data protection
With this data protection declaration we inform you about the scope of processing of your personal data (hereinafter “data”).
1. Responsible for data processing
Responsible for data processing in accordance with the provisions of the General Data Protection Regulation (GDPR) is:
Milk & Sons GmbH
Pappelallee 78/79
10437 Berlin
Email: hello@minimalcards.com
2. General information on data processing
We process data as part of our business and website operations.
This also includes disclosure through transmission to third parties and, if necessary, to so-called third countries outside the European Union (“EU”) and the European Economic Area (“EEA”). If we transmit data outside the EU or the EEA, we have marked this accordingly below.
3. Data processing
The individual data affected, processing purposes, legal basis, recipients and, if applicable, transfers to third countries are listed in the following list:
a) Log file when visiting the website
We log your website visit. We process:
- Name(s) of our accessed website(s),
- Date and time of retrieval,
- the amount of data transferred,
- the browser type and version,
- the operating system you use,
- the referrer URL (the previously visited website),
- your IP address,
- the requesting provider.
The legal basis for data processing is, in accordance with Article 6 Paragraph 1 f) GDPR, our overriding legitimate interest in the ongoing provision and security of our website.
The log file will be deleted after seven days, unless it is needed to prove or clarify specific legal violations that became known within the retention period.
b) Hosting via Shopify
To provide our online presence, we use services from web hosting providers who process the above-mentioned data and all data to be processed in connection with the operation of this website (log file when visiting the website) on our behalf.
The legal basis for data processing is our overriding legitimate interest in providing our website in accordance with Article 6 Paragraph 1 f) GDPR .
We use Shopify Inc., 150 Elgin St., 8th Fl., Ottawa, ON K2P 1L4, Canada (“Shopify”) for our hosting. It is possible that data will also be transferred to the Shopify Inc. servers in Canada.
There is an adequacy decision by the EU Commission for data transfers to Canada.
c) Contact
If you contact us, we will process the following data from you for the purpose of processing and handling your request: name, contact details - if provided by you - and your message.
The legal basis for data processing is our obligation to fulfill the contract and/or to fulfill our pre-contractual obligations in accordance with Art. 6 Para. 1 b) GDPR and/or our overriding legitimate interest in processing your request in accordance with Art. 6 Para. 1 f) GDPR.
d) Contact for applications
If you contact us to send us your application as an employee, for example by email or via a contact form, the data you provide (e.g. name, email address, desired location, etc.) will be yours The message and the submitted application documents are processed exclusively for the purpose of processing and processing your application request.
The legal basis for data processing is primarily Section 26 BDSG . Accordingly, the processing of data that is necessary in connection with the decision to establish an employment relationship is permitted.
If the data is necessary for legal prosecution after completion of the application process, data processing can take place to protect our legitimate interests in accordance with Art. 6 Para. 1 f) GDPR , namely to assert and/or defend claims.
e) Customer account
In connection with opening and using a customer account, we process your inventory data (name, address, email address, bank details) as well as your usage data (user name, password). This allows you to manage your orders and orders and allows us to identify you as a customer. The legal basis for this data processing is your consent in accordance with Art. 6 Para. 1 a) GDPR.
f) Contract execution
We process your order data to process the contractual relationship between you and us. We will transmit your address details to the company responsible for the delivery.
We transmit your transaction data (name, date of order, payment method, shipping and/or receipt date, amount and payee, bank details or credit card details if applicable) to the payment service provider responsible for processing the payment.
To create the invoice we use the service provider Billbee from Billbee GmbH, Arolser Str. 10,
34477 Twistetal, Germany. Your transaction and order data as well as your billing data are transmitted.
According to Art. 6 Para. 1 b) GDPR, the legal basis for data processing is the fulfillment of our contractual obligations and, in individual cases, the fulfillment of our legal obligations in accordance with Art. 6 Para. 1 c) GDPR.
g) Shipping status notifications
If you would like to be informed about the status of the shipment by the shipping service provider (DHL, Hermes, DPD), we will pass on your email address and telephone number to the shipping company you have chosen.
The legal basis for this data processing is your consent in accordance with Art. 6 Para. 1 a) GDPR.
h) Credit check via Klarna
If this is provided for the payment method you have selected, we will carry out a credit check via Klarna. We send your name and address to a credit agency, which compares this data with your own database to check your creditworthiness. The credit agency then sends the relevant credit information to us.
The legal basis for data processing in the case of purchase on account is our legitimate interest in accordance with Art. 6 Para. 1 f) GDPR , as we make advance payments with the dispatch of goods and bear the risk of default. In all other cases, data processing as part of a credit check takes place exclusively on the basis of your prior consent in accordance with Art. 6 Para. 1 a) GDPR.
i) Newsletters
In order to provide you with regular information about our company and offers, we offer to send an email newsletter. When you register for the newsletter, we process the data you enter when registering (email address and other voluntary information). To prevent misuse, we will send you an email after you register asking you to confirm your registration (double opt-in procedure). In order to be able to prove that the registration process is legally compliant, your registration will be recorded. The time of registration and confirmation as well as your IP address are affected.
The legal basis for sending the newsletter is your consent in accordance with Art. 6 Para. 1 a) GDPR . The data processing in connection with sending the confirmation email for your registration and the associated data logging is carried out in accordance with Art. 6 Para. 1 f) GDPR due to our legitimate interest in providing proof of your proper registration.
If you give us your consent, we will also evaluate in the newsletters whether you have opened the newsletter and the scrolling and clicking behavior in the newsletter. This is done for the purpose of optimally tailoring our newsletter to your interests and improving the content of our newsletter. The legal basis for the analysis of the newsletter is your consent in accordance with Art. 6 Para. 1 a) GDPR.
We use a service provider to send the newsletter to whom we transmit the data mentioned.
The data is transmitted to the servers of the following service provider in the USA: Klaviyo Inc., 60 South Street, Suite 910, Boston Massachusetts, USA (“Klaviyo”). There is no adequacy decision from the EU Commission for data transfers to the USA. Klaviyo ensures an appropriate level of data protection via the EU standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
j) Direct email advertising for existing customers
If you have placed an order with us, we will process the email address you provided when registering to recommend products that match the products you purchased.
The legal basis for shipping as a result of the sale of goods or services is our legitimate interest in direct advertising of our products to existing customers in accordance with Art. 6 Para. 1 f) GDPR .
We also use a service provider to send direct advertising to whom we transmit the data mentioned.
The data is transmitted to the servers of the following service provider in the USA: Klaviyo Inc., 60 South Street, Suite 910, Boston Massachusetts, USA (“Klaviyo”). There is no adequacy decision from the EU Commission for data transfers to the USA. Klaviyo ensures an appropriate level of data protection via the EU standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
k) Direct mail advertising for existing customers
If you have placed an order with us, we process the name and address you entered when registering to recommend products that match the products you purchased.
The legal basis for shipping as a result of the sale of goods or services is our legitimate interest in direct advertising of our products to existing customers in accordance with Art. 6 Para. 1 f) GDPR .
To send direct advertising, we use Deutsche Post as a service provider to whom we transmit the data mentioned.
l) Use of cookies
We use so-called cookies on our website. Cookies are small text files that are stored on your respective device (PC, smartphone, tablet, etc.) and saved by your browser.
You can find information about the specific cookies we use, their providers and purposes in our consent banner. There you give your consent to the respective services, you can revoke it or adjust your settings later.
In order to document your choice of certain data processing processes and to fulfill our data protection obligations, we use a consent banner. When you visit our website, your cookie preferences are requested via a banner. We then set a cookie in which data about consents given or revoked are stored. Data processing is carried out to fulfill our legal obligations in accordance with Art. 6 Para. 1 c) GDPR .
m) Analysis / Marketing
aa) Google services
We use various services from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”) on our website. It is possible that data will also be transferred to Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043 in the USA.
There is no adequacy decision from the EU Commission for data transfers to the USA. Google ensures an appropriate level of data protection via the EU standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
Google Analytics
We use the Google Analytics tracking tool from Google on our website. We use Google Analytics to evaluate your use of the website, to compile reports on the activities within this website and to provide other services related to website use and thus improve user-friendliness.
When using Google Analytics, website visitor interactions are primarily recorded and systematically evaluated using cookies.
We use Google Analytics with the “anonymizeIp()” extension. This shortens IP addresses within EU or EEA member states. If a transmission to Google's servers in the USA takes place, the full IP address will only be transmitted and shortened there in exceptional cases. A direct personal reference is therefore generally excluded. In particular, an assignment to the website visitor's accessed computer or device is no longer possible.
Through the use of Google Analytics, the following data is processed:
- 3 bytes of the IP address of the system accessed by the website visitor (anonymized IP address),
- the website accessed,
- the website from which the user accessed the page on our website (referrer),
- the sub-pages that are accessed from the website,
- the time spent on the website,
- the frequency of accessing the website.
According to its own information, Google will under no circumstances associate your IP address with other Google data.
Google Remarketing/Retargeting
We use so-called tracking cookies from Google on our website. When you visit our site, permanent cookies store information about which products you have viewed on our website and which advertisements and third-party pages users use to reach our website. When you subsequently visit a partner website, we can display personalized advertising for you based on the articles you viewed on our website.
Legal basis and revocation
The legal basis for data processing within the framework of the aforementioned Google services is your prior consent in accordance with Art. 6 Para. 1 a) GDPR.
You can revoke your consent at any time with future effect by adjusting your preferences in our consent banner.
bb) Facebook remarketing / retargeting
We use a so-called tracking pixel on our website from Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, a subsidiary of Meta Platforms Inc. 1601, Willow Road, Menlo Park, CA 94025, USA, a. We use Facebook Pixel to track the success of our own Facebook advertising campaigns and to optimize the display of Facebook advertising campaigns to interested target groups.
After you click on a Facebook ad or visit our website, a cookie is stored on your device using the pixel on our website. The cookie processes data about whether you came to our website via a Facebook ad and makes it possible to analyze the user's behavior until the purchase is completed. This allows us to track the success rate of our Facebook advertising campaigns. In addition, the pixel processes data about the fact that you have visited our website and makes it possible to adapt the advertising shown on Facebook to your interests.
When you visit our website, a direct connection to the Facebook servers is established via the Facebook pixel integrated on our website. The information generated by the cookie about your use of this website (including your IP address) is transmitted to Facebook in the USA.
There is no adequacy decision from the EU Commission for data transfers to the USA. Facebook ensures an appropriate level of data protection via the EU standard contractual clauses. We will provide a copy of the contractual clauses upon request.
The data collected is anonymous to us and does not allow us to draw any conclusions about the user. If you are registered with Facebook, Facebook can assign the information collected to your account. Even if you do not have a Facebook account or are not logged in when you visit our website, it is possible for Facebook to process and store your IP address and other identification data.
You can revoke your consent to data processing by Facebook Pixel for our web domain at any time with effect for the future by adjusting your preferences in our consent banner.
The legal basis for data processing is your consent in accordance with Art. 6 Para. 1 a) GDPR.
cc) Pinterest Insight Tags
We use the Pinterest Insight Tags service on our website for analysis, retargeting and marketing purposes. This is a service provided by Pinterest Europe Ltd. Palmerston House, 2nd Floot, Fenian Street, Dublin 2, Ireland (“Pinterest”).
Pinterest Insight Tags uses cookies to process the following data about you when you use our website:
- Referrer URL
- IP address
- Device information
- Browser information
- time stamp
As part of the Pinterest Insight Tags, data is forwarded to Pinterest Inc., 651 Brannan Street, San Francisco, CA 94107, USA and processed there. There is no adequacy decision from the EU Commission for data transfers to the USA. Pinterest ensures an appropriate level of data protection via the EU standard contractual clauses. We will provide a copy of the contractual clauses upon request.
You can revoke your consent to data processing by Pinterest for our web domain at any time with effect for the future by adjusting your preferences in our consent banner.
The legal basis for data processing is your consent in accordance with Art. 6 Para. 1 a) GDPR .
n) External content
We use dynamic content (“content”) from third parties to optimize the presentation and offering of our website. When you visit the website, a request is automatically made to the server of the respective content provider via an interface, during which certain log data (e.g. the user's IP address) is transmitted. The dynamic content is then transmitted to our website and displayed there.
We use external content in connection with the following functionalities:
aa) Integration of YouTube videos
We have videos on our website from the YouTube portal of YouTube LLC, 901 Cherry Ave. San Bruno, CA 94066, USA (“YouTube”) included. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”) is responsible for data processing on YouTube. However, when the videos are played, log data is transmitted to YouTube's servers in the USA.
The legal basis for processing is your prior consent in accordance with Art. 6 Para. 1 a) GDPR .
There is no adequacy decision from the EU Commission for data transfers to the USA. Google ensures an appropriate level of data protection via the EU standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
bb) Google Fonts
In order to make visiting our website attractive, we use external fonts from Google Fonts. When you visit the site, these are loaded from servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google does not store any cookies in your browser. However, according to our information, the IP address of the user's device is transmitted to Google and stored. This processing is carried out due to our overriding legitimate interest in optimal marketing of our offer in accordance with Art. 6 Para. 1 f) GDPR .
It cannot be ruled out that data will be transferred to Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.
There is no adequacy decision from the EU Commission for data transfers to the USA. Google ensures an appropriate level of data protection via the EU standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
cc) Google Maps
We use the “Google Maps” map service from Google on our website to provide you with an interactive map. When the map is displayed, data including your IP address and your location are transmitted to Google servers and stored there. The legal basis for processing is your prior consent in accordance with Art. 6 Para. 1 a) GDPR .
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”) is responsible for data processing at Maps. It cannot be ruled out that data will be transferred to Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.
There is no adequacy decision from the EU Commission for data transfers to the USA. Google ensures an appropriate level of data protection via the EU standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
dd) REVIEWS.io
In order to provide product reviews on our website, we use the REVIEWS.io service from REVIEWS.io 2020 GmbH, Stralauer Allee 6, 10245 Berlin. Your email address and the content of your review will be transmitted to REVIEWS.io.
REVIEWS.io also uses servers in the United States of America.
Therefore, a third country transfer to the USA cannot be ruled out. There is no adequacy decision from the EU Commission for the USA. REVIEWS.io ensures an appropriate level of data protection via standard contractual clauses. A copy of the relevant EU Standard Contractual Clauses will be provided upon request.
The legal basis for processing is our legitimate interest in accordance with Article 6 Paragraph 1 f) GDPR in exchanges with our customers in order to be able to improve our products.
ee) Seal of payment service providers
We use the seal of the payment service “Paypal” on our website. These are loaded from PayPal (Europe) S.à rl et Cie, SCA servers when you visit the website. The name of the website accessed, the date and time of access, the amount of data transferred, the browser type and version, the operating system you use, the referrer URL (the previously visited website), your IP address and the requesting provider are included transmitted to the respective provider’s servers.
The legal basis for data processing is our overriding legitimate interest in the optimal marketing of our online offering in accordance with Art. 6 Para. 1 f) GDPR.
Further information on data protection can be found at Paypal: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE
4. Duration of data storage
We only store personal data for as long as it is necessary for the purposes for which it is processed or if you have withdrawn your consent. To the extent that legal retention obligations must be observed, the storage period for certain data can be up to 10 years, regardless of the processing purposes.
5. Your data subject rights
a) Information
If you wish, you can receive information about all the personal data that we have stored about you free of charge at any time.
b) Correction, deletion, restriction of processing (blocking), objection
If you no longer agree to the storage of your personal data or if it has become incorrect, we will, upon appropriate instructions, delete or block your data or make the necessary corrections (to the extent this is possible under applicable law). The same applies if we are only supposed to process data to a limited extent in the future. You have the right to object in particular in cases where your data is required to carry out a task that is in the public interest or the data processing is based on our legitimate interest, as well as profiling based on this. You also have the right to object in the case of data processing for direct advertising purposes.
c) Right of withdrawal of consent with effect for the future
You can revoke your consent at any time with effect for the future. Your revocation will not affect the lawfulness of processing up to the time of revocation.
d) Data portability
If data processing takes place on the basis of a contract, pre-contractual negotiations, consent or using automated procedures, you have the right to data portability. Upon request, we will provide you with your data in a common, structured and machine-readable format so that you can transmit the data to another person responsible if you wish.
e) Restriction of processing
Data for which we are unable to identify the data subject, for example if it has been anonymized for analysis purposes, is not covered by the above rights. Access, deletion, blocking, correction or transfer to another company may be possible with respect to this data if you provide us with additional information that allows us to identify you.
f) Exercising your data subject rights and right to complain
If you have any questions about the processing of your personal data, information, correction, blocking, objection or deletion of data or if you wish to transfer the data to another company, please contact hello@minimalcards.com
You also have the option of complaining to a supervisory authority about your data subject rights.