Privacy Policy

1) INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE DATA CONTROLLER

1.1 We are delighted that you are visiting our website and thank you for your interest. Below, we provide information on how we handle your personal data when you use our website. Personal data is any information that can be used to identify you personally.

1.2 The data controller responsible for data processing on this website in accordance with the General Data Protection Regulation (GDPR) is elsaanddore.com. The data controller is a natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the data controller), this website uses SSL or TLS encryption. An encrypted connection can be recognized by the character sequence “https://” and the lock symbol in the address bar of your browser.

2) DATA COLLECTION WHEN VISITING OUR WEBSITE

When you visit our website for informational purposes only, i.e. without registering or providing other data, we only collect the data that your browser transmits to our server (so-called “server log files”). This data is technically necessary to display the website and includes:

The page you visited

The date and time of access

The amount of data transferred in bytes

The source/reference from which you accessed the website

The browser you are using

The operating system you are using

The IP address you are using (possibly anonymized)

This data is processed in accordance with Article 6(1)(f) of the GDPR, based on our legitimate interest in improving the stability and functionality of the website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files at a later date if there are specific indications of illegal use.

3) COOKIES

We use cookies to make our website more attractive and to enable certain functions. Cookies are small text files that are stored on your device. Some cookies are deleted at the end of the browser session (session cookies), while others remain and enable us or our partners to recognize your browser the next time you visit the website (persistent cookies).

When cookies are active, they collect and process certain information, such as browser data, location data, or IP address. Persistent cookies are automatically deleted after a certain period of time, depending on the file.

Some cookies facilitate the ordering process, e.g., by saving the contents of your shopping cart. If personal data is processed in connection with cookies, this is done on the basis of Article 6(1)(b) GDPR (performance of a contract) or Article 6(1)(f) GDPR (legitimate interest—optimal and user-friendly website operation).

We may also work with advertising partners who use their own cookies to make the website more attractive. Details about these cookies can be found in the relevant sections below.

You can manage your cookie settings in your browser. However, disabling cookies may limit the functionality of the website.

4) CONTACTING US

When you contact us (e.g., via the contact form or email), personal data is collected. The scope of the data is determined by the respective form. This data is stored and used exclusively for the purpose of responding to your inquiry and providing technical support. The legal basis for processing is Article 6(1)(f) of the GDPR. If the contact is related to the conclusion of a contract, Article 6(1)(b) of the GDPR also applies. After the inquiry has been processed, the data is deleted unless there are legal requirements to retain it.

5) DATA PROCESSING FOR THE PURPOSE OF CREATING AN ACCOUNT AND EXECUTING A CONTRACT

Personal data is collected and processed in accordance with Article 6(1)(b) of the GDPR when you provide it to us for the purpose of fulfilling an order or creating a customer account. The specific scope of the data is evident from the forms. You can delete your account by contacting us. The data is then blocked in accordance with the applicable retention periods and subsequently deleted.

6) USE OF DATA FOR DIRECT MARKETING PURPOSES

6.1 Newsletter subscription

Once you have subscribed to the newsletter, we will send you regular information about our offers. All you need is an email address. The newsletter operates on a double opt-in basis—it will only be sent once you have confirmed via a verification link. The legal basis is Article 6(1)(a) of the GDPR.

The IP address and date/time of registration are stored for the purpose of preventing abuse. You can unsubscribe from the newsletter at any time and your address will be deleted.

6.2 Newsletter for customers

If you provided your email address during the purchase, we may send you offers for similar products in accordance with Article 6(1)(f) of the GDPR. You can unsubscribe at any time.

7) DATA PROCESSING FOR ORDER FULFILLMENT

7.1 Transfer of data to carriers

Personal data is transferred to shipping companies and payment service providers for the purpose of order fulfillment (Article 6(1)(b) of the GDPR).

7.2 Payment services

– PayPal: data is transferred to PayPal (Europe) S.à r.l. et Cie, S.C.A.
– SOFORT: data is transferred to SOFORT GmbH (Klarna Group)

8) REMINDERS TO SUBMIT REVIEWS

If you have given your consent in accordance with Article 6(1)(a) of the GDPR, we may send you a reminder to submit a review. You can withdraw your consent at any time.

9) SOCIAL MEDIA PLUGINS

9.1 Facebook plugins (Shariff)
Interaction only takes place after clicking on the plugin. Facebook privacy policy: https://www.facebook.com/policy.php

9.2 Instagram plugins
Data is only transferred when you click on the plugin. Privacy policy: https://help.instagram.com/155833707900388/

10) ONLINE MARKETING

10.1 Google DoubleClick
Used to display tailored ads. Privacy policy: https://www.google.com/policies/privacy/

10.2 Google Ads — conversion tracking
Enables analysis of the effectiveness of ads. Can be disabled in your browser settings.

11) WEB ANALYTICS

Google Analytics
Used to analyze user behavior, based on Art. 6 (1) (f) GDPR. Can be disabled via plugin: https://tools.google.com/dlpage/gaoptout?hl=en

12) RETARGETING / REMARKETING

Facebook Pixel
A tracking tool for optimizing advertising campaigns. Processing takes place only with consent in accordance with Article 6(1)(a) of the GDPR.

13) RIGHTS OF DATA SUBJECTS

You have the right to:

Access your data (Article 15 of the GDPR)

Rectification (Article 16 of the GDPR)

Erasure (Article 17 of the GDPR)

Restriction of processing (Article 18 of the GDPR)

Data portability (Article 20 of the GDPR)

Withdraw consent (Article 7(3) of the GDPR)

Lodge a complaint with a supervisory authority (Article 77 of the GDPR)

13.2 Right to object
You may object to data processing based on legitimate interest, including direct marketing.

14) DATA RETENTION

Personal data is retained only for the period required by law or necessary to fulfill the purposes for which it was collected.