Privacy Notice
We are delighted about your interest in our online shop. Protecting your privacy is very important to us. Below you will find detailed information on how we handle your data. Your data will be processed on the basis of regulation (EU) 2016/679 of the European Parliament and of the Council – General Data Protection Regulation (GDPR).
Controller (Art. 4 (7) GDPR) is:
Onlineprinters GmbH
Dr.-Mack-Straße 83
90762 Fürth
Germany
1. Visiting our online shop
You can visit our online shops without providing any personal data. Each time you visit a website, the web server stores automatically only a so-called server log file which contains e.g. the name of the requested file, your IP address, the date and time of the request, the volume of data transferred and the requesting provider (access data), and documents the request. This serves according to Art. 6 (1) (f) GDPR the protection of our – within the frame of balancing of interests – overriding legitimate interests in the smooth operation of the website and the proper presentation of our offer.
1.1 Hosting
All data collected within the scope of using our online shops are stored on servers of WEBSALE AG, Gutenstetter Straße 2, 90449 Nürnberg, Germany, within the scope of processing on our behalf. Services that are processed on different servers will be explained below.
1.2 Geolocalisation
If you consent to this by clicking the corresponding button, the country from which you visit our website will be determined based on your IP address in order to redirect you to an offer tailored to your location and language where appropriate. The data processed here will be erased when you close your browser.
2. Collection of personal data
We collect personal data when you give them to us voluntarily in the context of your order, when you contact us or when you open a customer account. Which data are collected can be seen in the input forms. Mandatory fields are identified as such since, in accordance with Art. 6 (1) (b) GDPR, these data are absolutely necessary for processing your contact request, for opening the customer account or for contract performance.
After complete performance of the contract or closing your customer account, your data will be restricted for further processing and erased after the expiration of any fiscal or commercial statutory retention periods, unless you have expressly consented to continued use of your data or we reserve use of the data extending beyond this that is permitted by law and of which we inform you in this notice. Closing your customer account is possible by using the function provided for this purpose in the customer account or by sending a message to us.
3. Forwarding of data
3.1 Payment processing
Depending on the payment method you select in the ordering process, you will be redirected to the respective payment service provider who will collect the data required for payment itself. You have to set up an account with the payment service provider or log on to an existing account. Then, the respective provider’s privacy policy will apply. The payment service provider will only inform us that payment has been made so that we can continue the ordering process. We might require your payment data for payment processing. This is a necessary step to perform the contract in accordance with Art. 6 (1) (b) GDPR.
3.2 Credit check
3.2.1 payments after receipt of invoice or a direct debit
If we make deliveries prior to payment, e.g. in the case of payments after receipt of invoice or a direct debit, it is necessary for conclusion of the contract to obtain identity and creditworthiness information from specialised service providers (credit reference agencies). In accordance with Art. 6 (1) (f) GDPR, this serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests in avoiding or minimising defaults of payment. For this purpose, we will transfer your personal data required for a credit check to the following company/companies:
Creditsafe Deutschland GmbH, Schreiberhauer Straße 30, 10317 Berlin, Germany, Phone +49 30473929-000
3.2.2 Payment with Klarna
By selecting the "Klarna" payment option, you consent to the transmission of the following data for payment processing to our partner Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna") when clicking the "Buy" button for completing your order:
- Personal data and contact information: information on the identity of the purchaser (address, title, first and last name, telephone number, e-mail address)
- Transaction-related data: invoice amount and payment term, details of products you order, such as order number, quantity, shopping cart and invoice information, existing customer status.
Klarna uses the data provided to check which payment options they can offer. Klarna obtains information from credit agencies to verify your identity and creditworthiness. For details on how Klarna processes your data, please refer to the provider's information on data protection at www.klarna.com.
Klarna also uses your data to send you messages regarding payment processing.
You may revoke your consent to the transfer of data given during the ordering process with respect to Onlineprinters at any time with effect for the future, even without stating any reason.
3.3 Print data containing personal data
We will forward the artwork provided by you to print production on your behalf. The processing serves to perform the contract in accordance with Article 6(1)(1)(b) GDPR. Since these data may contain third-party personal data, we will provide you with a GDPR-compliant “Agreement on the Processing of Personal Data on behalf of the Controller” in accordance with Article 28 GDPR for the respective order. You can view and examine the content of the agreement on the product page before selecting the artwork options and immediately before checkout. The document will be attached (PDF) to the order confirmation which you will receive by e-mail immediately after placing your order.
3.4 -not applicable-
3.5 Data transfer to third countries
If data are transferred to servers provided by the following providers in third countries with your consent or to safeguard our – within the frame of balancing of interests – overriding legitimate interests, our cooperation with these providers will be based on the EU-US Data Privacy Framework in accordance with Article 45 GDPR and, in addition, on standard data protection clauses adopted by the European Commission in accordance with Article 46 GDPR unless otherwise specified in this privacy notice.
- Google services stated in this notice: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Information on their privacy policy: https://policies.google.com/privacy?hl=en
- Microsoft services (Bing) stated in this Data Privacy Statement: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland and Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Information on their privacy policy: https://privacy.microsoft.com/en-us/privacystatement
- Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland and Adobe Inc. 345 Park Avenue, San Jose, CA 95110-2704, USA. Information on their privacy policy: https://www.adobe.com/uk/privacy.html
- LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland and LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. Information on their privacy policy: https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
- Meta services stated in this notice: Meta Platforms Ireland Limited, Merrion Road , Dublin 4, D04 X2K5, Irland and Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Information on their privacy policy: https://en-gb.facebook.com/privacy/explanation
3.6 List of sanctions review
As a company based in the European Union, we are obliged to check whether services are related to a sanctioned natural or legal person (EU CFSP sanctions lists). The processing of personal data of a data subject (surname, first name, company name) will be carried out in accordance with Art. 6 (1) (c) GDPR in conjunction with Regulation (EC) No. 2580/2001. According to Art. 6 (1) (f) GDPR, this also serves to protect our legitimate prevailing interests to guarantee compliance with the above duties within the scope of a weighing of interests.
4. E-mail and postal advertising
We use the data submitted by you to send you information on our offers and services by e-mail or by letter. If this is not or no longer what you want, we quite understand it. Simply send your revocation or objection to our customer service or use any other contact option we offer. You can unsubscribe with just one click at the end of all our promotional e-mails. Of course, you will not incur any costs as a result of this.
4.1 Promotional approach by e-mail
We use the system by the Germany-based company Inxmail GmbH to send promotional e-mails. To ensure secure handling of your data, we have concluded an order processing agreement pursuant to Art. 28 GDPR.
We wish to send you only the information that may be of interest to you. We also do our best to ensure high technical quality of our e-mails to avoid their ending up in your junk e-mail folder. This is why our e-mails contain evaluable links to our offers as well as so-called tracking pixels that give us information about opening the message.
4.1.1 E-mail newsletter subscription
If you subscribe to our newsletter, we will send it to you on a regular basis. We will address you by your name if you optionally provide it to us. This requires your consent pursuant to Art. 6 para. 1 s. 1 (a) GDPR.
4.1.2 Product recommendations by e-mail
Once you have bought one of our products, we will send you e-mails with recommendations on similar products from our range if you have not objected. This is based on our overriding legitimate interests in a promotional approach to our customers pursuant to Art. 6 para. 1 s. 1 (f) GDPR.
4.2 Postal advertising
We use your postal address to send you offers and information on our products and services by letter mail. This is based on our overriding legitimate interests in a promotional approach pursuant to Art. 6 para. 1 s. 1 (f) GDPR.
5. Cookies – Consent and Management
So-called cookies help us to ensure that your visit to our online shop turns into a pleasant shopping experience. Cookies are small text files that can be stored on your terminal device.
We use a Consent Management Service to inform you in detail about the cookie technologies stated below and to obtain, manage and document your consent to the processing of your personal data using technologies that require consent. This is necessary to fulfil the legal obligation we are subject to in accordance with Art. 6 (1) (c) GDPR in order to be able to prove your consent in accordance with Art. 7 (1) GDPR.
Refusal and withdrawal
You can of course also configure every not strictly necessary cookie individually using the Consent Management Service. Detailed provider information can also be found in the Consent Management Service, which we will provide to you when you visit our online shop for the first time and for the future.
5.1 Necessary cookies
Thanks to technically necessary cookies, our online shop works optimally. They enable essential basic functions such as navigation on the website or correct display in your Internet browser and therefore cannot be deactivated. This serves to safeguard our – within the frame of balancing of interests – overriding legitimate interests in the optimal presentation of our offer pursuant to Art. 6 (1) (f) GDPR.
Usercentrics Consent Management Platform
The necessary Consent Management Service is provided by Usercentrics GmbH, Rosental 4, 80331 München, Germany, who process your data on our behalf. When our website is visited, the web server of Usercentrics GmbH stores a so-called server log file, which also contains your anonymised IP address, date and time of the visit, device and browser information as well as information on your consent behaviour.
Google Tag Manager
We use the Google Tag Manager to manage the services regarding usage-based advertising. The Tag Manager itself is a domain without any cookies and does not collect any personal data.
Google reCAPTCHA
The Google reCAPTCHA function serves for abuse prevention. The service checks whether the data entered on a website originate from a human being or from an automated program.
Adobe Fonts
Adobe Fonts is a font service by Adobe Systems Software Ireland Limited. It provides access to a font library and enables us to load appropriate fonts. Adobe uses the information from websites using Adobe Fonts to provide the “Adobe Fonts” service and to diagnose delivery or download problems
Google Fonts
When you visit our website, the browser establishes a connection to the Google servers while loading. In this process, your browser transfers various information to enable uniform display of the website. The font files will be stored on the used terminal device for one year. This improves the loading times of the websites on which Google fonts are used.
Onlineprinters cookies
In order to make communication between our online shop and you more comfortable, we store application data (IDs and flags) in the local cache of your browser. For example, the browser remembers whether a visitor has already set specific cookies. Thus, the respective cookie window will not be opened again every time you revisit the website.
Websale cookies
The cookies of our hosting provider Websale are technically necessary cookies which contribute to our website working optimally. The cookies enable essential basic functions such as navigation, registration or shopping cart control, but also protective functions against potential attacks. Our hosting provider is WEBSALE AG, Gutenstetter Straße 2, 90449 Nürnberg, Germany.
5.2 Functionality cookies
Functionality cookies enable us to improve the user friendliness of our online shop. With your consent in accordance with Art. 6 (1) (a) GDPR, we will use these cookies to present our products and contents in such a way to you that your visit to our website turns into a pleasant shopping experience.
Userlike chat tool
The Userlike chat tool can be used as an alternative to the contact form to chat live with our Customer Service if you have any questions about our offer. For this purpose, a chat widget in the form of source code will be loaded to and executed on your terminal device to enable the chat. This is provided by Userlike UG, Probsteigasse 44-46, 50670 Cologne, Germany (www.userlike.com).
Kameleoon
Kameleoon is a service for website optimisation and analysis. It allows us to compare the use of different design options of elements of our website in order to optimise our online shops and increase visitor satisfaction based on these insights. If you have given your consent, with the technologies similar to browser cookies the information about your use of our online shop will be transferred to a Kameleoon server in Germany and stored there in a pseudonymised form for a maximum of one year. Your IP address will be completely anonymised and will not be stored. This is an offer by Kameleoon GmbH, Beim Alten Ausbesserungswerk 4, 77654 Offenburg, Germany. Information on their privacy policy is provided at www.kameleoon.com
5.3 Statistics cookies
Pseudonymised information helps us to tailor our offer even better to your needs. With your consent in accordance with Art. 6 (1) (a) GDPR, we will use statistics cookies which analyse how often specific functions of our website are used. They also help us to understand what content and products on our website are of particular interest to you.
Google Analytics
Google Analytics is a web analytics service which helps to better understand the use of the website by the visitors in order to develop optimisation strategies from that. The thus gathered usage information for this website will be transferred to Google and stored there. By activating IP anonymisation on this website, the IP address will be shortened before transfer within the EU member states or other EEA states. Only in exceptional cases will the full IP address be transferred to a Google server and shortened there.
Google (Universal) Analytics is integrated as a sub-processor by our partner Trakken Web Services GmbH who takes action within the scope of processing on our behalf in accordance with Art. 28 GDPR.
Google Ads Conversion
We use the online marketing service Google Ads Conversion to place ads in the Google advertising network. For performance measurement, Google provides us with an individual “conversion cookie”, with the help of which statistics are compiled. However, we are only informed of the total number of users that clicked on our ad and were redirected to a specific site with a conversion tracking tag. We do not receive any personal data that would allow us to draw conclusions about the user.
Google Enhanced Conversions Tracking
We use Google Enhanced Conversions Tracking. When you shop with us, your e-mail address is encrypted with your consent by means of a one-way hash algorithm SHA256 and transmitted to Google under a secure pseudonym. If you click on an advertisement placed on Google and are logged into a Google account at the time you click/visit, the hashed data sent by us will be compared by Google with the hashed data of your Google account. This enables Google to provide us with statistical information about the success of our ad. The data will be deleted after 20 days or after your revocation.
Microsoft Conversion Tracking
We use the online marketing service Microsoft Conversion Tracking to place ads in Bing, Yahoo and MSN search results and on third-party websites. For performance measurement, Microsoft provides us with an individual “conversion cookie”, with the help of which statistics are compiled. However, we are only informed of the total number of users that clicked on our ad and were redirected to a specific site with a conversion tracking tag. We do not receive any personal data that would allow us to draw conclusions about the user.
Hotjar
Hotjar is a web analytics service for performance measurement of advertising campaigns which serves to develop optimisation strategies. The thus gathered usage information for this website will be transferred to Hotjar. Then, pseudonymised usage profiles will be generated, which will not be merged with personal data, however, unless separate explicit consent has been given. After the purpose has ceased to exist and we have ended using Hotjar, the data collected in this context will be erased. This is an offer by Hotjar Limited, 3, Elia Zammit Street, St Julians STJ 3155, Malta, Europe (www.hotjar.com).
Microsoft Clarity
Microsoft Clarity is a tool that shows us how users use our website. It helps us to identify possible improvements to offer our customers an ideal shopping experience. As Clarity sets great store by data protection and privacy, we do not have any information about individual users.
5.4 Marketing cookies
With your consent in accordance with Art. 6 (1) (a) GDPR, our marketing cookies will ensure that not too many ads are shown on our partners’ websites, but only those products from our offer you could be particularly interested in.
Google Ads Remarketing and Google Analytics Advertising
We use these services to advertise our website in the Google search results and on third-party websites. For this purpose, the Remarketing cookie is set and/or the Google Analytics cookie is used when this website is visited. In this case, both cookies allow automatic interest-based advertising by means of a pseudonymous cookie ID and on the basis of the sites you have visited. After the purpose has been fulfilled and we have ended using Google Dynamic Remarketing and Google Analytics, the data collected in this context will be erased.
Data processing extending beyond this will only take place if you have consented towards Google that your web and app browser history is connected with your Google account and information from your Google account is used to personalise ads that you see on the web. In this case, if you are logged in to Google when visiting our website, Google will use your data together with Google Analytics data to generate and define target group lists for cross-device remarketing. For this purpose, your personal data will be temporarily linked with Google Analytics data to generate target groups.
Microsoft Advertising Remarketing
We use Microsoft Advertising Remarketing to advertise our website in the Bing, Yahoo, and MSN search results and on third-party websites. For this purpose, a cookie is set when this website is visited that automatically allows interest-based advertising by means of a pseudonymous cookie ID and on the basis of the sites you have visited. After the purpose has ceased to exist and we have ended using Bing Ads, the data collected in this context will be erased.
AWIN
AWIN is a German affiliate network. We use so-called affiliate advertising to provide sales partners with our ads for their websites. The purpose of the cookie – which does not store any personal data – is to enable assessment of commission payments between us and our partners. This is provided by AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany (www.awin.com).
LinkedIn
The LinkedIn Insight Tag is an analysis and tracking tool. We use this tool only if you are forwarded to our website via our LinkedIn ad. When you visit our website, a cookie that collects your IP address, device and browser properties will be set with your consent only. LinkedIn does not share any personal data about its members with our website. All data related to the visitors and ads are pseudonymised summaries only (URL of origin, number of visitors, visit duration, actions taken on our websites). These data will be deleted within 180 days. We use these data to analyse the use of our website after clicking an ad and to deduce improvements for our advertising measures so that we can present relevant contents.
Meta Pixel
We use the Meta Pixel by Meta Platforms Ireland Limited. If you give your consent, with the Meta Pixel your data (IP address, time of visit, device and browser information, data on your use of our website on the basis of the events provided, such as your visit of a website or newsletter subscription) will be automatically collected and stored; from these data, usage profiles will be generated by using pseudonyms. For this purpose, a cookie is set by the Meta Pixel when our website is visited which allows recognising your browser by means of a pseudonymous cookie ID when you visit other websites. In connection with the extended data reconciliation, your e-mail address will be additionally transmitted to Meta in encrypted form (SHA256) and with your consent. Only if you are signed up for Facebook (by Meta) with this e-mail address, Meta will merge this information with other data from your Facebook account and use it to compile reports on website activity and provide other services related to website usage, particularly personalised and group-based advertising.
6. Social Media
Our presence on social networks and platforms serves for better, active communication with our customers and prospective clients as well as to inform about our products and campaigns. You need to actively register with the respective network yourself. Onlineprinters does not forward any personal or usage-based data to these providers. In our online shop, we only place a hyperlink to our pages on the social media networks.
If you granted the respective social media operator your consent in accordance with Art. 6 (1) (a) GDPR, your data will be automatically collected and stored for market research and advertising purposes when you visit these pages, from which usage profiles will be generated by using pseudonyms. These can be used, for example, to place ads inside and outside the platforms that presumably correspond to your interests. Usually, cookies are used for this. For detailed information on the processing and use of the data by the respective social media operator as well as contact information and your relevant rights and setting options to protect your privacy, please refer to the respective privacy policy linked below. Data processing within the scope of a visit to our respective presence is carried out on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR.
Facebook is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta Ireland”). The information on your use of our online presence on Facebook automatically gathered by Meta Ireland will usually be transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. Further information and privacy policy: https://en-gb.facebook.com/privacy/explanation
Instagram is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta Ireland”). The information on your use of our online presence on Instagram gathered automatically by Meta Ireland will usually be transferred to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. Further information and privacy policy: https://help.instagram.com/519522125107875
Google YouTube
YouTube is provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The information on your use of our online presence on YouTube gathered automatically by Google will usually be transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there. Further information and privacy policy: https://policies.google.com/privacy?hl=en-GB
LinkedIn is provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland (“LinkedIn”). The information on your use of our online presence on LinkedIn gathered automatically by LinkedIn will usually be transferred to a server of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA, and stored there. Further information and privacy policy: https://www.linkedin.com/legal/privacy-policy?trk=hb_ft_priv
Xing is a professional network. Xing is provided by New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. Further information and privacy policy: https://privacy.xing.com/en/privacy-policy
7. Your rights
Being the data subject, you have the following rights:
- In accordance with Art. 15 GDPR you have the right to obtain access to your personal data processed by us to the extent specified there;
- in accordance with Art. 16 GDPR you have the right to obtain without undue delay the rectification of inaccurate personal data or completion of incomplete personal data stored by us;
- in accordance with Art. 17 GDPR you have the right to erasure of your personal data stored by us, unless further processing is required
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation;
- for reasons of public interest; or
- for the establishment, exercise, or defence of legal claims;
- in accordance with Art. 18 GDPR you have the right to request restriction of processing of your personal data if
- you contest the accuracy of the personal data;
- the processing is unlawful but you oppose their erasure;
- we no longer require the data but you require them for the establishment, exercise, or defence of legal claims; or
- you have objected to processing in accordance with Art. 21 GDPR;
- in accordance with Art. 20 GDPR you have the right to receive the personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request transmission to another controller;
- in accordance with Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority. Usually you may approach the supervisory authority at your habitual residence or place of work or company domicile.
Right to object
Insofar as we process personal data as explained above to safeguard our – within the frame of balancing of interests – overriding legitimate interests, you may object to this processing with effect for the future. If the processing takes place for the purpose of direct marketing, you may exercise this right at any time as described above. If the processing takes place for other purposes, you only have a right to object on grounds related to your particular situation. After you have exercised your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise, or defence of legal claims. This does not apply if the processing takes place for the purpose of direct marketing. In this case, we will no longer process your personal data for this purpose.
8. Contact Data Protection Officer
If you have any questions regarding the collection, processing, or use of your personal data, for information, rectification, restriction of processing, or erasure of data, revocation of given consents, or objection to specific use of data, please contact our company Data Protection Officer (DPO):
Onlineprinters GmbH
Andreas Neuer
Dr.-Mack-Straße 83
90762 Fürth
Germany
2024-09-24