Privacy Policy

INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE RESPONSIBLE PARTY

1.1 We are pleased that you are visiting our website and thank you for your interest. The following informs you about how we handle your personal data when you use our website. Personal data is any information by which you can be personally identified.
1.2 The party responsible for data processing on this website under the General Data Protection Regulation (GDPR) is Shop Name. The responsible party for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the "https://" string and the lock symbol in your browser's address bar.

DATA COLLECTION WHEN VISITING OUR WEBSITE

When you use our website for informational purposes only, i.e., when you do not register or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

  • Our website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/reference from which you accessed the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form).

Processing is carried out in accordance with Article 6 para. 1 lit. f of the GDPR based on our legitimate interest in improving the stability and functionality of our website. The data is not transferred or used for other purposes. However, we reserve the right to review server log files subsequently should specific indications point to unlawful use.

COOKIES

To make our website attractive to visit and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files stored on your device. Some of the cookies we use are deleted after the browser session ends, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). If cookies are set, they collect and process specific user information such as browser and location data and IP address values in an individualized manner. Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.

Cookies are partly used to simplify the ordering process by saving settings (e.g., remembering the content of a virtual shopping cart for a later visit). If personal data is also processed by individual cookies we use, the processing is carried out under Article 6 para. 1 lit. b GDPR either for contract execution or under Article 6 para. 1 lit. f GDPR to safeguard our legitimate interests in ensuring the best possible functionality of the website and a customer-friendly and effective design of the site visit.

We may collaborate with advertising partners who help us make our internet offering more interesting for you. For this purpose, cookies from partner companies (third-party cookies) may also be stored on your hard drive when you visit our website. If we collaborate with the aforementioned advertising partners, you will be informed individually and separately about the use of such cookies and the information collected within the following paragraphs.

Please note that you can configure your browser to notify you of cookie settings and decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general. Each browser differs in how it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find them for the respective browsers at the following links:

Please note that if you do not accept cookies, the functionality of our website may be limited.

CONTACTING US

If you contact us (e.g., via contact form or email), personal data will be collected. The data collected in the case of a contact form is visible from the respective contact form. This data is stored and used solely for the purpose of responding to your request or for establishing contact and the related technical administration. The legal basis for processing the data is our legitimate interest in responding to your request pursuant to Article 6 para. 1 lit. f GDPR. If your contact aims at the conclusion of a contract, the additional legal basis for the processing is Article 6 para. 1 lit. b GDPR. Your data will be deleted after your request has been processed, provided that the circumstances indicate that the matter concerned has been conclusively clarified and there are no statutory retention obligations to the contrary.

DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING

Personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. The data collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be requested by sending a message to the responsible party's address mentioned above. We store and use the data you provide for contract processing. After the contract has been processed in full or your customer account has been deleted, your data will be blocked concerning retention periods under tax and commercial law and deleted after these periods have expired unless you have expressly consented to further use of your data or we have reserved a legally permitted further data use, about which we will inform you below.

USE OF YOUR DATA FOR DIRECT ADVERTISING

6.1 Subscription to our email newsletter
If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. The provision of further data is voluntary and is used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an email newsletter after you have expressly confirmed that you consent to the receipt of the newsletter. We will then send you a confirmation email asking you to confirm that you want to receive the newsletter by clicking on a corresponding link.

By activating the confirmation link, you consent to the use of your personal data pursuant to Article 6 para. 1 lit. a GDPR. When registering for the newsletter, we store your IP address as entered by your internet service provider (ISP) as well as the date and time of registration to trace any possible misuse of your email address at a later time. The data collected by us when you register for the newsletter will be used exclusively for promotional purposes via the newsletter. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a message to the responsible party mentioned above. After unsubscribing, your email address will immediately be deleted from our newsletter distribution list unless you have expressly consented to further use of your data, or we reserve the right to use data in a way permitted by law, about which we inform you in this policy.

6.2 Email advertising for existing customers
If you have provided us with your email address when purchasing goods or services, we reserve the right to send you regular offers for similar goods or services from our range by email. According to § 7 para. 3 UWG, we do not need to obtain separate consent for this. The processing of data in this context is based solely on our legitimate interest in personalized direct advertising pursuant to Article 6 para. 1 lit. f GDPR. If you initially objected to the use of your email address for this purpose, we will not send you emails. You are entitled to object to the use of your email address for the aforementioned advertising purposes at any time with effect for the future by notifying the responsible party named above. You only have to pay the transmission costs according to the basic tariffs. After receiving your objection, the use of your email address for advertising purposes will cease immediately.


7.2 Use of Payment Service Providers

PayPal
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal, we pass your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. The transfer is made in accordance with Article 6 para. 1 lit. b GDPR and only to the extent necessary for payment processing.

PayPal reserves the right to carry out a creditworthiness check for payment methods such as credit card via PayPal, direct debit via PayPal, or – if offered – "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be shared with credit agencies in accordance with Article 6 para. 1 lit. f GDPR, based on PayPal’s legitimate interest in determining your creditworthiness. PayPal uses the result of the credit check, in relation to the statistical probability of default, to decide whether to provide the respective payment method. The credit report may contain probability values (so-called scores). These scores are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of the scores.

Further information on data protection, including the credit agencies used, can be found in PayPal's privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-full.

You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if necessary for contractual payment processing.

Credit Card Payments
If you choose to pay by credit card (Visa, MasterCard, or American Express), payment processing will be handled through our authorized payment gateway provider. Your payment data, such as cardholder name, credit card number, expiration date, and CVV code, will be securely encrypted and transmitted in compliance with Payment Card Industry Data Security Standard (PCI DSS) guidelines.

The processing of your credit card payment is carried out in accordance with Article 6 para. 1 lit. b GDPR and is necessary for the execution of the contract. For New Zealand-based customers, our payment gateway provider complies with local regulations, ensuring all transactions meet the New Zealand Privacy Act 2020 standards.

We do not store your credit card details on our servers. The payment gateway provider processes your data only to the extent necessary to complete your payment and adheres to strict security measures to protect your information.

SOFORT
If you select the payment method "SOFORT," payment processing will be carried out via the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we pass on the information you provided during the order process, along with information about your order, in accordance with Article 6 para. 1 lit. b GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). Your data is shared exclusively for the purpose of payment processing with SOFORT and only to the extent necessary. Further information on SOFORT's data protection provisions is available at: https://www.sofort.com/payment/wizard/getCmsContent/dataProtection/EN.

For any inquiries related to payment security or concerns specific to New Zealand, you can contact us at support@avery-auckland.com.

8) INVITATION FOR REVIEW REQUESTS

Our Own Review Request (not sent via a customer review system)
We may use your email address to send you a one-time invitation to submit a review of your order via our own review system, provided you have given us your explicit consent to do so during or after your order, pursuant to Article 6 para. 1 lit. a GDPR. You can revoke your consent at any time by sending a message to the data controller.


9) USE OF SOCIAL MEDIA PLUGINS

9.1 Facebook Plugins with Shariff Solution
Our website uses so-called social media plugins (“plugins”) from the Facebook social network, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”).

To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins but are instead integrated using an HTML link. This integration ensures that no connection to Facebook’s servers is established when you visit a page on our website containing such buttons. If you click on a button, a new browser window will open, directing you to Facebook’s page where you can interact with the plugins (possibly after entering your login details).

Facebook Inc. is certified under the EU-U.S. Privacy Shield framework, which ensures compliance with European data protection standards. For more information about how Facebook handles user data, please refer to Facebook’s privacy policy: https://www.facebook.com/policy.php.

9.2 Instagram Plugins with Shariff Solution
Our website uses so-called social media plugins (“plugins”) from the Instagram service, operated by Instagram LLC, 1601 Willow Rd, Menlo Park, CA 94025, USA (“Instagram”).

As with Facebook, these buttons are integrated using an HTML link to improve the protection of your data when visiting our website. This ensures no connection is established with Instagram’s servers when you access a page on our website containing such buttons. If you click on the button, a new browser window will open, directing you to Instagram’s page where you can interact with the plugins (possibly after entering your login details).

Instagram LLC is also certified under the EU-U.S. Privacy Shield framework. For more information on Instagram’s data privacy policies, visit: https://help.instagram.com/519522125107875.


10) ONLINE MARKETING

10.1 Google Ads Conversion Tracking
This website uses the online advertising program "Google Ads" and, within the framework of Google Ads, conversion tracking by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

If you click on an ad placed by Google, a conversion tracking cookie will be stored on your device. These cookies expire after 30 days and are not used for personal identification. If the user visits specific pages on this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google Ads customer receives a different cookie. Cookies cannot be tracked across Google Ads customers’ websites.

The information collected through the conversion cookie is used to compile conversion statistics for Google Ads customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive information that personally identifies users.

If you do not wish to participate in tracking, you can object to this use by disabling the Google conversion tracking cookie via your internet browser’s user settings. You will then not be included in the conversion tracking statistics. The legal basis for data processing is Article 6 para. 1 lit. f GDPR, based on our legitimate interest in targeted advertising and analyzing the effectiveness of our advertisements.

For more information about Google Ads privacy, visit: https://policies.google.com/privacy.

10.2 Google Remarketing
Our website uses the Google Ads Remarketing function to advertise this website in Google search results and on third-party websites. The service provider is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

For this purpose, Google places a cookie in the browser of your device, which automatically enables interest-based advertising based on pseudonymous cookie IDs and the pages you visit. Data processing occurs based on Article 6 para. 1 lit. f GDPR, derived from our legitimate interest in the optimal marketing of our website.

Further data processing will only occur if you have agreed with Google to link your internet and app browsing history to your Google account and use information from your Google account to personalize ads. In this case, if you are logged in to Google while visiting our website, Google will use your data along with Google Analytics data to create and define audience lists for cross-device remarketing.

To disable the placement of cookies for ad preferences permanently, you can download and install the browser plugin available at the following link: https://support.google.com/ads/answer/7395996.

Alternatively, you can adjust your ad preferences directly in your Google account at: https://adssettings.google.com.

11) WEB ANALYTICS SERVICES

Google (Universal) Analytics
This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). Google Analytics uses so-called “cookies,” which are text files placed on your computer to help the website analyze how users use the site. The information generated by the cookie about your use of this website (including your shortened IP address) is usually transmitted to a Google server in the USA and stored there.

This website uses Google Analytics exclusively with the extension "_anonymizeIp()," which ensures anonymization of the IP address by truncation and excludes direct personal reference. With this extension, your IP address is truncated by Google within the member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there.

In these exceptional cases, this processing takes place in accordance with Article 6 para. 1 lit. f GDPR, based on our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes. Google uses this information on our behalf to evaluate your use of the website, compile reports on website activity, and provide us with other services relating to website activity and internet usage.

The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. You can prevent the storage of cookies by adjusting your browser software settings accordingly. However, please note that in this case, you may not be able to use all features of this website to their full extent.

You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) by Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout.

As an alternative to the browser plugin or within browsers on mobile devices, click on the following link to set an opt-out cookie, which will prevent the collection by Google Analytics within this website in the future (this opt-out cookie only works in this browser and for this domain. If you delete your cookies in this browser, you must click this link again): Disable Google Analytics

For more information on how Google Analytics handles user data, refer to Google’s privacy policy: https://support.google.com/analytics/answer/6004245.


12) RETARGETING/REMARKETING/RECOMMENDATION ADVERTISING

Facebook Custom Audience via the Pixel Process
This website uses Facebook’s “Facebook Pixel” to create custom audiences, provided by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA (“Facebook”). If explicit consent is granted, this tool enables the tracking of user behavior after they have seen or clicked on a Facebook advertisement.

This process is used to evaluate the effectiveness of Facebook ads for statistical and market research purposes and may help optimize future advertising efforts. The collected data is anonymous to us, so we cannot draw any conclusions about the identity of users. However, Facebook stores and processes the data, making it possible to connect to the respective user profile, and Facebook may use the data for its advertising purposes in accordance with the Facebook Data Policy (https://www.facebook.com/about/privacy).

This may allow Facebook and its partners to display advertisements on and off Facebook. A cookie may also be stored on your computer for these purposes. These processing activities are carried out only with your explicit consent under Article 6 para. 1 lit. a GDPR.

Consent to the use of the Facebook Pixel can only be given by users over 13 years of age. If you are younger, please ask your guardian for permission.

Facebook Inc., based in the USA, is certified under the EU-U.S. Privacy Shield framework, which ensures compliance with European data protection standards.

You can disable the use of cookies on your device by adjusting your browser settings to prevent the storage of future cookies or delete existing cookies. Please note that disabling all cookies may limit the functionality of our website.

For more information about data collection and processing by Facebook, as well as your rights in this regard and settings options for protecting your privacy, please visit Facebook’s privacy policy: https://www.facebook.com/about/privacy.


13) RIGHTS OF THE DATA SUBJECT

The applicable data protection law grants you comprehensive rights as a data subject regarding the processing of your personal data (rights of access and intervention), which we inform you about below:

13.1 Right of Access under Article 15 GDPR
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed and, where that is the case, access to the personal data and the following information:

  • The purposes of the processing;
  • The categories of personal data concerned;
  • The recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organizations;
  • Where possible, the envisaged period for which the personal data will be stored or, if not possible, the criteria used to determine that period;
  • The existence of the right to request rectification or erasure of personal data or restriction of processing of personal data concerning you or to object to such processing;
  • The right to lodge a complaint with a supervisory authority;
  • Where the personal data is not collected from you, any available information as to their source;
  • The existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for you;
  • Where personal data is transferred to a third country or an international organization, the appropriate safeguards pursuant to Article 46 GDPR relating to the transfer.

13.2 Right to Rectification under Article 16 GDPR
You have the right to obtain from us the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by providing a supplementary statement.

13.3 Right to Erasure under Article 17 GDPR
You have the right to request the deletion of your personal data if the conditions under Article 17 para. 1 GDPR are met. This right does not apply, in particular, where processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims.

13.4 Right to Restriction of Processing under Article 18 GDPR
You have the right to request the restriction of processing of your personal data if one of the following conditions is met:

  • You contest the accuracy of the personal data for a period enabling us to verify its accuracy;
  • The processing is unlawful, and you oppose the erasure of the personal data and request the restriction of its use instead;
  • We no longer need the personal data for the purposes of the processing, but you require it for the establishment, exercise, or defense of legal claims;
  • You have objected to processing pursuant to Article 21 para. 1 GDPR pending the verification of whether our legitimate grounds override yours.

13.5 Right to Notification under Article 19 GDPR
If you have asserted the right to rectification, erasure, or restriction of processing against the controller, the controller is obliged to communicate any rectification or erasure of personal data or restriction of processing to each recipient to whom the personal data has been disclosed unless this proves impossible or involves disproportionate effort. You have the right to be informed about these recipients.

13.6 Right to Data Portability under Article 20 GDPR
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and you have the right to transmit those data to another controller without hindrance from us, provided that the processing is based on your consent or a contract and the processing is carried out by automated means.

13.7 Right to Withdraw Consent under Article 7 para. 3 GDPR
You have the right to withdraw your consent at any time with effect for the future. If you withdraw your consent, we will delete the data concerned immediately, provided further processing cannot be based on a legal basis for consent-free processing. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

13.8 Right to Lodge a Complaint under Article 77 GDPR
If you consider that the processing of personal data relating to you infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, without prejudice to any other administrative or judicial remedy.

13.9 Right to Object under Article 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you based on Article 6 para. 1 lit. e or f GDPR. This also applies to profiling based on these provisions.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.

If we process your personal data for direct marketing purposes, you have the right to object at any time to processing for such marketing. If you object, your personal data will no longer be used for direct marketing.

14) DURATION OF STORAGE OF PERSONAL DATA

The duration of the storage of personal data is determined based on the respective legal retention period (e.g., retention periods under commercial and tax law). After the expiration of this period, the corresponding data is routinely deleted, provided it is no longer necessary for the fulfillment or initiation of a contract and/or there is no longer any legitimate interest on our part in the further storage.

If you have any further questions about data protection or wish to exercise your rights, you can contact us at any time at support@avery-auckland.com.