In the following, we inform you about the processing of your personal data via the website www.porthy.com (hereinafter "website") and about the rights you are entitled to. Personal data is any information relating to an identified or identifiable natural person, such as name, address, e-mail address, user behavior or even IP address.
1. person responsible
Responsible for the processing of your personal data is TuBe UG, Von-Möller-Strasse 63, 33649 Bielefeld, e-mail address: firstname.lastname@example.org (hereinafter: "we").
2. Data processing
a) Browser data
Each time you access our website, the following personal data is processed automatically:
- IP address,
- The date and time of the request,
- Browser type and version used,
- Operating system used,
- Request details and destination address,
- Content of the request (specific page),
- Website from which the request comes,
- Name of the file requested and amount of data transferred,
- Message whether the retrieval was successful (HTTP status code)
The data processing serves the purpose and our interest to properly display our website to you. For this purpose, your IP address must remain stored for the duration of the session. We delete your IP address after four weeks. We store it for four weeks so that we can pursue legal violations in the event of security deficiencies. After the end of the four-week retention period, the IP addresses are deleted immediately. The collection of data for the provision of the website is mandatory for the operation of the website. Legal basis for data processing is Art. 6 para.1 lit. f DS-GVO.
When using our website, cookies are stored on your computer. Cookies are small text files that are stored on your hard drive assigned to the browser you are using. Through this, certain information can flow to us.
The most common types of cookies are explained below:
- Session cookies: While you are active on a website, a session cookie is temporarily stored in the memory of your computer, in which a session identifier is stored, for example, to prevent you from having to log in again each time you change pages. Session cookies are deleted when you log out or lose their validity as soon as their session has automatically expired. Similarly, we proceed with so-called function cookies. If you are active on the website, certain functions, such as language options, are controlled and stored via function cookies.
- Permanent or protocol cookies: A permanent or protocol cookie stores a file on your computer for the period of time specified in the expiration date. Through these cookies, websites remember your information and settings the next time you visit. As a result, you can access the site faster and more conveniently, for example, because you do not have to set your language preference again. With the passing of the expiration date, the cookie is automatically deleted when you visit the website that generated it.
- Third-party cookies: Third-party cookies come from providers other than the website operator. They can be used, for example, to collect information for advertising, custom content and web statistics.
Some elements of our website require that the calling server can be identified even after the page change. The cookies are deleted when the browser is closed. The legal basis for the processing of personal data using these technically necessary cookies is Art. 6 (1) lit. f DS-GVO. The cookies serve our legitimate interest in enabling the use and provision of our website. The cookies are technically necessary for the use of the website.
b) Facebook Pixel and Instagram
For this purpose, we collect and transmit to Facebook information about the web browser or app you are using, your browsing behavior on our and possibly other websites, your IP address or other device ID and Facebook-related identifiers. We are jointly responsible with Facebook for this collection and transmission under data protection law. Here you can find the agreement according to Art. 26 para. 1 p. 2 DS-GVO, which we have agreed with Facebook for the Facebook Pixel. For more information on how it processes personal data when providing this so-called business tool, Facebook provideshere.
When you access our website, your data is collected and transmitted directly by storing a cookie on your terminal device. If you subsequently log in to Facebook or visit our website while logged in, the visit may be noted by Facebook in your Facebook profile. The data collected about you does not allow us to draw any conclusions about your identity. However, the data is stored and processed by Facebook, so that Facebook a connection to the respective user profile is possible.
The processing of your personal data is based on a voluntary and informed consent according to Art. 6 para. 1 lit. a DS-GVO, which you have given by your selection within the cookie banner. You can revoke your consent at any time with effect for the future by clicking on our homepage www.porthy.com on the left side the "Cookie Fingerprint" and make your desired selection.
We also embed content from our Instagram page on our website. Instagram is a service operated by Facebook. If you click on the images, you will automatically be redirected to our Instagram page. The user conditions and privacy policies of the network apply to the use of Instagram. The privacy information can be found here.
c) Google Analytics
The information is usually transferred to a Google server in the USA and stored there. However, due to the activation of the IP anonymization "_anonymizeIp()", your IP address will be truncated beforehand by Google within Member States of the European Union or in other contracting states to the Agreement on the European Economic Area. Nevertheless, the following should be noted: It cannot be guaranteed that data processing is carried out at the same level of protection as within the EU. In this respect, to our knowledge, there is in any case a risk that you will only be able to enforce your rights as a data subject with difficulty. In addition, there is no data protection supervision. In addition, there is a risk of disproportionate access to your data by state security authorities, against which there is no adequate legal protection if you are not a U.S. citizen. We expressly point this out.
Google uses the information to evaluate your use of the website, compiling reports on website activity and providing other services to us relating to website activity and internet usage. The information obtained enables us to improve our offer and make it more interesting for you as a user. Google also uses your personal data for its own purposes and links them, for example, with existing Google accounts, your search history or with usage data from other devices. The transmitted personal data is stored for 14 months. After that, the data will be deleted automatically.
The legal basis for the use of Google Analytics is your informed and voluntary consent in accordance with Art. 6 para. 1 lit. a DS-GVO. You can revoke your consent at any time with effect for the future by clicking on our homepage www.porthy.com on the left side the "Cookie Fingerprint" and make your desired selection. Regardless of this revocation, you can use browser settings to prevent Google from processing personal data.
Our website embeds videos from YouTube. The provider of the video platform is Google Ireland Limited, Gordon House, 4 Barrow Street, Dublin, Ireland. When you visit one of our pages with YouTube content, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited. In addition, YouTube obtains your IP address. This also applies if you are not logged into YouTube or do not have an account with Google. If you are logged in to your Google account on YouTube at the same time, you enable Google to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your Google account on YouTube. The legal basis for the processing of your IP address and related information is your voluntary and informed consent pursuant to Art. 6 (1) lit. a DS-GVO, which you can revoke at any time with effect for the future. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
For the transfer of data to third countries by Google, please refer to the explanations on Google Analytics. More information on the handling of user data can be found in the privacy information of Google here.
3. Ordering process
For the execution of the order we process the personal data entered by you of the following categories:
- first and surname,
- billing and shipping adress,
- payment made.
The processing of these data categories is mandatory for the fulfillment of the contract. This personal data is stored for this purpose until the contract is completed - including the expiry of warranty periods. For the fulfillment of legal obligations from the commercial law, we store some information related to the order beyond the fulfillment of the contract.
Legal basis for data processing is Art. 6 para.1 lit. b DS-GVO, when it comes to the processing of personal data for contract performance and Art. 6 para. 1 lit. c DS-GVO in conjunction with. § 257 HGB, if the commercial law storage obligations are concerned.
If you create a user account to simplify future orders, we may store your master data longer. The legal basis for data processing for the provision of the permanent user account is Art. 6 para.1 lit. a DS-GVO. Consent to the permanent storage can be revoked at any time with effect for the future. You can initiate the deletion of your user account by sending an email to email@example.com.
For our online store, we use the Shopify Shop of Shopify International Ltd, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, a company of Shopify Inc, 151 O'Connor Street, Ground floor, Ottawa, ON, K2P 2L8, Canada. There is a commissioned processing agreement with the company pursuant to Art. 28 (3) DS-GVO. We remain responsible for the data processing. It cannot be ruled out that personal data will be transferred to the third countries Canada and USA. Shopify uses infrastructure components there in each case. For Canada, there is an adequacy decision in accordance with Art. 45 (3) DS-GVO. The level of data protection there is comparable to that within the EU and the EEA.
For the USA, such an adequacy decision does not currently exist. Shopify therefore ensures a level of data protection equivalent to the EU/EEA via appropriate safeguards - standard contractual clauses, Art. 46 (2) c) DS-GVO. Nevertheless, we expressly point out that it cannot be guaranteed that data processing is carried out at the same level of protection as within the EU. In this respect, to our knowledge, there is in any case the risk that you can only enforce your rights as a data subject with difficulty. In addition, there is no data protection supervision. In addition, there is a risk of disproportionate access to your data by state security authorities, against which there is no adequate legal protection if you are not a U.S. citizen. We expressly point this out.
The payment of the order can be made using different payment services that we have integrated on our site, such as Amazon Pay and PayPal. The payment is processed in accordance with the respective existing privacy information of these payment service providers. We do not store any payment information and have no access to your payment data.
For the commissioning of shipping and delivery of shipments, we resort to the service of Billbee GmbH, Paulinenstrasse 54, 32756 Detmold. Billbeefacilitates the communication with our shipping partners UPS and DHL and thus the processing of the shipment of orders. There is an order processing agreement with the company according to Art. 28 para. 3 DS-GVO. We remain responsible for the data processing. The transmission of your personal data to the shipping partner - DHL Paket GmbH or UPS - is carried out for the execution of the contract based on Art. 6 para. 1 lit. b DS-GVO.
d) Trusted Shops Badge
On our site is the Trusted Shops Badge embedded. This allows you to use the buyer protection of Trusted Shops and to submit secure reviews via Trusted Shops. The data transmission to Trusted Shops takes place only when you click on the Trustbadge seal.
When you call up the Trustbadge, the web server automatically saves a so-called server log file, which also contains your IP address, date and time of the call, transferred data volume and the requesting provider (access data) and documents the call. Individual access data are stored in a security database for the analysis of security anomalies. The log files are automatically deleted no later than 90 days after creation.
The Trustbadge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany. We have concluded an order processing agreement with Trusted Shops pursuant to Art. 28 (3) DS-GVO. The legal basis for the processing is Art. 6 para. 1 lit. f DS-GVO. Our legitimate interest is to provide users with a facilitated evaluation. We thereby increase our reach.
If you use Trusted Shops GmbH's own services, the contractual agreements made between you and Trusted Shops GmbH apply.
If you have registered for our newsletter "PortHy Club", we process your email address so that we can send you our newsletter by email. The legal basis for this is your consent given by your selection within the cookie banner according to Art. 6 para. 1 lit. a DS-GVO. You can revoke your consent to receive our newsletter at any time by sending an email to firstname.lastname@example.org. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.
In principle, our newsletter can only be received if you have a valid e-mail address and have registered to receive it. When you register for the newsletter for the first time using your e-mail address, we will send you a confirmation e-mail. This enables us to check whether you, as the owner of the e-mail address, have authorized receipt of the newsletter.
When you register to receive the newsletter, we store your IP address and the date and time of registration. The processing of this data is necessary in order to be able to trace any misuse of the e-mail address of a data subject at a later date.
5. Data Safety
The security of your personal data is important to us. For security reasons and to protect the transmission of confidential content, such as via our contact form, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
6. Ihre Betroffenenrechte
With regard to the personal data concerning you You have the following rights to the extent permitted by law under the GDPR:
- Right to information (Art. 15 DS-GVO),
- Right to rectification (Art. 16 DS-GVO),
- Right to erasure (Art. 17 DS-GVO),
- Right to restriction of processing (Art. 18 DS-GVO),
- Right to object to processing (Art. 21 DS-GVO),
- Right to withdraw consent you have given (Art. 7(3) DS-GVO),
- Right to data portability (Art. 20 DS-GVO).
You also have the right to complain to a data protection supervisory authority about the processing of your personal data.