Data protection information according to Art. 13 DS-GVO
Since May 25, 2018, the requirements of the EU General Data Protection Regulation (hereinafter: GDPR) apply throughout Europe. In the following, we would like to inform you about the processing of personal data carried out by Whisky.de GmbH & Co. KG ("Whisky.de") about the processing of personal data in accordance with this new regulation (see Article 13 DSGVO). This data protection information also applies in particular to the use of the online stores operated by Whisky.de on the domains whisky.de and whisky.com. Please read our data protection information carefully. If you have any questions or comments about this data protection information, you can send them at any time to the e-mail address given in section 2.
Details & settings for cookies and third-party toolsContents
3.1 Using our website/application
3.2 Conclusion, execution or termination of a contract
3.3 Data processing for advertising purposes
3.4 Online presence and website optimization
4 Data transfer to recipients outside the EU
7 Changes to the privacy notice
1 Overview
The following data protection information explains the nature and extent of the processing of so-called personal data by Whisky.de GmbH & Co. KG ("Whisky.de"). Personal data is information that are or can be directly or indirectly attributed to you.
Data processing by Whisky.de can essentially be divided into two categories:
- For the purpose of processing the purchase contract via our shop, all data required for the execution of a contract with Whisky.de will be processed. If external service providers are involved during the processing of the contract, e.g. logistics companies or payment service providers, your data will be passed on to them to the necessary extent in each case.
- When you access the Whisky.de website and use the Whisky.de Community, various information is exchanged between your terminal device and our server. This may also include personal data. The information collected this way is used, among other things, to optimise our website or to display advertising in the browser of your end device.
In accordance with the provisions of the GDPR, you have various rights that you can assert against us. These include the right to object to selected data processing, in particular data processing for advertising purposes.
If you have any questions about our data protection information, you are welcome to contact our company data protection officer at any time. You will find the contact details below.
2 Name and contact details of the controller of personal information as well as the company data protection officer
This data protection information applies to data processing by Whisky.de GmbH & Co. KG, Am Grundwassersee 4, D-82402 Seeshaupt ("responsible party"), and for the following websites or applications: www.Whisky.de or www.Whisky.com as well as all associated domains and subdomains (<>Whisky.de/<> or <>Whisky.com/<>).
Ms Martina Demmel, Speer EDV GmbH, has been appointed as the company data protection officer for Whisky.de. The data protection officer can be contacted at the above address, for the attention of Ms Martina Demmel, or at datenschutz@whisky.de.
3 Purpose of data processing, legal bases and legitimate interests of Whisky.de, as well as categories of recipients
This section explains the purposes of data processing, legal bases and legitimate interests pursued by Whisky.de and categories of recipients of your personal data.
3.1 Using our website/application
When you access our website/application, information is automatically sent to the server of our website/application by the browser used on your end device and temporarily stored in a so-called log file. We have no influence on this. The following information is collected without your intervention and stored until automatic deletion:
- IP address of the requesting internet-capable device,
- date and time of access,
- name and URL of the accessed file,
- website/application the access was made from (referrer URL),
- the browser you use and, if applicable, the operating system of your internet-enabled computer as well as the name of your access provider.
The legal basis for the processing of the IP address is Article 6 paragraph 1 letter f) GDPR. Our legitimate interest follows from the purposes of data collection listed below. At this point, we would like to point out that we are not able to draw any direct conclusions about your identity from the collected data and that we will not do so.
The IP address of your end device and the other data listed above are used by us for the following purposes:
- Ensuring a smooth connection,
- Ensuring a comfortable use of our website/application,
- Evaluating system security and stability,
- Provision to law enforcement authorities for prosecution in the event of cyber attacks or fraud.
The data is stored for a period of two months and then automatically deleted, unless it is subject to a legal obligation to retain data. Furthermore, we use so-called cookies, analysis tools, targeting methods and social media plug-ins for our website/application. The exact procedures involved and how your data is used for this purpose are explained in more detail below in section 3.4.
If you have consented to so-called geolocation in your browser or operating system or other settings on your end device, we use this function to offer you individual services based on your current location. We process your location data processed in this way exclusively for this function. The data is deleted when you end the use of this function.
3.2 Conclusion, execution or termination of a contract
3.2.1 Data processing upon conclusion of the contract
The object of Whisky.de's activities is the distance selling of goods and services, the retail trade within the scope of the authorisations granted by the authorities and the serial production of the goods to be offered. In this context, we process the data required for the conclusion, performance or termination of a contract with you. This includes:
- First name, last name
- Billing and delivery address(es)
- E-mail address
- Billing and payment details
- Date of birth for age verification
- Telephone number for queries, if applicable
The legal basis for this is Article 6 Paragraph 1 Letter b) GDPR, i.e. you provide us with the data on the basis of the contractual relationship between you and us. We are also obliged to process your email address due to legal requirements to send an electronic order confirmation (Article 6 Paragraph 1 Letter c) GDPR). As far as we do not use your contact data for advertising purposes (see 3.3 below), we store the data collected for the purpose of processing the contract until the expiry of the statutory periods or possible contractual warranty and guarantee rights. After expiry of this period, we retain the information of the contractual relationship required by commercial and tax law for the periods determined by law. For this period (as a rule ten years from the conclusion of the contract), the data is processed again solely in the event of an audit by the tax authorities.
For the execution of the purchase contract als the following data processing is required:
If you have selected a payment method other than prepayment or cash on delivery, we will pass on the necessary payment data to a payment service provider commissioned by us.
When you enter your address, we will assist you with suggestions and validate your entry using the service provider Loqate GBG to prevent incorrect data from being entered making it difficult for us to fulfil the contract.
The addresses entered when completing an order or creating a customer account in the Whisky.de shop are forwarded to an external service provider for address suggestions and address verification. This serves the purpose of ensuring correct addresses for delivery in the course of contract fulfilment and to make the collection of addresses as convenient as possible for the user.
Furthermore, we pass on the necessary details of your order to a logistics company commissioned by us for the purpose of processing the purchase contract. In order to ensure that the goods are delivered in accordance with your wishes, we transmit your e-mail address and, if applicable, your telephone number to the logistics company commissioned by us. The logistics company may contact you in advance of the delivery in order to coordinate details of the delivery with you. The data is transmitted solely for this purpose and deleted after delivery. Furthermore, we ensure that we have concluded the necessary data processing agreement with external providers.
3.2.2 Creditworthiness and transmission to credit agencies
When concluding an order and requesting a method of payment that involves a credit risk for Whisky.de, we check your creditworthiness. For this purpose, we transmit your data to various credit agencies depending on the country.
3.2.2.1 Credit assessment for a German address
If you reside in Germany, we will transmit your data (name, address and date of birth) to infoscore Consumer Data GmbH (ICD), Rheinstr. 99, 76532 Baden-Baden, for the purpose of credit assessment.
The legal basis for these transfers is Article 6 Paragraph 1 Letter b) and Article 6 Paragraph 1 Letter f) of the GDPR. Transfers on the basis of these provisions may only be made as far as this is necessary to safeguard the legitimate interests of our company or third parties and does not override the interests of the fundamental rights and freedoms of the data subject which require the protection of personal data. Detailed information of ICD in the sense of Art. 14 European Data Protection Regulation, i.e. information on the business purpose, purposes of data storage, data recipients, right of self-disclosure, right to erasure or rectification, etc. can be found under the following link: https://www.experian.de/content/dam/marketing/emea/germany/de/assets/Informationsblatt-Art-14-2021-06-24-.pdf.
3.2.2.2 Credit assessment for an Austrian address
If you reside in Austria, we will transmit your data (name, address and, if applicable, date of birth) to Experian Austria GmbH, Gumpendorfer Straรe 21, 1060 Vienna, for the purpose of checking your creditworthiness, obtaining information for assessing the risk of non-payment on the basis of mathematical-statistical methods using economic data and address data, whereby this data will not be used for an automated decision, nor for verifying your address (checking for deliverability).
The legal bases for these transfers are Art. 6 Paragraph 1 Letter b and Art. 6 Paragraph 1 Letter f of the DSGVO. Transmissions on the basis of these provisions may only take place as far as this is necessary to safeguard the legitimate interests of our company or third parties and does not override the interests of the fundamental rights and freedoms of the data subjects which require the protection of personal data. Our legitimate interest is to request information on the creditworthiness and address verification of our customers in order to better assess the risk associated with our advance performance for certain types of payments and the delivery of goods and documents to addresses. Detailed information on data processing by Experian Austria GmbH within the meaning of Art. 14 GDPR can be found on its website at https://www.experian.at/art-14-dsgvo-info.
3.2.2.3 Consequences of a negative credit assessment
If a credit rating based on the transmitted data is negative, we reserve the right to restrict your payment methods before any further processing of your order.
You will not suffer any immediate disadvantage throgh this in any automated order processings of Whisky.de GmbH & Co. KG, (e.g. automatic rejection of an order). However one of our employees will review and process your order manually, if one or more automated checks fail.
3.2.2.4 Delayed payment and debt collection
In the event of a delay in payment, we will transmit the necessary data to a company commissioned to enforce the claim if the other legal requirements are met. The legal bases for this are both Article 6 Paragraph 1 Letter b) and Article 6 Paragraph 1 Letter f) GDPR. The assertion of a contractual claim is considered a legitimate interest within the meaning of the second-mentioned provision.
3.3 Data processing for advertising purposes
The following statements refer to the processing of personal data for advertising purposes. The GDPR declares such data processing on the basis of Article 6 Paragraph 1 Letter f) to be conceivable in principle and a legitimate interest. The duration of data storage for advertising purposes does not follow any rigid principles and is based on the question of whether the storage is necessary for the advertising approach. At Whisky.de, we also follow the principle of deleting data for promotional use after 3 years without use. Please refer to section 3.3.2 for information on how to proceed in the event of an objection.
3.3.1 Advertising purposes
If you have concluded a contract with us, we list you as an existing customer. In this case, we process your postal contact data outside of the existence of a specific consent in order to send you information about new products and services in this way. We process your e-mail address in order to send you information about our own, similar products outside of the existence of specific consent.
3.3.2 Right of objection
You can object to data processing for advertising purposes at any time, free of charge, separately for the respective communication channel and with effect for the future. An e-mail or a postal letter to the contact details mentioned under 2 is sufficient for this purpose.
If you object, the contact address concerned will be blocked from further data processing for advertising purposes. We would like to point out that in exceptional cases, advertising material may still be sent temporarily after receipt of your objection. This is technically due to the necessary lead time for advertisements and does not mean that we will not implement your objection. Thank you for your understanding.
3.3.3 Newsletter
On our website, we offer you the opportunity to register for our newsletters. To ensure that no mistakes are made when entering the e-mail address, we use the so-called double opt-in procedure: After you have entered your e-mail address in the registration field, we will send you a confirmation link. Your e-mail address be added to our distribution list only after you have clicked on this confirmation link.
You can revoke your consent at any time with effect for the future. To do so, simply unsubscribe from the newsletter via the link at the end of each newsletter you received or send a short note by email to the email address given under 2.
For sending our newsletters, we use a product from an external provider to whom we transfer the data you entered during registration for the newsletter. The transfer takes place in accordance with Article 6 paragraph 1 section f) GDPR, as the transfer serves our legitimate interest in using a secure, effective and user-friendly system for sending newsletters. The provider commissioned by us uses the transmitted data exclusively for sending the newsletter and for the statistical evaluation of the newsletter on our behalf. For evaluation purposes, the e-mails sent via our service provider contain so-called tracking pixels or web beacons, which can be used to determine whether a newsletter message is opened and which links, if any, were clicked. With the help of this data, the provider compiles non-personal statistics for us on the success of our newsletter and the response behaviour of our newsletter prospects.
All servers used by the service provider commissioned by us are located in selected data centres in Germany and are ISO 27001 certified. Furthermore, we have concluded the necessary data processing agreement with the provider.
3.4 Online presence and website optimization
3.4.1 Cookies - General note
We use so-called cookies on our website to optimise our website and to statistically record and evaluate the use of our website for the purpose of optimisation. We base the processing of your data by the cookies and pixels used for the aforementioned technically necessary purposes on our legitimate interest pursuant to Article 6 paragraph 1 s. 1 letter f) GDPR, which is to be regarded as legitimate within the meaning of the aforementioned provision.
In addition, we set cookies and process the data from the cookies used only on the basis of your consent in accordance with Art. 6 Para. 1 Sentence 1 Letter a) GDPR. You can revoke your consent at any time with effect for the future using our consent management tool. You can call up the consent management tool again at any time using the button at the top of this website.
Cookies are small files that are automatically created by your browser and stored on your end device (laptop, tablet, smartphone or similar) when you visit our site. Information is stored in the cookie that is related to the specific end device used. However, this does not mean that we gain direct knowledge of your identity. The use of cookies serves, on the one hand, to make the use of our offer more pleasant for you. For example, we use so-called session cookies to recognise that you have already visited individual pages of our website or that you have already logged into your customer account. These are automatically deleted when you leave our site or end your browser session. Furthermore, we also use temporary cookies for the purpose of user-friendliness, which are stored on your end device for a certain fixed period of time. If you visit our site again in order to use our services, it is automatically recognised that you have already been with us and which entries and settings you have made so that you do not have to enter them again.
If you have a Whisky.de customer shop account or a community account and are logged in or activate the "stay logged in" function, the information stored in cookies will be added to your account.
On the other hand, we use cookies to statistically record the use of our website and to evaluate it for the purpose of optimising our offer for you as well as to display information specially tailored to you. These cookies enable us to automatically recognise that you have already been on our website before when you visit it again. These cookies are automatically deleted after a defined period of time. Most browsers accept cookies automatically. However, you can configure your browser in such a way that no cookies are stored on your computer or a message always appears before a new cookie is created. However, the complete deactivation of cookies may mean that you cannot use all the functions of our website. The storage period of the cookies depends on their purpose.
3.4.2 Google Analytics
We use Google Analytics on our website, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereafter: "Google"). In this context, pseudonymous usage profiles are created and cookies are used. The information generated by the cookie about your use of this website, such as
- Browser type/version,
- operating system used,
- Referrer URL (the previously visited page),
- host name of the accessing computer (IP address),
- time of the server request,
are transmitted to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services associated with the use of the website and the internet for the purposes of market research and demand-oriented design of these internet pages. This information may also be transferred to third parties if this is required by law or if third parties process this data on our behalf. Under no circumstances will your IP address be merged with other Google data. The IP addresses are anonymised so that an assignment is not possible (so-called IP masking).
Google processes the information on our behalf in order to evaluate the use of the website, to compile reports on the website activities and to provide us with further services associated with the use of the website and the Internet for the purposes of market research and the needs-based design of these Internet pages. We have concluded a data processing agreement with Google for the use of Google Analytics. Through this contract, Google assures that they process the data in accordance with the GDPR and ensure the protection of the rights of the data subject.
Google Analytics is used on the basis of your consent pursuant to Art. 6 paragraph 1 sentence 1 letter a) GDPR. In this case, you also consent to the transfer of your data to the USA in accordance with Art. 49 paragraph 1 letter a) GDPR in the knowledge of the risks described.
You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) and the processing of this data by Google by downloading and installing this browser add-on. As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent the collection by Google Analytics by clicking on the following link: Deactivate Google Analytics
An opt-out cookie is set that prevents the future collection of your data when visiting this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again.
Further information on data protection in connection with Google Analytics can be found at the Google Analytics website.
3.4.3 Targeting procedure
The targeting procedures listed below and used by us are carried out on the basis of Article 6 Paragraph 1 Letter f) GDPR. With these targeting measures, we want to ensure that you are only shown advertising that is based on your actual or supposed interests on your end devices. Not bothering you with advertisements that are of no interest to you is in your interest as well as in ours.
3.4.3.1 Google AdWords
We use the Google AdWords service to advertise our website by displaying interest-relevant advertising. Google AdWords is a service operated by Google LLC ("Google"), 1600 Amphitheatre Parkway, Mountain View, CA 94043-1351, USA. Google AdWords allows advertisers to place advertisements in Google's search engine results and in the Google advertising network. For this purpose, certain keywords are defined in advance by the advertiser. If a user retrieves a keyword-relevant search result in the Google search engine, the ads are filtered accordingly. Similarly, ads are placed on relevant websites in the Google advertising network by means of an automatic algorithm, taking into account the specified keywords.
If a data subject accesses a Whisky.co.uk website via a Google AdWords ad, a conversion cookie will be stored by Google on the data subject's system. Such a conversion cookie loses its validity after thirty days and is not used to identify the data subject but to check whether certain sub-pages of whisky.de (e.g. the shopping basket) are called up within the period and thus to make the success of the advertising via AdWords measurable. The information collected by Google can be used statistically by Whisky.co.uk. However, neither Whisky.de nor other advertising customers of Google AdWords are able to identify the persons concerned.
Through the conversion cookie from Google, personal data, e.g. the web pages you visit, are stored. Each time you visit Whisky.de, personal data, including the IP address of the internet connection used by the person concerned, is therefore transmitted to Google in the USA and stored there. Google may pass this personal data on to third parties.
You can find more information and details about Google's privacy policy under this link.
3.4.3.2 Onsite-Targeting
Our website uses cookies to collect and analyse information in order to optimise advertising. This information contains, for example, details of which of our products you were interested in. The collection and evaluation is exclusively anonymous and does not enable us to identify you. In particular, the information is not combined with personal data about you. On the basis of this information, we can show you offers on our website that are specifically geared to your interests, as these result from your previous user behaviour. The cookie is automatically deleted after 30 days.
3.4.3.3 Objection-/Opt-Out option
You can prevent the aforementioned targeting technologies by making the appropriate cookie settings in your browser (see also 3.4.1) and deleting existing cookies on the end device via the settings of the internet browser or with the help of other software. In addition, you have the option of deactivating preference-based advertising for various providers with the help of the preference manager here. Personalised advertising by Google can be deactivated on this page.
3.4.4 Google Maps
Whisky.de uses the Google Maps API in some places to visually map geographical information. The Google Maps service is provided by Google LLC ("Google"), Amphitheatre Parkway, Mountain View, CA 94043, USA. When using Google Maps, Google also collects, processes and uses data on the use of the map functions by our website's visitors.
For further information on data processing by Google, please refer to the Google Maps Terms of Use and the privacy policy of Google Maps.
3.4.5 Google reCaptcha
We use "Google reCaptcha" service (hereinafter "reCaptcha") at certain points on our website and in the event of conspicuous access to protect against misuse by automatic programs (bots), spam or cyberattacks against our online presence. The provider of eCAPTCHAaptcha is Google LLC ("Google"), Amphitheatre Parkway, Mountain View, CA 94043, USA.
With the help of reCaptcha, we try to check whether the respective data entry on our websites (e.g. in the contact form, during registration) is made by a human or by a bot. For this purpose, reCaptcha analyses the behaviour of a visitor on the basis of various characteristics. For this analysis, reCaptcha evaluates various information (e.g. IP address, behaviour on the respective page). The data collected in this process is forwarded to Google.
Data processing through the use of Google reCaptcha is based on Art. 6 Para. 1 Letter f) GDPR (legitimate interest). Whisky.de has a legitimate interest in protecting its website from misuse, cyberattacks and SPAM. Last but not least, this also serves to protect the data stored on Whisky.de from criminal access.
For further information on Google reCaptcha please refer to Google's terms of use and the privacy policy.
3.4.6 YouTube-Videos on Whisky.de/Whisky.com
We use components (videos) from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter: "YouTube"), a Google company, on our website. The implementation is based on your consent in accordance with Art. 6 Para. 1 S. 1 Letter a) GDPR. By loading the videos on our website, data is forwarded to Google. In particular, it is transmitted to Google which of our websites you have visited and device-specific information including the IP address.
Whisky.de embeds videos from YouTube exclusively in the so-called "extended data protection mode", whereby, according to YouTube, no information about the users is stored on Whisky.de if the video is not viewed. Nevertheless, when you visit a website with an embedded YouTube video, your browser establishes a connection to YouTube's servers in order to display a preview of the video. In doing so, YouTube/Google is informed which page of Whisky.de you are visiting.
When starting an embedded video, YouTube also uses cookies, which collect information about your user behaviour. If you would like to prevent this, you must generally block the storage of cookies in the browser. You can also completely prevent the loading of Google plug-ins with add-ons for your browser, e.g. with the script blocker "NoScript".
If you are currently logged in to YouTube with your YouTube or Google account, YouTube/Google can assign your surfing behaviour to you personally. You can prevent this by logging out of your Google or YouTube account beforehand.
For more information on YouTube privacy, please see Google's privacy policy and at YouTube's privacy and security center.
3.4.7 Instagram content on Whisky.de/Whisky.com
The Whisky.de websites integrate content from the social network platform Instagram via corresponding plug-ins. The operator of the embedded plug-ins is Facebook Ireland Ltd, 4 Grand Canal Square, Dublin 2, Ireland. This may include, for example, content such as images, videos or texts and buttons with which users can express their liking of this content and/or subscribe to posts by the authors of this content and/or our posts. The content can be recognised by the "Instagram - symbol".
When you visit a website with embedded Instagram content, your browser establishes a connection to the Instagram servers in order to generate the preview of the content. If you are registered as a user on the social network Instagram and are logged in to Instagram with the browser you are using at the time you access the page, the pages you visit can be assigned to your account by Instagram.
We must point out that the content of the transmitted data and its use by Instagram is beyond our knowledge. You can find more information on data protection at Instagram at Instagram's privacy policy.
3.4.8 Use of Meta Pixel
This website uses the visitor action pixel from Meta for measuring conversions. The service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Meta, the collected data is also transferred to the United States and other third countries.
With the help of the pixel, the behavior of visitors who arrive at the website of Whisky.de/Whisky.com through a Meta advertisement, for example, on Meta platforms such as Instagram or Facebook, can be tracked. This allows the effectiveness of these advertisements to be evaluated for statistical and market research purposes, and future advertising measures to be optimized.
The data collected is anonymous for us as the operator of this website and does not allow any conclusions to be drawn about the identity of the users. However, the data is stored and processed by Meta, so that a link to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with its data usage policy. This allows Facebook to display ads on Facebook pages as well as outside of Facebook. As a page operator, we have no control over this use of the data. Further details on the use and utilization of the Meta Pixel can be found here on the manufacturer's website: https://de-de.facebook.com/business/tools/meta-pixel.
The use of the Meta Pixel is based on Art. 6(1)(f) GDPR. As a website operator, we have a legitimate interest in effective advertising measures, including the use of social media. If the appropriate consent has been obtained (e.g., consent for the storage of cookies), the processing is based exclusively on Art. 6(1)(a) GDPR; the consent can be revoked at any time.
The transfer of data to the United States is based on the European Commission's standard contractual clauses. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.
For further information on the protection of your privacy, please refer to Facebook's privacy policy: https://de-de.facebook.com/about/privacy/.
You can also deactivate the remarketing function "Custom Audiences" in the ad settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen if you are logged in to Facebook.
If you do not have a Facebook account, you can deactivate usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.
3.5 Customer account
In order to provide you with the greatest possible convenience when shopping, your personal data will be stored permanently in a password-protected customer account. The creation of the customer account is voluntary and is based on your consent within the meaning of Article 6 Paragraph 1 Letter a) GDPR. After setting up a customer account, no new data entry is required. You can view and change the data stored about you in your customer account at any time.
In addition to the data requested when placing an order, you must enter a password of your choice to set up a customer account. This is used together with your e-mail address to access your customer account. Please treat your personal access data confidentially and in particular do not make them accessible to unauthorised third parties. We cannot accept any liability for misused passwords unless we are responsible for the misuse. Please note that you will automatically remain logged in after leaving our website, unless you actively log out. You have the option of having your customer account deleted at any time. To do so, please use the contact details mentioned under 2.
If you do not wish to create a customer account at Whisky.de, please use the option of ordering via telephone at Whisky.de.
3.5.1 Third party login (Facebook, Google, Apple, PayPal)
To facilitate registration at the Whisky.de shop easier, you can also register voluntarily using your own Facebook, Google, Apple or PayPal account. These options are identifiable through the respective button with the name & logo of the provider on the registration pages or login pages in the shop below the input fields for user name and password. It is also possible to subsequently link existing Whisky.de customer accounts with the services of these third-party providers. In both cases, it is then possible to log in to the Whisky.de shop by logging in to the websites/services of the third parties instead of entering a username and password at Whisky.de.
If you click the respective button, you will be redirected to the pages of the third-party provider for registration. If you successfully register there, you will be asked to explicitly release the following data, depending on the provider:
- Facebook:
- E-Mail address
- Name
- Google:
- E-Mail address
- Name
- Apple:
- E-Mail address
- Name
- Address
- Country
This data will be used by Whisky.de to create your new customer account or to register for your linked Whisky.de account and will not be made accessible to any third party. The data is transmitted in encrypted form. This data is processed on the basis of your consent within the meaning of Article 6 Paragraph 1 Letter a) GDPR or, if you are creating an order, also within the meaning of Article 6 Paragraph 1 Letter b) GDPR.
Please note that if you use this voluntary option, the respective third party can trace your use of our website due to Whisky.de's request of your data for login purposes. Likewise, after linking your customer account, the third party providers will be contacted once each time you log in via this link in order to verify your identity. These processes may be logged by the third-party providers. For further information, please refer to the data protection information and terms of use of the respective third-party provider.
3.6 Community account
We operate an online community for the exchange of whisky lovers and connoisseurs. This includes the use of the so-called whisky/bottle database (https://www.Whisky.de/flaschen-db/<...>), the Whisky.de forum & the Whisky.de blog (https://www.Whisky.de/tfg/<...>). A community account is required to use the community. The creation of the community account is voluntary and is based on your consent within the meaning of Article 6 Paragraph 1 Letter a) GDPR. An e-mail address and a user name of your choice are required to create a user account. Your e-mail address is not visible to other members. The provision of further information (e.g. picture, first name, surname) is optional and voluntary.
3.6.1 Third party login
To facilitate registration at the Whisky.de Community, Whisky.de also offers a login via your own Facebook account ("register with facebook") or your own Google/YouTube account ("register with Google/YouTube"). This allows you to log in to the Whisky.de Community using the data stored with the respective third party. When using this function, Whisky.de requests the following data from the mentioned third parties: ID, e-mail address, first name, last name and profile picture. The data will be used exclusively for the creation of the account and subsequent logins and will not be made accessible to third parties. The transmission of the data is encrypted.
Please note that if you use this voluntary option, the respective third party can trace and possibly process your use of our website due to Whisky.de's request of your data for login purposes.
3.6.2 Community account deletion
You have the option to delete your community account at any time. This will delete the data you have stored in the background (e-mail address, first and last name, interests, profile picture). Please note, however, that this does not mean that your past activities in the community will be deleted at the same time and will continue to be displayed under an anonymised user name ("[Deleted user]").
3.7 Contacting Whisky.de/com
3.7.1 Contact
The online presence of Whisky.de provides a contact form and contact by e-mail for easy contacting. If you contact Whisky.de by e-mail or via the contact form, your personal data transmitted will be stored automatically. We use the information you provide via the contact form (mandatory information is marked with an asterisk) exclusively for the purpose of processing your request. The legal basis for this is both your consent within the meaning of Article 6 Paragraph 1 Letter a) GDPR and Article 6 Paragraph 1 Letter f) GDPR. The proper processing of your concerns is considered a legitimate interest within the meaning of the GDPR. If your contact is made in connection with a contractual relationship between you and us, Article 6 Paragraph 1 Letter b) GDPR, i.e. this contractual relationship, is also the legal basis for the data processing. You can revoke your consent to the use of data explained above at any time with effect for the future free of charge by sending a short message to the contact details given under 2. The lawfulness of the processing based on your consent up to the time of your revocation is not affected by this. However, we would like to point out that from the time of any revocation, it will no longer be possible to process your request. How we proceed in the event of the exercise of data subject rights is explained below.
3.7.2 Usage of Zammad Ticketing Systems
In order to process and answer your enquiries in our internal processes as quickly as possible, documented and reliably, we use the ticketing solution "Zammad" from Zammad GmbH, Marienstraรe 11, 10117 Berlin and thus process your personal data. This means in particular the input fields visible in the contact form or, in the case of contact by e-mail to info@whisky.de, the e-mail address you used as well as any other data you provide in the course of contacting us. This data is only used for the purpose of processing and answering your enquiry. With the help of Zammad, we can keep better track of open support requests and optimise our support processes - with the aim of processing all open customer requests quickly and reliably.
Data processing through Zammad is carried out on the basis of Art. 6 para. 1 letter b) GDPR for the fulfilment and implementation of contracts with you or our contractual obligations (e.g. in the event of a complaint or a revocation). Furthermore, the use is based on Art. 6 para. 1 letter f) GDPR (legitimate interest). Whisky.de has a legitimate interest in being able to process your request with high speed and efficiency through the use of up-to-date, secure technology.
Communication and data transfer with the ticketing system is always encrypted and the data is stored exclusively in German data centres. This data is not transferred to third countries. In addition, the necessary data processing agreement has been concluded with Zammad GmbH.
Data recorded in the ticketing system is automatically deleted after 24 months at the latest, unless it is subject to statutory retention obligations.
If you do not wish your personal data to be processed via the ticketing system, please use the option to contact us by telephone and inform our staff accordingly.
4 Data transfer to recipients outside the EU
With the exception of some of the processing described in 3.4 (online presence and website optimisation), we do not pass on your data to recipients based outside the European Union or the European Economic Area. The processing operations listed under 3.4 result in the transfer of data to the servers of the providers of analysis and targeting technologies commissioned by us. These servers are located in the USA. The data transfer takes place according to the principles of so-called standard contractual clauses of the EU Commission.
5 Your rights
5.1 Overview
In addition to the right to revoke the consent you have given us, you have the following further rights if the respective legal requirements are met:
- Right of access to your personal data stored by us pursuant to Art. 15 GDPR; in particular, you may request information on the purposes of processing, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the origin of your data if it has not been collected directly from you,
- Right to have inaccurate data corrected or to have correct data completed in accordance with Art. 16 GDPR,
- Right to have your data stored by us deleted in accordance with Art. 17 of the GDPR, as far as no legal or contractual retention periods or other legal obligations or rights to further storage are to be observed,
- Right to restrict the processing of your data pursuant to Article 18 of the GDPR, as far as you dispute the accuracy of the data, the processing is unlawful but you object to its erasure; the controller no longer requires the data but you need it to assert, exercise or defend legal claims or you have objected to the processing pursuant to Article 21 of the GDPR,
- Right to data portability pursuant to Art. 20 GDPR, i.e. the right to have selected data stored by us about you transferred in a common, machine-readable format, or to request the transfer to another controller.
- Right to complain to a supervisory authority: If you believe that the processing of your data violates data protection law or your data protection rights have otherwise been violated in some way, you can complain to the competent supervisory authority. This is the Bavarian State Office for Data Protection Supervision, Promenade 27, D-91522 Ansbach, Germany.
5.2 Right of objection
Under the conditions of Art. 21 Para. 1 GDPR, data processing can be objected to for reasons that arise from the particular situation of the data subject.
The above general right to object applies to all processing purposes described in this privacy notice that are processed on the basis of Article 6 paragraph 1 letter f) of the GDPR. In contrast to the specific right to object to data processing for marketing purposes (see 3.3 above), we are only obliged under the GDPR to implement such a general right of objection if you provide us with grounds of overriding importance (e.g. a possible risk to life or health). Furthermore, you have the option of contacting the data protection officer responsible for Whisky.de or the competent supervisory authority. This is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 27, 91522 Ansbach, Germany.
6 Data security measures
All data transmitted by you personally, including your payment data, are transmitted using the generally accepted and secure standard SSL (Secure Socket Layer). SSL is a secure and proven standard that is also used, for example, for online banking. You can recognise a secure SSL connection, among other things, by the appended s at the http (i.e. https://...) in the address bar of your browser or by the lock symbol in the upper or lower area of your browser.
To further protect the personal data of our customers (such as name, address, telephone number and e-mail address), we use an external control system, AC Sรผppmayer GmbH - a leading provider of professional address control systems in Germany. With the help of this system, we can determine - beyond our other technical IT security measures - whether customer data is being used without authorisation or has been lost. That way, our customers are protected, for example, from unwanted e-mail advertising and harassing telephone canvassing, because the checks are not only limited to postal addresses, but also extend to e-mail addresses and telephone numbers. You can find more information about this cooperation via this link.
We also use appropriate technical and organisational security measures to protect your personal data stored with us against manipulation, partial or complete loss and against unauthorised access by third parties. Our security measures are continuously improved in line with technological developments by us and by the service providers commissioned by us.
7 Changes to the privacy notice
We reserve the right to change the data protection information occasionally in order to adapt it to changed legal situations, changes in data processing or updated services. Changes that affect your contractual relationship with Whisky.de or for which your consent as a user is required will only be made with the consent of the users.
Customers, interested parties and users of Whisky.de are requested to inform themselves regularly about the current content of the data protection information.
Status: 18.04.2023