DATA PROTECTION
Data protection is an important part of my work. I take the protection of your data very seriously and comply with all applicable data protection regulations. This privacy policy provides an overview of what personal data I collect and how I process it.
Data Collection and Processing
Control Over Your Data
I collect and process personal data only if you voluntarily provide it to me, for example, as part of an inquiry or booking. The data you provide will be used exclusively to process your inquiry or booking. It will not be shared with third parties unless this is necessary to fulfill the contract or unless you have given your express prior consent.
Data Security
You have the right to request, free of charge, information about the personal data I have stored about you. You also have the right to have this data corrected, blocked, or deleted. Please contact me using the contact details provided in the legal notice.
Links to Other Websites
I employ technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. My security measures are continuously improved in line with technological developments.
Privacy Policy
We process personal data (hereinafter generally referred to as “data”) only to the extent necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered there.
Pursuant to Article 4(1) of Regulation (EU) 2016/679, i.e., the General Data Protection Regulation (hereinafter referred to as the “GDPR”), “processing” means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
In the following privacy policy, we inform you in particular about the nature, scope, purpose, duration, and legal basis of the processing of personal data, insofar as we determine the purposes and means of processing either alone or jointly with others. In addition, we inform you below about the third-party components we use for optimization purposes and to enhance the quality of use, insofar as third parties process data in this context under their own responsibility.
Our Privacy Policy is structured as follows:
I. Information about us as the data controller
II. Rights of users and data subjects
III. Information on data processing
I. Information about us as the data controller
Elena Gröger
P.O. Box
8021 Zurich 1
II. RIGHTS OF USERS AND DATA SUBJECTS
With regard to the data processing described in more detail below, users and data subjects have the right
-
the right to confirmation as to whether data concerning them is being processed, the right to access the data being processed, the right to further information regarding the processing of the data, and the right to receive copies of the data (see also Art. 15 of the GDPR);
-
the right to have inaccurate or incomplete data corrected or completed (see also Art. 16 of the GDPR);
-
to the immediate erasure of the data concerning them (see also Art. 17 of the GDPR), or, alternatively, to the restriction of processing in accordance with Art. 18 of the GDPR, to the extent that further processing is necessary pursuant to Art. 17(3) of the GDPR;
-
to receive the data concerning them that they have provided and to have that data transmitted to other providers/controllers (see also Art. 20 of the GDPR);
-
to lodge a complaint with the supervisory authority if they believe that the provider is processing their personal data in violation of data protection regulations (see also Art. 77 of the GDPR).
In addition, the controller is required to inform all recipients to whom data has been disclosed by the controller of any rectification or erasure of data or restriction of processing carried out pursuant to Articles 16, 17(1), and 18 of the GDPR. However, this obligation does not apply if such notification is impossible or would involve a disproportionate effort. Notwithstanding this, the user has the right to obtain information about these recipients.
Furthermore, pursuant to Article 21 of the GDPR, users and data subjects have the right to object to the future processing of their personal data, provided that the data is being processed by the provider in accordance with Article 6(1)(f) of the GDPR. In particular, an objection to data processing for the purposes of direct marketing is permitted.
III. INFORMATION ON DATA PROCESSING
The data processed when you use our website will be deleted or blocked as soon as the purpose for which it was stored no longer applies, provided that no legal retention requirements prevent the deletion of the data and no other information regarding specific processing procedures is provided below.
Server data
For technical reasons, particularly to ensure a secure and stable website, data is transmitted to us or to our web hosting provider via your web browser. These so-called server log files collect, among other things, the type and version of your web browser, the operating system, the website from which you navigated to our website (referrer URL), the page(s) of our website that you visit, the date and time of each visit, and the IP address of the Internet connection from which our website is accessed.
The data collected in this manner is stored temporarily, but not in conjunction with any other data you have provided.
This data is stored on the legal basis of Article 6(1)(f) of the GDPR. Our legitimate interest lies in improving the stability, functionality, and security of our website.
The data will be deleted after seven days at the latest, unless further retention is necessary for evidentiary purposes. Otherwise, the data is fully or partially exempt from deletion until an incident has been fully resolved.
Cookies
a) Session cookies
We use cookies on our website. Cookies are small text files or other storage technologies that are placed and stored on your device by the web browser you are using. These cookies process certain information about you on an individual basis, such as your browser or location data, or your IP address.
This processing makes our website more user-friendly, effective, and secure, as it enables, for example, the display of our website in different languages or the provision of a shopping cart function.
The legal basis for this processing is Article 6(1)(b) of the GDPR, provided that these cookies process data for the purpose of entering into or performing a contract.
If the processing is not for the purpose of entering into or performing a contract, our legitimate interest lies in improving the functionality of our website. In that case, the legal basis is Article 6(1)(f) of the GDPR.
These session cookies will be deleted when you close your web browser.
b) Third-party cookies
In some cases, our website may also use cookies from partner companies with whom we collaborate for the purposes of advertising, analysis, or to enhance the functionality of our website.
For more details on this, particularly regarding the purposes and legal basis for the processing of such third-party cookies, please refer to the information below.
c) Disposal options
You can prevent or restrict the installation of cookies by adjusting your web browser settings. You can also delete cookies that have already been stored at any time. However, the steps and measures required to do so depend on the specific web browser you are using. If you have any questions, please consult your web browser’s help function or documentation, or contact its manufacturer or support team. However, for so-called Flash cookies, processing cannot be prevented via the browser settings. Instead, you must change the settings of your Flash Player. The steps and measures required for this also depend on the specific Flash Player you are using. If you have any questions, please use the help function or documentation of your Flash Player or contact the manufacturer or user support.
However, if you block or restrict the use of cookies, this may prevent you from fully utilizing all the features of our website.
Contract processing
The data you provide when using our products and/or services will be processed by us for the purpose of fulfilling the contract and is necessary for that purpose. It is not possible to enter into or fulfill the contract without you providing your data.
The legal basis for the processing is Article 6(1)(b) of the GDPR.
We delete the data once the contract has been fully processed, but we must comply with the retention periods required by tax and commercial law.
As part of the order fulfillment process, we share your data with the shipping company responsible for delivering the goods or with the financial service provider, to the extent that such sharing is necessary for the delivery of goods or for payment purposes.
The legal basis for the transfer of data is then Article 6(1)(b) of the GDPR.
Customer Account / Registration Feature
If you create a customer account with us through our website, we will use the information you provide during registration (e.g., your name, address, or email address) exclusively for pre-contractual services, for the fulfillment of the contract, or for customer service purposes (e.g., to provide you with an overview of your previous orders with us or to offer you the “wish list” feature). At the same time, we will store your IP address and the date and time of your registration. This data will, of course, not be disclosed to third parties.
As part of the rest of the registration process, we will obtain your consent to this processing and refer you to this Privacy Policy. The data we collect during this process will be used exclusively for the purpose of providing you with a customer account.
To the extent that you consent to this processing, the legal basis for the processing is Article 6(1)(a) of the GDPR.
If the opening of the customer account also serves the purpose of pre-contractual measures or the performance of a contract, the legal basis for this processing is also Article 6(1)(b) of the GDPR.
You may revoke the consent you have given us for the opening and maintenance of the customer account at any time with future effect in accordance with Article 7(3) of the GDPR. To do so, you need only notify us of your revocation.
The data collected for this purpose will be deleted as soon as processing is no longer necessary. However, we must comply with retention periods required by tax and commercial law.
Newsletter
If you sign up for our free newsletter, the data requested for this purpose—namely your email address and, optionally, your name and address—will be transmitted to us. At the same time, we will store the IP address of the internet connection you use to access our website, as well as the date and time of your registration. As part of the registration process, we will obtain your consent to receive the newsletter, describe its content in detail, and refer you to this privacy policy. We use the data collected for this purpose exclusively for sending the newsletter—it is therefore not shared with third parties.
The legal basis for this is Article 6(1)(a) of the GDPR.
You may revoke your consent to receive the newsletter at any time with future effect, in accordance with Article 7(3) of the GDPR. To do so, simply notify us of your revocation or click the unsubscribe link included in every newsletter.
Contact Requests / How to Contact Us
If you contact us via the contact form or by email, the information you provide will be used to process your inquiry. Providing this information is necessary for us to process and respond to your inquiry—without it, we will be unable to respond to your inquiry, or our response may be limited.
The legal basis for this processing is Article 6(1)(b) of the GDPR.
Your data will be deleted once your inquiry has been fully resolved and provided that there are no legal retention requirements preventing its deletion, such as those related to any subsequent contract processing.
User posts, comments, and reviews
We invite you to post questions, answers, opinions, or reviews—hereinafter referred to simply as “posts”—on our website. If you take advantage of this offer, we will process and publish your post, the date and time of submission, and any pseudonym you may have used.
The legal basis for this is Article 6(1)(a) of the GDPR. You may withdraw your consent at any time with future effect in accordance with Article 7(3) of the GDPR. To do so, you simply need to notify us of your withdrawal.
In addition, we also process your IP address and email address. We process your IP address because we have a legitimate interest in taking or supporting further action if your post infringes on the rights of third parties and/or is otherwise unlawful.
The legal basis in this case is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the legal defense that may be necessary.
Subscribe to posts
If you post comments on our website, we also offer you the option to subscribe to any follow-up comments from third parties. We process your email address so that we can notify you of these follow-up comments via email.
The legal basis for this is Article 6(1)(a) of the GDPR. You may withdraw your consent to this subscription at any time with future effect in accordance with Article 7(3) of the GDPR. To do so, simply notify us of your withdrawal or click the unsubscribe link included in the relevant email.
Google Analytics
We use Google Analytics on our website. This is a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter referred to as “Google.”
Through its certification under the EU-U.S. Privacy Shield
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google guarantees that EU data protection regulations will be complied with even when data is processed in the United States.
We use Google Analytics to analyze how our website is used. The legal basis for this is Article 6(1)(f) of the GDPR. Our legitimate interest lies in analyzing, optimizing, and ensuring the efficient operation of our website.
Usage and user-related information, such as IP address, location, time, or frequency of visits to our website, is transmitted to a Google server in the United States and stored there. However, we use Google Analytics with the so-called anonymization feature. This feature causes Google to truncate the IP address while the data is still within the EU or the EEA.
The data collected in this way is then used by Google to provide us with an analysis of visits to our website and user activity on the site. This data may also be used to provide additional services related to the use of our website and the Internet.
Google states that it does not link your IP address to any other data. In addition, Google states under
https://www.google.com/intl/de/policies/privacy/partners
We have provided additional information regarding data protection for you, including, for example, how you can prevent the use of your data.
In addition, Google offers
https://tools.google.com/dlpage/gaoptout?hl=de
a so-called opt-out add-on, along with further information on this topic. This add-on can be installed with common web browsers and gives you greater control over the data that Google collects when you visit our website. The add-on instructs the Google Analytics JavaScript (ga.js) not to transmit information about your visit to our website to Google Analytics. However, this does not prevent information from being transmitted to us or to other web analytics services. You can, of course, also find out in this privacy policy whether we use any other web analytics services and, if so, which ones.
Google-Maps
On our website, we use Google Maps to display our location and provide directions. This is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter referred to as “Google.”
Through its certification under the EU-U.S. Privacy Shield
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google guarantees that EU data protection regulations will be complied with even when data is processed in the United States.
To enable the display of certain fonts on our website, a connection to the Google server in the United States is established when you visit our website.
When you access the Google Maps feature integrated into our website, Google stores a cookie on your device via your web browser. Your user settings and data are processed in order to display our location and generate directions. We cannot rule out the possibility that Google uses servers located in the United States.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in optimizing the functionality of our website.
Through this connection to Google, Google can determine which website your request was sent from and to which IP address the directions should be sent.
If you do not consent to this processing, you can prevent cookies from being installed by adjusting the settings in your web browser. For more details, please see the section titled “Cookies” above.
In addition, the use of Google Maps and the information obtained through Google Maps is governed by Google’s Terms of Service Google-Terms of Service https://policies.google.com/terms?gl=DE&hl=de and the Google Maps Terms of Services https://www.google.com/intl/de_de/help/terms_maps.html.
Furthermore, Google provides
https://adssettings.google.com/authenticated
https://policies.google.com/privacy
additional information.
Google Fonts
We use Google Fonts on our website to display external fonts. This is a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter referred to as “Google.”
Through certification under the EU-U.S. Privacy Shield
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google guarantees that EU data protection regulations will be complied with even when data is processed in the United States.
To enable the display of certain fonts on our website, a connection to the Google server in the United States is established when you visit our website.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in optimizing and ensuring the efficient operation of our website.
When you visit our website, the connection established with Google allows Google to determine which website your request originated from and to which IP address the font should be sent.
Google offers under
https://adssettings.google.com/authenticated
https://policies.google.com/privacy
Further information, particularly regarding the options for restricting data use.
YouTube
We use YouTube on our website. YouTube is a video portal operated by YouTube LLC, 901 Cherry Ave., 94066 San Bruno, CA, USA, hereinafter referred to as “YouTube.”
YouTube is a subsidiary of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter referred to as “Google.”
Through certification under the EU-U.S. Privacy Shield
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Google, and by extension its subsidiary YouTube, guarantees that EU data protection regulations will be complied with even when data is processed in the United States.
We use YouTube in conjunction with the “Enhanced Privacy Mode” feature to display videos to you. The legal basis for this is Article 6(1)(f) of the GDPR. Our legitimate interest lies in improving the quality of our website. According to YouTube, the “Enhanced Privacy Mode” feature ensures that the data described in more detail below is only transmitted to YouTube’s server if you actually start playing a video.
Without this “Enhanced Privacy,” a connection to YouTube’s server in the United States is established as soon as you visit one of our web pages that contains an embedded YouTube video.
This connection is necessary to display the respective video on our website via your web browser. In the process, YouTube will collect and process at least your IP address, the date and time, and the webpage you visited. Additionally, a connection is established to Google’s “DoubleClick” advertising network.
If you are logged into YouTube at the same time, YouTube will associate the connection information with your YouTube account. If you wish to prevent this, you must either log out of YouTube before visiting our website or adjust the relevant settings in your YouTube account.
For the purposes of functionality and to analyze user behavior, YouTube permanently stores cookies on your device via your web browser. If you do not consent to this processing, you have the option to prevent the storage of cookies by adjusting the settings in your web browser. For more information on this, please see the section above titled “Cookies.”
Google provides further information about the collection and use of data, as well as your rights and options for protection in this regard, at the following link:
https://policies.google.com/privacy
available in our privacy policy.
