Privacy Policy
DATA PROTECTION DECLARATION
1) INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we will inform you about the handling of your personal data when you use our website. Personal data are all data with which you can be personally identified.
1.2 The controller in charge of data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Elora & Grace Boutique.
The controller responsible for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
Contact: info@elora-grace.com
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or enquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string “https://” and the lock symbol in your browser line.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
When using our website for informational purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the data that your browser transmits to our server (so-called “server log files”). When you visit the website, we collect the following data, which is technically necessary for us to display the website to you:
-
Our visited website
-
Date and time at the time of access
-
Amount of data sent in bytes
-
Source/reference from which you reached the page
-
Browser used
-
Operating system used
-
IP address used (if applicable: in anonymized form)
The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of unlawful use.
3) COOKIES
In order to make your visit to our website attractive and to enable the use of certain functions, we use cookies on various pages. These are small text files that are stored on your end device. Some cookies are deleted after the end of the browser session (so-called session cookies). Other cookies remain on your end device and enable us or our partner companies (third-party cookies) to recognize your browser the next time you visit (persistent cookies). If cookies are set, certain user information such as browser and location data and IP address values may be collected and processed. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.
Cookies can simplify the ordering process (e.g. remembering the contents of a shopping cart for a later visit). Insofar as cookies implemented by us also process personal data, the processing takes place in accordance with Art. 6 para. 1 lit. b GDPR (performance of a contract) or Art. 6 para. 1 lit. f GDPR (our legitimate interests in optimal website functionality and a customer-friendly, effective site experience).
We may work with advertising partners who help us make our website more interesting for you. For this purpose, cookies from partner companies may also be stored on your hard disk when you visit our website (third-party cookies). If we work with such partners, you will be informed about the use of these cookies and the scope of the information collected below, individually and separately.
Cookie control: You can set your browser to inform you about the setting of cookies and to decide individually on their acceptance or to exclude cookies for certain cases or in general. How this works differs by browser; see the respective help menus:
-
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
-
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
-
Chrome: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en
-
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Please note that if you do not accept cookies, the functionality of our website may be restricted.
4) CONTACTING US
When you contact us (e.g. via contact form or e-mail), personal data is collected. Which data is collected can be seen from the respective contact form. This data is used exclusively for the purpose of responding to your request or for establishing contact and the associated technical administration. The legal basis is our legitimate interest in responding to your request (Art. 6 para. 1 lit. f GDPR). If your contact aims at the conclusion of a contract, the additional legal basis is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after final processing of your request, provided there are no statutory retention obligations.
5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING
In accordance with Art. 6 para. 1 lit. b GDPR, personal data will be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be done by sending a message to the controller’s contact above. We store and use the data you provide for contract execution. After complete processing of the contract or deletion of your customer account, your data will be blocked with regard to statutory retention periods and deleted after these periods, unless you have expressly consented to further use or we have reserved the right to further use as permitted by law.
6) USE OF YOUR DATA FOR DIRECT ADVERTISING
6.1 Newsletter Subscription
If you subscribe to our e-mail newsletter, we will regularly send you information about our offers. The only mandatory information is your e-mail address; other data is voluntary and used to address you personally. We use a double opt-in procedure. By activating the confirmation link, you consent (Art. 6 para. 1 lit. a GDPR). We store your IP address, date and time of registration to prevent misuse. You can unsubscribe at any time via the link in the newsletter or by contacting the controller above; your e-mail will then be deleted from our list unless further use is permitted by law or consented.
6.2 Newsletter to Existing Customers
If you provided your e-mail when purchasing, we may send offers for similar goods/services via e-mail based on our legitimate interests in personalized direct advertising (Art. 6 para. 1 lit. f GDPR). You can object at any time; after objection we will cease such use.
7) DATA PROCESSING FOR ORDER PROCESSING
7.1 We forward necessary personal data to the transport company for delivery and to the credit institution for payment processing (Art. 6 para. 1 lit. b GDPR). If payment service providers are used, details follow below.
7.2 Payment Service Providers
-
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Processing under Art. 6 para. 1 lit. b GDPR; credit checks may occur under Art. 6 para. 1 lit. f GDPR. Privacy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
-
SOFORT (Klarna Group) – SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany. Processing under Art. 6 para. 1 lit. b GDPR. Privacy: https://www.klarna.com/sofort/datenschutz
8) CONTACTING US FOR THE VALUATION REMINDER
We may use your e-mail address as a one-time reminder to review your order if you have expressly consented (Art. 6 para. 1 lit. a GDPR). You can revoke consent at any time by contacting the controller.
9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS
9.1 Facebook (Shariff Solution)
Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. Buttons integrated as HTML links to increase data protection. Privacy: https://www.facebook.com/policy.php
9.2 Google+ (Shariff Solution)
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy: https://www.google.com/intl/de/policies/privacy/
9.3 Instagram (Shariff Solution)
Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA. Privacy: https://help.instagram.com/155833707900388/
Note: Some providers reference the EU–US “Privacy Shield.” Although referenced here for legacy clarity, current transfer mechanisms may differ; we will update these references as required by law.
10) ONLINE MARKETING
10.1 DoubleClick by Google – Cookie-based ad delivery/measurement (Art. 6 para. 1 lit. f GDPR). Privacy: https://www.google.de/policies/privacy/
10.2 Google Ads Conversion Tracking – Cookie-based conversion stats (Art. 6 para. 1 lit. f GDPR). Privacy: https://www.google.de/policies/privacy/
Opt-out plugin: https://www.google.com/settings/ads/plugin?hl=de
11) WEB ANALYSIS SERVICES
Google (Universal) Analytics with _anonymizeIp(). Processing based on legitimate interests in statistical analysis (Art. 6 para. 1 lit. f GDPR).
Opt-out: https://tools.google.com/dlpage/gaoptout?hl=de
More info: https://support.google.com/analytics/answer/2838718?hl=de&ref_topic=6010376
12) RETARGETING / REMARKETING / REFERRAL ADVERTISING
Facebook Custom Audience (Pixel) – With explicit consent (Art. 6 para. 1 lit. a GDPR). Privacy: https://www.facebook.com/about/privacy/
Opt-out choices: https://www.aboutads.info/choices/
Google Ads Remarketing – Cookie-based remarketing (Art. 6 para. 1 lit. f GDPR).
Settings/opt-out: https://www.google.com/settings/ads/onweb/
Privacy: https://www.google.com/policies/technologies/ads/
13) RIGHTS OF THE DATA SUBJECT
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), notification (Art. 19), data portability (Art. 20), withdrawal of consent (Art. 7(3)), and to lodge a complaint (Art. 77 GDPR).
Right to Object (Art. 21 GDPR):
You may object at any time on grounds relating to your particular situation where processing is based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds. If your data is processed for direct marketing, you may object at any time; we will then stop processing for such purposes.
14) DURATION OF THE STORAGE OF PERSONAL DATA
Storage duration is determined by statutory retention periods (e.g. commercial/tax). After expiry, data is routinely deleted if no longer required for contract fulfillment/initiation and/or no legitimate interest justifies continued storage.
Controller contact for all privacy matters: Elora & Grace Boutique — info@elora-grace.com