PRIVACY POLICY

Online Privacy Policy


As a principle, the protection of your personal data is of highest priority for Bandex Textil & Handels-GmbH!

The security of personal data such as name, address, telephone number or email, is a serious and important concern for our company. Therefore, we conduct our online activities in compliance with the respective statutory provisions relating to data protection and data security. Below, you can find the information we process.

Registration

On our website, we offer users the opportunity to register by providing their personal data. The data is entered into an input screen and sent to us and stored. Data is not transferred to third parties. As part of the registration process, consent is obtained from the user to process this data.

The legal basis for processing data if the user’s consent is given is Article 6(1)(a) GDPR.

If the registration serves to fulfil a contract to which the user is party or to perform pre-contractual measures, the additional legal basis for the processing of data is Article 6(1)(b) GDPR.

User registration is necessary in order to provide certain content and services on our website.

User registration is necessary in order to fulfil a contract with the user or to perform pre-contractual measures.

The data will be deleted as soon as it is no longer necessary for the purpose of its collection.

If the data is necessary for the fulfilment of a contract or for performing pre-contractual measures, premature deletion of the data is only possible if contractual or legal obligations do not preclude deletion.

Data deletion and storage duration

The data subject’s personal data will be deleted or blocked as soon as the purpose of storage ceases to apply. Data may be stored beyond this if provisions have been made for this by the European or national legislator in Union regulations, laws or other rules to which the controller is subject. Data will also be blocked or deleted if a storage period prescribed by the standards mentioned above expires, unless there is a need for further storage of the data for the conclusion or fulfilment of a contract.

Exchange of data / contractual relationships with partners / third parties

In addition to the types of use described above, Bandex will transfer your data to third parties that are involved in the processing of your order or that participate in contracts. For example, if you place an order via our website (www.bandex.com), we will transmit your order information to Bandex partner companies and contractors who process and deliver your order to you. Data will only be transmitted to the extent required in order to fulfil or deliver your order or to process an enquiry. We will also transmit personal data to third parties where we are required to do so by law.

Data automatically collected on our website / usage data

We welcome anybody to visit and use our website free of charge and to look at the products on offer. When you visit our website, we record the following general usage data in order to assess which parts of our website you visit and how long you stay there:

1. Information about the browser type and version used
2. The user’s operating system
3. The user’s IP address
4. Date and time of access
5. Websites from which the user's system reaches our website
6. The services and functions used on our website

Such data will be combined with the usage data of all visitors to our website in order to measure the number of visitors, the average time of the visits, pages visited, etc. The data we collect is combined and used for internal purposes only.

The legal basis for the temporary storage of data and log files is Article 6(1)(f) GDPR.
We use this combined data for evaluating our products, services and the news we make available via our website, as well as for monitoring use of our website and generally improving its content.

The temporary storage of IP addresses by the system is required in order to allow the website to be delivered to the user’s computer. To do this, the user’s IP address must be stored for the duration of the session.

Data is stored in log files to ensure the functionality of the website. In addition, we use the data to optimize the website and to ensure the security of our information technology systems. These purposes are also the basis for our legitimate interests in data processing pursuant to Article 6(1)(f) GDPR.

The data will be deleted as soon as it is no longer necessary for the purpose of its collection. If data is stored in log files, this is the case after no more than seven days. Further storage is possible. In this case, the users’ IP addresses are deleted or distorted, so that it is no longer possible to associate them with the calling client.

The collection of data in order to provide the website and the storage of the data in log files is essential for the operation of the website. Therefore the user cannot opt out.

Cookies

Like many other commercial websites, Bandex sometimes uses the technology known as “cookies” to collect information on how you use the website, and to ensure your visit runs smoothly.

Cookies are text files that are stored in the Internet browser or come from the Internet browser on the user’s computer system. When a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a distinctive string that allows the browser to be uniquely identified when the website is visited again.

Our cookies neither disclose nor contain any personal data. Cookies cannot read any information from your computer or interact with other cookies on your hard disk. However, cookies enable us to recognize you when you revisit our website.

The following data is stored in the cookies:

1. Language settings
2. Items in a shopping basket

When accessing our website, the user is informed about the use of cookies and referred to this privacy policy.

The legal basis for processing personal data using cookies required for technical and analytical purposes is Article 6(1)(f) GDPR.

The purpose of using technically necessary cookies is to facilitate the use of websites for users. Some features of our website cannot be offered without the use of cookies. For these features, it is necessary to recognize the browser, even after moving to a different page.

We require cookies for the following:

1. Shopping basket
2. Watch list
3. Language settings and currency
4. Logged in or logged out

The user data collected through technically necessary cookies is not used to create user profiles.

Analysis cookies are used for the purpose of improving the quality of our website and its contents. Analysis cookies allow us to ascertain how the website is used and thus constantly optimize our service.

These purposes are also the basis for our legitimate interests in processing personal data pursuant to Article 6(1)(f) GDPR.

If you do not want your browser to accept cookies, you can deactivate or restrict this option in your browser settings. Cookies that have already been saved can be deleted at any time. This can also be done automatically. Deactivation of cookies may prevent this website from functioning properly. You may not be able to access all the options and information on this website.

Use of services for marketing and analysis purposes

Google Analytics

The Bandex website utilizes Google Analytics, a web analytics tool by Google Inc. (“Google”). Google Analytics uses “cookies”, text files stored on your computer that enable analysis of how you use the website. The cookie-generated information about your use of this website is usually transmitted to and stored on a Google server in the United States. However, if you are in a country that is a member state of the European Union or a contracting party to the Agreement on the European Economic Area, and if IP address anonymization has been activated on this website, Google will first truncate your IP address. Only by way of exception will the full IP address be transmitted to a Google server in the United States and shortened there. Google will use such information to evaluate your use of the website, to compile reports on website activity and to provide other services to Bandex in relation to website use and internet use. Google will not combine the IP address transmitted by your browser via Google Analytics with other Google data. You can disable cookies by setting your browser accordingly; however, if you do this you may not be able to use the full functionality of this website. Furthermore, you can prevent collection and transfer of the data generated by cookies on www.thomann.de and relating to your use of the website (including your IP address) to Google, as well as the processing of such data by Google, by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout/eula.html?hl=en.

As an alternative to installing the browser plug-in, particularly in internet browsers on mobile devices, you can prevent the collection of data by Google Analytics by clicking this link: Deactivate Google Analytics.

This will save an “opt-out” cookie to your device, meaning that none of your data will be collected on this website by Google Analytics.

Please note that if you delete cookies in your browser settings, this may mean the Google Analytics opt-out cookie is also deleted and may have to be re-activated by you.

More detailed information about the function of Google Analytics and the terms of use and privacy policy relevant to this service can be found under http://www.google.com/analytics/terms/gb.html and http://www.google.de/intl/en/policies/privacy/. We would also like to point out that our website uses Google Analytics with the anonymizeIP extension so that IP addresses are only processed further in an abbreviated form to prevent them being directly linked to a particular individual.

Newsletter

Our newsletters are created using the email marketing tool CleverReach. Only the e-mail address is passed on to the third party. CleverReach stores the data without exception in Europe. You have the opportunity to subscribe to our newsletter via our website. For this we need your e-mail address and your declaration that you agree with the subscription to the newsletter. In order to provide you with targeted information, we also collect and process voluntary information about the industry, your homepage and any comments. You can cancel the subscription to the newsletter at any time. Please send your cancellation to the following e-mail address: info@bandex.com. We will immediately delete your data in connection with the newsletter dispatch.

Payment system in the shop

On our website we offer payment via PayUnity. The provider of this payment service is SIX Payment Services (Austria) GmbH, Marxergasse 1B, 1030 Vienna, Austria (hereinafter "PayUnity"). If you choose to pay via PayUnity, the payment details you enter will be sent to PayUnity. The transmission of your data to PayUnity is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing to fulfill a contract). You have the option to revoke your consent to data processing at any time. Revocation does not affect the effectiveness of historical data processing operations.

Contact via E-Mail

You can contact us via the email addresses provided on our website. In this case, the user’s personal data transmitted by email will be stored.

No data is passed on to third parties in this context. The data is used exclusively for processing the conversation.

The legal basis for processing the data transmitted in the course of sending an email is Article 6 (1)(f) GDPR. If the purpose of the email is to conclude a contract, the additional legal basis for the processing shall be Article 6(1)(b) GDPR.

Security

Bandex takes precautions to ensure the security of your personal data. Your data will be diligently protected against loss, destruction, manipulation and unauthorized access or unauthorized disclosure and transmission.

Bandex protects collected customer data by saving it on servers protected by passwords and “firewalls” that use encryption technologies to prevent unauthorized access.

Bandex does its utmost and implements state-of-the-art technology to provide you with a secure environment for the completion of your order; however, we cannot guarantee absolute security of your data.

We ask you to take every available precaution to protect your personal data when online. We encourage you to at least change your passwords on a regular basis, to use a combination of letters and numbers, and to ensure you use a secure browser when surfing the internet.

Update of the Privacy Policy

Bandex may update this Privacy Policy from time to time. The version of the Privacy Policy on the website is always the actual value version. If you have any comments or questions regarding this Privacy Policy or any other guidelines on this website, please contact us in writing.

Rights as a data subject

If your personal data is processed, you are a data subject as defined in the GDPR and you have the following rights with regard to the controller:

1. Information, rectification, restriction and deletion

You have the right to access the data stored about you by Bandex and information concerning its origin and recipient and the purpose of data processing by Thomann’s websites free of charge at any time. In addition, you have the right to rectify, delete or restrict the processing of your personal data, provided the legal requirements to do so are met.

Details can be found in the relevant statutory provisions, Article 15 to 19 GDPR.

2. Right to data portability

You have the right to receive the personal data concerning you that you have provided to Bandex as the controller, in a structured, commonly used and machine-readable format. Bandex can comply with this right by providing a csv export of the customer data processed about you, for example.

3. Right to information

If you have exercised your right of rectification, deletion or restriction of processing against the controller, the controller is obliged to notify all recipients to whom your personal data has been disclosed of this rectification or deletion of data or restriction of processing, unless this proves to be impossible or involves a disproportionate effort.

You have the right to be informed about these recipients by the controller.

4. Right to object

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you that is based upon point (e) or (f) of Article 6(1) GDPR, including profiling based upon those provisions.

The controller shall no longer process the personal data concerning you unless the controller demonstrates compelling legitimate grounds for the processing that override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.

If you object to processing for direct marketing purposes, your personal data will no longer be processed for such purposes.

In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.

5. Revocability of declarations of consent under data protection law

You may also revoke your consent with regard to Bandex at any time with effect for the future using the contact details given below.

6. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.

The supervisory authority with which the complaint has been lodged will inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78 GDPR.

In the event of any questions, comments, complaints or to exercise your rights as a data subject in connection with our Privacy Notice and the processing of your personal data by Bandex websites, you can contact the Bandex data protection officer directly by email:

Bandex Textil & Handels-GmbH 
Attn.: data protection officer 
Herrschaftswiesen 17, 6842 Koblach, Austria
E-Mail: info@bandex.com