Privacy policy

Privacy policy of YELASAI GmbH

1. What is this privacy policy about?

2. Who is responsible for processing your data?

3. What data do we process?

4. For what purposes do we process your data?

5. On what basis do we process your data?

6. What applies to profiling and automated individual decisions?

7. To whom do we disclose your data?

8. Is your personal data also transferred abroad?

9. How long do we process your data?

10. How do we protect your data?

11. What rights do you have?

12. Do we use online tracking and online advertising technologies?

13. What data do we process on our pages in social networks?

14. What data do we process in connection with sending our newsletter?

15. What other third-party plugins and tools do we use?

16. What data is transmitted to payment providers?

17. Can this privacy policy be amended?

1. what is this privacy policy about?

YELASAI GmbH (hereinafter also referred to as "we", "us") collects and processes personal data concerning you or other persons (so-called "third parties"). We use the term "data" here synonymously with "personal data" or "personal information".

In this privacy policy, we describe what we do with your data when you visit our website (https://yelasai.com) (hereinafter "Website"), purchase our services or products, otherwise engage with us under a contract, communicate with us or otherwise deal with us. Where appropriate, we will provide you with timely written notice of additional processing activities not mentioned in this Privacy Policy. In addition, we may inform you separately about the processing of your data, e.g. in declarations of consent, contractual terms, additional data protection declarations, forms and notices.

If you transmit or disclose data about other persons to us, we assume that you are authorized to do so and that this data is correct. By transmitting data about third parties, you confirm this. Please also ensure that these third parties have been informed of this privacy policy.

This Privacy Policy is designed to meet the requirements of the EU General Data Protection Regulation ("GDPR"), the Swiss Data Protection Act ("DPA") and the revised Swiss Data Protection Act ("revDSG"). However, whether and to what extent these laws are applicable depends on the individual case.

2 Who is responsible for processing your data?

YELASAI GmbH, based in Wil SG (Switzerland) ( "YELASAI GmbH"), is responsible under data protection law for the data processing of YELASAI GMBH described in this data protection declaration, unless otherwise communicated in individual cases, e.g. in further data protection declarations, on forms or in contracts.

You can contact us as follows for your data protection concerns and to exercise your rights in accordance with section 11:

YELASAI GmbH
Bergtalstrasse 46
CH-9500 Wil SG
dataprotection@yelasai.com

3 What data do we process?

We process various categories of data about you. The most important categories are as follows:

  • Technical data: When you use our website or other electronic offers (e.g. free WLAN), we collect the IP address of your end device and other technical data to ensure the functionality and security of these offers. This data also includes logs in which the use of our systems is recorded. We generally store technical data for [6] months. In order to ensure the functionality of these offers, we can also assign you or your end device an individual code (e.g. in the form of a cookie, see section 12). The technical data itself does not allow any conclusions to be drawn about your identity. However, in the context of user accounts, registrations, access controls or the processing of contracts, they can be linked to other categories of data (and thus possibly to your person).

  • Registration data: Certain offers and services (e.g. login areas of our website, newsletter dispatch, free WLAN access, etc.) can only be used with a user account or registration, which can be done directly with us or via our external login service providers. In doing so, you must provide us with certain data and we collect data on the use of the offer or service. If you redeem a voucher from one of our contractual partners (e.g. hair growth specialists) with us, we may request certain data from you upon redemption and may transmit certain of your registration data or data relating to the products and/or services purchased with the voucher to the respective [contractual partner/hair growth specialist]. If we issue you with a voucher for one of our contractual partners, we may transmit certain of your registration data to the respective contractual partner or receive such data (see Section 7). Registration data may be collected during access controls to certain facilities; depending on the control system, biometric data may also be collected. As a rule, we retain registration data for [12] months after the end of the use of the service or the termination of the user account.

  • Communication data: If you are in contact with us via the contact form, by e-mail, telephone or chat, by letter or other means of communication, we collect the data exchanged between you and us, including your contact details and the marginal data of the communication. If we want or need to establish your identity, we collect data to identify you (e.g. a copy of an identity document). We generally retain this data for [12] months from the last exchange with you. This period may be longer if this is necessary for reasons of proof or to comply with legal or contractual requirements or for technical reasons. E-mails in personal mailboxes and written correspondence are generally stored for at least [10] years. Chats are generally stored for [2] years.

  • Master data: We define master data as the basic data that we require in addition to the contract data (see below) for the processing of our contractual and other business relationships or for marketing and advertising purposes, such as name, contact details and information, e.g. about your role and function, your bank account(s), your date of birth, customer history, powers of attorney, signature authorizations and declarations of consent. We process your master data if you are a customer or other business contact or work for one (e.g. as a contact person of the business partner), or because we want to contact you for our own purposes or the purposes of a contractual partner (e.g. as part of marketing and advertising, with invitations to events, with vouchers, with newsletters, etc.). We receive master data from you yourself (e.g. when you make a purchase or register), from bodies for which you work or from third parties such as our contractual partners, associations and address dealers and from publicly accessible sources such as public registers or the internet (websites, social media, etc.). We may also process health data and information about third parties as part of master data. As a rule, we store this data for [10] years from the last exchange with you, but at least from the end of the contract. This period may be longer if this is necessary for reasons of proof or to comply with legal or contractual requirements or for technical reasons. In the case of pure marketing and advertising contacts, the period is normally much shorter, usually no more than [2] years from the last contact.

  • Contract data: This is data that arises in connection with the conclusion or performance of a contract, e.g. information on contracts and the services to be provided or provided, as well as data from the run-up to the conclusion of a contract, the information required or used for processing and information on reactions (e.g. complaints or information on satisfaction, etc.). This also includes health data and information about third parties, e.g. about hereditary diseases in the family. We generally collect this data from you, from contractual partners and from third parties involved in the execution of the contract, but also from third-party sources (e.g. providers of credit rating data) and from publicly accessible sources. As a rule, we store this data for [10] years from the last contractual activity, but at least from the end of the contract. This period may be longer if this is necessary for reasons of proof or to comply with legal or contractual requirements or for technical reasons.

  • Behavioral and preference data: Depending on the relationship we have with you, we try to get to know you and better tailor our products, services and offers to you. To do this, we collect and use data about your behavior and preferences. We do this by evaluating information about your behavior in our area, and we may also supplement this information with information from third parties, including from publicly accessible sources. Based on this, we can, for example, calculate the probability that you will use certain services or behave in a certain way. Some of the data processed for this purpose is already known to us (e.g. when you use our services), or we obtain this data by recording your behavior (e.g. how you navigate our website). We anonymize or delete this data when it is no longer meaningful for the purposes pursued, which can be between [2-3] weeks and [24] months (for product and service preferences) depending on the type of data. This period may be longer if this is necessary for reasons of proof or to comply with legal or contractual requirements or for technical reasons. We describe how tracking works on our website in section 12.

  • Other data: We also collect data from you in other situations. In connection with official or judicial proceedings, for example, data is collected (such as files, evidence, etc.) that may also relate to you. We may also collect data for health protection reasons (e.g. as part of protection concepts). We may receive or produce photos, videos and audio recordings in which you may be recognizable (e.g. at events, through security cameras, etc.). We may also collect data about who enters certain buildings or has access rights to them and when (including access controls, based on registration data or visitor lists, etc.), who takes part in events or campaigns and when, or who uses our infrastructure and systems and when. The retention period for this data depends on the purpose and is limited to what is necessary. This ranges from a few days for many of the security cameras and usually a few weeks for contact tracing data to visitor data, which is usually stored for [3] months, to reports on events with images, which can be stored for several years or longer.

You provide us with much of the data mentioned in this section 3 yourself (e.g. via forms, in the context of communication with us, in connection with contracts, when using the website, etc.). You are not obliged to do so, subject to individual cases, e.g. as part of binding protection concepts (legal obligations). If you wish to conclude contracts with us or make use of services, you must also provide us with data as part of your contractual obligation in accordance with the relevant contract, in particular master data, contract data and registration data. When using our website, the processing of technical data is unavoidable. If you wish to gain access to certain systems or buildings, you must provide us with registration data. In the case of behavioral and preference data, however, you generally have the option of objecting or not giving your consent.

Unless this is not permitted, we also obtain data from publicly accessible sources (e.g. debt collection registers, land registers, commercial registers, media or the Internet including social media) or receive data from authorities and other third parties (e.g. credit agencies, contractual partners, etc.).


4. for what purposes do we process your data?

We process your data for the purposes explained below. Further information for the online area can be found in sections 12 and 13. These purposes and the underlying objectives represent legitimate interests of us and, where applicable, of third parties. You will find further information on the legal basis for our processing in section 5.

We process your data for purposes in connection with communication with you, in particular to respond to inquiries and assert your rights (section 11) and to contact you in the event of queries. In particular, we use communication data and master data for this purpose and, in connection with offers and services used by you, also registration data. We retain this data in order to document our communication with you, for training purposes, for quality assurance and for follow-up questions.

We process data for the initiation, administration and processing of contractual relationships.

We process data for marketing purposes and to maintain relationships, e.g. to send our customers and other contractual partners personalized advertising about our products and services and those of third parties (e.g. advertising contract partners). This may, for example, take the form of newsletters and other regular contacts (electronically, by post, by telephone), via other channels for which we have contact information from you, but also as part of individual marketing campaigns (e.g. events, competitions, etc.) and may also include free services (e.g. invitations, vouchers, etc.). You can refuse such contacts at any time (see the end of this section 4) or refuse or revoke your consent to being contacted for advertising purposes. With your consent, we can target our online advertising on the Internet more specifically to you (see section 12). Finally, we also want to enable our contractual partners to contact our customers and other contractual partners for advertising purposes (see section 7).

We also process your data for market research, to improve our services and operations and for product development.

We may also process your data for security purposes and for access control.

We process personal data to comply with laws, instructions and recommendations from authorities and internal regulations ("compliance").

We also process data for the purposes of our risk management and in the context of prudent corporate governance, including business organization and corporate development.

We may process your data for other purposes , e.g. as part of our internal processes and administration or for training and quality assurance purposes.

5 On what basis do we process your data?

If we ask for your consent for certain processing (e.g. for the processing of particularly sensitive personal data, for marketing mailings, for the creation of personalized movement profiles and for advertising control and behavior analysis on the website), we will inform you separately about the corresponding purposes of the processing. You can withdraw your consent at any time with effect for the future by sending us written notification (by post) or, unless otherwise stated or agreed, by email; our contact details can be found in Section 2. For the withdrawal of your consent in the case of online tracking, see Section 12. If you have a user account, you can also withdraw your consent or contact us via the relevant website or other service. Once we have received notification of the withdrawal of your consent, we will no longer process your data for the purposes to which you originally consented, unless we have another legal basis for doing so. The withdrawal of your consent does not affect the lawfulness of processing based on consent before its withdrawal.

Where we do not ask for your consent for processing, we base the processing of your personal data on the fact that the processing is necessary for the initiation or execution of a contract with you (or the entity you represent) or that we or third parties have a legitimate interest in it, in particular to pursue the purposes and associated objectives described above under section 4 and to be able to carry out corresponding measures. Our legitimate interests also include compliance with statutory provisions, insofar as this is not already recognized as a legal basis by the applicable data protection law (e.g. in the case of the GDPR, the law in the EEA and Switzerland). However, this also includes the marketing of our products and services, the interest in better understanding our markets and the secure and efficient management and further development of our company, including its operations.

If we receive sensitive data (e.g. health data, information on political, religious or ideological views or biometric data for identification purposes), we may also process your data on the basis of other legal grounds, e.g. in the event of disputes due to the necessity of processing for any legal proceedings or the enforcement of or defense against legal claims. In individual cases, other legal grounds may apply, which we will communicate to you separately if necessary.

6 What applies to profiling and automated individual decisions?

We may automatically evaluate certain of your personal characteristics for the purposes mentioned in Section 4 using your data (Section 3) ("profiling") if we want to determine preference data, but also to determine abuse and security risks, to carry out statistical evaluations or for operational planning purposes. For the same purposes, we can also create profiles, i.e. we can combine behavioral and preference data, but also master and contract data and technical data assigned to you in order to better understand you as a person with your different interests and other characteristics. Anonymous movement profiles are created.

In both cases, we pay attention to the proportionality and reliability of the results and take measures to prevent misuse of these profiles or profiling. If these can have legal consequences or significant disadvantages for you, we always provide for a manual review.

7 To whom do we disclose your data?

In connection with our contracts, the website, our services and products, our legal obligations or otherwise to protect our legitimate interests and the other purposes listed in section 4, we also transfer your personal data to third parties, in particular to the following categories of recipients:

  • Service providers: we work with service providers in Switzerland and abroad who process data about you on our behalf or under joint responsibility with us or who receive data about you from us under their own responsibility (e.g. IT providers, mail order companies, banks, insurance companies, debt collection agencies, credit reference agencies, hairdressers, hair growth specialists, Hair Active experts, therapists). In order to establish a personalized interaction with you by means of marketing activities, we may transfer personal data in encrypted form to advertising service providers. This enables us to provide you with relevant offers and inform you about them. You can request the deletion of your data at any time. Please send us an e-mail to do so.

  • Contractual partners including customers: This initially refers to customers (e.g. service recipients) and other contractual partners of ours, because this data transfer arises from these contracts. For example, you receive registration data for vouchers issued and redeemed, invitations, etc. If you work for such a contractual partner yourself, we may also transmit data about you to them in this context. This may also include health data. Recipients also include contractual partners with whom we cooperate or who advertise for us and to whom we therefore transmit data about you for analysis and marketing purposes (these may in turn be service recipients, but also sponsors and providers of online advertising, for example). We require these partners to only send you advertising or display it based on your data if you have consented to this (for the online area, see section 12). Our online advertising contract partners are listed in section 12.

  • Public authorities: We may disclose personal data to offices, courts and other authorities in Switzerland and abroad if we are legally obliged or entitled to do so or if this appears necessary to protect our interests. This may also include health data. The authorities process data about you that they receive from us under their own responsibility.

  • Other persons: This refers to other cases where the involvement of third parties arises from the purposes set out in section 4, e.g. service recipients, media or if you are part of one of our publications.

All these categories of recipients may in turn involve third parties, so that your data may also become accessible to them. We can restrict the processing by certain third parties (e.g. IT providers), but not by other third parties (e.g. authorities, banks, etc.).

We reserve the right to disclose this data even if it concerns confidential data (unless we have expressly agreed with you that we will not disclose this data to certain third parties, unless we are legally obliged to do so). Irrespective of this, your data will continue to be subject to appropriate data protection even after disclosure in Switzerland and the rest of Europe. The provisions of Section 8 apply to disclosure to other countries. If you do not wish certain data to be disclosed, please let us know so that we can check whether and to what extent we can accommodate you (Section 2).

We also allow certain third parties to collect personal data from you on our website and at our events (e.g. media photographers, providers of tools that we have integrated on our website, etc.). Insofar as we are not decisively involved in this data collection, these third parties are solely responsible for it. If you have any concerns and wish to assert your data protection rights, please contact these third parties directly. See section 12 for the website.

8. will your personal data also be transferred abroad?

As explained in section 7, we also disclose data to other bodies. These are not only located in Switzerland. Your data may therefore be processed in Europe as well as in Oman and the U.A.E.; in exceptional cases, however, in any country in the world.

If a recipient is located in a country without adequate legal data protection, we contractually oblige the recipient to comply with the applicable data protection law (we use the revised standard contractual clauses of the European Commission, which can be found here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj? ), unless the recipient is already subject to a legally recognized set of rules to ensure data protection and we cannot rely on an exception. An exception may apply in particular in the case of legal proceedings abroad, but also in cases of overriding public interests or if the performance of a contract requires such disclosure, if you have given your consent or if the data in question has been made generally accessible by you and you have not objected to its processing.

Please also note that data exchanged via the Internet is often routed via third countries. Your data may therefore be sent abroad even if the sender and recipient are located in the same country.

9 How long do we process your data?

We process your data for as long as required by our processing purposes, the statutory retention periods and our legitimate interests in processing for documentation and evidence purposes or for as long as storage is technically necessary. Further information on the respective storage and processing periods can be found for the individual data categories in section 3 or for the cookie categories in section 12. If there are no legal or contractual obligations to the contrary, we will delete or anonymize your data after the storage or processing period has expired as part of our normal processes.

10. how do we protect your data?

We take appropriate security measures to protect the confidentiality, integrity and availability of your personal data, to protect it against unauthorized or unlawful processing and to counteract the risks of loss, unintentional alteration, unwanted disclosure or unauthorized access.

11 What rights do you have?

Under certain circumstances, applicable data protection law grants you the right to object to the processing of your data, in particular for the purposes of direct marketing, profiling for direct marketing and other legitimate interests in processing.

To make it easier for you to control the processing of your personal data, you also have the following rights in connection with our data processing, depending on the applicable data protection law:

  • The right to request information from us as to whether we are processing data about you and, if so, which data;
  • the right to have us correct data if it is incorrect;
  • the right to request the deletion of data;
  • the right to request that we provide you with certain personal data in a commonly used electronic format or transfer it to another controller
  • the right to withdraw consent where our processing is based on your consent
  • the right to request further information necessary to exercise these rights
  • the right to express your point of view in the case of automated individual decisions (Section 6) and to request that the decision be reviewed by a natural person.

If you wish to exercise the above rights against us, please contact us in writing, at our premises or, unless otherwise stated or agreed, by e-mail; our contact details can be found in Section 2. In order for us to rule out misuse, we must identify you (e.g. with a copy of your ID, unless otherwise possible).

You also have these rights vis-à-vis other bodies that work with us on their own responsibility - please contact them directly if you wish to exercise rights in connection with their processing. You will find details of our key cooperation partners and service providers in section 7, and further details in section 12.

Please note that these rights are subject to conditions, exceptions or restrictions under the applicable data protection law (e.g. to protect third parties or business secrets). We will inform you accordingly if necessary.

If you do not agree with our handling of your rights or data protection, please let us know (Section 2). In particular, if you are located in the EEA, the United Kingdom or Switzerland, you also have the right to lodge a complaint with the data protection supervisory authority in your country. A list of authorities in the EEA can be found here: https://edpb.europa.eu/about-edpb/board/members_de. You can contact the supervisory authority in the United Kingdom here: https://ico.org.uk/global/contact-us/. You can contact the Swiss supervisory authority here: https://www.edoeb.admin.ch/edoeb/de/home/der-edoeb/kontakt/adresse.html.

12. do we use online tracking and online advertising technologies?

We use various technologies on our website with which we and third parties engaged by us can recognize you when you use our website and, under certain circumstances, track you over several visits. We will inform you about this in this section.

In essence, this is so that we can distinguish your access (via your system) from access by other users so that we can ensure the functionality of the website and carry out evaluations and personalization. We do not want to draw conclusions about your identity, even if we can, insofar as we or third parties engaged by us can identify you by combining this with registration data. Even without registration data, however, the technologies used are designed in such a way that you are recognized as an individual visitor each time you access a page, for example by our server (or the servers of third parties) assigning you or your browser a specific identification number (so-called "cookie").

We use such technologies on our website and allow certain third parties to do the same. However, depending on the purpose of these technologies, we may ask for your consent before using them. You can access your current settings here. You can program your browser to block, deceive or delete existing cookies or alternative technologies. You can also add software to your browser that blocks tracking by certain third parties. You can find more information about this on the help pages of your browser (usually under the heading "Data protection") or on the websites of the third parties listed below.

A distinction is made between the following cookies (technologies with similar functions such as fingerprinting are also included here):

  • Necessary cookies: Some cookies are necessary for the functioning of the website as such or certain functions (e.g. shopping cart function). They ensure, for example, that you can switch between pages without losing information entered in a form. They also ensure that you remain logged in. These cookies are only temporary ("session cookies"). If you block them, the website may not work. Other cookies are necessary so that the server can save decisions or entries made by you beyond a session (i.e. a visit to the website) if you use this function (e.g. selected language, consent given, the function for automatic log-in, etc.). These cookies have an expiry date of up to [60] months.
  • Performance cookies: In order to optimize our website and corresponding offers and to better tailor them to the needs of users, we use cookies to record and analyze the use of our website, possibly even beyond the session. We do this by using third-party analysis services. We have listed these below. Before we use such cookies, we will ask for your consent. You can revoke your consent at any time via the cookie settings here [link]. Performance cookies also have an expiration date of up to [60] months. Details can be found on the websites of the third-party providers.
  • Marketing cookies: We and our advertising contract partners have an interest in targeting advertising precisely, i.e. only displaying it to those we want to address. We have listed our advertising contract partners below. For this purpose, we and our advertising contract partners - if you consent - also use cookies with which the content accessed or contracts concluded can be recorded. This enables us and our advertising contract partners to display advertising that we can assume is of interest to you on our website, but also on other websites that display advertising from us or our advertising contract partners. Depending on the situation, these cookies have an expiration period of a few days to [12] months. If you consent to the use of these cookies, you will be shown appropriate advertising. If you do not consent to these cookies, you will not see less advertising, but simply any other advertising.

In addition to marketing cookies, we use other techniques to control online advertising on other websites and thereby reduce wastage. For example, we can transmit the email addresses of our users, customers and other people to whom we want to display advertising to operators of advertising platforms (e.g. social media). If these people are registered there with the same email address (which the advertising platforms determine by means of a comparison), the operators will display the advertising we have placed to these people in a targeted manner. The operators do not receive personal email addresses of people who are not already known. In the case of known e-mail addresses, however, they will learn that these people are in contact with us and what content they have accessed.

We may also integrate other third-party offers on our website, in particular from social media providers. These offers are deactivated by default. As soon as you activate them (e.g. by clicking a button), the relevant providers can detect that you are on our website. If you have an account with the provider, in particular with the corresponding social media provider, they can assign this information to you and thus track your use of online services. The providers process this data on their own responsibility. We currently use offers from the following service providers and advertising contract partners (insofar as they use data from you or cookies set by you for advertising purposes):

  • Google Analytics: Google Ireland Limited (based in Ireland) is the provider of the "Google Analytics" service and acts as our processor. Google Ireland relies on Google LLC (based in the USA) as its processor (both "Google"). Google uses performance cookies (see above) to track the behavior of visitors to our website (duration, frequency of pages accessed, geographical origin of access, etc.) and compiles reports for us on the use of our website on this basis. We have configured the service so that the IP addresses of visitors are truncated by Google in Europe before being forwarded to the USA and therefore cannot be traced. We have switched off the "Data sharing" and "Signals" settings. Although we can assume that the information we share with Google is not personal data for Google, it is possible that Google can use this data for its own purposes to draw conclusions about the identity of visitors, create personal profiles and link this data to the Google accounts of these persons. If you agree to the use of Google Analytics, you explicitly consent to such processing, which also includes the transfer of personal data (in particular usage data for the website and app, device information and individual IDs) to the USA and other countries. You can find information on Google Analytics data protection here https://support.google.com/analytics/answer/6004245 and if you have a Google account, you can find further information on processing by Google here https://policies.google.com/technologies/partner-sites?hl=de.
  • Google Analytics Remarketing: Google Ireland Limited (based in Ireland) is the provider of the "Google Analytics Remarketing" service and acts as our processor. Google Ireland relies on Google LLC (based in the USA) as its processor (both "Google"). Google Remarketing analyzes your user behavior on our website (e.g. clicks on certain products) in order to classify you into certain advertising target groups and then display suitable advertising messages to you when you visit other online offers (remarketing or retargeting). Furthermore, the advertising target groups created with Google Remarketing can be linked to the cross-device functions of Google AdWords and Google DoubleClick. In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. cell phone) can also be displayed on another of your devices (e.g. tablet or PC). If you have given your consent, Google will link your web and app browsing history to your Google account for this purpose. In this way, the same personalized advertising messages can be displayed on every device on which you sign in with your Google account. To support this function, Google Analytics collects Google-authenticated user IDs that are temporarily linked to our Google Analytics data to define and create target groups for cross-device advertising. You can permanently opt out of cross-device remarketing/targeting by turning off personalized advertising in your Google Account by following this link: https://www.google.com/settings/ads/onweb/. The summary of the data collected in your Google account is based exclusively on your consent, which you can give or withdraw from Google. In the case of data collection processes that are not merged in your Google account (e.g. because you do not have a Google account or have objected to the merging), the collection of data is based on the protection of a legitimate interest. The legitimate interest arises from the fact that the website operator has an interest in the anonymized analysis of website visitors for advertising purposes. Further information and the data protection provisions can be found in Google's privacy policy at https://www.google.com/policies/technologies/ads/.
  • Google AdWords and Google Conversion Tracking: Google Ireland Limited (based in Ireland) is the provider of the "Google Analytics Remarketing" service and acts as our processor. Google Ireland relies on Google LLC (based in the USA) as its processor (both "Google"). As part of Google AdWords, we use what is known as conversion tracking. When you click on an ad placed by Google, a cookie is set for conversion tracking. Cookies are small text files that the Internet browser stores on the user's computer. These cookies lose their validity after 30 days and are not used to personally identify the user. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. The cookies cannot be tracked via the websites of AdWords customers. The information collected using the conversion cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users. If you do not wish to participate in tracking, you can object to this use by easily deactivating the Google Conversion Tracking cookie via your Internet browser under user settings. You will then not be included in the conversion tracking statistics. The storage of "conversion cookies" takes place in the context of safeguarding a legitimate interest. The website operator has a legitimate interest in analyzing user behavior in order to optimize both its website and its advertising. You can find more information about Google AdWords and Google Conversion Tracking in Google's privacy policy: https://www.google.de/policies/privacy/. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.
  • Other service providers, advertising contract partners such as Meta (Facebook, Instagram, WhatsApp), Google Ads, Custom Audiences, LinkedIn, and others may follow, some of which have specific instructions on how to inform users of the website etc.

13. what data do we process on our pages on social networks?

We may operate pages and other online presences ("fan pages", "channels", "profiles", etc.) on social networks and other platforms operated by third parties and collect the data about you described in section 3 and below. We receive this data from you and the platforms when you come into contact with us via our online presence (e.g. when you communicate with us, comment on our content or visit our presence). At the same time, the platforms evaluate your use of our online presence and link this data with other data about you known to the platforms (e.g. about your behavior and preferences). They also process this data for their own purposes under their own responsibility, in particular for marketing and market research purposes (e.g. to personalize advertising) and to control their platforms (e.g. what content they show you).

We process this data for the purposes described in section 4, in particular for communication, for marketing purposes (including advertising on these platforms, see section 12) and for market research. You will find information on the relevant legal bases in section 5. We may redistribute content published by you (e.g. comments on an announcement) ourselves (e.g. in our advertising on the platform or elsewhere). We or the operators of the platforms may also delete or restrict content from or about you in accordance with the usage guidelines (e.g. inappropriate comments).

If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your device or by recording your IP address.

For further information on the processing of the platform operators, please refer to the privacy policies of the platforms. There you can also find out in which countries they process your data, which rights of access, erasure and other rights of data subjects you have and how you can exercise these or obtain further information. We currently use the following platforms

  • Facebook and Instagram: We have a Facebook profile (www.facebook.com/yelasai) and an Instagram profile (www.instagram.com/yelasai). The responsible body for the operation of these two social media platforms for users from Europe is Meta Platforms Ireland Ltd, Dublin, Ireland. Their privacy policy can be found at https://www.facebook.com/privacy/policy and https://privacycenter.instagram.com/policy respectively. Some of your data will be transferred to the USA. You can object to advertising here: https://www.facebook.com/adpreferences/ad_settings/?entry_product=account_settings_menu. We are jointly responsible with Meta Platforms Ireland Ltd, Dublin, Ireland, for the data that is collected and processed when you visit our Facebook profile to create "Page Insights" or when you visit our Instagram profile to create "Instragram Insights". Page Insights compiles statistics about what visitors do on our page (comment on posts, forward content, etc.). This is available at https://www.facebook.com/legal/terms/information_about_page_insights_data described. As part of Instragram Insights, statistics are compiled that provide us with insights about visitors to our Instagram page and their interactions with our Instagram page and its content. This is described at https://www.facebook.com/business/help/441651653251838?id=419087378825961 described. Page Insights and Instragram Insights help us to understand how our page is used and how we can improve it. We only receive anonymous, aggregated data. We have defined our responsibilities regarding data protection in accordance with the information on www.facebook.com/legal/terms/page_controller_addendum regulated .
  • LinkedIn: We are represented on the LinkedIn social network by an official company profile and by profiles of our employees who use it for professional purposes. The entity responsible for the operation of the platform for users from Europe is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, a subsidiary of LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA. In this respect, we would like to point out that there is a possibility that user data may be processed outside the European Union, the European Economic Area and Switzerland, in particular in the USA. The privacy policy of "LinkedIn" can be found at https://www.linkedin.com/legal/privacy-policy can be accessed. We may be jointly responsible with LinkedIn Ireland Unlimited Company for the data that is collected and processed when you visit our site for the creation of "Page Insights". As part of Page Insights, statistics are compiled about what visitors do on our site (comment on posts, forward content, etc.). This is available at https://legal.linkedin.com/pages-joint-controller-addendum described. It helps us to understand how our site is used and how we can improve it. We only receive anonymous, aggregated data. We have defined our responsibilities regarding data protection in accordance with the information on https://legal.linkedin.com/pages-joint-controller-addendum regulated.
  • Twitter: We use the short message service "Twitter" from Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA (see also https://twitter.com/yelasai). The entity responsible for operating the platform for users from Europe is Twitter International Unlimited Company, Dublin, Ireland. We would like to point out that the use of our Twitter page and its functions or the use of the Twitter short message service and its functions is at your own risk. This applies in particular to the use of the interactive functions (e.g. tweeting, retweeting, liking, etc.). When you visit our Twitter profile or profiles within the Twitter platform, Twitter collects usage data. We have no influence on what data Twitter processes, to what extent and how, and whether Twitter transfers this data to third parties, in particular to countries outside the European Union, the European Economic Area and Switzerland, in particular to the USA. Information about which data is processed by Twitter and for what purposes it is used can be found in Twitter's privacy policy, which is available at https://twitter.com/de/privacy is available. Twitter also uses certain data that it has collected from users of the Twitter platform (e.g. "re-tweets") to compile aggregated usage statistics and make them available to the respective operators of the Twitter profile ("Twitter Analytics"). YELASAI GmbH also receives such aggregated usage statistics. The information that YELASAI GmbH receives through Twitter Analytics does not allow any conclusions to be drawn about individual users. Only the user interactions with our tweets are visible to us. YELASAI GmbH itself has no access to personal data that Twitter processes for Twitter Analytics. Twitter alone determines which data is processed for Twitter Analytics and how. YELASAI GmbH has no legal or actual influence on data processing by Twitter. You can change your data protection settings on Twitter in the account settings at https://twitter.com/settings/account change.
  • YouTube: We use the video platform "YouTube" (see also www.youtube.com/user/YELASAI). The controller for the operation of the platform for users from Europe is Google Ireland Limited, Dublin, Ireland. Further information on data processing and notes on data protection by YouTube (Google) can be found at https://policies.google.com/privacy can be accessed. We use YouTube to play videos. When you visit our YouTube profiles, YouTube may process your personal data, whereby YouTube acts as an independent controller. Via "YouTube Analytics", we have the option of calling up anonymized statistics on the use of our YouTube channels, but without being able to determine who these users are.

14. What data do we process in connection with sending our newsletter ?


If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively for sending the requested information and do not pass it on to third parties.

The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent to the storage of the data, the e-mail address and its use for sending the newsletter at any time, for example via the "Unsubscribe" link in the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.

The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. e-mail addresses for the member area) remain unaffected by this.

We currently use the following services to send newsletters:

  • MailChimp/Intuit: This website uses the services of MailChimp to send newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, a subsidiary of Intuit Inc, USA. MailChimp is a service with which, among other things, the sending of newsletters can be organized and analyzed. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), this data is stored on MailChimp's servers in the USA. With the help of MailChimp, we can analyze our newsletter campaigns. When you open an email sent with MailChimp, a file contained in the email (known as a web beacon) connects to MailChimp's servers in the USA. This makes it possible to determine whether a newsletter message has been opened and which links, if any, have been clicked on. Technical information is also collected (e.g. time of access, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients. If you do not wish to be analyzed by MailChimp, you must unsubscribe from the newsletter. We provide a corresponding link for this purpose in every newsletter message. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https: //mailchimp.com/eu-us-data-transfer-statement/ and https://mailchimp.com/legal/data-processing-addendum/#Annex_C_-_Standard_Contractual_Clauses. After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist to prevent future mailings. The data from the blacklist will only be used for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR). The storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interest. You can find out more about the use of cookies at MailChimp at https://mailchimp.com/legal/cookiesYou can find more information on data protection at MailChimp (Privacy) at https://www.intuit.com/privacy/statement/ .
  • Klaviyo: This website uses the services of Klaviyo to send newsletters. The provider is Klaviyo Inc, 225 Franklin St., Boston, Massachusetts 02110, USA. Klaviyo is a service with which, among other things, the sending of newsletters can be organized and analyzed. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), this data is stored on Klaviyo's servers in the USA. The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Through these clauses, Klaviyo undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de. The Data Processing Agreement, which corresponds to the standard contractual clauses, can be found at https://www.klaviyo.com/legal/dpa. With the help of Klaviyo, we can analyze our newsletter campaigns. When you open an email sent with Klaviyo, a file contained in the email (known as a web beacon) connects to Klaviyo's servers in the USA. This makes it possible to determine whether a newsletter message has been opened and which links, if any, have been clicked on. Technical information is also collected (e.g. time of access, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. It is used exclusively for the statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients. If you do not wish to be analyzed by Klaviyo, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. You can also unsubscribe from the newsletter directly on the website. Data processing takes place on the basis of your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation. The data you provide us with for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter and deleted from both our servers and Klaviyo's servers after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. e-mail addresses for the member area) remain unaffected by this. Further information on data protection at Klaviyo can be found in Klaviyo's privacy policy at https://www.klaviyo.com/legal/privacy/privacy-notice .

15. what other third-party plugins and tools do we use?

We currently use the following third-party plugins and tools:

  • Vimeo: Our website uses plugins from the video portal Vimeo. The provider is Vimeo Inc, 555 West 18th Street, New York, New York 10011, USA. When you visit one of our pages equipped with a Vimeo plugin, a connection to the Vimeo servers is established. This results in a data transfer. This data is collected, stored and processed on the Vimeo servers. Regardless of whether you have a Vimeo account or not, Vimeo collects data about you. This includes your IP address, technical information about your browser type, your operating system or very basic device information. Furthermore, Vimeo stores information about which website you use the Vimeo service and which actions (web activities) you perform on our website. These web activities include, for example, session duration, bounce rate or which button you clicked on our website with built-in Vimeo function. Vimeo can track and store these actions with the help of cookies and similar technologies. If you are logged in to Vimeo as a registered member, more data can usually be collected, as more cookies may already have been set in your browser. In addition, your actions on our website will be linked directly to your Vimeo account. To prevent this, you must log out of Vimeo while "surfing" on our website. If you have consented to your data being processed and stored by integrated Vimeo elements, this consent is the legal basis for the corresponding data processing (Art. 6 para. 1 lit. a GDPR). In principle, your data will also be stored and processed on the basis of the legitimate interest (Art. 6 para. 1 lit. f GDPR) in fast and good communication with you or other customers and business partners. Nevertheless, we only use the integrated Vimeo elements if you have given your consent. Vimeo also processes your data in the USA, among other places. The data transfer to the USA is based on the standard contractual clauses of the EU Commission. These clauses oblige Vimeo to comply with the EU level of data protection when processing relevant data outside the EU. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the clauses here:https://ec.europa.eu/germany/news/20210604-datentransfers-eu_de. You can find more information on the standard contractual clauses at Vimeo at https://vimeo.com/privacy#international_data_transfers_and_certain_user_rights. You can find out more about the use of cookies at Vimeo at https://vimeo.com/cookie_policy. Further information on the handling of user data can be found in Vimeo's privacy policy at https://vimeo.com/privacy.
  • Google Fonts: We use Google Fonts from Google Inc. on our website. Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for the European region. We have integrated the Google fonts on Shopify web servers - not on Google's servers. This means that there is no connection to Google servers and therefore no data transfer or storage. Google Fonts used to also be called Google Web Fonts. This is an interactive directory with over 800 fonts that Google provides free of charge. With Google Fonts, you could use fonts without uploading them to your own server. However, in order to prevent any transfer of information to Google servers in this respect, we have downloaded the fonts to our server. In this way, we act in accordance with data protection regulations and do not send any data to Google Fonts. Unlike other web fonts, Google allows us unrestricted access to all fonts. This means we have unlimited access to a sea of fonts and can therefore get the most out of our website. You can find out more about Google Fonts and other questions athttps://developers.google.com/fonts/faq?tid=311269125.
  • Mapbox: We use the map service Mapbox from Mapbox Inc, 740 15th Street NW, 5th Floor, District of Columbia 20005, USA on our website via an API. Mapbox is an online map tool (open source mapping) that is accessed via an interface (API). Mapbox is used in the interest of an appealing presentation of our online offers and to make it easy to find the places we indicate on the website. In order for Mapbox to be able to offer its service in full, the company must collect and store data from you. In addition to your IP address, this includes browser information, your operating system, the content of the request, limited location and usage data, the URL of the website visited and the date and time of the website visit. However, this data storage takes place on the Mapbox websites. We can only inform you about this, but cannot influence it. As we have integrated Mapbox into our website, Mapbox sets at least one cookie (name: ppcbb-enable-content-mapbox_js) in your browser. This cookie stores data about your user behavior. According to Mapbox, the data is only used to improve its own products. In addition, Mapbox also collects randomly generated IDs to analyze user behavior and determine the number of active users. If you have consented to Mapbox being used, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur when Mapbox collects data. We also have a legitimate interest in using Mapbox to optimize our online service. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use Mapbox if you have given your consent. Mapbox also processes data in the USA. The data transfer to the USA is based on the standard contractual clauses of the EU Commission. These clauses oblige Mapbox to comply with the EU level of data protection when processing relevant data outside the EU. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the clauses here:https://ec.europa.eu/germany/news/20210604-datentransfers-eu_de. If you would like to find out more about Mapbox's data processing, we recommend that you read Mapbox's privacy policy at https://www.mapbox.com/legal/privacy/ to consult it.
  • OVR AI Chatbot: We use the AI-based chatbot from OVR AI to communicate with you. The provider is Tödter & Shehata GbR (owner Amin Shehata, Markus Tödter), Seestedt 10, 27337 Blender (hereinafter "OVR AI"). OVR AI is able to respond to your questions and other inputs without human assistance. For this purpose, OVR AI analyzes further data in addition to your input in order to provide suitable answers (e.g. names, telephone numbers, address data, customer numbers and other identifiers, orders and chat histories). Your IP address, log files, location information and other metadata may also be collected via the chatbot. This data is stored on OVR AI's servers. User profiles can be created based on the data collected. In addition, the data can be used to display interest-based advertising, provided that the other legal requirements (in particular consent) are met. OVR AI can be linked to analysis and advertising tools for this purpose. The data collected may also be used to improve OVR AI and response behavior. The data you enter in the course of communication will remain with us or OVR AI until you ask us to delete it, revoke your consent to storage or the purpose for data storage no longer applies. Mandatory statutory provisions - in particular retention periods - remain unaffected. The legal basis for the use of chatbots is Art. 6 para. 1 lit. b GDPR, insofar as OVR AI is used to initiate a contract or in the context of contract fulfillment. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's end device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time. In all other cases, the use is based on our legitimate interest in the most effective customer communication possible (Art. 6 para. 1 lit. f GDPR).

16. what data is transmitted to payment providers?

The processing of personal data by a payment provider is carried out on the basis of Article 6 (1) sentence 1 lit. b GDPR for the purpose of contract processing and only to the extent necessary for this purpose and within the scope of our legitimate interests pursuant to Article 6 (1) sentence 1 lit. f GDPR to be able to offer you reliable and secure payment processes. The responsibility for handling the data collected and processed by the payment provider in accordance with data protection regulations lies with the respective payment provider. We currently use the services of the following payment providers

  • PayPal: On our website, we offer payment via PayPal, among others. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as "PayPal"). If you select payment via PayPal, the payment data you enter will be transmitted to PayPal. The transmission of your data to PayPal is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). You have the option of withdrawing your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations in the past. PayPal may transfer, process and store personal data outside the EU and Switzerland (i.e. in particular also in the USA). The data transfer to these countries (i.e. in particular also to the USA) is based on the standard contractual clauses of the EU Commission. Through these clauses, PayPal undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de. You can find more information about the standard contractual clauses and the data that is processed through the use of PayPal in the privacy policy at https://www.paypal.com/webapps/mpp/ua/privacy-full.
  • Shopify Payments: On our website, we offer payment via Shopify Payments, among other things. The provider of this payment service is Shopify International Limited, 2nd Floor Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter referred to as "Shopify"). If you select payment via Shopify Payments, the payment data you enter will be transmitted to Shopify. The transmission of your data to Shopify is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). Your data will only be passed on for the purpose of payment processing with Shopify and only to the extent that it is necessary for this purpose. You have the option to withdraw your consent to data processing at any time. A revocation does not affect the effectiveness of past data processing operations. Shopify may transfer, process and store personal data outside the EU and Switzerland (i.e. in particular also in Canada and the USA). When transferred to Canada, your personal data is protected by Canadian law. The European Commission has determined that this ensures adequate protection of your data. If your personal data is then sent by Shopify to a country outside of Canada, this data is protected by contractual obligations similar to those in standard contractual clauses (https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en) are protected. For more information about this and the data that is processed through the use of Shopify Payments, please see Shopify's privacy policy at https://www.shopify.com/de/legal/datenschutz.
  • Stripe: On our website, we offer payment via Stripe and the associated payment methods. The provider of these payment services is Stripe Payments Europe Ltd, Block 4, Harcourt Centre, Harcourt Road, Dublin 2. If you select payment via Stripe, the payment data you enter will be transmitted to Stripe. The transmission of your data to Stripe is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). You have the option of withdrawing your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations in the past. All data required for payment processing is used exclusively for the execution of payments and transmitted via the "SSL" procedure. Stripe is certified according to PCI DSS. Stripe may transfer, process and store personal data outside the EU and Switzerland (i.e. in particular also in the USA). The data transfer to these countries (i.e. in particular also to the USA) is based on the standard contractual clauses of the EU Commission. Through these clauses, Stripe undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de. For more information on the standard contractual clauses and the data that is processed through the use of Stripe, please refer to the privacy policy at https://stripe.com/at/privacy.
  • Klarna: On our website, we offer payment with the services of Klarna, among others. The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden. Klarna offers various payment options (e.g. installment purchase). If you choose to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. Details can be found in Klarna's privacy policy at the following link: https://www.klarna.com/de/datenschutz/. Klarna uses cookies to optimize the use of the Klarna checkout solution. The optimization of the checkout solution constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Cookies are small text files that are stored on your end device and do not cause any damage. They remain on your device until you delete them. Details on the use of Klarna cookies can be found at the following link:https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf. The transmission of your data to Klarna is based on Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). You have the option of withdrawing your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations in the past.
  • TWINT: Among other things, we offer payment via TWINT and the associated payment methods on our website. The provider of these payment services is TWINT AG
    Stauffacherstrasse 41, CH-8004 Zurich. If you select payment via TWINT, the payment data you enter will be transmitted to TWINT. Your data is transmitted to TWINT on the basis of Art. 6 para. 1 lit. a GDPR (consent) and Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract). You have the option of withdrawing your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations in the past. Information on the type, scope and purpose of data processing can be found on the page on data protection for TWINT apps (https://www.twint.ch/datenschutz-app/). Further information can be found in the TWINT AG legal notice (https://www.twint.ch/impressum/) , in the privacy policy for the TWINT website (https://www.twint.ch/datenschutz-website/) and in the General Terms and Conditions (GTC) for the use of TWINT (https://www.twint.ch/agb-app/).

17.can this privacy policy be amended?

This privacy policy is not part of any contract with you. We may amend this Privacy Policy at any time. The version published on this website is the current version.

Last update: March 02, 2022