Privacy Information
1. Privacy Information
With this privacy policy, we inform you about the extent of the processing of your personal data (hereinafter only "data").2. Responsible for data processing
Responsible for data processing in accordance with the provisions of the General Data Protection Regulation (GDPR):- Lebkuchen-Schmidt GmbH & Co. KG
Zollhausstraße 30
90469 Nuremberg
Phone: + 49 (0) 911 - 89 66 0
Web: www.lebkuchen-schmidt.com
E-mail: service@lebkuchen-schmidt.com
3. Contact details of our data protection officer
4. Data processing
Within the scope of our website operation, we process data. This also includes disclosure by transfer to third parties and, if applicable, to so-called third countries outside the European Union ("EU") and the European Economic Area.
In the case of data transfers to the USA, there is an adequacy finding by the EU Commission, the so-called "EU-US Privacy Shield". Here, the EU Commission certifies that the guarantees for the transfer of data to the USA on the basis of the EU-US Privacy Shield comply with the data protection standards in the EU. If we transfer data to the USA, we have identified the participation of our service providers in the EU-US Privacy Shield.
The details of the data concerned, processing purposes, legal basis, recipients and transfers to third countries are listed below:
a) log file when visiting the website
We log your visit to our website. The following data are processed: Name of the website accessed, date and time of access, the amount of data transferred, the browser type and version, the operating system you are using, the referrer URL (the website previously visited), your IP address and the requesting provider. This is necessary to ensure the security of the website. We process the data accordingly on the basis of our legitimate interests in accordance with Art. 6 para. 1 f) GDPR, in order to guarantee the security of the website. The log file will be deleted after seven days, unless it is required for the clarification or proof of concrete violations of the law that have become known within the retention period.
b) Hosting
All data to be processed in connection with the operation of this website is stored as part of hosting. We process such data on the basis of our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR to enable the operation of the website. For the provision of our online presence, we use the services of web hosting providers to whom we transfer the above-mentioned data.
c) Making contact
If you contact us, your data (name, contact details, if provided by you) and your message will be processed exclusively for the purpose of processing and handling your request. This data will be processed by us on the basis of Art. 6 para. 1 b) GDPR for the purpose of fulfilling the contract and/or for the fulfilment of our pre-contractual obligations or on the basis of our legitimate interests in accordance with Art. 6 para. 1 f) GDPR for the purpose of processing your enquiry.
d) Contacting for applications
If you contact us in order to send us your application as an employee, e.g. by e-mail or via a contact form, your data (e.g. name, e-mail address, desired place of employment, if specified by you), your message and the application documents submitted will be processed exclusively for the purpose of processing and handling your application request. The legal basis for data processing is primarily § 26 BDSG. This allows the processing of data necessary for the decision to establish an employment relationship. Should the data be necessary for legal prosecution after the application procedure has been completed, data processing may be carried out to protect our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR, namely to assert and/or defend claims.
e) Newsletter
In order to provide you with regular information about our company and our offers, we offer the dispatch of a newsletter. With your newsletter registration, we process the data you enter (e-mail address and other voluntary information). The registration for the newsletter takes place in the so-called double opt-in procedure. To prevent misuse, we will send you an e-mail after your registration in which we ask you to confirm your registration. In order to be able to prove the registration process according to the legal requirements, your registration will be logged. The storage of the registration and confirmation time, as well as your IP address are affected.
The sending of the confirmation e-mail for your registration, as well as the associated data logging, is based on our legitimate interest in proof of your proper registration in accordance with Art. 6 para. 1 f) GDPR, the dispatch of the newsletter based on your consent in accordance with Art. 6 para. 1 a) GDPR.
To send the newsletter, we use service providers to whom we transfer the above mentioned data.
f) Catalogue order
We process your name and contact data for the processing of your requests in our catalogue. The processing of the data is carried out on the basis of Article 6(1)(b) of the GDPR as a pre-contractual measure. We transmit the data to the respective service provider or, in the case of catalogue orders, to the company commissioned with the delivery, in order to process your inquiries and orders.
g) Customer account
When you open a customer account, you agree that your inventory data (name, address, e-mail address, bank details) and your usage data (user name, password) are stored. This enables us to identify you as a customer and you have the possibility to manage your orders and assignments. The data processing is carried out on the basis of your consent in accordance with Art. 6 para. 1 a) GDPR.
h) Contract processing
We process your order data for processing the existing contractual relationship between you and us. The processing of the data is carried out accordingly on the basis of Art. 6 para. 1 b) GDPR. We transmit your address data to the company commissioned with the delivery. If necessary for the processing of the contract, we will also transmit your e-mail address or your telephone number to the company commissioned with the delivery in order to agree on a delivery date (notification). We use your data for our own marketing purposes, e.g. advertising for Lebkuchen, fine baked goods, other fine specialities and non-food articles, as well as for market research purposes such as opinion polls.
We transmit your transaction data (name, date of order, payment method, date of dispatch and/or receipt, amount and payee, bank details or credit card data, if applicable) to the payment service provider commissioned with the processing of the payment.
i) Rating reminder by e-mail
If you have activated the corresponding checkbox during or after your order or clicked the button provided for this purpose, we will process your e-mail address to send you a reminder to submit a rating of your order via our rating system. This processing is carried out on the basis of our legitimate interests in improving our services in accordance with Art. 6 Para. 1 f) GDPR
j) Credit check
When selecting the payment methods, invoice and direct debit, we will carry out a credit check. We transmit your name and address to a credit agency, which compares this data with its own database to check your creditworthiness. The credit agency then transmits the corresponding credit information to us. In the case of purchase on account, we process this data on the basis of our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR, as we make advance payment when the goods are dispatched and bear the risk of default. In all other cases, your data will be processed exclusively on the basis of your prior consent in accordance with Art. 6 para. 1 a) GDPR.
k) Userlike Chat
We use the Userlike chat on our website, the company Userlike UG. Deisterweg 7, D- 51109 Köln ("userlike"), to enable you to contact us via live chat. The integration of userlike is done on our site by means of a corresponding javascript. The following data is processed when using userlike: Content of the chat, date and time of the call, browser type/version, operating system used, URL of the previously visited website and amount of data sent. When using the Service, the chat is hosted on servers of AWS Cloudfront, the content delivery network of Amazon Web Services, Inc. 410 Terry Avenue North, Seattle WA 98109, USA and transfer your data. The data processing is carried out due to our predominant interest in the optimal marketing of our online offer in accordance with Art. 6 para. 1 f) GDPR.
Amazon Web Services is certified at:
https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4&status=Active
Further information on data protection at Amazon and userlike can be found at:
https://aws.amazon.com/de/compliance/data-privacy-faq/, https://www.userlike.com/de/terms#privacy-policy
l) Zendesk
On our website, we use the customer service platform Zendesk, of Zendesk Inc, 989 Market Street #300, San Francisco, CA 94102, USA ("Zendesk") to process customer inquiries. In order to process your request, data such as name, first name, postal address, telephone number, e-mail address will be processed and transmitted to Zendesk servers in the USA.
The data processing is carried out due to our predominant legitimate interest in the improvement of our services according to art.6 paragraph 1 f) GDPR.
Zendesk is certified under:
https://www.privacyshield.gov/participant?id=a2zt0000000TOjeAAG&status=Active
Further information on privacy can be found at:
https://www.zendesk.de/company/customers-partners/eu-data-protection/
m) Trusted Shops Buyer Protection
We have integrated the Trusted Shops buyer protection on our site. In order to determine whether you are already registered for Trusted Shops Buyer Protection, your e-mail address is hashed into a neutral parameter via a cryptological one-way function and transmitted to Trusted Shops. There an automated check for a match takes place. After checking for a match, the parameter is automatically deleted.
If you decide to use the Trusted Shops Buyer Protection after completing your order or if you are already registered for use, the following personal data will be automatically collected from your order data: Order date, order number, customer number, order amount, currency, delivery date if applicable, selected payment method and e-mail address. The data is transmitted to Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany. The data processing is carried out in order to provide the buyer protection linked to the specific order in accordance with Art.6 Para. 1 b) GDPR.
5. Cookies, website analysis and marketing
To enable the use of certain functions, we use so-called cookies. These are short data packets that are stored on your end device and exchanged with other providers. Some of the cookies we use are deleted immediately after closing your browser (so-called session cookies). Other cookies remain on your end device and make it possible to recognise your browser on your next visit (persistent cookies). Any data processing that is carried out on the basis of cookies, which are used solely to create the functionality of our website, is carried out on the basis of our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR.
You can delete all cookies stored on your terminal device and set the common browsers to prevent the storage of cookies.
In this case, you may have to change some settings each time you visit this website and you may have to accept the impairment of some functions.
We use other services in connection with the following functionalities:
a) Google Analytics
We use Google Analytics a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google uses certain cookies for this purpose. The information generated by the cookie about your use of this website (including your IP address) is transferred to a Google server in the USA and stored there. We use the stored information to evaluate your use of the website, to compile reports on website activities for the website operators and to provide further services associated with the use of the website. We process the data obtained in this way because of our overriding interest in the optimal marketing of our online offer in accordance with Art. 6 Para. 1 f) GDPR. Under no circumstances will Google link your IP address to other Google data.
Please note that this website uses Google Analytics with the extension "anonymizeIp()". This truncates IP addresses before sending them to a server in the USA. A direct personal reference in connection with the stored data is therefore generally excluded. Only in exceptional cases, is the full IP address transferred to a server in the USA and shortened there. You may opt out of future data collection at any time by using the Google Analytics opt-out browser add-on at http://tools.google.com/dlpage/gaoptout?hl=de or by clicking the following opt-out link: Google Analytics Opt-Out.
Please see the additional information about Google's use of data in the Google Partner Network at
http://www.google.com/intl/de/policies/privacy/partners/
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at:
https://policies.google.com/privacy?hl=de&gl=de
b) IntelliAd Webtracking
To analyse the effectiveness of online marketing measures and to enable performance-based remuneration of advertising partners, this website uses the web analytics service intelliAd, the web analytics service of intelliAd Media GmbH, Sendlinger Str. 7, 80331 Munich, Germany ("intelliAd"). IntelliAd uses cookies that process information such as page views, clicks on advertising, the achievement of goals set by us, and the truncated IP address of web site visitors. The data processing is carried out on the basis of our predominant legitimate interest in an optimal marketing of our offer in accordance with Art. 6 para. 1 f) GDPR.
First-party tracking - "First-party tracking" is used to improve tracking accuracy. A first-party cookie (ia- ) is set on the customer domain. Complete IP addresses are also not stored in the procedure and are only processed in anonymised form.
You can object to the data processing at any time with effect for the future by setting an opt-out cookie via the following link https://login.intelliad.com/optout.php. Please note that the link must be activated again if you delete the cookies in your browser.
c) Optimizely
In order to continuously improve our web offer, we use the web analysis service Optimizely, the Optimizely Inc. 631 Howard Street, Suite 100, San Francisco, CA 94105, USA. ("Optimizely"). Optimizely uses cookies. Optimizely uses cookies. These process information about the page accessed, the date and time of access, the referrer URL (the previously visited website), the browser used, the use of the website and your IP address. We point out that Optimizely is used on our website with IP anonymisation. This truncates IP addresses before sending them to a server in the USA. A direct personal reference in connection with the stored data is therefore generally excluded. Only in exceptional cases, is the full IP address transferred to a server in the USA and shortened there. The processing is carried out on the basis of our predominant legitimate interest in an optimal marketing of our offer in accordance with Art. 6 para. 1 f) GDPR.
Optimizely is certified under:
https://www.privacyshield.gov/participant?id=a2zt0000000TNkWAAW&status=Active
Further information on privacy can be found at:
https://www.optimizely.com/de/privacy/
You may object to the data processing by Optimizely at any time with effect for the future by setting an opt-out cookie via the following link: https://www.optimizely.com/opt_out. Please note that the link must be clicked again if you delete the cookies in your browser.
d) Scarabresearch
In order to evaluate our online marketing measures and to adapt our information and offers to the individual needs and interests of our users, we use the scarabresearch service of Emarsys eMarketing Systems AG, Märzstrasse 1, 1150 Vienna, Austria ("Scarabresearch"). Scarabresearch uses cookies. They process information about your surfing behaviour on our website and the success of certain marketing measures.
This data processing is carried out due to our predominant legitimate interest in an optimal marketing of our offer according to art. 6 para. 1 f) GDPR. You can object to the data collection at any time with effect for the future by either selecting your browser settings accordingly or by setting a so-called opt-out cookie. The storage of cookies can be deactivated in your browser under Tools/Internet Options or limited to certain websites. You can also set your browser to notify you when a cookie is sent. Please note that this may result in a limited presentation of the online offers. You can also deactivate the data processing at any time with effect for the future by clicking on the following opt-out link https://www.scarabresearch.com/privacy/#optout.
e) Pingdom
To ensure the functionality of our website we use the Pingdom monitoring service, provided by SolarWinds Worldwide LLC, 3711 South MoPac Expressway, Building Two, Austin, TX 78746, USA ("Pingdom"). Pingdom sets cookies. They process information on the loading behaviour and availability of the website as well as your computer name and your IP and e-mail address. The information generated by the cookie about your use of this website (including your IP address) is transferred to a Pingdom server in the USA and stored there. Data processing is carried out on the basis of our overwhelmingly justified interest in the error-free functioning of our website in accordance with Art. 6 Para. 1 f) GDPR.
You can prevent data processing at any time by adjusting your browser settings accordingly.
Pingdom is certified under:
https://www.privacyshield.gov/participant?id=a2zt00000008R6bAAE&status=Active
Further information on privacy can be found at:
https://www.solarwinds.com/legal/privacy
f) Criteo
In order to present you with advertisements relevant to you, we use on our website the service Criteo, of Criteo SA, Rue Blanche, 75009, Paris, France ("Criteo"). Criteo uses cookies. They process information about your viewed products and your surfing behaviour on our website. The cookie also stores a randomly generated identification number to which the information processed by the cookie is assigned. This data is not used to personally identify you as a visitor to our website. The data processing is carried out on the basis of our predominant legitimate interest in an optimal marketing of our offer in accordance with Art. 6 para. 1 f) GDPR.
You can object to the data collection at any time with effect for the future by either selecting your browser settings accordingly or by setting a so-called opt-out cookie. The storage of cookies can be deactivated in your browser under Tools/Internet Options or limited to certain websites. You can also set your browser to notify you when a cookie is sent. Please note that this may result in a limited presentation of the online offers. You can also deactivate data processing at any time with effect for the future by using the opt-out option contained in criteo's privacy policy:
https://www.criteo.com/de/privacy/.
g) Facebook Custom Audiences (Pixel/Cookies)
On our website we use a so-called tracking pixel of the Facebook Inc. 1601, Willow Road Menlo Park, CA 94025, USA. Here, a cookie is stored on your end device when you visit certain pages. The cookies remain permanently on your PC. Cookies are used to track which advertisements and pages of third parties are used to bring users to our website. This procedure serves to optimise our advertising by evaluating the statistical data that we receive through the cookies. The legal basis for data processing is your consent in accordance with Art. 6 para. 1 a) GDPR. The cookies do not serve to identify you personally. The data is anonymous to us and does not allow us to draw any conclusions about the user. The information generated by the cookie about your use of this website (including your IP address) is transferred to a Facebook server in the USA and stored there.
Facebook is certified at:
https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
You can find further information on data protection under:
https://www.facebook.com/help/568137493302217
You can revoke your consent at any time with effect for the future by clicking on the following opt-out link: Facebook Pixel Opt-Out
6. Integration of external content
We use dynamic content ("Content") from third parties in order to optimise the presentation and the offer of our website. When a website is visited, a request is automatically made to the server of the respective content provider via an application programming interface ("API"), in which certain log data (e.g. the user's IP address) is transmitted. The dynamic content is then transmitted to our website and displayed there.
We use external content in connection with the following functionalities:
a) Integration of YouTube videos
We have on our website videos of the portal YouTube of YouTube LLC, 901 Cherry Ave. San Bruno, CA 94066, USA ('YouTube'). When the videos are played, log data is transmitted to the servers of YouTube in the USA. This processing takes place due to our predominant legitimate interest in an optimal marketing of our offer according to Art. 6 para. 1 f) GDPR.
YouTube is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information under:
https://policies.google.com/privacy?hl=de&gl=de
b) Google Maps
On our website we use the map service "Google Maps" from Google to provide you with an interactive map. When the map is displayed, data, including your IP address and your location, are transmitted to Google servers in the USA and stored there. This processing takes place due to our predominant legitimate interest in an optimal marketing of our offer according to Art. 6 para. 1 f) GDPR.
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at:
https://policies.google.com/privacy?hl=de&gl=de
c) Google Fonts
To make the visit of our website attractive we use external fonts from Google-Fonts. These are loaded during your visit to the Site from servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google does not store cookies in your browser. According to our information, however, the IP address of the user's terminal device is transmitted to Google and stored. This processing takes place due to our predominant legitimate interest in an optimal marketing of our offer according to Art. 6 para. 1 f) GDPR.
Google is certified under:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
Further information on data protection can be found at:
https://policies.google.com/privacy?hl=de&gl=de
d) Quality seal
We have integrated a quality seal from Trusted Shops ("Trustbadge") on our website. The trust badge and the services advertised with it are an offer of the Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne (hereinafter "Trusted Shops"). The Trusted Shops quality seal is displayed with the help of a CDN provider. Trusted Shops also uses service providers from the USA for this purpose; an appropriate level of privacy is ensured.
When the trust badge is called up, your IP address, date and time of the call, transferred data volume and the requesting provider (access data) are transferred to the servers of the CDN provider. Here, individual access data is stored in a security database for the analysis of security incidents. The remaining data will be deleted after 90 days at the latest. The data will be transferred due to our predominant legitimate interest in the best possible marketing of our offer by enabling secure shopping in accordance with Art. 6 para. 1 f) GDPR. You can find further information on data protection at Trusted Shops at https://shop.trustedshops.com/de/datenschutz
7. Duration of data storage
Wir speichern personenbezogene Daten nur so lange, wie es für die Zwecke, für die sie verarbeitet werde erforderlich ist oder eine von Ihnen erteilte Einwilligung von Ihnen widerrufen wurde. Soweit gesetzliche Aufbewahrungspflichten zu beachten sind, kann die Speicherdauer zu bestimmten Daten ungeachtet der Verarbeitungszwecke bis zu 10 Jahre betragen.
8. Your rights as a data subject
a) information
Upon request, you will receive information free of charge at any time about all personal data that we have stored about you.
b) rectification, erasure, limitation of processing (blocking), opposition
If you no longer agree to the storage of your personal data or if the data has become incorrect, we will, upon your instruction, arrange for the deletion or blocking of your data or make the necessary corrections (as far as this is possible under the applicable law). The same applies if we are to process data in the future only to a limited extent. You have a right of objection in particular in those cases in which your data is required for the performance of a task that is in the public interest or in our legitimate interest, as well as profiling based on this data. You also have such a right of objection in the case of data processing for the purpose of direct marketing.
c) Data transferability
Upon request, we will provide you with your data in a common, structured and machine-readable format, so that you can transfer the data to another responsible person if you wish.
d) Cancellation right in case of consents with effect for the future
You may revoke any consent you have given at any time with effect for the future. Your revocation does not affect the lawfulness of the processing until the date of revocation.
e) Right of complaint
You also have the possibility to complain to a supervisory authority about your rights as a data subject:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
f) Restrictions
Data, where we are not able to identify the data subject, e.g. if they have been anonymised for analysis purposes, are not covered by the above rights. Information, deletion, blocking, correction or transfer to another company may be possible in relation to this data if you provide us with additional information that allows us to identify you.
9. Exercise of your rights as a data subject
If you have any questions regarding the processing of your personal data, for information, correction, blocking, objection or deletion of data or the wish to transfer the data to another company, please contact datenschutz@lebkuchen-schmidt.com.