Data protection
Privacy Policy
1. Responsible person
The responsible body within the meaning of the General Data Protection Regulation (GDPR) and other data protection regulations is:
PKT MAM GmbH
Bösendorferstrasse 2/18
1010 Vienna, Austria
Email: hilfe@mam-shop.at
2. General information on data processing
Legal basis
Unless otherwise stated in this privacy policy, our processing of personal data is based on:
- Consent: Art. 6 Para. 1 lit. a GDPR (and Art. 7 GDPR for proof of consent).
- Fulfillment of contract: Art. 6 Paragraph 1 Letter b GDPR.
- Fulfillment of legal obligations: Art. 6 Paragraph 1 Letter c GDPR.
- Legitimate interest: Art. 6 Paragraph 1 Letter f GDPR.
- Vital interests: Art. 6 Paragraph 1 Letter d GDPR.
Data deletion and storage period
We only collect and store personal data for as long as is necessary to fulfill the stated purposes or to comply with legal retention periods. It will then be quickly deleted.
Data transfer to third countries
Our website integrates tools and services from companies based in third countries. When such services are activated, your personal data may be transferred to servers in these countries. The level of data protection in these third countries often does not correspond to that of the EU, so authorities in these countries may have access to your data - we have no influence on these processing activities.
3. External links
Our website contains links to external third-party websites. When you click on such links, among other things: Your IP address, the time of the click and other information are transmitted to the respective operator. Please note that these websites have their own data protection declarations. We assume no liability for their content.
4. Rights of the data subject
As a data subject, you have the following rights:
- Right to information (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to deletion (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to object (Article 21 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to complain at a supervisory authority
Some data processing takes place exclusively on the basis of your express consent. You can revoke this consent at any time without affecting the lawfulness of the processing carried out up to the point of revocation.
5. Provision of the website (hosting)
Our website is hosted at:
Shopify International Ltd.
2nd Floor 1 and 2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland
Server location: Canada
When you access our website, technical data (e.g. IP address, device used, browser type, operating system, time of server request) is automatically recorded in server log files. This data is not merged with other data sources.
6. Use of local storage, session storage and cookies
Our website uses mechanisms such as local storage, session storage and cookies to:
- save user preferences (e.g. “day/night mode”),
- to control shopping cart functions,
- to ensure the functionality and security of the website and
- to collect statistical data (e.g. visitor behavior).
Distinction:
- Necessary cookies/storage: Based on our legitimate interest (Art. 6 Para. 1 lit. f GDPR).
- Non-essential cookies/storage: Are only saved after express consent (Art. 6 Para. 1 lit. a GDPR).
If third parties use corresponding technologies, we will inform you in the context of this data protection declaration and obtain your consent.
7. Use of external services
Below you will find a detailed list of the external services used on our website:
Meta Pixel & Facebook Conversion API
- Purpose: Conversion measurement and targeted advertising.
- Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
- Data transfer: There may be transfers to third countries (e.g. to the USA).
- Shared responsibility: We are jointly responsible for collecting and passing on the data to Meta (Article 26 GDPR). Further processing is carried out independently at Meta.
-
Further information:
Facebook/Meta privacy policy
Joint Processing Agreement
WhatsApp as a messaging service
- Purpose: Customer support and sending newsletters.
- Provider: WhatsApp Inc., 1601 Willow Road, Menlo Park, CA 94025, USA (part of Meta Platforms).
- Data transfer: Your phone number and, if applicable, message content will be transferred to WhatsApp/Meta.
- Legal basis: Processing takes place exclusively on the basis of your express consent (Art. 6 Para. 1 lit. a GDPR).
-
Further information:
WhatsApp privacy policy
Affiliate network
- Purpose: Integration of advertisements and links to partner sites to place orders.
- Technology: Use of cookies or comparable recognition technologies (e.g. device fingerprinting).
- Legal basis: Processing only takes place with your consent (Art. 6 Para. 1 lit. a GDPR).
Analytics Services
We use various tools to analyze user behavior and optimize our website:
· Google Analytics:
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Data transfer: Can be made to the USA.
-
Further information:
Google privacy policy
· Triple Whale:
- Provider: Triple Whale Inc., 266 N 5th Street, Columbus, OH 43215, USA.
-
Further information:
Triple Whale Privacy Notice
Lucky Orange
- Provider: Lucky Orange LLC, 8665 W 96th St Suite #100, Overland Park, KS 66212, USA.
- Data transfer: Transmission to the USA may occur.
- Certification: The provider is in accordance with EU-U.S. Data Privacy Framework certified.
-
Further information:
Lucky Orange Privacy Statement
Shopify Analytics
- Provider: Shopify International Ltd., 2nd Floor 1 and 2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland.
- Data transfer: Can be made to a third country (Canada); There is an adequacy decision for Canada.
-
Further information:
Shopify Privacy Policy
PageFly
- Provider: BraveBits JSC., 2nd floor Ecolife Capitol, 58 To Huu, Me Tri, Nam Tu Liem District, Hanoi, Vietnam.
- Data transfer: Transmission may occur in Vietnam.
-
Further information:
PageFly Privacy Policy
Google Tag Manager
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Data transfer: A transfer to third countries (e.g. to the USA) may occur.
-
Further information:
Google Tag Manager privacy policy
Web fonts
- Purpose: Uniform display of fonts.
- Technology: When you load the web fonts via an external provider, your IP address is transmitted to them.
- Legal basis: Our legitimate interest (Art. 6 Para. 1 lit. f GDPR).
Adobe Typekit
- Provider: Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland.
- Data transfer: A transfer to third countries (e.g. USA) may occur.
-
Further information:
Adobe Privacy Policy
Web security and hCaptcha
- Purpose: Protection against unauthorized access, spam and attacks.
- Provider hCaptcha: Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA.
- Data transfer: Transmission to the USA may occur.
-
Further information:
hCaptcha privacy policy
8. Newsletters and Marketing
Newsletter tools
- Klaviyo:
- Provider: Klaviyo, Inc., 125 Summer St, Floor 6, Boston, MA 02111, USA.
- Integration: Forms for registration and interaction are dynamically integrated.
- Data transfer: Transmission to the USA may occur.
-
Further information:
Klaviyo Privacy Policy
Advertising
- Google Ads:
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Data transfer: There may be transmission to the USA.
-
Further information:
Google privacy policy - Google DoubleClick:
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Data transfer: There may be transmission to the USA.
-
Further information:
Google privacy policy
Sending newsletters to existing customers
If you are already a customer and have provided your email address when placing an order, this can be used to send newsletters about your own, similar products.
- Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR).
- After unsubscribing from the newsletter distribution list, your email address can be stored in a blacklist to avoid unauthorized mailings.
9. Contact forms and other communication channels
Contact form
You can send us messages using our contact form. This includes, among other things: Your name and email address are collected in order to respond to your request.
- Legal basis: Art. 6 Paragraph 1 Letter b and Letter f GDPR.
Telephone contact and email contact
Via the telephone numbers and email addresses provided on our website (e.g. hilfe@mam-shop.at) you can contact us. The data transmitted will be saved to process your request.
- Legal basis: Art. 6 Paragraph 1 Letter b and Letter f GDPR.
10. Registration and Customer Accounts
Visitors can register on our website to gain access to additional services or content.
- The personal data collected for this purpose is processed to fulfill the contract, customer care and provide the desired content.
- Legal basis: Either your consent (Art. 6 Para. 1 lit. a GDPR) or to fulfill the contract (Art. 6 Para. 1 lit. b GDPR).
11. Processing of customer and contract data
We collect, process and use personal data that arises in the context of customer relationships to establish, structure and change our contractual relationships.
- After the business relationship has ended and statutory retention periods have expired, the data will be deleted.
- Legal basis: Art. 6 Paragraph 1 Letter b GDPR.
12. Payment service providers
When you make a purchase, your payment details (e.g. name, payment amount, account details, credit card number) are transmitted to our payment service providers.
- Klara:
- Provider: Klarna Bank AB German Branch, Chausseestraße 117, 10115 Berlin, Germany.
-
Further information:
Klarna privacy policy - PayPal:
- Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
- Data transfer: May result in transmission to the USA.
-
Further information:
PayPal Privacy Hub
13. Other external services and interface software
We use interface software to link different applications together and to enable smooth transfer of personal data between systems.
- Legal basis: Our legitimate interest (Art. 6 Para. 1 lit. f GDPR).
Examples of this are:
- Google Tag Manager
- Shopify (and Shopify Analytics)
- Affiliate networks
- Web security tools
14. Presence on social networks
We maintain a profile on Instagram.
- Provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
- Data transfer: When you visit the profile, you can, among other things: Your IP address and device information will be transferred.
- Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR).
-
Further information:
Instagram privacy policy
15. Other processing
Registration, customer and contract data
The data collected as part of customer relationships is processed exclusively for contract fulfillment and customer care and is deleted after the business relationship has ended (unless there are legal retention periods to the contrary).
Payment service provider
The data collected during payments is used exclusively to process the purchase process and is processed in accordance with the data protection information of the respective provider.
16. Summary and Notes
This data protection declaration provides you with comprehensive information about the collection, processing and use of your personal data as part of our website and the associated services.
If we obtain your consent to data processing (e.g. for cookies, meta tools, WhatsApp or newsletter tools), you can revoke this at any time without affecting the lawfulness of the processing carried out until the revocation.
If you have any questions about this privacy policy or the processing of your personal data, please contact:
PKT MAM GmbH
Bösendorferstrasse 2/18
1010 Vienna, Austria
Email: hilfe@mam-shop.at