0

Data Protection Declaration

Data protection

Website data protection declaration, plus information on the data subjects according to Articles 13 and 14 of the EU General Data Protection Regulation

General details

Details of the responsible entity
Company: ICB innovative cosmetic bands GmbH
Legal representatives: Helmut Baurecht, Matthias Baurecht, Stefan Neumeyer
Address: Gaußstraße 13, 85757 Karlsfeld
Tel.: 0049 8131 390 – 05
Email: online@anny-cosmetics.com

Contact details of data protection officer: datenschutz@artdeco.com

General data processing information

Relevant data: Personal data is only collected if you provide it to us of your own accord. No personal data beyond this scope will be collected. Any processing of your personal data that goes beyond the scope of the legal permissions will only be carried out on the basis of your express consent.

Purpose of processing: Contractual implementation.

Categories of recipient: Public bodies in the event of overriding legal provisions. External service providers or other contractors.
Other external bodies insofar as the data subject has given his/her consent or transmission is permissible for overriding interests.

Third country transfers: Within the permissible scope of the contractual implementation, processors outside the European Union may also be used.

Duration of data storage: The duration of the data storage depends on the legal storage obligations and is usually ten years.

Specific details of the website

Use of own “cookies” required for the website display

This website uses its own “cookies” to store settings required for website viewing (“cookies” are records sent by the web server to the user’s browser and stored there for later retrieval). No personal data is stored in our own “cookies”. You can generally prevent the use of “cookies” if you prohibit the storage of “cookies” in your browser.

The use of YouTube videos with the consent of website visitors

This website uses YouTube Video, a video player service provided by Google Ireland Limited (“Google”), based on the consent of website visitors. When you visit a page with an embedded video, a connection to Google’s servers is established and the content is displayed on the website by notifying your browser (Data subject: including: Device information, IP address, Referrer URL, Videos viewed.). If you are logged in to Google at the same time, this information will be assigned to your member account at YouTube. You can prevent this by logging out of your member account before visiting our website. The information generated by the cookie about your use of this website will also be transmitted to and stored by Google on servers in the United States. Information on what data is processed by Google and for what purposes can be found in the Google privacy policy:
https://policies.google.com/privacy?hl=de&gl=de#infocollect

The use of Hotjar with the consent of website visitors

This website uses Hotjar, a web analytics service provided by Hotjar Limited (Hotjar), based on the consent of website visitors. Hotjar will use cookies to collect data about user behavior and may also process information provided by you as part of surveys and feedback features embedded on our website. The information generated by the cookie about your use of this website may also be transmitted to a server in the U.S. and stored there. Information about what data is processed by Hotjar and for what purposes it is used can be found in Hotjar’s privacy policy: https://www.hotjar.com/legal/policies/privacy

Contact via the website

The website of ICB innovative cosmetic bands GmbH contains information that enables a quick electronic contact to our enterprise, as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address).
As part of customer communication, we collect personal data to process your inquiries in accordance with Art. 6 para. 1 sentence 1 lit. b GDPR if you voluntarily provide us with this data when contacting us (e.g. via contact form or e-mail). Mandatory fields are marked as such, as in these cases we absolutely need the data to process your contact. Which data is collected can be seen from the respective input forms.
We use the Gorgias tool from Gorgias Inc, San Francisco, CA, 34 Harriet St, San Francisco, USA, to process your inquiries from various channels (contact form, chat, email) quickly and efficiently.
When using Gorgias, the following personal data is collected and processed: Customer’s e-mail address, information about the customer’s order(s), information about previous interactions of the customer with our customer support. This data is used exclusively for the purpose of processing customer inquiries and improving our customer support. 

The data is stored and analyzed on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in communicating with customers and interested parties as easily as possible. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.
Gorgias is Privacy Shield certified as a US provider and thus undertakes to comply with EU data protection law. In addition, we have concluded a data processing agreement (DPA) with Gorgias. This ensures that Gorgias only uses the user data within the framework of EU data protection standards exclusively for processing the requests and does not pass them on to third parties. This data is not passed on to third parties unless this is necessary to fulfill our contractual obligations or we are legally obliged to do so.
If you do not agree to us processing your inquiry via Gorgias, you can alternatively communicate with us by telephone. You can find the data in the legal notice.
Further information can be found in Gorgias’ privacy policy at https://www.gorgias.com/privacy

Information on further data processing procedures

Specific information about the application process

Relevant data: Application details

Purpose of processing: Implementation application procedure.
Categories of recipient: Public bodies in the event of overriding legal provisions. External service providers or other contractors, e.g. for data processing and hosting. Other external bodies, subject to the data subject having already given his/her consent or where transmission is permissible for reasons of overriding interest, including customers and interested parties in the context of order acquisition.

Third country transfers: Within the permissible scope of the contractual implementation, processors outside the European Union may also be used.

Duration of data storage: Application data is generally deleted within four months of notification of the decision, unless consent has been given for data to be stored for a longer period in the context of inclusion in the applicant pool.

Specific information on the processing of customer/prospect data

Relevant data: Data provided for the performance of the contract and, where applicable, any additional data for processing on the basis of your express consent.

Purpose of processing: Contract execution, including quotations, orders, sales and invoicing, quality assurance.

Categories of recipient: Public bodies in the case of overriding legal provisions

External service providers or other contractors, including for data processing and hosting, shipping, transport and logistics, service providers for printing and mailing information. Other external bodies, subject to the data subject having already given his/her consent or where transmission is permissible for reasons of overriding interest, including the electrical transmission of information or quality assurance purposes.

Third country transfers: Within the permissible scope of the contractual implementation, processors outside the European Union may also be used.

Duration of data storage: The duration of the data storage depends on the legal storage obligations and is usually ten years.

Specific information on the processing of employee data

Relevant data: Data provided for the performance of the contract and, where applicable, any additional data for processing on the basis of your express consent.

Purpose of processing: Contract implementation within the scope of the employment relationship.

Categories of recipient: Public authorities in the case of overriding legal regulations, e.g. tax office, social insurance agency, employers’ liability insurance association. External service providers or other contractors, including for data processing and hosting, payroll accounting, travel expense accounting, insurance services and vehicle use. Other external bodies insofar as the data subject has given his/her consent or transmission is permissible for overriding interests, including order acquisition, insurance benefits.

Third country transfers: Within the permissible scope of the contractual implementation, processors outside the European Union may also be used.

Duration of data storage: The duration of the data storage depends on the legal storage obligations and is usually ten years.

Specific information on the processing of supplier data

Relevant data: Data provided for the performance of the contract and, where applicable, any additional data for processing on the basis of your express consent.

Purpose of processing: Contract execution, including inquiries, purchasing, quality assurance.

Categories of recipient: Public authorities in the case of overriding legal provisions, e.g. tax office, customs authorities. External service providers or other contractors, e.g. for data processing and hosting, accounting, payment processing. Other external bodies insofar as the data subject has given his/her consent or transmission is permissible for overriding interests.

Third country transfers: Within the permissible scope of the contractual implementation, processors outside the European Union may also be used.

Duration of data storage: The duration of the data storage depends on the legal storage obligations and is usually ten years.

Specific details of the use of the video conferencing/webinar software

Relevant data: Data provided for the use of the video conferencing software or the webinar software (esp. first name, last name, email address; optionally: Audio transmission; optional: Image transmission; optional: Questions when using chat functions); to the extent technically required, processing of data from your system to establish the connection with the provider of the conferencing software.

Purpose of processing: Conducting video conferences or webinars.

Categories of recipient: Public bodies in the event of overriding legal provisions. External service providers or other contractors, e.g. for data processing and hosting. Other external bodies insofar as the data subject has given his/her consent or transmission is permissible for overriding interests.

Third country transfers: Processors outside the European Union are used (here: United States of America); standard contractual clauses have been concluded with the service provider accordingly.

Duration of data storage: Video conferences are only recorded with the previously documented consent of the participants. The technical data is deleted if it is no longer required. The duration of the data storage is dictated by legal storage obligations and is usually ten years.

Further information and contacts

In addition, you may, at any time, exercise your rights to access, correct or erase said data, restrict processing or exercise your right to object to processing thereof, as well as exercise the right to data portability. We provide details below on how to contact us via email or postal mail. You are also entitled to contact the data protection supervisory authority in the event of complaints.

Version current as of December 2024