Privacy Policy
1) Introduction and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data means any information that can be used to identify you personally.
1.2 The controller responsible for data processing on this website within the meaning of the Swiss Data Protection Act (DSG) is Beate Giaquinto, Flower24, Chemin de la Vaux 7, 1303 Penthaz, Switzerland, Tel.: 0049216016700, E-Mail: [email protected]. The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
1.3 The controller has appointed a data protection advisor, who can be contacted as follows: "Beate Giaquinto".
2) Data Collection When Visiting Our Website
2.1 When you visit our website purely for informational purposes, i.e., when you do not register or otherwise provide us with information, we collect only the data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which are technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you accessed the page
- Browser used
- Operating system used
- IP address used (possibly in anonymized form)
No transmission or other use of the data takes place. However, we reserve the right to subsequently check the server log files if there are concrete indications of unlawful use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string “https://” and the lock symbol in your browser’s address bar.
3) Hosting & Content Delivery Network
3.1 For hosting our website and displaying its content, we use a provider that provides its services itself or through selected subcontractors exclusively on servers within the European Union.
All data collected on our website are processed on these servers.
We have entered into a data processing agreement with the provider, which protects the data of our website visitors and prohibits disclosure to third parties.
3.2 Bunny
We use a content delivery network from the following provider: BUNNYWAY d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia.
This service enables us to deliver large media files such as graphics, website content, or scripts more quickly via a network of regionally distributed servers. The processing takes place to protect our legitimate interest in improving the stability and functionality of our website. We have concluded a data processing agreement with the provider that ensures the protection of our visitors’ data and prohibits unauthorized disclosure to third parties.
3.3 Cloudflare
We use a content delivery network from the following provider: Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA.
This service enables us to deliver large media files such as graphics, website content, or scripts more quickly via a network of regionally distributed servers. The processing takes place to protect our legitimate interest in improving the stability and functionality of our website. We have concluded a data processing agreement with the provider that ensures the protection of our visitors’ data and prohibits unauthorized disclosure to third parties.
For the transfer of data to the USA, the provider relies on standard contractual clauses approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC), which are intended to ensure compliance with the Swiss data protection level.
4) Cookies
To make our website more attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). When cookies are set, they collect and process certain user information such as browser and location data as well as IP address values. Persistent cookies are automatically deleted after a specified period, which may differ depending on the cookie.
Some cookies are used to simplify the ordering process by storing settings (e.g. remembering the contents of a virtual shopping cart for a later visit to the website).
We may work with advertising partners who help us make our online offering more interesting for you. For this purpose, cookies from partner companies may also be stored on your hard drive when you visit our website (third-party cookies). If we work with these advertising partners, you will be informed individually and separately about the use of such cookies and the scope of the information collected in the sections below.
Please note that you can set your browser to inform you about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies in certain cases or in general. Each browser differs in the way it manages cookie settings. This is described in each browser’s help menu, which explains how to change your cookie settings. You can find these for the respective browsers at the following links:
Microsoft Edge: Microsoft Edge Support
Firefox: Mozilla Support
Chrome: Google Chrome Support
Safari: Apple Support
Opera: Opera Help
Please note that if you do not accept cookies, the functionality of our website may be limited.
5) Contact
When contacting us (e.g. via contact form or e-mail), personal data is collected. The specific data collected in the case of a contact form can be seen from the respective form. These data are stored and used exclusively for the purpose of responding to your inquiry or for establishing contact and the associated technical administration. Your data will be deleted after your inquiry has been fully processed. This is the case if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided that there are no statutory retention obligations to the contrary.
6) Data Processing When Opening a Customer Account and for Contract Execution
Personal data is collected and processed if you provide it to us for the performance of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be carried out by sending a message to our address. We store and use the data you provide for contract processing. After deletion of your customer account, your data will be blocked with regard to tax and commercial retention periods and deleted after the expiry of these periods, unless we can demonstrate an overriding interest in further processing under Art. 31(2) of the Swiss Data Protection Act (DSG) or a legal justification for continued storage.
7) Use of Single Sign-On Procedures
7.1 Facebook Connect
On our website, you can create a customer account or register using the “Facebook Connect” social plugin of the social network Facebook, operated by Meta Platforms Ireland Limited, 4 Grand Canal Quay, Square, Dublin 2, Ireland (“Facebook”), using the so-called Single Sign-On technique, provided you have a Facebook profile. You can recognize the social plugins of “Facebook Connect” on our website by the blue button with the Facebook logo and the inscription “Log in with Facebook” or “Sign in with Facebook”.
When you visit a page of our website that contains such a plugin, your browser establishes a direct connection to the servers of Facebook. The content of the plugin is transmitted directly from Facebook to your browser and integrated into the page. Through this integration, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged into Facebook.
This information (including your IP address) is transmitted from your browser directly to a Facebook server and stored there. This may also involve transmission to the servers of Meta Platforms Inc. in the USA.
Using the “Facebook Connect” button on our website, you also have the option to log in or register using your Facebook user data. Only if you give your explicit consent prior to the login process regarding the exchange of data with Facebook will we, depending on your personally set privacy settings on Facebook, receive the general and publicly accessible information stored in your profile. This information includes the user ID, name, profile picture, age, and gender.
We would like to point out that, depending on changes to Facebook’s data protection terms and conditions, the transfer of your profile pictures, user IDs of your friends, and friends list may also occur if these have been marked as “public” in your privacy settings on Facebook. The data transmitted by Facebook is stored and processed by us for the creation of a user account with the necessary data, if these have been released by you on Facebook (salutation, first name, last name, address, country, email address, date of birth). Conversely, data (e.g. information about your browsing or purchasing behavior) may be transferred from us to your Facebook profile based on your consent.
You can revoke your consent at any time by sending a message to the controller named at the beginning of this privacy policy.
For information on the purpose and scope of data collection and the further processing and use of data by Facebook, as well as your rights in this regard and settings options for protecting your privacy, please refer to Facebook’s privacy policy: http://www.facebook.com/policy.php
If you do not want Facebook to assign the data collected via our website directly to your Facebook profile, you must log out of Facebook before visiting our website. You can also completely prevent the loading of Facebook plugins with browser add-ons, e.g. with “Adblock Plus” (https://adblockplus.org/en/).
7.2 Google Sign-In
On our website, you can create a customer account or register via the “Google Sign-In” service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”), using the Single Sign-On technique, provided you have a Google profile. You can recognize the Google login function on our website by the buttons “Sign in with Google” or “Continue with Google”.
When you visit a page on our website that contains the Google login function, your browser establishes a direct connection to the Google servers. The content of the login button is transmitted directly from Google to your browser and integrated into the page. Through this integration, Google receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Google profile or are not logged into Google at the time.
This information (including your IP address) is transmitted directly to a Google server and stored there. This may also include transfers to Google LLC servers in the USA.
These data processing operations are carried out on the basis of Google’s legitimate interest in displaying personalized advertising based on browsing behavior.
By using the Google login button on our website, you also have the option to log in or register using your Google user data.
Only if you have given your explicit consent prior to the login process regarding the exchange of data with Google will we, depending on your personal privacy settings on Google, receive the general and publicly accessible information stored in your profile. This information includes the user ID, name, profile picture, age, and gender.
We would like to point out that, depending on changes to Google’s privacy policy and terms of use, the transmission of your profile pictures, user IDs of your friends, and friends list may also occur if these have been marked as “public” in your Google privacy settings. The data transmitted by Google is stored and processed by us for the creation of a user account with the necessary data (salutation, first name, last name, address, country, e-mail address, date of birth), if these have been released by you on Google. Conversely, based on your consent, data (e.g. information about your browsing or purchasing behavior) may be transferred from us to your Google profile.
You may revoke your consent at any time by sending a message to the controller named at the beginning of this privacy policy.
For information on the purpose and scope of data collection and the further processing and use of data by Google, as well as your rights in this regard and settings options to protect your privacy, please refer to Google’s privacy policy: https://policies.google.com/privacy?hl=en
The terms of use for “Google Sign-In” can be found here: https://policies.google.com/terms
If you do not want Google to associate data collected via our website directly with your Google profile, you must log out of Google before visiting our website. You can also completely prevent the loading of Google plugins with browser add-ons, e.g. “Adblock Plus” (https://adblockplus.org/en/).
Further information on Google’s data protection practices can be found here: https://business.safety.google/intl/en/privacy/
8) Use of Your Data for Direct Marketing
8.1 Subscribing to Our Email Newsletter
By providing your personal data, you agree that we may use this information to send you newsletters.
We store the IP address entered by your Internet service provider (ISP) as well as the date and time of registration, to be able to trace a possible misuse of your email address at a later time. The data collected when subscribing to the newsletter will be used exclusively for the purpose of advertising communication via the newsletter. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending us a corresponding message. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, unless we can demonstrate an overriding interest in further processing under Art. 31(2) DSG or a legal justification for continued storage.
8.2 MailChimp
The delivery of our email newsletters is carried out via the following provider: The Rocket Science Group, LLC d/b/a MailChimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
Based on our legitimate interest in efficient and user-friendly newsletter marketing, we forward the data you provided when registering for the newsletter to this provider so that it can handle the newsletter delivery on our behalf.
Subject to your express consent, the provider also performs statistical analysis of newsletter campaigns using web beacons or tracking pixels in sent emails to measure open rates and specific interactions with the content of the newsletters. Device information (e.g., access time, IP address, browser type, and operating system) may also be collected and analyzed but is not merged with other datasets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors’ data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider relies on the standard contractual clauses of the Swiss Federal Data Protection and Information Commissioner (FDPIC), which are intended to ensure compliance with the Swiss level of data protection.
9) Data Processing for Order Fulfillment
9.1 Personal data collected by us will be passed on to the transport company commissioned with the delivery, insofar as this is necessary for the delivery of the goods. Your payment data will be forwarded to the credit institution commissioned with the payment processing, insofar as this is necessary for handling payments. If we use special service providers for order processing, we will inform you explicitly below.
9.2 Forwarding of Personal Data to Shipping Service Providers
- Planzer
If delivery is made by the transport service provider Planzer (Planzer Transport AG, Lerzenstrasse 14, 8953 Dietikon, Switzerland), we will pass on your e-mail address prior to delivery for the purpose of coordinating a delivery date or delivery notice, provided that you have expressly consented to this during the ordering process. Otherwise, we will pass on only the recipient’s name and delivery address to Planzer for the purpose of delivery. The transfer takes place only insofar as it is necessary for delivery. In this case, prior coordination of the delivery date or transmission of status information is not possible.
You may withdraw your consent at any time with effect for the future, either to the controller named above or directly to the transport service provider Planzer.
- Post CH
If delivery is made by the transport service provider Post CH (Schweizerische Post AG, Wankdorfallee 4, 3030 Bern, Switzerland), we will pass on your e-mail address prior to delivery for the purpose of coordinating a delivery date or notification, provided that you have expressly consented to this during the ordering process. Otherwise, only the recipient’s name and delivery address will be transmitted to Post CH for the purpose of delivery. The transfer takes place only insofar as it is necessary for delivery. In this case, prior coordination of the delivery date or transmission of tracking information is not possible.
Consent may be withdrawn at any time with effect for the future either to the controller named above or directly to Post CH.
9.3 Use of Payment Service Providers (Payment Services)
- Klarna
If you select the payment method “Klarna Invoice” or (if offered) “Klarna Installment Purchase,” payment will be processed via Klarna Bank AB (publ) (https://www.klarna.com/de), Sveavägen 46, 111 34 Stockholm, Sweden. To enable payment, your personal data (first and last name, street, house number, postal code, city, gender, e-mail address, telephone number, and IP address) as well as order data (e.g., invoice amount, items, delivery method) will be transmitted to Klarna for identity and credit checks, provided that you have expressly consented to this in the order process. Information on the credit agencies to which your data may be forwarded can be found here: Klarna Credit Agencies.
Credit reports may contain probability values (so-called score values) calculated using scientific, statistical methods. Address data may also be included in these calculations. Klarna uses the information received to assess your creditworthiness and decide whether to establish or continue a contractual relationship.
You may revoke your consent at any time by notifying the data controller or Klarna. However, Klarna may still process your personal data where necessary to fulfill contractual payment obligations.
For more details, please refer to Klarna’s privacy policy: Klarna Privacy Policy.
- PayPal
If you pay via PayPal, credit card via PayPal, direct debit via PayPal or – if available – “Pay on Invoice” or “Installment Payment” via PayPal, your payment data will be transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal may carry out a credit check based on its legitimate interest in assessing your creditworthiness. Further information is available in PayPal’s privacy policy: PayPal Privacy Policy.
- PostFinance
If you choose a PostFinance payment method, payment will be processed by PostFinance AG, Mingerstrasse 20, CH-3030 Bern. We will transmit your order information (name, address, account number, bank code, possibly credit card number, invoice amount, currency and transaction number) to PostFinance solely for payment processing.
- Saferpay / PayUnity
This website offers one or more online payment options from SIX Payment Services (Germany) GmbH, Langenhorner Chaussee 92-94, 22415 Hamburg, Germany. When you choose a payment option that requires advance payment (e.g. credit card), your payment data and order information are transmitted to the provider solely for payment processing.
- TWINT
If you choose a TWINT payment method, payment is processed by TWINT AG, Stauffacherstrasse 31, CH-8004 Zurich. We transmit your order and payment information (name, address, account number, bank code, possibly credit card number, invoice amount, currency, and transaction number) to TWINT solely for payment processing.
10) Use of Social Media: Videos
Use of YouTube Videos
This website uses the YouTube embedding function to display and play videos from “YouTube,” a service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).
The extended data protection mode is used, which means that user information is only stored once the video is played. When a video is played, YouTube uses cookies to collect information about user behavior (for example, to compile statistics, improve user experience, and prevent abuse). If you are logged in to Google, your data will be linked to your Google account. To prevent this, log out before playing a video. Google stores user profiles and analyzes them even for non-logged-in users. You have the right to object to this profiling by contacting YouTube directly. Personal data may also be transferred to Google LLC servers in the USA.
Further information on data protection by YouTube can be found here: https://www.google.de/intl/en/policies/privacy
11) Online Marketing
11.1 Google AdSense
This website uses Google AdSense, a web advertising service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). Google AdSense uses cookies and so-called “web beacons” (invisible graphics) to analyze website usage and display personalized ads. Information generated (including your IP address) is usually transmitted to and stored on Google servers, possibly in the USA. We have a data processing agreement with Google to ensure data protection. More information is available here: https://business.safety.google/intl/en/privacy/ and https://www.google.de/policies/privacy/
You can permanently disable cookies for advertising preferences by downloading the browser plugin at: https://www.google.com/settings/ads/plugin?hl=en
11.2 Google Ads Conversion Tracking
This website uses Google Ads and its conversion tracking feature provided by Google Ireland Limited. We use Google Ads to promote our offers on external websites. The conversion cookie is set when a user clicks on a Google ad. These cookies expire after 30 days and do not identify the user personally. The information collected is used to create statistics for Google Ads advertisers. We do not receive data that personally identifies users. You can opt out by disabling Google conversion tracking cookies in your browser. More information is available here: https://www.google.de/policies/privacy/
12) Web Analytics Services
Google Analytics 4
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited. When you visit the site, cookies collect information including your IP address (which Google anonymizes by shortening it). The data is transferred to Google servers and used to compile reports and statistics for us. The data is stored for two months and then deleted. Google Analytics 4 is used only if you have given explicit consent via the cookie consent tool. You may withdraw your consent at any time.
Additional features such as “Demographic Characteristics,” “Google Signals,” and “User IDs” may be used to analyze age, gender, interests, or cross-device activity. You can deactivate personalized ads in your Google account settings.
Data transfers to the USA are based on the Swiss FDPIC Standard Contractual Clauses to ensure Swiss data-protection compliance.
13) Use of a Live-Chat System
Tidio
This website uses a live-chat system provided by the following vendor: Tidio Poland Sp. z o.o., Wojska Polskiego 81, 70-481 Szczecin, Poland.
The processing of personal data transmitted through the chat is carried out either because it is necessary for the initiation or performance of a contract, or on the basis of our legitimate interest in effectively supporting visitors to our site. Your transmitted data will be deleted once the issue has been conclusively resolved, unless statutory retention obligations require otherwise.
Additionally, to create pseudonymized user profiles, further information may be collected and analyzed using cookies; however, this information does not personally identify you and is not merged with other data sets. Where such information has a personal reference, processing takes place on the basis of our legitimate interest in statistical analysis of user behavior for optimization purposes.
The setting of cookies can be prevented by adjusting your browser settings; however, this may limit the functionality of our website. You can object at any time, with effect for the future, to the collection and storage of data for pseudonymized user-profiling purposes.
We have entered into a data-processing agreement with the provider that ensures the protection of our visitors’ data and prohibits unauthorized disclosure to third parties.
14) Tools and Miscellaneous
14.1 Cookie-Consent Tool
This website uses a so-called “cookie-consent tool” to obtain valid user consent for cookies and cookie-based applications that require consent. The tool is displayed to users as an interactive interface when they visit the page, where consent can be given for specific cookies and/or cookie-based applications by checking a box. All cookies and services requiring consent are loaded only when the user has granted consent by checking the corresponding box. This ensures that such cookies are set only if consent has been given.
The tool sets technically necessary cookies to store your cookie preferences. Personal user data are generally not processed. If, in individual cases, personal data (such as IP address) are processed to store or record cookie settings, this is done based on our legitimate interest in providing a lawful, user-specific, and user-friendly consent-management system and ensuring a legally compliant design of our website.
As the controller, we are also legally required to make the use of non-essential cookies dependent on the user’s consent. Further information about the operator and configuration options of the cookie-consent tool can be found directly in the respective interface on our website.
14.2 Cloudflare Turnstile
We use the CAPTCHA service provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare Turnstile”). This service checks whether data entry on our website (e.g., in a form) is made by a human or by automated programs. To accomplish this, Cloudflare Turnstile collects and analyzes information such as the IP address, browser and operating-system characteristics, date, and duration of the visit. These data are transmitted to Cloudflare’s servers for analysis and help prevent spam, DDoS attacks, and other automated abuse.
We have a data-processing agreement with Cloudflare that ensures the protection of our visitors’ data and prohibits unauthorized disclosure to third parties.
14.3 Google reCAPTCHA
We also use the “reCAPTCHA” function of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). This function serves primarily to determine whether data entry on a website is made by a natural person or is being misused by automated systems. The service involves sending the IP address and, if applicable, other data required by Google for the reCAPTCHA service. Personal data may also be transferred to the servers of Google LLC in the USA.
We have concluded a data-processing agreement with Google that protects our website visitors’ data and prohibits disclosure to third parties. Further information on Google reCAPTCHA and Google’s privacy policy can be found at: https://business.safety.google/intl/en/privacy/ and https://www.google.com/intl/en/policies/privacy/
15) Data-Subject Rights
Under applicable data-protection law, you have the following rights vis-à-vis the controller with respect to the processing of your personal data (rights of access and intervention):
- Right of access pursuant to Art. 25 DSG
- Right to data release or transfer pursuant to Art. 28 DSG
- Right to rectification pursuant to Art. 32 para. 1 DSG
16) Retention Period of Personal Data
The period for which personal data are retained is determined by the respective legal basis, the purpose of processing, and—if applicable—statutory retention periods (e.g., obligations under Swiss commercial or tax law).
Where processing is based on explicit consent, the data concerned will be retained until you withdraw your consent.
If statutory retention periods exist, the data will be stored for the legally required duration. Otherwise, personal data will be processed as long as you do not explicitly object to the processing, unless we can demonstrate an overriding interest in further processing under Art. 31 para. 2 DSG or another legal justification.