PRIVACY POLICY
PRIVACY POLICY
1) INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how your personal data is handled when you use our website. Personal data includes any information that can personally identify you.
1.2 The data controller for the processing of data on this website, in accordance with the General Data Protection Regulation (GDPR), is Brunetti. The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the "https://" protocol and the padlock icon in your browser’s address bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
When you use our website for informational purposes only, i.e., without registering or providing us with any other information, we only collect the data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary to display the website:
-
The website visited
-
Date and time of access
-
Amount of data transferred (in bytes)
-
Referring source (how you reached the site)
-
Browser used
-
Operating system used
-
IP address used (anonymized if applicable)
This data is processed pursuant to Article 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not disclosed or used in any other way. However, we reserve the right to review the server log files retrospectively if there is concrete evidence of unlawful use.
3) COOKIES
To make your visit to our website more attractive and to enable the use of certain features, we use cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the browser session ends, i.e., when you close your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies).
When cookies are set, they collect and process specific user information, such as browser and location data and IP address values, to varying extents. Persistent cookies are automatically deleted after a predetermined duration, which may vary depending on the cookie.
Some cookies are used to simplify the ordering process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit). If any personal data is processed via cookies we implement, the processing is carried out either in accordance with Article 6(1)(b) GDPR for the performance of a contract or…
…in accordance with Article 6(1)(f) GDPR to protect our legitimate interest in ensuring the optimal functionality of the website and a user-friendly and effective browsing experience.
We may work with advertising partners to make our online offerings more relevant to you. In this case, cookies from our partner companies (third-party cookies) may also be stored on your hard drive when you visit our website. If we work with such advertising partners, you will be informed separately and in detail about the use of such cookies and the specific data collected in the relevant sections below.
Please note that you can configure your browser settings to notify you when cookies are set and decide individually whether to accept them or reject them in specific cases or altogether. Each browser differs in how it manages cookie settings. You can find instructions for adjusting your cookie settings in your browser’s help menu. Below are links to instructions for the most common browsers:
-
Internet Explorer: https://support.microsoft.com/en/help/17442/windows-internet-explorer-delete-manage-cookies
-
Firefox: https://support.mozilla.org/en/kb/cookies-erlauben-und-ablehnen
-
Chrome: https://support.google.com/chrome/answer/95647?hl=en
-
Opera: https://help.opera.com/en/latest/web-preferences/#cookies
Please note that rejecting cookies may limit the functionality of our website.
4) CONTACTING US
When you contact us (e.g., via contact form or email), personal data is collected. The specific data collected through a contact form can be seen on the respective form. This data is stored and used solely for the purpose of responding to your inquiry or for initiating contact, including the associated technical administration.
The legal basis for processing this data is our legitimate interest in responding to your inquiry pursuant to Art. 6(1)(f) GDPR.
If your contact is aimed at the conclusion of a contract, an additional legal basis for processing is Art. 6(1)(b) GDPR.
Your data will be deleted once your inquiry has been fully resolved, provided that there are no statutory retention obligations preventing such deletion.
5) DATA PROCESSING FOR CUSTOMER ACCOUNT CREATION AND CONTRACT FULFILLMENT
In accordance with Art. 6(1)(b) GDPR, personal data is collected and processed when you provide it to us for the purpose of performing a contract or opening a customer account. The specific data collected is shown on the respective input forms.
You may request the deletion of your customer account at any time by notifying us at the contact address provided above.
We store and use the data you provide to fulfil the contract. After the contract has been fully executed or your customer account has been deleted, your data will be blocked and deleted following the retention periods required under tax and commercial law, unless you have expressly consented to the further use of your data or we are legally permitted to retain the data for other purposes, as we will inform you of below.
6) USE OF YOUR DATA FOR DIRECT MARKETING PURPOSES
6.1 Subscription to our Email Newsletter
If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information required for sending the newsletter is your email address. Providing additional data is optional and will be used to address you personally.
We use a double opt-in procedure for sending the newsletter. This means that we will only send you an email newsletter after you have explicitly confirmed your consent to receive newsletters. You will first receive a confirmation email asking you to click a link to confirm your subscription.
By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6(1)(a) GDPR.
7) DATA PROCESSING FOR ORDER HANDLING
7.1 Disclosure of Data for Contract Fulfilment
The personal data we collect will be passed on to the shipping company responsible for delivery, to the extent necessary to deliver the goods, as part of contract performance.
Your payment data will be passed on to the authorised credit institution as necessary for payment processing.
Where we use payment service providers, you will be explicitly informed below.
The legal basis for the transfer of data is Art. 6(1)(b) GDPR.
7.2 Use of Payment Service Providers (Payment Processors)
PayPal
If you choose to pay via PayPal, credit card via PayPal, direct debit via PayPal, or—where offered—"purchase on account" or "instalment payment" via PayPal, your payment data will be transferred to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg ("PayPal").
This data is shared pursuant to Art. 6(1)(b) GDPR and only to the extent necessary for payment processing.
For certain payment methods (e.g., credit card, direct debit, purchase on account), PayPal reserves the right to conduct a credit check. For this purpose, your payment data may be shared with credit agencies pursuant to Art. 6(1)(f) GDPR based on PayPal’s legitimate interest in determining your creditworthiness.
The result of the credit check (i.e., the statistical probability of non-payment) is used by PayPal to decide whether the selected payment method should be permitted.
The credit check may include so-called score values, which are calculated based on scientifically recognised mathematical-statistical methods, possibly including address data.
Further information on data protection at PayPal, including information on the credit reference agencies used, can be found at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
You can object to this data processing at any time by notifying PayPal. However, PayPal may still be entitled to process your personal data if required for contractual payment processing.
SOFORT
If you select "SOFORT" as your payment method, payment processing will be carried out by SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “SOFORT”).
We transmit the information provided during the ordering process, along with details of your order, to SOFORT pursuant to Art. 6(1)(b) GDPR.
SOFORT GmbH is a part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden).
Your data is transferred solely for the purpose of payment processing and only to the extent necessary.
Further details on SOFORT's privacy policy can be found at: https://www.klarna.com/sofort/datenschutz.
8) REVIEW REMINDERS
Own Review Reminder (No Use of Customer Review System)
We use your email address to send you a one-time reminder to submit a review of your order using our internal review system, provided that you have expressly consented to this during or after your order, in accordance with Art. 6(1)(a) GDPR.
You can withdraw your consent at any time by notifying the data controller.
9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS
9.1 Facebook Plugins with Shariff Solution
Our website uses so-called social plugins ("plugins") of the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook").
To enhance the protection of your data when visiting our website, these buttons are not fully integrated as unrestricted plugins, but instead embedded via HTML links. This integration ensures that no connection to Facebook servers is established simply by visiting a page on our website that contains such buttons.
Only when you click on the button, a new browser window will open and load the Facebook page where you can interact with Facebook features (possibly after logging in).
Facebook Inc. is certified under the EU-US Privacy Shield framework, ensuring compliance with EU data protection standards.
You can find more information about the purpose and scope of data collection and further processing by Facebook, as well as your rights and privacy settings, in Facebook's privacy policy: https://www.facebook.com/policy.php.
9.2 Google+ Plugins with Shariff Solution
Our website uses social plugins ("plugins") of the Google+ social network, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
For better protection of your data during your visit, these buttons are embedded using HTML links. This prevents a direct connection to Google servers when accessing a page on our site containing such buttons.
Only when you click the button, a browser window will open to the Google+ platform where interaction is possible.
Google LLC is certified under the EU-US Privacy Shield, ensuring compliance with EU data protection standards.
Details on the purpose and scope of data collection and processing by Google can be found in Google's privacy policy: https://www.google.com/intl/en/policies/privacy/.
9.3 Instagram Plugins with Shariff Solution
Our website uses social plugins ("plugins") of the Instagram platform, operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA ("Instagram").
For enhanced data protection, these buttons are embedded using HTML links instead of direct plugins. This ensures that no data is transmitted to Instagram servers by merely loading a page that contains such buttons.
Clicking the button opens an Instagram page in a new browser window, where you can interact (after logging in, if applicable).
Instagram LLC is certified under the EU-US Privacy Shield, ensuring EU-level data protection compliance.
Further details about Instagram’s data use can be found in its privacy policy: https://help.instagram.com/155833707900388/.
10) ONLINE MARKETING
10.1 DoubleClick by Google
This website uses DoubleClick by Google, a service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("DoubleClick").
DoubleClick uses cookies to deliver ads that are relevant to users, improve campaign performance, and avoid repeatedly showing the same ads. Through cookie IDs, Google is able to track which ads are displayed in which browsers, thereby preventing duplicates.
These cookies also help measure conversions, such as when a user clicks an ad and later takes an action on our website. Processing is carried out based on our legitimate interest in effective marketing under Article 6(1)(f) of the UK GDPR.
For more information about DoubleClick and Google's privacy practices, visit: https://www.google.com/policies/privacy/
10.2 Google Ads Conversion Tracking
We use Google Ads and its associated conversion tracking service, operated by Google LLC. When you click on a Google ad, a cookie is placed on your device. This cookie expires after 30 days and does not personally identify you.
If you visit certain pages of our website while the cookie is still valid, both we and Google can recognise that you clicked the ad and were redirected to our site. Each Google Ads client receives a different cookie, preventing cross-client tracking.
The data collected helps us generate conversion statistics without personally identifying users. Processing is carried out under our legitimate interest in targeted advertising pursuant to Article 6(1)(f) UK GDPR.
You can prevent tracking by adjusting your browser settings or using the following opt-out plugin: https://www.google.com/settings/ads/plugin?hl=en
11) WEB ANALYTICS
Google (Universal) Analytics
We use Google Analytics, a web analytics service by Google LLC, to analyse website usage. Google Analytics uses cookies to generate statistical reports.
We only use Google Analytics with IP anonymisation enabled ("_anonymizeIp()"), which means your IP address is shortened within the UK or EEA and cannot be linked back to you. In exceptional cases, the full IP address may be transmitted to the USA and shortened there.
Google processes this data on our behalf and does not combine it with other data. Processing is based on our legitimate interest in statistical analysis and website optimisation in accordance with Article 6(1)(f) UK GDPR.
You can opt out via: https://tools.google.com/dlpage/gaoptout?hl=en
We also use Google Analytics with User-ID to analyse cross-device behaviour. These IDs are anonymised and not traceable to individual users.
12) RETARGETING / REMARKETING / BEHAVIOURAL ADVERTISING
Facebook Custom Audiences & Facebook Pixel
Our website uses the "Facebook Pixel" by Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA.
When you give your consent, this pixel allows us to track user behaviour after interacting with a Facebook ad. This helps us measure the effectiveness of our campaigns.
Although the data collected is anonymous to us, Facebook may associate it with your user account and use it for its own advertising purposes. This allows ads to be shown to you both on and off Facebook.
This processing only occurs with your explicit consent, under Article 6(1)(a) UK GDPR. Users must be at least 13 years old to provide consent.
For more information, please refer to: https://www.facebook.com/about/privacy/
To opt out of Facebook-based advertising, visit: https://www.aboutads.info/choices/
Google Ads Remarketing
We use Google Ads Remarketing to show you personalised ads based on your previous interactions with our site. This involves the use of cookies and pseudonymous identifiers.
If you have given consent for Google to link your web and app history with your Google Account and allow personalised advertising, Google may tailor ads across devices. This processing is based on your consent under Article 6(1)(a) UK GDPR.
To manage or deactivate interest-based advertising by Google, go to: https://www.google.com/settings/ads/onweb/
13) YOUR RIGHTS AS A DATA SUBJECT
As a data subject, you have the following rights under the UK General Data Protection Regulation (UK GDPR):
13.1 Right of Access (Art. 15 UK GDPR)
You have the right to obtain confirmation as to whether we are processing personal data concerning you. Where this is the case, you are entitled to access the following information:
-
the purposes of the processing;
-
the categories of personal data involved;
-
the recipients or categories of recipients to whom the personal data have been or will be disclosed;
-
the envisaged retention period or the criteria used to determine that period;
-
your rights to rectification, erasure, restriction of processing or objection;
-
your right to lodge a complaint with a supervisory authority;
-
the source of the data, if not collected directly from you;
-
whether your data is used in automated decision-making, including profiling, and meaningful information about the logic and significance of such processing.