Privacy Policy
Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor necessary for the conclusion of a contract. You are not obliged to provide the data. Failure to provide it will have no consequences. This applies only insofar as no other information is given in the following processing operations.
"Personal data" means any information relating to an identified or identifiable natural person.
Server Log Files
You can visit our websites without providing any personal information.
Each time you access our website, usage data is transmitted to us or our web host / IT service provider by your internet browser and stored in log data (so-called server log files). This stored data includes, for example, the name of the accessed page, the date and time of access, the IP address, the amount of data transferred and the requesting provider.
Processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in ensuring the trouble-free operation of our website and improving our offerings.
Your data may be transferred to and processed in third countries outside the EU, in particular Canada and the USA. For Canada, an adequacy decision by the EU Commission exists. For the USA, an adequacy decision by the EU Commission exists, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations comparable to those of the EU Commission's standard contractual clauses.Processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR due to our overriding legitimate interest in ensuring the trouble-free operation of our website and improving our offerings.
Contact
Controller
Contact us if you wish. The controller for data processing is: Stefan Pella, Nürnbergerstr. 14, 96114 Hirschaid Germany, 01725143101, kontakt@bc-arts.de
Customer initiated contact via e-mail
If you proactively contact us by e-mail for business purposes, we collect your personal data (name, e-mail address, message text) only to the extent provided by you. The data processing serves to process and answer your contact request.
If the contact serves to carry out pre-contractual measures (e.g., advice on purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing takes place on the basis of Art. 6 (1) lit. b GDPR.
If contact is made for other reasons, this data processing takes place on the basis of Art. 6 (1) lit. f GDPR, due to our overriding legitimate interest in processing and answering your inquiry. In this case, you have the right to object at any time to this processing of your personal data based on Art. 6 (1) lit. f GDPR, for reasons arising from your particular situation.
We only use your e-mail address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.
Collection and processing when using the contact form
When using the contact form, we collect your personal data (name, e-mail address, message text) only to the extent provided by you. The data processing serves the purpose of making contact.
If the contact serves to carry out pre-contractual measures (e.g., advice on purchase interest, preparation of an offer) or concerns a contract already concluded between you and us, this data processing takes place on the basis of Art. 6 (1) lit. b GDPR.
If contact is made for other reasons, this data processing takes place on the basis of Art. 6 (1) lit. f GDPR due to our overriding legitimate interest in processing and answering your inquiry. In this case, you have the right to object at any time to this processing of your personal data based on Art. 6 (1) lit. f GDPR, for reasons arising from your particular situation.
We only use your e-mail address to process your request. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.
Collection and processing when sending images by e-mail
You have the option to send us images by e-mail in connection with ordering a personalized product.
By submitting your images, we may collect your personal data (depiction of identifiable persons) only to the extent provided by you. The data processing serves the purpose of creating personalized products. The transmitted image serves as a template for the product and is used for this purpose (e.g., T-shirt print). Processing takes place on the basis of Art. 6 Para. 1 lit. b GDPR and is necessary for the fulfillment of a contract with you.
Your data will not be passed on.
We only use the image you sent within the scope of service provision. Your data will then be deleted in compliance with statutory retention periods, unless you have consented to further processing and use.
Customer Account Orders
Customer Account
When opening a customer account, we collect your personal data to the extent indicated there. The data processing serves the purpose of improving your shopping experience and simplifying order processing. Processing takes place on the basis of Art. 6 (1) lit. a GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the legality of the processing carried out on the basis of the consent until revocation. Your customer account will then be deleted.
Collection, processing and disclosure of personal data for orders
When placing an order, we collect and process your personal data only to the extent necessary for the fulfillment and processing of your order and for handling your inquiries. The provision of data is necessary for the conclusion of the contract. Failure to provide data will result in the inability to conclude a contract. Processing takes place on the basis of Art. 6 (1) lit. b GDPR and is necessary for the fulfillment of a contract with you.
Your data may be passed on, for example, to shipping companies, dropshipping or fulfillment providers, payment service providers, service providers for order processing, and IT service providers. In all cases, we strictly adhere to legal requirements. The scope of data transmission is limited to a minimum.
Your data may be transferred to and processed in third countries outside the EU, in particular Canada and the USA. For Canada, an adequacy decision by the EU Commission exists. For the USA, an adequacy decision by the EU Commission exists, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place on the basis of contractual obligations comparable to those of the EU Commission's standard contractual clauses.Advertising
Use of the e-mail address for sending newsletters
We use your e-mail address to send you information and offers via newsletter, provided you have expressly consented to this. The data processing serves exclusively the purpose of promotional contact. For this purpose, we process your e-mail address and, if applicable, other data that you voluntarily provided when registering for our newsletter.
Processing takes place on the basis of Art. 6 (1) lit. a GDPR with your consent. You can revoke your consent at any time, without affecting the legality of the processing carried out on the basis of the consent until revocation.
You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your e-mail address will then be removed from the distribution list. Despite removal from the distribution list, we may continue to store your e-mail address in a so-called blacklist to prevent you from receiving newsletter e-mails from us in the future. This storage takes place on the basis of Art. 6 (1) lit. f GDPR due to our and your legitimate interest in preventing the renewed use of your e-mail address for sending our newsletter. You have the right to object at any time to this processing of your personal data for reasons arising from your particular situation.
Payment service providers
Use of PayPal Express
We use the payment service PayPal Express from PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the PayPal Express payment service. To integrate this payment service, it is necessary for PayPal to collect, store, and analyze data (e.g., IP address, device type, operating system, browser type, location of your device) when the website is accessed. Cookies may also be used for this purpose. Cookies enable the recognition of your browser.
The processing of your personal data is carried out on the basis of Art. 6 (1) lit. f GDPR due to our overriding legitimate interest in offering various customer-oriented payment methods. You have the right to object at any time to this processing of your personal data for reasons arising from your particular situation.
By selecting and using PayPal Express, the data required for payment processing is transmitted to PayPal in order to fulfill the contract with you using the selected payment method. This processing takes place on the basis of Art. 6 (1) lit. b GDPR. Further information on data processing when using the PayPal Express payment service can be found in the associated privacy policy at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE#Updated_PS.
Use of PayPal Checkout
We use the payment service PayPal Checkout from PayPal (Europe) S.à.r.l. et Cie, S.C.A. (22-24 Boulevard Royal L-2449, Luxembourg; "PayPal") on our website. The data processing serves the purpose of being able to offer you payment via the payment service. By selecting and using payment via PayPal, credit card via PayPal, direct debit via PayPal or "Pay Later" via PayPal, the data required for payment processing is transmitted to PayPal in order to fulfill the contract with you using the chosen payment method. This processing takes place on the basis of Art. 6 (1) lit. b GDPR.
Cookies may be stored, which enable the recognition of your browser. The data processing that occurs as a result is carried out on the basis of Art. 6 (1) lit. f GDPR due to our overriding legitimate interest in offering various customer-oriented payment methods. You have the right to object at any time to this processing of your personal data for reasons arising from your particular situation.
Credit card via PayPal, direct debit via PayPal & "Pay Later" via PayPal
For individual payment methods such as credit card via PayPal, direct debit via PayPal or "Pay Later" via PayPal, PayPal reserves the right to obtain a credit report based on mathematical-statistical procedures using credit agencies. For this purpose, PayPal transmits the personal data required for a credit check to a credit agency and uses the information received about the statistical probability of a payment default for a balanced decision on the establishment, execution or termination of the contractual relationship. The credit report may include probability values (score values) calculated on the basis of scientifically recognized mathematical-statistical procedures and whose calculation includes address data, among other things. Your legitimate interests are taken into account in accordance with the legal provisions. The data processing serves the purpose of credit assessment for the initiation of a contract. The processing is carried out on the basis of Art. 6 (1) lit. f GDPR due to our overriding legitimate interest in protecting against payment default when PayPal advances payment.
You have the right to object at any time to this processing of your personal data based on Art. 6 (1) lit. f GDPR, for reasons arising from your particular situation, by notifying PayPal. The provision of data is necessary for the conclusion of the contract with your desired payment method. Failure to provide data will result in the inability to conclude the contract with your chosen payment method.
Third-party providers
When paying via a third-party payment method, the data required for payment processing is transmitted to PayPal. This processing takes place on the basis of Art. 6 (1) lit. b GDPR. To carry out this payment method, the data may then be passed on by PayPal to the respective provider. This processing takes place on the basis of Art. 6 (1) lit. b GDPR. Local third-party providers may include:
- Apple Pay (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
- Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)
Purchase on account via PayPal
When paying using the "purchase on account" payment method, the data required for payment processing is initially transmitted to PayPal. To carry out this payment method, the data is then transmitted by PayPal to Ratepay GmbH (Franklinstraße 28-29, 10587 Berlin; "Ratepay") to enable the fulfillment of the contract with you using the selected payment method. This processing is based on Art. 6 para. 1 lit. b GDPR. Ratepay may carry out a credit assessment based on mathematical-statistical procedures (probability or score values) using credit agencies, following the process described above. Data processing serves the purpose of credit assessment for the initiation of a contract. The processing is based on Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in protecting against payment default when Ratepay makes advance payments. Further information on data protection and which credit agencies Ratepay uses can be found at https://www.ratepay.com/legal-payment-dataprivacy/ and https://www.ratepay.com/legal-payment-creditagencies/.
Further information on data processing when using PayPal can be found in the associated privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
Use of Shopify Payments
We use the payment service "Shopify Payments" from Shopify International Limited (2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") on our website. Payment processing in this case is carried out by the payment service provider Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; "Stripe"). Data processing serves the purpose of being able to offer you payment via the Shopify Payments service. By selecting and using a corresponding "Shopify Payments" payment method, the data required for payment processing is transmitted to Stripe to enable the fulfillment of the contract with you using the selected payment method. This processing is based on Art. 6 para. 1 lit. b GDPR.
Stripe reserves the right to obtain a credit assessment based on mathematical-statistical procedures using credit agencies, if necessary. For this purpose, Stripe transmits the personal data required for a credit assessment to a credit agency and uses the information received about the statistical probability of payment default for a balanced decision on the establishment, execution or termination of the contractual relationship. The credit assessment may include probability values (score values) calculated based on scientifically recognized mathematical-statistical procedures, and which incorporate, among other things, address data into their calculation. Your legitimate interests are taken into account in accordance with legal provisions. Data processing serves the purpose of credit assessment for the initiation of a contract. The processing is based on Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in protecting against payment default when Stripe makes advance payments.
You have the right to object to this processing of personal data concerning you, based on Art. 6 para. 1 lit. f GDPR, at any time for reasons arising from your particular situation, by notifying Stripe. The provision of the data is necessary for the conclusion of the contract with your desired payment method. Failure to provide it means that the contract cannot be concluded with the payment method you have chosen.
Further information on data processing when using the Shopify Payments service can be found in Shopify's privacy policy at: https://www.shopify.com/de/legal/datenschutz.
Further information on data processing during payment processing via the payment service provider Stripe can be found in Stripe's privacy policy at: https://stripe.com/de/privacy.
Cookies
Our website uses cookies. Cookies are small text files that are stored in the internet browser or by the internet browser on a user's computer system. If a user calls up a website, a cookie can be stored on the user's operating system. This cookie contains a characteristic string of characters that enables unique identification of the browser when the website is called up again.
Cookies are stored on your computer. Therefore, you have full control over the use of cookies. By selecting appropriate technical settings in your internet browser, you can be notified before cookies are set and decide individually whether to accept them, as well as prevent the storage of cookies and the transmission of the data they contain. Already stored cookies can be deleted at any time. However, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.
Under the following links you can find out how to manage (including deactivating) cookies in the most important browsers:
Chrome: https://support.google.com/accounts/answer/61416?hl=de
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Microsoft Edge: https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-lB6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-erlauben-und-ablehnen
Technically necessary cookies
Unless otherwise stated below in the privacy policy, we only use these technically necessary cookies for the purpose of making our offer more user-friendly, effective and secure. Furthermore, cookies enable our systems to recognize your browser even after a page change and to offer you services. Some functions of our website cannot be offered without the use of cookies. For these, it is necessary that the browser is recognized again even after a page change.
The use of cookies or comparable technologies is based on § 25 para. 2 TDDDG. The processing of your personal data is based on Art. 6 para. 1 lit. f GDPR due to our overriding legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective design of our offer.
You have the right to object to this processing of personal data concerning you at any time for reasons arising from your particular situation.
Analysis
Use of Shopify Statistics
We use the statistics and analysis functions of Shopify International Ltd. (Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; "Shopify") on our website as part of order processing. Shopify is an affiliated company of Shopify Inc. (151 O’Connor Street, Ground Floor, Ottawa, Ontario, K2P 2L8, Canada).
Data processing serves the purpose of analyzing this website and its visitors. For this purpose, data is stored for marketing and optimization purposes and provided in reports, analyses, and statistics. Among other things, the following device information is collected and processed: information about the web browser, the IP address, the time zone, and some of the cookies installed on your device. When you navigate the website, information about visited web pages or products, the referrer URL (the website from which you accessed our website), and information about how you interact with the website is also collected. Technologies such as cookies as well as web beacons, tags, and pixels (electronic files for collecting information about how you navigate the website) are used for this purpose.
Your data may be transferred to and processed in third countries outside the EU, particularly to Canada and the USA. An adequacy decision by the EU Commission exists for Canada. An adequacy decision by the EU Commission also exists for the USA, the Trans-Atlantic Data Privacy Framework (TADPF). Shopify is not certified under the TADPF. This data transfer takes place based on contractual obligations comparable to those of the EU Commission's standard contractual clauses.
The use of cookies or similar technologies is based on your consent in accordance with § 25 para. 1 S. 1 TDDDG in conjunction with Art. 6 para. 1 lit. a GDPR. The processing of your personal data is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time, without affecting the legality of the processing carried out based on the consent until withdrawal.
You can find more information on data protection at Shopify at https://www.shopify.com/de/legal/datenschutz, information on the order processing agreement at https://www.shopify.com/de/legal/dpa, and information on the cookies used at https://www.shopify.com/de/legal/cookies.
Data Subject Rights and Storage Period
Duration of storage
After complete processing of the contract, the data will initially be stored for the duration of the warranty period, then, taking into account statutory, in particular tax and commercial law, retention periods, and then deleted after the expiry of the period, unless you have consented to further processing and use.
Rights of the data subject
If the legal requirements are met, you have the following rights according to Art. 15 to 20 GDPR: Right to information, to rectification, to erasure, to restriction of processing, to data portability.
In addition, you have a right to object to processing based on Art. 6 para. 1 f GDPR, as well as to processing for direct marketing purposes, according to Art. 21 para. 1 GDPR.
Right to complain to the supervisory authority
According to Art. 77 GDPR, you have the right to lodge a complaint with the supervisory authority if you believe that the processing of your personal data is not lawful.
You can lodge a complaint, among other things, with the supervisory authority responsible for us, which you can reach at the following contact details:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Tel.: +49 981 1800930
Fax: +49 981 180093800
Email: poststelle@lda.bayern.de
Right to object
If the personal data processing listed here is based on our legitimate interest according to Art. 6 para. 1 lit. f GDPR, you have the right to object to this processing at any time with effect for the future for reasons arising from your particular situation.
After a successful objection, the processing of the data concerned will be terminated, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.