This Privacy Policy explains what data is stored when you visit the website accessible at www.figuya.de ("this website") and how it is used. If you have any questions about this Privacy Policy or the use of your data, you can contact us at any time via the email address provided in the imprint.
Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection provisions is:
Figuya GmbHWolfener Str. 36
12681 Berlin
Phone: +49 (0)30 577 011 989
Fax: +49 (0)30 577 011 987
Email: kontakt@figuya.de
Website: https://figuya.com
Definitions
"Personal data" means any information relating to an identified or identifiable natural person. A natural person is considered identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Data subject" means any identified or identifiable natural person whose personal data is processed by the controller.
Processing Operations
We collect and process the following personal data about you that you provide to us:
- Master data (e.g., name, address).
- Contact data (e.g., email, phone number).
- Meta/communication data (e.g., device information, IP addresses).
- Usage data (e.g., visited websites, interest in content, access times).
- Location data (data indicating the location of an end user's device).
- Contract data (e.g., subject matter, customer category).
- Payment data (e.g., bank details, invoices, payment history).
Purpose of Processing
We process your data for the following purposes:
- for managing and responding to inquiries,
- for providing information about our offers,
- for contract processing,
- for quality assurance,
- for security measures,
- for our statistics.
Legal Basis for Processing
The processing of your data is based on the following legal grounds:
- Consent (Art. 6 para. 1 lit. a) GDPR),
- Contract performance and pre-contractual inquiries (Art. 6 para. 1 lit. b) GDPR),
- Compliance with legal obligations (Art. 6 para. 1 lit. c) GDPR), or
- Legitimate interests (Art. 6 para. 1 lit. f) GDPR).
Insofar as we base the processing of your personal data on legitimate interests within the meaning of Art. 6 para. 1 lit. f) GDPR, such interests are:
- improving our offering,
- protection against misuse, and
- maintaining our statistics.
Duration of Storage
We only store your personal data for as long as necessary to achieve the processing purpose or as required by a statutory retention period.
We store your data:
- if you have consented to the processing, at most until you withdraw your consent,
- if we need the data for the performance of a contract, at most for as long as the contractual relationship with you exists or statutory retention periods are running,
- if we use the data on the basis of a legitimate interest, at most for as long as your interest in deletion or anonymization does not prevail.
Data Collection When Visiting This Website and Creation of Log Files
-
Each time a website is accessed, the browser used on your device
automatically sends information to the server of this website. The
following data is collected:
- Information about the browser type and version used
- User's operating system
- User's Internet service provider
- Date and time of access
- Websites from which the user's system reached this website
- Websites accessed by the user's system via this website
- The data is also stored in the log files of our system. This data is not stored together with other personal data of the user. The legal basis for the temporary storage of the data is Art. 6 para. 1 lit. f GDPR.
- The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user's computer. For this purpose, the user's IP address must be stored for the duration of the session.
- The data is deleted as soon as it is no longer necessary for the purpose of its collection. In the case of data collection for the provision of this website, this is the case when the respective session has ended.
- The collection of data for the provision of this website and the storage of data in log files is absolutely necessary for the operation of this website. There is therefore no possibility of objection on your part.
Use of Cookies
- This website uses cookies. Cookies are files that are stored in the internet browser or by the internet browser on the user's computer system. When a user accesses a website, a cookie may be stored on the user's operating system. Cookies contain a characteristic string that enables unique identification of the browser when the website is accessed again.
-
We use cookies to make this website more user-friendly. Some elements of
this website require that the requesting browser can be identified even
after a page change. The following data is stored and transmitted in the
cookies:
- Items in a shopping cart
- Login information
- Information about progress in the order process
- The legal basis for processing personal data using cookies is Art. 6 para. 1 lit. f GDPR.
-
The purpose of using technically necessary cookies is to simplify the use
of websites for users. Some functions of this website cannot be offered
without the use of cookies. For these, it is necessary that the browser is
recognized even after a page change.
We need cookies for the following applications:- Shopping cart
- Processing of the order process
- Cookies are stored on the user's computer and transmitted from there to this website. Therefore, as a user, you have full control over the use of cookies. By changing the settings in your internet browser, you can disable or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for this website, it may not be possible to use all functions of this website to their full extent.
Data Processing When Contacting Us via This Website
- We provide a contact form on this website that can be used for electronic contact. If a user uses this option, the data entered in the input mask will be transmitted to us and stored. The transmitted data results from the input mask. Alternatively, contact via the provided email address is possible. In this case, the personal data transmitted with the email will be stored.
- In this context, there is no disclosure of data to third parties. The data is used exclusively for processing the conversation.
- The legal basis for processing data is Art. 6 para. 1 lit. a GDPR if the user has given consent. The legal basis for processing data transmitted in the course of sending an email is Art. 6 para. 1 lit. f GDPR. If the email contact is aimed at concluding a contract, Art. 6 para. 1 lit. b GDPR is an additional legal basis for processing.
- The processing of personal data from the input mask serves us to handle the contact request. In the case of contact by email, this also constitutes the required legitimate interest in processing the data.
- The data is deleted as soon as it is no longer necessary for the purpose of its collection. For personal data from the contact form input mask and data sent by email, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively resolved.
- The user has the option at any time to withdraw consent to the processing of personal data. If the user contacts us by email, they can object to the storage of their personal data at any time. In such a case, the conversation cannot be continued. All personal data stored in the course of contacting us will be deleted in this case.
Data Processing for Contract and Order Processing
-
Orders and Creation of a Customer Account
- If you wish to order products via this website, it is necessary for the conclusion of the contract that you provide your personal data that we need for processing your order. Mandatory information required for contract processing is marked separately; other information is voluntary. We process the data you provide to process your order. For this purpose, we may pass on your payment data to our bank or to payment service providers. The legal basis for this is Art. 6 para. 1 sentence 1 lit. b GDPR.
- You can voluntarily create a customer account on this website by providing personal data, through which we can store your data for later purchases. When creating a customer account, the data you provide is transmitted to us and stored revocably. Which personal data is transmitted results from the input mask. There is no disclosure of data to third parties. The legal basis for processing the data is Art. 6 para. 1 lit. b GDPR.
- The data is deleted as soon as it is no longer necessary for the purpose of its collection. This is the case for data collected during the registration process for the performance of a contract or for the implementation of pre-contractual measures when the data is no longer necessary for the performance of the contract. Even after conclusion of the contract, there may be a need to store personal data of the contractual partner in order to comply with contractual or legal obligations. For example, due to commercial and tax law requirements, we are obliged to store your address, payment and order data for a period of ten years.
- You have the option at any time to change data stored in the customer account.
You can find these functions in the customer account under "Settings" and "Address Book". You can access your customer account by following the "My Page" link that becomes visible in the main menu after logging in.
Furthermore, you have the option at any time to have your customer account deleted. Simply send an email to kontakt@figuya.de with a brief request to delete your customer account.
If the data is necessary for the performance of a contract or for the implementation of pre-contractual measures, deletion of data is only possible to the extent that contractual or legal obligations do not prevent deletion.
-
Payment Processing
- Depending on which payment method you have chosen during the order, we pass on the data collected for payment processing to our bank or to payment service providers. The legal basis for this is Art. 6 para. 1 sentence 1 lit. b GDPR.
-
SOFORT Bank Transfer: Components of SOFORT Bank
Transfer are integrated on this website. SOFORT Bank Transfer is a
payment service that enables cashless payment on the Internet. The
provider of SOFORT Bank Transfer is SOFORT GmbH, Fußbergstraße 1,
82131 Gauting, Germany.
If you have selected "SOFORT Bank Transfer" as the payment method during the order, your data will be automatically transmitted to SOFORT Bank Transfer. By selecting this payment option, you consent to the transmission of personal data required for payment processing. As a buyer, you transmit the PIN and TAN to SOFORT GmbH. SOFORT Bank Transfer then executes a transfer to us after technical verification of the account balance and retrieval of further data to check account coverage. The execution of the financial transaction is then automatically communicated to us.
The personal data exchanged with SOFORT Bank Transfer includes first name, last name, address, email address, IP address, phone number, mobile phone number or other data necessary for payment processing. The purpose of data transmission is payment processing and fraud prevention. The privacy policy of SOFORT Bank Transfer can be found at https://www.sofort.com/ger-DE/datenschutzerklaerung-sofort-gmbh/ .
-
PayPal: Components of PayPal are integrated on this
website. PayPal is an online payment service provider. PayPal enables
online payments to third parties or receiving payments. The provider
is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449
Luxembourg.
If you have selected "PayPal" as the payment method during the order, your data will be automatically transmitted to PayPal. By selecting "PayPal" as the payment method, you consent to the transmission of personal data required for payment processing. The data transmitted to PayPal includes first name, last name, address, email address, IP address, phone number, mobile phone number or other data necessary for payment processing.
The purpose of data transmission is payment processing and fraud prevention. The privacy policy of PayPal can be found at https://www.paypal.com/de/webapps/mpp/ua/privacy-full .
Shipping
The data collected during the order is passed on to the transport company we have commissioned with delivery for the purposes of contract processing, to the extent necessary for delivery of the goods. Shipping is done via DHL. We pass on your name and delivery address to DHL exclusively for the purpose of delivering goods. The legal basis for this is Art. 6 para. 1 lit. b GDPR.
Newsletter
- You can subscribe to our newsletter during an order, through which we inform you about our current interesting offers.
- For registration to our newsletter, we use the so-called double opt-in procedure. This means that after your registration, we will send you an email to the email address you provided, asking you to confirm that you wish to receive the newsletter. If you do not confirm your registration within 24 hours, your information will be blocked and automatically deleted after one month. In addition, we store your IP addresses and times of registration and confirmation. The purpose of this procedure is to be able to prove your registration and, if necessary, to clarify any possible misuse of your personal data.
- The only mandatory information for sending the newsletter is your email address. After your confirmation, we store your email address for the purpose of sending the newsletter. The legal basis is Art. 6 para. 1 sentence 1 lit. a GDPR.
- You can withdraw your consent to receiving the newsletter at any time and unsubscribe from the newsletter. You can declare your withdrawal by clicking on the link provided in every newsletter email, by email to kontakt@figuya.de, or by a message to the contact details provided in the imprint.
Google Analytics
- This website uses Google (Universal) Analytics for analysis purposes, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). We use Google (Universal) Analytics to analyze the use of this website and to continuously and regularly improve individual functions and offerings as well as the user experience. Through the statistics obtained, we can improve our offering and make it more interesting for you as a user.
- Google (Universal) Analytics uses methods that enable analysis of your use of this website, such as cookies. Cookies are small files that are stored on your device and enable analysis of your use of this website. The information generated by cookies about your use of this website is usually transmitted to and stored on a Google server. This may also involve transmission to Google LLC servers in the USA.
- This website uses Google (Universal) Analytics exclusively with the "_anonymizeIp()" extension. By activating IP anonymization, the IP address is shortened before transmission within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google LLC server in the USA and shortened there. In these exceptional cases, data processing is carried out pursuant to Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.
- On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide us with other services relating to website and internet use. The anonymized IP address transmitted by your browser within the scope of Google (Universal) Analytics is generally not merged with other Google data.
- You can prevent the storage of cookies by setting your browser software accordingly. However, we point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en .
- Where legally required, we have obtained your consent pursuant to Art. 6 para. 1 lit. a GDPR for the processing of your data described above. You can withdraw your consent at any time with effect for the future.
Presence on Social Networks (Facebook, Twitter, Instagram, Pinterest)
We maintain online presences on various social media networks to inform about our products and special promotions and to actively communicate with customers and interested parties. This serves pursuant to Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests, which prevail in the context of a balancing of interests, in an optimized presentation of our products and effective communication with customers and interested parties.
When visiting social media presences, user data is usually automatically collected and stored for market research and advertising purposes. Usage profiles are created from this data using pseudonyms. For a detailed description of the respective processing forms and opt-out options, we refer to the privacy policies and information provided by the operators of the respective networks.
- Facebook: https://www.facebook.com/about/privacy/
- Twitter: https://twitter.com/en/privacy
- Instagram: https://help.instagram.com/519522125107875
- Pinterest: https://policy.pinterest.com/en/privacy-policy
Deletion of Data
The data processed by us will be deleted in accordance with legal requirements as soon as the consent given for processing is revoked or other permissions cease to apply (e.g., if the purpose of processing this data has ceased to exist or it is not required for the purpose).
If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted to these purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for the assertion, exercise or defense of legal claims or for the protection of the rights of another natural or legal person.
Your Rights as a Data Subject
The GDPR grants you as a data subject comprehensive rights (information and intervention rights) vis-à-vis the controller regarding the processing of your personal data. As a data subject, you have the following rights:
- pursuant to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;
- pursuant to Art. 16 GDPR, the right to immediately request the correction of inaccurate or completion of your personal data stored by us;
- pursuant to Art. 17 GDPR, the right to request the deletion of your personal data stored by us;
- pursuant to Art. 18 GDPR, the right to request the restriction of the processing of your personal data;
- pursuant to Art. 20 GDPR, the right to receive your personal data in a structured, commonly used and machine-readable format or to request transmission to another controller;
- pursuant to Art. 7 para. 3 GDPR, you have the right to withdraw consent once given to the processing of data at any time with effect for the future;
- pursuant to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority.
Right to Object
Insofar as we process personal data as explained above to safeguard our legitimate interests which prevail in the context of a balancing of interests, you can object to this processing with effect for the future. If the processing is for direct marketing purposes, you can exercise this right at any time as described above.
After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves the assertion, exercise or defense of legal claims.
Contact Options
For questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data, as well as revocation of consent given or objection to a specific use of data, please contact us directly via the contact details in our imprint.
Last updated: February 24, 2020