Thank you for visiting our website and your interest in our company and services. Data protection and data security are very important to us. For your further visits to our website, we would like to inform you about data collection, processing and use when visiting and using our service. As well as objection, revocation and other rights to which you are entitled as a person affected by data collection and use.
What is personal data?
Personal data refers to any information relating to an identified or identifiable natural person (“Personal Data”).
Accuracy
It is important that the data we hold about you is accurate and current, therefore please keep us informed of any changes to your personal data.
Children Data
Our website is not intended for children and we do not knowingly collect data relating to children. We are in compliance with the requirements of COPPA (Children’s Online Privacy Protection Act). We do not knowingly collect any information from anyone under 13 years of age.
What data do we collect?
- Information you provide to us
When you participate in, access, request or use to any of our services, activities or online content, we receive personal information about you which we use to provide these services. This may consist of data such as your name, email address, postal address and telephone number.
- Content you share with us
When you contact us and when you share comments and other content with, us we may receive personal information about you.
- Information collected online
We automatically collect personal data (technical and usage) when you browse or interact with our website, by using cookies, and other similar technologies. We may also receive technical data about you if you visit other websites which use our cookies.
- Email communications
We use web beacons in our emails to track the success of our marketing campaigns. If you open an email from us, we can see which of the pages of our website you visited. Our web beacons don’t store any information on your computer but communicate with our cookies and tell us when you have opened an email from us.
- Placing an order
When placing an order in the online shop, all data necessary for executing and processing are requested by means of mandatory fields: Your full name, your e-mail address, your address (billing address and, if applicable, different delivery address). Your data will only be used to process your order.
Data collected is linked, for example if you have used our service and later choose us again, we will link your data and treat that linked data as Personal Data.
How personal data is collected
We collect personal data in the following ways:
-
-
- direct interactions you may provide personal data when you complete online forms, request products/services, use our contact form or otherwise or correspond with us (by post, phone or email)
-
-
-
- automated technology we automatically collect personal data (technical and usage) when you browse or interact with our website, by using cookies, and other similar technologies. We may also receive technical data about you if you visit other websites which use our cookies.
-
On what grounds do we use Personal Data?
We use your Personal Data for the following purposes and on the following grounds:
- On the basis of fulfilling our contract (when you use our service)
- On the basis of your consent (when you contact us)
- On the basis of legal obligations (for obligations such as tax, accounting, anti-money laundering, or when a court or other authority asks us to)
- On the basis of our legitimate interest (for communications about security, privacy and performance improvements of our services. Or for establishing, exercising or defending our legal rights.) Of course, before relying on any of those legitimate interests we balance them against your interests and make sure they are compelling enough and will not cause any unwarranted harm.
When do we disclose your Personal Data?
We disclose your Personal Data in response to your business enquiry or your request for information within our Company in order to provide the best service possible and within our legitimate interest.
When shopping with us your personal data will be passed on to third parties within the scope of the online shop if it is necessary for the purpose of processing the contract, for accounting purposes or for the collection of the payment.
We may share your information with organisations that help us provide the services described in this policy and who may process such data on our behalf and in accordance with this policy, to support this website and our services. For example, with our legal other professional advisors.
In relation to information obtained about you from your use of our website, we may share a cookie identifier and IP data with analytic and advertising network services providers to assist us in the improvement and optimisation of our website which is subject to our Cookies Policy.
We may disclose personal information in other circumstances such as when you agree to it or if the law, a Court order, a legal obligation or regulatory authority ask us to. If the purpose is the prevention of fraud or crime or if it is necessary to protect and defend our right, property or personal safety of our staff, the website and its users.
Data retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Your Rights
GDPR Specific Rights
Under the GDPR you have a number of “Data Subject Rights” in particular the following:
You have the right to:
- information about the processing of your personal data;
- obtain access to the personal data held about you;
- ask for incorrect, inaccurate or incomplete personal data to be corrected;
- request that personal data be erased when it’s no longer needed or if processing it is unlawful;
- object to the processing of your personal data for marketing purposes or on grounds relating to your particular situation;
- request the restriction of the processing of your personal data in specific cases;
- receive your personal data in a machine-readable format and send it to another controller (‘data portability’);
- request that decisions based on automated processing concerning you or significantly affecting you and based on your personal data are made by natural persons, not only by computers. You also have the right in this case to express your point of view and to contest the decision; and
- Where the processing of your personal information is based on consent, you have the right to withdraw that consent without detriment at any time through our contact form.
If you wish to rely on any of your data subject rights or have a request, please contact us.
Virginia Specific Rights
According to the Virginia Consumer Data Protection Act, you have the right to:
- Confirmation whether your personal data is being processed by us;
- Correct inaccuracies in your data;
- Delete personal data obtained from or about you;
- Obtain a copy of the data you previously provided us in a portable and “readily usable” format; and
- Opt-out of data collection if the data is collected “for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning on you.
Do Not Track
Do Not Track is a privacy preference you can set in most browsers. We support Do Not Track because we believe that you should have genuine control over how your info gets used and our site responds to Do Not Track requests.
Do Not Sell My Personal Information
We do not sell information that directly identifies you, like your name, address, social security number, banking information, or phone records. In fact, we do not even share that type of information except with service providers who can use the information solely to provide a service on our behalf, when a consumer directs us to share the information. If applicable, you can choose whether you want this sharing or not. Remember, we don’t sell data that directly identifies you unless we have your explicit permission, no matter what choice you make.
To make your choices please contact us at the below address.
How do we protect your Personal Data?
We protect your data using state of the art technical, and physical safeguards and operate a firm system of policies, confidentiality agreements, digital safeguards and procedures to ensure the highest level of administrative protection.
Automated decision-making and profiling
We do not use automation for decision-making and profiling
International transfers
We do not currently share your data with recipients outside the USA. If we do then we will make sure that it is protected in the same way as if it was being processed in the USA. Some countries or territories outside the USA do not have adequate levels of data protection corresponding to the general data protection regulation. In order to protect your data and to achieve an adequate level of protection for your personal data when we transfer it to these countries or territories, we will ensure that one or more safeguards are put in place.
Virginia Personal Identity Information (Pii) Statement
Commercial Partners: Individual(s) or companies that have been approved by us as a recipient of organizational PII and from which EL friendly has received confirmation of their data protection practices conformance with the requirements of this policy. Commercial Partners include all external providers of services to EL friendly and include proposed Commercial Partners. No PII information can be transmitted to any vendor in any method unless the vendor has been pre-certified for the receipt of such information.
PII Training: All new hires entering EL friendly who may have access to PII are provided with introductory training regarding the provisions of this policy, a copy of this policy and implementing procedures for the department to which they are assigned. Employees in positions with regular ongoing access to PII or those transferred into such positions are provided with training reinforcing this policy and procedures for the maintenance of PII data and shall receive annual training regarding the security and protection of PII data and company proprietary data
PII Audit(s): EL friendly conducts audits of PII information maintained by EL friendly in conjunction with fiscal year closing activities to ensure that this policy remains strictly enforced and to ascertain the necessity for the continued retention of PII information. Where the need no longer exists, PII information will be destroyed in accordance with protocols for destruction of such records and logs maintained for the dates of destruction.
Data Breaches/Notification: Databases or data sets that include PII may be breached inadvertently or through wrongful intrusion. Upon becoming aware of a data breach, EL friendly will notify all affected individuals whose PII data may have been compromised, and the notice will be accompanied by a description of action being taken to reconcile any damage as a result of the data breach. Notices will be provided as expeditiously as possible after the breach was discovered.
Confirmation of Confidentiality: All company employees must maintain the confidentiality of PII as well as company proprietary data to which they may have access and understand that that such PII is to be restricted to only those with a business need to know. Employees with ongoing access to such data will sign acknowledgement reminders annually attesting to their understanding of this company requirement.
Violations of PII Policies and Procedures: EL friendly views the protection of PII data to be of the utmost importance. Infractions of this policy or its procedures will result in disciplinary actions under EL friendly’s discipline policy and may include suspension or termination in the case of severe or repeat violations. PII violations and disciplinary actions are incorporated in EL friendly’s PII onboarding and refresher training to reinforce EL friendly’s continuing commitment to ensuring that this data is protected by the highest standards.
Secure data transmission
The transmission of your personal information during an order transaction in the online shop is encrypted using industry standard Secure Socket Layer (“SSL”) technology, (SSL encryption version 3).
Credit card information
Any credit card information you provide will not be stored by EL friendly , but will be encrypted and collected directly from the payment service provider (PayPal) via hypertext transfer protocol secure (“https”).
Passwords
You should never disclose your password for accessing our customer portal to any third party and you should change it regularly. If you want to leave your customer account in the online shop, you should press the logout and close your browser to prevent anyone from gaining unauthorised access to it.
Market Research
All your data collected on the EL friendly website for the purpose of market research will be used exclusively for EL friendly internal purposes and will not be passed on to third parties. They will be deleted when their knowledge is no longer necessary for market research.
Subscribers of our newsletter
As a recipient of our newsletter, we store your e-mail address, as well as further information about the newsletter you have received (category, any frequency setting, time of cancellation) and about your usage behaviour on our offers. You can unsubscribe from these emails at any time by clicking on a corresponding link in the newsletter.
Integration Of Services And Contents Of Third Parties
We use within our online offer on the basis of our legitimate interests, we use content or services offered by third-party providers in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as “content”).
This always requires that the third-party providers of this content are aware of the IP address of the user, since without the IP address they could not send the content to their browser. The IP address is thus required for the display of this content. We endeavor to use only such content whose respective providers use the IP address only for the delivery of the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online offer, as well as be linked to such information from other sources.
The following presentation provides an overview of third-party providers and their content, along with links to their data protection policies, which contain further information on the processing of data and, in part already mentioned here.
Our online presence is provided on a so called Content Delivery Network and Web Hosting Service. Our Web Hosting Provider is BlueHost
Changes
This policy and our commitment to protecting the privacy of your personal data can result in changes to this policy. Please regularly review this policy to keep up to date with any changes.
Queries and Complaints
Any comments or queries on this policy should be directed to us using our contact form.
If you believe that we have not complied with this policy or acted otherwise than in accordance with data protection law, then you should notify us.