Privacy Policy
Responsible for the processing of data is:
Carmen Duffner
Schwarzwaldstraße 7
Schönwald
Deutschland
post@herzoase.com
Thank you for visiting our website. Protection of your privacy is very important to us. Below you will find extensive information about how we handle your data.
1. Access data and hosting
You may visit our website without revealing any personal information. With every visit on the website, the web server stores automatically only a so-called server log file which contains e.g. the name of the requested file, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request.
These access data are analysed exclusively for the purpose of ensuring the smooth operation of the website and improving our online appearance. This serves according to Art. 6 (1) 1 lit. f) GDPR the protection of our legitimate interests in the proper presentation of our online appearance that are overriding in the process of balancing of interests. All access data are deleted no later than seven days after the end of your visit on our website.
Third-party hosting services
Data are also processed by a third-party provider that we have engaged to render hosting and website presentation services on our behalf. This provider processes on its servers all data that are collected in the manner specified below when you visit our website or fill in forms made available for this purpose. Data are processed on other servers only in the scope described herein.
This service provider is based in an EU or EEA member state.
2. Cookies
In order to make a visit to our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use so-called cookies on various pages, provided that you have given your consent to do so in accordance with Art. 6 (1) 1 a GDPR.
Cookies are small text files that are automatically stored on your end device. Some of the cookies used by us are deleted again after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognize your browser the next time you visit us (persistent cookies). You can see the storage duration in the cookie settings of your web browser. You can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be limited. Each browser differs in the way it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You will find these for each browser under the following links:
Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
Below we present information on cookies we use and how you can customise your browser in that respect.
Necessary cookies
These cookies are necessary to enable you to use our website. This includes e.g. cookies that enable you to log into the visitor area.
Analytical / performance cookies
These cookies enable collecting anonymised data about user behaviour on our website. We analyse them e.g. to improve the functionality of our website and recommend you products that will be interesting to you.
Functionality cookies
These cookies are used for certain features of our website, e.g. to improve the website’s navigation, or deliver to you customised and relevant information (e.g. ads that match your interests).
Furthermore, you can revoke your consent at any time by sending a message to the contact option described in the privacy policy.
3. Online Marketing
Amazon Affiliate Program
Our website participates in the Amazon affiliate program. This is offered by Amazon Europe Core S.à r.l. (Société à responsabilité limitée), 5 Rue Plaetis, L-2338 Luxembourg (hereinafter “Amazon”). This is an affiliate system designed to provide a medium for websites that can be used to earn reimbursement by placing advertisements and links to Amazon.
This serves to safeguard our legitimate interests in optimising and commercially exploiting our online appearance accordance with Art. 6 (1) 1 lit. f) GDPR that are overriding in the process of balancing of interests.
Amazon can use cookies to track the progress of each order and in particular to verify that you clicked on the respective link and then ordered the product on Amazon.
You can prevent cookies from being set by our contractual partners or our website at any time by means of a corresponding setting in your Internet browser. In addition, cookies that have already been set can be deleted at any time via the Internet browser or other software programs.
Further information on data processing at Amazon can be found here.
Google reCAPTCHA
To protect against misuse of our web forms and spam, we use the Google reCAPTCHA service. Google reCAPTCHA is an offer from Google Ireland Limited, a company incorporated and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.co.uk). By checking a manual entry, this service prevents automated software (so-called bots) from carrying out abusive activities on the website. In accordance with art. 6 (1) 1 lit. f) GDPR, this serves to protect our legitimate interests in the protection of our website from misuse as well as in a trouble-free presentation of our online presence that are overriding in the balancing of interests.
Google reCAPTCHA uses a code integrated into the website, a so-called JavaScript, as part of the verification methods that enable an analysis of your use of the website, such as cookies. The automatically collected information about your use of this website including your IP address is usually transmitted to a Google server in the USA and stored there. In addition, other cookies stored by Google services in your browser are evaluated by Google reCAPTCHA.
No personal data is read out or saved from the input fields of the respective form.
Where information is transmitted to and stored by Google on servers located in the United States, the U.S. company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
You can prevent Google from collecting the data generated by the JavaScript or the cookie and relating to your use of the website (including your IP address) and from processing this data by preventing the execution of JavaScripten or the setting of cookies in your browser settings. Please note that this may limit the functionality of our website for your use. Further information about data processing by Google can be found in Google’s privacy policy.
Google Fonts
This website contains the script code “Google Fonts”. Google Fonts is an offer from Google Ireland Limited, a company incorporated and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.com). This serves to protect our legitimate interests in a uniform presentation of the contents on our website in accordance with Art. 6 (1) 1 lit. f) GDPR.
This will establish a connection between the browser you are using and Google’s servers. This gives Google knowledge that our website has been accessed via your IP address.
Where information is transmitted to and stored by Google on servers located in the United States, the U.S. company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. As a result of this agreement between the US and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
Further information about data processing by Google can be found in Google’s privacy policy.
4. Social Media
Our online presence on Facebook, Twitter, Youtube, Instagram, Pinterest, Xing, LinkedIn
Our presence on social networks and platforms serves a better, active communication with our customers and interested parties. We inform there about our products and current special offers.
When you visit our websiteson social media, your data may be automatically collected and stored for market research and advertising purposes. So-called usage profiles are created from these data using pseudonyms. These can be used, for example, to place advertisements inside and outside the platforms that presumably correspond to your interests. For this purpose, cookies are usually used on your terminal. The visitor behaviour and the interests of the users are stored in these cookies. This serves in accordance with Art. 6 (1) 1 lit. f) GDPR to protect our legitimate interest in an optimised presentation of our offer and effective communication with customers and interested parties that are overriding in the balancing of interests. If you are asked by the respective social media platform operators for a consent into the data processing, e.g. with the help of a checkbox, the legal basis of data processing is Art. 6 (1) 1 lit. a) GDPR.
If the aforementioned social media platforms are headquartered in the USA, the following applies: The European Commission has adopted a decision on appropriateness for the USA. This goes back to the EU-US Privacy Shield. A current certificate for the respective company can be viewed here.
For detailed information on the processing and use of the data by the providers on their pages as well as a contact option and your rights and setting options for the protection of your privacy, in particular opt-out options, please refer to the providers’ data protection information linked below. If you still need help, you can contact us.
Facebook: https://www.facebook.com/about/privacy/
The data processing is based on an agreement between jointly responsible parties in accordance with Art. 26 GDPR, which you can view here.
Further information on data processing within the framework of visiting a Facebook fan page (information on Insights data) can be found here.
Google/ YouTube: https://policies.google.com/privacy?hl=en-GB
Twitter: https://twitter.com/en/privacy
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://about.pinterest.com/en/privacy-policy
LinkedIn: https://www.linkedin.com/legal/privacy-policy
Xing: https://privacy.xing.com/en/privacy-policy
Possibility to object (opt-out):
Facebook: https://www.facebook.com/settings?tab=ads
Google/ YouTube: https://adssettings.google.com/authenticated?hl=en-GB
Twitter: https://twitter.com/personalization
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://www.pinterest.co.uk/settings
LinkedIn: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
Xing: https://privacy.xing.com/en/privacy-policy/what-rights-can-you-assert/right-to-object
5. Contact possibilities and your rights
Being the data subject, you have the following rights according to:
- art. 15 GDPR, the right to obtain information about your personal data which we process, within the scope described therein;
- art. 16 GDPR, the right to immediately demand rectification of incorrect or completion of your personal data stored by us;
- art. 17 GDPR, the right to request erasure of your personal data stored with us, unless further processing is required
- to exercise the right of freedom of expression and information;
- for compliance with a legal obligation;
- for reasons of public interest or
- for establishing, exercising or defending legal claims;
- art. 18 GDPR, the right to request restriction of processing of your personal data, insofar as
- the accuracy of the data is contested by you;
- the processing is unlawful, but you refuse their erasure;
- we no longer need the data, but you need it to establish, exercise or defend legal claims, or
- you have lodged an objection to the processing in accordance with art. 21 GDPR;
- art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request its transmission to another controller;
- art. 77 GDPR, the right to complain to a supervisory authority . As a rule, you can contact the supervisory authority at your habitual place of residence or workplace or at our company headquarters.
If you have any questions about how we collect, process or use your personal data, want to enquire about, correct, restrict or delete your data, or withdraw any consents you have given, or opt-out of any particular data use, please contact us directly using the contact data provided in our site notice.
Right to object After you have exercised your right to object, we will no longer process your personal data for such purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. This does not apply to the processing of personal data for direct marketing purposes. In such a case we will no longer process your personal data for such purposes. |