Privacy Notice
We are delighted about your interest in our online shop. Protecting your privacy is very important to us. Below you will find detailed information on how we handle your data. Your data will be processed on the basis of regulation (EU) 2016/679 of the European Parliament and of the Council – General Data Protection Regulation (GDPR).
Controller (Art. 4 (7) GDPR) is:
ONLINEPRINTERS GmbH
Dr.-Mack-Straße 83
90762 Fürth
Germany
1. Visiting our online shop
You can visit our online shops without providing any personal data. Each time you visit a website, the web server stores automatically only a so-called server log file which contains e.g. the name of the requested file, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request. This serves according to Art. 6 (1) (f) GDPR the protection of our – within the frame of balancing of interests – overriding legitimate interests in the smooth operation of the website and the proper presentation of our offer.
1.1 Hosting
All data collected within the scope of using our online shops are stored on servers of WEBSALE AG, Gutenstetter Straße 2, 90449 Nürnberg, Germany, within the scope of processing on our behalf. Services that are processed on different servers will be explained below.
1.2 Geolocalisation
If you consent to this by clicking the corresponding button, the country from which you visit our website will be determined based on your IP address in order to redirect you to an offer tailored to your location and language where appropriate. The data processed here will be erased when you close your browser.
2. Collection of personal data
We collect personal data when you give them to us voluntarily in the context of your order, when you contact us or when you open a customer account. Which data are collected can be seen in the input forms. Mandatory fields are identified as such since, in accordance with Art. 6 (1) (b) GDPR, these data are absolutely necessary for processing your contact request, for opening the customer account or for contract performance.
After complete performance of the contract or closing your customer account, your data will be restricted for further processing and erased after the expiration of any fiscal or commercial statutory retention periods, unless you have expressly consented to continued use of your data or we reserve use of the data extending beyond this that is permitted by law and of which we inform you in this notice. Closing your customer account is possible by using the function provided for this purpose in the customer account or by sending a message to us.
3. Forwarding of data
3.1 Payment processing
Depending on the payment method you select in the ordering process, you will be redirected to the respective payment service provider who will collect the data required for payment itself. You have to set up an account with the payment service provider or log on to an existing account. Then, the respective provider’s privacy policy will apply. The payment service provider will only inform us that payment has been made so that we can continue the ordering process. We might require your payment data for payment processing. This is a necessary step to perform the contract in accordance with Art. 6 (1) (b) GDPR.
3.2 Credit check in case of payments after receipt of invoice or a direct debit
If we make deliveries prior to payment, e.g. in the case of payments after receipt of invoice or a direct debit, it is necessary for conclusion of the contract to obtain identity and creditworthiness information from specialised service providers (credit reference agencies). In accordance with Art. 6 (1) (f) GDPR, this serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests in avoiding or minimising defaults of payment. For this purpose, we will transfer your personal data required for a credit check to the following company/companies:
Creditsafe Deutschland GmbH, Schreiberhauer Straße 30, 10317 Berlin, Germany, Phone +49 30473929-000
3.3 Print data containing personal data
We will forward the print data provided by you to print production on your behalf. Since these data may contain third-party personal data, we will provide you with a GDPR-compliant “Agreement on the Processing of Personal Data on behalf of the Controller” in accordance with Art. 28 GDPR for the respective order. You can view and examine the content of the agreement in the ordering process immediately before checkout. The document will be attached (PDF) to the order confirmation which you will receive by e-mail immediately after placing your order.
3.4 Trusted Shops Trustbadge
To display our Trusted Shops trustmark and any collected reviews as well as the offer of Trusted Shops products for customers after an order, the Trusted Shops Trustbadge is integrated into our online shop. This serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests in an optimal marketing by providing secure online shopping pursuant to Art. 6 (1) (f) GDPR.
When the Trustbadge is called up, the web server automatically saves a so-called server log file, which also contains your IP address, date and time of the call, the amount of transmitted data, and the requesting provider (access data), and documents the call. Individual access data will be stored in a security database for analysis of security anomalies. The log files will be automatically deleted 90 days after creation at the latest.
Further personal data will be transferred to Trusted Shops GmbH if you decide to use Trusted Shops products after having completed an order, or if you have already registered for the use. Then, the contractual agreement concluded between you and Trusted Shops will apply. For this purpose, personal data will be automatically collected from the ordering data.
The Trust Badge is an offer by Trusted Shops AG, Subbelrather Str. 15C, 50823 Köln, Germany. Information on their privacy policy: https://www.trustedshops.co.uk/imprint/
3.5 Data transfer to third countries
If data are transferred to servers provided by the following providers in third countries with your consent or to safeguard our – within the frame of balancing of interests – overriding legitimate interests, our cooperation with these providers will be based on standard data protection clauses adopted by the European Commission in accordance with Art. 46 GDPR unless otherwise specified in this privacy notice.
- Google services stated in this notice: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Information on their privacy policy: https://policies.google.com/privacy?hl=en
- Microsoft services (Bing) stated in this Data Privacy Statement: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland and Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Information on their privacy policy: https://privacy.microsoft.com/en-us/privacystatement
- Adobe Systems Software Ireland Limited, 4-6 Riverwalk,Citywest Business Campus, Dublin 24, Ireland and Adobe Inc. 345 Park Avenue, San Jose, CA 95110-2704, USA. Information on their privacy policy: https://www.adobe.com/uk/privacy.html
- LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland und LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. Information on their privacy policy: https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
3.6 List of sanctions review
As a company based in the European Union, we are obliged to check whether services are related to a sanctioned natural or legal person (EU CFSP sanctions lists). The processing of personal data of a data subject (surname, first name, company name) will be carried out in accordance with Art. 6 (1) (c) GDPR in conjunction with Regulation (EC) No. 2580/2001. According to Art. 6 (1) (f) GDPR, this also serves to protect our legitimate prevailing interests to guarantee compliance with the above duties within the scope of a weighing of interests.
4. Advertising via e-mail, mail
4.1 Contact via e-mail for advertising purposes
We collect address data for e-mailing, which is carried out by the service provider Inxmail GmbH, Wentzigerstraße 17, 79106 Freiburg, Germany. This service provider acts within the scope of processing on our behalf in accordance with Art. 28 GDPR. Information on its privacy policy: https://www.inxmail.com/data-conditions
You may refuse this use of your e-mail address at any time via the link in the received e-mail provided for that or by sending a message to our Customer Service; this will not entail any costs other than the cost of transfer calculated at the base rates. In the same way you may also object to the use of your postal address for our advertising purposes.
4.1.1 E-mail newsletter subscription
If you subscribe to our newsletter, we will use the respective data required or voluntarily given by you to send you our regular e-mail newsletter based on your consent in accordance with Art. 6 (1) (a) GDPR.
Apart from the objection options stated above, you may also comfortably unsubscribe from the newsletter in your customer account at any time.
4.1.2 Product recommendations by e-mail
If we receive your e-mail address in connection with selling a product or service and you did not refuse, we reserve the right to regularly e-mail you product recommendations from our product range based on your previous purchases. This serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests in promoting and advertising our products to our customers pursuant to Art. 6 (1) (f) GDPR.
4.2 Mail advertising
To promote and advertise our products to our customers, we will also use your postal address to send offers and information on our products by letter mail. This serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests to promote our products pursuant to Art. 6 (1) (f) GDPR. You may object to this mailing at any time by sending a message to our Customer Service; this will not entail any costs other than the cost of transfer calculated at the base rates.
5. Cookies – Consent and Management
So-called cookies help us to ensure that your visit to our online shop turns into a pleasant shopping experience. Cookies are small text files that can be stored on your terminal device.
We use a Consent Management Service to inform you in detail about the cookie technologies stated below and to obtain, manage and document your consent to the processing of your personal data using technologies that require consent. This is necessary to fulfil the legal obligation we are subject to in accordance with Art. 6 (1) (c) GDPR in order to be able to prove your consent in accordance with Art. 7 (1) GDPR.
Refusal and withdrawal
You can of course also configure every not strictly necessary cookie individually using the Consent Management Service. Detailed provider information can also be found in the Consent Management Service, which we will provide to you when you visit our online shop for the first time and for the future.
5.1 Necessary cookies
Thanks to technically necessary cookies, our online shop works optimally. They enable essential basic functions such as navigation on the website or correct display in your Internet browser and therefore cannot be deactivated. This serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests in the optimal presentation of our offer pursuant to Art. 6 (1) (f) GDPR.
Usercentrics Consent Management Platform
The necessary Consent Management Service is provided by Usercentrics GmbH, Rosental 4, 80331 München, Germany, who process your data on our behalf. When our website is visited, the web server of Usercentrics GmbH stores a so-called server log file, which also contains your anonymised IP address, date and time of the visit, device and browser information as well as information on your consent behaviour.
Google Tag Manager
We use the Google Tag Manager to manage the services regarding usage-based advertising. The Tag Manager itself is a domain without any cookies and does not collect any personal data.
Google reCAPTCHA
The Google reCAPTCHA function serves for abuse prevention. The service checks whether the data entered on a website originate from a human being or from an automated program.
Adobe Fonts
Adobe Fonts is a font service by Adobe Systems Software Ireland Limited. It provides access to a font library and enables us to load appropriate fonts. Adobe uses the information from websites using Adobe Fonts to provide the “Adobe Fonts” service and to diagnose delivery or download problems
Google Fonts
When you visit our website, the browser establishes a connection to the Google servers while loading. In this process, your browser transfers various information to enable uniform display of the website. The font files will be stored on the used terminal device for one year. This improves the loading times of the websites on which Google fonts are used.
ONLINEPRINTERS cookies
In order to make communication between our online shop and you more comfortable, we store application data (IDs and flags) in the local cache of your browser. For example, the browser remembers whether a visitor has already set specific cookies. Thus, the respective cookie window will not be opened again every time you revisit the website.
Websale cookies
The cookies of our hosting provider Websale are technically necessary cookies which contribute to our website working optimally. The cookies enable essential basic functions such as navigation, registration or shopping cart control, but also protective functions against potential attacks. Our hosting provider is WEBSALE AG, Gutenstetter Straße 2, 90449 Nürnberg, Germany.
5.2 Service cookies
The service cookies enable us to improve the user friendliness of our online shop. With your consent in accordance with Art. 6 (1) (a) GDPR, we will use these cookies to present our products and contents in such a way to you that your visit to our website turns into a pleasant shopping experience.
Userlike chat tool
The Userlike chat tool can be used as an alternative to the contact form to chat live with our Customer Service if you have any questions about our offer. For this purpose, a chat widget in the form of source code will be loaded to and executed on your terminal device to enable the chat. This is provided by Userlike UG, Probsteigasse 44-46, 50670 Cologne, Germany (www.userlike.com).
5.3 Statistics cookies
Pseudonymised information helps us to tailor our offer even better to your needs. With your consent in accordance with Art. 6 (1) (a) GDPR, we will use statistics cookies which analyse how often specific functions of our website are used. They also help us to understand what content and products on our website are of particular interest to you.
Google (Universal) Analytics
Google (Universal) Analytics is a web analytics service which helps to better understand the use of the website by the visitors in order to develop optimisation strategies from that. The thus gathered usage information for this website will be transferred to Google and stored there. By activating IP anonymisation on this website, the IP address will be shortened before transfer within the EU member states or other EEA states. Only in exceptional cases will the full IP address be transferred to a Google server and shortened there.
Google (Universal) Analytics is integrated as a sub-processor by our partner Trakken Web Services GmbH who takes action within the scope of processing on our behalf in accordance with Art. 28 GDPR.
Google Ads Conversion
We use the online marketing service Google Ads Conversion to place ads in the Google advertising network. For performance measurement, Google provides us with an individual “conversion cookie”, with the help of which statistics are compiled. However, we are only informed of the total number of users that clicked on our ad and were redirected to a specific site with a conversion tracking tag. We do not receive any personal data that would allow us to draw conclusions about the user.
Bing Ads Conversion
We use the online marketing service Bing Ads Conversion to place ads in Bing, Yahoo and MSN search results and on third-party websites. For performance measurement, Microsoft provides us with an individual “conversion cookie”, with the help of which statistics are compiled. However, we are only informed of the total number of users that clicked on our ad and were redirected to a specific site with a conversion tracking tag. We do not receive any personal data that would allow us to draw conclusions about the user.
Hotjar
Hotjar is a web analytics service for performance measurement of advertising campaigns which serves to develop optimisation strategies. The thus gathered usage information for this website will be transferred to Hotjar. Then, pseudonymised usage profiles will be generated, which will not be merged with personal data, however, unless separate explicit consent has been given. After the purpose has ceased to exist and we have ended using Hotjar, the data collected in this context will be erased. This is an offer by Hotjar Limited, 3, Elia Zammit Street, St Julians STJ 3155, Malta, Europe (www.hotjar.com).
Google Optimize
Google Optimize is a service for website optimisation and analysis. It allows us to compare the use of different design options of elements of our website in order to optimise our online shops and increase visitor satisfaction based on these insights.
Microsoft Clarity
Microsoft Clarity is a tool that shows us how users use our website. It helps us to identify possible improvements to offer our customers an ideal shopping experience. As Clarity sets great store by data protection and privacy, we do not have any information about individual users.
5.4 Marketing cookies
With your consent in accordance with Art. 6 (1) (a) GDPR, our marketing cookies will ensure that not too many ads are shown on our partners’ websites, but only those products from our offer you could be particularly interested in.
Google Ads Remarketing and Google Analytics Advertising
We use these services to advertise our website in the Google search results and on third-party websites. For this purpose, the Remarketing cookie is set and/or the Google Analytics cookie is used when this website is visited. In this case, both cookies allow automatic interest-based advertising by means of a pseudonymous cookie ID and on the basis of the sites you have visited. After the purpose has been fulfilled and we have ended using Google Dynamic Remarketing and Google Analytics, the data collected in this context will be erased.
Data processing extending beyond this will only take place if you have consented towards Google that your web and app browser history is connected with your Google account and information from your Google account is used to personalise ads that you see on the web. In this case, if you are logged in to Google when visiting our website, Google will use your data together with Google Analytics data to generate and define target group lists for cross-device remarketing. For this purpose, your personal data will be temporarily linked with Google Analytics data to generate target groups.
Bing Ads Remarketing
We use Bing Ads to advertise our website in the Bing, Yahoo, and MSN search results and on third-party websites. For this purpose, a cookie is set when this website is visited that automatically allows interest-based advertising by means of a pseudonymous cookie ID and on the basis of the sites you have visited. After the purpose has ceased to exist and we have ended using Bing Ads, the data collected in this context will be erased.
AWIN
AWIN is a German affiliate network. We use so-called affiliate advertising to provide sales partners with our ads for their websites. The purpose of the cookie – which does not store any personal data – is to enable assessment of commission payments between us and our partners. This is provided by AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany (www.awin.com).
The LinkedIn Insight Tag is an analysis and tracking tool. We use this tool only if you are forwarded to our website via our LinkedIn ad. When you visit our website, a cookie that collects your IP address, device and browser properties will be set with your consent only. LinkedIn does not share any personal data about its members with our website. All data related to the visitors and ads are pseudonymised summaries only (URL of origin, number of visitors, visit duration, actions taken on our websites). These data will be deleted within 180 days. We use these data to analyse the use of our website after clicking an ad and to deduce improvements for our advertising measures so that we can present relevant contents.
6. Social Media
Our presence on social networks and platforms serves for better, active communication with our customers and prospective clients as well as to inform about our products and campaigns. You need to actively register with the respective network yourself. ONLINEPRINTERS does not forward any personal or usage-based data to these providers. In our online shop, we only place a hyperlink to our pages on the social media networks.
If you granted the respective social media operator your consent in accordance with Art. 6 (1) (a) GDPR, your data will be automatically collected and stored for market research and advertising purposes when you visit these pages, from which usage profiles will be generated by using pseudonyms. These can be used, for example, to place ads inside and outside the platforms that presumably correspond to your interests. Usually, cookies are used for this. For detailed information on the processing and use of the data by the respective social media operator as well as contact information and your relevant rights and setting options to protect your privacy, please refer to the respective privacy policy linked below. If the relevant provider is based in a third country, our cooperation will be based on standard data protection clauses adopted by the EU Commission. Data processing within the scope of a visit to our respective presence is carried out on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR.
Facebook is provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Facebook Ireland”). The information on your use of our online presence on Facebook automatically gathered by Facebook Ireland will usually be transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. Further information and privacy policy: https://en-gb.facebook.com/privacy/explanation
Twitter is provided by Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (“Twitter”). The information on your use of our online presence on Twitter gathered automatically by Twitter will usually be transferred to a server of Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, and stored there. Further information and privacy policy: https://twitter.com/en/privacy
Instagram is provided by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Facebook Ireland”). The information on your use of our online presence on Instagram gathered automatically by Facebook Ireland will usually be transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. Further information and privacy policy: https://help.instagram.com/519522125107875
Google YouTube
YouTube is provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information on your use of our online presence on YouTube gathered automatically by Google will usually be transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there. Further information and privacy policy: https://policies.google.com/privacy?hl=en-GB
LinkedIn is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information on your use of our online presence on LinkedIn gathered automatically by LinkedIn will usually be transferred to a server of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA, and stored there. Further information and privacy policy: https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
Xing is a professional network. Xing is provided by New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. Further information and privacy policy: https://privacy.xing.com/en/privacy-policy
7. Your rights
Being the data subject, you have the following rights:- In accordance with Art. 15 GDPR you have the right to obtain access to your personal data processed by us to the extent specified there;
- in accordance with Art. 16 GDPR you have the right to obtain without undue delay the rectification of inaccurate personal data or completion of incomplete personal data stored by us;
- in accordance with Art. 17 GDPR you have the right to erasure of your personal data stored by us, unless further processing is required
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation;
- for reasons of public interest; or
- for the establishment, exercise, or defence of legal claims;
- in accordance with Art. 18 GDPR you have the right to request restriction of processing of your personal data if
- you contest the accuracy of the personal data;
- the processing is unlawful but you oppose their erasure;
- we no longer require the data but you require them for the establishment, exercise, or defence of legal claims; or
- you have objected to processing in accordance with Art. 21 GDPR;
- in accordance with Art. 20 GDPR you have the right to receive the personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request transmission to another controller;
- in accordance with Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority. Usually you may approach the supervisory authority at your habitual residence or place of work or company domicile.
Right to object
Insofar as we process personal data as explained above to safeguard our – within the frame of balancing of interests – overriding legitimate interests, you may object to this processing with effect for the future. If the processing takes place for the purpose of direct marketing, you may exercise this right at any time as described above. If the processing takes place for other purposes, you only have a right to object on grounds related to your particular situation.After you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise, or defence of legal claims. This does not apply if the processing takes place for the purpose of direct marketing. In this case, we will no longer process your personal data for this purpose.
8. Contact Data Protection Officer
If you have any questions regarding the collection, processing, or use of your personal data, for information, rectification, restriction of processing, or erasure of data, revocation of given consents, or objection to specific use of data, please contact our company Data Protection Officer (DPO):
ONLINEPRINTERS GmbH
Andreas Neuer
Dr.-Mack-Straße 83
90762 Fürth
Germany
2023-08-17