Data Protection Provisions

Overview

 

 

Types of Data

For Billing:
Name, Address, Email

Customer Account:
Email
For Account Use:
In-App (Security & Technical N.):
–IP Address

–Date and Time of Request

–Timezone Difference to Greenwich Mean Time (GMT)

–Content of the Request (specific page)

–Access Status/HTTP Status Code

–Data Volume Transmitted

–Website from which the request originates

–Browser

–Operating System and its Interface

- Language and Version of the Browser Software

 

Data Sharing

Payment Service Providers (PayPal, Heidelpay)

Newsletter (Cleverreach)

 

Cloud Usage

none

 

Tracking

Google Analytics

Hotjar

 

Advertising

only within the legal framework for similar products via email

 

§ 1 Information on the Collection of Personal Data and Provider Identification

  1. Below we inform you about the collection of personal data when using this website. Personal data is any data that can be related to you personally, such as name, address, email addresses, user behavior.
  2. The responsible party according to Art. 4 (7) EU General Data Protection Regulation (GDPR) is REPROGRAFIE EICHLER GmbH, Mohrenstraße 11-17, D-50670 Cologne, support@repro-online.de (see our imprint). Our data protection officer is Mr. Andreas Pinheiro LL.M., a.pinheiro@ap-datenschutz.de
  3. If we rely on contracted service providers for individual functions of our offer or wish to use your data for advertising purposes, we will inform you in detail about the respective processes below. We will also specify the established criteria for the storage duration.

§ 2 Rights, Especially the Right to Information and Revocation

  1. You have the following rights regarding your personal data:
    – Right to information,
    – Right to correction or deletion,
    – Right to restriction of processing,
    – Right to object to processing,
    – Right to data portability.
  2. If you have given consent to the use of data, you can revoke this at any time. If the legality of the processing is based on consent, it remains valid until the exercise of the revocation.
  3. Please direct all requests for information, inquiries, or objections to data processing by email to Support@repro-online.de or to the address mentioned in § 1 (2).
  4. You can request us to delete your data at any time. There may be statutory retention periods that allow us to retain your data until the expiration of the period.
  5. If your data should be incorrect, you have the right to request us to correct it. We will comply with this request without delay.
  6. You have the right to receive your personal data provided to us in a readable format, as far as technically possible, in order to provide it to another company (right to data portability).
  7. You have the right to lodge a complaint with the supervisory authority responsible for you.

§ 3 Data Security

  1. We maintain current technical measures to ensure data security, especially to protect your personal data from risks during data transmission and from third-party access. These will be adjusted according to the current state of technology.

§ 4 Collection of Personal Data during Informational Use

  1. When using the website purely for informational purposes, that is, if you do not register, sign up, or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data that is technically necessary for us to display our website and ensure stability and security (the legal basis is Art. 6 (1) S. 1 lit. f GDPR):
    – IP address
    – Date and time of the request
    – Time zone difference to Greenwich Mean Time (GMT)
    – Content of the request (specific page)
    – Access status/HTTP status code
    – Amount of data transmitted
    – Website from which the request comes
    – Browser
    – Operating system and its interface
    – Language and version of the browser software
  2. When you contact us by email or through the contact form, your email address, your name, and, if you provide it, your telephone number will be stored by us. The purpose of this storage is solely to contact you to answer your questions.
  3. The legal basis for the specified collection is the consent you expressed by visiting our website and confirming the cookie banner (Art. 6 (1) lit. a GDPR).
  4. We will only use your data within the legally permitted scope for advertising purposes. In particular, we will use your email address solely for direct advertising for our own similar goods or services. You can object to the use of your data for advertising purposes at any time in writing or in text form (email to support@repro-online.de). In this regard, we rely on our legitimate interest in promoting our products to our customers according to Art. 6 (1) lit. f GDPR.
  5. In addition to the data mentioned above, cookies will be stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive assigned to the browser you are using and through which specific information flows to the party that sets the cookie (in this case, us). Cookies cannot execute programs or transfer viruses to your computer. They serve to make the internet offering overall more user-friendly and effective.

§ 5 Cookies

  1. We use cookies on our website. Such cookies are necessary for you to navigate freely on the website and use its features; this includes access to secured areas of the website. Through cookies, we can track who has visited the page(s) and infer how often certain pages are visited and which parts of the site are particularly popular. Session cookies store information about your activities on our website.
  2. This website uses the following types of cookies, the scope and functionality of which are explained below:
    – Transient cookies (temporary use)
    – Persistent cookies (limited-time use)
    – Third-party cookies
  3. Transient cookies are automatically deleted when you close the browser. This includes session cookies, which store a so-called session ID, allowing various requests from your browser to be assigned to the same session. This enables your computer to be recognized when you return to the website. Session cookies are deleted when you log out or close the browser.
  4. Persistent cookies are automatically deleted after a predetermined period, which may vary depending on the cookie. You can delete cookies at any time in your browser's security settings.
  5. You can configure your browser settings according to your preferences, for example, to refuse the acceptance of third-party cookies or all cookies. Please note that you may not be able to use all features of this website.
  6. We use cookies to identify you for subsequent visits if you have an account with us. Otherwise, you would need to log in again for each visit.
  7. The following cookies are used:

Name

Persistence

Description

_ga

SESSION

Cookie for using Google Analytics

_gid

1 day

Cookie for using Google Analytics

hj*

1 day

Cookie for using Hotjar

PHPSESSID

3 days

Your session ID on the server.

lang

1 day

The store view or language you have selected.

form_key

3 days

Stores a randomly generated key used to prevent forged requests.

mage-cache-sessid

1 day

Facilitates caching of content on the browser to make pages load faster.

mage-cache-storage

1 day

Facilitates caching of content on the browser to make pages load faster.

mage-cache-storage-section-invalidation

1 day

Facilitates caching of content on the browser to make pages load faster.

mage-messages

1 day

Cookie for using the webpage

mage-translation-file-version

SESSION

Facilitates translation of content to other languages.

mage-translation-storage

SESSION

Facilitates translation of content to other languages.

product_data_storage

3 days

Data about the products in the shopping cart.

recently_compared_product

1 day

Data about the selected or compared products.

recently_compared_product_previous

1 day

Data about the selected or compared products.

recently_viewed_product

1 day

Data about the selected or compared products.

recently_viewed_product_previous

1 day

Data about the selected or compared products.

section_data_ids

1 day

Facilitates caching of content on the browser to make pages load faster.

private_content_version

1 year

Adds a random unique number and timestamp to pages with customer content to prevent them from being cached on the server.

_gcl_au

1 month

Used by Google AdSense to experiment with the advertising efficiency on websites that use their services.

_ga_#

1 month

Used by Google Analytics to collect data on how often a user has visited the website, as well as the date of their first and last visit.

collect

SESSION

Used to send data about the device and visitor behavior to Google Analytics. Tracks the visitor across devices and marketing channels.

_uetsid

1 day

Used to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.

_uetvid

25 days

Used to track visitors across multiple websites to present relevant advertising based on the visitor's preferences.

MUID

25 days

Commonly used by Microsoft as a unique user ID. This cookie enables user tracking by syncing the ID across many Microsoft domains.

MSPTC

25 days

This cookie registers data about the visitor. The information is used to optimize advertising relevance.

pagead/landing

Collects data about visitor behavior across multiple websites to present more relevant advertising. This also allows the website to limit how often the same ad is shown to them.

uetsid_exp

Contains the expiration date of the cookie with the corresponding name.

_uetvid_exp

Contains the expiration date of the cookie with the corresponding name.

mage-cache-timeout

This cookie is necessary for the cache function. The website uses a cache to optimize the response time between the visitor and the website. The cache is usually stored in the visitor's browser.

s_sq

SESSION

The purpose of this cookie is to enable persistent ID tracking in first-party status and is used as a reference ID when the AMCV cookie expires.

s_fid

1 day

This cookie is used to identify a unique visitor when the standard s_vi cookie is unavailable due to third-party cookie restrictions.

s_cc

SESSION

Just one cookie for all accounts

amcookie_policy_restriction

10 days

Stores the status of cookies

CookieConsent

Stores the status of cookies


§ 6 Data Sharing for Website Maintenance

  1. We will not share your personal data with third parties unless we inform you about such sharing in this section.
  2. Our IT service providers have access to our stored data to fix errors and enable us to implement the required technical and organizational measures. We rely on our legitimate interest in securing our IT according to Art. 6 (1) lit. f GDPR or on fulfilling legal obligations according to Art. 6 (1) lit. c GDPR.
  3. To provide the newsletter service, we pass your data to CleverReach GmbH & Co. KG (https://www.cleverreach.de/). This service allows us to organize the sending and management of newsletters, as well as the visual design. There is no further sharing of your data by CleverReach GmbH & Co. KG.
  4. The IT service providers have been carefully selected and commissioned by us in writing. They are bound to our instructions and are regularly monitored by us. The service providers will not share this data with third parties.
  5. There will be no transfer of your data outside the EU (EEA) area.

§ 7 Use of Our Webshop

  1. If you wish to order in our webshop, it is necessary to provide your personal data required for processing your order. Mandatory information necessary for the fulfillment of contracts is separately marked; additional information is voluntary. We process the data you provide to fulfill your order. For this purpose, we may pass your payment data to our house bank. The legal basis for this is Art. 6 (1) S. 1 lit. b GDPR.
  2. You can voluntarily create a customer account, through which we can store your data for future purchases. When creating an account under "My Account," the data you provide will be stored revocably. You can always delete all further data, including your user account, in the customer area.
  3. We may also process the data you provide to inform you about other interesting products from our portfolio or to send you emails with technical information.
  4. Due to commercial and tax law requirements, we are obliged to store your address, payment, and order data for ten years. However, after two years, we will restrict processing, meaning your data will only be used to comply with legal obligations.
  5. If you choose the payment method "prepayment," we will store your IBAN and BIC for processing the payment and according to the legal retention periods (e.g., § 147 Abs. 1 AO – 10 years). The legal basis for this collection is Art. 6 (1) lit. b GDPR (fulfillment of a contract) and lit. c (storage due to a legal obligation).
  6. We use the data you provide for processing your order. For this purpose, we will pass your address data to a contracted shipping company. We will delete this data after processing the contract and the expiration of tax and commercial retention obligations. The legal basis for this collection is your consent, which you expressed by creating the customer account or by placing the order (Art. 6 (1) lit. a GDPR).
  7. The payment processing occurs through the options "Instant Transfer" and "Credit Card" via the service provider Heidelberger Payment GmbH. This entity is responsible within the meaning of the BDSG and is a service provider within the meaning of the TMG. Please refer to the privacy policy of Heidelberger Payment GmbH at https://www.heidelpay.de/unternehmen/impressum/datenschutz/.
  8. If you choose the payment method "PayPal," the payment is processed by PayPal (Europe) S.à r.l. et Cie, S.C.A. PayPal is responsible for processing the payment in terms of the BDSG as a telemedia service provider. Please refer to the privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE.
  9. To prevent unauthorized access by third parties to your personal data, especially financial data, the order process is encrypted using SSL technology.

§ 8 Newsletter

  1. With your consent, you can subscribe to our newsletter, which informs you about our current interesting offers. The advertised goods and services are specified in the consent declaration. When registering for the user account, you can choose to subscribe to the Repro Eichler newsletter. To do this, you must check the box before "Register for Newsletter."
  2. For the registration of our newsletter, we use the so-called double opt-in procedure. This means that after your registration, we send you an email to the provided email address, asking you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your information will be blocked and automatically deleted after one month. Additionally, we store your used IP addresses and the timestamps of your registration and confirmation. The purpose of this procedure is to prove your registration and clarify any potential misuse of your personal data.
  3. The only mandatory information for sending the newsletter is your email address. The provision of further separately marked data is voluntary and is used to address you personally. After your confirmation, we will store your email address for the purpose of sending the newsletter. The legal basis is Art. 6 (1) S. 1 lit. a GDPR.
  4. You can revoke your consent to the sending of the newsletter at any time and unsubscribe from the newsletter. You can revoke by clicking on the link provided in each newsletter email, through this form on the website, by email to info@repro-eichler.de, or by a message to the contact details specified in the imprint.
  5. We would like to point out that we evaluate your user behavior when sending the newsletter. For this evaluation, the sent emails include so-called web beacons, also known as tracking pixels. These are one-pixel image files that link to our website and allow us to evaluate your user behavior. This is done by collecting the data mentioned in § 4 as well as web beacons that are associated with your email address and linked to a unique ID. The data is collected solely in a pseudonymized manner, meaning that the IDs are not linked to your other personal data, thus excluding direct personal reference. The information collected in this way is stored by the newsletter provider CleverReach on its server in Germany. Such tracking is also not possible if you have disabled the display of images by default in your email program. In this case, however, the newsletter may not be displayed in full, and you may not be able to use all functions. If you manually display the images, the tracking mentioned above occurs.
  6. If you have subscribed to our newsletter, you can revoke your consent to the sending of the newsletter at any time. You can revoke by email to support@repro-online.de or by a message to the contact details specified in the imprint. Your provided data will not be shared with third parties.
  7. You can also turn the newsletter subscription on or off at any time through the function in your user account.

§ 9 Web Tracking - Google Analytics

  1. This website uses Google Analytics, a web analytics service from Google Inc. ("Google"), if you have given consent. Google Analytics uses so-called "cookies," text files that are stored on your computer and enable analysis of your use of the website. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the USA and stored there. If IP anonymization is activated on this website, your IP address will be truncated by Google within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities, and to provide further services related to website usage and internet usage to the website operator.
  2. The IP address transmitted by your browser within the framework of Google Analytics will not be merged with other Google data.
  3. You can prevent the storage of cookies by adjusting your browser software accordingly; however, we would like to point out that in this case, you may not be able to use all the features of this website to their full extent. You can additionally prevent the collection of the data generated by the cookie related to your use of the website (including your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en.
  4. This website uses Google Analytics with the "_anonymizeIp()" extension. This means that IP addresses are further processed in a truncated form, which excludes any personal reference. If a personal reference is established for the data collected about you, it will be immediately excluded and the personal data will be promptly deleted.
  5. We use Google Analytics to analyze and regularly improve the use of our website. Through the statistics obtained, we can improve our offer and make it more interesting for you as a user. In exceptional cases where personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is your consent, namely Art. 6 (1) S. 1 lit. a GDPR.
  6. Information from the third party: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. User conditions: http://www.google.com/analytics/terms/en.html, Overview of data protection: http://www.google.com/intl/en/analytics/learn/privacy.html, and the privacy policy: http://www.google.com/intl/en/policies/privacy.
  7. This website also uses Google Analytics for cross-device analysis of visitor flows, which is carried out via a user ID. You can deactivate the cross-device analysis of your usage in your customer account under "My Data," "Personal Data."

§ 10 Hotjar Analytics Tool

  1. We use the web analytics service Hotjar from Hotjar Ltd, Level 2, St Julians Business Centre, 3 Elia Zammit Street, St Julians STJ 1000, Malta, Europe, +1 (855) 464-6788 on our websites.
  2. This tool captures movements on the observed websites in so-called heatmaps. This allows us to anonymously see where visitors click and how far they scroll. As a result, we can improve our website to be better and more user-friendly.
  3. The protection of your personal data is very important to us when using this tool. All data is collected without us being able to assign it to specific users. We can only track how the mouse is moved, where clicks occur, and how far scrolling has taken place. Additionally, information about the screen size of the device, the device type, browser information, the country from which access occurred, and the preferred language are collected. If personal data about you or third parties is displayed on a webpage, this will be automatically hidden by Hotjar. Therefore, it is not traceable to us.
  4. By using a “Do Not Track header,” you can prevent the use of the Hotjar tool. In this case, no data will be collected about your visit to our website. You must adjust your browser accordingly. You can find instructions in German at http://www.akademie.de/wissen/do-not-track-datenschutz. You can also deactivate the Hotjar tool using the opt-out switch at https://www.hotjar.com/opt-out.
  5. For more information about Hotjar Ltd. and the Hotjar tool, visit https://www.hotjar.com. The privacy policy of Hotjar Ltd. can be found at https://www.hotjar.com/privacy.
  6. With regard to the use of Hotjar, we rely on our legitimate interest in optimizing and improving the presentation of websites. Since Hotjar does not transmit personal data but tracks anonymously, this interest based on our entrepreneurial freedom (Art. 15 GrCh) outweighs according to Art. 6 (1) lit. f GDPR.
  7. Since we also store cookies for the use of the service, we need your consent for this (ECJ ruling of 1.10.2019 – Planet 49). We obtain this before storing the cookies (see § 5). We store these based on Art. 6 (1) lit. a GDPR.

§ 11 Use of Google AdSense

  1. This website uses the online advertising service Google AdSense, which can present you with advertisements tailored to your interests. Our goal is to show you ads that may be of interest to you, making our website more interesting for you. To achieve this, statistical information about you is collected, which is processed by our advertising partners. These advertisements are recognizable by the label “Google Ads” in the respective ad.
  2. By visiting our website, Google receives the information that you have accessed our website. To do this, Google uses a web beacon to place a cookie on your computer. The data mentioned in § 2 of this declaration is transmitted. We have no influence on the data collected, nor do we know the full extent of the data collection and the storage duration. Your data will be transmitted to the USA and evaluated there. If you are logged into your Google account, your data can be directly assigned to it. If you do not wish for your data to be associated with your Google profile, you must log out. It is possible that this data may be shared with Google's contractual partners, third parties, and authorities. The legal basis for processing your data is Art. 6 (1) S. 1 lit. f GDPR. EITHER: This website does not display ads from third parties through Google AdSense.
  3. You can prevent the installation of cookies from Google AdSense in various ways: a) by adjusting your browser software accordingly, especially suppressing third-party cookies will prevent you from receiving ads from third parties; b) by deactivating interest-based ads with Google via the link http://www.google.de/ads/preferences, noting that this setting will be deleted if you delete your cookies; c) by deactivating interest-based ads from providers that are part of the self-regulatory campaign "About Ads" via the link http://www.aboutads.info/choices, noting that this setting will be deleted if you delete your cookies; d) by permanently deactivating in your browsers Firefox, Internet Explorer, or Google Chrome under the link http://www.google.com/settings/ads/plugin. Please note that in this case, you may not be able to use all features of this offer to their full extent.
  4. For more information on the purpose and scope of data collection and its processing, as well as more information on your rights and options for protecting your privacy, please contact: Google Inc., 1600 Amphitheater Parkway, Mountain View, California 94043, USA; advertising privacy terms: http://www.google.de/intl/en/policies/technologies/ads. Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

§ 12 PLUGIN: Google Web Fonts

  1. This page uses so-called web fonts provided by Google for uniform representation of fonts. When you call up a page, your browser loads the necessary web fonts into your browser cache to display texts and fonts correctly.
  2. To this end, the browser you are using must connect to Google's servers. This gives Google knowledge that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and appealing presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR.
  3. If your browser does not support web fonts, a standard font from your computer will be used.
  4. For more information about Google Web Fonts, visit https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/.

§ 13 Use of Google Tag Manager:

  1. Google Tag Manager is a solution that allows marketers to manage website tags through an interface. The Tag Manager tool itself (which implements the tags) is a cookieless domain and does not collect any personal data. The tool triggers other tags that may collect data. Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, it remains in effect for all tracking tags that are implemented with Google Tag Manager. http://www.google.de/tagmanager/use-policy.html. Click here to opt-out of tracking via Google Tag Manager.
Top