Privacy Policy
Shopify Store, Checkout and Customer Accounts
Our online store is hosted by Shopify. Shopify processes contact details, billing and shipping addresses, order and payment information, as well as technical information about visits to and use of our store in order to provide the storefront, checkout and customer accounts. Processing on our behalf is subject to the Shopify Data Processing Addendum. If you use Shopify consumer services such as Shop Pay, Shopify also processes data in accordance with its Consumer Privacy Policy.
Shopify Network Intelligence
Shopify Network Intelligence is enabled for our store. Shopify uses information about interactions with our store together with information about interactions with other merchants and Shopify to provide enhanced services, including product improvements, advertising targeting and personalization. Information submitted to our store is shared with Shopify and service providers, which may also be located in other countries.
For these enhanced services, Shopify processes personal data as a controller in accordance with its Consumer Privacy Policy. You can manage your advertising consent in our cookie settings and exercise your rights, withdraw consent or object to processing by Shopify through the Shopify Privacy Portal.
Payments and Order Management
When you make a purchase, the information required for your selected payment method is processed through the checkout and the respective payment provider. Options displayed at checkout may include PayPal, Shop Pay and Google Pay. The respective provider’s own privacy policy applies to its processing activities.
Order information is also processed for delivery, customer service, returns and accounting purposes. Our store has a Visma integration for order management. To the extent required for order processing and accounting, customer and order information may be processed through this integration.
Cookies and Consent Management with Consentmo
We use Consentmo to display cookie choices, store preferences and support privacy requests. Consentmo processes consent decisions and records, technical visitor information and information you submit as part of a privacy request on our behalf.
Preference cookies store your choices. You can change or withdraw your consent through the store’s cookie settings. Essential functions support the operation of the store, while analytics and advertising preferences can be managed separately.
Further information is available in Consentmo’s Privacy Policy.
Analytics, Advertising and Shopify Customer Events Pixel
We use a custom Shopify Customer Events Pixel with Google Tag Manager to organize the measurement of visits, searches, product views, wishlist and cart activities, checkout steps and purchases.
The pixel processes page and browser information, a session identifier, product and transaction data and, where provided or available in the customer account or checkout, email address, telephone number, name and address information.
Contact details may be processed both in their original form and as SHA-256 hashes for matching and conversion measurement. Hashing constitutes pseudonymization and does not make this information anonymous.
Our configuration transmits consent signals to Google Tag Manager and distinguishes between analytics and advertising preferences.
Google Analytics 4 and Google Ads
Google Analytics 4 supports the measurement of store usage and shopping activities. Google Ads supports advertising attribution, conversion measurement and remarketing.
The configuration includes user data matching for conversion measurement, which may use hashed contact and address information. Google may receive page URLs, device and browser information, IP addresses, cookies or other identifiers, as well as shopping events.
Further information is available in Google’s information on the use of information from partner websites and Enhanced Conversions documentation.
Meta Pixel and Microsoft Advertising
The Tag Manager configuration includes Meta Pixel and Microsoft Advertising UET for advertising measurement, audience creation and remarketing.
Shopping events, product and transaction information and identifiers may be associated with advertising accounts. Contact information may be used for matching purposes, including hashed email addresses and telephone numbers.
Advertising measurement and matching are subject to your advertising consent choices.
Further information is available in the Meta Privacy Policy and Microsoft Privacy Statement.
Apps and Services Connected to the Store
Wishlist Plus by Swym
Wishlist Plus provides saved product lists. Information about saved products, wishlist interactions, browser or session identifiers and, where applicable, customer contact information provided by you may be processed to provide and synchronize the wishlist.
A Shopify Events Pixel also supports the measurement of interactions.
Further information is available in Swym’s Privacy Policy.
Judge.me Reviews
Judge.me provides product reviews and has a Shopify Events Pixel connected to our store. If you submit a review, its content, rating, display name and the information you provide are processed for this purpose.
The app has access to customer and order information to support review-related functions.
Further information is available in the Judge.me Privacy Policy.
Doofinder
Doofinder is connected through a Shopify Customer Events Pixel to measure search and product discovery. Search queries, product interactions and technical visitor information may be processed for search-related statistics and improvements.
Further information is available in the Doofinder Privacy Policy.
Attentive and HubSpot
Attentive is integrated into our storefront and is listed as an Events Pixel. HubSpot is installed with an Events Pixel.
These services support marketing communications, customer relationships and interaction measurement. Depending on the function used and the information provided, processing may include contact details, subscription and consent information, identifiers, as well as purchase or communication interactions.
Marketing subscriptions and cookie consent can be withdrawn through the respective unsubscribe link or cookie settings.
Further information is available in the Attentive Privacy Policy and HubSpot Privacy Policy.
Product Comparison
LDT Product Compare provides the product comparison functionality. Selected products and technical information required to display and save the comparison may be processed when this functionality is used.
Further information is available in LDT’s Privacy Policy.
ReturnZap Returns
ReturnZap provides our returns portal. When you submit a return request, identification and contact details, order and product information and the return request itself are processed in order to identify the purchase and process the return.
Further information is available in the ReturnZap Privacy Policy.
Userlike Customer Chat
We integrate Userlike for customer chat. When you use the chat, message content, contact information provided by you and technical session information may be processed in order to respond to your request.
Our storefront loader links activation of the chat to the advertising preference when the Consentmo banner is active.
Further information is available in the Userlike Privacy Policy.
Legal Bases and International Processing for These Store Services
Processing for orders, payments and requested customer service is based on the performance of a contract or pre-contractual measures pursuant to Art. 6(1)(b) GDPR. Compliance with accounting obligations is based on Art. 6(1)(c) GDPR.
Consent pursuant to Art. 6(1)(a) GDPR is the legal basis for optional analytics and advertising processing activities for which consent is requested.
Essential store operations, security and the management of consent decisions are based on the applicable legal obligation or our legitimate interest in the secure operation of the store pursuant to Art. 6(1)(c) or (f) GDPR.
Providers may process data outside the EEA. Applicable contractual safeguards and transfer mechanisms are described in the respective provider’s privacy terms. The general information regarding your rights and data retention also applies.
General Privacy Information
PRIVACY
Privacy Policy
This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offering and the websites, functions and content connected to it, as well as external online presences such as our social media profiles (collectively referred to as the “online offering”).
With regard to terminology used, such as “processing” or “controller”, we refer to the definitions set out in Art. 4 of the General Data Protection Regulation (GDPR).
Controller
BERING Time ApS
Skraenten 34
6200 Aabenraa / Denmark
Email address: info@beringtime.de
Managing Director: Michael Witt Johansen
Link to Legal Notice: https://beringtime.com/de-de/policies/legal-notice
Data Protection Officer:
PROLIANCE GmbH
www.datenschutzexperte.de
Leopoldstraße 21
80802 Munich
Germany
datenschutzbeauftrager@datenschutzexperte.de
Types of Data Processed
- Master data (e.g. names, addresses)
- Contact data (e.g. email, telephone numbers)
- Content data (e.g. text entries, photographs, videos)
- Usage data (e.g. websites visited, interest in content, access times)
- Meta/communication data (e.g. device information, IP addresses)
Categories of Data Subjects
Visitors and users of the online offering (hereinafter collectively referred to as “users”).
Purpose of Processing
- Provision of the online offering, its functions and content
- Responding to contact requests and communicating with users
- Security measures
- Audience measurement/marketing
Terminology Used
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Applicable Legal Bases
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing activities.
Unless the legal basis is specifically stated in this Privacy Policy, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing for the performance of our services, implementation of contractual measures and responding to inquiries is Art. 6(1)(b) GDPR; the legal basis for processing in order to comply with our legal obligations is Art. 6(1)(c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6(1)(f) GDPR.
Where the vital interests of the data subject or another natural person require the processing of personal data, Art. 6(1)(d) GDPR serves as the legal basis.
Security Measures
In accordance with Art. 32 GDPR and taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical access to data as well as access, input, disclosure, ensuring availability and separation of data.
We have also established procedures to ensure the exercise of data subject rights, deletion of data and responses to threats to data security. Furthermore, we take the protection of personal data into account during the development or selection of hardware, software and procedures, in accordance with the principles of data protection by design and by default pursuant to Art. 25 GDPR.
Cooperation with Processors and Third Parties
Where, as part of our processing activities, we disclose data to other persons and companies (processors or third parties), transfer data to them or otherwise grant them access to the data, this is done only on the basis of a legal authorization—for example, where transfer to third parties such as payment service providers is required for the performance of a contract pursuant to Art. 6(1)(b) GDPR—where you have given your consent, where a legal obligation requires it or on the basis of our legitimate interests, for example when using agents, web hosts or other service providers.
Where we engage third parties to process data on the basis of a data processing agreement, this is done pursuant to Art. 28 GDPR.
Transfers to Third Countries
Where we process data in a third country—that is, outside the European Union (EU) or European Economic Area (EEA)—or where such processing occurs in connection with the use of third-party services or the disclosure or transfer of data to third parties, this takes place only where necessary for the performance of our contractual or pre-contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests.
Subject to statutory or contractual permissions, we process or have data processed in a third country only where the specific requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of specific safeguards such as an officially recognized adequacy decision or officially recognized contractual obligations, including Standard Contractual Clauses.
Rights of Data Subjects
You have the right pursuant to Art. 15 GDPR to request confirmation as to whether personal data concerning you are being processed and to obtain access to such data as well as further information and a copy of the data.
Pursuant to Art. 16 GDPR, you have the right to request completion of personal data concerning you or correction of inaccurate personal data concerning you.
Pursuant to Art. 17 GDPR, you have the right to request that personal data concerning you be deleted without undue delay or, alternatively, pursuant to Art. 18 GDPR, to request restriction of processing.
Pursuant to Art. 20 GDPR, you have the right to receive personal data concerning you that you have provided to us and to request its transmission to another controller.
You also have the right pursuant to Art. 77 GDPR to lodge a complaint with the competent supervisory authority.
Right to Withdraw Consent
You have the right to withdraw consent previously granted pursuant to Art. 7(3) GDPR with effect for the future.
Right to Object
You may object at any time to the future processing of personal data concerning you in accordance with Art. 21 GDPR. In particular, you may object to processing for direct marketing purposes.
Deletion of Data
Data processed by us will be deleted or its processing restricted in accordance with Art. 17 and 18 GDPR.
Unless expressly stated otherwise in this Privacy Policy, data stored by us will be deleted as soon as it is no longer required for its intended purpose and provided that deletion does not conflict with statutory retention obligations.
Where data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and will not be processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law purposes.
Under statutory requirements in Germany, records are retained in particular for 10 years pursuant to Sections 147(1) AO and 257(1) Nos. 1 and 4 and (4) HGB (books, records, management reports, accounting documents, commercial books, tax-relevant documents, etc.) and for six years pursuant to Section 257(1) Nos. 2 and 3 and (4) HGB (commercial correspondence).
Under statutory requirements in Austria, records are retained in particular for seven years pursuant to Section 132(1) BAO (accounting documents, receipts/invoices, accounts, business documents, statements of income and expenditure, etc.), for 22 years in connection with real estate and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU Member States where the Mini One Stop Shop (MOSS) is used.
Business-Related Processing
In addition, we process:
- Contract data (e.g. subject matter of contract, term, customer category)
- Payment data (e.g. bank details, payment history)
relating to our customers, prospective customers and business partners for the purposes of providing contractual services, service and customer care, marketing, advertising and market research.
Order Processing in the Online Store and Customer Account
We process our customers’ data as part of the ordering process in our online store in order to enable them to select and order the chosen products and services and to facilitate payment, delivery and/or performance.
The data processed includes master data, communication data, contract data and payment data. The persons affected by the processing include our customers, prospective customers and other business partners.
Processing is carried out for the purpose of providing contractual services in connection with the operation of an online store, billing, delivery and customer service.
We use session cookies to store shopping cart contents and persistent cookies to store login status.
Processing is based on Art. 6(1)(b) GDPR for order processing and Art. 6(1)(c) GDPR for legally required archiving.
Information marked as mandatory is required to establish and perform the contract. We disclose data to third parties only in connection with delivery, payment or where permitted or required by law, including disclosure to legal advisers and authorities.
Data is processed in third countries only where this is necessary for the performance of the contract, for example at the customer’s request in connection with delivery or payment.
Users may optionally create a user account, through which they can, in particular, view their orders. During registration, users are informed of the required mandatory information.
User accounts are not public and cannot be indexed by search engines. If users terminate their user account, data relating to the user account will be deleted, subject to retention where required for commercial or tax law purposes pursuant to Art. 6(1)(c) GDPR.
Information in the customer account remains until the account is deleted, followed by archiving where legally required. Users are responsible for securing their data before the end of the contractual relationship in the event of termination.
During registration, subsequent logins and use of our online services, we store the IP address and time of the respective user action.
This storage is based on our legitimate interests and those of users in protection against misuse and other unauthorized use. As a general rule, this data is not disclosed to third parties unless required to pursue our claims or where there is a legal obligation pursuant to Art. 6(1)(c) GDPR.
Deletion takes place after expiry of statutory warranty and comparable obligations. The need to retain data is reviewed every three years. Where statutory archiving obligations apply, deletion takes place after the relevant retention period has expired.
Administration, Financial Accounting, Office Organization and Contact Management
We process data in connection with administrative tasks, the organization of our business, financial accounting and compliance with legal obligations such as archiving.
In doing so, we process the same data that we process in connection with the provision of our contractual services.
The legal bases for processing are Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. Customers, prospective customers, business partners and website visitors are affected by this processing.
The purpose of and our interest in processing lies in administration, financial accounting, office organization and data archiving—in other words, activities that serve to maintain our business operations, perform our duties and provide our services.
Deletion of data relating to contractual services and contractual communication follows the provisions specified for those processing activities.
In this context, we disclose or transfer data to tax authorities, advisers such as tax consultants or auditors, other fee authorities and payment service providers.
Furthermore, on the basis of our business interests, we store information relating to suppliers, event organizers and other business partners, for example for the purpose of future contact. We generally retain this predominantly business-related data permanently.
Business Analysis and Market Research
In order to operate our business economically and identify market trends and the preferences of contractual partners and users, we analyze data available to us relating to business transactions, contracts, inquiries and similar activities.
We process master data, communication data, contract data, payment data, usage data and metadata on the basis of Art. 6(1)(f) GDPR. The data subjects include contractual partners, prospective customers, customers, visitors and users of our online offering.
The analyses are carried out for business evaluation, marketing and market research purposes. In doing so, we may take into account profiles of registered users together with information such as the services they have used.
The analyses serve to improve user-friendliness, optimize our offering and improve the economic efficiency of our business.
The analyses are used solely by us and are not disclosed externally unless they consist of anonymous analyses containing aggregated values.
Where these analyses or profiles contain personal data, they are deleted or anonymized upon termination of the user relationship, otherwise after two years from conclusion of the contract.
Where possible, overall business analyses and general trend assessments are conducted anonymously.
Privacy Information in the Application Process
We process applicant data solely for the purpose of and within the scope of the application process in accordance with applicable legal requirements.
Applicant data is processed in order to fulfil our pre-contractual obligations within the application process pursuant to Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR where data processing is required by us, for example in connection with legal proceedings. In Germany, Section 26 BDSG also applies.
The application process requires applicants to provide us with applicant data. Where we provide an online form, the necessary applicant information is marked accordingly; otherwise it follows from the job description.
As a general rule, applicant data includes personal information, postal and contact addresses and application documents such as a cover letter, CV and certificates. Applicants may also voluntarily provide us with additional information.
By submitting an application to us, applicants consent to the processing of their data for the purposes of the application process in accordance with the nature and scope described in this Privacy Policy.
Where special categories of personal data within the meaning of Art. 9(1) GDPR are voluntarily provided as part of the application process, they are additionally processed pursuant to Art. 9(2)(b) GDPR—for example, health information such as severe disability status or ethnic origin.
Where special categories of personal data within the meaning of Art. 9(1) GDPR are requested from applicants as part of the application process, they are additionally processed pursuant to Art. 9(2)(a) GDPR—for example, health information where required for the performance of the job.
Where available, applicants may submit their applications using an online form on our website. Data is transmitted to us in encrypted form in accordance with the state of the art.
Applicants may also submit applications to us by email. Please note, however, that emails are generally not transmitted in encrypted form and applicants themselves are responsible for encryption.
We therefore cannot assume responsibility for the transmission route between the sender and receipt on our server and recommend using an online form or postal delivery instead. Applicants continue to have the option of submitting their application by post.
Where an application is successful, the data provided by the applicant may be further processed by us for the purposes of the employment relationship.
Otherwise, if the application is unsuccessful, the applicant’s data will be deleted. Applicant data will also be deleted if an application is withdrawn, which applicants may do at any time.
Subject to a legitimate objection by the applicant, deletion takes place after a period of six months so that we can answer any follow-up questions relating to the application and comply with our obligations to provide evidence under equal treatment legislation.
Invoices relating to any reimbursement of travel expenses will be archived in accordance with applicable tax regulations.
Contact
When contacting us—for example via contact form, email, telephone or social media—the information provided by the user is processed for the purpose of handling and responding to the inquiry pursuant to Art. 6(1)(b) GDPR in the context of contractual/pre-contractual relationships and Art. 6(1)(f) GDPR for other inquiries.
User information may be stored in a Customer Relationship Management system (“CRM system”) or a comparable inquiry management system.
We delete inquiries when they are no longer required. We review the necessity of retaining them every two years. Statutory archiving obligations also apply.
Online Presence on Social Media
We maintain online presences within social networks and platforms in order to communicate with customers, prospective customers and users active on those platforms and to inform them about our services.
When accessing the respective networks and platforms, the terms and conditions and data processing policies of the respective operators apply.
Unless otherwise stated in this Privacy Policy, we process users’ data where they communicate with us through these social networks and platforms, for example by posting content on our online presences or sending us messages.