Privacy policy
Controller of data processing:
K-Innovations GmbH
Hasselborner Str. 19-21
35647 Waldsolms
Germany
Phone: +49 (0) 6475 2009874
Email: service@nutraply.com
We appreciate your interest in our online shop. Protecting your privacy is extremely important to us. Below, we provide detailed information about how we handle your data.
1. Access Data and Hosting
You can visit our website without providing any personal information. Each time a website is accessed, the web server automatically saves only a so-called server log file which contains e.g. the name of the requested file, your IP address, date and time of access, transferred data volume and the requesting provider (access data) and documents the access.
This access data is evaluated exclusively for the purpose of ensuring trouble-free operation of the site and improving our offering. This serves to protect our legitimate interests in a correct presentation of our offer, which predominate in the context of a balancing of interests. All access data is deleted no later than seven days after the end of your page visit.
Third-party hosting services
As part of processing on our behalf, a third-party provider provides us with hosting and website display services. All data collected in the context of using this website or in forms provided for this purpose in the online shop as described below is processed on its servers. Processing on other servers only takes place within the scope explained here.
This service provider is based in the USA and is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
2. Data Collection and Use for Contract Processing, Contact and Customer Account Creation
We collect personal data when you voluntarily provide it to us during the ordering process, when contacting us (e.g., via contact form or email), or when creating a customer account. Mandatory fields are marked as such because we require this data for contract processing or to process your contact request, and you cannot complete the order or send the contact request without providing it. The data collected can be seen in the respective input forms. We use the data you provide in accordance with Art. 6 (1) (b) GDPR for contract processing and handling your inquiries.
If you have given your consent according to Art. 6 (1) (a) GDPR by creating a customer account, we use your data for the purpose of creating the customer account.
After complete processing of the contract or deletion of your customer account, your data will be restricted for further processing and deleted after expiry of tax and commercial law retention periods, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this declaration. You can delete your customer account at any time by sending a message to the contact option described below or by using a dedicated function in the customer account.
3. Data Transfer
To fulfill the contract according to Art. 6 (1) (b) GDPR, we pass on your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the ordering process, we pass on the payment data collected for this purpose to the credit institution commissioned with the payment and any payment service providers commissioned by us or to the selected payment service. In some cases, the selected payment service providers collect this data themselves if you create an account there. In this case, you must log in to the payment service provider with your access data during the ordering process. The privacy policy of the respective payment service provider applies in this respect.
For order and contract processing, we also use an external merchandise management system. The data transfer or processing that takes place in this context is based on order processing.
The same applies to the transfer of data to our manufacturers or wholesalers in cases where they handle shipping for us (dropshipping).
Data transfer to shipping service providers
If you have given us your express consent during or after your order, we will pass on your telephone number to the selected shipping service provider based on this consent according to Art. 6 (1) (a) GDPR so that they can contact you before delivery for the purpose of delivery notification or coordination.
This consent can be withdrawn at any time by sending a message to the contact option described below or directly to the shipping service provider at the contact address listed below. After withdrawal, we will delete your data provided for this purpose unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this declaration.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Deutschland
4. Email Newsletter
E-Mail-Werbung mit Anmeldung zum Newsletter
Email Advertising with Newsletter Registration
When you subscribe to our newsletter, we use the data required for this purpose or separately provided by you to regularly send you our email newsletter based on your consent according to Art. 6 (1) (a) GDPR.
You can unsubscribe from the newsletter at any time by sending a message to the contact option described below or via a dedicated link in the newsletter. After unsubscribing, we will delete your email address from the recipient list unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is legally permitted and about which we inform you in this declaration.
The newsletter is sent as part of processing on our behalf by a service provider, to whom we pass on your email address for this purpose.
This service provider is based in the USA and is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the USA and the European Commission, the latter has established an adequate level of data protection for companies certified under the Privacy Shield.
5. Data Use in Payment Processing
Installment Purchase
If you select the "installment purchase" payment method and provide the required data protection consent according to Art. 6 (1) (a) GDPR, personal data (first name, last name, address, email, phone number, date of birth, IP address, gender) together with data required for transaction processing (articles, invoice amount, due dates, total amount, invoice number, taxes, currency, order date and time) will be transmitted to our partner Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm for the purpose of processing this payment method.
To verify the customer's identity and creditworthiness, our partner conducts queries and obtains information from publicly accessible databases and credit agencies. The providers from whom information and, if applicable, credit information based on mathematical-statistical procedures are obtained, as well as further details on the processing of your data after transmission to our partner Klarna Bank AB (publ), can be found in their privacy policy here: https://www.klarna.com/de/datenschutz/
Our partner Klarna Bank AB (publ) uses the received information about the statistical probability of payment default for a balanced decision about the establishment, implementation or termination of the contractual relationship. You have the possibility to present your position by contacting our partner Klarna Bank AB (publ) and contest the decision.
The consent to data transfer given during the ordering process can be revoked at any time with effect for the future, even without stating reasons.
6. Cookies and Web Analysis
To make visiting our website attractive and enable certain functions, to display suitable products or for market research, we use cookies on various pages, provided you have given your consent pursuant to Art. 6(1)(a) GDPR.
Cookies are small text files that are automatically stored on your device. Some cookies we use are deleted after your browser session ends (session cookies). Other cookies remain on your device and enable us to recognize your browser on your next visit (persistent cookies). You can see the duration of storage in your browser's cookie settings overview. You can configure your browser to be informed about cookie placement and decide individually about their acceptance or exclude cookie acceptance for certain cases or generally. Each browser differs in how it manages cookie settings. This is described in each browser's help menu, which explains how to change your cookie settings. When cookies are not accepted, our website's functionality may be limited.
Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
You can also withdraw your consent at any time by sending a message to the contact option described in the privacy policy.
DoubleClick-Cookie
If you have given your consent pursuant to Art. 6(1)(a) GDPR, this website also uses the DoubleClick cookie as part of Google Analytics (see below) for advertising purposes, which enables recognition of your browser when visiting other websites. The automatically generated information about your website visit is typically transmitted to and stored on a Google server in the USA. IP anonymization is activated on this website, so your IP address is truncated beforehand within European Union member states or other European Economic Area treaty states. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. The anonymized IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. Google will use this information to compile reports about website activities and provide other services related to website usage. Google may also transfer this information to third parties where required by law or where third parties process this data on Google's behalf. After purpose cessation and end of our use of Google DoubleClick, the data collected in this context will be deleted.
Google Double Click is offered by Google Ireland Limited, a company registered and operated under Irish law with headquarters at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). Where information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the US and European Commission, the Commission has determined an adequate level of data protection exists for certified companies.
You can withdraw your consent with future effect at any time by deactivating the DoubleClick cookie via this link. Additionally, you can obtain information about cookie placement from the Digital Advertising Alliance and adjust related settings. Finally, you can configure your browser to be informed about cookie placement and decide individually about their acceptance or exclude cookie acceptance for certain cases or generally. When cookies are not accepted, our website's functionality may be limited.
If you have given your consent pursuant to Art. 6(1)(a) GDPR, this website uses Google (Universal) Analytics for website analysis purposes. This web analytics service is offered by Google Ireland Limited, a company registered and operated under Irish law with headquarters at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). Google (Universal) Analytics uses methods that enable analysis of your website use, such as cookies. The automatically collected information about your website use is typically transmitted to and stored on a Google server in the USA. IP anonymization is activated on this website, so your IP address is truncated beforehand within European Union member states or other European Economic Area treaty states. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. The anonymized IP address transmitted by your browser as part of Google Analytics will generally not be merged with other Google data. After purpose cessation and end of our use of Google Analytics, the data collected in this context will be deleted.
Where information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the US and European Commission, the Commission has determined an adequate level of data protection exists for certified companies.
You can withdraw your consent with future effect at any time by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en. This prevents collection of data generated by the cookie about your website use (including your IP address) and its processing by Google.
Alternatively, you can click to prevent future collection by Google Analytics on this website. This places an opt-out cookie on your device. If you delete your cookies, you will be asked to provide your consent again.
7. Online-Marketing
Google Ads Remarketing
We advertise this website in Google search results and on third-party websites via Google Ads. For this purpose, the Google remarketing cookie is set when visiting our website, which automatically enables interest-based advertising through a pseudonymous cookie ID and based on the pages you visit. This serves our legitimate interests in optimal marketing of our website pursuant to Art. 6(1)(a) GDPR, as determined through balancing of interests. After purpose cessation and end of our use of Google Ads Remarketing, the data collected in this context will be deleted.
Further data processing occurs only if you have agreed with Google that your web and app browsing history will be linked to your Google account and information from your Google account will be used to personalize ads you see on the web. If you are logged into Google while visiting our website, Google will use your data together with Google Analytics data to create and define target group lists for cross-device remarketing. For this purpose, Google temporarily links your personal data with Google Analytics data to create target groups.
Google Ads is offered by Google Ireland Limited, a company registered and operated under Irish law with headquarters at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). Where information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the US and European Commission, the Commission has determined an adequate level of data protection exists for certified companies.
You can deactivate the remarketing cookie via this link. Additionally, you can obtain information about cookie placement from the Digital Advertising Alliance and adjust related settings.
Microsoft Advertising
We advertise this website in Bing, Yahoo and MSN search results and on third-party websites via Microsoft Advertising. If you have given your consent pursuant to Art. 6(1)(a) GDPR, a cookie is automatically set when visiting our website, which enables interest-based advertising through a pseudonymous cookie ID and based on the pages you visit. After purpose cessation and end of our use of Microsoft Advertising, the data collected in this context will be deleted.
Microsoft Advertising is offered by Microsoft Corporation (www.microsoft.com). Microsoft Corporation is headquartered in the USA and certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the US and European Commission, the Commission has determined an adequate level of data protection exists for certified companies.
You can withdraw your consent with future effect at any time by deactivating the remarketing cookie via this link. Additionally, you can obtain information about cookie placement from the Digital Advertising Alliance and adjust related settings.
Amazon-Partnerprogramm
Our website participates in the Amazon Partner Program offered by Amazon Europe Core S.à r.l. (Société à responsabilité limitée), 5 Rue Plaetis, L-2338 Luxembourg ("Amazon"). This is an affiliate system designed to provide a medium for websites through which advertising cost reimbursement can be earned by placing advertisements and links to Amazon. This serves our legitimate interests in optimizing and economic operation of our online offering pursuant to Art. 6(1)(f) GDPR, as determined through balancing of interests. Through cookies, Amazon can track the progress of orders and particularly verify that you clicked the respective link and then ordered the product on Amazon. You can prevent cookie placement by our contractual partners or our website at any time through appropriate settings in your internet browser. Additionally, cookies already placed can be deleted at any time via the internet browser or other software programs. Further information about data processing by Amazon can be found here.
Google Maps
This website uses Google Maps to visually display geographical information. Google Maps is offered by Google Ireland Limited, a company registered and operated under Irish law with headquarters at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves our legitimate interests in optimized presentation of our offering and easy location finding for our sites pursuant to Art. 6(1)(f) GDPR. When using Google Maps, Google collects data about Maps feature usage by website visitors, which may include particularly IP addresses and location data. We have no influence over this data processing. Where information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the US and European Commission, the Commission has determined an adequate level of data protection exists for certified companies. To deactivate Google Maps service and prevent data transfer to Google, you must deactivate JavaScript in your browser. In this case, Google Maps cannot or can only be used in a limited way. Further information about data processing by Google can be found in Google's privacy policy. Google Maps terms of use contain detailed information about the map service. Data processing occurs based on an agreement between joint controllers pursuant to Art. 26 GDPR, which you can view here.
Google Fonts
This website incorporates the "Google Fonts" script code. Google Fonts is offered by Google Ireland Limited, a company registered and operated under Irish law with headquarters at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves our legitimate interests in unified presentation of content on our website pursuant to Art. 6(1)(f) GDPR. In this context, a connection is established between your browser and Google's servers. Through this, Google gains knowledge that our website was accessed via your IP address. Where information is transferred to and stored on Google servers in the USA, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Based on this agreement between the US and European Commission, the Commission has determined an adequate level of data protection exists for certified companies. Further information about data processing by Google can be found in Google's privacy policy.
8. Social Media
Use of Social Plugins from Facebook, Twitter, Instagram, Pinterest
Our website uses social plugins ("Plugins") from social networks.
When you access a page of our website containing such a plugin, your browser establishes a direct connection to the respective social network's servers. The plugin content is transmitted by the provider directly to your browser and integrated into the page. Through plugin integration, providers receive the information that your browser has accessed the corresponding page of our website, even if you don't have a profile or aren't currently logged in. This information (including your IP address) is transmitted by your browser directly to a provider server (possibly in the USA) and stored there. If you're logged into one of the services, providers can directly associate your website visit with your profile in the respective social network. If you interact with plugins, for example by clicking the "Like" or "Share" button, the corresponding information is also transmitted directly to a provider server and stored there. The information is also published in the social network and displayed to your contacts. This serves our legitimate interests in optimal marketing of our offering pursuant to Art. 6(1)(f) GDPR.
For information about the purpose and scope of data collection and further processing and use of data by providers on their pages, as well as contact options and your related rights and setting options for protecting your privacy, please see providers' privacy policies:
https://www.facebook.com/policy.php
https://twitter.com/de/privacy
https://help.instagram.com/155833707900388
https://policy.pinterest.com/en/privacy-policy
https://www.whatsapp.com/legal/#privacy-policy
If you don't want social networks to directly associate data collected via our website with your profile in the respective service, you must log out of the corresponding service before visiting our website. You can also completely prevent plugins from loading with browser add-ons, e.g., with the script blocker "NoScript".
Our Online Presence on Facebook, Twitter, Youtube, Instagram, Pinterest
Our presence on social networks and platforms serves better, active communication with our customers and interested parties. We inform there about our products and ongoing special promotions. When visiting our online presence in social media, your data may be automatically collected and stored for market research and advertising purposes. From this data, usage profiles are created under pseudonyms. These can be used to place advertisements within and outside platforms that presumably correspond to your interests. For this purpose, cookies are typically placed on your device. Visitor behavior and interests of users are stored in these cookies. This serves pursuant to Art. 6(1)(f) GDPR our legitimate interests in optimized presentation of our offering and effective communication with customers and interested parties, as determined through balancing of interests. If you are asked by respective social media platform operators for consent to data processing, e.g., using a checkbox, the legal basis for data processing is Art. 6(1)(a) GDPR.
Insofar as the aforementioned social media platforms are headquartered in the USA, the following applies: The European Commission has issued an adequacy decision for the USA. This goes back to the EU-US Privacy Shield. A current certificate for the respective company can be viewed here.
For detailed information on data processing and usage by providers on their pages, as well as contact options and your related rights and setting options for protecting your privacy, particularly opt-out options, please see the providers' linked privacy notices below. Should you need help with this, you can contact us.
Facebook: https://www.facebook.com/about/privacy/ Data processing occurs based on an agreement between joint controllers pursuant to Art. 26 GDPR, which you can view here. Further information about data processing when visiting a Facebook fan page (information about Insights data) can be found here.
Google/ YouTube: https://policies.google.com/privacy?hl=de
Twitter: https://twitter.com/de/privacy
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://about.pinterest.com/de/privacy-policy
Widerspruchsmöglichkeit (Opt-Out):
Facebook: https://www.facebook.com/settings?tab=ads
Google/ YouTube: https://adssettings.google.com/authenticated?hl=de
Twitter: https://twitter.com/personalization
Instagram: https://help.instagram.com/519522125107875
Pinterest: https://www.pinterest.de/settings
9. Sending Review Reminders by Email
If you have given your express consent during or after your order pursuant to Art. 6(1)(a) GDPR, we will use your email address to remind you to review your order using our review system. You may withdraw this consent at any time by sending a message to the contact option described below.
10. Contact Options and Your Rights
As a data subject, you have the following rights:
- pursuant to Art. 15 GDPR, the right to request information about your personal data processed by us to the extent described therein;
- pursuant to Art. 16 GDPR, the right to immediately request correction of incorrect or completion of your personal data stored by us;
- pursuant to Art. 17 GDPR, the right to request deletion of your personal data stored by us, unless further processing is necessary
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation;
- for reasons of public interest; or
- for establishing, exercising or defending legal claims;;
- pursuant to Art. 18 GDPR, the right to request restriction of processing of your personal data, insofar as
- you contest the accuracy of the data;
- the processing is unlawful but you oppose deletion;
- we no longer need the data but you need it for establishing, exercising or defending legal claims; or
- you have objected to processing pursuant to Art. 21 GDPR;
- pursuant to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request transmission to another controller;
- pursuant to Art. 77 GDPR, the right to complain to a supervisory authority. You can generally contact the supervisory authority of your usual place of residence or workplace or our company headquarters.
For questions about collection, processing or use of your personal data, for information, correction, restriction or deletion of data, and withdrawal of granted consents or objection to specific data use, please contact us directly using the contact details in our imprint.
Right to Object After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. This does not apply if the processing is for direct marketing purposes. Then we will no longer process your personal data for this purpose. |