Privacy

Thank you for visiting our online store.

The protection of your privacy is very important to us. Below you will find more information on how we handle and process your data.

The person responsible for data processing on this website is:
Franziska Sumberaz
Mühlfeldgasse 1/18
1020 Vienna
Austria
office@sumsumthebrand.com



Contact

If you contact us by e-mail, the data you provide will be processed for the purpose of handling your inquiry. In case of follow-up questions, they will be stored until your revocation. Without your prior consent, we will pass on data to third parties only under the conditions set out in the section "Data transmission". Nevertheless, data transmission within the scope of online services (e.g. communication by e-mail) may have security gaps. A complete protection of data against access by third parties is not possible.


Order and payment

The processing and use of your personal data (name, date of birth, address, telephone number, e-mail address), which you provide to us in connection with the order of a product, serves the execution of your order and the provision of our services and is thus part of the performance of the contract pursuant to Art 6 para 1lit b DSGVO. Under no circumstances will this data be sold to third parties.
For the processing of payments in our online store, we work with service partners. Depending on the selected payment method, we pass on the data required for the processing of the payment transaction. This serves the fulfillment of the contract according to Art 6 para 1lit b DSGVO. In some cases, the payment service providers collect the data required for payment processing themselves, e.g. on their own website or through technical integration into the ordering process. In these cases, the data protection provisions of the selected payment service provider apply.


Hosting & content delivery network

We work with the store system of the service provider Shopify for the hosting and presentation of our website. All data collected by the website is processed on Shopify's servers. As part of this processing, data may also be transferred to Shopify lnc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) lnc., Shopify Payments (USA) lnc. or Shopify (USA) lnc. These are located in a country outside the European Union, for which the European Commission has determined by decision an adequate level of data protection. By placing an order in our store, you agree to the storage and processing of your personal data by the service provider, therefore the terms of use and privacy policy of Shopify apply. For more information, please visit https:// www.shopify.de/legal/datenschutz.


Cookies

Our website is based on the online content management system of Shopify and uses so-called cookies. This is done under the protection of legitimate interest pursuant to Art. 6 (1) lit. f DSGVO to ensure the functionality and user-friendliness of the website.
Cookies are small text files that are stored on your terminal device with the help of the browser. Some cookies are deleted after you close your browser (session cookies). Other cookies remain stored on your end device and enable us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). If you do not wish this, you can set your browser to inform you about the storage of cookies and to allow you individual settings. Each browser differs in the way it manages cookie settings. For more information about each browser and how to change their cookie settings, please see the following links:
Internet Explorer: https://support.microsoft.com/de-de/help/1 7442/windows-internet¬ explorerdelete-manage-cookies
Firefox: https://support.mozilla.org/de/kb/cookies-erlauben -and-reject Chrome: https://support.google.com/chrome/answer/95647?hl=de&hlrm=en Safari: https://support.apple.com/kb/ph21 411?locale=en_DE
Opera: http://help.opera.com/Windows/10.20/de/cookies.html

If you disable these cookies, it may limit the functionality of the website. However, it is also possible to accept only essential cookies in a pop-up window.


Web analysis

Our website uses Google Analytics, a web analytics service provided by Google inc. GoogleAnalytics. These are also so-called cookies. The information obtained through cookies about the use of our website is transmitted to Google in the USA and stored there. Google uses this information to evaluate the use of our website and to compile reports on website activity for website operators. If required by law or if third parties process this data on behalf of Google, Google will also pass this information on to these third parties. The use is anonymized or pseudonymized. You can find more information about this directly at Google http://www.google.com/intl/de/privacypolicy.html#information. If you do not wish your website activity to be recorded by Google Analytics, you can install the browser add-on to disable Google Analytics. This prevents activity data from being shared with Google Analytics via the Javascript executed on websites (ga.js, analytics.js and dc.js). More information and the download link can be found here: https://tools.google.com/dlpage/gaoptout?hl=de.
Alternatively, you can also refuse cookies from being stored by our website or change preferences at any time. For more information, please see the privacy policy under the item "Cookies".



Newsletter

With your consent, we use your e-mail address to send you our newsletter. You can unsubscribe from our newsletter at any time by contacting us here or sending an email to office@sumsumthebrand.com.
Use of social media

We use a link on our website to the services lnstagram and Facebook. lnstagram is a service of "lnstagram lnc", Facebook of "Facebook lnc". Through the link on our site, these social media platforms receive the information that you have visited the corresponding website. If you are logged in to one of these services, they can assign the visit to our site to your account and thus link the data.
The data transmitted by clicking on the link is stored by the services themselves. For more information on the purpose and scope of data collection, its processing and use, and your rights, please refer to the privacy notices of Facebook and lnstagram. To prevent these social media platforms from associating your visit to our website with your social media account, you must log out of your lnstagram or Facebook account before visiting our website.

 

Data transfer

We only pass on your personal data to third parties if:

a) you have given your express consent to this in accordance with Art. 6 Para. 1S. 1lit. a) DSGVO.

b) This is legally permissible and in accordance with Art. 6 para. 1S. 1lit. b) DSGVO for the fulfillment of a contractual relationship with you or the implementation of pre-contractual measures is required.

c) According to Art. 6 para. 1S. 1lit. c) DSGVO a legal obligation exists for the transfer.

d) We are legally obliged to transfer data to state authorities, e.g. tax authorities, social insurance carriers, health insurance companies, supervisory authorities and law enforcement agencies.

e) The transfer according to Art. 6 para. 1lit. f) DSGVO is necessary for the protection of legitimate business interests, as well as for the assertion, exercise or defense of legal claims and there is no reason to believe that you have an overriding legitimate interest in the non-disclosure of your data.

f) In accordance with Art. 28 DSGVO, we use external service providers, so-called order processors, who are obliged to handle your data with care.
We may use such service providers in the areas of:

- IT, logistics, telecommunications.

When transferring data to external entities in third countries, i.e. outside the EU or EEA, we ensure that these entities treat your personal data with the same care as within the EU or EEA. We only transfer personal data to third countries for which the EU Commission has confirmed an adequate level of protection or if we ensure the careful handling of personal data through contractual agreements or other suitable guarantees.
We only transfer your data to the USA if the requirements of the ECJ ruling v. 16.07.2020 - C-311/18 - are observed. If you have given us your consent to do so, we will also transfer data to companies located in the USA.



Data subject rights

Since we collect and process data from you, you have some rights as a data subject of data processing:

Right to information from us. If you assert this right, we will inform you which of your personal data we have processed.

- Right to correction or deletion

- Right to restriction of processing

- Right to object to processing

- Right to data portability

- Right to withdraw your consent

- Right to lodge a complaint with a supervisory authority

- Right to object to processing

- Art. 21 DSGVO allows you, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6 para. 1S. 1lit. e or f DSGVO).


Duration of the storage of personal data

The duration of the storage of personal data is measured by the respective statutory retention period (e.g. retention periods under commercial and tax law). After expiry of the period, the corresponding data is routinely deleted, provided that it is no longer required for the fulfillment or initiation of the contract and/or there is no continued legitimate interest on our part in the continued storage.

If you have any questions about data protection, please feel free to contact me:

Franziska Sumberaz office@sumsumthebrand.com
+43 676 9436474