Data protection

Privacy policy

In this privacy policy, we inform you about the processing of personal data when using our website.

Personal data is information that relates to an identified or identifiable person. This primarily includes information that allows conclusions to be drawn about your identity, for example your name, telephone number, address or e-mail address. Statistical data that we collect, for example, when you visit our website and that cannot be linked to your person do not fall under the concept of personal data.

You can print or save this privacy policy by using the usual functionality of your browser.

1. contact person

The contact person and so-called data controller for the processing of your personal data when visiting this website within the meaning of the EU General Data Protection Regulation (GDPR) is BENEGANIC GmbH, Churerstrasse 54, 8808 Pfäffikon, Switzerland, phone: +41 78 300 66 76, e-mail: info@beneganic.com. For all questions regarding data protection in connection with the use of our website, you can also contact our data protection officer at any time. He can be reached at the above postal address and at the e-mail address given above (keyword: "attn. data protection officer").

2 Data processing on our website

2.1 Calling up our website / access data

Each time you use our website, we collect the access data that your browser automatically transmits to enable you to visit the website. The access data includes in particular:

  • IP address of the requesting device;

  • Date and time of the request;

  • Address of the website accessed and the requesting website;

  • Information about the browser used and the operating system;

  • Online identifiers (e.g. device identifiers, session IDs).

The data processing of these access data is necessary to enable the visit of the website and to ensure the permanent functionality and security of our systems. The access data is also temporarily stored in internal log files for the purposes described above, in order to compile statistical information about the use of our website, to further develop our website with regard to the usage habits of our visitors (e.g., if the proportion of mobile devices used to access the pages increases) and to generally maintain our website administratively. The legal basis is Art. 6 para. 1 p. 1 lit. b DSGVO.

The information stored in the log files does not allow any direct conclusions to be drawn about your person; in particular, we only store the IP addresses in shortened, anonymized form. The log files are stored for 30 days and archived after subsequent anonymization.

2.2 Contacting us

You have various options for contacting us. In this context, we process your data transmitted in the context of contacting you exclusively for the purpose of communicating with you. The legal basis is Art. 6 para. 1 lit. b DSGVO. The data we collect will be automatically deleted after your request has been fully processed, unless we still need your request for the purpose of

2.3 Registration

You have the option to register for our login area in order to use the full range of functions of our website (e.g. to place orders in our online store, except for guest orders). We have highlighted the data you are required to enter by marking them as mandatory fields. Without this data, registration is not possible. The legal basis for the processing is Art. 6 para. 1 lit. b DSGVO.

2.4 Orders

During an order process, we collect mandatory data necessary for the processing of the contract:

  • Salutation;

  • First and last name;

  • Date of birth (only for some payment methods);

  • e-mail address;

  • password;

  • Billing and shipping address;

  • Payment information, payment data.

Without this data, the processing of the contract is not possible. Optionally, information such as telephone and fax number are possible, so that we can contact you in case of queries also on these ways. The legal basis for the processing is Art. 6 para. 1 p. 1 lit. b DSGVO.

2.5 Payment options, payment service providers

For orders in our online store, we offer PayPal and credit card payment. In doing so, we work together with a payment service provider from whom we receive your payment data or to whom we transmit your payment data. Without this payment data and payment service provider, the payment and contract processing is not possible. The legal basis for this data processing is Art. 6 para. 1 p. 1 lit. b DSGVO.

Our payment service provider is

  • Saferpay: SIX Payment Services AG, Hardturmstrasse 201, CH-8021 Zurich (http://www.six-payment-services.com).

Most browsers are set to accept cookies by default. However, you can adjust your browser settings so that cookies are rejected or only stored after prior consent. If you reject cookies, not all of our offers may work properly for you.

We use our own cookies in particular

  • for login authentication,

  • for load balancing,

  • for session-spanning storage of your shopping cart

  • to note that information placed on our website has been displayed to you - so that it is not displayed again the next time you visit the website.

Our intention is to provide you with a more convenient and personalized experience on our website. These services are based on our aforementioned legitimate interests, the legal basis is Art. 6 para. 1 p. 1 lit. f DSGVO.

In addition, we also use cookies and comparable technologies (e.g. web beacons) from partners for analysis and marketing purposes. This is described in more detail in the following sections.

2.6 Use of cookies and comparable technologies for analysis purposes

In order to improve our website, we use cookies and comparable technologies (e.g. web beacons) for statistical collection and analysis of general usage behavior based on access data. We also use analytics services to evaluate the use of our various marketing channels.

The legal basis for the data processing described in the following section is Art. 6 (1) p. 1 lit. f DSGVO, based on our legitimate interest in the needs-based design and continuous optimization of our website.

In the following list of the technologies we use, you will also find information in each case on the options for objecting with regard to our analysis measures by means of a so-called opt-out cookie. Please note that after deleting all cookies in your browser or the subsequent use of another browser and/or profile, an opt-out cookie must be set again.

2.7 Google Analytics

Our website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses cookies and similar technologies to analyze and improve our website based on your user behavior. The data generated in this context may be transferred by Google to a server in the USA for analysis and stored there. In the event that personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield. However, your IP address will be shortened before the usage statistics are evaluated, so that no conclusions can be drawn about your identity. For this purpose, Google Analytics on our website has been extended by the code "anonymizeIP" to ensure anonymized collection of IP addresses.

Google will process the information obtained through the cookies in order to evaluate your use of the website, compile reports on website activity for website operators and provide other services relating to website activity and internet usage.

You can configure your browser to refuse cookies, or you can prevent the collection of data generated by cookies and related to your use of this website (including your IP address) and the processing of this data by Google by downloading and installing the browser add-on provided by Google. As an alternative to the browser add-on or if you access our website from a mobile device, please use this opt-out link. This will prevent collection by Google Analytics within this website in the future (the opt-out only works in the browser and only for this domain). If you delete your cookies in this browser, you must click this link again.

You can find more information on this in Google's privacy policy.

2.8 E-mail advertising with newsletter registration

If you register for our newsletter, we use the data required for this purpose or separately provided by you to regularly send you our e-mail newsletter based on your consent.

Unsubscribing from the newsletter is possible at any time and can be done either by sending a message to the contact option described below or via a link provided for this purpose in the newsletter. After unsubscribing, we will delete your e-mail address, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this statement.

3. passing on of data

A passing on of the data collected by us takes place in principle only if:

  • you have given your express consent to this in accordance with Art. 6 (1) p. 1 lit. a DSGVO;

  • the disclosure is necessary in accordance with Art. 6 (1) p. 1 lit. f DSGVO for the assertion, exercise or defense of legal claims and there is no reason to assume that you have an overriding interest worthy of protection in not having your data disclosed;

  • we are legally obliged to disclose your data according to Art. 6 para. 1 p. 1 lit. c DSGVO; or

  • this is legally permissible and necessary according to Art. 6 para. 1 p. 1 lit. b DSGVO for the processing of contractual relationships with you or for the implementation of pre-contractual measures that take place at your request.

Part of the data processing may be carried out by our service providers. In addition to the service providers mentioned in this privacy policy, this may include, in particular, data centers that store our website and databases, IT service providers that maintain our systems, and delivery and logistics service providers. If we pass on data to our service providers, they may only use the data to perform their tasks. The service providers have been carefully selected and commissioned by us. They are contractually bound to our instructions, have suitable technical and organizational measures in place to protect the rights of the data subjects and are regularly monitored by us.

4. integration of contents and services of third parties

It may happen that third-party content, for example videos from YouTube, maps from Google Maps, RSS feeds or graphics from other websites are integrated within our website. This always requires that the providers of this content ("third-party providers") know your IP address. This is because without the IP address, they cannot send the content to your browser. The IP address is thus required for the display of this content. The legal basis for this data processing is Art. 6 para. 1 lit. b, f DSGVO.

We endeavor to use only such content whose respective providers use the IP address only for the delivery of the content. However, we have no influence if the third-party providers store the IP address for statistical purposes, for example.

5. storage period

In principle, we store personal data only as long as necessary to fulfill contractual or legal obligations for which we have collected the data. Thereafter, we delete the data immediately, unless we still need the data until the expiry of the statutory limitation period for evidence purposes for civil law claims or due to statutory retention obligations.

For evidentiary purposes, we must retain contractual data for three years from the end of the year in which the business relationship with you ends. Any claims become statute-barred at this point at the earliest in accordance with the standard statutory limitation period.

Even after this, we still have to store some of your data for accounting reasons. We are obliged to do so because of legal documentation obligations that may arise from the German Commercial Code, the German Fiscal Code, the German Banking Act, the German Money Laundering Act and the German Securities Trading Act. The periods specified there for the retention of documents are two to ten years.

6. your rights

You have the right to request information about the processing of your personal data by us at any time. When you request information, we will explain the data processing to you and provide you with an overview of the data stored about you.

If any data stored by us is incorrect or no longer up to date, you have the right to have this data corrected. You can also request the deletion of your data. If deletion is exceptionally not possible due to other legal regulations, the data will be blocked so that it is only available for this legal purpose.

You can also have the processing of your data restricted, for example, if you believe that the data we have stored is incorrect.

You also have the right to data portability, which means that we will provide you with a digital copy of the personal data you have provided to us upon request.

To exercise your rights described here, you can contact us at any time using the contact details above. This also applies if you wish to receive copies of guarantees demonstrating an adequate level of data protection.

In addition, you have the right to object to data processing based on Art. 6(1)(e) or (f) DSGVO. Finally, you have the right to complain to the data protection supervisory authority responsible for us. You can assert this right at a supervisory authority in the member state of your residence, your workplace or the location of the alleged infringement. In Berlin, our headquarters, the competent supervisory authority is: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin.

7 Right of revocation and objection

In accordance with Article 7 (2) DSGVO, you have the right to revoke consent you have given to us at any time. This has the consequence that we no longer continue the data processing based on this consent for the future. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

Insofar as we process your data on the basis of legitimate interests pursuant to Art. 6(1)(f) DSGVO, you have the right to object to the processing of your data pursuant to Art. 21 DSGVO and to provide us with reasons that arise from your particular situation and which, in your opinion, argue for an overriding of your interests worthy of protection. If it concerns an objection to data processing for direct marketing purposes, you have a general right of objection, which will also be implemented by us without giving reasons.

If you would like to exercise your right of revocation or objection, it is sufficient to send an informal message to the contact details above.

8. data security

We maintain current technical measures to ensure data security, in particular to protect your personal data from dangers during data transmissions and from third parties gaining knowledge. These are adapted to the current state of the art in each case. To secure the personal data you enter on our website, we use Transport Layer Security (TLS), which encrypts the information you enter.

9. changes to the data protection declaration

We occasionally update this privacy policy, for example when we adapt our website or when legal or regulatory requirements change.

© BENEGANIC GmbH - Version: 2.0 / Status: September 2019