Privacy policy
Privacy Policy
1. General Information
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required. You are not obliged to provide your data. Failure to provide it has no consequences, unless otherwise stated for individual processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.
2. Server Log Files
You can visit our website without providing personal information.
Each time you access our site, data is automatically transmitted by your internet browser to us or our hosting service provider and stored in so-called server log files.
The data recorded includes, for example, the name of the page accessed, date and time of access, IP address, amount of data transferred, and the requesting provider.
Processing takes place on the basis of Art. 6 (1) (f) GDPR, due to our legitimate interest in ensuring the smooth operation of the website and optimizing our services.
3. Controller
Responsible for data processing:
Steven Kmiec
Mathiasstraße 66
50189 Elsdorf, Germany
Phone: +49 (0)2274 939908
Email: love@wimspa.com
4. Contact
If you contact us via email or a contact form, we process your personal data (name, email address, message) only to the extent necessary to handle your inquiry.
Data processing is carried out in accordance with Art. 6 (1) (b) GDPR, if it serves to initiate or fulfill a contract, or according to Art. 6 (1) (f) GDPR, due to our legitimate interest in effective communication.
Your data will be deleted after the request has been fully processed, unless statutory retention obligations apply.
5. Orders
To process orders, we process your personal data only as necessary to fulfill the contract (Art. 6 (1) (b) GDPR).
Your data is shared with shipping providers, payment processors, and technical service providers only to the extent required for contract fulfillment.
No further data will be shared without your explicit consent.
6. Inventory Management System
We use an external inventory management system as part of order processing.
Recipient of data:
easybill GmbH, Düsselstraße 21, 41654 Kaarst, Germany.
7. Payment Service Providers
PayPal:
All transactions are subject to PayPal’s privacy policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Klarna Checkout:
Provider: Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden.
Klarna uses cookies to make the checkout process user-friendly (Art. 6 (1) (a) GDPR).
Details about the cookies used:
https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_at/checkout.pdf
8. Cookies
Our website uses cookies.
Cookies are small text files stored on your device that enable your browser to be recognized.
You can configure your browser to allow or block cookies. Deactivating cookies may limit website functionality.
Information on cookie management:
-
Chrome
-
Firefox
-
Safari
We use technically necessary cookies based on Art. 6 (1) (f) GDPR to ensure the secure and functional operation of our website.
9. Analytics & Marketing Tools
Google Analytics
We use Google Analytics (Google Ireland Limited, Gordon House, Dublin 4, Ireland).
Data processing serves to analyze user behavior for website optimization.
IP address, browser, location, and device data may be processed.
Your IP address is anonymized (IP anonymization).
Processing is based on Art. 6 (1) (f) GDPR due to our legitimate interest in a user-oriented website design.
You can prevent data collection via this browser add-on:
https://tools.google.com/dlpage/gaoptout?hl=en
Facebook Pixel
We use the Facebook Pixel from Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland, to target visitors with interest-based ads on Facebook.
Processing is based on Art. 6 (1) (f) GDPR due to our legitimate interest in targeted marketing.
More information:
https://www.facebook.com/about/privacy
Google Ads Conversion Tracking
We use Google Ads Conversion Tracking (Google Ireland Limited, Dublin 4, Ireland) to measure ad performance.
Cookies are used but do not personally identify users.
Processing occurs under Art. 6 (1) (f) GDPR based on our legitimate interest in effective advertising.
Details:
https://www.google.de/policies/privacy/
10. Security & Spam Protection
We use Google reCAPTCHA (Google Ireland Limited, Dublin 4, Ireland) to distinguish between human and automated inputs.
Processing is based on Art. 6 (1) (f) GDPR out of our legitimate interest in protecting our website from abuse.
More information:
https://www.google.com/privacy
11. Rights of Data Subjects
Under the GDPR, you have the following rights:
-
Right of access (Art. 15)
-
Right to rectification (Art. 16)
-
Right to erasure (Art. 17)
-
Right to restriction of processing (Art. 18)
-
Right to data portability (Art. 20)
-
Right to object (Art. 21 GDPR)
12. Data Retention Period
After complete contract fulfillment, personal data will be stored in compliance with legal retention periods and then deleted, unless further consent has been given.
13. Right to Lodge a Complaint
According to Art. 77 GDPR, you have the right to lodge a complaint with the competent data protection authority if you believe your data is being processed unlawfully.