Privacy policy
Controller:
Sonia Abassi, Arnulfstraße 26, 40545 Düsseldorf, Germany
Email: info@soniaabassijewelry.com
1. Access Data & Hosting
You may visit our website without disclosing personal data. Each time a page is accessed, the server stores a log file (e.g., requested file name, IP address, date/time, transferred data volume, requesting provider).
Processing is based on our legitimate interests in stable operation and improvement (Art. 6(1)(f) GDPR). Access logs are deleted no later than 7 days after your visit.
Hosting:
Hosting/display services may be provided by processors. Unless stated otherwise, access and form data are processed on their servers. Contact us for details.
2. Contract Processing, Contact, Customer Account
We process personal data you provide when ordering or contacting us (form/email). Mandatory fields are required to complete your request.
Legal basis: Art. 6(1)(b) GDPR. With your consent (Art. 6(1)(a)) we set up a customer account. After contract completion or account deletion, data will be restricted and deleted after statutory retention periods (Art. 6(1)(c)), unless you consent to further use.
3. Shipping
For contract fulfilment (Art. 6(1)(b)) we share necessary data with shipping providers. This also applies to drop-shipping by manufacturers/wholesalers.
4. Payments
We work with technical providers, banks, and payment services.
4.1 Transactions
Depending on the method, we share required data with processors, banks, or payment services (Art. 6(1)(b)). Some providers collect data themselves; their privacy policy applies.
4.2 Fraud Prevention / Process Optimisation
We may share additional data with processors to prevent fraud and streamline processes (billing, disputes, accounting) based on legitimate interests (Art. 6(1)(f)).
4.3 Klarna
Selecting Klarna requires your consent (Art. 6(1)(a)) for identity/credit checks. Credit agencies may be used (per Klarna’s policy). Consent can be withdrawn (with us or Klarna); certain methods may then be unavailable.
5. Email Marketing
5.1 Newsletter
With your consent (Art. 6(1)(a)) we send newsletters. Unsubscribe anytime via link or by contacting us.
5.2 Service Providers
Newsletters may be sent via processors.
6. Cookies & Technologies (General)
We use technologies incl. cookies for features and a pleasant experience. Some are necessary (e.g., cart) and expire after the session; others are persistent. Processed data may include IP address, timestamps, device/browser info, usage (Art. 6(1)(f)).
We also use tools for legal compliance (consent records) and for analytics/marketing (details below). You can manage cookies in your browser.
Where consent is required (Art. 6(1)(a)), you may withdraw it at any time.
7. Analytics & Advertising (with Consent)
With your consent (Art. 6(1)(a)) we use third-party tools. Data is deleted after purpose ends. You may withdraw consent at any time.
7.1 Google (Google Ireland Ltd.)
Data may be transferred to Google LLC (USA) under SCCs; IPs are usually anonymised.
– Google Analytics (pseudonymous profiles; cookies possible), processor agreement in place.
– Google Ads Conversion Tracking (post-ad events).
– Google Fonts (uniform display; IP/tech data sent to Google).
7.2 Meta/Facebook (Facebook Ireland Ltd.)
– Facebook Pixel for statistics, audiences, ads/remarketing (pseudonymous cookie-ID). US transfers under SCCs.
– Facebook Ads/Custom Audiences/Conversions: joint controllership for collection/transfer (Art. 26 GDPR); further processing by Facebook under its own responsibility.
8. Trusted Shops Trustbadge
Integrated to display the seal/reviews and offer buyer protection (legitimate interests, Art. 6(1)(f)). Log files may be stored up to 90 days. Further data is transmitted if you choose a Trusted Shops product post-purchase. See Trusted Shops’ privacy notice.
9. Social Media
9.1 Plugins as Links
Social buttons are HTML links; no connection on page load.
9.2 Our Profiles
With your consent (Art. 6(1)(a)), platform operators may process data for research/advertising (cookies, profiles). See each provider’s policy.
10. Your Rights
You have rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and complaint (Art. 77).
Contact us via the details above.
Right to Object:
Where processing is based on legitimate interests (Art. 6(1)(f)), you may object at any time with effect for the future. For direct marketing, you may object at any time without reasons. Otherwise, we may continue processing if we demonstrate compelling legitimate grounds or for legal claims.