Data protection
PRIVACY POLICY
1. GENERAL
We are delighted that you are interested in our company. Data protection is of paramount importance to us. In this privacy policy, we inform you about the data processing in our company – especially regarding our website and within the order process – insofar as this data processing also concerns your data.
If you would like an introduction to data protection and general information on the terms used in the General Data Protection Regulation, you can find this, for example, on the website of the Federal Commissioner for Data Protection, available at https://www.bfdi.bund.de/DE/Datenschutz/datenschutz-node.html.
2. INFORMATION ABOUT THE CONTROLLER
The controller for the processing of your personal data is doubleyou UG (haftungsbeschränkt), Dänenweg 38a, 22926 Ahrensburg. You can reach us for general inquiries by email at service.flairieur@gmail.com
3. ACTIVITIES INVOLVING THE PROCESSING OF PERSONAL DATA
3.1 Visiting our website without logging in
When you visit our website without logging in, registering, or otherwise filling out input fields on the website, we process your personal data as follows:
3.1.1 For the purpose of providing our website, we process the name of the accessed website, the accessed file, date and time of access, amount of data transferred, notification of successful retrieval, browser type and version, the user's operating system, referrer URL (the previously visited page) and IP address of all website visitors. The processing is technically necessary to enable the use of our website (Art. 6 para. 1 b GDPR). The data will be deleted after the end of your visit to our website, unless individual data continues to be processed for one of the stated purposes.
3.1.2 For the purpose of detecting and defending against attacks on our website and the technical infrastructure (e.g., hacking, denial-of-service attack), we process the IP addresses, [data categories] of all website visitors. The processing serves to fulfill our legal obligation to take protective measures (Art. 6 para. 1 c GDPR). The data will be deleted seven (7) days after the end of your visit to our website, unless an attack attempt is detected. In the event of a detected attack attempt from your connection, the data will be further processed for complete technical and, if necessary, legal analysis.
3.1.3 For the purpose of implementing the specific design of our website, fonts from MyFonts Inc. 600 Unicorn Park Drive, Woburn, MA 01801, USA are dynamically embedded. The IP addresses are transmitted in this process. This transmission is technically necessary to transfer the file containing the font from the third-party provider's server to the website user's device and thus to display our website correctly to the website user (Art. 6 para. 1 b GDPR). The data is not specifically stored for this purpose on our server. Further information on Myfonts' privacy policy can be found here: https://www.monotype.com/legal/privacy-policy/
3.2 VISITING OUR WEBSITE WITH REGISTRATION
3.2.1 You can register on our website by creating a user account. Registration allows you to complete the ordering process on our website faster and easier, save multiple shipping addresses, and view and track orders. During registration, we process your first and last name, your email address, and a password you choose. The processing serves the execution and fulfillment of the user agreement (Art. 6 para. 1 b GDPR). Your data will remain stored with us as long as your user account remains active. You have the option to delete your user account yourself. Unless we are legally obliged to retain the data, it will also be deleted.
3.2.2 In all other respects, the same data processing takes place as described under section 3.1.
3.3 ORDERING IN OUR ONLINE SHOP
3.3.1 When placing an order in our online shop, we collect the following data from the orderer: name, address, date of birth, phone number, gender, and email address. We need this data for the processing of the purchase contract, the shipment of goods, invoicing, and returns management. The processing of this data is necessary for the fulfillment of the purchase contract concluded via our online shop (Art. 6 para. 1 b GDPR). We delete this data as soon as it is no longer needed for the aforementioned purposes and there are no longer any legal retention obligations. In the latter case, we will not delete the data but will block it for any further processing.
3.3.2 We process your payment information for the purpose of payment processing when you purchase a product through our website. Depending on the payment method you choose, we may forward this payment information to third parties (e.g., to the credit card provider for credit card payments). The following payment methods can be selected as part of an order:
-
a) When paying via PayPal, credit card via PayPal, direct debit via PayPal, "purchase on account" or "installment payment" via PayPal, we transmit your payment data within the framework of payment processing to PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"). This data processing is necessary for the execution or fulfillment of the contract (Art. 6 para. 1 b GDPR). The data is only forwarded to the extent necessary for payment processing. PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 para. 1 lit. f GDPR on the basis of PayPal's legitimate interest in determining your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of payment default to decide on the provision of the respective payment method. The credit check may contain probability values (so-called score values). Insofar as score values are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, but not exclusively, are included in the calculation of the score values. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing. Further data protection information, including the credit agencies used, can be found in PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full -
c) When selecting payment by credit card, Apple Pay, or Google Pay, we use the payment service Shopify Payments. This is a service of Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. Your credit card data is collected and processed directly by Shopify Payments and is not stored by us. The transmission of your payment data only takes place insofar as it is necessary for payment processing. When choosing this payment method, this data processing is necessary for the performance or fulfillment of the contract (Art. 6 para. 1 b GDPR). The privacy policy of BS PAYONE GmbH can be found here: https://www.shopify.de/legal/datenschutz.
3.3.3 DATA TRANSFER TO THIRD PARTIES IN THE CONTEXT OF ORDER PROCESSING
In the context of order processing, we use the services of various partners to ensure proper order fulfillment and to provide you with advertising for other interesting products. We collaborate with the following partners:
- As a logistics service provider, we use the... . The... provides logistics services on our behalf. For this purpose, we transmit your name and recipient address, your email address, telephone number, customer reference number, the name of the invoice recipient, and the billing address to the... The... is contractually obliged to use this data only for the purpose described above and according to our instructions.
3.4 BACK IN STOCK NOTIFICATION
If one of our products is out of stock, you have the option to set up a reminder for that product. For this purpose, we provide a text field on the product page where you can enter your email address. As soon as the specific product is available again, we will send you an email with a corresponding notification to the email address provided. This data processing is necessary for the performance or fulfillment of the contract (Art. 6 para. 1 b GDPR). Your email address will be deleted after the reminder email has been sent.
3.5 Cookies
3.5.1 We use cookies on our website. Cookies are small text files. These allow us to specifically store information related to you, the user, that is connected to the use of our website. The cookies we use can be distinguished between technically necessary, technically non-necessary, and third-party cookies.
Technically necessary cookies are those that are absolutely essential for using all of our website. Without them, faultless use of our website cannot be guaranteed.
Non-technically necessary cookies are, for example, those that allow us to recognize you as a customer when you visit our site again. Then we can restore the settings you chose during your first visit to our site. Furthermore, these cookies help us analyze user behavior with regard to our webshop.
Third-party cookies record your visit to our website, other websites you have visited, and the links you have followed. We use this information to optimize our website and the advertising we target at you, and to tailor it to your interests.
- For the provision of our website and a personalized presentation of our website, we store technically necessary cookies on the end devices of website visitors. These cookies contain the following data: an identifier that serves as an identification feature to recognize several related requests from a user and assign them to a session, the accessed category of the website, language settings, and the content of the shopping cart. The processing is technically necessary to enable the use of our website (Art. 6 para. 1 b GDPR). All cookies are allowed, blocked, and deleted according to the settings stored in your web browser (e.g., when closing the browser window). If cookies are deactivated for our website, not all functions of the website may be fully usable.
- On our site, the third-party cookies listed below are set to tailor our online offering to your interests and with the aim that you only receive advertising for products that you are interested in.
4. WEB ANALYSIS AND WEB TRACKING
4.1 We use Facebook's "Custom Audiences" remarketing function. This service of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, enables us to target visitors to our website with advertising on Facebook. To enable this advertising, Facebook's remarketing pixel is integrated into our website. When the website is visited, a direct connection to the Facebook servers is established via this pixel. We transmit your IP address to Facebook. Facebook also learns which of our internet pages you have visited and can then assign interests to your personal Facebook user account. It is then possible to display individualized advertising to you in your Facebook network. This data processing is necessary to protect our overriding legitimate interest (Art. 6 para. 1 lit. f GDPR) to show visitors of our website only advertising for products that the user is interested in. Further information on the collection and use of data by Facebook can be found in Facebook's privacy policy at https://www.facebook.com/about/privacy/. If you do not want Facebook to directly assign the collected information to your Facebook user account, you can deactivate the "Custom Audiences" remarketing function. To do this, you must be logged in to Facebook.
4.2 We use the "conversion pixel" or visitor action pixel from Facebook. This is a service of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook"). By calling up this pixel from your browser, Facebook can subsequently recognize whether a Facebook advertisement was successful, e.g., led to an online purchase. We only receive statistical data from Facebook without reference to a specific person. This allows us to measure the effectiveness of Facebook ads for statistical and market research purposes. Especially if you are logged in to Facebook, we refer to their privacy policy at www.facebook.com/about/privacy/. This data processing is necessary to protect our overriding legitimate interest (Art. 6 para. 1 lit. f GDPR) to show visitors to our website only advertisements for products in which the user is also interested.
4.3 We use a Pinterest tag on our website. This is a technology from Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA ("Pinterest"). This tag is a pixel file integrated into our website that tells Pinterest which subpage of our website you have visited. This information is used on Pinterest to show you targeted advertisements on Pinterest. This data processing is necessary to protect our overriding legitimate interest (Art. 6 para. 1 lit. f GDPR) to show visitors of our website on Pinterest only advertisements for products that the user is also interested in.
5. SOCIAL PLUGINS ON OUR WEBSITE
Our website integrates the plugin of the social network Pinterest. This is a social network of Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA ("Pinterest"). The Pinterest plugin recognizes you by the "Pin It" button on our site. If you click the Pinterest "Pin It" button while logged into your Pinterest account, you can link the content of our pages to your Pinterest profile. This allows Pinterest to associate your visit to our pages with your user account. We point out that we have no knowledge of the content of the transmitted data or their use by Pinterest. This data processing is necessary to protect our overriding legitimate interest (Art. 6 para. 1 f GDPR) in optimizing the advertising of our website for users. Further information can be found in Pinterest's privacy policy: https://about.pinterest.com/de/privacy .
6. CONTACTING US
You can reach us through various communication channels:
6.1 If you contact us via our contact form, the data you provide will be processed and stored by us to answer the request and related questions. The processing of personal data from the input mask of the contact form serves solely for us to process the contact. The processing of the IP address during the sending process serves to prevent misuse of the contact form and to ensure the security of our information technology systems. When contacting us via our contact form, you must provide your first and last name and your email address. We need your name to assign the request when responding and to address you personally. We need the email address to send our response. Furthermore, you can voluntarily provide information that may help us answer the request, namely the order number, telephone number, your country of origin, and the subject of the contact request. The lawfulness of processing the data communicated to us via the contact form is based on Art. 6 para. 1 b GDPR. We will delete the data collected in this context once storage is no longer necessary or restrict processing if there are legal retention obligations.
6.2 For general processing of telephone inquiries and answering telephone customer inquiries, we process the name, first name, telephone number, customer number of the caller, other personal data communicated by the caller by telephone, and information on the content of the telephone inquiry. The processing is necessary for the performance or fulfillment of the contract (Art. 6 para. 1 b GDPR). Depending on the content of the respective request, processing will be restricted immediately after completion of the processing of the respective request to processing for the specific purpose of the respective request (e.g., use of our products by the customer, advertising our services as part of new customer acquisition). After fulfillment of the respective purpose and all legal, in particular commercial and tax law retention obligations, the data will be automatically deleted.
6.3 If you contact us via our presences on the social networks Facebook or Instagram, we process the personal data you have stored with the respective social network. The processing of your data is necessary to process the request (Art. 6 para. 1 b GDPR). After fulfillment of the respective purpose and all legal, in particular commercial and tax law retention obligations, the data will be automatically deleted.
7. NEWSLETTER
We offer a newsletter service on our website. If you wish to receive the newsletter offered on the website, you can order it via the designated field on our website. We will then send you a confirmation link by email, which you must click to activate the newsletter service. By clicking, you confirm that you are the owner of the specified email address and simultaneously declare that you agree to receive the newsletter. The data is processed exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your given consent to the storage of data, the email address, and their use for sending the newsletter at any time. The data you provide to us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted after unsubscribing from the newsletter. Data stored by us for other purposes (e.g., email addresses for the member area) remain unaffected. Unsubscribing from the newsletter is possible at any time and can be done either by a message to service@flairieur.com or via a designated link in the newsletter. After unsubscribing, we will delete your email address unless you have expressly consented to further use of the data or we reserve the right to further data use that is legally permitted and about which we inform you in this statement.
Newsletter delivery via Klaviyo
Our email newsletters are sent via the technical service provider "Klaviyo", 225 Franklin St, Boston, MA 02110, USA (http://www.klaviyo.com/), to whom we pass on the data you provided when registering for the newsletter. This transfer is made in accordance with Art. 6 para. 1 lit. f GDPR and serves our legitimate interest in using an effective, secure, and user-friendly newsletter system. Please note that your data is usually transferred to a Klaviyo server in the USA and stored there.
Klaviyo uses this information to send the newsletters on our behalf. Klaviyo does not use the data of our newsletter recipients to contact them themselves or to pass them on to third parties.
To protect your data in the USA, we have concluded a data processing agreement ("Data-Processing-Agreement") with Klaviyo, in which Klaviyo undertakes to protect the data of our users, to process it on our behalf in accordance with its data protection provisions, and in particular not to pass it on to third parties.
Klaviyo's data protection provisions can be viewed here: https://www.klaviyo.com/privacy
8. APPLICATION TO FLAIR.IEUR
If you would like to work at FLAIR.IEUR, you can submit an online application to us via the email address provided on our website. We will use the personal data you submit to us exclusively for processing your application. As part of the application process, we will forward your data to the relevant internal department to which the job description refers. Your data will not be used for other purposes unrelated to the application, and in particular, will not be transmitted to third-party companies. We process your data for the purpose of making a decision about the establishment of an employment relationship (§ 26 para. 1 BDSG 2018). After the application process is completed and the associated legal deadlines have expired, we will delete your application data. Further storage, for example for future vacancies, will only take place if you expressly consent to this storage in advance.
For applications by mail or using the LinkedIn career network, the same applies to data processing as for applications by email.
9. RIGHTS AS A DATA SUBJECT
9.1 Your rights against us can be asserted at any time by mail to our address mentioned in Section 2.1 above or by email to the email address mentioned in Section 2.2 above. Please understand that we do not process requests for personal data by telephone, as the identity of the caller cannot usually be established with sufficient certainty.
9.2 You have the following rights against us regarding the personal data concerning you:
9.2.1 You can assert your right to information (Art. 15 GDPR), right to rectification (Art. 16 GDPR), right to erasure (Art. 17 GDPR), and right to restriction of processing, i.e., blocking for certain purposes (Art. 18 GDPR), against us at any time if the respective legal requirements are met.
9.2.2 Your right to data portability (Art. 20 GDPR) also provides that, if the legal requirements are met, you can demand that we transmit the personal data concerning you to you – or, if technically feasible, to another controller designated by you – in a structured, common, and machine-readable format.
9.2.3 You have the right to object to processing (Art. 21 GDPR) for certain processing purposes, in particular for advertising purposes. Insofar as we process your data on the basis of a balancing of interests (in accordance with Art. 6 para. 1 f GDPR), you have the right to object to this processing at any time for reasons arising from your particular situation. Such reasons exist in particular if these give your interests particular weight and therefore outweigh our interests, for example, if we are not aware of these reasons and therefore could not be considered in the balancing of interests.
9.2.4 You have the right to withdraw any consent given to us for data processing at any time. The lawfulness of data processing operations carried out up to the withdrawal remains unaffected by the withdrawal.
9.3 You also have the right to contact the competent data protection supervisory authority if you have any questions or complaints regarding our processing of your personal data.
10. SECURITY OF YOUR DATA
10.1 We use appropriate and modern security measures to protect your data from loss, misuse, and alteration. Only authorized employees have access to personal data. We do everything in our power to prevent a violation of your rights or a risk to your personal data.
10.2 Please note that data transmission over the internet is not completely secure. We cannot guarantee the security of data entered on our website during transmission over the internet. This is done at your own risk.
11. CHANGES TO THIS PRIVACY POLICY
We reserve the right to change this privacy policy when updating our website or changing our data processing procedures. We therefore recommend that you regularly read our privacy policy to be aware of any changes. This privacy policy was last updated on 01.09.2021.