top of page
Privacy Policy
The data controller is:
Sebastian Stratmann
Winterhuder Weg 29, 7th Floor
22085 Hamburg
Germany
mail@harboryorkway.store
Thank you for your interest in our online store. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data.
1. ACCESS DATA AND HOSTING
You can visit our websites without providing any personal information. Each time a webpage is accessed, the web server automatically stores a so-called server log file containing, for example, the name of the requested file, your IP address, the date and time of access, the amount of data transferred, and the requesting provider (access data), thereby documenting the access. This access data is evaluated exclusively for the purpose of ensuring the smooth operation of the site and improving our offering. This serves to safeguard our legitimate interests, which prevail following a balancing of interests, in the correct presentation of our offering in accordance with Art. 6(1)(f) GDPR. All access data is processed for as long as necessary for the purposes described above.
HOSTING
The services for hosting and displaying the website are partially provided by our service providers as part of processing on our behalf. Unless otherwise specified in this Privacy Policy, all access data as well as all data collected in the forms provided for this purpose on this website are processed on their servers. If you have any questions about our service providers and the basis of our cooperation with them, please contact us using the contact information provided in this Privacy Policy.
Our service providers are based in Israel and use servers there. The European Commission has determined by decision that Israel provides an adequate level of data protection. In addition, our service providers use servers in the United States, South Korea, and Taiwan, as well as in other countries outside the EU and the EEA for which no adequacy decision has been issued by the European Commission. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
2. DATA PROCESSING FOR CONTRACT FULFILLMENT AND CONTACT PURPOSES
2.1 DATA PROCESSING FOR CONTRACT FULFILLMENT
For the purpose of contract fulfillment (including inquiries regarding and the handling of any existing warranty claims and claims for breach of contract, as well as any statutory update obligations) pursuant to Art. 6(1)(b) GDPR, we collect personal data if you voluntarily provide it to us as part of your order. Mandatory fields are marked as such, as we require this data for contract fulfillment and cannot ship the order without it. The data collected is indicated in the respective input forms.
Further information regarding the processing of your data, in particular regarding its transfer to our service providers for the purposes of order, payment, and shipping processing, can be found in the following sections of this Privacy Policy. After the contract has been fully processed, your data will be restricted for further processing and deleted after the expiration of the retention periods under tax and commercial law in accordance with Art. 6(1)(c) GDPR, unless you have expressly consented to further use of your data pursuant to Art. 6(1)(a) GDPR or we reserve the right to use your data beyond this scope, which is permitted by law and about which we inform you in this policy.
2.2 CUSTOMER ACCOUNT
To the extent that you have given your consent pursuant to Article 6(1)(a) of the GDPR by deciding to open a customer account, we use your data for the purpose of opening the customer account and for storing your data for future orders on our website. You may delete your customer account at any time by either sending a message to the contact address provided in this Privacy Policy or using the function provided for this purpose in your customer account. After your customer account is deleted, your data will be deleted unless you have expressly consented to further use of your data pursuant to Art. 6(1)(a) GDPR or we reserve the right to use your data beyond this scope, which is permitted by law and about which we inform you in this policy.
2.3 CONTACTING US
As part of our customer communications, we collect personal data to process your inquiries in accordance with Article 6(1)(b) of the GDPR if you voluntarily provide it to us when contacting us (e.g., via a contact form, live chat tool, or email). Mandatory fields are marked as such, as we require this data to process your inquiry. The specific data collected is indicated in the respective input forms. Once your inquiry has been fully processed, your data will be deleted unless you have expressly consented to further use of your data in accordance with Article 6(1)(a) of the GDPR or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.
LIVE CHAT TOOL ASCEND BY WIX
If you use the live chat tool to contact us, the data you voluntarily enter there (name, email address, message) will be processed by us in accordance with Art. 6(1)(b) GDPR for the purpose of responding to your inquiry as part of contract fulfillment. Furthermore, the use of this tool serves to safeguard our legitimate interests, which prevail following a balancing of interests, in effective and improved customer communication in accordance with Article 6(1)(f) of the GDPR. The data is subsequently deleted. The live chat tool is provided by Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv 6350671, Israel (“Wix”), which acts on our behalf. Wix uses servers in Israel. The European Commission has determined by decision that Israel has an adequate level of data protection. In addition, Wix uses servers in the United States, South Korea, and Taiwan, as well as in other countries outside the EU and the EEA for which no adequacy decision has been issued by the European Commission. Our cooperation with Wix is based on the European Commission’s Standard Data Protection Clauses.
3. DATA PROCESSING FOR THE PURPOSE OF SHIPPING
To fulfill the contract pursuant to Art. 6(1)(b) GDPR, we transfer your data to the shipping service provider commissioned with the delivery, to the extent necessary for the delivery of ordered goods.
DATA TRANSFER TO SHIPPING SERVICE PROVIDERS FOR THE PURPOSE OF SHIPPING NOTIFICATION
If you have given us your express consent to this during or after your order, we will, on this basis and in accordance with Art. 6(1)(a) GDPR, transfer your email address to the selected shipping service provider so that they can contact you prior to delivery for the purpose of delivery notification or coordination.
You may revoke your consent at any time by sending a message to the contact information provided in this Privacy Policy or directly to the shipping service provider at the contact address listed below. Upon revocation, we will delete the data you provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to use your data beyond this scope, which is permitted by law and about which we inform you in this policy.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
4. DATA PROCESSING FOR PAYMENT PROCESSING
When processing payments in our online store, we work with the following partners: technical service providers, credit institutions, and payment service providers.
4.1 DATA PROCESSING FOR TRANSACTION PROCESSING
Depending on the selected payment method, we transfer the data necessary for processing the payment transaction to our technical service providers, who act on our behalf as data processors, or to the designated credit institutions or the selected payment service provider, to the extent necessary for processing the payment. This serves the purpose of contract performance pursuant to Art. 6(1)(b) GDPR. In some cases, the payment service providers collect the data required for processing the payment themselves, e.g., on their own website or through technical integration into the ordering process. In this regard, the privacy policy of the respective payment service provider applies.
If you have any questions regarding our payment processing partners and the basis of our cooperation with them, please contact us using the contact information provided in this privacy policy.
4.2 DATA PROCESSING FOR THE PURPOSES OF FRAUD PREVENTION AND OPTIMIZING OUR PAYMENT PROCESSES
Where necessary, we provide our service providers with additional data, which they use—along with the data required to process the payment—in their capacity as our data processors for the purposes of fraud prevention and the optimization of our payment processes (e.g., invoicing, handling disputed payments, and supporting accounting). This serves, pursuant to Art. 6(1)(f) GDPR, to safeguard our legitimate interests—which prevail following a balancing of interests—in protecting ourselves against fraud and in ensuring efficient payment management.
5. EMAIL MARKETING
5.1 EMAIL NEWSLETTERS WITH SUBSCRIPTION, NEWSLETTER TRACKING WITH SEPARATE CONSENT
When you subscribe to our newsletter, we use the data required for this purpose or separately provided by you to send you our email newsletter on a regular basis based on your consent pursuant to Art. 6(1)(a) GDPR. You may unsubscribe from the newsletter at any time by either sending a message to the contact address provided below or by clicking a link provided for this purpose in the newsletter. After unsubscribing, we will delete your email address from the recipient list, unless you have expressly consented to further use of your data in accordance with Article 6(1)(a) of the GDPR or we reserve the right to use your data for other purposes that are permitted by law and about which we inform you in this statement.
If you have additionally granted us your consent pursuant to Art. 6(1)(a) GDPR to analyze our newsletters, we will also analyze your interaction with our newsletter by measuring, storing, and evaluating open rates and click-through rates for the purpose of designing future newsletter campaigns (“newsletter tracking”).
For this evaluation, the emails sent contain single-pixel technologies (e.g., so-called web beacons, tracking pixels) that are stored on our website. For the evaluations, we link the following “newsletter data” in particular:
* the page from which the page was requested (so-called referrer URL),
* the date and time of the request,
* the description of the type of web browser used,
* the IP address of the requesting computer,
* the email address,
* the date and time of registration and confirmation
and the one-pixel technologies with your email address or your IP address and, if applicable, an individual ID. Links contained in the newsletter may also contain this ID.
You can opt out of newsletter tracking at any time by either sending a message to the contact address provided or using a link provided for this purpose in the newsletter.
The information is stored for as long as you remain subscribed to the newsletter.
5.2 NEWSLETTER DISTRIBUTION
Our service providers are located in and/or use servers in Israel. The European Commission has determined by decision that Israel provides an adequate level of data protection. In addition, our service providers use servers in the United States, South Korea, and Taiwan, as well as in other countries outside the EU and the EEA for which no adequacy decision has been issued by the European Commission. Our cooperation with you is based on the European Commission’s Standard Data Protection Clauses.
6. COOKIES AND OTHER TECHNOLOGIES
GENERAL INFORMATION
To make your visit to our website more enjoyable and to enable the use of certain features, we use various technologies on different pages, including so-called cookies. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted at the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies).
We use technologies that are strictly necessary for the use of certain features of our website (e.g., the shopping cart feature). These technologies collect and process your IP address, the time of your visit, device and browser information, as well as information regarding your use of our website (e.g., information about the contents of your shopping cart). This is based on a balancing of interests, serving our overriding legitimate interest in optimizing the presentation of our offerings in accordance with Article 6(1)(f) of the GDPR.
You can find the cookie settings for your browser at the following links: Microsoft Edge™ [https://support.microsoft.com/de-de/help/4027947/microsoft-edge-delete-cookies] / Safari™ [https://support.apple.com/de-de/guide/safari/sfri11471/12.0/mac/10.14] / Chrome™ [https://support.google.com/chrome/answer/95647?hl=de&hlrm=en] / Firefox™ [https://support.mozilla.org/de/products/firefox/protect-your-privacy/cookies] / Opera™ [https://help.opera.com/de/latest/web-preferences/#cookies]
If you have consented to the use of these technologies pursuant to Art. 6(1)(a) of the GDPR, you may revoke your consent at any time by sending a message to the contact address provided in the Privacy Policy.
7. USE OF COOKIES AND OTHER TECHNOLOGIES FOR WEB ANALYSIS AND ADVERTISING PURPOSES
To the extent that you have given your consent pursuant to Article 6(1)(a) of the GDPR, we use the following cookies and other third-party technologies on our website. Once the purpose has been fulfilled and we have ceased using the respective technology, the data collected in this context will be deleted. You may revoke your consent at any time with future effect. Further information regarding your options for revocation can be found in the section “Cookies and Other Technologies.” Further information, including the basis for our cooperation with the individual providers, can be found under the respective technologies. If you have any questions regarding the providers and the basis for our cooperation with them, please contact us using the contact details provided in this Privacy Policy.
USE OF GOOGLE SERVICES FOR WEB ANALYSIS AND ADVERTISING PURPOSES
We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) described below. The information automatically collected by Google technologies regarding your use of our website is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. There is no adequacy decision by the European Commission for the United States. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses. If your IP address is collected via Google technologies, it is truncated before being stored on Google’s servers by activating IP anonymization. Only in exceptional cases is the full IP address transmitted to a Google server and truncated there. Unless otherwise specified for the individual technologies, data processing is based on an agreement concluded between joint controllers for the respective technology in accordance with Art. 26 GDPR. Further information about data processing by Google can be found in Google’s privacy policy [https://policies.google.com/privacy?hl=de].
GOOGLE ANALYTICS
For the purpose of website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information, and information regarding your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Your IP address is generally not combined with other data held by Google. Data processing is carried out on the basis of an agreement regarding data processing by Google.
8. SOCIAL MEDIA
8.1 SOCIAL PLUGINS FROM FACEBOOK (BY META), INSTAGRAM (BY META), AND WHATSAPP
Our website uses social media buttons from various social networks. These are embedded in the page solely as HTML links, so no connection to the respective provider’s servers is established when you visit our website. If you click on one of the buttons, the website of the respective social network opens in a new window of your browser. There you can, for example, click the Like or Share button.
8.2 OUR ONLINE PRESENCE ON FACEBOOK (BY META), INSTAGRAM (BY META), LINKEDIN
To the extent that you have given your consent to the respective social media operator pursuant to Art. 6(1)(a) GDPR, your data will be automatically collected and stored for market research and advertising purposes when you visit our online presences on the aforementioned social media platforms, from which usage profiles are created using pseudonyms. These profiles may be used, for example, to display advertisements within and outside the platforms that are presumed to match your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the respective social media operator, as well as contact information, your rights in this regard, and settings to protect your privacy, please refer to the providers’ privacy policies linked below. If you still need assistance in this regard, please contact us.
Facebook (by Meta) [http://www.facebook.com/about/privacy/] is a service provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta Platforms Ireland”). The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Facebook (by Meta) is generally transmitted to a server operated by Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA, and stored there. There is no adequacy decision by the European Commission for the United States. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses. Data processing in connection with a visit to a Facebook (by Meta) fan page is based on an agreement between joint controllers pursuant to Article 26 of the GDPR. Further information (information on Insights data) can be found here [https://www.facebook.com/legal/terms/information_about_page_insights_data].
Instagram (by Meta) [http://help.instagram.com/519522125107875] is a service provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (“Meta Platforms Ireland”) The information automatically collected by Meta Platforms Ireland regarding your use of our online presence on Instagram is generally transmitted to a server operated by Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA, and stored there. There is no adequacy decision by the European Commission for the United States. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses. Data processing in connection with a visit to an Instagram (by Meta) fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. Further information (information on Insights data) can be found here [https://www.facebook.com/legal/terms/information_about_page_insights_data].
LinkedIn [https://www.linkedin.com/legal/privacy-policy] is a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information automatically collected by LinkedIn regarding your use of our online presence on LinkedIn is generally transmitted to and stored on a server operated by LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. There is no adequacy decision by the European Commission for the United States. Our cooperation with them is based on the European Commission’s Standard Data Protection Clauses.
9. CONTACT INFORMATION AND YOUR RIGHTS
9.1 YOUR RIGHTS
As a data subject, you have the following rights:
* pursuant to Art. 15 of the GDPR, the right to request information about your personal data processed by us to the extent specified therein;
* pursuant to Art. 16 of the GDPR, the right to request the immediate rectification of inaccurate personal data or the completion of your personal data stored by us;
* pursuant to Art. 17 GDPR, the right to request the erasure of your personal data stored by us, unless further processing is necessary
* for the exercise of the right to freedom of expression and information;
* to comply with a legal obligation;
* for reasons of public interest; or
* for the establishment, exercise, or defense of legal claims;
* pursuant to Art. 18 GDPR, the right to request the restriction of the processing of your personal data, provided that
* you contest the accuracy of the data;
* the processing is unlawful, but you oppose its erasure;
* we no longer need the data, but you require it for the establishment, exercise, or defense of legal claims; or
* you have objected to the processing pursuant to Article 21 of the GDPR;
* pursuant to Article 20 of the GDPR, the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format or to request its transmission to another controller;
* pursuant to Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority of your usual place of residence, place of work, or our company headquarters for this purpose.
Right to Object
To the extent that we process personal data as described above to safeguard our legitimate interests that prevail following a balancing of interests, you may object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you may exercise this right at any time as described above. To the extent that the processing is carried out for other purposes, you have a right to object only if there are grounds arising from your particular situation.
After you exercise your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims.
This does not apply if the processing is carried out for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.
9.2 CONTACT INFORMATION
If you have any questions regarding the collection, processing, or use of your personal data, or if you wish to request information, correction, restriction, or deletion of data, or to revoke consent or object to a specific use of your data, please contact us directly using the contact details in our legal notice.
Privacy Policy [https://legal.trustedshops.com/produkte/rechtstexter] created using the Trusted Shops [https://legal.trustedshops.com] legal text generator in cooperation with FÖHLISCH Rechtsanwälte [https://foehlisch.com].
bottom of page