Data Protection

Dear website user,

We would like to inform you about the processing of your personal data by us and about your data protection rights.

 

I. Name and Contact Information of the Controller

As the controller within the meaning of Article 4 No. 7 GDPR, the responsible party for the legality of the processing of your personal data on this website is:

 

Healthygarden GmbH,

represented by the managing director Dominik Sperling

Volksdorfer Weg 186,

22393 Hamburg,

Germany

Tel. +49 (0) 40 63 91 88 90

Email: hello@omura.com

II. Data processing on the website.

1.Collection of personal data during the informational use of the website

During the mere informational use of the website, meaning that you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data, which is technically necessary for us to display our website and ensure its stability and security:

  • IP address
  • Date and time of the request
  • Time zone difference to Greenwich Mean Time (GMT)
  • Content of the request (specific page)
  • Access status / HTTP status code
  • Amount of data transferred
  • Website from which the request originates
  • Browser
  • Operating system and its interface
  • Language and version of the browser software

We store the data in server log files and delete it after 72 hours. The legal basis is Art. 6(1)(f) of the General Data Protection Regulation (GDPR).

The web server is hosted by the following service provider:

Domainfactory GmbH

Oskar-Messter-Str. 33

85737 Ismaning

In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive and associated with the browser you are using, through which certain information flows to the entity setting the cookie (in this case, us). Cookies cannot execute programs or transmit viruses to your computer. They serve to make the overall Internet offering more user-friendly and effective. The legal basis is Art. 6(1)(f) of the GDPR. Cookies also serve to simplify the order process by storing settings (e.g., remembering the content in our virtual shopping cart and a virtual wish list for a later visit to our website). The legal basis is Art. 6(1)(b) of the GDPR.

This website uses transient cookies and persistent cookies.

Transient cookies are automatically deleted when you close the browser. This includes session cookies in particular. They store a so-called session ID, which can be used to assign various requests from your browser to the shared session. This allows your computer to be recognized when you return to our website. The session cookies are deleted when you log out or close the browser.

Persistent cookies are automatically deleted after a predetermined period, which may vary depending on the cookie. You can delete the cookies at any time in the security settings of your browser.

You can configure your browser settings according to your preferences, for example, to reject the acceptance of third-party cookies (e.g., Google Analytics) or all cookies. We would like to point out that in this case you may not be able to use all functions of this website.

 2. Processing of personal data when ordering in our webshop

a) Guest orders

If you wish to place an order in our webshop, it is necessary for the conclusion of the contract that you provide your personal data, which we require for the processing of the contract. Mandatory information necessary for the processing of the contract is marked separately, while additional information is voluntary. We process the data you provide for the purpose of processing your order. The legal basis for the processing of your data is Article 6(1)(b) of the General Data Protection Regulation (GDPR).

You are neither legally nor contractually obliged to provide your personal data. However, without the data required for the processing of your order, you will unfortunately not be able to place an order in our webshop.

b) Customer Account

Alternatively, to guest ordering, you have the option to voluntarily create a customer account, through which we can store your data for future purchases. When creating a customer account, the data you provide will be stored revocably. We process the data for the following purposes:

  • Processing orders
  • Overview of your past orders and easy reordering
  • Management of your wish list
  • Management of your account information
  • Storage of your payment methods
  • Overview of your product reviews
  • Management of your newsletter subscription

The legal basis for data processing is Art. 6(1)(f) of the General Data Protection Regulation (GDPR). Our legitimate interest is to provide you with good service when using our online offers. If data processing is necessary for the fulfillment of an order or the initiation of a contract, Art. 6(1)(b) GDPR serves as the corresponding legal basis.

You can modify the data stored about you at any time. You can delete your customer account at any time in the customer area under "Account Information". You can also contact the contact details mentioned in Section I. to request the deletion of your customer account. If the data is necessary for the fulfillment of a contract or the implementation of pre-contractual measures, premature deletion of the data is only possible to the extent that contractual or legal obligations do not conflict with the deletion.

You are neither legally nor contractually obligated to provide your personal data in a customer account. You are welcome to place an order as a "guest" (see Section II. 2. a)).

 aa) Registration and Log-in

You can register for our customer account using your first and last name and your email address. You can log in using your access credentials (email address and password). At the time of registration, the following data will also be stored: date and time of registration, date, and time of the last login. The legal basis for processing is Art. 6(1)(a) of the GDPR (consent). By clicking the corresponding checkbox within the registration process, you consent to the processing of your data for the purpose of registering for our customer account. You can revoke your registration at any time by deleting your customer account (see Section II.2.a)) or by contacting the contact details mentioned in Section I. Please note that the lawfulness of the processing carried out based on your consent prior to revocation remains unaffected.

bb) Log-in via Facebook (Facebook Connect)

Through a plug-in integrated into our website, you have the option to expedite the registration and ordering process by logging in with your existing Facebook account. To log in, you will be redirected to Facebook's page, where you can sign in using your user credentials.

Once you have logged in, our server establishes a connection with the Facebook servers. Data that you have designated as viewable on Facebook, such as your Facebook name, email address associated with Facebook, user ID, birthday, gender, profile picture, cover photo, friend list, likes, as well as your country and language, will be transmitted to us. There is also a reciprocal exchange of data. We send information to Facebook about your browsing behavior (e.g., products you showed interest in, information you accessed, and products you purchased from us).

The legal basis for data processing within the scope of Facebook Connect is Art. 6(1)(a) of the General Data Protection Regulation (GDPR) (consent). By clicking the corresponding checkbox, you activate the "Log in with Facebook" button and consent to the data processing. For this, you can contact the contact details mentioned in Section I. Please note that the lawfulness of the processing carried out until the revocation of your consent remains unaffected.

Contact information for Facebook:

Facebook Ireland Ltd.,

4 Grand Canal Square,

Grand Canal Harbour,

Dublin 2, Ireland.

Facebook is subject to the EU-US Privacy Shield. For more information, please visit www.privacyshield.gov.

For more information on Facebook Connect and privacy settings, please refer to Facebook's privacy policy and terms of use at www.facebook.com.

 cc) Log-in via Google (Google Sign In)

Through a plug-in integrated into our website, you have the option to expedite the registration and ordering process by logging in with your existing Google account. To log in, you will be redirected to Google's page, where you can sign in with your user credentials.

Once you have logged in, our server establishes a connection with Google servers. This links your Google profile to our website, granting us access to the data you have provided to Google. This includes your Google name, user ID, email address associated with your Google account, age, and gender.

The legal basis for data processing in the context of Google Sign In is Article 6(1)(a) of the General Data Protection Regulation (GDPR) (consent). By clicking on the corresponding checkbox, you activate the "Sign in with Google" button and give your consent to the data processing. You have the option to withdraw your consent at any time by contacting the contact details mentioned in Section I. Please note that the lawfulness of the processing carried out based on your consent prior to withdrawal remains unaffected.

Contact information for Google:

Google Dublin, Google Ireland Ltd.

Gordon House, Barrow Street, Dublin 4, Ireland

Google has adhered to the EU-US Privacy Shield. For further information, please visit www.privacyshield.gov.

For more information about Google Sign In and privacy settings, please refer to Google's privacy policy and terms of service at www.google.com.

c) Transfer of personal data for processing your order

For the purpose of contract processing, we store your data in an ERP software hosted by the following service provider:

Next Tröber Europe GmbH & Co. KG

Volksdorfer Weg 186

22393 Hamburg

Germany

Your data will be transferred to the shipping company responsible for delivering the goods, to the extent necessary for the delivery of the products:

General Logistics Systems Germany GmbH & Co. KG (GLS)

GLS Germany-Straße 1-7

36286 Neuenstein

United Parcel Service Deutschland Inc. & Co. oHG (UPS)

Ursulum 9

35396 Gießen

The legal basis for the transfer to any of the mentioned providers is Article 6(1)(b) of the General Data Protection Regulation (GDPR).

 

Depending on the payment method you choose, we will transfer your data for payment processing to the following providers:

 

 

As a payment service provider, we use the following service provider:

 

Mollie B.V. 

Keizersgracht 126

1015CW Amsterdam, Netherlands

For more about the data processed through the use of Mollie, Please read Mollies privacy statement.

 

Payment method Klarna

In order to offer you Klarna’s payment methods, we might in the checkout pass your personal data in the form of contact and order details to Klarna, in order for Klarna to assess whether you qualify for their payment methods and to tailor those payment methods for you. Your personal data transferred is processed in line with Klarna’s own privacy notice.

 

3. Contact Form

When you contact us through our contact form or via email, the data you provide will be processed to handle your inquiry.

To respond to your contact request through the contact form, it is necessary for you to provide your personal data, which we require to address your inquiry. These details are marked as mandatory. Any additional information is optional.

We process your personal data collected through the contact form or via email to respond to your contact request. The legal basis for this processing is Art. 6(1)(f) of the General Data Protection Regulation (GDPR). We have a legitimate economic interest in contacting potential customers and interested parties through the contact form or via email. Our contact form is a service provided by us, designed to facilitate quick and straightforward communication for you as a (potential) customer. We aim to provide you with excellent customer service. Frequently, contact inquiries serve the purpose of initiating a contractual relationship. Therefore, Article 6(1)(b) of the GDPR serves as the corresponding legal basis.

You are not legally or contractually obligated to provide your data. However, we can only respond to your contact request if you provide the aforementioned data marked as mandatory.

 

4. Newsletter Subscription

With your consent, you can subscribe to our newsletter, through which we will inform you about our current interesting offers for our products in our webshop.

For the newsletter subscription, we use the so-called double opt-in procedure. This means that after your registration, we will send you an email to the provided email address, in which we ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration, your information will be automatically deleted. Additionally, we store the IP addresses and timestamps of your registration and confirmation. The purpose of this procedure is to be able to prove your registration and, if necessary, clarify any possible misuse of your personal data.

The mandatory information for sending the newsletter is solely your email address. Providing additional, separately marked data is voluntary and is used to address you personally. After your confirmation, we store the data you have provided for the purpose of sending the newsletter. The legal basis is Art. 6(1)(a) of the General Data Protection Regulation (GDPR) (consent).

You can revoke your consent to receive the newsletter and unsubscribe at any time. You can do this by clicking on the link provided in each newsletter email, using the form provided on our website under "Unsubscribe from the Newsletter," or by sending a message to the contact details mentioned above. The revocation will only apply to the future; this means that the lawfulness of the data processing based on the consent prior to the revocation will not be affected.

You are neither legally nor contractually obliged to provide your email address for the purpose of sending the newsletter. However, we can only send you our newsletter if you provide your email address.

For the newsletter dispatch, we use the newsletter tool provided by the following service provider:

HubSpot

2nd Floor 30 North Wall Quay

Dublin 1, Ireland

 

5. Customer Reviews

We appreciate it if you review our products on our website. Your review will be published with the "nickname" you provided. We recommend using a pseudonym instead of your real name. When you submit a review, we store your IP address, which we delete after one week. The storage is necessary for us to defend ourselves against liability claims in the event of potential unlawful content being published. The legal basis for this is Art. 6(1)(f) of the General Data Protection Regulation (GDPR). The reviews are not checked before publication. We reserve the right to delete reviews if they are contested as unlawful by a third party.

 

6. Social Media

a) Links to our social media profiles

On our website, we have embedded links to our social media profiles (Facebook, Instagram, YouTube). When you visit our website and click on the link, you will be directed to the respective profile where we provide information about data processing.

b) AddToAny - Bookmark & Share

On our website, we use the AddToAny service. Through this service, we offer you the opportunity to interact with social networks and other users, allowing us to improve our offerings and make them more interesting for you as a user. The legal basis for this is Article 6(1)(f) of the General Data Protection Regulation (GDPR).

Through these plugins, your internet browser establishes a direct connection to the servers of AddToAny and, if applicable, the selected social network. This connection is established when you visit our pages. The recipients of this information are informed that you have accessed the corresponding website of our online offerings, along with the data mentioned in Section II.1 "Collection of personal data during informational use of the website." This information is processed on the servers of AddToAny in the United States. When using AddToAny, cookies are employed. AddToAny can track which other pages with AddToAny plugins and which social networks you visit through these cookies. If you send content from our website to social networks, a connection can be established between your visit to our website and your user profile on the respective network. We have no control over the data collected and the processing operations, nor do we have full knowledge of the extent of data collection, the purposes of processing, or the retention periods. We also do not have information about the deletion of data collected by the plugin provider.

The plugin provider stores this data as user profiles and uses it for advertising, market research, and/or customized design of its website. Such evaluation is carried out, in particular (even for users who are not logged in), to provide personalized advertising and inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, but you must contact the respective plugin provider to exercise this right.

If you do not wish to participate in this process, you can opt-out directly through this link: http://optout.networkadvertising.org/?c=1

For further information on the purpose and scope of data collection and its processing by AddToAny, as well as additional information on your rights and privacy settings, please visit www.addtoany.com.

 

7. Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses "cookies," which are text files stored on your computer that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is generally transmitted to and stored on a Google server in the United States. However, if IP anonymization is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before transmission. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website activity and internet usage to the website operator.

You can prevent the storage of cookies by adjusting the settings of your browser software; however, please note that if you do this, you may not be able to use all the features of this website to their full extent. Furthermore, you can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en.

This website uses Google Analytics with the extension "_anonymizeIp()". As a result, IP addresses are further processed in a shortened form, thereby excluding any direct association with individuals. If any data collected about you is personally identifiable, it will be immediately excluded and the personal data will be promptly deleted.

We use Google Analytics to analyze and improve the use of our website on a regular basis. Through the statistics obtained, we can improve our offering and make it more interesting for you as a user. For exceptional cases in which personal data is transferred to the United States, Google has submitted to the EU-US Privacy Shield. For more information, please visit www.privacyshield.gov. The legal basis for the use of Google Analytics is Art. 6(1)(f) of the General Data Protection Regulation (GDPR).

This website uses Google Analytics for cross-device analysis of visitor traffic conducted via a user ID.

Contact details of Google:

Google Dublin, Google Ireland Ltd.

Gordon House, Barrow Street, Dublin 4, Ireland

Fax: +353 (1) 436 1001

The terms of use and privacy policy can be found on the Google website (www.google.com).

 

8. Google Adwords Conversion Tracking

We use Google Adwords to promote our attractive offers through advertising materials (known as Google Adwords) on external websites. By analyzing the data from advertising campaigns, we can determine the success of individual advertising measures. Possible advertising successes (known as conversions) may include signing up for our newsletter or ordering a product. Our aim is to display advertisements that are of interest to you, make our website more appealing to you, and achieve a fair calculation of advertising costs. The legal basis for data processing is Article 6(1)(f) of the General Data Protection Regulation (GDPR).

To measure your actions as a result of an Adwords click, a combination of cookies and measurement points (known as measurement pixels) is necessary on our website. The cookie is set when you click on the Google Adwords ad, provided your browser settings allow it. If you then go through our order process and complete it, a measurement pixel is integrated on the confirmation page ("Thank you for your purchase"). The content of the cookie is read, and the Adwords system receives feedback on which browser (represented by a cookie ID) achieved a conversion. In addition to the cookie ID, additional variables can be passed through the Adwords pixel (e.g., shopping cart value).

We only receive statistical evaluations from Google. Based on these evaluations, we can identify which advertising measures are particularly effective. We do not receive any further data from the use of advertising materials, and in particular, we cannot identify you based on this information.

Due to the marketing tools used, your browser automatically establishes a direct connection to Google's server. We have no control over the scope and further use of the data collected by Google through the use of this tool. To the best of our knowledge, we inform you as follows: By incorporating AdWords Conversion, Google receives the information that you have accessed the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can associate the visit with your account. Even if you are not registered with Google or not logged in, it is possible that the provider may obtain and store your IP address.

You can prevent participation in this tracking procedure in various ways: a) by adjusting your browser software accordingly, in particular, suppressing third-party cookies will prevent you from receiving ads from third-party providers; b) by deactivating cookies for conversion tracking by setting your browser to block cookies from the domain "www.googleadservices.com," https://www.google.de/settings/ads, although this setting will be deleted if you delete your cookies; c) by deactivating interest-based ads from providers that are part of the self-regulatory campaign "About Ads" via the link http://www.aboutads.info/choices, although this setting will be deleted if you delete your cookies; d) by permanently deactivating it in your browsers Firefox, Internet Explorer, or Google Chrome using the link http://www.google.com/settings/ads/plugin. Please note that in this case, you may not be able to fully utilize all the functions of this offer.

Contact details of Google:

Google Dublin, Google Ireland Ltd.

Gordon House, Barrow Street, Dublin 4, Ireland

Fax: +353 (1) 436 1001

You can find the terms of use and the privacy policy on Google's website (www.google.de). Google is subject to the EU-US Privacy Shield. For more information, please visit www.privacyshield.gov.

 

9. Facebook Conversion Tracking

With Facebook Conversion Tracking, we aim to achieve transparency regarding the causes of certain advertising successes (referred to as "events"). Through Facebook Conversion Tracking, we can determine if certain advertising successes on our website occur as a result of clicking on a Facebook ad. Possible advertising successes (referred to as "conversions") may include signing up for our newsletter or placing an order for a product. The purpose of this tracking is to display advertisements that are of interest to you, make our website more appealing to you, and achieve fair calculation of advertising costs. The legal basis for data processing is Article 6(1)(f) of the General Data Protection Regulation (GDPR).

To measure your actions on our website as a result of interacting with a Facebook ad, a combination of cookies, login data, and measurement points (referred to as "measurement pixels") on our website is necessary. The cookie is set in the browser when logging into Facebook. If you use Facebook on multiple devices or browsers with the same login, these devices and browsers can be associated with you. If you then go through our ordering process and complete it, a measurement pixel of the Facebook Conversion Tracking (referred to as an "event" by Facebook) is integrated on the confirmation page ("Thank you for your purchase"). The cookie content is read, providing feedback to the Facebook system about which user login has achieved a conversion. In addition to the cookie ID, additional event parameters can be passed (e.g., shopping cart value). Through cross-device tracking, it is possible, for example, to associate an advertising success on a computer with a previous advertising contact on a smartphone.

We only receive statistical evaluations provided by Facebook. Based on these evaluations, we can identify which advertising measures are particularly effective. We do not receive any further data from the use of advertising materials, and in particular, we cannot identify you based on this information.

Deactivation is possible for logged-in Facebook users at https://www.facebook.com/settings/?tab=ads#_.

Contact information for Facebook:

Facebook Ireland Ltd.,

4 Grand Canal Square,

Grand Canal Harbour,

Dublin 2, Ireland.

You can find the terms of use and privacy policy on Facebook's website (www.facebook.com). Facebook is subject to the EU-US Privacy Shield. For more information, visit www.privacyshield.gov.

 

10. Google Remarketing

On our website, we use Google Remarketing. The purpose of this is to significantly increase the likelihood of making a purchase by targeting users who have previously visited our website. With the help of Google Remarketing, you will be shown ads within the Google Display Network to reach you again in a targeted manner, with the aim of increasing advertising recall or triggering repeat visits to the advertised website. The legal basis for data processing is Art. 6(1)(f) of the General Data Protection Regulation (GDPR).

This is done by means of cookies stored in your browser, through which Google captures and analyzes your user behavior when visiting various websites (see Section II.7). In this way, Google can determine your previous visit to our website.

According to Google's own statements, the data collected within the scope of remarketing is not merged with your personal data, which may be stored by Google. Google specifically employs pseudonymization.

Contact information for Google:

Google Dublin, Google Ireland Ltd.

Gordon House, Barrow Street, Dublin 4, Ireland

Fax: +353 (1) 436 1001

You can find the terms of use and privacy policy on the Google website (www.google.com). Google is committed to the EU-US Privacy Shield. For more information, please visit www.privacyshield.gov.

 

11. Google Fonts

On this website, we incorporate the fonts ("Google Fonts") provided by Google. These Google Fonts are stored locally on the web server. This means that no data is transmitted to Google when loading our website. The use of Google Fonts is in the interest of a consistent and visually appealing presentation of our online offerings. The legal basis for this processing is Art. 6(1)(f) of the General Data Protection Regulation (GDPR). You have the option to object to the processing of your data: https://adssettings.google.com/authenticated.

Google has certified its adherence to the EU-US Privacy Shield. Further information can be found at www.privacyshield.gov.

Contact information for Google:

Google Dublin, Google Ireland Ltd.

Gordon House, Barrow Street, Dublin 4, Ireland

Fax: +353 (1) 436 1001

The terms of use and privacy policy can be found on the Google website (www.google.com).

 

12. Google reCaptcha

We use the Google reCaptcha service to determine whether a human or a computer is making a specific input in our contact or newsletter form. Google checks the following data to determine whether you are a human or a computer: IP address of the device used, the webpage you visit on our site where the Captcha is embedded, the date and duration of the visit, the detection data of the browser and operating system type used, Google account if you are logged into Google, mouse movements on the reCaptcha areas, and tasks where you need to identify images. The legal basis for the described data processing is Art. 6(1)(f) of the General Data Protection Regulation. We have a legitimate interest in this data processing to ensure the security of our website and protect ourselves against automated inputs (attacks).

Google is subject to the EU-US Privacy Shield. Further information can be found at www.privacyshield.gov.

Contact details for Google:

Google Dublin, Google Ireland Ltd.

Gordon House, Barrow Street, Dublin 4, Ireland

Fax: +353 (1) 436 1001

You can find the terms of use and the privacy policy on the Google website (www.google.de).

 

13. HubSpot

This website uses the software HubSpot, provided by the software company of the same name based in the United States, with a branch in Ireland, HubSpot, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland. HubSpot is a software solution for managing and implementing inbound marketing. The stored information is saved on HubSpot's servers. We may use this information to engage with visitors to our website and determine which services of our company may be of interest to you. We use all collected information exclusively for the optimization of our marketing activities. Further information can be found in the terms of service and privacy policy of HubSpot Inc. at http://www.hubspot.com/terms-of-service and http://www.hubspot.com/privacy-policy. HubSpot is also certified under the Privacy Shield agreement, providing an additional guarantee to comply with European data protection law (https://www.privacyshield.gov). We require HubSpot for the efficient and prompt processing of user inquiries. The legal basis for the data processing is Art. 6(1)(f) of the General Data Protection Regulation (GDPR), which allows the processing of data for the legitimate interests pursued by the data controller, provided that the interests or fundamental rights and freedoms of the data subject do not override those interests.

 

14. Postal Advertising / Email Advertising without Newsletter Registration and Your Right to Object

We reserve the right to process your first and last name, as well as your address, which we have collected as part of your order in the webshop, in order to send you interesting offers and information about our products by postal mail.

If we obtain your email address in connection with the sale of a product or service and you have not objected to this, we reserve the right to regularly send you offers for similar products, such as those you have already purchased, from our range by email, based on § 7 (3) of the German Unfair Competition Act (UWG). This is in line with our overriding legitimate interests in addressing our customers with advertising.

The legal basis for the processing is Article 6 (1) sentence 1 lit. f of the General Data Protection Regulation (GDPR). We have a legitimate economic interest in personalized direct advertising to convince you of our offers.

You can object to the use of your email address for these purposes at any time by sending a message to the contact information described below or by using a designated link in the advertising email, without incurring any costs other than the transmission costs according to the basic rates.

If you do not wish for this processing to occur, you have the right to object at any time in accordance with Article 21 of the GDPR. You can address your objection to the contact details mentioned in Section I below.

 

 

 

III. SSL/TLS Encryption

For security reasons and to protect your personal data, our website is encrypted using SSL/TLS technology. The encryption technology is visible to you through "https://" and the padlock symbol in your browser's address bar.

 

IV. Storage Period

Unless otherwise stated in this privacy policy, we will store your personal data for as long as necessary for the purpose of collection. After that, we will delete the data unless processing is justified for another purpose and deletion is not in conflict with legal proof and retention periods. Corresponding proof and retention obligations arise from the Commercial Code (Handelsgesetzbuch) and the Fiscal Code (Abgabenordnung). The prescribed periods for retention and documentation specified therein are six years in accordance with commercial regulations pursuant to Section 257 of the Commercial Code (HGB) and up to ten years due to tax regulations pursuant to Section 147 of the Fiscal Code (AO).

 

V. Your data protection rights

You have the following rights regarding the personal data concerning you:

  • Right to Information: according to Article 15 of the General Data Protection Regulation (GDPR), you have the right to obtain information about the data stored about you.
  • Right to Rectification: if incorrect personal data has been processed, you have the right to rectify it in accordance with Article 16 of the GDPR.
  • Right to Erasure and Restriction of Processing: if the legal requirements are met, you can request the erasure (Article 17 of the GDPR) or restriction of processing (Article 18 of the GDPR).
  • Right to Object: if your data is processed based on Article 6(1)(f) or Article 6(1)(e) of the GDPR, you have the right to object to the processing under Article 21 of the GDPR.
  • Right to Data Portability: according to Article 20 of the GDPR, you have the right to data portability for data that is processed automatically based on your consent or a contract with you.

If you wish to exercise your rights, please contact the contact details provided above.

 

VI. Your Right to Lodge a Complaint

If you believe that data processing violates data protection laws, you have the right to lodge a complaint with a supervisory authority of your choice (Art. 77 GDPR in conjunction with § 19 BDSG). This includes the supervisory authority responsible for us, which you can reach using the following contact information:

Hamburg Commissioner for Data Protection and Freedom of Information

Ludwig-Erhard-Str. 22, 7th floor

20459 Hamburg

Tel.: +49 (0) 40 428 54-4040

Fax: +49 (0) 40 428 54-400

Email: mailbox@datenschutz.hamburg.de

____________________________________________________________________________

Information about Your Right to Object under Art. 21 GDPR

You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Article 6(1)(f) GDPR (processing necessary for the purposes of legitimate interests). This also applies to profiling based on this provision within the meaning of Article 4(4) GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims.

In individual cases, we process your personal data for the purpose of direct marketing. You have the right to object at any time to the processing of personal data concerning you for such marketing purposes, including profiling to the extent that it is related to such direct marketing.

If you object to processing for direct marketing purposes, we will no longer process your personal data for such purposes.

The objection can be made informally and should be addressed to:

Healthygarden GmbH,

represented by Managing Director Dominik Sperling

Volksdorfer Weg 186,

22393 Hamburg

Tel. +49 (0) 40 [63 91 88 90]

Email: [hello@omura.com]