PRIVACY STATEMENT
Thank you for your interestin The Smart Spirit!
The Smart Spirit believes very strongly in keeping your personal information confidential. It is an Austrian company based in Langegg 19/1, 8511 Sankt Stefan operated
by Claudia Hackl, MA MSc.
If you have any questions regarding the collection, processing or use of your personal data, information, correction, blocking or deletion of data or revocation of consents given, you can send them by e-mail or letter to the following contact details:
The Smart Spirit
Claudia Hackl
Langegg 19/1
8511 St. Stefan
E-mail: info@thesmartspirit.com
The following policy describes what information is collected and how it is handled.
SCOPE OF THE PRIVACY STATEMENT
The privacy statement applies to this website including, social media sites – In particular theInstagram and Facebook fan pages – and Youtube.
DATA COLLECTION
BLOG
Visitors can use the site without registering or revealing any personal information about them. As for most websites, our web server collects anonymous statistical data such as number of visits, pages viewed, browser used, keywords typed, etc. The visitor’s IP address is collected for this purpose.
In order to post a comment, visitors are required to provide their email address and name (or pseudonym). Users’ email addresses will never be shared or sold to any third party unless required by law. Security measures such as passwords, firewalls and antivirus programs are in place to prevent any unauthorized access to this information. While every effort is made to protect users’ personal information, I can not be held liable for any fraudulent access by an unauthorized third party. If you choose to disclose your personal information, you do so at your own risk. You remain solely responsible for the content of your messages and I reserve the right to delete any message at our discretion.
SHOP
The personal data processed by The Smart Spiritin the Shop includes:
- personal data such as name, address, birthday, place of birth and delivery address,
- physical data such as clothing size, but only to the extent that it will not be possible to identify you personally,
- contact details such as telephone number, email address,
- data and information from electronic data interchange, such as IP addresses, cookies, pixels, apps, etc;
- order data from purchase orders,
- advertising and salesdata,
- general communication data, such as inquiries and consultations via the Contact Form
- data for the fulfilment of legal and official obligations,
- data for the fulfilment of contractual obligations such as warranties or guarantees,
- credit card data, which is masked before processing and used only within the context of abuse control,
- other account data, only for bank deposits and (return) transfers.
In compliance with data minimisation, The Smart Spirit only processes data that is required for the performance of the contract, the fulfilment of legal obligations or within the scope of our legitimate interests, or if you have expressly agreed to this. Wherever possible, The Smart Spirit (pseudo)-anonymises your data. You can read more on the subject under point Security measures. The Smart Spirit does not process any special categories of customer data as laid out in Art. 9 GDPR.
PURPOSE Of PROCESSING DATA AND LEGAL BASIS
The Smart Spirit wants to offer you an optimum product range as well as the best possible selection of products and services, specifically tailored to your preferences and interests. We must also take into account country-specific circumstances such as currency for example.
We process data on the basis of the above-cited legal grounds and the purposes associated with them.
a) For the fulfilment of (pre)contractual obligations (Art. 6 (1) lit b GDPR)
- Fulfillment of your purchase according to our GTCs,
- Advice and information in the buying process,
- Provision of services, such as books and courses,
b) For safeguarding the legitimate interests of The Smart Spirit or a third party (Art. 6 (1) lit f)
We collect, store, process and analyse the data mentioned above in order to enhance your shopping experience in our web shop and stores and to offer you the best advice and services such as books, travel, courses, contests and also to inform you about products, trends, innovations and services.
Legitimate interests of The Smart Spirit or a third party are:
- the execution of marketing activities, in particular personalised advertising in cooperation with third parties, e.g. advertising partners,
- the implementation of loyalty programs for customers,
- the provision of a customer account and customer profile on The Smart Spirit’s websites
- the processing and storage of communication contents from emails, phone calls or other communication means (e.g. in the event of complaints, requests for information in accordance with point 6),
- the dispatch of your order by order processors, in particular carriers who may also receive your email address and telephone number for delivery and tracking purposes,
- maintaining the functionality of our website, our online shops and other The Smart Spirit online media,
- the analysis of purchasing behaviour by The Smart Spirit and advertising partners,
- the implementation of monitoring measures to protect employees, customers and the property of The Smart Spirit, suppliers and other partners,
- the enforcement of legal claims and defence against unjustified claims,
- measures to combat and prevent fraud, e.g. credit card fraud,
- consultation of credit agencies and data exchange for credit checks,
- the implementation of measures for the further development of the product and service range,
- statistical evaluations
- coordination, business development and strategic measures within the The Smart Spirit Group.
According to Art. 21 GDPR, in individual cases it is possible to object to data processing on the basis of legitimate interests. You can find out more about this under point ‘How long data is processed and stored’.
c) Within the scope of your consent (Art. 6 (1) lit a)
Apart from points a) and b), The Smart Spirit only processes your personal data after you have given us your consent, e.g. for sending newsletters or using cookies (more on this under point 10 ‘Cookies policy’). Your consent can be revoked at any time.
WHO RECEIVES YOUR DATA
a) General provisions
The Smart Spirit has clear rules on who may receive personal data.
Your data is made available to processors commissioned by The Smart Spirit, i.e. companies that support us in fulfilling our corporate goals and tasks, such as IT companies, payment providers, suppliers, deliverers, printers, to the extent necessary to perform the tasks assigned to them. The Smart Spirit concludes written agreements with these processors which oblige them to comply with the same requirements that apply to The Smart Spirit.
In addition, The Smart Spirit also makes personal data available to third parties with whom The Smart Spirit cooperates within the scope of the aforementioned processing purposes or who may have a legitimate interest within the scope of the cooperation, e.g. debt collection agencies, payment providers.
If there is a legal or official obligation, public authorities may also receive data from us.
b) Data transfer to third countries
Data will only be transferred to countries outside the EU if the country has an adequate level of protection according to Art. 45 GDPR or if other safeguards according to Art. 46 GDPR appropriately protect your data.
HOW LONG DATA IS PROCESSED AND STORED
We retain your data for the duration of the business relationship and in order to carry out advertising activities within the framework of legitimate interests, for as long as you do not exercise your right to object to this processing according to Art 21 GDPR or, where you have given us your consent, if you do not revoke it.
Longer retention periods may be required due to legal storage and documentation obligations. In particular, this refers to the Austrian Federal Fiscal Code (BAO) and the Business Code (UGB) as well as other national and European legal requirements.
Due to our warranty obligations and the guarantees of our suppliers, or on the basis of statutory regulations, retention periods of 3 years (short period of limitation) or, in individual cases, also considerably longer retention periods (long period of limitation) may be necessary.
YOUR RIGHTS AS DATA SUBJECT.
The GDPR grants you comprehensive protection and information rights and particularly the right to object and withdraw in accordance with point g). You can contact our data protection officer with your request or complaint at any time.
The supervisory authority responsible for the Group is the Austrian data protection authority. They can also be contacted in the event of a complaint. http://www.dsb.gv.at
Your rights, which you can normally exercise free of charge, in detail:
a) Right to be informed according to Art. 15 GDPR
You have the right to obtain information free of charge concerning the personal data stored about you and, if necessary, the right to correct, block or delete it, and to withdraw given consents. Please contact Claudia Hackl if you would like to know how your data is used.
b) Right to rectification according to Art. 16 GDPR
Is your data no longer correct, do you want to exercise your rights or do you have anything else on your mind? Just let us know.
Email: info@thesmartspirit.com
c) Right to erasure or restriction according to Articles 17 and 18 GDPR
Upon request and under the conditions of Art. 17 GDPR, we will delete your data unless we are entitled to its further use.
Under the conditions of Art. 18 GDPR, where we cannot delete the data, you can request a restriction of our data processing.
We will also always inform data recipients of your request and ask them to comply with it.
d) Right to data portability: regulated in Art 20 GDPR
You can request us to make your personal data available to you.
e) Right to object in accordance with Art. 21 GDPR and to withdraw consent in accordance with Art. 13 GDPR
If the processing of your data is based on your consent according to Art. 6 (1) lit a, you can withdraw this consent at any time.
If we process your data on the basis of our legitimate interests, you can object to such processing in accordance with Art. 21 GDPR. We will then immediately check whether your request is justified.
To exercise your right to withdraw and object, simply contact Claudia Hackl.
MUST YOU PROVIDE US WITH DATA?
We need your data to process your order. When you make data available to us, you are obliged to provide truthful information. In the case of wrong information, i.e. if the age you indicate is incorrect, we are entitled to assert any resulting damages and to also file a complaint, if this is of criminal relevance.
You are not obliged to provide data or to give your consent for processing if the data is not relevant for the fulfilment of the contract.
However, due to the different age limits for approval and legal capacity, we may need to know your age in some cases.
COOKIE POLICY, WEBSITE ANALYSIS, SOCIAL MEDIA AND EMAIL ADVERTISING
[cookie_declaration]
b) Revocation and objection options
- You can revoke your consent at any time and also object to the use of cookies/pixels that do not require consent, provided that these are not necessary or if deactivation is technically possible. However, we would like to point out that in the event of an objection, you may not be able to use the website’s functionality in full.
You have several options to object to the use of cookies/pixels or to revoke a consent you have already given.
The most common browsers offer the possibility to block the use of cookies.
By using browser extensions such as “Ghostery” you can deactivate individual cookies and determine which cookies are set. Installing the extension is quick and easy and it is available for all major browsers.
c) Website analysis and social media
GOOGLE ANALYTICS
Google Analytics is a service offered by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses “cookies,” which are text files that are stored on your computer, to help the The Smart Spirit website analyse how users use the site. The information collected by the cookie regarding the use of our websites (including your IP address) is usually transferred to a Google server in the USA and stored there. Your IP address is only recorded by Google in a shortened form, which guarantees anonymisation and does not allow any conclusions to be drawn about your identity. If IP anonymisation is activated on our websites, your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and truncated there. Google will use the mentioned information to evaluate your use of the The Smart Spirit websites, to compile reports on the website activities for The Smart Spirit and to provide other services associated with the use of websites and the Internet to The Smart Spirit. The IP address that your browser transmits within the scope of Google Analytics is not merged with any other data held by Google. A transfer of this data by Google to third parties only takes place dur to legal regulations or within the scope of order data processing. Under no circumstances will Google match your data with other data collected by Google. With your consent you agree to the processing of the data collected about you by Google in the aforementioned manner of data processing and for the named purpose. You can prevent the storage of cookies by selecting the appropriate settings on your browser and other options. The Smart Spirit points out that in this case you may not be able to use all the functions on our websites to their full extent. For more information about Google Analytics and data protection, see http://tools.google.com/dlpage/gaoptout?hl=de.
USE OF SOCIAL MEDIA PLUGINS
Our website uses social plugins (“plugins”) provided by the social network facebook.com, operated by Facebook Inc., 1601 S. California Avenue, Palo Alto, CA 94304, USA (“Facebook”). The plugins are identifiable by a Facebook logo. When you visit a page of our website that contains a social plugin, your browser establishes a direct connection to Facebook servers. Facebook directly transfers the plugin content to your browser which embeds the latter into the website, enabling Facebook to receive information about your having accessed the respective page of our website. Thus I have no influence on the data gathered by the plugin and inform you according to our state of knowledge: The embedded plugins provide Facebook with the information that you have accessed the corresponding page of our website. If you are logged into Facebook, your visit can be assigned to your Facebook account. If you interact with the plugins, for example by clicking “Like”, or entering a comment, the corresponding information is transmitted from your browser directly to Facebook and stored by it. Even if you are not logged into Facebook, there is possibility that the plugins transmits your IP-address to Facebook. For the information on the purpose and scope of data collection and procession by Facebook, as well as your rights in this respect and settings options for protecting your privacy please visit Facebook’s privacy policy:http://www.facebook.com/policy.php. If you are a Facebook member and do not want Facebook to connect the data concerning your visit to our website with your member data already stored by Facebook, please log off Facebook before entering our website.
The same applies for other Social Plugins, such as Youtube or Instagram.
d) Email marketing
By subscribing to the newsletter, your email address will be used for our own advertising purposes until you unsubscribe from the newsletter. You can unsubscribe at any time by clicking on the “Unsubscribe” link at the end of a newsletter, without incurring any costs other than the transmission costs according to the basic rates of your access provider. As a newsletter subscriber, we will regularly send you carefully selected offers of similar products from our range by email.
e) GOOGLE OAuth Authentication for SMTP
This site uses Google’s OAuth verification system for our emails that uses SMTP. No personal information as aside from the information willingly submitted by the user is used for these email communications. The scope of emails are limited to newsletter communications and purchase notifications that the user has previously agreed to. Please refer to earlier sections about these notifications.
OUR SECURITY MEASURES
Your personal data is encrypted during the order process using “Secure Socket Layer” (SSL) over the Internet (address transmission is excluded for newsletter subscriptions). Credit card data are not stored, but are collected and processed directly by our payment service provider “Stripe Payments Europe Ltd.”.
We protect our website and other systems using technical and organisational measures against loss, destruction, access, modification or distribution of your data by unauthorised persons.
In all processing activities, we observe the principles of the GDPR as laid out in Art. 5. and subject all processing activities to close scrutiny within the framework of our data protection management system.
Access to your customer account is only possible after entering your personal password. You should always keep your access information confidential and close the browser window when you have finished communicating with us, especially if you share your computer with others
LINKS TO OTHER WEBSITES
The Smart Spirit’s websites contain links to websites of other companies. The Smart Spirit has no influence on the design and content of these third party websites, nor do we have any control over how the providers of these websites handle your information. Therefore, our privacy statement and our responsibility and liability do not extend to linked websites. If you have any questions, please contact these companies directly.