Privacy policy
Datenschutzerklärung
Introduction
This privacy policy informs users ("you") about the nature, scope and purposes of the collection and use of personal data on the website www.phuiphuistudio.com and our presence on social networks and platforms ("Online Offer").
Name and contact details of the responsible party:
Phui Phui Studio
Phui Yan Khuong
Kirchstr. 29, 52428 Jülich
Germany
Phone: +49 157 50888391
Email: contact@phuiphuistudio.com
Managing director: Phui Yan Khuong
Legal form: Sole Proprietorship
Collection, use and storage of personal data
Collection of personal data when visiting the website
When using the website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the data that your browser transmits to our servers. If you wish to view our website, the following data is technically necessary to display the website to you and to ensure its stability and security. The legal basis for the collection are corresponding legitimate interests according to Art. 6 para. 1 f) DSGVO:
IP address,
Date and time of the request,
Time zone difference to Greenwich Mean Time (GMT),
Content of the request (specific page),
access status/HTTP status code,
amount of data transferred in each case,
Website from which the request came,
Browser,
operating system and its interface, and
Language and version of the browser software.
We reserve the right to check the log data retrospectively if there is a justified suspicion of unlawful use based on concrete indications. We store IP addresses in the log files for a limited period of time if this is required for security purposes or necessary for the provision of services, as well as in the case of concrete suspicion of a criminal offense in connection with the use of the website.
Further personal information is only collected if you provide it voluntarily, for example in the context of an inquiry or purchase. Depending on the area concerned, Phui Phui Studio uses the personal data provided by you to answer your inquiries, to process your order and for the purpose of technical administration of the websites. In detail, the use in the respective areas follows as follows:
Online store
If you order in our online store, we store the following information for the fulfillment of the contract concluded between you and Phui Phui Studio or for the implementation of pre-contractual measures according to Article 6 lit. b) DSGVO:
a) Order without setting up a customer account
When placing an order in the online store, all data necessary for execution and processing will be requested by means of mandatory fields: Your full name, your e-mail address, your address (billing address and, if applicable, different delivery address). Your data will only be used to process your order.
b) Customer account / registration
It is also possible that you register for your purchase at Phui Phui Studio. For this purpose, you can choose a password together with your e-mail address, both of which will allow you to log in more easily without having to enter your data again in case of a later purchase. Phui Phui Studio stores the data you enter to set up a customer account through which your orders are recorded, executed and processed. Phui Phui Studio will keep your data for further orders as long as you maintain the registration. You have the right to retrieve, correct or delete your registration data at any time. To delete please use the "delete account" function.
c) Retention of order data
If you submit data to Phui Phui Studio for an order, your data will be stored for as long as necessary for the purchase transaction and mandatory according to the legal retention periods. The extended storage for the fulfillment of the retention obligations is carried out according to article 6 lit. c) DSGVO.
Contact form
If you contact Phui Phui Studio via a contact form on the Phui Phui Studio internet pages, the data you provide will be stored so that your message can be answered. This is done according to article 6 lit. b) DSGVO to process your request. Your data provided via a contact form will not be used for other purposes, especially not for advertising.
Newsletter
You can subscribe to the Phui Phui Studio email newsletter by registering for it with your first and last name and an email address and submitting the form. Likewise, you can do this by ticking the checkbox in the checkout area.
If you subscribe to our e-mail newsletter, we will send you regular information about our promotions, offers and services. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an e-mail newsletter if you have expressly confirmed that you consent to the sending of the newsletter. We will then send you a confirmation e-mail asking you to confirm that you wish to receive future newsletters from us by clicking on an appropriate link.
When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your e-mail address at a later date. In the case of the confirmation e-mail sent out for control purposes (double opt-in mail), we also save the date and time of the click on the confirmation link and the IP address entered by the Internet service provider (ISP). The processing of this data is based on your consent according to Art. 6 para. 1 lit. a) DSGVO or based on legitimate interests of us according to Art. 6 para. 1 lit. f) DSGVO to prove the required consent.
You can revoke your consent to receive the newsletter at any time by clicking on the unsubscribe link located at the end of each newsletter.
The data you have provided to us for the purpose of receiving the newsletter and the data stored by us for the purpose of proving your consent will be stored by us until you unsubscribe from the newsletter and will be deleted after you unsubscribe from the newsletter. After unsubscribing, your e-mail address will be deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration.
Disclosure and deletion of personal data
Visiting the Phui Phui Studio websites
The data stored during the mere visit of the Phui Phui Studio websites will not be passed on to third parties.
Online store
a) Passing on of data
Your personal data will only be passed on to third parties within the scope of the online store if it is necessary for the purpose of contract processing, for accounting purposes or for the collection of the payment.
b) Deletion of the customer account
If you have registered for a customer account in the context of the online store at Phui Phui Studio, you can delete it yourself by using the function "Delete account".
Contact form
The data you have entered in our contact form will not be passed on to other third parties, unless you are separately informed about this.
Newsletter
The e-mail address you provide for newsletter registration will not be passed on to third parties. Only for data processing on behalf Phui Phui Studio uses Shopify Inc. 151 O'Connor Street, Ottawa, ON K2P 2L8, Canada. If you no longer wish to receive the newsletter, your e-mail address will be deleted from the distribution list.
Transfer to authorities and other public bodies
Your data will only be passed on to third parties outside Phui Phui Studio if the responsible public authority or governmental institution orders the release in individual cases, in which case Phui Phui Studio is obliged to do so.
Security
Technical organizational measures
Phui Phui Studio has taken a variety of security measures to protect personal information to an appropriate extent and adequately. All information stored by Phui Phui Studio is protected by physical, technical, and procedural measures that limit access to the information to specifically authorized individuals in accordance with this Privacy Policy.
Phui Phui Studio websites are located behind a software firewall to prevent access from other networks that connect to the Internet. In addition, only employees who need the information to perform a specific task are granted access to personally identifiable information. These employees are trained in security and privacy practices and treat your information confidentially.
Data Transfer
The transmission of your personal information during an order transaction in the online store is encrypted using industry-standard Secure Socket Layer ("SSL") technology, (SSL encryption version 3
Credit card information
Any credit card information you provide will not be stored by Phui Phui Studio, but will be collected in encrypted form directly from the payment service provider (Shopify and PayPal) via hypertext transfer protocol secure ("https").
Passwords
You should never give your password for accessing our customer portal to third parties and you should also change it regularly. If you want to leave your customer account in the online store, you should press the logout and close your browser to avoid that someone gains unauthorized access to it.
Cookies
Use of cookies
Cookies are text files that contain data from visited websites or domains and are stored by a browser on the user's computer. The primary purpose of a cookie is to store information about a user during or after their visit within an online site. Stored information may include, for example, language settings on a website, login status, a shopping cart, or where a video was watched. We further include in the term cookies other technologies that perform the same functions as cookies (e.g., when user information is stored using pseudonymous online identifiers, also referred to as "user IDs")
The following cookie types and functions are distinguished:
Temporary cookies (also: session cookies): temporary cookies are deleted at the latest after a user has left an online offer and closed his browser.
Permanent cookies
Permanent cookies remain stored even after the browser is closed. For example, login status can be saved or preferred content can be displayed directly when the user visits a website again. Likewise, the interests of users used for range measurement or marketing purposes can be stored in such a cookie.
First-party cookies
First-party cookies are set by ourselves.
Third-party cookies
Third-party cookies are mainly used by advertisers (so-called third parties) to process user information.
Necessary cookies
Cookies may be absolutely necessary for the operation of a website (e.g. to store logins or other user input or for security reasons).
Statistical, marketing and personalization cookies
Furthermore, cookies are usually also used in the context of range measurement and when a user's interests or behavior (e.g. viewing certain content, using functions, etc.) on individual websites are stored in a user profile. Such profiles are used, for example, to show users content that matches their potential interests. This process is also referred to as "tracking", i.e., tracking the potential interests of users. Insofar as we use cookies or "tracking" technologies, we will inform you separately in our data protection declaration or in the context of obtaining consent.
Notes on legal basis
The legal basis on which we process your personal data using cookies depends on whether we ask you for consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is your declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in the business operation of our online offer and its improvement) or, if the use of cookies is necessary to fulfill our contractual obligations.
Storage period
Unless we provide you with explicit information about the storage period of permanent cookies (e.g. in the context of a so-called cookie opt-in), please assume that the storage period can be up to two years.
Revocation and objection (opt-out)
Depending on whether the processing is based on consent or legal permission, you have the option at any time to revoke any consent you have given or to object to the processing of your data by cookie technologies (collectively referred to as "opt-out"). You can initially declare your objection by means of your browser settings, e.g. by deactivating the use of cookies (whereby this may also restrict the functionality of our online offer).
An objection to the use of cookies for online marketing purposes can also be declared by means of a variety of services, especially in the case of tracking, via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. In addition, you can obtain further instructions on how to object in the context of the information on the service providers and cookies used.
Processing of cookie data on the basis of consent: Before we process or have data processed within the scope of the use of cookies, we ask users for consent that can be revoked at any time. Before the consent has not been expressed, cookies are used at most, which are absolutely necessary for the operation of our online offer.
Legal basis
Consent (Art. 6 para. 1 p. 1 lit. a. DSGVO), Legitimate Interests (Art. 6 para. 1 p. 1 lit. f. DSGVO).
Your rights as a data subject
Revocation of your consent
As a data subject, you have the right pursuant to Art. 7 (3) DSGVO to withdraw your consent given once to Phui Phui Studio at any time. As a result, we may no longer process your personal data. After revocation of consent, processing that was lawful in the past remains lawful.
Objection
Insofar as your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) f) DSGVO, you have the right to object to the processing of your personal data pursuant to Art. 21 DSGVO if there are grounds for doing so that arise from your particular situation. This is the case if the processing is not necessary, in particular, for the performance of a contract with you, which is shown in each case in the following description of the functions. When exercising such an objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will review the merits of the case and either stop the data processing, adapt it or show you our compelling legitimate grounds on the basis of which we will continue the processing.
You can lodge your objection by sending us a simple e-mail or by filling out our contact form. Of course, you can also object to the processing
of your personal data for purposes of advertising and data analysis at any time. In addition, we will point out how you can object at the time of use.
Information
In accordance with Art. 15 DSGVO, you will receive information about your personal data processed by Phui Phui Studio free of charge upon request. The information informs you about:
the processing purposes,
the category of personal data,
the categories of recipients to whom the data has been or will be disclosed,
the intended storage period,
the existence of a right to rectification, erasure, restriction of processing or objection,
the existence of a right of appeal,
the origin of your data, if it has not been collected by us,
any existing automated decision-making including profiling.
Correction
In accordance with Art. 16 DSGVO, you may request rectification if we store your personal data incorrectly or incompletely.
Deletion
In accordance with Art. 17 DSGVO, you may request the erasure of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defense of legal claims.
Restriction
In accordance with Art. 18 DSGVO, you have the right to request the restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you object to its erasure and we no longer require the data, but you need it for the assertion, exercise or defense of legal claims or you have objected to the processing in accordance with Art. 21 DSGVO.
Data portability
In accordance with Art. 20 DSGVO, you will receive your personal data that you have provided to us in a structured, common and machine-readable format. You may request their transfer to another controller, provided that this is technically possible for us.
Complaint
You may complain to a supervisory authority pursuant to Article 77 of the GDPR if you believe that the processing of your personal data violates the GDPR. As a rule, you may contact the supervisory authority at your usual place of residence, place of work or the place of an alleged infringement.
Additionally
In addition to the data protection regulations of the General Data Protection Regulation, national regulations on data protection apply in Germany. These include, in particular, the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act - BDSG). In particular, the BDSG contains special regulations on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases, including profiling. Furthermore, it regulates data processing for employment purposes (Section 26 BDSG), in particular with regard to the establishment, implementation or termination of employment relationships as well as the consent of employees. Furthermore, state data protection laws of the individual federal states may apply.
Relevant legal bases
In the following, we share the legal bases of the General Data Protection Regulation (DSGVO), on the basis of which we process personal data. Please note that in addition to the regulations of the DSGVO, the national data protection regulations in your or our country of residence and domicile may apply. Furthermore, should more specific legal bases be relevant in individual cases, we will inform you of these in the data protection declaration.
Consent (Art. 6 para. 1 p. 1 lit. a. DSGVO) - The data subject has given his/her consent to the processing of personal data relating to him/her for a specific purpose or purposes.
Performance of a contract and pre-contractual requests (Art. 6 (1) p. 1 lit. b. DSGVO) - Processing is necessary for the performance of a contract to which the data subject is a party or for the performance of pre-contractual measures taken at the data subject's request.
Legitimate interests (Art. 6 (1) p. 1 lit. f. DSGVO) - Processing is necessary for the purposes of the legitimate interests of the controller or a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
Supplementary
The supervisory authority
The State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW) in Germany is the competent authority for us in matters of data protection. You have the right to lodge a complaint with the LDI NRW at any time (www.ldi.nrw.de). However, we would appreciate it if you would contact us with your concern before contacting the LDI NRW. Therefore, please contact us first.
Hosting
We use the web hosting service Shopify to provide the website. Shopify stores this website and data on its servers (hosting). The use of Shopify is in accordance with Art. 6 para. 1 f) DSGVO due to our legitimate interest in keeping our website secure and available. We have concluded an order processing contract with Shopify including EU standard contractual clauses for the use of Shopify. Through this contract, Amazon assures that they process the data in accordance with the GDPR and ensure the protection of the rights of the data subject. Shopify is certified by reliable security standards. You can find more information about Shopify's data protection here.
Data processing in third countries
If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or the processing takes place in the context of using third-party services or disclosing or transferring data to other persons, entities or companies, this will only be done in accordance with the legal requirements.
Subject to express consent or contractually or legally required transfer, we only process or have data processed in third countries with a recognized level of data protection, contractual obligation through so-called standard protection clauses of the EU Commission, in the presence of certifications or binding internal data protection regulations (Art. 44 to 49 DSGVO, information page of the EU Commission.
Social media
Phui Phui Studio embeds links to pages on Instagram. Users can distribute links to the corresponding networks via this. The social bookmarks are only integrated as links to the corresponding services via corresponding graphics. If such a link is clicked, a forwarding to the Instagram page takes place. We do not process any personal data in this respect. However, when the linked page is called up via the link, data is processed by Instagram. How Instagram handles this data can be found here.
Changes
This policy and our commitment to protecting your personal information may result in changes to this policy. Please review this policy periodically to keep up to date with any changes.
Questions and Complaints
Any comments or questions about this Policy should be directed to us. If you believe that we have not adhered to this Policy or acted differently than in accordance with the Privacy Act, you should let us know.