Privacy Policy


*** PRIVACY POLICY ***

1. Name and address of the person responsible for data processing
The controller responsible for processing personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is: Grüezi bag GmbH, Managing Director: Markus Wiesböck, Schmiedgasse 31, D-83075 Bad Feilnbach, Telephone: +49 80 64 / 906 29 220, Fax: +49 80 64 / 906 29 24, Email: info@gz-bag.de

When you access our website, we use the widespread SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser. This is generally 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is being transmitted encrypted by the closed display of the key or lock symbol in the lower status bar of your browser. We also use suitable technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

2. Cookies
This website uses so-called cookies. Cookies are text files that expressly do not contain any personal data and are created on your computer and saved by the browser you use. The use of cookies enables our systems to recognize your browser and offer you additional useful information. If personal data is also processed by individual cookies we use, the processing is carried out in accordance with Article 6 (1) (b) GDPR either to execute the contract or in accordance with Article 6 (1) (f) GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the visit to this website operated by us. However, you can configure your browser so that no cookies are saved on your computer or so that a warning always appears before a new cookie is created. Please refer to the description of the browser you are using for details. However, completely deactivating cookies may mean that you cannot use all functions of our website.

3. Social plugins
This website uses so-called "social plugins" from Facebook and Twitter.
We provide you with the following information:

a) Information on the use of Google Analytics
This website uses "Google Analytics". This is a web analysis service provided by Google Inc. We would like to point out that on this website Google Analytics has been extended by the code "gat._anonymizeIp();" to ensure anonymous recording of IP addresses (so-called IP masking). Google Analytics uses so-called "cookies", text files that are stored on your computer and enable an analysis of website usage by the customer. The information generated by the cookie about the use of this website is transmitted to a Google Inc. server in the USA and stored there. If IP anonymization is activated on this website, your IP address will be shortened by Google Inc. within the member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google Inc. server in the United States and then shortened there. On behalf of the operator of this website, Google Inc. will evaluate the information collected about your website usage in order to compile reports on website activity and to provide the operator with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be linked to any other data held by Google Inc. If you do not agree, you can prevent cookies from being saved by selecting the appropriate settings in your browser software. However, if you do this, you may not be able to use all the functions of this website. You can also prevent Google Inc. from collecting the data generated by the cookie and relating to your use of the website, including your IP address, by downloading and installing the browser add-on for deactivating "Google Analytics" available under the following link (http://tools.google.com/dlpage/gaoptout?hl=de). By using this browser add-on to deactivate Google Analytics JavaScript (ga.js, analytics.js, dc.js), visitors to the website can prevent Google Analytics from using their data. Please note that using this browser plug-in may prevent all functions of this website from being available.

b) Notes on using the Facebook plug-in
This website uses plug-ins from the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, California 94025, USA. Facebook plug-ins can be identified by the Facebook logo or "Like" button. An overview of Facebook plug-ins can be found here: http://developers.facebook.com/docs/plugins/. When you visit this website, a direct connection is established between your browser and the Facebook server via the plug-in. This transmits to Facebook the information that you have visited this website using your IP address. If you are logged in to Facebook and click the "Like" button, you can link the content of this website to your Facebook profile. Facebook can then associate your visit to our website with your user account. Further information on the data transmitted and processed by Facebook can be found in Facebook's privacy policy at http://de-de.facebook.com/policy.php. If you want to prevent Facebook from associating your visit to our website with your Facebook user account, please log out of Facebook.

c) Information on using the Twitter service
This website uses functions of the Twitter service provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. By using Twitter and the "Retweet" function, the websites you visit are linked to your Twitter account and made known to other users. Data is also transferred to Twitter in the process. Further information on the data transferred and how Twitter processes this data can be found in Twitter's privacy policy at http://twitter.com/privacy. You can change your privacy settings on Twitter in your account settings at http://twitter.com/account/settings.

4. Collection of general data and information
a) Collection of data
When you visit our website, your device's browser automatically sends information to us. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until it is automatically deleted:

- IP address of the requesting computer,
- Date and time of access,
- Name and web address of the retrieved file,
- Website from which access is made,
- browser used and, if applicable, the operating system of your computer as well as the name of the provider.

The data mentioned are processed by us for the following purposes:

- Ensuring a smooth connection to the website,
- Ensuring comfortable use of our website,
- Evaluation of the system security and stability of our website,
- for further administrative purposes.

The legal basis for data processing is Article 6 (1) (f) GDPR.

Our legitimate interest arises from the purposes for data collection listed above. Under no circumstances will we use the collected data to draw conclusions about you personally.

b) Disclosure of collected data
A transfer of your personal data to third parties for purposes other than those listed below does not take place.

We only share your personal information with third parties if:

- you have given your express consent in accordance with Article 6 (1) (a) GDPR,

- the transfer is necessary according to Article 6 (1) (f) GDPR to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in not transferring your data,

- in the event that there is a legal obligation to transfer data in accordance with Article 6 (1) (c) GDPR, and

- this is legally permissible and is necessary according to Article 6 (1) (b) GDPR for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures taken at the request of the data subject.

5. Data processing during registration on our website
The data subject has the possibility to register on the website of the data controller by providing personal data. The personal data to be sent to the controller is derived from the respective input mask used for the registration. The personal data entered by the data subject shall be collected and stored solely for internal use by the controller and for his own purposes. The controller may arrange for the transfer to one or more processors, such as a parcel service, who also uses the personal data only for internal use attributable to the controller.

By registering on the website of the controller, the IP address assigned to the data subject by the Internet service provider, as well as the date and time of registration, are also stored. This data is stored because it is the only way to prevent misuse of our services and, if necessary, to enable the investigation of committed crimes. Therefore, the storage of this data is necessary to protect the controller. As a general rule, this data will not be passed on to third parties unless there is a legal obligation to do so or the transfer serves the purpose of criminal prosecution.

By registering the data subject voluntarily providing personal data, the data controller serves to provide the data subject with content or services that, due to the nature of the case, can only be offered to registered users. Registered persons are free to modify the personal data given at registration at any time or to delete it completely from the database of the data controller.

The controller shall, at any time upon request, provide information to each data subject as to which personal data about the data subject is stored. Furthermore, the data controller corrects or deletes personal data at the request or reference of the data subject, insofar as this does not conflict with any statutory storage requirements. All data subjects of the controller are available to the data subject as a contact person in this context.

6. Data processing in the context of order processing
a) The personal data we collect will be passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the delivery of the goods. If the delivery is made by a transport company, we will pass on your email address to this company in accordance with Article 6 (1) (a) GDPR before the goods are delivered if you have given your express consent to do so. Otherwise, in accordance with Article 6 (1) (b) GDPR, we will only pass on the name of the recipient and the delivery address to the transport company insofar as this is necessary for the delivery of the goods. Consent given can be revoked at any time with future effect by notifying the person responsible named above or the transport service provider.

b) We will pass on your payment details to the commissioned credit institution as part of the payment processing, solely to the extent that this is necessary for the payment processing.

(1) When paying by credit card via PayPal or by direct debit via PayPal, the customer's payment data will be passed on to PayPal (Europe) S.à rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg, in accordance with Article 6 (1) (b) GDPR and only to the extent necessary for payment processing. After the contract has been fully processed, the customer's data will be blocked with regard to retention periods under tax and commercial law and deleted after the expiry of these aforementioned periods unless the customer has expressly consented to further use of the data. Further information on data protection can be found in the PayPal data protection principles at https://www.paypal.com/de/webapps/mpp/ua/privacy-full. The legal basis for the transfer of data is Article 6 (1) (b) GDPR.

(2) If you select "Sofort" (hereinafter "Sofort") as your payment method, your contact details will be transmitted to the service provider Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden, as part of the order processing. The personal data transmitted includes, in particular, your first name, last name, address, telephone number, IP address, email address, or other data required for order processing, as well as data related to the order, such as the item name, item number, number of ordered items, invoice amount, etc. Sofortüberweisung may also share personal data with service providers, subcontractors, or other affiliated companies if this is necessary to fulfill contractual obligations or if the personal data is to be processed on behalf of the service provider. Under certain circumstances, the personal data transmitted to the service provider will be transmitted by the service provider to credit agencies. This transmission serves to verify your identity and creditworthiness in relation to the order you have placed. The "Sofort" privacy policy will also be displayed during the payment process. If you have any questions about the use of your personal data, please contact the service provider. You can find the contact details in the imprint at https://www.klarna.com/sofort/impressum/.

7. Duration of storage of personal data
The duration of storage of personal data depends on the applicable statutory retention period. After expiration of the respective retention period, the corresponding data will be deleted if it is no longer required for the fulfillment or initiation of a contract and/or if we no longer have a legitimate interest in continued storage.

8. Contact possibility via the webiste
Our website contains data that enables quick electronic contact with our company and direct communication with us, which also includes a general address for so-called electronic mail (email address). If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject will be automatically stored. Such personal data voluntarily transmitted by a data subject to the controller will be stored for the purposes of processing the request or for contacting the data subject. This personal data will not be passed on to third parties.

9. Subscribe to the newsletter
a) Collection of data when registering for the newsletter
Upon express request, we will regularly inform you about current offers and news via a newsletter. Our company's newsletter can generally only be received by the data subject if the recipient has a valid e-mail address and has also registered for the newsletter. A confirmation e-mail will be sent to an e-mail address registered for the first time for the purpose of verifying whether the owner of the e-mail address, as the data subject, has authorized receipt of the newsletter. When registering for the newsletter, the personal data provided by the user in the registration form, the IP address assigned to the data subject by the Internet service provider, and the date and time of registration are stored. This aforementioned data collection is necessary in order to be able to trace any misuse of the data of a data subject at a later date.

The personal data collected when you register for the newsletter will be used exclusively to send our newsletter. Furthermore, newsletter subscribers may be informed by email if this is necessary for the operation of the newsletter service or a related registration, as could be the case in the event of changes to the newsletter offer or changes to technical conditions. The personal data collected as part of our newsletter will not be passed on to third parties. You can cancel your newsletter subscription at any time. You can revoke your consent to the storage of personal data, which you gave us during registration for the purpose of sending the newsletter, at any time. For this purpose, every newsletter contains an unsubscribe link that you can use to unsubscribe. You also have the option of unsubscribing directly on our website at any time and/or informing us of this request, e.g. by email.

b) Newsletter tracking
The newsletter we send contains so-called tracking pixels. These are miniature graphics embedded in emails sent in HTML format to enable log file recording and analysis. Using such a tracking pixel, we can determine whether and when an email was opened and which links within the email were clicked. This helps us conduct a statistical evaluation of the success or failure of online marketing campaigns.

Such personal data collected via the tracking pixels contained in the newsletters are stored and further evaluated by the controller. This personal data will not be passed on to third parties. Data subjects are entitled to revoke the separate declaration of consent given via the double opt-in procedure at any time. After revocation and also after unsubscribing from the newsletter, this personal data will be deleted by the controller.

10. Duration of storage of personal data
The duration of storage of personal data is determined by the respective statutory retention period. After expiration of the applicable retention period, we routinely delete this data if it is no longer required for contractual purposes and/or there is no longer a legitimate interest in continuing to store it on our website.

11. Data subject rights
With regard to the processing of your personal data, you are entitled to the following rights as a data subject. You have:

- Right to information, Article 15 GDPR: This includes the right to information about your personal data processed by us, the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients to whom your data has been or will be disclosed, the planned storage period or the criteria for determining the storage period, the existence of a right to rectification, erasure, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if it was not collected from you by us, the existence of automated decision-making including profiling and, if applicable, meaningful information about the logic involved and the scope and intended effects of such processing concerning you, as well as your right to information about the guarantees pursuant to Article 46 GDPR when your data is transferred to third countries;

- Right to rectification, Article 16 GDPR: This includes the right to have inaccurate data concerning you rectified without delay and/or to have incomplete data stored by us completed;

- Right to erasure, Article 17 GDPR: This includes the right to request that we erase your personal data if the requirements of Article 17 (1) GDPR are met. However, this right does not apply if processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest, or to assert, exercise, or defend legal claims.

- Right to restriction of processing, Article 18 GDPR: This includes the right to request the restriction of the processing of your personal data as long as the accuracy of your data, which you contest, is being verified, if you refuse to delete your data due to unlawful data processing and instead request the restriction of the processing of your data, if you need your data to assert, exercise or defend legal claims after we no longer need this data after the purpose has been achieved or if you have lodged an objection for reasons related to your particular situation, as long as it has not yet been subsequently determined whether our legitimate reasons outweigh yours;

- Right to information, Article 19 GDPR: If you have asserted your right to rectification, erasure, or restriction of processing vis-à-vis the designated controller, the controller is obligated to inform all recipients to whom the personal data concerning you was disclosed of this rectification, erasure, or restriction of processing, unless doing so proves impossible or involves disproportionate effort. You have the right to be informed by the controller of these recipients.

- Right to data portability, Article 20 GDPR: This includes the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transmitted to another controller, where technically feasible;

- Right to revoke consent granted, Article 7 (3) GDPR: This includes the right to revoke consent to the processing of data at any time with future effect. In the event of a declared revocation, we will delete the data in question immediately, unless further processing can be based on a legal basis for processing without consent. The revocation of consent does not affect the legality of the processing carried out on the basis of the consent until the revocation.

- Right to lodge a complaint, Article 77 GDPR: Irrespective of any existing administrative or judicial remedies, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of personal data concerning you violates the provisions of the GDPR.

+ + + + + + + + + + +
12. RIGHT TO OBJECT
IF YOUR PERSONAL DATA IS PROCESSED ON THE BASIS OF LEGITIMATE INTERESTS PURSUANT TO ARTICLE 6 (1) (SENTENCE 1) (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING OF YOUR PERSONAL DATA WITH FUTURE EFFECT PURSUANT TO ARTICLE 21 GDPR, PROVIDED THAT THERE ARE REASONS ARISING FROM YOUR PARTICULAR SITUATION. The controller will then no longer process the personal data unless they can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or the processing serves to assert, exercise, or defend legal claims. If your objection is directed against direct marketing, you have a general right of objection, which we will implement without requiring you to state a particular situation. If you wish to exercise your right of objection, simply send an email to: info@gz-bag.de
+ + + + + + + + + + +

13. Information and contact
You have the right at any time to obtain free information from the user about your stored data, as well as, if applicable, the right to correct, block, or delete this data. You can therefore request information about the data we store from us at any time, free of charge. We expressly point out the right of objection granted above.

Transparency in data protection is important to us! If you have any questions, please contact us:

Grüezi bag GmbH
Managing Director: Markus Wiesböck
Schmidgasse 31
D-83075 Bad Feilnbach
Telephone: +49 80 64 / 906 29 220
Fax: +49 80 64 / 906 29 24 
Email: info[at]gz-bag.de