1. ALGEMEINE INFORMATION(1.1) In the following we inform you about the collection of personal data when using our websites www.shop.mycoffeecup.de, www.mycoffeecup.de, https://www.my-cups.at/de, . Personal data is all data that can be related to you personally, e.g.B. Name, address, email addresses, user behavior.(1.2) Responsible acc. Art. 4 Abs. 7 EU General Data Protection Regulation (GDPR) is Unicaps GmbH, Im Technologiepark 6, 15236 Frankfurt (Oder), helpdesk@unicaps.eu. The person responsible for www.my-cups.ch is Unicaps Suisse, Seestrasse 5a, CH-8810 Horgen, helpdesk@unicaps.eu.(1.3) The contact details of our data protection officer are: Mr. Udo Wenzel, Im Technologiepark 6, 15236 Frankfurt (Oder), email: datenschutz@unicaps.eu.(1.4) When you contact us by e-mail, the personal data you provide (your e-mail address, possibly Your name and phone number) stored by us to respond to your request. We delete the personal data arising in this context 3 months after the storage is no longer necessary, or restrict the processing if there are statutory storage obligations.2. YOUR RIGHTS
(2.1) You have the following rights towards us with regard to the personal data concerning you:
- right to information,
- right to correction or deletion,
- right to restriction of processing,
- right to object to processing (see Section 10),
- right to data portability.
(2.2) You also have the right to complain to the responsible data protection supervisory authority about the processing of your personal data by us if you believe that the processing of your personal data by us is unlawful: https://datenschutz.hessen.de
3. DATA PROCESSING WHEN VISITING OUR WEBSITE
(3.1) LOGFILES (INTERNET PROTOCOLS)
If you only use the website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we may collect the following Personal data that is technically required for us to display our website to you and to ensure stability and security (our legitimate interest; the legal basis is Art. 6 Abs. 1 S. 1 f) GDPR):
- IP address
- date and time of the request
- time zone difference to Greenwich Mean Time (GMT)
Content of the request (specific page)- Access status/HTTP status code
- Amount of data transferred in each case
- Website from which the request comes
- Browser
- Operating system and its interface
- Language and version of the browser software.
2) REGISTRATIONIf you register as a My Cups customer, we process the mandatory information marked with an asterisk (e.g.B. name, email address). Other personal data (eg.B. address) you can voluntarily enter in your profile.
We process this personal data in order to manage a user account for you and to enable you to use the website more conveniently and to make ordering easier. The legal basis is Art. 6 Abs. 1 S. 1 b) DS-GVO.
Your registration data will be deleted if we or you terminate the user relationship (e.g.B. upon termination), unless we have the right to continue storing the personal data for another reason.(p.3) ORDERIf you place an order in our online shop, we collect personal data from you as part of the ordering process. Fields marked with an asterisk are mandatory. You can provide further personal data voluntarily.
If you are a registered My Cups customer and have logged in, we will use personal data from your user account for the order.
We process this personal data for the conclusion of the contract and the processing of your order. The legal basis is Art. 6 Abs. 1 S. 1 b) DS-GVO.
We are legally obliged to store this personal data for a period of ten years. Your personal data will therefore not be completely deleted even after the contract has been processed. However, processing only takes place to the extent necessary to comply with legal obligations. The legal basis is Art. 6 Abs. 1 S. 1 c) DS-GVO.(p.4) CONTACT FORM FOR PRIVATE CUSTOMERSAs a consumer, you can use our contact form to get in touch with us. For this we need the mandatory information marked with an asterisk (e.g.B. name, email address). You can provide further personal data voluntarily.
This personal data will only be used to contact you (our legitimate interest, the legal basis is Art. 6 Abs. 1 S. 1 f) DS-GVO) Your personal data will be automatically deleted 3 months after your request has been answered, unless there is a legal basis for longer storage (e.g. an existing contractual relationship) or statutory retention periods.(p.5) CONTACT FORM FOR BUSINESS CUSTOMERSAs a business owner you can use our contact form for business customers to get in touch with us. For this we need the mandatory information marked with an asterisk (e.g.B. name, email address). You can provide further personal data voluntarily.
This personal data will only be used to contact you (our legitimate interest, the legal basis is Art. 6 Abs. 1 S. 1 f) DS-GVO) Your personal data will be automatically deleted 3 months after your request has been answered, unless there is a legal basis for longer storage (e.g. an existing contractual relationship) or statutory retention periods.(p.6) EMAIL ADVERTISING WITH NEWSLETTER REGISTRATIONIf you register for our newsletter, we will use the data required for this or separately provided by you in order to regularly send you our e-mail newsletter based on your consent kind 6 Abs. 1 S. 1 lit. a GDPR. Unsubscribing from the newsletter is possible at any time and can be done either by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After you have unsubscribed, we will delete your e-mail address, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we will inform you in this declaration.(p.7) BUSINESS NEWSLETTER FOR BUSINESS CUSTOMERSAs an entrepreneur, you can order a business newsletter from us by entering and sending the mandatory information marked with an asterisk on our website. You can provide further personal data voluntarily. We will then contact you at the e-mail address and ask you to confirm that you are the owner of the e-mail address provided and that you agree to receive the newsletter (double opt-in; the legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO).
You can revoke your consent to the use of your personal data for the newsletter at any time. In this case we will delete your personal data. Furthermore, we delete your personal data if we have indications that it is not (or no longer) correct. If you do not confirm your e-mail address, we will also delete your personal data 3 months after we have received it. We do not delete data if we have the right to further storage for another reason or if we are obliged to do so due to statutory storage obligations.(p.8) ADVERTISINGWith your express consent, we will regularly inform you about promotions, vouchers and trends and process your e-mail address for this (legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO).
You can revoke your consent to the use of your personal data for advertising purposes at any time. In this case we will delete your personal data. Furthermore, we delete your personal data if we have indications that it is not (or no longer) correct. We do not delete data if we have the right to further storage for another reason or if we are obliged to do so due to statutory storage obligations.(p.9) FURTHER DATA PROCESSINGWe can also process your personal data if we offer participation in campaigns, competitions or similar services. You will receive more detailed information on this when you provide your personal data.
4. EXTERNAL SERVICE PROVIDERS
We use external service providers to process your order:
(4.1) We transmit your address data to shipping companies. These shipping companies are obliged to treat your personal data confidentially and to process it exclusively for the purpose of delivery. After delivery, the personal data must be deleted. The legal basis for the transmission of personal data is Art. 6 Abs. 1 S. 1 b) DS-GVO.
(h.2) Except for the "payment in advance" payment method, we transmit the personal data required for processing the payment ("payment data") to the commissioned bank or passed on to the selected payment service provider in order to enable payment processing. The respective payment service provider is responsible for your payment data. Information, in particular about who is responsible for the payment method you have selected and which data processing the payment service provider carries out, can be found at the following Internet addresses. The legal basis for the transmission is Art. 6 Abs. 1 S. 1 b) DS-GVO.
We integrate third-party payment services on our website. When you make a purchase from us, your payment details (eg. B Name, payment amount, account details, credit card number) processed by the payment service provider for the purpose of payment processing. The respective contract and data protection provisions of the respective provider apply to these transactions. The payment service providers are used on the basis of Art. 6 Abs. 1 lit. b GDPR (contract execution) and in the interest of a payment process that is as smooth, convenient and secure as possible (Art. 6 Abs. 1 lit. f DSGVO). If your consent is requested for certain actions, Art. 6 Abs. 1 lit. a GDPR legal basis for data processing; Consent can be revoked at any time for the future.
We use the following payment services / payment service providers on this website:
(4.21) PAYPAL
The provider of this payment service is PayPal (Europe) S.To.rl and Cie, St.CA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.
Details can be found in PayPal's data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.(4.22) KLARNAProvider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers various payment options (eg. B hire purchase). If you decide to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna checkout solution. Details on the use of Klarna cookies can be found at the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
You can read details about this in Klarna's data protection declaration under the following link: https://www.klarna.com/de/datenschutz/.(4.23) MASTERCARDThe provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter "Mastercard").
Mastercard may transfer data to its parent company in the United States. Data transmission to the USA is based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.(4.24) VISAThe provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).
Great Britain is considered a safe third country in terms of data protection. This means that Great Britain has a data protection level that corresponds to the data protection level in the European Union.
VISA may transfer data to its parent company in the United States. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.
For more information, see VISA's privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.(4.25) AMEXThe provider of this payment service is American Express Europe S.A, Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter "American Express").
American Express may transfer data to its parent company in the United States. Data transmission to the USA is based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-pl/company/legal/privacy-centre/european-implementing- principles/.
For more information, see American Express' privacy policy: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.(4.26) AMAZON PAYThe provider of this payment service is Amazon Payments Europe S.CA, 38 avenue J.F Kennedy, L-1855 Luxembourg.
You can read details about how your data is handled in the Amazon Pay data protection declaration under the following link:
https://pay.amazon.de/help/201212490?ld=APDELPADirect.
5. COOKIES
(5.1) In addition to the personal data mentioned above, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive in the browser you are using and through which certain information flows to the place that sets the cookie (here from us). Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
(5.2) Use of cookies:
(5.21) This website uses the following types of cookies, the scope and functionality of which are explained below:
- Transient cookies (see 5.22)
- Persistent cookies (plus 5.23)
(5.22) Transient cookies are automatically deleted when you close the browser. These include in particular the session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
(5.23) Persistent cookies are automatically deleted after a specified period, which can vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time. We use the following persistent cookies on the website:
- Google Analytics (ga - storage period: 2 years,_gid - storage period: 1 day). You can find more information about Google Analytics under section 6.
- Google Marketing Platform (IDE - storage period: 390 days). You can find more information about the Google Marketing Platform under Section 7.
- Facebook Custom Audiences (fbp - storage period 90 days, fr - storage period: 90 days). You can find more information about Facebook Custom Audiences under Section 8.
- as well as a cookie with which we can save the contents of your shopping cart (basketSessionId - storage period: 7 days).
(5.24) The cookies we use are required for the technical implementation of interactive user functions. For example, cookies enable the contents of your virtual shopping cart to be retained across multiple websites. In addition, we use cookies in accordance with this data protection declaration for the technically error-free and optimized provision of our services. The data processed by cookies Personal data is for the purposes mentioned to protect our legitimate interests and those of third parties in accordance with Art. 6 Abs. 1 S. 1 f) GDPR required.
(5.25) We also use cookies to collect statistical data about the general usage behavior of our users. By evaluating this data, we get a better understanding of the needs of our users, so that we can further develop our website in a more targeted manner and improve the overall user experience. However, these cookies do not contain any personal data and are not linked to such data.
(5.26) We also use cookies for analysis and targeting purposes. Further information, also on the legal basis, can be found in sections 6, 7 and 8.
(5.27) You can configure your browser settings according to your wishes and e.g. B refuse to accept third-party cookies or all cookies. We would like to point out that you may not be able to use all the functions of this website.
(5.29) Consent with Usercentrics
This website uses the consent technology from Usercentrics to obtain your consent to the storage of certain cookies on your end device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Website:
https://usercentrics.com/de/(hereinafter "Usercentrics").
When you enter our website, the following personal data will be transmitted to Usercentrics:
- Your consent(s) or the revocation of your consent(s)
- your IP address
- information about your browser
- information about your end device
- time of your visit to the website
Usercentrics also stores a cookie in your browser in order to give you the consent or to assign their revocation. The data collected in this way is stored until you request us to delete it, delete the Usercentrics cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention requirements remain unaffected.
Usercentrics is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 Abs. 1 lit. c DSGVO.
We have concluded an order processing contract (AVV) with the above-mentioned provider. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed according to our instructions and in compliance with the GDPR.
6. USE OF GOOGLE ANALYTICS
(6.1) This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as B Page views, length of stay, operating systems used and origin of the user. This data may be used by Google summarized in a profile that is assigned to the respective user or whose end device is assigned.
We can also use Google Analytics and a Record your mouse and scroll movements and clicks. Furthermore, Google Analytics uses various modeling approaches to supplement the recorded data sets and uses machine learning technologies for data analysis.
Google Analytics uses technologies that enable the user to be recognized for the purpose of analyzing user behavior (e.g. B Cookies oder Device-Fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.
The use of this analysis tool is based on Art. 6 Abs. 1 lit. f DSGVO The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent was requested (eg. B consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Abs. 1 lit. a GDPR; the consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/.
(sh.2) The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
(sh.3) You can prevent the storage of cookies by setting your browser software accordingly; we would like to point out to you however that in this case you will if applicable not be able to use all functions of this website in full. You can also prevent the collection of the data generated by the cookie and related to your use of the website (incl. your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
More information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
(sh.4) As an alternative to the browser add-on or on mobile devices, you can prevent Google Analytics from collecting data by clicking on the following link. An opt-out cookie will be set to prevent future collection of your data when you visit our website/our online shop: Disable Google Analytics. If you delete your cookies, you must click this link again. To prevent Google Analytics from collecting data across different devices, you must opt out on all systems used.
(sh.5) We have activated the IP anonymization function on this website. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator.
(sh.6) We use Google Analytics to analyze and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. Our legitimate interest in data processing also lies in these purposes. The legal basis for the use of Google Analytics is § 15 para. 3 TMG or Art. 6 Abs. 1 S. 1 f) DS-GVO Sessions and campaigns are terminated after a certain period of time. By default, sessions are terminated after 30 minutes of inactivity and campaigns are terminated after 6 months. The time limit for campaigns can be a maximum of 2 years.
(sh.7) Storage periodData stored by Google at user and event level, which is linked to cookies, user IDs (e.g. B User ID) or advertising IDs (e.g. B DoubleClick cookies, Android advertising ID) will be anonymized or deleted after 2 months. turned off You can find details on this under the following link: https://support.google.com/analytics/answer/7667196?hl=de
(6.8) With your consent, this website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out using a user ID. The legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO
(sh.9) Order processingWe have concluded an order processing contract with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
7. USE OF GOOGLE MARKETING PLATFORM
(7.1) This website uses the Google Marketing Platform of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). The Google Marketing Platform uses cookies to serve ads relevant to users, to improve reports on campaign performance, or to prevent a user from seeing the same ads multiple times. Google uses a cookie ID to record which ads are placed in which browser and can thus prevent them from being displayed more than once. In addition, the Google Marketing Platform can use cookie IDs to Track conversions related to ad requests. This is the case, for example, when a user sees an ad and later goes to the advertiser's website with the same browser and buys something there. According to Google, cookies from the Google Marketing Platform do not contain any personal information.
(sh.2) Due to the marketing tools used, your browser automatically establishes a direct connection to the Google server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and are therefore informing you according to our current level of knowledge: By integrating the Google Marketing Platform, Google receives the information that you have accessed the relevant part of our website or clicked on one of our advertisements. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google If you have not logged in, there is a possibility that Google will find out and store your IP address.(sh.3) The legal basis for the processing of your data is your consent (Art. 6 Abs. 1 S. 1 a) DS-GVO). You can revoke your consent at any time [here].(sh.4) Further information on the Google Marketing Platform can be found at https://marketingplatform.google.com, as well as on data protection at Google in general: https://policies.google.com/privacy. Alternatively, you can visit the Network Advertising Initiative (NAI) website at http://www.networkadvertising.org.8. USE OF FACEBOOK CUSTOM AUDIENCES
(8.1) The website uses the "Custom Audiences" remarketing function of Facebook Inc. („Facebook“). As a result, users of the website can be shown interest-based advertisements ("Facebook Ads") when they visit the social network Facebook or other websites that also use the process. In doing so, we are interested in showing you advertising that is of interest to you in order to make our website more interesting for you.
(8.2) Due to the marketing tools used, your browser automatically establishes a direct connection to the Facebook server. We have no influence on the scope and further use of the data collected by Facebook through the use of this tool and are therefore informing you according to our state of knowledge: By integrating Facebook Custom Audiences, Facebook receives the information that you have visited the corresponding website of ours accessed our website or clicked on one of our advertisements. If you are registered with a Facebook service, Facebook can assign the visit to your account. Even if you are not registered with Facebook or If you have not logged in, there is a possibility that the provider will find out and store your IP address and other identifiers.Insofar as personal data is collected on our website and forwarded to Facebook using the tool described here, we and Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing responsible (Art. 26 GDPR). Joint responsibility is limited to collecting the data and passing it on to Facebook. The processing by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been set out in a joint processing agreement. The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for issuing data protection information when using the Facebook tool and for implementing the tool on our website in a secure manner in accordance with data protection law. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g. B Request for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert the rights of data subjects with us, we are obliged to forward them to Facebook.
Facebook's data protection information contains further information on protecting your privacy: https://de-de.facebook.com/about/privacy/.
(8.3) We do not transmit any (hashed) e-mail addresses to Facebook and do not carry out an "automatic extended comparison" in which further user data would be transmitted.(8.4) Third party information: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. According to Facebook, however, the data collected is also transferred to the USA and other third countries. User conditions: https://www.facebook.com/legal/terms/update, overview of data protection: https://de-de.facebook.com/privacy/explanation.Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
(8.5) The legal basis for the processing of your data is your consent (Art. 6 Abs. 1 S. 1 a) DS-GVO). You can revoke your consent at any time [here].9. RECIPIENTS OF YOUR DATA / THIRD COUNTRY TRANSFERS
(9.1) Apart from the recipients mentioned above under items 4, 6, 7 and 8, we may disclose or forward your personal data to IT service providers. The IT service providers are carefully selected by us and work for us as processors.
(ia.2) In addition, your personal data will only be transmitted to third parties if and to the extent that this is legally permissible and necessary for the fulfillment of contracts concluded with you or for the performance of the services (the legal basis in this respect is Art. 6 Abs. 1 S. 1 b) GDPR), you have given us your consent to the transmission (legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO), the disclosure is necessary to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data (legal basis is Art. 6 Abs. 1 S. 1 f) GDPR) or in the event that there is a legal obligation for the transfer (legal basis Art. 6 Abs. 1 S. 1 c) DS-GVO).(ia.3) If personal data is to be transferred to a country outside the European Economic Area (EEA), we will inform you of this in these data protection regulations or when the personal data is collected.10. REVOCATION OF CONSENT OR OBJECTION TO THE PROCESSING OF YOUR PERSONAL DATA
(10.1) If you have given your consent to the processing of your personal data, you can revoke this at any time. Such a revocation affects the admissibility of the processing of your personal data after you have given it to us.
(10.2) If we base the processing of your personal data on the balancing of interests, you can object to the processing. This is the case if the processing is not necessary in particular to fulfill a contract with you, which is shown by us in the following description of the functions. If you exercise such an objection, we ask that you explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and will either stop processing the data or adapt or show you our compelling legitimate grounds on which we continue processing.(10.3) Of course, you can object to the processing of your personal data for advertising and data analysis purposes at any time. You can contact us about your objection to advertising under the number 1.2 provided contact information.11. LINKEDIN
Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.linkedin.com/legal/l/dpa and
https://www.linkedin.com/legal/l/eu-sccs.
Object to the analysis of usage behavior and targeted advertising by LinkedIn under the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Furthermore, LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To prevent LinkedIn from linking data collected on our website to your LinkedIn account, you must log out of your LinkedIn account before visiting our website.
We have concluded an order processing contract with LinkedIn.
2. YOUR RIGHTS
(2.1) You have the following rights towards us with regard to the personal data concerning you:
- right to information,
- right to correction or deletion,
- right to restriction of processing,
- right to object to processing (see Section 10),
- right to data portability.
(2.2) You also have the right to complain to the responsible data protection supervisory authority about the processing of your personal data by us if you believe that the processing of your personal data by us is unlawful: https://datenschutz.hessen.de
3. DATA PROCESSING WHEN VISITING OUR WEBSITE
(3.1) LOGFILES (INTERNET PROTOCOLS)
If you only use the website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we may collect the following Personal data that is technically required for us to display our website to you and to ensure stability and security (our legitimate interest; the legal basis is Art. 6 Abs. 1 S. 1 f) GDPR):
- IP address
- date and time of the request
- time zone difference to Greenwich Mean Time (GMT)
- Access status/HTTP status code
- Amount of data transferred in each case
- Website from which the request comes
- Browser
- Operating system and its interface
- Language and version of the browser software.
2) REGISTRATION If you register as a My Cups customer, we process the mandatory information marked with an asterisk (e.g.B. name, email address). Other personal data (eg.B. address) you can voluntarily enter in your profile.
We process this personal data in order to manage a user account for you and to enable you to use the website more conveniently and to make ordering easier. The legal basis is Art. 6 Abs. 1 S. 1 b) DS-GVO.
Your registration data will be deleted if we or you terminate the user relationship (e.g.B. upon termination), unless we have the right to continue storing the personal data for another reason.
(p.3) ORDER If you place an order in our online shop, we collect personal data from you as part of the ordering process. Fields marked with an asterisk are mandatory. You can provide further personal data voluntarily.
If you are a registered My Cups customer and have logged in, we will use personal data from your user account for the order.
We process this personal data for the conclusion of the contract and the processing of your order. The legal basis is Art. 6 Abs. 1 S. 1 b) DS-GVO.
We are legally obliged to store this personal data for a period of ten years. Your personal data will therefore not be completely deleted even after the contract has been processed. However, processing only takes place to the extent necessary to comply with legal obligations. The legal basis is Art. 6 Abs. 1 S. 1 c) DS-GVO.
(p.4) CONTACT FORM FOR PRIVATE CUSTOMERS As a consumer, you can use our contact form to get in touch with us. For this we need the mandatory information marked with an asterisk (e.g.B. name, email address). You can provide further personal data voluntarily.
This personal data will only be used to contact you (our legitimate interest, the legal basis is Art. 6 Abs. 1 S. 1 f) DS-GVO) Your personal data will be automatically deleted 3 months after your request has been answered, unless there is a legal basis for longer storage (e.g. an existing contractual relationship) or statutory retention periods.
(p.5) CONTACT FORM FOR BUSINESS CUSTOMERS As a business owner you can use our contact form for business customers to get in touch with us. For this we need the mandatory information marked with an asterisk (e.g.B. name, email address). You can provide further personal data voluntarily.
This personal data will only be used to contact you (our legitimate interest, the legal basis is Art. 6 Abs. 1 S. 1 f) DS-GVO) Your personal data will be automatically deleted 3 months after your request has been answered, unless there is a legal basis for longer storage (e.g. an existing contractual relationship) or statutory retention periods.
(p.6) EMAIL ADVERTISING WITH NEWSLETTER REGISTRATION If you register for our newsletter, we will use the data required for this or separately provided by you in order to regularly send you our e-mail newsletter based on your consent kind 6 Abs. 1 S. 1 lit. a GDPR. Unsubscribing from the newsletter is possible at any time and can be done either by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After you have unsubscribed, we will delete your e-mail address, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we will inform you in this declaration.
(p.7) BUSINESS NEWSLETTER FOR BUSINESS CUSTOMERS As an entrepreneur, you can order a business newsletter from us by entering and sending the mandatory information marked with an asterisk on our website. You can provide further personal data voluntarily. We will then contact you at the e-mail address and ask you to confirm that you are the owner of the e-mail address provided and that you agree to receive the newsletter (double opt-in; the legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO).
You can revoke your consent to the use of your personal data for the newsletter at any time. In this case we will delete your personal data. Furthermore, we delete your personal data if we have indications that it is not (or no longer) correct. If you do not confirm your e-mail address, we will also delete your personal data 3 months after we have received it. We do not delete data if we have the right to further storage for another reason or if we are obliged to do so due to statutory storage obligations.
(p.8) ADVERTISING With your express consent, we will regularly inform you about promotions, vouchers and trends and process your e-mail address for this (legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO).
You can revoke your consent to the use of your personal data for advertising purposes at any time. In this case we will delete your personal data. Furthermore, we delete your personal data if we have indications that it is not (or no longer) correct. We do not delete data if we have the right to further storage for another reason or if we are obliged to do so due to statutory storage obligations.
(p.9) FURTHER DATA PROCESSING We can also process your personal data if we offer participation in campaigns, competitions or similar services. You will receive more detailed information on this when you provide your personal data.
4. EXTERNAL SERVICE PROVIDERS
We use external service providers to process your order:
(4.1) We transmit your address data to shipping companies. These shipping companies are obliged to treat your personal data confidentially and to process it exclusively for the purpose of delivery. After delivery, the personal data must be deleted. The legal basis for the transmission of personal data is Art. 6 Abs. 1 S. 1 b) DS-GVO.
(h.2) Except for the "payment in advance" payment method, we transmit the personal data required for processing the payment ("payment data") to the commissioned bank or passed on to the selected payment service provider in order to enable payment processing. The respective payment service provider is responsible for your payment data. Information, in particular about who is responsible for the payment method you have selected and which data processing the payment service provider carries out, can be found at the following Internet addresses. The legal basis for the transmission is Art. 6 Abs. 1 S. 1 b) DS-GVO. We integrate third-party payment services on our website. When you make a purchase from us, your payment details (eg. B Name, payment amount, account details, credit card number) processed by the payment service provider for the purpose of payment processing. The respective contract and data protection provisions of the respective provider apply to these transactions. The payment service providers are used on the basis of Art. 6 Abs. 1 lit. b GDPR (contract execution) and in the interest of a payment process that is as smooth, convenient and secure as possible (Art. 6 Abs. 1 lit. f DSGVO). If your consent is requested for certain actions, Art. 6 Abs. 1 lit. a GDPR legal basis for data processing; Consent can be revoked at any time for the future.
We use the following payment services / payment service providers on this website:
(4.21) PAYPAL
The provider of this payment service is PayPal (Europe) S.To.rl and Cie, St.CA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full.Details can be found in PayPal's data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
(4.22) KLARNA Provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). Klarna offers various payment options (eg. B hire purchase). If you decide to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimize the use of the Klarna checkout solution. Details on the use of Klarna cookies can be found at the following link: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf.
You can read details about this in Klarna's data protection declaration under the following link: https://www.klarna.com/de/datenschutz/.
(4.23) MASTERCARD The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter "Mastercard").
Mastercard may transfer data to its parent company in the United States. Data transmission to the USA is based on Mastercard's Binding Corporate Rules. Details can be found here: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf.
(4.24) VISA The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).
Great Britain is considered a safe third country in terms of data protection. This means that Great Britain has a data protection level that corresponds to the data protection level in the European Union.
VISA may transfer data to its parent company in the United States. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html.
For more information, see VISA's privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.
(4.25) AMEX The provider of this payment service is American Express Europe S.A, Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter "American Express").
American Express may transfer data to its parent company in the United States. Data transmission to the USA is based on the Binding Corporate Rules. Details can be found here: https://www.americanexpress.com/en-pl/company/legal/privacy-centre/european-implementing- principles/.
For more information, see American Express' privacy policy: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html.
(4.26) AMAZON PAY The provider of this payment service is Amazon Payments Europe S.CA, 38 avenue J.F Kennedy, L-1855 Luxembourg.
You can read details about how your data is handled in the Amazon Pay data protection declaration under the following link:
https://pay.amazon.de/help/201212490?ld=APDELPADirect.5. COOKIES
(5.1) In addition to the personal data mentioned above, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive in the browser you are using and through which certain information flows to the place that sets the cookie (here from us). Cookies cannot run programs or transmit viruses to your computer. They serve to make the Internet offer more user-friendly and effective overall.
(5.2) Use of cookies: (5.21) This website uses the following types of cookies, the scope and functionality of which are explained below:
- Transient cookies (see 5.22)
- Persistent cookies (plus 5.23)
(5.22) Transient cookies are automatically deleted when you close the browser. These include in particular the session cookies. These store a so-called session ID, with which various requests from your browser can be assigned to the joint session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.
(5.23) Persistent cookies are automatically deleted after a specified period, which can vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time. We use the following persistent cookies on the website: - Google Analytics (ga - storage period: 2 years,_gid - storage period: 1 day). You can find more information about Google Analytics under section 6.
- Google Marketing Platform (IDE - storage period: 390 days). You can find more information about the Google Marketing Platform under Section 7.
- Facebook Custom Audiences (fbp - storage period 90 days, fr - storage period: 90 days). You can find more information about Facebook Custom Audiences under Section 8.
- as well as a cookie with which we can save the contents of your shopping cart (basketSessionId - storage period: 7 days).
(5.24) The cookies we use are required for the technical implementation of interactive user functions. For example, cookies enable the contents of your virtual shopping cart to be retained across multiple websites. In addition, we use cookies in accordance with this data protection declaration for the technically error-free and optimized provision of our services. The data processed by cookies Personal data is for the purposes mentioned to protect our legitimate interests and those of third parties in accordance with Art. 6 Abs. 1 S. 1 f) GDPR required.
(5.25) We also use cookies to collect statistical data about the general usage behavior of our users. By evaluating this data, we get a better understanding of the needs of our users, so that we can further develop our website in a more targeted manner and improve the overall user experience. However, these cookies do not contain any personal data and are not linked to such data. (5.26) We also use cookies for analysis and targeting purposes. Further information, also on the legal basis, can be found in sections 6, 7 and 8. (5.27) You can configure your browser settings according to your wishes and e.g. B refuse to accept third-party cookies or all cookies. We would like to point out that you may not be able to use all the functions of this website. (5.29) Consent with Usercentrics This website uses the consent technology from Usercentrics to obtain your consent to the storage of certain cookies on your end device or to the use of certain technologies and to document this in compliance with data protection regulations. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Website:
https://usercentrics.com/de/(hereinafter "Usercentrics").When you enter our website, the following personal data will be transmitted to Usercentrics:
- Your consent(s) or the revocation of your consent(s)
- your IP address
- information about your browser
- information about your end device
- time of your visit to the website
Usercentrics also stores a cookie in your browser in order to give you the consent or to assign their revocation. The data collected in this way is stored until you request us to delete it, delete the Usercentrics cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention requirements remain unaffected.
Usercentrics is used to obtain the legally required consent for the use of certain technologies. The legal basis for this is Art. 6 Abs. 1 lit. c DSGVO.
We have concluded an order processing contract (AVV) with the above-mentioned provider. This is a contract required by data protection law, which ensures that the personal data of our website visitors is only processed according to our instructions and in compliance with the GDPR.
6. USE OF GOOGLE ANALYTICS
(6.1) This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as B Page views, length of stay, operating systems used and origin of the user. This data may be used by Google summarized in a profile that is assigned to the respective user or whose end device is assigned.
We can also use Google Analytics and a Record your mouse and scroll movements and clicks. Furthermore, Google Analytics uses various modeling approaches to supplement the recorded data sets and uses machine learning technologies for data analysis.
Google Analytics uses technologies that enable the user to be recognized for the purpose of analyzing user behavior (e.g. B Cookies oder Device-Fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.
The use of this analysis tool is based on Art. 6 Abs. 1 lit. f DSGVO The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. If a corresponding consent was requested (eg. B consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 Abs. 1 lit. a GDPR; the consent can be revoked at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://privacy.google.com/businesses/controllerterms/mccs/.(sh.2) The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. (sh.3) You can prevent the storage of cookies by setting your browser software accordingly; we would like to point out to you however that in this case you will if applicable not be able to use all functions of this website in full. You can also prevent the collection of the data generated by the cookie and related to your use of the website (incl. your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de. More information on how Google Analytics handles user data can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
(sh.4) As an alternative to the browser add-on or on mobile devices, you can prevent Google Analytics from collecting data by clicking on the following link. An opt-out cookie will be set to prevent future collection of your data when you visit our website/our online shop: Disable Google Analytics. If you delete your cookies, you must click this link again. To prevent Google Analytics from collecting data across different devices, you must opt out on all systems used. (sh.5) We have activated the IP anonymization function on this website. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. (sh.6) We use Google Analytics to analyze and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. Our legitimate interest in data processing also lies in these purposes. The legal basis for the use of Google Analytics is § 15 para. 3 TMG or Art. 6 Abs. 1 S. 1 f) DS-GVO Sessions and campaigns are terminated after a certain period of time. By default, sessions are terminated after 30 minutes of inactivity and campaigns are terminated after 6 months. The time limit for campaigns can be a maximum of 2 years. (sh.7) Storage period Data stored by Google at user and event level, which is linked to cookies, user IDs (e.g. B User ID) or advertising IDs (e.g. B DoubleClick cookies, Android advertising ID) will be anonymized or deleted after 2 months. turned off You can find details on this under the following link: https://support.google.com/analytics/answer/7667196?hl=de
(6.8) With your consent, this website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out using a user ID. The legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO
(sh.9) Order processing We have concluded an order processing contract with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
7. USE OF GOOGLE MARKETING PLATFORM
(7.1) This website uses the Google Marketing Platform of Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). The Google Marketing Platform uses cookies to serve ads relevant to users, to improve reports on campaign performance, or to prevent a user from seeing the same ads multiple times. Google uses a cookie ID to record which ads are placed in which browser and can thus prevent them from being displayed more than once. In addition, the Google Marketing Platform can use cookie IDs to Track conversions related to ad requests. This is the case, for example, when a user sees an ad and later goes to the advertiser's website with the same browser and buys something there. According to Google, cookies from the Google Marketing Platform do not contain any personal information.
(sh.2) Due to the marketing tools used, your browser automatically establishes a direct connection to the Google server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and are therefore informing you according to our current level of knowledge: By integrating the Google Marketing Platform, Google receives the information that you have accessed the relevant part of our website or clicked on one of our advertisements. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google If you have not logged in, there is a possibility that Google will find out and store your IP address. (sh.3) The legal basis for the processing of your data is your consent (Art. 6 Abs. 1 S. 1 a) DS-GVO). You can revoke your consent at any time [here]. (sh.4) Further information on the Google Marketing Platform can be found at https://marketingplatform.google.com, as well as on data protection at Google in general: https://policies.google.com/privacy. Alternatively, you can visit the Network Advertising Initiative (NAI) website at http://www.networkadvertising.org. 8. USE OF FACEBOOK CUSTOM AUDIENCES
(8.1) The website uses the "Custom Audiences" remarketing function of Facebook Inc. („Facebook“). As a result, users of the website can be shown interest-based advertisements ("Facebook Ads") when they visit the social network Facebook or other websites that also use the process. In doing so, we are interested in showing you advertising that is of interest to you in order to make our website more interesting for you.
(8.2) Due to the marketing tools used, your browser automatically establishes a direct connection to the Facebook server. We have no influence on the scope and further use of the data collected by Facebook through the use of this tool and are therefore informing you according to our state of knowledge: By integrating Facebook Custom Audiences, Facebook receives the information that you have visited the corresponding website of ours accessed our website or clicked on one of our advertisements. If you are registered with a Facebook service, Facebook can assign the visit to your account. Even if you are not registered with Facebook or If you have not logged in, there is a possibility that the provider will find out and store your IP address and other identifiers. Insofar as personal data is collected on our website and forwarded to Facebook using the tool described here, we and Facebook Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing responsible (Art. 26 GDPR). Joint responsibility is limited to collecting the data and passing it on to Facebook. The processing by Facebook after the forwarding is not part of the joint responsibility. Our joint obligations have been set out in a joint processing agreement. The text of the agreement can be found at:
https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for issuing data protection information when using the Facebook tool and for implementing the tool on our website in a secure manner in accordance with data protection law. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g. B Request for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert the rights of data subjects with us, we are obliged to forward them to Facebook.Facebook's data protection information contains further information on protecting your privacy: https://de-de.facebook.com/about/privacy/.
(8.3) We do not transmit any (hashed) e-mail addresses to Facebook and do not carry out an "automatic extended comparison" in which further user data would be transmitted. (8.4) Third party information: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. According to Facebook, however, the data collected is also transferred to the USA and other third countries. User conditions: https://www.facebook.com/legal/terms/update, overview of data protection: https://de-de.facebook.com/privacy/explanation. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.(8.5) The legal basis for the processing of your data is your consent (Art. 6 Abs. 1 S. 1 a) DS-GVO). You can revoke your consent at any time [here]. 9. RECIPIENTS OF YOUR DATA / THIRD COUNTRY TRANSFERS
(9.1) Apart from the recipients mentioned above under items 4, 6, 7 and 8, we may disclose or forward your personal data to IT service providers. The IT service providers are carefully selected by us and work for us as processors.
(ia.2) In addition, your personal data will only be transmitted to third parties if and to the extent that this is legally permissible and necessary for the fulfillment of contracts concluded with you or for the performance of the services (the legal basis in this respect is Art. 6 Abs. 1 S. 1 b) GDPR), you have given us your consent to the transmission (legal basis is Art. 6 Abs. 1 S. 1 a) DS-GVO), the disclosure is necessary to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data (legal basis is Art. 6 Abs. 1 S. 1 f) GDPR) or in the event that there is a legal obligation for the transfer (legal basis Art. 6 Abs. 1 S. 1 c) DS-GVO). (ia.3) If personal data is to be transferred to a country outside the European Economic Area (EEA), we will inform you of this in these data protection regulations or when the personal data is collected. 10. REVOCATION OF CONSENT OR OBJECTION TO THE PROCESSING OF YOUR PERSONAL DATA
(10.1) If you have given your consent to the processing of your personal data, you can revoke this at any time. Such a revocation affects the admissibility of the processing of your personal data after you have given it to us.
(10.2) If we base the processing of your personal data on the balancing of interests, you can object to the processing. This is the case if the processing is not necessary in particular to fulfill a contract with you, which is shown by us in the following description of the functions. If you exercise such an objection, we ask that you explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and will either stop processing the data or adapt or show you our compelling legitimate grounds on which we continue processing. (10.3) Of course, you can object to the processing of your personal data for advertising and data analysis purposes at any time. You can contact us about your objection to advertising under the number 1.2 provided contact information. 11. LINKEDIN
Data transmission to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:
https://www.linkedin.com/legal/l/dpa and
https://www.linkedin.com/legal/l/eu-sccs.Object to the analysis of usage behavior and targeted advertising by LinkedIn under the following link:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.Furthermore, LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To prevent LinkedIn from linking data collected on our website to your LinkedIn account, you must log out of your LinkedIn account before visiting our website.
We have concluded an order processing contract with LinkedIn.