Privacy Policy
1) Introduction and Contact Details of the Controller
1.1 We are pleased that you visit our website and thank you for your interest. Below we inform you about the handling of your personal data when using our website. Personal data means all data with which you can be personally identified.
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Parmel GmbH, Friedrich Strasse 7, 86709 Wolferstadt, Germany, Tel.: +4990922265500, Email: info@parmel.de. The person responsible for processing personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
2) Data Collection When Visiting Our Website
2.1 When using our website for purely informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the server of the site (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:
- The website you visited
- Date and time at the moment of access
- Amount of data sent in bytes
- Source/referrer from which you accessed the page
- Browser used
- Operating system used
- IP address used (possibly anonymized)
The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used otherwise. However, we reserve the right to review the server log files retrospectively if there are concrete indications of illegal use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser's address bar.
3) Hosting & Content Delivery Network
For hosting our website and displaying the site content, we use a provider who provides their services exclusively on servers within the European Union, either themselves or through selected subcontractors.
All data collected on our website is processed on these servers.
We have concluded a data processing agreement with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files that are stored on your device. Some cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device longer and allow the storage of site settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.
If individual cookies used by us also process personal data, the processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR either to perform the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the case of consent granted, or in accordance with Art. 6 Para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a customer-friendly and effective design of the visit.
You can configure your browser so that you are informed about the setting of cookies and decide individually on their acceptance or exclude the acceptance of cookies for certain cases or generally.
Please note that if you do not accept cookies, the functionality of our website may be limited.
5) Contact
When contacting us (e.g. via contact form or email), personal data is collected. Which data is collected when using a contact form can be seen from the respective contact form. These data are stored and used exclusively for the purpose of responding to your request or for contact and the associated technical administration.
The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 Para. 1 lit. f GDPR. If your contact aims at concluding a contract, the additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted after the final processing of your request. This is the case when the circumstances indicate that the matter has been finally clarified and provided that no statutory retention obligations prevent this.
6) Data processing when opening a customer account
According to Art. 6 Para. 1 lit. b GDPR, personal data will continue to be collected and processed to the extent necessary if you provide them to us when opening a customer account. Which data is required for account opening can be found in the input mask of the corresponding form on our website.
Deletion of your customer account is possible at any time and can be done by sending a message to the above-mentioned address of the controller. After deletion of your customer account, your data will be deleted, provided that all contracts concluded via this account have been fully processed, no statutory retention periods prevent this, and we have no legitimate interest in further storage.
7) Use of customer data for direct advertising
7.1 Subscription to our email newsletter
If you subscribe to our email newsletter, we regularly send you information about our offers. The only mandatory information for receiving the newsletter is your email address. Providing additional data is voluntary and is used to address you personally. We use the so-called double opt-in procedure for sending the newsletter. This means that we will only send you an email newsletter if you have explicitly confirmed your consent to receive newsletters. We then send you a confirmation email, asking you to confirm by clicking a corresponding link that you want to receive the newsletter in the future.
By activating the confirmation link, you give us your consent to use your personal data according to Art. 6 Para. 1 lit. a GDPR. When subscribing to the newsletter, we store the IP address assigned by your Internet Service Provider (ISP) as well as the date and time of registration to be able to trace possible misuse of your email address at a later date. The data collected by us when subscribing to the newsletter is used exclusively for advertising purposes via the newsletter. You can unsubscribe from the newsletter at any time using the link provided in the newsletter or by sending a corresponding message to the above-mentioned controller. After cancellation, your email address will be deleted immediately from our newsletter distribution list, unless you have explicitly consented to further use of your data or we reserve the right to further data use that is legally permitted and about which we inform you in this declaration.
7.2 Sending the email newsletter to existing customers
If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range by email. According to § 7 Para. 3 UWG, we do not have to obtain separate consent from you for this. Data processing is therefore based solely on our legitimate interest in personalized direct advertising according to Art. 6 Para. 1 lit. f GDPR. If you initially objected to the use of your email address for this purpose, no emails will be sent from our side.
You are entitled to object to the use of your email address for the above advertising purpose at any time with effect for the future by sending a message to the controller named at the beginning. You will only incur transmission costs according to basic tariffs. After receipt of your objection, the use of your email address for advertising purposes will be stopped immediately.
8) Data processing for order processing
8.1 To the extent necessary for contract processing for delivery and payment purposes, the personal data collected by us will be forwarded to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 Para. 1 lit. b GDPR.
If, based on a corresponding contract, we owe you updates for goods with digital elements or for digital products, we process the contact data you provided when ordering to inform you personally within the framework of our legal information obligations according to Art. 6 Para. 1 lit. c GDPR. Your contact data is strictly used for notifications about updates owed by us and processed by us only to the extent necessary for this purpose.
For the processing of your order, we also cooperate with the following service provider(s) who support us wholly or partially in executing concluded contracts. Certain personal data will be transmitted to these service providers based on the following information.
8.2 Use of payment service providers
- Apple Pay
If you choose the payment method "Apple Pay" of Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, payment processing takes place via the "Apple Pay" function of your device operated with iOS, watchOS, or macOS by charging a payment card stored in "Apple Pay". Apple Pay uses security features integrated into the hardware and software of your device to protect your transactions. To authorize a payment, you must enter a code previously set by you and verify it using the "Face ID" or "Touch ID" function of your device.
For payment processing, your information provided during the order process, along with information about your order, will be transmitted in encrypted form to Apple. Apple then encrypts these data again with a developer-specific key before forwarding the data to the payment service provider of the payment card stored in Apple Pay. This encryption ensures that only the website where the purchase was made can access the payment data. After the payment has been made, Apple sends your device account number and a transaction-specific dynamic security code to the originating website to confirm the payment success.
If personal data is processed during these transmissions, processing takes place exclusively for payment processing purposes in accordance with Art. 6 Para. 1 lit. b GDPR.
Apple stores anonymized transaction data, including approximate purchase amount, approximate date and time, and whether the transaction was successfully completed. Anonymization completely excludes any personal reference. Apple uses anonymized data to improve "Apple Pay" and other Apple products and services.
If you use Apple Pay on the iPhone or Apple Watch to complete a purchase made via Safari on the Mac, the Mac and the authorization device communicate via an encrypted channel on Apple servers. Apple does not process or store any of this information in a format that can identify you personally. You can disable the possibility to use Apple Pay on your Mac in your iPhone settings by going to "Wallet & Apple Pay" and disabling "Allow Payments on Mac".
More information on data protection with Apple Pay can be found at the following internet address: https://support.apple.com/de-de/HT203027
- Paypal
This website offers one or more online payment methods from the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
If you choose a payment method from the provider where you pay in advance, your payment data provided during the order process (including name, address, bank and card information, currency, and transaction number) as well as information about your order will be forwarded to the provider in accordance with Art. 6 Para. 1 lit. b GDPR. The data transfer takes place exclusively for payment processing with the provider and only to the extent necessary for this purpose.
If you select a payment method for which we pay in advance, you will also be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and if applicable data on an alternative payment method).
To safeguard our legitimate interest in determining your creditworthiness in such cases, this data will be forwarded by us to the provider for credit checking purposes according to Art. 6 Para. 1 lit. f GDPR. The provider checks, based on the personal data you have provided and other data (such as shopping cart, invoice amount, order history, payment experience), whether the payment method you selected can be granted regarding payment and/or default risks.
The credit check may include probability values (so-called score values). Where score values influence the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of the score values includes, among other things but not exclusively, address data.
You can object to the processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for proper payment processing.
9) Rights of the Data Subject
9.1 The applicable data protection law grants you the following rights as a data subject vis-à-vis the controller regarding the processing of your personal data (rights to information and intervention), whereby the respective legal basis for exercising these rights is referenced:
- Right of access pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to notification pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw consent pursuant to Art. 7(3) GDPR;
- Right to lodge a complaint pursuant to Art. 77 GDPR.
9.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR LEGITIMATE INTEREST AFTER WEIGHING INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF THE PROCESSING SERVES THE ASSERTION, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING AT ANY TIME. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.
10) Duration of Storage of Personal Data
The duration of storage of personal data is determined by the respective legal basis, the processing purpose, and – where applicable – the respective statutory retention periods (e.g., commercial and tax law retention periods).
When processing personal data based on an explicit consent pursuant to Art. 6(1)(a) GDPR, the data concerned will be stored until you revoke your consent.
If there are statutory retention periods for data processed in the context of contractual or similar obligations based on Art. 6(1)(b) GDPR, these data will be routinely deleted after the expiry of these retention periods unless they are still necessary for fulfilling or initiating the contract and/or we have a legitimate interest in further storage.
When processing personal data based on Art. 6(1)(f) GDPR, the data will be stored until you exercise your right to object pursuant to Art. 21(1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.
When processing personal data for direct marketing purposes based on Art. 6(1)(f) GDPR, the data will be stored until you exercise your right to object pursuant to Art. 21(2) GDPR.
Unless otherwise stated in the other information in this declaration about specific processing situations, stored personal data will otherwise be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.