In the following, we would like to inform you about how your personal data is handled when using our website www.luisacerano.com, in accordance with art. 12, 13 and 21 of the General Data Protection Regulation (GDPR) and sect. 13 German Telemedia Act (TMG).
This website is operated by
LUISA CERANO GmbH
Tel.: +49 (0) 7022 / 705 - 137
as the responsible party in terms of data protection law.
The Data Protection Officer of the responsible party can be reached at:
LUISA CERANO GmbH
For the attention of the Data Protection Officer
Tel.: +49 (0) 7022 / 705 -160
LUISA CERANO GmbH ('LUISA CERANO') respects the privacy of all visitors to this website. We process your personal data in accordance with the provisions of the General Data Protection Regulation, the Federal Data Protection Act and other applicable data protection regulations.
'Personal information' means any information relating to an identified or identifiable natural person ('data subject'). These include, for example, name, address, telephone number or e-mail address.
This data protection statement explains what information LUISA CERANO collects, stores and how it is used. This statement al-so explains how you can verify the accuracy of the personal information that LUISA CERANO holds about you and how you can have that personal information deleted or updated.
The purposes of data processing, as well as the corresponding legal bases, are named below.
3.2 Informational use of the website
You can visit our website without providing any personal information. If you use our website for informational purposes only, i.e. if you do not register, log in or otherwise provide us with information about yourself, we will not collect any personal data, with the exception of the data transmitted by your browser to enable you to visit the website and information. This information is transmit-ted to us within the framework of the cookies used.
3.2.1 Technical provision of the website
Automated collection of data and processing by the browser
For the purpose of the technical provision of the website, the server of this website automatically and temporarily collects and stores the following information in the server log files transmitted by your browser, provided that this function has not been deac-tivated by you:
- IP address of the requesting computer
- File request of the client
- The http response code
- The website from which you are visiting this website (referrer-url)
- Date and time of the server request
- Browser type and version
- Operating system that is used by the requesting computer
- Search term with which the website was found, e.g. via Google
An evaluation of the server log files on the basis of personal information does not take place. At no point can these data be as-signed to specific persons for LUISA CERANO. This data is not merged with data from other data sources.
This website uses so-called session cookies in order to make our website available for you to use. Session cookies are small text files that the provider stores in the memory of the visitor's computer. A randomly generated unique identification number is stored in a session cookie, a so-called session ID. In addition, a cookie contains information about its origin and the retention peri-od. These cookies cannot save other data and do not contain any personal information.
Date on which the cookie was created
Expiration date of the cookie
Values concerning variables
Information for Google Analytics
220.127.116.11 Legal basis
We process your personal data for the technical provision of our website on the basis of the following legal requirements:
- to fulfil a contract or to carry out pre-contractual measures, in accordance with art. 6 para. 1 letter b GDPR, insofar as you are visiting our website to inform yourself about our product range, especially in the webshop, our events and other offers and
- to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR, in order to make the website technical-ly available to you. Our legitimate interest is to provide you with an attractive, technically-functional and user-friendly web-site for our company.
3.2.2 Statistical analysis of the use of our website
The information obtained through the statistical analysis of our website will not be merged with any other information you provide which is collected through the website.
Google Analytics, AdWords and Remarketing
Regarding the web analytics service Google Analytics, LUISA CERANO would like to point out the following in accordance with the privacy regulators' guidelines:
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ('Google'). Google Analytics uses so-called cookies, which are text files that are stored on your computer and that allow your use of the website to be analysed. The information generated by the cookie about your use of this website (includ-ing your IP address) is usually transmitted to a Google server in the USA and stored there. LUISA CERANO would like to point out that this website 'Google Analytics' has been extended by the code '_anonymizeIp()' in order to ensure an anonymous collec-tion of IP addresses (so-called IP-masking).
Through the process of IP anonymisation on this website, your IP address will be truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before a transfer takes place. This is done in order to prevent the data from being linked to a specific person The full IP address will only be sent to a Google server in the US and truncated there in exceptional cases.
On behalf of LUISA CERANO, Google will use this information to evaluate your use of the website, compile reports on website activity and provide other services related to website activity and internet usage with respect to LUISA CERANO. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
You can prevent the storage of cookies by setting your browser software accordingly; However, LUISA CERANO would like to point out that in this case, you may not be able to use all the features of this website to the full extent. In addition, by downloading and installing the browser plug-in available under the following link, you may prevent Google from collecting the data generated by the cookie which is related to your use of the website (including your IP address), as well as their processing of this data: http://tools.google.com/dlpage/gaoptout?hl=de.
If you use our website on a mobile device, you can also prevent Google Analytics from collecting your data by clicking on the fol-lowing link. An opt-out cookie will be set which prevents your data being collected during future visits to this website. If you delete your cookies, you must click this link again. https://www.google.com/settings/ads/onweb/
Google has signed a Privacy Shield certification in order to comply with the US Department of Trade's Privacy Shield Agreement between the EU and the US concerning the collection, use and storage of personal data from EU Member States. For more in-formation about Google Analytics and data protection at Google, please visit https://support.google.com/analytics/answer/6004245?hl=de.
LUISA CERANO also uses Google AdWords remarketing technology and Google Tag Manager, an advertising platform of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ('Google'). Using pseudonyms, users who have visit-ed this site will be redirected through targeted advertising on the pages of the Google Partner network. Cookies may be used for this purpose (see section 18.104.22.168), which enable the recognition of an Internet browser. These usage profiles serve to analyse visi-tor behaviour and are used for targeted product recommendation and interest-based advertising. The ‘pseudonymised’ user pro-files are not merged by LUISA CERANO with personal data about the bearer of the pseudonym. You may opt-out of the collection and storage of data for the purpose of web analytics and advertising control at any time by activating Google's opt-out link https://www.google.com/settings/ads/plugin. For more information about Google Remarketing and Google's data protection policy, please visit: http://www.google.com/privacy/ads/.
In addition, you can also use Google Remarketing and Google Tag Manager, as well as all cookies or other types of tracking (eg, counting pixels) by means of their browser settings and/or via free browser add-ons, such as 'Adblock Plus' (https: // adblock-plus.org/de/) in combination with the 'EasyPrivacy' list (https://easylist.to/).
22.214.171.124 Legal Requirements
We process your personal data for the statistical analysis of our website on the basis of the following legal requirements:
• to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR, in connection with sect. 15 para. 3 Tel-emedia Act; our legitimate interest lies in the needs-based design of our website.
3.2.3 Links to social media operators
On this website you will find links (hyperlinks) to the social media networks and the platforms Facebook, YouTube and Insta-gram. These services are offered by the companies listed below ('Providers').
Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ('Facebook').
YouTube is operated by YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA, ('YouTube') - a subsidiary of Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA.
Instagram is operated by Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA ('Instagram').
Data protection policy of Facebook: https://de-de.facebook.com/policy.php
Data protection statement of YouTube/Google: https://www.google.de/intl/de/policies/privacy/
Data protection policies of Instagram: https://help.instagram.com/155833707900388
3.3 Active use of the website
In addition to using our website purely for information, you can also actively use our website to contact us. In addition to the pro-cessing of your personal data for a purely informative use (as described above), we then collect and process further personal data from you which we need in order to process and answer your enquiry.
3.3.1 Communication via the contact form or e-mail
In order to process and answer the enquiry you send to us (e.g. via the contact form or to our e-mail address) to the collection, processing and use of your personal data communicated in this context is earmarked exclusively for receiving and answering and/or processing your request as well as for statistical purposes. If LUISA CERANO no longer needs your data for this purpose, your data will be deleted.
126.96.36.199 Legal basis
We process your personal data in order to respond to user enquiries on the basis of the following legal requirements:
- to safeguard our legitimate interests, in accordance with art. 6 para. 1 letter f GDPR; our legitimate interest lies in answering customer enquiries appropriately.
3.3.2 Sending of newsletters
If you subscribe to the LUISA CERANO newsletter, we will need your e-mail address and you also have the option of giving your name and date of birth. This data is only used in order to communicate with you, within the context of providing the newsletter.
In order to register for the newsletter, LUISA CERANO uses the so-called double-opt-in procedure, i.e. the newsletter will only be sent to you by e-mail if you have previously expressly confirmed to LUISA CERANO that the newsletter service should be acti-vated. Following your registration, you will initially receive an e-mail confirmation at the e-mail address which you have provided, asking you to confirm that you wish to receive the newsletter (by clicking on a link in this e-mail). By clicking on this link, you give your consent to subscribe to the newsletter.
If you purchase goods and services on our website and leave your e-mail address here, this can subsequently be used by us in order to send a newsletter. In such cases, the newsletter will only send direct mail for similar goods or services from our range.
The newsletter will be sent by 'MailChimp', a newsletter sending platform from the American provider Rocket Science Group, LLC, 675 Ponce de Leon Ave NE #5000, Atlanta GA 30308 USA. Its data protection policy can be found here: https://mailchimp.com/legal/privacy/. The Rocket Science Group LLC is certified under the Privacy Shield Agreement, and as such, it provides a guarantee to comply with European data protection standards. The shipping service provider is used on the ba-sis of our legitimate interests in accordance with art. 6 para. 1 letter f GDPR and a contract processing agreement, in accordance with art. 28 para 3 sentence 1 GDPR.
The shipping service provider may use the recipients’ data in the form of a pseudonym, i.e. use without assignment to the user in order to optimise its own services or use the data for statistical purposes. However, the shipping service provider does not use the data of our newsletter recipients in order to write to them itself or to pass the data on to third parties.
If you don't want to receive any further newsletters, you can revoke your consent for the future at any time, without incurring any costs other than the transmission costs according to the basic rates. A message in writing, sent to the e-mail address firstname.lastname@example.org is sufficient for this. Of course, you will also find an unsubscribe link in every newsletter.
188.8.131.52 Legal basis
We process your personal data in order to send newsletters on the basis of the following legal requirements:
- after the user has subscribed to the newsletter and given his/her consent to this, in accordance with art. 6 para. 1 letter a GDPR;
- for the sending of the newsletter as a result of a sale of goods or services, in accordance with sect. 7 para. 3 (German) Act against Unfair Competition.
Initially, only our staff will be aware of your personal data. In addition, to the extent which is permitted or required by law, we will share your personal information with other recipients who provide services related to our website. We restrict the transfer of your personal data to what is necessary, especially to that which is necessary for processing your order. Sometimes, our service pro-viders receive your personal data as an order processor and are then strictly bound by our instructions when handling your per-sonal data. In part, the recipients act independently with your data which we transmit to them.
The following section lists the categories of recipients of your personal data:
- Payment service providers and banks, for settling payments,
- Providers of logistics services in order to send you the goods,
- IT service providers in the administration and hosting of our website,
- Collection agencies and legal advisors who assert our claims
LUISA CERANO is committed to securing your personal information by using appropriate security measures to protect it from loss, misuse or tampering. These security measures will be updated from time to time according to current advances in technol-ogy.
LUISA CERANO uses SSL (Secure Sockets Layer) encryption when capturing or transmitting sensitive data. This includes all pages with input boxes into which user data can be entered (e.g. newsletter subscription, contact form, etc.). SSL encryption en-sures that no one but LUISA CERANO can read the data. This security standard is active if either the symbol of an intact key or a closed lock (browser-dependent) appears in the status bar or in the lower part of your browser window.
If LUISA CERANO processes data in a third country (i.e. outside the European Union or the European Economic Area), or within the context of using third party services or discloses, or transmits data to third parties, this will only be done on the basis of your consent or on the basis of our legitimate interests. LUISA CERANO only allows the data to be processed in a third country if the special conditions of art. 44 GDPR et seq. are met, e.g. the processing takes place on the basis of special guarantees, such as the officially recognised level of data protection corresponding to EU regulations (e.g. the 'Privacy Shield' in the USA), or the observance of officially recognised specific contractual obligations ('standard contract clauses').
7.1 Informational use of the website
If you use our website solely for the purpose of receiving information, we will only store your personal data on our servers for the duration of your visit to our website. After you have left our website, your personal data will be deleted immediately.
Server log files have been disabled.
7.2 Active use of the website
In the case of active use of our website, we initially store your personal data for the duration of your enquiry or for the duration of our business relationship. This also includes the initiation of a contract (pre-contractual legal relationship) and the execution of a contract.
In addition, we will then store your personal information until the statute of limitations of any legal claims arising from the relation-ship with you starts, to use as evidence where appropriate. The limitation period is usually between 12 and 36 months, but can al-so last up to 30 years.
We will delete your personal data at the start of the limitation period unless there is a statutory storage obligation, e.g. in the Ger-man Commercial Code (sects. 238, 257 para. 4 German Commercial Code) or the German Tax Code (sect. 147 para. 3, 4 (German) Tax Code) in front. These storage requirements may be two to ten years.
Under the legal requirements, you are entitled to the following rights as a data subject, which you can assert against us:
- Right to information: Under art. 15 GDPR, you are entitled to demand confirmation from us at any time as to whether we process personal data relating to you; If this is the case, you are also entitled under art. 15 GDPR to receive information about this personal data and certain other information (including among other things, purposes of processing data, categories of personal data, categories of recipients, planned storage period, your rights, the source of the data, the use of automated decision making and in the case of a transfer to a third country the appropriate guarantees) and to obtain a copy of your data.
- Right to rectification In accordance with art. 16 GDPR, you are entitled to demand that we correct the personal data stored about you if it does not apply or is incorrect.
- Right to deletion (‘right to be forgotten’) You are entitled, under the conditions of art. 17 GDPR, to demand that we de-lete your personal data without delay. Among other things, there is no right to deletion if the processing of personal data is required for (i) exercising the right to freedom of expression and information, (ii) the fulfilment of a legal obligation to which we are subject (e.g. statutory retention obligations) or (iii) enforcement, exercising or defending legal claims.
- Right to restricting processing: Under the conditions of art. 18 GDPR, you are entitled to demand that we limit the pro-cessing of your personal data.
- Right to data transferability: Under the conditions of Art. 20 GDPR, you are entitled to demand that we provide you with the personal data relating to you, which you have provided to us, in a structured, standard, machine-readable format.
- Right of objection: Under the conditions of art. 21 GDPR, you are entitled to object to the processing of your personal data. In such cases, we have to stop the processing of your personal data. The right to objection only exists within the limits pro-vided for in art. 21 GDPR. In addition, our interests may preclude any termination of processing, so we may, despite your opposition, process your personal information.
- Right of appeal to a supervisory authority: If you feel that the processing of your personal data infringes the GDPR, you are entitled to file a complaint with a supervisory authority under the conditions of art. 77 GDPR, especially within the Member State of your place of residence, your place of work or the place of the alleged infringement. The right of appeal is without prejudice to any other administrative or judicial remedy.
You can address your concern to the LUISA CERANO data protection officer by e-mail (email@example.com).
The supervisory authority responsible for us is:
State officer for Data Protection and Freedom of Information, Baden-Württemberg
Königstraße 10 a
Right of objection:
You have the right, for reasons arising from your particular situation, to file an objection against the processing of your personal data by us at any time, which takes place pursuant to art. 6 para. 1 lit. f GCPR (legitimate interest of the responsible person). We will then no longer process your personal information, unless we can demonstrate compel-ling legitimate grounds for processing it that outweigh your interests, rights and freedoms, or if the processing serves the purpose of enforcing, pursuing or defending legal claims.
If the personal data relating to you is processed in order to send direct mail, you have the right to object to the pro-cessing of your personal data for the purposes of such advertising at any time. If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.
As a general rule, you are not obliged to provide us with your personal data. However, if you do not, we will not be able to provide you with our website correspond to your enquiries and we will not be able to enter into a contract with you via our online store. Personal data that we do not necessarily need for the above-mentioned processing purposes are marked accordingly as voluntary information.
LUISA CERANO GmbH
Mon.-Thurs. 09:00 - 17:00
Fri.: 09:00 - 16:00
Tel.: +49 (0) 7022 / 705 - 181
Data protection statement for LUISA CERANO GmbH, 30.01.2019