• 0
    Cart empty

Privacy Policy

Privacy Policy

This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to briefly as “data”) within our online offering and the websites, functions and content associated with it, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terminology used, such as “processing” or “controller”, we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

Controller

Blanket Store
Hasengasse 2
60311 Frankfurt
Germany
Email: natalie(at)blanketstore.de
Owner: Natalie Gray

Legal Notice: http://blanketstore.de/index.php/de/impressum

Types of Data Processed

  • Master data (e.g. names, addresses).

  • Contact data (e.g. email, telephone numbers).

  • Content data (e.g. text entries, photographs, videos).

  • Usage data (e.g. websites visited, interest in content, access times).

  • Meta/communication data (e.g. device information, IP addresses).

Categories of Data Subjects

Visitors and users of the online offering (hereinafter we also refer to the data subjects collectively as “users”).

Purpose of Processing

  • Provision of the online offering, its functions and content.

  • Responding to contact requests and communicating with users.

  • Security measures.

  • Reach measurement/marketing.

Terminology Used

“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.

“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.

“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.

“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Relevant Legal Bases

In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing activities. Unless the legal basis is specified in this Privacy Policy, the following applies: The legal basis for obtaining consent is Art. 6 para. 1 lit. a and Art. 7 GDPR; the legal basis for processing for the performance of our services and implementation of contractual measures as well as responding to enquiries is Art. 6 para. 1 lit. b GDPR; the legal basis for processing for compliance with our legal obligations is Art. 6 para. 1 lit. c GDPR; and the legal basis for processing for the purposes of our legitimate interests is Art. 6 para. 1 lit. f GDPR. Where the vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d GDPR serves as the legal basis.

Security Measures

In accordance with Art. 32 GDPR and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input, disclosure, safeguarding of availability and separation of the data. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data and response to threats to data security. In addition, we take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principles of data protection by design and by default (Art. 25 GDPR).

Cooperation with Processors and Third Parties

Where, as part of our processing, we disclose data to other persons and companies (processors or third parties), transfer data to them or otherwise grant them access to the data, this is done only on the basis of a legal authorisation (e.g. where the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR), where you have consented, where a legal obligation requires it or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

Where we commission third parties to process data on the basis of a so-called “data processing agreement”, this is done on the basis of Art. 28 GDPR.

Transfers to Third Countries

Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transferring data to third parties, this is done only where it is necessary for the performance of our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests.

Subject to statutory or contractual permissions, we process or have data processed in a third country only where the special requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of special safeguards, such as the officially recognised determination of a level of data protection corresponding to that of the EU (e.g. for the USA through the “Privacy Shield”) or compliance with officially recognised special contractual obligations (so-called “Standard Contractual Clauses”).

Rights of Data Subjects

You have the right to request confirmation as to whether data concerning you are being processed and to obtain information about such data, as well as further information and a copy of the data in accordance with Art. 15 GDPR.

In accordance with Art. 16 GDPR, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.

In accordance with Art. 17 GDPR, you have the right to request that data concerning you be deleted without undue delay or, alternatively, in accordance with Art. 18 GDPR, to request restriction of the processing of the data.

You have the right to request that the data concerning you which you have provided to us be received in accordance with Art. 20 GDPR and to request that such data be transmitted to other controllers.

Furthermore, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.

Right of Withdrawal

You have the right to withdraw consent that you have given pursuant to Art. 7 para. 3 GDPR with effect for the future.

Right to Object

You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. The objection may in particular be made against processing for direct marketing purposes.

Cookies and Right to Object to Direct Marketing

“Cookies” are small files that are stored on users’ computers. Various types of information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offering.

Temporary cookies, also referred to as “session cookies” or “transient cookies”, are cookies that are deleted after a user leaves an online offering and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online shop or a login status.

Cookies that remain stored even after the browser has been closed are referred to as “permanent” or “persistent”. For example, the login status can be stored if users return after several days. Such a cookie may also store users’ interests, which are used for reach measurement or marketing purposes.

“Third-party cookies” are cookies offered by providers other than the controller operating the online offering (otherwise, if they are only the controller’s cookies, they are referred to as “first-party cookies”).

We may use temporary and permanent cookies and provide information about this within our Privacy Policy.

If users do not want cookies to be stored on their computer, they are requested to disable the corresponding option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. The exclusion of cookies may lead to functional limitations of this online offering.

A general objection to the use of cookies used for online marketing purposes can be declared for many services, particularly in the case of tracking, via the US website aboutads.info/choices or the EU website Your Online Choices. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that in this case not all functions of this online offering may be available.

Deletion of Data

The data processed by us will be deleted or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated otherwise within this Privacy Policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and provided that deletion does not conflict with statutory retention obligations.

Where the data are not deleted because they are required for other legally permissible purposes, their processing will be restricted. This means that the data will be blocked and will not be processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

In accordance with statutory requirements in Germany, records are retained in particular for 10 years pursuant to §§ 147 para. 1 AO, 257 para. 1 nos. 1 and 4, para. 4 HGB (books, records, management reports, accounting documents, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to § 257 para. 1 nos. 2 and 3, para. 4 HGB (commercial correspondence).

In accordance with statutory requirements in Austria, records are retained in particular for 7 years pursuant to § 132 para. 1 BAO (accounting records, receipts/invoices, accounts, documents, business papers, statements of income and expenditure, etc.), for 22 years in connection with real estate and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU Member States for which the Mini One Stop Shop (MOSS) is used.

Business-Related Processing

In addition, we process:

  • Contract data (e.g. subject matter of the contract, term, customer category).

  • Payment data (e.g. bank details, payment history)

of our customers, prospective customers and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.

Order Processing in the Online Shop and Customer Account

We process our customers’ data as part of the ordering processes in our online shop in order to enable them to select and order the chosen products and services and to enable their payment and delivery or performance.

The data processed include master data, communication data, contract data and payment data, and the persons affected by the processing include our customers, prospective customers and other business partners. Processing is carried out for the purpose of providing contractual services in connection with the operation of an online shop, billing, delivery and customer service. In this context, we use session cookies to store the contents of the shopping cart and permanent cookies to store the login status.

Processing is carried out on the basis of Art. 6 para. 1 lit. b (processing of orders) and c (legally required archiving) GDPR. Information marked as required is necessary for the establishment and performance of the contract. We disclose data to third parties only in connection with delivery, payment or within the framework of statutory permissions and obligations towards legal advisers and authorities. Data are processed in third countries only where this is necessary for the performance of the contract (e.g. at the customer’s request for delivery or payment).

Users may optionally create a user account, in which they can in particular view their orders. During registration, users are informed of the required mandatory information. User accounts are not public and cannot be indexed by search engines.

When users have terminated their user account, their data relating to the user account will be deleted, unless retention is necessary for commercial or tax law reasons pursuant to Art. 6 para. 1 lit. c GDPR. Information in the customer account remains until its deletion, followed by archiving where there is a legal obligation. It is the users’ responsibility to back up their data before the end of the contract in the event of termination.

As part of registration and subsequent logins as well as the use of our online services, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests as well as those of users in protection against misuse and other unauthorised use. As a general rule, these data are not passed on to third parties unless this is necessary for the pursuit of our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c GDPR.

Deletion takes place after the expiry of statutory warranty and comparable obligations; the necessity of retaining the data is reviewed every three years. In the case of statutory archiving obligations, deletion takes place after their expiry (end of the commercial-law retention period of 6 years and the tax-law retention period of 10 years).

External Payment Service Providers

We use external payment service providers through whose platforms users and we can carry out payment transactions (e.g., in each case with a link to the Privacy Policy):

PayPal: PayPal Privacy Policy
Klarna: Klarna Privacy Policy
Skrill: Skrill Privacy Policy
Giropay: Giropay Privacy Information
Visa: Visa Privacy Policy
Mastercard: Mastercard Privacy Policy
American Express: American Express Privacy Policy

For the performance of contracts, we use payment service providers on the basis of Art. 6 para. 1 lit. b GDPR. In addition, we use external payment service providers on the basis of our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR in order to offer our users effective and secure payment options.

The data processed by payment service providers include master data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and verification codes, as well as contract-related, amount-related and recipient-related information. The information is required in order to carry out the transactions.

However, the data entered are processed and stored only by the payment service providers. This means that we do not receive any account- or credit-card-related information, but only information confirming or rejecting the payment. Under certain circumstances, the payment service providers may transmit the data to credit agencies. The purpose of this transmission is identity and creditworthiness checks. In this regard, we refer to the terms and conditions and privacy information of the payment service providers.

The terms and conditions and privacy information of the respective payment service providers apply to payment transactions and can be accessed on the respective websites or transaction applications. We also refer to these for further information and for exercising rights of withdrawal, access and other data subject rights.

Administration, Financial Accounting, Office Organisation, Contact Management

We process data in connection with administrative tasks and the organisation of our business, financial accounting and compliance with legal obligations, such as archiving. In this context, we process the same data that we process in connection with the provision of our contractual services.

The legal bases for processing are Art. 6 para. 1 lit. c GDPR and Art. 6 para. 1 lit. f GDPR. The processing concerns customers, prospective customers, business partners and website visitors. The purpose of and our interest in processing lies in administration, financial accounting, office organisation and data archiving, i.e. tasks that serve to maintain our business activities, perform our duties and provide our services. The deletion of data relating to contractual services and contractual communication corresponds to the information stated for these processing activities.

In this context, we disclose or transmit data to the financial authorities, advisers such as tax advisers or auditors, as well as other fee-collecting bodies and payment service providers.

Furthermore, on the basis of our business interests, we store information about suppliers, organisers and other business partners, e.g. for the purpose of contacting them at a later date. As a general rule, we store these predominantly company-related data permanently.

Registration Function

Users can create a user account. During registration, users are informed of the required mandatory information, which is processed on the basis of Art. 6 para. 1 lit. b GDPR for the purpose of providing the user account. The data processed include, in particular, login information (name, password and an email address). The data entered during registration are used for the purposes of using the user account and its intended purpose.

Users may be informed by email about information relevant to their user account, such as technical changes. If users have terminated their user account, their data relating to the user account will be deleted, subject to any statutory retention obligation. It is the users’ responsibility to back up their data before the end of the contract in the event of termination. We are entitled to irretrievably delete all user data stored during the term of the contract.

As part of the use of our registration and login functions and the use of the user account, we store the IP address and the time of the respective user action. Storage is based on our legitimate interests as well as those of users in protection against misuse and other unauthorised use. As a general rule, these data are not passed on to third parties unless this is necessary for the pursuit of our claims or there is a legal obligation to do so pursuant to Art. 6 para. 1 lit. c GDPR. IP addresses are anonymised or deleted after no more than 7 days.

Contact

When contacting us (e.g. via contact form, email, telephone or social media), the information provided by the user is processed for the purpose of handling and processing the contact request pursuant to Art. 6 para. 1 lit. b GDPR. Users’ information may be stored in a Customer Relationship Management system (“CRM system”) or comparable enquiry management system.

We delete enquiries if they are no longer required. We review the necessity every two years; statutory archiving obligations also apply.

Hosting and Email Dispatch

The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, email dispatch, security services and technical maintenance services, which we use for the purpose of operating this online offering.

In this context, we or our hosting provider process master data, contact data, content data, contract data, usage data, meta data and communication data of customers, prospective customers and visitors to this online offering on the basis of our legitimate interests in the efficient and secure provision of this online offering pursuant to Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of a data processing agreement).

Collection of Access Data and Log Files

We, or our hosting provider, collect data about every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6 para. 1 lit. f GDPR.

The access data include the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page), IP address and the requesting provider.

Log file information is stored for security reasons (e.g. to investigate misuse or fraud) for a maximum period of 7 days and is then deleted. Data whose further retention is necessary for evidentiary purposes are excluded from deletion until the respective incident has been finally clarified.

Google Fonts

We integrate fonts (“Google Fonts”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Privacy Policy: Google Privacy Policy
Opt-Out: Google Ads Settings

Created with Datenschutz-Generator.de by attorney Dr. Thomas Schwenke.