This data privacy policy explains the extent to which your personal data (referred to hereinafter as “data”) is processed.

1. Data controller

The data controller responsible for the processing of your personal data in accordance with the General Data Protection Regulation (GDPR) is:

Schönbuch GmbH
Ottelmannshäuser Strasse 1
97631 Bad Königshofen
Germany
Phone: 09761 39 62-0
Web: https://www.schoenbuch.com
Email: info@schoenbuch.com

2. General information on data processing

As part of our business and website operations, we process data.

This includes disclosure by transfer to third parties and, where applicable, to so-called third countries outside the European Union ("EU") and the European Economic Area ("EEA"). Cases where data is transferred outside the EU or the EEA are indicated below.

3. Data processing

The specifically affected data, processing purposes, legal bases, recipients and transfers to third countries are listed below:

a) Log file when you visit our website
We log your visit to our website. In doing so, we process the following data:

  • The name of the web page you visited
  • The date and time of your visit
  • The amount of data transferred
  • The browser type and version
  • The operating system you used
  • The referrer URL (the previous website you visited)
  • Your IP address
  • The requesting provider.

We process the data based on our legitimate interests as per Art. 6 Section 1 f) GDPR.

The log file is deleted after seven days, unless it is required for clarification or as evidence of specific legal infringements that have come to light within the retention period.

b) Hosting
In order to provide our online presence, we use the services of web hosting providers, which on our behalf process the above-mentioned data and all data processed in connection with the operation of this website (log file when visiting the website).

The legal basis for data processing is our overriding legitimate interest in the provision of our website in accordance with Art. 6 sec. 1 f) GDPR.

c) Contacting us
If you contact us, your data (name and any contact details you specify) and your message will be processed solely for the purposes of dealing with your request.

The legal basis for data processing is our obligation to fulfil the contract and/or to fulfil our pre-contractual obligations in accordance with Art. 6 sec. 1 b) GDPR and/or our overriding legitimate interest in the processing of your request in accordance with Art. 6 sec. 1 f) GDPR.

d) Contract handling
We process your order data for the purpose of handling the contractual relationship between you and us.

The legal basis for data processing is the fulfilment of our contractual obligations in accordance with Art. 6 sec. 1 b) GDPR, and, in individual cases, the fulfilment of our legal obligations in accordance with Art. 6 sec. 1 c) GDPR.

We transmit your address data to the company responsible for the delivery of your order. If necessary for the execution of the contract, we will also send your e-mail address or telephone number to the delivery company to coordinate a delivery date (notification).

Your transaction data (name, order date, payment method, shipping and/or receipt date, amount and payee, bank details or credit card details if applicable) will be transmitted to the payment service provider responsible for processing the payment.

e) Newsletter
To provide you with regular information about our company and offers, we offer an e-mail newsletter. We also offer the possibility to use our download offering.

When you register for our newsletter, we process the data you entered at the time of registration (e-mail address as well as other voluntary information). In order to prevent misuse, we will send you an e-mail after your registration, in which we ask you to confirm the registration (double-opt-in procedure). In order to be able to prove the registration process in accordance with the law, your login will be logged: this applies to your login and confirmation time as well as your IP address.

The legal basis for sending you our newsletter is your consent in accordance with Art. 6 sec. 1 (a) GDPR. To send the confirmation e-mail for your registration and for the associated data logging, we will process your data in accordance with Art. 6 sec.1 f) GDPR. The legal basis for doing this is our legitimate interest in proving your registration was carried out in accordance with the rules.

If you give us your consent, we also evaluate whether you have opened the newsletter and your scrolling and clicking behaviour in the newsletter. This is done so that we can align our newsletter as closely as possible with your interests and improve the content. The legal basis for the analysis of the newsletter is your consent in accordance with Art. 6 sec. 1 (a) GDPR.

To send the newsletter, we use service providers to whom we transmit the data named above.

To send the newsletter, we use the Mailchimp service of Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. Your data will therefore be transferred to servers in the United States. There is no adequacy decision by the EU Commission to cover data transfers to the US. Mailchimp ensures an adequate level of data protection through the EU standard contractual clauses. A copy of the clauses can be found here: https://mailchimp.com/legal/data-processing-addendum/

f) Customer account
When you open a customer account, we process your basic data (name, address, email address, bank details) and your user data (username, password). This allows us to identify you as a customer and lets you manage your orders. The data is processed accordingly based on Art. 6 Abs. 1 a) DSGVO.

g) Cookies
Our website uses cookies. Cookies are small text files that are stored on your respective device (PC, smartphone, tablet, etc.) and stored by your browser.

Purpose
We use technically required cookies to enable the optimal functionality of our website. These cookies allow the user to navigate the website, for example, and enable us to offer other basic functions of the website.

Furthermore, we use optional cookies that provide us with additional information, for example to analyse traffic or for advertising and marketing purposes.

Lifetime
The cookies used remain on your device for different periods of time:

Session cookies are deleted from your device immediately after closing your internet browser.

Persistent cookies remain on your device even after you close your web browser. They allow us to recognise you on your next visit to our website, for example.

Cookie provider
Cookies placed directly by us are called first-party cookies. Third-party cookies, on the other hand, are set by third-party websites, for example to display content (advertisements, images, tracking pixels, etc.).

Legal basis for data processing
Essentially, the legal basis for data processing via a cookie is your consent in accordance with Art. 6 sec. 1 a) GDPR, or our overriding legitimate interests in optimising and establishing the functionality of our website in accordance with Art. 6 sec. 1 f) GDPR.

Revocation and objection
If data processing is carried out based on your consent, you can revoke your consent at any time for the future (so-called "opt-out"). Where your data is processed due to our legitimate interest, you can object to further data processing with effect for the future.

You can revoke your consent via the opt-out link in the privacy policy section of the respective service or by adjusting your preferences in our cookie settings.

For information about objecting to data processing, see Section 5 (b) of this Privacy Policy.

Browser settings for cookies
In addition, you can prevent or restrict future data processing via cookies by selecting appropriate browser settings and using them to deactivate the use of cookies, for example. Cookies that have already been saved can be deleted via the browser settings. For more information about your browser settings, see the following links:

Mozilla Firefox: https://support.mozilla.org/en

Internet Explorer: https://support.microsoft.com//help/17442/

Google Chrome: https://support.google.com/accounts/

Opera: http://www.opera.com/help

Safari: https://support.apple.com/kb/PH17191?

Our cookies
For more information about the specific cookies that have been set, their purposes and their lifetime, please refer to our cookie information.

h) Analysis/marketing

aa) Google Services
On our website we use various services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (referred to hereinafter as "Google"). It is possible that this will also lead to data transfers to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 in the USA.

Google ensures an adequate level of data protection through the EU standard contractual clauses. A copy of the contractual clauses can be found here: https://policies.google.com/privacy/frameworks?hl=de&gl=de

Google Analytics
We use the Google Analytics tracking tool on our website. We use Google Analytics to evaluate your use of the website, compile reports on the activities within this website, and provide other services related to website usage, thereby improving the user experience.

When using Google Analytics, interactions of website visitors are primarily recorded and systematically evaluated using cookies.

Details of the cookies used can be found in our cookie information.

When Google Analytics is used, the following data is processed:

  • 3 bytes of the IP address of the website visitor's system accessed (anonymized IP address),
  • The website accessed
  • The website from which the user reached our website (referrer)
  • The subpages accessed from the website
  • The length of the visit
  • The frequency of website visits.

Google says it will not associate your IP address with any other data from Google under any circumstances.

The legal basis for data processing is your prior consent in accordance with Art. 6 sec. 1 (a) GDPR.

Withdrawal of your consent
You can revoke your consent at any time with effect for the future by adjusting your preferences in our cookie settings or the settings options under  http://www.google.de/ads/preferences.

For more about the use of data from Google in the Google Partner Network, please refer to the notes at: http://www.google.com/intl/de/policies/privacy/partners/

Google remarketing/retargeting
Our website uses tracking cookies from Google. When you visit our website, persistent cookies store information about which of our products you looked at and which adverts and third-party websites took you directly to our website. If you then visit one of our partner websites, we can have personalised advertising displayed for you based on which of our items you viewed.

We process the data obtained in this way based on your consent according to Art. 6 Section 1 a) GDPR. The information generated by the cookie about your use of this website (including your IP address) is transferred to a Google server in the USA and stored there.

bb) Facebook Custom Audiences (Pixel/Cookies)
Our website uses a so-called tracking pixel by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, a subsidiary of Facebook Inc. 1601, Willow Road Menlo Park, CA 94025, USA. We use the Facebook pixel to track the success of our own Facebook advertising campaigns and optimise the distribution of Facebook advertising campaigns to suit interested target groups.

After clicking on a Facebook advertisement or when visiting our website, the pixel on our website stores a cookie on your device. This cookie processes data about whether you have reached our website via a Facebook advertisement. It also allows us to analyse user behaviour until a purchase is completed so we can better understand the success rate of our Facebook advertising campaigns. In addition, the pixel processes data about the fact that you have visited our website and allows the advertising displayed on Facebook to be adjusted to meet your interests.

When you visit our website, the Facebook pixel on our website establishes a direct connection to the Facebook servers. The information it generates about your use of our website (including your IP address) will be transmitted to Facebook in the USA.

There is no adequacy decision by the EU Commission regarding data transfers to the USA. Facebook ensures an adequate level of data protection that meets the standard contractual clauses of the EU. A copy of the contractual clauses can be found at: https://www.facebook.com/legal/EU_data_transfer_addendum

The data that is collected is anonymous for us and does not allow us to infer the user. If you are registered with Facebook, Facebook may assign the information concerned to your account. Your IP address and other identification data may be processed by Facebook even if you do not have a Facebook account or are not logged in when you visit our website.

You can revoke your consent to data processing by Facebook pixel for our web domain at any time with effect for the future. To do this, adjust your preferences in our consent banner. The legal basis for data processing is your consent pursuant to Article 6 (1) (a) GDPR.

i) External content
We use dynamic content from third parties to optimise the appearance and content of our website. When you visit our website, a request is automatically sent to the server of the relevant content provider, and certain log data (e.g. your IP address) is transferred with it. The dynamic content is then transferred to our website and displayed there.

We use external content in connection with the following functionalities:

aa) Integration of YouTube videos
We have integrated videos from the YouTube portal, which is operated by YouTube LLC, 901 Cherry Ave. San Bruno, CA 94066, USA ("YouTube") into our website. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (referred to hereinafter as "Google") is responsible for data processing on YouTube. However, when you play back a video, log data is transferred to YouTube servers in the United States.

This data is processed based on our overriding legitimate interest in optimising the marketing of our content as per Art. 6 Section 1 f) GDPR.

Google ensures an adequate level of data protection through the EU standard contractual clauses. A copy of the contractual clauses can be found here: https://policies.google.com/privacy/frameworks?hl=de&gl=de

For more information, visit: https://policies.google.com/privacy?hl=de&gl=de

bb) Integration of Vimeo videos
We have integrated videos from the Vimeo portal, which is operated by Vimeo, Inc., 555 West 18th Street, New York, New York 10011, USA into our website. When you play back these videos, log data is transferred to Vimeo’s servers in the USA.

This data is processed based on our overriding legitimate interest in optimising the marketing of our content as per Art. 6 Section 1 f) GDPR.

For more information, visit: https://vimeo.com/privacy

cc) Google Maps

We use Google’s "Google Maps" on our website to provide you with an interactive map. When the map is displayed, data including your IP address and location is transferred to Google's servers in the USA and stored there.

This data is processed based on our overriding legitimate interest in optimising the marketing of our content as per Art. 6 Section 1 f) GDPR.

Google ensures an adequate level of data protection through the EU standard contractual clauses. A copy of the contractual clauses can be found here: https://policies.google.com/privacy/frameworks?hl=de&gl=de

For more on data privacy, visit: https://policies.google.com/privacy?hl=de&gl=de

4. Data storage duration

We store personal data only for as long as is necessary for the purposes for which it is being processed or until you withdraw your consent. Insofar as statutory retention requirements need to be complied with, the retention period for certain data can be up to 10 years, regardless of the purposes for which it is being processed.

5. Your rights as a data subject

a) Information
You can request information free of charge at any time about all personal data we keep on you.

b) Rectification, erasure, restriction of processing (blocking), opting out
If you no longer agree to your personal data being stored or if your personal data is no longer correct, on receipt of a corresponding instruction from you, we will have your data erased or blocked, or make the necessary corrections (insofar as this is possible under applicable law). The same applies if you wish us to restrict the processing of your data in future. You have the right to object, in particular where your data is required in order to carry out a task in the public interest or in our legitimate interest, and where profiling based on the data. You are also entitled to object where data is processed for the purpose of direct marketing.

c) Right to withdraw consent with future effect
You can withdraw your consent with effect for the future at any time. This will not affect the legality of the processing prior to your withdrawal.

d) Data portability
On request we will provide your data to you in a commonly-used, structured and machine-readable format, so that you can transfer it to another controller if you wish.

e) Right of complaint
Users have the right to lodge a complaint with the responsible supervisory authority: (https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node).

f) Restrictions
The above rights do not apply to data where we are not able to identify the data subject, for example if the data has been anonymised for analysis purposes. It may be possible for you to exercise your rights to information/access, erasure, blocking, rectification, or transfer to another organisation in relation to this data, if you provide us with additional information that enables us to identify you.

6. Exercising your rights as a data subject

If you have any questions about the processing of your personal data, or if you wish to exercise your rights to access/information, rectification, blocking, opt-out or erasure of data, or if you wish your data to be transferred to another organisation, please contact info@schoenbuch.com.

Sidebar