Privacy Policy

Privacy Policy

Privacy policy

 

Responsible for the data processing:
Cristian Accardo
Wrangelstrasse 57
10997
Berlin
office@tomhemps.com

Thank you for your interest in our online shop. The protection of your privacy is from high importance to us. Below we inform you in detail about the handling of your data.

  1. Access data and hosting

You can visit our websites without giving any personal information. Whenever you call up a website, the web server merely automatically saves a so-called server log file, which contains e.g. the name of the requested file, your IP address, date and time of the call, transferred data volume and the requesting provider (access data) and documents the visit.

This access data is evaluated exclusively for the purpose of ensuring the trouble-free operation of the site and improving our offer. In accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO, this serves to protect our legitimate interests in the correct presentation of our offer, which are predominant in the context of a weighing of interests. All access data is deleted at the latest seven days after the end of your visit to our website.

  1. Data collection and use for contract processing / contact

We collect personal data when you voluntarily provide us with this information as part of your order or when contacting us (e.g. via contact form or e-mail). Mandatory fields are marked as such, because in these cases we need the data for the processing of the contract or for the processing of your contact and you cannot send the order or contact without their indication.

Which data is collected can be seen from the respective input forms. We use the data you provide us within accordance with Art. 6 Para. 1 S. 1 lit. b DSGVO for the purpose of processing contracts and handling your enquiries. Insofar as you have given your consent in accordance with Art. 6 Para. 1 S. 1 lit. a DSGVO by deciding to open a customer account, we will use your data for the purpose of opening a customer account. 

After complete processing of the contract or deletion of your customer account, your data will be restricted for further processing and deleted after expiry of the tax and commercial law retention periods, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this which is legally permitted and about which we inform you in this declaration. The deletion of your customer account is possible at any time and can be done either by sending a message to the contact option described below or by using a function in the customer account intended for this purpose.

  1. Data transfer

In order to fulfil the contract in accordance with Art. 6 Para. 1 S. 1 lit. b DSGVO, we pass on your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the ordering process, we will pass on the payment data collected for this purpose to the credit institution commissioned with the payment and, if applicable, to the payment service provider commissioned by us or to the selected payment service for the processing of payments. In some cases, the selected payment service providers also collect this data themselves if you open an account there. In this case you must log in to the payment service provider with your access data during the ordering process. In this respect the data protection declaration of the respective payment service provider applies.

  1. Integration of the Trusted Shop Trustbadge

For the display of our Trusted Shops seal of approval and the possibly collected ratings as well as the offer of Trusted Shops products for buyers after an order, the Trusted Shops trust badge is integrated on this website.

This serves to safeguard our legitimate interests in optimal marketing, which predominate in the context of a weighing of interests, by enabling safe shopping in accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO. The trust badge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne. The trust badge is made available by a CDN provider (Content Delivery Network) within the scope of order processing. Trusted Shops GmbH also uses service providers from the USA. An appropriate level of data protection is guaranteed. Further information on data protection at Trusted Shops GmbH can be found here.

When the trust badge is called up, the web server automatically saves a so-called server log file, which also contains your IP address, date and time of the call, transferred data volume and the requesting provider (access data) and documents the call. Individual access data is stored in a security database for the analysis of security incidents. The log files are automatically deleted at the latest 90 days after creation.

Further personal data is transferred to Trusted Shops GmbH, if you decide after completion of an order for the use of Trusted Shops products or have already registered for the use. The contractual agreement met between you and Trusted Shops applies. For this an automatic collection of personal data from the order data takes place. Whether you are already registered as a buyer for a product use, the e-mail address hashed by cryptological one-way function it is checked automatically on the basis of a neutral parameter. The email address is converted before transmission into this hash value, which cannot be decrypted by Trusted Shops. After checking for a match, the parameter is automatically deleted.

This is necessary for the fulfilment of our and Trusted Shops’ predominant legitimate interests in the provision of the buyer protection linked to the specific order and the transactional valuation services in accordance with Art. 6 para. 1 sentence 1 lit. f DSGVO. Further details, also on the objection, can be found in the Trusted Shops data protection declaration linked above and in the trust badge.

  1. Cookies and web analytics

In order to make visiting our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use so-called cookies on various pages. This serves to protect our legitimate interests in an optimised presentation of our offer in accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO.

Cookies are small text files that are automatically stored on your end device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognize your browser the next time you visit us (persistent cookies).

The duration of the storage can be seen in the overview in the cookie settings of your web browser. You can set your browser in a way that you are informed about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or generally. Each browser differs in the way it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for each browser under the following links:

Internet Explorer™: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
Safari™: https://support.apple.com/de-de/guide/safari/sfri11471/12.0/mac/10.14
Chrome™: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en
Firefox™ https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Opera™ : https://help.opera.com/de/latest/web-preferences/#cookies

If cookies are not accepted, the functionality of our website may be limited.
Use of Google (Universal) Analytics for web analysis

This website uses Google (Universal) Analytics for website analysis. The web analytics service is provided by Google Ireland Limited, a company incorporated and operated under the laws of Ireland, with a registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves to safeguard our predominantly legitimate interests in an optimised presentation of our offer in accordance with Art. 6 para. 1 sentence 1 lit. f DSGVO. Google (Universal) Analytics uses methods that enable an analysis of your use of the website, such as cookies.

The automatically collected information about your use of this website is usually transferred to a Google server in the USA and stored there. By activating IP anonymisation on this website, the IP address is shortened before transmission within the member states of the European Union or in other states that are party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. The anonymised IP address transmitted by your browser within the framework of Google Analytics is not combined with other Google data. The data collected in this context will be deleted after the end of the purpose and use of Google Analytics by us.

As far as information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. On the basis of this agreement between the USA and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield. 

You may refuse the transfer of data generated by the cookie and relating to your use of the website (including your IP address) to Google and prevent the processing of such data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de

As an alternative to the browser plugin, you can click this link to prevent Google Analytics from recording data on this website in the future. In doing so, an opt-out cookie will be stored on your end device. If you delete your cookies, you have to click the link again.

Google Fonts

On this website the script code “Google Fonts” is integrated. Google Fonts is an offer of Google Ireland Limited, a company registered and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. (www.google.de). This serves to safeguard our legitimate interests, which outweigh our own in the context of a balancing of interests, in a uniform presentation of the content on our website in accordance with Art. 6 para. 1 lit. f) DSGVO.

In this context, a connection is established between the browser you are using and Google’s servers. This enables Google to know that our website has been accessed via your IP address.

As far as information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. On the basis of this agreement between the USA and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield. Further information about data processing by Google can be found in Google’s privacy policy.

Our online presence on Facebook, Google and Instagram

Our presence on social networks and platforms serves to improve active communication with our customers and interested parties. There we inform about our products and current special offers.
When you visit our online presence in social media, your data may be automatically collected and stored for market research and advertising purposes.So-called user profiles are created from this data using pseudonyms. These can be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. For this purpose, cookies are usually used on your end device. The visitor behaviour and interests of the users are stored in these cookies. This serves according to Art. 6 Para. 1 lit. f. DSGVO, this serves to safeguard our legitimate interests, which predominate in the context of weighing up interests, in an optimised presentation of our offer and effective communication with customers and interested parties.  If you are asked by the respective social media platform operators for consent (permission) to data processing, e.g. with the help of a checkbox, the legal basis for data processing is Art. 6 para. 1 lit. a DSGVO.
As far as the aforementioned social media platforms have their headquarters in the USA, the following applies: The European Commission has issued an adequacy finding for the USA. This goes back to the EU-US Privacy Shield. A current certificate for the respective company can be viewed here.
For detailed information on the processing and use of data by the providers on their sites as well as a contact option and your rights and settings options for the protection of your privacy, in particular the possibility to object (opt-out), please refer to the providers’ data protection information linked below.  Should you nevertheless require assistance in this regard, please contact us.
Facebook: https://www.facebook.com/about/privacy/

The data processing is carried out on the basis of an agreement between jointly responsible parties in accordance with Art. 26 DSGVO, which you can view here:
https://www.facebook.com/legal/terms/page_controller_addendum
Google/ YouTube: https://policies.google.com/privacy
Instagram: https://help.instagram.com/519522125107875

Right of appeal (Opt-Out):
Facebook: https://www.facebook.com/settings?tab=ads
Google/ YouTube: https://adssettings.google.com/authenticated
Instagram: https://help.instagram.com/519522125107875

  1. Contact details and your rights

As a data subject, you have the following rights:
In accordance with Art. 15 DSGVO, the right to request information about your personal data processed by us to the extent described therein;
According to Art. 16 DSGVO the right to demand the immediate correction of incorrect or completion of your personal data stored with us;
According to Art. 17 DSGVO the right to demand the deletion of your personal data stored with us, as far as further processing is not

– on the exercise of the right to freedom of expression and information;
– to fulfil a legal obligation;
– for reasons of public interest; or
– to assert, exercise or defend legal claims is required;

In accordance with Art. 18 DSGVO, you have the right to demand the restriction of the processing of your personal data, provided that

– the correctness of the data is disputed by you;
– the processing is unlawful, but you object to its deletion;
– we no longer need the data, but you need it to assert, exercise or defend legal claims; or
– you have lodged an objection to the processing pursuant to Art. 21 DSGVO;

In accordance with Art. 20 DSGVO, the right to receive the personal data you have provided us with in a structured, common and machine-readable format or to request that it be transferred to another responsible party;

Pursuant to Art. 77 DSGVO the right to complain to a supervisory authority. As a rule, you can turn to the supervisory authority of your usual place of residence or workplace or to the supervisory authority of our company headquarters for this purpose.

If you have any questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data, as well as revocation of consents granted or objection to a specific use of data, please contact us directly via the contact data in our imprint.

********************************************************************

Right of objection

Insofar as we process personal data as explained above in order to safeguard our legitimate interests, which are predominant when weighing up the interests, you can object to this processing with effect for the future. If the processing is for direct marketing purposes, you may exercise this right at any time as described above. If processing is carried out for other purposes, you only have the right to object if there are reasons arising from your particular situation.

After exercising your right to object, we will not further process your personal data for these purposes, unless we can prove compelling reasons for processing worthy of protection that outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.

This does not apply if the processing is for direct marketing purposes. In this case we will not process your personal data further for this purpose.

********************************************************************

Privacy policy created with the Trusted Shops legal texter in cooperation with Wilde Beuger Solmecke Rechtsanwälte.

Are you above 18 years old?
Are you above 18 years old?
0