Privacy policy 

finkid GmbH (finkid) attaches great importance to the protection of your personal data and your right to informational self-determination. finkid processes your data exclusively in accordance with the principles described below and in compliance with the statutory regulations, in particular the EU General Data Protection Regulation (DSGVO) and the German Federal Data Protection Act (BDSG). With this data protection declaration, we inform you about how we process personal data when you use the finkid website in the case of

•    orders placed in our online store (see section 2)
•    the use of our website (see section 3)
•    applying for a job (see section 4.)
•    provision of your contact data (see clause 5.)
•    participation in competitions (see section 6.)
•    visiting our Facebook fan page (Facebook Insight data) and posting (section 7.).

1. Your personal data
Personal data are individual details about personal or factual circumstances that are suitable for establishing a relationship to your person. This includes, for example, your name, your telephone number and your postal and e-mail addresses.

2. Orders in the online store
If you order in our online store, we process your personal data to fulfill contractual obligations.

a) Use of your personal data for the acceptance and processing of an order

finkid uses your personal data that you provide during the actual purchase process on the website, in particular your name (first and last name), your address, your telephone number, your e-mail address, your credit card number, your date of birth and your bank account details, as far as this is necessary for the processing and billing of your order.

In order to use your order, finkid will transmit your personal data to a logistics provider used by finkid, who will process these data on behalf of finkid and in compliance with these data protection provisions and the required security measures.

b) Use of your personal data for the collection of outstanding debts
finkid shall use your personal data, which we have collected and stored for the acceptance and processing of your order, furthermore for the collection of outstanding debts. For this purpose, we commission a debt collection company to which we transmit the necessary data and have it processed in compliance with these data protection provisions and the necessary security measures.

c) Credit assessment at SCHUFA or other companies

finkid transmits certain information that you have provided to us during the ordering process to carefully selected service providers that check your creditworthiness. The information provided to these companies includes your first and last name, mailing address, date of birth, and credit card information. These service providers check for the presence of negative features about your creditworthiness and determine your "score value". A "score value" predicts the risks of possible payment defaults on the basis of already known empirical values through a statistical procedure. Currently, these service providers are SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden, the company Creditreform Rosenheim Karl KG, Oberaustraße 14, 83026 Rosenheim and the company CEG Consumer Reporting GmbH, Hellersbergstr. 11, 41460 Neuss.

Irrespective of this, finkid will also transmit data to the aforementioned companies due to non-contractual behavior, insofar as this is permissible after weighing all affected interests. These companies store and transmit the data to their contractual partners in the EU internal market in order to provide them with information to assess the creditworthiness of natural persons. You can obtain information from SCHUFA or the other companies about the data stored concerning you. Further information about the SCHUFA information and score procedure is contained in a leaflet which is available on request from the SCHUFA contract partner (at www.meineschufa.de/score).

3. data processing to enable website use
When you visit our website, we collect the data necessary to enable you to use it (usage data). This includes your IP address and data about the beginning, end and subject of your use of the website as well as, if applicable, data for identification (e.g. your login data if you log into a secure area). This data is used to provide the service and to design it to meet your needs. They are generally deleted as soon as they are no longer required and there are no retention obligations. For the processing of pseudonymous user profiles, see point d) We process this data for the provision and needs-based design of this website in our legitimate interest (Art. 6 para. 1 lit. f DSGVO). If you would like detailed information on the balance of interests, please contact one of the addresses listed under item 14.

a) Newsletter and e-mail advertising
If you would like to receive our newsletter and register for it, we collect your e-mail address and send you a confirmation e-mail with a confirmation link that you must click to subscribe to our newsletter. In addition, if you purchase goods or services from us, we will add you to our mailing list in order to send you e-mail advertising for our own similar goods or services, unless you have objected to this use of your e-mail address. You can unsubscribe from the newsletter at any time and object to the e-mail advertising at any time. You will find an option for declaring your objection in every newsletter and every other advertising e-mail that we send you.

b) Cookie banner: consent to cookies and pseudonymous profiling
When you visit our website, information may be stored on your terminal device in the form of cookies. A cookie is a small text file that is sent to your browser by a web server and stored on your terminal device. When you visit our website again, cookie data is again transmitted to our web server. This allows us, for example, to recognize you and take your individual settings into account when displaying the website. Cookies can be divided into first-party cookies (used by finkid) and third-party cookies (used by third parties). We further categorize cookies as follows:

 

Type:   

Description:

Category 1:
Technical
necessary cookies

These cookies are mandatory to ensure the technical functionality of the website (e.g. enabling the shopping cart function or login during a session, etc.). Without these cookies, we cannot properly offer use of the website.

Category 2:
Functional cookies

These cookies are used to design the most pleasant browsing experience possible on our website, with the highest level of individual usage conformity (e.g. enabling cross-session login, high browsing speed through search suggestions, or storing individual page settings such as the language or text size, etc.).

Category 3:
Performance cookies

 

These cookies are used for the continuous optimization of our website and lead to a continuously improved browsing experience (e.g. through the usage evaluation of offered website functions, the reporting of display errors, etc.).

Category 4:
Social network and advertising cookies.

One part of these cookies gives you the ability to connect to your social networks and thus share content. The other part helps to better personalize advertising for you by customizing it to your interests through information collection.

 

 

Cookies of categories 2 to 4 can be used in the context of web analytics and then helps to analyze web traffic. They can be combined with other information about your activities on our website and are processed in pseudonymized usage profiles. This helps us analyze web traffic and improve our website to adapt it to users' needs. We only use this information for statistical analysis. In addition to cookie-based web analytics, there is non-cookie-based web analytics using other means, such as your individual device settings, to recognize you when you revisit our website.

 

The legal basis for the use of category 1 cookies is our legitimate interest in providing our website according to Art. 6 para. 1 lit. f DSGVO. The legal basis for the use of category 2 to 4 cookies and web analytics is your consent according to Art. 6 para. 1 lit. a DSGVO. When you visit our website for the first time or as well as on revisits, if applicable, we will (i) inform you about the use of cookies of categories 2 to 4 and web analytics and (ii) ask for your consent. To indicate your consent, we will display a banner to that effect. If you click on "Agree" or simply continue browsing, you declare your consent. If you click on "Decline", cookies of categories 2 to 4 will not be stored. You can also limit consent in whole or in part by configuring your browser settings and disabling cookies in whole or in part. In addition, you can install a browser plugin. Plugins offer the possibility to prevent web analytics - e.g. AdBlock, Ghostery. NoScript or uBlock Origin (please refer to the privacy information of the respective plugin provider).

In addition, some web analytics providers are members of industry associations whose websites allow you to centrally prevent the use of web analytics. Below you will find a reference to the websites of these associations to explain your choice regarding web analytics and data processing in pseudonymous profiles.

•    "European Interactive Digital Advertising Alliance (EDAA): http://www.youronlinechoices.com/de/praferenzmanagement/
•    "Digital Advertising Alliance" (DAA): www.aboutads.info/choices/
•    "Network Advertising Initiative" (NAI): http://www.networkadvertising.org/choices/

If you do not declare your consent to the use of cookies or delete cookies from your terminal device, this may affect your ability to use the website or individual functionalities. 

c) Pseudonymous usage profiles for advertising and market research (web tracking and analysis)

For advertising, market research and to make your use of our website as pleasant as possible, finkid uses web tracking systems. Data about the use of our website is stored in pseudonymous user profiles (your IP address is anonymized). This allows us to further develop our website and to tailor the content even better to your needs.

The pseudonymous user profiles are not merged with personal data. Before we process your data for the purposes mentioned in this section, we obtain your consent (see b) and categories 2 to 4 cookies).

The following table lists the web analysis technologies used on our website and the respective providers that process usage data in pseudonymous profiles for the purposes stated in each case. In addition, the link to the provider's privacy policy is given and an explanation of how you can specifically prevent web tracking by the individual service providers with effect from the time the action is taken. As a rule, an "anti-tracking cookie" is then stored on your terminal device, which excludes the collection of usage data from your terminal device by the respective provider for the future. Please note that if you delete the cookies from your end device, you may have to set the "anti-tracking cookie" again.

Tool/Provider

Purpose

Link to the provider's privacy policy / Prevent processing.

Google Analytics: Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Web analytics, interest-based advertising

https://www.google.de/intl/de/policies/

 

Preventing processing: Via browser plugin (see add-on) and further information under section 4.3.1.

Google Double-Click, Google AdWords Conversion, Google Dynamic Remarketing: Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Web analysis, interest-based advertising

https://www.google.de/intl/de/policies/

 

Prevent processing: Google's Ads Preferences Manager and for more information see section 4.3.2.

Facebook Exchange (FBX) / Facebook Custom Audience: Facebook, 1601 S. California Avenue, Palo Alto, 94304 CA, USA.

 

Web analysis, interest-based advertising

https://www.facebook.com/privacy/explanation

Further information on data protection

 

Preventing processing: Via anti-tracking cookie (see privacy policy).

 

 

 

d) Google Analytics

This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (Google). Google Analytics uses cookies (see item 6.) to enable an analysis of your use of the website. The information generated by the cookie about your use of the website will be transmitted to and stored by Google on servers in the United States. However, your IP address will be truncated beforehand by Google within Member States of the European Union or in other contracting states to the Agreement on the European Economic Area and thus anonymized. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

 

You can prevent the storage of cookies by selecting the appropriate settings on your browser software) or a privacy plugin (see b)). You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link  (http://tools.google.com/dlpage/gaoptout?hl=de). Alternatively, you can prevent the collection by Google Analytics by setting a so-called "anti-tracking cookie" on your computer; use the following link for this purpose: Set anti-tracking cookie

 

e) Google Double- Click (including Floodlight and Spotlight), Google AdWords Conversion, Google Dynamic Remarketing

We also use Google Analytics to evaluate data from the Google services AdWords and DoubleClick for statistical purposes. This allows us to analyze what happens after a user clicks on our ad, e.g. whether the user bought our product or called up the ad from a cell phone, in order to improve our offers. Furthermore, you will receive interest-based advertising by means of these services. 

 

Your consent is required for this (see b)). If you do not wish to do so, you can, in addition to the variant described in point b), also prevent this via Google's Ads Preferences Manager: http://www.google.com/settings/ads/onweb/?hl=de.

DoubleClick sets a cookie on your computer to record your surfing behavior on various websites (tracking) and to play out interest-based advertising. If you do not wish to do this permanently, you can download a plug-in at the following link to prevent the DoubleClick cookie: https://www.google.com/settings/u/0/ads/plugin?hl=de

f) Facebook Exchange (FBX); Facebook Custom Audience.
Our website contains tracking technology from Facebook, 1601 S. California Avenue, Palo Alto, 94304 CA, United States ("Facebook"). This may include cookies (see section b) Facebook collects and stores usage data in pseudonymous profiles for the purpose of web analysis or to enable interest-based advertising. 

g) Google Tag Manager
This website uses Google Tag Manager to manage website tags. A tag is a JavaScript snippet that is used to send information from a website to third parties, in particular as part of web tracking. The Google Tag Manager tool itself does not collect any personal data. The tool takes care of triggering other tags, which in turn may collect data (e.g., the Google Analytics tag). Google Tag Manager does not access this data. If a deactivation has been made at the domain or cookie level, it will remain in place for all tracking tags implemented with Google Tag Manager. This makes it easier to effectively implement your objections to tracking methods.

h) Social networks 


Our website contains links to social networks (e.g. Facebook). These social networks are operated exclusively by third parties. If you follow the links, information may be transmitted to these third parties. We use the so-called 2-click solution. This means that when you visit our site, no personal data is transmitted as a matter of principle. Only if you click on one of the social share buttons / plugins, data will be transmitted to the respective provider.

 

By activating the social share button, the respective social network receives the information that your browser has accessed the corresponding page of our website, even if you do not have an account with this provider or are not currently logged in to this provider. This information is then transmitted by your browser to a server of the provider and processed there. If you are logged in to this provider, the provider can assign your visit to our website directly to your account with this social network. If you interact with the Share Dialog window (e.g. submit a comment), the corresponding information is also transmitted directly to a server of the social network. The information will also be published on the social network's site and displayed to your contacts. If you do not want the social network to assign the data collected on our website to your user account, you must log out of the provider before activating the plug-in for the first time.

 

For the purpose and scope of the data collection and the further processing and use of the data by the social network, as well as your rights in this regard and setting options for protecting your privacy, please refer to the privacy policy of the respective provider, which can be found here: 

Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA

http://www.facebook.com/policy.php/

4. Application for a job
We process your personal data within the application process.

a. Legal basis
§ 26 Abs. 1, Abs. 8 S. 2 BDSG oder § 26 Abs. 2, Abs. 8 S. 2 BDSG.

b. Purpose and necessity of the processing of personal data.

We process your personal data for the purpose of contacting you and assessing your suitability for the position for which you are applying.

It is not possible to apply to finkid without providing personal data. You are neither obliged to apply at finkid nor to provide personal data. If you do not provide us with personal data, we may not be able to consider your application. Otherwise there will be no consequences for you.

5. Provision of your contact data
In the follow-up to trade fairs or other events, we process the personal data you provide to us, e.g. by handing over your business card or entering it in a contact form. We also process your personal data if you contact us via other communication channels (e-mail or similar).

a. Legal basis
Art. 6 para. 1 lit. b or f DSGVO - depending on the object of providing your personal data or contacting you.

b. Purpose and necessity of the processing of personal data.

We process your personal data when you provide us with your contact details by entering them in a form or by handing us a business card. Your information will be stored so that we can refer to it in case we need to contact you.

Our legitimate interest is to provide you with information about finkid and our services and to communicate with you.

If you would like detailed information on the balance of interests, please contact one of the addresses listed in section 14.

6. Participation in competitions
We process your personal data if you participate in one of our competitions (on postcards or flyers).

a. Legal basis
Art. 6 Abs. 1 lit. a DSGVO.

b. Purpose and necessity of the processing of personal data.

Your information will be stored for the purpose of participating in the competition and for possible contact with you so that we can inform you about your possible win.

You can revoke your consent to the processing of your personal data at any time. To do so, please contact us by e-mail, by telephone or by letter to the persons mentioned under item 14.

7. Visiting the Facebook fan page (Facebook Insight data).
When you visit or interact with our Facebook fan page, your personal data (e.g. "Like" information) is processed as described in this section.

a. Shared responsibility
Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland, ("Facebook") provides us, as the service provider of our Facebook Fan Page, with statistics and information to help us understand what types of actions people take on our Page ("Page Insights"). In this case, Facebook and finkid are jointly responsible for data processing ("joint data controllers").

b. Legal basis
Art. 6 Abs. 1 lit. f DSGVO.

c. Purposes and necessity of the processing of personal data.
We use information that you provide to us via your Facebook profile or by visiting our Fanpage via your browser to provide the functionalities of our Fanpage. This may include checking the reach of our posts, defining our audience more precisely, tailoring ads to our audience, and shaping our Facebook Fan Page to the actual interests of our visitors. We process this data in our legitimate interest to maintain all the features of our Fan Page, to check our reach, and to design and display our Fan Page in accordance with our interests. If you would like more information about the balance of interests, please contact one of the addresses listed in section 14.

d. Further information about our joint responsibilities with Facebook

In order to transparently and explicitly define the responsibilities for compliance with the obligations under the GDPR between finkid and Facebook, we have entered into an agreement with Facebook stating that Facebook is primarily responsible for data processing in connection with visits to our Fanpage. In particular, Facebook assures you that it is responsible for exercising your rights under Articles 12 and 13 of the GDPR, Articles 15 to 22 of the GDPR and compliance with Articles 32 to 34 of the GDPR.

However, you may at any time address your request to us regarding data processing in connection with our Fanpage or assert your rights against us (for more information on your rights, see section 12). To the extent necessary to carry out your request or exercise your rights, we will forward your matter to Facebook.

For more information about Insight data and how to exercise your rights, please see Facebook's information: https://www.facebook.com/legal/terms/information_about_page_insights_data
Weitere Informationen über die Festlegung der Verantwortlichkeiten innerhalb der gemeinsamen Verantwortlichkeit im Sinne von Art. 26 DSGVO, finden Sie in der Vereinbarung mit Facebook: https://www.facebook.com/legal/terms/page_controller_addendum

For more information about the determination of responsibilities within the joint responsibility in the sense of Art. 26 DSGVO, please refer to the agreement with Facebook: https://www.facebook.com/policies/cookies/
For more information about protecting your privacy on Facebook, please see Facebook's privacy policy: https://www.facebook.com/privacy/explanation.

8. Transmission to third parties
We only pass on the personal data described here insofar as this is necessary for the provision of our service or is legally required in this context. Within the scope of the purposes stated here, personal data is forwarded to service providers who work for us and in particular support us in the provision of services. In addition to their legal obligation to comply with all data protection regulations, these service providers are bound by further contractual data protection requirements. This includes, in particular, an obligation as a processor in accordance with Art. 28 DSGVO. In particular, we share personal data with the following categories of service providers:
•    Accounting, financial institutions, tax and legal advice,
•    IT service and infrastructure,
•    IT support and maintenance,
•    data destruction and facility services,
•    in addition to the categories already mentioned, other categories of service providers may exist or be added at any time.

9. Data transfer to countries outside the EU
As far as necessary for our purposes, we may also transfer your data to recipients outside the EU. This is particularly the case if we have to transfer this data to recipients in countries within the scope of contract processing or due to legal regulations. Otherwise, we only transfer data to third countries if it is ensured that the recipient of the data has implemented an adequate level of data protection within the meaning of Article 45 of the GDPR or appropriate safeguards within the meaning of Article 46 (2) and (3) of the GDPR and no other interests worthy of protection speak against the transfer of data. We use to ensure an adequate level of protection at the recipient of the data, unless there is an adequacy decision within the meaning of Art. 45 (1) DSGVO by the EU Commission, in particular the standard contractual clauses of the EU Commission for the transfer of personal data to third countries (processor to processor; processor to processor transfer). In particular, we share personal data with the following categories of service providers:

•    IT service and infrastructure,
•    IT support and maintenance,
•    web analytics,
•    intra-group order processing and data transfer,

•    in addition to the categories already mentioned, other categories of service providers may exist or be added at any time.

10. Deletion
We delete your personal data as soon as they are no longer necessary for the previously named purposes of processing, in the case of an objection no compelling reasons worthy of protection by finkid are opposed or in the case of a revocation no other legal basis for the processing exists. In certain cases, e.g. if there is a legal obligation to retain data, your personal data will initially be blocked and deleted upon expiry of the retention period.

11. Data security

finkid has taken the necessary technical and organizational measures to protect the personal data you have provided against loss, destruction, manipulation and unauthorized access. Our employees and all persons involved in data processing are obliged to comply with data protection laws and to handle personal data confidentially. Our employees are trained accordingly. Both internal and external audits ensure compliance with all data protection-relevant processes at finkid.

To protect the personal data of our users, we use a secure online transmission method, the so-called "Secure Socket Layer" (SSL) transmission. You can recognize this by the fact that an "s" is appended to the address component http:// ("https://") or a green, closed lock symbol is displayed. By clicking on the symbol, you will receive information about the SSL certificate used. The display of the symbol depends on the browser version you are using. SSL encryption ensures the encrypted and complete transmission of your data.

12. Your rights regarding personal data
As a data subject, you have the following rights:

•    A right to confirmation as to whether personal data relating to you is being processed by finkid and, if so, the right to information about this personal data (Art. 15 DSGVO) as well as
•    a right to have your incorrect data corrected (Art. 16 DSGVO),
•    a right to deletion (Art. 17 DSGVO) or
•    a right to restriction (blocking) of your data (Art. 18 DSGVO).

In addition, in the case of processing based on Art. 6(1)(e) or (f) DSGVO, you may object to the processing (Art. 21 DSGVO), in which case, except in the case of direct marketing, you must provide a specific reason. If you have provided the data, you may request the transfer of the data (Art. 20 DSGVO). Whether and to what extent these rights exist in individual cases and under what conditions they apply is specified by law in the designated standards. If the processing is based on consent within the meaning of Art. 6(1)(a) or Art. 9(2)(a) DSGVO, you may revoke this consent at any time for the future (Art. 7(3) DSGVO). You also have the right to contact the competent data protection supervisory authority (Art. 77 DSGVO).

If you have questions or complaints about data protection at finkid, we recommend that you first contact our data protection officer (see the contact details under section 14).

13. No automated individual decision
Unless this is exceptionally necessary for the conclusion of a contract or permitted by law (as in the case of age verification), we do not use your personal data for automated individual decisions within the meaning of Article 22 (1) DSGVO..

14. How can you contact us?

You can find our contact details as the responsible party in the imprint.

If you would like to exercise your rights mentioned in section 24 or if you have any questions about data protection at our company or about this data protection declaration, you can also contact our data protection officer:

Dr. Bernd Schmidt, PLANIT // LEGAL, Neuer Wall 54, 20354 Hamburg, mail@planit.legal

15. Modification of the data protection statement
New legal requirements, business decisions or technical developments may require changes to our data protection statement. The privacy policy will then be adapted accordingly. You will always find the most current version on our website.

Stand: September 2019