Privacy policy

 

General Information

The following information and hints give a simple overview of what happens to your data when you visit our website.
As the person responsible for these pages, we take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. This Privacy Policy explains what information we collect and what we use it for.
If you use our website, various personal data will be collected. Personal information is information that personally identifies you.
Personal data (hereinafter usually only “data”) are collected within the scope of the necessity to ensure a flawless, functional and user-friendly provision of the website and the services offered there. Other data can be used to analyze your user behavior.
Pursuant to Article 4 (1) of Regulation (EU) 2016/679, the Basic Data Protection Regulation (hereinafter referred to as the ‘GDPR’), ‘processing’ means any operation or series of operations carried out with or without the aid of automated procedures personal data, such as collecting, collecting, organizing, organizing, storing, adapting or modifying, reading, querying, using, disclosing through transmission, dissemination or any other means of providing, reconciling or the join, the restriction, the deletion or the annihilation.
In particular, the following privacy policy informs you of the nature, scope, purpose, duration and legal basis of the processing of personal data, insofar as we decide on the purposes and means of processing either alone or together with others. In addition, we will inform you about the third-party components used by us for optimization purposes and to increase the quality of use, insofar as third parties process data in their own responsibility.

Contradiction against advertising mails

The use of published in the context of the imprint obligation contact information for sending unsolicited advertising and information materials is hereby prohibited. The operators of these pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.

Media

If you have registered on our pages and upload photos in the comments, you should avoid uploading photos with an EXIFF GPS location. Visitors to this website could download photos stored on this website and extract their location information.

Our privacy policy is structured as follows:

 

1. Information about us as responsible
2. Rights of users and stakeholders

a. Right to information
b. Correction, completion and blocking
c. Deletion and restriction
d. Data portability
e. Right of appeal to the competent supervisory authority
f. Revocation of your consent to data storage
g. SSL or TLS encryption
h. Encrypted payments on this website

3. Information about data processing

a. what data we collect and why

1.  Sending information about your account and order
2.  Response to your inquiries, including refunds and complaints
3.  Processing of payment transactions and prevention of fraud
4.  Set up your account for our shop
5.  Compliance with all legal obligations, such as the tax calculation
6.  Improvement of our shop offers
7.  Sending marketing messages, if permitted

b. Serverdata
c. Cookies

1.    Session cookies
2.    Third party cookies
3.    disposal option

d. Customer account / registration function
e. Contact requests / contact possibilities

3.1. Data that we share with third parties

a. contract management
b. Payment provider / Paypal
c. User contributions, comments and ratings
d. Google Analytics
e. “Facebook” and “Instagram”-Social plug-in
f. Woocommerce Services and Tools

 

1.       Information about us as responsible

The address of our website is:
URL: http://garego.de
The responsible provider of this website in terms of data protection is:
garego Artprints
represented by:
Gabriela Goronzy
Mathildenstr. 8
20357 Hamburg
Germany
Telefon: +49 040 439 14 16
E-Mail: info@gargo.de

2.       Rights of users and stakeholders

With regard to the data processing described in more detail below, you have the following rights to your personal data, which we process automatically on the basis of your consent or in fulfillment of a contract:

a. Right to information

At any time you have the right to obtain free information about the origin, recipient and purpose of your stored personal data. As a user and data subject, you have the right to confirm whether the data in question is being processed, information about the processed data, further information about data processing and copies of the data (see also Art. 15 GDPR);

b. Correction, completion and blocking

You have the right to correct or complete incorrect or incomplete data. You also have a right to request the correction, blocking or deletion of this data. You can contact the above address at any time. (see also Art. 16 GDPR)

c. Deletion and restriction

You have the right to immediate deletion of the data concerning them (see also Art. 17 GDPR) or, alternatively, to the extent that further processing under Art. 17 (3) GDPR is required, to limit processing in accordance with Art 18 GDPR;

d. Data portability

You have the right to receive the data relating to and related to you and to transmit such data to other providers / controllers., To have them delivered to themselves or to a third party in a standard, machine-readable format to transfer the data to another person in charge, this will only be done as far as technically feasible. Notwithstanding, the user has a right to information about these recipients. (see also Art. 20 GDPR);

e. Right of appeal

to the competent supervisory authorityYou have a right to complain to the Regulatory Authority if you believe your data is being processed by the Provider in violation of data protection laws The competent supervisory authority in matters of data protection law is the state data protection officer of the federal state in which our company is based. (see also Art. 77 GDPR).A list of the data protection officers as well as their contact data can be taken from the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.

f. Revocation of your consent to data storage

 Many data processing operations are only possible with your express consent. You can revoke an already given consent at any time. An informal message by e-mail to us is sufficient. The legality of the data processing carried out until the revocation remains unaffected by the revocation. In particular, an objection to data processing for the purpose of direct advertising is permitted. Likewise, according to Art. 21 GDPR, users and data subjects have the right to object to the future processing of data relating to them, provided that the data are submitted by the provider in accordance with Art. 6 para. 1 lit. f) GDPR be processed.

g. SSL or TLS encryption

This site uses, for security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as a site operator, an SSL or. TLS encryption. An encrypted connection is indicated by the browser’s address bar changing from “http: //” to “https: //” and the lock icon in your browser bar. If SSL or TLS encryption is enabled, the data you submit to us can not be read by third parties.

h. Encrypted payments

on this websiteIf, after the conclusion of a fee-based contract, there is an obligation to provide us with your payment details (eg account number for direct debit authorization), this data will be required for payment processing.Payment transactions via the common means of payment (Visa / MasterCard, direct debit) are made exclusively via an encrypted SSL or TLS connection. An encrypted connection is indicated by the browser’s address bar changing from “http: //” to “https: //” and the lock icon in your browser bar. In the case of encrypted communication, your payment details that you send to us can not be read by third parties.

In addition, the provider is obliged to disclose any data subject to disclosure by the provider, any rectification or deletion of data or restriction of processing under Articles 16, 17 (1), 18 GDPR teaching. However, this obligation does not exist insofar as this notification is impossible or disproportionate.

3.      Information about data processing

Your data will be collected on the one hand, that you tell us. This may be e.g. to trade data that you enter in a contact form. Other data is collected automatically when visiting the website through our IT systems. These are above all technical data (for example Internet browser, operating system or time of the page call). The collection of this information is automatic as soon as you enter our website.We usually store information about you as long as we need it for the purpose of collection and use and are required to store it. For example, we store order information for 10 years for tax and billing reasons. This includes the invoice number, your name, your e-mail address and billing and shipping address.Your data processed on the use of our website will be deleted or blocked as soon as the purpose of the storage is omitted, the deletion of the data does not conflict with statutory storage requirements and subsequently no other information is provided on individual processing methods.

a. What data do we collect and why?

When you shop with us, we will ask you to provide information such as your name, billing and shipping address, e-mail address and phone number, payment details, and optional account information such as username and password. We use this information for the following purposes:

1. Sending information about your account and order
2. Response to your inquiries, including refunds and complaints
3. Processing of payment transactions and prevention of fraud
4. Set up your account for our shop
5. Compliance with all legal obligations, such as the tax calculation
6. Improvement of our shop offers
7. Sending marketing messages, if permitted

Members of our team have access to the information you provide to us. For example, both administrators and shop managers can access:

1. Ordering information such as purchased products, the time of purchase and the shipping address and
2. Customer information such as your name, e-mail address, as well as billing and shipping information.

Our team members have access to this information to process orders, refund, and assist you.We also collect comments or ratings if you decide to leave them.

b. Serverdata

For technical reasons, in particular to ensure a secure and stable website, data is transmitted through your Internet browser to us or to our web space provider. With these so-called server log files i.e. Type and version of your Internet browser, the operating system, the website from which you have changed to our website (referrer URL), the website (s) of our website you are visiting, the date and time of access and the IP address of the Internet connection, from which the use of our Internet presence occurs.These data collected will be temporarily stored but will not be shared with other data by you.This storage takes place on the legal basis of Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality and security of our website.The data will be deleted at the latest after seven days, as long as no further storage for evidence is required. Otherwise, all or part of the data will be exempted from the cancellation until final clarification of an incident.

c. Cookies

 

1. Session cookies
We use so-called cookies with our website. Cookies are small text files or other storage technologies that are stored and stored on your device by the Internet browser you use. These cookies process certain information about you, such as your browser or location data or your IP address, to an individual extent.This processing makes our website more user-friendly, effective and secure, as the processing, for example, allows us to reproduce our website in different languages ​​or to offer a shopping cart function. The legal basis for this processing is Article 6 (1) (b) of the GDPR, insofar as these cookies are used to process the contract or to process the contract.If the processing does not serve to initiate the contract or to fulfill the contract, our legitimate interest lies in improving the functionality of our website. Legal basis is then in Art. 6 para. 1 lit. f) GDPR.Closing your internet browser deletes these session cookies.

2. Third party cookies
If necessary, our website also uses cookies from partner companies with whom we cooperate for the purpose of advertising, analyzing or functionalizing our website.For details, in particular for the purposes and legal bases of processing such third-party cookies, please refer to the information below.

3. disposal option
You can prevent or limit the installation of cookies by setting your Internet browser. You can also delete previously saved cookies at any time. However, the necessary steps and measures depend on your specific Internet browser. If you have questions, please use the help function or documentation of your Internet browser or contact its manufacturer or support. With so-called Flash cookies, however, the processing cannot be prevented by the settings of the browser. Instead, you need to change the setting of your Flash Player. The necessary steps and measures depend on your specific Flash player. If you have any questions, please also use the help function or documentation of your Flash Player or contact the manufacturer or user support. Should you prevent or restrict the installation of the cookies, however, this may result in not all functions of our website being fully usable.

d. Customer account / registration function

If you create a customer account with us via our website, we will use the data entered by you during registration (eg your name, address or e-mail address) exclusively for pre-contractual services, for the fulfillment of the contract or for the purpose of Customer care (eg to give you an overview of your previous orders to provide us) and save. At the same time, we then save the IP address and the date of your registration along with the time. This data is not passed on to third parties.As part of the further registration process, your consent to this processing is obtained and reference is made to this privacy policy. The data collected by us are used exclusively for the provision of the customer account.Insofar as you consent to this processing, Art. 6 para. 1 lit. a) GDPR Legal basis for processing. Insofar as the opening of the customer account additionally serves pre-contractual measures or the fulfillment of the contract, the legal basis for this processing is also Art. 6 para. 1 lit. b) GDPR.The consent given to us in the opening and maintenance of the customer account can be withdrawn at any time with effect for the future, in accordance with Art. 7 para. 3 GDPR. For this you only have to inform us about your withdrawal.The data collected will be deleted as soon as the processing is no longer necessary. However, we must observe tax and commercial retention periods. (Order data 10 years, statistics 1 year, contact details, 6 months)

e. Contact requests / contact possibilities

If you contact us via contact form or e-mail, the data provided by you will be used to process your request. The specification of the data is necessary for processing and answering your inquiry – without their provision we can not answer your inquiry or at best only to a limited extent.The legal basis for this processing is Article 6 (1) lit. b) GDPR.Your data will be deleted, provided that your request has been finally answered and deletion does not conflict with any statutory storage requirements, such as in the event of subsequent contract execution.We use a recaptcha function to determine if a human or a computer makes a specific entry in our contact form. The legal basis for the described data processing is Art. 6 para. 1 lit. f GDPR. There is a legitimate interest on our part in this data processing to ensure the security of our website and to protect us from automated input (attacks).

 

3.1.   Data that we share with third parties

 

a. contract management

The data transmitted by you for the use of our goods and / or service offer are processed by us for the purpose of contract execution and are required to that extent. Conclusion of contract and contract are not possible without provision of your data.
Featured Products: Here are some products you have recently viewed.
Location, IP address and browser type: We use this for purposes such as estimating taxes and shipping costs
Shipping address: We will ask you to indicate this, for example to be able to determine the shipping costs before you place your order, and to be able to send you the order.The legal basis for processing is Art. 6 para. 1 lit. b) GDPR.
We delete the data with complete contract processing, but must observe the tax and commercial retention periods.
As part of the contract, we pass on your data to the printing company commissioned with the print job, as well as to the transport company commissioned to deliver the goods or to the financial service provider, insofar as the transfer is required for the delivery of goods or for payment purposes.The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) GDPR.

b. payment provider

PayPal
On our website we offer u.a. Payment via PayPal. Provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).If you choose to pay via PayPal, the payment details you enter will be sent to PayPal. The transmission of your data to PayPal is based on Art. 6 para. 1 lit. a DSGVO (consent) and Art. 6 para. 1 lit. b DSGVO (processing to fulfill a contract). You have the opportunity to revoke your consent to data processing at any time. A revocation does not affect the effectiveness of historical data processing operations. https://www.paypal.com/us/webapps/mpp/ua/privacy-full  The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) GDPR.

c. User contributions, comments and ratings

We offer you to post questions, answers, opinions or ratings on our websites, hereinafter referred to as “posts.” If you make use of this offer, we will process and publish your contribution, the date and time of submission and the pseudonym you may use.
When visitors write comments on the site, we collect the data displayed in the comment form, as well as the visitor’s IP address and the user-agent string (which identifies the browser) to help detect spam .The legal basis here is Art. 6 para. 1 lit. a) GDPR.
The consent can be withdrawn at any time with effect for the future in accordance with Art. 7 para. 3 GDPR. For this you only have to inform us about your withdrawal.
In addition, we also process your IP and e-mail address. The IP address is processed because we have a legitimate interest in initiating or supporting further action, provided that your contribution interferes with third party rights and / or otherwise is unlawful. The legal basis in this case is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the necessary legal defense.
From your email address, you can create an anonymous string (called a hash) and submit it to the Gravatar service to see if you’re using it. The privacy policy of the Gravatar service can be found here:  https://automattic.com/privacy/ Once your comment is shared, your profile picture will be publicly visible in the context of your comment.
Trusted Shops
Our shop is certified by Trusted Shops, we have committed ourselves to the merchant code of Trusted Shops.
Trusted Shops collects data such as names and ratings for the purchased products. The evaluation is voluntary and possible with their consent. We offer you the valuation service of Trusted Shops. Here you can make reviews of our products. Trusted Shops GmbH, Colonius Carré, Subbelrather Strasse 15c, 50823 Cologne, Telephone: +49 0221 – 77 53 66, Fax: +49 0221 – 77 53 6 89, E-Mail: info@trustedshops.de, Trusted Shops Imprint and Privacy Policy: https://www.trustedshops.de/impressum/ The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) GDPR.

d. Google Analytics

In our website we use Google Analytics. This is a web analytics service provided by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043 USA, and hereafter referred to as “Google.
“Certified under the EU-US Privacy Shield https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active guarantees that Google complies with EU data protection standards when processing data in the United States.
The service Google Analytics is used to analyze the usage behavior of our website. Legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis, optimization and economic operation of our website.
User and user-related information, such as IP address, location, time or frequency of visiting our website, are transmitted to a Google server in the USA and stored there. However, we use Google Analytics with the so-called anonymization function. With this feature, Google already truncates the IP address within the EU / EEA.
The data collected in this way will again be used by Google to provide us with an evaluation of the visit to our website as well as about the usage activities there. Also, this data may be used to provide other services related to the use of our website and the use of the Internet.
Google states that you do not associate your IP address with any other data. In addition, Google keeps under https://www.google.com/intl/de/policies/privacy/partners
Further data protection information is ready for you, including, for example, the possibilities to prevent the use of data.In addition, Google offers below https://tools.google.com/dlpage/gaoptout?hl
a so-called deactivation add-on together with further information on this. This add-on can be installed with the popular Internet browsers and offers you further control over the data that Google collects when you visit our website.
The add-on informs the JavaScript (ga.js) of Google Analytics that information for visiting our website should not be transmitted to Google Analytics. This does not prevent information from being passed to us or other web analytics services. Of course, you will also find out in this privacy policy whether and which other web analysis services we use.

e. „Facebook“and “Instagram”-Social-Plug-in

In our website we use the plug-in of the social network Facebook and Instagram. Facebook and Instagram is an internet service of facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. In the EU, this service is again operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, hereinafter referred to as “Facebook”.
Certified under the EU-US Privacy Shield
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
guarantees Facebook that EU data protection standards will be respected even when processing data in the US.
Legal basis is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest lies in the quality improvement of our website.
Further information about the possible plug-ins and their respective functions Facebook holds https://developers.facebook.com/docs/plugins/ ready for you.
If the plug-in is stored on one of the pages you visit on our website, your Internet browser downloads a display of the plug-in from the Facebook servers in the USA. For technical reasons, it is necessary that Facebook processes your IP address. In addition, however, the date and time of the visit to our website are recorded.
If you are logged in to Facebook while visiting one of our plug-ins, the information collected by the plug-in will be recognized by Facebook. The information collected in this way may be assigned to your personal user account by Facebook. For example, if you use the so-called “Like” button from Facebook, this information will be stored in your Facebook user account and, if applicable, published via the Facebook platform. If you want to prevent this, you must either log out of Facebook before visiting our website or prevent the loading of the Facebook plug-in by using an add-on for your Internet browser.Further information about the collection and use of data as well as your related rights and protections Facebook holds in the under https://www.facebook.com/policy.php available privacy notices.

f.     Woocommerce Services und Tools

This website works with the content management system of WordPress and other tools like Woocommerce, Akismet. Data used: For payments with PayPal:Purchase price, currency, billing information. For taxes: value of goods in shopping cart, shipping value, destination address. For cash prizes: destination address, purchased product IDs, dimensions, weight, and quantities. For shipping labels: name of the customer, address and dimensions, weight and quantities of purchased products.Data Synced (?):payment provider: Woocommerce-gateaway-espress-checkaout
https://docs.woocommerce.com/document/privacy-payments/#woocommerce-gateway-paypal-express-checkout
For payments, we will send the customer’s purchase price, currency and payment information to the respective payment service provider. For more information, see the privacy policy of each third party (see Privacy Policy 3b: PayPal Privacy Policy).

Akismet
We collect information about visitors who leave comments on websites using our Akismet Anti-Spam Service. The amount of information we collect depends on how the user has posted their site. Typically, this data includes the user’s IP address, user agent, referrer, and website URL (as well as the information that the user entered directly, such as name, username, email address, and the comment itself).
Automattic Inc., 60 29th Street #343, San Francisco, CA 94110.
If you are outside the designated countries (for services other than those offered on WooCommerce.com): Aut O’Mattic A8C Ireland Ltd., Business Centre, No.1 Lower Mayor Street, International Financial Services Centre, Dublin 1, Ireland
Automattic Inc. is also the controller for some of the processing activities related to Services provided by Aut O’Mattic A8C Ireland Ltd.
https://automattic.com/privacy/ .The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) GDPR.

Newsletter / Clever Reach
If you subscribe to our free newsletter, the data requested by you, ie your e-mail address and – optionally – your name and address will be sent to us. At the same time, we store the IP address of the Internet access from which you access our website as well as the date and time of your registration. As part of the further registration process we will to obtain your consent to the sending of the newsletter, to describe the content concretely and to refer to this privacy policy. We use the data collected exclusively for the newsletter dispatch – they are therefore not passed on to third parties in particular.The consent to the newsletter dispatch can be withdrawn at any time with effect for the future in accordance with Art. 7 para. 3 GDPR. For this you only need to inform us about your withdrawal or press the unsubscribe link contained in each newsletter. CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany,Tel .: +49 (0) 4402 97390-00, Fax: +49 (0) 4402 97390-99, E-Mail: info@cleverreach.com* Clever Reach https://www.cleverreach.com/en/privacy/. The legal basis here is Art. 6 (1) lit. a) GDPR.

Woocommerce Multilingual
In order to offer our customers and users the service of multilingualism, we use the plugin WordPress Multilingual. WPML is a plugin for WordPress / Woocommerce. Simply put, plugins extend the functionality of the basic WordPress CMS. In our case, WPML WordPress runs multilingual. WordPress Multilingual and Icanlocalize are products of OnTheGoSystems Limited, 22 / F3 Lockhart Road, Wanchai Hong Kong, https://www.onthegosystems.com: Privacy Policy: https://www.onthegosystems.com/legal/privacy-policy-and-gdpr-compliance/
WooCommerce Multilingual uses cookies to understand the basket information, when using languages ​​in domains, and to handle data between domainsto transfer the domains.WooCommerce Multilingual also uses cookies to determine the language and currency of each customer’s order, as well as the currency of reports produced by WooCommerce. WooCommerce Multilingual adds currency information to these reports. The legal basis here is Art. 6 (1) lit. a) GDPR.
WPML Translation Management
WPML Translation Management will send the e-mail address and name of each manager and associated translator and the content itself to the extended translation editor and translation services deployed. The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) GDPR.
WPML String Translation
WPML String Translation will send all strings to WPML’s extended Translation Editor and to the translation services used. The legal basis for the transfer of the data is then Art. 6 para. 1 lit. b) GDPR.

Sample privacy policy of the law firm Weiß & Partner and Woocommerce