1. An overview of data protection
General
The following gives a simple overview of what happens to your personal information when you visit our website. Personal information is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy found below.
Data collection on our website
Who is responsible for the data collection on this website?
The data collected on this website are processed by the website operator. The operator’s contact details can be found in the website’s required legal notice.
How do we collect your data?
On the one hand, your data is collected when you provide it to us. This can be, for example, data that you enter in a contact form. If you only use our website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called “server log files”) and that are technically necessary for us, to show you the website. This is mainly technical data (e.g. internet browser, operating system or time of the page was viewed). This data is collected automatically as soon as you enter our website.
What do we use your data for?
The data is processed in accordance with Article 6 (1) (f) GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.
What rights do you have regarding your data?
You have the right to receive information about the origin, recipient and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the legal notice if you have any further questions on the subject of data protection. You also have the right to lodge a complaint with the responsible supervisory authority.
Analytics and third-party tools
When you visit our website, your surfing behavior can be statistically evaluated. This is done primarily with cookies and so-called analysis programs. The analysis of your surfing behavior is usually anonymous; surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. You can find detailed information on this in the following data protection declaration. You can contradict this analysis. We will inform you about the possibilities of objection in this data protection declaration.
2. General information and mandatory information
Data protection
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this data protection declaration. When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This data protection declaration explains which data we collect and what we use it for. It also explains how and for what purpose this is done. We would like to point out that data transmission over the Internet (e.g. when communicating by e-mail) can have security gaps. A complete protection of the data against access by third parties is not possible.
Notice concerning the party responsible for this website
The party responsible for processing data on this website is:
Niaria – Gesundheitsbewusstsein Linh Le
Maximilianstraße 46
13187 Berlin
Telephone: +49 17623439781
Email: info@niaria.com
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (names, email addresses, etc.).
Revocation of your consent to the processing of your data
Many data processing operations are only possible with your express consent. You can revoke your consent at any time. An informal e-mail to us is sufficient. The legality of the data processing carried out before the revocation remains unaffected by the revocation.
Right to file complaints with regulatory authorities
The applicable data protection law grants you comprehensive data protection rights (information and intervention rights) vis-à-vis the person responsible with regard to the processing of your personal data, about which we will inform you below:
- Right to information according to Art. 15 GDPR: In particular, you have a right to information about your personal data processed by us, the processing purposes, the categories of the processed personal data, the recipients or categories of recipients to whom your data has been or will be disclosed, the planned Storage period or the criteria for determining the storage period, the existence of a right to correction, deletion, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if we did not collect it from you, the Existence of automated decision-making including profiling and, if necessary, meaningful information about the logic involved and the scope and the intended effects of such processing, as well as your right to be informed about the guarantees in accordance with Art. 46 GDPR when your data is forwarded in Third countries exist;
- Right to correction in accordance with Art. 16 GDPR: You have the right to immediate correction of incorrect data concerning you and / or completion of your incomplete data stored by us;
- Right to deletion in accordance with Art. 17 GDPR: You have the right to request the deletion of your personal data if the requirements of Art. 17 Para. 1 GDPR are met. However, this right does not exist in particular if the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
- Right to restriction of processing in accordance with Art. 18 GDPR: You have the right to request that the processing of your personal data be restricted as long as the correctness of your data is being checked, if you reject deletion of your data due to inadmissible data processing and instead the Request restriction of the processing of your data if you need your data to assert, exercise or defend legal claims, after we no longer need this data after the purpose has been achieved or if you have objected to reasons of your particular situation, as long as it is not certain whether our legitimate interests Reasons outweigh;
- Right to information in accordance with Art. 19 GDPR: If you have asserted the right to correction, deletion or restriction of processing vis-à-vis the person responsible, the person responsible is obliged to notify all recipients to whom the personal data relating to you has been disclosed, this correction or deletion of the data or Notification of the restriction of processing, unless this proves to be impossible or involves a disproportionate effort. You have the right to be informed about these recipients.
- Right to data portability in accordance with Art. 20 GDPR: You have the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another person responsible, insofar as this is technically feasible;
- Right to revoke consent given in accordance with Art. 7 Paragraph 3 GDPR: You have the right to revoke your consent to the processing of data at any time with effect for the future. In the event of revocation, we will delete the data concerned immediately, unless further processing can be based on a legal basis for processing without consent. Withdrawing your consent does not affect the legality of the processing carried out on the basis of your consent up to the point of withdrawal;
- Right to lodge a complaint in accordance with Art. 77 GDPR: If you are of the opinion that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged infringement. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is based. A list of data protection officers and their contact details can be found at the this link [click]
Right of Withdrawal
If we process your personal data on the basis of our predominantly legitimate interest as part of a weighing of interests, you have the right at any time to object to this processing with effect for the future for reasons arising from your particular situation. If you make use of your right of objection, we will stop processing the data concerned. However, we reserve the right to further processing if we can prove compelling reasons worthy of protection for the processing that outweigh your interests, fundamental rights and freedoms or if the processing serves to assert, exercise or defend legal claims. If your personal data is processed by us in order to operate direct mail, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising. You can exercise the objection as described above. If you make use of your right of objection, we will stop processing the data concerned for direct marketing purposes.
SSL or TLS encryption
For security reasons and to protect the transmission of the transmission of personal data and other confidential content, such as orders or inquiries that you send to us as the website operator, this site uses an SSL or. TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http: //” to “https: //” and by the lock symbol in your browser line. If the SSL or TLS encryption is activated, the data that you transmit to us cannot be read by third parties.
3. Data collection on our website
Cookies
Some of the websites use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, more effective and safer. Cookies are small text files that are stored on your computer and saved by your browser. Most of the cookies we use are so-called “session cookies”. They are automatically deleted at the end of your visit. Other cookies remain stored on your device (so-called persistent cookies) until you delete them. These cookies enable us to recognize your browser the next time you visit. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when you close the browser. If cookies are deactivated, the functionality of this website may be restricted. Cookies that are required to carry out the electronic communication process or to provide certain functions you want (e.g. shopping cart function) are stored on the basis of Art. 6 Para. 1 lit.f GDPR. The website operator has a legitimate interest in the storage of cookies for the technically error-free and optimized provision of its services. If other cookies (e.g. cookies for analyzing your surfing behavior) are stored, these will be treated separately in this data protection declaration.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data will not be merged with other data sources. The basis for data processing is Article 6 (1) (f) GDPR, which allows the processing of data for the fulfillment of a contract or pre-contractual measures.
Contact form
If you send us inquiries via the contact form or e-mail, your details from the contact form, including the contact details you provided there, will be stored by us for the purpose of processing the request and in case of follow-up questions. Which data is collected in the case of a contact form can be seen from the respective contact form. These data are stored and used exclusively for the purpose of answering your request or for establishing contact and the associated technical administration. The legal basis for processing this data is our legitimate interest in answering your request in accordance with Art. 6 Para. 1 lit.f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. We do not pass on this data without your consent. The processing of the data entered in the contact form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR). You can revoke this consent at any time. An informal e-mail to us is sufficient. The legality of the data processing operations carried out before the revocation remains unaffected by the revocation. The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
Data processing when opening a customer account and for contract processing
According to Art. 6 Para. 1 lit. b GDPR, personal data will continue to be collected and processed if you provide us with this in order to execute a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. A deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. We save and use the data you provide to process the contract. After the contract has been fully processed or your customer account has been deleted, your data will be blocked with due regard to tax and commercial retention periods and deleted after these periods have expired, unless you have expressly consented to further use of your data or we reserve the right to further use of your data as permitted by law became.
Comment function
As part of the comment function on this website, in addition to your comment, information about the time the comment was created and the name of the commentator you have chosen will be saved and published on this website. Your IP address will also be logged and saved. The IP address is stored for security reasons and in the event that the person concerned violates the rights of third parties by submitting a comment or posts illegal content. We need your e-mail address in order to contact you if a third party should object to your published content as illegal. The legal basis for storing your data is Article 6 Paragraph 1 lit. b and f GDPR. We reserve the right to delete comments if third parties complain that they are illegal.
Data processing for order processing
To process your order, we work together with the following service provider (s) who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information. The personal data collected by us will be passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the delivery of the goods. We will pass on your payment data to the commissioned credit institution as part of the payment processing, if this is necessary for the payment processing. If payment service providers are used, we will explicitly inform you about this below. The legal basis for the transfer of data is Art. 6 Paragraph 1 lit. b GDPR.
In order to fulfill our contractual obligations towards our customers, we work together with external shipping partners. We will pass on your name and delivery address and – if necessary for delivery – your telephone number, exclusively for the purpose of delivery of goods, Article 6 (1) (b) GDPR, to a shipping partner selected by us.
Use of payment service providers (payment services)
PAYPAL
When paying via PayPal, credit card via PayPal, direct debit via PayPal or – if offered – “purchase on account” or “installment payment” via PayPal, we will give your payment details to PayPal (Europe) S.a.r.l. as part of the payment process. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). The transfer takes place in accordance with Art. 6 Para. 1 lit. b GDPR and only insofar as this is necessary for payment processing. PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or – if offered – “purchase on account” or “payment in installments” via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Article 6 (1) (f) GDPR on the basis of PayPal’s legitimate interest in determining your solvency. PayPal uses the result of the credit check with regard to the statistical probability of default for the purpose of deciding on the provision of the respective payment method. The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. Further data protection information, including the credit agencies used, can be found in PayPal’s data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
SOFORT
If the payment method “SOFORT” is selected, the payment will be processed by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “SOFORT”), to whom we will send the information you provided during the ordering process along with the information about your order in accordance with Art. 6 Para. 1 lit.b GDPR. Sofort GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). The transfer of your data takes place exclusively for the purpose of payment processing with the payment service provider SOFORT and only insofar as it is necessary for this. You can find more information about SOFORT’s data protection provisions at the following Internet address: https://www.klarna.com/sofort/datenschutz.
Duration of storage of personal data
The duration of the storage of personal data is based on the respective legal basis, the processing purpose and – if relevant – additionally based on the respective statutory retention period (e.g. commercial and tax retention periods). 6 Para. 1 lit. a GDPR, this data is stored until the person concerned revokes his consent. Are there statutory retention periods for data that are required within the scope of legal or similar obligations on the basis of Art. 6 Para. 1 lit. b GDPR are processed, these data are routinely deleted after the retention periods have expired, provided they are no longer required to fulfill or initiate a contract and / or we have no legitimate interest in further storage n on the basis of Art. 6 Paragraph 1 lit. which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims. When processing personal data for the purpose of direct marketing on the basis of Art. 6 Para. 1 lit. Data stored until the person concerned exercises his right of objection according to Art. 21 Para. 2 GDPR. Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will otherwise be deleted if they are used for the purposes for which they were collected or otherwise processed are no longer necessary.
4. Social media
Instagram plugin
Functions of the Instagram service are integrated on our website. These functions are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. If you are logged into your Instagram account, you can link the contents of our pages to your Instagram profile by clicking the Instagram button. This enables Instagram to assign your visit to our website to your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the data transmitted or its use by Instagram. You can find more information on this in Instagram’s privacy policy: https://instagram.com/about/legal/privacy/.
5. Analytics and advertising
Google Analytics
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses so-called “cookies”. These are text files that are saved on your computer and that enable your use of the website to be analyzed. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. The storage of Google Analytics cookies is based on Art. 6 Para. 1 lit.f GDPR. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising.
IP anonymization
We have activated the IP anonymization function on this website. As a result, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before it is transmitted to the USA. The full IP address will only be transmitted to a Google server in the USA and shortened there in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Browser plugin
If cookies are set, they collect and process certain user information such as browser and location data as well as IP address values on an individual basis. Persistent cookies are automatically deleted after a specified period, which can differ depending on the cookie. You can see the duration of the respective cookie storage in the overview of the cookie settings in your web browser. In some cases, the cookies are used to simplify the ordering process by saving settings (e.g. remembering the contents of a virtual shopping cart for a later visit to the website) . If personal data is also processed by individual cookies we use, the processing takes place in accordance with Art. 6 Para. 1 lit. b GDPR either for the execution of the contract, in accordance with Art. 6 Para. 1 lit. in accordance with Art. 6 Paragraph 1 lit.f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.
Please note that you can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general. Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find this for the respective browser under the following links:
Internet Explorer:
https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Chrome:
https://support.google.com/chrome/answer/95647?hl=de&hlrm=enSafari: https://support.apple.com/de-de/guide/safari/sfri11471/mac
Opera:
https://help.opera.com/de/latest/web-preferences/#cookies
Please note that if you do not accept cookies, the functionality of our website may be restricted. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading the browser plug-in available under the following link and install: https://tools.google.com/dlpage/gaoptout?hl=de.
Objecting to the collection of data
You can prevent Google Analytics from collecting your data by clicking on the following link. An opt-out cookie will be set which prevents the collection of your data on future visits to this website: Deactivate Google Analytics. You can find more information on how Google Analytics handles user data in Google’s data protection declaration: https://support.google.com/analytics/answer/6004245?hl=de.
Outsourced data processing
We have concluded a contract data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic data collection by Google Analytics
This website uses the “demographic characteristics” function of Google Analytics. This allows reports to be created that contain statements on the age, gender and interests of the site visitors. This data comes from interest-based advertising from Google as well as from visitor data from third-party providers. These data cannot be assigned to a specific person. You can deactivate this function at any time via the ad settings in your Google account or generally prohibit the collection of your data by Google Analytics as described in the section “Objection to data collection”.
Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on our websites. The provider is Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (“Google”). The purpose of reCAPTCHA is to check whether data is entered on our website (e.g. in a contact form) by a person or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g. IP address, length of stay of the website visitor on the website or mouse movements made by the user). The data collected during the analysis are forwarded to Google. The reCAPTCHA analyzes run completely in the background. Website visitors are not informed that an analysis is taking place. The data processing takes place on the basis of Art. 6 Para. 1 lit.f GDPR. The website operator has a legitimate interest in protecting its web offers from abusive automated spying and from SPAM. For more information on Google reCAPTCHA and Google’s privacy policy, please refer to the following links: https://www.google.com/intl/de/policies/privacy/ and https://www.google.com/recaptcha/intro/android. html.
6. Newsletter
With the following information, we inform you about the contents of our newsletter as well as the registration, dispatch, and statistical evaluation procedures as well as your right of objection. By subscribing to our newsletter, you agree to receive it and the procedures described.
6.1. Content of the newsletter
We send newsletters, e-mails, and other electronic notifications with advertising information (hereinafter “newsletter”) only with the consent of the recipient or legal permission. If the contents of the newsletter are specifically described when registering for the newsletter, they are decisive for the consent of the user. Our newsletter also contains information about our products, offers, promotions, and our company.
6.2. Double opt-in and logging
Registration for our newsletter takes place in a so-called double opt-in procedure. This means that after registration you will receive an e-mail in which you will be asked to confirm your registration. This confirmation is necessary so that nobody can register with someone else’s e-mail address. The registrations for the newsletter are logged in order to be able to prove the registration process is in accordance with the legal requirements. This includes storing the time of registration and confirmation as well as the IP address. The changes to your data stored by the shipping service provider are also logged.
6.3. Dispatch service provider
The newsletter is dispatched using “Direct Mail for Mac”, a newsletter dispatch platform from the US provider e3 Software, LLC, 1166 East Warner Road, Suite 101 Gilbert, AZ 85296, USA. You can view the data protection regulations of the shipping service provider here: https://directmailmac.com/privacy. The e-mail addresses of our newsletter recipients, as well as their other data described in this notice, are stored on the servers of e3 Software, LLC in the USA. e3 Software, LLC uses this information to send and evaluate the newsletter on our behalf. According to its own information, e3 Software, LLC can also use this data to optimize or improve its own services, e.g. for the technical optimization of the dispatch and presentation of the newsletter or for economic purposes, in order to determine from which countries the recipients come. However, e3 Software, LLC does not use the data of our newsletter recipients to write to them itself or pass the data on to third parties. We trust in the reliability and IT and data security of e3 Software, LLC. Furthermore, we have concluded a “Data Processing Agreement” with e3 Software, LLC. This is a contract in which e3 Software, LLC undertakes to protect the data of our users, to process it on our behalf in accordance with their data protection regulations, and, in particular, not to pass it on to third parties. e3 Software, LLC’s privacy policy can be viewed here.
According to its own information, the shipping service provider can use this data in pseudonymous form, i.e. without assignment to a user, to optimize or improve its own services, e.g. for the technical optimization of shipping and the presentation of the newsletter or for statistical purposes to determine from which countries the recipients come, use. However, the shipping service provider does not use the data of our newsletter recipients to write to them themselves or to pass them on to third parties.
6.4. Registration data
In order to register for the newsletter, it is sufficient if you enter your e-mail address. Optionally, we ask you to enter a name so that we can address you personally in the newsletter.
6.4. Success measurement
The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from our server when the newsletter is opened or, if we use a shipping service provider, from their server. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and time of retrieval, are initially collected. This information is used to technically improve the services based on the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or the access times. The statistical surveys also include determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our aim nor, if used, that of the shipping service provider to monitor individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
6.6. Germany
The sending of the newsletter and the measurement of success are based on the consent of the recipient in accordance with Article 6 Paragraph 1 Letter a, Article 7 GDPR in conjunction with Section 7 Paragraph 2 No. 3 UWG or on the basis of the legal permission in accordance with Art § 7 paragraph 3 UWG.
6.7. Cancellation
Newsletter recipients can cancel the receipt of our newsletter at any time, i.e. revoke their consent. You will find a link to cancel the newsletter at the end of each newsletter. At the same time, your consent to the success measurement expires. Unfortunately, it is not possible to revoke the success measurement separately. In this case, the entire newsletter subscription must be canceled. When you unsubscribe from the newsletter, the personal data will be deleted unless their storage is legally required or justified, in which case their processing will only be limited to these exceptional purposes. In particular, we can store the unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before we delete them for the purpose of sending the newsletter in order to be able to prove a previously given consent. The processing of this data is limited to the purpose of a possible defense against claims. An individual request for deletion is possible at any time, provided that the previous existence of a consent is confirmed at the same time.