DATA PROTECTION
DATA PROTECTION
Personal data (hereinafter mostly referred to as "data") will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered there.
According to Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as “GDPR”), “processing” is any process carried out with or without the help of automated processes or any such series of processes in connection with personal data, such as collecting, recording, organizing, arranging, storing, adapting or changing, reading, querying, using, disclosing through transmission, dissemination or any other form of provision, comparison or the linking, the restriction, the deletion or the destruction.
With the following data protection declaration we inform you in particular about the type, scope, purpose, duration and legal basis of the processing of personal data, as far as we decide either alone or together with others about the purposes and means of processing. In addition, we will inform you below about the third-party components we use for optimization purposes and to increase the quality of use, insofar as third parties process data on their own responsibility.
Our data protection declaration is structured as follows:
I. Information about us as responsible
II. Rights of users and data subjects
III. Information on data processing
I. Information about us as responsible
Responsible provider of this website in terms of data protection law is:
Steffen Gärlich
Bänschstrasse 66, D - 10247 Berlin
Email: office@holyframes.de
II. Rights of users and data subjects
With regard to the data processing described in more detail below, users and data subjects have the right
-
for confirmation as to whether the data concerning you are being processed, for information about the processed data, for further information about the data processing and for copies of the data (see also Art. 15 GDPR);
-
to correct or complete incorrect or incomplete data (see also Art. 16 GDPR);
-
to the immediate deletion of the data concerning you (cf. also Art. 17 GDPR), or, alternatively, if further processing is required in accordance with Art. 17 Para. 3 GDPR, to restriction of processing in accordance with Art. 18 GDPR;
-
to receive the data concerning them and provided by them and to transfer this data to other providers / responsible parties (cf. also Art. 20 GDPR);
-
to complain to the supervisory authority, provided that they are of the opinion that the data concerning them are being processed by the provider in violation of data protection regulations (see also Art. 77 GDPR).
In addition, the provider is obliged to notify all recipients to whom data has been disclosed by the provider of any correction or deletion of data or the restriction of processing that takes place on the basis of Articles 16, 17 Paragraph 1, 18 GDPR teaching. However, this obligation does not exist if this notification is impossible or involves disproportionate effort. Irrespective of this, the user has a right to information about these recipients.
According to Art. 21 GDPR, users and data subjects also have the right to object to the future processing of the data concerning them, provided that the data is provided by the provider in accordance with Art. 6 Para. 1 lit. f) GDPR are processed. In particular, an objection to data processing for the purpose of direct advertising is permitted.
III. Information on data processing
Your data processed when using our website will be deleted or blocked as soon as the purpose of storage no longer applies, the deletion of the data does not conflict with any statutory retention requirements and no other information on individual processing methods is given below.
Server data
For technical reasons, in particular to ensure a secure and stable website, your internet browser transmits data to us or to our web space provider. These so-called server log files record the type and version of your internet browser, the operating system, the website from which you switched to our website (referrer URL), the website (s) of our website that you are visiting, the date and time of the respective access as well as the IP address of the internet connection from which our website is used.
This data collected in this way is temporarily stored, but not together with other data from you.
This storage takes place on the legal basis of Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality and security of our website.
The data will be deleted again after seven days at the latest, unless further storage is required for evidence purposes. Otherwise, the data will be excluded from deletion in whole or in part until an incident has been finally clarified.
Cookies
a) Session cookies / session cookies
We use so-called cookies on our website. Cookies are small text files or other storage technologies that are stored and stored on your device by the internet browser you use. These cookies process certain information about you on an individual basis, such as your browser or location data or your IP address.
This processing makes our website more user-friendly, more effective and more secure, as the processing enables, for example, the reproduction of our website in different languages or the offer of a shopping cart function.
The legal basis for this processing is Art. 6 Para. 1 lit b.) GDPR, provided that these cookies are used to process data to initiate or process contracts.
If the processing does not serve to initiate or process a contract, our legitimate interest lies in improving the functionality of our website. The legal basis is then Art. 6 Para. 1 lit. f) GDPR.
These session cookies are deleted when you close your Internet browser.
b) Third party cookies
Our website may also use cookies from partner companies with whom we work for the purpose of advertising, analysis or the functionalities of our website.
Please refer to the following information for details on this, in particular on the purposes and legal basis for processing such third-party cookies.
c) possibility of elimination
You can prevent or restrict the installation of cookies by setting your internet browser. You can also delete cookies that have already been saved at any time. The steps and measures required for this, however, depend on the specific Internet browser you are using. If you have any questions, please use the help function or documentation of your Internet browser or contact its manufacturer or support. In the case of so-called flash cookies, however, processing cannot be prevented via the browser settings. Instead you have to change the setting of your Flash player. The steps and measures required for this also depend on the specific Flash player you are using. If you have any questions, please use the help function or documentation of your Flash player or contact the manufacturer or user support.
However, should you prevent or restrict the installation of cookies, this may mean that not all functions of our website can be used to their full extent.
Contract processing
The data transmitted by you for the use of our range of goods and / or services will be processed by us for the purpose of processing the contract and are required in this respect. Contract conclusion and contract processing are not possible without providing your data.
The legal basis for the processing is Art. 6 Para. 1 lit. b) GDPR.
We delete the data when the contract has been fully processed, but must observe the retention periods under tax and commercial law.
As part of the contract processing, we pass on your data to the transport company commissioned with the delivery of goods or to the financial service provider, insofar as the transfer is necessary for the delivery of goods or for payment purposes.
The legal basis for forwarding the data is then Art. 6 Para. 1 lit. b) GDPR.
Customer account / registration function
If you create a customer account with us via our website, we will use the data you entered during registration (e.g. your name, address or e-mail address) exclusively for pre-contractual services, for the fulfillment of the contract or for the purpose of Customer care (e.g. to provide you with an overview of your previous orders with us or to be able to offer you the so-called memo function) collect and save. At the same time, we then save the IP address and the date of your registration, along with the time. This data will of course not be passed on to third parties.
As part of the further registration process, your consent to this processing is obtained and reference is made to this data protection declaration. The data collected by us will only be used to provide the customer account.
Insofar as you consent to this processing, Art. 6 Para. 1 lit. a) GDPR legal basis for processing.
If the opening of the customer account also serves pre-contractual measures or the fulfillment of the contract, the legal basis for this processing is also Art. 6 Para. 1 lit. b) GDPR.
The consent given to us to open and maintain the customer account can be revoked at any time with effect for the future in accordance with Art. 7 Para. 3 GDPR. All you have to do is inform us of your revocation.
The data collected in this respect will be deleted as soon as processing is no longer necessary. In doing so, we have to observe retention periods under tax and commercial law.
Newsletter
If you register for our free newsletter, the data you have requested for this purpose, i.e. your e-mail address and - optionally - your name and address, will be transmitted to us. At the same time, we save the IP address of the Internet connection from which you access our website, as well as the date and time of your registration. As part of the further registration process, we will obtain your consent to the sending of the newsletter, describe the content in detail and refer to this data protection declaration. We use the data collected in this way exclusively for sending the newsletter - in particular, they are therefore not passed on to third parties.
The legal basis for this is Art. 6 Para. 1 lit. a) GDPR.
You can revoke your consent to the sending of the newsletter at any time with effect for the future in accordance with Art. 7 Para. 3 GDPR. To do this, all you have to do is inform us of your revocation or use the unsubscribe link in each newsletter.
Contact inquiries / contact options
If you contact us via the contact form or email, the data you provide will be used to process your request. The specification of the data is necessary for processing and answering your request - without providing it, we cannot answer your request, or at least only partially.
The legal basis for this processing is Art. 6 Para. 1 lit. b) GDPR.
Your data will be deleted if your request has been finally answered and the deletion does not conflict with any statutory retention requirements, such as in the event of a subsequent contract processing.
To advertise our products and services and to communicate with interested parties or customers, we operate a company presence on the Instagram platform.
We are jointly responsible for this social media platform with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2 Ireland.
Instagram's data protection officer can be reached using a contact form:
https://www.facebook.com/help/contact/540977946302970
We have regulated the joint responsibility in an agreement with regard to the respective obligations within the meaning of the GDPR. This agreement, from which the mutual obligations arise, can be accessed under the following link:
https://www.facebook.com/legal/terms/page_controller_addendum
The legal basis for the processing of personal data that ensues and is reproduced below is Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in the analysis, communication, sales and promotion of our products and services.
The legal basis can also be the consent of the user in accordance with Art. 6 Para. 1 lit. a GDPR to the platform operator. According to Art. 7 Para. 3 GDPR, the user can revoke his consent to this at any time by notifying the platform operator for the future.
When you visit our online presence on the Instagram platform, Facebook Ireland Ltd. as the operator of the platform in the EU processes user data (e.g. personal information, IP address, etc.).
This user data is used for statistical information about the use of our company presence on Instagram. Facebook Ireland Ltd. uses this data for market research and advertising purposes and to create user profiles. Based on these profiles, Facebook Ireland Ltd. For example, it is possible to advertise users within and outside of Instagram based on their interests. If the user is logged into their Instagram account at the time of access, Facebook Ireland Ltd. also link the data with the respective user account.
If the user makes contact via Instagram, the personal data entered by the user on this occasion will be used to process the request. The user's data will be deleted by us, provided that the user's request has been finally answered and there are no legal retention requirements, such as in the subsequent contract processing.
To process the data, Facebook Ireland Ltd. possibly also set cookies.
If the user does not agree to this processing, it is possible to prevent the installation of cookies by setting the browser accordingly. Cookies that have already been saved can also be deleted at any time. The settings for this depend on the respective browser. In the case of Flash cookies, processing cannot be prevented via the settings of the browser, but through the corresponding setting of the Flash player. Should the user prevent or restrict the installation of cookies, this may mean that not all Facebook functions can be used to their full extent.
You can find more information about the processing activities, their prevention and the deletion of the data processed by Instagram in Instagram's data policy:
https://help.instagram.com/519522125107875
It cannot be ruled out that the processing by Facebook Ireland Ltd. also via Facebook Inc., 1601 Willow Road, Menlo Park, California 94025 in the USA.
Linking social media via graphic or text link
We also advertise presences on the social networks listed below on our website. The integration takes place via a linked graphic of the respective network. The use of this linked graphic prevents that when a website that has a social media application is called up, a connection is automatically established to the respective server of the social network in order to display a graphic of the respective network itself. The user is only forwarded to the service of the respective social network by clicking on the corresponding graphic.
After the user has been forwarded, information about the user is recorded by the respective network. It cannot be ruled out that the data collected in this way will be processed in the USA.
This is initially data such as IP address, date, time and the page visited. If the user is logged into their user account of the respective network during this time, the network operator can, if necessary, assign the information collected from the specific visit of the user to the user's personal account. If the user interacts via a “share” button on the respective network, this information can be saved in the user's personal user account and published if necessary. If the user wants to prevent the information collected from being directly assigned to his user account, he must log out before clicking on the graphic. It is also possible to configure the respective user account accordingly.
The following social networks are linked to our site:
Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.
Data protection declaration: https://help.instagram.com/519522125107875
Klarna "CHECK-OUT"
To process orders through our online shop, we use the payment service of Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden, hereinafter referred to as “Klarna”, on our website.
For this purpose, we have integrated the so-called Klarna check-out into the final order page of our online shop.
The legal basis is the fulfillment of the contract according to Art. 6 Para. 1 lit. b.) GDPR. In addition, we have a legitimate interest in offering effective and secure payment options, so that a further legal basis from Art. 6 Para. 1 lit. f.) GDPR follows.
By integrating Klarna, your internet browser loads the check-out page from a Klarna server. As a result, the operating system you are using, the type and version of your Internet browser, the website from which the check-out was requested, the date and time of the call and the IP address are transmitted to Klarna - even without you with interact with the check-out page.
As soon as you complete the order in our online shop, the data you entered in the input fields on the check-out page will be processed by Klarna on its own responsibility to process the payment.
With the offered payment methods “PayPal” and “Prepayment”, the processing without your further consent is limited to the transfer of the payment data to us or PayPal.
With the offered payment methods "purchase on account", "hire purchase", "credit card", "direct debit" or "instant transfer", the following personal data in particular are processed by Klarna for the purpose of payment processing as well as for identity and credit checks:
- Contact information, such as names, addresses, date of birth, gender, email address, telephone number, mobile phone number, IP address, etc.
- Information on processing the order, such as product type, product number, price, etc.
- Payment information, such as debit and credit card details (card number, expiry date and CCV code), billing details, account number, etc.
If you select the payment method "purchase on account" or "hire purchase", Klarna collects and uses personal data and information about your previous payment history to decide whether you will be granted the desired payment method. In addition, probability values are used for your future payment behavior (so-called scoring). The calculation of the scoring is carried out on the basis of scientifically recognized mathematical-statistical procedures.
Klarna puts under
https://cdn.klarna.com/1.0/shared/content/policy/data/de_de/data_protection.pdf
Further information on the processing described above as well as the applicable data protection regulations are available.
Sample data protection declaration from the law firm Weiß & Partner
Status: October 29, 2020
The German version is authoritative!