Data Protection Declaration

 

A. General information

 

When you use this website, data is collected. This basically serves the use of the website and the use of the online shop or the payment process. However, the data may also be used to analyze user behavior.

 

We share this information with Squarespace Ireland Ltd. (Le Pole House, Ship Street Great Dublin 8, Ireland, hereafter “Squarespace”), our website hosting provider, so that they can provide website services to us.

In addition, information is shared with other companies if this is necessary for processing payments and analyzing data. When using plugins, data may also be transmitted.

 

You can find details in the following data protection declaration.

 

Responsible within the meaning of Art. 4. No. 7 GDPR is

 

CASSIDAH

Dipl.-Ing. Kathrin Boldt

Drosselstrasse 26

50858 Köln (Germany)

 

B. Data collection and processing

 

B.1. Data collection when visiting the website / functional cookies

 

When you access this website, your personal data can be processed in connection with the use of so-called "cookies". Cookies are text files that are stored on your device and are required for certain functions of this website. You can configure your browser settings according to your wishes and e.g. reject the acceptance of third-party cookies or all cookies. Depending on which cookies you deactivate, you may not be able to use all functions of this website. If you visit our website without further steps (without contacting us by email, creating a customer account or ordering), data will be collected from you via cookies. These are only data that are used to provide the website itself (“functional cookies”).

 

These are:

• IP address

• Date and time of the request

• Time zone difference to Greenwich Mean Time (GMT)

• Content of the request (specific page)

• Access status / HTTP status code

• Amount of data transferred in each case

• Website from which the request came

• Browser type or app used

• Operating system and its interface

• Language and version of the browser software

 

In connection with the use of functional cookies, we process your personal data in order to provide you with certain functions of this website.

 

We use the service provider Squarespace to operate the website.

 

We have concluded an order processing agreement with Squarespace in accordance with Art. 28 GDPR.

 

The processing of your personal data in connection with the use of functional cookies on this website is based on our legitimate interest.

 

We store your personal data as long as this is necessary for the use of the respective cookie.

 

Details on the type and storage duration of the respective functional and required cookies can be found here.

 

You can view Squarespace's Cookie Policy here.

 

B.2. Purchase and contract processing

 

The personal data that are used by us for the order, its processing, the delivery of the goods and, if necessary, subsequent returns and warranty processing can be seen from the respective input forms.

 

 

When you create a customer account on this website, we collect personal data in order to improve our payment process and our customer service.

This can include the following information:

• Your billing and delivery address (es)

• Details of your orders

• E-mail address

• Surname

• Telephone number

 

We use the payment service provider, Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin) to process payments. In the case of a payment, we transmit your data to Stripe Payments Europe, Ltd., which, as a service provider, compares your payment data with the respective credit institutions (Visa, Mastercard, etc.).

 

When paying by credit card, the following data is processed:

• Card type (American Express, Mastercard or VISA, Diner's Club, Apple Pay)

• Name of Cardholder

• Card number

• Check digit

• Period of validity

More information on data protection at Stripe Payments Europe Ltd. can be found under the following link: https://stripe.com/de/privacy

Your personal data will continue to be passed on to the service providers who are necessary to fulfill the purchase order. The following service providers come into question: credit institute, post office, transport company and logistician.

 

The processing of the data for the purposes of the purchase and shipping takes place on the basis of the contract concluded with you and on the basis of legal regulations.

 

As soon as the order has been processed, your data will be blocked for further use and deleted after the commercial and tax law periods have expired. Unless you have expressly consented to the further use of your data or we reserve the right to use data beyond this if it is legally compliant.

 

B.3. Newsletter - Email Marketing

 

You have the option of registering for our email newsletter. Either as part of the checkout process or via the newsletter window.

 

After registering for our newsletter, you will receive an email requesting you to expressly consent to the receipt of newsletters. This corresponds to the so-called double opt-in procedure. It should be avoided that third party email addresses are used to subscribe to the newsletter.

 

If you decide to subscribe to our newsletter, we will send you marketing emails, from which you can unsubscribe by clicking on the link at the end of the email. We, our email marketing provider, use Squarespace to send the newsletter. We pass on your data to them so that Squarespace can send these emails on our behalf.

 

We have concluded an order processing agreement with Squarespace in accordance with Art. 28 GDPR. You can view Squarespace's privacy policy at https://www.squarespace.com/privacy

 

The processing of your personal data in connection with the use of functional cookies on this website is based on your consent via the cookie banner.

 

We store your personal data for as long as is necessary for sending the newsletter or until you have unsubscribed from the newsletter.

 

 

B.4. Fonts

 

This website uses font files from Google Fonts and Adobe Fonts. In order to display this website correctly to you, servers on which the font files are stored may receive personal data about you. This includes:

• Information about your browser, network, or device

• your IP address

 

 

 

B5. Analysis tracking / Squarespace Analytics

 

This website collects usage data in anonymous form, which serves as the basis for analyzing the use of our website. For this we use the Squarespace Analytics service.

 

This includes:

 

• Information about your browser, your network and your device

• Web pages that you accessed before visiting this website

 

This information may also include details about your use of this website, including:

 

• Clicks

• Internal links

• Pages visited

• Scrolling

• Searches

•Time stamp

 

We use Squarespace Analytics cookies to gain insight into website traffic, website activity, and other data. Details on the type and storage duration of Squarespace's analytics and performance cookies can be found here.

 

The processing of the data for analysis purposes is based on your consent via the "OK" button on the cookie banner. If you do not click the "OK" button, no analytics cookies will be used.

You can view the cookie policy here.

 

B.6. Plugin from Instagram

 

This website features an Instagram icon, an audio-visual platform for sharing photos and videos (product of Facebook Inc., 471 Emerson St.

Palo Alto, CA 94301-160). This icon takes you to Cassidah's Instagram account.

If you use this plugin and have an account with Facebook or Instagram yourself, your IP address will be forwarded to Instagram or Facebook. If you do not want this, we ask you to log out of Facebook or Instagram before using the icon.

Information on the scope of the data collection as well as its processing and use and your related rights and setting options to protect your privacy can be found in Instagram's data protection information. You can find this data protection declaration under the following link: https://help.instagram.com/519522125107875

 

B.7. Google Maps

 

This site uses the Google Maps map service via an API. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

To use the functions of Google Maps it is necessary to save your IP address. This information is usually transferred to a Google server in the USA and saved there. The provider of this site has no influence on this data transfer.

Google Maps is used in the interest of an appealing presentation of our online offers and to make it easy to find the places we have indicated on the website. This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.

You can find more information on handling user data in Google's data protection declaration: https://policies.google.com/privacy?hl=en

 

C. Data security

In order to prevent misuse when using our website, it is secured by SSL certificates. Payment transactions that are carried out via the stripe payment platform are also protected with high security standards. You can find more information about the security standards at stripe at https://stripe.com/en-de/guides/pci-compliance

Furthermore, we take all possible measures to prevent misuse or theft of your data.

At this point, however, we have to point out that despite all precautionary measures, absolute security of data transfer (e.g. by email) is not possible.

 

D. Your privacy rights

 

Under certain conditions you can assert the following data protection rights against us:

• Right to revoke consent: If you have given your consent to certain types of processing activities, you can revoke this consent at any time with effect for the future. However, this revocation does not affect the lawfulness of the processing before the revocation of your consent or insofar as the processing is justified on another legal basis.

• Right to information: You have the right to receive information from us about your data stored by us in accordance with the rules of Art. 15 GDPR (possibly with restrictions under Section 34 BDSG).

• Right to correction: At your request, we will process the data stored about you in accordance with Correct Art. 16 GDPR if these are incorrect, incomplete or incorrect.

• Right to deletion: If you wish, we will delete your data in accordance with the principles of Art. 17 GDPR, provided that other legal regulations (e.g. statutory retention requirements or the restrictions according to § 35 BDSG) or an overriding interest on our part (e.g. . B. to defend our rights and claims) do not conflict with this.

• Right to restriction of processing: Taking into account the requirements of Art. 18 GDPR, you can request that the processing of your data be restricted

• Right to data portability: You also have the right to receive your data in accordance with the regulations of Art. 20 GDPR in a structured, commonly used and machine-readable format or to transfer it to a third party.

• Complaint to the data protection authority: You also have the right to lodge a complaint with any competent data protection supervisory authority (Art. 77 GDPR).

• Right to object: You have the right to object to the processing of your data at any time, based on Art. 6 Paragraph 1 f GDPR (data processing based on a balance of interests) or Art. 6 Paragraph 1 e GDPR (data processing in the public interest) takes place, to contradict, as far as the requirements for this are met. In the case of data processing of your personal data for the purposes of direct advertising, an objection is possible at any time without further requirements.

 

To exercise your rights, please send an email to info@cassidah.com

last updated on August 1rst, 2020