We take the protection of your personal data during your visit to our website very importantly. We therefore observe the statutory regulations of data protection, in particular the General Data Protection Regulation (GDPR), the German Federal Data Privacy Act (FDPA), the German Telemedia Act (TMA) and the regulations of the individual states with regard to data protection.
The subject of data protection is ‘personal data’. This data refers to any information relating to an identified or identifiable natural person (data subject). This includes details such as name, postal address, email address or phone number, but also information associated with you, such as purchases made by you.
This website is intended solely for the use of persons aged 16 and above. Please keep this in mind when using our website. We must also point out that persons under the age of 16 will not be able to use our services, unless they have the consent of their parents or legal guardian. This shall apply in particular for the use of contact forms, ordering goods and registering for the newsletter.
1. Data controller
For the collection, processing and use of personal data, the data controller pursuant to Art. 1 (7) GDPR and service provider pursuant to Section 13 of the German Telemedia Act is:
PAUL HEWITT GmbH
26122 Oldenburg, Germany
Tel.: +49 441 3794893-0
Fax: +49 441 3794893-9
Court of registry: Oldenburg Local Court
Commercial register no.: HRB 213475
VAT ID no.: DE304123183
2. Data Protection Officer
The Data Protection Officer at PAUL HEWITT GmbH can be contacted at:
ViCoTec Internetsysteme GmbH & Co. KG
- Data Protection PAUL HEWITT -
Tel: +49 441 / 20 57 22 20
3. Collection, processing and use of personal data
3.1. Collection of personal data upon use of website for informational purposes
If you use the website solely for informational purposes, i.e. if you do not log in or register to use the website or disclose any other information to us, we do not collect any personal data, with the exception of the data that your browser transmits to enable you to visit the website. This data includes:
- IP address
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/http status code
- Volume of transmitted data
- Website from which the request was made
- Operating system and interface
- Language and version of the browser software
We process the aforementioned data for the following purposes:
- to ensure the smooth establishment of a connection to our website,
- to ensure that our website is easy to use,
- to evaluate the security and stability of the system, and
- for other administrative purposes.
Art. 6 (1) f) GDPR provides the legal basis for the processing of data. Our legitimate interest follows from the purposes for processing data listed above.
This data shall be stored separately from other data provided within the context of using our website. We shall not be able to link this data to a specific individual. This data shall be evaluated for statistical purposes. This data shall be evaluated exclusively for the purpose of optimising our website and shall be subsequently erased. They cannot be used to identify you.
Information obtained in connection with the specific terminal device is stored on the cookie. However, this does not mean that we are immediately aware of your identity.
The website uses the following cookies:
- Transient cookies (temporary)
- Persistent cookies (time-limited)
- Third-party cookies (from third parties)
a) Transient cookies are automatically deleted when you close your browser. These include, in particular, session cookies. These store a so-called session ID that enables various requests from your browser to be assigned to the same session. Your computer can therefore be recognised when you return to our website. Session cookies are deleted when you log out or close the browser.
b) Persistent cookies are deleted automatically after a specified time, which may vary from one cookie to the next. You can delete the cookies at any time in your browser’s security settings.
c) You can configure your browser settings according to your own requirements and, for example, refuse to accept third-party cookies or all cookies. We must point out, however, that you may not be able to use all of this website’s functions in this case.
Types and purpose of cookies used by PAUL HEWITT:
Functional cookies ensure that all of the functions of the website work properly. These cookies, for example, transmit information from page to page. They ensure that certain preferences stated by you for the use of the website (e.g. language preference) are stored. Prior consent for the use of these cookies is not required.
PAUL HEWITT would like to make the visit to our website as easy as possible for users. To do so, PAUL HEWITT evaluates how the visitors interact with the website. PAUL HEWITT uses Google Analytics and Shopwarefor this purpose. Please see the privacy policies of our partners for further information on the cookies used by these partners and the data that can be collected by them.
PAUL HEWITT uses marketing cookies to identify which marketing channels are used by the users to access the PAUL HEWITT online shop.
PAUL HEWITT uses this information to help you choose a product that best suits your needs and to offer you products in which you might be interested in the course of remarketing campaigns.
Please see the privacy policies of these partners for further information on the cookies used by these partners and the data that can be collected by them.
The PAUL HEWITT online shop uses retargeting technologies available from several providers. Retargeting technologies enable us to target ads to those users who have already shown interest in our shop and our products. A number of studies have shown that relevant advertising is more appealing for users than non-personalised advertising. In retargeting, the ads are displayed on the basis of an analysis of the user’s previous conduct on the Internet. No personal or pseudonymous data is stored. Retargeting technologies are used in compliance with the currently valid statutory data protection regulations. By disabling and/or deleting the existing cookies, you can prevent these ads from being displayed.
The data processed by these cookies is necessary for the specified purposes in order to safeguard our legitimate interests and the interests of third parties pursuant to Art. 6 (1) f) GDPR.
The information shall be stored separately from any other data provided to us. In particular, the data collected by the cookies shall not be linked with any other data relating to you.
3.3. Particular forms of website use
Apart from using our website for purely informational purposes, we also offer a wide variety of services that you are welcome to use, if interested. For this purpose, you will usually have to provide personal data which we require and use to provide the respective service. Where additional voluntary data is required, such data is marked accordingly.
3.3.1. Using our web shop
- Our web shop may only be used by persons aged 16 and above or with the consent of a parent or legal guardian. By using our web shop, you thereby confirm that you are over 16 years of age or that a parent or legal guardian has given their consent.
- If you would like to order something in our web shop, you can either enter the data required for the order once only for this particular order or create a customer account, thereby allowing your data to be stored for future purchases. If you create an account, we store your data for the purpose of fulfilling the contract and erase this data as soon as we are no longer legally obligated to store the data. Mandatory details necessary for performing the contracts are marked accordingly; other information is provided voluntarily.
- The data provided by you when you create an account under [‘My account’] is stored on a revocable basis. Please contact customer service at shop[at]paul-hewitt.com to delete your customer account.
- We use the data provided by you to process your order pursuant to Art. 6 (1) b) GDPR. For this purpose, we forward your address details to a shipping company contracted by us and, where required, your bank details are sent to our main bank. We shall erase this data once the contract has been fulfilled and the data retention obligations under tax and commercial law have expired.
- The order process is SSL encrypted to prevent unauthorised access by third parties to your personal data, particularly financial data.
3.3.2. Use of our contact form and email contact
- You may only provide us with your email address for contact purposes if you are aged 16 and above or if you have the consent of a parent or legal guardian. By using this function, you thereby confirm that you are over 16 years of age or that you have the consent of a parent or legal guardian.
- If you have any questions, you can also contact us using a form provided for this purpose on the website. In this case, you are required to state your email address so that we can answer your questions. Other details (e.g. name and phone number) may be provided voluntarily and are marked accordingly.
- Alternatively, you may contact us using the email address provided. In such cases, we store your personal data transmitted in the email.
- The legal basis for data processing is point b of Article 6 (1) of the GDPR. Your personal data will be erased once your request has been processed. If the intention of getting in touch is to conclude a contract, your personal data will be erased after the legal retention period for tax documents.
- To support our legitimate interest in fast and customer-friendly communication and technical administration, we use the following partner applications pursuant to point f of Article 6 (1) of the GDPR:
We process and store incoming emails and requests that come from our contact form or social media using an application from Zendesk, a processor contracted by us, which is a customer service platform from Zendesk Inc., 1019 Market Street San Francisco, CA 94103. Zendesk Inc. is certified under the US-EU Privacy Shield data protection agreement, which ensures compliance with the level of data protection applicable in the EU (https://www.privacyshield.gov/participant?id=a2zt0000000TOjeAAG&status=Active). User data is only processed in accordance with our instructions. Data processing takes place in the USA. You can find more information in Zendesk’s data protection guidelines: https://www.zendesk.de/company/customers-partners/eu-data-protection/.
- You may only register for the newsletter if you are aged 16 and above or if you have the consent of a parent or legal guardian. By registering for the newsletter, you thereby confirm that you are over 16 years of age or that you have the consent of a parent or legal guardian.
- Where you have given us your express consent to do so pursuant to Art. 6 (1) a) GDPR, we shall use your email address to send you our newsletter at regular intervals.
- For newsletter registration, we use the so-called double opt-in procedure. This means that, after you have provided us with your email address, we send a confirmation email to this address asking you to confirm that you wish to receive the newsletter. If you do not confirm this within 24 hours, your registration will be automatically deleted. If you confirm that you would like to receive the newsletter, we will store your email address until such time as you unsubscribe from the newsletter. We store your data solely for the purpose of sending you the newsletter. Additionally, we also store the time of registration and confirmation, as well as the IP addresses used by you, to prevent any misuse of your personal data.
- You may withdraw your consent to have the newsletter sent to you at any time. You can withdraw your consent by clicking on the link provided in each newsletter email, by way of the online contact form, by sending an email to shop[at]paul-hewitt.com or by contacting us using the contact details stated in the Legal Notice, without incurring costs other than the transmission costs charged at the basic rates. Your data shall not be forwarded to third parties.
- The only mandatory information required to send you our newsletter is your email address. The provision of other separately marked data is voluntary and shall be used solely to personalise the newsletter. This data shall also be completely erased where consent is withdrawn.
- Pseudonymised data is collected and stored on this website using technology from Zendesk Inc., 1019 Market St, San Francisco, USA (www.zendesk.com) for the purposes of web analysis and to run the live chat system to respond to live support requests. A pseudonymous user profile may be created using this pseudonymised data. Cookies may be used to do so. If the information collected refers to a person, processing takes place on the basis of our legitimate interest in effective customer support and the statistical analysis of user behaviour for optimisation purposes, pursuant to point f of Article 6 (1) of the GDPR. You can find more details concerning data processing in point 3.3.2.
- Data collected by Zendesk technologies is not used to personally identify visitors to this website and shall not be merged with personal data relating to the owner of this pseudonym without having obtained separate consent from the data subject. Entering a name and e-mail address indicates consent.
- To avoid saving Zendesk cookies, you can change your browser settings such that cookies can no longer be saved on your computer, or such that saved cookies are deleted. However, disabling all cookies may result in you no longer being able to use some functions on our pages.
- Depending on the nature of the conversation with our employees, additional personal data may be generated in the chat, entered by you. The nature of this information depends on your request or the problem you have. All information that you share in the chat with our employees is done so voluntarily.
- You may only contact us via the live chat if you are aged 16 and above or if you have the consent of a parent or legal guardian. By using this function, you thereby confirm that you are over 16 years of age or that you have the consent of a parent or legal guardian.
3.4. USE OF YOUR DATA FOR DIRECT MARKETING
In addition to processing your data to process your purchase, we also use your data in individual cases to communicate with you in connection with the planned or completed purchase of our goods and to recommend by e-mail similar products of our company (such as watches, jewellery and accessories) which might interest you. In doing so, we also take into account goods that you have placed in the shopping basket but ultimately did not purchase. This serves to protect our legitimate interests in advertising to our customers, which outweigh the interests of our customers.
Section 6 (1) f) provides the legal basis for transmitting these direct marketing measures following the sale of goods or services.
You may object to the use of your personal data for the aforementioned marketing purposes at any time, either for all measures or for individual measures, without incurring costs other than the transmission costs charged at the basic rates. Notification in text form (e.g. call, email, letter) to the contact addresses specified in 1 and 2 above shall be sufficient in that respect.
4. Disclosure of data
We shall only disclose your data to third parties (data recipients) where:
- you have given us your express consent to do so pursuant to Art. 6 (1) a) GDPR;
- the disclosure of said data pursuant to Art. 6 (1) f) GDPR is necessary to safeguard our legitimate interests and there is no reason to assume that you have an overriding and legitimate interest in not allowing your data to be disclosed;
- there is a legal obligation to disclose said data pursuant to Art. 6 (1) c) GDPR;
- this is necessary to execute contractual relationships with you pursuant to Art. 6 (1) b) GDPR;
- we engage a processor to process the data in compliance with Art. 28 GDPR.
Your personal data shall not be disclosed for purposes other than those specified above.
5. Further information
- Pursuant to Art. 13 (1) f) GDPR, please note that, for the purposes of contract fulfilment, we may be required to transmit personal data to PAUL HEWITT Trading (Shenzhen) Co., Ltd., Room 311‐08, 3F New Times Plaza, No. 1 Taizi Road, Shekou, Nanshan District, Shenzhen 518067, China or to our Fulfillment Center PAUL HEWITT US, B Walker Street, Unit D, 7/F, King Yip Factory Building, US-10731 Cypress, USA. China and the USA are not subject to any adequacy decision, which is why we apply the standard contractual clauses of the European Commission in this respect. Further information and the option to receive copies of these clauses are available here: https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32010D0087
- Pursuant to Art. 13 (2) e) GDPR, please note that the provision of your personal data to us is neither a statutory nor a contractual requirement. The fields marked as mandatory in the order process are, however, necessary for the conclusion of a contract. You are under no obligation to provide us with your personal data. Failure to provide personal data shall have no negative consequences for you.
6. Rights of the data subject
You have the right
- pursuant to Art. 15 GDPR, to request access to the personal data that we have processed in relation to you.
- pursuant to Art. 16 GDPR, to request the rectification of any incorrect or incomplete personal data we have stored in relation to you;
- pursuant to Art. 17 GDPR, to request the erasure of personal data that we have stored in relation to you;
- pursuant to Art. 18 GDPR, to request the restriction of processing of your personal data;
- pursuant to Art. 20 GDPR, to request the provision of the personal data provided to us by you in a structured, commonly used and machine-readable format or to have this data transmitted to another controller;
- pursuant to Art. 7 (3) GDPR, to withdraw any consent granted to us by you at any time. This means that, in future, we shall not be permitted to continue with the processing of the data for which this consent was granted, and
- pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a general rule, you can address this complaint to the competent supervisory authority at your usual place of residence or work or at our place of business.
- Provided that your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) f) GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, insofar as there are reasons for this relating to your particular situation or where the objection refers to direct marketing. In the latter case, you have a general right of objection that will be implemented by us without reference to a particular situation.
Please address any queries and/or declarations concerning your above rights by email to datenschutz[at]paul-hewitt.com or to the address specified in Section 1 (2) above.
7. Web tracking
7.1. Social plug-ins of Facebook
The PAUL HEWITT website uses so-called social plug-ins (‘plug-ins’) of the social network Facebook, operated by Facebook Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA (‘Facebook’). The plug-ins are marked with a Facebook logo or the addition ‘social plug-in of Facebook’ or ‘Facebook social plug-in’. You can find an overview of the Facebook plug-ins and what they look like here: https://developers.facebook.com/docs/plugins
If you access a page of our website that contains such a plug-in, your browser establishes a direct connection to the Facebook servers. The content of the plug-in is transmitted directly to your browser by Facebook and integrated into the page. This integrated content allows Facebook to receive information that your browser has accessed the respective page of our website even if you do not have a Facebook profile or are currently not logged into Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the USA and stored there.
If you are logged into Facebook, Facebook can directly link your visit to our website to your Facebook profile. If you interact with plug-ins, for example, by pressing the ‘Like’ button or posting a comment, this information is also transmitted directly to a Facebook server and stored there. The information is also published on your Facebook profile and is then visible to your Facebook friends.
If you do not want Facebook to directly link the information collected on your visit to our website to your Facebook profile, you should log out of Facebook before visiting our website. You can also prevent Facebook plug-ins from being uploaded by installing add-ons in your browser, for example,
for Mozilla Firefox: https://addons.mozilla.org/en-US/firefox/addon/facebook_blocker/
for Opera: https://addons.opera.com/de/extensions/details/facebook-blocker/?display=en
for Chrome: https://chrome.google.com/webstore/detail/facebook-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf
7.2. Social plug-ins of Google+
The PAUL HEWITT website uses so-called social plug-ins (‘plug-ins’) of the social network Google+, operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (‘Google’). The plug-ins can be recognised, for example, by the ‘+1’ button on a white or coloured background. You can find an overview of the Google plug-ins and what they look like here: https://developers.google.com/+/plugins
If you access a page of the PAUL HEWITT website that contains such a plug-in, your browser establishes a direct connection to the Google servers. The content of the plug-in is transmitted directly to your browser by Google and integrated into the page. This integrated content allows Google to receive information that your browser has accessed the respective page of our website even if you do not have a Google+ profile or are currently not logged into Google+. This information (including your IP address) is transmitted directly from your browser to a Google server in the USA and stored there.
If you are logged into Google+, Google can directly link your visit to our website to your Google+ profile. If you interact with plug-ins, for example, by pressing the ‘+1’ button, this information is also transmitted directly to a Google server and stored there. The information is also published on Google+ and is then visible to your contacts.
If you do not want Google to directly link the information collected on your visit to our website to your Google+ profile, you should log out of Google+ before visiting our website. You can also completely prevent Google plug-ins from being uploaded by installing add-ons in your browser, for example, the script blocker ‘NoScript’ (http://noscript.net/).
7.3. Social plug-ins of Twitter (e.g. ‘Twitter’ button)
The PAUL HEWITT website uses so-called social plug-ins (‘plug-ins’) of the microblogging service Twitter, operated by Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA (‘Twitter’). The plug-ins are marked with a Twitter logo, for example, in the form of a blue ‘Twitter’ bird. You can find an overview of the Twitter plug-ins and what they look like here: https://publish.twitter.com/
If you access a page of our website that contains such a plug-in, your browser establishes a direct connection to the Twitter servers. The content of the plug-in is transmitted directly to your browser by Twitter and integrated into the page. This integrated content enables Twitter to receive information that your browser has accessed the respective page of our website even if you do not have a Twitter profile or are currently not logged into Twitter. This information (including your IP address) is transmitted directly from your browser to a Twitter server in the USA and stored there.
If you are logged into Twitter, Twitter can directly link your visit to our website with your Twitter profile. If you interact with plug-ins, for example, by pressing the ‘Twitter’ button, this information is also transmitted directly to a Twitter server and stored there. The information is also published on your Twitter account and is then visible to your contacts.
If you do not want Twitter to directly link the information collected on your visit to our website to your Twitter profile, you should log out of Twitter before visiting our website. You can also completely prevent Twitter plug-ins from being uploaded by installing add-ons in your browser, for example, the script blocker ‘NoScript’ (http://noscript.net/).
7.4. Social plug-ins of Instagram
The PAUL HEWITT website uses so-called social plug-ins (‘plug-ins’) of Instagram, operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (‘Instagram’). The plug-ins are marked with an Instagram logo, for example, in the form of an ‘Instagram camera’. You can find an overview of the Instagram plug-ins and what they look like here:http://blog.instagram.com/post/36222022872/introducing-instagram-badges
If you access a page of the PAUL HEWITT website that contains such a plug-in, your browser establishes a direct connection to the Instagram servers. The content of the plug-in is transmitted directly to your browser by Instagram and integrated into the page. This integrated content enables Instagram to receive information that your browser has accessed the respective page of our website even if you do not have a Instagram profile or are currently not logged into Instagram. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there.
If you are logged into Instagram, Instagram can directly link your visit to our website to your Instagram account. If you interact with plug-ins, for example, by pressing the ‘Instagram’ button, this information is also transmitted directly to an Instagram server and stored there. The information is also published on your Instagram account and is then visible to your contacts.
If you do not want Instagram to directly link the information collected on your visit to our website to your Instagram profile, you should log out of Instagram before visiting our website. You can also completely prevent Instagram plug-ins from being uploaded by installing add-ons in your browser, for example, the script blocker ‘NoScript’ (http://noscript.net/).
7.5. Integration of the Trusted Shops Trustbadge
The Trusted Shops Trustbadge is integrated into this website to enable the Trusted Shops trustmark, any customer reviews and the range of Trusted Shops products to be displayed to buyers following an order.
In balancing the various interests, this serves to safeguard our legitimate overriding interests in the optimal marketing of our product range. The Trustbadge and the services advertised by it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany.
When the Trustbadge is retrieved, the web server automatically stores a so-called server log file which contains, for example, your IP address, the date and time of retrieval, the transmitted data volume and the requesting provider (access data). It also documents the retrieval. This access data is not evaluated and is automatically overwritten seven days after your visit to the website.
Other personal data shall only be forwarded to Trusted Shops if you decide, after placing an order, to use Trusted Shops products or have already registered to use them. In this case, the contractual agreement concluded between you and Trusted Shops shall apply.
In order to write a review via www.trustpilot.comwww.trustpilot.com, a prior registration with trustpilot.de is required. The review will be published on the websites of Trustpilot and its partners. For the purpose of using trustpilot.de the e-mail address, name and an internal reference number will be passed on by PAUL HEWITT GmbH to Trustpilot A/S, Trommesalen 5, 3. sal, 1614 København, Denmark. Trustpilot will not use this information itself or pass it on to third parties and will use it as a reference to assign your rating to our company. If a rating is placed with the rating system www.trustpilot.com, the data protection regulations published there apply. The necessary information can be found at https://de.legal.trustpilot.com/end-user-privacy-terms and https://de.legal.trustpilot.com/end-user-terms-and-conditions.
7.7. Web analysis using Google Analytics
This website uses Google Analytics, a web analysis service provided by Google Inc. (‘Google’). Google Analytics uses so-called cookies (i.e. text files) which are stored on your computer and enable an analysis of how you use the website. The information generated by the cookie about your use of this website is normally sent to a Google server in the USA and stored there. If IP anonymisation has been enabled on this website, however, your IP address will first be truncated by Google within the member states of the European Union or in other countries that are party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and truncated there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, to compile reports about website activity and to provide the website operator with other services relating to website activity and Internet usage.
The IP address transmitted by Google Analytics from your browser will not be combined with any other data held by Google.
You can prevent the storage of cookies on your computer by adjusting your browser settings accordingly; we should point out, however, that in this case you may not be able to use all of this website’s functions to their full extent.
You may also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) for Google, as well as the processing of this data by Google, by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en
This website uses Google Analytics with the extension ‘_anonymizeIp()’. This allows further processing of the truncated IP addresses, thereby preventing any direct connection being established to a particular individual.
Google Analytics is used in compliance with the requirements agreed on by the German Data Protection Authorities and Google. Third-party provider details: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001
Terms and Conditions of Use: http://www.google.com/analytics/terms/en.html
Data protection overview: http://www.google.com/intl/en/analytics/learn/privacy.html
7.8. Doubleclick by Google
7.9. Google Maps
This website uses the map service Google Maps by way of an API. The provider of this service is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
The storage of your email address is required to enable you to use the Google Maps feature. This information is usually transmitted to a Google server in the USA and stored there. The provider of this website has no influence over the data transmitted.
Google Maps is used in the interests of ensuring that our website is visually appealing to the user and that the locations specified on the website are easy to find. This constitutes a legitimate interest within the meaning of Art. 6 (1) f) GDPR.
This website uses technologies of Episerver GmbH (https://www.episerver.com/products/platform/personalization/)(hereafter "Episerver") to store data for marketing and optimization purposes. This data enables us to tailor our Internet pages specifically to your interests and then offer you suitable product recommendations and content. This is done by analyzing your user behavior based on the products you have already been interested in in our shop.
The analysis is carried out with the help of so-called "cookies", small text files that are stored on your computer or mobile device. These cookies enable us to recognize your browser when you visit our website again. You have the possibility to delete the cookies in your browser at any time. User profiles are created exclusively under pseudonyms and are not merged with your personal data.
Episerver does not store any personal data. The analysis is based on completely anonymous data, which is deleted as soon as it is no longer required for the purpose of its collection.
7.11. Klaviyo (newsletter mailing)
This website uses the services of Klaviyo for sending newsletters. The provider is Klaviyo Inc, 125 Summer St, Boston, MA 02110, USA.
Klaviyo is a service that allows to organise the distribution of newsletters, among other things. If you enter data for the purpose of receiving newsletters (e.g. e-mail address), this data is stored on Klaviyo's servers in the USA.
Users automatically receive a profile in Klaviyo, provided they are registered for our newsletter (double-opt-in) or have a shop account with a customer number and have thus agreed to receive the email.
Furthermore, it enables the website operator to analyse the behaviour of the website visitors. In this context, the website operator receives various, detailed usage data, such as the submission of a rating, support requests, purchasing behaviour in the shop and the origin of the user.
Klaviyo may combine this data in a profile that is assigned to the respective user or their end device. The data may be shared with our service providers or business partners. If you do not want your data to be transferred to Klaviyo, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message.
The data processing is based on your consent (Art. 6 para. 1 lit. a DSGVO). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations already carried out remains unaffected by the revocation.
The data you provide for the purpose of receiving the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and will be deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data that has been stored by us for other purposes remains unaffected by this.
After you have unsubscribed from the newsletter distribution list, your e-mail address will be stored by us or the newsletter service provider in a blacklist, if necessary, in order to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f DSGVO). The storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest.
For more details, please refer to the Klaviyo data protection provisions at: https://www.klaviyo.com/privacy.
7.12. Pinterest Tag
We have embedded Pinterest tag on this website. The provider is Pinterest Europe Ltd, Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
Pinterest Tag is used to record certain activities that you perform on our website. The data may subsequently be used to display interest-based advertising to you on our website or on another page of the Pinterest tag advertising network.
For this purpose, the Pinterest tag collects, among other things, a tag ID, your location and the referrer URL. It may also collect promotion-specific data such as order value, order quantity, order number, category of items purchased and video views.
Pinterest Tag uses technologies that enable the recognition of the user across pages for the analysis of user behaviour (e.g. cookies or device fingerprinting).
The use of Pinterest Tag is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in marketing measures that are as effective as possible. Insofar as a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO; the consent can be revoked at any time.
Pinterest is a globally operating company, which means that data may also be transferred to the USA. According to Pinterest, this data transfer is based on the standard contractual clauses of the EU Commission. Details can be found here: https://policy.pinterest.com/de/privacy-policy.
You can find more information on Pinterest tag here: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag.
7.13. TikTok Pixel
The PAUL HEWITT online shop uses the "TikTok pixel" of the social network TikTok, which is operated by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland ("TikTok"). With the help of the TikTok pixel, it is possible for TikTok to determine the visitors to our online store as a target group for the display of advertisements (so-called "TikTok Ads"). Accordingly, we use the TikTok pixel to display the TikTok ads placed by us only to those TikTok users who have also shown an interest in our online offer or who have certain characteristics that we transmit to TikTok. The TikTok pixel also allows us to statistically analyze the TikTok ads that are served. Data processing by TikTok is carried out within the framework of TikTok's Data Use Policy. For specific information and details about the TikTok Pixel and how it works, please visit the TikTok help section: https://www.tiktok.com/legal/privacy-policy?lang=en The use of the TikTok Pixel as well as the storage of "conversion cookies" is based on Art. 6 (1) lit. a DSGVO. You can object to the data collection by the TikTok pixel and use of your data to display TikTok ads. You can find an opt-out option in our cookie settings.
This website uses Hotjar. The provider is Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe (website: https://www.hotjar.com). Hotjar is a tool used to analyse your user behaviour on this website. Hotjar allows us to record, among other things, your mouse movements, scrolling movements and clicks. Hotjar can also determine how long you have stayed with the mouse pointer on a certain spot. From this information, Hotjar creates so-called heat maps, which can be used to determine which website areas are viewed preferentially by the website visitor. Furthermore, we can determine how long you stayed on a page and when you left it. We can also determine at which point you abandoned your entries in a contact form (so-called conversion funnels). In addition, Hotjar can be used to obtain direct feedback from website visitors. This function serves to improve the website operator's web offerings. Hotjar uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or the use of device fingerprinting). Insofar as consent has been obtained, the above-mentioned service is used exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 TTDSG. Consent can be revoked at any time. If no consent has been obtained, the use of this service is based on Art. 6 para. 1 lit. f GDPR; the website operator has a legitimate interest in analysing user behaviour in order to optimise both its website and its advertising.
We have concluded a data processing agreement(DPA) with the above-mentioned provider. This is a contract required by data protection law, which ensures that the provider only processes the personal data of our website visitors in accordance with our instructions and in compliance with the GDPR.
8. Location tracking service
The PAUL HEWITT website can determine the geographic location of your device. The collection of the data serves only to provide you with information that could be interesting and relevant for you on grounds of your geographic location.