1) Introduction and contact details of the person responsible

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following we inform you about the handling of your personal data when using our website. Personal data is all data with which you can be personally identified.

1.2 The person responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Tana Cosmetics GmbH & Co. KG, Driburger Straße 16, 33647 Bielefeld, Germany, Tel.: 0521 - 62 15 6, Fax: 0521 - 174254, Email: info@tana-cosmetics.de. The person responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data.

1.3 For security reasons and to protect the transmission of personal data and other confidential content (eg orders or inquiries to the person responsible), this website uses an SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser line.

2) Data collection when visiting our website

If you only use our website for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the site server (so-called "server log files"). When you visit our website, we collect the following data that is technically necessary for us to display the website to you:

  • Our visited website
  • Date and time at the time of access
  • Amount of data sent in bytes
  • Source/reference from which you came to the page
  • Browser used
  • Operating system used
  • IP address used (if necessary: ​​in anonymous form)

The processing takes place in accordance with Article 6 Paragraph 1 Letter f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.

3) Cookies

In order to make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your end device. Some of these cookies are automatically deleted after closing the browser (so-called “session cookies”), some of these cookies remain on your end device for a longer period of time and enable page settings to be saved (so-called “persistent cookies”). In the latter case, you can find the storage period in the overview of the cookie settings in your web browser.

If personal data is also processed by individual cookies used by us, the processing takes place in accordance with Article 6 (1) (b) GDPR either for the execution of the contract, in accordance with Article 6 (1) (a) GDPR in the event that consent has been given or in accordance with Art. 6 (1) (f) GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general.

Please note that if cookies are not accepted, the functionality of our website may be restricted.

4) Contact

When contacting us (e.g. via contact form or email), personal data is processed – exclusively for the purpose of processing and answering your request and only to the extent required for this.

The legal basis for the processing of this data is our legitimate interest in answering your request in accordance with Article 6 (1) (f) GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted if it can be inferred from the circumstances that the facts in question have been finally clarified and provided that there are no legal storage obligations to the contrary.

5) Data processing when opening a customer account

In accordance with Article 6 Paragraph 1 Letter b GDPR, personal data will continue to be collected and processed to the extent required in each case if you provide it to us when opening a customer account. The data required for opening an account can be found in the input mask of the relevant form on our website.

A deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. After your customer account has been deleted, your data will be deleted provided that all contracts concluded have been completed, there are no legal retention periods to the contrary and we have no legitimate interest in further storage.

6) comment function

As part of the comment function on this website, your comment, information about the time the comment was created and the name of the commentator you have chosen will be saved and published on this website. Furthermore, your IP address will be saved for security reasons in order to enable attribution to the author in the event of illegal comments. Your e-mail address will be saved so that you can be contacted if a third party should complain that your published content is illegal.

The legal basis for the storage of your data is Article 6 Paragraph 1 lit. b and f GDPR. We reserve the right to delete comments if they are objected to as illegal by third parties.

7) Use of Customer Data for Direct Marketing

7.1 Subscribing to our email newsletter

If you register for our e-mail newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your e-mail address. Providing further data is voluntary and is used to be able to address you personally. We use the so-called double opt-in procedure to send the newsletter, which ensures that you only receive the newsletter if you have expressly confirmed your consent to receive the newsletter by clicking on a verification link sent to the email address provided

By activating the confirmation link, you give us your consent to the use of your personal data in accordance with Article 6 (1) (a) GDPR. We store your IP address entered by the Internet Service Provider (ISP) as well as the date and time of registration in order to be able to trace possible misuse of your e-mail address at a later point in time. The data we collect when registering for the newsletter is used strictly for the intended purpose.

You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a message to the person responsible mentioned above. After you have unsubscribed, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we will inform you in this declaration.

7.2 Sending the e-mail newsletter to existing customers

If you have provided us with your e-mail address when purchasing goods or services, we reserve the right to regularly send you offers for goods or services from our range by e-mail that are similar to those you have already purchased. According to Section 7 (3) UWG, we do not have to obtain your separate consent for this. In this respect, data processing takes place solely on the basis of our legitimate interest in personalized direct advertising in accordance with Article 6 (1) (f) GDPR. If you initially objected to the use of your e-mail address for this purpose, we will not send you an e-mail.

You are entitled to object to the use of your e-mail address for the aforementioned advertising purpose at any time with effect for the future by notifying the person responsible named at the beginning. You only incur transmission costs for this according to the basic tariffs. After receipt of your objection, the use of your e-mail address for advertising purposes will be stopped immediately.

7.3 Campaign.Plus

Our e-mail newsletter is sent via this provider: Campaign.Plus GmbH, Wollmarktstrasse 115b, 33098 Paderborn, Germany

Based on our legitimate interest in effective and user-friendly newsletter marketing, we pass on the data you provided when registering for the newsletter to this provider in accordance with Article 6 (1) (f) GDPR so that they can send the newsletter on our behalf.

Subject to your express consent in accordance with Article 6 (1) (a) GDPR, the provider also carries out a statistical evaluation of the success of newsletter campaigns using web beacons or tracking pixels in the emails sent, the opening rates and specific interactions with the content of the newsletter can be measured. Device information (e.g. time of access, IP address, browser type and operating system) is also collected and evaluated, but not merged with other databases.

You can revoke your consent to newsletter tracking at any time with effect for the future.

We have concluded an order processing contract with the provider, which protects the data of our site visitors and prohibits disclosure to third parties.

7.4 Postal Advertising
On the basis of our legitimate interest in personalized direct advertising, we reserve the right to store your first and last name, your postal address and - insofar as we have received this additional information from you as part of the contractual relationship - your title, academic degree, your year of birth and your professional, Store the industry or business name in accordance with Art. 6 (1) (f) GDPR and use it to send interesting offers and information about our products by post.
You can object to the storage and use of your data for this purpose at any time.

8) Data processing for order processing

8.1 Insofar as it is necessary for the execution of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned bank in accordance with Article 6 Paragraph 1 lit. b GDPR.

If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we process the contact data you provide when ordering (name, address, e-mail address) in order to inform you within the framework of our legal information obligations in accordance with Art. 6 Para 1 lit. c GDPR via a suitable communication channel (e.g. by post or e-mail) about upcoming updates in the period stipulated by law. Your contact details will be used strictly earmarked for notifications about updates owed by us and will only be processed by us for this purpose to the extent that this is necessary for the information in question.

In order to process your order, we also work together with the following service provider(s), who support us in whole or in part in the implementation of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.

8.2 Use of payment service providers (payment services)

- giropay

One or more online payment methods from the following provider are available on this website: paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main, Germany

If you select a payment method from the provider where you pay in advance (e.g. credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) and information about the content of your order will be sent to them passed on in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be passed on for the purpose of payment processing with the provider and only to the extent that it is necessary for this.
- Pay directly

One or more online payment methods from the following provider are available on this website: paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany

If you select a payment method from the provider where you pay in advance (e.g. credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) and information about the content of your order will be sent to them passed on in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be passed on for the purpose of payment processing with the provider and only to the extent that it is necessary for this.
-Paypal

One or more online payment methods from the following provider are available on this website: PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg

If you select a payment method from the provider where you pay in advance (e.g. credit card payment), the payment details you provided during the ordering process (including name, address, bank and payment card information, currency and transaction number) and information about the content of your order will be sent to them passed on in accordance with Art. 6 Para. 1 lit. b GDPR. In this case, your data will only be passed on for the purpose of payment processing with the provider and only to the extent that it is necessary for this.

If you select a payment method in which the provider makes an advance payment (e.g. invoice or installment purchase or direct debit), you will also be asked to enter certain personal data (first and last name, street, house number, zip code, city, date of birth, E -Mail address, telephone number, if necessary data on an alternative means of payment).

In order to safeguard our legitimate interest in determining the solvency of our customers, we forward this data to the provider for the purpose of a credit check in accordance with Article 6 (1) (f) GDPR. Based on the personal data you provide and other data (e.g. shopping cart, invoice amount, order history, payment history), the provider checks whether the payment option you have selected can be granted with regard to payment and/or bad debt risks.

The credit report can contain probability values ​​(so-called score values). As far as score values ​​are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical process. Among other things, but not exclusively, address data is included in the calculation of the score values.

You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for contractual payment processing.

9) Online Marketing

Facebook pixel to create custom audiences

Within our online offering, we use the "Facebook Pixel" service from the following provider: Meta Platforms Ireland Limited, 4 Grand Canal Quare, Dublin 2, Ireland ("Facebook")

If a user clicks on an advertisement placed by us on Facebook, the URL of our linked page is extended by a parameter with the help of "Facebook Pixel". After forwarding, this URL parameter is then entered into the user's browser by a cookie that our linked page sets itself.

On the one hand, this enables Facebook to determine the visitors of our online offer as a target group for the display of advertisements (so-called "Facebook Ads"). Accordingly, we use the service to only display the Facebook ads we have placed to those Facebook users who have also shown an interest in our online offer or who have certain characteristics (e.g. interests in certain topics or products, which are determined on the basis of the websites visited will have), which we transmit to Facebook (so-called “Custom Audiences”).

On the other hand, "Facebook Pixel" can be used to track whether users were redirected to our website after clicking on a Facebook ad and what actions they take there (so-called "conversion tracking").

The data collected is anonymous to us, so we cannot draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes.

All of the processing described above, in particular the setting of cookies for reading information on the end device used, will only be carried out if you have given us your express consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the “Cookie Consent Tool” provided on the website.

We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

The information generated by Facebook is usually transmitted to a Facebook server and stored there; in this context, data may also be transmitted to Meta Platforms Inc. servers in the USA.

For the transmission of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

10) Web Analytics Services

10.1 Google (Universal) Analytics

This website uses Google (Universal) Analytics, a web analysis service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.

Google (Universal) Analytics is used on this website exclusively without the use of cookies, which means that the service never sets cookies on your device.

Instead, the local memory of your browser is used to store an individual ID assigned by Google (Universal) Analytics, which enables an analysis of your use of the website. For this purpose, certain user information is processed via the ID. The scope of this information also includes your IP address, which, however, is shortened by Google by the last digits in order to exclude direct personal reference.

The information is transmitted to Google servers and processed there. Transmissions to Google LLC based in the USA are also possible.

Google uses the information collected on our behalf to evaluate your use of the website, to compile reports on website activity for us and to provide other services related to website activity and internet usage. The shortened IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. The data collected as part of the use of Google (Universal) Analytics is stored for a period of two months and then deleted.

All of the processing described above, including the storage of information on the end device used in the form of the ID, only takes place if you have given us your express consent in accordance with Article 6 (1) (a) GDPR.

Without your consent, Google (Universal) Analytics will not be used during your visit to the site. You can revoke your consent at any time with effect for the future.

To exercise your revocation, you can download and install the browser plug-in available under the following link:
https://tools.google.com/dlpage/gaoptout?hl=de

As an alternative to the browser plugin or within browsers on mobile devices, you can revoke your consent by clicking on the following link to set an opt-out cookie that will prevent future collection by Google Analytics within this website (this opt -Out-Cookie only works in this browser and only for this domain. If you delete your cookies in this browser, you must click this link again):
Disable Google Analytics

We have concluded an order processing contract with Google, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

For the transmission of data to the USA, Google relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with European data protection standards.

For more legal information about Google (Universal) Analytics, including a copy of the Standard Contractual Clauses mentioned, see https://policies.google.com/privacy ?hl=de &gl=de and under https://policies.google.com/technologies/partner-sites

Demographics
Google (Universal) Analytics uses the special "demographic characteristics" function and can use this to create statistics that make statements about the age, gender and interests of site visitors. This is done by analyzing advertising and information from third parties. This allows target groups to be identified for marketing activities. However, the collected data cannot be assigned to a specific person and will be deleted after being stored for a period of two months.

Google Signals
As an extension to Google (Universal) Analytics, Google Signals can be used on this website to create cross-device reports. If you have activated personalized ads and linked your devices to your Google account, Google can analyze your usage behavior across devices and database models, including cross-devices, subject to your consent to the use of Google Analytics in accordance with Article 6(1)(a) GDPR conversions, create. We do not receive any personal data from Google, only statistics. If you want to stop the cross-device analysis, you can disable the "Personalized advertising" function in your Google account settings. To do this, follow the instructions on this page: https://support.google.com /ads /answer /2662922 ?hl=en For more information about Google Signals, see the following link: https://support.google.com /analytics /answer /7532985 ?hl=en

UserIDs
As an extension to Google (Universal) Analytics, the "UserIDs" function can be used on this website. If you have consented to the use of Google (Universal) Analytics in accordance with Article 6(1)(a) GDPR, have set up an account on this website and log in to this account on different devices, your activities, including conversions, analyzed across devices.

10.2 PayPal Marketing Solutions

This website uses the web analysis service of the following provider: PayPal (Europe) S.à rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg

With the help of cookies and/or comparable technologies (tracking pixels, web beacons, algorithms for reading end device and browser information), the service collects and stores pseudonymised visitor data, including information on the end device used, such as the IP address and browser information, in order to be able to use it for to evaluate statistical analyzes of usage behavior on our website and to create pseudonymised usage profiles. Among other things, it is possible to evaluate movement patterns (so-called heat maps), which show the duration of page visits and interactions with page content (e.g. text input, scrolling, clicks and mouse-overs). Pseudonymisation basically excludes direct personal reference. A combination with other clear data collected about you does not take place.

All of the processing described above, in particular the reading out or saving of information on the end device used, will only be carried out if you have given us your express consent in accordance with Article 6 Paragraph 1 Letter a GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the “Cookie Consent Tool” provided on the website.

We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

10.3 Google Tag Manager

This website uses the "Google Tag Manager", a service of the following provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "Google").

The Google Tag Manager provides a technical basis for bundling various web applications, including tracking and analysis services, and being able to calibrate, control and attach conditions via a uniform user interface. The Google Tag Manager itself does not store or read any information on user devices. The service also does not carry out any independent data analyses. However, the Google Tag Manager transmits your IP address to Google when the page is accessed and may store it there. Also a transmission to servers of Google LLC. In the US it is possible.

This processing will only be carried out if you have given us your express consent in accordance with Article 6 (1) (a) GDPR. Without this consent, Google Tag Manager will not be used during your visit to the site. You can revoke your consent at any time with effect for the future. To exercise your revocation, please deactivate this service in the "Cookie Consent Tool" provided on the website.

We have concluded an order processing contract with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

For the transmission of data to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European level of data protection.

11) Retargeting/ remarketing and conversion tracking

Google Ads Remarketing
Our website uses the functions of Google Ads Remarketing, with which we advertise this website in Google search results and on third-party websites. The provider is Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"). For this purpose, Google sets a cookie in the browser of your end device, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. Any further data processing will only take place if you have given your consent to Google linking your Internet and app browser history to your Google account and using information from your Google account to personalize ads that you see on the web regard. In this case, if you are logged in to Google while visiting our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. To do this, Google will temporarily link your personal data to Google Analytics data in order to form target groups. As part of the use of Google Ads Remarketing, personal data may also be transmitted to the servers of Google LLC. come in the US.
Details on the processing initiated by Google Ads Remarketing and how Google handles data from websites can be found here: https://policies.google.com/technologies/partner-sites
You can permanently object to the setting of cookies by Google Ads Remarketing by downloading and installing the Google browser plug-in available under the following link:
https://support.google.com /ads /answer /7395996 ?
Further information and the data protection regulations regarding advertising and Google can be found here:
https://www.google.com/policies/technologies/ads/
All of the processing described above, in particular the setting of cookies for reading information on the end device used, will only be carried out if you have given us your express consent in accordance with Article 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the “Cookie Consent Tool” provided on the website.

12) Site Functionalities

Trusted Shops Trust Badge

Graphic elements from the following provider are integrated on our website to display external customer ratings and/or an externally awarded quality mark: Trusted Shops AG, Subbelrather Str. 15C, 50823 Cologne, Germany

If you call up a page on our website that contains such graphic elements, your browser establishes a direct connection to the provider's servers in order to load the elements properly. Certain browser information, including your IP address, is transmitted to the provider.

If personal data is also processed, this is done in accordance with Article 6 Paragraph 1 Letter f GDPR on the basis of our legitimate interest in the optimal marketing of our offer and the attractive design of our website.

13) Tools and Miscellaneous

Gambio

This website uses a service for the automatic transmission of error reports from the following provider: Gambio GmbH, Parallelweg 30, 28219 Bremen, Germany

In the event of technical complications or functional impairments in connection with the operation of the provider's software, the system automatically sends error reports to the provider containing information on the respective source of the error and its origin. Both server information and usage parameters such as the IP address, the browser used, the time stamp and the URL accessed are transmitted.

Depending on the origin of the error, error reports may also contain further personal customer data that we have collected and stored in the course of concluding contracts (in particular first and last name, address, e-mail address). This is always conceivable if the error occurs in connection with software-based processing of customer data.

If personal data is also part of the information transmitted in this way, processing is carried out in accordance with Article 6 (1) (f) GDPR on the basis of our legitimate interest in an efficient analysis of the causes of errors to improve the reliability and functionality of our website.

14) Rights of the data subject

14.1 The applicable data protection law grants you the following data subject rights (rights to information and intervention rights) vis-à-vis the person responsible with regard to the processing of your personal data, whereby reference is made to the legal basis given for the respective exercise requirements:

  • Right to information according to Art. 15 GDPR;
  • Right to rectification according to Art. 16 GDPR;
  • Right to erasure according to Art. 17 GDPR;
  • Right to restriction of processing in accordance with Art. 18 GDPR;
  • Right to information according to Art. 19 GDPR;
  • Right to data portability according to Art. 20 GDPR;
  • Right to revoke granted consent in accordance with Art. 7 Para. 3 GDPR;
  • Right to complain according to Art. 77 GDPR.

14.2 RIGHT TO OBJECT

IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF A BALANCING OF INTERESTS IN OUR PREVIOUS LEGITIMATE INTERESTS, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THIS PROCESSING FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP THE PROCESSING OF THE DATA INVOLVED. HOWEVER, FURTHER PROCESSING REMAINS RESERVED IF WE CAN PROVE COMPREHENSIVE REASONS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FUNDAMENTAL FREEDOMS, OR IF THE PROCESSING IS FOR THE CERTIFICATION, EXERCISE OR DEFENSE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT ADVERTISING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING. YOU MAY OBJECT AS DESCRIBED ABOVE.

IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP THE PROCESSING OF THE DATA INVOLVED FOR DIRECT MARKETING PURPOSES.

15) Duration of storage of personal data

The duration of the storage of personal data is based on the respective legal basis, the processing purpose and - if relevant - also based on the respective statutory retention period (e.g. commercial and tax retention periods).

When processing personal data on the basis of an express consent in accordance with Article 6 Paragraph 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.

If there are statutory retention periods for data that are processed as part of legal or similar obligations on the basis of Article 6 (1) (b) GDPR, this data will be routinely deleted after the retention period has expired, provided that it is no longer required to fulfill or initiate a contract and/or we have no legitimate interest in further storage.

When processing personal data on the basis of Article 6 Paragraph 1 Letter f GDPR, this data will be stored until you exercise your right of objection in accordance with Article 21 Paragraph 1 GDPR, unless we can provide compelling reasons worthy of protection prove the processing that outweighs your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

When processing personal data for the purpose of direct advertising on the basis of Article 6 (1) (f) GDPR, this data will be stored until you exercise your right of objection under Article 21 (2) GDPR.

Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.