Data protection
"Personal data" means any information relating to an identified or identifiable natural person.
Contact
Responsible
Contact us if you wish. The person responsible for data processing is: Anna Pfeiffer, Badenerstrasse 575, 8048 Zurich Switzerland, +41797186083, dsgvo@fiveskincare.com
Customer contact via e-mail
If you initiate business contact with us by e-mail, we will only collect your personal data (name, e-mail address, message text) to the extent you have made them available. The data processing serves to process and answer your contact request.
If the establishment of contact serves to carry out pre-contractual measures (e.g. advice on purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing takes place on the basis of Article 6 Paragraph 1 lit. b GDPR.
If contact is made for other reasons, this data processing takes place on the basis of Article 6 (1) (f) GDPR from our overriding legitimate interest in processing and answering your request. In this case, you have the right, for reasons arising from your particular situation, to object to the processing of your personal data based on Article 6 (1) (f) GDPR at any time.
We only use your e-mail address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.
Customer Account Orders
customer account
When you open a customer account, we collect your personal data to the extent specified there. The purpose of data processing is to improve your shopping experience and to simplify order processing. The processing takes place on the basis of Article 6 (1) (a) GDPR with your consent. You can revoke your consent at any time by notifying us without affecting the legality of the processing carried out on the basis of the consent up to the revocation. Your customer account will then be deleted.
reviews Advertising
Evaluation reminder by Okendo Pty Ltd
If you have given us your express consent to this during or after your order in accordance with Article 6 Paragraph 1 Clause 1 Letter a GDPR, we will send your email address to Okendo, 100 Harris Street, Pyrmont, New South Wales 2009 , Australia ( https://www.okendo.io/ ) so that they can email you a review reminder. This consent can be revoked at any time by sending a message to the contact option described in the imprint or directly to Okendo Pty Ltd.
Irrespective of contract processing, we use your e-mail address exclusively for our own advertising purposes for sending newsletters, provided you have expressly consented to this. The processing takes place on the basis of Article 6 (1) (a) GDPR with your consent. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation. You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your e-mail address will then be removed from the mailing list.
Your data will be passed on to a service provider for e-mail marketing as part of order processing. A transfer to other third parties does not take place.
Shipping service provider merchandise management
Forwarding of the e-mail address to shipping companies for information about the shipping status
We pass on your e-mail address to the transport company as part of the contract processing. The purpose of the transfer is to inform you about the shipping status by e-mail. The processing takes place on the basis of Article 6 (1) (a) GDPR with your consent. You can revoke your consent at any time by notifying us or the transport company, without affecting the legality of the processing carried out on the basis of the consent up to the revocation.
Use of an external merchandise management system
We use a merchandise management system for contract processing as part of order processing. For this purpose, your personal data collected as part of the order will be sent to JTL-Software-GmbH, Rheinstr. 7, 41836 Hückelhoven .
Payment service provider credit report
Using PayPal
All PayPal transactions are subject to the PayPal Privacy Policy. You can find this at https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Using PayPal Express
We use the PayPal Express payment service from PayPal (Europe) S.à.rl et Cie, SCA (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The purpose of data processing is to be able to offer you payment via the PayPal Express payment service. In order to integrate this payment service, it is necessary for PayPal to collect, store and analyze data (e.g. IP address, device type, operating system, browser type, location of your device) when the website is accessed. Cookies can also be used for this. The cookies enable your browser to be recognized.
The processing of your personal data takes place on the basis of Art. 6 Para. 1 lit. f GDPR from our overriding legitimate interest in a customer-oriented offer of various payment methods. You have the right to object to the processing of your personal data at any time for reasons that arise from your particular situation.
By selecting and using PayPal Express, the data required for payment processing is transmitted to PayPal in order to be able to fulfill the contract with you using the selected payment method. This processing takes place on the basis of Article 6 Paragraph 1 Letter b GDPR. More information on data processing when using the PayPal Express payment service can be found in the associated data protection declaration at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS .
- Immediately (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
- giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main
In order to be able to offer you Klarna's payment options, we will transmit personal data, such as contact data and order data, to Klarna. In this way, Klarna can assess whether you can use the payment options offered via Klarna and adapt the payment options to your needs. General information about Klarna is available at: https://www.klarna.com/de/ . Your personal information will be treated by Klarna in accordance with the applicable data protection regulations and in accordance with the information in Klarna's data protection regulations at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy .
All Stripe transactions are subject to the Stripe Privacy Policy. You can find this at https://stripe.com/de/privacy
We use the payment service provider Mollie BV (Keizersgracht 313, 1016 EE Amsterdam, Netherlands; "Mollie") for payment processing on our website. The data processing serves the purpose of being able to offer you various payment methods through payment processing via the payment service provider Mollie. If you have chosen one of the payment options of the payment service provider Mollie, the data required for payment processing will be transmitted to Mollie. This includes your payment details (e.g. bank account number or credit card number), your IP address, your internet browser and device type and in some cases your first and last name, your address details and information about the product or service you have purchased from us. This data processing takes place on the basis of Art. 6 Para. 1 lit. b GDPR. Further information on data processing when using the payment service provider Mollie can be found in the associated data protection declaration https://www.mollie.com/de/privacy
cookies
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
We use the consent management tool GDPR Legal Cookie from beeclever GmbH (Universitätsstraße 3, 56070 Koblenz a. Rh.; "beeclever") on our website. The tool enables you to give consent to data processing via the website, in particular the setting of cookies, and to make use of your right of withdrawal for consent that has already been given.
Data processing serves the purpose of obtaining and documenting the necessary consent to data processing and thus complying with legal obligations. Cookies can be used. The following information, among others, can be collected and transmitted to beeclever: anonymized IP address, date and time of consent, URL from which the consent was sent, anonymous, random, encrypted key, consent status. This data will not be passed on to other third parties.
Data processing is carried out to fulfill a legal obligation on the basis of Article 6 (1) (c) GDPR.
You can find more information on the terms of use and data protection at beeclever at: https://gdpr-legal-cookie.com/pages/terms-conditions and at https://gdpr-legal-cookie.com/pages/datenschutzerklarung.
Analysis advertising tracking communication
Use of Google Analytics
We use the web analytics service Google Analytics from Google Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
The data processing serves the purpose of analyzing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator. Among other things, the following information can be collected: IP address, date and time of the page view, click path, information about the browser you are using and the device you are using (device), pages visited, referrer URL (website via which you visit our website). visited the website), location data, purchase activities. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Google Analytics uses technologies such as cookies, web storage in the browser and tracking pixels, which enable an analysis of your use of the website. The information generated in this way about your use of this website is usually transmitted to a Google server in the USA and stored there. There is no adequacy decision by the EU Commission for the USA. The data transmission takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks and https://business.safety.google/adsprocessorterms/ . Both Google and US government agencies have access to your data. Your data may be linked by Google with other data, such as your search history, your personal accounts, your usage data from other devices and any other data that Google has about you.
IP anonymization is activated on this website. As a result, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there.
Cookies or comparable technologies are used with your consent on the basis of Section 25 (1) sentence 1 TTDSG in conjunction with Article 6 (1) (a) GDPR. Your personal data will be processed with your consent on the basis of Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation.
You can find more information on terms of use and data protection at https://www.google.com/analytics/terms/de.html or at https://www.google.de/intl/de/policies/ and at https:/ /policies.google.com/technologies/cookies?hl=de .
Using Hotjar
We use the analysis tool of Hotjar Ldt on our website. (Level 2, St Julian's Business Centre, 3, Elia Zammit Street, St Julians STJ1000, Malta; “Hotjar”).
The data processing serves the purpose of the needs-based design, optimization and analysis of our website.
The tool is used to randomly record the movements of site visitors on the website. This creates a log of mouse movements, scrolling behavior, length of stay and clicks on the website (so-called heat map).
Hotjar uses cookies, among other things, for this purpose. Among other things, the following information can be collected: IP address (in anonymous form), information about the device you are using (screen size, devices, unique device identifier), information about the browser you are using, location data (only for the country), preferred language to display the website, operating system used. Detailed information on the cookies used, their function and storage period can be found here: https://help.hotjar.com/hc/en-us/articles/115011789248-Hotjar-Cookies
User profiles are created from this data under a pseudonym. The data is not used to personally identify the visitor to the website and is not combined with the personal data of the bearer of the pseudonym. Hotjar is contractually prohibited from selling the collected data to other third parties.
Your data may be transmitted to the USA. There is no adequacy decision by the EU Commission for the USA. The data transmission takes place, among other things, on the basis of appropriate protective measures. Hotjar will provide you with further information on the measures taken on request.
Cookies or comparable technologies are used with your consent on the basis of Section 25 (1) sentence 1 TTDSG in conjunction with Article 6 (1) (a) GDPR. Your personal data will be processed with your consent on the basis of Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation.
Further information on data protection when using Hotjar can be found here: https://www.hotjar.com/legal/policies/privacy#enduserenglish
Using the Facebook Pixel
We use the "Custom Audiences" remarketing function of Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland "Facebook") on our website.
Meta Platforms Ireland and we are jointly responsible for the collection of your data that takes place when the service is integrated and the transmission of this data to Facebook. This is based on an agreement between us and Meta Platforms Ireland on the joint processing of personal data, in which the respective responsibilities are defined. The agreement is available at https://www.facebook.com/legal/controller_addendum . According to this, we are particularly responsible for fulfilling the information obligations in accordance with Art. 13, 14 GDPR, for complying with the security requirements of Art. 32 GDPR with regard to the correct technical implementation and configuration of the service and for complying with the obligations in accordance with Art. 33 , 34 GDPR to the extent that a personal data breach affects our obligations under the Joint Processing Agreement. Meta Platforms Ireland is responsible for enabling the rights of data subjects in accordance with Art. 15 - 20 GDPR, complying with the security requirements of Art. 32 GDPR with regard to the security of the service and the obligations under Art. 33, 34 GDPR, insofar as a violation of personal data protection affects Meta Platforms Ireland's obligations under the Joint Processing Agreement.
The purpose of the application is to target visitors to the website with interest-based advertising on the social network Facebook. For this purpose, the Facebook remarketing tag was implemented on the website. This tag is used to establish a direct connection to the Facebook servers when you visit the website. This transmits to the Facebook server which of our pages you have visited. Facebook assigns this information to your personal Facebook user account. If you visit the social network Facebook, you will then be shown personalized, interest-based Facebook ads. Your data may be transmitted to the USA. There is no adequacy decision by the EU Commission for the USA. The data transfer takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://www.facebook.com/legal/EU_data_transfer_addendum .
Cookies or comparable technologies are used with your consent on the basis of Section 25 (1) sentence 1 TTDSG in conjunction with Article 6 (1) (a) GDPR. Your personal data will be processed with your consent on the basis of Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation.
You can find more information about the collection and use of data by Facebook, your rights in this regard and options for protecting your privacy in Facebook's data protection information at https://www.facebook.com/about/privacy/ .
We use the online advertising program "Google Ads" on our website and, in this context, conversion tracking (evaluation of visits). Google Conversion Tracking is an analysis service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; Google).
If you click on an ad placed by Google, a conversion tracking cookie will be placed on your computer. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of our website and the cookie has not yet expired, Google and we can recognize that you clicked on the ad and were redirected to this page. Each Google Ads customer receives a different cookie. As a result, there is no way that cookies can be tracked through Ads customers' websites.
The information obtained using the conversion cookie is used to generate conversion statistics. This tells us the total number of users who clicked on one of our ads and were redirected to a page with a conversion tracking tag. However, we do not receive any information with which users can be personally identified.
Your data may be transmitted to the servers of Google LLC in the USA. There is no adequacy decision by the EU Commission for the USA. The data transmission takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks and https://business.safety.google/adscontrollerterms/ .
For more information and Google's privacy policy, visit: https://www.google.de/policies/privacy/ .
We use the remarketing or "similar target groups" function of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
The application serves the purpose of analyzing visitor behavior and visitor interests. Google uses cookies to analyze website usage, which forms the basis for creating interest-based advertisements. Visits to the website as well as anonymous data about the use of the website are recorded via the cookies. There is no storage of personal data of visitors to the website. If you then visit another website in the Google Display Network, you will be shown advertisements that are highly likely to take into account previously accessed product and information areas.
Your data may be transmitted to Google LLC servers in the USA. There is no adequacy decision by the EU Commission for the USA. The data transmission takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks .
Cookies or comparable technologies are used with your consent on the basis of Section 25 (1) sentence 1 TTDSG in conjunction with Article 6 (1) (a) GDPR. Your personal data will be processed with your consent on the basis of Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation.
You can find more information about Google Remarketing and the associated data protection declaration at: https://www.google.com/privacy/ads/
We use the Pinterest tag from Pinterest Europe Limited (Palmerston House, 2nd, Fenian Street, Floor, Dublin 2, Ireland "Pinterest") on our website.
The purpose of the application is to target visitors to the website with interest-based advertising on the social network Pinterest. For this purpose, the Pinterest conversion tag was implemented on the website. This tag is used to establish a direct connection to the Pinterest servers when you visit the website. This transmits to the Pinterest server which of our pages you have visited. Pinterest assigns this information to your personal Pinterest user account if you are logged into the social network. If you visit Pinterest, you will then be shown personalized, interest-based Pinterest ads.
If you access our website via a pin on the Pinterest social network, a conversion tracking cookie will be placed on your computer. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of our website and the cookie has not yet expired, Pinterest and we can recognize that you clicked on the pin and were redirected to this page. The information obtained with the help of the conversion cookie serves the purpose of creating conversion statistics and thus optimizing our website. The following information can be processed here: Total number of users who clicked on one of our pins and were forwarded to our website, subpages visited on our website (e.g. category or product pages), search queries on our website, the contents of your shopping cart, completed transactions.
Your data may be transmitted to the USA. There is no adequacy decision by the EU Commission for the USA. The data transfer takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection /standard-contractual-clauses-scc_en .
Cookies or comparable technologies are used with your consent on the basis of Section 25 (1) sentence 1 TTDSG in conjunction with Article 6 (1) (a) GDPR. Your personal data will be processed with your consent on the basis of Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation.
You can find more information on the collection and use of data by Pinterest, your rights in this regard and options for protecting your privacy in Pinterest's data protection information at https://policy.pinterest.com/de/privacy-policy .
We use the live chat system from Saasberry Apps, Inc. (1321 Upland Dr. PMB: 12643 Houston, TX 77043 United States; "DelightChat") on our website. The system serves the purpose of communication between you and us as a provider. User profiles can be created from this data under a pseudonym. Cookies are used for this. Cookies enable recognition of the Internet browser.
Your data may be transmitted to the USA. There is no adequacy decision by the EU Commission for the USA. The data transfer takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data. A copy of the Standard Contractual Clauses will be made available to you by DelightChat upon request.
The processing of your personal data takes place on the basis of Art. 6 Para. 1 lit. f GDPR from our overriding legitimate interest in direct customer communication. You have the right to object to the processing of your personal data at any time for reasons that arise from your particular situation.
You can prevent the storage of cookies by selecting the appropriate technical settings in your browser software; we would like to point out to you however that in this case you will if applicable not be able to use all functions of this website in full.
More information on the collection and use of data by DelightChat, you can find out about your rights in this regard and options for protecting your privacy in DelightChat's data protection information athttps://www.delightchat.io/legal/privacy-policy .
Plugins and Miscellaneous
We use the invisible reCAPTCHA service from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This serves the purpose of distinguishing between input by a human and automated, machine processing. In the background, Google collects and analyzes usage data that is used by Invisible reCaptcha to distinguish regular users from bots. For this purpose, your input will be transmitted to Google and used there. In addition, the IP address and any other data required by Google for the Invisible reCAPTCHA service will be transmitted to Google.
This data is processed by Google within the European Union and possibly also in the USA. There is no adequacy decision by the EU Commission for the USA. The data transmission takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks .
Your personal data is processed on the basis of Article 6 (1) (f) GDPR in our overriding legitimate interest in protecting our website from automated spying, misuse and SPAM. You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6 (1) (f) GDPR.
You can find more information about Google reCAPTCHA and the associated data protection declaration at: https://www.google.com/recaptcha/intro/android.html and https://www.google.com/privacy
Using Cloudflare
We use the Content Delivery Network Cloudflare CDN from Cloudflare Inc. (101 Townsend St, San Francisco, CA 94107, USA; “Cloudflare”) on our website. This is a nationwide network of servers in various data centers to which our web server connects and via which certain content on our website is delivered.
The data processing serves the purpose of optimizing the loading times of our website and thus making our offer more user-friendly.
Among other things, the following information can be collected: IP address, system configuration information, information about the traffic to and from customer websites (so-called server log files).
Your data may be transferred to the USA . There is no adequacy decision by the EU Commission for the USA. The data transfer takes place, among other things, on the basis of standard contractual clauses as suitable guarantees for the protection of personal data, which can be viewed at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection /standard-contractual-clauses-scc_en .
The processing of your personal data takes place on the basis of Article 6 Paragraph 1 Letter f GDPR from our overriding legitimate interest in the needs-based and targeted design of the website. You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6 (1) (f) GDPR.
You can find more information on data protection when using Cloudflare athttps://www.cloudflare.com/de-de/privacypolicy/ .
Data subject rights and storage period
Duration of storage
After completion of the contract, the data will initially be stored for the duration of the warranty period, then taking into account statutory retention periods, in particular tax and commercial law, and then deleted after the period has expired, unless you have consented to further processing and use.
rights of the data subject
If the legal requirements are met, you have the following rights under Art. 15 to 20 GDPR: Right to information, to correction, to deletion, to restriction of processing, to data portability.
In addition, according to Art. 21 Para. 1 GDPR, you have the right to object to the processing based on Art. 6 Para. 1 f GDPR and to processing for the purpose of direct advertising.
Right of appeal to the supervisory authority
According to Art. 77 GDPR, you have the right to complain to the supervisory authority if you believe that your personal data is not being processed lawfully.
Right to object
If the personal data processing listed here is based on our legitimate interest in accordance with Article 6 Paragraph 1 lit. f GDPR, you have the right to object to this processing at any time for reasons that arise from your particular situation with effect for the future.
After an objection has been raised, the processing of the data concerned will be terminated unless we can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.
last update: 01/10/2022