Privacy Policy
1) Information About the Collection of Personal Data and Contact Details of the Responsible Party
1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about the handling of your personal data when using our website. Personal data includes all data that can personally identify you.
1.2 The party responsible for data processing on this website under the General Data Protection Regulation (GDPR) is Aura Folio. The responsible party for processing personal data is the individual or legal entity that decides alone or jointly with others on the purposes and means of processing personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser's address bar.
2) Data Collection When Visiting Our Website
When you use our website purely for informational purposes, i.e., without registering or providing us with information, we only collect data that your browser transmits to our server ("server log files"). When you visit our website, we collect the following data:
- Website visited
- Date and time of access
- Data volume sent in bytes
- Source/reference from which you accessed the page
- Browser used
- Operating system used
- IP address (if necessary, anonymized)
Processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be disclosed or used for other purposes. However, we reserve the right to retrospectively review server log files if concrete indications of unlawful use arise.
3) Cookies
To make visiting our website attractive and enable the use of certain functions, we use cookies. Cookies are small text files stored on your device. Some cookies are deleted after the browser session ends (session cookies), while others remain on your device and allow us or partner companies (third-party cookies) to recognize your browser on your next visit.
Cookies may collect user data, including browser and location data or IP addresses. Persistent cookies are deleted automatically after a specified duration, which may vary depending on the cookie.
Cookies simplify processes, such as saving the contents of a virtual shopping cart for future visits. Data processing occurs in accordance with Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR to optimize functionality and user experience.
Browser settings can be adjusted to inform you about cookies and to individually decide on their acceptance or exclusion. If you refuse cookies, the website's functionality may be limited.
4) Contacting Us
When contacting us via a contact form or email, personal data is collected solely to respond to your inquiry. This data is stored and processed under Art. 6(1)(f) GDPR based on our legitimate interest in resolving your inquiry. If your inquiry seeks to establish a contract, Art. 6(1)(b) GDPR applies.
Your data will be deleted after your request is resolved unless legal retention obligations apply.
5) Data Processing When Opening a Customer Account and for Contract Fulfillment
Personal data will be collected and processed in accordance with Art. 6(1)(b) GDPR when you provide it to us for the purpose of fulfilling a contract or opening a customer account. The specific data collected is visible in the input forms.
You can delete your customer account at any time by sending a message to the address mentioned above. After the contract is fulfilled or your account is deleted, your data will be restricted for further use and deleted upon expiration of legal retention periods, unless you have expressly consented to further use or we are legally allowed to continue using the data.
6) Use of Your Data for Direct Marketing
6.1 Subscription to Our Email Newsletter
If you subscribe to our newsletter, we will send you regular updates about our offers. Providing your email address is mandatory for receiving the newsletter. Any additional information is voluntary and used to address you personally.
We use the double opt-in process, meaning you will receive a confirmation email after subscribing, asking you to confirm your subscription. By activating the confirmation link, you consent to the processing of your data as per Art. 6(1)(a) GDPR.
You can unsubscribe at any time via the link provided in the newsletter or by contacting us. Once you unsubscribe, your email address will be removed unless further use is explicitly permitted by law.
6.2 Sending Email Newsletters to Existing Customers
If you provide your email address when purchasing goods or services, we may use it to send you marketing emails for similar products or services. This is based on our legitimate interest in personalized direct advertising as per Art. 6(1)(f) GDPR. You can object to this use at any time without incurring any costs other than the transmission costs according to basic rates.
7) Data Processing for Order Handling
7.1 General
We share personal data with the delivery company responsible for shipping to the extent necessary to deliver your order. Payment data is shared with the processing bank or payment service provider. Data sharing is based on Art. 6(1)(b) GDPR for contract fulfillment.
7.2 Use of Payment Service Providers
-
PayPal: Payments processed via PayPal may require sharing your data with PayPal (Europe) S.a.r.l. et Cie, S.C.A., Luxembourg. The data shared includes information required for payment processing. PayPal may perform credit checks where necessary. For details, see PayPal’s Privacy Policy: PayPal Privacy Policy.
-
SOFORT: If you select SOFORT as a payment option, payment processing is conducted by SOFORT GmbH, Germany. Data sharing occurs solely for payment purposes and is based on Art. 6(1)(b) GDPR. For more details, visit: SOFORT Privacy Policy.
8) Contact for Review Requests
We may use your email address to request a review of your order if you have explicitly consented under Art. 6(1)(a) GDPR. You can withdraw consent at any time by contacting us.
9) Use of Social Media Plugins
9.1 Facebook Plugins
Our website integrates plugins from Facebook, operated by Facebook Inc., USA. To protect your data, these are embedded as HTML links rather than unrestricted plugins. Clicking the button redirects you to Facebook, where you can interact with their features.
Facebook complies with the EU-US Privacy Shield framework, ensuring adequate data protection levels. For more information, visit: Facebook Privacy Policy.
9.2 Instagram Plugins
Similarly, we use Instagram plugins operated by Instagram LLC, USA. They are embedded as links to protect your data. Instagram complies with the EU-US Privacy Shield. For details, visit: Instagram Privacy Policy.
10) Online Marketing
10.1 DoubleClick by Google
This website uses the DoubleClick by Google online marketing tool operated by Google LLC, USA. DoubleClick uses cookies to display relevant ads, improve campaign performance reports, and prevent users from seeing the same ad multiple times. This processing is based on our legitimate interest in optimal marketing under Art. 6(1)(f) GDPR.
DoubleClick can track conversions via cookie IDs. For example, it tracks whether a user clicks on a DoubleClick ad and subsequently makes a purchase. According to Google, DoubleClick cookies do not contain personally identifiable information.
For more information about DoubleClick's data protection policies, visit: Google Privacy Policy.
10.2 Google AdWords Conversion Tracking
We use Google AdWords, an online advertising program by Google LLC, including conversion tracking. This allows us to measure the success of our advertisements. Cookies set for conversion tracking expire after 30 days and do not identify users personally.
You can disable cookies for Google conversion tracking by configuring your browser settings. For more information, see: Google AdWords Privacy Policy.
11) Web Analytics
Google (Universal) Analytics
This website uses Google Analytics, a web analytics service by Google LLC, USA. Google Analytics uses cookies to analyze how visitors use the website. Data collected is typically transmitted to and stored on Google servers in the USA. This website uses Google Analytics with the “_anonymizeIp()” extension to anonymize IP addresses and exclude direct personal identification.
You can opt out of Google Analytics tracking by using the following browser plugin: Google Analytics Opt-Out.
12) Retargeting/Remarketing/Referral Advertising
Facebook Custom Audience via Pixel
This website uses the “Facebook Pixel” by Facebook Inc., USA, to analyze the effectiveness of Facebook advertisements. Data collected is anonymized for us but may be processed by Facebook for targeted advertising. Processing occurs only with explicit consent under Art. 6(1)(a) GDPR.
For more details, visit: Facebook Privacy Policy.
Google AdWords Remarketing
We use Google AdWords Remarketing to advertise on Google search results and third-party websites. A cookie in your browser identifies ads based on your previous activity. You can opt out of remarketing by using the following plugin: Google Ad Settings.
13) Rights of the Data Subject
13.1 Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right to access (Art. 15 GDPR): Obtain information about your stored personal data and its processing.
- Right to rectification (Art. 16 GDPR): Correct inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): Request deletion of personal data under certain conditions.
- Right to restriction of processing (Art. 18 GDPR): Limit data processing in specific cases.
- Right to data portability (Art. 20 GDPR): Receive your personal data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): Object to processing based on legitimate interests.
13.2 Right to Object
If your data is processed for direct marketing, you have the right to object at any time. Once you object, your data will no longer be used for this purpose.
14) Duration of Storage of Personal Data
The retention period for personal data depends on legal retention requirements (e.g., commercial or tax law). Once these periods expire, the data is routinely deleted unless it is needed for contract fulfillment or further legitimate purposes.