Privacy policy
1. responsible body in the sense of the DSGVO
The Plant Magic Company GmbH
Lothstraße 3
80335 Munich
Germany
Phone: 089 - 215 28 120
E-mail: daten@theplantmagic.co
Thank you for your interest in our online store. The protection of your personal data is important to us. We observe the legal regulations on data protection and data security.
In the following we inform you in detail about the handling of your data. We explain what personal data we collect when you use our online store and how we use it and for what purposes.
2. access data and hosting
Unless otherwise stated below, the provision of your personal data is neither required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide it will have no consequences. This applies only to the extent that no other indication is made in the subsequent processing operations.
"Personal data" means any information relating to an identified or identifiable natural person. You can visit our online store or websites without providing any personal information.
Each time you access our website, usage data is transmitted to us or our web hoster / IT service provider by your Internet browser and stored in log files (so-called server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the IP address, the amount of data transferred and the requesting provider. The processing is based on Art. 6 (1) lit. f DSGVO from our overriding legitimate interest in ensuring the trouble-free operation of our website and to improve our services. The Plant Magic Company does not store any personal data in this context. During your visit to our site, you thus remain fundamentally anonymous and the connection data transmitted by your Internet browser with each page view is used by us without personal reference and only evaluated using certain analysis tools.
This website or online store is hosted by external service providers (hosters). Our service providers are located and/or use servers in the USA and in other countries outside the EU and the EEA. For these countries, there is no adequacy decision of the European Commission. Our cooperation with them is based on standard data protection clauses of the European Commission. The personal data collected on this website is stored on the hoster's servers. This may include, but is not limited to, IP addresses, meta and communication data, website accesses and other data generated via a website. The hoster is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f DSGVO). Our hoster will only process your data to the extent necessary to fulfill its service obligations and follow our instructions regarding this data. Your data may be transferred to third countries outside the European Union for which an adequacy decision of the EU Commission is available. If there is no adequacy decision of the EU Commission, such as for transfers to the USA, the data transfers are based, among other things, on standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at this link of the EU Commission.
3. personal data collection
Personal data will only be collected, processed and used by The Plant Magic Company if you have consented to this. By agreeing to this privacy policy, you consent to the collection, processing and use of the personal data you provide. When giving your consent, you will be informed about the purpose of the data collection and this privacy policy. You have the right to revoke your consent at any time, with effect for the future. The contact details for this can be found in the imprint.
3.1 Contacting
When using the contact form, we collect your personal data (name, e-mail address, message text) only to the extent provided by you. The data processing serves the purpose of contacting you. By sending your message, you consent to the processing of the transmitted data. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. We will only use your e-mail address to process your request. Your data will then be deleted unless you have consented to further processing and use.
If you contact us by e-mail or telephone - e.g. to obtain information about our products, to ask general questions or to make complaints - your data and information provided will be forwarded to us via our provider and, if necessary, stored by us digitally or offline. The information provided will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g. after the inquiry has been processed). Mandatory legal provisions - in particular retention periods - remain unaffected.
Your inquiry will only be processed by our authorized service staff. Data will not be used for any other purpose or passed on to third parties. A comparison with personal data that we may have collected elsewhere will only be made if it is useful for the rapid clarification of your request. In the case of communication by e-mail, we cannot guarantee complete data security.
3.2 Newsletter
We use your e-mail address independently of the contract processing exclusively for our own advertising purposes for sending newsletters, provided that you have expressly consented to this. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. To do so, you can unsubscribe from the newsletter at any time by using the corresponding links in the newsletter or by notifying us. Your e-mail address will then be removed from the distribution list.
Your data will be passed on to a service provider for e-mail marketing within the scope of order processing. Your data will not be passed on to any other third parties. The newsletter may also be sent by our service providers as part of processing on our behalf. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy. Our service providers are located and/or use servers in the USA. There is no adequacy decision for the USA from the European Commission. Our cooperation with them is based on standard data protection clauses of the European Commission.
4. data processing for contract and shipment processing
4.1 Merchandise management systems
We use merchandise management systems of external service providers for order and contract processing. Our service providers work for us within the framework of order processing. If you have any questions about our service providers and the basis of our cooperation with them, please use the contact option described in this privacy policy.
4.2 Transport companies
We pass on your e-mail address to the transport company as part of the contract processing, provided you have expressly agreed to this in the order process. The purpose of the forwarding is to inform you by e-mail about the shipping status. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time by notifying us or the transport company, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. We have commissioned DHL International GmbH (Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany) as the transport company to deliver your order - click here for the DHL privacy statement.
4.3 Payment service provider
When processing payments in our online store, we work with various partners: technical service providers, credit institutions, payment service providers. Depending on the selected payment method, we pass on the data necessary for processing the payment transaction to our technical service providers, who work for us as part of order processing, or to the commissioned credit institutions or to the selected payment service provider, insofar as this is necessary for processing the payment. This serves the fulfillment of the contract according to Art. 6 para. 1 p. 1 lit. b DSGVO. In some cases, the payment service providers collect the data required for processing the payment themselves, e.g. on their own website or via a technical integration in the ordering process. In this respect, the privacy policy of the respective payment service provider applies.
PayPal
PayPal transactions (PayPal as well as PayPal Express) are subject to the PayPal privacy policy. You can find it under this link.
We use the PayPal Express payment service of PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. To integrate this payment service, it is necessary for PayPal to collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when you call up the website. Cookies may also be used for this purpose. The cookies enable the recognition of your browser.
This data processing, in particular the setting of cookies, is carried out on the basis of Art. 6 (1) lit. f DSGVO from our overriding legitimate interest in a customer-oriented offer of various payment methods. You have the right to object to processing of your personal data based on Art. 6 (1) (f) DSGVO at any time for reasons arising from your particular situation. With the selection and use of PayPal Express, the data required for payment processing will be transmitted to PayPal in order to fulfill the contract with you with the selected payment method. This processing is based on Art. 6 para. 1 lit. b DSGVO. For more information on data processing when using the PayPal Express payment service, please see the associated privacy policy here.
Klarna
Insofar as you have opted for Klarna's payment service Klarna Invoice, you have consented to us collecting and transmitting to Klarna the following personal data necessary for the processing of the purchase on account and an identity and credit check, such as first and last name, address, date of birth, gender, e-mail address, IP address, telephone number, as well as the data necessary for the processing of the purchase on account, which are related to the order, such as the number of items, item number, invoice amount and taxes in percent. The data processing serves the purpose of offering the payment methods invoice purchase and installment purchase as well as the credit assessment required for this. The processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time by notifying us, without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
The transmission of this data takes place so that Klarna can create an invoice and carry out an identity and credit check for the processing of your purchase with the invoice processing requested by you. Klarna requires the personal data of the buyer to obtain information from credit agencies for the purpose of identity and credit checks. In Germany, this may be the following credit agencies:
- Schufa Holding AG, Kormoranweg 5, 65203 Wiesbaden, Germany.
- Bürgel Wirtschaftsinformationen GmbH & Co KG, P.O. Box 5001 66, 22701 Hamburg, Germany
- Creditreform Bremen Seddig KG, Contrescarpe 17, 28203 Bremen, Germany
- infoscore Consumer Data GmbH, Rheinstrasse 99, 76532 Baden-Baden.
In the context of the decision on the establishment, implementation or termination of the contractual relationship, Klarna collects and uses, apart from an address check, information on the past payment behavior of the buyer and probability values for this behavior in the future. The calculation of these score values by Klarna is based on a scientifically recognized mathematical-statistical method. For this purpose, Klarna will also use your address data, among other things. If this calculation shows that your creditworthiness is not given, Klarna will inform you about this immediately.
You can revoke your consent to the use of personal data at any time to Klarna. However, Klarna remains entitled to process, use and transfer the personal data, if necessary, to the extent that this is necessary for the contractual payment processing by Klarna's services, is required by law, or is required by a court or an authority. You can, of course, obtain information about the personal data stored by Klarna at any time. This right is guaranteed by the Federal Data Protection Act. If you as a buyer wish to do so or to notify Klarna of any changes regarding the stored data, you can contact datenschutz@klarna.de.
4.4 Fraud prevention
Where applicable, we provide our service providers with further data, which they use together with the data necessary for the processing of the payment as our order processors for the purpose of fraud prevention and optimization of our payment processes (e.g. invoicing, processing of contested payments, accounting support). Pursuant to Art. 6 (1) p. 1 lit. f DSGVO, this serves to protect our legitimate interests in our protection against fraud or in efficient payment management, which outweigh our interests in the context of a balancing of interests.
5. cookies
Our website uses cookies to make your visit to our website attractive and to enable the use of certain functions. Cookies are small text files that are stored in the Internet browser or on the operating system of the user. A cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again. Cookies are stored on your computer, therefore you have full control over the use of cookies at all times. By selecting appropriate technical settings in your Internet browser, you can be notified before cookies are set and decide on their acceptance individually, as well as prevent the storage of cookies and transmission of the data they contain. Cookies that have already been stored can be deleted at any time.
Some cookies are deleted after closing your browser, other cookies remain on your terminal device and allow us to recognize your browser on your next visit (persistent cookies). We use cookies to be able to collect and process certain functions of our website - such as information about the contents of the shopping cart. Within the framework of a balancing of interests, this serves overriding legitimate interests in an optimized presentation of our offer in accordance with Art. 6 (1) p. 1 lit. f DSGVO. In addition, we use technologies to fulfill our legal obligations (e.g. to be able to prove consent to the processing of your personal data) as well as for web analysis and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
The respective cookie settings of your internet browser can be found here:
Insofar as you have consented to the use of the technologies pursuant to Art. 6 para. 1 p. 1 lit. a DSGVO, you may revoke your consent at any time by sending a message to the contact option described in the privacy policy. Non-acceptance of cookies may limit the functionality of our website. In addition, we reserve the right to use analytics cookies, advertising cookies and third-party advertising cookies on our site. More about this in the following sections on web analytics.
6. web analysis
Facebook Pixel
On our website, we use the remarketing function "Custom Audiences" of Facebook Inc (1601 S. California Ave, Palo Alto, CA 94304, USA; "Facebook"). This application serves the purpose of targeting visitors to the website with interest-based advertising on the Facebook social network. For this purpose, the remarketing tag of Facebook has been implemented on the website. Via this tag, a direct connection to the Facebook servers is established when visiting the website. This transmits to the Facebook server which of our pages you have visited. Facebook assigns this information to your personal Facebook user account. When you visit the Facebook social network, you will then be shown personalized, interest-related Facebook ads. Your data may be transferred to the USA. Facebook has certified itself in accordance with the US-EU "Privacy Shield" data protection agreement and has thus undertaken to comply with European data protection guidelines. The data processing, in particular the setting of cookies, is carried out with your consent on the basis of Art. 6 para. 1 lit. a DSGVO. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
For more information on the collection and use of data by Facebook, your rights in this regard and options for protecting your privacy, please refer to Facebook's privacy policy.
Google Analytics
We use the web analytics service Google Analytics of Google LLC on our website. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller of your data. Accordingly, Google Ireland Limited is the company affiliated with Google that is responsible for processing your data and ensuring compliance with applicable data protection laws.Data processing is for the purpose of analyzing this website and its visitors, as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. In doing so, the following information may be collected, among others: IP address, date and time the page was accessed, click path, information about the browser you are using and the device you are using (device), pages visited, referrer URL (website from which you accessed our website), location data, purchase activities. The IP address transmitted by your browser as part of Google Analytics is not merged with other data from Google.
Google Analytics uses technologies such as cookies, web memory in the browser and tracking pixels that allow an analysis of your use of the website. The information generated by this about your use of this website is usually transferred to a Google server in the USA and stored there. IP anonymization is activated on this website. This means that your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Google has certified itself in accordance with the US-EU data protection agreement "Privacy Shield" and is thus obliged to comply with the European data protection guidelines.
The data processing, in particular the setting of cookies, is carried out with your consent on the basis of Art. 6 para. 1 lit. a DSGVO. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent up to the revocation. You can find more information on terms of use and data protection here.
Google Remarketing
On our website, we use the remarketing or "similar target groups" function of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller of your data. Accordingly, Google Ireland Limited is the company affiliated with Google that is responsible for processing your data and complying with applicable data protection laws. The application serves the purpose of analyzing visitor behavior and visitor interests. To perform the analysis of website usage, which forms the basis for the creation of interest-based advertisements, Google uses cookies. The cookies are used to record visits to the website as well as anonymized data on the use of the website. No personal data of the website visitors is stored. If you subsequently visit another website in the Google Display Network, you will be shown advertisements that are highly likely to take into account previously accessed product and information areas. Your data may be transferred to the USA. Google has certified itself in accordance with the US-EU data protection agreement "Privacy Shield" and has thus undertaken to comply with the European data protection guidelines.
The data processing, in particular the setting of cookies, is carried out with your consent on the basis of Art. 6 Para. 1 lit. a DSGVO. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation. Here you can find more detailed information on Google Remarketing and the associated privacy policy.
Google Tag Manager
Our website uses the Google Tag Manager of Google LLC. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google") is used on our website. If you have your habitual residence in the European Economic Area or Switzerland, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is the controller of your data. Google Ireland Limited is therefore the company affiliated with Google that is responsible for processing your data and complying with applicable data protection laws.
This application manages JavaScript tags and HTML tags that are used to implement tracking and analysis tools in particular. The data processing serves the purpose of demand-oriented design and optimization of our website. The Google Tag Manager itself neither stores cookies nor does it process personal data. However, it enables the triggering of other tags that can collect and process personal data. Here you will find more detailed information on terms of use and data protection.
Social plug-ins
Our website uses various plug-ins of social networks. The integration of social plug-ins and the data processing that takes place serves the purpose of optimizing advertising for our products. When social plug-ins are integrated, a link is established between your computer and the servers of the social network providers and the plug-in is displayed on the page by notifying your browser, provided you have expressly consented to this. In this process, both your IP address and the information about which of our pages you have visited are transmitted to the provider servers. This applies regardless of whether you are registered or logged in to the social network. Transmission also takes place for non-registered or non-logged-in users. If you are connected to one or more of your social network accounts at the same time, the collected information can also be assigned to your corresponding profiles. When using the plug-in functions (e.g. by pressing the button), this information is also assigned to your user account. You can prevent this assignment by logging out of your social media accounts before visiting our website and before activating the buttons. The data processing is based on Art. 6 para. 1 lit. a DSGVO with your consent. You can revoke your consent at any time without affecting the lawfulness of the processing carried out on the basis of the consent until the revocation.
Social networks named below are integrated on our website by means of social plug-ins. For more information on the scope and purpose of the collection and use of the data, as well as your rights in this regard and options for protecting your privacy, please refer to the linked data protection notices of the providers:
- Instagram of Instagram LLC. (1601 Willow Road, Menlo Park, CA 94025, USA).
- Facebook of Facebook Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA)
- LinkedIn of LinkedIn Corporation (2029 Stierlin Court, Mountain View, CA 94043, USA)
7. data protection contact and your rights
Based on the General Data Protection Regulation, you have various rights to protect your data. These include
- Pursuant to Art. 15 DSGVO, the right to request information about your personal data processed by us to the extent specified therein;
- pursuant to Art. 16 DSGVO, the right to demand the correction of inaccurate or incomplete personal data stored by us without undue delay;
- pursuant to Art. 17 DSGVO the right to request the erasure of your personal data stored by us, unless the further processing * is necessary for the exercise of the right to freedom of expression and information; for compliance with a legal obligation; for reasons of public interest or for the establishment, exercise or defense of legal claims;
- pursuant to Art. 18 DSGVO the right to request the restriction of the processing of your personal data, insofar as * the accuracy of the data is disputed by you; the processing is unlawful, but you object to its erasure; we no longer need the data, but you need it for the assertion, exercise or defense of legal claims or you have objected to the processing pursuant to Art. 21 DSGVO;
- pursuant to Art. 20 DSGVO, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transferred to another controller;
- pursuant to Art. 77 DSGVO, the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.
If you have any questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data as well as revocation of any consent given or objection to a specific use of data, please contact our company data protection officer.
7.1 Data Protection Officer
Frank Molter
The Plant Magic Company GmbH
Lothstraße 3
80335 Munich
Germany
Phone: 089 - 215 28 120
E-mail: datenschutz@theplantmagic.co
7.2 Right of objection
Insofar as we process personal data as explained above in order to protect our legitimate interests, which prevail in the context of a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. If the processing is carried out for other purposes, you will only have the right to object if there are grounds arising from your particular situation. After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims. This does not apply if the processing is for direct marketing purposes. Then we will not further process your personal data for this purpose.
Status: 20.10.2021