's identity is provided. If you do not wish to participate in the tracking process, you can also refuse the required setting of a cookie, for example through a browser setting that generally disables the automatic setting of cookies. For more information about privacy and cookies used with Microsoft Bing, visit the Microsoft Web site.
8.9 Instagram
We have integrated components of the Instagram service on our website. Instagram is a service that qualifies as an audiovisual platform, which allows users to share photos and videos, as well as redistribute such data through social networks.
The operating company of Instagram services is Instagram LLC, 1 Hacker Way, Building 14 First Floor, Menlo Park, California, USA.
Whenever you visit one of the individual pages of this website that is operated by us and on which an Instagram component (Insta-Button) has been integrated, the Internet browser on the computer system of the person concerned is automatically prompted by the respective Instagram Component, a representation of the corresponding Instagram component. As part of this technical process, Instagram is aware of which specific page of our Web site is visited by the data subject.
If the data subject is simultaneously logged into Instagram, Instagram recognizes each visit to our Web site by the data subject and which specific subpage the data subject visits during the entire duration of the respective stay on our Web site. This information is collected via the Instagram component and assigned via Instagram to the data subject's Instagram account. If the data subject activates one of the integrated Instagram buttons on our website, the data and information transmitted with it is assigned to the data subject's personal Instagram user account and saved and processed by Instagram.
Instagram always receives information via the Instagram component that the data subject has visited our website if the data subject is simultaneously logged into Instagram at the time of accessing our website; this happens regardless of whether the person clicks on the Instagram component or not. If this information is not intended for transmission to Instagram by the data subject, the individual can prevent transmission by logging out of their Instagram account before accessing our Web site.
More information and Instagram's privacy policy can be found at https://help.instagram.com/155833707900388 and https://www.instagram.com/about/legal/privacy/.
8.10 YouTube
We have incorporated YouTube components on this site. YouTube is an Internet video portal that allows video publishers to freely watch video clips and other users to view, rate, and comment on them for free. YouTube allows all types of videos to be published, so that full broadcasts of movies and television, as well as music videos, trailers or user-made videos are available through the Internet portal.
The operating company of YouTube is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.
Whenever you visit any of the pages on this site operated by us in which a YouTube component (YouTube video) is embedded, the Internet browser on the subject's computer system is automatically prompted by the particular YouTube component, a representation of the corresponding YouTube component by YouTube. More information about YouTube can be found at https://www.youtube.com/yt/about/en/. As part of this technical process, YouTube and Google will be aware of which specific page of our Web site the person is visiting.
If the person is logged in to YouTube at the same time, YouTube will recognize when linking to a subpage containing a YouTube video, which specific page of our Web site the person has visited. This information will be collected by YouTube and Google and associated with the data subject's YouTube account.
YouTube and Google always receive information through the YouTube component that the data subject has visited our Web site if the data subject is concurrently logged into YouTube at the time of accessing our Web site; this happens regardless of whether or not the person clicks on a YouTube video. If such information is not intended to be transmitted to YouTube and Google by the data subject, the individual could prevent transmission by logging out of their YouTube account before accessing our Web site.
YouTube's privacy policy, available at https://www.google.de/intl/en/policies/privacy/, identifies the collection, processing, and use of personally identifiable information by YouTube and Google.
9. Payment service provider
9.1 PayPal as a payment method
We have integrated PayPal components on this Web site. PayPal is a provider of online payment services. Payments are made through so-called PayPal accounts, which are virtual private or business accounts. In addition, PayPal has the ability to process virtual credit card payments if a user does not have a PayPal account. A PayPal account is managed through an e-mail address, which is why there is no classic account number. PayPal allows users to initiate online payments to third parties or to receive payments. PayPal also acts as a trustee and offers buyer protection services.
PayPal's European operating company is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg.
If the data subject selects "PayPal" as a payment option during the order process in our online store, the data subject's information will automatically be transmitted to PayPal. By selecting this payment option, the data subject consents to the transfer of personal data required for payment processing.
The personal data sent to PayPal are generally first name, last name, address, e-mail address, IP address, telephone number, cell phone number or other data required for payment processing. For the execution of the purchase contract, such personal data, which are related to the respective order, are also required.
The purpose of data transmission is payment processing and fraud prevention. The controller will provide PayPal with personally identifiable information, particularly if there is a legitimate interest in the transfer. Personal data exchanged between PayPal and the controller may be transferred by PayPal to credit reporting agencies. This transfer is for identity and credit verification purposes.
PayPal may disclose personal information to affiliated companies and service providers or subcontractors to the extent necessary to fulfill its contractual obligations or to process data on behalf of the data controller.
The data subject has the opportunity to revoke consent to the processing of personal data against PayPal at any time. A revocation has no effect on personal data to be processed, used or transmitted for (contractual) payment processing.
PayPal's applicable privacy policy is available at https://www.paypal.com/it/webapps/mpp/ua/privacy-full.
9.2 Visa and Mastercard as payment methods
We use external payment service providers, through whose platforms users and we can make payment transactions, e.g. Visa (https://www.visaitalia.com/termini-di-utilizzo/centro-della-privacy-visa.html) and Mastercard (https://www.mastercard.it/it-it/mastercard/cosa-facciamo/privacy.html).
Payment transactions through the offered means of payment take place exclusively via an encrypted SSL or TLS connection. You can recognize an encrypted connection by changing the browser address line from "http: //" to "https: //" and the padlock symbol in the browser line. In the case of encrypted communications, the payment details you send to us cannot be read by third parties.
Among the data processed by payment service providers are inventory data, e.g., name and address, bank details such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, summary and recipient information. The information is necessary to complete transactions. However, the data entered will be processed and stored only by payment service providers. We do not receive any account or credit card information, only information with confirmation or negative payment disclosure. Data may be transmitted by payment service providers to credit reporting agencies. This transmission is for the purpose of identity and credit verification. We refer to the terms and privacy policy of the payment service providers for this.
For payment transactions, the terms and conditions and privacy policies of the respective payment service providers, available on their respective websites or transaction applications, apply. We also refer to these for further information and affirmation of termination rights, disclosures, and other data subjects.
10.What data protection rights do I have?
You have against us the right of access (Art. 15 GDPR), the right to rectification (Art. 16 GDPR), the right to erasure (Art. 17 GDPR), the right to restriction of processing (Art. 18 GDPR) and the right to data portability (Art. 20 GDPR). With regard to the right of access and the right to erasure, the restrictions set forth in §§ 34 and 35 BDSG apply. You also have the right to object to our data processing (Article 21 GDPR). To the extent that our processing of your personal data is based on consent (Art. 6 (1), sentence 1 (a) GDPR), you can withdraw it at any time; the lawfulness of the data processing carried out on the basis of consent as long as the withdrawal remains unaffected.
To assert all of these rights and for further questions on matters relating to personal data, you can always contact our data protection officer or our postal address (see section 1).
In addition, you have the right to lodge a complaint with a supervisory authority-particularly in the EU member state where your place of residence or work is located or of alleged breach-if you believe that the processing of your personal data the data is contrary to the GDPR or other applicable data protection laws (Art. 77 GDPR, § 19 BDSG).