1. responsible body in the sense of the DSGVO
The Plant Magic Company GmbH
Phone: 089 - 215 28 120
Thank you for your interest in our online store. The protection of your personal data is important to us. We observe the legal regulations on data protection and data security.
In the following we inform you in detail about the handling of your data. We explain what personal data we collect when you use our online store and how we use it and for what purposes.
2. access data and hosting
Unless otherwise stated below, the provision of your personal data is neither required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide it will have no consequences. This applies only to the extent that no other indication is made in the subsequent processing operations.
"Personal data" means any information relating to an identified or identifiable natural person. You can visit our online store or websites without providing any personal information.
Each time you access our website, usage data is transmitted to us or our web hoster / IT service provider by your Internet browser and stored in log files (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred and the requesting provider. The processing is based on Art. 6 (1) lit. f DSGVO from our overriding legitimate interest in ensuring the trouble-free operation of our website and to improve our services. The Plant Magic Company does not store any personal data in this context. During your visit to our site, you thus remain fundamentally anonymous and the connection data transmitted by your Internet browser with each page view is used by us without personal reference and only evaluated using certain analysis tools.
This website or online store is hosted by external service providers (hosters). Our service providers are located and/or use servers in the USA and in other countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on standard data protection clauses of the European Commission. The personal data collected on this website is stored on the hoster's servers. This may include, but is not limited to, IP addresses, meta and communication data, website accesses and other data generated via a website. The hoster is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f DSGVO). Our hoster will only process your data to the extent necessary to fulfill its service obligations and follow our instructions regarding this data. Your data may be transferred to third countries outside the European Union for which an adequacy decision of the EU Commission is available. If there is no adequacy decision of the EU Commission, such as for transfers to the USA, the data transfers are based, among other things, on standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at this link of the EU Commission.
3. personal data collection
When using the contact form, we collect your personal data (name, e-mail address, message text) only to the extent provided by you. The data processing serves the purpose of contacting you. By sending your message, you consent to the processing of the transmitted data. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. We will only use your e-mail address to process your request. Your data will then be deleted unless you have consented to further processing and use.
If you contact us by e-mail or telephone - e.g. to obtain information about our products, to ask general questions or to make complaints - your data and information provided will be forwarded to us via our provider and, if necessary, stored by us digitally or offline. The information provided will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after the inquiry has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
Your inquiry will only be processed by our authorized service staff. Data will not be used for any other purpose or passed on to third parties. A comparison with personal data that we may have collected elsewhere will only be made if it is useful for the rapid clarification of your request. In the case of communication by e-mail, we cannot guarantee complete data security.
We use your e-mail address independently of the contract processing exclusively for our own advertising purposes for sending newsletters, provided that you have expressly consented to this. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. To do so, you can unsubscribe from the newsletter at any time by using the corresponding links in the newsletter or by notifying us. Your e-mail address will then be removed from the distribution list.
4. data processing for contract and shipment processing
4.1 Merchandise management systems
4.2 Transport companies
We pass on your e-mail address to the transport company as part of the contract processing, provided you have expressly agreed to this in the order process. The purpose of the forwarding is to inform you by e-mail about the shipping status. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time by notifying us or the transport company, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. We have commissioned DHL International GmbH (Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany) as the transport company to deliver your order - click here for the DHL privacy statement.
4.3 Payment service provider
We use the PayPal Express payment service of PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. To integrate this payment service, it is necessary for PayPal to collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you call up the website. Cookies may also be used for this purpose. The cookies enable the recognition of your browser.
Insofar as you have opted for Klarna's payment service Klarna Invoice, you have consented to us collecting and transmitting to Klarna the following personal data necessary for the processing of the purchase on account and an identity and credit check, such as first and last name, address, date of birth, gender, e-mail address, IP address, telephone number, as well as the data necessary for the processing of the purchase on account, which are related to the order, such as the number of items, item number, invoice amount and taxes in percent. The data processing serves the purpose of offering the payment methods invoice purchase and installment purchase as well as the credit assessment required for this. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
The transmission of this data takes place so that Klarna can create an invoice and carry out an identity and credit check for the processing of your purchase with the invoice processing requested by you. Klarna requires the personal data of the buyer to obtain information from credit agencies for the purpose of identity and credit checks. In Germany, this may be the following credit agencies:
- Schufa Holding AG, Kormoranweg 5, 65203 Wiesbaden, Germany.
- Bürgel Wirtschaftsinformationen GmbH & Co KG, P.O. Box 5001 66, 22701 Hamburg, Germany
- Creditreform Bremen Seddig KG, Contrescarpe 17, 28203 Bremen, Germany
- infoscore Consumer Data GmbH, Rheinstrasse 99, 76532 Baden-Baden.
In the context of the decision on the establishment, implementation or termination of the contractual relationship, Klarna collects and uses, apart from an address check, information on the past payment behavior of the buyer and probability values for this behavior in the future. The calculation of these score values by Klarna is based on a scientifically recognized mathematical-statistical method. For this purpose, Klarna will also use your address data, among other things. If this calculation shows that your creditworthiness is not given, Klarna will inform you about this immediately.
You can revoke your consent to the use of personal data at any time to Klarna. However, Klarna remains entitled to process, use and transfer the personal data, if necessary, to the extent that this is necessary for the contractual payment processing by Klarna's services, is required by law, or is required by a court or an authority. You can, of course, obtain information about the personal data stored by Klarna at any time. This right is guaranteed by the Federal Data Protection Act. If you as a buyer wish to do so or to notify Klarna of any changes regarding the stored data, you can contact email@example.com.
4.4 Fraud prevention
Where applicable, we provide our service providers with further data, which they use together with the data necessary for the processing of the payment as our order processors for the purpose of fraud prevention and optimization of our payment processes (e.g. invoicing, processing of contested payments, accounting support). Pursuant to Art. 6 (1) p. 1 lit. f DSGVO, this serves to protect our legitimate interests in our protection against fraud or in efficient payment management, which outweigh our interests in the context of a balancing of interests.
The respective cookie settings of your internet browser can be found here:
6. web analysis
On our website, we use the remarketing function "Custom Audiences" of Facebook Inc (1601 S. California Ave, Palo Alto, CA 94304, USA; "Facebook"). This application serves the purpose of targeting visitors to the website with interest-based advertising on the Facebook social network. For this purpose, the remarketing tag of Facebook has been implemented on the website. Via this tag, a direct connection to the Facebook servers is established when visiting the website. This transmits to the Facebook server which of our pages you have visited. Facebook assigns this information to your personal Facebook user account. When you visit the Facebook social network, you will then be shown personalized, interest-related Facebook ads. Your data may be transferred to the USA. Facebook has certified itself in accordance with the US-EU "Privacy Shield" data protection agreement and has thus undertaken to comply with European data protection guidelines. The data processing, in particular the setting of cookies, is carried out with your consent on the basis of Art. 6 para. 1 lit. a DSGVO. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
We use the web analytics service Google Analytics of Google LLC on our website. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller of your data. Accordingly, Google Ireland Limited is the company affiliated with Google that is responsible for processing your data and ensuring compliance with applicable data protection laws.Data processing is for the purpose of analyzing this website and its visitors, as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. In doing so, the following information may be collected, among others: IP address, date and time the page was accessed, click path, information about the browser you are using and the device you are using (device), pages visited, referrer URL (website from which you accessed our website), location data, purchase activities. The IP address transmitted by your browser as part of Google Analytics is not merged with other data from Google.
Google Analytics uses technologies such as cookies, web memory in the browser and tracking pixels that allow an analysis of your use of the website. The information generated by this about your use of this website is usually transferred to a Google server in the USA and stored there. IP anonymization is activated on this website. This means that your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Google has certified itself in accordance with the US-EU data protection agreement "Privacy Shield" and is thus obliged to comply with the European data protection guidelines.
Google Tag Manager
Our website uses the Google Tag Manager of Google LLC. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google") is used on our website. If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller of your data. Google Ireland Limited is therefore the company affiliated with Google that is responsible for processing your data and complying with applicable data protection laws.
Our website uses various plug-ins of social networks. The integration of social plug-ins and the data processing that takes place serves the purpose of optimizing advertising for our products. When social plug-ins are integrated, a link is established between your computer and the servers of the social network providers and the plug-in is displayed on the page by notifying your browser, provided you have expressly consented to this. In this process, both your IP address and the information about which of our pages you have visited are transmitted to the provider servers. This applies regardless of whether you are registered or logged in to the social network. Transmission also takes place for non-registered or non-logged-in users. If you are connected to one or more of your social network accounts at the same time, the collected information can also be assigned to your corresponding profiles. When using the plug-in functions (e.g. by pressing the button), this information is also assigned to your user account. You can prevent this assignment by logging out of your social media accounts before visiting our website and before activating the buttons. The data processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
Social networks named below are integrated on our website by means of social plug-ins. For more information on the scope and purpose of the collection and use of the data, as well as your rights in this regard and options for protecting your privacy, please refer to the linked data protection notices of the providers:
- Instagram of Instagram LLC. (1601 Willow Road, Menlo Park, CA 94025, USA).
- Facebook of Facebook Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA)
- LinkedIn of LinkedIn Corporation (2029 Stierlin Court, Mountain View, CA 94043, USA)
7. data protection contact and your rights
Based on the General Data Protection Regulation, you have various rights to protect your data. These include
- Pursuant to Art. 15 DSGVO, the right to request information about your personal data processed by us to the extent specified therein;
- pursuant to Art. 16 DSGVO, the right to demand the correction of inaccurate or incomplete personal data stored by us without undue delay;
- pursuant to Art. 17 DSGVO the right to request the erasure of your personal data stored by us, unless the further processing * is necessary for the exercise of the right to freedom of expression and information; for compliance with a legal obligation; for reasons of public interest or for the establishment, exercise or defense of legal claims;
- pursuant to Art. 18 DSGVO the right to request the restriction of the processing of your personal data, insofar as * the accuracy of the data is disputed by you; the processing is unlawful, but you object to its erasure; we no longer need the data, but you need it for the assertion, exercise or defense of legal claims or you have objected to the processing pursuant to Art. 21 DSGVO;
- pursuant to Art. 20 DSGVO, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transferred to another controller;
- pursuant to Art. 77 DSGVO, the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.
If you have any questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data as well as revocation of any consent given or objection to a specific use of data, please contact our company data protection officer.
7.1 Data Protection Officer
The Plant Magic Company GmbH
Phone: 089 - 215 28 120
7.2 Right of objection
Insofar as we process personal data as explained above in order to protect our legitimate interests, which prevail in the context of a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. If the processing is carried out for other purposes, you will only have the right to object if there are grounds arising from your particular situation. After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims. This does not apply if the processing is for direct marketing purposes. Then we will not further process your personal data for this purpose.