DATA PROTECTION DECLARATION AND CONSENT TO DATA USE
(valid from 25.05.2018)
Thank you for your interest in our website “Oh April”. The protection of your privacy is very important to us. The transparent and legally compliant collection, processing and use of your personal data (e.g. name, address, e-mail addresses, user behaviour) is therefore very important to us. In the following we therefore inform you in detail about how we handle your data.
1. Person responsible and contact details
The person responsible for the collection, processing and use of your personal data in accordance with the DSVGO is
JCA Fashion GmbH
Antwerpener Strasse 42
E-mail: [email protected]
If you wish to object to the collection, processing or use of your data by us in accordance with these data protection provisions, either as a whole or for individual measures, you can send your objection by letter or e-mail to the above-mentioned contact data. In addition, you can of course also obtain information about the data stored by us free of charge at any time under the contact data (see also section 7).
When you contact us, the data you provide will be stored by us in order to answer your questions. We delete the data arising in this connection after storage is no longer necessary or restrict processing if there are legal obligations to retain data.
2. Collection, storage and use of personal data
2.1 When visiting our website
When you call up our website www.oh-april.com, the browser used on your end device automatically sends information to the server of our website. This information is temporarily stored in a so-called log file. The following information is recorded without your intervention and stored until it is automatically deleted:
- IP address of the requesting computer,
- Date and time of access,
- Name and URL of the retrieved file,
- Website from which the access takes place (referrer URL),
- the browser used and, if applicable, the operating system of your computer and the name of your access provider.
We process the above data for the following purposes:
- Ensure a smooth connection of the website,
- Guarantee a comfortable use of our website,
- Evaluation of system security and stability and
- for other administrative purposes.
The legal basis for the data processing is Art. 6 para. 1 sentence 1 lit. f DSGVO. Our legitimate interest follows from the above listed purposes for data collection. Under no circumstances do we use the data collected for the purpose of drawing conclusions about your person.
2.2 When using further functions and offers of our website
In addition to the purely informative use, we offer various services which you can use if you are interested. For this purpose, you will usually have to provide further personal data which we use to provide the respective service.
a) Registration for our newsletter
If you have given your express consent in accordance with Art. 6 para. 1 sentence 1 lit.a DSGVO (we use the double opt-in procedure to register for our newsletter), we will use your e-mail address to send you our newsletter regularly and pass it on to hypelab GbR ( Imprint Hypelab GbR ) so that they can also send you their newsletter. For the receipt of the newsletter the indication of an E-Mail address is sufficient.
The notice of departure is at any time possible, for example over a link at the end of each newsletter. Alternatively, you can also unsubscribe (for one or both newsletters) at any time by sending an e-mail to [email protected]
We may also pass on your e-mail address to third parties if this is necessary for sending the newsletter. The legal basis for this is Art. 6 Para. 1 S.1 lit.a DSGVO.
Currently, our newsletter is sent via the service “MailChimp”. MailChimp is a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA.
The e-mail addresses of our newsletter recipients as well as the data mentioned in paragraph 2.1 are stored on the servers of MailChimp in the USA. MailChimp uses this information to send and evaluate the newsletter on our behalf. Furthermore MailChimp may use this information according to its own information to optimize or improve its own services, e.g. for technical optimization of sending and presentation of newsletters or for economic purposes to determine from which countries the recipients come. However, MailChimp does not use the data of our newsletter recipients to contact them itself or pass them on to third parties.
The newsletters contain a so-called “web-beacon”, i.e. a pixel-sized file which is retrieved from the server of MailChimp when the newsletter is opened. In the context of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and time of retrieval are collected. This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behaviour based on their retrieval locations (which can be determined by means of the IP address) or the access times.
Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our nor MailChimp’s intention to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our contents to them or to send different contents according to the interests of our users Translated
b) Use of our shop
If you would like to order “Oh April” in our webshop, it is necessary for the conclusion of the contract that you provide your personal data, which we need for the processing of your order. Mandatory data necessary for the processing of the contracts are marked separately, further data are voluntary. We process the data provided by you to process your order. For this purpose, we may also pass on your payment data to third parties (such as transport companies, logistics companies, banks, payment providers), insofar as this is necessary for processing your order.
Finally, we need your e-mail address so that we can confirm receipt of your order and communicate with you, in particular to send you technical information in connection with your order. The legal basis for this is also Art. 6 Para. 1 S.1 lit.b DSGVO.
We are obliged by commercial and tax law to store your address, payment and order data for a period of 10 years.
2.3 Disclosure to third parties
If we use external service providers for processing your data, these have been carefully selected and commissioned by us. They are also bound to our instructions by the conclusion of commissioned data processing contracts in accordance with § 28 DSGVO and are regularly checked by us.
In general, we only pass on your personal data to third parties if:
- you have given your express consent in accordance with Art. 6 para. 1 sentence 1 letter a DSGVO,
- the disclosure pursuant to Art. 6 para. 1 sentence 1 letter f DSGVO is necessary for the assertion, exercise or defence of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data,
- in the event that there is a legal obligation to pass on the data pursuant to Art. 6 para. 1 sentence 1 lit. c DSGVO, and
- this is legally permissible and required under Art. 6 para. 1 sentence 1 lit. b DSGVO for the processing of contractual relationships with you.
3. Cookies/html storage objects
Information is stored in the cookie that is related to the specific terminal device used. This does not mean, however, that we obtain direct knowledge of your identity.
In addition, we also use temporary cookies (persistent cookies) to optimise user-friendliness. These are stored on your terminal device for a certain specified period of time. If you visit our site again in order to use our services, it is automatically recognized that you have already been with us and which entries and settings you have made so that you do not have to enter them again.
The data processed by cookies is required for the above-mentioned purposes to protect our legitimate interests and those of third parties in accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO.
Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or so that a message always appears before a new cookie is created. However, completely deactivating cookies may mean that you cannot use all the functions of our website.
Incidentally, only pseudonymous data is stored in the cookies we use. When the cookie is activated, it is assigned an identification number and your personal data is not assigned to this identification number. Your name, your IP address or similar data that would allow the cookie to be assigned to you will not be placed in the cookie. On the basis of cookie technology, we only receive pseudonymised information, for example about which pages of our shop have been visited, which products have been viewed, etc.
Furthermore we use HTML5 storage objects, which are stored on your end device. These objects store the required data independently of the browser you use and have no automatic expiration date. You can prevent the use of HTML5 storage objects by setting your browser to private mode. We also recommend that you regularly delete the browser history manually.
The use of HTML5 storage objects serves to make the use of our offer more pleasant for you. The legal basis for the use is Art. 6 para. 1 sentence 1 lit. f DSGVO.
4. Analysis tools
The tracking measures listed below and used by us are carried out on the basis of Art. 6 para. 1 sentence 1 lit. f DSGVO. With the tracking measures used, we want to ensure that our website is designed to meet the needs of our customers and is continuously optimised. On the other hand, we use the tracking measures to record the use of our website statistically and evaluate it for the purpose of optimising our offer for you. These interests are to be regarded as justified in the sense of the aforementioned regulation.
The respective data processing purposes and data categories can be taken from the corresponding tracking tools.
4.1 Google Analytics
For the purpose of designing our pages to meet your needs and continuously optimizing them, we use Google Analytics, a web analysis service provided by Google LLC (https://www.google.de/intl/de/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”). In this context, pseudonymised user profiles are created and cookies (see section 4) are used. The information generated by the cookie about your use of this website such as
- Browser type/version,
- the operating system used,
- Referrer URL (the previously visited page),
- Host name of the accessing computer (IP address),
- Time of the server request,
are transmitted to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on the website activities and to provide further services associated with the use of the website and the Internet for the purposes of market research and the design of these Internet pages in line with requirements. This information may also be transferred to third parties if required by law or if third parties process this data on our behalf. Under no circumstances will your IP address be merged with other Google data. The IP addresses are made anonymous, so that an assignment is not possible (IP masking).
You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=de).
As an alternative to the browser add-on, especially in the case of browsers on mobile devices, you can also prevent the collection by Google Analytics by clicking on this link. An opt-out cookie is set to prevent future collection of your information when you visit this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you will need to set the opt-out cookie again.
Further information on data protection in connection with Google Analytics can be found in the Google Analytics help.
4.2 Google Adwords Conversion Tracking
In order to record the use of our website statistically and to evaluate it for the purpose of optimizing our website for you, we also use Google Conversion Tracking. Google Adwords sets a cookie (see point 3) on your computer if you have reached our website via a Google ad.
These cookies lose their validity after 30 days and are not used for personal identification. If the user visits certain pages of the Adwords client’s website and the cookie has not yet expired, Google and the client can recognize that the user clicked on the ad and was redirected to that page.
Each Adwords client receives a different cookie. As a result, cookies cannot be tracked through the websites of Adwords clients. The information collected through the conversion cookie is used to compile conversion statistics for Adwords clients who have opted for conversion tracking. Adwords advertisers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
5. Facebook Remarketing
On our website we use the remarketing function “Custom Audiences” of Facebook Inc. on the basis of Art. 6 para. 1 sentence 1 lit. f DSGVO. This function is used to present visitors to our website with interest-related advertisements (“Facebook Ads”) as part of their visit to the social network Facebook. For this purpose, the remarketing tag of Facebook was implemented on our website. This tag is used to establish a direct connection to the Facebook servers when visiting the website. In doing so, it is transmitted to the Facebook server that you have visited our website and Facebook assigns this information to your personal Facebook user account.
6. Google AdSense
Our website uses the online advertising service Google AdSense, through which advertising tailored to your interests can be presented. We thus pursue the interest in showing you advertising that could be of interest to you in order to make our website more interesting for you. For this purpose, statistical information about you is collected and processed by our advertising partners. These advertisements can be identified by the reference “Google Ads” in the respective ad.
By visiting our website, Google receives the information that you have called up our website. For this purpose Google uses a web beacon to set a cookie on your computer. The data mentioned in section 2.1 is transmitted. We have no influence on the data collected, nor are we aware of the full extent of the data collection and the storage period. Your data will be transferred to the USA and evaluated there. If you are logged in with your Google account, your data can be directly assigned to it. If you do not want the assignment with your Google profile, you have to log out. It is possible that this data is passed on to contractual partners of Google to third parties and authorities.
The legal basis for the processing of your data is Art. 6 para. 1 sentence 1 lit. f DSGVO.
This website does not use Google AdSense to display ads from third parties.
You can prevent the installation of Google AdSense cookies in different ways: a) by adjusting your browser software settings accordingly, in particular the suppression of third-party cookies means that you will not receive ads from third parties; b) by deactivating interest-based ads on Google via the link http://www.google. de/ads/preferences, this setting being deleted if you delete your cookies; c) by deactivating the interest-based ads of the providers that are part of the self-regulation campaign “About Ads” via the link http://www.aboutads.info/choices, this setting being deleted if you delete your cookies; d) by permanently deactivating them in your Firefox, Internetexplorer or Google Chrome browsers via the link http://www.google.com/settings/ads/plugin. We would like to point out that in this case you may not be able to use all functions of this offer to their full extent.
7. Rights of data subjects
You have the right:
- to request information about your personal data processed by us in accordance with Art. 15 DSGVO In particular, you may request information on the purposes of processing, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right of rectification, erasure, restriction of processing or opposition, the existence of a right of appeal, the origin of your data, if not collected by us, as well as the existence of automated decision making including profiling and, if applicable, meaningful information on the details of such data;
- in accordance with Art. 16 DSGVO to immediately request the correction of incorrect or incomplete personal data stored by us;
- in accordance with Art. 17 DSGVO to demand the deletion of your personal data stored with us, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims
- pursuant to Art. 18 DSGVO, to demand the restriction of the processing of your personal data, if the accuracy of the data is disputed by you, if the processing is unlawful, but you refuse to delete it and we no longer require the data, but you require it for the assertion, exercise or defence of legal claims or if you have lodged an objection to the processing pursuant to Art. 21 DSGVO
- in accordance with Art. 20 DSGVO to receive your personal data that you have provided us with in a structured, common and machine-readable format or to request its transfer to another responsible party;
- in accordance with Art. 7 Para. 3 DSGVO to revoke your once given consent to us at any time. As a result, we may no longer continue to process the data which was based on this consent in the future and
- complain to a supervisory authority pursuant to Art. 77 DSGVO. As a rule, you can turn to the supervisory authority of your usual place of residence or workplace or to the supervisory authority of our company headquarters.
8. Right of objection and revocation
If your personal data are processed on the basis of legitimate interests in accordance with Art. 6 para. 1 sentence 1 letter f DSGVO, you have the right to object to the processing of your personal data in accordance with Art. 21 DSGVO if there are reasons for doing so arising from your particular situation or if the objection is directed against direct marketing. In the latter case, you have a general right of objection, which will be implemented by us without indicating any special situation.
If we process your personal data on the basis of your consent pursuant to Art. 6 para. 1 sentence 1 lit. a DSGVO, you may revoke this Art. 7 para. 3 DSGVO at any time with effect from the date of revocation.
If you wish to exercise your right of revocation or objection, an e-mail via this link is sufficient.
9. Data security
We use the common SSL (Secure Socket Layer) procedure within the website visit in connection with the highest encryption level supported by your browser. As a rule, this is a 256 bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is being transmitted in encrypted form by the closed display of the key or lock symbol in the lower status bar of your browser.
We also use suitable technical and organisational security measures to protect your data against accidental or deliberate manipulation, partial or complete loss, destruction or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.
10. Topicality and amendment of this data protection declaration
It may become necessary to amend this data protection declaration as a result of the further development of our website and offers above or due to changes in legal or official requirements. You can access and print out the current data protection declaration at any time on the website at https://www.oh-april.com/pages/datenschutzerklarung.