Data Protection Policy
We are very pleased that you are interested in our website – and thus in our company. The protection of your private rights and freedoms is important to us; we only use your data for the purposes intended. Since it is important to us that you know at all times to what extent we collect, use and, if necessary, pass your data onto third parties, we will subsequently inform you in detail about the processing of your personal data (collected via our website).
In principle, you can use our pages without providing any data; if there are exceptions for selected services, we will explain these in the following chapters. We will not process data without a legal basis without your informed consent.
When processing personal data, we strictly adhere to the requirements of the EU Data Protection Regulation (GDPR) and, if necessary, other data protection regulations.
Name and Address of the data controller
Knotique GmbH
Kühnehöfe 7 a
22761 Hamburg
Phone: 015788425409
E-Mail: hello@knotique.de
Website: www.knotique.de
Chapter III of the EU Data Protection Regulation (GDPR) provides for extensive rights for data subjects, which we will explain to you below with regard to the processing of your personal data:
1. The right to be informed
This specification applies in particular to the following data processing details:
2. The right of rectification
If necessary, we will correct faulty data immediately if you inform us about the circumstance accordingly.
3. Right to deletion (right to be forgotten)
If the processing is no longer necessary and one of the following conditions is fulfilled:
As part of the deletion request, we may pass on your request to those third parties to whom your data was previously transferred.
4. The right to restriction of processing
Provided one of the following conditions is met:
5. The right to data portability
As long as it is technically possible and the rights and freedoms of other persons are not affected, we will – at your request – transfer your data to another recipient (data controller).
6. Right to object
If we collect personal data from you or have it collected and process it (on the basis of Art. 6 Para. 1(e) or (f) or Art. 9 Para. 2(a) GDPR), you have the right to object to data processing (including profiling) at any time (with effect for the future). In exceptional cases, the objection may be invalid, e.g. if we can prove compelling legitimate interests for processing that outweigh your interests, or processing serves to assert, exercise or defend legal claims. If we process your personal data for direct marketing purposes, you have the right to object to such processing at any time. This also applies to any profiling connected with such direct advertising. You also have the right to object to the processing of the data we hold about you, which is carried out by us for scientific or historical research purposes or for statistical purposes in accordance with Art. 89 para. 1 GDPR unless such processing is necessary to fulfil a task in the public interest.
7. Automated individual decision-making including profiling
If we collect personal data from you or have it collected and process it, you have the right not to be subject to decision based exclusively on automated processing – including profiling – which has a legal effect on you or significantly impairs you in a similar manner. Exceptions to this requirement apply if the decision to conclude or fulfil a contract between you and us is necessary or if you have expressly consented to the processing. In any event, we will take reasonable measures to protect your rights and freedoms and your legitimate interests, including at least the right on our part to obtain the intervention of a person to express our position and to challenge the decision.
8. Right to withdraw consent under the data protection laws
You have the right to revoke your consent to the processing of personal data at any time.
9. The right to file a legal complaint with a supervisory authority
A list of supervisory authorities in Germany can be found on the website of the Federal Commissioner for Data Protection or via the following link: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/AufsBehoerdFuerDenNichtOeffBereich/AufsichtsbehoerdenNichtOeffBereich_liste.html
General information about data processing on the website
The following information applies to the data processing on our website in general. If there are exceptions or additions to this information, these are described in detail in the respective sections.
Information on data security
We secure your personal data processed by us against loss, destruction, access, modification or distribution of your data by unauthorised persons by appropriate technical and organisational measures. We have also implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all risks is not possible.
Legal basis for processing
We process personal data according to the specifications of the GDPR, depending on the type and purpose of processing, as follows:
Where allowed by law | Specification of the GDPR |
Informed consent | Art. 6 para. 1(a) |
In performance of a contract | Art. 6 para. 1(b) |
Implementation of pre-contractual measures | Art. 6 para. 1(b) |
Fulfilment of legal obligations | Art. 6 para. 1(c) |
Protection of vital interests | Art. 6 para. 1(d) |
Safeguarding our legitimate interest | Art. 6 para. 1(f) |
Our legitimate interest
Our legitimate interest, as defined in Article 6 para. 1(f) GDPR, is based on the performance of our business activities to maintain our operability and to safeguard the employment of our employees.
General deadlines for data deletion
After elimination of the storage purpose, the retention periods are generally at least six or ten years. As a rule, the deletion of data generally takes place without delay in accordance with our deletion plan, insofar as it does not preclude any obligation to retain data, the need to fulfil a contract or a legitimate interest.
Deletion or blocking of personal data
We store your personal data only for the period necessary to fulfill the intended purpose. After elimination of the purpose and after expiration of any existing retention periods, your data will be deleted immediately. If deletion is not possible, the data will be blocked instead.
Collection of general data and information
As soon as you visit our website, our web server collects some general data and technical information – as shown in the table below:
Used browser types and versions | Correct presentation of the page content |
Used operating system, visitor origin (referrer, e.g. Google), clicked subpages | Optimization of our website content as well as our advertising |
Date and time of access to the website and the visitor’s IP address and Internet service provider | Ensuring the lasting functioning of our IT systems (for the operation of the website) and preventing misuse |
Other data and security information in case of attacks | Providing relevant information to law enforcement agencies in the event of a cyberattack |
Obligation to provide personal data
Under certain conditions (eg due to legal or contractual regulations) you have the obligation to provide us with your personal data. Examples of such processing are as follows:
Type or purpose of processing | Need |
Conclusion of a purchase contract (eg your address) | Fulfillment of the contractual obligation (eg delivery of the goods to your address) |
|
|
An infringement (ie the non-provision of the required data) would mean that the respective data processing and consequently the corresponding contract with you could not be closed. We will inform you on request in individual cases before collection of your data on whether the provision is required by law or contract or for the conclusion of the contract is necessary and what consequences for you would possibly arise from the refusal.
Shopify
For the operation of our online shop, we use a solution from the provider Shopify, i.e. the data mentioned in section 1 are processed to the Irish company Shopify International Ltd. , 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2, Ireland and partly also transferred to Shopify companies in Canada and the USA. These companies have submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. Further information on data protection at Shopify can be found at: https://www.shopify.com/legal/privacy
The legal basis for this is Art. 6 para. 1 sentence 1 (b) GDPR.
Information about specific data processing on the website
Depending on the processing, the purposes, legal basis and other information may vary. You will find the exact assignment of the information in the following chapter.
Contact form
The purpose of the processing operation | Processing and, if necessary, answering the request of the form sender |
Legal basis (in accordance with Art. 6/9 GDPR) | – Performance of a contract (Art. 6 para. 1 (b)) |
if applicable, data receiver (when passing on) | A transfer to third parties and / or to a third country does not take place. |
if applicable, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) | No data transfer to a third country takes place and is not planned. |
Where known: Duration of data retention | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity |
|
Consequences of non-compliance (if the required data are not provided) | None |
if applicable, existence of automated decision making | In this context, we refrain from purely automated decision making. |
if applicable, origin of data (if not collected directly from the data subject) | The data usually comes from the person concerned. |
if applicable, categories of personal data (if not collected directly from the data subject) | The data usually comes from the person concerned. |
if applicable, change of purpose | None |
Newsletter
The purpose of the processing operation | Providing information in the form of electronic circular mailings |
Legal basis (in accordance with Art. 6/9 GDPR) | – Informed consent (Article 6 (1) a) |
if applicable, data receiver (when passing on) or operator of the addon | Mailchimp; Operator: The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA; https://mailchimp.com/legal/ |
if applicable, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) | USA, the Rocket Science Group, LLC has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. |
Where known: Duration of data retention | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity |
|
Consequences of non-compliance (if the required data are not provided) | An infringement (ie the non-provision of the required data) would mean that the newsletter can not be delivered to you. |
if applicable, Existence of automated decision-making | In this context, we do not use automated decision making. |
if applicable, Origin of data (if not collected directly from the data subject) | The data comes from the person concerned. |
if applicable, Categories of personal data (if not collected directly from the data subject) | The data comes from the person concerned. |
Newsletter-Tracking (*) | Our newsletters contain so-called counting pixels, which is a 1×1 pixel graphic, which we integrate into our HTML-formatted emails. This graphic is downloaded from our web server, which registers the number of downloads. We use this technique for statistical purposes in order to measure the scope and success of our newsletter campaigns and to adapt our content as best as possible to your interests. This data is not passed on to third parties. You can object to the use of this technique at any time by For example, you can prevent the download of graphics from the Internet within your mail program or the receipt of HTML e-mails. When unsubscribing from our newsletter, any data assigned to the respective e-mail address will be automatically deleted. |
Registration
The purpose of the processing operation | Creation of the customer account | |
Legal basis (in accordance with Art. 6/9 GDPR) | Performance of a contract (Art. 6 para. 1 (b)) | |
Purpose of processing special categories of personal data | Creation of the customer account | |
Where known: Duration of data retention | See General deadlines for data deletion | |
if applicable, Existence of automated decision-making | In this context, we do not use automated decision making. | |
if applicable, Origin of data (if not collected directly from the data subject) | The data comes from the person concerned. | |
if applicable, Categories of personal data (if not collected directly from the data subject) | The data comes from the person concerned. | |
if applicable, Change of purpose | In principle, there is no change of purpose and is not planned. | |
Cookies
On this website we use cookies. These are small text files that are stored or saved on your computer via your Internet browser (eg Google Chrome, Safari, Firefox, Edge). This cookie may contain a so-called cookie ID – a unique identifier consisting of a string that allows mapping of web pages and servers to the storing browser. At the same time, these cookies give us information that enables us to optimize our websites to meet the needs of our visitors. We use cookies partly only for the duration of your stay on the website. All cookies on our websites contain purely technical information, not personal data. Use of our offers is possible (even if not fully functional) without cookies. Most browsers are set to automatically accept cookies. However, you can disable the storage of cookies or set your browser to notify you when cookies are sent.
Bing Ads
Purpose of the processing | Placement of advertisements in search engines and networks |
Legal basis (according to Art. 6 / 9 DSGVO) | Informed consent (Article 6 (1) a) |
If applicable, data receiver (when passing on) or operator of the addon | Microsoft Ireland Operations Limited, Attn: Data Protection Officer, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. phone: +353 (0) 1 295 3826 |
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) | A data transfer to a third country generally does not take place and is not planned. |
If known: Duration of data storage | A conversion cookie is placed on the visitor's PC and remains valid for 30 days. See General time limits for data erasure |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (if the required data are not provided) | none |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. |
if applicable, Origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
If applicable, categories of personal data (if not collected directly from the data subject) | • Which pages and functions are called up or clicked on while visiting the website (click behavior) • date as well • time of visit • generated sales |
Possible change of purpose | none |
Opt-Out | • Prevent cookies from being set • See also under cookies |
Privacy policy of the addin |
Purpose of the processing | Creation of a detailed user profile, which is linked to the social network 'Facebook' | |
Legal basis (according to Art. 6 / 9 DSGVO) | Informed consent (Article 6 (1) a) | |
If applicable, data receiver (when passing on) or operator of the addon | Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland | |
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) | A data transfer to a third country generally does not take place and is not planned. | |
If known: Duration of data storage | See General time limits for data erasure | |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none | |
Consequences of non-compliance (if the required data are not provided) | none | |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. | |
if applicable, Origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. | |
If applicable, categories of personal data (if not collected directly from the data subject) | • Which pages and functions are called up or clicked on while visiting the website (click behavior) • Surname • Age • All possible data that are revealed in the social network | |
Possible change of purpose | none | |
Opt-Out | • Log out of Facebook before visiting the website • Opt-Out button on this page • See also under cookies | |
Privacy policy of the addin | ||
Google Analytics
The purpose of the processing operation | Creation of usage profiles to optimise the cost-benefit factor on the website |
Legal basis (according to Art. 6 / 9 DSGVO) | Informed consent (according to Art. 6 para. 1 a DSGVO) |
if applicable, data receiver (for transfer) or operator of the addon | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
if applicable, intention to transfer to a third country or international organisation (incl. information on the Commission's adequacy decision or appropriate guarantees) |
|
If known: Duration of data storage | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | None |
Consequences of non-compliance (if the required data are not provided) | None |
if applicable, existence of automated decision making | In this context, we refrain from purely automated decision making. |
if applicable, origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
if applicable, categories of personal data (if not collected directly from the data subject) |
|
if applicable, change of purpose | None |
Opt-Out |
|
Privacy policy of the addin | https://www.google.de/intl/de/.../" class="redactor-autoparser-object">https://www.google.de/intl/de/... |
Google Remarketing
Purpose of the processing | Creation of personalized usage profiles, which enables the display of interest-relevant advertising |
Legal basis (according to Art. 6 / 9 DSGVO) | Informed consent (according to Art. 6 para. 1 a DSGVO) |
If applicable, data receiver (when passing on) or operator of the addon | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) | • if applicable, transfer, storage and processing in the USA |
If known: Duration of data storage | See General time limits for data erasure |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (if the required data are not provided) | none |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. |
if applicable, origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
If applicable, categories of personal data (if not collected directly from the data subject) | • Which pages and functions are called up or clicked on while visiting the website (click behavior) • Anonymous IP address assigned by the Internet service provider (ISP) • previously visited website (referrer) • visited subpages • Time spent on the website • Frequency of visit • date • Access location as well • time of visit |
Possible change of purpose | none |
Opt-Out |
|
Privacy policy of the addin | https://www.google.de/intl/de/.../" class="redactor-autoparser-object">https://www.google.de/intl/de/... |
Google Ads
Purpose of the processing | Placement of advertisements for relevant search queries in the results of the Google search engine and in the network of Google Ads participants |
Legal basis (according to Art. 6 / 9 DSGVO) | Informed consent (according to Art. 6 para. 1 a DSGVO) |
If applicable, data receiver (when passing on) or operator of the addon | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) | • if applicable, transfer, storage and processing in the USA |
If known: Duration of data storage | Conversion cookie that remains valid for 30 days |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (if the required data are not provided) | none |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. |
if applicable, origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
If applicable, categories of personal data (if not collected directly from the data subject) | • Which pages and functions are called up or clicked on while visiting the website (click behavior) • Anonymous IP address assigned by the Internet service provider (ISP) • previously visited website (referrer) • visited subpages • Time spent on the website • Frequency of visit • date • Access location as well • time of visit |
Possible change of purpose | none |
Opt-Out |
|
Privacy policy of the addin | https://www.google.de/intl/de/.../" class="redactor-autoparser-object">https://www.google.de/intl/de/... |
Youtube
Purpose of the processing | Creation of a detailed, personalized usage profile, which is linked to YouTube |
Legal basis (according to Art. 6 / 9 DSGVO) | Informed consent (according to Art. 6 para. 1 a DSGVO) |
If applicable, data receiver (when passing on) or operator of the addon |
|
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) |
|
If known: Duration of data storage | See General time limits for data erasure |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (if the required data are not provided) | none |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. |
if applicable, origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
If applicable, categories of personal data (if not collected directly from the data subject) | • Which pages and functions are called up or clicked on while visiting the website (click behavior) • Anonymous IP address assigned by the Internet service provider (ISP) • Time spent on the website • All information shared on YouTube |
Possible change of purpose | none |
Opt-Out |
|
Privacy policy of the addin | https://www.google.de/intl/de/.../" class="redactor-autoparser-object">https://www.google.de/intl/de/... |
Google Fonts
The purpose of the processing operation | Uniform representation of the font |
Legal basis (in accordance with Art. 6/9 GDPR) | – Safeguarding our legitimate interest (Art. 6 para. 1 (f)) |
If necessary, data receiver (when passing on) or operator of the addon | Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland |
If necessary, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) | Forwarding to Ireland |
Where known: Duration of data retention | Unknown |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity |
|
Consequences of non-compliance (if the required data are not provided) | None |
If necessary, Existence of automated decision-making | In this context, we do not use automated decision making. |
If necessary, Origin of data (if not collected directly from the data subject) | The data usually comes from the person concerned. |
If necessary, Categories of personal data (if not collected directly from the data subject) | IP address |
If necessary, change of purpose | None |
Opt-Out | Use a browser that does not support Google Fonts |
Privacy information of the Addin |
Google Maps
Purpose of the processing | Display of an interactive map, which enables a graphic overview of the location of the website operator |
Legal basis (according to Art. 6 / 9 DSGVO) | Protection of our legitimate interest (Article 6(1)(f)) |
If applicable, data receiver (when passing on) or operator of the addon |
|
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) | • Forwarding to Ireland • Expected to be transferred, stored and processed in the United States |
If known: Duration of data storage | unknown |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (if the required data are not provided) | none |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. |
If necessary, Origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
If applicable, categories of personal data (if not collected directly from the data subject) |
|
Possible change of purpose | none |
Opt-Out |
|
Privacy policy of the addin |
Paypal
The purpose of the processing operation | Providing a secure and convenient payment method |
Legal basis (in accordance with Art. 6/9 GDPR) | – Safeguarding our legitimate interest (Article 6 (1) (f) GDPR) |
if applicable, data receiver (when passing on) or operator of the addon | PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, Luxembourg |
if applicable, Intention to transfer to a third country or international organisation (including information on the Commission’s adequacy decision or appropriate guarantees) | For identity and / or credit checks, forwarding to business information units can take place |
Where known: Duration of data retention | See General deadlines for data deletion |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity |
|
Consequences of non-compliance (if the required data are not provided) | none |
if applicable, Existence of automated decision-making | In this context, we do not use automated decision making. |
if applicable, Origin of data (if not collected directly from the data subject) | The data comes from the person concerned. |
if applicable, Categories of personal data (if not collected directly from the data subject) | name |
if applicable change of purpose | A change of purpose does not take place and is not planned. |
Opt-out | Reject the payment method |
Privacy information of the add-on | https://www.paypal.com/de/webapps/mpp/ua/privacy-full |
Sofortüberweisung
Purpose of the processing | Providing a secure and convenient payment method |
Legal basis (according to Art. 6 / 9 DSGVO) | Safeguarding our legitimate interest (Article 6 (1) (f) GDPR) |
If applicable, data receiver (when passing on) or operator of the addon |
|
If applicable, intention of forwarding to a third country or international organisation (incl. information on the Commission's adequacy decision or suitable guarantees) |
|
If known: Duration of data storage | unknown |
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessity | none |
Consequences of non-compliance (if the required data are not provided) | none |
Existence of an automated decision making process, if applicable | In this context, we refrain from a purely automatic decision-making process. |
if applicable, Origin of data (if not collected directly from the data subject) | Usually the data originates from the data subject himself. |
If applicable, categories of personal data (if not collected directly from the data subject) |
|
Possible change of purpose | none |
Opt-Out |
|
Privacy policy of the addin | https://www.klarna.com/sofort/... https://www.sofort.com/payment... |