Data protection

1. Scope and Overview
This data protection declaration applies to the use of the website www.naturalsophy.ch (hereinafter referred to as "website").
The privacy policy only applies to personal data.
This Privacy Policy sets out the nature and purpose of data collection and use and your choices regarding that
data on.
By using this website, you agree to the collection, use and transfer of your data in accordance with this privacy policy.
2. Controller
The person responsible within the meaning of the EU General Data Protection Regulation (hereinafter referred to as "GDPR") is:
NATURALSOPHY FENG-GOHRINGER, info@naturalsophy.com
If you want to object to the collection, processing or other use of your data by us in full or for individual measures, you may address your objection to the person responsible.
3. Legal bases for data processing
Insofar as we obtain the consent of the data subject for the processing of personal data, Article 6 (1) (a) GDPR serves as the legal basis.
Article 6 (1) (b) GDPR serves as the legal basis for the processing of personal data required to fulfill a contract to which the data subject is a party. This also applies to
Processing operations that are necessary to carry out pre-contractual measures.
Insofar as processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Article 6 (1) (c) GDPR serves as the legal basis.
If the processing is to protect a legitimate interest of ours
company or a third party and the interests, fundamental rights and fundamental freedoms of the data subject do not outweigh the former interest, Art. 6 (1) lit. f GDPR serves as the legal basis for the
Processing.
4. Data Erasure and Retention Period
Unless specifically stated, the personal data of the person concerned will be deleted or blocked as soon as the purpose of storage
omitted.
However, storage that goes beyond this can take place if this is mandatory in the applicable legal regulations. The data will also be blocked or deleted if one of the aforementioned
statutory storage period expires, unless there is a need for further storage of the data for the purposes specified in Section 3 of this data protection declaration.
5. Use of the Website
5.1 Log files and other access data
When you use this website, we will collect information about you; we collect, store and use data. The access data includes the name and URL of the file accessed, the date and time of access and the IP address.
We use this log data without assignment to your person or other creation of a profile for statistical evaluations for operational purposes, for anonymous recording of the number of visitors to our website ("traffic") and the scope and type of use of our website and services. We store IP addresses for a limited period of time.
Third Party Hosting Service.
A third party provides in the case of processing in our
Order for us the services for hosting and displaying the website. This serves to protect our overriding legitimate interests in a correct presentation of our offer within the framework of a balancing of interests. All data collected as part of the use of this website or in the forms provided for this purpose in the online shop are processed on its servers.
Our service provider is based in Germany.
5.2 Data collection and data use for contract processing and when opening a customer account.
As part of your order and when contacting us, e.g. via the contact form or email or when opening a customer account, we collect personal data if you provide it to us voluntarily. The marked mandatory fields are required as part of your order to process the contract or to process your contact or opening of the customer account and you cannot complete the order or the account opening or send the contact without providing them. The data that is collected can be seen from the respective input forms. For the execution of the contract and processing of your inquiries, we use the data you have provided in accordance with Art. 6 Para. 1 S.1 lit.b DSGVO.
Before completing each order, you must confirm that you have taken note of the current terms and conditions and data protection notices and that you are informed about the newsletter and the existing right to unsubscribe. You provide further information voluntarily and failure to provide it has no effect whatsoever. The data is stored by us permanently for the purpose of answering your inquiry, processing your order and sending the newsletter, for example. You have the right to information and objection to your data stored by us at any time. This can be sent to us by sending a message.
If you communicate with us on social media channels such as Instagram or Facebook, link, "like", send greetings and leave comments and photos to us and we agree to a link, your messages, comments, photos or greetings will be published on our homepage visible through the link and will not be saved by us.
We use Woocommerce to create and manage your customer account.
5.3 Email newsletters
We use the data required for this to regularly send you our
To send email newsletters based on your consent in accordance with Art. 6 Para. 1S.1 lit.a DSGVO if you register for our newsletter or tick the appropriate option in the ordering process. You can unsubscribe from the newsletter at any time by sending us a message. Unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration, we will delete your email address after you have unsubscribed. Please send an email to us at info@naturalsophy.com with a corresponding request to be removed from the mailing list. The newsletter is sent by us by email. Your email address will be
not passed on to this.
5.4 Data Sharing
We pass on your data to the shipping company commissioned with the delivery for the fulfillment of the contract in accordance with Article 6 Paragraph S.1 lit. In order to process payments, we pass on the payment data collected for this purpose to the credit institution commissioned with the payment and, if applicable, to the payment service provider commissioned by us or to the selected payment service provider, depending on which payment service provider you selected in the ordering process. If you create an account there, the selected payment service providers collect some of this data themselves. In this case, you must therefore register with the payment service provider with your access data during the ordering process. In this respect, the data protection declaration of the respective payment service provider applies.
Data transfer to shipping service providers
With regard to Art. 6 Para. 1 S.1 lit.a DSGVO, we pass on your email address and telephone number to the selected shipping service provider, provided that you give us your express consent to this during or after your order
have given so that the shipping service provider can contact you before delivery for the purpose of delivery notification or delivery coordination. If you wish to revoke your consent, you can send a message to the contact option described below or contact the shipping service provider directly at the following contact address (post https://www.post.ch/de ). Unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration,
we will delete your data provided for this after revocation.
5.5 Cookies and Google Analytics
We use cookies on various pages to make visiting our website attractive, to display suitable products and to enable market research and the use of certain functions. This serves to protect our overriding legitimate interests in the context of a weighing of interests in an optimized presentation of our offer in accordance with Art. 6 Para.1 S.1 lit.f DSGVO. These are small text files that are automatically stored on your end device
get saved. Eg session cookies are deleted after the end of the browser session. Other cookies remain on your end device, which enables us to recognize your browser the next time you visit (so-called persistent cookies). Under the cookie settings of your web browser you can see the duration of the storage. You can set your browser to set cookies and accept them or exclude cookies for specific cases or in general. This differs in the way he manages the cookie setting. If cookies are not accepted, the website may function with restrictions.
We use Google Analytics, the web analytics service provided by Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files that are stored on your hardware (e.g. computer) and enable user analysis of the homepage. The data generated by cookies about the use of this website by users is usually transmitted to a Google server in the USA and stored.
If IP anonymization is activated on our website, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. IP anonymization is active on this website. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide us with other services related to website activity and internet usage.
The IP address transmitted by Google Analytics from your browser will not be merged with other Google data. You can prevent the storage of cookies by setting your browser software accordingly.
However, we would like to draw your attention to the fact that in this case not all functions of this website may be fully available for use.
You can prevent the identification of the data generated by the cookie and related to your use of the website (including your IP address) and forwarding to Google as well as the processing of this data by Google: To do this
please download and install the browser plug-in available under the following link: http://tools.google.com/dlpage/gaoptout?hl=de. Using an opt-out cookie to disable at this link
Your end device can be prevented from being recorded by Google Analytics on this website in the future. The opt-out cookie is only valid for www.naturalsopyh.com and the browser used. If you have deleted the cookies in your browser history, you must click the link to deactivate tracking again when you visit our site again or when you visit it with a different browser.
5.6 Use of Facebook Custom Audiences Pixel
On our website we use "Custom Audiences Pixel" from Facebook Inc.
("Facebook"). This serves the purpose of presenting interest-based advertisements to visitors to our website as part of their visit to the social network Facebook. For this purpose, a pixel from Facebook was implemented on our website. This pixel establishes a direct connection to the Facebook servers when you visit our website. It is transmitted to the Facebook server that you have visited our website and Facebook assigns this information to your personal Facebook user account. You can find more information about the collection and use of data by Facebook and about your rights in this regard and options for protecting your privacy in Facebook's data protection information at https://www.facebook.com/about/privacy/. Alternatively, you can object to interest-based advertising on Facebook at https://www.facebook.com/settings/?tab=ads#_=_. To do this, you must be logged in to Facebook or you can object directly to us.
5.7 Integration of Third-Party Services and Content
5.7.1 YouTube videos
On our websites we use the YouTube embedding function to display and play videos from the provider "Youtube", which belongs to Google LLC., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google").
According to the provider, user information is only stored when the video is played. As soon as the embedded YouTube videos start, the provider uses cookies to collect information about user behavior. These are used to collect video statistics, improve user-friendliness and prevent abusive practices. Your data is assigned directly to your account when you are logged into Google and click on a video. You must log out before activating the button to prevent assignment to your YouTube profile. Your profile will then be saved as a user profile on YouTube as a user who is not logged in and will be evaluated. This evaluation is carried out in accordance with Article 6 (1) (f) GDPR on the basis of Google's notorious interests in the display of personalized advertising, market research and the needs-based design of its website. If you wish to object to the creation of user profiles, you must address YouTube directly.
Each time this website is called up, a connection to the Google network "DoubleClick" is established, which can trigger further data processing operations without our influence, regardless of the playback of the embedded videos. Google LLC based in the USA is certified for the US-European data protection agreement "Privacy Shield", which ensures compliance with the data protection level applicable in the EU.
Further information on data protection at "YouTube" can be found in the provider's data protection declaration at: https://www.google.de/intl/de/policies/privacy
5.7.2 Use of Facebook social media plugins
Due to our legitimate interest in the analysis, optimization and operation of our online offer (in the sense of Art. 6 Para. 1 lit. f. DSGVO), this website uses the Facebook social plugin, which is provided by Facebook Inc. ( 1 Hacker Way, Menlo Park, California 94025, USA). The integration can be recognized by the Facebook logo or by the terms "Like", "Like", "Share" in the Facebook colors (blue and white).
Information on all Facebook plugins can be found via the following link:
https://developers.facebook.com/docs/plugins/
Facebook Inc. complies with European data protection law and is certified under the Privacy Shield Agreement: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active
The plugin establishes a direct connection between your browser and the Facebook servers. The website operator has no influence whatsoever on the nature and scope of the data that the plugin transmits to the Facebook Inc. servers. Information can be found here:
https://www.facebook.com/help/186325668085084
The plugin informs Facebook Inc. that you, as a user, have visited this website. It is possible that your IP address will be saved. If you are logged into your Facebook account while visiting this website, the information mentioned will be linked to it.
If you use the functions of the plugin - for example by sharing or "liking" a post - the corresponding information will also be transmitted to Facebook Inc. Would you like to prevent the Facebook. inc
If this data is linked to your Facebook account, please log out of Facebook before visiting this website and delete the stored cookies. You can make further settings for data processing for advertising purposes via your Facebook profile or object to the use of your data for advertising purposes. You can access the settings here: Profile settings on Facebook: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen Cookie deactivation page on the European website: http://optout.networkadvertising.org/?c=1 #!/ You can read about what data, for what purpose and to what extent Facebook collects, uses and processes data and what rights and setting options you have to protect your privacy in Facebook's data protection guidelines. You can find them here: https://www.facebook.com/about/privacy/
5.7.3 Instagram
Functions and content of the Instagram service, which is offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA, are integrated into our website. The integrated Instagram button on our site informs Instagram that you have accessed the corresponding page of our website. If you are logged in to Instagram, Instagram can assign this visit to our site to your Instagram account and thus link the data. The data transmitted by clicking the Instagram button will be saved by Instagram. For the purpose and scope of the data collection, its processing and use as well as your rights in this regard and setting options for protecting your privacy, you will find further information in the Instagram data protection information, which you can access at http://instagram.com/about/legal/privacy/ . To prevent Instagram from associating your visit to our site with your Instagram account, you must log out of your Instagram account before visiting our site.
5.7.4 Pinterest
Functions and content of the service Pinterest,
offered by Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA. Through the integrated Pinterest button on our site, Pinterest receives the information that you have accessed the corresponding page of our website. If you are logged in to Pinterest, Pinterest can assign this visit to our site to your Pinterest account and thus link the data. The data transmitted by clicking the Pinterest button is stored by Pinterest. You can find more information about the purpose and scope of the data collection, its processing and use, as well as your related rights and setting options for protecting your privacy, in the Pinterest data protection information, which you can access via https://about.pinterest.com/de/privacy-policy can.
To prevent Instagram from associating your visit to our site with your Pinterest account, you must log out of your Pinterest account before visiting our site.
5.7.5 Google+
Functions and content of the Google+ platform, offered by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"), can be integrated within our website. The integrated Google+ button on our site informs Google that you have accessed the corresponding page of our website.
If the users are members of the Google+ platform, Google can assign the above-mentioned content and functions to the user profiles there.
Google is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law
(https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
You can find more information on data use by Google, setting and objection options in Google's data protection declaration (https://policies.google.com/technologies/ads) and in the settings for the display of advertisements by Google (https:// adssettings.google.com/authenticated).
6. Your rights as a data subject
To assert the rights listed below with regard to your personal data, please send an inquiry to the person responsible named under point 2, clearly identifying yourself.
6.1 Right to information and confirmation
You can request confirmation from the person responsible as to whether personal data relating to you is being processed by us. If such processing is available, you can be contacted by the person responsible
request the following information:
(1) the processing purposes;
(2) the categories of personal data being processed;
(3) the recipients or categories of recipients to whom your personal data has been or will be disclosed;
(4) the currently planned duration of the storage of the personal data concerning you or, if specific information on this is not possible, criteria for determining the storage duration;
(5) the existence of a right to rectification or erasure of personal data concerning you, a right to restriction of processing by the person responsible or a right to object to this processing;
(6) the existence of a right of appeal to a supervisory authority;
(7) all available information about the origin of the data if the personal data are not collected from the data subject;
(8) the existence of automated decision-making including profiling in accordance with Art. 22 Para. 1 and 4 GDPR and - at least in these cases - meaningful information about the logic involved and the scope
and the envisaged effects of such processing on the data subject. You have the right to request information as to whether the personal data concerning you is sent to a third country or to a
be sent to an international organization. In this context, you can request to be informed of the appropriate guarantees pursuant to Art. 46 GDPR in connection with the transmission.
6.2 Right to Rectification
You have the right to correction and completion if the processed personal data concerning you is incorrect or incomplete. The person responsible must carry out the correction or completion immediately upon your request.
6.3 Right to erasure
Obligation to delete
You are entitled and we are obliged to delete the personal data concerning you immediately if one of the following reasons applies:
(1) The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed, and there are no compelling reasons based on statutory provisions to prevent deletion.
(2) You revoke your consent on which the processing was based pursuant to Article 6 Paragraph 1 Letter a or Article 9 Paragraph 2 Letter a GDPR and there is no other legal basis for the processing.
(3) You object to the processing in accordance with Article 21 (1) GDPR and there are no overriding legitimate reasons for the processing, or you object to the processing in accordance with Article 21 (2) GDPR.
(4) The personal data concerning you was processed unlawfully.
(5) The deletion of the personal data concerning you is required due to an applicable legal provision.
(6) The personal data concerning you was collected in relation to information society services offered pursuant to Article 8 (1) GDPR.
Information to third parties If we have made the personal data concerning you public and we are obliged to delete them in accordance with Art. 17 DSGVO, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform those responsible for data processing who process the personal data that you have requested them to delete any links to, or copies or replications of, that personal data.
exceptions
The right to erasure does not exist if processing is necessary
(1) to exercise the right to freedom of expression and information;
(2) to comply with a legal obligation which requires processing under the applicable legal provisions to which we are subject, or to perform a task carried out in the public interest or in the exercise of official authority vested in the controller;
(3) for reasons of public interest in the field of public health in accordance with Article 9 (2) lit. h and i and Article 9 (3) GDPR;
(4) for archiving purposes in the public interest, scientific or historical research purposes or for statistical purposes pursuant to Art
makes it impossible or seriously impairs the achievement of the objectives of this processing, or
(5) to establish, exercise or defend any legal claim or other right.
6.4 Right to restriction of processing
You have the right to request us to restrict processing,
if one of the following conditions is met:
the accuracy of the personal data is disputed by you for a period of time that enables us to verify the accuracy of the personal data, the processing is unlawful and you refuse the deletion of the personal data and instead request the restriction of the use of the personal data; we no longer need the personal data for the purposes of processing, but you need the data to assert, exercise or defend against legal claims, or you object to the processing in accordance with Article 21 (1) GDPR
filed, as long as it has not yet been determined whether the legitimate reasons of our company outweigh yours.
6.4 Right to Data Portability
You have the right to receive the personal data that you have provided to us in a structured, common and machine-readable format. You also have the right to transmit this data to another person responsible without hindrance from us, provided that
(1) the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR and
(2) the processing is carried out using automated procedures. When exercising your right to data portability, you have the right to have the personal data transmitted directly by us to another person responsible, insofar as this is technically feasible. The freedoms and rights of other people must not be impaired by this.
6.6 Right to Object
You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data, which is based on Article 6 Paragraph 1 lit. e or f GDPR; this also applies to profiling based on these provisions.
In the event of an objection, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend against legal claims or other rights.
If the personal data concerning you is processed in order to operate direct advertising, you have the right to object at any time to the processing of your personal data for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct advertising. You have the right, for reasons arising from your particular situation, to object to the processing of your personal data for scientific or historical research purposes or for statistical purposes pursuant to Article 89 Paragraph 1 GDPR, unless , the processing is for
Fulfillment of a task in the public interest required.
6.7 Automated Decisions Including Profiling
You have the right not to use one solely on an automated basis
Processing - including profiling - to be subject to a decision that has legal effect on you or significantly affects you in a similar way.
This does not apply if the decision
(1) is necessary for the conclusion or performance of a contract between you and the person responsible,
(2) is permitted on the basis of legal provisions to which we are subject and these legal provisions contain appropriate measures to protect your rights and freedoms and your legitimate interests or
(3) with your express consent.
6.8 Right to revoke consent under data protection law
You have the right to revoke consent to the processing of personal data at any time.
6.9 Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority, particularly in the Member State where you live, work or where the alleged infringement took place, if you believe that
the processing of your personal data violates the GDPR.
The supervisory authority to which the complaint was lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Art. 78
GDPR.
7. Disclosure of data to third parties; basically no data transfer to non-EU countries. In principle, we only use your personal data within our company.
If and to the extent that we involve third parties in the fulfillment of contracts, they will only receive your personal data to the extent that the transmission is necessary for the corresponding service.
In the event that we outsource certain parts of the data processing, we contractually oblige the processors to only use personal data in accordance with the requirements of data protection laws and to ensure the protection of the rights of the data subject.
A data transfer to bodies or persons outside the European Union outside of the cases specifically mentioned in this declaration does not take place and is not planned.
8. You are entitled to save and print out this data protection declaration.