privacy and data protection

Data protection

Welcome to Jolly Designs!

With the following data protection regulations we would like to inform you about how your data is handled when you use our homepage or our web shop www.jolly-designs.de (hereinafter: homepage). When using our homepage, you agree to the following data protection regulations. The data protection information and declarations there apply to websites of other providers, which are referred to via links, for example.

I. Responsible body

We are responsible for the collection, processing and use of your personal data within the meaning of Article 4 No. 7 of the General Data Protection Regulation (GDPR).

Jolly Designs GmbH
Hans-Mess-Straße 3, 61440
Oberursel (Taunus), Germany
Germany
Email: info@jolly-designs.com

as operator of the homepage www.jolly-designs.de. If you have any questions about your data or this data protection declaration or to assert your data subject rights, you can contact us using the contact details above.

II. Encryption

All incoming and outgoing data is transmitted using TLS encryption. You can recognize the encrypted connection when using our homepage by the fact that the address line of your browser begins with “https://” and the encryption symbol there. Thanks to TLS encryption, the transmitted data cannot be read by third parties.

III. Collection, processing and use of personal data

1. Personal data

“Personal data” within the meaning of the GDPR is all information that relates to an identified or identifiable natural person; A natural person is considered identifiable if he or she can be identified directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an online identifier or one or more special features that express the physical , physiological, genetic, psychological, economic, cultural or social identity of that natural person.

Your personal data will only be processed in accordance with the provisions of applicable data protection law. Further information about the type, scope and purpose of the collection, processing and use of personal data can be found below:

2. Collection of data when you visit our homepage

When you visit our homepage, the web server automatically records log files based on our legitimate interests in accordance with Article 6 (1) (f) GDPR. These cannot be assigned to a specific person; This data includes, for example, browser type and version, language, operating system used, referrer URL (the previously visited page), IP address of the requesting computer, access date and time of the server request and the client's file request (file name and URL). This data is only collected for the purpose of statistical analysis and for security reasons (e.g. to investigate acts of abuse or fraud) and is stored for a period of 7 days and then deleted. If it is necessary to store the data for a longer period of time for evidentiary purposes, it is exempt from deletion until the respective incident has been finally clarified.

In principle, you can visit our homepage without having to enter any personal data.

3. Use of cookies

We or third parties commissioned by us store so-called cookies on the customer's hard drive in order to make the use of our website more user-friendly and effective overall. The legal basis for this is Article 6 Paragraph 1 Letter f GDPR.

A cookie is a small text file that is used, among other things, to collect information regarding the use of a website. These cookies cannot run programs or transmit viruses to your computer. They do not contain any personal data, cannot be assigned to specific people and, unless otherwise stated, are automatically deleted after one year at the latest. This data will not be merged with other data sources.

You can also use our website without cookies. The storage of cookies can be deactivated in the respective browser, restricted to certain websites or the browser can be set so that it notifies the user as soon as a cookie is sent. The user can also delete cookies from the hard drive of their PC at any time.

IV. Data exchange with third parties, involvement of third countries in data processing

We also collect and store data provided by third-party providers based on your consent in accordance with Article 6 (1) (a) GDPR and transmit the corresponding data to them.

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing or transmitting data to third parties, this will only be done:

a. if it is necessary to fulfill our (pre-)contractual obligations (Art. 6 Para. 1 lit. b GDPR),

b. based on your consent (Art. 6 Para. 1 lit. a GDPR),

c. due to a legal obligation (Art. 6 Para. 1 lit. c GDPR) or

d. based on our legitimate interests (Art. 6 Para. 1 lit. f GDPR).

Subject to legal or contractual permissions, we only process or have the data processed in a third country if the special requirements of Art. 44 ff. GDPR are met. The processing is carried out, for example, on the basis of special guarantees, such as compliance with officially recognized special contractual obligations (“standard contractual clauses”).

V. Creation of a customer account

You have the option of registering as a customer on our homepage and setting up a customer account. To do this, you must fill out the form under “Create account” with your first name, last name, email address, password and birthday. When you log into your customer account for the first time, you can add your details. Mandatory fields are marked [* Required]. Your complete contact details will then be automatically applied to every (subsequent) order. You can view your past orders via your customer account. The collection and use of the data is based on your consent in accordance with Art. 6 Para. 1 lit. a GDPR.

VI. Use of the contact form

If you use our contact form, we collect your full name and email address in order to fulfill (pre-)contractual obligations or carry out measures, Art. 6 Para. 1 lit. b GDPR. The personal data that you provide to us as part of this contact request is only required to answer your request or contact you and is used for the associated technical administration. It will not be passed on to third parties.

Your personal data will be deleted even without your revocation if we have processed your request or you revoke your consent to storage given here. This also happens if storage is not permitted for other legal reasons.

VII. Newsletter subscription

We offer to inform you regularly by email about new products, interesting offers and current price developments. Subscribing to our newsletter is voluntary and takes place via the so-called single opt-in procedure. To do this, all you have to do is register for the newsletter on our homepage. In order to be able to prove the subscription in accordance with the legal requirements, the registration time, confirmation time and the IP address are logged based on our legitimate interests in accordance with Art. 6 Para. 1 lit. f GDPR. When registering for the newsletter, you consent to the processing of the data provided for sending or receiving emails, Art. 6 Para. 1 lit. a GDPR. You also agree that data about your usage behavior (opening and clicking on links in the email) will be collected and processed by us in order to be able to tailor the content of the mailings to your needs.

You can revoke your consent to the sending of the newsletter at any time and without giving reasons with future effect via a link that you will find at the end of each newsletter or by sending an email to info@jolly-designs.com .

We can store the unsubscribed email addresses and the data stored as part of logging the registration for up to three years based on our legitimate interests before we delete them for the purpose of sending newsletters in order to be able to prove that consent was previously given. The processing of this data is limited to the purpose of possible defense against claims. An individual request for deletion is possible at any time, provided that the previous existence of consent is confirmed at the same time.

The newsletter is sent using “Omnisend”, an email marketing service from Omnisend LLC, Unit A3, Gateway Tower, 32 Western Gateway, E16 1YL, London, England. Omnisend supports us, for example, by sending personalized messages, promoting products and acquiring customers. This is software that is integrated into e-commerce platforms such as Shopify. The processing of your data is based on our legitimate interests in accordance with Art. 6 Para. 1 lit f GDPR. Further information on data protection can be found at: https://www.omnisend.com/privacy/

The shipping service provider is used on the basis of our legitimate interests in accordance with Article 6 Paragraph 1 Letter f of the GDPR and an order processing contract in accordance with Article 28 Paragraph 3 Sentence 1 of the GDPR.

The shipping service provider can use the recipient's data in anonymized form, ie without assigning it to a user, to optimize or improve its own services, e.g. to technically optimize shipping and the presentation of the newsletter or for statistical purposes. However, the shipping service provider does not use the data of our newsletter recipients to write to them itself or to pass the data on to third parties.

VIII. Disclosure of personal data

1. Transfer of data to service providers

Your personal data will be passed on in accordance with Article 6 (1) (b) GDPR if this is necessary to process and fulfill contractual obligations, e.g. logistics partners such as DHL, Hermes, dpd, GLS, FEDEX or payment service providers such as Paypal or Stripe, StripeKlarna , Klarna Pay Later, VISA or Mastercard. The transfer of your personal data is limited to the minimum (e.g. name, delivery address for logistics partners). Our contractual partners may only use this data to fulfill the order.

In addition, your personal data will be passed on on the basis of Article 6 Paragraph 1 Letters a, c, f GDPR.

2. Transfer of data to hosting providers

Hosting services serve to provide infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services.

Our homepage is provided via “Shopify”, a service of Shopify International Limited, Victoria Buildings, 2nd Floor 1-2, Haddington Road, Dublin 4, D04 XN32, Ireland.

Further information about the data protection regulations can be found at: https://www.shopify.de/legal/datenschutz .

We or our hosting provider processes inventory data, contact data, content data, contract data, usage data, meta and communication data from customers, interested parties and visitors to our homepage on the basis of our legitimate interests in the efficient and secure provision of our homepage in accordance with Art. 6 Para. 1 lit. f GDPR. Any processing of data by Shopify is based on a contract data processing relationship, Art. 28 GDPR.

IX. Use of web analysis, remarketing and retargeting tools

Based on our legitimate interests within the meaning of Art. 6 Para. 1 lit. f GDPR, we use various tools or plugins for web analysis, remarketing and retargeting to optimize our online presence and to be able to put together more targeted offers for you.

Cookies are used, the IP address is forwarded and/or different types of data are recorded and evaluated. This includes, for example, the number of website visitors, duration of the visit, average page loading time, and the origin of the visitors.

In detail:

1. Google Analytics

We use Google Analytics, a web analysis service provided by Google Inc. based at 1600 Amphitheater Parkway, Mountain View, CA 94043, USA. Google Analytics uses cookies that enable an analysis of how users use the homepage. The information generated by the cookie about your use of this homepage (including your IP address) is usually transmitted to a Google server in the USA and stored there. On our homepage, IP anonymization is activated by adding the code “gat._anonymizeIp();” so that your IP address is transmitted shortened by Google within EU member states or in other contracting states to the Agreement on the European Economic Area (so-called .IP masking). Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On our behalf, Google will use this information to evaluate your use of the homepage, to compile reports on our homepage activities and to provide other services related to homepage and Internet use. Google may also transfer this information to third parties if this is required by law or if third parties process this data on behalf of Google.

Google offers an extension for web browsers (add-on) through which the collection of data by Google Analytics and the processing of this data by Google can be prevented. The add-on can be downloaded and installed at https://tools.google.com/dlpage/gaoptout at your own risk.

You can find further information about this at: https://www.google.com/policies/privacy (general information about Google Analytics and data protection).

2. Facebook

We use remarketing tags from the social network facebook.com from Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA (“Facebook”). The “Custom Audiences” feature used is a targeting option for advertisements to build our target group of Facebook users. When you visit our homepage, the remarketing tags establish a direct connection between your browser and the Facebook server. This allows Facebook to assign your visit to our pages to your user account. We can use the information obtained in this way to display Facebook Ads.

Further information can be found in Facebook's data protection declaration at https://www.facebook.com/about/privacy/ .

X. Social media plugins

Based on our legitimate interests within the meaning of Art. 6 Para. 1 lit. f GDPR, we use various social media plugins for web analysis, remarketing and retargeting to optimize our online presence and to be able to put together more targeted offers for you.

1. Facebook

We use the social plugin from the social network facebook.com. This is operated by Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA (“Facebook”). The plugins can be recognized by a Facebook logo or are marked with the addition “Facebook Social Plugin”. The list and appearance of the Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins .

If you access a function of this online offer that contains such a plugin, a direct connection will be established with the Facebook servers. The content of the plugin is transmitted directly to your device by Facebook and integrated into the online offering. Usage profiles can be created from the processed data. We therefore have no influence on the amount of data that Facebook collects with the help of this plugin and will therefore inform you according to our level of knowledge. By integrating the plugins, Facebook receives the information that you have accessed the corresponding page of the online offer. If you are logged in to Facebook, Facebook can assign the visit to your Facebook account. When you interact with the plugins, e.g. For example, if you share our homepage on Facebook using the “share” button, the corresponding information from your device will be transmitted directly to Facebook and stored there. If you are not a Facebook member, there is still the possibility that Facebook will find out and store your IP address. According to Facebook, only an anonymized IP address is stored in Germany. If you are a Facebook member and do not want Facebook to collect data about you via this online offering and link it to your member data stored on Facebook, you must log out of Facebook and delete your cookies before using our online offering.

Further information can be found in Facebook's data protection information:

https://www.facebook.com/about/privacy and at
http://www.aboutads.info/choices (US site) or
http://www.youronlinechoices.com (EU site).

The settings are platform-independent, meaning they are applied to all devices, such as desktop computers or mobile devices.

2. Twitter

Functions and content from the Twitter service may be integrated into our online offering, offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. This may in particular include buttons with which the user can share the link to the website. If you are a member of the Twitter platform, Twitter can assign access to the above-mentioned content and functions to your profile there.

Twitter privacy policy: https://twitter.com/de/privacy

3. Instagram

In addition, functions and content from the Instagram service may be integrated into our online offering. The provider is Meta Platforms Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. This may include, for example, content such as images, videos or texts and buttons with which users can express their liking for the content, subscribe to the authors of the content or subscribe to our posts.

If you are a member of the Instagram platform, Instagram can assign access to the above-mentioned content and functions to your profile there.

More about Instagram’s privacy policy at: http://instagram.com/about/legal/privacy/

4. TikTok

Furthermore, functions and content of the TikTok service may be integrated into the online offer, offered via TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380 Ireland. This includes, for example, content such as videos and buttons with which users can express their liking for the content, subscribe to the author of the content or the provider's contributions.

If you are a member of the TikTok platform, TikTok can assign access to the above-mentioned content and functions to your profile there. The information generated by the pixel about your use of this website is transmitted to several TikTok servers, including in third countries such as the USA, and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened beforehand by TikTok within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to TikTok's servers in third countries and shortened there. On behalf of the operator of this website, TikTok will use this information to evaluate your activities on the website, to compile reports on website activity and to provide other services related to website use and internet use to the website operator.

TikTok offers extensive data protection information at https://www.tiktok.com/legal/privacy-policy?lang=de .

5. Pinterest

We also use the Pinterest social media plugin, which is provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland. This may include content such as images, videos or texts and buttons with which users can express their liking for the content, subscribe to the authors of the content or subscribe to our posts.

If you are a member of the Pinterest platform, Pinterest can assign access to the above-mentioned content and functions to your profile there. The information generated by the plugin about your website usage is transferred to a Pinterest server in the USA and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened by Pinterest within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Pinterest server in the USA and shortened there. On our behalf, Pinterest will use this information to evaluate your website activities, to compile reports on them and to provide us with other services related to website and internet usage.

Pinterest privacy policy: https://policy.pinterest.com/de/privacy-policy

XI. Integration of videos via YouTube

We use videos from YouTube, LLC 901 Cherry Ave., 94066 San Bruno, CA, USA, a company of Google Inc., AmphitheaterParkway, Mountain View, CA 94043, USA. If you access the page of one of our products that has an embedded video (can also be accessed directly via YouTube), a connection will be established to the YouTube servers and the content will be displayed on the website by notifying your browser. The information generated by the plugin about your website use is transferred to a YouTube server in the USA and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened beforehand by YouTube within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a YouTube server in the USA and shortened there. On our behalf, YouTube will use this information to evaluate your website activities, to compile reports on them and to provide us with other services related to website and internet usage. According to YouTube, in “– extended data protection mode -” only data is transmitted to the YouTube server, in particular which of our product pages you have visited when you watch the video. If you are logged in to YouTube at the same time, this information will also be assigned to your YouTube member account. You can prevent this by logging out of your member account before visiting our homepage.

Further information about YouTube's data protection is provided by Google under the following link. https://www.google.de/intl/de/policies/privacy/

XII. Your rights

You have the following rights:

1. Right to information (Article 15 GDPR)

You have the right at any time to request free information about your personal data stored by us, its origin and recipient, the purpose of data processing, the planned duration of data storage, including a copy of the personal data that is the subject of processing.

2. Right to rectification (Article 16 GDPR)

You also have the right at any time to have incorrect personal data corrected immediately or incomplete personal data completed.

3. Right to revoke consent (Art. 7 Para. 3 GDPR)

You have the right to revoke your consent to data processing at any time and with effect for the future, without there having to be a reason for revocation.

4. Right to deletion (Article 17 GDPR)

Under the conditions of Art. 17 GDPR, you can request the deletion of your personal data. Your right to deletion depends, among other things, on whether the data concerning you is still required by us to fulfill our legal tasks.

5. Right to restriction of processing (Article 18 GDPR)

Under the conditions of Art. 18 GDPR, you can request the restriction of the processing of personal data concerning you.

6. Right to data portability (Article 20 GDPR)

You have the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to transmit it to another controller, provided that the processing is based on consent and the processing is carried out using automated procedures.

7. Right to object (Article 21 GDPR)

You have the right to object at any time to the creation of user profiles and to the processing of your personal data, provided that the processing takes place on the basis of Article 6 (1) (e) or (f) of the GDPR. Your personal data will no longer be processed unless there are compelling legitimate reasons that outweigh your interests, rights and freedoms. If your personal data is used for direct advertising purposes, you of course have the right to object to such processing at any time.

8. Right not to be subject to automated decisions (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you

9. Right to complain (Art. 77 GDPR)

You also have the right to lodge a complaint with a supervisory authority.