Thank you for visiting our online shop. Protecting your privacy is very important to us. In the following document we inform you in detail about how your data is handled.
1. Access data and hosting
You can visit our website without providing any personal information. Each time a website is accessed, the web server automatically saves only a so-called server log file, which contains the name of the requested file, your IP address, date and time of access, transferred data volume and the requesting provider (access data) and documents the access.
This access data is evaluated exclusively for the purpose of ensuring trouble-free operation of the site and improving our services. In accordance with Art. 6 para. 1 sentence 1 f GDPR, this serves to preserve our legitimate interest in correctly presenting our offer. All access data will be deleted at the latest seven days after the end of your page visit.
Third-party hosting services
In the context of processing on our behalf, a third-party provider supplies us with the services of hosting and display of the website. This serves to preserve our legitimate interest in correctly presenting our offer. All data collected as part of the use of this website or in the forms provided in the online shop as described below will be processed on its servers. Processing on other servers takes place only in the framework explained here.
This service provider is located within a country of the European Union or the European Economic Area.
2. Data collection and use for processing an order and when opening a customer account
We collect personal data when you voluntarily provide us with it in connection with your order, when you contact us (e.g. via contact form or e-mail) or when you open a customer account. Mandatory fields are marked as such, because in these cases we need the data to process the order, handle your inquiry or open a customer account. The data being collected can be seen in the respective input forms. We use the data provided by you pursuant to Art. 6 Para. 1 S. 1 b GDPR to process contracts and your inquiries. After complete processing of the order or deletion of your customer account, your data will be restricted for further processing and deleted at the end of the tax and commercial retention periods, unless you have expressly consented to further use of your data or we reserve the right to use more data, which is permitted by law and about which we inform you in this statement. You can delete your customer account at any time by sending a message by email to abovo(at)abovohome.com.
3. Data transfer
In order to fulfil the order pursuant to Art. 6 Para. 1 S. 1 b GDPR, we pass on your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the ordering process, we will pass on the payment data collected for this purpose to the relevant payment service provider in order to process payments. In some cases, the selected payment service providers also collect this data themselves when you create an account. In this case, you must log on to the payment service provider with your access data during the ordering process. In this case, the data protection declaration of the respective payment service provider applies.
E-mail advertising with newsletter registration
If you subscribe to our newsletter, we will use the data required for this purpose or provided separately by you in order to send you our e-mail newsletter regularly on the basis of your consent pursuant to Art. 6 Para. 1 S. 1 a GDPR.
The cancellation of the newsletter is possible at any time and can be done either by sending a message by email to: abovo(at)abovohome.com; by post to Abovo GmbH, attn. Lisa Graef, Rumfordstrasse 8, 80469 Munich or via a link provided in the newsletter. After you unsubscribe, we will delete your e-mail address unless you have expressly consented to the further use of your data or unless we reserve the right to use further data that is permitted by law and about which we inform you in this statement.
The newsletter is sent on our behalf by a service provider (MailChimp, The Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 500, Atlanta, Georgia 30308, USA) to whom we forward your e-mail address. This service provider is based in the USA and is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has determined an appropriate level of data protection for companies certified under the Privacy Shield.
5. Integration of the Trusted Shops Trustbadge
The Trusted Shops Trustbadge is integrated on this website to display our Trusted Shops seal of approval and the collected evaluations as well as to offer Trusted Shops products to buyers after an order.
This serves to safeguard our overriding legitimate interests in an optimal marketing of our offer in accordance with Art. 6 para. 1 sentence 1 f GDPR. The Trustbadge and the services advertised with it are an offer of the Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne.
When the Trustbadge is called up, the web server automatically saves a so-called server log file which contains, for example, your IP address, the date and time of the call, the amount of data transferred and the requesting provider (access data) and documents the call. These access data are not evaluated and are automatically overwritten at the latest seven days after the end of your page visit.
Further personal data will only be transferred to Trusted Shops if you have consented to this, have decided to use Trusted Shops products after completing an order or have already registered for use. In this case the contractual agreement between you and Trusted Shops applies.
6. Cookies and Web Analytics
In order to make visiting our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use so-called cookies on various pages. This serves to safeguard our predominating legitimate interests in an optimized presentation of our offer in accordance with Art. 6 Para. 1 S. 1 f GDPR as part of a weighing of interests. Cookies are small text files that are automatically stored on your terminal device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognize your browser during your next visit (persistent cookies). You can find the duration of the storage in the overview in the cookie settings of your web browser.
You can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them or whether to exclude the acceptance of cookies in certain cases or in general. Each browser differs in the way it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. These can be found for each browser under the following links:
Internet Explorer™: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies
Opera™ : https://help.opera.com/en/latest/web-preferences/
Please note that disabling cookies may limit your access to some features of our website.
Use of Google (Universal) Analytics for web analytics
For the purpose of website analytics, this website uses Google (Universal) Analytics, a web analytics service provided by Google LLC (www.google.com). This serves the protection of our legitimate interests in the optimized presentation of our offer according to Art. 6 (1) 1 lit. f) GDPR that are overriding in the process of balancing of interests. Google (Universal) Analytics uses methods, like e.g. cookies, that enable an analysis of your use of the website. The information collected automatically by cookies about your use of this website are as a rule transmitted to and stored on a Google server in the United States. At the same time, as IP anonymization is enabled on this website, the IP address will be shortened before being transmitted within the area of member states of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases, the full IP address will be sent to a Google server in the USA and shortened there. Generally, Google does not associate the anonymized IP address, transmitted from your browser through Google Analytics, with any other data held by Google.
The Google LLC is headquartered in the USA and is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has determined an appropriate level of data protection for companies certified under the Privacy Shield.
You can prevent Google from collecting the data generated by the cookie and related to your use of the website (including your IP address) and from processing this data by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en
As an alternative to the browser plug-in, you can click this link to prevent Google Analytics from collecting data from this website in the future. An opt-out cookie is stored on your device. If you delete your cookies, you must click the link again.
7. Sending rating reminders by email
Rating reminder by Trusted Shops
If, when or after placing your order, you have given us your express consent to do so according to Art. 6 (1) 1 lit. a) GDPR, we will disclose your e-mail address to Trusted Shops GmbH, Subbelrather Str. 15c, 50823 Cologne, Germany (www.trustedshops.com), so that they can email you a rating reminder.
This consent can be revoked at any time by sending a message to email@example.com or directly to Trusted Shops.
8. Contact options and your rights
As a concerned party, you have the following rights:
- pursuant to Art. 15 GDPR, the right to request information about your personal data processed by us in the scope specified therein;
- in accordance with Art. 16 GDPR, the right to demand immediate correction of incorrect or complete personal data stored with us;
- according to Art. 17 GDPR the right to demand the deletion of your personal data stored by us, unless the further processing
– to exercise the right to freedom of expression and information;
– to fulfill a legal obligation;
– for reasons of public interest or
– to assert, exercise or defend legal claims
- according to Art. 18 GDPR the right to demand the restriction of the processing of your personal data, as far as
– the accuracy of the data is disputed by you;
– the processing is illegal, but you reject its deletion;
– we no longer need the data, but you do not need it
– you filed an objection against the processing in accordance with Art. 21 GDPR;
- according to Art. 20 GDPR, the right to receive your personal data provided to us in a structured, common and machine-readable format or to request transmission to another responsible party;
- according to Art. 77 GDPR, the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or work or our company headquarters.
If you have any questions regarding the collection, processing or use of your personal data, information, correction, blocking or deletion of data as well as revocation of consents given or objection to a specific use of data, please contact us directly via the contact data in our imprint.
Right to object
If we process personal data as described above to protect our legitimate interests that are overriding in the process of balancing of interests, you may object to such data processing with future effect. If your data are processed for direct marketing purposes, you may exercise this right at any time as described above. If your data are processed for other purposes, you have the right to object only on grounds relating to your particular situation.
After you have exercised your right to object, we will no longer process your personal data for such purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
This does not apply to the processing of personal data for direct marketing purposes. In such a case we will no longer process your personal data for such purposes.