This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to briefly as “data”) within our online offering and the websites, functions and content associated with it, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terminology used, such as “processing” or “controller”, we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Blanket Store
Hasengasse 2
60311 Frankfurt
Germany
Email: natalie(at)blanketstore.de
Owner: Natalie Gray
Legal Notice: http://blanketstore.de/index.php/de/impressum
Master data (e.g. names, addresses).
Contact data (e.g. email, telephone numbers).
Content data (e.g. text entries, photographs, videos).
Usage data (e.g. websites visited, interest in content, access times).
Meta/communication data (e.g. device information, IP addresses).
Visitors and users of the online offering (hereinafter we also refer to the data subjects collectively as “users”).
Provision of the online offering, its functions and content.
Responding to contact requests and communicating with users.
Security measures.
Reach measurement/marketing.
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing activities. Unless the legal basis is specified in this Privacy Policy, the following applies: The legal basis for obtaining consent is Art. 6 para. 1 lit. a and Art. 7 GDPR; the legal basis for processing for the performance of our services and implementation of contractual measures as well as responding to enquiries is Art. 6 para. 1 lit. b GDPR; the legal basis for processing for compliance with our legal obligations is Art. 6 para. 1 lit. c GDPR; and the legal basis for processing for the purposes of our legitimate interests is Art. 6 para. 1 lit. f GDPR. Where the vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.
In accordance with Art. 32 GDPR and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input, disclosure, safeguarding of availability and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data and response to threats to data security. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principles of data protection by design and by default (Art. 25 GDPR).
Where, as part of our processing, we disclose data to other persons and companies (processors or third parties), transfer data to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR), where you have consented, where a legal obligation requires it or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).
Where we commission third parties to process data on the basis of a so-called “data processing agreement”, this is done on the basis of Art. 28 GDPR.
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transferring data to third parties, this is done only where it is necessary for the performance of our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests.
Subject to statutory or contractual permissions, we process or have data processed in a third country only where the special requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of special safeguards, such as the officially recognised determination of a level of data protection corresponding to that of the EU (e.g. for the USA through the “Privacy Shield”) or compliance with officially recognised special contractual obligations (so-called “Standard Contractual Clauses”).
You have the right to request confirmation as to whether data concerning you are being processed and to obtain information about such data, as well as further information and a copy of the data in accordance with Art. 15 GDPR.
In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
In accordance with Art. 17 GDPR, you have the right to request that data concerning you be deleted without undue delay or, alternatively, in accordance with Art. 18 GDPR, to request restriction of the processing of the data.
You have the right to request that the data concerning you which you have provided to us be received in accordance with Art. 20 GDPR and to request that such data be transmitted to other controllers.
Furthermore, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
You have the right to withdraw consent that you have given pursuant to Art. 7 para. 3 GDPR with effect for the future.
You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. The objection may in particular be made against processing for direct marketing purposes.
“Cookies” are small files that are stored on users’ computers. Various types of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offering.
Temporary cookies, also referred to as “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online offering and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online shop or a login status.
Cookies that remain stored even after the browser has been closed are referred to as “permanent” or “persistent”. For example, the login status can be stored if users return after several days. Such a cookie may also store users’ interests, which are used for reach measurement or marketing purposes.
“Third-party cookies” are cookies offered by providers other than the controller operating the online offering (otherwise, if they are only the controller’s cookies, they are referred to as “first-party cookies”).
We may use temporary and permanent cookies and provide information about this within our Privacy Policy.
If users do not want cookies to be stored on their computer, they are requested to disable the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. The exclusion of cookies may lead to functional limitations of this online offering.
A general objection to the use of cookies used for online marketing purposes can be declared for many services, particularly in the case of tracking, via the US website aboutads.info/choices or the EU website Your Online Choices. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that in this case not all functions of this online offering may be available.
The data processed by us will be deleted or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated otherwise within this Privacy Policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and provided that deletion does not conflict with statutory retention obligations.
Where the data are not deleted because they are required for other legally permissible purposes, their processing will be restricted. This means that the data will be blocked and will not be processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
In accordance with statutory requirements in Germany, records are retained in particular for 10 years pursuant to §§ 147 para. 1 AO, 257 para. 1 nos. 1 and 4, para. 4 HGB (books, records, management reports, accounting documents, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to § 257 para. 1 nos. 2 and 3, para. 4 HGB (commercial correspondence).
In accordance with statutory requirements in Austria, records are retained in particular for 7 years pursuant to § 132 para. 1 BAO (accounting records, receipts/invoices, accounts, documents, business papers, statements of income and expenditure, etc.), for 22 years in connection with real estate and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU Member States for which the Mini One Stop Shop (MOSS) is used.
In addition, we process:
Contract data (e.g. subject matter of the contract, term, customer category).
Payment data (e.g. bank details, payment history)
of our customers, prospective customers and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.
We process our customers’ data as part of the ordering processes in our online shop in order to enable them to select and order the chosen products and services and to enable their payment and delivery or performance.
The data processed include master data, communication data, contract data and payment data, and the persons affected by the processing include our customers, prospective customers and other business partners. Processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer service. In this context, we use session cookies to store the contents of the shopping cart and permanent cookies to store the login status.
Processing is carried out on the basis of Art. 6 para. 1 lit. b (processing of orders) and c (legally required archiving) GDPR. Information marked as required is necessary for the establishment and performance of the contract. We disclose data to third parties only in connection with delivery, payment or within the framework of statutory permissions and obligations towards legal advisers and authorities. Data are processed in third countries only where this is necessary for the performance of the contract (e.g. at the customer’s request for delivery or payment).
Users may optionally create a user account, in which they can in particular view their orders. During registration, users are informed of the required mandatory information. User accounts are not public and cannot be indexed by search engines.
When users have terminated their user account, their data relating to the user account will be deleted, unless retention is necessary for commercial or tax law reasons pursuant to Art. 6 para. 1 lit. c GDPR. Information in the customer account remains until its deletion, followed by archiving where there is a legal obligation. It is the users’ responsibility to back up their data before the end of the contract in the event of termination.
As part of registration and subsequent logins as well as the use of our online services, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests as well as those of users in protection against misuse and other unauthorised use. As a general rule, these data are not passed on to third parties unless this is necessary for the pursuit of our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c GDPR.
Deletion takes place after the expiry of statutory warranty and comparable obligations; the necessity of retaining the data is reviewed every three years. In the case of statutory archiving obligations, deletion takes place after their expiry (end of the commercial-law retention period of 6 years and the tax-law retention period of 10 years).
We use external payment service providers through whose platforms users and we can carry out payment transactions (e.g., in each case with a link to the Privacy Policy):
PayPal: PayPal Privacy Policy
Klarna: Klarna Privacy Policy
Skrill: Skrill Privacy Policy
Giropay: Giropay Privacy Information
Visa: Visa Privacy Policy
Mastercard: Mastercard Privacy Policy
American Express: American Express Privacy Policy
For the performance of contracts, we use payment service providers on the basis of Art. 6 para. 1 lit. b GDPR. In addition, we use external payment service providers on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR in order to offer our users effective and secure payment options.
The data processed by payment service providers include master data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and verification codes, as well as contract-related, amount-related and recipient-related information. The information is required in order to carry out the transactions.
However, the data entered are processed and stored only by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit agencies. The purpose of this transmission is identity and creditworthiness checks. In this regard, we refer to the terms and conditions and privacy information of the payment service providers.
The terms and conditions and privacy information of the respective payment service providers apply to payment transactions and can be accessed on the respective websites or transaction applications. We also refer to these for further information and for exercising rights of withdrawal, access and other data subject rights.
We process data in connection with administrative tasks and the organisation of our business, financial accounting and compliance with legal obligations, such as archiving. In this context, we process the same data that we process in connection with the provision of our contractual services.
The legal bases for processing are Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. The processing concerns customers, prospective customers, business partners and website visitors. The purpose of and our interest in processing lies in administration, financial accounting, office organisation and data archiving, i.e. tasks that serve to maintain our business activities, perform our duties and provide our services. The deletion of data relating to contractual services and contractual communication corresponds to the information stated for these processing activities.
In this context, we disclose or transmit data to the financial authorities, advisers such as tax advisers or auditors, as well as other fee-collecting bodies and payment service providers.
Furthermore, on the basis of our business interests, we store information about suppliers, organisers and other business partners, e.g. for the purpose of contacting them at a later date. As a general rule, we store these predominantly company-related data permanently.
Users can create a user account. During registration, users are informed of the required mandatory information, which is processed on the basis of Art. 6 para. 1 lit. b GDPR for the purpose of providing the user account. The data processed include, in particular, login information (name, password and an email address). The data entered during registration are used for the purposes of using the user account and its intended purpose.
Users may be informed by email about information relevant to their user account, such as technical changes. If users have terminated their user account, their data relating to the user account will be deleted, subject to any statutory retention obligation. It is the users’ responsibility to back up their data before the end of the contract in the event of termination. We are entitled to irretrievably delete all user data stored during the term of the contract.
As part of the use of our registration and login functions and the use of the user account, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests as well as those of users in protection against misuse and other unauthorised use. As a general rule, these data are not passed on to third parties unless this is necessary for the pursuit of our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c GDPR. IP addresses are anonymised or deleted after no more than 7 days.
When contacting us (e.g. via contact form, email, telephone or social media), the information provided by the user is processed for the purpose of handling and processing the contact request pursuant to Art. 6 para. 1 lit. b GDPR. Users’ information may be stored in a Customer Relationship Management system (“CRM system”) or comparable enquiry management system.
We delete enquiries if they are no longer required. We review the necessity every two years; statutory archiving obligations also apply.
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services and technical maintenance services, which we use for the purpose of operating this online offering.
In this context, we or our hosting provider process master data, contact data, content data, contract data, usage data, meta data and communication data of customers, prospective customers and visitors to this online offering on the basis of our legitimate interests in the efficient and secure provision of this online offering pursuant to Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
We, or our hosting provider, collect data about every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR.
The access data include the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider.
Log file information is stored for security reasons (e.g. to investigate misuse or fraud) for a maximum period of 7 days and is then deleted. Data whose further retention is necessary for evidentiary purposes are excluded from deletion until the respective incident has been finally clarified.
We integrate fonts (“Google Fonts”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Privacy Policy: Google Privacy Policy
Opt-Out: Google Ads Settings
Created with Datenschutz-Generator.de by attorney Dr. Thomas Schwenke.
This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to briefly as “data”) within our online offering and the websites, functions and content associated with it, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terminology used, such as “processing” or “controller”, we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Blanket Store
Hasengasse 2
60311 Frankfurt
Germany
Email: natalie(at)blanketstore.de
Owner: Natalie Gray
Legal Notice: http://blanketstore.de/index.php/de/impressum
Master data (e.g. names, addresses).
Contact data (e.g. email, telephone numbers).
Content data (e.g. text entries, photographs, videos).
Usage data (e.g. websites visited, interest in content, access times).
Meta/communication data (e.g. device information, IP addresses).
Visitors and users of the online offering (hereinafter we also refer to the data subjects collectively as “users”).
Provision of the online offering, its functions and content.
Responding to contact requests and communicating with users.
Security measures.
Reach measurement/marketing.
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing activities. Unless the legal basis is specified in this Privacy Policy, the following applies: The legal basis for obtaining consent is Art. 6 para. 1 lit. a and Art. 7 GDPR; the legal basis for processing for the performance of our services and implementation of contractual measures as well as responding to enquiries is Art. 6 para. 1 lit. b GDPR; the legal basis for processing for compliance with our legal obligations is Art. 6 para. 1 lit. c GDPR; and the legal basis for processing for the purposes of our legitimate interests is Art. 6 para. 1 lit. f GDPR. Where the vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.
In accordance with Art. 32 GDPR and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input, disclosure, safeguarding of availability and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data and response to threats to data security. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principles of data protection by design and by default (Art. 25 GDPR).
Where, as part of our processing, we disclose data to other persons and companies (processors or third parties), transfer data to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR), where you have consented, where a legal obligation requires it or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).
Where we commission third parties to process data on the basis of a so-called “data processing agreement”, this is done on the basis of Art. 28 GDPR.
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transferring data to third parties, this is done only where it is necessary for the performance of our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests.
Subject to statutory or contractual permissions, we process or have data processed in a third country only where the special requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of special safeguards, such as the officially recognised determination of a level of data protection corresponding to that of the EU (e.g. for the USA through the “Privacy Shield”) or compliance with officially recognised special contractual obligations (so-called “Standard Contractual Clauses”).
You have the right to request confirmation as to whether data concerning you are being processed and to obtain information about such data, as well as further information and a copy of the data in accordance with Art. 15 GDPR.
In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
In accordance with Art. 17 GDPR, you have the right to request that data concerning you be deleted without undue delay or, alternatively, in accordance with Art. 18 GDPR, to request restriction of the processing of the data.
You have the right to request that the data concerning you which you have provided to us be received in accordance with Art. 20 GDPR and to request that such data be transmitted to other controllers.
Furthermore, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
You have the right to withdraw consent that you have given pursuant to Art. 7 para. 3 GDPR with effect for the future.
You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. The objection may in particular be made against processing for direct marketing purposes.
“Cookies” are small files that are stored on users’ computers. Various types of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offering.
Temporary cookies, also referred to as “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online offering and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online shop or a login status.
Cookies that remain stored even after the browser has been closed are referred to as “permanent” or “persistent”. For example, the login status can be stored if users return after several days. Such a cookie may also store users’ interests, which are used for reach measurement or marketing purposes.
“Third-party cookies” are cookies offered by providers other than the controller operating the online offering (otherwise, if they are only the controller’s cookies, they are referred to as “first-party cookies”).
We may use temporary and permanent cookies and provide information about this within our Privacy Policy.
If users do not want cookies to be stored on their computer, they are requested to disable the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. The exclusion of cookies may lead to functional limitations of this online offering.
A general objection to the use of cookies used for online marketing purposes can be declared for many services, particularly in the case of tracking, via the US website aboutads.info/choices or the EU website Your Online Choices. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that in this case not all functions of this online offering may be available.
The data processed by us will be deleted or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated otherwise within this Privacy Policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and provided that deletion does not conflict with statutory retention obligations.
Where the data are not deleted because they are required for other legally permissible purposes, their processing will be restricted. This means that the data will be blocked and will not be processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
In accordance with statutory requirements in Germany, records are retained in particular for 10 years pursuant to §§ 147 para. 1 AO, 257 para. 1 nos. 1 and 4, para. 4 HGB (books, records, management reports, accounting documents, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to § 257 para. 1 nos. 2 and 3, para. 4 HGB (commercial correspondence).
In accordance with statutory requirements in Austria, records are retained in particular for 7 years pursuant to § 132 para. 1 BAO (accounting records, receipts/invoices, accounts, documents, business papers, statements of income and expenditure, etc.), for 22 years in connection with real estate and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU Member States for which the Mini One Stop Shop (MOSS) is used.
In addition, we process:
Contract data (e.g. subject matter of the contract, term, customer category).
Payment data (e.g. bank details, payment history)
of our customers, prospective customers and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.
We process our customers’ data as part of the ordering processes in our online shop in order to enable them to select and order the chosen products and services and to enable their payment and delivery or performance.
The data processed include master data, communication data, contract data and payment data, and the persons affected by the processing include our customers, prospective customers and other business partners. Processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer service. In this context, we use session cookies to store the contents of the shopping cart and permanent cookies to store the login status.
Processing is carried out on the basis of Art. 6 para. 1 lit. b (processing of orders) and c (legally required archiving) GDPR. Information marked as required is necessary for the establishment and performance of the contract. We disclose data to third parties only in connection with delivery, payment or within the framework of statutory permissions and obligations towards legal advisers and authorities. Data are processed in third countries only where this is necessary for the performance of the contract (e.g. at the customer’s request for delivery or payment).
Users may optionally create a user account, in which they can in particular view their orders. During registration, users are informed of the required mandatory information. User accounts are not public and cannot be indexed by search engines.
When users have terminated their user account, their data relating to the user account will be deleted, unless retention is necessary for commercial or tax law reasons pursuant to Art. 6 para. 1 lit. c GDPR. Information in the customer account remains until its deletion, followed by archiving where there is a legal obligation. It is the users’ responsibility to back up their data before the end of the contract in the event of termination.
As part of registration and subsequent logins as well as the use of our online services, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests as well as those of users in protection against misuse and other unauthorised use. As a general rule, these data are not passed on to third parties unless this is necessary for the pursuit of our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c GDPR.
Deletion takes place after the expiry of statutory warranty and comparable obligations; the necessity of retaining the data is reviewed every three years. In the case of statutory archiving obligations, deletion takes place after their expiry (end of the commercial-law retention period of 6 years and the tax-law retention period of 10 years).
We use external payment service providers through whose platforms users and we can carry out payment transactions (e.g., in each case with a link to the Privacy Policy):
PayPal: PayPal Privacy Policy
Klarna: Klarna Privacy Policy
Skrill: Skrill Privacy Policy
Giropay: Giropay Privacy Information
Visa: Visa Privacy Policy
Mastercard: Mastercard Privacy Policy
American Express: American Express Privacy Policy
For the performance of contracts, we use payment service providers on the basis of Art. 6 para. 1 lit. b GDPR. In addition, we use external payment service providers on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR in order to offer our users effective and secure payment options.
The data processed by payment service providers include master data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and verification codes, as well as contract-related, amount-related and recipient-related information. The information is required in order to carry out the transactions.
However, the data entered are processed and stored only by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit agencies. The purpose of this transmission is identity and creditworthiness checks. In this regard, we refer to the terms and conditions and privacy information of the payment service providers.
The terms and conditions and privacy information of the respective payment service providers apply to payment transactions and can be accessed on the respective websites or transaction applications. We also refer to these for further information and for exercising rights of withdrawal, access and other data subject rights.
We process data in connection with administrative tasks and the organisation of our business, financial accounting and compliance with legal obligations, such as archiving. In this context, we process the same data that we process in connection with the provision of our contractual services.
The legal bases for processing are Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. The processing concerns customers, prospective customers, business partners and website visitors. The purpose of and our interest in processing lies in administration, financial accounting, office organisation and data archiving, i.e. tasks that serve to maintain our business activities, perform our duties and provide our services. The deletion of data relating to contractual services and contractual communication corresponds to the information stated for these processing activities.
In this context, we disclose or transmit data to the financial authorities, advisers such as tax advisers or auditors, as well as other fee-collecting bodies and payment service providers.
Furthermore, on the basis of our business interests, we store information about suppliers, organisers and other business partners, e.g. for the purpose of contacting them at a later date. As a general rule, we store these predominantly company-related data permanently.
Users can create a user account. During registration, users are informed of the required mandatory information, which is processed on the basis of Art. 6 para. 1 lit. b GDPR for the purpose of providing the user account. The data processed include, in particular, login information (name, password and an email address). The data entered during registration are used for the purposes of using the user account and its intended purpose.
Users may be informed by email about information relevant to their user account, such as technical changes. If users have terminated their user account, their data relating to the user account will be deleted, subject to any statutory retention obligation. It is the users’ responsibility to back up their data before the end of the contract in the event of termination. We are entitled to irretrievably delete all user data stored during the term of the contract.
As part of the use of our registration and login functions and the use of the user account, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests as well as those of users in protection against misuse and other unauthorised use. As a general rule, these data are not passed on to third parties unless this is necessary for the pursuit of our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c GDPR. IP addresses are anonymised or deleted after no more than 7 days.
When contacting us (e.g. via contact form, email, telephone or social media), the information provided by the user is processed for the purpose of handling and processing the contact request pursuant to Art. 6 para. 1 lit. b GDPR. Users’ information may be stored in a Customer Relationship Management system (“CRM system”) or comparable enquiry management system.
We delete enquiries if they are no longer required. We review the necessity every two years; statutory archiving obligations also apply.
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services and technical maintenance services, which we use for the purpose of operating this online offering.
In this context, we or our hosting provider process master data, contact data, content data, contract data, usage data, meta data and communication data of customers, prospective customers and visitors to this online offering on the basis of our legitimate interests in the efficient and secure provision of this online offering pursuant to Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).
We, or our hosting provider, collect data about every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR.
The access data include the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider.
Log file information is stored for security reasons (e.g. to investigate misuse or fraud) for a maximum period of 7 days and is then deleted. Data whose further retention is necessary for evidentiary purposes are excluded from deletion until the respective incident has been finally clarified.
We integrate fonts (“Google Fonts”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Privacy Policy: Google Privacy Policy
Opt-Out: Google Ads Settings
Created with Datenschutz-Generator.de by attorney Dr. Thomas Schwenke.
Diese Datenschutzerklärung klärt Sie über die Art, den Umfang und Zweck der Verarbeitung von personenbezogenen Daten (nachfolgend kurz „Daten“) innerhalb unseres Onlineangebotes und der mit ihm verbundenen Webseiten, Funktionen und Inhalte sowie externen Onlinepräsenzen, wie z.B. unser Social Media Profile auf (nachfolgend gemeinsam bezeichnet als „Onlineangebot“). Im Hinblick auf die verwendeten Begrifflichkeiten, wie z.B. „Verarbeitung“ oder „Verantwortlicher“ verweisen wir auf die Definitionen im Art. 4 der Datenschutzgrundverordnung (DSGVO).
Blanket Store
Hasengasse 2
60311 Frankfurt
Deutschland
E-Mail: natalie(at)blanketstore.de
Inhaberin Natalie Gray
Impressum http://blanketstore.de/index.php/de/impressum
- Bestandsdaten (z.B., Namen, Adressen).
- Kontaktdaten (z.B., E-Mail, Telefonnummern).
- Inhaltsdaten (z.B., Texteingaben, Fotografien, Videos).
- Nutzungsdaten (z.B., besuchte Webseiten, Interesse an Inhalten, Zugriffszeiten).
- Meta-/Kommunikationsdaten (z.B., Geräte-Informationen, IP-Adressen).
Besucher und Nutzer des Onlineangebotes (Nachfolgend bezeichnen wir die betroffenen Personen zusammenfassend auch als „Nutzer“).
- Zurverfügungstellung des Onlineangebotes, seiner Funktionen und Inhalte.
- Beantwortung von Kontaktanfragen und Kommunikation mit Nutzern.
- Sicherheitsmaßnahmen.
- Reichweitenmessung/Marketing
„Personenbezogene Daten“ sind alle Informationen, die sich auf eine identifizierte oder identifizierbare natürliche Person (im Folgenden „betroffene Person“) beziehen; als identifizierbar wird eine natürliche Person angesehen, die direkt oder indirekt, insbesondere mittels Zuordnung zu einer Kennung wie einem Namen, zu einer Kennnummer, zu Standortdaten, zu einer Online-Kennung (z.B. Cookie) oder zu einem oder mehreren besonderen Merkmalen identifiziert werden kann, die Ausdruck der physischen, physiologischen, genetischen, psychischen, wirtschaftlichen, kulturellen oder sozialen Identität dieser natürlichen Person sind.
„Verarbeitung“ ist jeder mit oder ohne Hilfe automatisierter Verfahren ausgeführte Vorgang oder jede solche Vorgangsreihe im Zusammenhang mit personenbezogenen Daten. Der Begriff reicht weit und umfasst praktisch jeden Umgang mit Daten.
„Pseudonymisierung“ die Verarbeitung personenbezogener Daten in einer Weise, dass die personenbezogenen Daten ohne Hinzuziehung zusätzlicher Informationen nicht mehr einer spezifischen betroffenen Person zugeordnet werden können, sofern diese zusätzlichen Informationen gesondert aufbewahrt werden und technischen und organisatorischen Maßnahmen unterliegen, die gewährleisten, dass die personenbezogenen Daten nicht einer identifizierten oder identifizierbaren natürlichen Person zugewiesen werden.
„Profiling“ jede Art der automatisierten Verarbeitung personenbezogener Daten, die darin besteht, dass diese personenbezogenen Daten verwendet werden, um bestimmte persönliche Aspekte, die sich auf eine natürliche Person beziehen, zu bewerten, insbesondere um Aspekte bezüglich Arbeitsleistung, wirtschaftliche Lage, Gesundheit, persönliche Vorlieben, Interessen, Zuverlässigkeit, Verhalten, Aufenthaltsort oder Ortswechsel dieser natürlichen Person zu analysieren oder vorherzusagen.
Als „Verantwortlicher“ wird die natürliche oder juristische Person, Behörde, Einrichtung oder andere Stelle, die allein oder gemeinsam mit anderen über die Zwecke und Mittel der Verarbeitung von personenbezogenen Daten entscheidet, bezeichnet.
„Auftragsverarbeiter“ eine natürliche oder juristische Person, Behörde, Einrichtung oder andere Stelle, die personenbezogene Daten im Auftrag des Verantwortlichen verarbeitet.
Nach Maßgabe des Art. 13 DSGVO teilen wir Ihnen die Rechtsgrundlagen unserer Datenverarbeitungen mit. Sofern die Rechtsgrundlage in der Datenschutzerklärung nicht genannt wird, gilt Folgendes: Die Rechtsgrundlage für die Einholung von Einwilligungen ist Art. 6 Abs. 1 lit. a und Art. 7 DSGVO, die Rechtsgrundlage für die Verarbeitung zur Erfüllung unserer Leistungen und Durchführung vertraglicher Maßnahmen sowie Beantwortung von Anfragen ist Art. 6 Abs. 1 lit. b DSGVO, die Rechtsgrundlage für die Verarbeitung zur Erfüllung unserer rechtlichen Verpflichtungen ist Art. 6 Abs. 1 lit. c DSGVO, und die Rechtsgrundlage für die Verarbeitung zur Wahrung unserer berechtigten Interessen ist Art. 6 Abs. 1 lit. f DSGVO. Für den Fall, dass lebenswichtige Interessen der betroffenen Person oder einer anderen natürlichen Person eine Verarbeitung personenbezogener Daten erforderlich machen, dient Art. 6 Abs. 1 lit. d DSGVO als Rechtsgrundlage.
Wir treffen nach Maßgabe des Art. 32 DSGVO unter Berücksichtigung des Stands der Technik, der Implementierungskosten und der Art, des Umfangs, der Umstände und der Zwecke der Verarbeitung sowie der unterschiedlichen Eintrittswahrscheinlichkeit und Schwere des Risikos für die Rechte und Freiheiten natürlicher Personen, geeignete technische und organisatorische Maßnahmen, um ein dem Risiko angemessenes Schutzniveau zu gewährleisten.
Zu den Maßnahmen gehören insbesondere die Sicherung der Vertraulichkeit, Integrität und Verfügbarkeit von Daten durch Kontrolle des physischen Zugangs zu den Daten, als auch des sie betreffenden Zugriffs, der Eingabe, Weitergabe, der Sicherung der Verfügbarkeit und ihrer Trennung. Des Weiteren haben wir Verfahren eingerichtet, die eine Wahrnehmung von Betroffenenrechten, Löschung von Daten und Reaktion auf Gefährdung der Daten gewährleisten. Ferner berücksichtigen wir den Schutz personenbezogener Daten bereits bei der Entwicklung, bzw. Auswahl von Hardware, Software sowie Verfahren, entsprechend dem Prinzip des Datenschutzes durch Technikgestaltung und durch datenschutzfreundliche Voreinstellungen (Art. 25 DSGVO).
Sofern wir im Rahmen unserer Verarbeitung Daten gegenüber anderen Personen und Unternehmen (Auftragsverarbeitern oder Dritten) offenbaren, sie an diese übermitteln oder ihnen sonst Zugriff auf die Daten gewähren, erfolgt dies nur auf Grundlage einer gesetzlichen Erlaubnis (z.B. wenn eine Übermittlung der Daten an Dritte, wie an Zahlungsdienstleister, gem. Art. 6 Abs. 1 lit. b DSGVO zur Vertragserfüllung erforderlich ist), Sie eingewilligt haben, eine rechtliche Verpflichtung dies vorsieht oder auf Grundlage unserer berechtigten Interessen (z.B. beim Einsatz von Beauftragten, Webhostern, etc.).
Sofern wir Dritte mit der Verarbeitung von Daten auf Grundlage eines sog. „Auftragsverarbeitungsvertrages“ beauftragen, geschieht dies auf Grundlage des Art. 28 DSGVO.
Sofern wir Daten in einem Drittland (d.h. außerhalb der Europäischen Union (EU) oder des Europäischen Wirtschaftsraums (EWR)) verarbeiten oder dies im Rahmen der Inanspruchnahme von Diensten Dritter oder Offenlegung, bzw. Übermittlung von Daten an Dritte geschieht, erfolgt dies nur, wenn es zur Erfüllung unserer (vor)vertraglichen Pflichten, auf Grundlage Ihrer Einwilligung, aufgrund einer rechtlichen Verpflichtung oder auf Grundlage unserer berechtigten Interessen geschieht. Vorbehaltlich gesetzlicher oder vertraglicher Erlaubnisse, verarbeiten oder lassen wir die Daten in einem Drittland nur beim Vorliegen der besonderen Voraussetzungen der Art. 44 ff. DSGVO verarbeiten. D.h. die Verarbeitung erfolgt z.B. auf Grundlage besonderer Garantien, wie der offiziell anerkannten Feststellung eines der EU entsprechenden Datenschutzniveaus (z.B. für die USA durch das „Privacy Shield“) oder Beachtung offiziell anerkannter spezieller vertraglicher Verpflichtungen (so genannte „Standardvertragsklauseln“).
Sie haben das Recht, eine Bestätigung darüber zu verlangen, ob betreffende Daten verarbeitet werden und auf Auskunft über diese Daten sowie auf weitere Informationen und Kopie der Daten entsprechend Art. 15 DSGVO.
Sie haben entsprechend. Art. 16 DSGVO das Recht, die Vervollständigung der Sie betreffenden Daten oder die Berichtigung der Sie betreffenden unrichtigen Daten zu verlangen.
Sie haben nach Maßgabe des Art. 17 DSGVO das Recht zu verlangen, dass betreffende Daten unverzüglich gelöscht werden, bzw. alternativ nach Maßgabe des Art. 18 DSGVO eine Einschränkung der Verarbeitung der Daten zu verlangen.
Sie haben das Recht zu verlangen, dass die Sie betreffenden Daten, die Sie uns bereitgestellt haben nach Maßgabe des Art. 20 DSGVO zu erhalten und deren Übermittlung an andere Verantwortliche zu fordern.
Sie haben ferner gem. Art. 77 DSGVO das Recht, eine Beschwerde bei der zuständigen Aufsichtsbehörde einzureichen.
Sie haben das Recht, erteilte Einwilligungen gem. Art. 7 Abs. 3 DSGVO mit Wirkung für die Zukunft zu widerrufen
Sie können der künftigen Verarbeitung der Sie betreffenden Daten nach Maßgabe des Art. 21 DSGVO jederzeit widersprechen. Der Widerspruch kann insbesondere gegen die Verarbeitung für Zwecke der Direktwerbung erfolgen.
Als „Cookies“ werden kleine Dateien bezeichnet, die auf Rechnern der Nutzer gespeichert werden. Innerhalb der Cookies können unterschiedliche Angaben gespeichert werden. Ein Cookie dient primär dazu, die Angaben zu einem Nutzer (bzw. dem Gerät auf dem das Cookie gespeichert ist) während oder auch nach seinem Besuch innerhalb eines Onlineangebotes zu speichern. Als temporäre Cookies, bzw. „Session-Cookies“ oder „transiente Cookies“, werden Cookies bezeichnet, die gelöscht werden, nachdem ein Nutzer ein Onlineangebot verlässt und seinen Browser schließt. In einem solchen Cookie kann z.B. der Inhalt eines Warenkorbs in einem Onlineshop oder ein Login-Status gespeichert werden. Als „permanent“ oder „persistent“ werden Cookies bezeichnet, die auch nach dem Schließen des Browsers gespeichert bleiben. So kann z.B. der Login-Status gespeichert werden, wenn die Nutzer diese nach mehreren Tagen aufsuchen. Ebenso können in einem solchen Cookie die Interessen der Nutzer gespeichert werden, die für Reichweitenmessung oder Marketingzwecke verwendet werden. Als „Third-Party-Cookie“ werden Cookies bezeichnet, die von anderen Anbietern als dem Verantwortlichen, der das Onlineangebot betreibt, angeboten werden (andernfalls, wenn es nur dessen Cookies sind spricht man von „First-Party Cookies“).
Wir können temporäre und permanente Cookies einsetzen und klären hierüber im Rahmen unserer Datenschutzerklärung auf.
Falls die Nutzer nicht möchten, dass Cookies auf ihrem Rechner gespeichert werden, werden sie gebeten die entsprechende Option in den Systemeinstellungen ihres Browsers zu deaktivieren. Gespeicherte Cookies können in den Systemeinstellungen des Browsers gelöscht werden. Der Ausschluss von Cookies kann zu Funktionseinschränkungen dieses Onlineangebotes führen.
Ein genereller Widerspruch gegen den Einsatz der zu Zwecken des Onlinemarketing eingesetzten Cookies kann bei einer Vielzahl der Dienste, vor allem im Fall des Trackings, über die US-amerikanische Seite http://www.aboutads.info/choices/ oder die EU-Seite http://www.youronlinechoices.com/ erklärt werden. Des Weiteren kann die Speicherung von Cookies mittels deren Abschaltung in den Einstellungen des Browsers erreicht werden. Bitte beachten Sie, dass dann gegebenenfalls nicht alle Funktionen dieses Onlineangebotes genutzt werden können.
Die von uns verarbeiteten Daten werden nach Maßgabe der Art. 17 und 18 DSGVO gelöscht oder in ihrer Verarbeitung eingeschränkt. Sofern nicht im Rahmen dieser Datenschutzerklärung ausdrücklich angegeben, werden die bei uns gespeicherten Daten gelöscht, sobald sie für ihre Zweckbestimmung nicht mehr erforderlich sind und der Löschung keine gesetzlichen Aufbewahrungspflichten entgegenstehen. Sofern die Daten nicht gelöscht werden, weil sie für andere und gesetzlich zulässige Zwecke erforderlich sind, wird deren Verarbeitung eingeschränkt. D.h. die Daten werden gesperrt und nicht für andere Zwecke verarbeitet. Das gilt z.B. für Daten, die aus handels- oder steuerrechtlichen Gründen aufbewahrt werden müssen.
Nach gesetzlichen Vorgaben in Deutschland, erfolgt die Aufbewahrung insbesondere für 10 Jahre gemäß §§ 147 Abs. 1 AO, 257 Abs. 1 Nr. 1 und 4, Abs. 4 HGB (Bücher, Aufzeichnungen, Lageberichte, Buchungsbelege, Handelsbücher, für Besteuerung relevanter Unterlagen, etc.) und 6 Jahre gemäß § 257 Abs. 1 Nr. 2 und 3, Abs. 4 HGB (Handelsbriefe).
Nach gesetzlichen Vorgaben in Österreich erfolgt die Aufbewahrung insbesondere für 7 J gemäß § 132 Abs. 1 BAO (Buchhaltungsunterlagen, Belege/Rechnungen, Konten, Belege, Geschäftspapiere, Aufstellung der Einnahmen und Ausgaben, etc.), für 22 Jahre im Zusammenhang mit Grundstücken und für 10 Jahre bei Unterlagen im Zusammenhang mit elektronisch erbrachten Leistungen, Telekommunikations-, Rundfunk- und Fernsehleistungen, die an Nichtunternehmer in EU-Mitgliedstaaten erbracht werden und für die der Mini-One-Stop-Shop (MOSS) in Anspruch genommen wird.
Zusätzlich verarbeiten wir
- Vertragsdaten (z.B., Vertragsgegenstand, Laufzeit, Kundenkategorie).
- Zahlungsdaten (z.B., Bankverbindung, Zahlungshistorie)
von unseren Kunden, Interessenten und Geschäftspartner zwecks Erbringung vertraglicher Leistungen, Service und Kundenpflege, Marketing, Werbung und Marktforschung.
Wir verarbeiten die Daten unserer Kunden im Rahmen der Bestellvorgänge in unserem Onlineshop, um ihnen die Auswahl und die Bestellung der gewählten Produkte und Leistungen, sowie deren Bezahlung und Zustellung, bzw. Ausführung zu ermöglichen.
Zu den verarbeiteten Daten gehören Bestandsdaten, Kommunikationsdaten, Vertragsdaten, Zahlungsdaten und zu den von der Verarbeitung betroffenen Personen gehören unsere Kunden, Interessenten und sonstige Geschäftspartner. Die Verarbeitung erfolgt zum Zweck der Erbringung von Vertragsleistungen im Rahmen des Betriebs eines Onlineshops, Abrechnung, Auslieferung und der Kundenservices. Hierbei setzen wir Session Cookies für die Speicherung des Warenkorb-Inhalts und permanente Cookies für die Speicherung des Login-Status ein.
Die Verarbeitung erfolgt auf Grundlage des Art. 6 Abs. 1 lit. b (Durchführung Bestellvorgänge) und c (Gesetzlich erforderliche Archivierung) DSGVO. Dabei sind die als erforderlich gekennzeichneten Angaben zur Begründung und Erfüllung des Vertrages erforderlich. Die Daten offenbaren wir gegenüber Dritten nur im Rahmen der Auslieferung, Zahlung oder im Rahmen der gesetzlichen Erlaubnisse und Pflichten gegenüber Rechtsberatern und Behörden. Die Daten werden in Drittländern nur dann verarbeitet, wenn dies zur Vertragserfüllung erforderlich ist (z.B. auf Kundenwunsch bei Auslieferung oder Zahlung).
Nutzer können optional ein Nutzerkonto anlegen, indem sie insbesondere ihre Bestellungen einsehen können. Im Rahmen der Registrierung, werden die erforderlichen Pflichtangaben den Nutzern mitgeteilt. Die Nutzerkonten sind nicht öffentlich und können von Suchmaschinen nicht indexiert werden. Wenn Nutzer ihr Nutzerkonto gekündigt haben, werden deren Daten im Hinblick auf das Nutzerkonto gelöscht, vorbehaltlich deren Aufbewahrung ist aus handels- oder steuerrechtlichen Gründen entspr. Art. 6 Abs. 1 lit. c DSGVO notwendig. Angaben im Kundenkonto verbleiben bis zu dessen Löschung mit anschließender Archivierung im Fall einer rechtlichen Verpflichtung. Es obliegt den Nutzern, ihre Daten bei erfolgter Kündigung vor dem Vertragsende zu sichern.
Im Rahmen der Registrierung und erneuter Anmeldungen sowie Inanspruchnahme unserer Onlinedienste, speichern wir die IP-Adresse und den Zeitpunkt der jeweiligen Nutzerhandlung. Die Speicherung erfolgt auf Grundlage unserer berechtigten Interessen, als auch der Nutzer an Schutz vor Missbrauch und sonstiger unbefugter Nutzung. Eine Weitergabe dieser Daten an Dritte erfolgt grundsätzlich nicht, außer sie ist zur Verfolgung unserer Ansprüche erforderlich oder es besteht hierzu eine gesetzliche Verpflichtung gem. Art. 6 Abs. 1 lit. c DSGVO.
Die Löschung erfolgt nach Ablauf gesetzlicher Gewährleistungs- und vergleichbarer Pflichten, die Erforderlichkeit der Aufbewahrung der Daten wird alle drei Jahre überprüft; im Fall der gesetzlichen Archivierungspflichten erfolgt die Löschung nach deren Ablauf (Ende handelsrechtlicher (6 Jahre) und steuerrechtlicher (10 Jahre) Aufbewahrungspflicht).
Wir setzen externe Zahlungsdienstleister ein, über deren Plattformen die Nutzer und wir Zahlungstransaktionen vornehmen können (z.B., jeweils mit Link zur Datenschutzerklärung, Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full), Klarna (https://www.klarna.com/de/datenschutz/), Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/), Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/), Visa (https://www.visa.de/datenschutz), Mastercard (https://www.mastercard.de/de-de/datenschutz.html), American Express (https://www.americanexpress.com/de/content/privacy-policy-statement.html)
Im Rahmen der Erfüllung von Verträgen setzen wir die Zahlungsdienstleister auf Grundlage des Art. 6 Abs. 1 lit. b. DSGVO ein. Im Übrigen setzen wir externe Zahlungsdienstleister auf Grundlage unserer berechtigten Interessen gem. Art. 6 Abs. 1 lit. f. DSGVO ein, um unseren Nutzern effektive und sichere Zahlungsmöglichkeit zu bieten.
Zu den, durch die Zahlungsdienstleister verarbeiteten Daten gehören Bestandsdaten, wie z.B. der Name und die Adresse, Bankdaten, wie z.B. Kontonummern oder Kreditkartennummern, Passwörter, TANs und Prüfsummen sowie die Vertrags-, Summen und empfängerbezogenen Angaben. Die Angaben sind erforderlich, um die Transaktionen durchzuführen. Die eingegebenen Daten werden jedoch nur durch die Zahlungsdienstleister verarbeitet und bei diesen gespeichert. D.h. wir erhalten keine konto- oder kreditkartenbezogenen Informationen, sondern lediglich Informationen mit Bestätigung oder Negativbeauskunftung der Zahlung. Unter Umständen werden die Daten seitens der Zahlungsdienstleister an Wirtschaftsauskunfteien übermittelt. Diese Übermittlung bezweckt die Identitäts- und Bonitätsprüfung. Hierzu verweisen wir auf die AGB und Datenschutzhinweise der Zahlungsdienstleister.
Für die Zahlungsgeschäfte gelten die Geschäftsbedingungen und die Datenschutzhinweise der jeweiligen Zahlungsdienstleister, welche innerhalb der jeweiligen Webseiten, bzw. Transaktionsapplikationen abrufbar sind. Wir verweisen auf diese ebenfalls zwecks weiterer Informationen und Geltendmachung von Widerrufs-, Auskunfts- und anderen Betroffenenrechten.
Wir verarbeiten Daten im Rahmen von Verwaltungsaufgaben sowie Organisation unseres Betriebs, Finanzbuchhaltung und Befolgung der gesetzlichen Pflichten, wie z.B. der Archivierung. Hierbei verarbeiten wir dieselben Daten, die wir im Rahmen der Erbringung unserer vertraglichen Leistungen verarbeiten. Die Verarbeitungsgrundlagen sind Art. 6 Abs. 1 lit. c. DSGVO, Art. 6 Abs. 1 lit. f. DSGVO. Von der Verarbeitung sind Kunden, Interessenten, Geschäftspartner und Websitebesucher betroffen. Der Zweck und unser Interesse an der Verarbeitung liegt in der Administration, Finanzbuchhaltung, Büroorganisation, Archivierung von Daten, also Aufgaben die der Aufrechterhaltung unserer Geschäftstätigkeiten, Wahrnehmung unserer Aufgaben und Erbringung unserer Leistungen dienen. Die Löschung der Daten im Hinblick auf vertragliche Leistungen und die vertragliche Kommunikation entspricht den, bei diesen Verarbeitungstätigkeiten genannten Angaben.
Wir offenbaren oder übermitteln hierbei Daten an die Finanzverwaltung, Berater, wie z.B., Steuerberater oder Wirtschaftsprüfer sowie weitere Gebührenstellen und Zahlungsdienstleister.
Ferner speichern wir auf Grundlage unserer betriebswirtschaftlichen Interessen Angaben zu Lieferanten, Veranstaltern und sonstigen Geschäftspartnern, z.B. zwecks späterer Kontaktaufnahme. Diese mehrheitlich unternehmensbezogenen Daten, speichern wir grundsätzlich dauerhaft.
Nutzer können ein Nutzerkonto anlegen. Im Rahmen der Registrierung werden die erforderlichen Pflichtangaben den Nutzern mitgeteilt und auf Grundlage des Art. 6 Abs. 1 lit. b DSGVO zu Zwecken der Bereitstellung des Nutzerkontos verarbeitet. Zu den verarbeiteten Daten gehören insbesondere die Login-Informationen (Name, Passwort sowie eine E-Mailadresse). Die im Rahmen der Registrierung eingegebenen Daten werden für die Zwecke der Nutzung des Nutzerkontos und dessen Zwecks verwendet.
Die Nutzer können über Informationen, die für deren Nutzerkonto relevant sind, wie z.B. technische Änderungen, per E-Mail informiert werden. Wenn Nutzer ihr Nutzerkonto gekündigt haben, werden deren Daten im Hinblick auf das Nutzerkonto, vorbehaltlich einer gesetzlichen Aufbewahrungspflicht, gelöscht. Es obliegt den Nutzern, ihre Daten bei erfolgter Kündigung vor dem Vertragsende zu sichern. Wir sind berechtigt, sämtliche während der Vertragsdauer gespeicherten Daten des Nutzers unwiederbringlich zu löschen.
Im Rahmen der Inanspruchnahme unserer Registrierungs- und Anmeldefunktionen sowie der Nutzung des Nutzerkontos, speichern wird die IP-Adresse und den Zeitpunkt der jeweiligen Nutzerhandlung. Die Speicherung erfolgt auf Grundlage unserer berechtigten Interessen, als auch der Nutzer an Schutz vor Missbrauch und sonstiger unbefugter Nutzung. Eine Weitergabe dieser Daten an Dritte erfolgt grundsätzlich nicht, außer sie ist zur Verfolgung unserer Ansprüche erforderlich oder es besteht hierzu besteht eine gesetzliche Verpflichtung gem. Art. 6 Abs. 1 lit. c DSGVO. Die IP-Adressen werden spätestens nach 7 Tagen anonymisiert oder gelöscht.
Bei der Kontaktaufnahme mit uns (z.B. per Kontaktformular, E-Mail, Telefon oder via sozialer Medien) werden die Angaben des Nutzers zur Bearbeitung der Kontaktanfrage und deren Abwicklung gem. Art. 6 Abs. 1 lit. b) DSGVO verarbeitet. Die Angaben der Nutzer können in einem Customer-Relationship-Management System ("CRM System") oder vergleichbarer Anfragenorganisation gespeichert werden.
Wir löschen die Anfragen, sofern diese nicht mehr erforderlich sind. Wir überprüfen die Erforderlichkeit alle zwei Jahre; Ferner gelten die gesetzlichen Archivierungspflichten.
Die von uns in Anspruch genommenen Hosting-Leistungen dienen der Zurverfügungstellung der folgenden Leistungen: Infrastruktur- und Plattformdienstleistungen, Rechenkapazität, Speicherplatz und Datenbankdienste, E-Mail-Versand, Sicherheitsleistungen sowie technische Wartungsleistungen, die wir zum Zwecke des Betriebs dieses Onlineangebotes einsetzen.
Hierbei verarbeiten wir, bzw. unser Hostinganbieter Bestandsdaten, Kontaktdaten, Inhaltsdaten, Vertragsdaten, Nutzungsdaten, Meta- und Kommunikationsdaten von Kunden, Interessenten und Besuchern dieses Onlineangebotes auf Grundlage unserer berechtigten Interessen an einer effizienten und sicheren Zurverfügungstellung dieses Onlineangebotes gem. Art. 6 Abs. 1 lit. f DSGVO i.V.m. Art. 28 DSGVO (Abschluss Auftragsverarbeitungsvertrag).
Wir, bzw. unser Hostinganbieter, erhebt auf Grundlage unserer berechtigten Interessen im Sinne des Art. 6 Abs. 1 lit. f. DSGVO Daten über jeden Zugriff auf den Server, auf dem sich dieser Dienst befindet (sogenannte Serverlogfiles). Zu den Zugriffsdaten gehören Name der abgerufenen Webseite, Datei, Datum und Uhrzeit des Abrufs, übertragene Datenmenge, Meldung über erfolgreichen Abruf, Browsertyp nebst Version, das Betriebssystem des Nutzers, Referrer URL (die zuvor besuchte Seite), IP-Adresse und der anfragende Provider.
Logfile-Informationen werden aus Sicherheitsgründen (z.B. zur Aufklärung von Missbrauchs- oder Betrugshandlungen) für die Dauer von maximal 7 Tagen gespeichert und danach gelöscht. Daten, deren weitere Aufbewahrung zu Beweiszwecken erforderlich ist, sind bis zur endgültigen Klärung des jeweiligen Vorfalls von der Löschung ausgenommen.
Wir binden die Schriftarten ("Google Fonts") des Anbieters Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, ein. Datenschutzerklärung: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
Erstellt mit Datenschutz-Generator.de von RA Dr. Thomas Schwenke
Widerrufsrecht für Verbraucher
(Verbraucher ist jede natürliche Person, die ein Rechtsgeschäft zu Zwecken abschließt, die überwiegend weder ihrer gewerblichen noch ihrer selbstständigen beruflichen Tätigkeit zugerechnet werden kann.)
Widerrufsbelehrung
Widerrufsrecht Sie haben das Recht, binnen vierzehn Tagen ohne Angabe von Gründen diesen Vertrag zu widerrufen.
Die Widerrufsfrist beträgt vierzehn Tage ab dem Tag,
Um Ihr Widerrufsrecht auszuüben, müssen Sie uns (Natalie Gray/Blanket Store, Hasengasse 2, 60311 Frankfurt, Telefonnummer: 069-59771263, E-Mail-Adresse:
Zur Wahrung der Widerrufsfrist reicht es aus, dass Sie die Mitteilung über die Ausübung des Widerrufsrechts vor Ablauf der Widerrufsfrist absenden.
Folgen des Widerrufs
Wenn Sie diesen Vertrag widerrufen, haben wir Ihnen alle Zahlungen, die wir von Ihnen erhalten haben, einschließlich der Lieferkosten (mit Ausnahme der zusätzlichen Kosten, die sich daraus ergeben, dass Sie eine andere Art der Lieferung als die von uns angebotene, günstigste Standardlieferung gewählt haben), unverzüglich und spätestens binnen vierzehn Tagen ab dem Tag zurückzuzahlen, an dem die Mitteilung über Ihren Widerruf dieses Vertrags bei uns eingegangen ist. Für diese Rückzahlung verwenden wir dasselbe Zahlungsmittel, das Sie bei der ursprünglichen Transaktion eingesetzt haben, es sei denn, mit Ihnen wurde ausdrücklich etwas anderes vereinbart; in keinem Fall werden Ihnen wegen dieser Rückzahlung Entgelte berechnet.
Wir können die Rückzahlung verweigern, bis wir die Waren wieder zurückerhalten haben oder bis Sie den Nachweis erbracht haben, dass Sie die Waren zurückgesandt haben, je nachdem, welches der frühere Zeitpunkt ist.
Sie haben die Waren unverzüglich und in jedem Fall spätestens binnen vierzehn Tagen ab dem Tag, an dem Sie uns über den Widerruf dieses Vertrags unterrichten, an uns oder an Sabine Eilers, Steinauer Str. 16, 36396 Steinau/ Ulmbach zurückzusenden oder zu übergeben. Die Frist ist gewahrt, wenn Sie die Waren vor Ablauf der Frist von vierzehn Tagen absenden.
Sie tragen die unmittelbaren Kosten der Rücksendung der Waren.
Sie müssen für einen etwaigen Wertverlust der Waren nur aufkommen, wenn dieser Wertverlust auf einen zur Prüfung der Beschaffenheit, Eigenschaften und Funktionsweise der Waren nicht notwendigen Umgang mit ihnen zurückzuführen ist.
Ausschluss- bzw. Erlöschensgründe
Das Widerrufsrecht besteht nicht bei Verträgen
- zur Lieferung von Waren, die nicht vorgefertigt sind und für deren Herstellung eine individuelle Auswahl oder Bestimmung durch den Verbraucher maßgeblich ist oder die eindeutig auf die persönlichen Bedürfnisse des Verbrauchers zugeschnitten sind;
- zur Lieferung von Waren, die schnell verderben können oder deren Verfallsdatum schnell überschritten würde;
- zur Lieferung alkoholischer Getränke, deren Preis bei Vertragsschluss vereinbart wurde, die aber frühestens 30 Tage nach Vertragsschluss geliefert werden können und deren aktueller Wert von Schwankungen auf dem Markt abhängt, auf die der Unternehmer keinen Einfluss hat;
- zur Lieferung von Zeitungen, Zeitschriften oder Illustrierten mit Ausnahme von Abonnement-Verträgen.
Das Widerrufsrecht erlischt vorzeitig bei Verträgen
- zur Lieferung versiegelter Waren, die aus Gründen des Gesundheitsschutzes oder der Hygiene nicht zur Rückgabe geeignet sind, wenn ihre Versiegelung nach der Lieferung entfernt wurde;
- zur Lieferung von Waren, wenn diese nach der Lieferung aufgrund ihrer Beschaffenheit untrennbar mit anderen Gütern vermischt wurden;
- zur Lieferung von Ton- oder Videoaufnahmen oder Computersoftware in einer versiegelten Packung, wenn die Versiegelung nach der Lieferung entfernt wurde.
________________________________________________________________________________
Muster-Widerrufsformular
(Wenn Sie den Vertrag widerrufen wollen, dann füllen Sie bitte dieses Formular aus und senden Sie es zurück.)
- An Natalie Gray/Blanket Store, Hasengasse 2, 60311 Frankfurt, E-Mail-Adresse:
- Hiermit widerrufe(n) ich/ wir (*) den von mir/ uns (*) abgeschlossenen Vertrag über den Kauf der folgenden Waren (*)/
die Erbringung der folgenden Dienstleistung (*)
- Bestellt am (*)/ erhalten am (*)
- Name des/ der Verbraucher(s)
- Anschrift des/ der Verbraucher(s)
- Unterschrift des/ der Verbraucher(s) (nur bei Mitteilung auf Papier)
- Datum
(*) Unzutreffendes streichen.