Privacy Policy
1. Information on the Collection of Personal Data and Contact Details of the Controller
1.1 We are pleased that you are visiting our website. In the following, we inform you about the handling of your personal data when using our website. Personal data is any data by which you can be personally identified.
1.2 The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) for the operation of the online shop is:
Tropical Concept SARL
42, rue Monge
F-75005 Paris
France
Represented by the Managing Directors (Gérants):
Dr. Eric Lundwall, Dr. Patrick Lundwall
Contact:
E-mail: kontakt@nobite.com
Registry Entry:
Registered in the French Trade and Companies Register (RCS)
Registry Court: RCS Paris
Registration Number: 412 933 368
VAT Identification Number (FR): FR21412933368
Sales Management:
NOBITE Sales Manager
Alexander Dominguez
Paraschkenmühle 6
07743 Jena
Germany
E-mail: nobite-shop@cfdh.de
2. Data Collection When Visiting Our Website
When using our website for informational purposes only, we only collect data that your browser transmits to our server (so-called “server log files”). The legal basis for this is our legitimate interest in the stability and security of the website in accordance with Art. 6 (1) lit. f GDPR. Data collected includes: website visited, date/time, amount of data sent, browser type, operating system, and IP address.
3. Data Processing for Order Fulfillment
3.1 We collect data when you provide it to us as part of an order. The legal basis is Art. 6 (1) lit. b GDPR (performance of a contract). The data collected can be seen from the respective input forms (name, address, e-mail, payment data).
3.2 Storage Duration: We store your data for the duration of the tax and commercial retention periods (usually 10 years), after which it is deleted.
4. Payment Service Provider (Mollie)
We use the payment service provider Mollie B.V. (Keizersgracht 126, 1015 CW Amsterdam, Netherlands) to process payments (Art. 6 (1) lit. b & f GDPR). Data is passed on to the respective providers of the chosen payment method:
* E-wallets: Apple Pay, Google Pay.
* Direct systems: iDEAL, Wero, Klarna (Sofort), eps, Przelewy24, Bancontact, Bancomat Pay.
* Classic: Credit card, Bank transfer, PayPal.
Details can be found in Mollie’s privacy policy.
5. Shipping and Delivery (DHL)
For the performance of the purchase contract (delivery of the goods), we pass on your address data (first name, last name, and delivery address) to our shipping partner, DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany.
The legal basis for this transfer is Art. 6 (1) (b) GDPR (processing necessary for the performance of a contract). No other contact details (such as your email address or phone number) will be transferred to the shipping service provider.
5.1 Address Autocomplete Function (Google Places API)
For the convenient entry of delivery addresses, we use the Address Autocomplete function provided by Google Ireland Limited on our checkout page. When you enter an address during the ordering process, the entered text fragments are transmitted to Google in order to display matching address suggestions to you.
* Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
* Legal Basis: The processing is carried out on the basis of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR in preventing the misdirection of shipments due to incorrect address entries and in ensuring a user-friendly design of the ordering process.
* Third-Country Transfer: It cannot be ruled out that data may be transmitted to servers of Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF). This ensures an adequate level of data protection for processing in the USA.
5.2 Address Verification (EasyPost)
To ensure that the delivery address you have entered actually exists and can be delivered without errors by shipping service providers, we use the EasyPost service for automated address verification in the background when the order form is submitted.
* Provider: Simpler Postage, Inc. (dba EasyPost), 345 California St, San Francisco, CA 94104, USA.
* Legal Basis: The processing is carried out for the performance of a contract or to take steps prior to entering into a contract pursuant to Art. 6 (1) lit. b GDPR (orderly delivery of goods), as well as on the basis of our legitimate interest pursuant to Art. 6 (1) lit. f GDPR in order to prevent returns and additional costs caused by undeliverable packages.
* Third-Country Transfer / Safeguards: Data processing takes place on servers in the USA. The transfer of data to the USA is safeguarded by EasyPost’s integrated Data Processing Addendum, which includes the unaltered Standard Contractual Clauses (SCC) of the EU Commission pursuant to Art. 46 (2) lit. c GDPR, thereby contractually guaranteeing a European level of data protection.
6. Analysis and Marketing Tools (Consent Required)
The legal basis for the following tools is your express consent pursuant to Art. 6 (1) lit. a GDPR:
* Google Analytics 4: For analyzing website usage (Google Ireland Ltd.).
* Meta Pixel (Facebook Pixel): For measuring advertising success and retargeting (Meta Platforms Ireland Ltd.).
* Google Tag Manager: For the technical management of the aforementioned tags.
You can withdraw your consent at any time via our cookie consent banner.
The providers Google and Meta are certified under the EU-U.S. Data Privacy Framework (DPF). This ensures an adequate level of data protection for processing in the USA.
7. Your Rights as a Data Subject
You have the following rights regarding your personal data:
* Right of access (Art. 15 GDPR)
* Right to rectification (Art. 16 GDPR) or erasure (Art. 17 GDPR)
* Right to restriction of processing (Art. 18 GDPR)
* Right to data portability (Art. 20 GDPR)
* Right to object to processing (Art. 21 GDPR)
* Right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
8. Hosting
Web Hosting
For the operation of this website, we use the web hosting services provided by T-Mobile Austria GmbH. In this process, data (specifically server log files such as IP addresses, access timestamps, as well as order and contact details from form entries) are processed on the provider’s servers.
* Provider: T-Mobile Austria GmbH, Rennweg 97-99, 1030 Wien, Austria (Brand: Magenta Business).
* Legal Basis: The processing is based on our legitimate interest in providing a technically flawless, secure, and efficient online presence in accordance with Art. 6 para. 1 lit. f GDPR.
* Data Processing Agreement (DPA): We have entered into a data processing agreement with the provider pursuant to Art. 28 GDPR. This agreement ensures that the provider processes the data of our website visitors strictly according to our instructions and in compliance with European data protection standards.
* Data Location: Data processing takes place in certified data centers within the European Union.
9. Contact (Contact Form and E-mail)
When contacting us (e.g., via contact form or e-mail), personal data is collected. This data is stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration.
* Legal basis: Processing is carried out for the performance of a contract or for the implementation of pre-contractual measures in accordance with Art. 6 (1) lit. b GDPR or based on our legitimate interest in responding to your request in accordance with Art. 6 (1) lit. f GDPR.
* Deletion: Your data will be deleted when the circumstances indicate that the matter has been finally clarified and there are no statutory retention obligations.
10. Web Fonts
To ensure the uniform display of fonts, this site uses web fonts. These are hosted locally on our server. No connection to third-party servers (such as Google) takes place when the page is accessed.
* Legal basis: Our legitimate interest in a technically secure and visually appealing design of our website in accordance with Art. 6 (1) lit. f GDPR.
