Privacy and security are especially important to Klatt & Haas GbR. Through constant optimisation of all technical security fundamentals, Klatt & Haas GbR is continuously improving the protection of your data.
If you voluntarily provide us with personal data, e.g. via our contact form, by e-mail or as part of the use of our online shop, the processing is carried out in accordance with the requirements of the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).
Name and contact details of the authority designated as responsible for the processing of that data:
Klatt & Haas GbR
Mühlbachgasse 2
87629 Füssen Germany
Email: fragen@haeute.com
Tel. +49 (0)8362 505 6885
Available Mon-Fri 8am-12am, Berlin Time
Data Protection Officer
Mister Claus Haas, E-Mail: fragen@haeute.com
Transfer of data
Your data is in good hands. We promise you that: We will not sell your personal data to third parties, nor lease it to other companies for advertising purposes.
We only share your personal information with third parties if:
" you have given us explicit consent to do so in accordance with Art. 6 para. 1 lit. a GDPR
" to the extent permitted by law and in accordance with Art. 6 para. 1 lit. b GDPR necessary for the settlement of contractual relationships with you, your personal data will be passed on to third parties. This includes credit institutions, postal and courier services and logistics companies.
" External service companies process data on our behalf as a processor. Your data is subject to the same privacy standards as ours. The recipient of the data may only use the data for the purposes for which the data was transmitted to them. The external service providers include data centres and companies that support us in the maintenance of computer equipment and IT applications.
" in the event that disclosure pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR there is a legal obligation.
" disclosure pursuant to Art. 6 para. 1 lit. f GDPR is required to assert, exercise or defend legal claims and there is no reason to believe that you have an overriding interest in not disclosing your data.
For further details on the transfer of personal data, please refer to the explanations below.
SSL Encryption
Personal data on this website are transmitted only in an encrypted form, using the TLS encryption method (Transport Layer Security, also known as SSL, Secure Sockets Layer). The TLS v1.0 method used is at this time one of the safest ways to encrypt data. Klatt & Haas GbR.de uses a 256-bit encryption pursuant to AES (Advanced Encryption Standard) and thus meets the highest security standards. The issuer of the SSL certificate is digicert, and the method used for the key exchange is DHE_RSA (2048 Bit).
Through the application of the SSL encryption, your data will be mutated so that a third party could not reconstruct it before it is transmitted to the Klatt & Haas GbR-server. This encryption procedure also ensures that your data will be sent exclusively to the server from which it was requested. Once the data is received by the Klatt & Haas GbR server, it is verified in regards to completeness and immutability.
If you use the Internet Explorer as your browser, you can identify the encrypted data transmission by the yellow lock icon in the address bar of your browser.
Personal data
Pursuant to Art. 4 No. 1 GDPR, personal data means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Personal data is therefore any data that is personally available to you, e.g. name, address, e-mail address, phone number or IP address.
Collection and storage of personal data and the nature and purpose of its use
When visiting the website
When you visit our website, the browser on your device automatically sends information to the server on our website. This information is temporarily stored in a so-called log file. The following information is recorded without your intervention and stored until it is automatically deleted:
" IP address of the requesting computer (shortened in the logfile),
" Date and time of access,
" Name and URL of the retrieved file,
" Website from which access is made (referrer URL),
" the browser used and, if applicable, the operating system of your computer and the name of your access provider.
The mentioned data will be processed by us for the following purposes:
" Ensuring a smooth connection of the website,
" Ensuring comfortable use of our website,
" evaluation of system security and stability as well as
" for other administrative purposes. Klatt & Haas GbR uses the IP address to protect the customer and to prevent misuse of the website or to detect misuse. We point out that the IP address is only used in a shortened version and further processed in order to exclude a direct reference to a person.
The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR. Our legitimate interest follows from the purposes listed above for data collection. Under no circumstances do we use the data collected for the purpose of drawing conclusions about you personally.
In addition, we use cookies when you visit our website. You will find more detailed explanations under the data protection declaration below.
Customer registration
Here, Klatt & Haas GbR processes and uses the data, which has been voluntarily entered into input forms and transmitted to Klatt & Haas GbR. These are, e.g. the name, address and other contact details such as telephone number and e-mail address, a user name and password (Art. 6 (1) (1) (b) GDPR for the execution of contractual relationships). You can also order as a guest user and your data will then be used and processed for the implementation of the contractual relationship and to process the order.
Orders in the online shop
We collect personal data when you voluntarily provide it to us for the purpose of carrying out a contract or opening a customer account. This can include, e.g. name, address and e-mail address. This data is used and stored by us for the execution of the contract and the delivery of your order (Art. 6 (1) (1) (b) GDPR for the execution of contractual relationships).
Processing of orders
In order for us to be able to process and deliver your online shop orders, we pass on the necessary data to the logistics company responsible for the delivery, e.g. name and delivery address (Art. 6 (1) (1) (b) GDPR for the execution of contractual relationships). In addition, your e-mail address can be forwarded to the supplier. You will then receive an e-mail to use the tracking service and to know when your package will arrive. The data transmitted in this way may only be used by the recipient for the purpose of performing his task. Any other use of the information is not permitted.
Newsletter registration and shipping
If, pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR, you have given your explicit consent and have registered to our newsletter (double opt-in procedure), we use your e-mail address and any other personal data you have provided to send you regular newsletters. For the receipt of the newsletter the indication of an e-mail address is sufficient. You can resign from receiving these newsletters from us at any time e.g. via a link at the end of each newsletter. You can also send us an e-mail to unsubscribe at any time. The data is then deleted and no longer used for the newsletter distribution.
Use of our contact form, contact by e-mail
For questions of any kind, we offer you the opportunity to contact us via a form provided on the website or to send us an e-mail. It is necessary to provide a name and a valid e-mail address in the contact form so that we know who the request came from and where to send the reply. Further information can be made voluntarily in the contact form. The legal basis for processing data is our legitimate interest in responding to your request and establishing contact in accordance with Art. 6 (1) point f GDPR. Your data will be deleted after final processing of your enquiry; this is the case if it can be inferred from the circumstances that the facts in question have been finally clarified, provided that there are no legal storage obligations to the contrary. If your contact is aimed at the conclusion of a contract, then additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR (processing of contractual relationships).
Payment Services
Payment via PayPal
For payment via the payment service provider PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" via PayPal, we will transfer your payment data to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as "PayPal"), in accordance with Article 6 (1) (1) (b) GDPR for the execution of contractual relationships. PayPal reserves the right to undertake a credit check for the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account". The result of the credit check on the statistical probability of default is used by PayPal to confirm creditworthiness, willingness and ability of the customers to pay. The credit information can contain probability values (so-called score values). Insofar as score values are included in the results of the credit rating, they are based on a scientifically recognised mathematical-statistical procedure. The calculation of score values includes, among other things, address data. For further information in regards to data protection and credit checks by PayPal, please refer to the PayPal privacy policy:
https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Sofortüberweisung
When paying via the online payment service provider Sofortüberweisung, your contact details will be sent to Sofortüberweisung within the scope of the order that has been placed. Sofortüberweisung is offered by SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany. The personal data transferred to Sofortüberweisung is usually a first name, last name, address, telephone number, IP address, e-mail address, or other data required for order processing, as well as data related to the order (Art. 6 (1) (1) (b) GDPR for the execution of contractual relationships). Under certain circumstances, the personal data transmitted to Sofortüberweisung will be transferred by instant transfer to credit reference agencies. This transfer is used to verify the identity and credit rating of the order you have placed. You can find out which data protection principles are based on the immediate processing of your data when processing your data, as shown in the data protection guidelines that are displayed during the payment process of Sofortüberweisung.
Cookies
Klatt & Haas GbR uses so-called cookies on some internet sites in order to enable web-based applications to manage the status of an online visit and to provide smooth navigation between the separate services and contents on the website as well as to provide the internet user with permanent settings on the Klatt & Haas GbR website.
A cookie is a small file that is transferred by Klatt & Haas GbR onto the user's computer when he or she visits the Klatt & Haas GbR website. A cookie only contains information that Klatt & Haas GbR itself transmits to the user's computer - private files cannot be read by a cookie.
When cookies are accepted by the user, Klatt & Haas GbR does not have access to his or her personal information. Klatt & Haas GbR may however identify the user's computer through the use of the cookies. Klatt & Haas GbR uses cookies so that the user can fill and manage the shopping cart during a session, and that Klatt & Haas GbR's website can be tailored even more towards the desires of the customer.
Klatt & Haas GbR uses "session-based" cookies that are not stored permanently on the visitor's computer. These temporary cookies will be deleted after leaving the website. Using the gathered information, Klatt & Haas GbR is able to analyse usage patterns and structures of the website. This enables further continuous optimisation of the website by improving the content and the usage.
Klatt & Haas GbR also uses "persistent" cookies. These cookies remain on the customer's computer, simplifying shopping and registration services during their next visit. For example, the cookies are able to remember which articles the customer has chosen for purchase while he or she continues to shop. Furthermore, the customer only has to enter passwords once on sites that require registration.
Permanent cookies can be removed manually by the user. The permanent cookies used by Klatt & Haas GbR will be stored for up to 1000 days on your hard disk. Afterwards, they are automatically deleted. Most of the standard browsers accept cookies by default. Temporary or stored cookies can be enabled or disabled independently in the browser's security settings. If cookies are disabled, certain features on Klatt & Haas GbR webpages may not be available and some websites may not be displayed correctly.
In order to use the Klatt & Haas GbR shopping cart and the checkout, session-related cookies have to be allowed! If the customer generally does not wish to, or cannot, allow cookies it is also possible to order at Klatt & Haas GbR by email, phone or fax.
Klatt & Haas GbR works with some partner companies in order to increase the value of the internet assortment and of the websites for the user. Therefore, cookies from partner companies are also stored on your website when you visit Klatt & Haas GbR websites. These cookies are "persistent" cookies. These cookies remain on the computer of the user and are automatically deleted after the specified lifetime. The lifetimes may be up to 22 years in some cases. Our partner companies do not have any access to your personal information and personal data. The pseudonymous data is never merged with your personal data. The pseudonymous data includes data about the products that were searched for or which ones were viewed and bought by the user. This information is only used to enable our partner companies to, for example, show advertising that might actually interest the user or to prevent a user seeing the same advertisements over and over.
All Your dates collected by cookies are necessary for running the contract in accordance with Art. 6 Abs. 1 S. 1 lit. f GDPR or Art 6 Abs. 1 lit b GDPR.
Use of social media, online marketing, web analytics and tracking services as well as tools of other service providers
The technologies and measures used by Klatt & Haas GbR are in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR based on our legitimate interests. With the measures and the associated statistical recording and evaluation of the use of our website, we want to ensure a needs-based design and continuous optimisation of our website and optimal marketing of our website and reach. The described data processing operations can acc. Art. 6 (1) lit. F. GDPR also exist on the basis of the legitimate interests of the individual providers (e.g. in the display of personalised advertising or to inform other users of social networks about your activities on our website).
Google Analytics
This website uses Google Analytics, including the function Universal Analytics, a web analysis service of the Google Inc. Google Analytics uses so-called Cookies, text files which are stored on your computer and which allow an analysis of the use of the website by you. Through Universal Analytics and the use of a pseudonym user ID, device-crossing activities (e.g. tablet, PC or laptop) on our website can be analysed. The information generated by the cookie concerning your use of this website (including your IP address) will be passed on to a Google server in the USA and saved there. In case of an activation of the IP-anonymization on this website, your IP-address will be shortened by Google within the member states of the European Union or in other contractual states of the Agreement on the European Economic Area. Only in exceptional cases will the complete IP-address be transmitted to a Google-server in the USA and shortened then and there. Google will use this information on behalf of this website's provider for the purpose of evaluating your website to gather reports concerning the website's activities and to furthermore provide services around this website. Google Analytics does not combine your transmitted IP-address data with other data collected by Google. You can prevent the storage of cookies by a specific setting in your browser-software; however please note that if you do this you may not be able to use the full functionality of this website. You can furthermore prevent the collection of your data (including your IP-address) by Google as well as the processing of that data by Google by downloading and installing the following browser-plugin: http://tools.google.com/dlpage/gaoptout?hl=de
Alternatively, you can prevent the processing of your data by Google by clicking on the following link: Click here, to be excluded from the Google Analytics measurement protocol.
Google is certified for the US-American data protection convention "Privacy Sield".
We hereby point out that this website uses Google Analytics including Universal Analytics with the add-on "anonymizeIp()", which is in accordance with privacy regularities. IP-addresses thereby are processed only in a shortened version to exclude any possibility of direct personal relation.
Facebook Plugins
Our website also includes plugins by the social network Facebook. Our website is configured so that a direct connection between your browser and the Facebook server is made only when you click on a Facebook plugin. A connection will not be made automatically as soon as you open our website. Data is transmitted to Facebook only after you click on the plug-in, consciously "activating" it. If you click on the Facebook button while you're logged in on your Facebook account, Facebook can possibly associate the visit to our website with your account. We would like to point out that as the provider of the web page we have no knowledge of the content of the transmitted data or of their use through Facebook. Further information about this can be found in Facebook's Data Policy: http://de-de.facebook.com/policy.php. If you do not wish for Facebook to be able to associate the visit of our website with your Facebook account, please do not click on the Facebook plugins or log out of your Facebook account.
Facebook is certified for the US-American data protection convention "Privacy Sield".
Google+
Our website uses plugins by the social network Google+ (Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Our website is configured so that a direct connection between your browser and the Google+ server is made only when you click on a Google+ plugin. A connection will not be made automatically as soon as you open our website. Data is transmitted to Google only after you click on a plug-in, consciously "activating" it. If you click on the Google+ button while you're logged in on your Google+ account, Google can possibly associate the visit to our website with your account. We would like to point out that as the provider of the web page we have no knowledge of the content of the transmitted data or of their use through Google. Further information and settings options can be found in the Google+ privacy policy here: http://www.google.com/intl/de/+/policy/+1button.html. If you do not wish for Google+ to be able to associate the visit of our website with your Google+ account, please do not click on the Google+ plugins or log out of your Google+ account.
Google is certified for the US-American data protection convention "Privacy Sield".
Deletion and blocking of personal data
We only process and store personal data for the period of time required to achieve the purpose of storage (e.g. due business transaction) or which corresponds to a legal storage / retention period. If the purpose of the storage is omitted or if a legal storage / retention period expires, the personal data will be deleted. If legal storage / storage obligations should continue to exist, e.g. after proper business transaction or having answered your inquiry, we will restrict the processing, e.g. by blocking your data. If retention periods relating to commercial or tax law must be observed, the storage time for particular data may equal up to 10 years.
Rights of the affected person
As an affected person(s), you have the right:
" to demand information about your personal data processed by Klatt & Haas GbR in accordance with Art. 15 GDPR. In particular, you have the right to information regarding processing purposes, the recipients or categories of recipients to whom the personal data have been disclosed, the planned duration for which the personal data is stored, the right of rectification, deletion, limitation of the processing or the right to object to such processing, all available information on the source of the information, and the existence of an automated decision-making process;
" to request the immediate correction or completion of incomplete personal data in accordance with Art. 16 GDPR;
" to demand, in accordance with Art. 17 GDPR, the immediate deletion of your personal data, unless the processing is necessary for the fulfilment of a legal obligation by Klatt & Haas GbR or for the performance of a public interest task or in the exercise of public authority delegated to Klatt & Haas GbR and /or assertion, exercise, or defence of legal claims;
" to demand the restriction of the processing of your personal data in accordance with Art. 18 GDPR, as far as the accuracy of the personal data is disputed by you, the processing is unlawful but you refuse its deletion and we no longer need the data, but you require them to assert exercise or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR;
" to receive personally identifiable information provided to Klatt & Haas GbR in accordance with Art. 20 GDPR, in a structured, common and machine-readable format, and to transfer that data to another responsible person;
" to revoke your once given consent to us at any time pursuant to Art. 7 para. 3 GDPR. As a result, we are not allowed to continue the data processing based on this consent for the future and
" to lodge a complaint to a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or work or our company headquarters.
Right to withdraw
If your personal data is based on legitimate interests in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, you have the right to file an objection against the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is directed against direct marketing. In the latter case, you have a general right of objection, which is implemented by us without specifying any particular situation.
If you exercise your right of objection, we will stop the processing of the data concerned. However, we can continue to process your personal data, despite your objections, if in the case of processing based on legitimate interests or on the performance of a task in the public interest/exercise of official authority, we can prove that we have compelling legitimate grounds that override your interests, rights and freedoms.
If you would like to make use of your rights, please send us an e-mail: fragen@haeute.com