We, SANVT GmbH, Eisnergutbogen 16, 80639 Munich, Germany (Imprint), are the operator of the website https://sanvtstaging.madebycolorelephant.com. We are therefore responsible for the collection, processing and use of your personal data in terms of Data Privacy provisions, when visiting our website.
Our data protection officer can be reached under firstname.lastname@example.org.
We use your personal data in compliance with the applicable data privacy provisions. Below we will describe what data we collect, how we use it and what rights you have in terms of our use of your data:
I. SCOPE & PURPOSE OF COLLECTION, PROCESSING AND USE OF PERSONAL DATA
1. When visiting our Website
When you visit our website, our servers temporarily save every access in a log file. The following data are automatically recorded without any action on your part and stored until automatic deletion:
- the IP address of the accessing computer,
- the date and time of access,
- the name and URL of the accessed file,
- the website from which you accessed our website (referrer),
- your computer’s operating system and the browser used by you,
- the name of your Internet access provider.
These data are collected and processed for the purposes of facilitating use of our website (creating the connection), guaranteeing long-term system security and stability and optimising our web service, as well as for internal statistical purposes. This will not allow us to identify you as an individual person.
Legal basis is Art. 6 Abs. 1 Satz 1 lit. f) DSGVO. Your data is being deleted as soon as there is no need for fulfilling their initial purpose. When gathering data for providing the page, this will be the case, then closing the browser session.
In addition, we also set cookies and use web analytics during visits to our website. You can find more detailed information on this in Sections III, IV and V.
2. When signing up for our newsletter
Sending of Newsletters / Content
We only send out newsletters, E-Mails and further electronical messages with commercial purpose (hereby “newsletter”) only with your explicit consent. Our newsletter contains information about our products, frequent offers and campaigns.
Double-Opt-In and Logging
Subscribing to our newsletter works with the double-opt-in process. This means, after entering your email-address you will receive an email with a confirmation link. The subscription is being logged in order to adhere to legal requirements. This includes logging the subscription and confirmation time as well as the IP-address. Furthermore your data changed within Mailchimp will be logged.
Using „MailChimp“ as Service Provider
Our newsletter is distributed via “MailChimp”, a mailing-platform from the US-based provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. Both the email-addresses of our subscribers as well as the gathered data (as explained here) will be persisted on MailChimp-servers in the USA. Mailchimp uses those data for sending out and analysing the newsletter on behalf of SANVT. Furthermore, MailChimp can use this data in order to improve their own service, e.g. optimising the technical distribution or displaying the email appropriately do distinguish the country the receiver are localised. MailChimp is not providing the data to any third party. Furthermore we have signed a „Data-Processing-Agreement“. In this agreement Mailchimp commits to protect our customers’ data, process our data based on our data-protection law and particularly does not pass on the data to any third party. You can view MailChimp’s data privacy statement here.
To subscribe to our newsletter, it is sufficient to provide your email-address.
The newsletter contains so-called “web-beacons”. That is a pixel-sized file, which is called by the MailChimp server when opening the newsletter. With this call, technical information as to the used browser, your system, IP-address and point of time are stored. This data is used to improve the technical services and distribution quality. Furthermore, the information is stored, if and when the newsletter was opened by the user and which links have been clicked. This information can indeed be related to a specific user, but we as SANVT will not track and explicitly insist with MailChimp on not tracking a single user. This information only helps us to identify general user behaviour due to the usage of our newsletter and to improve the contents towards the optimal user experience.
Online-Call and Data Management
Right of Withdrawal
You can withdraw your consent to the newsletter subscription at any time via the un-subscription link contained in every newsletter.
Legal Basis data Protection Law
Your subscription to our newsletter is based Art. 6 Abs. 1 lit. a, Art. 7 the General Data Protection Regulation (GDPR) as of 25th of May 2018 GDPR as well as § 7 Abs. 2 Nr. 3,. Abs. 3 UWG. Using MailChimp, applying statistical analysis as well logging the subscription process are based on our legitimate interest as per 6 Abs. 1 lit. f GDPR. Our interest goes towards using a both user-friendly as well as secure service provider that adheres both to our commercial needs as well as our customer’s expectations.
3. When using the Contact Form
You can use the contact form on our website for general requests. Your name, a valid e-mail-address and the reason for the request are required. Additional data is non-mandatory. We collect this data to know the author of the request and to reply individually and through whichever method you have specified (via mail, phone or e-mail).
4. When creating a Customer Account
When registering as customer we persist data only in the most necessary extent. Data processing happens for the purpose of improving your shopping experience as well as optimising our fulfilment processes. The data processing happens as per Art. 6 Absatz 1 lit. a DSGVO with your explicit consent. You can withdraw your consent at any time without touching the legitimacy of the data processing based on your consent until your withdrawal. Your account will be deleted subsequently.
Legal Basis data Protection Law
Your subscription to our newsletter is based Art. 6 Abs. 1 lit. a, Art. 7 the General Data Protection Regulation (GDPR) as of 25th of May 2018 GDPR as well as § 7 Abs. 2 Nr. 3,. Abs. 3 UWG.
Using MailChimp, applying statistical analysis as well logging the subscription process are based on our legitimate interest as per 6 Abs. 1 lit. f GDPR. Our interest goes towards using a both user-friendly as well as secure service provider that adheres both to our commercial needs as well as our customer’s expectations.
II. DISCLOSURE OF DATA TO THIRD PARTIES FOR CONTRACTUAL PURPOSES
We will share your personal data with third parties only if you have expressly agreed to this, if we are under a legal obligation to do so, or if this is required in order to assert our rights, in particular to enforce claims arising from the contractual relationship.
Beyond this, we will pass your data on to third parties to the extent that this is necessary for processing the contract. We collaborate with external companies for the purpose of processing our various payment transactions: This is Paypal Deutschland GmbH, Am Marktplatz 1, 14532 Kleinmachnow, Germany when paying via Paypal and Stripe, 510 Townsend Street, San Francisco, CA 94103, USA when paying via Stripe. Stripe reviews and evaluates the data you provided and in case of legitimate interest performs a data exchange with other companies and credit rating agencies. Your personal data will be processed in accordance with applicable data protection law as described in Stripe’s privacy statement.
Further third party providers, that are necessary for carrying out the contracts are: shipping provider, logistics fulfilment provider, service provider for processing our orders as well as webhoster. In any case we strictly adhere to legal requirements. Persisted data limits to the necessary minimum.
Personal data will not be disclosed to third parties for any other purpose.
We use website cookies in several areas of our website. Cookies are small files that your web browser automatically generates and are stored on the hard drive of your device (laptop, tablet, smartphone etc.) when you visit our website. Cookies do not harm your device and do not contain any viruses, Trojans or other malicious software.
Cookies store information, generated when you visit our website with your specific device. This, however, does not mean that we receive immediate information about personal data.
The use of the cookies does not allow us to obtain new personal data about you as an online visitor. The majority of Internet browsers accept cookies automatically. However, you can configure your browser to reject cookies or to notify you whenever you receive a new cookie.
Deactivation of cookies can lead to you not being able to use all of the functions of our website.
The following cookies are being set:
|Newsletter_pagecount||Counts the visited pages to identify when to show the newsletter popup||7 days|
|Newsletter_status||In case the user has already seen the newsletter popup, she should not see it again. This information is handled by this cookie.||7 days|
|Visited_top_banner||If the top-banner regarding delivery options has already been seen and clicked, it should reappear.||30 days|
|Visited_cookie||If the top-banner regarding cookies has already been seen and clicked, it should not reappear.||30 days|
|PHPSESSID||Unique ID for the server to identify the current user session||duration of current user session|
|woocommercecart_hash||Shopsystem checks if something changed in the cart.||Lifetime of the cart (Closure through purchase, reset through removing items from the cart)|
|wp_woocommerce_session+md5-hash||Uniquely identifieds the customers cart||Lifetime of the cart (Closure through purchase, reset through removing items from the cart)|
|wpml_referer_url||Saves the latest visited page of the customer for language reasons||1 day|
|icl_current_language||Saves the currently selected language of the customer||1 day|
Besides cookies we use local storage objects for the following functionality:
- ds_recently_viewed_6: The user gets an overview of recently viewed products. This information is stored as long as the local cache of the browser is active.
IV. WEB ANALYTICS
For the purpose of demand-responsive design and ongoing optimisation of our sites we use Google Analytics, a web analytics service of the Google Inc., 1600 Amphitheatrae Parkway, Mountain View, CA 94043 USA. The information generated by the Cookie about your use of this website (including your IP address) is transferred to a server by Google in the USA and is stored there. IP addresses are anonymised to exclude all possibility of such association (IP masking). The information is used to evaluate use of the website, to compile reports on website activity and to provide further services associated with website and Internet use for the purposes of market research and needs-based design of these web pages. Your data will not in any case be associated with other data from Google. This information may be forwarded to third parties only, insofar as this is prescribed by law or insofar as these parties process the data on behalf of the commissioning party. You can prevent the installation of cookies by adjusting your browser accordingly; in this case, however, not all functions of the website may be available to the user to their full extent. You can also prevent the data generated by the cookie and relating to your use of the website (including your IP address) and the processing of these data by Google, by downloading and installing a browser-add-on. As an alternative to a browser add-on, especially for browsers on mobile devices, you can also avoid the information collection by Google Analytics by clicking on this link. An opt-out cookie is then put in place, which will prevent future collection of your information whenever you visit this website. The opt-out cookie applies only to this browser and our website, and this cookie will be stored on your device. Should you delete the cookies in this browser, you will need to set the opt-out cookie again. Further information about Google Universal Analytics can be found in the Google Analytics help pages. We trust in the reliability of Google’s IT and data security. Google is certified under the US-EU-data protection agreement „Privacy Shield“ and hereby commits to comply with European data protection law.
V. SOCIAL PLUG INS
On our website, so-called social plugins (“plugins”) by the social network Instagram are used, which is operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”). The plugins are marked with an “Instagram button” on our website. When you click on the “Instagram-button” while you are logged into your Instagram-profile, you can link the content of our sites to your Instagram profile. This enables Instagram to connect your visit to our sites to your user account. Instagram does not inform us about which information is transmitted and how it is used. For more information, please see the Privacy Statement of Instagram.
VI. RIGHT TO INFORMATION, CORRECTION, BLOCKING & DELETION
Where permitted by applicable law or regulation, you have the right to:
- Access your personal data held about you and to learn the origin of the data, the purposes and means of the processing, the details of the data controller(s), the data processor(s) and the parties to whom the data may be disclosed;
- Withdraw your consent at any time where your personal data is processed with your consent;
- Update and correct your personal data so that it is accurate;
- Delete your personal data from our records if it is no longer needed for the purposes indicated above;
- Restrict the processing of your personal data in certain circumstances, e.g. where you have contested the accuracy of your personal data, for the period enabling us to verify its accuracy;
- Obtain your personal data in an electronic format;
- File a complaint with us and/or the relevant data protection authority; and
- Object to us processing your personal data or tell us to stop processing it (including for purposes of direct marketing).
VI. DATA SECURITY
Your connection to our website is TLS-secured.
We use appropriate technical and organisational security measures to protect your stored personal data against manipulation, partial or complete loss and against unauthorised access by third parties. Our security measures are continuously enhanced as new technology becomes available.