PRIVACY POLICY

1.Name and Address of the Processor

With regards to the General Data Protection Regulation, national data protection laws and other data protection regulations I am the processor:

Helene Fanghänel

Hufelandstraße 29

10407 Berlin

E-Mail: heylenochka@berlin.de

Website: www.heylenochka.de

2.General

a.Extent of Data Processing

Your personal data is processed in such a manner that a functional website and the services offered on this website can be delivered to you. Processing takes place on the basis of given consent by you or where it is permitted by law.

b.Legal Basis

Insofar as processing operations require consent, these have Art. 6 (1) (a) GDPR as their legal basis.

Personal data required for the performance of a contract are processed pursuant to Art. 6 (1) (b) GDPR.

If the processing must take place due to legal obligations, Art. 6 (1) (c) GDPR serves as the legal basis.

c.Deletion and Retention Period

Your personal data will be deleted as soon as it becomes unnecessary for the purposes for which it has been collected. Storing your data beyond this point may be necessary due to legal obligation. The deletion will then take place in accordance with the deletion periods specified in the relevant laws, in particular GDPR or national legislation, unless the storage is still necessary for contract conclusion or fulfilment of other obligations.

3.Description of the Scope of Data Processing

a.Deployment of the Website with Wix.com Ltd.

Each time you visit my website, data of your computer system is automatically collected. I make my website available via the website builder provided by Wix.com Ltd, 40 Hanamal Tel Aviv St., Tel Aviv 6350671, Israel, which also has an office in Berlin.

Wix is a website builder that can be used to create HTML5 and mobile websites and is based on the cloud principle. Various website functions can be integrated into the website with so-called apps provided by Wix itself or third-party providers. For me, this construction kit allows me to create a beautiful, user-friendly website that is easy to manage and administrate. The following data is collected by Wix.com:

  1. IP Address

  2. Geographic Location

  3. Browser and Clickstream Activity

  4. Session Heatmaps

  5. Data about your computer

  6. Operating System, Browser, and Screen Resolution

  7. Language and Keyboard Settings

  8. Internet Service Provider

  9. Date of Page Visit

Wix.com Ltd. has its principal place of business in Israel. Israel is considered as a country with adequate protection for personal data of EU citizens by the European Commission and is subject to a so-called adequacy decision. Wix.com is also an active participant in the EU-US Privacy Shield. For more detailed information about Wix.com's privacy practices, please see their privacy policy.

b.Use of Cookies

My website uses cookies, which are text files that are stored in the browser or on your computer. They contain a characteristic string of characters and allow unique identification of the browser when you return to the website.

The technically necessary cookies make the website more secure and user-friendly. Some elements of the website require that you can be identified as a user even when you change pages. The following data, among others, is stored in the process:

  1. Language Settings

  2. Items in your shopping cart

  3. Log-in Information

In addition, cookies are used to enable analysis of the surfing behaviour. Here, among other, the following data can be transmitted:

  1. Particularly frequently visited subpages

  2. Time spent on subpages

  3. Search Terms

Cookies are stored on your computer and transmitted from it to my site. Therefore, you also have full control over their use. By changing the settings in your browser, the transmission of cookies can be restricted or prevented altogether. Already stored cookies can be deleted at any time, this can also be done automatically. By deactivating cookies, it may no longer be possible to fully use all functions of the website.

c.Registration

My website offers the possibility to register by providing personal data. The data is entered into an input mask and stored. Personal data is required for the registration itself. A transfer to third parties does not take place in this context. This data includes:

  1. E-Mail Address

  2. IP Address

Additional information may be stored in your user account. Only the information that you enter via the corresponding mask of your user account will be stored. This data includes:

  1. First Name and Surname

  2. Telephone Number

  3. Address Data

  4. Data on the Means of Payment

d.Purchase Order

You can place orders via my website. Data will be stored as part of the order processing. This data includes:

  1. First Name and Surname

  2. Telephone Number

  3. Address Data

  4. Data on the Means of Payment

In the context of order processing, your shipping data will be passed on to a logistics service provider.

e.Contact Form and E-Mail Contact

My website offers a contact form. You can use this to send me a message. In doing so, the data from the input mask will be transmitted and stored. This data includes:

  1. First Name and Surname

  2. E-Mail Address

  3. Phone Number

  4. Message Content

If you wish, you can alternatively contact me directly via my e-mail address. In this case, the data transmitted by e-mail will be stored.

I use this data exclusively for contacting and direct conversation with you.

4.Social Media

The plug-in Instagram Feed, developed by Wix.com Ltd., is integrated on my website. It enables to display the feed of my Instagram fan page on my website. The Instagram service is offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA. The plug-in retrieves information from Instagram and integrates it directly into my website.

If you click on a link in the newsfeed, you will be redirected to my Instagram page. For more information about what data is collected by Instagram, see Instagram's privacy policy.

5.Your Rights

a.Access

You may request confirmation from me as to whether personal data concerning you is being processed. If processing takes place, you can request the following information:

  1. Processing purposes.

  2. Categories of personal data that is being processed.

  3. The recipients or categories of recipients to whom your personal data have been or will be disclosed.

  4. Intended storage period or criteria for determining the storage period, if no specific storage period is determined.

  5. Existence of a right to rectification or erasure, restriction of processing, or to object to processing.

  6. Existence of a right to file a complaint with a supervisory authority.

  7. Any available information on the origin of your data if it was not collected directly from you.

  8. Existence of automated decision-making, including profiling, pursuant to Art. 22 (1) and (4) GDPR.

b.Rectification

You may request rectification and / or completion of your processed personal data insofar as it is inaccurate or incomplete.

c.Restriction

You may request the restriction of the processing of your personal data under the following conditions:

  1. In case of contestation of the accuracy of the data concerning you, for the duration of the verification process.

  2. If erasure is not desired, in cases of unlawfulness processing.

  3. If your personal data is no longer required for the purposes of processing, but is needed for the assertion, exercise or defense of legal claims.

  4. If processing has been objected pursuant to Art. 21 (1) GDPR by you and it has not yet been determined whether legitimate claims prevail over your claim.

Personal data subject to restriction may only be processed with your consent, for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person, or for reasons of substantial public interest of the European Union or a Member State.

You will be informed before a restriction on processing is lifted.

d.Erasure

You can request immediate deletion in accordance with the following reasons:

  1. Your personal data is no longer necessary for the purposes for which it was collected or processed.

  2. You revoke consent and there is no other legal basis for the processing.

  3. You object to the processing and there are no overriding legitimate grounds for the processing.

  4. Your personal data has been processed unlawfully.

  5. The erasure of your data is necessary for compliance with a legal obligation under Union or national law.

  6. The personal data concerning you has been collected in relation to information society services offered pursuant to Art. 8 (1) GDPR.

The right to erasure does not apply insofar as the processing is necessary for the following reasons:

  1. For the exercise of the right to freedom of expression and information.

  2. For compliance with a legal obligation which requires processing under Union or national law; for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

  3. For reasons of public interest in the area of public health pursuant to Art. 9 (2) (h) and (i) and Art. 9 (3) of the GDPR.

  4. For archiving purposes in the public interest, scientific or historical research purposes or for statistical purposes pursuant to Art. 89 (1) GDPR, insofar as the exercise of the right of erasure is likely to render impossible or seriously prejudice the achievement of the purposes of such processing.

  5. For the assertion, exercise or defence of legal claims.

e.Information

If the right to rectification, erasure or restriction is exercised, all recipients to whom this data has been disclosed shall be informed thereof, unless this proves impossible or involves a disproportionate effort. There is the right to be informed about these recipients.

f.Data Portability

You have the right to receive your data concerning you in a structured, common and machine-readable format. You also have the right to have this data transferred to another controller without hindrance, provided that:

  1. the processing is based on consent pursuant to Art. 6 (1) a GDPR or Art. 9 (2) a GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and

  2. the processing is carried out with the help of automated procedures.

In addition, in exercising this right, you may request that your data be transferred to another controller, insofar as this is technically feasible and the freedom of other persons is not thereby affected.

This right does not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

g.Object

You can object to processing based on Art. 6 (1) (e) or (f) GDPR at any time.

Processing of your data must be stopped immediately if no compelling legitimate grounds for the processing can be demonstrated which override your interests, rights and freedoms, or if the processing serves the purpose of asserting, exercising or defending legal claims.

Objection can also be raised at any time against direct advertising.

h.Revocation

Consent given by you for the processing of your personal data can be revoked at any time. The lawfulness of the processing until the revocation is not affected by this.

i.Automated Individual Decision-making, Including Profiling

It is your right not to be subject to a decision based on automated processing, including profiling, which results in legal effects concerning you or significantly affects you similarly. This does not apply in the following cases:

  1. The decision is necessary for the conclusion or performance of a contract between you and the controller.

  2. The decision is permitted by national or Union legislation and that legislation contains appropriate measures to safeguard your rights and freedoms and your legitimate interests.

  3. The processing is carried out with your explicit consent.

These decisions must not be based on special categories of personal data pursuant to Art. 9 (1) GDPR. This does not apply if Art. 9 (2) (a) or (g) GDPR applies and appropriate measures have been taken to protect the rights and freedoms as well as your legitimate interests.

With regard to the cases referred to in 1) and 3), reasonable measures shall be taken to safeguard the rights and freedoms as well as legitimate interests, including at least the right to obtain the intervention of a person on the part of the responsible person, to express his or her point of view and to contest the decision.

j.Complaint to the Supervisory Authority

Irrespective of any other administrative or judicial remedy, you have the right to file a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes your rights as per GDPR.