Privacy policy

Privacy policy

1) Introduction and contact details of the responsible person

1.1 Thank you for visiting our website and for your interest. In the following, we will inform you about the handling of your personal data when using our website. Personal data is any data with which you can be personally identified.

1.2 The controller in charge of data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Marlene Busch Zoilo, Makidy Muttermilchschmuck, Prenzlauer Berg 17, 10405 Berlin, Deutschland, Tel.: 01776452400, Fax: -, E-Mail: info@makidy-muttermilchschmuck.de. The controller in charge of the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

2) Data collection when visiting our website

2.1 When you use our website for information purposes only, i.e. if you do not register or otherwise transmit information to us, we only collect the data that your browser transmits to the page server (so-called "server log files"). When you call up our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you reached the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymised form)

The processing is carried out in accordance with Art. 6 para. 1 lit. f DSGVO on the basis of our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used in any other way. However, we reserve the right to check the server log files subsequently if there are concrete indications of illegal use.

2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or enquiries to the person responsible). You can recognise an encrypted connection by the string "https://" and the lock symbol in your browser line.

3) Cookies

In order to make visiting our website more attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your terminal device. In some cases, these cookies are automatically deleted again after the browser is closed (so-called "session cookies"), in other cases, these cookies remain on your end device for longer and allow page settings to be saved (so-called "persistent cookies"). In the latter case, you can find the storage period in the overview of the cookie settings of your web browser.

If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 Para. 1 lit. b DSGVO either for the performance of the contract, in accordance with Art. 6 Para. 1 lit. a DSGVO in the case of consent given or in accordance with Art. 6 Para. 1 lit. f DSGVO to protect our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the page visit.

You can set your browser in such a way that you are informed about the setting of cookies and can decide individually about their acceptance or can exclude the acceptance of cookies for certain cases or generally.

Please note that if you do not accept cookies, the functionality of our website may be limited.

4) Contacting

4.1 TidioChat (Tidio Ltd.)
This website uses technology from Tidio Ltd. 220C Blythe Road, W14 0HH, London, United Kingdom (www.tidiochat.com) to collect and store anonymised data for the purposes of web analysis and to operate the live chat system for answering live support enquiries. This anonymised data can be used to create user profiles under a pseudonym. Cookies can be used for this purpose. Cookies are small text files that are stored locally in the cache of the website visitor's Internet browser. Cookies make it possible to recognise the Internet browser.
The data collected with TidioChat technologies will not be used to personally identify the visitor to this website without the separately granted consent of the person concerned and will not be merged with personal data about the bearer of the pseudonym. In order to avoid the storage of TidioChat cookies, you can set your Internet browser so that no more cookies can be stored on your computer in the future or cookies that have already been stored are deleted. However, switching off all cookies may mean that some functions on our website can no longer be carried out. You can object to the collection and storage of data for the purpose of creating a pseudonymised user profile at any time with effect for the future by sending us your objection informally by e-mail to the e-mail address stated in the legal notice.
We have concluded an order processing contract with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorised disclosure to third parties.

4.2 When contacting us (e.g. via contact form or e-mail), personal data is processed - exclusively for the purpose of processing and answering your request and only to the extent necessary for this purpose.

The legal basis for the processing of this data is our legitimate interest in responding to your request in accordance with Art. 6 (1) lit. f DSGVO. If your contact is aimed at a contract, the additional legal basis for the processing is Art. 6 (1) lit. b DSGVO. Your data will be deleted when the circumstances indicate that the matter concerned has been conclusively clarified and provided that there are no statutory retention obligations to the contrary.

5) Comment function

As part of the comment function on this website, in addition to your comment, information about the time the comment was created and the commentator name you have chosen will be saved and published on this website. Your IP address will also be logged and stored. The IP address is stored for security reasons and in the event that the person concerned violates the rights of third parties or posts illegal content by posting a comment. We need your e-mail address in order to contact you if a third party should object to your published content as unlawful.

The legal basis for the storage of your data is Art. 6 para. 1 lit. b and f DSGVO. We reserve the right to delete comments if they are objected to by third parties as unlawful.

6) Data processing when opening a customer account

Pursuant to Art. 6 para. 1 lit. b DSGVO, personal data will continue to be collected and processed to the extent required in each case if you provide us with this data when opening a customer account. The data required for opening an account can be found in the input mask of the corresponding form on our website.

Deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. After deletion of your customer account, your data will be deleted, provided that all contracts concluded via it have been fully processed, no legal retention periods are opposed and no legitimate interest on our part in the continued storage exists.

7) Data processing for order handling

7.1 Insofar as necessary for the processing of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Para. 1 lit. b DSGVO.

If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we will process the contact data (name, address, e-mail address) provided by you when placing the order in order to inform you personally by suitable means of communication (e.g. by post or e-mail) about upcoming updates within the legally stipulated period of time within the framework of our statutory duty to inform pursuant to Art. 6 (1) lit. c DSGVO. Your contact details will be used strictly for the purpose of informing you about updates owed by us and will only be processed by us for this purpose to the extent that this is necessary for the respective information.

In order to process your order, we also work together with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers after the following information has been provided.

7.2 Transfer of personal data to shipping service providers

- DHL

We use the following provider as our transport service provider: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany

We will pass on your e-mail address and/or telephone number to the provider in accordance with Art. 6 para. 1 lit. a GDPR before delivery of the goods for the purpose of coordinating a delivery date or for delivery notification, provided that you have given your express consent to this during the ordering process. Otherwise, we will only pass on the name of the recipient and the delivery address to the provider for the purpose of delivery in accordance with Art. 6 para. 1 lit. b GDPR. The information will only be passed on if this is necessary for the delivery of goods. In this case, prior coordination of the delivery date with the provider or notification of delivery is not possible.

Consent can be withdrawn at any time with effect for the future from the controller named above or from the provider.

7.3 Use of payment service providers (payment services)

Paypal

One or more online payment methods of the following provider are available on this website: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg

If you select a payment method of the provider for which you make an advance payment, your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) lit. b DSGVO. In this case, your data will only be passed on for the purpose of processing payment with the provider and only insofar as it is necessary for this purpose.

If you select a payment method for which we make advance payments, you will also be asked to provide certain personal data (first and last name, street, house number, postcode, town, date of birth, e-mail address, telephone number and, if applicable, data on an alternative means of payment) during the ordering process.

In order to safeguard our legitimate interest in determining your solvency in such cases, this data will be forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 Para. 1 lit. f DSGVO. On the basis of the personal data provided by you and other data (such as shopping basket, invoice amount, order history, payment experience), the provider checks whether the payment option selected by you can be granted with regard to payment and/or bad debt risks.

The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognised mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
Stripe

One or more online payment methods are available on this website from the following provider: Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

If you select a payment method from the provider for which you make an advance payment (e.g. credit card payment), your payment data provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) as well as information about the content of your order will be passed on to the provider in accordance with Art. 6 (1) lit. b DSGVO. In this case, your data will only be passed on for the purpose of processing payment with the provider and only insofar as it is necessary for this purpose.

If you select a payment method for which the supplier makes an advance payment (e.g. invoice or instalment purchase or direct debit), you will also be asked to provide certain personal data (first and last name, street, house number, postcode, town, date of birth, e-mail address, telephone number and, if applicable, data on an alternative means of payment) during the ordering process.

In order to safeguard our legitimate interest in determining the solvency of our customers, this data is forwarded by us to the provider for the purpose of a credit check in accordance with Art. 6 Para. 1 lit. f DSGVO. The provider checks on the basis of the personal data provided by you as well as further data (such as shopping cart, invoice amount, order history, payment experience) whether the payment option selected by you can be granted with regard to payment and/or bad debt risks.

The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognised mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual processing of payments.

8) Web analytics services

Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

Google (Universal) Analytics is used on this website exclusively without the use of cookies, which means that the service does not set cookies on your terminal device at any time.

Instead, the local memory of your browser is used to store an individual ID assigned by Google (Universal) Analytics, which enables an analysis of your use of the website. For this purpose, certain user information is processed via the ID. The scope of this information also includes your IP address, which is, however, shortened by Google by the last digits in order to exclude a direct personal reference.

The information is transferred to Google servers and processed there. In the process, transfers to Google LLC, based in the USA, are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, compile reports on website activity for us and provide other services relating to website activity and internet usage. The IP address transmitted and shortened by your browser as part of Google Analytics will not be merged with other Google data. The data collected in the context of the use of Google (Universal) Analytics will be stored for a period of two months and then deleted.

All processing described above, including the storage of information on the end device used in the form of the ID, only takes place if you have given us your express consent for this in accordance with Art. 6 Para. 1 lit. a DSGVO.

Without your consent, Google (Universal) Analytics will not be used during your visit to the site. You can revoke your consent at any time with effect for the future.

To exercise your revocation, you can download and install the browser plugin available at the following link:
https://tools.google.com/dlpage/gaoptout?hl=en

As an alternative to the browser plug-in or within browsers on mobile devices, you can revoke your consent by clicking on the following link to set an opt-out cookie that will prevent the collection by Google Analytics within this website in the future (this opt-out cookie only works in this browser and only for this domain. If you delete your cookies in this browser, you must click this link again):
Deactivate Google Analytics

We have concluded an order processing agreement with Google, which ensures the protection of our site visitors' data and prohibits unauthorised disclosure to third parties.

Further legal information on Google (Universal) Analytics can be found at https://policies.google.com/privacy?hl=en&gl=en and under https://policies.google.com/technologies/partner-sites

Demographic characteristics
Google (Universal) Analytics uses the special function "demographic characteristics" and can use this to create statistics that make statements about the age, gender and interests of site visitors. This is done by analysing advertising and information from third-party providers. This allows target groups to be identified for marketing activities. However, the collected data cannot be assigned to a specific person and is deleted after being stored for a period of two months.

Google Signals
As an extension to Google (Universal) Analytics, Google Signals can be used on this website to have cross-device reports generated. If you have activated personalised ads and linked your devices to your Google account, Google may, subject to your consent to the use of Google Analytics pursuant to Art. 6 (1) lit. a DSGVO, analyse your usage behaviour across devices and create database models, including on cross-device conversions. We do not receive any personal data from Google, only statistics. If you would like to stop the cross-device analysis, you can deactivate the "Personalised advertising" function in the settings of your Google account. To do so, follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en You can find more information about Google Signals at the following link: https://support.google.com/analytics/answer/7532985?hl=en

UserIDs
As an extension to Google (Universal) Analytics, the "UserIDs" function can be used on this website. If you have consented to the use of Google (Universal) Analytics pursuant to Art. 6 (1) lit. a DSGVO, have set up an account on this website and log in with this account on various devices, your activities, including conversions, can be analysed across devices.

For data transfers to the USA, the provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

9) Page functionalities

9.1 AddThis bookmarking plugins

Our website uses social network plugins from the following provider: AddThis LLC, Inc. 8000 Westpark Drive, Suite 625, McLean, VA 2210, USA

These plugins enable direct interactions with content on the social network.

In order to increase the protection of your data when visiting our website, the plugins are initially deactivated and integrated into the page by means of a so-called "2-click" or "Shariff" solution.

This integration ensures that when a page of our website containing such plugins is called up, no connection is yet established with the provider's servers.

Only when you activate the plugins and thus give your consent to the data transfer in accordance with Art. 6 para. 1 lit. a DSGVO, does your browser establish a direct connection to the provider's servers. Here, regardless of a login to an existing user profile, information about your end device used (including your IP address), your browser and your page history is transmitted to the provider to a certain extent and processed there if necessary.

If you are logged into an existing user profile on the provider's social network, information on interactions carried out via the plugins will also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation has no influence on the data that has already been transmitted to the provider.

We have concluded an order processing contract with the provider, which ensures the protection of our site visitors' data and prohibits unauthorised disclosure to third parties.

For the transfer of data to the USA, the provider refers to standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

9.2 ShopVote graphics

Graphic elements from the following provider are integrated on our website to display external customer ratings and/or an externally awarded quality mark: Blickreif GmbH, Schulstraße 46, 80634 Munich, Germany

When you call up a page of our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers in order to load the elements properly. In this process, certain browser information, including your IP address, is transmitted to the provider.

Insofar as personal data is also processed in the process, this is done in accordance with Art. 6 para. 1 lit. f DSGVO on the basis of our legitimate interest in the optimal marketing of our offer and the appealing design of our website.

9.3 Google Web Fonts

This site uses so-called web fonts from the following provider for the standardised display of fonts: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland

When you call up a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly and establishes a direct connection to the provider's servers. In the process, certain browser information, including your IP address, is transmitted to the provider.

Data may also be transmitted to: Google LLC, USA

The processing of personal data in the course of establishing a connection with the font provider is only carried out if you have given us your express consent to do so in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service via the "cookie consent tool" provided on the website. If your browser does not support web fonts, a standard font will be used by your computer.

For data transfers to the USA, the provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

9.4 Google Customer Reviews (formerly Google Certified Dealer Programme)

We work with Google as part of the "Google Customer Reviews" programme. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). This programme gives us the opportunity to collect customer reviews from users of our website. After making a purchase on our website, you will be asked if you would like to participate in an email survey from Google.

If you give your consent in accordance with Art. 6 (1) lit. a DSGVO, we will transmit your email address to Google. You will receive an email from Google Customer Reviews asking you to rate the purchase experience on our website. The rating you provide will then be aggregated with our other ratings and displayed in our Google Customer Reviews logo and in our Merchant Center dashboard. In addition, your review will be used for Google Seller Reviews. The use of Google Customer Reviews may also involve the transmission of personal data to the servers of Google LLC. in the USA.

You can withdraw your consent at any time by sending a message to the data controller or to Google.

For data transfers to the USA, the provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.

10) Tools and miscellaneous

Cookie consent tool

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users when they access the website in the form of an interactive user interface on which consent for certain cookies and/or cookie-based applications can be given by ticking a box. By using the tool, all cookies/services requiring consent are only loaded if the respective user gives their consent by ticking the appropriate box. This ensures that such cookies are only set on the user's end device if consent has been granted.

The tool sets technically necessary cookies to save your cookie preferences. Personal user data is not processed in this process.

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done pursuant to Art. 6 (1) lit. f DSGVO on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.

Further legal basis for the processing is Art. 6 para. 1 lit. c DSGVO. As the responsible party, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.

Where necessary, we have concluded an order processing agreement with the provider, which ensures the protection of our site visitors' data and prohibits unauthorised disclosure to third parties.

You can find further information on the operator and the setting options of the cookie consent tool directly in the corresponding user interface on our website.

11) Rights of the data subject

11.1 The applicable data protection law grants you the following data subject rights (rights of access and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the cited legal basis for the respective exercise prerequisites:

  • Right to information according to Art. 15 DSGVO;
  • Right to rectification according to Art. 16 DSGVO;
  • Right to erasure according to Art. 17 DSGVO;
  • Right to restrict processing pursuant to Art. 18 DSGVO;
  • Right to information pursuant to Art. 19 of the GDPR;
  • Right to data portability according to Art. 20 DSGVO;
  • Right to revoke consent granted pursuant to Art. 7 (3) DSGVO;
  • Right to lodge a complaint pursuant to Art. 77 of the GDPR.

11.2 RIGHT OF OBJECTION

IF WE PROCESS YOUR PERSONAL DATA IN THE CONTEXT OF A BALANCING OF INTERESTS ON THE BASIS OF OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE AT ANY TIME ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING WHICH OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING IS FOR THE PURPOSE OF ASSERTING, EXERCISING OR DEFENDING LEGAL CLAIMS.

IF WE PROCESS YOUR PERSONAL DATA FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH MARKETING. YOU CAN EXERCISE THE RIGHT TO OBJECT AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

12) Duration of the storage of personal data

The duration of the storage of personal data is measured on the basis of the respective legal basis, the purpose of processing and, if applicable, additionally on the basis of the respective statutory retention period (e.g. retention periods under commercial and tax law).

When processing personal data on the basis of explicit consent pursuant to Art. 6 (1) a DSGVO, the data concerned will be stored until you revoke your consent.

If there are legal retention periods for data that is processed within the scope of legal business or legal business obligations on the basis of Art. 6 Para. 1 lit. b DSGVO, this data will be routinely deleted after the retention periods have expired, insofar as it is no longer required for the fulfilment of a contract or the initiation of a contract and/or there is no further justified interest on our part in the continued storage.

When processing personal data on the basis of Art. 6(1)(f) DSGVO, this data is stored until you exercise your right to object pursuant to Art. 21(1) DSGVO, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

When processing personal data for the purpose of direct marketing based on Art. 6 (1) lit. f DSGVO, this data will be stored until you exercise your right to object in accordance with Art. 21 (2) DSGVO.

Unless otherwise stated in the other information on specific processing situations in this statement, stored personal data are deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.