PRIVACY POLICY


Your data is safe with us

This Privacy Policy describes how alessajoosten.com (the “Site” or “we”) collects, uses, and discloses your personal data ("data") when you visit or make a purchase from the Site.

Personal data will only be processed by us to the extent necessary and for the purpose of providing a functional and user-friendly website, including its contents, and the services offered there.

Per Art. 4 No. 1 of Regulation (EU) 2016/679, i.e. the General Data Protection Regulation (hereinafter referred to as the "GDPR"), "processing" refers to any operation or set of operations such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction performed on personal data, whether by automated means or not.

The following privacy policy is intended to inform you about the type, scope, purpose, duration, and legal basis for the processing of such data either under our own control or in conjunction with others. We also inform you below about the third-party components we use to optimize our website and improve the user experience which may result in said third parties also processing data they collect and control.


I. INFORMATION ABOUT US AS CONTROLLERS OF YOUR DATA
The party responsible for this website (the "controller") for purposes of data protection law is:

Alessa Joosten, Bruchstraße 99, 40235 Düsseldorf, Germany (0049178234095, info[@]alessajoosten.com)

 

II. THE RIGHTS OF USERS AND DATA SUBJECTS
General Data Protection Regulation (“GDPR”)
If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your personal data be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information.

Your personal data will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.

Regarding the data processing to be described in more detail below, users and data subjects have the right

  • to confirmation of whether data concerning them is being processed, information about the data being processed, further information about the nature of the data processing, and copies of the data (cf. also Art. 15 GDPR);
  • to correct or complete incorrect or incomplete data (cf. also Art. 16 GDPR);
  • to the immediate deletion of data concerning them (cf. also Art. 17 DSGVO), or, alternatively, if further processing is necessary as stipulated in Art. 17 Para. 3 GDPR, to restrict said processing per Art. 18 GDPR;
  • to receive copies of the data concerning them and/or provided by them and to have the same transmitted to other providers/controllers (cf. also Art. 20 GDPR);
  • to file complaints with the supervisory authority if they believe that data concerning them is being processed by the controller in breach of data protection provisions (see also Art. 77 GDPR).

In addition, the controller is obliged to inform all recipients to whom it discloses data of any such corrections, deletions, or restrictions placed on processing the same per Art. 16, 17 Para. 1, 18 GDPR. However, this obligation does not apply if such notification is impossible or involves a disproportionate effort. Nevertheless, users have a right to information about these recipients.

Likewise, under Art. 21 GDPR, users and data subjects have the right to object to the controller's future processing of their data pursuant to Art. 6 Para. 1 lit. f) GDPR. An objection to data processing for the purpose of direct advertising is permissible.

If you would like to make a complaint, please contact us by e-mail at info[@]alessajoosten.com or by mail using the details provided below:

Alessa Joosten, Bruchstraße 99, 40235 Düsseldorf, Deutschland

If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority here https://www.ldi.nrw.de/mainmenu_Ueberuns/submenu_Kontaktpersonen/index.php#O

III. INFORMATION ABOUT THE DATA PROCESSION
When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information that can uniquely identify an individual (including the information below) as “personal data” or just as “data”. See the list below for more information about what personal dnformation we collect and why.

COLLECTION OF DATA WHEN VISITING OUR SITE
For technical reasons, the following data sent by your internet browser to us or to our server provider will be collected, especially to ensure a secure and stable website

Examples of personal data collected:
type and version of web browser, IP address, the website from which you came (referrer URL), operating system, date and time of your visit, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.

Purpose of collection:
to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.

Source of collection:
Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels

Disclosure for a business purpose:
shared with our processor Shopify

The data thus collected will be temporarily stored, but not in association with any other of your data.

The basis for this storage is Art. 6 Para. 1 lit. f) GDPR. Our legitimate interest lies in the improvement, stability, functionality, and security of our website.

COLLECTION OF DATA WITHIN AN ORDER
The data you submit when ordering goods from us will have to be processed to fulfil your order. Please note that orders cannot be processed without providing this data.

The legal basis for this processing is Art. 6 Para. 1 lit. b) GDPR.

After your order has been completed, your personal data will be deleted, but only after the retention periods required by tax and commercial law.

Examples of personal Information collected:
name, billing address, shipping address, email address, phone number, information concerning the product you have purchased, date and time of purchase, payment information (including card holder, card number, expiration date, Paypal references)

Purpose of collection:
to provide products or services to you to fulfil our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.

Disclosure for a business purpose:
shared with our processor Shopify

When you place an order through the Site, we will retain your personal data for our records unless and until you ask us to erase this information.

DISCLOSING DATA TO THIRD PARTY AS PART OF THE EXECUTION OF THE ORDER
To process your order, we will share your data with the shipping company responsible for delivery to the extent required to deliver your order. We will forward personal data (name, shipping address, e-mail address, phone number) to the following transport companies:

United Parcel Service Deutschland Inc.& Co. oHG, Görlitzer Straße 1, 41460 Neuss, Germany

For handling the payment of your order, we will transfer your chosen payment details with the payment service provider to the extent required to process your payment.
The legal basis for the transfer of this data is Art. 6 Para. 1 lit. b) GDPR.

Paypal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden

Visa Europe Services Inc., Zweigniederlassung London, 1 Sheldon Square, London W2 6TT, United Kingdom

Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium

COLLECTION OF DATA WITHIN REGISTRATION/ CREATING A CUSTOMER ACCOUNT
If you create a customer account with us via our website, we will use the data you entered during registration (e.g. your name, your address, or your email address) exclusively for services leading up to your potential placement of an order or entering some other contractual relationship with us, to fulfil such orders or contracts, and to provide customer care (e.g. to provide you with an overview of your previous orders or to be able to offer you a wish list function). We also store your IP address and the date and time of your registration. This data will not be transferred to third parties.

During the registration process, your consent will be obtained for this processing of your data, with reference made to this privacy policy. The data collected by us will be used exclusively to provide your customer account. 

If you give your consent to this processing, Art. 6 Para. 1 lit. a) GDPR is the legal basis for this processing.

If the opening of the customer account is also intended to lead to the initiation of a contractual relationship with us or to fulfil an existing contract with us, the legal basis for this processing is also Art. 6 Para. 1 lit. b) GDPR.

You may revoke your prior consent to the processing of your personal data at any time under Art. 7 Para. 3 GDPR with future effect. All you must do is inform us that you are revoking your consent.

The data previously collected will then be deleted as soon as processing is no longer necessary. However, we must observe any retention periods required under tax and commercial law.

COLLECTION OF DATA WITHIN CONTACTING US
If you contact us via email or the contact form, the data you provide will be used for the purpose of processing your request. We must have this data to process and answer your inquiry; otherwise, we will not be able to answer it in full or at all.

Examples of personal data collected:
name, email address, date and time of your inquiry and the content of your text.

Purpose of collection:
to provide customer support

The legal basis for this data processing is Art. 6 Para. 1 lit. b) GDPR.

Your data will be deleted once we have fully answered your inquiry and there is no further legal obligation to store your data, such as if an order or contract resulted therefrom.

SHARING DATA
We use Shopify to power our online store. To help us to provide our services and fulfil our contracts with you, we share your personal data with our service provider Shopify.
The legal basis is Art.  6 para. 1 lit. b) GDPR (contract initiation/contract processing).

a) Shopify-Shop-Software
"Shopify" is the service of a group of companies consisting of the companies Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc., Shopify (USA) Inc., Shopify Commerce Singapore Pte.  Ltd., and Shopify International Limited.

Insofar as we are located in the European Economic Area (EEA), processing is carried out by Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, hereinafter referred to only as "Shopify".

However, due to the interconnection of the companies, it cannot be ruled out that processing will also take place in Canada and the USA, i.e. outside the EEA.  However, when the data is transmitted to Shopify Inc., Canada, an appropriate level of data protection is guaranteed by the adequacy decision of the European Commission. 

Shopify processes the following data on our behalf:

Name, billing and, if applicable, delivery address, email address, payment details, possibly company name, possibly telephone number, IP address, information about orders, information about the shops supported by Shopify that you visit, as well as information about your device and your internet browser.

At https://www.shopify.de/legal/datenschutz Prospectone Sp.z.o.o. offers further data protection information.

b) Shopify web analysis
Insofar as we also use Shopify's web analysis service on our website, Shopify will save cookies on your device via your internet browser.  These cookies transfer and evaluate further information to a Shopify server, such as i.e. the location, time or frequency of your visit to our website.

The legal basis is Art.  6 para. 1 lit. f) GDPR. Our legitimate interest lies in the analysis and optimisation of our website.

If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. You can find more information on this under “Cookies”.

You can read more about how Shopify uses your personal data here: https://www.shopify.com/legal/privacy.

We may share your personal data to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

PINTEREST
We maintain an online presence on Pinterest to present our company and our services and to communicate with customers/prospects. Pinterest is a service of Pinterest Inc., 651 Brannan Street, San Francisco, CA, 94107, USA.

We would like to point out that this might cause user data to be processed outside the European Union, particularly in the United States. This may increase risks for users that, for example, may make subsequent access to the user data more difficult. We also do not have access to this user data. Access is only available to Pinterest.

The Pinterest privacy policy can be found here:

https://policy.pinterest.com/de/privacy-policy

INSTAGRAM
To advertise our products and services as well as to communicate with interested parties or customers, we have a presence on the Instagram platform.

On this social media platform, we are jointly responsible with Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland.

The data protection officer of Instagram can be reached via this contact form:

https://www.facebook.com/help/contact/540977946302970

We have defined the joint responsibility in an agreement regarding the respective obligations within the meaning of the GDPR. This agreement, which sets out the reciprocal obligations, is available at the following link:

https://www.facebook.com/legal/terms/page_controller_addendum

The legal basis for the processing of the resulting and subsequently disclosed personal data is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the analysis, communication, sales, and promotion of our products and services.

The legal basis may also be your consent per Art. 6 para. 1 lit. a GDPR granted to the platform operator. Per Art. 7 para. 3 GDPR, you may revoke this consent with the platform operator at any time with future effect.

When accessing our online presence on the Instagram platform, Facebook Ireland Ltd. as the operator of the platform in the EU will process your data (e.g., personal information, IP address, etc.).

This data of the user is used for statistical information on the use of our company presence on Instagram. Facebook Ireland Ltd. uses this data for market research and advertising purposes as well as for the creation of user profiles. Based on these profiles, Facebook Ireland Ltd. can provide advertising both within and outside of Instagram based on your interests. If you are logged into Instagram at the time you access our site, Facebook Ireland Ltd. will also link this data to your user account.

If you contact us via Instagram, the personal data you provide at that time will be used to process the request. We will delete this data once we have completely responded to your query, unless there are legal obligations to retain the data, such as for subsequent fulfilment of contracts.

Facebook Ireland Ltd. might also set cookies when processing your data.

If you do not agree to this processing, you have the option of preventing the installation of cookies by making the appropriate settings in your browser. Cookies that have already been saved can be deleted at any time. The instructions to do this depend on the browser and system being used. For Flash cookies, the processing cannot be prevented by the settings in your browser, but instead by making the appropriate settings in your Flash player. If you prevent or restrict the installation of cookies, not all the functions of Instagram may be fully usable.

Details on the processing activities, their suppression, and the deletion of the data processed by Instagram can be found in its privacy policy:

https://help.instagram.com/519522125107875

It cannot be excluded that the processing by Facebook Ireland Ltd. will also take place in the United States by Facebook Inc., 1601 Willow Road, Menlo Park, California 94025.

SOCIAL MEDIA LINKS VIA GRAPHICS
We also integrate the following social media sites into our website. The integration takes place via a linked graphic of the respective site. The use of these graphics stored on our own servers prevents the automatic connection to the servers of these networks for their display. Only by clicking on the corresponding graphic will you be forwarded to the service of the respective social network.

Once you click, that network may record information about you and your visit to our site. It cannot be ruled out that such data will be processed in the United States.

Initially, this data includes such things as your IP address, the date and time of your visit, and the page visited. If you are logged into your user account on that network, however, the network operator might assign the information collected about your visit to our site to your personal account. If you interact by clicking Like, Share, etc., this information can be stored your personal user account and possibly posted on the respective network. To prevent this, you need to log out of your social media account before clicking on the graphic. The various social media networks also offer settings that you can configure accordingly.

The following social networks are integrated into our site by linked graphics:

PINTEREST
Pinterest Inc., 651 Brannan Street, San Francisco, CA, 94107, USA.

Privacy Policy: https://policy.pinterest.com/de/privacy-policy

INSTAGRAM
Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland, a subsidiary of Facebook Inc., 1601 S. California Ave., Palo Alto, CA 94304, USA.

Privacy Policy: https://help.instagram.com/519522125107875

COOKIES
We use cookies on our website. A cookie is a small amount of information that’s downloaded to your computer or device by your browser when you visit our Site.
We use several cookies, including functional, performance, advertising, and social media or content cookies.
The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

a) Session Cookies
Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and shopping card function). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.
When you close your browser, these session cookies are deleted.

The legal basis for such processing is Art. 6 Para. 1 lit. b) GDPR, insofar as these cookies are used to collect data to initiate or process contractual relationships.

If the processing does not serve to initiate or process a contract, our legitimate interest lies in improving the functionality of our website. The legal basis is then Art. 6 Para. 1 lit. f) GDPR.

b) Third-party cookies
If necessary, our website may also use cookies from companies with whom we cooperate for the purpose of advertising, analysing, or improving the features of our website.

Please refer to the following information for details, for the legal basis and purpose of such third-party collection and processing of data collected through cookies.

c) cookies necessary for the function of the store

Name

Function

_ab

Used in connection with access to admin.

_secure_session_id

Used in connection with navigation through a storefront.

cart

Used in connection with shopping cart.

cart_sig

Used in connection with checkout.

cart_ts

Used in connection with checkout.

checkout_token

Used in connection with checkout.

secret

Used in connection with checkout.

secure_customer_sig

Used in connection with customer login.

storefront_digest

Used in connection with customer login.

_shopify_u

Used to facilitate updating customer account information.

 

 

 

d) Reporting and analytics

Name

Function

_tracking_consent

Tracking preferences.

_landing_page

Track landing pages

_orig_referrer

Track landing pages

_s

Shopify analytics.

_shopify_fs

Shopify analytics.

_shopify_s

Shopify analytics.

_shopify_sa_p

Shopify analytics relating to marketing & referrals.

_shopify_sa_t

Shopify analytics relating to marketing & referrals.

_shopify_y

Shopify analytics.

_y

Shopify analytics.

 

e) Disabling cookies
You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.

You can refuse the use of cookies by changing the settings on your browser. Likewise, you can use the browser to delete cookies that have already been stored. However, the steps and measures required vary, depending on the browser you use. Most browsers automatically accept cookies, but you can choose whether to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as www.allaboutcookies.org.

Browser settings cannot prevent so-called flash cookies from being set. Instead, you will need to change the setting of your Flash player. The steps and measures required for this also depend on the Flash player you are using.

Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

CHANGES
We may update this Privacy Policy from time to time to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

Last update: 10.08.2021

We made use of the free data protection generator: Model Data Protection Statement for Anwaltskanzlei Weiß & Partner