This Privacy Policy applies to Sandu Vintage Fashion GmbH and the online store operated by them at the provided URL. Protecting your privacy is very important to us, so we take the requirements of data protection and data security for your personal data very seriously. Below, we provide detailed information on how we handle your data in accordance with the General Data Protection Regulation (GDPR) of the European Union.
Privacy Policy
1) Introduction and Contact Information of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data includes all data with which you can be personally identified. 1.2 The controller for data processing on this website, as defined by the General Data Protection Regulation (GDPR), is Sandu Vintage Fashion GmbH, Urbanstr. 71, 10967 Berlin, Germany, Tel.: +49176 11613801, Email: showroom@luxury-concierge.de. The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data. 1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string “https://” and the lock symbol in your browser bar.2) Data Collection When You Visit Our Website
When you visit our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called “server log files”). When you visit our website, we collect the following data, which is technically necessary for us to display the website:- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you accessed the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
3) Cookies
To make your visit to our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of the cookies we use are deleted after you close your browser (so-called “session cookies”), while others remain on your device and allow us to save your settings for future visits (so-called “persistent cookies”). In the latter case, you can find the duration of storage in your web browser’s cookie settings. If individual cookies we use also process personal data, the processing is carried out in accordance with Art. 6(1)(b) GDPR either for the performance of a contract, in accordance with Art. 6(1)(a) GDPR in the case of consent given, or in accordance with Art. 6(1)(f) GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit. You can configure your browser to inform you about the setting of cookies and decide on their acceptance individually or to exclude the acceptance of cookies for certain cases or in general. Please note that if you do not accept cookies, the functionality of our website may be limited.4) Contact
When you contact us (e.g., via contact form or email), we process personal data solely for the purpose of handling and responding to your request, and only to the extent necessary for this purpose. The legal basis for processing this data is our legitimate interest in responding to your request pursuant to Art. 6(1)(f) GDPR. If your contact is aimed at concluding a contract, an additional legal basis for processing is Art. 6(1)(b) GDPR. Your data will be deleted when it can be inferred from the circumstances that the relevant matter has been finally clarified and provided that there are no legal retention obligations to the contrary.5) Data Processing When Opening a Customer Account
Pursuant to Art. 6(1)(b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can find out which data is required for opening an account from the input mask of the corresponding form on our website. You can delete your customer account at any time by sending a message to the address of the controller provided above. After your customer account has been deleted, your data will be deleted provided that all contracts concluded with it have been fully processed, there are no legal retention obligations, and we have no legitimate interest in further storage.6) Use of Customer Data for Direct Marketing
6.1 Registration for our Email Newsletter When you subscribe to our email newsletter, we will regularly send you information about our offers. The only required information for sending the newsletter is your email address. Providing additional data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an email newsletter if you have expressly confirmed that you consent to receiving newsletters. We will then send you a confirmation email asking you to click on a link to confirm that you wish to receive newsletters in the future. 6.2 Legal Basis The processing of the email address of the recipient takes place on the basis of consent pursuant to Art. 6(1)(a) GDPR or, if consent is not required, on the basis of our legitimate interests in direct marketing pursuant to Art. 6(1)(f) GDPR. 6.3 Duration of Storage The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. The recipient’s email address will therefore be stored for as long as the subscription to the newsletter is active.7) Data Processing for Order Processing
7.1 The personal data collected by us will be passed on to the transport company commissioned with the delivery within the scope of contract processing, insofar as this is necessary for the delivery of the goods. We will pass on your payment data to the commissioned credit institution within the framework of payment processing, if this is necessary for payment processing. If payment service providers are used, we explicitly inform you of this below. The legal basis for the transfer of data is Art. 6(1)(b) GDPR.8) Rights of the Data Subject
You have the right:- to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you may request information on the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, deletion, restriction of processing, or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information on its details;
- pursuant to Art. 16 GDPR, to demand the correction of incorrect or incomplete personal data stored by us without undue delay;
- pursuant to Art. 17 GDPR, to demand the deletion of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims;
- pursuant to Art. 18 GDPR, to demand the restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful but you refuse to delete it, and we no longer need the data, but you need it to assert, exercise, or defend legal claims, or you have objected to the processing pursuant to Art. 21 GDPR;
- pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, common, and machine-readable format or to request its transfer to another controller;
- pursuant to Art. 7(3) GDPR, to revoke your consent to us at any time. As a result, we are no longer allowed to continue the data processing based on this consent in the future and
- pursuant to Art. 77 GDPR, to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.