GERMAN

Data protection

This data protection declaration explains the type, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer and the associated websites, functions and content as well as external online presences, such as our social media profile. (hereinafter jointly referred to as "online offer"). With regard to the terms used, such as "processing" or "person responsible", we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

Responsible person

Susanne Kurwig

Wevelinghoven 26a

41334 Nettetal

Germany

skurwig@gmx.de

www.susannekurwig.com

Imprint:   www.susannekurwig.com/AGB

Types of data processed:

- Inventory data (e.g., names, addresses).

- Contact details (e.g., email, phone numbers).

- Content data (e.g., text input, photographs, videos).

- Usage data (e.g. websites visited, interest in content, access times).

- Meta / communication data (e.g. device information, IP addresses).

Categories of data subjects

Visitors and users of the online offer (in the following we refer to the affected persons collectively as "users").

Purpose of processing

- Provision of the online offer, its functions and content.

- Answering contact inquiries and communicating with users.

- Safety measures.

- Reach measurement / marketing

Terms used

“Personal data” is all information that relates to an identified or identifiable natural person (hereinafter “data subject”); A natural person is regarded as identifiable who can be identified directly or indirectly, in particular by means of assignment to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or one or more special features, which express the physical, physiological, genetic, psychological, economic, cultural or social identity of this natural person.

“Processing” is any process carried out with or without the aid of automated processes or any such series of processes in connection with personal data. The term goes far and includes practically every handling of data.

“Responsible person” is the natural or legal person, authority, institution or other body that alone or jointly with others decides on the purposes and means of processing personal data.

Relevant legal bases

In accordance with Art. 13 GDPR, we will inform you of the legal basis for our data processing. If the legal basis is not mentioned in the data protection declaration, the following applies: The legal basis for obtaining consent is Art. 6 Para. 1 lit. a and Art. 7 GDPR, the legal basis for processing for the performance of our services and the implementation of contractual measures Answering inquiries is Art. 6 Para. 1 lit.b GDPR, the legal basis for processing to fulfill our legal obligations is Art. 6 Para. 1 lit.c GDPR, and the legal basis for processing to safeguard our legitimate interests is Art . 6 para. 1 lit.f GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 (1) (d) GDPR serves as the legal basis.

Cooperation with contract processors and third parties

If we disclose data to other persons and companies (contract processors or third parties) as part of our processing, transmit them to them or otherwise grant them access to the data, this is only done on the basis of legal permission (e.g. if the data is transmitted to third parties, such as to payment service providers, according to Art. 6 Para. 1 lit.b GDPR is required to fulfill the contract), you have consented, a legal obligation provides for this or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

If we commission third parties to process data on the basis of a so-called "order processing contract", this is done on the basis of Art. 28 GDPR.

Transfers to third countries

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this happens in the context of the use of third-party services or disclosure or transmission of data to third parties, this will only take place if it happens to fulfill our (pre) contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permissions, we process or have the data processed in a third country only if the special requirements of Art. 44 ff. GDPR are met. This means that processing takes place, for example, on the basis of special guarantees, such as the officially recognized determination of a data protection level corresponding to the EU (e.g. for the USA through the "Privacy Shield") or compliance with officially recognized special contractual obligations (so-called "standard contractual clauses").

Rights of data subjects

You have the right to request confirmation as to whether the data in question is being processed and to request information about this data as well as further information and a copy of the data in accordance with Art. 15 GDPR.

You have accordingly. Art. 16 GDPR the right to request the completion of the data concerning you or the correction of the incorrect data concerning you.

In accordance with Art. 17 GDPR, you have the right to demand that the relevant data be deleted immediately or, alternatively, in accordance with Art. 18 GDPR, to request a restriction on the processing of the data.

You have the right to request that you receive the data concerning you that you have provided to us in accordance with Art. 20 GDPR and to request that it be transmitted to other responsible parties.

In accordance with Art. 77 GDPR, you also have the right to lodge a complaint with the competent supervisory authority.

Right of withdrawal

You have the right to revoke your consent in accordance with Article 7 (3) GDPR with effect for the future

Right to object

You can object to the future processing of your data in accordance with Art. 21 GDPR at any time. The objection can in particular be made against processing for direct marketing purposes.

Cookies and right to object to direct mail

"Cookies" are small files that are stored on the users' computers. Various information can be stored within the cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offer. Temporary cookies, or "session cookies" or "transient cookies", are cookies that are deleted after a user leaves an online offer and closes his browser. Such a cookie can, for example, store the content of a shopping cart in an online shop or a login status. Cookies are referred to as "permanent" or "persistent" and remain stored even after the browser is closed. For example, the login status can be saved if users visit it after several days. The interests of the users can also be stored in such a cookie, which are used for range measurement or marketing purposes. "Third-party cookies" are cookies that are offered by providers other than the person responsible for operating the online offer (otherwise, if they are only their cookies, they are referred to as "first-party cookies").

We can use temporary and permanent cookies and clarify this in the context of our data protection declaration.

If users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in the system settings of their browser. Saved cookies can be deleted in the system settings of the browser. The exclusion of cookies can lead to functional restrictions of this online offer.

A general objection to the use of cookies used for online marketing purposes can be made for a large number of services, especially in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/ to be explained. Furthermore, cookies can be saved by deactivating them in the browser settings. Please note that if you do so, you may not be able to use all the functions of this online offer.

Deletion of data

The data processed by us will be deleted or restricted in their processing in accordance with Art. 17 and 18 GDPR. Unless expressly stated in this data protection declaration, the data stored by us will be deleted as soon as they are no longer required for their intended purpose and the deletion does not conflict with any statutory retention requirements. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be kept for commercial or tax reasons.

According to legal requirements in Germany, the storage takes place in particular for 6 years in accordance with § 257 Paragraph 1 HGB (trading books, inventories, opening balances, annual financial statements, commercial letters, accounting documents, etc.) and for 10 years in accordance with § 147 Paragraph 1 AO (books, records , Management reports, accounting documents, commercial and business letters, documents relevant for taxation, etc.).

Business related processing

We also process

- Contract data (e.g., subject of the contract, duration, customer category).

- Payment data (e.g. bank details, payment history)

by our customers, interested parties and business partners for the purpose of providing contractual services, service and customer care, marketing, advertising and market research.

Hosting

The hosting services we use serve to provide the following services: Infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services that we use for the purpose of operating this online offer.

We or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta and communication data from customers, interested parties and visitors to this online offer on the basis of our legitimate interests in an efficient and secure provision of this online offer in accordance with Art. 6 Para. 1 lit.f GDPR in conjunction with Art. 28 GDPR (conclusion of an order processing contract).

Collection of access data and log files

We, or our hosting provider, collect data on every access to the server on which this service is located (so-called server log files) on the basis of our legitimate interests within the meaning of Art. 6 Paragraph 1 lit. The access data includes the name of the accessed website, file, date and time of access, amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), IP address and the requesting provider .

For security reasons (e.g. to investigate acts of abuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data, the further storage of which is necessary for evidence purposes, are excluded from deletion until the respective incident has been finally clarified.

Provision of contractual services

We process inventory data (e.g. names and addresses as well as contact details of users), contract data (e.g. services used, names of contact persons, payment information) for the purpose of fulfilling our contractual obligations and services in accordance with Art. 6 Para. 1 lit b. GDPR. The entries marked as mandatory in online forms are required for the conclusion of the contract.

When using our online services, we save the IP address and the time of the respective user action. The storage takes place on the basis of our legitimate interests, as well as the users in protection against misuse and other unauthorized use. This data is generally not passed on to third parties, unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Article 6 (1) (c) GDPR.

We process usage data (e.g., the websites of our online offer visited, interest in our products) and content data (e.g., entries in the contact form or user profile) for advertising purposes in a user profile, in order to show the user e.g. product information based on the services they have previously used.

The data is deleted after the expiry of statutory warranty and comparable obligations; the necessity of storing the data is checked every three years; In the case of legal archiving obligations, the deletion takes place after their expiry. Information in any customer account remains until it is deleted.

Registration function

Users can optionally create a user account. As part of the registration, the required mandatory information is communicated to the users. The data entered during registration will be used for the purpose of using the offer. Users can be informed of information relevant to the offer or registration, such as changes to the scope of the offer or technical circumstances, by email. If users have terminated their user account, their data will be deleted with regard to the user account, subject to their retention is necessary for commercial or tax reasons in accordance with Art. 6 Para. 1 lit. c GDPR. It is up to the users to save their data before the end of the contract if they have canceled. We are entitled to irretrievably delete all user data stored during the term of the contract.

As part of the use of our registration and login functions as well as the use of the user account, the IP address and the time of the respective user action are saved. The storage takes place on the basis of our legitimate interests, as well as the users in protection against misuse and other unauthorized use. This data is generally not passed on to third parties, unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Article 6 (1) (c) GDPR. The IP addresses are anonymized or deleted after 7 days at the latest.

contact

When contacting us (e.g. via the contact form, email, telephone or via social media), the information provided by the user is processed in order to process the contact request and to process it in accordance with Art. 6 Para. 1 lit. b) GDPR. The information provided by the users can be stored in a customer relationship management system ("CRM system") or a comparable request organization.

We delete the inquiries if they are no longer required. We review the requirement every two years; The statutory archiving obligations also apply.

Comments and contributions

If users leave comments or other contributions, their IP addresses are stored for 7 days on the basis of our legitimate interests within the meaning of Art. 6 Paragraph 1 lit. This is done for our safety if someone leaves illegal content in comments and contributions (insults, prohibited political propaganda, etc.). In this case we can be prosecuted for the comment or contribution and are therefore interested in the identity of the author.

Comment subscriptions

The follow-up comments can be subscribed to by users with their consent in accordance with Article 6 (1) (a) GDPR. The users receive a confirmation email to check whether they are the owner of the email address they entered. Users can unsubscribe from ongoing comment subscriptions at any time. The confirmation email will contain information on the cancellation options.

Newsletter

With the following information we inform you about the contents of our newsletter as well as the registration, dispatch and statistical evaluation procedures as well as your right of objection. By subscribing to our newsletter, you declare that you agree to the receipt and the procedures described.

Content of the newsletter: We send newsletters, e-mails and other electronic notifications with advertising information (hereinafter “newsletter”) only with the consent of the recipient or with legal permission. If the contents of the newsletter are specifically described when registering for the newsletter, they are decisive for the consent of the user. Incidentally, our newsletters contain information about our services and us.

Double opt-in and logging: The registration for our newsletter takes place in a so-called double opt-in procedure. This means that after registration you will receive an email in which you will be asked to confirm your registration. This confirmation is necessary so that nobody can register with someone else's e-mail address. The registrations for the newsletter are logged in order to be able to prove the registration process in accordance with the legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Changes to your data stored by the shipping service provider are also logged.

Registration data: To register for the newsletter, it is sufficient to provide your email address. Optionally, we ask you to provide a name so that we can address you personally in the newsletter.

The dispatch of the newsletter and the success measurement associated with it are based on the consent of the recipient in accordance with Article 6 (1) (a) and Article 7 GDPR in conjunction with Section 107 (2) TKG or on the basis of legal permission in accordance with Section 107 para. 2 and 3 TKG.

The logging of the registration process is based on our legitimate interests in accordance with Article 6 (1) (f) GDPR. Our interest is directed towards the use of a user-friendly and secure newsletter system that serves our business interests as well as the expectations of users and also allows us to prove consent.

Cancellation / Revocation - You can cancel the receipt of our newsletter at any time, ie revoke your consent. You will find a link to cancel the newsletter at the end of each newsletter. We can save the e-mail addresses that have been deleted for up to three years on the basis of our legitimate interests before we delete them for the purpose of sending the newsletter in order to be able to prove that consent was given previously. The processing of this data is limited to the purpose of a possible defense against claims. An individual request for deletion is possible at any time, provided that the former existence of a consent is confirmed at the same time.

Newsletter - shipping service provider

The newsletter is sent using the mailing service provider "MailChimp", a newsletter mailing platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE # 5000, Atlanta, GA 30308, USA. You can view the data protection regulations of the shipping service provider here: https://mailchimp.com/legal/privacy/ . The Rocket Science Group LLC d / b / a MailChimp is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with the European level of data protection ( https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active ). The shipping service provider is used on the basis of our legitimate interests in accordance with Article 6 (1) (f) GDPR and an order processing contract in accordance with Article 28 (3) sentence 1 GDPR.

The shipping service provider can use the recipient's data in pseudonymous form, ie without assignment to a user, to optimize or improve their own services, e.g. to technically optimize the shipping and presentation of the newsletter or for statistical purposes. However, the shipping service provider does not use the data of our newsletter recipients to write to them itself or to pass the data on to third parties.

Newsletter - success measurement

The newsletters contain a so-called "web beacon", ie a pixel-sized file that is retrieved from our server when the newsletter is opened or, if we use a shipping service provider, its server. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and the time of retrieval, are initially collected.

This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined with the help of the IP address) or the access times. The statistical surveys also include determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to the individual newsletter recipients. However, it is neither our aim nor, if used, that of the shipping service provider to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

Google Analytics

We use Google Analytics, a web analysis service provided by Google LLC (“Google”), on the basis of our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 Para. 1 lit. f. GDPR). Google uses cookies. The information generated by the cookie about the use of the online offer by the user is usually transmitted to a Google server in the USA and stored there.

Google is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active ).

Google will use this information on our behalf to evaluate the use of our online offer by users, to compile reports on the activities within this online offer and to provide us with other services related to the use of this online offer and the internet. In doing so, pseudonymous user profiles can be created from the processed data.

We only use Google Analytics with activated IP anonymization. This means that the IP address of the user is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. The full IP address will only be sent to a Google server in the USA and shortened there in exceptional cases.

The IP address transmitted by the user's browser will not be merged with other Google data. Users can prevent the storage of cookies by setting their browser software accordingly; Users can also prevent Google from collecting the data generated by the cookie and relating to their use of the online offer and from processing this data by downloading and installing the browser plug-in available under the following link: http: // tools .google.com / dlpage / gaoptout? hl = de .

You can find more information on the use of data by Google, setting and objection options on the Google website: https://www.google.com/intl/de/policies/privacy/partners (“Use of data by Google when you use websites or apps of our partners "), http://www.google.com/policies/technologies/ads (" Use of data for advertising purposes "), http://www.google.de/settings/ads (" Manage information that Google uses, to show you advertisements ").

Online presence in social media

We maintain an online presence within social networks and platforms in order to be able to communicate with the customers, interested parties and users active there and to inform them about our services. When calling up the respective networks and platforms, the terms and conditions and the data processing guidelines of their respective operators apply.

Unless otherwise stated in our privacy policy, we process the data of the users as long as they communicate with us within the social networks and platforms, e.g. write articles on our online presence or send us messages.

Integration of services and content from third parties

We use content or service offers from third-party providers within our online offer on the basis of our legitimate interests (i.e. interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 Para. 1 lit. Integrate services such as videos or fonts (hereinafter uniformly referred to as “content”).

This always presupposes that the third-party providers of this content perceive the IP address of the users, since they would not be able to send the content to their browser without the IP address. The IP address is therefore required to display this content. We strive to only use content whose respective providers only use the IP address to deliver the content. Third-party providers can also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information can also be stored in cookies on the user's device and contain, among other things, technical information about the browser and operating system, referring websites, visiting time and other information about the use of our online offer, as well as being linked to such information from other sources.

Use of Facebook social plugins

On the basis of our legitimate interests (ie interest in the analysis, optimization and economic operation of our online offer within the meaning of Art. 6 Para. 1 lit. f. GDPR), we use social plugins ("plugins") from the social network facebook.com , which operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland ("Facebook"). The plugins can display interaction elements or content (e.g. videos, graphics or text contributions) and can be recognized by one of the Facebook logos (white “f” on a blue tile, the terms “like”, “like” or a “thumbs up” sign ) or are marked with the addition "Facebook Social Plugin". The list and the appearance of the Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/ .

Facebook is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active ).

When a user calls up a function of this online offer that contains such a plugin, his device establishes a direct connection with the Facebook servers. The content of the plug-in is transmitted directly from Facebook to the user's device, which integrates it into the online offer. User profiles can be created from the processed data. We therefore have no influence on the amount of data that Facebook collects with the help of this plugin and therefore informs users according to our level of knowledge.

By integrating the plugins, Facebook receives the information that a user has called up the corresponding page of the online offer. If the user is logged in to Facebook, Facebook can assign the visit to his Facebook account. When users interact with the plugins, for example by pressing the Like button or making a comment, the corresponding information is transmitted directly from your device to Facebook and stored there. If a user is not a member of Facebook, there is still the possibility that Facebook will find out his IP address and save it. According to Facebook, only an anonymized IP address is saved in Germany.

The purpose and scope of the data collection and the further processing and use of the data by Facebook as well as the related rights and setting options to protect the privacy of users can be found in Facebook's data protection information: https://www.facebook.com/about/privacy/ .

If a user is a Facebook member and does not want Facebook to collect data about him through this online offer and link it to his member data stored on Facebook, he must log out of Facebook before using our online offer and delete his cookies. Further settings and contradictions to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US website http://www.aboutads.info / choices / or the EU page http://www.youronlinechoices.com/ . The settings are platform-independent, ie they are adopted for all devices such as desktop computers or mobile devices.

Twitter

Functions and contents of the Twitter service, offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, can be integrated into our online offer. This can include, for example, content such as images, videos or texts and buttons with which users can express their favor with regard to the content, subscribe to the authors of the content or our contributions. If the users are members of the Twitter platform, Twitter can assign the above-mentioned content and functions to the profiles of the users there. Instgram's privacy policy: https://twitter.com/de/privacy . Twitter is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active ). Data protection declaration: https://twitter.com/de/privacy , Opt-Out: https://twitter.com/personalization .

Instagram

Functions and contents of the Instagram service, offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA, can be integrated into our online offer. This may include, for example, content such as images, videos or texts and buttons with which users can express their liking for the content, subscribe to the authors of the content or our contributions. If the users are members of the Instagram platform, Instagram can assign the access to the above content and functions to the profiles of the users there. Instagram's privacy policy: http://instagram.com/about/legal/privacy/ .

Pinterest

Functions and contents of the Pinterest service, offered by Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA, can be integrated into our online offer. This may include, for example, content such as images, videos or texts and buttons with which users can express their liking for the content, subscribe to the authors of the content or our contributions. If the users are members of the Pinterest platform, Pinterest can assign the access to the above-mentioned content and functions to the profiles of the users there. Pinterest data protection declaration: https://about.pinterest.com/de/privacy-policy .

LinkedIn

Functions and contents of the LinkedIn service, offered by LinkedIn AG, Dammtorstraße 29-32, 20354 Hamburg, Germany, can be integrated into our online offer. This can include, for example, content such as images, videos or texts and buttons with which users can express their favor with regard to the content, subscribe to the authors of the content or our contributions. If the users are members of the LinkedIn platform, LinkedIn can assign the above-mentioned content and functions to the profiles of the users there. LinkedIn privacy policy: https://www.linkedin.com/legal/privacy-policy. . LinkedIn is certified under the Privacy Shield Agreement and thus offers a guarantee to comply with European data protection law ( https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active ). Data protection declaration: https://twitter.com/de/privacy , Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out .

ENGLISH

Privacy policy

1. Introduction

1.1 We are committed to safeguarding the privacy of our website visitors, collectors and customers.

1.2 This policy applies where we are acting as a data controller with respect to the personal data of our website visitors, collectors and customers; in other words, where we determine the purposes and means of the processing of that personal data.

1.3 We use cookies on our website. Insofar as those cookies are not strictly necessary for the provision of our website and services, we will ask you to consent to our use of cookies when you first visit our website.

2. Credit

2.1 This document was created using a template from SEQ Legal ( https://seqlegal.com ).

3. How we use your personal data

3.1 In this Section 3 we have set out:

(a) the general categories of personal data that we may process;

(b) in the case of personal data that we did not obtain directly from you, the source and specific categories of that data;

(c) the purposes for which we may process personal data; other

(d) the legal bases of the processing.

3.2 We may process data about your use of our website and services ("usage data"). The usage data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the usage data is Google Analytics. This usage data may be processed for the purposes of analyzing the use of the website and services. The legal basis for this processing is our legitimate interests, namely monitoring and improving our website and services.

3.3 We may process information that you post for publication on our website or through our services ("publication data"). The publication data may be processed for the purposes of enabling such publication and administering our website and services. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business

3.4 We may process information contained in any inquiry you submit to us regarding goods and / or services ("inquiry data"). The inquiry data may be processed for the purposes of offering, marketing and selling relevant goods and / or services to you. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business.

3.5 We may process information relating to our customer relationships, including customer contact information ("customer relationship data"). The customer relationship data may include your name, your, your contact details, and information contained in communications between us and you. The source of the customer relationship data is you. The customer relationship data may be processed for the purposes of managing our relationships with customers, communicating with customers, keeping records of those communications and promoting our products and services to customers. The legal basis for this processing is our legitimate interests, namely the proper management of our customer relationships.

3.6 We may process information relating to transactions, including purchases of goods and services, that you enter into with us and / or through our website ("transaction data"). No payment information (card details, account details, etc) will be processed directly through our website. The transaction data may include your contact details and the transaction details. Any payment processing of direct online purchases will be through PayPal. The transaction data may be processed for the purpose of supplying the purchased goods and services and keeping proper records of those transactions. The legal basis for this processing is the performance of a contract between you and us and / or taking steps, at your request, to enter into such a contract and our legitimate interests, namely the proper administration of our website and business.

3.7 We may process information that you provide to us for the purpose of subscribing to our email notifications and / or newsletters ("notification data"). The notification data may be processed for the purposes of sending you the relevant notifications and / or newsletters. The legal basis for this processing is the performance of a contract between you and us and / or taking steps, at your request, to enter into such a contract.

3.8 We may process information contained in or relating to any communication that you send to us ("correspondence data"). The correspondence data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms. The correspondence data may be processed for the purposes of communicating with you and record-keeping. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business and communications with users.

3.9 We may process any of your personal data identified in this policy where necessary for the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure. The legal basis for this processing is our legitimate interests, namely the protection and assertion of our legal rights, your legal rights and the legal rights of others.

3.10 We may process any of your personal data identified in this policy where necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice. The legal basis for this processing is our legitimate interests, namely the proper protection of our business against risks.

3.11 In addition to the specific purposes for which we may process your personal data set out in this Section 3, we may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.

3.12 Please do not supply any other person's personal data to us, unless we prompt you to do so.

4. Providing your personal data to others

4.1 We may disclose your personal data to our insurers and / or professional advisers insofar as reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice, or the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.

4.2 Financial transactions relating to our website and services are handled by our payment services provider, PayPal. We will share transaction data with our payment services provider only to the extent necessary for the purposes of processing your payments, refunding such payments and dealing with complaints and queries relating to such payments and refunds. You can find information about the payment services providers' privacy policies and practices at https://www.paypal.com/uk/webapps/mpp/ua/privacy-full .

4.3 In addition to the specific disclosures of personal data set out in this Section 4, we may disclose your personal data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your personal data where such disclosure is necessary for the establishment, exercise or defense of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.

5. International transfers of your personal data

5.1 In this Section 5, we provide information about the circumstances in which your personal data may be transferred to countries outside the European Economic Area (EEA).

5.2 You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.

6. Retaining and deleting personal data

6.1 This Section 6 sets out our data retention policies and procedure, which are designed to help ensure that we comply with our legal obligations in relation to the retention and deletion of personal data.

6.2 Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

6.3 We will retain your personal data as follows:

(a) Transaction data will be retained for a minimum period of 4 years and for a maximum period of 5 years.

(b) Publication data will be retained for the duration of the lifespan of the publicized article.

(c) All other personal data will only be retained for as long as it is necessary for the proper administration of our website and business.

6.4 Notwithstanding the other provisions of this Section 6, we may retain your personal data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.

7. Amendments

7.1 We may update this policy from time to time by publishing a new version on our website.

7.2 You should check this page occasionally to ensure you are happy with any changes to this policy.

7.3 We may notify you of significant changes to this policy by email.

8. Your rights

8.1 In this Section 8, we have summarized the rights that you have under data protection law. Some of the rights are complex, and not all of the details have been included in our summaries. Accordingly, you should read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights.

8.2 Your principal rights under data protection law are:

(a) the right to access;

(b) the right to rectification;

(c) the right to erasure;

(d) the right to restrict processing;

(e) the right to object to processing;

(f) the right to data portability;

(g) the right to complain to a supervisory authority; other

(h) the right to withdraw consent.

8.3 You have the right to confirmation as to whether or not we process your personal data and, where we do, access to the personal data, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of personal data concerned and the recipients of the personal data. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your personal data. The first copy will be provided free of charge, but additional copies may be subject to a reasonable fee.

8.4 You have the right to have any inaccurate personal data about you rectified and, taking into account the purposes of the processing, to have any incomplete personal data about you completed.

8.5 In some circumstances you have the right to erasure your personal data without undue delay. Those circumstances include: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the personal data have been unlawfully processed. However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary: ​​for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defense of legal claims.

8.6 In some circumstances you have the right to restrict the processing of your personal data. Those circumstances are: you contest the accuracy of the personal data; processing is unlawful but you oppose erasure; we no longer need the personal data for the purposes of our processing, but you require personal data for the establishment, exercise or defense of legal claims; and you have objected to processing, pending the verification of that objection. Where processing has been restricted on this basis, we may continue to store your personal data. However, we will only otherwise process it: with your consent; for the establishment, exercise or defense of legal claims; for the protection of the rights of another natural or legal person; or for reasons of important public interest.

8.7 You have the right to object to our processing of your personal data on grounds relating to your particular situation, but only to the extent that the legal basis for the processing is that the processing is necessary for: the performance of a task carried out in the public interest or in the exercise of any official authority vested in us; or the purposes of the legitimate interests pursued by us or by a third party. If you make such an objection, we will cease to process the personal information unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defense of legal claims.

8.8 You have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.

8.9 You have the right to object to our processing of your personal data for scientific or historical research purposes or statistical purposes on grounds relating to your particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

8.10 To the extent that the legal basis for our processing of your personal data is:

(a) consent; or

(b) that the processing is necessary for the performance of a contract to which you are party or in order to take steps at your request prior to entering into a contract, and such processing is carried out by automated means, you have the right to Receive your personal data from us in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.

8.11 If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.

8.12 To the extent that the legal basis for our processing of your personal information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.

8.13 You may exercise any of your rights in relation to your personal data by written notice to us.

9. About cookies

9.1 A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and is stored by the browser. The identifier is then sent back to the server each time the browser requests a page from the server.

9.2 Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; A session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.

9.3 Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies.

10. Cookies that we use

10.1 We use cookies for the following purposes:

(a) analysis - we use cookies to help us to analyze the use and performance of our website and service

(b) cookie consent - we use cookies to store your preferences in relation to the use of cookies more generally.

11. Cookies used by our service providers

11.1 Our service providers use cookies and those cookies may be stored on your computer when you visit our website.

11.2 We use Google Analytics to analyze the use of our website. Google Analytics gathers information about website use by means of cookies. The information gathered relating to our website is used to create reports about the use of our website. Google's privacy policy is available at: https://www.google.com/policies/privacy/ .

11.3 We use MailChimp to maintain and process newsletter subscribers. Mailchimp may use cookies. Mailchimp's privacy policy is available at:

https://mailchimp.com/legal/privacy/

11.4. We use Facebook Pixels to collect information about site visitors that allow us to create targeted marketing campaigns. The information may be collected using third party cookies, web beacons, and similar technologies. Please see the following link for information on how to opt out of this collection and use of collected information www.aboutads.info/choices

12. Managing cookies

12.1 Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:

(a) https://support.google.com/chrome/answer/95647?hl=en (Chrome);

(b) https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences (Firefox);

(c) http://www.opera.com/help/tutorials/security/cookies/ (Opera);

(d) https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);

(e) https://support.apple.com/kb/PH21411 (Safari); other

(f) https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy (Edge).

12.2 Blocking all cookies will have a negative impact upon the usability of many websites.

12.3 If you block cookies, you will not be able to use all the features on our website.

13. Our details

13.1 This website is owned and operated by Julia Badow.

13.2 Our principal place of business is at Am Tempelberg 26, 16225 Eberswalde, Germany.

13.3 You can contact us:

(a) by post, to the postal address given above;

(b) using our website contact form;

(c) by email, using the email address published on our website from time to time.

COPPA (Children Online Privacy Protection Act)

When it comes to the collection of personal information from children under 13, the Children's Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, the nation's consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children's privacy and safety online.

We do not specifically market to children under 13.

CAN SPAM Act

The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.

We collect your email address in order to:

• Process orders and to send information and updates pertaining to orders.

• We may also send you additional information related to your product and / or service.

• Market to our mailing list or continue to send emails to our clients after the original transaction has occurred.

To be in accordance with CANSPAM we agree to the following:

• NOT use false or misleading subjects or email addresses.

• Identify the message as an advertisement in some reasonable way.

• Include the physical address of our business or site headquarters.

• Monitor third-party email marketing services for compliance, if one is used.

• Honor opt-out / unsubscribe requests quickly.

• Allow users to unsubscribe by using the link at the bottom of each email.

If at any time you would like to unsubscribe from receiving future emails, you can email us at the address on my Contact page or follow the instructions at the bottom of each email newsletter and we will promptly remove you from ALL correspondence.