Privacy policy
General
As the operator of this website and as a company, we come into contact with your personal data. This concerns all data that reveals something about you and by which you can be identified. In this privacy policy, we would like to explain how, for what purpose and on which legal basis we process your data.
Responsible for the data processing (“data controller”) on this website and in our company is:
Babsi´s Bio Kräuterwelt
Kandoy House, 2 Fairview Strand, Dublin, Dublin 3,
D03Y1E2 Ireland
Phone: 0000 00000
E-mail: Flora-Astoria@mail.com
General information
How long do we store your data?
In some parts in this privacy policy, we inform you about how long we or the companies that process your data on our behalf will store your data. In the absence of such information, we store your data until the purpose of the data processing no longer applies, you object to the data processing or you revoke your consent to the data processing.
In the event of an objection or revocation, we may however continue to process your data if at least one of the following conditions applies:
- We have compelling legitimate grounds for continuing to process the data that override your interests, rights and freedoms (only applies in the case of an objection to data processing; if the objection is to direct marketing, we cannot provide legitimate grounds).
- The data processing is necessary to assert, exercise or defend legal claims (does not apply if your objection is directed against direct advertising).
- We are required by law to retain your data.
In this case, we will delete your data as soon as the requirement(s) cease to apply.
Data transfer to the USA
On our website, we use tools from companies that transfer your data to the USA and store it there and, if necessary, process it further. The European Commission has adopted an adequacy decision for the EU-US data protection framework. The decision establishes that the US ensures an adequate level of protection for EU personal data transferred to US companies. This decision is based on new safeguards and measures put in place by the US to meet data protection requirements. The adequacy decision includes, among other things, restrictions and safeguards on access to data by US intelligence agencies. Binding safeguards were introduced to limit US intelligence agencies' access to what is necessary and proportionate to protect national security. In addition, enhanced oversight of US intelligence activities was established to ensure that restrictions on surveillance activities are respected. An independent redress mechanism has also been established to handle and resolve complaints from European citizens about access to their data. The EU-US data protection framework thus allows European companies to transfer data to certified US companies without having to introduce additional data protection safeguards. A list of all certified companies can be found at the following link: https://www.dataprivacyframework.gov/s/participant-search.
A change in the European Commission's decision cannot be ruled out.
Your rights
Objection to data processing
IF IT'S STATED IN THIS PRIVACY STATEMENT THAT WE HAVE LEGITIMATE INTERESTS FOR THE PROCESSING OF YOUR DATA AND THAT THIS PROCESSING IS THEREFORE BASED ON ART. 6 PARA. 1 SENTENCE 1 LIT. F) GDPR, YOU HAVE THE RIGHT TO OBJECT IN ACCORDANCE WITH ART. 21 GDPR. THIS ALSO APPLIES TO PROFILING THAT IS CARRIED OUT ON THE BASIS OF THE AFOREMENTIONED PROVISION. THE PREREQUISITE IS THAT YOU STATE REASONS FOR THE OBJECTION THAT ARISE FROM YOUR PARTICULAR SITUATION. NO REASONS ARE REQUIRED IF THE OBJECTION IS DIRECTED AGAINST THE USE OF YOUR DATA FOR DIRECT ADVERTISING.
THE CONSEQUENCE OF THE OBJECTION IS THAT WE MAY NO LONGER PROCESS YOUR DATA. THIS ONLY DOES NOT APPLY IF ONE OF THE FOLLOWING PREREQUISITS EXISTS:
- WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS.
- THE PROCESSING IS NECESSARY FOR ASSERTING, EXERCISING OR DEFENDING LEGAL CLAIMS.
THESE EXCEPTIONS DO NOT APPLY IF YOUR OBJECTION IS DIRECTED AGAINST THE USE OF YOUR DATA FOR DIRECT ADVERTISING OR TO PROFILING RELATED TO IT.
Other rights
Withdrawal of your consent to data processing
Many data processing operations are based on your consent. You can give this consent, for example, by ticking the appropriate box on online forms before you send the form, or by allowing the operation of certain cookies when you visit our website. You may revoke your consent at any time without giving reasons (Art. 7 (3) GDPR). From the time of revocation, we may then no longer process your data. The only exception: we are required by law to retain the data for a certain period of time. Such retention periods exist in particular in tax and commercial law.
Right to complain to the competent supervisory authority
If you believe that we are in breach of the General Data Protection Regulation (GDPR), you have the right to complain to a supervisory authority in accordance with Art. 77 GDPR. You may contact a supervisory authority in the Member State of your residence, place of work or the place where the alleged infringement took place. The right to complain exists alongside administrative or judicial remedies.
Right to data portability
We must hand over data that we process automatically on the basis of your consent or in fulfillment of a contract to you or a third party in a common machine-readable format if you request this. We can only transfer the data to another “data controller” if this is technically possible.
Right to information, deletion, and correction of data
According to Art. 15 GDPR, you have the right to receive information free of charge about which of your personal data we have stored, where the data came from, to whom we transmit the data and for what purpose it is stored. If the data is incorrect, you have a right to rectification (Art. 16 GDPR), and under the conditions of Art. 17 GDPR you may demand that we delete the data.
Right to restriction of processing
In certain situations, according to Art. 18 GDPR, you may demand that we restrict the processing of your data. The data may then - apart from storage - only be processed as follows:
- with your consent
- for the assertion, exercise or defense of legal claims
- to protect the rights of another natural or legal person
- for reasons of important public interest of the European Union or a Member State.
The right to restrict processing exists in the following situations:
- You have disputed the accuracy of your personal data stored by us and we need time to verify this. The right exists for the duration of the review.
- The processing of your personal data is unlawful or was unlawful in the past. The right exists alternatively to the deletion of the data.
- We no longer need your personal data, but you need it to exercise, defend or assert legal claims. The right exists alternatively to the deletion of the data.
- You have filed an objection pursuant to Art. 21 (1) GDPR and now your interests and our interests must be weighed against each other. The right exists as long as the result of the balancing of interests has not yet been determined.
Hosting and Content Delivery Networks (CDN)
External hosting
Our website is hosted on a server of the following Internet service provider (hoster):
Iwanow-IT
Borsigstraße 10
65205 Wiesbaden
Has a data processing agreement been concluded with the hoster or are standard contractual clauses (SCC) in place?
Yes
How do we process your data?
The hoster stores all the data from our website. This includes all personal data that is collected automatically or through entering. This can be in particular: Your IP address, pages accessed, names, contact details and requests, as well as meta and communication data. When processing data, our hoster adheres to our instructions and always processes the data only insofar as this is necessary to fulfill the service obligation to us.
On what legal basis do we process your data?
Since we address potential customers via our website and maintain contacts with existing customers, the data processing by our hoster serves to initiate and fulfill contracts and is therefore based on Art. 6 (1) lit. b) GDPR. In addition, it is our legitimate interest as a company to provide a professional Internet offering that meets the necessary requirements for security, speed and efficiency. In this respect, we also process your data on the legal basis of Art. 6 (1) lit. f) GDPR.
Data collection on this website
Use of cookies
Our website places cookies on your device. These are small text files that are used for various purposes. Some cookies are technically necessary for the website to function at all (necessary cookies). Others are needed to perform certain actions or functions on the site (functional cookies). For example, without cookies it would not be possible to take advantage of a shopping cart in an online store. Still other cookies are used to analyze user behavior or to optimize advertising measures. If we use third-party services on our website, for example to process payment transactions, these companies may also leave cookies on your device when you access the website (so-called third-party cookies).
How do we process your data?
Session cookies are only stored on your device for the duration of a session. As soon as you close the browser, they therefore disappear by themselves. Permanent cookies, on the other hand, remain on your device unless you delete them yourself. This can, for example, lead to your user behavior being permanently analyzed. You can use the settings in your browser to influence how it handles cookies:
- Do you want to be informed when cookies are set?
- Do you want to exclude cookies in general or for certain cases?
- Do you want cookies to be deleted automatically when you close the browser?
If you disable or do not allow cookies, the functionality of the website may be limited.
If we use cookies from other companies or for analysis purposes, we will inform you about this as part of this privacy policy. We also request your consent in this regard when you access our website.
On what legal basis do we process your data?
We have a legitimate interest in ensuring that our online offers can be used by visitors without technical problems and that all desired functions are available to them. The storage of necessary and functional cookies on your device therefore takes place on the legal basis of Art. 6 (1) lit. f) GDPR. We use all other cookies on the legal basis of Art. 6 (1) lit. a) GDPR, provided you give us your consent. You can revoke this at any time with effect for the future. If you have consented to the placement of necessary and functional cookies when requesting consent, these cookies will also be stored exclusively on the basis of your consent.
Cookie consent with Legal Cockpit
What is the Legal Cockpit cookie tool?
Consent management platform (CMP) for obtaining and processing GDPR-compliant consent.
Who processes your data?
Legalcore AG, Reinhardtstr. 7, 10117 Berlin, Germany
Has a data processing agreement been concluded with Legal Cockpit?
Yes
Where can you find more information about data protection at Legal Cockpit?
https://cockpit.legal/datenschutz/
How do we process your data?
We use Legal Cockpit's consent management platform to obtain your consent to store cookies on your device in a data protection compliant manner. When you visit our website and close the Legal Cockpit cookie window requesting consent, the following data is transmitted to the company:
- your IP address
- information about your browser
- information about your terminal device
- the time of your visit to the website
In addition, the Legal Cockpit stores a cookie in your browser in order to be able to assign the consent given or its revocation to your browser. All collected data is stored until the cookies are no longer needed, you delete the Legal Cockpit cookie or request us to delete the data. This does not apply only if we are required by law to retain the data.
On what legal basis do we process your data?
We are legally obliged to obtain the consent of our website visitors for the use of certain cookies. In order to fulfill this obligation, we use Legal Cockpit. The legal basis for data processing is therefore Art. 6 (1) lit. c) GDPR.
Server log files
Server log files log all requests and accesses to our website and record error messages. They also include personal data, in particular your IP address. However, this is anonymized by the provider after a short time, so that we cannot assign the data to your person. The data is automatically transmitted to our provider by your browser.
How do we process your data?
Our provider stores the server log files in order to be able to track the activities on our website and to locate errors. The files contain the following data:
- browser type and version
- operating system used
- referrer URL
- host name of the accessing computer
- Time of the server request
- IP address (anonymized if necessary)
We do not combine this data with other data but use it only for statistical analysis and to improve our website.
On what legal basis do we process your data?
We have a legitimate interest in ensuring that our website runs without errors. It is also our legitimate interest to obtain an anonymized overview of the accesses to our website. Therefore, the data processing is lawful according to Art. 6 (1) lit. f) GDPR.
Contact form
You can send us a message via the contact form on this website.
How do we process your data?
We store your message and the information from the form in order to process your request including follow-up questions. This also applies to the contact details provided. We do not pass on the data to other persons without your consent.
How long do we store your data?
We delete your data as soon as one of the following occurs:
- Your request has been conclusively processed.
- You request us to delete the data.
- You revoke your consent to the storage.
This does not apply only if we are required by law to retain the data.
On what legal basis do we process your data?
If your request is related to our contractual relationship or serves the implementation of pre-contractual measures, we process your data on the legal basis of Art. 6 (1) lit. b) GDPR. In all other cases, it is our legitimate interest to effectively process requests directed to us. The legal basis for data processing is therefore Art. 6 (1) lit. f) GDPR. If you have consented to the storage of your data, Art. 6 (1) lit. a) GDPR is the legal basis. In this case, you can revoke your consent at any time with effect for the future.
Inquiry by e-mail, telephone or fax
You can send us a message by e-mail or fax or call us.
How do we process your data?
We store your message as well as your self-made contact details or the transmitted telephone number in order to be able to process your inquiry including follow-up questions. We do not pass on the data to other persons without your consent.
How long do we store your data?
We delete your data as soon as one of the following occurs:
- Your inquiry has been conclusively processed.
- You request us to delete the data.
- You revoke your consent to the storage.
This does not apply only if we are required by law to retain the data.
On what legal basis do we process your data?
If your request is related to our contractual relationship or serves the implementation of pre-contractual measures, we process your data on the legal basis of Art. 6 (1) lit. b) GDPR. In all other cases, it is our legitimate interest to effectively process requests directed to us. The legal basis for data processing is therefore Art. 6 (1) lit. f) GDPR. If you have consented to the storage of your data, Art. 6 (1) lit. a) GDPR is the legal basis. In this case, you can revoke your consent at any time with effect for the future.
Analysis tools and advertising
We use the following tools to analyze the behavior of our website visitors and show you advertisements.
Google Analytics
What is Google Analytics?
Tool for analyzing user behavior of Google Ireland Ltd.
Who processes your data?
Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland.
Has a data processing agreement been concluded with Google Analytics?
Yes
Where can you find more information about Google Analytics data protection?
https://support.google.com/analytics/answer/6004245?hl=en
On what legal basis do we transfer your data to the USA?
On the basis of the European Commission's adequacy decision and the company's corresponding certification.
How can you prevent data collection?
Among other things, with a browser plugin: https://tools.google.com/dlpage/gaoptout?hl=en
How do we process your data?
We are always interested in optimizing our web offer for visitors to our website and placing advertisements in the best possible way. We are helped in this by Google Analytics, a tool that analyzes the behavior of users and thus provides us with the necessary database for adjustments. Through the tool, we receive information about the origin of our visitors, their page views and the time they spend on the pages, as well as the operating system they use.
Standard processing
To collect the data, Google Analytics uses cookies, device fingerprinting or other user recognition technologies. The data is transmitted to Google servers in the USA and, with the help of the IP address that is also collected, summarized in a profile that can be assigned to you or your device.
You can prevent Google from processing your data by installing a browser plugin that Google itself provides: https://tools.google.com/dlpage/gaoptout?hl=de.
IP anonymization
We have activated the "IP anonymization" function within Google Analytics. For you, this means that Google truncates your IP address (from the EU or EEA) before transmitting it to the USA. Only in exceptional cases does Google transmit the full IP address to servers in the USA and only shorten it there.
How long do we store your data?
According to its own information, Google deletes or anonymizes data stored at user and event level that is linked to cookies, user identifiers (e.g. user IDs) or advertising IDs after 14 months (cf. https://support.google.com/analytics/answer/7667196?hl=de).
On what legal basis do we process your data?
As a website operator, we have a legitimate interest in analyzing user behavior for the purpose of optimizing our website and the advertising placed there. The data processing is therefore lawful according to Art. 6 (1) lit. f) GDPR. In the event that you have consented, for example, to the storage of cookies or have otherwise consented to data processing by Google Analytics, only Art. 6 (1) lit. a) GDPR is the legal basis. You can revoke your consent at any time with effect for the future.
WP Statistics
How do we process your data?
We are always interested in optimizing our website for users and placing advertising optimally. We are helped in this by the plugin WP Statistics, which analyzes the behavior of users and thus provides us with the necessary database for adjustments. The provider is Veronalabs, ARENCO Tower, 27th Floor, Dubai Media City, Dubai, Dubai 23816, United Arab Emirates. WP Statistics collects the following data, among others:
- IP address
- referrer
- Browser used
- origin of the user
- search engine used
- clicks, page views and other actions
The data is only stored locally.
On what legal basis do we process your data?
As a website operator, we have a legitimate interest in analyzing user behavior for the purpose of optimizing our website and the advertising placed there. The data processing is therefore lawful according to Art. 6 para. 1 lit. f) GDPR. In the event that you have, for example, consented to the storage of cookies or otherwise consented to data processing, the legal basis is exclusively Art. 6 (1) lit. a) GDPR. You can revoke your consent at any time with effect for the future.
Plugins and tools
Google Fonts (local hosting)
We use fonts from the US company Google on our website. We have installed the fonts locally, so there is no connection to Google's servers when you visit our website.
For more information about Google Fonts, please visit https://developers.google.com/fonts/faq and read Google's privacy policy: https://policies.google.com/privacy?hl=de.
Manage WP
What is Manage WP?
Website management system
Who processes your data?
GoDaddy.com WP Europe, Trg republike 5, 11000 Belgrade, Serbia
Where can you find more information about data protection at Manage WP?
How do we process your data?
With ManageWP, we can monitor the security and performance of our website and initiate automatic backups, among other things. ManageWP thus has access to all website content, including our databases. ManageWP is hosted on the provider's servers.
On what legal basis do we process your data?
As a website operator, we have a legitimate interest in operating our website effectively. The data processing is therefore lawful according to Art. 6 (1) lit. f) GDPR.
In the event that you have consented to data processing, only Art. 6 (1) lit. a) GDPR is the legal basis. You can revoke your consent at any time with effect for the future. From the time of revocation, we may no longer process your data.
eCommerce and payment providers
Data transfer for the shipment of goods
How do we process your data?
When you order goods from us, we transmit your data to companies that we commission with the delivery and/or through which we process the payment. In doing so, only data that is necessary for the commissioned company to carry out the specific order will be transmitted. If we want to pass on data beyond this, we will obtain your consent. We do not pass on your data for advertising purposes.
On what legal basis do we process your data?
We pass on your data in order to fulfill the contract we have concluded with you. The basis of the data processing is therefore Art. 6 (1) lit. b) GDPR.
Payment services
To enable you to conveniently pay for your purchases on our website, we use the services of payment services, i.e. external companies that process the payments for us. You can see which ones these are specifically from the list at the end of this section.
How do we process your data?
For the payment process, you must provide certain personal data, e.g. your name, your account details or credit card number. We pass this data on to the respective payment service. For the transaction itself, the respective contract and data protection provisions of the respective services apply.
On what legal basis do we process your data?
We pass on your data in order to fulfill the contract we have concluded with you. The basis of the data processing is therefore Art. 6 (1) lit. b) GDPR. In addition, we have a legitimate interest in processing purchases as quickly, conveniently and securely as possible. In this respect, the legal basis is also Art. 6 (1) lit. f) GDPR. If you have consented to the transfer of your data, the data processing is based on Art. 6 (1) lit. a) GDPR. You can revoke your consent at any time with effect for the future.
Which payment services do we use?
Sofortüberweisung
What is Sofortüberweisung?
Online payment method that works like a bank transfer, but where a third company is interposed and confirms the payment to us as the seller.
Who processes your data?
Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany (Sofort GmbH is part of the Klarna Group).
Where can you find more information about data protection at Sofortüberweisung?
https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/
The website was created by Iwanov-IT.