I) Responsible parties, scope
This data protection declaration informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as "data") within our online offer ("website").
Responsible persons:
her1 GmbH
3rd transverse building, ground floor
Brunnenstrasse 196,
10119 Berlin
Further information can be found in the imprint within our online offer.
II) General information on data processing
a) Scope of the processing of personal data
As a matter of principle, we process personal data of our users only insofar as this is necessary for the provision of a functional online offer, as well as for the provision of the services offered by us. The processing of personal data of our users is regularly carried out only after the consent of the user or on the basis of other legal provisions that permit data processing.
If we process your personal data on the basis of your consent, you have the right to revoke your consent at any time without giving reasons with effect for the future.
We also process personal data for statistical and market analysis purposes. In this context, statistics are compiled and analyzed in anonymous form, for example, on the industry affiliation, location, and market area of the website visitors. Details of this can be found in the relevant sections of this data protection declaration.
Additional data protection information may apply to special services (e.g. sending newsletters). We will inform you about these at the beginning of the use of the respective service.
b) Data deletion and storage period
In principle, and unless otherwise stated, your personal data will only be stored until the purpose for which it was collected and stored no longer applies. In accordance with your consent, data may also be stored for longer as long as you do not revoke your consent.
In addition, storage may take place if this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which we are subject. This is the case, for example, with invoice data, which must generally be stored for at least 10 years.
If data is stored on the basis of such a statutory provision, its processing shall also be restricted accordingly, i.e. the data shall no longer be processed for any other purposes for which it was collected. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the conclusion or performance of a contract.
c) Use of processors
In performing the services we offer, we use external service providers who, among other things, also process your personal data exclusively on our behalf. This is the case with content delivery networks, payment service providers, fulfillment and shipping service providers, accounting service providers, newsletter shipping service providers, and CRM and hosting service providers. We have concluded agreements with all such processors - where required by law - on the processing of personal data on behalf pursuant to Art. 28 DSGVO.
d) Transfer to third countries
Unless otherwise specified, all data processing operations take place within the EU or EEA countries.
Data processing operations carried out via third-party providers established outside the aforementioned geographical area may be carried out in part or in full in the countries of the respective establishment or in accordance with the respective data protection provisions.
Any transfer of personal data outside the EU or the EEA will only be made on the basis of an adequacy decision by the European Commission, or in accordance with standard contractual clauses of the European Commission. A list of current adequacy decisions is available on the European Commission's website.
III) Use of data in general form in the provision of the website and creation of log files
When you visit our website, we automatically store usage-related data about the usage process. This includes in particular the IP address, the URLs visited, the length of stay, the operating system and browser used and the amount of data transferred.
We collect this data to ensure that our website is available to you. In addition, it is used to analyze, store and evaluate user behavior anonymously and to continuously improve and develop the service. For more details on the systems used in this process, please refer to the sections on cookies and social media below.
We only store your IP address in the log files for a limited period of time, insofar as this is necessary for security purposes. In addition, your IP address is hashed in the process, so that it is not possible for us to draw a conclusion about your connection or your device.
The aforementioned purposes are also our legitimate interest, which justifies the data processing pursuant to Art. 6 Par. 1 lit. f) DSGVO.
The basis of the processing is Art. 6 para. 1 letter f) DSGVO.
IV) Data processing during the creation of a user account
-
-
User account creation
-
On our website you have the possibility to create a user account to place orders and store information about past orders. To register an account, you are required to provide the following data: name, surname, e-mail address and password. Other data, such as phone number, address, contact details, billing information and date of birth, etc., you can provide voluntarily.
We require the above-mentioned data to ensure that the user account functions as intended and can only be assigned to you. The collection and processing of personal data in this context is justified by the user contract that we conclude with you. If you do not provide us with this data, we will unfortunately not be able to set up a customer account for you and provide our associated services.
The basis of the processing is Art. 6 para. 1 letter b) DSGVO.
-
-
Placing an order
-
On our website, you can place an order either via your user account or "as a guest" and purchase the products offered by us either once or recurring as part of a subscription. In this case, we collect the following personal data during the ordering process: first name, last name, delivery address, billing address (if different). You can provide us with further information voluntarily. If this data is already stored in your user account, it is no longer necessary to provide it.
This information is mandatory in order to carry out the purchase contract concluded with you and the associated communication with you. If you do not provide us with this data, we can unfortunately not enter into a contract with you.
Payment data is not collected and stored by us, but directly by the respective payment service provider selected by you, which carries out the payment. We receive from the payment service provider only the information about whether the payment was successful.
The basis of the processing is Art. 6 para. 1 letter b) DSGVO.
-
-
Further processing due to legal obligations
-
Personal data that we collect in connection with your use of our website and the tasks of orders, we also store and process if we are required or authorized to do so by relevant statutory provisions. This is the case, for example, with invoice data that we require for proper accounting.
The basis of the processing is Art. 6 para. 1 lit. c) DSGVO.
V) Data transmission when using the contact form
If you contact us via the contact form on the website, we will receive the personal data that you voluntarily provide to us, i.e. name, e-mail address, details of your request. We use this data exclusively to respond to your contact. If you do not provide us with this data, we will unfortunately not be able to process your request.
The basis of the processing is Art. 6 para. 1 lit. b) DSGVO.
In order to process your inquiries from various channels (contact form, chat, e-mail, meta) quickly and efficiently we use the Gorgias tool from Gorgias Inc, San Francisco, CA, 34 Harriet St, San Francisco, USA, .
The following personal data is collected and processed when using Gorgias: The customer's e-mail address, information about the customer's order(s), information about the customer's previous interactions with our customer support. This data is used exclusively for the purpose of processing customer inquiries and improving our customer support.
The data is stored and analyzed on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in communicating with customers and interested parties as easily as possible. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.
Gorgias is Privacy Shield certified as a US provider and thus undertakes to comply with EU data protection law. In addition, we have concluded a Data Processing Agreement (DPA) with Gorgias. This ensures that Gorgias only uses the user data within the framework of EU data protection standards exclusively for processing the requests and does not pass them on to third parties. This data will not be passed on to third parties unless this is necessary to fulfill our contractual obligations or we are legally obliged to do so.
If you do not agree with the processing of your request by us via Gorgias, you can alternatively communicate with us by telephone. You can find the data in the legal notice.
You can find further information in Gorgias' privacy policy at https://www.gorgias.com/privacy
VI) Market analyses
In order to run our business economically, to be able to recognize market trends, wishes of contractual partners and users, we analyze the data we have on business transactions, contracts, inquiries, etc.. In doing so, we process inventory data, communication data, contract data, payment data, usage data, metadata on the basis of Art. 6 para. 1 lit. f. DSGVO, whereby the data subjects include contractual partners, interested parties, customers, visitors and users of our online offer.
The analyses are carried out for the purpose of business evaluations, marketing and market research. In doing so, we may take into account information about users with details, e.g., about the services they have used. The analyses serve us to increase the user-friendliness, the optimization of our offer and the business management. The analyses serve us alone and are not disclosed externally, unless they are anonymous analyses based on aggregated values.
The basis of the processing is Art. 6 para. 1 letter f) DSGVO.
VII) Friends-recruit-friends
On our website you have the possibility to generate a referral code that you can send to another person. If this person redeems the code when purchasing one of our products, you will receive the respective benefit provided. When you participate in the refer-a-friend program, we collect your e-mail address and, on a voluntary basis, your name. We need this data in order to be able to clearly assign the purchase to you under redemption of the code. If you do not provide us with this data, we will unfortunately not be able to grant you the contractually promised benefits.
The basis of the processing is Art. 6 para. 1 lit. b) DSGVO.
VIII) Use of cookies and other trackers
a) Description and scope of data processing
In order to make visiting our website more attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your terminal device. Some of the cookies we use are deleted after the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your terminal device and enable us or our partner companies to recognize your browser on your next visit (persistent cookies).
You can set your browser so that you are informed about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general. In addition, you can manually delete cookies from your terminal device at any time.
If cookies are not accepted, the functionality of our website may be limited.
We use cookies in accordance with Art. 6 para. 1 lit. c) DSGVO, insofar as this is necessary for the fulfillment of a legal obligation to which we are subject, as well as, pursuant to Art. 6 para. 1 lit. f) DSGVO, for the protection of our legitimate interests in an optimized presentation of our offer, which prevail in the context of a balancing of interests.
We only use other cookies that allow us to monitor and evaluate user behavior for market analysis purposes if you have given us your consent pursuant to Art. 6 (1) a) DSGVO. These are third-party cookies that are applied when you use our services. Please refer to the following sections for details. Unless otherwise stated, the transfer of your data to third parties in the USA whose cookies are used via our website takes place within the framework of the EU-USA Privacy Shield. However, there is currently no adequacy decision by the European Commission for the USA.
Unless explicitly stated otherwise, we use the following cookies and trackers only with your consent. The basis of the processing is therefore Art. 6 (1) a) DSGVO.
GOOGLE ANALYTICS
We work with "Google Analytics". This is a web analysis service of Google Inc. The information generated by the Google Analytics cookie about your use of our website is usually transmitted to a Google server in the USA and stored there. IP anonymization has been activated on our websites so that the IP address of users is shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the unabbreviated IP address be transmitted to a Google server in the USA and shortened there. On our behalf, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of this data, by installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de. Alternatively, you can click on the following link: Google Analytics deactivate. An opt-out cookie will then be set, which prevents the future collection of your data when visiting this website.
For more information on the handling of personal data by Google, please refer to Google's privacy policy
GOOGLE ADS
Our website uses the "Google Ads" service, which is offered for users from the European Economic Area and Switzerland by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland and for all other users by Google LLC 1600 Amphitheatre Parkway Mountain View, CA 94043, USA (together "Google").
Google Ads uses "Google Ads Conversion Tracking" to record and analyze customer actions defined by us (such as clicking on an ad, page views, downloads, purchases). We use "Google Ads Remarketing" to show you individualized advertising messages for our products on Google partner websites. Both services use cookies and similar technologies for this purpose.
The data collected in this context may be transferred by Google to a server in the USA for analysis and stored there. In the event that personal data is transferred to the USA, we have concluded standard contractual clauses with Google.
If you use a Google account, Google may link your web and app browsing history to your Google account and use information from your Google account to personalize ads, depending on the settings stored in your Google account. If you do not want this association with your Google Account, you must log out of Google before visiting our website.
If you have not consented to the use of Google Ads, Google will only display general advertising that has not been selected based on the information collected about you on this website. In addition to withdrawing your consent, you also have the option of deactivating personalized advertising in Google's advertising settings.
We have concluded an order processing agreement with Google Ireland Limited for the use of Google Ads. In the event that personal data is transferred from Google Ireland Limited to the USA, Google Ireland Limited and Google LLC have concluded standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3) in accordance with Art. 46 para. 2 lit. c GDPR. In addition, we also obtain your express consent for the transfer of your data to third countries in accordance with Art. 49 para. 1 lit. a GDPR.
The following cookies are set by Google:
_gcl_au for 90 days
_gcl_aw for 90 days
IDE for 13 - 24 months
_gcl_dc for 90 days
We use Google Enhanced Conversions. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
We only use the data collected by Google Enhanced Conversions to improve the conversion rate on our website and to optimize our marketing activities and collect additional information about our users. We do not use the data for any other purpose and do not share it with third parties unless required to do so by law or if we are legally obliged to do so.
Google Enhanced Conversions collects the following data: Clicks on certain elements on our website, such as links, buttons and images. Entries in forms on our website. Visits to certain pages on our website.
This data is used by Google in an anonymized or hashed version in accordance with Google's privacy policy: For more information, see: Advanced Conversions - Google Ads Help
The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be withdrawn at any time.
We only store the data collected by Google Enhanced Conversions for as long as is necessary for the stated purpose. The exact duration depends on various factors, such as the type of data and the requirements of applicable law.
You can find more information on this in the information on data use and Google's privacy policy.
GOOGLE RECAPTCHA
For the purpose of protection against misuse of our web forms as well as against spam by automated software (so-called bots), Google reCAPTCHA collects data (IP address, time of visit, browser information as well as information about your use of our website) and carries out an analysis of your use of our website by means of a so-called JavaScript as well as cookies. In addition, other cookies stored by Google services in your browser are evaluated. A readout or storage of personal data from the input fields of the respective form does not take place.
These are also our legitimate interests that justify the processing by GOOGLE RECAPTCHA pursuant to Art. 6 (1) (f) DSGVO.
OMNISEND
Omnisend is an analytics service provided by Omnisend llc., attn. Soundest LLC, Verkiu str. 25C, Vilnius, Lithuania, through which we can, among other things, track your user behavior in the course of visits to our website and orders and thereby gain valuable insights to constantly improve our offer and adapt it to your preferences. We analyze the data collected in aggregate form without drawing any conclusions about your personal identity. For more information about Omnisend's handling of personal data, please refer to the relevant privacy policy: https://www.omnisend.com/privacy/.
MICROSOFT CLARITY
We use Microsoft Clarity on our website, a service offered by Microsoft Corporation. Clarity analyzes the performance of our website anonymously. For example, we receive heatmaps that show us which parts of our website are particularly popular and help us to better adapt our website to the needs of our users. This is also the purpose of the processing. Microsoft Claritiy is only used if you have given your consent (Art. 6 para. 1 sentence 1 lit. a GDPR). The storage period for the collected data is one year. Microsoft processes the data in accordance with our instructions and on our behalf. We have concluded a corresponding order processing agreement with Microsoft.
You can find out more about data processing by MICROSOFT at https://www.microsoft.com/de-de/privacy/privacystatement