data protection

1.Data protection at Sonnewelt

Protecting your privacy is very important to us. We therefore carry out all data processing operations (e.g. collection, processing and transmission) in accordance with the legal regulations of European and German data protection law.

2.What data do we need from you to use our websites? What data is collected and stored during use?

Personal data is all information relating to an identified or identifiable natural person (“data subject”), such as your name, address, telephone number, date of birth, bank details and IP address.

We generally only collect and use our users' personal data to the extent that this is necessary to provide a functional website and our content and services. The collection and use of our users' personal data generally only occurs with the user's consent. An exception applies in cases where prior consent cannot be obtained for actual reasons and the processing of the data is permitted by law.

usage data

When you use our websites, the following data is logged, whereby the storage serves exclusively internal system-related and statistical purposes, so-called usage data:

Names of the pages accessed, the browser used, the operating system and the requesting domain, date and time of access, search engines used, names of downloaded files and anonymized IP address of the customer. E-commerce data (ordered products, price, quantity)

The data is also stored in the log files of our system. This does not affect the user's IP addresses or other data that enable the data to be assigned to a user. This data is not stored together with other personal data of the user.

The legal basis for the temporary storage of data is Art. 6 Para. 1 lit. f GDPR.

The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this purpose, the user's IP address must remain stored for the duration of the session.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. If the data is collected to provide the website, this is the case when the respective session has ended.

The collection of data to provide the website and the storage of data in log files is essential for the operation of the website. Consequently, the user has no option to object.

registration

On our website, we offer users the opportunity to register by providing personal data. The data is entered into an input mask and transmitted to us and stored. The data is not passed on to third parties. The following data is processed as part of the registration process:

Full name of the customer or full company name, email address, address (billing address and possibly different delivery address, optionally the parcel shop details), telephone number and optionally date of birth

At the time of registration, the following data is also stored:

login date and time
Date and time when the account was created
IP address

The legal basis for the processing of data is Art. 6 (1) lit. a GDPR if the user has given their consent.

If the registration serves to fulfill a contract to which the user is a party or to carry out pre-contractual measures, the additional legal basis for the processing of the data is Art. 6 (1) (b) GDPR.

Registration is in the user's interest in making ordering easier, as the order data stored in the customer account can be easily accessed for future orders. If you as a user do not wish to have a customer account created, you are welcome to order from us as a guest.

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected.

This is the case during the registration process for the performance of a contract or for the implementation of pre-contractual measures if the data is no longer required for the implementation of the contract. Even after the contract has been concluded, it may be necessary to store the contractual partner's personal data in order to comply with contractual or legal obligations.

Continuing obligations require the storage of personal data for the duration of the contract. In addition, warranty periods must be observed and data must be stored for tax purposes. It is not possible to set a blanket rule for the storage periods to be observed, but must be determined on a case-by-case basis for each contract and contracting party.

As a user, you have the option of canceling your registration or changing the data stored about you at any time by contacting info@sonnewelt.de.

If the data is required to fulfil a contract or to carry out pre-contractual measures, early deletion of the data is only possible if contractual or legal obligations do not prevent deletion.

contact form

We have a contact form available on our website that you can use to conveniently contact us electronically and address your concerns to us. We only collect your name and email address via the contact form.

Your consent will be obtained for the processing of the data during the sending process and reference will be made to this data protection declaration.

Alternatively, you can contact us using the email address provided. In this case, the user's personal data transmitted with the email will be stored.

We only use your data to process your request and may contact you for this purpose using the contact details provided. This data will not be used for advertising purposes or passed on to third parties.

The legal basis for the processing of data transmitted via the contact form or when sending an email is Art. 6 (1) (f) GDPR. If the aim of the contact is to conclude a contract, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

The processing of personal data from the input mask serves us solely to process the contact. In the case of contact via email, this also constitutes the necessary legitimate interest in processing the data.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input mask of the contact form and those that were sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

The additional personal data collected during the sending process will be deleted after a period of seven days at the latest.

The user has the option to revoke his consent to the processing of personal data at any time via info@sonnewelt.de. If the user contacts us by email, he can object to the storage of his personal data at any time. In such a case, the conversation cannot be continued.

In this case, all personal data stored during the contact process will be deleted.

3.How will my data be used and possibly passed on to third parties and for what purpose?

We use the personal data you provide to answer your inquiries and to process your order in our online shop. We only use your data to check your creditworthiness if we make advance payments for your order, e.g. if you order on account.

Your personal data will only be passed on or otherwise transmitted to third parties if the transfer is necessary for the purpose of contract processing or for billing purposes or to collect the fee (e.g. shipping companies or payment service providers) or if you have expressly consented. We are also entitled to pass on personal data for debt collection purposes and reserve the right to exchange data with business protection organizations (e.g. Schufa); of course, this only occurs if the legal requirements for this are met.

Occasionally we will ask you to provide information anonymously as part of surveys. We need this to make the service more interesting for you and to be able to offer our information in a constantly updated manner. These surveys are of course voluntary, your information is collected anonymously and treated confidentially. Users cannot be identified.

payment processing

For payment processing in our online shop, we use the payment systems of the external payment service provider PayPal (Europe) S.à rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PAYPAL"). If, for example, you want to pay via PayPal, a connection to the online payment system of your choice is automatically established via a technical interface. The payment data you provide is transmitted to the payment service provider via an encrypted connection solely for the purpose of payment processing and is stored and processed there. The data is also processed solely for the aforementioned purpose of processing the payment for your order, whereby the payment data must be forwarded by PAYPAL to the credit institution you specified in order to initiate and authorize the payment process. If you select one of the payment systems mentioned as your payment method, PAYPAL will direct you directly to the respective payment system via an interface; there you can then authorize the payment process yourself by entering your access data there.

Payment by cash on delivery can be processed via DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn or DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg. The purpose of the transmission is to carry out the payment processing.

The legal basis for the processing of the data is Art. 6 Para. 1 lit. b GDPR.

shipping service providers

The delivery of ordered goods takes place in cooperation with logistics service providers, transport companies and partners. The following data can be sent to them for the purpose of delivery, tracking or notification of the ordered goods: first name, last name, postal address, email address, telephone number, optional: details of the parcel shop.

The legal basis for the processing of the data is Art. 6 paragraph 1 letter b) GDPR.

4. References to external social network services

On our websites we link to the social media platforms Facebook, Instagram, Pinterest, Google+, YouTube and Twitter. This is done via a corresponding symbol on our websites, which is marked with the corresponding logo of the respective social media platform and behind which there is a corresponding link to our corresponding social media page. Social plugins (such as the Facebook "Like" button) are not integrated here.

Our links to social media services do not transmit any of your data to these services. These are normal hyperlinks, which do not normally transmit any data. If you click on the link, you will be redirected directly to our social media presence on the respective social media service. Data is only transmitted if you are logged into your user account on the respective social media service. You can then link or share content from our websites directly with the social media service or, in the case of YouTube, watch the videos on our YouTube channel. The respective social media service may therefore learn which content you have viewed on our websites.

The following are solely responsible for the social media services linked to by us:

for Facebook and its website: Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA;
for Instagram and its website: Instagram, LLC, 1601 Willow Rd. Menlo Park, CA 94025, USA;
for Pinterest and its website, Pinterest Inc., 808 Brannan Street, San Francisco, CA 94103, USA;
for Google+ and its website, Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA;
for YouTube and its website: YouTube, LLC, 901 Cherry Ave., St. Bruno, CA 94066, USA;
for Twitter and its website, Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA;

Further information about the purpose and scope of data collection and the further processing and use of your data by the respective social media service can be found in the data protection provisions of the respective service. These are available on the Internet:

Facebook: https://www.facebook.com/about/privacy/
Instagram: https://www.instagram.com/about/legal/privacy/
Pinterest: https://about.pinterest.com/de/privacy-policy

Google+ and YouTube: https://www.google.de/intl/de/policies/privacy/
Twitter: https://twitter.com/privacy
Under the links mentioned you will also find information about setting options for protecting your privacy and about your further rights regarding the collection, processing and use of your data by the respective social media service.

You are responsible for the data transmission to the aforementioned social network services, since by logging into your respective social network account and following the respective link, you become active yourself and thus initiate the subsequent data processing by the respective social network service.

5. Advertising via email (e.g. email newsletter)

On our website you have the option of subscribing to a free newsletter. When you register for the newsletter, the data from the input mask is transmitted to us.

1.Email address

2. Salutation, first name, last name (optional)

In addition, the following data is collected during registration:

1.IP address of the accessing computer
2.Date and time of registration

Your consent to the processing of data will be obtained during the registration process and reference will be made to this privacy policy.

If you purchase goods or services on our website and provide your email address, we may subsequently use it to send you a newsletter. In such a case, the newsletter will only be used to send direct advertising for our own similar goods or services.

In connection with data processing for sending newsletters, no data will be passed on to third parties. The data will be used exclusively for sending the newsletter.

The legal basis for the processing of data after the user has registered for the newsletter is Art. 6 (1) (a) GDPR if the user has given his consent.

The legal basis for sending the newsletter as a result of the sale of goods or services is Section 7 Paragraph 3 of the German Act Against Unfair Competition (UWG). In this regard, email advertising is carried out on this legal basis. You can object to the use for advertising purposes by clicking on the unsubscribe link in the newsletter. There are no additional transmission costs for this according to the basic rates.

The purpose of collecting the user’s email address is to deliver the newsletter.

The collection of other personal data during the registration process serves to prevent misuse of the services or the email address used.

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. The user's email address will therefore be stored as long as the newsletter subscription is active.

The user can cancel the newsletter subscription at any time. For this purpose, there is a corresponding link in every newsletter.

This also makes it possible to revoke the consent to the storage of personal data collected during the registration process.

6.Newsletter tracking

We use what is known as newsletter tracking in our email messages. This enables us to evaluate the opening rate of emails and clicks within the newsletter. We use this technology to determine the level of interest in certain topics and to measure the effectiveness of our communication measures. This is also our legitimate interest in accordance with Art. 6 (1) (f) GDPR. This data is stored in segmented and anonymous form. We do not share this data with anyone and we do not attempt to link the "click-throughs" to individual email addresses. The individual user data is deleted after the anonymized overall evaluation has been created - after 18 months at the latest.

7.When you use our websites, a cookie is stored on your computer. What does that mean?

We use so-called cookies on our websites. Cookies are small amounts of data in the form of text information that the web server sends to your browser. These are simply stored on your hard disk. Cookies can only be read by the server that previously stored them and contain information about what you viewed on a website and when. Cookies themselves only identify the IP address of your computer and do not store any personal information, such as your name. The data stored in the cookies is not linked to your personal data (name, address, etc.).

We use cookies to make our website more user-friendly. Some elements of our website require that the browser that is accessing the website can be identified even after a page change.

You can find the specific cookies used on our website here. There you will also find information on the purpose of use and storage period.

The user data collected in this way is pseudonymized using technical precautions. It is therefore no longer possible to assign the data to the user who accessed the site. The data is not stored together with other personal data of the user.

You can decide for yourself whether you want to accept cookies. On the one hand, by changing your browser settings (usually found under "Options" or "Settings" in the browser menu), you have the choice of accepting all cookies, being informed when a cookie is set, or rejecting all cookies. On the other hand, you can freely decide whether you want to give us your consent to set cookies or reject this via the banner that is displayed when you first visit our website and refers to this privacy policy.

The legal basis for the processing of personal data using technically necessary cookies and cookies for analysis purposes is Art. 6 (1) (f) GDPR.

The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized even after changing pages.

The user data collected through technically necessary cookies is not used to create user profiles.

The analysis cookies are used to improve the quality of our website and its content. The analysis cookies tell us how the website is used and enable us to continually optimize our offering.

Our legitimate interest in processing personal data for these purposes also lies in accordance with Art. 6 (1) (f) GDPR.

Cookies are stored on the user's computer and transmitted from there to our site. Therefore, you as the user have full control over the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your Internet browser. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to fully use all of the website's functions.

8. Transfer of personal data to third parties
Data will only be passed on to third parties within the scope of the clauses described above and for the purposes described therein. Any further data will not be sent without your prior, express consent. However, we reserve the right to transmit data to third parties without consent if this is necessary to avert threats to public order or for criminal prosecution. Of course, data will only be passed on if the requesting party has the authorization to do so. If one of the latter reasons applies, the personal data you have provided will be passed on, in particular to the responsible law enforcement and supervisory authority.

Your personal data will not be passed on to third parties, especially not for advertising purposes. We will not use your stored data for advertising or marketing purposes and will not sell it to third parties unless you give us your express consent beforehand.

9.Changes to this Privacy Policy

We reserve the right to change this privacy policy from time to time without prior notice. Please check this page regularly for any changes to this privacy policy.