Data protection declaration
1) Introduction and contact details of the person responsible
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following we will inform you about how your personal data is handled when you use our website. Personal data is all data with which you can be personally identified.
1.2 The person responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is KAYOLI Inh. Oliver Kalz e.K.
Owner: Oliver Kalz, Wanninchener Str. 8, 15926 Luckau, Germany, Tel.: 03544555851, E-Mail: sales@kayoli.com. The person responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
2) Data collection when visiting our website
2.1 If you use our website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the site server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
The website you visited
Date and time of access
Amount of data sent in bytes
Source/reference from which you accessed the site
Browser used
Operating system used
IP address used (if applicable: in anonymized form)
The processing takes place in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently check the server log files if there are concrete indications of illegal use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or inquiries to the person responsible), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser line.
3) Hosting & Content Delivery Network
For hosting our website and displaying the page content, we use a provider who provides its services itself or through selected subcontractors exclusively on servers within the European Union.
All data collected on our website is processed on these servers.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
4) Cookies
In order to make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e. small text files that are stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), some of these cookies remain on your device for longer and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can find out the storage period from the overview of the cookie settings in your web browser.
If personal data is also processed by individual cookies used by us, the processing takes place in accordance with Art. 6 Para. 1 lit. b GDPR either to execute the contract, in accordance with Art. 6 Para. 1 lit. a GDPR in the event of consent being granted, or in accordance with Art. 6 Para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.
You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general.
Please note that if you do not accept cookies, the functionality of our website may be restricted.
5) Contacting us
5.1 WhatsApp Business
You have the option of contacting us via the WhatsApp messaging service of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. For this purpose, we use the so-called “business version” of WhatsApp.
If you contact us via WhatsApp in connection with a specific transaction (for example, an order placed), we will save and use the mobile phone number you use with WhatsApp and – if provided – your first and last name in accordance with Art. 6 Para. 1 lit. b. GDPR to process and answer your request. On the basis of the same legal basis,
We may ask you to provide additional data (order number, customer number, address or email address) via WhatsApp in order to be able to assign your request to a specific process.
If you use our WhatsApp contact for general inquiries (e.g. about the range of services, availability or our website), we will save and use the mobile phone number you use with WhatsApp and - if provided - your first and last name in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in the efficient and timely provision of the information you require.
Your data will always only be used to answer your request via WhatsApp. It will not be passed on to third parties.
Please note that WhatsApp Business has access to the address book of the mobile device we use for this purpose and automatically transfers telephone numbers stored in the address book to a server of the parent company Meta Platforms Inc. in the USA. To operate our WhatsApp business account, we use a mobile device in whose address book only the WhatsApp contact details of those users who have contacted us via WhatsApp are stored.
This ensures that every person whose WhatsApp contact details are stored in our address book has consented to the transmission of their WhatsApp telephone number from the address books of their chat contacts in accordance with Art. 6 Paragraph 1 Letter a of GDPR by accepting the WhatsApp terms of use when using the app for the first time on their device. The transmission of data from users who do not use WhatsApp and/or have not contacted us via WhatsApp is therefore excluded.
For the purpose and scope of data collection and the further processing and use of the data by WhatsApp as well as your related rights and setting options to protect your privacy, please refer to WhatsApp's data protection information: https://www.whatsapp.com/legal/?eea=1#privacy-poli...
We have concluded a data processing agreement with the provider that protects the data of our site visitors and prohibits it from being passed on to third parties.
As part of the processing mentioned above, data may be transferred to Meta Platforms Inc. servers in the USA.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level on the basis of an adequacy decision of the European Commission.
5.2 When you contact us (e.g. via contact form or email), personal data is collected. The data collected when you use a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of answering your request or for making contact and the associated technical administration.
The legal basis for processing this data is our legitimate interest in answering your request in accordance with Art. 6 (1) (f) GDPR. If your contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted after your request has been processed. This is the case if the circumstances indicate that the matter in question has been conclusively clarified and provided that there are no statutory retention periods to the contrary.
6) Data processing when opening a customer account
In accordance with Art. 6 Paragraph 1 Letter b of the GDPR, personal data will continue to be collected and processed to the extent required if you provide it to us when opening a customer account. You can find out which data is required to open an account in the input mask of the corresponding form on our website.
You can delete your customer account at any time and can do so by sending a message to the above-mentioned address of the person responsible. After your customer account has been deleted, your data will be deleted provided that all contracts concluded through it have been fully processed, there are no statutory retention periods to the contrary and we have no legitimate interest in continuing to store it.
7) Data processing for order processing
7.1 Transmission of image files for order processing by email
On our website, we offer customers the opportunity to request the personalization of products by sending image files by email. The submitted image motif is used as a template for the personalization of the selected product.
The customer can send us one or more image files from the memory of the end device used via the email address provided on the website. We
capture, save and use the files transmitted in this way exclusively for the production of the personalized product in accordance with the respective service description on our website. If the transmitted image files are passed on to special service providers for the production and processing of the order, you will be explicitly informed of this in the following paragraphs. No further transfer will take place. If the transmitted files or the digital motifs contain personal data (in particular images of identifiable persons), all of the processing operations just mentioned are carried out exclusively for the purpose of processing your online order in accordance with Art. 6 Paragraph 1 Letter b of GDPR.
After the order has been processed, the transmitted image files are automatically and completely deleted.
7.2 Transmission of image files for order processing via upload function
On our website, we offer customers the option of ordering the personalization of products by transmitting image files via an upload function. The submitted image motif is used as a template for the personalization of the selected product.
Using the upload form on the website, the customer can send one or more image files from the memory of the device used to us directly via automated, encrypted data transfer. We then record, save and use the transmitted files exclusively to produce the personalized product in accordance with the respective service description on our website. If the transmitted image files are passed on to special service providers for the production and processing of the order, you will be explicitly informed of this in the following paragraphs. No further transfer will take place. If the transmitted files or the digital motifs contain personal data (in particular images of identifiable persons), all of the processing operations just mentioned are carried out exclusively for the purpose of processing your online order in accordance with Art. 6 Para. 1 lit. b GDPR.
After the order has been finally processed, the transmitted image files are automatically and completely deleted.
7.3 To the extent necessary for the contract processing for delivery and payment purposes, the personal data we collect will be passed on to the commissioned transport company and the commissioned credit institution in accordance with Art. 6 (1)(b) GDPR.
If we owe you updates for goods with digital elements or for digital products on the basis of a corresponding contract, we will process the contact details you provided when ordering (name, address, email address) in order to inform you personally about upcoming updates within the legally stipulated period by suitable communication channels (e.g. by post or email) within the scope of our statutory information obligations in accordance with Art. 6 (1)(c) GDPR. Your contact details will be used strictly for the purpose of notifications about updates owed by us and will only be processed by us for this purpose to the extent that this is necessary for the respective information.
To process your order, we also work with the following service provider(s), who support us in whole or in part in the implementation of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.
8) Tools and other
Cookie consent tool
This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed to users when they visit the page in the form of an interactive user interface on which consent for certain cookies and/or cookie-based applications can be given by ticking boxes. By using the tool, all cookies/services that require consent are only loaded if the respective user gives the corresponding consent by ticking the box. This ensures that such cookies are only placed on the user's respective device if consent has been given.
The tool sets technically necessary cookies to save your cookie preferences. Personal user data is generally not processed.
If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 (1) lit. f GDPR on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a
legally compliant design of our website.
Another legal basis for the processing is Art. 6 Paragraph 1 Letter c of GDPR. As the responsible party, we are subject to the legal obligation to make the use of technically unnecessary cookies dependent on the respective user consent.
Where necessary, we have concluded a data processing agreement with the provider that ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.
You can find further information about the operator and the setting options of the cookie consent tool directly in the corresponding user interface on our website.
9) Rights of the data subject
9.1 The applicable data protection law grants you the following data subject rights (rights to information and intervention) vis-à-vis the responsible party with regard to the processing of your personal data, whereby reference is made to the legal basis cited for the respective exercise requirements:
Right to information in accordance with Art. 15 GDPR;
Right to rectification in accordance with Art. 16 GDPR;
Right to erasure in accordance with Art. 17 GDPR;
Right to restriction of processing in accordance with Art. 18 GDPR;
Right to information in accordance with Art. 19 GDPR;
Right to data portability in accordance with Art. 20 GDPR;
Right to revoke consent granted in accordance with Art. 7 Para. 3 GDPR;
Right to lodge a complaint in accordance with Art. 77 GDPR.
9.2 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTEREST AS PART OF A BALANCE OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA IN QUESTION. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN PROVE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, FUNDAMENTAL RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US IN ORDER TO CARRY OUT DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING. YOU CAN EXERCISE YOUR OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.
10) Duration of storage of personal data
The duration of storage of personal data is determined by the respective legal basis, the purpose of processing and - if applicable - also by the respective statutory retention period (e.g. retention periods under commercial and tax law).
When processing personal data on the basis of an explicit consent in accordance with Art. 6 Para. 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.
If there are statutory retention periods for data that are processed in the context of legal or quasi-legal obligations on the basis of Art. 6 Para. 1 lit. b GDPR, these data will be routinely deleted after the retention periods have expired, provided that they are no longer required to fulfill or initiate a contract and/or we have no legitimate interest in continuing to store them.
When processing personal data on the basis of Art. 6 Para. 1 lit. f GDPR, these data will be stored until you exercise your right of objection in accordance with Art. 21 Para. 1 GDPR, unless we can demonstrate compelling legitimate reasons for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
When processing personal data for the purpose of direct advertising on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right of objection in accordance with Art. 21 (2) GDPR.
Unless the other information in this declaration on specific processing situations indicates otherwise, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.