We are pleased about your use of ourwebsite. The protection of your personal data is important to us and we wantyou to feel safe when using our website.
1. Information concerning the collection of personal data
a. The following shall inform youabout the collection, processing and utilization of personal data on ourwebsite. Personal data means all data relating to a living individual who canbe identified.
b. Controller as per the UnitedKingdom General Data Protection Regulation (“GDPR”) is:
60329 Frankfurt am Main
You can reach our Data ProtectionOfficer ("DPO") through the following details:
Emma Sleep GmbH
60329 Frankfurtam Main
c. If we use contracted serviceproviders for individual functions to present our services to you or to yourdata for advertising purposes, we will inform you in detail about therespective processes below.
2. Your rights as a data subject
a. You have the following rightsagainst us with respect to the personal data concerning you:
Right of access by the data subject(Article 15, UK GDPR):
You have the right to requestinformation on the data we hold about you from us at any time. This informationincludes, but is not limited to, the categories of data we process, thepurposes for which it is processed, the source of the data if not collecteddirectly from you, and, if applicable, the recipients with whom we have sharedyour data. You can obtain a copy of your data from us free of charge. If yourequire additional copies, we reserve the right to charge you for these copies.
Right to rectification (Article 16, UKGDPR):
You have the right to request that werectify inaccurate data relating to you. We will take appropriate steps to keepthe data we store and process on an ongoing basis accurate, complete andcurrent, based on the most up-to-date information available.
Right to erasure (Article 17, UKGDPR):
You have the right to demand thedeletion of your personal data stored with us, unless the processing isnecessary to exercise the right to freedom of expression and information, tofulfil a legal obligation, for reasons of public interest or to assert, exerciseor defend legal claims.
Right to restriction of processing(Article 18, UK GDPR):
You have the right to demand therestriction of the processing of your personal data if the accuracy of the datais disputed by you, if the processing is unlawful but you refuse to have itdeleted and we no longer need the data, but you need it for the assertion,exercise or defense of legal claims or if you have lodged an objection to theprocessing pursuant to Art. 21 GDPR.
Right to data portability (Article 20,UK GDPR):
You have the right to request that wetransfer your data – if technically possible – to another responsible party.However, you may only enforce this right if data processing is based on yourconsent or is necessary for the performance of a contract. Rather thanreceiving a copy of your data, you may also ask us to submit the data directlyto another responsible party specified by you.
Right to object (Article 21, UK GDPR):
You have the right to object to theprocessing of your data at any time for reasons that arise from your particularsituation, as long as data processing is based on your consent, on ourlegitimate interests or those of a third party. In this case, we will cease toprocess your data. This does not apply if we can show that there are compellinglegitimate grounds for processing that outweigh your interests, or if we needyour data for the establishment, exercise or defense of legal claims.
Right to withdraw consent (Article7(3), UK GDPR):
You have the right to revoke yourconsent to us at any time. As a result, we are not allowed to continue thepersonal data processing that was based on this consent in the future.
b. If you have the feeling that wehave not responded in an appropriate manner to your requests, or complaints, oryou have further concerns, you additionally have the right to complain to adata protection authority. The responsible authority to us is the
Hessische Beauftragte für Datenschutzund Informationsfreiheit.
c. You can send your inquiriesregarding your rights as a data subject to us by sending a data subject requestto email@example.com.
3. Collection of personal data when you visit our website
When visiting our website, i.e.without registering or agreeing to our further processing or utilization of thedata, only the personal data which your browser transmits to our server isautomatically saved. In order to fulfil these technical requirements for you toview our website and provide for the necessary security, the following data issaved:
- IP Address,
- Date and time of your visit,
- Time zone difference to Greenwich Mean Time (GMT),
- Content of the query (specific site visited),
- Access status/HTTP status code,
- Amount of transferred data,
- Website from which the initial request emanates,
- Operating system, device, and its user interface
- Language and version of browser software.
The personal data mentioned above getsprocessed for the following purposes and legitimate interests (Article 6(1)(f), UK GDPR):
To ensure a smooth connection of thewebsite
To guarantee a comfortable use of ourwebsite
To evaluate system security andstability as well as for other administrative purposes.
These information are temporarilystored in so-called log files. When you visit this website, this information isautomatically recorded without your intervention and stored until it isautomatically deleted. If you don’t want the above personal data to becollected, you should not access our website as we will be unable to allow youaccess to our website without such personal data.
4. Recipients of personal data
a. Within the scope of our activitiesand services, it may become necessary for us to disclose the personal datastored about you to natural persons, legal entities or public authorities. Weconclude contracts with our service providers, which ensure that they may onlyprocess your personal data in a way that we have explicitly instructed them todo so. Furthermore, we ensure that they take the necessary technical andorganizational measures to process your data securely and store your personaldata only as long as necessary. External service providers who may receivepersonal data generally fall into the following categories of recipients:
· Subsidiaries and affiliates
· Credit institutions and providers ofpayment services for billing and payment processing (online payment providers)
· Parcel Shipper
· Non-Governmental/CharitableOrganization that collects product returns
· IT service provider to maintain our ITinfrastructure
· Cloud provider
· Service provider for the optimizationof the online offer
· Collection service providers or lawyers to collect receivables andenforce claims in court. If, in the event of a collection case, personal data(customer and contact data, payment and consumption data and data on the claim)is transferred to a collection service provider, we will inform you in advanceabout the intended transfer.
b. If personal data is processed incountries outside of the United Kingdom, we will ensure that your personal datais processed in accordance with United Kingdom’s data protection level. In theabsence of an adequacy decision, we only transfer data to service providersfrom third countries that offer suitable guarantees in accordance with Art. 46,UK GDPR (usually Standard Contract Clauses).
In our blog, where we publish variousarticles on topics related to our activities, you can make public comments.Your comment will be published with your given username right under the post.You can use a pseudonym instead of your real name. You are required to provideyour username and e-mail address while all further information is voluntary. Ifyou leave a comment, we will continue to save your IP address. The storage isnecessary for us in order to be able to defend ourselves against liability claimsin cases of a possible publication of illegal content. We need your e-mailaddress in order to contact you if a third party should object to your commentas illegal. Comments are not checked before publication. We reserve the right to delete comments ifthird parties complain that they are illegal.
6. Communications and contact form
When you contact us such as throughe-mail or via a contact form, the information you provide will be processed forthe purpose of processing your request and for the event that follow-upquestions arise. If you are contacting us in relation to other matters, ourlegal basis for the processing of your personal data is our legitimate interestto address your concern and to enable you to contact us quickly and easily. Thelegal basis is Article 6(1)(f), UK GDPR. The personal data collected by us inthis context will be deleted when the request associated with the contact hasbeen completely clarified and it is also not to be expected that the specificcontact will become relevant again in the future unless legal storageobligations stand against this.
7. Newsletters and electronic notifications
a. We send newsletters, e-mails andother electronic notifications containing promotional information. Ournewsletters contain information about our products, offers, promotions and ourcompany. With the following notes we inform you about the contents of ournewsletter as well as the registration, dispatch and statistical evaluationprocedure and your right of objection. Newsletter subscriptions are logged inorder to be able to prove the registration process in accordance with the legalrequirements. This includes the storage of the registration and confirmationtime as well as the IP address. Changes to your data stored by the serviceprovider are also logged. The purpose of this procedure is to be able to proveyour registration and, if necessary, to clarify any possible misuse of yourpersonal data.
To subscribe to the newsletter, it issufficient to enter your e-mail address. The provision of further data isvoluntary and is used to address you personally. After your confirmation wewill save your e-mail address for the purpose of sending the newsletter. Thenewsletter dispatch and the measurement of performance are based on yourconsent if you subscribed.
b. To stop receiving the newsletter,you may withdraw your consent to or object to receiving the same at any time byclicking on the unsubscribe link provided in every newsletter e-mail or byreaching out to us through firstname.lastname@example.org.
8. Data retention
We keep your personal data for theperiod of the customer relationship with you or for the legally-required periodafter termination of such relationship or agreement in order to defend ourlegal claims, to protect and enforce our rights, or to comply with laws andregulations. In general, the legal retention period for documents important fortaxation (such as accounting receipts) is ten (10) years while other documentsthat can be considered as commercial or business transaction documents is six(6) years.
9. Social-Media portals
a. We are represented in the socialnetworks and employer evaluation portals mentioned below. These presences areoperated exclusively by the respective provider. They serve to communicatedirectly with customers, interested parties and users. If you contact us viaour social media channels, we process the personal data that you provide uswith as well as the personal data that is necessary to process your request.Insofar as you have given your consent to the operators of the respectivesocial media platforms (e.g. by means of a checkbox opt-in), the processing iscarried out on the basis of your consent. You can revoke your consent at anytime with the operator of the respective platform with effect for the future.
b. When you visit our social mediapages, your user data is recorded and provided to us by the operator. The exacttypes of data differ from provider to provider, but generally include thefollowing information:
Follower: number and stored profiles;information about growth and development over a defined time frame.
Reach: number of people who see aspecific contribution; number of interactions with a contribution. From this,it can be deduced, for example, which content is better received by thecommunity than others.
Ad performance: how many people were reached bya contribution or a paid ad and have interacted with it?
Demographics: average age of visitors, sex,location, language.
c. Since our social media channels areoperated by the providers of the respective social network, there may be asupplementary use of your personal data by the respective operator, over whichwe have no influence. This often involves the recording of your IP address, thecreation of static evaluations and the processing of further information storedin the form of cookies. We have no influence on the generation and presentationof this personal data and can neither turn off this function nor prevent theprocessing of the personal data.
d. The assertion of data subjectrights and requests can most effectively be addressed directly to the platformproviders, since only they have access to your personal data and can takeimmediate action and provide information. Should our cooperation be necessaryfor this, we will support you in enforcing your rights as a data subject.
10. Social-Media plug-ins
We have integrated plug-ins on our webservices. These plug-ins are indicated by the respective button belonging tothe service. With the help of the plug-ins, users can share or post links tothe corresponding websites in social networks such as Facebook or Twitter orrecommend the contents there. Through your active interaction with theseplugins, (e.g., by clicking the respective button or leaving a comment) thisinformation is transmitted directly to the respective service and stored there.
When you visit one of our web servicesthat contain an activated plugin, your browser establishes a connection withthe servers of the respective service, which in turn transmits the content ofthe plugin to your browser, which then integrates it into the displayed page.Thus, the information about the visit of our web services is forwarded to therespective service. We do not collect personal data ourselves by means of thesocial plugins or about their use and have no influence on which data anactivated plugin collects and how these are used by the provider. It must beassumed that at least the IP address and device-related information iscollected and used. It is also possible that the service provider will attemptto store cookies on the computer used. If you are logged in to the respectiveservice at the same time as visiting our web services via your personal useraccount (e.g. via another browser session), the service provider can assign thevisit to our web services to your account.
11. Facebook Insights - "Facebook Fanpages"
Upon a visit of our Facebook pagecollects Facebook among others your IP address as well as other information,which is saved on your device in form of cookies. This information will be usedto provide us as the operator of the Facebook page with statistical informationon Facebook usage. We can access these statistics through so-called Facebook“insights”. These statistics are collected and provided solely by Facebook. Weas the operator of the page have no influence over their generation andpresentation. We cannot either stop or prevent their generation and dataprocessing. You can find further information about “Insights” provided byFacebook here: https://www.facebook.com/help/pages/insights. Followinginformation will be provided to us by Facebook through “Insights”: Number ofpage views, “likes”, page activities, reach, impressions, video views, postclicks and reactions, post reach, comments, shared content, answers, genderratio, regional distribution of the users (origin based on country and city), language,opens and clicks in the shop, clicks on the address and on the telephonenumber. The operation of this Facebook page and processing of personal data ofthe users arising out of it is based on Article 6(1)(f), UK GDPR and ourlegitimate interest to inform and interact with users and visitors of ourFacebook page.
b. This website uses the followingtypes of cookies: