Aufgrund des hohen Bestellaufkommens verlängert sich die Lieferzeit für Massvorhänge. Vielen Dank für dein Verständnis!

Verzögerte Lieferzeit für Massvorhänge.

Browse our shop

Data protection

Privacy Policy Vorhangschweiz.ch, by STOTZ DECOR AG

As of September 2024

Table of contents

A........... Cross-channel information. 2

1............ Responsible party and content of this privacy policy. 2

2............ Contact person for data protection. 2

3............ Your rights. 2

4............ Data security . 3

5............ Contact us. 3

6............ Use of your data for marketing purposes. 4

6.1......... Central data storage and analysis in the CRM system.. 4

6.2......... Email Marketing and Newsletters 4

7............ Disclosure to third parties and access by third parties 5

8............ Transfer of personal data abroad. 6

9............ Retention periods. 6

B........... Special notes for our website. 6

10.......... Log file data. 6

11.......... Cookies. 7

12.........Google SiteSearch / Google Custom Search Engine. 8

13.......... Tracking and web analytics tools. 8

13.1....... General information on tracking. 8

13.2.......Google Analytics. 9

14.......... Social Media. 9

14.1....... Social media profiles. 9

14.2.......Social media plugins. 10

15.......... Online advertising and targeting. 11

15.1....... In general. 11

15.2....... Google Ads. 12

16.......... Using our chat function. 12

17.......... Registration for a customer account. 12

18.......... Ordering products. 13

19.......... Online payment processing. 14

20.......... Submitting ratings. 14

C........... Special instructions for our store 15

21.......... Video surveillance. 15

22.......... Use of our WiFi network. 15

23.......... Opening a customer account. 16

24.......... Purchase or ordering of products in the store 16

25.......... Payment processing. 17

26.......... Use of customer services in the store 17


 

Cross-channel information

1. Responsible party and content of this privacy policy

We, STOTZ DECOR AG, Stationsstrasse 9 A, 8906 Bonstetten, Switzerland, are the operator of the Vorhangschweiz.ch business premises ("business premises") and the website www.vorhangschweiz.ch (hereinafter "website") and, unless otherwise stated, are responsible for the data processing described in this privacy policy.

To ensure you are aware of what personal data we collect from you and for what purposes we use it, please take note of the information below. Our data protection practices are primarily based on the legal requirements of Swiss data protection law, in particular the Federal Act on Data Protection (FADP).

Please note that the following information is reviewed and amended from time to time. We therefore recommend that you check this privacy policy regularly. Furthermore, other companies are responsible under data protection law for some of the data processing activities listed below, or are jointly responsible with us, so in these cases the information provided by these providers is also applicable.

2. Contact person for data protection

If you have any questions about data protection or wish to exercise your rights, please contact our data protection officer by sending an email to the following address:

info@vorhangschweiz.ch

3. Your rights

Provided the legal requirements are met, you, as a data subject, have the following rights:

Right to information : You have the right to request access to your personal data stored by us at any time and free of charge, if we process it. This allows you to check which personal data we process about you and that we use it in accordance with applicable data protection regulations.

 

Right to rectification : You have the right to have inaccurate or incomplete personal data corrected and to be informed of the correction. In this case, we will inform the recipients of the data concerned about the corrections made, unless this proves impossible or involves disproportionate effort.

 

Right to erasure : You have the right to have your personal data erased under certain circumstances. In individual cases, particularly where statutory retention obligations apply, the right to erasure may be excluded. In such cases, and if the necessary conditions are met, the data may be blocked instead of erased.

 

Right to restriction of processing : You have the right to request that the processing of your personal data be restricted.

 

Right to data portability : You have the right to receive from us, free of charge, the personal data you have provided to us in a readable format.

 

Right to object : You can object to data processing at any time, in particular for data processing in connection with direct marketing (e.g. advertising emails).

 

Right of withdrawal: You generally have the right to withdraw your consent at any time. However, processing activities carried out in the past based on your consent do not become unlawful as a result of your withdrawal.

To exercise these rights, please send us an email to the following address:

info@vorhangschweiz.ch

Right to lodge a complaint : You have the right to lodge a complaint with a competent supervisory authority, e.g. against the way in which your personal data is processed.

4. Data security

We employ appropriate technical and organizational security measures to protect your personal data stored with us against loss and unlawful processing, in particular unauthorized access by third parties. Our employees and the service providers we commission are bound by confidentiality agreements and are obligated to maintain data protection. Furthermore, these individuals are only granted access to personal data to the extent necessary for the performance of their duties.

Our security measures are continuously adapted to technological developments. However, the transmission of information via the internet and electronic communication channels always carries certain security risks, and we cannot offer an absolute guarantee for the security of information transmitted in this way.

5. Contacting us

When you contact us via our contact addresses and channels (e.g., email, telephone, or contact form), your personal data will be processed. The data processed includes the information you provide, such as your company name, your name, your job title, your email address or telephone number, and your inquiry. The date and time of receipt of your inquiry will also be recorded. Required fields in contact forms are marked with an asterisk (*).

We process this data exclusively to fulfill your request (e.g. providing information about a product, support with contract processing such as product returns, incorporating your feedback into improving our service, etc.).

6. Use of your data for marketing purposes

6.1 Central data storage and analysis in the CRM system

Provided that a clear association with your identity is possible, we will store and link the data described in this privacy policy, i.e., in particular your personal details, your contact information, your contract data, and your browsing behavior on our websites, in a central database. This serves the purpose of efficiently managing customer data, allows us to respond appropriately to your requests, and enables the efficient provision of the services you have requested and the processing of the associated contracts.

We analyze this data to further develop our offerings in a needs-oriented way and to show and suggest the most relevant information and offers to you. We also use methods that predict potential interests and future orders based on your website usage.

6.2 Email marketing and newsletters

When you register for our email newsletter (e.g., when creating an account or within your customer account), the following data will be collected. Required fields are marked with an asterisk (*) in the registration form:

  • E-mail address
  • Salutation
  • First and Last Name

To prevent misuse and ensure that the owner of an email address has actually given their consent, we use the so-called double opt-in process for registration. After submitting your registration, you will receive an email from us containing a confirmation link. To definitively subscribe to the newsletter, you must click this link. If you do not click the confirmation link within the specified period, your data will be deleted and our newsletter will not be delivered to that address.

By registering, you consent to the processing of this data in order to receive messages from us about our company, our curtain fabric offers, and related products and services. This may also include invitations to participate in competitions or to review any of the aforementioned products and services. Collecting your title and name allows us to verify the registration's connection to any existing customer account and to personalize the email content. Linking your registration to a customer account helps us make the offers and content in the newsletter more relevant to you and better tailored to your potential needs.

We use your data for sending emails until you withdraw your consent. You can withdraw your consent at any time, in particular via the unsubscribe link in all our marketing emails.

Our marketing emails may contain a so-called web beacon or 1x1 pixel (tracking pixel) or similar technical tools. A web beacon is an invisible graphic linked to the user ID of the respective newsletter subscriber. For each marketing email sent, we receive information about which addresses have not yet received the email, which addresses it was sent to, and which addresses experienced delivery failures. We also see which addresses opened the email, for how long, and which links they clicked. Finally, we also receive information about which addresses have unsubscribed. We use this data for statistical purposes and to optimize our promotional emails in terms of frequency, timing, structure, and content. This allows us to better tailor the information and offers in our emails to the individual interests of the recipients.

The web beacon is deleted when you delete the email. To prevent the use of the web beacon in our marketing emails, please configure your email program to block HTML from being displayed in messages, if this is not already the default setting. Refer to your email software's help section for instructions on how to configure this setting; for example, here for Microsoft Outlook.

By subscribing to the newsletter, you also consent to the statistical evaluation of user behavior for the purpose of optimizing and adapting the newsletter.

We use the email marketing software Klaviyo from Klaviyo, 49 Southwark Bridge Rd

London SE1 9HH, UK for marketing emails. Therefore, your data will be stored in a Klaviyo database, which allows Klaviyo to access your data when necessary for providing and supporting the use of the software.

7. Disclosure to third parties and access by third parties

Without the support of other companies, we would not be able to provide our services in the desired form. In order for us to utilize the services of these companies, it is necessary to share your personal data to a certain extent. Such sharing occurs specifically to the extent necessary for fulfilling the contract you have requested, i.e., for example, with the logistics or transport companies that deliver the products you have ordered, or with a manufacturer who is responsible for fulfilling your warranty claim.

Data is also shared with selected service providers, but only to the extent necessary for providing the service. Several third-party service providers are already explicitly mentioned in this privacy policy, for example, in the sections on marketing. These include, for example, IT service providers (such as software solution providers), advertising agencies, and consulting firms.

Furthermore, your data may be disclosed, in particular to authorities, legal advisors, or debt collection agencies, if we are legally obligated to do so or if this is necessary to protect our rights, especially to enforce claims arising from our relationship with you. Data may also be disclosed if another company intends to acquire our company or parts thereof, and such disclosure is necessary for conducting due diligence or for completing the transaction.

8. Transfer of personal data abroad

We are entitled to transfer your personal data to third parties abroad if this is necessary for carrying out the data processing activities described in this privacy policy (see in particular sections 12-15). We will, of course, comply with all applicable legal regulations regarding the disclosure of personal data to third parties. If the country in question does not have an adequate level of data protection, we ensure through contractual agreements that your data is adequately protected by these companies.

9. Retention periods

We store personal data only as long as necessary to carry out the processing activities described in this privacy policy, based on our legitimate interests. For contract data, storage is mandated by statutory retention obligations. Requirements that obligate us to retain data arise from accounting and tax regulations. According to these regulations, business correspondence, concluded contracts, and accounting documents, in particular, must be retained for up to 10 years. If we no longer require this data to provide services to you, the data will be restricted. This means that the data may then only be used if necessary to fulfill retention obligations or to defend and enforce our legal interests. Data will be deleted as soon as there is no longer a legal obligation to retain it or a legitimate interest in its continued storage.

  1. Special notes for our website

10. Log file data

When you visit our website, the servers of our hosting provider, shopify Commerce Singapore Pte. Ltd., Attn: Data Protection Officer, 77 Robinson Road, #13-00 Robinson 77, Singapore 068896, temporarily store each access in a log file. The following data is collected automatically without your intervention and stored by us until its automated deletion:

  • the IP address of the requesting computer,
  • the date and time of access,
  • the name and URL of the retrieved file,
  • the website from which the access was made, with the search term used,
  • your computer's operating system and the browser you are using (including type, version and language settings),
  • Device type in case of access via mobile phones,
  • the city or region from which the access was made,
  • The name of your internet access provider.

The collection and processing of this data is carried out for the purpose of enabling the use of our website (establishing a connection), ensuring the long-term security and stability of the system, as well as for error and performance analysis, and allows us to optimize our website (see also section 13 regarding the last points).

In the event of an attack on the website's network infrastructure or in case of suspected unauthorized or abusive use of the website, the IP address and other data will be evaluated for investigation and defense purposes and, if necessary, used in criminal proceedings for identification and civil and criminal action against the users concerned.

Finally, when you visit our website, we use cookies as well as applications and tools that rely on cookies. The data described here may also be processed in this context. You can find more detailed information in the following sections of this privacy policy, in particular section 11.

11. Cookies

Cookies are information files that your web browser stores on your computer's hard drive or in its memory when you visit our website. Cookies are assigned identification numbers that identify your browser and allow the information contained in the cookie to be read.

Cookies help make your visit to our website easier, more enjoyable, and more meaningful. We use cookies for various purposes that are necessary for your desired use of the website, i.e., "technically necessary." For example, we use cookies to identify you as a registered user after logging in, so you don't have to log in again each time you navigate between different pages. The shopping cart and ordering functions also rely on the use of cookies. Furthermore, cookies perform other technical functions required for the operation of the website, such as load balancing, which distributes the website's workload across different web servers to reduce the load on the servers. Cookies are also used for security purposes, for example, to prevent the unauthorized posting of content. Finally, we also use cookies in the design and programming of our website, for example, to enable the uploading of scripts or code.

Most internet browsers accept cookies automatically. However, when you access our website, we ask for your consent to the cookies we use that are not technically necessary, especially third-party cookies for marketing purposes. You can adjust your settings using the corresponding buttons in the cookie banner. Details about the services and data processing associated with each cookie can be found within the cookie banner and in the following sections of this privacy policy.

You may also be able to configure your browser so that no cookies are stored on your computer or so that a notification always appears when you receive a new cookie. The following pages provide explanations on how to configure cookie settings in selected browsers.

Disabling cookies may prevent you from using all the features of our website.

12. Google SiteSearch / Google Custom Search Engine

This website uses Google SiteSearch/Google Custom Search Engine from Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). This allows us to provide you with an efficient search function on our website.

When using our search fields, your browser may transmit the log file data listed in Section 10 (including your IP address) and your search term to Google, provided you have JavaScript installed in your browser. If you wish to prevent this data transmission, you can disable JavaScript in your browser settings (usually in the "Privacy" menu). Please note that the search function and other website features may be impaired in this case.

For information on how Google processes your data, please refer to Google's privacy policy: www.google.com/intl/de_de/policies/privacy .

13. Tracking and web analytics tools

13.1 General information about tracking

For the purpose of tailoring our website to user needs and continuously optimizing it, we use the web analytics services listed below. In this context, pseudonymized user profiles are created and cookies are used (see also section 11). The information generated by the cookie about your use of this website is generally transmitted to a server of the service provider, stored and processed there, together with the log file data listed in section 10. This may also involve transfer to servers abroad, e.g., in the USA (see section 8, in particular regarding the safeguards in place).

By processing the data, we obtain, among other things, the following information:

  • Navigation path that a visitor follows on the site (including viewed content and selected or purchased products),
  • Time spent on the website or subpage,
  • the subpage on which the website is exited,
  • the country, region or city from which access is made,
  • Device (type, version, color depth, resolution, width and height of the browser window) and
  • Returning or new visitor.

On our behalf, the provider will use this information to evaluate website usage, to compile reports on website activity for us, and to provide other services related to website and internet usage for market research and to tailor these web pages to user needs. For this processing, we and the provider may be considered joint controllers under data protection law to a certain extent.

You can refuse processing by rejecting or disabling the relevant cookies in your web browser settings (see section 11) or by using the service-specific options described below.

For further processing of the data by the respective provider as the (sole) controller under data protection law, in particular also any possible transfer of this information to third parties such as authorities due to national legal regulations, please refer to the respective data protection information of the provider.

13.2 Google Analytics

We use the web analytics service Google Analytics from Google Ireland Limited (Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) or Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) ("Google").

The data described regarding the use of this website may be transmitted to Google LLC's servers in the USA for the processing purposes explained (see section 13.1). By activating IP anonymization ("anonymizeIP") on this website, the IP address is shortened before transmission within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

Users can prevent Google from collecting and processing data generated by the cookie relating to their use of the website (including their IP address) by downloading and installing the browser plugin available at the following link:

http://tools.google.com/dlpage/gaoptout?hl=de . You can find more information about data protection at Google here .

14. Social Media

14.1 Social Media Profiles

On our website we have included links to our profiles on the social networks of the following providers:

  • Meta Platforms Inc., 1601 S California Ave, Palo Alto, CA 94304, USA;
  • Instagram Inc. 1601 Willow Road, Menlo Park, CA 94025, USA;
  • Twitter Inc., located at 1355 Market Street, Suite 900, San Francisco, CA 94103, USA;
  • Linkedin Unlimited Company, Wilton Place, Dublin 2, Ireland.

When you click on the social media icons, you will be automatically redirected to our profile on the respective network. This establishes a direct connection between your browser and the server of the respective social network. As a result, the network receives information that you have visited our website and clicked the link using your IP address.

If you click on a link to a social network while logged into your user account on that network, the content of our website can be linked to your profile, allowing the network to directly associate your visit to our website with your account. If you wish to prevent this, you should log out before clicking the relevant links. A connection between your access to our website and your user account will be established in any case if you log in to the respective network after clicking the link. The respective provider is the data controller for the associated data processing. Please therefore refer to the information on the network's website.

14.2 Social media plugins

On our website you can use social plugins from the following providers:

  • Meta Platforms Inc., 1601 S California Ave, Palo Alto, CA 94304, USA, Privacy Policy ;
  • Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, Privacy Policy ;
  • Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, Privacy Policy ;
  • LinkedIn Unlimited Company, Wilton Place, Dublin 2, Ireland, Privacy Policy .

We use social plugins to make it easier for you to share content from our website. These plugins help us increase the visibility of our content on social networks and thus contribute to better marketing.

The plugins are deactivated by default on our websites and therefore do not send any data to the social networks simply by visiting our website. To enhance data protection, we have integrated the plugins in such a way that a connection to the networks' servers is not automatically established. Only when you activate the plugins and thereby give your consent to the data transfer and further processing by the social network providers will your browser establish a direct connection to the servers of the respective social network.

The content of the plugin is transmitted directly from the social network to your browser and integrated into the website. This allows the respective provider to receive information that your browser has accessed the corresponding page of our website, even if you do not have an account with that social network or are not currently logged in. This information (including your IP address) is transmitted directly from your browser to a server of the provider (usually in the USA) and stored there. We have no control over the scope of the data that the provider collects with the plugin, although from a data protection perspective, we can be considered jointly responsible with the providers up to a certain extent.

If you are logged into the social network, it can directly associate your visit to our website with your user account. If you interact with the plugins, the corresponding information is also transmitted directly to a server of the provider and stored there. The information (e.g., that you like one of our products) may also be published on the social network and potentially displayed to other users of the social network. The social network provider may use this information for the purpose of displaying advertisements and tailoring its services to user needs. For this purpose, usage, interest, and relationship profiles may be created, for example, to evaluate your use of our website in relation to the advertisements displayed to you on the social network, to inform other users about your activities on our website, and to provide other services related to the use of the social network. For information on the purpose and scope of data collection and the further processing and use of data by the social network providers, as well as your related rights and privacy settings, please refer directly to the privacy policies of the respective providers.

If you do not want the social network provider to associate the data collected via our website with your user account, you must log out of the social network before activating the plugins. You can revoke your consent at any time by declaring your revocation to the plugin provider in accordance with the information in their privacy policy.

15. Online advertising and targeting

15.1 In general

We use services from various companies to present you with interesting offers online. Your user behavior on our website and other providers' websites is analyzed in order to subsequently display online advertising tailored to your individual interests.

Most technologies for tracking your user behavior ("tracking") and for displaying targeted advertising ("targeting") use cookies (see also section 11), which allow your browser to be recognized across different websites. Depending on the service provider, it may even be possible for you to be recognized online when using different devices (e.g., laptop and smartphone). This can happen, for example, if you have registered with a service that you use with multiple devices.

In addition to the data already mentioned, which is generated when accessing websites ("log file data", see section 10) and when using cookies (section 11) and which may be passed on to the companies involved in the advertising networks, the following data in particular are used in the selection of the advertising that is potentially most relevant to you:

  • Information about you that you provided when registering for or using a service from advertising partners (e.g., your gender, your age group);
  • User behavior (e.g. search queries, interactions with advertising, types of websites visited, products viewed and purchased, newsletters subscribed to).

We and our service providers use this data to determine whether you belong to our target audience and take this into account when selecting advertisements. For example, after visiting our site, you may see ads for the products you viewed when you visit other websites ("retargeting"). Depending on the amount of data, a user profile may also be created, which is automatically analyzed, and the ads are selected according to the information stored in the profile, such as membership in certain demographic segments or potential interests or behaviors. Such ads may be presented to you on various channels, including our website or app (as part of on-site and in-app marketing), as well as advertisements delivered through online advertising networks we use, such as Google.

The data can then be analyzed for billing purposes with the service provider and to assess the effectiveness of advertising measures, thereby helping us better understand the needs of our users and customers and improve future campaigns. This may also include information indicating that an action (e.g., visiting specific sections of our websites or submitting information) can be attributed to a particular advertisement. Furthermore, we receive aggregated reports from the service providers on advertising activity and information about how users interact with our website and our advertisements.

You can withdraw your consent at any time by rejecting or disabling the relevant cookies in your web browser settings (see section 11). Further options for blocking advertising can also be found in the information provided by the respective service provider, such as Google .

15.2 Google Ads

This website uses the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") for online advertising. Google uses cookies for this purpose, such as the so-called DoubleClick cookie, which enables your browser to be recognized when you visit other websites. The information generated by the cookies about your visit to these websites (including your IP address) is transmitted to and stored on a Google server in the USA (see also section 6). You can find further information about data protection at Google here .

You can withdraw your consent at any time by rejecting or disabling the relevant cookies in your web browser settings (see section 11). Further options for blocking advertising can be found here .

16. Using our chat function

When you contact us via chat, your personal data will be processed. This includes the data you provide, such as your company name, your name, your job title, your email address, and your inquiry. The time of receipt of your request will also be recorded. Required fields are marked with an asterisk (*).

We process this data exclusively to fulfill your request (e.g., providing information about a product, assisting with contract processing such as product returns, incorporating your feedback into improving our service, etc.). For the chat function, we use a tool from Zendesk, 989 Market St, San Francisco, CA 94103. Therefore, your data is stored in a Zendesk database, which may allow Zendesk access to your data if necessary for providing the software and for supporting its use.

17. Registration for a customer account

If you open a customer account on our website, we collect the following data, whereby mandatory fields in the corresponding form are marked with an asterisk (*):

  • Personal details:
    • Salutation
    • name
    • First name
    • Billing and delivery address
    • Birthday
    • Company name, company address and VAT ID number for corporate clients
  • Login details:
    • E-mail address
    • password
  • More information:
    • Languages
    • Gender

We use your personal information to verify your identity and check that you meet the registration requirements. Your email address and password serve as your login credentials, ensuring that the correct person is using the website with your information. We also need your email address to verify and confirm your account opening and for future communication with you regarding contract processing. Furthermore, this data is stored in your customer account for future contracts. For this purpose, we also allow you to store additional information in your account (e.g., your preferred payment method).

We also use the data to provide an overview of the products ordered and services received (see in particular sections 18 and 23) and a simple way to manage your personal data, to administer our website and contractual relationships, i.e. to establish, define the content of, process and amend the contracts concluded with you via your customer account.

We process information about language and gender in order to display offer suggestions on the website that are tailored to your profile and personal needs in the best possible way, for statistical recording and evaluation of the selected offers, and thus to optimize our suggestions and offers.

To prevent misuse, you must always keep your login details confidential and close the browser window when you have finished communicating with us, especially if you share the computer with others.

18. Ordering products

If you wish to order products or book services on the website, we require various data to process the contract. If you do not log in to your customer account (see section 17), we collect the following data – depending on the product or service – with mandatory fields marked with an asterisk (*) in the corresponding form:

  • Salutation
  • name
  • First name
  • Billing and delivery address
  • E-mail address
  • Birthday
  • Company name, company address and VAT ID number for corporate clients
  • Telephone number

We use this data to verify your identity before concluding a contract. We also need your email address to confirm your order and for future communication with you necessary for processing the contract. We store your data, along with the order details (e.g., date, order number, etc.), data on the ordered/booked services (e.g., product name, price, and features; "product data"), payment details (e.g., chosen payment method, payment confirmation, and date; see also section 19), and information on processing and fulfilling the contract (e.g., product returns, use of service or warranty services, etc.), in our CRM database (see section 6.1) so that we can ensure correct order processing and contract fulfillment.

To the extent necessary for the performance of the contract, we will also pass on the required information to any third-party service providers (e.g. transport companies).

Providing data that is not marked as mandatory is voluntary. We process this data to tailor our services to your personal needs as effectively as possible, to facilitate contract processing, to contact you via alternative communication channels if necessary to fulfill the contract, and for statistical analysis and evaluation to optimize our services.

19. Online Payment Processing

When you purchase paid services or products on our website, depending on the product or service and your chosen payment method, you will be required to provide additional information beyond what is stated in section 18. This may include your credit card information or login details for your payment service provider. This information, along with the fact that you purchased a service from us for the relevant amount and time, will be forwarded to the respective payment service providers (e.g., payment solution providers, credit card issuers, and credit card acquirers). Always refer to the information provided by the respective company, in particular their privacy policy and terms and conditions.

To prevent payment defaults, the necessary data, in particular your personal details, may be transmitted to a credit agency for an automated assessment of your creditworthiness. In this context, the credit agency may assign you a so-called score. This is an estimate of the future risk of payment default, for example, expressed as a percentage. The score is calculated using mathematical and statistical methods and by incorporating data from other sources. Based on the information received, we reserve the right not to offer you the payment method "invoice".

20. Submitting ratings

To help other users with their purchasing decisions and to support our quality management (especially in processing negative feedback), you have the option to rate ordered products on our website. The data you provide will be processed and published on the website; this includes your rating and the date and time of submission, any comments you may have added to your rating, and your name.

We reserve the right to delete unlawful reviews and to contact you if we suspect any wrongdoing and request a statement from you.

  1. Special instructions for our store

21. Video surveillance

To prevent misuse and to take action against unlawful behavior (especially theft and property damage), the entrance area and publicly accessible areas of our premises are monitored by cameras. The footage is only reviewed if there is suspicion of unlawful activity. Otherwise, the recordings are automatically deleted after 72 hours.

For the provision of the video surveillance system, we rely on a service provider who may have access to the data if this is necessary for the provision of the system. Should the suspicion of unlawful conduct be substantiated, the data may then be forwarded to consulting firms (in particular our law firm) and authorities to the extent necessary for the enforcement of claims or for filing charges.

22. Opening a customer account

When you open a customer account in our store, we collect the following data, with mandatory fields marked with an asterisk (*) in the corresponding form:

  • Salutation
  • name
  • First name
  • Billing and delivery address
  • E-mail address
  • Birthday
  • Company name, company address and VAT ID number for corporate clients
  • Telephone number

We use this data to verify your identity and check that you meet the requirements for opening an account. We collect your email address and telephone number for future communication with you necessary for processing your order. Furthermore, this data, along with data relating to the purchase of products and the use of services (see Section 18), is stored under a customer number in your customer account. This allows us to provide you with an overview of your data upon request and to enable future linking with data from other channels. Your account and the stored data will therefore also be linked to your online account (see Section 17) if the personal details are identical.

23. Purchase or ordering of products in the store

In our store, you can usually purchase products without providing your name. In this case, please refer to the section on payment processing (see section 25). Upon request, you will receive a paper receipt, which you should keep and present when using customer services after your purchase (see section 26). Alternatively, you can purchase products using your customer account details. In this case, please also refer to the section on opening a customer account (see section 23).

When you purchase or order certain products, we require your name and various other data to process the contract. Depending on the product or service, we collect the following data, with mandatory fields marked with an asterisk (*) in forms:

  • Salutation
  • name
  • First name
  • Billing and delivery address
  • E-mail address
  • Birthday
  • Company name, company address and VAT ID number for corporate clients
  • Telephone number

We use this data to verify your identity before concluding a contract. We also require your email address for future communication with you necessary for processing the contract. We store your data, along with the order details (e.g., date, order number, etc.), data relating to the ordered/booked services (e.g., product name, price, and features; "product data"), payment details (e.g., chosen payment method, payment confirmation, and date; see also section 19), and information related to processing and fulfilling the contract (e.g., product returns, use of service or warranty claims, etc.), in our CRM database (see section 6.1) to ensure correct order processing and contract fulfillment.

To the extent necessary for the performance of the contract, we will also pass on the required information to any third-party service providers (e.g. transport companies).

Providing data that is not marked as mandatory is voluntary. We process this data to tailor our services to your personal needs as effectively as possible, to facilitate contract processing, to contact you via alternative communication channels if necessary to fulfill the contract, and for statistical analysis and evaluation to optimize our services.

24. Payment processing

When you purchase products in our store using electronic payment methods, the processing of personal data is necessary. By using the payment terminals, you transmit the information stored in your payment method, such as the cardholder's name and card number, to the involved payment service providers (e.g., payment solution providers, credit card issuers, and credit card acquirers). These providers also receive information that the payment method was used in our store, the amount, and the time of the transaction. Conversely, we only receive the credit for the payment amount at the corresponding time, which we can assign to the relevant receipt number, or information that the transaction was unsuccessful or canceled. Please always refer to the information provided by the respective company, in particular their privacy policy and terms and conditions.

25. Use of customer services in the store

In our stores, you can take advantage of numerous customer services that may require the processing of personal data. This includes, for example, picking up an ordered product, returning products under a right of return or warranty claim, and filing a complaint about a service. In such cases, we collect the following data – depending on the product or service requested – with mandatory fields marked with an asterisk (*) in the forms:

  • Salutation
  • name
  • First name
  • Billing and delivery address
  • E-mail address
  • Birthday
  • Company name, company address and VAT ID number for corporate clients
  • Telephone number

We use this data to verify your identity. We also need your email address for communication with you necessary to provide customer service. We store this data, along with the details, date, and content of the requested service, in our CRM database (see section 6.1) to ensure the correct processing of the requested service. Where necessary for contract fulfillment, we will also share the required information with any third-party service providers (e.g., transport companies) or other involved third parties (e.g., manufacturers in the event of a claim under the manufacturer's warranty).

***

To reduce data protection risks when using social plugins, it should be ensured that the plugins are deactivated by default, for example by implementing the so-called "Shariff solution," which allows simple HTML links, individually styled with CSS, to be embedded in the website. Further information can be found on the website heise.de .