Privacy

Data protection information Brainstoxx GmbH, Otto-Lindenmeyer-Straße 40, 86153 Augsburg, Germany, as of: 03.04.2020

Since May 25, 2018, the uniform requirements of the EU General Data Protection Regulation(DSGVO) apply in the area of data protection throughout Europe. In the following data protection information, we inform you about the processing of personal data carried out by Brainstoxx GmbH, Otto-Lindenmeyer-Straße 40, 86153 Augsburg ("BRAINSTOXX" and/or "we" and/or "controller") in accordance with the DSGVO and the German Federal Data Protection Act(BDSG 2018).

Please read our data protection information carefully.

You can request information (Art 15 DSGVO, § 34 BDSG 2018) about your personal information stored by us at datenschutz@wallstoxx.com. You can likewise assert the right to data portability via this.


1. NAME AND CONTACT DETAILS OF THE PERSON RESPONSIBLE FOR PROCESSING.

This privacy information applies to data processing by.

Brainstoxx GmbH
Otto-Lindenmeyer-Strasse 40
86153 Augsburg

Phone: +49 821 999792 20
E-mail: info@wallstoxx.com
Website: www.wallstoxx.de

represented by:
Jürgen Schmachtel (Managing Director)
for the following websites: www.wallstoxx.de and www.wallstoxx.com


2. CONTACT DATA OF THE DATA PROTECTION OFFICER

You can contact the data protection officer(s) of the controller at datenschutz@wallstoxx.com.


3. PURPOSES OF DATA PROCESSING, LEGAL BASES AND LEGITIMATE INTERESTS PURSUED BY THE CONTROLLER OR A THIRD PARTY, AND CATEGORIES OF RECIPIENTS

3.1. ACCESSING OUR WEBSITES/APPLICATIONS

3.1.1. LOG FILES

Each time websites/applications are accessed, information is sent to the server of our website/application by the respective Internet browser of your respective end device and temporarily stored in log files, the so-called log files. The data records stored in this process contain the following data, which is stored until automatic deletion: Date and time of the retrieval, name of the page accessed, IP address of the requesting device, referrer URL (origin URL from which you came to our websites), the amount of data transferred, loading time, as well as product and version information of the respective browser used and the name of your access provider.

The legal basis for the processing of the IP address is Article 6(1)(f) DSGVO. Our legitimate interest results from the

  • Ensuring a smooth connection setup,
  • Ensuring a comfortable use of our website/application,
  • Evaluation of system security and stability.

A direct conclusion to your identity is not possible on the basis of the information and will not be drawn by us.

The data is stored and automatically deleted after the aforementioned purposes have been achieved. The standard periods for deletion are based on the criterion of necessity.


3.1.2. COOKIES, TRACKING, SOCIAL MEDIA PLUG-INS

We use so-called cookies, tracking tools, as well as social media plugins for our website/application. The exact procedures involved and how their data is used for this purpose are explained in detail below.


3.2. ONLINE PRESENCE AND WEBSITE OPTIMIZATION INCLUDING CONSENT

3.2.1. COOKIES - GENERAL INFORMATION

We use cookies on various pages to make visiting our website more attractive and to enable the use of certain functions, as well as to statistically record the use of our website. Cookies are small text files that are automatically created by your browser and stored on your end device (laptop, tablet, smartphone or similar) when you visit our site. Cookies do not cause any damage to your end device, do not contain viruses, Trojans or other malware. In the cookie, information is stored that arises in each case in connection with the specific end device used. This does not mean, however, that we gain direct knowledge of your identity. Most of the cookies we use are deleted at the end of the browser session (so-called session cookies). These allow us to offer you, for example, the cross-page shopping cart display, in which you can see how many items are currently in your shopping cart and what your current purchase value is. Other cookies remain on your computer and enable us to recognize your computer on your next visit (so-called permanent or cross-session cookies). These cookies in particular serve to make our offer user-friendly, more effective and safer. Thanks to these files, it is possible, for example, for you to receive information on the site that is specifically tailored to your interests.

On the one hand, we use cookies on the basis of Art. 6 (1) f) DSGVO (legitimate interest in optimizing our offers). Certain cookies are used exclusively on the basis of your consent (Art. 6 para. 1 a) DSGVO). You will find the respective legal basis in the information on the respective service.

BUTTON SETTINGS!!!!

3.2.2 GOOGLE RECAPTCHA

In order to ensure sufficient data security when submitting forms, we use in certain cases the service reCAPTCHA of the company Google Inc. This serves primarily to distinguish whether the input is made by a natural person or abusively by machine and automated processing. The service includes the sending of the IP address and possibly other data required by Google for the reCAPTCHA service to Google. The deviating data protection regulations of Google Inc. apply here.

Further information on the privacy policy of Google Inc. can be found at:

www.google.de/intl/de/privacy or www.google.com/intl/de/policies/privacy/


3.2.3 GOOGLE CONVERSION TRACKING

Furthermore, we use the so-called conversion tracking within the scope of using the Google Ads service. When you click on an ad placed by Google, a cookie for conversion tracking is stored on your computer/end device. These cookies lose their validity after 30 days, do not contain any personal data and are therefore not used for personal identification. The information obtained using the conversion cookie is used to create conversion statistics for Google Ads customers who have opted in to conversion tracking.

The legal basis for this data processing is Article 6(1)(f) DSGVO (legitimate interest).

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. In addition, you can deactivate interest-based ads on Google as well as interest-based Google ads on the web (within the Google display network) in your browser by activating the "Off" button at www.google.de/settings/ads or by deactivating at www.aboutads.info/choices. For more information on your settings options in this regard and Google's data protection, please visit: www.google.de/intl/de/policies/privacy/?fg=1.


3.2.4 GOOGLE ANALYTICS

For the purpose of demand-oriented design and continuous optimization of our pages, we use Google Analytics, a web analytics service of Google Inc ("Google"), on the basis of Article 6(1)(f) DSGVO (legitimate interest). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. In this context, pseudonymized usage profiles are created and cookies are used. The information generated by the cookie about your use of this website, such as

  • Browser type/version,
  • operating system used,
  • Referrer URL (the previously visited page)
  • Host name of the accessing computer (IP address),
  • time of the server request

On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: tools.google.com/dlpage/gaoptout?hl=en


3.3. SOCIAL MEDIA PLUG-INS.

We use social plug-ins of the social network Facebook on our website on the basis of Article 6(1)(f) DSGVO in order to make our company better known via this. The underlying promotional purpose is to be regarded as a legitimate interest within the meaning of the DSGVO. The responsibility for data protection-compliant operation is to be ensured by their respective providers.

The purpose and scope of the data collection and the further processing and use of the data by the respective provider, as well as your rights in this regard and setting options for protecting your privacy, can be found in the respective privacy notices of the provider, which we link to below.

By logging out of the pages of social networks beforehand and deleting cookies that have been set, you can prevent social networks from assigning the information collected about you to your user account with the respective social network during your visit to wallstoxx.de. If you do not want social networks to directly assign the data collected via our website to your profile, you must log out of the corresponding social networks before visiting our website.

By logging out of the pages of social networks beforehand and deleting cookies that have been set, you can prevent social networks from assigning the information collected about you to your user account with the respective social network during your visit to wallstoxx.de. If you do not want social networks to directly assign the data collected via our website to your profile, you must log out of the relevant social networks before visiting our website.


3.3.1. FACEBOOK

A social plugin from Facebook is used on this website. This is an offer of the US company Facebook.

When you visit a page that contains such a plugin, your browser establishes a connection to Facebook and the content is loaded from this page. Your visit to this website may thus be tracked by Facebook, even if you do not actively use the function of the social plugin. If you have an account with Facebook, you can use such a social plugin and can thus share information with your friends. BRAINSTOXX has no influence on the content of the plugins and the transmission of information.

On their website, Facebook provides detailed information on the scope, type, purpose and further processing of your data. Here you will also find further information on your rights and setting options for protecting your privacy.

Data protection information from Facebook: www.facebook.com/about/privacy


3.3.2. INSTAGRAM

Plugins of the social network Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA ("Instagram") are also integrated on this website. You can recognize the Instagram plugin by the "Instagram - Button" on our page.

If you click the "Instagram - Button" while you are logged into your Instagram - account, you can link the content of our pages on your Instagram - profile. This allows Instagram to assign the visit to our pages to your user account. We point out that we have no knowledge of the content of the transmitted data and its use by Instagram.

For more information, please refer to the privacy policy of Instagram: instagram.com/about/legal/privacy.


3.3.3. PINTEREST

Plugins of the social network Pinterest Inc, 635 High Street, Palo Alto, CA, 94301, USA ("Pinterest") are integrated on this website. You can recognize the Pinterest plugin by the "Pin it button" on our site.

If you click the Pinterest "Pin it button" while you are logged into your Pinterest account, you can link the content of our pages on your Pinterest profile. This allows Pinterest to associate the visit to our pages with your user account. We would like to point out that we have no knowledge of the content of the transmitted data or its use by Pinterest.

For more information, please refer to Pinterest's privacy policy: about.pinterest.com/en/privacy.


3.3.4 YOUTUBE

Plugins of the YouTube site operated by Google are integrated on this website. The operator of the pages is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. When you visit one of our pages equipped with a YouTube plugin, a connection to the YouTube servers is established. This tells the YouTube server which of our pages you have visited.

WWhen you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

For more information on the handling of user data, please refer to YouTube's privacy policy. policies.google.com/privacy


3.4. ESTABLISHMENT, EXECUTION AND/OR TERMINATION OF A CONTRACT

3.4.1. DATA PROCESSING UPON CONCLUSION OF A CONTRACT

If you register with one of our websites/apps and/or enter into another contract with us, we process the data required for the conclusion, performance or termination of the contract with you. This includes:

  • First name, last name
  • Billing and delivery address
  • E-mail address
  • Billing and payment data
  • Date of birth
  • Telephone number

The legal basis for this is Article 6(1)(a) and (b) DSGVO, i.e. you provide us with the data on the basis of the respective contractual relationship (e.g. management of your customer/user account, processing of a purchase contract) between you and us. We are also obliged to process your e-mail address in the event of a purchase via our websites/apps due to legal requirements in the German Civil Code(BGB) to send an electronic order confirmation in the form of an advance invoice (Article 6(1)(c) DSGVO).

Insofar as we do not use your data for advertising purposes, we store the data collected for contract processing for the duration of the contract, as well as until the expiry of the statutory or possible contractual warranty and guarantee rights. After the expiration of this period, we retain the information of the contractual relationship required by commercial and tax law for the periods determined by law. For this period, the data will be processed again solely in the event of an audit by the tax authorities.

Furthermore, the following data processing is required for the execution of a purchase contract via our websites/applications:

We pass on details of your delivery address to logistics companies and shipping partners commissioned by us, as well as to our manufacturer. In order to ensure that the goods are delivered in accordance with your wishes, we transmit your e-mail address and, if applicable, telephone number to the logistics company and/or shipping partner commissioned by us to carry out the delivery. If necessary, they will contact you in advance of the delivery in order to coordinate details of the delivery with you. The respective data will be transmitted solely for the respective purposes and deleted again after delivery has taken place.


3.4.2. TRANSMISSION OF DATA TO TRANSPORT SERVICE PROVIDERS AND MANUFACTURERS

For the purpose of delivering ordered goods, we work together with logistics service providers/transport companies and/or shipping partners: The following data may be transmitted to them for the purpose of delivery of the ordered goods or for their announcement: First name, last name, postal address, e-mail address, telephone number (e.g. for shipping announcements). The legal basis of the processing is Art. 6(1)(b) DSGVO.


3.5. CONTACTING US

You have the possibility to contact us in several ways. By email, by phone, by chat, or by mail. When you contact us, we use the personal data that you voluntarily provide in this context solely for the purpose of contacting you and processing your request.

The legal basis for this data processing is Art. 6(1)(a), Art. 6(1)(b), Art. 6(1)(c) DSGVO and Art. 6(1)(f) DSGVO.


3.5.1 ZENDESK

Brainstoxx uses the ticket system Zendesk and Zendesk Chat, a customer service platform of Zendesk Inc. to process customer inquiries. For this purpose, necessary data such as surname, first name, postal address, telephone number, email address are collected via our website in order to be able to answer your support ticket. The data will be deleted after the correspondence has been completed. The data can be located in the EU as well as in the USA. Zendesk certifies compliance with the Privacy Shield and Safe Harbor frameworks between the U.S. and the EU and between the U.S. and Switzerland, respectively, as specified by the U.S. Department of Commerce. For more information about Zendesk's data processing, please see Zendesk's Privacy Policy at:

www.zendesk.de/company/customers-partners/privacy-policy/

If you have any questions, you may also contact Zendesk's Privacy Officer directly at: Zendesk, Inc, Attn: Privacy Officer, 1019 Market Street, San Francisco, CA 94103, United States, or by email at privacy@zendesk.com.

In this case, the data processing is based on our legitimate interests in receiving and processing the request you have made, Art. 6 (1) lit. f DSGVO.


3.6 PAYMENTS

We process your payment information for the purpose of payment processing, e.g. if you purchase or use a product and/or service via wallstoxx.de. Depending on the payment method, we forward your payment information to third parties (e.g. in the case of credit card payments, to your credit card provider).

The legal basis for this data processing is Art. 6(1)(a), Art. 6(1)(b), DSGVO and Art. 6(1)(f) DSGVO.

3.6.1 PAYPAL PLUS

When paying via PayPal Plus, your payment data will be forwarded to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal Plus, direct debit via PayPal Plus or - if offered - "purchase on account" via PayPal Plus. PayPal uses the result of the credit check with regard to the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they have their basis in a scientifically recognized mathematical-statistical procedure. Among other things, address data is included in the calculation of the score values. For further information on data protection law, including information on the credit agencies used, please refer to PayPal's data protection declaration: www.paypal.com/de/webapps/mpp/ua/privacy-full.


4. YOUR RIGHTS

4.1 OVERVIEW

In addition to the right to revoke your consent given to us, you are entitled to the following additional rights if the respective legal requirements are met:

  • the right to information about your personal data stored by us (Art. 15 DSGVO), in particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the origin of your data if it has not been collected directly from you;
  • the right to have inaccurate data corrected or to have correct data completed (Art. 16 DSGVO),
  • the right to have your data stored by us deleted (Art. 17 DSGVO), insofar as no legal or contractual retention periods or other legal obligations or rights to further storage are to be observed by us,
  • the right to restrict the processing of your data (Art. 18 DSGVO), insofar as the accuracy of the data is disputed by you.
  • the right to data portability (Art. 20 DSGVO), i.e. the right to have selected data stored by us about you transferred in a common, machine-readable format, or to request the transfer to another responsible party.
  • The right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.

You can assert the aforementioned rights to which you are entitled vis-à-vis us at datenschutz@wallstoxx.com.

You can also request information about your personal data stored by us here.


4.2. RIGHT OF OBJECTION

Under the conditions of Article 21 (1) DSGVO, data processing may be objected to for reasons arising from the particular situation of the data subject.

The above general right to object applies to all processing purposes described in this Privacy Notice, which are processed on the basis of Article 6(1)(f) DSGVO. Unlike the specific right of objection directed at data processing for promotional purposes, under the GDPR we are only obliged to implement such a general right of objection if you provide us with reasons of overriding importance for doing so (e.g. a possible risk to life or health).


4.3. RIGHT OF REVOCATION

Insofar as we process data on the basis of consent granted by you, you have the right to revoke the granted consent at any time. The revocation of the consent does not have the consequence that the data processing carried out on the basis of the consent up to the time of the revocation becomes ineffective.


5. DATA SECURITY

All data transmitted by you personally, including your payment data, are transmitted using the generally accepted and secure standard SSL (Secure Socket Layer). SSL is a secure and proven standard that is also used, for example, in online banking. You can recognize a secure SSL connection, among other things, by the appended s at the http (i.e. https://...) in the address bar of your browser or by the lock symbol in the lower area of your browser.

We also use appropriate technical and organizational security measures to protect your personal data stored by us against manipulation, partial or complete loss and against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.


5.1. WARNING AGAINST FORGED E-MAILS (SPOOFING), SPAM AND PHISHING

The security of our customers' data is our top priority. In the following we would like to give you some security advice.

Beware of so-called phishing and spoofing attempts

In this scam, unfortunately, the WALLSTOXX brand is also misused as the supposed sender. Specifically, this means that consumers receive fake e-mails in the name of WALLSTOXX. These e-mails are even often based on the WALLSTOXX brand layout and may be difficult to distinguish from genuine e-mails from WALLSTOXX.

The fraudsters want to exploit the position of trust between WALLSTOXX and our customers and thus steal sensitive data (e.g. login, customer data, payment information) or install harmful software (such as viruses or Trojans) on your computer or smartphone.

WALLSTOXX does not create these e-mails or send them, even if our name is used as the sender. Therefore, WALLSTOXX unfortunately cannot influence the sending of these illegal e-mails.

Thefollowing are some characteristics that you can use to recognizee-mails from WALLSTOXX:

  • WALLSTOXX does not ask you for personal information via e-mail, nor does WALLSTOXX ask you to confirm personal information via a link in an e-mail.
  • You will receive order confirmations and invoices from WALLSTOXX only for orders that you have actually placed.
  • WALLSTOXX will only send e-mails with file attachments if you have explicitly requested them from us (e.g. preliminary invoices, or operating instructions).
  • Mails from WALLSTOXX should not contain spelling or grammatical errors, as they are always proofread before being sent.

This is the correct way to deal with spam, phishing and spoofing e-mails:

  • We recommend that you delete suspicious emails immediately.
  • Never open links and attachments in suspicious emails and do not disclose any personal information.
  • If you have nevertheless accidentally clicked on links in the e-mail, we recommend that you run a virus scan on your computer.