Privacy Policy
1. General
1.1 Definition: Personal data
Personal data is information that reveals or may reveal the identity of the user. We adhere to the principle of data avoidance. The collection of personal data is avoided as far as possible.
This Privacy Policy describes how your personal information is collected, used, and shared when you visit or make a purchase from https://www.hess-sound.de (the "Site"). In this Privacy Policy, "personal information" refers to both device information and order information.
1.2 Handling of personal data
When you buy something or try to buy something on the website, we collect certain information about you. This includes your name, billing address, shipping address, payment information (including credit card numbers), email address, and phone number. We refer to this information as "Order Information."
Personal data is used exclusively for the justification of the contract, the content design of the contract and for the execution or processing of the contractual relationship (Art. 6 I S. 1 b GDPR) or your order with us. In addition, personal data will only be processed if we have received your consent to do so (Art. 6 I S. 1 a GDPR). These data will generally not be passed on to third parties, unless this is essential for the fulfillment of the contract.
1.3 Data exchange or contractual relationships with partners
Hess Sound GmbH & Co. KG shares your data (including for processing your payment information, preparing for shipping, and sending invoices and/or order confirmations) with third parties who are involved in processing your order or providing support for orders. For example, we use Shopify to run our online store. You can find more information about how Shopify uses your personal data here: https://www.shopify.com/legal/privacy.
Data is also passed on to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of your ordered goods. For the processing of payments, the payment data required for this purpose is also passed on to the credit institution commissioned with the payment and, if applicable, to the commissioned and selected payment service provider.
In principle, data will only be passed on if it is required to fulfill your order, deliver it, or process an inquiry.
In addition, we use this order information to communicate with you, to check our orders for potential risks or fraud, and to provide you with information or advertising related to our products or services, in accordance with your privacy settings.
Finally, we may also share your personal information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
1.4 Usage data
When you visit our website, general technical information is collected, such as the IP address used, time, duration of the visit, browser type, and, if applicable, the referring page. This usage data is technically registered in a log file and may be used and stored for the purpose of statistical analysis of this website. This usage data is not linked to your other personal data.
1.5 Registration data
To fully use the functions of our website, registration is required. The registration data is collected through your corresponding entries and used for the specifically stated purpose in accordance with your consent (Art. 6 I S. 1 a GDPR).
1.6 Duration of storage
After the end of the purpose for which your personal data was originally collected, we will only store it for as long as this is necessary due to legal (in particular tax law) regulations.
1.7 Do Not Track
Please note that we do not change our website's data collection and usage practices when we receive a "Do Not Track" signal from your browser.
2. Your rights
2.1 Information
If you are based in Europe, you have the right to access the personal data we hold about you and to request its correction, update or deletion. If you would like to exercise this right, please contact us using the contact details below. Please note that your data will also be transferred outside of Europe, namely to the United States.
You can request information from us about whether we are processing personal data from you, and if this is the case, you have a right to information about this personal data and to the further information mentioned in Art. 15 GDPR.
2.2 Right to rectification
You have the right to correct any incorrect personal data concerning you and, in accordance with Art. 16 GDPR, you can request the completion of incomplete personal data.
2.3 Right to erasure
You have the right to request that we delete your personal data immediately. We are obliged to delete this data immediately, especially if one of the following reasons applies:
-
Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
-
You withdraw your consent on which the processing of your data was based, and there is no other legal basis for the processing.
-
Your data has been processed unlawfully.
The right to erasure does not exist if your personal data is required to assert, exercise, or defend our legal claims.
2.4 Right to restriction of processing
You have the right to request that we restrict the processing of your personal data if
-
You dispute the accuracy of the data, and we are therefore verifying the accuracy,
-
The processing is unlawful, and you refuse the deletion and instead request the restriction of use
-
We no longer need the data, but you need it to assert, exercise, or defend legal claims,
-
You have objected to the processing of your data and it is not yet clear whether our legitimate reasons outweigh your reasons.
2.5 Right to data portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, common, and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided that the processing is based on consent or a contract and the processing is carried out by us using automated procedures.
2.6 Right of revocation
If the processing of your personal data is based on consent, you have the right to revoke this consent at any time.
2.7 General and right of appeal
The exercise of your above rights is fundamentally free of charge for you. You have the right to contact the supervisory authority responsible for us, the State Data Protection Officer, directly with complaints.
3. Data security
3.1 Data Security
All data on our website is protected against loss, destruction, access, modification, and distribution through technical and organizational measures.
3.2 Sessions and Cookies
We may use cookies or server-side sessions to operate our website, which can store data. Cookies are files that a website places on your hard drive to automatically recognize your computer on your next visit and to customize the use of the website for you. Some of the cookies used are deleted after the end of the browser session. These are so-called session cookies. Other cookies remain on your device and enable the recognition of the browser on a later visit to our website (persistent cookies). You can set your browser to inform you about the setting of cookies and decide individually whether to accept them or to exclude the acceptance of cookies for specific cases or in general. Please note that you may not be able to use some functions of this website if cookies are deactivated. We ensure that no personal data is transferred from sessions or through cookies and that cookies are only used if this is technically necessary for the website. Thus, the consideration results in that there are no overriding interests on your part to the contrary (Art. 6 I S. 1 f GDPR).
4. Newsletter
If you subscribe to our newsletter, we will use the data required for this purpose or separately provided by you to send you our email newsletter regularly. It is possible to unsubscribe from the newsletter at any time, either by sending us a message via the contact options stated in the legal notice or via the link provided for this purpose in the newsletter.
5. Comments
If you use the comment function on our website, the time of creation, your chosen pseudonym and, temporarily, your IP address will also be saved in addition to these comments. This is done so that we can protect our rights in the event of illegal content.
6. Services from Third-Party Providers
When you visit the website, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies installed on your device. As you browse the website, we also collect information about the individual web pages or products you view, the websites or search terms that led you to the website, and information about how you interact with the website. We refer to this automatically collected information as "Device Information."
We collect device information using the following third-party technologies:
-
Cookiebot (Consent Management)
Data transfer from domain before consent: cookiebot.com
https://www.cookiebot.com/de/privacy-policy/ -
Shopify (shop system, shopping cart functionality, payment processing, login)
Data transfer from domains before Consent: shopify.com, shopifysvc.com
https://www.shopify.com/legal/privacy -
Shop (Shopify's own marketplace platform; payment transfer)
Data transfer from domain before Consent: shop.app
https://www.shopify.com/legal/privacy/app-users -
Paypal (payment function)
https://www.paypal.com/uk/legalhub/paypal/privacy-full -
Weglot (Translations into other languages)
Data transfer from domain weglot.com
https://www.weglot.com/privacy -
Elfsight (Social Share Buttons)
https://elfsight.com/privacy-policy/ -
Instafeed (Instagram image gallery on homepage)
https://www.instafeed.co.uk/privacy-policy/ -
FlipHtml5 (Page catalogue)
https://fliphtml5.com/de/privacy-policy.php -
Meta Platforms Pixel (Analytics/Tracking, Targeting, Marketing)
https://www.facebook.com/privacy/policy/ -
Google Analytics (Analytics/Tracking, Targeting, Marketing)
https://business.safety.google/privacy/ -
Youtube (Embedding of videos)
https://business.safety.google/privacy/ -
Mailchimp (Newsletter)
https://mailchimp.com/de/gdpr -
BSS B2B Solution (Pricing: B2B prices and various discounts)
https://bsscommerce.com/shopify/privacy-policies/ -
Trusted Shops (reviews)
https://www.trustedshops.com/de/legal/datenschutz
We use the device information we collect to check for potential risks and fraud (in particular, your IP address) and to generally improve and optimize our website (e.g., by using analytics on how our customers navigate and interact with the website, and to assess the success of our marketing and advertising campaigns).
6.1 Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google, operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”), and collects and stores data via this web analytics service from which user profiles are created using pseudonyms. The user profiles created in this way are used to evaluate visitor behavior in order to design and improve the offer presented on this website in line with requirements. Google Analytics uses so-called “Cookies”, small text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. However, if IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area beforehand. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The usage profiles managed under a pseudonym will also not be merged with the personal data about the user without the user's express and separately declared consent. Thus, the balancing shows that there are no overriding interests on your part to the contrary (Art. 6 I S. 1 f GDPR). You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available under the following link (http://tools.google.com/dlpage/gaoptout?hl=de).
You can view Google's privacy policy at http://www.google.de/intl/de/policies/privacy/. Further information on the terms of use and data protection can be found at http://www.google.com/analytics/terms/de.html or at http://www.google.com/intl/de/analytics/privacyoverview.html. We would like to point out that on this website Google Analytics has been extended by the code “anonymizeIp“ in order to ensure anonymized collection of IP addresses (so-called IP masking).
6.2 Social Media Links
We have our own social media pages with the third-party providers that can be reached via links from this website. By using the links, you will be taken to the respective websites of the third-party providers (e.g. Facebook, Twitter, Google+). As soon as you have accessed the page of the third-party provider, you are in the area of responsibility of the respective third-party provider, so that their data protection declaration or their declarations on data use also apply. We have no influence on this, but we recommend that you log out of the respective third-party provider before using a corresponding link in order to avoid unnecessary data transfer, so that user profiles cannot be created by the third-party provider simply by using the link.
6.3 Google Web Fonts
We also use web fonts from Google to display a uniform font on our website. These are automatically stored in your browser cache when you visit one of our pages to enable the desired display. If your browser does not support the web fonts used, a standard font from your computer may be used. Here, no interests of the users are affected which outweigh this technical necessity (Art. 6 I S. 1 f GDPR). You can view Google's privacy policy here: https://www.google.com/policies/privacy/ You can find more information about Google Web Fonts at https://developers.google.com/fonts/faq
6.4 Data Protection in Connection with Re-Targeting
Our website uses re-targeting technologies that are implemented using the Facebook pixel and Facebook's advertising manager.
We use these technologies to make our website more interesting for you. This technology makes it possible to target internet users who have already shown interest in our products with advertising on the websites of our partners, such as Facebook. We are convinced that the display of personalized, interest-based advertising is generally more interesting for the internet user than advertising that has no such personal relevance. The display of these advertisements on our partners' pages is based on a cookie technology and an analysis of previous usage behavior. This form of advertising is completely anonymous. No personal data is stored and no user profiles are merged with your personal data.
You can give your consent to this function via opt-in in the data protection notice that is displayed when you first visit our website. You can revoke your consent at any time via the following option:
7. Changes
We may change this privacy policy from time to time to reflect changes to our practices or for other operational, legal or regulatory reasons.
8. Contact
8.1 Name and address of the person responsible for the website
The responsible party within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is:
Hess Sound GmbH & Co. KG
Uenzer Dorfstrasse 71
27305 Bruchhausen-Vilsen
Germany
Walsrode District Court HRA 205108
VAT identification number: DE363299697
Tax number 4620406405
Complementary:
Hess Sound Beteiligungs-GmbH
Management: Jana Hess, Tjalf Hoyer
Walsrode District Court HRB 211254
Tax number 4620406421
Tel: +49 (0) 4252-2411
Fax: +49 (0) 4252-3436
E-Mail: [email protected]
8.2 Name and address of the data protection officer
The data protection officer of the responsible party is:
D & C Datenschutz und Consulting
Belemannweg 15
22419 Hamburg
https://www.dundc.org/
E-Mail: [email protected]