Privacy policy


1. General Information

We take the protection of your data very seriously, which is why we comply with data protection requirements and make arrangements to ensure the confidentiality and security of your data.

We would like to point out that data transmission over the internet (eg email) can have security gaps and complete data protection against access through third parties is not possible.

In the following, we will inform you about the collection and processing of personal data by our company. We use the terms as they are defined in art 4 of the GDPR [EU General Data Protection Regulation].

Scope

This Privacy Policy, as well as the legal notice, exclusion of liability and disclaimer, are to be considered part of the Internet offer from which references have been made to this page.

This Privacy Policy does not apply to internet appearances outside our website (eg for use through third party links).

Storage periods

We delete personal data as soon as the purpose of storage no longer applies but for any operation of the law (eg commercial or tax law) to which the person responsible is subject, unless further storage is necessary for (further) conclusion of contracts or the fulfilment of contracts with the person concerned or the person concerned has agreed to storage.

Insofar as we do not state concrete storage deadlines or criteria for setting storage deadlines, we point out that such deadlines may be exceeded if concrete indications of unlawful use are known. In such a case, we reserve the right to run a subsequent check of stored date, and, if necessary, present it to the competent authorities for the purpose of prosecution.


2. Contact details

2.1 Name and address of the person responsible

The person responsible according to the definition of the GDPR and other national data protection laws as well as that of arts 5, 6 of the TMG [German Telemedia Act], is named in the Legal Notice.

2.2 Data Protection Officer

You can reach our Data Protection Supervisor at: datenschutz@roba-kids.com

3. Processing of personal data

3.1 Visiting the website

The use of our online services is possible without disclosure of your identity. When visiting the website, the browser you use will automatically send information to our website server. The following information shall be transmitted without your involvement:

  1. date and time of access
  2. host name of the accessing computer
  3. URL of the reference website (referrer URL)
  4. retrieved files
  5. transmitted data volume
  6. browser type and version
  7. operating system
  8. IP address used

We do not merge this data with other data sources. We also do not assign this information to a specific individual and do not receive any personally related analyses or statistics from third parties.

We reserve the right to run a subsequent check of stored data in case specific indications of unlawful use are known and, if necessary, to provide to the competent authorities for the purpose of prosecution.

Processing purpose

We process the data mentioned to

  • ensure smooth connection setup of the website and its functionality and availability
  • allow comfortable use of the websites
  • conserve and optimise statements about system security and stability
  • prosecute misuse

Legal basis & storage time

The legal basis for the storage of the above information is art 6(1)(f) of the GDPR. Our legitimate interest stems from the processing purposes.

This information is stored until automated deletion.


3.2 When using a contact form

We provide the opportunity to contact us through a contact form. The information entered in the form is transmitted encrypted. If there is a possibility to transmit files, they will also be transferred encrypted.

If you use this method of contact, we collect the following personal data depending on context:

  1. name (first/surname)
  2. company
  3. phone
  4. valid email address
  5. your message
  6. address (road, house no., postcode, city, country)
  7. request (observations, comments)

Handling your request requires the input of a valid email address and a message. All other information is voluntary.

Processing purpose

The processing of the data you provide is only for the processing of your concern and contact. Without your consent, we will not pass your data on to third parties.

Legal basis & storage time

Data processing related to the use of a contact form is carried out on the basis of your consent (art 6 (1)(a) of the GDPR).

We store the information you provide for the duration of the processing of your concern or until the conversation is over. The conversation is ended when it can be seen from the circumstances that your concern is finally settled and another conversation is not required and you do not want another conversation.

Business relevant components of a communication may be subject to legal storage periods or may be required for the validation, exercise or defence of legal claims. In this case, we store the data at least until the storage and warranty periods are completed.


3.3 When creating user accounts (registration)

To place orders, the customer must set up a password-protected user account. You can use a corresponding dialogue to provide log-in details. Please treat your log-in details confidentially. We do not assume liability for password abuse unless it has been caused by ourselves.

Your log-in details are stored encrypted. We have no access to your log-in details.

Our offer is expressly aimed only at people who have reached the age of 16 at the time of registration. You must confirm this to us by clicking the corresponding checkbox.

Registration offers the advantage of using our shop with your log-in details and placing future orders without having to enter your personal information again.

You may delete your customer account. Please note below the information on the storage time of your personal data.

Processing purpose

The information provided is used to set up a user account. In the context of an order process, the entry of further information (eg date of birth) may be required.

Legal basis & storage time

Data processing related to your registration is based on your consent (art 6 (1)(a) of the GDPR), which you grant by registering as a user.

We store the information you provide for the duration of your property as a registered user of our shop system.

If you delete your customer account, please note that business-related information accumulated during your time as a user (eg order information), legal storage periods are subject to and/or may be required for the validation, exercise or defence of legal claims.

In such cases, we store the data at least until the expiry of the relevant deadlines.

3.4 Orders

Orders can only be placed by registered users.

Personal data required for the fulfilment of an order shall be collected and encrypted in a template and transmitted. To process an order, the following information is required (required fields):

  1. name (first/surname)
  2. address (road, house no., postcode, city, country)
  3. date of birth
  4. valid email address
  5. phone number for inquiries
  6. depending on the selceted payment method: bank details/credit card information

For registered users, this information is saved in the customer account. This information only needs to be collected once.

Processing purpose

We use the transmitted information

  • to identify you as a customer/registered user
  • to perform an age verification
  • to process your order (commission goods, organise delivery)
  • to conduct a credit check
  • to communicate with you
  • for accounting
  • for the application, exercise or defence of claims
  • to ensure data is processed securely
  • to manage customer data and implement customer-related services (eg order history, shopping cart)

To ensure your and our security, we may carry out a credit check before conclusion of a contract (eg first-time orders, new customers, etc). We use external service providers. In the context of this examination, your personal data (name, address, date of birth) will be sent to the Bavarian debt collection agency BID Bayerischer Inkasso Dienst GmbH, Weichengereuth 26, 96450 Coburg, www.bid-coburg.de.

Legal basis & storage time

Your information is processed on the basis of your registration, your request, an order and/or to fulfil a contract with you (art 6(1)(b) of the GDPR).

In the case of a credit check, the legal basis is in our legitimate interest (art 6(1)(f) of the GDPR) to minimising bad debt.

The data collected for order processing shall be stored and deleted until the expiry of statutory retention, warranty and documentation obligations (6–10 years according to the German Commercial Code [HGB], the German penal code [StGB], the German tax code [AO], etc) and after that, unless we are obliged to store for longer storage in accordance with art 6(1)(c) of the GDPR or you have agree to a longer period of time in accordance with art 6(1)(a) of the GDPR.

3.5 When receiving a newsletter

We offer the option to subscribe to our company newsletter on our site. We regularly inform you about our offers in this newsletter. To send you our newsletter, we need a valid email address from you. The email address you entered will be checked to determine whether you are actually the owner of the given email address or the owner who authorised the subscription to the newsletter (double opt-in).

You can cancel the subscription to this newsletter at any time. For details, please refer to the confirmation mail and to each individual newsletter.

Newsletter mailings can be made using a mailing service provider. In this case, your email address will be sent directly to the despatch service provider and processed by it. We currently work with <Name und Adresse des Versanddienstleister>. For information on the privacy provisions of the shipping service provider, see <Link auf Datenschutzerklärung des Versanddienstleisters>.

Processing purpose

Upon your registration to our newsletter we will save your IP address and the date as well as time of your registration.

The data collected in this way is used exclusively for the receipt of the newsletter. No transfer to third parties for advertising purposes is made. The email address collected when registering for the newsletter is not compared with data that may be collected by other components of our site.

Our newsletter may contain advertisements for our own products. You will be notified of this upon registry and have agreed to receive this advertisement to the specified email address.

Legal basis & storage time

We process the data collected on the basis of your consent (art 6(1)(a) of the GDPR) for the transmission of the newsletter to the specified email address and from the legitimate interest (art 6(1)(f) of the GDPR) to minimise liability/damage risks arising from a possible abuse of your email address by third parties.

If you have made your email address available exclusively for the receipt of the newsletter, we will delete the address from our distributor if you unsubscribe.

This deletion does not concern email addresses that you have provided us with in connection with a registration or contract.

3.6 Children's data (Minor Protection)

Persons under the age of 16 should not provide personal data to us without the consent of parents or legal guardians. We do not request personal data from children and adolescents and do not collect such data knowingly.

4. Data transfer

Your data may be passed on (transmission) as part of the contract processing to service providers involved in the contract processing. Such service providers may be:

  • credit agencies consulted by us or a service provider involved in creditworthiness enquiries
  • credit institutions entrusted with payment matters
  • logistics companies commissioned with delivery

The transmission shall be limited to the extent necessary for the provision of the service.

Processing purpose

Data is passed on to the extent necessary to enable processing of our contract with you.

Legal basis & storage time

Data is shared:

  • if you have granted your consent in accordance with art 6(1)(a) of the GMO
  • to the extent necessary to allow the application, exercise or defence of rights (art 6(1)(f) of the GDPR)
  • where there is a legal obligation for the transfer under art 6(1)(c) of the GMO
  • if legally admissible and required for the settlement of the contractual relationship with you (art 6(1)(b) GDPR)

If your consent is required for processing, it will be obtained within the ordering process.

5. Payment systems

We offer you the PayPal and credit card.

5.1 PayPal use as a method of payment

If you decide to make a payment via the online payment service provider PayPal as part of your order process, your contact details will be sent to PayPal as part of the order triggered in this way. PayPal is an offer from PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal acts as an online payment service provider and a trustee and offers buyer protection services.

The personal data transmitted to PayPal is mostly first name, surname, address, telephone number, IP address, email address, or other information necessary for order processing, as well as information related to the order , such as number of items, item number, invoice amount and taxes in percent, invoice information, etc.

This transmission is necessary to process your order with the payment method you have selected, in particular to confirm your identity, to administer your payment and the customer relationship.

However, please note: Personal data can also be passed on by PayPal to service providers, subcontractors or other affiliated companies, insofar as this is necessary to fulfill the contractual obligations from your order or the personal information is to be processed in the order.

Depending on the payment method selected via PayPal, eg invoice or direct debit, the personal data transmitted to PayPal is transmitted by PayPal to credit reporting agencies. This transmission serves the identity and credit check in relation to the order you placed. You can find out which credit agencies are concerned and which data is generally collected, processed, stored and passed on by PayPal in PayPal's data protection declaration at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

6. Use of cookies

Cookies are small text files that are stored on your device. They do not contain any executable software and do no damage to your computer. Information is stored in cookies that results in connection with the specific device used. However, this does not automatically mean that we are immediately aware of your identity.

You can set your browser so that you are informed about cookie settings, only allow cookies in individual cases, or generally allow or reject cookies. You can also set cookies to be deleted when the browser is closed. Your settings (eg shopping cart content, selection in the cookie banner, etc) will then be lost when you close the browser and must be entered again the next time you open the browser.

Please note that your cookie settings affect the functionality of the website.

6.1 Own cookies

Processing purpose

We use different types of cookies. Essential cookies are required to provide certain content in the desired manner (eg the content of your shopping cart, your selection in the cookie banner, etc). These cookies are required and therefore always active.

We also use cookies for statistical purposes. Here, information about the use of our website is collected and processed statistically. We receive these statistics from the web host or web shop operator in anonymised form. It is not possible to assign this data to a specific user.

Consent

If cookies are not explicitly required for the provision of our website, we will explicitly obtain your consent at the start of the usage process. This is done via a cookie banner. However, the cookie banner is only displayed if you allow the use of JavaScript in your browser.

You can revoke the selection made in the cookie banner at any time. To do this, locate the cookie banner by clicking on the tab on the bottom left side of the page and change the settings as you wish.

Legal basis & storage time

The use of essential cookies is based on our legitimate interest in ensuring the functionality of our website (Article 6(1)(f) of the GDPR). Essential cookies are so-called session cookies that are deleted when the browser session ends.

Cookies that contain personal settings (eg selection in the cookie banner, shopping cart content, etc) remain on your computer until you delete them manually or by making the appropriate settings in your browser.

The setting of statistical cookies and cookies for marketing purposes takes place in accordance with your consent (art 6(1)(a) of the GDPR). These cookies remain on your computer until you delete them manually or by using the appropriate settings in your browser.

To exercise your right of withdrawal, please see the section “Consent”

6.1 Thirdy-party cookies

We use functionalities within our website (eg payment function, sharing content in social networks, providing videos, etc) that are provided by third parties.

These functions are provided by links so that data (eg IP address, URL, time, date, etc) or cookies are only set by the third-party provider when you use the corresponding link knowingly.

By clicking on such a link (eg selection of the payment method, buttons for sharing content, etc), you will be forwarded to the website of the respective provider, where cookies can also be used. We have no influence on the setting of these cookies and the further processing of the data collected. The respective provider is solely responsible for compliance with (data protection) legal requirements.

Therefore, please note the data protection information of the respective provider.

7. Third-party links

Content or services from third-party providers (eg YouTube, Google Maps, Pinterest, Instagram, etc) can be integrated into our website. The integration of this content requires that the third-party providers perceive the IP address of the user, since without the IP address they could not send the content to the user's browser. The IP address is therefore required to display this content. Furthermore, the providers of third-party content can set their own cookies and process user data for their own purposes. Usage profiles of site visitors can also be created from the processed data.

Please note the data protection declaration of the respective provider when using corresponding offers.

Links published by us are researched and compiled with the greatest possible care. However, we have no influence on the design and content of linked pages. We are not responsible for the content of linked sites, nor do we adopt their content as our own.

The provider of the website referred to is solely liable for illegal, incorrect or incomplete content as well as for damage caused by the use or non-use of the information. The liability of those who merely refer to the publication by a link is excluded. We are only responsible for third-party notices if we also have positive knowledge of any illegal or punishable content and it is technically possible and reasonable for us to prevent their use.

8. Tracking and analysis tools

We use the results from the use of analytical and tracking tools to optimise our offer and to design our website in a suitable manner.

8.1 Analysis Tools of Shopify Shop-Shop System

Our web shop is based on the Shopify shop software. Shopify offers a number of analytical tools, which we use as described below to optimise our offer. In some cases, personal evaluations can also be created:

  • open shopping carts
    The following information is available in the report:
    • customer’s name and email address
    • number of products in your cart
    • subtotal
    • date of creation of the shopping cart
    • date of last update
  • newsletter issues
    The following information is available in the report:
    • name of the recipient in question
    • mailing date
    • subject
    • detailed information about the specific error
  • review reports (sorted by customer or product)
    • list of customers who have submitted a product review
    • number of ratings per customer
    • link to the list of reviews
  • information about PayPal transactions
    • filtering by date, seller account, transaction ID, invoice ID, PayPal reference ID
    • type of transaction (eg credit card payment)
    • start/end date
    • total
    • fees
  • customer reports
    • information on customer activities
    • information about orders (order sums, number of orders per customer, average order amount, total orders)
    • overview of newly created customer accounts in a specific time interval or date range
  • order, invoice, shipping information
  • overview of refunds made
  • information on the use of vouchers and coupon codes

The available analytical tools are subject to technical progress and may change. If we use new or other personal evaluations, this privacy statement will be adapted.

Opting out

If you do not agree with this processing, please refrain from registering as a user and using the web shop. It is not possible to object to these analytical tools, as they are an integral part of the shop software and are required for administrative purposes (eg open shopping carts, etc).

8.2 Google Webfonts

We use Google web fonts. Google Fonts is a service of Google LLC ("Google"). These web fonts are integrated by calling up a server, usually a Google server in the USA. This tells the server which of our websites you have visited. The IP address of the browser of the visitor’s end device to this website is also stored by Google. You can find more information in Google's privacy policy, which you can access here:
www.google.com/fonts#AboutPlace:about
www.google.com/policies/privacy/

9. Social Media Plugins

Our company maintains profiles on Facebook, YouTube, Instagram and Pinterest.

The providers of these network platforms may collect information about your visit to our website when you are logged in with your account.

Our company has no influence on the data processing of the respective providers.

Comment function

Some social media platforms offer a commentary feature. We would like to point out that your comments and other input will be processed by the platform provider. Further data (eg your IP address) can also be processed by the provider.

We reserve the right to delete comments from the company’s social media profile, to block the access function or the user account altogether or to request the deletion/blocking if the user violates personal, copyright or criminal law provisions, violates the personal rights of third parties or posts offensive, defamatory, anti-constitutional, racist, sexist, violent or pornographic statements or images.

This data protection declaration does not apply to data processing by social media providers. Therefore, please note the privacy policy of the provider.

Handling comments about our company

If you leave a post or comment on our website, your IP address will be saved. This serves the security of the website operator:

If your comment violates applicable law, we can be prosecuted, for which reason we have an interest in the identity of the author.

You have the option of subscribing to both the entire website and subsequent comments on your contribution. You will receive an email confirming your email address. Apart from this, no other data is collected. The stored data will not be passed on to third parties. You can unsubscribe at any time.

9.1 Facebook

This website uses Facebook Social Plugins, which is operated by Facebook, Inc. (1 Hacker Way, Menlo Park, California 94025, USA). The integration can be recognized by the Facebook logo or by the terms "Like", "Share" in the Facebook colours (blue and white). You can find information on all Facebook plugins in the following link: https://developers.facebook.com/docs/plugins/

The plugin establishes a direct connection between your browser and the Facebook servers. The website operator has no influence on the nature and scope of the data that the plugin transmits to the Facebook, Inc. servers. You can find information on this here: https://www.facebook.com/help/186325668085084. The plugin informs Facebook, Inc. that users have visited this website. There is a possibility that your IP address will be saved. If you are logged into your Facebook account while visiting this website, the information mentioned will be linked to it.

If you use the plugin functions—for example, by sharing or "liking" a post—the corresponding information will also be transmitted to Facebook, Inc.

If you would you like to prevent Facebook, Inc. from linking this data to your Facebook account, please log out of Facebook before visiting this website.

9.2 Pinterest

We use the Pinterest service on our website. Pinterest is a service offered by Pinterest, Inc., 808 Brannan St, San Francisco, CA 94103, USA. Through the integrated "Pin it" button on our website, Pinterest receives the information that you have accessed the corresponding page on our website. If you are logged in to Pinterest, Pinterest can assign this visit to our page to your Pinterest account and thus link the data. The data transmitted by clicking the "Pin it" button is saved by Pinterest. For more information on the purpose and scope of data collection, its processing and use, as well as your rights and setting options to protect your privacy, please refer to the Pinterest privacy policy, which you can access at http://pinterest.com/about/privacy/.

To prevent Pinterest from associating your visit to our site to your Pinterest account, you must log out of your Pinterest account before visiting our site.

10. Data security

By using the widely used SSL procedure (Secure Socket Layer) we enable you to send your data in encrypted form. You can tell whether individual pages are being encrypted by display of the closed key or lock symbol in the status bar of your browser.

When visiting a secure website, the website identity button (a lock) is displayed in the address bar. This allows you to quickly determine whether the connection to the website you are viewing is encrypted, and in some cases you can also see to whom the website belongs. This is to help you identify malicious sites and prevent them from getting to your personal information.

We also use suitable technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

11. Rights of the persons affected

As one of the persons affected, you have the following rights under the GDPR:

11.1 Right to information

You can get information according to art 15 of the GDPR about your personal data processed by us. In your request for information, you should specify your concerns in order to make it easier for us to compile the necessary data. Please note that your right to information may be restricted in certain circumstances in accordance with the statutory provisions (in particular art 34 of the German Federal Data Protection Act [BDSG]).

11.2 Right to correction

If the information concerning you is no longer correct, you can request a correction in accordance with art 16 of the FDPA. If your data is incomplete, you can request completion.

11.3 Right to deletion

You can request the deletion of your personal data under the conditions of art 17 of the GDPR. Your right to deletion may depend on whether we still need the data relating to your person to fulfill legal tasks.

11.4 Right to restrict processing

Within the framework of the provisions of art 18 of the GDPR, you have the right to request that the processing of your data be restricted.

11.5 Right to objection

According to art 21 of the GDPR, you have the right to object to the processing of your data at any time for reasons that arise from your particular situation. However, we cannot always comply with this, eg if we are legally obliged to process data as part of our official performance of duties. In this case, we will restrict the processing of your data.

11.6 Right to withdraw the declaration of consent under the dates of the law

Insofar as the processing of your data is based on your consent, you have the right to revoke it at any time in accordance with art 7(3) of the GDPR. The revocation does not affect the legality of the processing carried out up to that point. You can declare a revocation in writing, by email and, if necessary, as part of the service offered (newsletter).

11.7 Right to appeal

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged violation, if you believe that the processing of your personal data is violates the GDPR.

The contact details of the supervisory authority responsible for the company are:

Bavarian State Office for Data Protection Supervisory Service

Promenade 27
91522 Ansbach

Phone: 0981/53-1300
Fax: 0981/53-53 98 1300

Email: poststelle@lda.bayern.de
Homepage: www.lda.bayern.de

12. Reservation of amendments

We reserve the right to adapt this data protection declaration to current technical and legal developments. Therefore, if you visit our website again, please inform yourself about the content of the current data protection declaration.

If parts or individual formulations of the following text do not, no longer or do not completely correspond to the applicable legal situation, the remaining parts of the document remain unaffected in their content and validity.

The last change was made on 15.03.2019