Privacy policy
Thank you for your interest in our company. We take data protection seriously.
You can use our website without providing any personal data. If a data subject wants to use services of our enterprise via our website, processing of personal data could become necessary. If processing of personal data is necessary and if there is no legal basis for such processing, we will always obtain the consent of the data subject.
The processing of personal data (e.g. the name, address, e‑mail address, or telephone number of a data subject) shall always be in line with the General Data Protection Regulation (GDPR), and in accordance with the country-specific data protection regulations applicable to us.
With the following data protection declaration, we would like to inform the public about the type, scope and purpose of the personal data collected, used and processed by us. Likewise, data subjects are informed by this privacy policy about the rights to which they are entitled.
As the controller, we have implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through our website. However, data transmissions over the Internet can always contain security vulnerabilities. Therefore, we cannot guarantee a 100 %iger level of protection. Therefore, every data subject can of course also transmit personal data to us alternatively, e.g. by telephone.
Definitions
This data protection declaration is based on the definitions used by the European Directive and Regulation (Article 4 DSGVO). This data protection declaration should be both easy to read and easy to understand for any person. To ensure this, we would first like to explain the terms used. These definitions, among others, are used in this privacy statement:
- “personal data” any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- “person concerned” any identified or identifiable natural person whose personal data are processed by the controller.
- “Processing” any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- “Restriction of processing” the marking of stored personal data with the aim of limiting their future processing;
- “Profiling” any automated processing of personal data which consists in using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects relating to that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or change of location;
- “Responsible“the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law;
- “Receiver“a natural or legal person, public authority, agency or other body to whom personal data are disclosed, whether or not a third party. However, public authorities that may receive personal data in the context of a specific investigation mandate under Union or Member State law shall not be considered as recipients and the processing of such data by those authorities shall be carried out in accordance with the applicable data protection rules, in line with the purposes of the processing;
- “Third” means a natural or legal person, public authority, agency or other body, other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or the processor, are authorised to process the personal data;
- “Consent”© ‘indication of the data subject’s wishes’ means any freely given specific, informed and unambiguous indication of his or her wishes, in the form of a declaration or other unambiguous affirmative act, by which the data subject signifies his or her agreement to personal data relating to him or her being processed.
Name and contact details of the controller
This privacy notice applies to data processing by:
ResponsibleMr. Detlef Herrmann, St.-Petri-Platz 7, 21614 Buxtehude, phone: 041617497981, fax: 04161749437, e‑mail: info@rollenshop-nr1.de
Our website is encrypted for security reasons (SSL or TLS encryption).
You can recognize an encrypted connection by the lock symbol in the browser line and the character string “https://” in the browser.
Collection and storage of personal data as well as type and purpose of their use
When visiting the website
In principle, you can use our website without disclosing your identity. When you access our website, the browser used on your terminal device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until automatic deletion:
- IP address of the requesting computer,
- Date and time of access,
- Name and URL of the retrieved file,
- Website from which the access is made (referrer URL),
- the browser used and, if applicable, the operating system of your computer as well as the name of your access provider.
The aforementioned data will be processed by us for the following purposes:
- Ensuring a smooth connection of the website,
- Ensuring a comfortable use of our website,
- Evaluation of system security and stability, and
- for other administrative purposes.
The legal basis for the data processing is Art. 6 para. 1 p. 1 lit. f DSGVO. Our legitimate interest follows from the purposes for data collection listed above. In no case do we use the collected data for the purpose of drawing conclusions about your person.
In addition, we use cookies and analysis services when you visit my website. You can find more information about this in sections 5 and 7 of this privacy policy.
When using our contact form
For questions of any kind, we offer you the possibility to contact us via a form provided on our website. It is necessary to provide a valid e‑mail address so that we know from whom the request originates and to be able to answer it. Further information can be provided voluntarily. It is your free decision whether you want to enter this data in the contact form.
Data processing for the purpose of contacting us is carried out in accordance with Art. 6 Para. 1 S. 1 lit. a DSGVO on the basis of your voluntarily given consent.
The personal data collected by us for the use of the contact form will be automatically deleted after completion of your request.
When ordering via our website
You can either place orders via our website as a guest without registering or register in our shop as a customer for future orders. A registration has the advantage for you that you can log in directly with your e‑mail address and password in our shop in case of a future order without having to enter your contact details again.
Your personal data is entered into an input mask and transmitted to us and stored. If you place an order via our website, we collect the following data first, both in the case of a guest order and in the case of registration in the shop:
- Salutation, first name, last name,
- a valid e‑mail address,
- Address,
- Telephone number (landline and/or mobile)
The collection of this data takes place,
- to be able to identify you as our customer;
- in order to be able to process, fulfil and handle your order;
- for correspondence with you;
- for invoicing purposes;
- for the settlement of any existing liability claims, as well as the assertion of any claims against you;
- to ensure the technical administration of our website;
- to manage our customer data.
As part of the ordering process, consent is obtained from you for the processing of this data.
The data processing is carried out in response to your order and/or registration and is necessary for the aforementioned purposes in accordance with Art. 6 Para. 1 S. 1 lit. b DSGVO for the appropriate processing of your order and for the mutual fulfilment of obligations arising from the purchase contract.
The personal data collected by us for the processing of your order will be stored until the expiry of the legal obligation to keep records and then deleted, unless we are obliged to store the data for a longer period of time in accordance with Article 6 (1) sentence 1 lit. c DSGVO due to tax and commercial law obligations to keep records and documentation (from HGB, StGB or AO) or you have consented to storage beyond this in accordance with Article 6 (1) sentence 1 lit. a DSGVO.
information disclosure
A transfer of your personal data (name, delivery address) from us to third parties takes place exclusively to the service partners involved in the contract processing, such as the logistics company commissioned with the delivery and the credit institution commissioned with payment matters, insofar as this is necessary for the delivery of the goods or for the payment processing. The legal basis for the transfer of data is Art. 6 para. 1 p. 1 lit. b DSGVO.
Forwarding of the e‑mail address and/or telephone number to shipping service providers
- e.g. DHL, DPD, GLS, Hermes, UPS
If you have given your express consent to the forwarding of your e‑mail address and/or telephone number to the shipping service provider as part of the ordering process, we will forward this personal data to the respective shipping service provider on the basis of Art. 6 Para. 1 lit. a DSGVO so that they can coordinate all details of the delivery (e.g. delivery date, place) with you.
You can revoke your consent at any time with effect for the future vis-à-vis the above-mentioned person responsible for data protection or vis-à-vis the respective shipping service provider.
We work together with external shipping partners to fulfil our contractual obligations to our customers. Therefore, we pass on your name and delivery address to our shipping partners on the basis of Art. 6 para. 1 lit. b DSGVO exclusively for the purpose of delivering the goods.
We work together with the following service provider for order processing:
- PayPal
When paying via PayPal, credit card via PayPal, direct debit via PayPal or “purchase on account” via PayPal, we pass on your payment data to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L‑2449 Luxembourg (hereinafter “PayPal”) as part of the payment processing. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or “purchase on account” or “payment by instalments” via PayPal. For this purpose, your payment data may be transmitted by PayPal to credit agencies on the basis of Art. 6 Para. 1 lit. f DSGVO.
PayPal uses the result of the credit check with regard to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, these have their basis in a scientifically recognised mathematical-statistical procedure. Among other things, address data is included in the calculation of the score values. Further information on data protection can be found in the PayPal data protection principles: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to the processing of your data at any time by notifying PayPal. However, PayPal could still be authorized to process your personal data if this is necessary for the contractual payment processing.
Your personal data will not be transferred to third parties for purposes other than those mentioned above.
We also only share your personal information with third parties when:
- you have given your express consent to this in accordance with Art. 6 Para. 1 S. 1 lit. a DSGVO,
- the disclosure is necessary in accordance with Art. 6 (1) sentence 1 lit. f DSGVO for the assertion, exercise or defence of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data,
- in the event that a legal obligation exists for the disclosure pursuant to Art. 6 (1) sentence 1 lit. c DSGVO, as well as
- this is legally permissible and necessary according to Art. 6 para. 1 p. 1 lit. b DSGVO for the processing of contractual relationships with you.
As part of the ordering process, we obtain your consent to pass on your data to third parties.
use of cookies
We use cookies on our website. These are small files that are automatically created by your browser and stored on your end device (laptop, tablet, smartphone or similar) when you visit our website. Cookies do not cause any damage to your end device and do not contain any viruses, Trojans or other malware.
In the cookie, information is stored that arises in each case in connection with the specific end device used. However, this does not mean that we gain direct knowledge of your identity.
The use of cookies serves on the one hand to make the use of our offer more pleasant for you. We use so-called session cookies to recognise that you have already visited individual pages of our website. These are automatically deleted after you leave our site.
In addition, we also use temporary cookies to optimise user-friendliness, which are stored on your end device for a certain fixed period of time. If you visit our site again to make use of our services, it is automatically recognised that you have already been with us and which entries and settings you have made so that you do not have to enter them again.
On the other hand, we use cookies to statistically record the use of our website and to evaluate it for the purpose of optimising our offer for you (see section 7). These cookies enable us to automatically recognise that you have already been to our website when you visit it again. These cookies are automatically deleted after a defined period of time.
The data processed by cookies is necessary for the aforementioned purposes to protect our legitimate interests and those of third parties in accordance with Art. 6 (1) sentence 1 lit. f DSGVO.
Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or a message always appears before a new cookie is created. However, the complete deactivation of cookies may mean that you cannot use all the functions of our website.
Links to third party websites
The links published on our website are researched and compiled by us with the greatest possible care. However, we have no influence on the current and future design and content of the linked pages. We are not responsible for the content of the linked pages and expressly do not adopt the content of these pages as our own. For illegal, incorrect or incomplete contents as well as for damage, which develops from the use or non-use of the information, alone the offerer of the Web Site, to which one referred, is responsible. The liability of the person who merely refers to the publication by a link is excluded. We are only responsible for external references if we have positive knowledge of them, i.e. also of possible illegal or punishable content, and if it is technically possible and reasonable for us to prevent their use.
Data subject rights
You have the right:
- in accordance with Art. 15 DSGVO to request information about your personal data processed by us. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data, if it was not collected by me, as well as the existence of automated decision-making, including profiling and, if applicable, meaningful information about its details;
- in accordance with Art. 16 DSGVO to demand the immediate correction of incorrect or completion of your personal data stored by us;
- in accordance with Art. 17 DSGVO to request the deletion of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;
- to demand the restriction of the processing of your personal data in accordance with Art. 18 DSGVO, insofar as the correctness of the data is disputed by you, the processing is unlawful, but you object to its deletion and we no longer require the data, but you need it for the assertion, exercise or defence of legal claims or you have objected to the processing in accordance with Art. 21 DSGVO;
- pursuant to Art. 20 DSGVO to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another controller;
- to revoke your consent at any time in accordance with Art. 7 (3) DSGVO. This has the consequence that we may no longer continue the data processing based on this consent for the future and
- complain to a supervisory authority in accordance with Art. 77 DSGVO. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
Right of objection
If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) sentence 1 lit. f DSGVO, you have the right to object to the processing of your personal data pursuant to Art. 21 DSGVO, provided that there are grounds for doing so that arise from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right to object, which is implemented by us without specifying a particular situation. If you wish to exercise your right of objection, it is sufficient to send an e‑mail to the e‑mail address of the data controller mentioned at the beginning.
Data security
Within the website visit, we use the widespread SSL procedure (Secure Socket Layer) in connection with the highest encryption level supported by your browser. As a rule, this is a 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is encrypted by the closed key or lock symbol in the lower status bar of your browser.
We also use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
Zu Verbesserung der Interaktion mit unseren Besuchern benutzen wir ein Java-Script Plugin der uptain GmbH (“uptain-Plugin). Dies erlaubt uns eine Analyse Ihrer Benutzung der Webseite und eine Verbesserung der Kundenansprache (z.B. durch ein Dialogfenster). Hierzu erheben wir Informationen über Ihr Nutzungsverhalten, d.h. Bewegung des Cursors, Verweildauer, angeklickte Links und ggf. gemachte Angaben. Rechtsgrundlage der Verarbeitung ist unser berechtigtes Interesse an Direktmarketing und der Bereitstellung unserer Webseite (Art. 6 Abs. 1 lit f DSGVO). Die uptain GmbH ist dabei als Auftragsverarbeiter strikt an unsere Weisungen gebunden. Die erhobenen Informationen werden nicht an Dritte weitergegeben, außer wir sind dazu gesetzlich verpflichtet. Soweit die vom uptain-Plugin erhobenen Informationen personenbezogene Daten enthalten, werden diese unmittelbar nach Ihrem Besuch unserer Webseite gelöscht.
Sie können den Einsatz des uptain-Plugins jederzeit über folgenden Link deaktivieren: https://www.rollenshop-nr1.de/datenschutz?__up_tracking_unsubscribe