Skip to content

Privacy policy

Privacy Information for the Online Shop of Wonster GmbH

1. NAME AND ADDRESS OF THE CONTROLLER

We, Wonster GmbH, are the data protection controller within the meaning of Art. 4 No. 7 of the General Data Protection Regulation (GDPR) for our online store ('Online-Shop') and the associated data processing. Our contact details are:

Wonster GmbH
Obstplantage 26
14547 Beelitz

Phone No. 030 232 560 80

Email Address: mail@wonster.de

2. PROVISION OF THE ONLINE SHOP

2.1 Description and scope of data processing

Each time the online shop is accessed, our system, i.e. the web server, automatically collects information from your computer or end device system.

The following data are collected by us:

  • Information about the browser type and version used,
  • the operating system of the end device,
  • the Internet service provider,
  • the IP address,
  • date and time of access,
  • the previous website from which you accessed our online shop.

2.2 Purpose of data processing

The collection of your IP address by our system is necessary to enable you to use our online shop. For this purpose, we must necessarily store your IP address for the duration of the session. The storage of your data in log files is carried out to ensure the functionality of the online shop. Furthermore, these data serve us to optimize the online shop and to ensure the security of our information technology systems (e.g., for attack detection).

2.3 Legal basis for data processing

The legal basis for the storage of these data is Art. 6 para. 1 lit. f) GDPR (balancing of interests). Our legitimate interest is the provision of a functional online shop.

2.4 Duration of storage

The data mentioned above will be deleted as soon as they are no longer required for the purpose of their collection. In the case of data collection for the provision of the online shop, this is the case when the respective session has ended. Log files will be deleted after a maximum of seven days. Storage beyond this period is possible. In this case, we will delete or anonymize your IP address so that it is no longer possible to assign the calling client, and the data contained will no longer have any personal reference.

3. EMAIL CONTACT AND CONTACT FORM

3.1 Description and scope of data processing

You can contact us via our contact form and the provided email address. In this case, we process your personal data transmitted with the request.

3.2 Purpose of data processing

The processing of personal data from the contact form or email is solely for the purpose of handling the contact and communication with you.

3.3 Legal basis for data processing

The legal basis for processing your personal data in the context of your contact is Art. 6 para. 1 lit. f) GDPR (balancing of interests). Our legitimate interest is the communication of our company with you as the inquirer. If the request is aimed at concluding a contract, then Art. 6 para. 1 lit. b) GDPR (performance of a contract or pre-contractual measures) is the legal basis for the associated data processing.

3.4 Duration of storage

The data mentioned above will be deleted as soon as they are no longer required for the purpose of their collection. We delete your personal data that you have sent us via email or through the contact form when your request has been finally answered.

4. NEWSLETTER

4.1 Description and scope of data processing

There is the possibility to subscribe to a newsletter on our online shop. When registering for the newsletter, the data you provide in the input mask, among other things, is transmitted to us.

4.2 Purpose of data processing

This data processing is used to deliver the newsletter to you.

4.3 Legal basis for data processing

The legal basis for processing your data is your consent according to Art. 6 para. 1 lit. a) GDPR.

4.4 Duration of storage

The data will be deleted as soon as they are no longer required for the purpose of their collection. Your email address is stored as long as your newsletter subscription is active.

4.5 Unsubscribing from the newsletter

The subscription to the newsletter can be cancelled by the affected user at any time. For this purpose, there is a corresponding link in every newsletter.

5. USE OF COOKIES

5.1 Description and scope of data processing

Our online shop uses cookies. Cookies are text files that are stored in your internet browser, for example. This text file contains a characteristic string of characters that allows us and third parties to uniquely identify the browser during a session and when you revisit the online shop. Our online shop uses technically necessary cookies as well as analysis and reach measurement cookies.

5.2 Purpose of data processing

Use of technically necessary cookies: The purpose of using technically necessary cookies is the functional provision of our online shop. For some functions of our online shop, it is necessary that your browser is recognized even after a page change.

Use of analysis and reach measurement cookies: The use of analysis and reach measurement cookies is for the purpose of continuously improving the user-friendliness of our online shop.

5.3 Legal basis for data processing

Use of technically necessary cookies: The legal basis for processing your personal data using technically necessary cookies is Art. 6 para. 1 lit. f) GDPR. Our legitimate interest is the provision of a functional online shop.

Use of analysis and reach measurement cookies: The legal basis for processing your personal data using cookies for analysis and reach measurement purposes is your consent according to Art. 6 para. 1 lit. a) GDPR or a balancing of interests according to Art. 6 para. 1 lit. f) GDPR. Our legitimate interest is the user-friendly design of our online shop.

5.4 Objection and revocation possibility

You can control the use of cookies. By changing the settings in your internet browser, you can deactivate or limit the transfer of files through cookies. You can delete cookies that are already stored at any time. You can also set your internet browser to automate this deletion.

In addition to preventing the storage of cookies in your internet browser software, you can also prevent the collection of personal data generated by the cookie and related to your use of the website by clicking on the link in the table below and/or observing the information provided there. Depending on whether you have given consent for the setting of the cookie, you can thus revoke your consent or object to the setting of the cookie.

If cookies are deactivated for our online shop, it may no longer be possible to use all functions of the online shop to their full extent.

5.5 Cookies used

Designation Provider/Application

Purpose

Storage Duration

Opt-out / Revocation of Consent

Shopify

Provision of essential functions of the online shop

Dauer der Browser-Session

N/A

6. REGISTRATION AND USER ACCOUNT

6.1 Description and scope of data processing

We offer you the opportunity to register on our online shop and create a user account. For this, you must choose a login name (e.g., your email address) and a password. After registration, you can store further data in your user account, such as your name, address, and contact details.

6.2 Purpose of data processing

Registration and the user account serve the purpose of simplifying orders in our online shop.

6.3 Legal basis for data processing

The legal basis for processing the data is Art. 6 para. 1 lit. b) GDPR (performance of pre-contractual measures).

6.4 Duration of storage

Your above-mentioned data will be deleted as soon as they are no longer required for the purpose of their collection. This is generally the case for the data stored in your user account when you delete your user account. Even after the deletion of the user account, it may be necessary for us to store your personal data from the user account to comply with contractual or legal obligations (e.g., tax retention obligations).

Login log files to your user account are stored for security reasons and for support requests for seven days and then deleted.

6.5 Deletion of the user account

As a registered user, you have the option to delete your user account at any time. The data stored about you in the user account can be changed by you at any time in the user account.

7 PROVISIONS IN THE ONLINE SHOP

7.1 Description and scope of data processing

We process your personal data when you place orders for our products in our online shop. You can buy products in our online shop as a registered customer (see item 6) or as an unregistered guest.

7.2 Purpose of data processing

When executing an order, we process data about you (e.g., name and address) and the products you have purchased for the purpose of processing your order ("order data"). If you have registered with our webshop and created a user account, we add these order data to your user account so that you can track your orders even after the successful processing of the order.

As part of the order, we also collect payment data from you for the purpose of order processing. The payment data is transmitted to payment service providers as necessary for payment processing purposes.

7.3 Legal basis for data processing

The legal basis for this is Art. 6 para. 1 lit. b) GDPR (performance of pre-contractual measures and fulfillment of a contract).

7.4 Duration of storage

We store your order data and your payment data for as long as necessary for the execution of the order or the provision of these data in your user account or until the expiration of legal retention periods (e.g., tax retention obligations) and to preserve our product monitoring obligation as well as possible contractual warranty and guarantee rights. These periods are usually three to ten years.

8. PROCESSING FOR MARKETING PURPOSES

8.1 Description and scope of data processing

We process personal data that we collect about you according to the preceding paragraphs (e.g., order data) within the legally permissible framework for advertising and market research.

8.2 Purpose of data processing

The processing serves, for example, the purpose of understanding in which delivery areas which products are purchased or which products are typically ordered together in a purchase process. Furthermore, we process your personal data to be able to make you offers tailored to your interests.

8.3 Legal basis for data processing

We process your data for the aforementioned purposes either on the basis of a balancing of interests (Art. 6 para. 1 lit. f) GDPR) or on the basis of a consent given by you (Art. 6 para. 1 lit. a) GDPR). Our legitimate interests are the analysis of customer data for the purpose of improving our products and offers and conducting direct advertising.

8.4 Duration of storage

We store your personal data for the aforementioned purposes only as long as it is necessary for the purposes for which they are processed. We continuously delete your data after three years or immediately if you object to data processing for the purpose of direct marketing. If we process your data based on consent, we delete your data if you revoke your consent (and there is no other legal basis for processing).

9. RECIPIENTS OF THE DATA

For processing your personal data for the aforementioned purposes, we pass on your data to the following recipients:

Name of recipient

Purpose 

Country of residence

Shopify International Limited

Provision of webshop infrastructure

Ireland

10. RIGHTS OF THE DATA SUBJECT

When we process your personal data, you are a "data subject" within the meaning of the GDPR. You have the following rights against us:

10.1 Your general rights

You have the right to obtain information about the personal data we store about you (Art. 15 GDPR), the right to rectification (Art. 16 GDPR), to erasure (Art. 17 GDPR), and to restriction of processing of your personal data (Art. 18 GDPR). Furthermore, you are entitled to exercise your right to data portability (Art. 20 GDPR) and to object to the processing of your personal data (Art. 21 GDPR).

10.2 Right to revoke consent to data protection

You have the right to revoke your consent at any time. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent until the revocation (Art. 7 para. 3 GDPR).

10.3 Right to object

You have the right at any time to object to the processing of your personal data which is carried out pursuant to Art. 6 para. 1 lit. e) or f) GDPR. To the extent that we are no longer legally obliged or entitled to continue processing your personal data, we will no longer process your personal data (Art. 21 para. 1 GDPR).

If you object to the use of your data for direct marketing purposes, we will no longer process your personal data for this purpose following the objection (Art. 21 para. 2 GDPR).

10.4 Note on the right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data by us violates the GDPR.