Privacy Policy
1) INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data refers to all data that can be used to personally identify you.
1.2 The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Beyza Nur Baslik, Ayza Fashion, Lise-Meitner-Straße 11, 45699 Herten, Germany, email: support@ayzafashion.de. The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
If you use our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you came to the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
Processing is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be shared or used for any other purpose. However, we reserve the right to subsequently review the server log files if there are concrete indications of illegal use.
3) HOSTING
External hosting
This website is hosted by an external service provider (hoster). The personal data collected on this website is stored on the hoster's servers. This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access, and other data generated via a website.
The hoster is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 (1) (b) GDPR) and in the interest of a secure, fast and efficient provision of our online service by a professional provider (Art. 6 (1) (f) GDPR).
Our host will only process your data to the extent necessary to fulfill its service obligations and will follow our instructions regarding this data.
We use the following hoster:
IONOS SE
Elgendorfer Str. 57
56410 Montabaur
4) COOKIES
To make visiting our website more attractive and enable the use of certain functions, we use cookies, i.e., small text files that are stored on your device. Some of these cookies are automatically deleted after closing your browser (so-called "session cookies"); others remain on your device for a longer period and allow you to save page settings (so-called "persistent cookies"). In the latter case, you can find out how long cookies are stored in the overview of your web browser's cookie settings.
If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 (1) (b) GDPR either to execute the contract, in accordance with Art. 6 (1) (a) GDPR in the event of consent being given, or in accordance with Art. 6 (1) (f) GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.
You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or to exclude the acceptance of cookies in certain cases or in general.
Please note that if you do not accept cookies, the functionality of our website may be limited.
5) CONTACT
5.1 When you contact us (e.g., via contact form or email), personal data will be processed exclusively for the purpose of processing and responding to your request and only to the extent necessary for this purpose. The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 (1) (f) GDPR. If your contact is aimed at a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention periods to the contrary.
5.2 WhatsApp Business
We offer visitors to our website the opportunity to contact us via the WhatsApp messaging service provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For this purpose, we use the so-called "Business Version" of WhatsApp.
If you contact us via WhatsApp regarding a specific transaction (for example, a placed order), we will store and use the mobile phone number you use for WhatsApp and – if provided – your first and last name in accordance with Art. 6 (1) (b) GDPR to process and respond to your request. Based on the same legal basis, we may ask you via WhatsApp to provide additional data (order number, customer number, address, or email address) so that we can assign your request to a specific process.
If you use our WhatsApp contact for general inquiries (e.g. about the range of services, availability or our website), we will save and use the mobile phone number you use on WhatsApp and - if provided - your first and last name in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in the efficient and timely provision of the requested information.
Your data will only be used to respond to your request via WhatsApp. It will not be shared with third parties.
Please note that WhatsApp Business receives access to the address book of the mobile device we use for this purpose and automatically transfers telephone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. To operate our WhatsApp Business account, we use a mobile device whose address book only stores the WhatsApp contact data of users who have contacted us via WhatsApp.
This ensures that every person whose WhatsApp contact details are stored in our address book has consented to the transmission of their WhatsApp telephone number from the address books of their chat contacts in accordance with Art. 6 (1) (a) GDPR by accepting the WhatsApp Terms of Use upon first use of the app on their device. The transmission of data from users who do not use WhatsApp and/or have not contacted us via WhatsApp is therefore excluded.
For information on the purpose and scope of data collection and the further processing and use of data by WhatsApp, as well as your rights and setting options for protecting your privacy, please refer to WhatsApp's privacy policy: https://www.whatsapp.com/legal/?eea=1#privacy-policy
6) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT
In accordance with Art. 6 (1) (b) GDPR, personal data will continue to be collected and processed to the extent necessary if you provide it to us when opening a customer account. You can find out which data is required to open an account in the input mask of the corresponding form on our website. You can delete your customer account at any time by sending a message to the controller at the above-mentioned address. After your customer account has been deleted, your data will be deleted provided that all contracts concluded through it have been fully processed, there are no statutory retention periods to the contrary, and we have no legitimate interest in continuing to store it.
7) DATA PROCESSING FOR ORDER PROCESSING
7.1 To the extent necessary for the execution of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 (1) (b) GDPR.
If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we will process the contact information you provided when placing your order (name, address, email address) in order to inform you personally about upcoming updates within the legally stipulated period via a suitable communication channel (e.g., by post or email) within the scope of our statutory information obligations pursuant to Art. 6 (1) (c) GDPR. Your contact information will be used strictly for the purpose of notifying you about updates owed by us and will only be processed by us to the extent necessary for the respective information.
To process your order, we also work with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.
7.2 Use of payment service providers (payment services)
– Klarna
If you select a Klarna payment service, the payment will be processed via Klarna Bank AB (publ), https://www.klarna.com/de/ , Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna"). To enable payment processing, your personal data (first and last name, street, house number, postal code, city, gender, email address, telephone number, and IP address) as well as data related to the order (e.g., invoice amount, item, delivery method) will be passed on to Klarna for the purpose of identity and credit checks, provided that you have expressly consented to this in accordance with Art. 6 (1) (a) GDPR during the ordering process. You can see which credit agencies your data may be forwarded to here:
https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies
The credit report may contain probability values (so-called score values). To the extent that score values are included in the credit report results, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. Klarna uses the information obtained regarding the statistical probability of a payment default to make a considered decision regarding the establishment, implementation, or termination of the contractual relationship.
You can revoke your consent at any time by sending a message to the data controller or to Klarna. However, Klarna may still be entitled to process your personal data if this is necessary for contractual payment processing.
Your personal data will be processed in accordance with applicable data protection regulations and in accordance with the information in Klarna's privacy policy for data subjects based in Germany https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy
or for those affected based in Austria https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_at/privacy
treated.
– Paypal
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "payment by installments" via PayPal, we will pass your payment data on to PayPal (Europe) Sarl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. This transfer takes place in accordance with Art. 6 (1) (b) GDPR and only to the extent necessary for payment processing.
PayPal reserves the right to conduct a credit check for payment methods such as credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "payment by installments" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 (1) (f) GDPR based on PayPal's legitimate interest in determining your ability to pay. PayPal uses the result of the credit check regarding the statistical probability of default to decide whether to provide the respective payment method. The credit check may contain probability values (so-called score values). To the extent that score values are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is used to calculate the score values. For further data protection information, including information on the credit agencies used, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
- IMMEDIATELY
If you select the "SOFORT" payment method, payment processing will be handled by the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we will forward the information you provided during the ordering process, along with information about your order, in accordance with Art. 6 (1) (b) GDPR. Sofort GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data will be transferred exclusively for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this purpose. You can find further information about SOFORT's privacy policy at the following website address: https://www.klarna.com/sofort/datenschutz .
8) PAGE FUNCTIONALITIES
– FontAwesome
This website uses so-called web fonts from "FontAwesome," a service provided by Fonticons, Inc., 710 Blackhorn Dr, Carl Junction, 64834, MO, USA ("FontAwesome"), to ensure consistent font display. When you visit a page, your browser loads the required web fonts into your browser cache to display text and fonts correctly.
For this purpose, the browser you use must establish a connection to the FontAwesome servers. This may also result in the transmission of personal data to the FontAwesome servers in the USA. In this way, FontAwesome becomes aware that our website was accessed via your IP address. The processing of personal data when establishing a connection with the font provider will only take place if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a standard font from your computer will be used.
For more information about FontAwesome, please visit: https://fontawesome.com/privacy
– Google Web Fonts
This website uses so-called web fonts provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google") for the consistent display of fonts. When you visit a page, your browser loads the required web fonts into your browser cache to display text and fonts correctly.
For this purpose, the browser you use must establish a connection to Google's servers. This may also result in the transmission of personal data to the servers of Google LLC in the USA. In this way, Google becomes aware that our website was accessed via your IP address. The processing of personal data when establishing a connection with the font provider will only take place if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future by deactivating this service in the "Cookie Consent Tool" provided on the website. If your browser does not support web fonts, a standard font from your computer will be used.
For more information about Google Web Fonts, see https://developers.google.com/fonts/faq and in Google’s privacy policy: https://www.google.com/policies/privacy/
9) TOOLS AND MISCELLANEOUS
Cookie Consent Tool
This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users when they visit the page in the form of an interactive user interface, where consent for specific cookies and/or cookie-based applications can be given by checking the appropriate boxes. By using the tool, all cookies/services that require consent are only loaded if the respective user gives their consent by checking the appropriate boxes. This ensures that such cookies are only placed on the user's device if consent has been given.
The tool uses technically necessary cookies to save your cookie preferences. Personal user data is generally not processed.
If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.
A further legal basis for processing is Art. 6 (1) (c) GDPR. As the controller, we are legally obliged to make the use of technically unnecessary cookies dependent on the respective user's consent.
Further information about the operator and the setting options of the cookie consent tool can be found directly in the corresponding user interface on our website.
10) RIGHTS OF THE DATA SUBJECT
10.1 The applicable data protection law grants you the following data subject rights (rights of information and intervention) vis-à-vis the controller with regard to the processing of your personal data, whereby reference is made to the legal basis stated for the respective conditions for exercising these rights:
- Right to information pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to information pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to revoke consent given in accordance with Art. 7 (3) GDPR;
- Right to lodge a complaint pursuant to Art. 77 GDPR.
10.2 RIGHT OF OBJECTION
IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTEREST AS PART OF A BALANCE OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME WITH FUTURE EFFECT FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION.
If you exercise your right to object, we will stop processing the data in question. However, we reserve the right to continue processing if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves to assert, exercise, or defend legal claims.
If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes. You can exercise your right of objection as described above.
IF YOU EXERCISE YOUR RIGHT OF OBJECTION, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.
11) PERIOD OF STORAGE OF PERSONAL DATA
The duration of storage of personal data is determined by the respective legal basis, the purpose of the processing and – where applicable – also by the respective statutory retention period (e.g. retention periods under commercial and tax law).
When personal data is processed on the basis of an express consent in accordance with Art. 6 (1) (a) GDPR, this data will be stored until the data subject revokes his or her consent.
If there are statutory retention periods for data that are processed within the framework of legal transactions or obligations similar to legal transactions on the basis of Art. 6 (1) (b) GDPR, these data will be routinely deleted after the retention periods have expired, provided that they are no longer required to fulfil or initiate a contract and/or we no longer have a legitimate interest in continuing to store them.
When processing personal data on the basis of Art. 6 (1) (f) GDPR, these data will be stored until the data subject exercises his or her right of objection in accordance with Art. 21 (1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which outweigh the interests, rights and freedoms of the data subject, or the processing serves to assert, exercise or defend legal claims.
When processing personal data for the purpose of direct marketing on the basis of Art. 6 (1) (f) GDPR, these data will be stored until the data subject exercises his or her right of objection in accordance with Art. 21 (2) GDPR.
Unless otherwise stated in the other information in this statement on specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.