Privacy policy

To what extent is personal data processed?

1. Collection of personal data when you visit our website

a) Log files

When using the Neofita Design website for information purposes only, so when you do not log in to use the website, register or otherwise provide information, we collect the data that your browser transmits to our server. This includes in particular:

  • IP address,
  • date and time of the request,
  • time zone difference to Greenwich Mean Time (GMT),
  • name of the requested file,
  • access status/HTTP status code,
  • volume of data transferred,
  • the page from which you came to visit us,
  • your operating system and its interface,
  • your browser type and the language and version of the browser software,
  • a report of successful retrieval

The data is technically necessary for us to display our website to you. It is also evaluated to make the website user-friendly and to ensure stability and security. 

b) Cookies and similar technologies

In addition, we also use cookies on our website. Cookies are small text files that are assigned to your browser and stored on your device. Through them, certain information flows to the place that sets the cookie, such as settings or data for exchange with the system. This helps us to make our website more user-friendly and effective overall. The legal bases for this are Art. 6(1) Sentences 1(a) and (f) GDPR. Cookies cannot execute programs or transmit viruses to your device.

Our website uses the following types of cookies:

  • session (transient) cookies,
  • long-term (persistent) cookies,
  • third-party cookies.

Session cookies store what’s called a session ID, which can be used to assign different requests of your browser to a common session. This allows your device to be recognised when you return to our website. For example, this lets you store certain information you have entered (such as log-in information, language settings) in such a way that you do not have to repeat it constantly. Session cookies are automatically deleted when you log out or close your browser.

Long-term cookies remain on your device for the time being, so that we can recognise your browser on your next visit and we can, for example, assign your preferred information and settings. Long-term cookies are automatically deleted after a specified period, which may vary depending on the cookie.

When you visit our website, our partner companies also store third-party cookies on your device. The cookies contain information about how our website is used, e.g. which pages and products were visited. The data is collected in a pseudonymised form by assigning an identification number, which is not combined with any other personal data you may have provided to us.

You can delete cookies in your browser settings at any time or prevent them from being stored, although the latter may result in a restriction of the functionality of our website for you. In the relevant sections of this Privacy Policy, we explain which technologies that are comparable to cookies are used on our website and how you can object to the use of cookies and other technologies with the individual third-party providers.

2. Ordering from Neofita Designs / User Account

a) If you want to order something in our online shop, it is necessary for the conclusion of the contract that you give us the personal data we need to process the order. The mandatory data required to process the contract is marked as such; all other data you provide is voluntary. You can either enter your data only once for the order or use your email address to set up a password-protected user account with us, in which your data can be stored for later purchases until you revoke your consent. You can deactivate or delete the data and the user account at any time via the account.

To prevent unauthorised access to your personal data by third parties, the order process is encrypted using TLS technology.

When we process the data provided by you to process your order, this includes, for example, individual customer service. In the course of order processing, we pass on personal data to one of our production companies within the group, to a shipping company commissioned by us and (with the exception of PayPal).

Payment via PayPal is processed by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (“PayPal”). For information about data protection at PayPal, please refer to PayPal’s privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-prev?locale.x=en.

In the case of trackable parcels, we also pass on your order and address data to our couriers, to make it possible to track your parcel and to inform you about delivery deviations or delays, for example.

The legal bases for the processing of personal data as part of order processing are Art. 6(1) Sentences 1(b) and (f) GDPR. Due to commercial and tax regulations, we are obliged to store your order, address and payment data for a period of ten years.

b) During the order process we also conduct a fraud prevention check via our Natwest bank, which involves using your IP address to carry out a geolocalisation and compare your data with previous experience. This may mean that an order cannot be placed with the selected payment method. Our aim in this regard is to prevent any abuse of your chosen payment method by third parties and to protect ourselves from payment defaults. The legal basis for the processing is Art. 6(1) Sentence 1(f) GDPR.

Since this involves automated decision-making, you have the right to challenge the decision (in this case the refusal of a certain payment method) and have the decision reviewed by a person. In such cases we ask that you contact us using the contact details mentioned in Section 1. Please note that the payment method may have been rejected due to a typing error and you should, therefore, check what you have entered again during the order process if necessary.

c) During the ordering process we use Google Maps Autocomplete, a service of Google LLC (“Google”). This allows an address you start typing to be completed automatically, avoiding delivery errors. Google sometimes conducts a geolocalisation using your IP address and receives the information that you have retrieved the corresponding subpage of our website. In addition, the data referred to in Section 2.1 is transmitted. This is regardless of whether you have a Google account and are logged in. Once you are logged in to your Google Account, the information will be directly associated with your account. If you do not want this assignment to occur, you must log out before entering your address. Google stores your data as user profiles and uses it (even in the case of users who are not logged in) for the purposes of advertising, market research and/or the needs-oriented design of its own website. Google also processes your personal data in the USA and has subjected itself to the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). You can object to Google creating such user profiles. For more information about the purpose and scope of data processing by Google and about protecting your privacy, please refer to Google’s Privacy Policy: https://policies.google.com/privacy?hl=en. The binding terms of use for Google Maps/Google Earth can be found here: https://www.google.com/intl/en_US/help/terms_maps.html. Third-party provider information: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

The legal basis for the processing is Art. 6(1) Sentence 1(f) GDPR.

d) After you place an order, we will process your order and address data to send you a personalised email asking you to rate our products. By obtaining ratings, our aim is to improve our services and adapt them to our customers’ wishes. We use the feedback software of Judge.me reviews.

For the purpose of sending the feedback email (and in the event that a moderation or conciliation procedure is conducted via Judge.me following negative feedback), we pass on your email address, name, order number, product types and a unique ID to Judge.me for identification purposes and in order to generate a feedback link.

The legal basis for the processing is Art. 6(1) Sentence 1(f) GDPR. If you no longer want your data to be used for this purpose, you can object to this at any time. Just click on the unsubscribe link included with each email or send a message using the contact details provided under Section 1.

e) We also use Google Customer Reviews, a service of Google Ireland Ltd. (“Google”), through which we receive feedback about us as a seller and about our products. This allows us to improve our services and adapt them to our customers’ wishes. The legal basis is Art. 6(1) Sentence 1(f) GDPR. After placing an order, you can give Google permission to use your email address to request a review. In the event that data is also transferred to a Google server in the USA, Google LLC has subjected itself to the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework/). You can revoke your consent to the use of your data at any time by clicking on the unsubscribe link contained in the emails from Google. For more detailed information about the purpose and scope of data processing by Google and about protecting your privacy, please refer to Google’s Privacy Policy: https://policies.google.com/privacy?hl=en. Third-party provider information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, fax: + 353 (1) 436 1001.

3. Communication with Neofita Designs

a) Establishing contact

If you contact us via a contact form, email, social media, we process the data provided by you for the purpose of processing your enquiry and – only in the legally permissible cases when communicating with entrepreneurs – for advertising purposes.

The legal basis for the processing is Art. 6(1) Sentence 1(f) GDPR. If the aim of establishing contact is to conclude a contract, then an additional legal basis is Art. 6(1) Sentence 1(b) GDPR.

b) Blog

In our blog, where we publish various articles on topics related to our activities, you can post public comments. Your comment will be published along with your chosen username. We recommend using a pseudonym instead of your real name. It is necessary to provide a username and email address, while all other information is voluntary. The necessary information is processed to run the Forum. We need your email address to contact you if a third party should complain that your comment is unlawful. We reserve the right to delete comments if third parties complain that they are unlawful. The legal basis for the processing is Art. 6(1) Sentence 1(f) GDPR.

c) Forum

With the exception of a few sections, our Forum can be read without the need to register. If you wish to actively participate in the Forum under your chosen username, you must log in using your Neofita Designs user account access data. To open a Neofita Designs user account, only your email address and a password are required. We process your activities (public posts, private messages, likes, profile information, activity logs) and your IP address in order to operate the Forum. The legal basis is Art. 6(1) Sentence 1(f) GDPR. If you deactivate or delete your user account, your public posts will continue to be visible. If you would like your public posts to be deleted, please contact us using the contact details provided in Section 1. When writing a comment and in the Forum settings (under “Preferences” – “Emails” and “Notifications”), you can specify in which cases and to what extent you would like to be notified by email about new activities in the Forum. You can unsubscribe again at any time, either in the Forum settings or by clicking on the unsubscribe link contained in the respective notification email.

4. Processing of data for web analytics

a} Googole Analytics

Our website uses Google Analytics, a web analytics service provided by Google Ireland Ltd. (“Google”). Google uses cookies (see Section 2.1 b), which enable an analysis of your use of our website. The information generated by the cookie about usage is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymisation on our website, your IP address will first be shortened by Google within the Member States of the European Union or in other states party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide us with other services relating to website and internet use.

The IP address transmitted by your browser in the context of Google Analytics will not be combined with other data held by Google.

You can prevent the storage of cookies by selecting the appropriate settings in your browser software; however, please note that if you do this you may not be able to use the full functionality of our website. You can also prevent the data generated by the cookie and relating to your use of the website (including your IP address) from being recorded and processed by Google by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout/. Specifically in the case of mobile devices, you can prevent Google Analytics from recording data by clicking here: Disable Google Analytics. This will place an opt-out cookie which prevents recording when you visit our website in future. Please note that if you delete all cookies on your device, this opt-out cookie will also be deleted; in this case, if you still wish to object then you must place the cookie again using the above button. The opt-out cookie is set per top-level domain, per browser and per device and only prevents the recording of data for this website.

This website uses Google Analytics with the “_anonymizeIp()” extension. Consequently, IP addresses are further processed in shortened form, so that any personal association with the data subject can be ruled out. As far as the data collected about you relates to you personally, that association is therefore ruled out immediately and the personal data thus erased without delay.

We use Google Analytics to analyse and regularly improve the use of our website. The statistics this yields allow us to improve our website and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Google LLC has subjected itself to the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). The legal bases for our use of Google Analytics are Art. 6(1) Sentences 1(a) and (f) GDPR.

Third-party provider information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, fax: + 353 (1) 436 1001. See also the terms of use (https://www.google.de/analytics/terms/gb.html) and privacy overview (https://support.google.com/analytics/answer/6004245?hl=en) for Google Analytics as well as Google’s privacy policy: https://policies.google.com/privacy?hl=en.

b) Adobe Analytics

To allow us to analyse and regularly improve the use of our website, our website also uses the Adobe Analytics web analytics service. The statistics this yields allow us to improve our website and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Adobe has subjected itself to the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). The legal bases for our use of Adobe Analytics are Art. 6(1) Sentences 1(a) and (f) GDPR.

The analysis involves storing cookies (see Section 2.1 b) on your device. The information collected in this way is stored on servers, including in the USA. We would like to point out that if you prevent the storage of cookies, you may not be able to use this website in its entirety. You can adjust your browser settings to prevent the storage of cookies. You can also prevent Adobe Analytics from recording your data on this website by clicking here: Disable Adobe Analytics. This will place an opt-out cookie which prevents recording when you visit our website in future. Please note that if you delete all cookies on your device, this opt-out cookie will also be deleted; in this case, if you still wish to object then you must place the cookie again using the above button. The opt-out cookie is set per top-level domain, per browser and per device and only prevents the recording of data for this website. How to prevent the recording of your data on other websites is explained on the respective sites and at https://www.adobe.com/privacy/opt-out.html.

Our website uses Adobe Analytics with the settings “Before Geo-Lookup: Replace visitor’s last IP octet with 0” and “Obfuscate IP-Removed”, which removes the last octet from your IP address and replaces it with a generic IP address, i.e. one that can no longer be assigned. Any personal connection can therefore be ruled out.

Third-party provider information: Adobe Systems Software Ireland Limited, 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland; privacy@adobe.com; Adobe’s privacy policy: https://www.adobe.com/privacy/policy.html.

5. Advertising activities by Neofita Designs

a) Newsletter

If you register separately for our newsletter via our website and give us your consent, we will use your email address to send you regular emails about product offers, discounts and contests. 

When you register for our newsletter, we use the so-called double opt-in procedure. This means that after you register we will send you an email to the email address you provided, in which we ask you to confirm that you would like to receive the newsletter. If you do not confirm your registration, your information will be automatically deleted after one month. On the other hand, if you confirm the newsletter subscription, we will save your email address for the purpose of sending you the newsletter until you unsubscribe from the newsletter.

You can revoke your consent to the sending of the newsletter at any time (without this affecting the lawfulness of the processing up to the point of revocation). You can declare your revocation by clicking on the link provided in every newsletter email, by emailing neofitadesigns@gmail.com or by sending a message to the contact details provided in Section 1.

The legal bases for the processing are Art. 6(1) Sentences 1(a) and (f) GDPR.

b) Product recommendations

As a Neofita Designs customer, so if you order something in our online shop (see Section 2.2 a), we process the email address you provide in order to send you regular email recommendations for products that might be of interest to you based on your previous orders from us. We also use your name to allow us to personalise these emails. 

You receive these product recommendations because you did not object to the use of your email address for this purpose by removing the corresponding check mark during the order process. If you subsequently no longer wish to receive product recommendations or any advertising messages, you can object at any time without incurring any costs other than the transmission costs at the basic rates. Just click on the unsubscribe link included with each email, send a message using the contact details provided under Section 1 or – if you have a user account with us – adjust your newsletter settings accordingly (“Account settings” - “Newsletter subscriptions”).

6. Who is responsible for data processing?

The service provider and party responsible for processing personal data (‘controller’) is Neofita Designs. You can reach us using the following contact details:

Email: info@neofitadesigns.com