Data protection


1 Information about the collection of personal data

and contact details of the responsible party. Personal data refers to all data that can be used to identify you personally. We treat your data with the utmost confidentiality. We do not share data with third parties. The server meets the highest security standards. The party responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data. This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the string "https://" and the padlock symbol in your browser's address bar.

2 Data Collection When Visiting Our Website

When using our website for informational purposes only, meaning when you do not register or otherwise transmit information to us, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data, which is technically required for us to display the website to you: Our visited website Date and time of access Amount of data sent in bytes Source/reference from which you arrived at the page Browser used Operating system used IP address used (if applicable, in anonymized form) The processing is carried out in accordance with Art. 6(1) lit. f of the GDPR, based on our legitimate interest in improving the stability and functionality of our website. The data is not shared or otherwise used. However, we reserve the right to review the server log files retrospectively if there are specific indications of illegal use.

3 Cookies

To make your visit to our website more attractive and enable the use of certain features, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, that is, after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser during your next visit (persistent cookies). When cookies are set, they collect and process certain user information, such as browser and location data, as well as IP address values, on an individual basis. Persistent cookies are automatically deleted after a predetermined duration, which can vary depending on the cookie. Some cookies are used to simplify the ordering process by saving settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). If personal data is processed by individual cookies we implement, the processing is done in accordance with Art. 6(1) lit. b of the GDPR either to perform the contract or, in accordance with Art. 6(1) lit. f of the GDPR, to protect our legitimate interests in ensuring the best possible functionality of the website and providing a user-friendly and efficient website experience. We may work with advertising partners who help us make our internet offering more interesting for you. For this purpose, cookies from partner companies (third-party cookies) may also be stored on your device during your visit to our website. If we work with such advertising partners, you will be individually and separately informed about the use of such cookies and the scope of the information collected in the following sections. Please note that you can configure your browser to notify you when cookies are set and to individually decide whether to accept them, or to exclude the acceptance of cookies in specific cases or altogether. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how to change your cookie settings. You can find the relevant links for each browser here:

Please note that if you do not accept cookies, the functionality of our website may be limited.

Shopware Analytics

Purpose of processing: Together with our e-commerce software provider, we jointly process certain information from our customer database (e.g., customer group, visited pages, click paths, date and time of visit, information about the device used (resolution, resolution density, operating system), referrer URL, browser information, locale, search queries, and time zone). This information is processed by an external service provider and sent to us in near real-time so that we can monitor the use of our website and improve our offerings. Legal basis: Art. 6(1)(f) GDPR Data categories: Derived data from master and contact data (customer group, no individual customer data), usage data, connection data. Recipients of the data: shopware AG, Ebbinghoff 10, 48624 Schöppingen, Germany (as joint controller), IT service provider. Essential aspects of joint control: The joint control exists between us and shopware AG; data is collected on our store and then transferred to shopware servers or their service providers. Except for obtaining your consent for the use of cookies or similar technologies and fulfilling these information obligations, all obligations, including the implementation of rights of the data subjects, lie with shopware AG, which can be contacted at legal@shopware.com. You may also assert your rights with us, and we will forward your request to shopware AG. shopware AG may derive behaviors from the collected data on our store but cannot attribute this data to you as an individual. Intended transfer to third countries: None. Do we store personal data on your device based on your consent or read such data? Yes, details can be found in the Consent Management.

4 Contacting Us

When contacting us (e.g., via contact form or email), personal data is collected. The data collected in the case of a contact form is specified in the respective form. This data is solely used for the purpose of responding to your inquiry, for contacting you, and for the associated technical administration. The legal basis for processing the data is our legitimate interest in answering your inquiry in accordance with Art. 6(1) lit. f GDPR. If your contact aims at entering into a contract, the additional legal basis for processing is Art. 6(1) lit. b GDPR. Your data will be deleted after your inquiry has been fully processed, which occurs when it is clear from the circumstances that the matter has been resolved, and provided no legal retention obligations conflict with this deletion.

5 Comment Function

As part of the comment function on this website, in addition to your comment, the date and time of the comment's creation and the commenter name you selected are stored and published on the website. Furthermore, your IP address is recorded and stored. The storage of the IP address is done for security reasons and in case the person concerned violates third-party rights or posts illegal content through their comment. We require your email address to contact you if a third party should object to your published content as being illegal. The legal basis for storing your data are Art. 6(1) lit. b and f of the GDPR. We reserve the right to delete comments if they are objected to by third parties as being unlawful.

6 Use of Your Data for Direct Marketing Subscription to Our Email Newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you the email newsletter after you have explicitly confirmed that you consent to receiving the newsletter. We will then send you a confirmation email asking you to click a link to confirm that you wish to receive future newsletters. By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6(1) lit. a GDPR. When subscribing to the newsletter, we store your IP address, as registered by the Internet Service Provider (ISP), as well as the date and time of subscription, in order to be able to trace any possible misuse of your email address at a later time. The data we collect during the newsletter subscription is used exclusively for the purpose of marketing communication via the newsletter. You can unsubscribe from the newsletter at any time by using the designated link in the newsletter or by sending a message to the responsible party mentioned at the beginning. After unsubscribing, your email address will be promptly deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use the data in a way that is legally permitted and which we inform you about in this statement. If you no longer wish to receive the newsletters, you can log in to your customer account and deactivate the newsletter subscription.

7 Use of Social Media: Social Plugins Facebook as Default Plugin

Our website uses so-called social plugins ("plugins") of the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). The plugins are identified by the Facebook logo or the label "Social Plugin by Facebook" or "Facebook Social Plugin." An overview of the Facebook plugins and their appearance can be found here: https://developers.facebook.com/docs/plugins

When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to Facebook's servers. The content of the plugin is transmitted by Facebook directly to your browser and integrated into the page. Through this integration, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not logged into Facebook at the time. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there. If you are logged into Facebook, Facebook can directly associate the visit to our website with your Facebook profile. If you interact with the plugins, for example, by clicking the "Like" button or leaving a comment, this information is also transmitted directly to a Facebook server and stored there. The information is also published on your Facebook profile and displayed to your Facebook friends. The described data processing operations are carried out in accordance with Art. 6(1) lit. f GDPR, based on Facebook’s legitimate interest in displaying personalized advertising to inform other users of the social network about your activities on our website and for the service's demand-oriented design. If you do not want Facebook to associate the data collected through our website directly with your Facebook profile, you must log out of Facebook before visiting our website. You can also block the loading of Facebook plugins and, therefore, the data processing described above, by using add-ons for your browser, such as the script blocker "NoScript" (http://noscript.net/). Facebook Inc., based in the USA, is certified under the US-EU Privacy Shield agreement, which ensures compliance with the data protection level applicable in the EU. For the purpose and scope of data collection, further processing, and use of data by Facebook, as well as your related rights and options for protecting your privacy, please refer to Facebook’s privacy policy: http://www.facebook.com/policy.php

Google+ as Default Plugin

Our website also uses social plugins ("plugins") of the social network Google+, which is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). The plugins are, for example, recognizable by buttons with the "+1" symbol on either a white or colored background. An overview of the Google plugins and their appearance can be found here: https://developers.google.com/+/plugins

When you visit a page on our website that contains such a plugin, your browser establishes a direct connection to Google’s servers. The content of the plugin is transmitted by Google directly to your browser and integrated into the page. Through this integration, Google receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Google+ profile or are not logged into Google+ at the time. This information (including your IP address) is transmitted directly from your browser to a Google server in the USA and stored there. If you are logged into Google+, Google can directly associate the visit to our website with your Google+ profile. If you interact with the plugins, for example, by clicking the "+1" button, this information is also transmitted directly to a Google server and stored there. The information is also published on Google+ and displayed to your contacts there. The described data processing operations are carried out in accordance with Art. 6(1) lit. f GDPR, based on Google’s legitimate interest in displaying personalized advertising to inform other users of the social network about your activities on our website and for the service's demand-oriented design. If you do not want Google to associate the data collected through our website directly with your Google+ profile, you must log out of Google+ before visiting our website. You can also block the loading of Google+ plugins and, therefore, the data processing described above, by using add-ons for your browser, such as the script blocker "NoScript" (http://noscript.net/). Google LLC, based in the USA, is certified under the US-EU Privacy Shield agreement, which ensures compliance with the data protection level applicable in the EU. For the purpose and scope of data collection, further processing, and use of data by Google, as well as your related rights and options for protecting your privacy, please refer to Google’s privacy policy: https://www.google.com/intl/de/policies/privacy/

8 Web Analytics Services Google Analytics

This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses so-called "cookies," text files that are stored on your computer and allow an analysis of your use of the website. The information generated by the cookie about your use of this website (including the truncated IP address) is generally transmitted to a Google server in the USA and stored there. This website uses Google Analytics exclusively with the "_anonymizeIp()" extension, which ensures anonymization of the IP address by truncation and excludes direct personal identification. Through this extension, your IP address is truncated by Google within European Union member states or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. In these exceptional cases, this processing is carried out in accordance with Art. 6(1) lit. f GDPR, based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes. On our behalf, Google will use this information to evaluate your use of the website, compile reports on website activities, and provide other services related to website usage and internet usage to us. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data. You can prevent the storage of cookies by adjusting your browser settings; however, please note that in this case, you may not be able to fully use all features of this website. Furthermore, you can prevent the collection of the data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of these data by Google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en. Alternatively, for mobile device browsers, please click the following link to set an opt-out cookie, which will prevent the future collection by Google Analytics on this website (this opt-out cookie works only in this browser and for this domain; if you delete your cookies in this browser, you must click this link again): Disable Google Analytics. Google LLC, based in the USA, is certified under the US-EU Privacy Shield agreement, which ensures compliance with the data protection level applicable in the EU. More information about the handling of user data in Google Analytics can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=en

9 Tools and Miscellaneous Google reCAPTCHA

On this website, we also use the reCAPTCHA function from Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This function is primarily used to distinguish whether an input is made by a natural person or abusively through automated processing. The service includes the transmission of the IP address and, if applicable, other data required by Google for the reCAPTCHA service to Google, and is carried out in accordance with Art. 6(1) lit. f GDPR based on our legitimate interest in determining the individual intent of actions on the internet and preventing abuse and spam. Google LLC, based in the USA, is certified under the US-EU Privacy Shield framework, which ensures compliance with the data protection standards applicable in the EU. For more information on Google reCAPTCHA and Google's privacy policy, you can view the following links: https://www.google.com/intl/en/policies/privacy/

Google Maps
On our website, we use Google Maps (API) provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Maps is a web service for displaying interactive (land) maps to visually represent geographical information. By using this service, our location is shown to you, and directions are made easier. When you visit the subpages where the Google Maps map is embedded, information about your usage of our website (such as your IP address) is transmitted to Google's servers in the USA and stored there. This occurs regardless of whether Google provides a user account that you are logged into or whether no user account exists. If you are logged into Google, your data will be directly associated with your account. If you do not want the data to be associated with your Google profile, you must log out before activating the map. Google stores your data (even for non-logged-in users) as usage profiles and evaluates them. The collection, storage, and evaluation are carried out in accordance with Art. 6(1) lit. f GDPR based on Google's legitimate interests in displaying personalized advertising, market research, and/or the design of Google websites to meet user needs. You have the right to object to the creation of these user profiles, in which case you must contact Google. Google LLC, based in the USA, is certified under the US-EU Privacy Shield framework, which ensures compliance with the data protection standards applicable in the EU. If you disagree with the future transmission of your data to Google in connection with the use of Google Maps, you can also deactivate the Google Maps web service entirely by disabling JavaScript in your browser. In this case, Google Maps and the map display on this website cannot be used. The terms of use of Google can be found at: http://www.google.com/intl/en/policies/terms/regional.html, and additional terms of use for Google Maps can be found at: https://www.google.com/intl/en_US/help/terms_maps.html. Detailed information on data protection in connection with the use of Google Maps can be found on Google's privacy policy page: http://www.google.com/intl/en/policies/privacy/

Google Web Fonts
This website uses so-called Web Fonts provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google") for uniform font display. When you visit a page, your browser loads the required Web Fonts into your browser cache to correctly display texts and fonts. For this purpose, the browser you use must connect to Google's servers. This allows Google to know that our website was accessed via your IP address. The use of Google Web Fonts is in the interest of uniform and attractive presentation of our online offerings. This constitutes a legitimate interest within the meaning of Art. 6(1) lit. f GDPR. If your browser does not support Web Fonts, a standard font from your computer will be used. Google LLC, based in the USA, is certified under the US-EU Privacy Shield framework, which ensures compliance with the data protection standards applicable in the EU. More information on Google Web Fonts can be found at: https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/

10 Rights of the Data Subject

The applicable data protection law grants you comprehensive rights (right to access and intervention rights) regarding the processing of your personal data by the data controller, which we inform you about below:

  • Right of Access under Art. 15 GDPR: You have the right to obtain information about the personal data we process about you, the purposes of processing, the categories of personal data processed, the recipients or categories of recipients to whom your data has been or will be disclosed, the planned duration of storage or the criteria used to determine the storage duration, the existence of the right to rectification, erasure, restriction of processing, objection to processing, complaints to a supervisory authority, the source of your data if it was not collected directly from you, the existence of automated decision-making including profiling, and if applicable, meaningful information about the logic involved, as well as the scope and consequences of such processing. Additionally, you have the right to be informed about the guarantees in accordance with Art. 46 GDPR when your data is transferred to third countries.
  • Right to Rectification under Art. 16 GDPR: You have the right to request the immediate rectification of inaccurate personal data concerning you and/or the completion of incomplete data stored by us.
  • Right to Erasure under Art. 17 GDPR: You have the right to request the erasure of your personal data under the conditions specified in Art. 17(1) GDPR. However, this right does not apply if processing is necessary for the exercise of the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.
  • Right to Restriction of Processing under Art. 18 GDPR: You have the right to request the restriction of processing of your personal data as long as the accuracy of the data you dispute is being verified, if you refuse to erase your data due to unlawful processing and instead request restriction of processing, if you need your data for the establishment, exercise, or defense of legal claims after we no longer need the data for its original purpose, or if you have objected to the processing due to your particular situation and it is not yet clear whether our legitimate grounds override your objections.
  • Right to Notification under Art. 19 GDPR: If you have exercised your right to rectification, erasure, or restriction of processing, the controller is required to notify all recipients to whom your personal data has been disclosed about the correction, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. You have the right to be informed about these recipients.
  • Right to Data Portability under Art. 20 GDPR: You have the right to receive your personal data, which you have provided to us, in a structured, commonly used, and machine-readable format, or to request the transmission to another data controller, as long as this is technically feasible.
  • Right to Withdraw Consent under Art. 7(3) GDPR: You have the right to withdraw your consent to the processing of data at any time with effect for the future. In the event of withdrawal, we will promptly delete the affected data unless further processing can be based on another legal ground for processing without consent. The withdrawal of consent does not affect the lawfulness of processing based on consent before the withdrawal.
  • Right to Lodge a Complaint under Art. 77 GDPR: If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, without prejudice to any other administrative or judicial remedy. You can file a complaint with the supervisory authority in the member state of your residence, place of work, or the place of the alleged infringement.
  • Right to Object: If we process your personal data based on our legitimate interest, you have the right to object at any time to such processing for reasons related to your particular situation, with effect for the future. If you exercise your right to object, we will cease processing your personal data. However, further processing may still be justified if we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims.
  • Right to Object to Direct Marketing: If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes. You can exercise this right as described above. If you exercise your right to object, we will cease processing the affected data for direct marketing purposes.

11 Duration of Storage of Personal Data

The duration of the storage of personal data is determined based on the respective legal retention periods (e.g., commercial and tax retention periods). After the retention period has expired, the relevant data will be routinely deleted, unless it is still required for the performance of the contract or the initiation of a contract and/or we have a legitimate interest in continuing to store the data.

12 Use of a Live Support System

This website uses a live chat system to answer live inquiries. Your provided chat name and the content of the chat will be collected and stored for the duration of the chat. The chat and the chat name you provided are stored exclusively in the so-called RAM (Random-Access Memory) and are immediately deleted once we or you end the chat conversation, or at the latest, 2 hours after the last message in the chat history. Cookies are used to operate the chat function. Cookies are small text files that are stored locally in the browser cache of the visitor. These cookies allow for the recognition of the visitor's browser to differentiate between individual users of the chat function on our website. If the information collected in this manner is personally identifiable, the processing is carried out in accordance with Art. 6(1)(f) DSGVO based on our legitimate interest in effective customer support and statistical analysis of user behavior for optimization purposes. To avoid the storage of cookies, you can set your internet browser to prevent cookies from being placed on your computer in the future or to delete already stored cookies. However, disabling all cookies may result in the chat function on our website no longer being usable.

13 Links ("Hyperlinks")

In the case of direct or indirect references to external websites ("hyperlinks") that are outside the author's area of responsibility, liability would only apply if the author is aware of the content and if it would have been technically possible and reasonable to prevent the use in the case of illegal content. The author hereby explicitly declares that at the time the link was set, no illegal content was identifiable on the linked pages. The author has no influence over the current and future design, content, or authorship of the linked/connected pages. Therefore, the author expressly distances themselves from all content of all linked/connected pages that have been modified after the link was set. This statement applies to all links and references set within the author's own internet offerings, as well as for external entries in guest books, discussion forums, link directories, mailing lists, and other forms of databases created by the author, where external write access is possible. For illegal, incorrect, or incomplete content, and especially for damages arising from the use or non-use of such offered information, the provider of the linked page alone is liable, not the one who merely refers to the respective publication via links.

14 Copyright and Trademark Law

The author strives to observe the copyrights of the images, graphics, audio documents, video sequences, and texts used in all publications, to use images, graphics, audio documents, video sequences, and texts created by themselves, or to rely on royalty-free graphics, audio documents, video sequences, and texts. All trademarks and service marks mentioned within the internet offering and possibly protected by third parties are subject without limitation to the provisions of the applicable trademark law and the ownership rights of the respective registered owners. The mere mention of a trademark does not imply that it is not protected by the rights of third parties! The copyright for published objects created by the author remains with the author of the pages. Reproduction or use of such graphics, audio documents, video sequences, and texts in other electronic or printed publications is not permitted without the express consent of the author.

15 Blog

The author strives to observe the copyrights of the images, graphics, audio documents, video sequences, and texts used in all publications, to use images, graphics, audio documents, video sequences, and texts created by themselves, or to rely on royalty-free graphics, audio documents, video sequences, and texts. If this is not possible, all sources will be fully credited.

16 Further Information and Contacts

If you have any questions regarding security, please feel free to email us at info(at)bischofbergergardening.ch or use the contact form.