top of page

data protection

The person responsible within the meaning of the General Data Protection Regulation ("DSVGO")  is:

Miss Lotti

Anna Bauer

Jahnstrasse 3/1

89233 Neu-Ulm

kontakt@fraeuleinlotti.com

 

1) Information about the collection of personal data and contact details of the person responsible

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following we will inform you about the handling of your personal data when using our website. Personal data are all data with which you can be personally identified.
1.2 Is the person responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR)

Anna Bauer

Jahnstrasse 3/1

89233 Neu-Ulm

kontakt@fraeuleinlotti.com.

The person responsible for processing personal data is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the person responsible), this website uses an SSL or. TLS encryption. You can recognize an encrypted connection by the character string "https: //" and the lock symbol in your browser line.

2) Data collection when you visit our website
If you only use our website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the time of access
- Amount of data sent in bytes
- Source / reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymous form)
The processing takes place in accordance with Art. 6 Para. 1 lit.f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.

3) hosting
We use 1 & 1, Telecommunication SE, Elgendorfer Str. 57 for hosting and displaying the online shop based on processing on our behalf.

4) contact
When you contact us (e.g. using the contact form or email), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. These data are stored and used exclusively for the purpose of answering your request or for establishing contact and the associated technical administration. The legal basis for processing this data is our legitimate interest in answering your request in accordance with Art. 6 Para. 1 lit.f GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted after your request has been processed. This is the case if it can be inferred from the circumstances that the matter in question has been finally clarified and provided that there are no statutory retention requirements.

5) Data processing when opening a customer account and for contract processing
In accordance with Article 6 (1) (b) GDPR, personal data will continue to be collected and processed if you provide them to us for the execution of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. A deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. We save and use the data you provide to process the contract. After the contract has been fully processed or your customer account has been deleted, your data will be blocked with due regard to tax and commercial retention periods and deleted after these periods have expired, unless you have expressly consented to further use of your data or we reserve the right to further use your data as permitted by law became.

6) Use of single sign-on procedures
6.1 Facebook Connect
On our website you can create a customer account or register using the social plug-in "Facebook Connect" from the Facebook social network operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2, Ireland (" Facebook ”), if you have a Facebook profile, register using the so-called single sign-on technology. You can recognize the "Facebook Connect" social plugins on our website by the blue button with the Facebook logo and the label "Log in with Facebook" or "Connect with Facebook" or "Log in with Facebook" or "Sign in with." Facebook ".
When you call up a page on our website that contains such a plugin, your browser establishes a direct connection to the Facebook servers. The content of the plugin is transmitted directly from Facebook to your browser and integrated into the page. Through this integration, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged into Facebook. This information (including your IP address) is sent directly from your browser to a Facebook Inc. server in the USA and stored there. These data processing operations are carried out in accordance with Article 6 (1) (f) GDPR on the basis of Facebook's legitimate interest in displaying personalized advertising based on your surfing behavior.
By using this “Facebook Connect” button on our website, you also have the option of logging in or registering on our website using your Facebook user data. Only if you give your express consent in accordance with Art. 6 Para. 1 lit. Depending on your personal data protection settings on Facebook, the general and publicly accessible information stored in your profile. This information includes user ID, name, profile picture, age and gender.
We would like to point out that following changes to Facebook's data protection conditions and terms of use, if you give your consent, your profile pictures, the user IDs of your friends and the friends list may also be transferred if this is marked as "public" in your privacy settings on Facebook became. The data transmitted by Facebook will be stored and processed by us to create a user account with the necessary data (title, first name, last name, address data, country, email address, date of birth), if you have approved them on Facebook. Conversely, on the basis of your consent, we can transfer data (e.g. information on your surfing or purchasing behavior) to your Facebook profile.
The consent given can be revoked at any time by sending a message to the person responsible named at the beginning of this data protection declaration.
The purpose and scope of the data collection and the further processing and use of the data by Facebook as well as your related rights and setting options to protect your privacy can be found in Facebook's data protection information: https://www.facebook.com/policy.php
If you do not want Facebook to assign the data collected via our website directly to your Facebook profile, you must log out of Facebook before visiting our website. You can also completely prevent the Facebook plugins from loading with add-ons for your browser, eg with "Adblock Plus" (https://adblockplus.org/de/).
6.2 Google Sign-In
On our website you can log in to create a customer account or to register using the “Google Sign-In” service from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”) as part of the so-called Register for Single Sign On technology if you have a Google profile. You can recognize the Google login function on our website by clicking the button “Log in with Google”, “Log in with a Google account” or “Log in with Google”.
When you call up a page on our website that contains a Google login function, your browser establishes a direct connection to the Google servers. The content of the registration button is transmitted directly from Google to your browser and integrated into the page. Through this integration, Google receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Google profile or are not currently logged into Google. This information (including your IP address) is transmitted directly from your browser to a Google server and stored there; it can also be transmitted to the Google LLC server. come in the US. These data processing operations are carried out in accordance with Article 6 (1) (f) GDPR on the basis of Google's legitimate interest in displaying personalized advertising based on surfing behavior.
By using the Google login button on our website, you also have the option of logging in or registering on our website using your Google user data. Only if you give your express consent in accordance with Art. 6 Para. 1 lit. Personally made data protection settings on Google, the general and publicly accessible information stored in your profile. This information includes user ID, name, profile picture, age and gender.
We would like to point out that after changes to Google's data protection conditions and terms of use, if you give your consent, your profile pictures, the user IDs of your friends and the friends list may also be transferred if this is marked as "public" in your privacy settings on Google became. The data transmitted by Google will be saved and processed by us to create a user account with the necessary data (title, first name, last name, address data, country, email address, date of birth), if you have given Google permission to do so. Conversely, on the basis of your consent, we can transfer data (e.g. information on your surfing or purchasing behavior) to your Google profile.
The consent given can be revoked at any time by sending a message to the person responsible named at the beginning of this data protection declaration.
The purpose and scope of the data collection and the further processing and use of the data by Google as well as your related rights and setting options to protect your privacy can be found in Google's data protection information: https://policies.google.com/privacy?hl=de&gl=de
The terms of use for the use of “Google Sign-In” can be viewed here: https://policies.google.com/terms
If you do not want Google to directly assign the data collected via our website to your Google profile, you must log out of Google before visiting our website. You can also completely prevent the Google plugins from loading with add-ons for your browser, eg with "Adblock Plus" (https://adblockplus.org/de/).

7) Use of customer data for direct mail
7.1 Registration for our e-mail newsletter
If you register for our e-mail newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. The provision of further data is voluntary and is used in order to be able to address you personally. We use the so-called double opt-in procedure to send the newsletter. This means that we will only send you an e-mail newsletter if you have expressly confirmed to us that you consent to receiving the newsletter. We will then send you a confirmation email asking you to click on a link to confirm that you want to receive the newsletter in the future.
By activating the confirmation link, you give us your consent to the use of your personal data in accordance with Article 6 (1) (a) GDPR. When you register for the newsletter, we save your IP address entered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your e-mail address at a later point in time. The data collected by us when registering for the newsletter are used exclusively for the purpose of advertising via the newsletter. You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a message to the person responsible mentioned above. After you have unsubscribed, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we will inform you in this declaration.

8) Data processing for order processing
8.1 To process your order, we work together with the following service provider (s) who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
The personal data collected by us will be passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the delivery of the goods. We will pass on your payment data to the commissioned credit institution as part of the payment processing, if this is necessary for the payment processing. If payment service providers are used, we will explicitly inform you about this below. The legal basis for the transfer of data is Art. 6 Paragraph 1 lit. b GDPR.
8.2 In order to fulfill our contractual obligations towards our customers, we work together with external shipping partners. We will pass on your name and delivery address and, if necessary for delivery, your telephone number, exclusively for the purpose of delivery of goods, Article 6 (1) (b) GDPR, to a shipping partner selected by us.
8.3 Transfer of personal data to shipping service providers
- German postal service
If the goods are delivered by Deutsche Post (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn), we will give your email address in accordance with Article 6 (1) (a) GDPR prior to delivery of the goods to Deutsche Post for the purpose of agreeing a delivery date or to announce the delivery, provided that you have given your express consent for this in the ordering process. Otherwise, we will only pass on the name of the recipient and the delivery address to Deutsche Post for the purpose of delivery in accordance with Article 6 (1) (b) GDPR. The transfer takes place only as far as this is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with Deutsche Post or the delivery notification is not possible.
The consent can be revoked at any time with effect for the future vis-à-vis the person in charge named above or vis-à-vis Deutsche Post.
- DHL
If the goods are delivered by the transport service provider DHL (DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn), we will give your e-mail address in accordance with Article 6 (1) (a) GDPR before the goods are delivered for the purpose of coordination of a delivery date or delivery notification to DHL, provided that you have given your express consent for this in the ordering process. Otherwise, we will only pass on the name of the recipient and the delivery address to DHL for the purpose of delivery in accordance with Article 6 (1) (b) GDPR. The transfer takes place only as far as this is necessary for the delivery of the goods. In this case, prior coordination of the delivery date with DHL or the delivery notification is not possible.
The consent can be revoked at any time with effect for the future vis-à-vis the above-mentioned person responsible or vis-à-vis the transport service provider DHL.
9.4 Use of payment service providers (payment services)
- Klarna
If a Klarna payment service is selected, the payment will be processed by Klarna Bank AB (publ) [https://www.klarna.com/de], Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). In order to enable the processing of the payment, your personal data (first and last name, street, house number, zip code, city, gender, e-mail address, telephone number and IP address) as well as data related to the order (e.g. invoice amount, article, type of delivery) passed on to Klarna for the purpose of the identity and credit check, provided that you have expressly consented to this in accordance with Art. 6 Para. 1 lit. a GDPR as part of the ordering process. You can see here which credit agencies your data can be forwarded to:
https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies
The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. Klarna uses the information received about the statistical probability of a payment default for a balanced decision on the establishment, implementation or termination of the contractual relationship.
You can revoke your consent at any time by sending a message to the person responsible for data processing or to Klarna. However, Klarna may still be entitled to process your personal data if this is necessary for contractual payment processing.
Your personal details are processed in accordance with the applicable data protection regulations and in accordance with the information in Klarna’s data protection regulations for data subjects based in Germany https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy
or for data subjects based in Austria https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy
treated.
- Paypal
When paying via PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment in installments" via PayPal, we give your payment data to PayPal (Europe) Sarl et Cie, SCA, 22- 24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"), continue. The transfer takes place in accordance with Art. 6 Para. 1 lit. b GDPR and only insofar as this is necessary for payment processing.
PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment in installments" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Article 6 (1) (f) GDPR on the basis of PayPal's legitimate interest in determining your solvency. PayPal uses the result of the credit check with regard to the statistical probability of default for the purpose of deciding on the provision of the respective payment method. The credit report can contain probability values (so-called score values). As far as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. Further data protection information, including the credit agencies used, can be found in PayPal's data protection declaration: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
- Wix Payments

- Giropay

9) rights of the data subject
9.1 The applicable data protection law grants you comprehensive rights of data subjects (information and intervention rights) vis-à-vis the person responsible with regard to the processing of your personal data, about which we will inform you below:
- Right to information in accordance with Art. 15 GDPR: In particular, you have a right to information about your personal data processed by us, the processing purposes, the categories of personal data processed, the recipients or categories of recipients to whom your data has been or will be disclosed Planned storage period or the criteria for determining the storage period, the existence of a right to correction, deletion, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if we did not collect it from you, the existence of automated decision-making including profiling and, if necessary, meaningful information about the logic involved and the scope and the intended effects of such processing, as well as your right to be informed about the guarantees in accordance with Art. 46 GDPR when your data is forwarded in Third countries exist;
- Right to correction in accordance with Art. 16 GDPR: You have the right to immediate correction of incorrect data concerning you and / or completion of your incomplete data stored by us;
- Right to deletion in accordance with Art. 17 GDPR: You have the right to request the deletion of your personal data if the requirements of Art. 17 Paragraph 1 GDPR are met. However, this right does not exist in particular if the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
- Right to restriction of processing in accordance with Art. 18 GDPR: You have the right to request that the processing of your personal data be restricted as long as the correctness of your data is checked, if you refuse to delete your data due to inadmissible data processing and instead Request the restriction of the processing of your data if you need your data to assert, exercise or defend legal claims after we no longer need this data after the purpose has been achieved or if you have objected to reasons of your particular situation, as long as it is not yet clear whether ours legitimate reasons prevail;
- Right to information in accordance with Art. 19 GDPR: If you have asserted the right to correct, delete or restrict processing against the person responsible, the person responsible is obliged to correct or delete the data to all recipients to whom the personal data relating to you has been disclosed or restriction of processing, unless this proves to be impossible or involves a disproportionate effort. You have the right to be informed about these recipients.
- Right to data portability in accordance with Art. 20 GDPR: You have the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another person responsible, insofar as this is technically feasible ;
- Right to revoke consent given in accordance with Art. 7 Paragraph 3 GDPR: You have the right to revoke your consent to the processing of data at any time with effect for the future. In the event of revocation, we will delete the data concerned immediately, unless further processing can be based on a legal basis for processing without consent. Withdrawing your consent does not affect the legality of the processing carried out on the basis of your consent up to the point of withdrawal;
- Right to lodge a complaint in accordance with Art. 77 GDPR: If you are of the opinion that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, without prejudice to any other administrative or judicial remedy the Member State of your place of residence, your place of work or the place of the alleged infringement.
9.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR MAINLY LEGITIMATE INTEREST IN THE CONTEXT OF A WEIGHING OF INTERESTS, YOU HAVE THE EVERY TIME TO PROCESS YOUR PERSONAL DATA, FOR REASONS THAT WE GIVE UPON YOUR SPECIFIC SITUATION.
IF YOU MAKE USE OF YOUR RIGHT TO OBJECT, WE WILL END THE PROCESSING OF THE DATA CONCERNED. FURTHER PROCESSING IS RESERVED IF WE CAN PROVE COMPULSORY REASONS FOR THE PROCESSING, THAT OUTSIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS OR IF THE PROCESSING OR EXPRESSION OF THE EXPRESSION APPLIES.
IF YOUR PERSONAL DATA ARE PROCESSED BY US FOR DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING. YOU MAY OBJECTIVE AS DESCRIBED ABOVE.
IF YOU MAKE USE OF YOUR RIGHT TO OBJECT, WE WILL END THE PROCESSING OF THE DATA CONCERNED FOR DIRECT ADVERTISING PURPOSES.

10) Duration of storage of personal data
The duration of the storage of personal data is based on the respective legal basis, the processing purpose and - if relevant - additionally based on the respective statutory retention period (e.g. commercial and tax retention periods).
When processing personal data on the basis of express consent in accordance with Article 6 (1) (a) GDPR, this data is stored until the person concerned revokes his or her consent.
If there are statutory retention periods for data that are processed in the context of legal or similar obligations on the basis of Art. 6 Paragraph 1 lit. and / or we have no legitimate interest in further storage.
When processing personal data on the basis of Art. 6 Paragraph 1 lit. prove for the processing that the interests, rights and freedoms of the data subject outweigh, or the processing serves to assert, exercise or defend legal claims.
When processing personal data for the purpose of direct advertising on the basis of Art. 6 Para. 1 lit.
Unless otherwise stated in the other information in this declaration about specific processing situations, stored personal data will otherwise be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.

 

11) Google Analytics

We use the web analysis service Google Analytics (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) for this website.
Google Analytics uses cookies ". These are text files that are stored on your computer and that enable your use of the website to be analyzed.


If you have given your consent, Google Analytics, a web analysis service provided by Google LLC, is used on this website. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

Scope of processing
Google Analytics uses cookies that enable your use of our website to be analyzed. The information collected by the cookies about your use of this website is usually transferred to a Google server in the USA and stored there.

We use the 'anonymizeIP' function (so-called IP masking): Due to the activation of IP anonymization on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. The full IP address will only be transmitted to a Google server in the USA and shortened there in exceptional cases. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

During your visit to the website, the following data is recorded:

  • the pages you have visited, your "click path"

  • Achievement of "website goals" (conversions, e.g. newsletter registrations, downloads, purchases)

  • Your user behavior (e.g. clicks, length of stay, bounce rates)

  • Your approximate location (region)

  • Your IP address (in abbreviated form)

  • technical information about your browser and the end devices you use (e.g. language setting, screen resolution)

  • Your internet provider

  • the referrer URL (via which website / via which advertising material you came to this website)

Purposes of processing
The recipient of the data is

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

as a processor. We have concluded an order processing contract with Google for this purpose. Google LLC, based in California, USA, and, if applicable, US authorities, can access the data stored by Google.

Transfer to third countries
A transmission of data to the USA cannot be ruled out.

Storage period
The data sent by us and linked to cookies is automatically deleted after 14 months. The deletion of data whose retention period has expired takes place automatically once a month.

You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google.

You can also prevent the storage of cookies by setting your browser software accordingly. However, if you configure your browser so that all cookies are rejected, functionality on this and other websites may be restricted.

Legal basis and possibility of revocation
Your consent is required for this data processing, Article 6 Paragraph 1 Sentence 1 Letter a GDPR . You can revoke your consent at any time with effect for the future by calling up the cookie settings and changing your selection there.

You can find more information on the terms of use of Google Analytics and data protection at Google at https://marketingplatform.google.com/about/analytics/terms/de/ and at https://policies.google.com/?hl=de .

12)  Cookies

Our website uses so-called cookies. These are small text files that are stored on your device with the help of the browser. They do no harm.

We use cookies to make our offer user-friendly. Some cookies remain stored on your device until you delete them. They enable us to recognize your browser the next time you visit.

If you do not want this, you can set up your browser so that it informs you about the setting of cookies and you only allow this in individual cases.

Deactivating cookies may restrict the functionality of our website.

bottom of page