Data Protection Statement

The controller as defined by the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions relating to data protection is beeAthletica GmbH, Hasselstrasse 11, D-35614 Asslar, Germany, represented by the managing director Bettina Beringer (hereinafter referred to as "controller" or "we" or "us").


A. General information about data processing

1) Personal Data

Personal data is individual items of information about personal or material circumstances of a particular or identifiable natural person. This includes information such as name, address, telephone number and e-mail address, but also the IP address assigned to a connection. Information not directly associated with a person – for example favourite internet sites or the number of users of a site – is not personal data.

2) Scope of processing of personal data

As a matter of principle we collect and use personal data of our users only insofar as is necessary for provision of a functional website and for our content and services. Collection and use of our users’ personal data normally takes place only after consent from the user. An exception is made in cases where it is not possible to obtain consent in advance for objective reasons and processing of the data is permitted by statutory regulations. 

3) The legal basis for processing personal data

Insofar as we obtain consent from the data subject for processing operations for personal data, Art. 6 (1) a of the General Data Protection Regulation (GDPR) is the legal basis for processing personal data.
Where it is necessary to process personal data for fulfilment of a contract, the contracting party for which is the data subject, Art. 6 (1) b GDPR is the legal basis. This also applies for processing operations required to carry out pre-contractual measures.
If the vital interests of the data subject or of another natural person necessitate processing of personal data, Art. 6 (1) d GDPR is the legal basis.
If processing is necessary to safeguard a justified interest of our company or of a third party and the interests, basic rights and fundamental freedoms of the data subject do not outweigh the aforementioned justified interest, Art. 6 (1) f of the GDPR is the legal basis for processing.

4) Erasure of data and duration of storage

Personal data of the data subject is erased or blocked as soon as the purpose of storage no longer applies. Storage beyond this may take place if this is provided for by the European or national legislator in EU regulations, laws or other rules to which the controller is subject. Blocking or deletion of data is also carried out if a storage period prescribed by the above-mentioned standards expires, unless further storage of the data is necessary for conclusion of a contract or fulfilment of a contract.


B. Provision of the website and creation of log files

Each time our website is accessed, we record data and information by means of an automated system.
The following data is collected in this process:

  1. Information about the browser type and version used
  2. The user’s operating system
  3. The user’s internet service provider
  4. The user’s IP address
  5. Time and date of access
  6. Websites from which the user’s system has come to our website (referrer)
  7. Websites accessed by the user’s system via our website

This data is likewise stored in our system's log files. This data is not stored together with the user's other personal data.

Legal basis for data processing

The legal basis for temporary storage of the data and log files is Art. 6 (1) f GDPR

Purpose of data processing

Temporary storage of the IP address by the system is necessary to facilitate provision of the website for the user’s computer. For this purpose the user’s IP address must be stored for the duration of the session.

The storage in log files is carried out to ensure the functional capability of the website. The data also helps us to optimise the website and to ensure the security of our IT systems. There is no analysis of the data for marketing purposes in this connection.

These purposes also include our justified interest in data processing in accordance with Art. 6 (1) f GDPR.

Duration of storage

The data is erased as soon as it is no longer required to achieve the purpose for which it was obtained. When data is recorded for provision of the website, this is the case when the respective session ends.

When data is stored in log files, this is the case after 6 months at the latest. Storage beyond this period is possible. In this case, the IP addresses of users are deleted or scrambled so that assignment of the accessing client is no longer possible.

Option for objection and elimination

Recording of data for provision of the website and the storage of data in log files is necessary for operation of the website. Therefore, the user has no right of objection. 


C. Use of cookies

Our webpages use cookies in several places. Cookies are small text files that are kept on your computer and stored by your browser. This makes it possible to store on your PC specific information related to you, the user, when you visit our webpages. Cookies help to determine the frequency of use and the number of users on a website and to design the website for you in the most convenient and efficient way possible.

We use session cookies which are only stored for the duration of your visit to our website. Session cookies are deleted automatically after the end of your visit.

The following data is stored and transferred in session cookies:

  • Log-in data
  • articles in a shopping basket

We also use permanent cookies to obtain information about visitors who visit our website repeatedly. The purpose of these cookies is to offer you optimum user guidance, to recognise you and to avoid your having to register again in the case of repeated use. The content of the permanent cookie is limited to the identification number. Name, IP address etc. are not stored. No individual profile is created relating to your user habits.

When our website is accessed, the user is informed about the use of cookies for analytical purposes and his consent is obtained for processing of the personal data used in this connection. A reference to the data protection statement is also displayed in this connection.

Legal basis for data processing

The legal basis for processing personal data with the use of cookies necessary for technical reasons is Art. 6 (1) f GDPR.

The legal basis for processing personal data with the use of cookies for analytical purposes where the user has granted consent for this is Art. 6 (1) a GDPR.

Purpose of data processing

The purpose of using cookies required for technical reasons is to make the use of websites easier for users. Some functions of our website cannot be provided without the use of cookies. For this purpose, the browser has to be recognised again even after going to another page.


We require cookies for the following purposes:

  • for the shopping basket

The data obtained through technically necessary cookies will not be used to construct user profiles.

The use of analytical cookies serves the purpose of improving the quality and content of our website. Through these analytical cookies, we learn how the website is being used, and are thereby able to continuously improve our offering. 

These purposes also include our justified interest in data processing in accordance with Art. 6 (1) f GDPR.

Duration of storage

Cookies are stored on the computer of the user and transferred to us from it. Because of this, you as the user have the full control over the use of cookies. By changing the settings in your internet browser, you can deactivate or limit the use of cookies at any time. Already stored cookies can be deleted at any time. This can also be done through an automated function. If cookies are deactivated for our website, it is possible that not all of its functions can be used in their entirety. 

Option for objection and elimination

The use of our website is possible without cookies as well. You can deactivate the storage of cookies or restrict their use to certain websites in your internet browser, or set it in a way that it informs you when a cookie is being sent. Please note that in these cases you will have to accept a limited display of our website and a restricted usage of its menu.


D. Registering for the newsletter

When a user subscribes to our newsletter, the input of his/her email address into the respective framework is necessary. With registration and cancellation to and from the newsletter will the date and time of that activity be stored. On top of that, we use the data received from a newsletter (e.g. clicked content of it) to optimize our offering.

For processing the data, we will collect your consent in the process of registration and refer to our data protection statement then and there.

The data will be transferred to us and to our partner service CleverReach GmbH&Co KG, Mühlenstrasse 43, D-26180 Rastede, Ggermany. CleverReach performs the service of sending the newsletter.

There is no transfer of data to other third parties in connection with the data processing for the sending of the newsletter. The data will be used solely to send the newsletter.

The subscription of the newsletter can be cancelled at any time by the respective user. The consent to store the pesonal data can also be repealed at any time. For this purpose, there is a linkin each newsletter.

Webbugs

We use webbugs exclusively in the newsletters sent by us. Webbugs are small, around 1*1Pixel in size GIF files, that can be hidden in other graphics or emails. Webbugs serve similar functions to cookies, but they are not recognizable to users. The webbugs used by us are stored on your computer and tell us whether you have opened the newsletter sent to the email addess provided or not. The webugs we use restrict the information sent to your IP address, the IP address of the website visited (URL), the time when the webbug was viewed, the type of browser used and previously set cookie information. By using webbugs we can identify your computer and analyse the usage pattern. The collected data are anonymus and will not be related to personal data on the computer of theuser or with a data base.

To prevent the use of webbugs in our newsletter, you can set your mail program to prevent the display of HTML in news.

Webbugs will also be suppressed when you read your emails off-line.

Legal basis for data processing

Rechtsgrundlage für die Verarbeitung der Daten nach Anmeldung zum Newsletters durch den Nutzer ist bei Vorliegen einer Einwilligung des Nutzers Art. 6 Abs. 1 lit. a DSGVORechtsgrundlage für die Vearbeitung von Daten in Webbugs ist Art. 6 Abs. 1 lit. f DSGVO. Unser berechtigtes Interesse besteht hierbei in der Erkenntnis über die Nutzung der von uns versendeten Inhalte in Newslettern.

Purpose of data processing

The purpose of  collecting the email address of the user is the delivery of the newsletter to him/her. The collection of other personal data during the newsletter registration process serves the purpose of preventing a misuse of the services or of the email address provided. 

The collection of the IP address in the context of the webbugs serves the purpose of viewing statistical connections between the sent newsletters and orders received in connection with them. 

Duration of storage

The data is erased as soon as it is no longer required to achieve the purpose for which it was obtained. This is the case when you have cancelled your subscription of the newsletter. Other data collected during the newsletter registration process will generally be deleted within 6 weeks.

Option for objection and elimination

The subscription of the newsletter can be cancelled by the respective user at any time. For that purpose, there is a respective link in each newsletter. Through this move, the repeal of consent to store the personal data collected during registering for the newsletter is  enabled as well. 


E. Registration as Customer

An order can be made as a guest, without registration, or by registering and opening up a customer account. In case of ordering as a guest, we will only need the data necessary to process the contract and the dispatch of the goods, like name, surname, address and email address.

In the case of registering as a customer, the data provided to us by you when entering them on our registration site is transferred to us.

The registration requires providing your name, surname, address, email address and a password.

At the time of registration, the user's IP address and the date and time of registration will also be stored.

During the registration process, the user will be asked for and must consent to process this data.

Legal basis for data processing

Assuming the user gives his or her consent, the legal basis for the processing of the data is Art. 6 (1) a GDPR.

If registration serves to perform a contract, of which the contractual partner is the user, or in order to take steps prior to enetring into a contract, the legal basis for the processing of the data is also Art. 6 (1) b GDPR.

Purpose of data processing

The provision of the contract data of the user is also required for the performance of a contract with the user, or to take steps prior to entering into a contract.

At a registration, the provided data will be displayed at the next log in and they won't have to be re-entered then. The data provided at a registration will also be used as contact data when entering into a contract.

Duration of storage

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected.

Insofar as the data collected during the registration process is required to perform a contract, or to take steps prior to entering into a contract, this is only the case when the data is no longer required to perform the contract.

Even after conclusion of the contract it may still be necessary to store personal data in order to fulfil contractual or statutory obligations.

Option for objection and elimination

As a user, you can cancel your registration at any time. You can have the data stored about you altered at any time. You can alter your data after logging in as a registered user, and you can then alter or delete all the data you entered.


F. Making contact by e-mail or contact form

Our website provides a contact form which can be used to make contact electronically. Alternatively, you can make contact via the e-mail address provided.

If you contact us via the contact form, your name and your e-mail address will be transferred to us in any case. Furthermore, the user's IP address as well as the time and date are stored.

At the time of submission, your consent is obtained for data processing and your attention is drawn to the data protection statement.

When contact is made by e-mail, your e-mail address and your message are transferred to us and stored by us.

Legal basis for data processing

The legal basis for processing data where the user has granted consent for this is Art. 6 (1) a GDPR.

The legal basis for processing data transferred when an e-mail is sent is Art. 6 (1) f GDPR. If e-mail contact is made for the purpose of concluding a contract, the additional legal basis for the processing is Art. 6 (1) b GDPR.

Purpose of data processing

The processing of personal data from the entry screen of the contact form only allows us to process the contact. Contact by e-mail also gives rise to a necessary justified interest in processing the data.

The other personal data processed during the submission process serves to prevent misuse of the contact form and to guarantee the security of our IT systems.

Duration of storage

The data is deleted after the periods in which we are required to preserve it for commercial and tax purposes. 

Option for objection and elimination

The user has the option at any time to revoke his consent for processing personal data. If the user makes contact with us by e-mail, he may refuse to allow storage of his personal data at any time. In such a case the conversation cannot be continued. Consent may be revoked by sending an e-mail or by making contact with us by telephone or by post.

All personal data stored when contact is made is deleted in this case.


G. Use of the analytical tool Google Analytics

Our website uses functions of the web analysis service Google Analytics.

The provider of these services is Google Inc.,1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses so-called “Cookies”. Cookies are small text files that are kept on your computer and that enable the analysis of your usage of our website.

The information generated by that cookie regarding your usage of our website will generally be sent to a server of Google in the USA and stored there. Because of the activation of the IP anonymization tool on this website, your IP address will be abbreviated by Google within the member countries of the EU or other countries contractually associated to the EEA. Only in exceptional cases will the entire IP address be sent to a Google server in the US and abbreviated there. The IP address transferred in the process of Google Analytics will not be joined with other Google data.

Legal basis for data processing

The legal basis for the temporary storage of the data and the log files is Art. 6 (1) f of the GDPR. The justified interest is the analysis of the visitor volume.

Purpose of data processing

Google will use the hereby generated information on our behalf, in order to analyse the usage of our website, to generate reports about website activities and to provide us with further services related to website and internet usage.

Duration of storage

The personal data is erased immediately after being generated, through the activation of the anonymity tool.

Option for objection and elimination

You can prevent the storage of cookies by making the relevant setting in your browser software; however, we draw your attention to the fact that in this case you may not be able to make full use of all the functions of the website.

On top of that, you can prevent the collection of your website usage related data (incl. your IP address) generated by the cookie by Google and the processing of that data by Google by downloading and installing the browser-plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de

Alternatively, you can prevent the tracking by clicking here. In this case, a cookie will be set in your browser, which prevents the tracking by Google Analytics. However, if you delete your cookies, this will also result in your cookie being deleted, which you will then need to reactivate if necessary.


H. Other transfer of data to third parties

1. As part of executing the order, it is necessary to pass on your name and address, consisting of street name and location, to our payment provider and parcel delivery service. The transfer is necessary to finalize your payment and to deliver your order. The transfer of data is restricted to the necessary minimum. The legal basis for that is Art. 6 (1) b GDPR.

If you requested the notification of delivery by the parcel delivery service, your email address will also be made available to them. This email address will solely be used by the parcel delivery service to notify you of the delivery date. The legal basis for that is Art. 6 (1) a GDPR.

After delivery of your goods, the data will be deleted at the parcel service provider.

With your confirmed order, you consent to the provision of the data for the finalization of payment and for delivery as described above to the parcel service provider.

Your rights are upheld and defined as above and in the following paragraphs.

2. If you make use of the payment option „paypal“, credit card via paypal, or direct debit via paypal, we will provide your email address, your address and the payment information you gave for that purchase to Paypal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (henceforth „Paypal“). The legal basis for that provision is Art. 6 (1) b GDPR, and that only insofar as this is necessary for the processing of your payment.

When paying by paypal-invoice or installment, Paypal performs risk-checks and decides whether payment by your as such chosen form is possible. For that, your payment information and data might be forwarded to credit check agencies to determine your payment ability, on the basis of Paypal's justified interest according to Art. 6(1)f GDPR. The result of that credit check will be used by Paypal with regard to the calculation of the statistical probability of payment default, to determine the provision of the payment method in question.

The credit check result can include probability scores. Insofar as such scores comprise part of the result of the credit check, they are based upon generally accepted scientific mathematic statistical processes. The calculation of such scores is comprised of, amonst other things and not exclusively, address data. Further data protection related information can be obtained from the data potection statement of Paypal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

You can object to the processing of your data at any time through a notification of Paypal. In this case, Paypal remains entitled to use your personal data insofar as it is necessary for the processing of your payment.


I. Rights of the data subject

When your personal data is processed, you are the data subject as defined by the GDPR and you have the following rights in relation to us (“the controller”):

1) Right to information

You may demand from the controller confirmation as to whether personal data relating to you is processed by us.

If there is such processing, you may demand the following information from the controller:

  1. The purposes for which personal data is processed.
  2. The categories of personal data processed.
  3. The recipients or categories of recipients to whom personal data relating to you has been or will be disclosed.
  4. The planned duration of storage of your personal data or, if it is not possible to provide any concrete information about this, criteria for determining the duration of storage.
  5. The existence of a right to correction or deletion of your personal data, of a right to restriction of processing by the controller or a right to object to this processing.
  6. The existence of the right to lodge a complaint with a regulatory authority.
  7. All available information about the origin of the data if personal data is not obtained from the data subject.
  8. The existence of automated decision-making including profiling in accordance with Art. 22 (1) and (4) of the GDPR and – at least in these cases – conclusive information about the logic involved as well as the implications and the intended effects of such processing for the data subject.

You have the right to demand information concerning whether personal data relating to you is transferred to a third country or an international organisation. In this context you may demand to be informed about suitable guarantees in accordance with Art. 46 of the GDPR in connection with the transfer. 

2) Right to correction 

You have the right in relation to the controller to correction and/or completion insofar as personal data relating to you is incorrect or incomplete. The controller must make the correction immediately.

3) Right to deletion

3.1) You may demand from the controller that personal data relating to you be deleted immediately, whereupon the controller is required to delete this data immediately insofar as one of the following reasons applies:

 

  1. The personal data relating to you is no longer needed for the purposes for which it was obtained or otherwise processed.
  2. You revoke your consent on which the processing was based in accordance with Art. 6 (1) a of the GDPR or Art. 9 (2) a of the GDPR, and there is no other legal basis for the processing. 
  3. You lodge an objection in accordance with Art. 21 (1) of the GDPR against the processing and there are no overriding justified grounds for the processing, or you lodge an objection against the processing in accordance with Art. 21 (2) of the GDPR.
  4. The personal data relating to you has been processed illegally.
  5. Deletion of the personal data relating to you is required for fulfilment of a legal obligation in accordance with EU law or the law of Member States to which the controller is subject.
  6.  The personal data relating to you was obtained in relation to the services offered by the information society in accordance with Art. 8 (1) GDPR.

 

3.2) If the controller has disclosed personal data relating to you and the data controller is required to delete it in accordance with Art. 17 (1) GDPR, he must take reasonable measures, including measures of a technical nature, taking into account the available technology and implementation costs, to inform the parties responsible for the data processing that you as the data subject have demanded from them deletion of all links to this personal data or copies or replications of this personal data. 

3.3) The right to deletion does not exist insofar as the processing is necessary

  1. To exercise the right to freedom of expression and information
  2. To fulfil a legal obligation that requires the processing under the law of the EU or of the Member States to which the controller is subject or to carry out a task that is in the public interest or that is carried out in the exercise of official authority that has been transferred to the controller
  3. For reasons of public interest in the sphere of public health in accordance with Art. 9 (2) h and i as well as Art. 9 (3) of the GDPR
  4. For archiving purposes in the public interest, scientific or historic research purposes or for statistical purposes in accordance with Art. 89 (1) of the GDPR insofar as the right stated in (1) is expected to make realisation of these objectives impossible or seriously impede them or
  5. For assertion, exercise or defence of legal claims

4) Right to restriction of processing

Under the following conditions you may demand restriction of processing of personal data relating to you:

  1. If you dispute the correctness of the personal data relating to you for a duration that allows the controller to check the correctness of the personal data.
  2. The processing is illegal and you reject deletion of the personal data and instead demand restriction of use of the personal data.
  3. The controller no longer needs the personal data for the purposes of processing but you nevertheless require it for assertion, exercise or defence of legal claims.
  4. If you have lodged an objection against processing in accordance with Art. 21 (1) GDPR and it is not yet established whether the controller's justified interests outweigh your reasons.

If processing of the personal data relating to you has been restricted, this data may – apart from storage – be processed only with your consent or for assertion, exercise or defence of legal claims or for the protection of rights of another natural person or legal entity or for reasons of an important public interest of the European Union or of a Member State.

If processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restrictions are lifted.

5) Right to be informed

If you have asserted the right to correction, deletion or restriction of processing in relation to the controller, the latter is required to notify all recipients, to whom the personal data relating to you has been disclosed, about this correction or deletion of data or restriction of processing unless it proves to be impossible or entails inordinate expenditure.

You have the right in relation to the controller to be informed about these recipients.

6) Right to data portability

You have the right to receive the personal data relating to you, which you have provided to the controller, in a structured, common, machine-readable format. You also have the right to transfer this data to another controller, without obstruction by the controller to whom you have provided the personal data, insofar as

  1. The processing is based on consent in accordance with Art. 6 (1) a GDPR or Art. 9 (2) a GDPR or on a contract in accordance with Art. 6 (1) b GDPR and
  2. Processing is carried out by an automated process

When exercising this right you also have the right to arrange to receive the personal data relating to you directly from another controller insofar as this is technically feasible. Rights and freedoms of other persons must not be affected by this.

The right to data portability does not apply to processing of personal data required to carry out a task in the public interest or which is carried out in the exercise of official authority that has been transferred to the controller.

7) Right of objection

You have the right, for reasons arising from your particular situation, to lodge an objection at any time to processing of personal data relating to you which takes place on the basis of Art. 6 (1) e or f GDPR; this also applies to profiling based on these provisions. 

After an objection the controller will no longer process the personal data relating to you unless he can prove compelling reasons for the processing that warrant protection that outweigh your interests, rights and freedoms or the processing serves the purpose of asserting, exercising or defending legal claims.

8) Right to revoke the declaration of consent under data protection law

You have the right to revoke your declaration of consent under data protection law at any time. Revocation of consent does not affect the legality of processing carried out on the basis of consent up to the time of revocation.

9) Automated decision-making in the individual case including profiling

You have the right to refuse to be subject to a decision based exclusively on automated processing – including profiling – that has a legal effect for you or which affects you substantially in a similar way. This does not apply if the decision 

  1. Is necessary for conclusion or fulfilment of a contract between you and the controller.
  2. Is permissible on the basis of legal regulations of the European Union or Member States to which the controller is subject and these legal regulations include appropriate measures to safeguard your rights and freedoms as well as your justified interests.
  3. Is taken with your express consent.

However, these decisions must not be based on specific categories of personal data in accordance with Art 9 (1) GDPR insofar as Art 9 (2) a or g does not apply and appropriate measures have been taken for the protection of rights and freedoms as well as your justified interests.

With regard to the cases stated in a. and c. the controller must take suitable measures to safeguard rights and freedoms as well as your justified interests which includes as a minimum the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.

10) Right to lodge a complaint with a regulatory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a regulatory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.

The regulatory authority receiving the complaint will inform the person lodging the complaint about the status and the result of the complaint, including the possibility of a legal recourse in accordance with Art. 78 GDPR.