If you have discovered something, please send me a short email. Thank you. My email address: hello@carlhenkel.com
The data controller is:
Carl Henkel GmbH
Zürichstrasse 11
6004 Luzern
Switzerland
info@carlhenkel.com
Thank you for your interest in our online shop. The protection of your privacy is very important to us. Below, we inform you in detail about the handling of your data.
1. Access Data and Hosting
You can visit our websites without providing any personal information. With each access to a website, the web server merely automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, date and time of access, amount of data transferred, and the requesting provider (access data), and documents the access. This access data is exclusively evaluated for the purpose of ensuring the trouble-free operation of the site and improving our offer. This serves to protect our legitimate interests in a correct presentation of our offer, which are predominant in the context of a balancing of interests, in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR. All access data will be deleted no later than seven days after the end of your visit to the site.
Hosting
The services for hosting and displaying the website are partly provided by our service providers as part of processing on our behalf. Unless otherwise explained in this privacy policy, all access data and all data collected in forms provided for this purpose on this website are processed on their servers. For questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
2. Data Processing for Contract Execution, Contacting, and Account Opening
We collect personal data when you voluntarily provide it to us in the context of your order or when contacting us (e.g., via contact form or email). Mandatory fields are marked as such, as in these cases we urgently need the data for contract processing or for processing your contact request, and you cannot send the order or contact request without providing them. Which data is collected can be seen from the respective input forms. We use the data you provide for contract execution and processing your inquiries in accordance with Art. 6 Para. 1 S. 1 lit. b GDPR.
If you have given your consent according to Art. 6 Para. 1 S. 1 lit. a GDPR by deciding to open a customer account, we use your data for the purpose of opening the customer account. Further information on the processing of your data, especially on the transfer to our service providers for the purpose of order, payment, and shipping processing, can be found in the following sections of this privacy policy. After complete execution of the contract or deletion of your customer account, your data will be restricted for further processing and deleted after the expiry of tax and commercial retention periods in accordance with Art. 6 Para. 1 S. 1 lit. c GDPR, unless you have expressly consented to further use of your data in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR or we reserve the right to further data use that is legally permitted and about which we inform you in this statement. The deletion of your customer account is possible at any time and can be done either by a message to the contact option described in this privacy policy or via a dedicated function in the customer account.
3. Data Processing for Shipping Purposes
For the fulfillment of the contract in accordance with Art. 6 Para. 1 S. 1 lit. b GDPR, we pass on your data to the shipping service provider commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods.
Data transfer to shipping service providers for the purpose of delivery notification
If you have given us your express consent for this during or after your order, we will, based on this, pass on your email address and telephone number to the selected shipping service provider in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR, so that they can contact you before delivery for the purpose of delivery notification or coordination.
You can revoke your consent at any time by sending a message to the contact option described in this privacy policy or directly to the shipping service provider at the contact address listed below. After revocation, we will delete your data provided for this purpose, unless you have expressly consented to further use of your data or we reserve the right to further data use that is legally permitted and about which we inform you in this statement.
DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany
4. Data Processing for Payment Processing
When processing payments in our online shop, we work with the following partners: technical service providers, credit institutions, payment service providers.
4.1 Data Processing for Transaction Processing
Depending on the selected payment method, we pass on the data necessary for the processing of the payment transaction to our technical service providers, who act on our behalf as part of order processing, or to the commissioned credit institutions or to the selected payment service provider, insofar as this is necessary for payment processing. This serves to fulfill the contract in accordance with Art. 6 Para. 1 S. 1 lit. b GDPR. In some cases, payment service providers collect the data required for payment processing themselves, e.g., on their own website or through a technical integration in the order process. In this respect, the privacy policy of the respective payment service provider applies.
For questions about our partners for payment processing and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
4.2 Data Processing for Fraud Prevention and Optimization of Our Payment Processes
If necessary, we pass on further data to our service providers, which they use together with the data necessary for payment processing as our processors for the purpose of fraud prevention and optimizing our payment processes (e.g., invoicing, processing of disputed payments, accounting support). This serves, in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR, to protect our predominant legitimate interests in securing ourselves against fraud and in efficient payment management as part of a balancing of interests.
4.3 Use of Payment Service Providers
Mollie
If you choose a payment method from the payment service provider Mollie, payment processing takes place via the payment service provider Mollie B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands, to whom we transfer the information you provided during the order process, along with information about your order (name, address, IBAN, BIC, invoice amount, currency, and transaction number) in accordance with Art. 6 Para. 1 lit. b GDPR. The transfer of your data is exclusively for the purpose of payment processing with the payment service provider Mollie and only to the extent necessary for this. Mollie's privacy policy can be found here: https://www.mollie.com/de/privacy
PayPal
When paying via PayPal, credit card via PayPal, direct debit via PayPal or – if offered – "purchase on account" or "installment payment" via PayPal, we transfer your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of payment processing. The transfer takes place in accordance with Art. 6 Para. 1 lit. b GDPR and only to the extent necessary for payment processing.
PayPal reserves the right to carry out a credit check for the payment methods credit card via PayPal, direct debit via PayPal or – if offered – "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 Para. 1 lit. f GDPR based on PayPal's legitimate interest in determining your solvency. PayPal uses the result of the credit check regarding the statistical probability of payment default for the purpose of deciding whether to provide the respective payment method. The credit check may contain probability values (so-called score values). Insofar as score values are included in the result of the credit check, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, but not exclusively, is included in the calculation of the score values. Further data protection information, including about the credit agencies used, can be found in PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
SOFORT / KLARNA
In order to offer you Klarna’s payment methods, we might pass your personal data in the form of contact and order details to Klarna during the checkout process. This is done so that Klarna can assess whether you are eligible for their payment methods and to tailor those methods to you. Your personal data transferred is processed in line with Klarna’s own privacy notice.
If you choose the payment method "SOFORT," payment processing takes place via the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we transfer the information you provided during the order process, along with information about your order, in accordance with Art. 6 Para. 1 lit. b GDPR. Sofort GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). The transfer of your data is exclusively for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary for this. Further information on SOFORT's data protection regulations can be found at the following internet address: https://www.klarna.com/sofort/datenschutz.
5. Email Advertising
5.1 Email Newsletter with Registration
If you subscribe to our newsletter, we use the data required for this or separately provided by you to regularly send you our email newsletter based on your consent in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR. Unsubscribing from the newsletter is possible at any time and can be done either by a message to the contact option described below or via a dedicated link in the newsletter. After unsubscribing, we will delete your email address from the recipient list, unless you have expressly consented to further use of your data in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR or we reserve the right to further data use that is legally permitted and about which we inform you in this statement.
5.2 Newsletter Dispatch
The newsletter may also be sent by our service providers as part of processing on our behalf. For questions about our service providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
6. Cookies and Other Technologies General Information
To make visiting our website attractive and to enable the use of certain functions, we use technologies, including so-called cookies, on various pages. Cookies are small text files that are automatically stored on your end device. Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognize your browser on your next visit (persistent cookies).
We use such technologies that are absolutely necessary for the use of certain functions of our website (e.g., shopping cart function). Through these technologies, IP address, time of visit, device and browser information, and information about your use of our website (e.g., information about the contents of the shopping cart) are collected and processed. This serves, in the context of a balancing of interests, our predominant legitimate interests in an optimized presentation of our offer in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR.
In addition, we use technologies to fulfill the legal obligations we are subject to (e.g., to be able to prove consent to the processing of your personal data) as well as for web analysis and online marketing. Further information on this, including the respective legal basis for data processing, can be found in the following sections of this privacy policy.
You can find the cookie settings for your browser under the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™
If you have consented to the use of technologies in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR, you can revoke your consent at any time by sending a message to the contact option described in the privacy policy.
7. Use of Cookies and Other Technologies for Web Analysis and Advertising Purposes
If you have given your consent in accordance with Art. 6 Para. 1 S. 1 lit. a GDPR, we use the following cookies and other technologies from third-party providers on our website. After the purpose has ceased and the use of the respective technology by us has ended, the data collected in this context will be deleted. You can revoke your consent at any time with effect for the future. Further information on your revocation options can be found in the section "Cookies and Other Technologies". Further information, including the basis of our cooperation with the individual providers, can be found in the individual technologies. For questions about the providers and the basis of our cooperation with them, please contact the contact option described in this privacy policy.
7.1 Use of Google Services
We use the technologies of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google") presented below. The information about your use of our website automatically collected by Google technologies is usually transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there. There is no adequacy decision from the European Commission for the USA. Our cooperation is based on standard contractual clauses of the European Commission. If your IP address is collected via Google technologies, it will be truncated before being stored on Google's servers by activating IP anonymization. Only in exceptional cases will the full IP address be transmitted to a Google server and truncated there. Unless otherwise specified for individual technologies, data processing takes place on the basis of an agreement on joint controllership concluded for the respective technology in accordance with Art. 26 GDPR. Further information on data processing by Google can be found in Google's privacy policy.
Google Analytics
For the purpose of website analysis, data (IP address, time of visit, device and browser information, and information about your use of our website) is automatically collected and stored with Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Your IP address is generally not merged with other Google data. Data processing is based on an agreement on order processing by Google.
For the purpose of optimized marketing of our website, we have activated the data sharing settings for "Google products and services." This allows Google to access and then use the data collected and processed by Google Analytics to improve Google services. Data sharing with Google as part of these data sharing settings is based on an additional agreement between controllers. We have no influence on the subsequent data processing by Google.
For web analysis and advertising purposes, the so-called DoubleClick cookie, an extension function of Google Analytics, enables your browser to be recognized when visiting other websites. Google will use this information to compile reports on website activity and to provide further services associated with website usage.
For website analysis and event tracking, we measure your subsequent usage behavior via Google Ads Conversion Tracking if you have reached our website via a Google Ads advertisement. For this purpose, cookies can be used and data (IP address, time of visit, device and browser information, and information about your use of our website based on events specified by us, such as visiting a website or subscribing to a newsletter) can be collected, from which usage profiles are created using pseudonyms.
Google reCAPTCHA
For the purpose of protecting against misuse of our web forms and against spam by automated software (so-called bots), Google reCAPTCHA collects data (IP address, time of visit, browser information and information about your use of our website) and analyzes your use of our website using a JavaScript and cookies. In addition, other cookies stored by Google services in your browser are evaluated. No personal data from the input fields of the respective form is read or stored.
Google Fonts
For the uniform display of content on our website, data (IP address, time of visit, device and browser information) is collected by the script code "Google Fonts", transmitted to Google and then processed by Google. We have no influence on this subsequent data processing.
YouTube Video Plugin
To embed third-party content, data (IP address, time of visit, device and browser information) is collected via the YouTube Video Plugin in the extended data protection mode we use, transmitted to Google and subsequently processed by Google, only when you play a video.
7.2 Use of Facebook Services Use of Facebook Pixel
We use the Facebook Pixel as part of the technologies of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook") as described below. With the Facebook Pixel, data (IP address, time of visit, device and browser information as well as information about your use of our website based on events specified by us, such as visiting a website or subscribing to a newsletter) is automatically collected and stored, from which usage profiles are created using pseudonyms. As part of the so-called extended data matching, information for matching purposes is also collected and stored in hashed form, which can be used to identify individuals (e.g. names, email addresses and phone numbers). For this purpose, when you visit our website, the Facebook Pixel automatically sets a cookie that automatically enables your browser to be recognized when you visit other websites using a pseudonymous CookieID. Facebook will combine this information with other data from your Facebook account and use it to compile reports on website activities and to provide other services related to website usage, in particular personalized and group-based advertising.
The information about your use of our website automatically collected by Facebook technologies is usually transferred to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. There is no adequacy decision by the European Commission for the USA. Insofar as the data transfer to the USA falls within our responsibility, our cooperation is based on standard data protection clauses of the European Commission. Further information on data processing by Facebook can be found in the Facebook data protection notices.
Facebook Analytics
As part of Facebook Analytics, statistics on visitor activities on our website are created from the data collected via the Facebook Pixel about your use of our website. Data processing is based on an agreement on order processing by Facebook. Its analysis serves the optimal presentation and marketing of our website.
Facebook Ads
We advertise this website on Facebook and other platforms via Facebook Ads. We determine the parameters of the respective advertising campaign. Facebook is responsible for the exact implementation, in particular the decision on the placement of ads for individual users. Unless otherwise specified in the individual technologies, data processing is based on an agreement between joint controllers according to Art. 26 GDPR. Joint responsibility is limited to the collection of data and its transmission to Facebook Ireland. Subsequent data processing by Facebook Ireland is not covered by this.
7.3 Use of Klar! Pixel
We use the services of Klar (Klar Insights GmbH, Marktstr. 18, 80802 Munich, Germany) on our website. Klar collects, processes and stores data on this website and its subpages for reach measurement and statistical analysis on our behalf. This collection is based on the following legal basis:
If the user has given consent according to Art. 6 Para. 1 S. 1 a GDPR and § 25 Para. 1 S. 1 TTDSG, the data to be processed will be collected user-related.
Different cookies are used for the aforementioned different types of collection to ensure the respective type of collection.
To generally object to the use of Klar, please use this [link](https://1724043625.carlhenkel.com/donottrack/me). This will set a cookie named "do_not_track" from the domain "carlhenkel.com". Please do not delete this, otherwise it cannot be guaranteed that you will not be tracked by Klar.
Information on data protection and data use by Klar can be found on the following website: [https://www.getklar.com/data-protection](https://www.getklar.com/data-protection)
7.4 Other providers of web analytics and online marketing services Use of Vimeo Video Plugin for embedding third-party content
To embed third-party content, data (IP address, time of visit, device and browser information) is collected via the video plugin of Vimeo LLC, 555 West 18th Street, New York 10011, USA ("Vimeo"), transmitted to Vimeo and subsequently processed by Vimeo. Data processing is based on an agreement between joint controllers according to Art. 26 GDPR. Google Analytics is automatically integrated into the Vimeo Video Plugin. For the purpose of website analysis, data (IP address, time of visit, device and browser information and information about your use of our website) is automatically collected and stored with Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. Google Analytics is a service of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information about your use of our website automatically collected by Google is usually transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. Your IP address will be shortened before being stored on Google's servers by activating IP anonymization. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. We have no influence and access to data processing by Vimeo, including the settings and results of Google Analytics. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission.
8. Integration of the Trusted Shops Trustbadge
The Trusted Shops Trustbadge is integrated on this website to display our Trusted Shops seal of approval and any collected reviews, and to offer Trusted Shops products to buyers after an order.
This serves to protect our predominantly legitimate interests in optimal marketing through enabling secure shopping, which are balanced within the scope of a weighing of interests, in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. The Trustbadge and the services advertised with it are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne. The Trustbadge is provided within the framework of order processing by a CDN provider (Content Delivery Network). Trusted Shops GmbH also uses service providers from the USA. An adequate level of data protection is ensured. Further information on data protection at Trusted Shops GmbH can be found here.
When the Trustbadge is called up, the web server automatically stores a so-called server log file, which also contains your IP address, date and time of retrieval, amount of data transferred and the requesting provider (access data) and documents the retrieval. Individual access data is stored in a security database for the analysis of security anomalies. The log files are automatically deleted at the latest 90 days after creation.
Further personal data is transferred to Trusted Shops GmbH if you decide to use Trusted Shops products after completing an order or have already registered for use. The contractual agreement made between you and Trusted Shops applies. For this purpose, personal data from the order data is automatically collected. Whether you, as a buyer, are already registered for product use is automatically checked using a neutral parameter, the email address hashed using a cryptographic one-way function. The email address is converted into this hash value, which cannot be decrypted by Trusted Shops, before transmission. After checking for a match, the parameter is automatically deleted.
This is necessary for the fulfillment of our and Trusted Shops' predominantly legitimate interests in providing buyer protection linked to the specific order and transactional review services in accordance with Art. 6 Para. 1 S. 1 lit. f GDPR. Further details, including regarding objection, can be found in the Trusted Shops privacy policy linked above and in the Trustbadge.
9. Social Media Our online presence on Facebook, Instagram, YouTube, Pinterest
Provided that you have given your consent to the respective social media operator in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, when you visit our online presences on the social media platforms mentioned above, your data will be automatically collected and stored for market research and advertising purposes, from which usage profiles will be created using pseudonyms. These can be used, for example, to place advertisements within and outside the platforms that presumably correspond to your interests. Cookies are generally used for this purpose. For detailed information on the processing and use of data by the respective social media operator, as well as contact options and your rights and setting options for protecting your privacy, please refer to the providers' privacy policies linked below. Should you still require assistance, you can contact us.
Facebook is an offering of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). The information about your use of our online presence on Facebook automatically collected by Facebook Ireland is generally transmitted to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission. Data processing in the context of visiting a Facebook fan page is based on an agreement between jointly responsible parties in accordance with Art. 26 GDPR. Further information (information on Insights data) can be found here.
Instagram is an offering of Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). The information about your use of our online presence on Instagram automatically collected by Facebook Ireland is generally transmitted to a server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission. Data processing in the context of visiting an Instagram fan page is based on an agreement between jointly responsible parties in accordance with Art. 26 GDPR. Further information (information on Insights data) can be found here.
YouTube is an offering of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information about your use of our online presence on YouTube automatically collected by Google is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission.
Pinterest is an offering of Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest"). The information about your use of our online presence on Pinterest automatically collected by Pinterest is generally transmitted to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA and stored there. There is no adequacy decision by the European Commission for the USA. Our cooperation is based on standard data protection clauses of the European Commission.
10. Contact options and your rights
As a data subject, you have the following rights:
- in accordance with Art. 15 GDPR, the right to request information about your personal data processed by us to the extent specified therein;
- in accordance with Art. 16 GDPR, the right to demand the immediate rectification of inaccurate personal data stored by us or its completion;
- in accordance with Art. 17 GDPR, the right to demand the erasure of your personal data stored by us, unless further processing is
- in accordance with Art. 18 GDPR, the right to demand the restriction of the processing of your personal data, if
- in accordance with Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to demand its transmission to another controller;
- in accordance with Art. 77 GDPR, the right to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose.
If you have any questions regarding the collection, processing or use of your personal data, for information, rectification, restriction or erasure of data, as well as revocation of granted consents or objection to a specific data use, please contact us directly using the contact details in our impressum.
Right to object
Insofar as we process personal data as explained above to protect our predominantly legitimate interests within the scope of a balancing of interests, you can object to this processing with effect for the future. If the processing is carried out for direct marketing purposes, you can exercise this right at any time as described above. If the processing is carried out for other purposes, you have a right to object only if there are reasons arising from your particular situation.
After exercising your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves to assert, exercise or defend legal claims.
This does not apply if the processing is carried out for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.
Privacy policy created with rechtstexter.de.


