A configurator is available for each of your desired items. Ab einem Bestellwert von 350,00 € liefern wir kostenfrei in DE, AT, LU und CH. We supply you in DE, AT, LU and CH with our own delivery fleet
0561-220798-0

Data protection

1. Name and contact details of the controller as well as of the internal data protection officer

This information notice regarding data protection shall apply to data processed by:

Controller: Heike Sostmann, trading under the name Spiegel-Shop

Holländische Str. 205b, 34127 Kassel

Phone number: 0561-220798-0, Fax number: 0561-220798-29, E-mail address: info@myspiegel.de

The appointment of an internal data protection officer is not necessary as a result of the size of the company. The contact person in matters concerning personal data protection is the owner of the controller at the above-mentioned address.

2. Collection and recording of personal data, as well as the nature and purposes of the processing

a) When you visit the website

When you access our website www.myspiegel.de, through the browser used on your device, information is sent automatically to the server of our website. This information is stored temporarily in a so-called log file. The following data is collected, without any action on your part and stored until it is automatically erased:

  • IP address of the requesting computer,
  • Date and time of access,
  • Name and URL of the retrieved data,
  • Website from which the access is made (referrer URL),
  • Browser used and eventually the operating system of your computer, as well as the name of your access provider.

The data referred to is processed by us with the following purposes:

  • To ensure a smooth connection setup of the website,
  • To ensure a comfortable use of our website,,
  • To evaluate the system security and stability, as well as
  • for other administrative purposes.

The legal basis for data processing is Art. 6 paragraph 1 sentence 1 point (f) GDPR. Our legitimate interest is a result of the data collection purposes listed above. In no case, the data collected are used to draw conclusions about you as an individual.

Moreover, when visiting our website, we use cookies, as well as analytical services. Further details can be found in this data protection statement.

b) When subscribing to our newsletter

As long as you explicitly agreed upon this matter, in accordance with art. 6 paragraph 1 sentence 1 point (a) GDPR, we use your e-mail address to send you our regular newsletter. In order to receive the newsletter an e-mail address is sufficient.

You can unsubscribe at any time, by means of a link provided for this purpose in the newsletter.

c) When using our contact form:

For questions of any kind, we offer you the opportunity to contact us using a form provided on our website. Here the provision of a valid e-mail address is necessary, so that we know from whom the request has come and in order to be able to answer it. Further information can be provided voluntarily.

We provide different forms, specific for the content of the request. The necessary content for each specific request is marked as mandatory information in the form.

Data processing for the purposes of contacting us is carried out in accordance with art. 6 paragraph 1 sentence 1 point (a) GDPR, based on your voluntary consent. The personal data collected by us for the purpose of using the contact form is automatically erased upon completion of your request.

d) Shop functions/customer account

We only collect personal data, if you voluntarily submit it while placing an order, contacting us or by registering for a customer account. Fields with mandatory information are marked as such, given that, in this case, we need it for processing orders, contacting you or for registering a customer account. Without this information, your order and/or the registration of the account can not be processed, respectively it would be impossible to communicate.

The type of data to be collected is shown in the input forms. We use the data you provide in accordance with art. 6 paragraph 1 sentence 1 point (b) GDPR (required for the fulfilment of the contract) for processing orders and your requests. After complete performance of the contract or erasure of your customer account, your data shall be restricted for further processing and erased after expiry of the tax and commercial retention periods.

Data are not used for other purposes, unless you have expressly consented to a further use of your data or if we reserve the right to further data use, which is legally permitted and about which we inform you in this statement. The deletion of your customer account is possible at any time and can be done either by a message to the point of contact or via a designated function in the customer account.

3. Transmission of data

A transmission of your personal data to third parties for other purposes, than those listed below shall not take place. We will only forward your personal data to third parties if:

  • You have given your consent for this purpose in accordance with art. 6 paragraph 1 sentence 1 point (a) GDPR,
  • The transmission is required in accordance with art. 6 paragraph 1 sentence 1 point (f) GDPR and there is no reason to assume, that you have an overriding interest worthy of protection in non-disclosure of your data,
  • In the event that there is a legal obligation for the transmission in accordance with art. 6 paragraph 1 sentence 1 point (c) GDPR.
  • This is permitted by law and at the same time is required for the performance of the contract in accordance with art. 6 paragraph 1 sentence 1 point (b) GDPR.

We only transmit personal data to third parties if this is necessary to achieve the contract's purpose and we send it to the following interested parties:

  • to the credit card provider or payment service provider for the purpose of direct debiting or collection of the purchase price,
  • to the transport/shipping company commissioned by us to deliver the products,
  • to the hosting, shop system or marketplace provider for the technical provision of shop and bidding data.
  • to our accountant in order to fulfil our fiscal obligations.

Third parties have the contractual or legal obligation to maintain the confidentiality of the data.
 For the chosen payment service provider you are also a contractual partner and you have accepted his conditions and data protection rules.

4. External payment service providers

We deploy external payment service providers. On their platform the users and we can process payments:

  • Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full)
  • Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/)
  • Visa (https://www.visa.de/datenschutz)
  • Mastercard (https://www.mastercard.de/de-de/datenschutz.html)

The link to the data protection statement of each provider is indicated in brackets.

Within the framework of the performance of the contract, we deploy payment service providers on the basis of art. 6 paragraph 1 point (b) GDPR. In addition, we deploy external payment service providers on the basis of our legitimate interest in accordance with art. 6 paragraph 1 point (f) GDPR in order to offer our users an effective and secure payment option.

The general terms and conditions, as well as the data protection provisions of each payment service provider, shall apply for the payment processing. These are directly made available by the payment service provider when making the payment transaction. You have the right to be informed about the here stored data and you will be granted the rights of data subjects.

Such data, processed by the payment service provider are, for example, name and address, bank details (for example, account numbers or credit card number, access data and checksums), as well as the information regarding the payment and the payment recipient. This information is necessary in order to carry out the payment processing. The submitted data are processed and stored only through the payment service provider. We only receive information about the confirmation or rejection of the payment. However, it is possible that data are sent by the payment service provider to credit reporting agencies. In this context, we refer to the general terms and conditions and to the data protection provisions of the respective payment service provider.

5. Routine erasure and storage of personal data

We process and store personal data of data subjects only for the period needed to achieve the storage purposes or if this is provided by the European regulator or by another legislator in laws and regulations to which the controller is subject.

If the storage purpose no longer applies or if the retention period provided by the European regulator or by another legislator expires, the data shall be blocked or erased routinely and in accordance with the statutory provisions.

6. Cookies

On our website, we are using cookies. Cookies are small files, which are created automatically by your browser and stored on your terminal (laptop, tablet, smart phone or similar) when you visit our website. Cookies do not cause any damage and are free from viruses, trojans or other malware. Cookies store information resulting from the specific used device. However, this does not mean that we receive information about your identity.

On the one hand, the use of cookies serves to make the use of our offer more enjoyable for you. For example, we use session cookies to recognize that you have already visited individual pages on our website. These are automatically deleted after leaving our page.

In addition, to improve usability, we also use temporary cookies that are stored on your device for a specified period of time. If you visit our site again to take advantage of our services, it will automatically recognize that you have already visited us and what inputs and settings you have made, so you do not have to re-enter them.

On the other hand, we use cookies in order to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer (see Section 5). These cookies allow us to automatically recognize when you visit our site again, if you have already visited us. These cookies are automatically erased after a defined period.

The data processed by cookies for the purposes mentioned, is required in order to safeguard our legitimate interests, as well as those of third parties, in accordance with art. 6 paragraph 1 sentence 1 point (f) GDPR. Most browsers accept cookies automatically. You can configure your browser so that no cookies are stored on your computer or a note always appears before a new cookie is created. However, disabling cookies completely may mean that you will not be able use all features of our website.

7. Analytics tools

Tracking tools

The tracking measures listed below and used by us are in accordance with art. 6 paragraph 1 sentence 1 point (f) GDPR. Through the used tracking measures, we want to ensure a needs-based design and the continuous optimization of our website. On the other hand, we use tracking measures in order to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer. These interests are to be regarded as legitimate within the sense of the aforementioned provision.

The respective data processing purposes and data categories can be found in the corresponding tracking tools.

Google Analytics

For the purpose of ensuring a needs-based design and the continuous optimization of our pages, we use Google Analytics, a web analytics service provided by Google Inc. (https://www.google.de/intl/de/about/) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter referred to as “Google”). In this context, pseudonymised usage profiles are created and cookies (see section 4) are used. The information generated by the cookie about your use of this website such as :

  • browser type/version,
  • used operating system,
  • referrer URL (the previously visited page),
  • host name of the accessing computer (IP address),
  • time of server request,

are transmitted to a Google server in the US and stored there. This information is used to evaluate the use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage for the purposes of market research and needs-based website design.

This information may also be transferred to third parties if required by law or if third parties process these data. Under no circumstances will your IP address be merged with any other data provided by Google. The IP addresses are rendered anonymous, so that mapping is not possible (IP masking).

You can prevent the installation of cookies by setting the browser software accordingly; however, we would like to point out that in this case not all features of this website may be fully exploited.

You can also prevent the collection of data generated by the cookie that is related to your use of the website (including your IP address) and the processing of these data by Google by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=de).

As an alternative to the browser add-on, especially for browsers on mobile devices, you can prevent the collection by Google Analytics by clicking on this link. An opt-out cookie will be set that will prevent the future collection of your data when you visit this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again.

For more information about data protection related to Google Analytics, see the Google Analytics Help Center (https://support.google.com/analytics/answer/6004245?hl=de).

8. Social media links

On our website, we use social media links, in accordance with art. 6 paragraph 1 sentence 1 point (f) GDPR, to the following social networks. The underlying commercial purpose is to be regarded as legitimate within the sense of GDPR. The responsibility for the compliance of operations with the data protection provisions shall be ensured by the respective provider. We are not using tracking or other data storage.

We inform you that our website is linked to different social media networks or video-platforms. Usually, these websites can determine that you access them from our website.

If you have an account registered on these platforms and you are logged in on them, than the visited website can not store publicly on your profile that you entered there using our website

Further information about data protection can be obtained from the respective provider:

Facebook Ireland Ltd.,

4 Grand Canal Square, Grand Canal Harbour,

Dublin 2, Ireland

https://www.facebook.com/policy.php

 

YouTube LLC,

901 Cherry Ave.,

San Bruno, CA 94066, USA

https://www.google.de/intl/de/policies/privacy/

9. Social media pages

We have pages on social media networks. We inform our customers and interested parties about our services also through them. Furthermore, through them we can enable an efficient communication about our services. In this case, the specific terms and conditions and the data protection directives of the platform operator shall be applicable.

Data transmitted there by our customers, interested parties and users within the framework of this data protection statement, can also be processed by us. The data are processed based on your consent (art. 6 paragraph 1 sentence 1 point (b) GDPR) and on our legitimate interest (art. 6 paragraph 1 sentence 1 point (f) GDPR).

10. Integration of third party services

Based on our legitimate interest (interest to analyse, optimise and operate our on-line offer within the sense of art. 6 paragraph 1 point (f) GDPR), we use content and service offers provided by third party.

In order to ensure this content feature, the provider of these offers must use the IP-address of the user. Thus, the IP-address is required for the presentation and use of this content.

However, third parties may also use pixel tags or cookies for statistical and marketing purposes. Pixel tags are invisible graphics and are also referred to as „web beacons”. Thanks to them, providers can determine and evaluate further information regarding the use of websites. In this data protection statement, we inform you how to prohibit or restrict the use of these usually anonymous data.

11. Google Maps

Our website uses Google Maps API for the visual representation of geographical information. By using Google Maps, Google (Google Inc., 1600 Amphitheatre Parkway, Mountain View, California, 94043) collects, processes and uses also data about the use of the maps-features by the visitors of the website. For this purpose, especially IP-addresses and user location data, can be processed in the USA.

You can find more information about the collection and processing of your data by Google as well as your rights in this regard in Google's data protection provisions under www.google.com/privacypolicy.html.

An opt out function can be found under: https://adssettings.google.com/authenticated. On mobile devices, it is possible to restrict the collection of data through individual settings.

12. Google fonts

We integrate the fonts ("Google Fonts") of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. By calling up the website, Google can determine that you accessed it and can store your IP-address; it can also assign this IP-address to other websites, which use Google services.

You can find more information about the processing of your data by Google under: https://www.google.com/policies/privacy.

An opt out function can be found at: https://adssettings.google.com/authenticated.

13. Data protection for our Facebook page

For our Facebook page we use the technical platform and services of Facebook Ireland Ltd., 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland.

We inform you that by visiting our Facebook pages amongst other things your IP-address, as well as further information will be stored. This information is used to provide us, as the operator of the Facebook pages, with statistical information about the use of the Facebook page.

Facebook provides more detailed information on this under the following link:

https://de-de.facebook.com/help/pages/insights.

Data transmitted there by our customers, interested parties and users within the framework of our data protection statement, can also be processed by us. The data are processed based on your consent (art. 6 paragraph 1 sentence 1 point (b) GDPR) and on our legitimate interest (art. 6 paragraph 1 sentence 1 point (f) GDPR).

The data collected in this context regarding the use is processed by Facebook Ltd. and may be transferred to countries outside the European Union. Please note that, you use this Facebook page and its functions under your own responsibility. This applies in particular to the use of the interactive functions (commenting, sharing, rating etc.). For this you have logged in to Facebook and accepted its terms of use.

Facebook describes what information it processes in its data usage guidelines:

https://de-de.facebook.com/about/privacy

Configuration settings related to data protection and to the privacy of your Facebook account you can find here:

https://www.facebook.com/policy

Information about if and how Facebook uses data from Facebook pages for its own purposes and to what extend data are assigned to individual user profiles, is currently not provided by Facebook. It is also unclear if data are passed on to third parties and if and when these are eventually deleted.

When you access a Facebook page, the IP address assigned to your end device, respectively to your internet connection, is transmitted to Facebook. According to Facebook, this IP address is anonymised (for "German" IP addresses) and erased after 90 days. Facebook also stores information about its users' end devices (e.g. as part of the "registration notification" function); Facebook may thus be able to assign IP addresses to individual users.

If you are currently logged in to Facebook, a cookie with your Facebook identification is stored on your device. In connection with cookies, reference is made in particular to the cookies statement, as part of our data protection statement and to the cookie policy of Facebook (https://www.facebook.com/policies/cookies). This enables Facebook to track that you have visited this page and how you have used it. This also applies to all other Facebook pages. Facebook uses Facebook buttons embedded in websites to record your visits to these websites and to associate them with your Facebook profile. This information can be used to tailor content or advertising to you.

If you want to avoid this, you should log out of Facebook or deactivate the function "stay logged in", delete the cookies available on your device and close and restart your browser. This deletes Facebook information that immediately identifies you.

By doing this, you can use Facebook pages without revealing your Facebook identification. When you use interactive page functions (like, comment, share, messenger, etc.) a Facebook log-in mask will appear. If you then log in, you will again be recognisable for Facebook as a certain user.

14. Rights of data subjects

You have the right:

  • in accordance with art.15 GDPR to obtain information as to whether or not your personal data are being processed. You have the right to be informed, particularly about the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipient to whom the personal data have been or will be disclosed, the envisaged period for which the personal data will be stored, the existence of the right to request rectification or erasure of personal data or restriction of processing or to object to such processing, the source of your data, if these are not collected by us, as well as the existence of automated decision-making, including profiling and where relevant, the request of meaningful information about the details;
  • in accordance with art. 16 GDPR, to obtain without undue delay the rectification of your inaccurate personal data stored by us;
  • in accordance with art. 17 GDPR, to obtain the erasure of personal data stored by us, if these are not necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;
  • in accordance with art. 18 GDPR, to obtain restriction of processing, if the accuracy of the personal data is contested by the data subject, the processing is unlawful and the data subject opposes the erasure of the personal data and we no longer need the data, but you need these for the establishment, exercise or defence of legal claims or if you object, in accordance with art. 21 GDPR, to processing;
  • in accordance with art. 20 GDPR, to receive your personal data, provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller;
  • in accordance with art. 7 paragraph 3 GDPR, to withdraw your consent at any time. This means that, in the future, we are no longer allowed to continue processing data based on this consent and
  • in accordance with art. 77 GDPR, to lodge a complaint with a supervisory authority. In order to do this, you can normally contact the supervisory authority from your habitual residence, place of work or from our corporate headquarters.

15. Right to object

If your personal data is processed on the basis of legitimate interest in accordance with art. 6 paragraph 1 sentence 1 point (f) GDPR, you have the right, in accordance with art. 21 GDPR to object the processing of your personal data, if there are compelling reasons related to your particular situation or if you object to personal data processed for direct marketing purposes. In the latter case, you have a general right to object and your decision shall be implemented by us without being necessary to indicate a particular situation.

If you want to use of your right to withdraw your consent or to object, sending an e-mail to the address provided in these instructions is sufficient.

16. Data security

We use during your visit to the website, the popular on-line system SSL (Secure Socket Layer) in connection with the highest encryption level supported by your browser. In this case, normally a 256-bit encryption is used. If your browser does not support a 256-bit encryption, we will use instead a 128-Bit v3 technology. If one single page of our website is encrypted before being sent, you will recognize it by the symbol of a closed key or lock in the lower status bar of your browser.

We apply appropriate technical and organisational security measures in order to protect your personal data against accidental or deliberate manipulation, loss, destruction or access by unauthorized third parties. Our security measures are improved on an ongoing basis in accordance with the development of technical standards.

17. Validity and modification of this data protection statement

This data protection statement is valid and its status is may 2018.

Due to further development of our website and offers or as a result of statutory amendments or modified governmental guidelines, a change of this data protection statement can be necessary. You can access, at any time, the latest data protection statement on our website in the section „Data protection” and you can print it.