Privacy
With this privacy policy, we inform you about the scope of the processing of your personal data (hereinafter "data").
1. Responsible for data processing
Responsible for data processing in accordance with the provisions of the General Data Protection Regulation (GDPR) is:
CREADERM GmbH & Co. KG
Turnerstr. 54b · D-33602 Bielefeld
E-Mail: info@creaderm.de
2. Contact details of our data protection officer
CREADERM GmbH & Co. KG
Turnerstr. 54b · D-33602 Bielefeld
E-Mail: info@creaderm.de
3. General information on data processing
We process data as part of our business and website operations.
This also includes disclosure by transfer to third parties and, where applicable, to so-called third countries outside the European Union ("EU") and the European Economic Area ("EEA"). Where we transfer data outside the EU or the EEA, we have marked this accordingly below.
4. Data processing
The individual data concerned, processing purposes, legal bases, recipients and, where applicable, transfers to third countries are listed below:
a) Website visit log file
We log your website visit. In doing so, we process:
- name(s) of our accessed website(s),
- date and time of retrieval,
- the amount of data transferred,
- the browser type and version,
- the operating system you are using,
- the referrer URL (the previously visited website),
- your IP address,
- the requesting provider.
The legal basis for data processing is our overriding legitimate interest in the ongoing provision and security of our website in accordance with Art. 6 (1) f) DSGVO.
The log file is deleted after seven days, unless it is needed to prove or clarify specific legal violations that have become known within the retention period.
b) Hosting via ADMIN INTELLIGENCE
To provide our online presence, we use the services of web hosting providers who process the above-mentioned data and all data to be processed in connection with the operation of this website (log file when visiting the website) on our behalf.
The legal basis for data processing is our overriding legitimate interest in the provision of our website in accordance with Art. 6 (1) f) DSGVO.
We use ADMIN INTELLIGENCE GmbH, Sedanstrasse 124, 89077 Ulm, Germany for our hosting. The servers are operated exclusively in Germany.
c) Contact
If you contact us, we process the following data from you for the purpose of processing and handling your enquiry: Name, contact details -if provided by you- and your message.
The legal basis of the data processing is our obligation to fulfil the contract and/or to fulfil our pre-contractual obligations pursuant to Art. 6 (1) b) DSGVO and/or our overriding legitimate interest in processing your enquiry pursuant to Art. 6 (1) f) DSGVO.
d) Contact for applications
If you contact us to send us your application as an employee, e.g. by e-mail or via a contact form, the data you provide (e.g. name, e-mail address, desired place of employment, etc.), your message and the application documents submitted will be processed exclusively for the purpose of processing and handling your application request.
The legal basis for data processing is primarily § 26 BDSG. According to this, the processing of data required in connection with the decision on the establishment of an employment relationship is permissible.
Should the data be necessary for legal prosecution after completion of the application process, data processing may be carried out in order to safeguard our legitimate interests pursuant to Art. 6 (1) f) DSGVO, namely for the assertion and/or defence of claims.
e) Customer account
In connection with the opening and use of a customer account, we process your customer data (name, address, e-mail address, bank details) as well as your usage data (username, password). This enables you to manage your orders and we can identify you as a customer. The legal basis for this data processing is your consent in accordance with Art. 6 (1) a) DSGVO.
f) Contract processing
We process your order data to handle the contractual relationship between you and us.
We transmit your address data to the company commissioned with the delivery.
We transmit your transaction data (name, date of order, payment method, date of dispatch and/or receipt, amount and payee, bank details or credit card details, if applicable) to the payment service provider commissioned to process the payment.
The legal basis for the data processing is the fulfilment of our contractual obligations pursuant to Art. 6 (1) b) DSGVO and, in individual cases, the fulfilment of our legal obligations pursuant to Art. 6 (1) c) DSGVO.
We use an inventory management system for contract processing as part of order processing. For this purpose, your personal data collected as part of the order will be transmitted to JTL-Software-GmbH, Rheinstr. 7, 41836 Hückelhoven, Germany.
g) Shipping status notifications
If you would like to be informed by the shipping service provider about the status of the shipment, we will pass on your e-mail address and telephone number to the shipping company selected in each case, if necessary.
The legal basis of this data processing is your consent pursuant to Art. 6 (1) a) DSGVO.
h) PayPal
All PayPal transactions are subject to the PayPal privacy policy. This can be found here: PayPal privacy policy
i) Amazon Pay
All Amazon Pay transactions are subject to the Amazon Pay privacy policy. This can be found here: Amazon Pay privacy policy
j) Apple Pay
All Apple Pay transactions are subject to the Apple Pay privacy policy. This can be found at https://www.apple.com/de/legal/privacy/data/de/apple-pay/
k) Credit check via Mollie
If this is provided for the payment method you have selected, we will carry out a credit check via Mollie. In this process, we transmit your name and address to a credit agency, which compares this data with its own database in order to check your creditworthiness. The credit agency then sends the relevant credit information to us.
The legal basis for data processing in the case of purchase on account is our legitimate interest pursuant to Art. 6 (1) f) DSGVO, as we make advance payments for the dispatch of goods and bear the risk of default. In all other cases, data processing in the context of a credit check is carried out exclusively based on your prior consent in accordance with Art. 6 (1) a) DSGVO.
l) Dispatch of your consignments and returns processing
We cooperate with the company Luleni GmbH, Hainstraße 110, 09130 Chemnitz, Germany, to process your shipments and returns. All data necessary for the handling of your shipments and returns will be processed (name, order data, invoice data).
The legal basis for data processing is the fulfilment of our contractual obligations in accordance with Art. 6 (1) b) DSGVO and, in individual cases, the fulfilment of our legal obligations in accordance with Art. 6 (1) c) DSGVO.
m) Newsletter
To provide you with regular information about our company and offers, we offer to send you an e-mail newsletter. With your newsletter registration, we process the data you entered during registration (e-mail address and other voluntary information). In order to prevent misuse, we will send you an e-mail after your registration in which we ask you to confirm your registration (double opt-in procedure). In order to be able to prove the registration process in a legally compliant manner, your registration is logged. This concerns the time of registration and confirmation as well as your IP address.
The legal basis for sending the newsletter is your consent pursuant to Art. 6 (1) a) DSGVO. The data processing in connection with the sending of the confirmation email for your registration and the associated data logging is carried out in accordance with Art. 6 (1) f) DSGVO due to our legitimate interest in the proof of your proper registration.
If you give us your consent, we also evaluate in the newsletters whether you have opened the newsletter as well as the scrolling and clicking behaviour in the newsletter. This is done for the purpose of optimally tailoring our newsletter to your interests and improving the content of our newsletter. The legal basis for the analysis of the newsletter is your consent in accordance with Art. 6 (1) a) DSGVO.
For the dispatch of the newsletter, we use a service provider to whom we transmit the named data.
n) Direct email advertising for existing customers
If you have placed an order with us, we will process the email address you entered during registration to recommend products that match the products you have purchased.
The legal basis for the dispatch as a result of the sale of goods or services is our legitimate interest pursuant to Art. 6 (1) f) DSGVO in direct advertising of our products to existing customers.
We also use a service provider for the dispatch of direct advertising, to whom we transmit the named data.
o) Direct advertising by post for existing customers
If you have placed an order with us, we process the name and address you entered when registering to recommend products that match the products you purchased.
The legal basis for the dispatch following the sale of goods or services is our legitimate interest pursuant to Art. 6 (1) f) DSGVO in the direct advertising of our products to existing customers.
We use Deutsche Post as a service provider for the dispatch of direct mail, to which we transmit the aforementioned data.
p) Customer rating after purchase
To manage customer surveys after your purchase from us, we use the service JTL-Software-GmbH, Rheinstr. 7, 41836 Hückelhoven, Germany. In doing so, we process your email address that you provided during the purchase and which products you ordered from us.
The legal basis for data processing is your consent pursuant to Art. 6 (1) a) DSGVO.
q) Use of cookies
We use so-called cookies on our website. Cookies are small text files that are stored on your respective end device (PC, smartphone, tablet, etc.) and saved by your browser.
Information about the specific cookies we use, their providers and purposes can be found in our Consent banner (See footer: "change cookie settings"). There you can give your consent to the respective services, revoke it, or subsequently adjust your settings.
Our Consent Banner
In order to document your selection of certain data processing procedures and to fulfil our obligations under data protection law, we use a consent banner. When you access our website, your cookie preferences are requested via a banner. We then set a cookie in which data on consent given or revoked is stored. The data processing is carried out to fulfil our legal obligations according to Art. 6 (1) c) DSGVO.
r) Analysis / Marketing
Matomo Analytics
We use the Google Analytics tracking tool Matomo on our website. We use this to evaluate your use of the website, to compile reports on the activities within this website and to provide other services related to the use of the website in order to improve the user experience.
When Matomo is used, the interactions of website visitors are primarily recorded and systematically analysed using cookies / Java Script.
We use Matomo with the extension "anonymiseIp()". This truncates IP addresses within the member states of the EU or EEA. A direct personal reference is therefore generally excluded. In particular, it is no longer possible to identify the computer or end device used by the website visitor.
The following data is processed through the use of Matomo:
- 3 bytes of the IP address of the called system of the website visitor (anonymised IP address),
- the website accessed,
- the website from which the user accessed the page on our website (referrer),
- the sub-pages that are accessed from the website,
- the length of time spent on the website,
- the frequency with which the website is accessed.
The data is hosted on the server itself and is not passed on to third parties.
Google services
We use various services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google") on our website. It is possible that data may also be transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 in the USA.
Google is certified under the EU-US Data Privacy Framework and is covered by the adequacy decision of the EU for the USA.
Google Remarketing / Retargeting
We use so-called tracking cookies from Google on our website. When you visit our site, permanent cookies store information about which products you have viewed on our site and through which third-party advertisements and pages users reach our website. If you subsequently visit a partner website, we can display personalised advertising for you based on the items you have viewed on our site.
Google Ads and Google Merchant Center
We use Google Ads and Google Merchant Center, online advertising programs from Google. This involves so-called conversion tracking. If you click on an ad placed by Google, a cookie is set. This cookie loses its validity after 30 days and is not used to personally identify users. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user has clicked on the ad and was redirected to this page.
Legal basis and revocation
The legal basis for data processing within the scope of the aforementioned Google services is your prior consent pursuant to Art. 6 (1) a) DSGVO.
You can revoke your consent at any time with effect for the future by adjusting your preferences in our Consent Banner.
Meta Pixel
We use a so-called tracking pixel of Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, a subsidiary of Meta Platforms Inc. 1601, Willow Road Menlo Park, CA 94025, USA, on our website. We use Meta Pixel to track the success of our own advertising campaigns on Meta platforms and to optimise the playout of Meta advertising campaigns to interested target groups.
After clicking on a Meta ad or visiting our website, a cookie is stored on your terminal device using the pixel on our website. The cookie processes data about whether you have reached our website via a Meta ad and allows us to analyse the user's behaviour until the purchase is completed. This allows us to track the success rate of our Meta advertising campaigns. In addition, the pixel processes data about the fact that you have visited our website and makes it possible to adapt the advertising played on Meta platforms to your interests.
Via the Meta pixel integrated on our website, a direct connection to the Meta servers is established when you visit our website. The information generated by the cookie about your use of this website (including your IP address) is transmitted to Meta in the USA.
The data collected is anonymous for us and does not allow us to draw any conclusions about the user. If you are registered with a Meta platform, Meta can assign the collected information to your account. Even if you do not have an account or are not logged in when you visit our website, it is possible for Meta to process and store your IP address and other identification data.
The use of cookies or comparable technologies takes place with your consent on the basis of § 25 (1) sentence 1 TDDDG. The legal basis for data processing is your consent in accordance with Art. 6 (1) a) DSGVO.
You can revoke your consent for data processing by Meta Pixel for our web domain at any time with future effect by adjusting your preferences in our Consent Banner (See footer: "change cookie settings").
Meta is certified under the EU-US Data Privacy Framework and is therefore subject to the EU adequacy decision for the USA.
s) External contents
We use dynamic contents ("content") from third parties to optimise the presentation and offer of our website. When visiting the website, a request is automatically made to the server of the respective content provider via an interface, during which certain log data (e.g. the user's IP address) is transmitted. The dynamic content is then transmitted to our website and displayed there.
We use external content in connection with the following functionalities:
aa) Integration of YouTube videos
We have embedded videos from the YouTube portal of YouTube LLC, 901 Cherry Ave. San Bruno, CA 94066, USA ("YouTube"). Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google") is responsible for data processing at YouTube. When playing the videos, however, log data is transmitted to YouTube's servers in the USA.
The legal basis for the processing is your prior consent pursuant to Art. 6 (1) a) DSGVO.
There is no EU Commission adequacy decision for data transfers to the USA. Google ensures an adequate level of data protection via the EU standard contractual clauses. A copy of the relevant EU standard contractual clause will be provided upon request. Please contact info@creaderm.de for this.
bb) Google Fonts
To make visiting our website attractive, we use external fonts from Google Fonts. These are loaded from servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google") when you visit the site. Google does not store any cookies in your browser. However, according to our information, the IP address of the user's terminal device is transmitted to Google and stored. This processing is carried out on the basis of our overriding legitimate interest in the optimal marketing of our offer in accordance with Art. 6 (1) f) DSGVO.
It cannot be ruled out that a data transmission to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA takes place.
There is no EU Commission adequacy decision for data transfers to the USA. Google ensures an adequate level of data protection via the EU standard contractual clauses. A copy of the relevant EU standard contractual clause will be provided upon request. Please contact info@creaderm.de for this.
cc) Google Maps
We use the map service "Google Maps" from Google on our website to provide you with an interactive map. When displaying the map, data including your IP address and your location are transmitted to Google servers and stored there. The legal basis for the processing is your prior consent in accordance with Art. 6 (1) a) DSGVO.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter "Google") is responsible for data processing in Maps. It cannot be ruled out that data is transmitted to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
There is no EU Commission adequacy decision for data transfers to the USA. Google ensures an adequate level of data protection via the EU standard contractual clauses. A copy of the relevant EU standard contractual clause will be provided upon request. Please contact info@creaderm.de for this.
dd) Server log files
You can visit our website without providing any personal information. Every time you access our website, usage data is transmitted by your Internet browser and stored in log data (server log files). This stored data includes, for example, the name of the page accessed, the date and time of access, the amount of data transferred and the requesting provider. This data is used exclusively to ensure the trouble-free operation of our website and to improve our services. It is not possible to assign this data to a specific person.
ee) Payment service provider seals
We use seals of the payment service "Paypal" on our website. These are loaded from servers of PayPal (Europe) S.à r.l. et Cie, S.C.A. when you visit the website. The name of the website accessed, the date and time of access, the amount of data transferred, the browser type and version, the operating system you are using, the referrer URL (the website previously visited), your IP address and the requesting provider are transmitted to the servers of the respective provider.
The legal basis for data processing is our overriding legitimate interest in the optimal marketing of our online offer in accordance with Art. 6 (1) f) DSGVO.
For more information on data protection, see: Paypal privacy
5. Duration of data storage
We only store personal data for as long as it is necessary for the purposes for which it is processed or if you have withdrawn your consent. Insofar as statutory retention obligations must be observed, the storage period for certain data can be up to 10 years, regardless of the processing purposes.
6. Your data subject rights
a) Information
Upon request, you will receive information about all personal data we have stored about you free of charge at any time.