Data Protection Declaration and Information on Data Protection
The protection of your personal data is of high importance to us in particular the protection of your personality rights when processing and using these data. Hereinafter we inform you about the processing of personal data when using our website. Personal data are all data which refer to you personally such as the name, address, email address, user behavior, etc.
WMF Group GmbH strictly complies with statutory provisions when collecting, processing or using your data including, but not limited to, the provisions of the General Data Protection Regulation of the EU (“GDPR”), the Data Protection Law of Germany (Bundes-Datenschutzgesetz – (“BDSG”) and the Telemedia Law of Germany (Telemediengesetz). In this privacy declaration we provide an overview of the type of data we collect, the purposes for which we collect it, and our efforts to ensure it remains protected. This privacy declaration applies to this website only and does not apply to any website to which this website provides a link. Because legal provisions and commerce in general change, we reserve the right to amend or modify this privacy declaration at any time.
1. Responsible body and Data protection Officer
This website is a service of WMF Group GmbH, Eberhardstr. 35, 73312 Geislingen/Steige, Germany, email: firstname.lastname@example.org (“WMF”) being the controller in the meaning of Article 4 GDPR.
You can contact our Data Protection officer via the contact form under “request too the data protection officer” or our postal address adding “Attn. data protection officer”.
2. Automated data collection and processing
2.1 In general, you will not be required to disclose your identity if you visit our website without registering, making a purchase, or completing any other transaction. As is typical for websites, unless deactivated by you our server collects the following data automatically and saves it temporarily in the server log files transmitted by the browser:
- browser type and version;
- operating system of the requesting computer;
- file inquiry received from the requesting computer;
- http response code;
- referring URL, that is, the site visited last;
- IP address of the requesting computer; and
- time of the server inquiry
Server log files will not be analyzed for personal data. We do not allocate personal data to specific persons at any time or aggregate this data with data from other sources except for the IP address connected to your order which we save when you place an order in our online shop.
We use econda to analyze how we can improve our website permantly. The statistics we receive help us to improve our services so it becomes of more value for you as a user. The collected data is saved and will be analyzed pseudonymously. Legal basis for the use of econda is Article. 6 para 1 Sentence 1 (f) GDPR. For further information please refer to the data protection declaration of econda: https://www.econda.de/datenschutzhinweise/.
2.3 This website uses Google Analytics, a web analytics service provided by Google Inc. (hereinafter, “Google”). Google Analytics uses small text files, referred to as cookies, which are saved on your computer to facilitate analysis of your website use. The information generated by cookies regarding your use of this website typically is transmitted to and saved on a Google server located in the United States. If and when IP anonymization is activated on this website, Google will truncate your IP address for transmission among member states of the European Union or to other member states of the Agreement on the European Economic Area. Only in exceptional cases will your full IP address be transmitted to a Google server in the United States and then truncated. At the request of the operator of this website, Google will use the information to evaluate your use of this website, to compile reports on website activity, and to provide the operator of this website with other services relating to website activity and Internet use.
According to Google, the IP address transmitted from your browser as part of Google Analytics will not be merged with any other data held by Google.
You may refuse the saving of cookies by selecting the appropriate settings in your browser software; however, please note that if you do so you may not be able to use the full functionality of this website. In addition, you can object to Google’s collection of data generated by cookies which data relates to your use of this website (including your IP address) as well as to Google’s processing of the data. To do so, download and install the browser plug-in available at https://tools.google.com/dlpage/gaoptout?hl=en.
This website uses Google Analytics with the addendum _anonymizeIp(). This means that IP addresses are truncated before being processed and cannot be associated with individual persons. In the event a personal association to you of any data collected in connection with you is possible, such association is excluded without delay and the personal data is erased immediately.
We use Google Analytics regularly to analyze and enhance the use of our website. The resulting statistics allow us to improve our offerings and make them more interesting for you, the user. In exceptional cases in which personal data is transmitted to the United States, Google is bound by the EU-US Privacy Shield. The legal basis of our use of Google Analytics is Article 6 (1) p. 1 f) of the GDPR.
2.4 As an “AdWords” customer this website uses Google Conversion Tracking, an analytical service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). This means that Google AdWords puts a cookie (“conversion cookie”) on your computer if you have arrived at our website via a Google advert. These cookies expire after 30 days and cannot be used for personal identification. If you visit certain of our pages and the cookie has not yet expired, we and Google can recognise that someone has clicked on the advert and then been forwarded to our page. Every AdWords customer is given a unique cookie. This means cookies cannot be traced via the websites of AdWords customers. The information gained by means of the conversion cookie helps produce conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers find out the total number of users who have clicked on their adverts and been forwarded to a page with a conversion tracking tag. But they are not given information with which they can identify users personally. If you do not wish to take part in the tracking process, you can reject the setting of a cookie that is required - either as a browser setting or by deactivating the setting of cookies in general. You can also deactivate cookies for conversion tracking by setting your browser to block cookies from the domain “googleadservices.com.”
By using our services, you declare your consent to the processing of data collected by Google about you in the manner described above and for the purposes mentioned here. Legal basis for the processing of the data is Article 6 para.1 sentence 1 (f) GDPR.
We would like to point out that Google has its own data protection guidelines, which are independent of ours. We accept no responsibility or liability for these guidelines and processes. Before using our website, please read also about the Google data protection regulations.
2.5 With your consent, our website uses the “tracking pixel” of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). This pixel allows user behaviour to be tracked when they are taken to our website having clicked on a Facebook advert. This allows us to record the effectiveness of Facebook adverts for statistical and market research purposes. The data recorded in this way is anonymous for us. In other words, we do not see personal data on individual users. However, this data is saved by Facebook and processed, and we will inform you of this based on the knowledge we have. Legal basis for the processing of the data is Article 6 para. 1 sentence 1 (f) GDPR.
Facebook can connect this data with your Facebook account and also use it for its own advertising purposes in accordance with Facebook’s data usage policy https://www.facebook.com/about/privacy/. You have the option of blocking Facebook and its partners from showing adverts. The Facebook advertising settings can be edited at the following address: https://www.facebook.com/ads/website_custom_audiences/.
3. Collecting and processing data provided voluntarily
3.1 General visit of our website
In principle, you can visit our website without logging in. However, if you provide us with personal data including your name, address, date of birth, e-mail address, or phone number by e-mail or through our website, you are doing so on a voluntary basis. We mainly will use the personal data you voluntarily provide to us to perform our contractual obligations, to process your inquiries and/or orders. The personal data collected will automatically be deleted when the storage is not necessary anymore or the processing will be restricted if we have to comply with statutory retention requirements. Legal basis for the processing is Article 6 para. 1 sentence 1 (a), (b) and (f) GDPR.
3.2 Ordering products from our website
If you want to order products from our shop on our website, it is necessary for the execution of the contract that you provide us with the personal data we need to perform our contractual obligations. The mandatory information are highlighted. Any other data you will provide voluntary. We use the data we receive from you solely to perform our contractual obligations and may forward payment details to our bank or the online payment service used. If you use an online payment service (e.g., PayPal) or if you pay by credit card, we will transmit your data to the relevant service provider for settlement. Legal basis for this is Article 6 para. 1 sentence 1 (b) GDPR.
We will process your personal data only as long as it is necessary for the existing customer relation. However, we are legally obliged in accordance with statutory law to retain your address, payment or order details for ten years.
We offer you the option of saving your personal data in a password-protected customer account so you will not have to enter your name and address on subsequent visits to our website. The data you provided initially will be entered automatically into the order form for every purchase you make. You can delete your customer account at any time. Please send us an email to email@example.com
3.3 Using of free services of WMF
However, we also may have to collect your personal data if you wish to use other free services we offer including
- subscribing to the WMF newsletter;
- participating in a lucky draw;
- contacting us;
- registering for My WMF and using your profile and/or wish list in a secured mode;
- requesting a catalogue;
- reserving products; or
- submitting an application online.
Please note that you are free to provide us with personal data. If and when you do not submit the data required to use a specific service, you will not be able to use the service at all or only in part. We process the personal data only to provide the free services to you. Legal basis is Article 6 para. 1 sentence 1 (a) GDPR. The data is deleted and/or blocked automatically pursuant to the applicable laws. Provided, deleting the data does not violate any statutory or contractual retention periods.
To subscribe to the WMF newsletter, you will be required to provide your e-mail address. We will use this address only to communicate with you in connection with our newsletter and will not disclose it to third parties. If you provide your name and address (e.g., by registering for My WMF) in addition to your e-mail address, we also will send regional information to you (e.g., regarding WMF stores in your region). By subscribing to the newsletter you agree to the aforementioned data being saved by us to enable us to dispatch the newsletter. Your data will not be used in any other way. For statistical purposes, we will execute anonymized analyses of clicks on links in the newsletters. In these analyses, the persons who click on the links cannot be identified. You can administer your consent at any time in your customer account.
You may revoke your consent to the use, processing and dissemination of your personal data for newsletter dispatch purposes at any time with future effect by sending a message to us by mail at WMF Group GmbH, DATS, Eberhardstr. 35, 73312 Geislingen/Steige, Germany or by filling in the contact form. To unsubscribe from the WMF newsletter, you can also click the respective link inserted at the end of every newsletter.
3.4 Acceptance of voucher offering by Solvendus
In case you want to accept a voucher offered by Sovendus GmbH on our website the following applies:
The pseudonymized and encoded hash values of your email address and your IP-address are forwarded to Sovendus GmbH, Moltkestr. 11, 73133 Karlsruhe, Germany to make specific and interesting voucher offerings to you. Legal basis for the processing is Article 6 para. 1 sentence 1 (f) GDPR. The pseudonymized hash value of the email address is necessary to observe possible objections against advertisement by Sovendus. Legal basis for the processing is Article 21 para. 3 and Article 6 para. 1 sentence 1 (f) GDPR. The IP-address is used by Sovendus for data security only and will normally be anonymized within seven days. Legal basis for the processing is Article 6 para. 1 sentence 1 (f) GDPR. Moreover we forward the pseudonymized order number, order value with the currency, session-ID, voucher code and time stamp to Sovendus. Legal basis for the processing is Article 6 para. 1 sentence 1 (f) GDPR.
If you are interested in a voucher of Sovendus, there is no objection registered under your email address and the you click on the voucher banner which will be only shown in this case then your encoded title, name and email address will be forwarded to Sovendus to prepare the voucher. Legal basis for the processing is Article 6 para. 1 sentence 1 (f) GDPR.
You will find further information on the processing of your data by Sovendus in Sovendus’ online data privacy declaration at www.sovendus.de/datenschutz.
4. Disclosing data to third parties
We will not disclose any personal data you provide to us to any third parties without your express previous consent as set out under 3. above unless such disclosure is required to process your requests and orders or in connection with your use of our services. In this case, your data will be transmitted to our subcontractors who will use the data only to fulfill the respective orders, for example, to ship goods or settle payments.
Your data may be transmitted for the reasons below to the following organizations:
- if you want to collect Payback points for your purchase in the WMF online shop, to Payback Rabattverein e.V., Theresienhöhe 12, 80339 Munich, Germany;
- for a credit rating if you opted to pay upon receipt of the invoice, to arvato infoscore Risk Management infoscore Consumer Data GmbH, Rheinstr. 99, 76532 Baden-Baden, Germany;
- for collection purposes within Germany if you default on a payment, to EOS KSI Inkasso Deutschland GmbH, Mallaustr. 58, 68219 Mannheim, Germany, where the data will be saved and used;
- as part of order data processing pursuant to § 11 of the Federal Data Protection Act (Bundesdatenschutzgesetz), to service providers in line with the provisions of the Federal Data Protection Act; or
- to fulfill our statutory obligations, to entities authorized to disclose such information.
5. Using cookies
5.2 This website uses the following categories of cookies:
5.2.1 Advertising and targeting cookies
We use these cookies to ensure that the information we provide matches you and your interests. In addition, we use them to determine the frequency of specific advertising pop-ups and the success of advertising campaigns. Advertising and targeting cookies are cookies placed by third parties with our consent. The information saved in the cookies relates to the fact that you visited our website and this information will be shared with other providers. Advertising and targeting cookies may be linked to the functions of specific third-party content.
5.2.2 Necessary cookies
These cookies are necessary for you to use our website and they allow you to make use of all the content and functions on our website, for example, they allow you to register for or log into specific sections of our website and they allow us to provide you with a cart for your orders. These cookies are necessary for you to use the services offered on our website.
5.2.3 Performance cookies
These cookies collect statistical information regarding the use of our website including the pages visited most frequently and the occurrence of errors. Performance cookies do not collect information that can be used to identify you as the user. The information saved in these cookies is aggregated and anonymized for us. We use performance cookies only to improve our website’s performance.
5.2.4 Functional cookies
Functional cookies save the settings you use to display our website including the login, language, region, etc. They do not contain any other information and cannot be read by third parties.
5.2.5 Prudsys Cookies
Your shopping history is used to provide you with the best personal product recommendations. This includes in particular products or product categories that you have already clicked on, searched or bought. This data are stored anonimously and processed by the prudsys AG. We use this information to provide you with personalised product recommendations and help you find relevant products. You can contradict this surfing behavior analysis by the prudsys AG at any time. Please note that in that case we will not be able to offer you personalised recommendations in this browser.
The surfing behavior analysis can be cancelled at any time:
5.3 In your browser settings you can select whether you want to allow or avoid cookies. To adjust your settings, please review your browser’s documentation.
6. Security of transmitted data
Your personal data will be encoded before transmission. When transferring data, we use the Secure Socket Layer in connection with 256 bit encoding. Offering the highest level of security, this method also is used by banks for their online banking offerings.
Payment settlements are subject to the highest security standard. All data is transferred with 256 bit SSL encoding to protect it against illegal access. In addition, your credit card data is processed and saved by the certified payment service provider PAYONE GmbH in compliance with the credit card industry’s strictest security requirements, the Payment Card Industry Data Security Standard (PCI DSS). This means that your personal and card-related data also is protected by the highest standard of data protection security.
7. Your Rights
7.1 You have the following rights with regard to your personal data:
- right of access
- right of rectification or erasure
- right of restriction of processing
- right to object against the processing, in particular in case of
- right to data portability
Please send a letter with your request to us at WMF Group GmbH, Eberhardstr. 35, 73312 Geislingen/Steige, Germany, or by fill in the contact form.
7.2 In addition you have the right to file a complaint to a data protection authority about the processing of personal data by us.
8. More information
Your trust is our priority. This is why we will answer all your questions regarding the processing of your personal data. If you have any questions beyond this data protection declaration, you can contact us at any time by using the contact form.
Your message to the WMF Data Protection Officer
We are happy to answer your questions.