Privacy Policy
With this Privacy Policy, we would like to inform you about the nature, scope, and purpose of the processing of personal data in our Etsy shop.
Name and contact details of the data controller
The controller is:
Phone:
Email:
Terms and Definitions
The following terms are used in this Privacy Policy:
Personal data
Data subject
Processing
Restriction of processing
Controller
Recipient
Third-party
Consent
These terms are all defined in Art. 4 of the General Data Protection Regulation (hereinafter: GDPR).
Scope of processing of personal data
You have already been informed about the scope and purpose of the collection and storage of your personal data by Etsy as part of your registration on Etsy. Etsy maintains its own privacy policy on this subject, which you can find at the following link: https://www.etsy.com/de/legal/privacy/ . As part of your registration with Etsy, you consented to Etsy sending us your personal data for the purpose of contract processing. Specifically, this is the data we need to fulfill the contract concluded between us. This includes, in particular, your name and address details, as well as the services used. This data is stored by us. We do not collect or store any other personal data concerning you.
Purpose of Data Processing
The processing itself is based on your order and serves to process your order and fulfill the contract concluded between us. Specifically, we use the data transmitted to us by Etsy in particular to
identify you as our customer,
process, fulfill, and handle your order,
contact you,
invoice you,
handle any liability claims, and
assert contractual claims against you.
Disclosure of data to third parties
We will only disclose your personal data to third parties if:
You have expressly consented to this in accordance with Art. 6 (1) (a) GDPR,
the disclosure is necessary in accordance with Art. 6 (1) (f) GDPR to assert, exercise, or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data,
there is a legal obligation to do so in accordance with Art. 6 (1) (c) GDPR,
this is necessary for the execution of the contract concluded with you in accordance with Art. 6 (1) (b) GDPR (e.g., disclosure of data to the logistics company commissioned with the delivery or for the purpose of payment processing).
Furthermore, your personal data will not be disclosed to third parties without your express consent. If we disclose your personal data to third parties, we limit the scope of the data transmitted to the minimum necessary.
Legal Basis
The legal basis for processing your data, with regard to the processing of your order, is Art. 6 (1) (b) GDPR. This also applies to processing operations necessary to carry out pre-contractual measures. If processing is necessary to fulfill a legal obligation to which we are subject, Art. 6 (1) (c) GDPR serves as the legal basis. If processing is necessary to protect one of our legitimate interests or that of a third party, and your interests, fundamental rights, and freedoms do not outweigh the former interest, Art. 6 (1) (f) GDPR serves as the legal basis for processing.
Storage Period and Data Deletion
Due to commercial and tax law requirements, we are obliged to store your address, payment, and order data for a period of 10 years. However, after the expiration of the statutory warranty period (2 years), we restrict processing to the extent that your data will only be used to comply with legal obligations.
Rights of Data Subjects
Under the GDPR, you are entitled to the following rights, which you can assert at any time with the controller named in Section 1 of this Privacy Policy:
Right to Information: Pursuant to Art. 15 GDPR, you can request confirmation as to whether and which of your personal data we process. Furthermore, you can request information from us free of charge about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing, or objection, the existence of a right to lodge a complaint, and the origin of your data, if it was not collected by us. Furthermore, you have the right to information as to whether your personal data has been transferred to a third country or to an international organization. If this is the case, you have the right to receive information about the appropriate safeguards in connection with the transfer.
Right to rectification: According to Art. 16 GDPR, you can request the rectification of inaccurate personal data concerning you stored by us or the completion of incomplete personal data.
Right to erasure: According to Art. 17 GDPR, you have the right to request the erasure of your personal data stored by us, provided that we do not need to process it
to fulfill a legal obligation,
to assert, exercise, or defend legal claims,
to exercise the right to freedom of expression and information, or
for reasons of public interest referred to in Art. 17 (3) (c) and (d) GDPR.
Right to restriction: According to Art. 18 GDPR, you have the right to request the restriction of the processing of your personal data if:
you contest the accuracy of the data, for a period enabling us to verify the accuracy of the personal data;
the processing of your data is unlawful, but you refuse to delete it and instead request that its use be restricted;
we no longer need the personal data for the purposes of processing, but you require the data to assert, exercise, or defend legal claims;
you have objected to the processing of your data pursuant to Art. 21 GDPR, but it has not yet been determined whether the legitimate reasons that entitled us to continue processing despite your objection outweigh your rights.
Right to information: If you have asserted your right to rectification, erasure, or restriction of processing against us, we are obliged to inform all recipients to whom the personal data concerning you was disclosed of the rectification, erasure, or restriction of processing you have requested, unless doing so proves impossible or involves disproportionate effort. You have the right to be informed by us of these recipients.
Right to data portability: According to Art. 20 GDPR, you can request that we receive the personal data concerning you that you have provided to us in a structured, common, and machine-readable format or request that it be transmitted to another controller.
Right to lodge a complaint: According to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. To do so, you can contact the supervisory authority of your habitual residence, your place of work, or our company headquarters.
Right of withdrawal: According to Art. 7 (3) GDPR, you have the right to withdraw your consent to the processing of your data at any time. Your withdrawal does not change the legality of the processing of your personal data carried out up to the time of withdrawal.
Right of withdrawal: According to Art. 7 (3) GDPR, you have the right to withdraw your consent to the processing of your data at any time. Your withdrawal of consent does not change the legality of the processing of your personal data carried out up to the time of withdrawal.
Right of objection
You have the right to object at any time to the processing of personal data concerning you based on a balance of interests (Art. 6 (1) (f) GDPR), for reasons arising from your particular situation. This is particularly the case if the data processing is not necessary to fulfill a contract. If you exercise your right of objection, we ask you to explain the reasons. We will then no longer process your personal data unless we can demonstrate to you that compelling legitimate grounds for data processing outweigh your interests and rights.
Notwithstanding the above, you have the right to object to the processing of your personal data for advertising and data analysis purposes at any time.
Security Measures
For information on data security, please refer to the privacy policy provided by Etsy, which can be accessed via the link provided in Section 4.
We also take state-of-the-art technical and organizational security measures to comply with data protection laws and to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties.
Currency and Changes to This Privacy Policy
This Privacy Policy is currently valid and was last updated in July 2022.
Due to the further development of Etsy's website or due to changes in legal or regulatory requirements, it may become necessary to adapt this Privacy Policy.