Privacy Policy
Thank you for visiting the online presence of boy-katzennetze.de. This privacy policy serves to inform you in detail about the handling of your personal data.
General Information
Below you will find some initial and general information regarding data collection and data processing when visiting this online presence.
About this Privacy Policy
This privacy policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "data") when visiting this online presence. Terms such as "processing" or "controller" are used in the following information in accordance with the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
Responsible for this online presence is:
HF Boy Handelsgesellschaft mbH,
represented by the Managing Director, Mr Holger Boy
hereinafter referred to as: Boy Katzennetze
Von-Kurtzrock-Ring 16
22391 Hamburg, Germany
Phone: +49 (0) 40 226 129 76
Email: info@boy-katzennetze.de
Website: https://www.boy-katzennetze.de/en/
Definitions
This privacy policy is based on the definitions of the General Data Protection Regulation (GDPR). The individual definitions are listed in Art. 4 GDPR.
Within the meaning of the GDPR and this privacy policy, the term:
- "personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- "data subject" means any identified or identifiable natural person whose personal data is processed by the controller;
- "processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- "restriction of processing" means the marking of stored personal data with the aim of limiting their processing in the future;
- "profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
- "controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
- "recipient" means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
- "third party" means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
- "consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Legal Bases for Data Processing
If the legal basis for data processing is not explicitly mentioned further below in this privacy policy, the following applies: The legal basis for obtaining consent is Art. 6 (1) lit. a and Art. 7 GDPR.
The legal basis for processing to fulfill our services and perform contractual measures, as well as respond to inquiries, is Art. 6 (1) lit. b GDPR.
The legal basis for processing to fulfill our legal obligations is Art. 6 (1) lit. c GDPR. The legal basis for processing to safeguard our legitimate interests is Art. 6 (1) lit. f GDPR.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 (1) lit. d GDPR serves as the legal basis.
Cooperation with Processors and Third Parties
Insofar as this is necessary for the delivery of ordered goods, Boy Katzennetze will transmit your data to the shipping company commissioned with the delivery.
This data processing is carried out in accordance with Art. 6 (1) lit. b) GDPR for the fulfillment of the contract concluded with you.
If third parties are commissioned by Boy Katzennetze to process data, this is done on the basis of a data processing agreement in accordance with Art. 28 GDPR.
Collection and Storage of Server Data
Access data (server log files) is collected every time the server hosting this online presence is accessed.
Access data includes:
- Name of the accessed website
- File
- Date and time of access
- Amount of data transferred
- Notification of successful access
- Browser type and version, the user's operating system
- Referrer URL (the previously visited page)
- IP address of the site visitor
- Requesting provider
For security reasons, such as to investigate acts of abuse or fraud, server log files are stored for a maximum of 7 days and then deleted. Data whose further retention is required for evidential purposes is exempt from deletion until the respective incident has been finally clarified.
This data processing takes place in accordance with Art. 6 (1) lit. f GDPR to safeguard legitimate interests.
Cookies
Cookies are used on this online presence. Cookies support the display of this online presence and enable the use of certain functions. These are small text files that are stored on your device. Cookies collect data regarding your IP address, your browser, your operating system, and your internet connection.
Some of the cookies used on this online presence are deleted after the browser session ends, i.e., after closing your browser (so-called session cookies). Other cookies remain on your device and enable us to recognize your browser on your next visit (persistent cookies). You can set your browser so that you are informed about the setting of cookies and individually decide on their acceptance, or exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be restricted.
This data processing is based on Art. 6 (1) lit. a) GDPR upon your consent.
You can find the duration of storage in the overview of your web browser's cookie settings. You can set your browser so that you are informed when cookies are set and individually decide on their acceptance or completely exclude the acceptance of cookies for certain cases or in general.
Cookie settings are managed differently in various internet browsers. The help menu of your browser provides more information on how to change your cookie settings.
Information on cookie settings for Internet Explorer™ can be found at the following link:
Information on cookie settings for Safari™ can be found at the following link:
Information on cookie settings for Chrome™ can be found at the following link:
Information on cookie settings for Firefox™ can be found at the following link:
Information on cookie settings for Opera™ can be found at the following link:
You can also use our website without the use of cookies, which may result in some displays and functions of our offer working only to a limited extent.
You can manage online advertising cookies via the following links:
- http://www.aboutads.info/choices for the USA;
- http://www.youronlinechoices.com/uk/your-ad-choices for Europe.
Data Deletion / Data Blocking after the Purpose of Collection or Retention Period has Expired
The data stored and processed by Boy Katzennetze will be deleted or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated in this privacy policy, the stored data will be deleted as soon as it is no longer required for its intended purpose and the deletion does not conflict with any statutory retention requirements. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. In this case, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons.
According to legal requirements in Germany, the retention periods are 6 years in accordance with § 257 (1) HGB (German Commercial Code) for account books, inventories, opening balance sheets, annual financial statements, trade letters, accounting vouchers, etc., as well as 10 years in accordance with § 147 (1) AO (German Fiscal Code) for books, records, management reports, accounting vouchers, commercial and business letters, documents relevant for taxation, etc.
Rights of the Data Subject
Data protection law grants you a number of rights vis-à-vis the controller operating this online presence. Your rights are outlined below.
Right of Access
Pursuant to Art. 15 GDPR, you have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to this data as well as further information, and a copy of the personal data undergoing processing.
Right to Rectification
Pursuant to Art. 16 GDPR, you have the right to request the completion of the data concerning you or the rectification of inaccurate data concerning you.
Right to Erasure or Restriction of Processing
Pursuant to Art. 17 GDPR, you have the right to demand that data concerning you be deleted immediately. Alternatively, pursuant to Art. 18 GDPR, you have the right to demand a restriction of the processing of the data.
Right to Data Portability
Pursuant to Art. 20 GDPR, you have the right to receive the data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and to request its transmission to other controllers.
Right to Lodge a Complaint
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority.
Right of Withdrawal
Pursuant to Art. 7 (3) GDPR, you have the right to withdraw granted consents with effect for the future.
Right to Object
Pursuant to Art. 21 GDPR, you have the right to object to the future processing of the personal data concerning you at any time. The objection can in particular be made against processing for direct marketing purposes. If you object to processing for direct marketing purposes, your personal data will no longer be processed for such purposes.
Additional Functions on the Website
Encryption and Data Security
When you access this online presence, the widely used SSL (Secure Socket Layer) procedure is used in conjunction with the highest level of encryption supported by your browser. As a rule, this is a 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. Whether a single page of this online presence is transmitted encrypted is indicated by the closed display of the key or lock symbol in the lower status bar of your browser.
Furthermore, appropriate technical and organisational security measures are used to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or against unauthorised access by third parties. These security measures are continuously improved in line with technological developments.
Use of reCAPTCHA
The "ReCAPTCHA" service is integrated into this online presence. The provider of this service is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This service serves the purpose of detecting bots, e.g. when entering information into online forms, to prevent misuse.
This data processing serves to safeguard legitimate interests in accordance with Art. 6 (1) lit. f) GDPR.
The provider's corresponding privacy policy can be found at the following link:
https://www.google.com/policies/privacy/
Information on the opt-out option can be found at the following link:
https://adssettings.google.com/authenticated
Contact Form
When visiting this online presence, you have the opportunity to contact Boy Katzennetze via a contact form. In this case, the information you provide will be stored for the purpose of processing your inquiry. The data will not be passed on to third parties. The data collected in this way is also not matched with data that may be collected by other components of this online presence.
This data processing thus takes place with your consent in accordance with Art. 6 (1) lit. a) GDPR.
Registration Function
When visiting this online presence, you have the opportunity to register there. The data recorded in the course of this registration is derived from the input mask of the registration form.
The purpose of this data processing is to be able to fulfill existing contractual obligations towards you and to keep in touch with you.
This data processing thus takes place with your consent in accordance with Art. 6 (1) lit. a) GDPR.
Commenting Option
When visiting this online presence, you have the opportunity to leave comments on the individual posts. In this context, the IP address from which you accessed this online presence is stored.
This data processing takes place in accordance with Art. 6 (1) lit. a) GDPR based on your consent.
Furthermore, the IP address is stored to protect Boy Katzennetze in the event that the author's comment infringes on the rights of third parties and/or illegal content is posted, thereby creating the risk of claims being asserted against Boy Katzennetze due to these legal violations.
This storage serves to safeguard legitimate interests in accordance with Art. 6 (1) lit. f) GDPR. The processing of this data is restricted to the purpose of a possible defence against claims.
Data Transmission to Third Parties: Payment Services
For convenient processing of payments during the ordering process, you are given the opportunity to choose an external payment service provider at various points within this online presence.
This data processing is therefore carried out in accordance with Art. 6 (1) lit. a) GDPR with your consent.
Below you will find detailed information about the payment service providers offered for selection and the data processing involved.
PayPal as a Payment Option
The provider of this service is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
If you choose to pay with the online payment service provider PayPal during your order process, your contact details will be transmitted to PayPal as part of the order thus triggered.
PayPal assumes the function of an online payment service provider and a trustee, and offers buyer protection services.
The personal data transmitted to PayPal usually includes first name, last name, address, telephone number, IP address, email address, or other data required for order processing, as well as data related to the order, such as number of items, article number, invoice amount and taxes in percent, invoice information, etc.
This transmission is necessary to process your order with your selected payment method, in particular to confirm your identity, administer your payment and the customer relationship.
A note on data sharing: Personal data may also be passed on by PayPal to service providers, subcontractors, or other affiliated companies, insofar as this is necessary to fulfill the contractual obligations from your order or if the personal data is to be processed on a commissioned basis.
Depending on the payment method selected via PayPal, e.g., invoice or direct debit, the personal data transmitted to PayPal will be sent by PayPal to credit reference agencies. This transmission serves the purpose of identity and credit checks in relation to your order. Which credit reference agencies are involved and which data is generally collected, processed, stored, and shared by PayPal can be found in PayPal's privacy policy. You can access this privacy policy under the following link:
https://www.paypal.com/webapps/mpp/ua/privacy-full
Saferpay as a Payment Option
The provider of this service is SIX Payment Services AG, Hardturmstrasse 201, 8021 Zurich, Switzerland.
If you choose to pay with Saferpay during your order process, the payment data you entered will be transmitted to SIX Payment Services AG as part of the order thus triggered.
Which data is generally collected, processed, stored, and shared by SIX Payment Services AG can be found in their privacy policy. You can access this privacy policy under the following link:
https://www.six-payment-services.com/en/services/legal/privacy-statement.html
Sofortüberweisung (Sofort) as a Payment Option
The provider of this service is SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany, a company of the Klarna Group.
If you choose to pay with the online payment service provider Sofortüberweisung during your order process, your contact details will be transmitted to SOFORT GmbH as part of the order thus triggered.
SOFORT GmbH assumes the function of an online payment service provider that enables cashless payment of products and services on the internet.
The personal data transmitted to SOFORT GmbH usually includes first name, last name, address, telephone number, IP address, email address, or other data required for order processing, as well as data related to the order, such as number of items, article number, invoice amount and taxes in percent, invoice information, etc.
This transmission is necessary to process your order with your selected payment method, in particular to confirm your identity, administer your payment and the customer relationship.
A note on data sharing: Personal data may also be passed on by SOFORT GmbH to service providers, subcontractors, or other affiliated companies, insofar as this is necessary to fulfill the contractual obligations from your order or if the personal data is to be processed on a commissioned basis.
Under certain circumstances, the personal data transmitted to SOFORT GmbH will be further transmitted from there to credit reference agencies. This transmission serves the purpose of identity and credit checks in relation to your order.
You can find out which data protection principles SOFORT GmbH applies when processing your data in the privacy policy displayed to you during the Sofortüberweisung payment process.
If you have any further questions regarding the use of your personal data, you can contact SOFORT GmbH via email (datenschutz@sofort.com) or in writing (SOFORT GmbH, Datenschutz, Theresienhöhe 12, 80339 Munich, Germany).
Integration of Third-Party Providers: Web Analytics Tools
The web analysis and tracking tools detailed below are integrated into this online presence.
The purpose of this data processing is to ensure a needs-based design and continuous optimisation of this online presence, as well as to statistically record the use of this online presence and to evaluate it for the purpose of adapting content.
This data processing thus takes place in accordance with Art. 6 (1) lit. f) GDPR to safeguard legitimate interests.
Google Analytics with Anonymisation Function
The "Google Analytics" service with an anonymisation function is integrated into this online presence.
The provider of this service is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This provider is certified under the EU-US Privacy Shield agreement:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI
Google Analytics makes it possible to analyse your use of this online presence, for example with the help of "cookies" stored on your device. The information generated about your use of this website is usually transmitted to a Google server in the USA and stored there. By activating IP anonymisation on this website, your IP address will be truncated beforehand within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. The anonymised IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
You can prevent the collection of the data generated by the cookie and related to your use of the website (including your IP address) to Google as well as the processing of this data by Google by downloading and installing the browser plugin available under the following link:
http://tools.google.com/dlpage/gaoptout?hl=en
As an alternative to the browser plugin, you can set an opt-out cookie on your device. Note: If you delete your cookies, you must set this opt-out cookie on your device again. The opt-out cookie is provided to you by Google at the following link:
https://developers.google.com/analytics/devguides/collection/gajs/?hl=en#disable
Integration of Third-Party Providers: Social Networks
The social media plug-ins detailed below are integrated into this online presence. Responsibility for privacy-compliant operation rests with their respective providers.
The purpose of using these extensions is to make this online presence better known via social networks.
This data processing thus takes place in accordance with Art. 6 (1) lit. f) GDPR to safeguard legitimate interests.
Social Plug-ins from Facebook
Social plug-ins from Facebook, such as the "Like" button or the "Share" button, are integrated into this online presence.
The provider of this service is Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA. If you are based in the EU, the provider of this service is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Information on the individual social plug-ins from Facebook and their appearance can be accessed at the following link:
https://developers.facebook.com/docs/plugins/
When you visit a page of this online presence that contains a social plug-in, your browser establishes a direct connection with Facebook's servers. The content of the plugin is transmitted by Facebook directly to your browser and integrated into the website.
By integrating the plugins, Facebook receives the information that your browser has accessed the corresponding page of this online presence, even if you do not have a Facebook account or are currently not logged in to Facebook. This information, including your IP address, is transmitted by your browser directly to a Facebook server in the USA and stored there.
If you are logged into Facebook, Facebook can directly associate the visit to our website with your Facebook account. If you interact with the plugins, for example by pressing the "Like" or "Share" button, the corresponding information is also transmitted directly to a Facebook server and stored there. The information will also be published on Facebook and shown to everyone.
Facebook can use this information for the purpose of advertising, market research, and tailoring Facebook pages to meet needs. For this purpose, Facebook creates usage, interest, and relationship profiles, e.g. to evaluate your use of this online presence in relation to the advertisements shown to you on Facebook, to inform other Facebook users about your activities on this online presence, and to provide other services associated with the use of Facebook.
If you do not want Facebook to associate the data collected during your visit to this online presence with your Facebook account, you must log out of Facebook before visiting this online presence.
For the purpose and scope of data collection and the further processing and use of data by the provider on its pages, as well as your respective rights and settings options for protecting your privacy, please refer to the privacy policies of the provider.
The provider's corresponding privacy policy with information on the collection and use of data by Facebook, your rights in this regard, and the settings options for protecting your privacy can be found under the following link:
https://www.facebook.com/about/privacy/
Integration of Third-Party Providers: Media
The third-party media detailed below are integrated into this online presence.
The purpose of using these media is to be able to offer content that is appealing both in substance and visually.
This data processing thus takes place in accordance with Art. 6 (1) lit. f) GDPR to safeguard legitimate interests.
Google Web Fonts
"Google Fonts" are integrated into this online presence.
The provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This provider is certified under the EU-US Privacy Shield agreement:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
The corresponding privacy policy of the provider can be found at the following link:
https://www.google.com/policies/privacy/
Information on the opt-out option can be found at the following link:
https://adssettings.google.com/authenticated
YouTube
Videos from the "YouTube" platform are integrated into this online presence. The provider of this service is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This provider is certified under the EU-US Privacy Shield agreement:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
For the purpose and scope of data collection and the further processing and use of data by the provider on its pages, as well as your respective rights and settings options for protecting your privacy, please refer to the privacy policy of the provider.
The corresponding privacy policy of the provider can be found at the following link:
https://www.google.com/policies/privacy/
Information on the opt-out option can be found at the following link:
https://adssettings.google.com/authenticated
Integration of Third-Party Providers: Google Marketing Services
The Google marketing services detailed below are integrated into this online presence.
The provider of these services is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This provider is certified under the EU-US Privacy Shield agreement:
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active
The purpose of using these services is to be able to offer interest-based advertising.
This data processing thus takes place in accordance with Art. 6 (1) lit. f) GDPR to safeguard legitimate interests.
By using this online presence, you consent to the processing of data collected about you by Google in the manner described below for the respective marketing service and for the designated purpose.
The corresponding privacy policy of the provider can be found at the following link:
https://www.google.com/policies/privacy/
Further information on the use of data for marketing purposes by Google can be found under the following link:
https://www.google.com/policies/technologies/ads
If you wish to object to interest-based advertising by Google Marketing Services, you can use the settings and opt-out options provided by Google under the following link:
http://www.google.com/ads/preferences
Google AdWords
The "Google AdWords" (Google Conversion Tracking) service is integrated into this online presence.
The purpose of this data processing is to promote this online presence via the "Google" search engine. To this end, the "Conversion Tracking" analytics service is integrated into this online presence.
If you have reached this online presence via a Google ad, a cookie will be placed on your device. This so-called "conversion cookie" expires after 30 days and does not serve for personal identification. If you visit certain pages of this online presence and the cookie has not yet expired, Boy Katzennetze and Google can recognise that you, as a user, clicked on one of the ads placed by Boy Katzennetze on Google and were redirected to this online presence.
The information obtained using the "conversion cookie" is used by Google to create visit statistics for this online presence. This reveals the total number of users who clicked on the ad from Boy Katzennetze. Furthermore, it reveals which pages of this online presence were subsequently called up by the respective user. However, Boy Katzennetze or other advertisers using "Google Adwords" do not receive any information that personally identifies users.
You can prevent the installation of "conversion cookies" by adjusting your browser settings, for example, via a browser setting that generally deactivates the automatic setting of cookies or specifically blocks only cookies from the domain "googleadservices.com".
A separate privacy policy from Google can be found at the following link:
https://services.google.com/sitestats/en.html
Shopware Analytics
Purpose of processing:
Together with our store software service provider, we evaluate certain information from our customer base under joint responsibility (e.g. customer group, pages visited, click paths, date and time of the visit, information about the end device used (resolution, resolution density, operating system), referrer URL, information about the browser used, locale, search queries and time zone). This information is processed by an external service provider and forwarded to us in approximate real time so that we can monitor the use of our website and improve our offerings.
Legal basis:
Art. 6 para. 1 letter f GDPR
Data categories:
Derived from core and contact data (the customer group, no individual customer data), usage data, connection data
Recipients of the data:
shopware AG, Ebbinghoff 10, 48624 Schöppingen, Germany (as joint controller), IT service provider
The essence of joint responsibility:
The joint responsibility exists between us and shopware AG; the data is collected in our store and then transferred to servers of shopware or its service providers; with the exception of obtaining your consent for the use of cookies or comparable technologies and the fulfillment of these information obligations, all obligations, in particular the implementation of the rights of data subjects, are the responsibility of shopware AG, which you can reach at legal@shopware.com. You can also assert your data subject rights with us; we will then forward your request to shopware AG accordingly. shopware AG can derive behavior patterns on our store from the data collected, but cannot assign this data to you as a person.
Intended third country transfer:
None
Do we store or read personal data on your end device based on your consent?
Yes, see Consent Management for details.
Last updated: 21.06.2019