Polityka prywatności
Privacy Policy of LUISA CERANO GmbH & Co. KG
(Date: December 2024)
In the following, we would like to inform you about how your personal data is handled when using our website www.luisacerano.com in accordance with art. 12, 13 and 21 of the General Data Protection Regulation (GDPR) and sect. 13 German Telemedia Act (TMG).
1. Name and contact details of the data controller
This website is operated by
LUISA CERANO GmbH & Co. KG
Weberstraße 1
72622 Nürtingen
Tel.: +49 (0) 7022 / 705 - 137
E-mail: info@luisacerano.de
as the responsible party in terms of data protection law.
2. Contact details of the data controller’s Data Protection Officer
LUISA CERANO GmbH & Co. KG
Attn.: Data Protection Officer
Weberstraße 1
72622 Nürtingen
Tel.: +49 (0) 7022 / 705 -160
E-mail: datenschutz@luisacerano.com
3. Information about the processing of personal data
3.1 General
LUISA CERANO GmbH & Co. KG ('LUISA CERANO') respects the privacy of all visitors to this website. We process your personal data in accordance with the provisions of the General Data Protection Regulation, the Federal Data Protection Act and other applicable data protection regulations.
'Personal information' means any information relating to an identified or identifiable natural person ('data subject'). These include, for example, name, address, telephone number or e-mail address.
This data protection statement explains what information LUISA CERANO collects, stores and how it is used. This statement also explains how you can verify the accuracy of the personal information that LUISA CERANO holds about you and how you can have that personal information deleted or updated.
The privacy policy does not apply to third-party websites of other operators, which are linked from this website.
Our website is operated on the shop system of the external service provider "Shopify" (Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, DO4 XN32, Ireland).
Shopify hosts our website with the external provider Google Ireland Limited (Gordon House, Barrow Street, Dublin 4 Ireland) in the data centre. The operation of our online shop is carried out within the framework of an order processing agreement. All data collected on our website is processed on Shopify's servers. Your data may also be transferred to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc., Shopify Payments (USA) Inc. or Shopify (USA) Inc. as part of the processing by Shopify. The adequacy decision of the European Commission ensures an adequate level of data protection in Canada. Shopify also processes your data in the US. For more information on data protection at Shopify, please visit: www.shopify.com/legal/privacy
The purposes of data processing, as well as the corresponding legal bases, are named below.
3.2 Informational use of the website
Every time you visit the website, our shop provider Shopify automatically collects information that your browser transmits to the Shopify server. These are also stored in Shopify's so-called log files. The information includes the request, the IP address, browser type and language and the date and time of the call. The information is used by Shopify to analyse and maintain the technical operation of the servers and the network as well as to combat abuse. They are automatically deleted after 7 days. LUISA CERANO does not have access to these server log files.
3.2.1 Technical provision of the website
3.2.1.1 Purpose
Automated collection of data and processing by the browser
For the technical provision of the website, the server of this website automatically and temporarily collects and stores the following information in the server log files transmitted by your browser, provided that this function has not been deactivated by you:
- IP address of the requesting computer
- File request of the client
- The http response code
- The website from which you are visiting this website (referrer-url)
- Date and time of the server request
- Browser type and version
- Operating system that is used by the requesting computer
- Search term with which the website was found, e.g., via Google
An evaluation of the server log files based on personal information does not take place. At no point can these data be assigned to specific persons for LUISA CERANO. This data is not merged with data from other data sources.
This data is collected on the basis of Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website.
Content Delivery Network (CND)
Unser Online-Shop verwendet sogenannte Content Delivery Networks (CDN). Diese werden von unserem Shopsystem-Dienstleister Shopify bereitgestellt. CDNs bewirken, dass die Ladezeit der Webseite verkürzt wird, weil die Dateien von schnellen, standortnahen oder wenig ausgelasteten Servern externer Dienstleister übertragen werden. Über CDNs wird unser Online-Shop global, über eine international verteilte Server-Landschaft bereitgestellt, um die Zugriffszeit bei den Besuchern zu reduzieren. CDNs übernehmen zudem Sicherheitsfunktionen. Unser Online-Shop wird über die externen Dienstleister Cloudflare und Cloudfront verteilt. Wenn Sie unsere Webseite besuchen, wird diese von einem standortnahen Server an Sie ausgeliefert.
Durch die Nutzung von CDNs auf unserem Shopify-Online-Shop werden Ihre Daten an eines der nachfolgenden CDNs übermittelt:
Cloudflare ist ein Dienst der Cloudflare, Inc. Weitere Informationen finden Sie in der Datenschutzerklärung von Cloudflare unter www.cloudflare.com/security-policy/
Cloudfront ist ein Dienst der Amazon Web Services, Inc., Weitere Informationen zu Cloudfront finden Sie unter: https://aws.amazon.com/de/cloudfront/
Cookies
Our websites use so-called "cookies". Cookies are small text files that are stored on your device by your browser They serve to make our offer more user-friendly, effective and secure.
Cookies are stored on your device either temporarily for the duration of a session (session cookies) or perma-nently (persistent cookies). Session cookies are automatically deleted at the end of your visit, permanent cook-ies remain stored on your device until you delete them yourself or your web browser deletes them automatically.
In some cases, third-party cookies may also be stored on your device when you visit our website (so-called third-party cookies). These allow us or you to use certain services provided by the third party.
If cookies are used by third-party companies or for analysis purposes, we will inform you separately about this within the framework of this privacy policy and, if necessary, obtain consent.
Cookies have different functions. Many cookies are technically necessary because certain website functions would not work without them. Other cookies are used to evaluate user behaviour or to display advertising.
You can set your browser so that no cookies are stored on the hard drive and/or cookies which are already stored are deleted once again. Please follow the instructions in your browser settings to prevent and delete cookies. Some features of our website are not available without the use of cookies. The following information is stored in the cookies and transmitted to us:
Date on which the cookie was created
Expiration date of the cookie
Values concerning variables
Information for Google Analytics
Change cookie settings https://www.luisacerano.com/de/de/de/#
Cookie consent with Cookiefirst
This website uses Big Data Solutions' cookie consent technology to obtain your consent to the storage of cer-tain cookies on your device or to the use of certain technologies and to document them in compliance with data protection regulations. The provider of this technology is Digital Data Solution B.V., Plantage Middenlaan 42a, 1018 DH Amsterdam, The Netherlands, Website: https://cookiefirst.com (hereinafter referred to as "Cookiefirst").
When you enter our website, the following personal data is transmitted to Cookiefirst:
• Your consent(s) or the withdrawal of your consent(s)
• Your IP address
• Information about your browser
• Information about your device
• Time of your visit to the website
Furthermore, Cookiefirst stores a cookie in your browser to be able to assign you the consents you have given or their revocation. The data collected in this way will be stored until you ask us to delete it, delete the Cookief-irst cookie yourself or the purpose for which the data is stored no longer applies. Mandatory statutory retention obligations remain unaffected.
Cookiefirst is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Art. 6 (1) lit. c GDPR.
We have concluded a data processing agreement with Cookiefirst. This is a contract required by data protection law that ensures that Cookiefirst processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3.2.1.2 Legal basis
We process your personal data for the technical provision of our website based on the following legal requirements:
- to fulfil a contract or to carry out pre-contractual measures, in accordance with art. 6 para. 1 letter b GDPR, insofar as you are visiting our website to inform yourself about our product range, especially in the web shop, our events, and other offers and
- to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR, to make the website technically available to you. Our legitimate interest is to provide you with an attractive, technically functional and user-friendly website for our company.
3.2.2 Statistical Analysis of the use of our website
3.2.2.1 Purpose
To analyze the use of our website, we use tools and cookies that enable an analysis of your surfing behavior. This will help us to improve the quality of our website and its content. We learn how the website is used and in doing so, this enables us to continuously optimise our goods and services.
The information obtained through the statistical analysis of our website will not be merged with any other information you provide which is collected through the website.
Google Analytics
Regarding the web analytics service Google Analytics, LUISA CERANO would like to point out the following in accordance with the privacy regulators' guidelines:
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ('Google'). Google Analytics uses so-called cookies, which are text files that are stored on your computer and that allow your use of the website to be analysed. The information generated by the cookie about your use of this website (including your IP address) is usually transmitted to a Google server in the USA and stored there. LUISA CERANO would like to point out that this website 'Google Analytics' has been extended by the code '_anonymizeIp()' in order to ensure an anonymous collection of IP addresses (so-called IP-masking).
Through the process of IP anonymisation on this website, your IP address will be truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before a transfer takes place. This is done in order to prevent the data from being linked to a specific person The full IP address will only be sent to a Google server in the US and truncated there in exceptional cases.
On behalf of LUISA CERANO, Google will use this information to evaluate your use of the website, compile reports on website activity and provide other services related to website activity and internet usage with respect to LUISA CERANO. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
You can prevent the storage of cookies by setting your browser software; accordingly, However, LUISA CERANO would like to point out that in this case, you may not be able to use all the features of this website to the full extent. In addition, by downloading and installing the browser plug-in available under the following link, you may prevent Google from collecting the data generated by the cookie which is related to your use of the website (including your IP address), as well as their processing of this data: http://tools.google.com/dlpage/gaoptout?hl=de.
If you use our website on a mobile device, you can also prevent Google Analytics from collecting your data by clicking on the following link. An opt-out cookie will be set which prevents your data being collected during future visits to this website. If you delete your cookies, you must click this link again. https://www.google.com/settings/ads/onweb/
For further information about the terms of use and data protection, please visit the URL http://www.google.com/analytics/terms/de.html and/or the URL https://www.google.de/intl/de/policies/.
3.2.2.2 Legal Requirements
We process your personal data for the statistical analysis of our website on the basis of the following legal requirements:
- Your consent in accordance with Art. 6 para. 1 lit. a GDPR
- to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR, in connection with sect. 15 para. 3 Telemedia Act; our legitimate interest lies in the needs-based design of our website.
ABlyft Testing Platform
This website uses the A/B testing and web analysis service Conversion Expert GmbH (ABlyft Testing Platform), Zeppelinring 52c, D-24146 Kiel, Germany, to improve the user-friendliness of our website and to make targeted optimizations. No personal data such as IP addresses or user IDs are stored. All data collected is processed ex-clusively in aggregated form, so that no conclusions can be drawn about individual visitors. ABlyft integrates in-to our cookie consent system and is only activated after your consent (Art. 6 para. 1 lit. a GDPR). Data pro-cessing takes place exclusively on highly secure servers in Germany and complies with the strict requirements of the GDPR. You can control the use of cookies at any time via your browser settings, although this may limit the functionality of our online shop. For more information, please see ABlyft's Privacy Policy at https://ablyft.com/en/privacy-notice.
3.2.3 Online marketing
Google Ads and remarketing
LUISA CERANO also uses Google Ads remarketing technology and Google Tag Manager, an advertising platform of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ('Google'). Using pseudonyms, users who have visited this site will be redirected through targeted advertising on the pages of the Google Partner network. Cookies may be used for this purpose (see section 3.2.1.1), which enable the recognition of an Internet browser. These usage profiles serve to analyse visitor behaviour and are used for targeted product recommendation and interest-based advertising. The ‘pseudonymised’ user profiles are not merged by LUISA CERANO with personal data about the bearer of the pseudonym. You may opt-out of the collection and storage of data for the purpose of web analytics and advertising control at any time by activating Google's opt-out link https://www.google.com/settings/ads/plugin. For more information about Google Remarketing and Google's data protection policy, please visit: http://www.google.com/privacy/ads/.
LUISA CERANO uses the User-ID function. Using the User ID, we can assign a unique, persistent ID to one or more sessions (and the activities within those sessions) and analyze user behavior across devices.
In addition, you can deactivate Google Remarketing and the Google Tag Manager as well as all cookies or other types of tracking (e.g. tracking pixels) by means of your browser settings or by means of free browser add-ons, such as "Adblock Plus" (https://adblockplus.org/de/) in combination with the "EasyPrivacy" list (https://easylist.to/).
Using Google Ads Conversion Tracking
On this website, LUISA CERANO uses the online advertising program "Google Ads" and, in this context, conversion tracking, an analysis service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; Google). When you click on an ad placed by Google, a cookie for conversion tracking is placed on your computer. These cookies have a limited validity, do not contain any personal data and are therefore not used for personal identification. If you visit certain pages of our website and the cookie has not yet expired, Google and we can recognise that you have clicked on the ad and have been redirected to that page. Each Google Ads customer receives a different cookie. As a result, there is no way that cookies can be tracked through the websites of Ads customers. The information collected with the help of the conversion cookie serves the purpose of compiling conversion statistics.
To do this, we've set up Enhanced Conversions. This is a feature that can improve the accuracy of conversion tracking, where user privacy is protected by supplementing existing conversion tags with the hashed first-party conversion data from the website. Hashing the first-party data before sending it to Google Ads ensures privacy because personal information such as (in this case, for example, the email address) is converted into a hashed/pseudonomysed (SHA256) string.
Your data may be transmitted to the servers of Google LLC in the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Google has certified itself according to the TADPF and is thus obliged to comply with European data protection principles.
The use of cookies or comparable technologies takes place with your consent based on § 25 para. 1 sentence 1 TTDSG in conjunction with Art. 6 para. 1 lit. a) GDPR. The processing of your personal data is carried out with your consent based on Art. 6 (1) (a) GDPR. You may withdraw your consent at any time, without affecting the lawfulness of the processing carried out on the basis of your consent before its withdrawal. For more information and Google's privacy policy, please visit: https://www.google.de/policies/privacy/
Using Meta Pixel
LUISA CERANO uses the Meta Pixel of Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; "Meta").
Meta and LUISA CERANO are jointly responsible for the collection of your data when the service is integrated and for the transmission of this data to Meta. The basis for this is an agreement between LUISA CERANO and Meta on the joint processing of personal data, which sets out their respective responsibilities. The agreement is available at https://de-de.facebook.com/legal/terms/businesstools. Accordingly, LUISA CERANO is responsible, in particular, for the fulfilment of the information obligations pursuant to Articles 13 and 14 of the GDPR, for compliance with the security requirements of Article 32 of the GDPR with regard to the correct technical implementation and configuration of the Service, as well as for compliance with the obligations under Articles 33 and 34 of the GDPR, insofar as a personal data breach affects our obligations under the Joint Processing Agreement. Meta is responsible for enabling the rights of data subjects pursuant to Articles 15 - 20 of the GDPR, complying with the security requirements of Article 32 of the GDPR regarding the security of the Service and the obligations under Articles 33, 34 of the GDPR, insofar as a personal data breach affects Meta's obligations under the Joint Processing Agreement.
The purpose of the application is to target visitors to the website with interest-based advertising on the social networks Facebook and Instagram. To do this, Meta's remarketing tag has been implemented on the website. This tag is used to establish a direct connection to the Meta servers when you visit the website. This transmits to the Meta server which of our pages you have visited. Meta associates this information with your personal Facebook and/or Instagram user account. When you visit the social networks Facebook or Instagram, you will then be shown personalized, interest-based ads.
The application also serves the purpose of compiling conversion statistics. In doing so, LUISA CERANO learns the total number of users who clicked on one of the advertisements and were redirected to a page with a conversion tracking tag, as well as what actions are taken after being redirected to that website. However, LUISA CERANO does not receive any information that can be used to personally identify users.
Your data may be transferred to the USA. For the USA, there is an adequacy decision of the EU Commission, the Trans-Atlantic Data Privacy Framework (TADPF). Meta has certified itself according to the TADPF and is thus committed to complying with European data protection principles.
The processing of your personal data is carried out with your consent based on Art. 6 para. 1 lit. a) GDPR. You may withdraw your consent at any time, without affecting the lawfulness of the processing carried out based on your consent before its withdrawal. You can opt out of the "Custom Audiences" remarketing feature here. For more information on the collection and use of data by Meta, your rights in this regard and options for protecting your privacy, please refer to Meta's privacy policy under https://www.facebook.com/about/privacy/.
This website uses Bing Ads, a program from Microsoft Corporation ("Microsoft") using Universal Event Tracking (UEN) to implement remarketing and conversion tracking. For this purpose, a cookie is set on your computer if you have reached our website via Bing or Yahoo. In this text file, information about the use of our website, i.e. the pages you have accessed, is stored by Bing Ads for 180 days and then deleted. This information includes, among other things, the URL of the page visited, the URL of the referring page and your IP address. By using the remarketing function, we can provide you with offers that are specifically tailored to you in a later search on one of the above-mentioned search engines. If you do not agree with the collection of information, you can deactivate the setting of cookies via the settings of your Internet browser. By using the consumer opt-out page of the Network Advertising Initiative (NAI) http://www.networkadvertising.org/choices/, you can check which of the participating sites set cookies in your browser and disable them. Microsoft's privacy policy on the handling of collected data can be found at the following link: https://privacy.microsoft.com/de-de/privacystatement/
Using Criteo
The retargeting technology of Criteo SA, 32 Rue Blanche, 75009 Paris, is integrated into this website. By using this technology, it is possible to show you advertisements on third-party sites (publisher sites) of products that you have viewed on this website. For this purpose, information about your usage behavior on this website using tracking cookies and similar technologies that are placed in your browser or by using advertising IDs in environments that do not support cookies is collected by Criteo SA and us in joint responsibility in accordance with Art. 26 GDPR and transmitted to Criteo SA. The further processing of the data transmitted to Criteo SA is the sole responsibility of Criteo SA under data protection law. With the help of these technologies, Criteo can analyze trends and identify the interests of individual users regarding websites and apps. Criteo uses these technologies to tag visitors to its partners' websites and apps. Users marked by Criteo receive a technical ID. In addition, we transmit your e-mail address stored in the customer account as a hash value to Criteo, if we recognize you in your logged-in state and you give your consent to this data transmission via the banner solution used on this website. The hash value of the e-mail address is used by Criteo exclusively to recognize website visitors.
At no time does Criteo collect personal data that makes it possible to identify you, such as names or addresses. Criteo only analyzes the products viewed or the search behavior and the pages visited on the website of the partner for whom Criteo delivers advertising. To deliver personalized advertisements to you and to provide you with a seamless online experience, Criteo may synchronize the IDs of the different browsers you use. ("ID Synchronization") Thanks to its ID synchronization technology, Criteo can always provide you with the most relevant ads – regardless of your browser or device – without having to collect and process personal data such as names or addresses. For this purpose, Criteo uses exact linking methods based on the technical data collected through the Criteo technologies used, such as the IDs of our advertising partners or encrypted e-mail addresses that the partners share with Criteo.
Further information on data protection at Criteo can be found at https://www.criteo.com/privacy. The legal basis for this data processing is Article 6 (1) (a) GDPR (consent). You can revoke your consent regarding the use of Criteo technology at any time here by deselecting the category "Performance" in the cookie settings .
3.2.4 Links to social media operators
On this website you will find links (hyperlinks) to the social media networks and the platforms Facebook, YouTube and Instagram. These services are offered by the companies listed below ('Providers').
Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ('Facebook').
YouTube is operated by YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA, ('YouTube') - a subsidiary of Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA.
Instagram is operated by Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA ('Instagram').
For information concerning the purpose and scope of data collection the further processing of data and its use by Facebook, YouTube and Instagram, as well as your rights regarding this and the options that are available for protecting your privacy, please refer to the provider’s privacy policy:
Data protection policy of Facebook: https://de-de.facebook.com/policy.php
Data protection statement of YouTube/Google: https://www.google.de/intl/de/policies/privacy/
Data protection policies of Instagram: https://help.instagram.com/155833707900388
If you do not want a provider to be able to associate the click of a link which links its website presence to your local user account, you must log out of the relevant service before clicking on such a link. Even if you are not registered with the providers, after clicking on a link concerning the use of cookies, data can be sent to the provider.
Our social media presences are intended to ensure the widest possible presence on the Internet. This is a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. The analysis processes initiated by the social media may be based on different legal bases, which must be specified by the operators of the social networks (e.g. consent within the meaning of Art. 6 para. 1 lit. a DSGVO).
3.3 Active use of the website
In addition to l using our website purely for information, you can also actively use our website to buy goods in our online shop or to contact us. In addition to the processing of your personal data for a purely informative use (as described above), we then collect and process further personal data from you which we need to process your order and/or to process and answer your enquiry.
3.3.1 Communication via the contact form or e-mail
3.3.1.1 Purpose
To process and answer the enquiry you send to us (e.g. via the contact form or to our e-mail address) to the collection, processing and use of your personal data communicated in this context is earmarked exclusively for receiving and answering and/or processing your request as well as for statistical purposes. If LUISA CERANO no longer needs your data for this purpose, your data will be deleted.
3.3.1.2 Legal basis
We process your personal data to respond to user enquiries based on the following legal requirements:
- to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR; our legitimate interest lies in answering customer enquiries appropriately.
- Orders in the LUISA CERANO online shop
- Description of the processing
As part of your order process, we process your personal data. You can shop on our website as a guest or as a registered user. If you are a registered user shopping on our website, you can store your billing and delivery addresses, as well as your preferred payment method, in your user profile for a faster and more convenient order with us.
If you are shopping as a guest, you will need to fill in the order form when you make your purchase. The mandatory fields marked with an asterisk in our online shop (e-mail address, first name, last name, address) must be entered by you. Otherwise, it is not possible for us to conclude a purchase contract with you and send you the desired goods. All other information is voluntary. When making a purchase on our website, you can also choose one of the payment methods offered (PayPal or Shopify Payments) to pay the purchase price.
When completing your order, the data required for payment will be passed on to the respective payment service provider. In addition, your first name, last name and address will be transmitted to the respective shipping service provider DHL, DPD or UPS for the purpose of processing the delivery. As part of the ordering process, you will receive information about the status of your order shipment from us to the e-mail address you have provided. You will receive a link from us that you can use to check the shipping status of your order directly with the shipping service provider.
Setting up a customer account
LUISA CERANO only uses the personal information that you provide during the creation of your customer account on the website, such as your name (first and last name), your address, telephone number, e-mail address and date of birth in the context in which this is necessary for the justification, content, or modification of our contractual relationship with you.
Receipt and processing of your order
LUISA CERANO uses the personal information that you provide during the purchasing process in the web shop, such as your name (first and last name), address, telephone number, e-mail address, date of birth, credit card number and account details only within the scope that is required to process and invoice your order (and possibly for enquiries about your order).
Processing of payments
For processing payments LUISA CERANO works with different providers of payment services.
These are merely external providers of payment services, not sellers of goods. Within the scope of ordering, you must agree to their activities, especially the collection and processing of your order and payment data.
Personal data, such as the bank details or credit card number, is also transferred to the payment service providers. This processing is necessary for the examination and processing of the payment instruction, which is initiated to fulfill the contract concluded by you with us. The legal basis is Article 6(1) lit. b) of the GDPR.
Shopify Payment
The provider of this payment service in the EU is Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as “Shopify payment”). For details, please refer to Shopify Payment’s privacy policy: https://www.shopify.com/legal/privacy
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l et Cie, S.C.A, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”). Details can be found in the privacy policy of PayPal: https://www.paypal.com/myaccount/privacy/privacyhub
Creditworthiness check
If you decide to purchase by invoice as an end user, your data will be forwarded to a credit agency. If this check does not provide the desired result, e.g. If the data cannot be clearly assigned, LUISA CERANO will automatically offer you other available payment methods.
In accordance with art. 14 EU-GDPR, information concerning the data processing that takes place at the credit agency can be found at the corresponding website.
Compliance with legal regulations
We also process your personal data to fulfil other legal obligations that we have in connection with the processing of the order. These include trade-related, commercial, or tax-related retention periods.
Legal enforcement
In addition, we process your personal data to assert our rights and enforce our legal claims. We also process your personal data to defend ourselves against legal claims.
3.3.2.2 Purpose
The processing is carried out for the purpose of concluding and processing purchase contracts and for your information by e-mail about the current order status.
3.3.2.3 Legal requirements
We process your personal data in order to process orders in the online shop on the basis of the following legal requirements:
- to fulfil a contract or to carry out pre-contractual measures, in accordance with art. 6 para. 1 letter b GDPR;
- to fulfil a legal obligation, which we are subject to, in accordance with art. 6 para. 1 letter c GDPR in connection with commercial, commercial or tax law, insofar as we are obliged to record and store your data; and
- to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR, insofar as we assert legal claims or defend ourselves in legal disputes.
- If LUISA CERANO obtains your consent during registration, the processing will be carried out based on this consent in accordance with Art. 6 (1) (a) GDPR. Your consent is voluntary.
3.3.2.4. Storage period and revocation of consent
We generally process your personal data in connection with your customer account until the termination of your user contract, if we have asked you for consent during registration, until you withdraw your consent. You can revoke your consent at any time with effect for the future. A simple declaration is sufficient (by post to LUISA CERANO GmbH, Weberstraße 1, 72622 Nürtingen, by e-mail to info@luisacerano.de). The withdrawal of consent does not affect the lawfulness of the processing carried out based on the consent before the withdrawal. In the event of a revocation, however, we will delete your customer account in our online shop. After the termination of your user contract or the revocation of your consent, we will automatically delete your customer account on our online shop. In addition, as a logged-in user, you can edit and remove your own details and information at any time.
Due to commercial and tax law requirements, we are obliged to store your address, payment, and order data for a period of ten years.
3.3.3 Sending of newsletters
3.3.3.1 Purpose
If you subscribe to the LUISA CERANO newsletter, we will need your e-mail address and you also have the option of giving your name and date of birth. This data is only used to communicate with you, within the context of providing the newsletter.
To register for the newsletter, LUISA CERANO uses the so-called double-opt-in procedure, i.e. the newsletter will only be sent to you by e-mail if you have previously expressly confirmed to LUISA CERANO that the newsletter service should be activated. Following your registration, you will initially receive an e-mail confirmation at the e-mail address which you have provided, asking you to confirm that you wish to receive the newsletter (by clicking on a link in this e-mail). By clicking on this link, you give your consent to subscribe to the newsletter.
If you purchase goods and services on our website and leave your e-mail address here, this can subsequently be used by us in order to send a newsletter. In such cases, the newsletter will only send direct mail for similar goods or services from our range.
The newsletter is sent by the shipping service provider "klaviyo", 125 Summer Street, Boston, MA 02110 USA. You can access its privacy policy here: https://www.klaviyo.com/legal/privacy-notice.
The shipping service provider is used based on our legitimate interests in accordance with Art. 6 (1) (f) GDPR and on a data processing agreement in accordance with Art. 28 (3) sentence 1 GDPR.
The shipping service provider may use the recipients’ data in the form of a pseudonym, i.e. use without assignment to the user to optimise its own services or use the data for statistical purposes. However, the shipping service provider does not use the data of our newsletter recipients to write to them itself or to pass the data on to third parties.
If you don't want to receive any further newsletters, you can revoke your consent for the future at any time, without incurring any costs other than the transmission costs according to the basic rates. A message in writing, sent to the e-mail address datenschutz@luisacerano.de is sufficient for this. Of course, you will also find an unsubscribe link in every newsletter.
3.3.3.2 Legal basis
We process your personal data to send newsletters on the basis of the following legal requirements:
- after the user has subscribed to the newsletter and given his/her consent to this, in accordance with art. 6 para. 1 letter a GDPR.
- for the sending of the newsletter because of a sale of goods or services, in accordance with sect. 7 para. 3 (German) Act against Unfair Competition.
4. Categories of recipients
Initially, only our staff will be aware of your personal data. In addition, to the extent, which is permitted or required by law, we will share your personal information with other recipients who provide services related to our website. We restrict the transfer of your personal data to what is necessary, especially to that which is necessary for processing your order. Sometimes, our service providers receive your personal data as an order processor and are then strictly bound by our instructions when handling your personal data. In part, the recipients act independently with your data which we transmit to them.
The following section lists the categories of recipients of your personal data:
- Payment service providers and banks, for settling payments,
- Providers of logistics services to send you the goods,
- IT service providers in the administration and hosting of our website,
- Collection agencies and legal advisors who assert our claims.
5. Data security
LUISA CERANO is committed to securing your personal information by using appropriate security measures to protect it from loss, misuse, or tampering. These security measures will be updated from time to time according to current advances in technology.
LUISA CERANO uses SSL (Secure Sockets Layer) encryption when capturing or transmitting sensitive data. This includes all pages with input boxes into which user data can be entered (e.g. newsletter subscription, contact form, etc.). SSL encryption ensures that only LUISA CERANO can read the data. This security standard is active if either the symbol of an intact key or a closed lock (browser-dependent) appears in the status bar or in the lower part of your browser window.
6. Transfer to third countries
If LUISA CERANO processes data in a third country (i.e., outside the European Union or the European Economic Area), or within the context of using third party services or discloses, or transmits data to third parties, this will only be done based on your consent or based on our legitimate interests. LUISA CERANO only allows the data to be processed in a third country if the special conditions of art. 44 GDPR et seq. are met, e.g. the processing takes place based on special guarantees, such as the officially recognised level of data protection corresponding to EU regulations or the observance of officially recognised specific contractual obligations ('standard contract clauses').
7. Duration of the storage
7.1 Informational use of the website
If you use our website solely for the purpose of receiving information, we will only store your personal data on our servers for the duration of your visit to our website. After you have left our website, your personal data will be deleted immediately.
Server log files have been disabled.
7.2 Active use of the website
In the case of active use of our website, we initially store your personal data for the duration of your enquiry or for the duration of our business relationship. This also includes the initiation of a contract (pre-contractual legal relationship) and the execution of a contract.
In addition, we will then store your personal information until the statute of limitations of any legal claims arising from the relationship with you starts, to use as evidence where appropriate. The limitation period is usually between 12 and 36 months but can also last up to 30 years.
We will delete your personal data at the start of the limitation period unless there is a statutory storage obligation, e.g., in the German Commercial Code (sects. 238, 257 para. 4 German Commercial Code) or the German Tax Code (sect. 147 para. 3, 4 (German) Tax Code) in front. These storage requirements may be two to ten years.
8. Your rights as a data subject
Under the legal requirements, you are entitled to the following rights as a data subject, which you can assert against us:
- Right of access: Under art. 15 GDPR, you are entitled to demand confirmation from us at any time as to whether we process personal data relating to you; If this is the case, you are also entitled under art. 15 GDPR to receive information about this personal data and certain other information (including among other things, purposes of processing data, categories of personal data, categories of recipients, planned storage period, your rights, the source of the data, the use of automated decision making and in the case of a transfer to a third country the appropriate guarantees) and to obtain a copy of your data.
- Right to rectification: In accordance with art. 16 GDPR, you are entitled to demand that we correct the personal data stored about you if it does not apply or is incorrect.
- Right to erasure (‘right to be forgotten’): You are entitled, under the conditions of art. 17 GDPR, to demand that we delete your personal data without delay. Among other things, there is no right to deletion if the processing of personal data is required for (i) exercising the right to freedom of expression and information, (ii) the fulfilment of a legal obligation to which we are subject (e.g. statutory retention obligations) or (iii) enforcement, exercising or defending legal claims.
- Right to restriction of processing: Under the conditions of art. 18 GDPR, you are entitled to demand that we limit the processing of your personal data.
- Right to data portability: Under the conditions of Art. 20 GDPR, you are entitled to demand that we provide you with the personal data relating to you, which you have provided to us, in a structured, standard, machine-readable format.
- Right to object: Under the conditions of art. 21 GDPR, you are entitled to object to the processing of your personal data. In such cases, we have to stop the processing of your personal data. The right to objection only exists within the limits provided for in art. 21 GDPR. In addition, our interests may preclude any termination of processing, so we may, despite your opposition, process your personal information.
- Right to lodge a complaint to a supervisory authority: If you feel that the processing of your personal data infringes the GDPR, you are entitled to file a complaint with a supervisory authority under the conditions of art. 77 GDPR, especially within the Member State of your place of residence, your place of work or the place of the alleged infringement. The right of appeal is without prejudice to any other administrative or judicial remedy.
You can address your concern to the LUISA CERANO data protection officer by e-mail (datenschutz@luisacerano.com).
Right to object: You have the right, for reasons arising from your particular situation, to file an objection against the processing of your personal data by us at any time, which takes place pursuant to art. 6 para. 1 lit. f GCPR (legitimate interest of the responsible person). We will then no longer process your personal information, unless we can demonstrate compelling legitimate grounds for processing it that outweigh your interests, rights and freedoms, or if the processing serves the purpose of enforcing, pursuing or defending legal claims. If the personal data relating to you is processed to send direct mail, you have the right to object to the processing of your personal data for the purposes of such advertising at any time. If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes. |
9. Obligation to provide data
Generally, you are not obliged to provide us with your personal data. However, if you do not, we will not be able to provide you with our website correspond to your enquiries and we will not be able to enter a contract with you via our online store. Personal data that we do not necessarily need for the above-mentioned processing purposes are marked accordingly as voluntary information.
10. Amendment of this privacy policy
LUISA CERANO reserves the right to change this privacy policy in the future. You should therefore regularly review the data protection statement when you visit this website. The current version of this data protection statement applies during your visit.
LUISA CERANO GmbH & Co. KG
Weberstraße 1
72622 Nürtingen
Customer service:
Mon.-Thurs. 9 am to 5 pm
Fri.: 9 am to 4 pm
Tel.: +49 (0) 7022 / 705 - 137
E-mail : info@luisacerano.de