Privacy Policy
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor is it necessary for entering into a contract. You are not obligated to provide the data. Failure to provide it will have no consequences. This applies only insofar as no other information is provided in the following processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.
contact
Responsible
Please contact us if you wish. The data controller is: Eshteawy Ewida, Gartenstr. 36, 70563 Stuttgart , Germany, +49 711 99732471, chic.net.sales@gmail.com
Customer initiates contact via email
If you contact us proactively via email, we collect your personal data (name, email address, message text) only to the extent that you provide it. This data processing serves the purpose of processing and responding to your inquiry.
If the contact is for the purpose of carrying out pre-contractual measures (e.g., providing advice on purchase interest, preparing an offer) or relates to a contract already concluded between you and us, this data processing is based on Art. 6 para. 1 lit. b GDPR.
If you contact us for other reasons, this data processing is based on Article 6(1)(f) GDPR, due to our overriding legitimate interest in processing and responding to your inquiry. In this case, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR.
We will only use your email address to process your request. Your data will then be deleted in accordance with statutory retention periods, unless you have consented to further processing and use.
When you use the contact form, we collect your personal data (name, email address, message text) only to the extent that you provide it. The data is processed for the purpose of contacting you.
If the contact is for the purpose of carrying out pre-contractual measures (e.g., providing advice on purchase interest, preparing an offer) or relates to a contract already concluded between you and us, this data processing is based on Art. 6 para. 1 lit. b GDPR.
If you contact us for other reasons, this data processing is based on Article 6(1)(f) GDPR, due to our overriding legitimate interest in processing and responding to your inquiry. In this case, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR.
We will only use your email address to process your request. Your data will then be deleted in accordance with statutory retention periods, unless you have consented to further processing and use.
Collection and processing when images are sent via email
You have the option of sending us pictures via email in connection with ordering a personalized product.
By submitting your images, we may collect your personal data (images of identifiable individuals) only to the extent you provide it. This data processing serves the purpose of creating personalized products. The submitted image serves as a template for the product and is used for this purpose (e.g., T-shirt printing). This processing is based on Article 6(1)(b) GDPR and is necessary for the performance of a contract with you.
Your data will not be shared with third parties.
We will only use the image you sent us for the purpose of providing our services. Your data will then be deleted in accordance with statutory retention periods, unless you have consented to further processing and use.
Customer account Orders
Customer account
When you open a customer account, we collect your personal data to the extent specified there. This data processing serves the purpose of improving your shopping experience and simplifying order processing. The processing is based on Article 6(1)(a) GDPR with your consent. You can withdraw your consent at any time by notifying us, without affecting the lawfulness of the processing carried out based on the consent before its withdrawal. Your customer account will then be deleted.
Advertising
Use of the email address for sending direct marketing.
We use your email address, which we obtained in connection with the sale of goods or services, to send you electronic advertising for our own goods or services that are similar to those you have already purchased from us, unless you have objected to this use. Providing your email address is necessary for the conclusion of the contract. Failure to provide it will result in the contract not being concluded. This processing is based on Article 6(1)(f) GDPR, due to our overriding legitimate interest in direct marketing. You can object to this use of your email address at any time by notifying us. Our contact details for exercising your right to object can be found in the legal notice. You can also use the unsubscribe link provided in the advertising email. No costs other than standard transmission fees will be incurred.
Using Sendinblue
We use the service of Sendinblue GmbH (Köpenicker Straße 126, 10179 Berlin; “Sendinblue”) for sending newsletters as part of a data processing agreement.
We forward the information you provide during newsletter registration (email address, and optionally first and last name) to Sendinblue. This data processing serves the purpose of sending the newsletter and its statistical evaluation.
To evaluate newsletter campaigns, the email newsletters we send contain a 1x1 pixel graphic (tracking pixel) and/or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any embedded links. In this context, your personal data, such as your IP address, browser type and device, and the time you opened the newsletter, may also be collected. Usage profiles can be created from this data under a pseudonym. The collected data will not be used to personally identify you. It will only be used for statistical analysis to improve our newsletter campaigns.
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in a targeted, effective, and user-friendly newsletter system. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you.
Further information and SendinBlue's privacy policy can be found at: https://de.sendinblue.com/legal/privacypolicy/ .
Using Mailchimp
We use the service of Rocket Science Group LLC (675 Ponce de Leon Ave NE, Suite 5000 Atlanta, GA 30308, USA; “Mailchimp”) for sending newsletters as part of a data processing agreement.
We forward the information you provide during newsletter registration (email address, and optionally first and last name) to Mailchimp. This data processing serves the purpose of sending the newsletter and its statistical evaluation.
To evaluate newsletter campaigns, the newsletters we send contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any embedded links. In this context, we collect your personal data, such as your IP address, browser type and device, and the time of access. Usage profiles can be created from this data under a pseudonym. The collected data is not used to personally identify you. It is used solely for statistical analysis to improve our newsletter campaigns.
Your data is generally transferred to and stored on Mailchimp servers in the USA. The EU Commission has not issued an adequacy decision for the USA. The data transfer is based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de .
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in a targeted, effective, and user-friendly newsletter system. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you.
Further information and MailChimp's privacy policy can be found at: https://mailchimp.com/de/legal/data-processing-addendum/ and https://www.intuit.com/privacy/statement/ .
Using Klaviyo
We use the service of Klaviyo Inc. (125 Summer St Floor 7, Boston, MA 02111, USA; “Klaviyo”) for sending newsletters as part of a data processing agreement.
We forward the information you provide during newsletter registration (email address, and optionally first and last name) to Klaviyo. This data processing serves the purpose of sending the newsletter and its statistical evaluation.
To evaluate newsletter campaigns, the newsletters we send contain a 1x1 pixel graphic (tracking pixel) or a tracking link. This allows us to determine whether you have opened the newsletter and whether you have clicked on any embedded links. In this context, we collect your personal data, such as your IP address, browser type and device, and the time of access. Usage profiles can be created from this data under a pseudonym. The collected data is not used to personally identify you. It is used solely for statistical analysis to improve our newsletter campaigns.
Your data is generally transferred to and stored on Klaviyo servers in the USA. The EU Commission has not issued an adequacy decision for the USA. The data transfer is based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_de .
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in a targeted, effective, and user-friendly newsletter system. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you.
Further information on data protection at Klaviyo can be found at https://www.klaviyo.com/legal/privacy-notice and at https://www.klaviyo.com/legal/data-processing-agreement .
Inventory management
Use of an external merchandise management system
We use an enterprise resource planning (ERP) system for order processing. For this purpose, your personal data collected during the ordering process will be transferred to...
JTL-Software-GmbH, Rheinstr. 7, 41836 Hückelhoven
transmitted.
Payment service provider
- Sofort (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
- giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main
Further information on data processing when using PayPal can be found in the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full .
Cookies
Internet Explorer: https://support.microsoft.com/de-de/help/17442/windows-internet-explorer-delete-manage-cookies
analysis
Use of Google Analytics
We use the web analytics service Google Analytics from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The data processing serves the purpose of analyzing this website and its visitors, as well as for marketing and advertising purposes. To this end, Google, on behalf of the operator of this website, will use the information obtained to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website activity and internet usage to the website operator. The following information may be collected, among other things: IP address, date and time of the page view, click path, information about the browser and device you are using, pages visited, referrer URL (website from which you accessed our website), location data, and purchase activity. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Google Analytics uses technologies such as cookies, browser storage, and tracking pixels to analyze your use of the website. The information generated about your use of this website is generally transmitted to and stored on a Google server in the USA. The EU Commission has not issued an adequacy decision for the USA. Data transfers are based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks and https://business.safety.google/adsprocessorterms/ . Both Google and US government authorities have access to your data. Google may combine your data with other data, such as your search history, personal accounts, usage data from other devices, and any other data Google holds about you.
IP anonymization is activated on this website. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in designing the website to meet user needs and be targeted effectively. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you.
You can prevent Google Analytics from collecting and processing data (including your IP address) related to your use of the website by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
To prevent data collection and storage by Google Analytics across all devices, you can set an opt-out cookie. Opt-out cookies prevent the future collection of your data when you visit this website. You must perform the opt-out on all systems and devices you use for it to be fully effective. If you delete the opt-out cookie, requests will again be sent to Google. Click here to set the opt-out cookie: Disable Google Analytics .
Further information on terms of use and data protection can be found at https://www.google.com/analytics/terms/de.html , https://www.google.de/intl/de/policies/ , and https://policies.google.com/technologies/cookies?hl=de .
Use of Google Analytics 4
We use the web analytics service Google Analytics from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; “Google”) on our website.
The data processing serves the purpose of analyzing this website and its visitors, as well as for marketing and advertising purposes. To this end, Google, on behalf of the operator of this website, will use the information obtained to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website activity and internet usage to the website operator.
The following information may be collected, among other things: IP address, date and time of the page visit, click path, information about the browser and device you are using, pages visited, referrer URL (website from which you accessed our website), location data, and purchase activity. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
Google uses technologies such as cookies, browser storage, and tracking pixels to analyze your use of the website. The information generated about your use of this website is generally transmitted to and stored on a Google server in the USA. The EU Commission has not issued an adequacy decision for the USA. Data transfers are based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://policies.google.com/privacy/frameworks . Both Google and US government authorities have access to your data. Google may combine your data with other data, such as your search history, personal accounts, usage data from other devices, and any other data Google holds about you.
When using Google Analytics 4, the IP address transmitted by your website is automatically collected and processed in anonymized form. Google shortens the IP address within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before processing it.
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in designing the website to meet user needs and be targeted effectively. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you.
You can prevent Google Analytics from collecting and processing data (including your IP address) related to your use of the website by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
To prevent data collection and storage by Google Analytics across all devices, you can set an opt-out cookie. Opt-out cookies prevent the future collection of your data when you visit this website. You must perform the opt-out on all systems and devices you use for it to be fully effective. If you delete the opt-out cookie, requests will again be sent to Google. Click here to set the opt-out cookie: Disable Google Analytics .
Further information on terms of use and data protection can be found at https://policies.google.com/technologies/partner-sites and at https://policies.google.com/privacy?hl=de&gl=de .
Plug-ins and other
We use the Google Tag Manager from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google") on our website.
This application manages JavaScript and HTML tags used to implement tracking and analytics tools. The data processing serves the purpose of tailoring and optimizing our website to user needs.
The Google Tag Manager itself does not store cookies, nor does it process personal data. However, it enables the triggering of other tags that can collect and process personal data.
Further information on terms of use and data protection can be found here .
We use the single sign-on function (formerly Facebook Connect) of Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; “Facebook”) on our website.
Meta Platforms Ireland and we are jointly responsible for the collection of your data and its transfer to Facebook when you use this service. This is based on an agreement between us and Meta Platforms Ireland regarding the joint processing of personal data, which defines the respective responsibilities. The agreement can be accessed at https://www.facebook.com/legal/controller_addendum . Specifically, we are responsible for fulfilling the information obligations under Articles 13 and 14 of the GDPR, for complying with the security requirements of Article 32 of the GDPR with regard to the correct technical implementation and configuration of the service, and for complying with the obligations under Articles 33 and 34 of the GDPR insofar as a personal data breach affects our obligations under the joint processing agreement. Meta Platforms Ireland is responsible for enabling the data subject rights in accordance with Articles 15-20 GDPR, complying with the security requirements of Article 32 GDPR with regard to the security of the service, and fulfilling the obligations under Articles 33 and 34 GDPR insofar as a personal data breach affects Meta Platforms Ireland's obligations under the joint processing agreement.
This feature allows website visitors to log in to the website using their existing Facebook account. The data processing serves the purpose of verification during registration, personalization, and interest-based advertising.
To offer this feature on the website, a connection to the Facebook server is established. Cookies are used for this purpose. The following information, among other things, may be collected and transmitted to Facebook: IP address, browser information, referrer URL (website from which you accessed our website), and location data. This applies regardless of whether you are registered with or logged into the social network. Data is also transmitted for users who are not registered or logged in. If you are simultaneously connected to one or more of your social network accounts, the collected information can also be associated with your corresponding profiles. You can prevent this association by logging out of your social media accounts before visiting our website and before activating the buttons. Your data may be transferred to the USA. The EU Commission has not issued an adequacy decision for the USA. The data transfer is based, among other things, on standard contractual clauses as suitable safeguards for the protection of personal data, which can be viewed at: https://www.facebook.com/legal/EU_data_transfer_addendum .
When using the single sign-on function, the website visitor's Facebook profile is linked to a customer account for this website. In doing so, we receive personal data from Facebook, as specified during the login process. This may include, among other things, the following information: name, address, public profile information (e.g., name, profile picture, age, gender), email address, friend lists, and "likes".
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in designing the website to meet user needs and be targeted effectively. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you.
Further information on the collection and use of data by Facebook, your related rights and options for protecting your privacy can be found in Facebook's privacy policy at https://www.facebook.com/about/privacy/ .
We use the cloud service wao.io from Avenga Germany GmbH (Am Bahnhofsvorplatz 1, 50667 Cologne; "wao.io") on our website.
The data processing serves the purpose of optimizing the loading times and security of our website and thus making our offer more user-friendly.
The following information is collected and stored for 7 days in so-called server log files: pseudonymized IP address, system configuration information, and information about traffic to and from customer websites. Cookies are also used to display user behavior (reporting) and to analyze user behavior (analytics). Cookies can collect data including: pseudonymized IP address, browser type, internet service provider, URL of the previously visited website, the operating system you are using, and clickstream data. The data collected via cookies is not used to identify individual users.
Your data will be transferred to wao.io as part of a data processing agreement. Your data will not be shared with any other third parties. Data will not be transferred to third countries.
Your personal data is processed on the basis of Article 6(1)(f) GDPR, based on our overriding legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our services. You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR.
Further information on data protection when using wao.io can be found at https://wao.io/de/privacy .
Data subject rights and storage period
Storage duration
After complete contract fulfillment, the data will initially be stored for the duration of the warranty period, then taking into account legal, in particular tax and commercial law retention periods, and then deleted after the expiry of the period, unless you have consented to further processing and use.
Rights of the data subject
Provided the legal requirements are met, you have the following rights under Articles 15 to 20 GDPR: right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability.
Furthermore, pursuant to Article 21 Paragraph 1 GDPR, you have the right to object to processing based on Article 6 Paragraph 1 f GDPR, as well as to processing for direct marketing purposes.
Right to lodge a complaint with the supervisory authority
According to Article 77 of the GDPR, you have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data is unlawful.
You can lodge a complaint with the supervisory authority responsible for us, which you can reach using the following contact details:
State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Königstrasse 10 a
70173 Stuttgart
Tel.: +49 711 6155410
Fax: +49 711 61554115
Email: poststelle@lfdi.bwl.de
Right to object
If the processing of personal data listed here is based on our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR, you have the right to object to this processing at any time with effect for the future on grounds relating to your particular situation.
After an objection has been lodged, the processing of the data in question will cease, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of establishing, exercising or defending legal claims.
If your personal data is processed for direct marketing purposes, you can object to this processing at any time by notifying us. Upon receipt of your objection, we will cease processing the data in question for direct marketing purposes.
Last updated: November 29, 2022