Privacy Policy

 

Privacy Policy

Responsible for data processing is:
Yusuf Ilica
Dr.-Hans-Wolf-Platz 1
67069 Ludwigshafen
Germany

info@otanto.de

We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below we inform you in detail about how we handle your data.

 

1. Access data and hosting

 

You can visit our websites without providing personal information. Each time a webpage is called up, the web server automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, date and time of the request, amount of data transferred, and the requesting provider (access data) and documents the request.

These access data are evaluated exclusively for the purpose of ensuring the smooth operation of the site and improving our offer. This serves, according to Art. 6 para. 1 sentence 1 lit. f GDPR, to protect our overriding legitimate interests in a correct presentation of our offer as part of a balancing of interests. All access data will be deleted no later than seven days after the end of your site visit.

 

2. Data collection and use for contract processing, contact, and opening a customer account

 

We collect personal data when you voluntarily provide it to us as part of your order or when contacting us (e.g., via contact form or email). Mandatory fields are marked as such because we need the data in these cases to process the contract or handle your inquiry, and without providing them, you cannot submit the order or contact request. Which data is collected is visible from the respective input forms. We use the data you provide in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR for contract processing and handling your inquiries.
If you have given your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR by choosing to open a customer account, we use your data for the purpose of opening the customer account.
After the contract has been fully processed or your customer account has been deleted, your data will be restricted for further processing and deleted after the expiration of the tax and commercial retention periods, unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this which is legally permitted and about which we inform you in this statement. Deleting your customer account is possible at any time and can be done either by sending a message to the contact option described below or via a designated function in the customer account.

3. Data transfer

 

To fulfill the contract according to Art. 6 para. 1 sentence 1 lit. b GDPR, we forward your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select during the ordering process, we forward the payment data collected for this purpose to the credit institution commissioned with the payment and, if applicable, to payment service providers commissioned by us or to the selected payment service. In some cases, the selected payment service providers also collect this data themselves if you create an account there. In this case, you must log in to the payment service provider with your access data during the ordering process. The privacy policy of the respective payment service provider applies in this regard.

 

 

We also use an external merchandise management system for order and contract processing. The data transfer or processing that takes place in this regard is based on order processing.

 

Data transfer to shipping service providers
If you have given us your explicit consent during or after your order, we will forward your email address to the selected shipping service provider based on this consent according to Art. 6 para. 1 sentence 1 lit. a GDPR so that they can contact you before delivery for the purpose of delivery notification or coordination.

Consent can be revoked at any time by sending a message to the contact option described below or directly to the shipping service provider at the contact address listed below. After revocation, we will delete the data you provided for this purpose unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this statement.
Sendcloud GmbH
Fürstenrieder Str. 70
80686 Munich
Germany

4. Email newsletter and postal advertising

Email advertising with newsletter subscription
When you sign up for our newsletter, we use the data required for this or separately provided by you to regularly send you our email newsletter based on your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR.

You can unsubscribe from the newsletter at any time either by sending a message to the contact option described below or via a designated link in the newsletter. After unsubscribing, we delete your email address from the recipient list unless you have explicitly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this statement.

The newsletter is sent on our behalf by a service provider to whom we pass on your email address for this purpose. This service provider is located within a country of the European Union or the European Economic Area.

 

Postal advertising and your right to object
Furthermore, we reserve the right to use your first and last name as well as your postal address for our own advertising purposes, e.g., to send interesting offers and information about our products by postal mail. This serves to protect our overriding legitimate interests in advertising communication with our customers within the framework of a balancing of interests according to Art. 6 para. 1 sentence 1 lit. f GDPR.

 

5. Data use in payment processing

 

 

 

Identity and credit check when selecting Klarna payment services
If you choose Klarna's payment services, we ask for your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR, allowing us to transmit the data necessary for processing the payment and for identity and credit checks to Klarna. In Germany, the credit agencies named in Klarna's Privacy Policy may be used for identity and credit checks.
Klarna uses the information received about the statistical probability of a payment default for a balanced decision regarding the establishment, execution, or termination of the contractual relationship.
You can revoke your consent at any time by sending a message to the contact details below. This may result in us no longer being able to offer you certain payment options. You can also revoke your consent to this use of personal data at any time directly with Klarna.

 

 

6. Cookies and Web Analysis

To make visiting our website attractive and to enable the use of certain functions, to display suitable products, or for market research, we use so-called cookies on various pages, provided you have given your consent according to Art. 6 para. 1 sentence 1 lit. a GDPR.

Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies). You can find the duration of storage in the overview in your web browser's cookie settings. You can set your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. If you do not accept cookies, the functionality of our website may be limited. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers at the following links:

Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™

You can revoke your consent at any time by sending a message to the contact option described in the privacy policy.

7. Online Marketing

Live Chat Tool TIDIO
If you use the live chat tool to contact us, the data you voluntarily enter there (name, email address, message) will be processed by us in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR for the purpose of responding to the inquiry within the scope of contract processing. Furthermore, the use of this tool serves to protect our overriding legitimate interests in effective and improved customer communication in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR as part of a balancing of interests. The data will then be deleted.
As part of processing on our behalf, the third-party provider Userlike provides the services for the live chat tool. All data collected during the use of the chat tool is processed on its servers.

 

Google AdSense
This website uses Google AdSense, a service for embedding advertisements from Google Inc. ("Google"). Provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google AdSense uses so-called "cookies," text files that are stored on your computer and allow an analysis of website usage. Google AdSense also uses so-called web beacons (invisible graphics). These web beacons allow information such as visitor traffic on these pages to be evaluated.

The information generated by cookies and web beacons about the use of this website (including your IP address) and the delivery of advertising formats is transmitted to a Google server in the USA and stored there. This information may be passed on by Google to Google's contractual partners. However, Google will not merge your IP address with other data stored by you.

The storage of AdSense cookies is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its web offering and its advertising.

You can prevent the installation of cookies by adjusting your browser software settings accordingly; however, we point out that in this case you may not be able to use all functions of this website fully. By using this website, you agree to the processing of the data collected about you by Google in the manner described above and for the purpose stated above.

Google Analytics Remarketing
Our websites use the functions of Google Analytics Remarketing in conjunction with the cross-device functions of Google AdWords and Google DoubleClick. Provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

This feature allows the advertising audiences created with Google Analytics Remarketing to be linked with the cross-device functions of Google AdWords and Google DoubleClick. This way, interest-based, personalized advertising messages tailored to you based on your previous usage and browsing behavior on one device (e.g., mobile phone) can also be displayed on another of your devices (e.g., tablet or PC).

If you have given the corresponding consent, Google links your web and app browser history with your Google account for this purpose. This way, the same personalized advertising messages can be displayed on every device where you sign in with your Google account.

To support this function, Google Analytics collects google-authenticated user IDs, which are temporarily linked to our Google Analytics data to define and create audiences for cross-device advertising.

You can permanently object to cross-device remarketing/targeting by disabling personalized advertising in your Google account; follow this link: https://www.google.com/settings/ads/onweb/.

The summary of the data collected in your Google account is based solely on your consent, which you can give or withdraw at Google (Art. 6 para. 1 lit. a GDPR). For data collection processes that are not merged in your Google account (e.g., because you do not have a Google account or have objected to the merging), data collection is based on Art. 6 para. 1 lit. f GDPR. The legitimate interest arises from the website operator's interest in anonymized analysis of website visitors for advertising purposes.

Further information and the privacy policy can be found in Google's privacy statement at: https://www.google.com/policies/technologies/ads/.

Google AdWords and Google Conversion Tracking
This website uses Google AdWords. AdWords is an online advertising program by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”).

As part of Google AdWords, we use so-called conversion tracking. When you click on an ad placed by Google, a cookie for conversion tracking is set. Cookies are small text files that the internet browser stores on the user's computer. These cookies expire after 30 days and are not used for personal identification of users. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page.

Each Google AdWords customer receives a different cookie. The cookies cannot be tracked across the websites of AdWords customers. The information collected using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged with conversion tracking. However, they do not receive any information that would allow users to be personally identified. If you do not want to participate in tracking, you can object to this use by easily disabling the Google Conversion Tracking cookie via your internet browser in user settings. You will then not be included in the conversion tracking statistics.

The storage of "conversion cookies" and the use of this tracking tool are based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its web offering and its advertising.

More information about Google AdWords and Google Conversion Tracking can be found in Google's privacy policy: https://www.google.de/policies/privacy/.

You can set your browser to inform you about the setting of cookies and to allow cookies only in individual cases, to exclude the acceptance of cookies for certain cases or in general, and to activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Google reCAPTCHA
We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on our websites. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").

reCAPTCHA is used to verify whether data entry on our websites (e.g., in a contact form) is performed by a human or by an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of the website visitor's stay on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.

The reCAPTCHA analyses run entirely in the background. Website visitors are not notified that an analysis is taking place.

Data processing is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated data scraping and SPAM.

For more information about Google reCAPTCHA and Google's privacy policy, please refer to the following links: https://www.google.com/intl/de/policies/privacy/ and https://www.google.com/recaptcha/intro/android.html.

Google Maps
This website uses Google Maps to visually display geographic information. Google Maps is an offering of Google Ireland Limited, a company registered and operated under Irish law with its headquarters at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves to safeguard our overriding legitimate interests in an optimized presentation of our offer and easy accessibility of our locations according to Art. 6 para. 1 sentence 1 lit. f) GDPR.
When using Google Maps, Google transmits or processes data about the use of the Maps functions by website visitors, which may include the IP address and location data. We have no influence on this data processing. To the extent that information is transmitted to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here . Due to this agreement between the USA and the European Commission, the latter has determined an adequate level of data protection for companies certified under the Privacy Shield. 
To disable the Google Maps service and thus prevent data transmission to Google, you must disable the JavaScript function in your browser. In this case, Google Maps cannot be used or can only be used with limitations. 
Further information about data processing by Google can be found in the privacy policy of Google. The terms of use for Google Maps include detailed information about the map service. 
The data processing is based on an agreement between joint controllers according to Art. 26 GDPR, which you can view here .

Facebook Pixel


Our website uses the Facebook visitor action pixel from Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook") for conversion tracking.

This allows the behavior of site visitors to be tracked after they have been redirected to the provider’s website by clicking on a Facebook ad. This enables the effectiveness of Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.

The data collected is anonymous to us as the operator of this website; we cannot draw conclusions about the identity of users. However, the data is stored and processed by Facebook, so a connection to the respective user profile is possible, and Facebook can use the data for its own advertising purposes according to the Facebook Data Use Policy . This allows Facebook to enable advertising on Facebook pages as well as outside of Facebook. This use of data cannot be influenced by us as the site operator.

The use of Facebook Pixel is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in effective advertising measures including social media.

In Facebook’s privacy policy, you will find further information on protecting your privacy: https://www.facebook.com/about/privacy/.

You can also disable the remarketing feature “Custom Audiences” in the ad settings section at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen disable. For this, you must be logged into Facebook.

If you do not have a Facebook account, you can disable usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.

 

8. Social Media

Use of social plugins from Facebook, Instagram, using the Shariff solution.

Social buttons from social networks are used on our website.

This serves to protect our overriding legitimate interests in the optimal marketing of our offer in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR as part of a balancing of interests. To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins but only embedded in the page using an HTML link. This integration ensures that when a page of our website containing such buttons is called up, no connection is yet established with the servers of the respective social network provider.

Clicking on one of the buttons will open a new window in your browser and load the page of the respective service provider, where you can (if necessary, after entering your login details) for example, click the Like or Share button.

Purpose and scope of data collection and the further processing and use of data by the providers on their sites, as well as a contact option and your related rights and settings to protect your privacy, can be found in the privacy notices of the providers:

https://www.facebook.com/policy.php

https://help.instagram.com/155833707900388

Our online presence on Facebook, Instagram

Our presence on social networks and platforms serves better, active communication with our customers and interested parties. We provide information there about our products and ongoing special promotions.
When visiting our online presences on social media, your data may be automatically collected and stored for market research and advertising purposes. Pseudonymized usage profiles are created from this data. These can be used, for example, to display advertisements within and outside the platforms that presumably match your interests. For this purpose, cookies are usually used on your device. These cookies store visitor behavior and user interests. This serves, according to Art. 6 para. 1 lit. f GDPR, to safeguard our overriding legitimate interests in an optimized presentation of our offer and effective communication with customers and interested parties within the framework of a balancing of interests. If you are asked by the respective social media platform operators for consent to data processing, e.g., by means of a checkbox, the legal basis for data processing is Art. 6 para. 1 lit. a GDPR.
If the aforementioned social media platforms have their headquarters in the USA, the following applies: For the USA, there is an adequacy decision by the European Commission. This is based on the EU-US Privacy Shield. A current certificate for the respective company can be viewed here .
Detailed information on the processing and use of data by the providers on their sites, as well as a contact option and your related rights and settings to protect your privacy, especially objection options (opt-out), can be found in the privacy notices of the providers linked below. If you still need assistance in this regard, you can contact us.

Facebook: https://www.facebook.com/about/privacy/
The data processing is based on an agreement between joint controllers according to Art. 26 GDPR, which you can view here .
Further information on data processing in the context of visiting a Facebook fan page (information on Insights data) can be found here.

Instagram: https://help.instagram.com/519522125107875

Opt-out option:

Facebook: https://www.facebook.com/settings?tab=ads

Instagram: https://help.instagram.com/519522125107875

9. Sending review reminders by email

  

Review reminder by Trusted Shops
If you have given us your explicit consent according to Art. 6 para. 1 sentence 1 lit. a GDPR during or after your order, we will transmit your email address to Trusted Shops GmbH, Subbelrather Str. 15c, 50823 Cologne (www.trustedshops.de), so that they can send you a review reminder by email.

This consent can be revoked at any time by sending a message to the contact option described below or directly to Trusted Shops.

 

Review reminder by Trustpilot 
If you have given us your explicit consent according to Art. 6 para. 1 sentence 1 lit. a GDPR during or after your order, we will transmit your email address to Trustpilot A/S, Pilestræde 58, 5, 1112 Copenhagen (de.trustpilot.com), so that they can send you a review reminder by email.

This consent can be revoked at any time by sending a message to the contact option described below or directly to Trustpilot A/S.

10. Contact options and your rights

 

As a data subject, you have the following rights:

  • According to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified there;
  • According to Art. 16 GDPR, the right to request the immediate correction of incorrect or completion of your personal data stored with us;
  • According to Art. 17 GDPR, the right to request the deletion of your personal data stored with us, unless further processing is required
    • To exercise the right to freedom of expression and information;
    • To fulfill a legal obligation;
    • For reasons of public interest; or
    • It is necessary for the assertion, exercise, or defense of legal claims;
  • According to Art. 18 GDPR, the right to request restriction of the processing of your personal data, insofar as
    • The accuracy of the data is disputed by you;
    • The processing is unlawful, but you refuse its deletion;
    • We no longer need the data, but you require it for the assertion, exercise, or defense of legal claims; or
    • You have lodged an objection to the processing according to Art. 21 GDPR;
  • According to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request the transfer to another controller;
  • According to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. Usually, you can contact the supervisory authority of your usual place of residence, workplace, or our company headquarters for this purpose.

If you have questions about the collection, processing, or use of your personal data, about information, correction, restriction, or deletion of data, as well as revocation of given consents or objection to a specific data use, please contact us directly using the contact details in our imprint.

Right to object
To the extent that we process personal data as described above to protect our overriding legitimate interests within the scope of a balancing of interests, you may object to this processing with effect for the future. If the processing is for direct marketing purposes, you may exercise this right at any time as described above. If the processing is for other purposes, you have a right to object only if there are reasons arising from your particular situation.

After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves the assertion, exercise, or defense of legal claims.

This does not apply if the processing is carried out for direct marketing purposes. In that case, we will not further process your personal data for this purpose.