Tax included and shipping calculated at checkout
Privacy Policy
Data protection information of Forrest & Love GmbH
(Version 1.0; Stand 25.05.2018)
As of May 25, 2018, the provisions of the EU General Data Protection Regulation (hereinafter: GDPR) apply throughout Europe. Below, we would like to inform you about the processing of personal data by Forrest & Love GmbH in accordance with this new regulation (see Article 13 GDPR). Please read our privacy policy carefully. If you have any questions or comments regarding this privacy policy, you can send them at any time to the email address provided under Section 2.
Table of Contents
1. Overview
2. Name and contact details of the controller and the company data protection officer
3. Purposes of data processing, legal bases and legitimate interests pursued by Forrest & Love GbR or a third party as well as categories of recipients
3.1. Accessing our website
3.2. Conclusion, execution or termination of a contract
3.3. Data processing for advertising purposes
3.4. Online presence and website optimization
3.5. Customer account
4. Transfer to recipients outside the EU
5. Your rights
6. Data security measures
1. Overview
The following privacy policy informs you about the nature and scope of the processing of so-called personal data by Forrest & Love GmbH. Personal data is information that can be directly or indirectly attributed to you.
Data processing by Forrest & Love GmbH can essentially be divided into two categories:
- For the purpose of contract processing, all data required for the execution of a contract with Forrest & Love GmbH will be processed. If external service providers are involved in the processing of the contract, e.g., logistics companies or payment service providers, your data will be passed on to them to the extent necessary.
When you visit the Forrest & Love GmbH website, various information is exchanged between your device and our server. This may also include personal data. The information collected in this way is used, among other things, to optimize our website or to display advertising in your device's browser.
In accordance with the provisions of the GDPR, you have various rights that you can assert against us. These include, among other things, the right to object to certain data processing activities, particularly data processing for advertising purposes.
If you have any questions about our privacy policy, please feel free to contact our data protection officer at any time. You will find the contact details below.
2. Name and contact details of the controller and the company data protection officer
This privacy policy applies to data processing by Forrest & Love GmbH, Bussardstr. 5, 82166 Gräfelfing, Germany ("Data Protection Officer"), and the following websites: www.forrestandlove.de, www.forrestandlove.com. The company data protection officer of Forrest & Love GmbH can be contacted at the above address, attention: Data Protection Department, or at info@forrestandlove.de.
3. Purposes of data processing, legal bases and legitimate interests pursued by Forrest & Love GmbH or a third party as well as categories of recipients
3.1. Accessing our website
When you visit our website, the browser used on your device automatically sends information to our website server and temporarily stores it in a so-called log file. We have no control over this. The following information is collected without your intervention and stored until it is automatically deleted:
- the IP address of the requesting internet-enabled device,
- the date and time of access,
- the name and URL of the retrieved file,
- the website/application from which access was made (referrer URL),
- the browser you use and, if applicable, the operating system of your internet-enabled computer as well as the name of your access provider.
The legal basis for processing the IP address is Article 6 (1) (f) GDPR. Our legitimate interest arises from the purposes of data collection listed below. Please note that we cannot, and will not, draw any direct conclusions about your identity from the data collected.
We use the IP address of your device and the other data listed above for the following purposes:
- Ensuring a smooth connection setup,
- Ensuring comfortable use of our website,
- Evaluation of system security and stability.
The data is stored for a period of 38 months and then automatically deleted. Furthermore, we use cookies, tracking tools, targeting processes, and social media plug-ins on our website. The exact processes involved and how your data is used for this purpose are explained in more detail below in Section 3.4.
If you have consented to geolocation in your browser, operating system, or other settings on your device, we use this function to offer you personalized services based on your current location (e.g., the location of the nearest branch). We process your location data exclusively for this purpose. If you discontinue use, the data will be deleted.
3.2. Conclusion, execution or termination of a contract
3.2.1. Data processing upon conclusion of contract
The business activities of Forrest & Love GmbH include the production, printing, finishing, other upgrading and distribution of copper bottles, scented pillows, copper cups and copper products of all kinds.
In this context, we process the data necessary for the conclusion, execution, or termination of a contract. This includes:
- First name Last Name
- Billing and delivery address
- E-Mail-Address
- Billing and payment data
- telephone number if applicable
The legal basis for this is Article 6 (1) (b) GDPR, i.e. you provide us with the data on the basis of the contractual relationship between you and us. We are also obliged to process your email address due to a requirement in the German Civil Code (BGB) to send an electronic order confirmation (Article 6 (1) (c) GDPR). Unless we use your contact details for advertising purposes (see below 3.3.), we will store the data collected for contract processing until the expiry of the statutory or possible contractual warranty and guarantee rights. After this period, we will retain the information relating to the contractual relationship required by commercial and tax law for the periods specified by law. For this period (usually ten years from the conclusion of the contract), the data will only be processed again in the event of an audit by the tax authorities.
The following data processing is also required to process the purchase contract:
If you have selected a payment method other than advance payment or cash on delivery, we will pass the required payment details on to a payment service provider commissioned by us. We will pass on your delivery address information to a logistics company commissioned by us for the purpose of processing the purchase contract. To ensure that the goods are delivered according to your wishes, we will transmit your email address and, if applicable, your telephone number to the logistics company commissioned by us. The logistics company will contact you prior to delivery to coordinate delivery details with you. The data will be transmitted solely for this purpose and deleted after delivery.
3.2.2. Identity, creditworthiness and transmission to credit agencies
If necessary, we will verify your identity using information from service providers. The legal basis for this is Article 6 (1) (b) and (f) GDPR. This is justified by the need to protect your identity and prevent fraud attempts at our expense. The circumstances and results of our inquiry will be saved in your customer account or guest account for the duration of the contractual relationship.
In the event of a payment delay, and provided the other legal requirements are met, we will transmit the necessary data to a company commissioned to assert the claim. The legal basis for this is both Article 6 (1) (b) and Article 6 (1) (f) GDPR. The assertion of a contractual claim is deemed to be a legitimate interest within the meaning of the latter provision. If the other legal requirements are met, we will also transmit information about the payment delay or any default to credit agencies cooperating with us. The legal basis for this is Article 6 (1) (f) GDPR. The legitimate interest required here arises from our interest and the interest of third parties in reducing contractual risks for future contracts.
3.3. Data processing for advertising purposes
The following statements refer to the processing of personal data for advertising purposes. The GDPR declares such data processing to be fundamentally conceivable and a legitimate interest based on Article 6, Paragraph 1, Letter f. The duration of data storage for advertising purposes does not follow any rigid principles and is based on the question of whether storage is necessary for the advertising approach. At Forrest & Love GmbH, we also follow the principle of deleting data used for advertising purposes after 38 months. Please see Section 3.3.3 for details of how we will proceed in the event of your objection procedure.
3.3.1. Advertising purposes of Forrest & Love GmbH and third parties
If you have concluded a contract with us, we will treat you as an existing customer. In this case, we process your postal contact details without the need for specific consent in order to send you information about new products and services. We process your email address to send you information about our own, similar products without the need for specific consent.
3.3.2. Interest-based advertising
To ensure you only receive information that is likely to be of interest to you, we categorize and supplement your customer profile with additional information. We use both statistical information and information about you personally (e.g., basic data from your customer profile). The goal is to send you advertising that is tailored solely to your actual or perceived needs and thus avoid bothering you with unnecessary advertising.
3.3.3. Right of objection
You can object to the processing of your data for the aforementioned purposes at any time, free of charge, separately for each communication channel, and with future effect. To do so, simply send an email or a letter to the contact details listed under 1.
If you object, the contact address in question will be blocked for further processing of data for advertising purposes. Please note that in exceptional cases, advertising material may still be sent temporarily even after receipt of your objection. This is due to the technical lead time required for advertisements and does not mean that we will not implement your objection. Thank you for your understanding.
3.3.4. Newsletterversand
On our website, we offer you the opportunity to subscribe to our newsletter. To ensure that no errors have been made when entering your email address, we use the so-called double opt-in procedure: After you have entered your email address in the registration field, we will send you a confirmation link. Only when you click this confirmation link will your email address be added to our mailing list. You can revoke your consent at any time with future effect. To do so, simply send a short email to the email address provided under 2. or via the corresponding link in the newsletter.
3.4. Online presence and website optimization
3.4.1 Cookies – General information
We use so-called cookies on our website based on Article 6 (1) (f) GDPR. Our interest in optimizing our website is deemed to be legitimate within the meaning of the aforementioned provision. Cookies are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our site. Cookies do not cause any damage to your device and do not contain viruses, Trojans, or other malware. Information that is related to the specifically used device is stored in the cookie. However, this does not mean that we thereby directly learn your identity. The use of cookies serves, on the one hand, to make using our services more pleasant for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our website or that you have already logged into your customer account. These are automatically deleted after you leave our site. In addition, we also use temporary cookies for the purpose of user-friendliness, which are stored on your device for a specific period of time. If you visit our site again to use our services, it will automatically recognize that you have already visited us and which entries and settings you have made so that you do not have to enter them again.
If you have a customer account with Forrest & Love GbR and are logged in or activate the "stay logged in" function, the information stored in cookies will be added to your customer account.
We also use cookies to statistically record the use of our website and to evaluate it in order to optimise our service for you, as well as to display information specifically tailored to you. These cookies enable us to automatically recognise that you have already visited us when you visit our site again. These cookies are automatically deleted after a defined period of time. Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or so that a warning always appears before a new cookie is created. However, completely deactivating cookies may mean that you cannot use all of the functions of our website. The storage period of cookies depends on their intended use and is not the same for all users.
3.4.2. Google Analytics
For the purpose of tailoring our website to meet your needs and continuously optimising it, we use Google Analytics, a web analysis service provided by Google Inc. ("Google"), based on Article 6 (1) (f) GDPR. In this context, pseudonymised user profiles are created and cookies are used. The information generated by the cookie about your use of this website, such as
- Browser-Typ/-Version,
- operating system used,
- Referrer URL (the previously visited page),
- Hostname of the accessing computer (IP address),
- Time of the server request,
are transmitted to a Google server in the USA and stored there. This information is used to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website activity and internet usage for the purposes of market research and the needs-based design of these websites. This information may also be transferred to third parties if required to do so by law, or if third parties process this data on Google's behalf. Under no circumstances will your IP address be merged with other data held by Google. IP addresses are anonymized so that assignment is not possible (so-called IP masking).
You can prevent the installation of cookies by setting your browser software accordingly; however, we would like to point out that in this case, not all functions of this website may be able to be used to their full extent. In addition, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) as well as the processing of this data by Google by downloading and installing this browser add-on. An opt-out cookie will be set which prevents the future collection of your data when you visit this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again. Further information on data protection in connection with Google Analytics can be found on the Google Analytics website.
3.4.3. Targeting
The targeting measures listed below and used by us are carried out on the basis of Article 6 (1) (f) GDPR. Through the targeting measures we use, we want to ensure that only advertising tailored to your actual or perceived interests is displayed on your devices. It is in both your and our interest not to bother you with advertisements that are of no interest to you.
3.4.3.1 Onsite-Targeting
Our website uses cookies to collect and evaluate information to optimize advertising. This information includes, for example, details about which of our products you are interested in. The data is collected and evaluated exclusively pseudonymously and does not allow us to identify you. In particular, the information is not combined with any personal data relating to you. Based on this information, we can show you offers on our site that are specifically tailored to your interests, as they arise from your previous user behavior. The cookie is automatically deleted after 6 months.
3.4.3.2 Re-Targeting
We also use retargeting technologies from Google, Facebook, and others. This allows us to tailor our online offerings to your needs and interests. A cookie is set for this purpose, which collects interest data using pseudonyms. Based on this information, interest-based advertisements related to our offerings are displayed to you on our partners' websites. No directly personal data is stored, and no user profiles are combined with your personal data. The cookie is deleted for a period of six months and then automatically deleted.
3.4.3.3 Affiliates
We work with advertising partners to make the online offering on our site even more interesting for you. For this purpose, cookies from our advertising partners are also set when you visit our site (so-called third-party cookies). Our advertising partners' cookies also store information about your user behavior and interests when visiting our site using pseudonyms. In some cases, information that appeared on other websites before you visited our site is also recorded. Based on this information, you will be shown interest-based advertisements from our advertising partners. No personal data is stored and no user profiles are merged with your personal data. The cookie is stored for a period of 6 months and then automatically deleted. You can prevent interest-based advertising from our advertising partners by selecting the appropriate cookie settings in your browser (see also 3.4.1).
3.4.3.4. Objection/opt-out option
You can prevent the targeting technologies described above by setting the appropriate cookies in your browser (see also 3.4.1). You also have the option of deactivating preference-based advertising using the preference manager available here.
3.4.4 Social-Media-Plug-ins
Based on Article 6 (1) (f) GDPR, we use social plug-ins from the social network Facebook on our website to raise awareness of our company. The underlying advertising purpose is considered a legitimate interest within the meaning of the GDPR. Responsibility for ensuring data protection-compliant operation rests with the respective providers. We integrate these plug-ins using the so-called two-click method to best protect visitors to our website.
3.4.4.1 Facebook
Our website uses plug-ins from the social network Facebook, which is operated by Facebook Inc. These plug-ins are marked with a Facebook logo or the "Like" or "Share" symbol. You can find an overview of Facebook plug-ins and their appearance here.
When you activate such a plug-in (first click), your browser establishes a direct connection to the Facebook servers. The content of the plug-in is transmitted from Facebook directly to your browser and integrated into the page. Through this integration, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged in to Facebook. This information (including your IP address) is transmitted from your browser directly to a Facebook server in the USA and stored there. If you are logged in to Facebook, Facebook can directly associate your visit to our website with your Facebook profile. If you interact with the plug-ins, for example by clicking the "Like" button, this information is also transmitted directly to a Facebook server and stored there. The information is also published on your Facebook profile and displayed to your Facebook friends.
For information about the purpose and scope of data collection, the further processing and use of data by Facebook, as well as your rights and settings options for protecting your privacy, please refer to Facebook's privacy policy. If you do not want Facebook to directly associate the information collected about your visit to our website with your Facebook profile, you must log out of Facebook before visiting our website. You can also completely prevent Facebook plug-ins from loading using add-ons for your browser available online, e.g., the "Facebook Blocker."
3.5. Customer account
To provide you with the greatest possible convenience when shopping, we offer the permanent storage of your personal data in a password-protected customer account. Once you have created a customer account, you will not need to re-enter your data. Furthermore, you can view and edit the data stored about you in your customer account at any time.
In addition to the data requested when placing an order, you must provide a password of your choice to set up a customer account. This password, along with your email address, will be used to access your customer account. Please treat your personal login information confidentially and, in particular, do not make it accessible to unauthorized third parties. We cannot accept liability for misused passwords unless we are responsible for the misuse. Please note that you will remain automatically logged in even after leaving our website unless you actively log out. You have the option of deleting your customer account at any time. Please note, however, that this does not automatically delete the data visible in your customer account.
4. Recipients outside the EU
With the exception of the processing described above, we do not transfer your data to recipients located outside the European Union or the European Economic Area. This processing involves data being transferred to the servers of the tracking or targeting technology providers we have commissioned. These servers are located in the USA. Data transfer is carried out in accordance with the principles of the so-called Privacy Shield and on the basis of the so-called standard contractual clauses of the EU Commission.
5. Your rights
5.1 Overview
In addition to the right to revoke your consent given to us, you are entitled to the following additional rights if the respective legal requirements are met:
- Right to information about your personal data stored by us in accordance with Art. 15 GDPR; in particular, you can obtain information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the origin of your data, if it was not collected directly from you,
- Right to rectification of inaccurate data or to completion of correct data in accordance with Art. 16 GDPR,
- Right to deletion of your data stored by us in accordance with Art. 17 GDPR, provided that no statutory or contractual retention periods or other statutory obligations or rights to further storage must be observed,
- Right to restriction of processing of your data pursuant to Art. 18 GDPR, insofar as you contest the accuracy of the data, the processing is unlawful but you oppose its deletion; the controller no longer needs the data, but you require it to assert, exercise or defend legal claims, or you have objected to processing pursuant to Art. 21 GDPR,
- Right to data portability pursuant to Art. 20 GDPR, i.e. the right to have data stored about you that you have provided to us transferred in a common, machine-readable format, or to request that it be transferred to another responsible party
- Right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority at your usual place of residence or work, or at our company headquarters.
5.2. Right of objection
Under the conditions of Art. 21 Para. 1 GDPR, data processing can be objected to for reasons arising from the particular situation of the data subject.
The above general right of objection applies to all processing purposes described in this data protection information that are processed on the basis of Article 6 (1) (f) GDPR. Unlike the specific right of objection directed at data processing for advertising purposes, under the GDPR we are only obligated to implement such a general objection if you provide us with reasons of overriding importance (e.g., a potential threat to life or health). Furthermore, you have the option of contacting the supervisory authority responsible for Forrest & Love GbR, the Munich Commissioner for Data Protection and Freedom of Information.
6. Data security
All personal data you submit, including your payment details, is transmitted using the generally accepted and secure SSL (Secure Socket Layer) standard. SSL is a secure and proven standard that is also used in online banking, for example. You can recognize a secure SSL connection by the "s" appended to the "http" (i.e., https://...) in your browser's address bar or by the lock symbol at the bottom of your browser.
We also use appropriate technical and organizational security measures to protect your personal data stored with us against manipulation, partial or complete loss, and unauthorized access by third parties. Our security measures are continuously improved in line with technological developments and are certified where appropriate.
Withdraw from Contract
Please fill out the form to submit your withdrawal. No account required.
We only collect data strictly necessary for processing your withdrawal (GDPR Art. 5(1)(c)). No login required.
