Before we go into the legal mumbo jumbo that almost no one reads…
We will need your personal information to provide our services. Our promise in short: We will protect your personal information like it's ours, will not share it with anyone and will not use it for ANYTHING other than providing you the best service possible. And your data will not leave the EU. That's it.
Privacy Policy
Last updated: 22.06.2025
This Privacy Policy describes how hey lisi (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from heylisi.com (the "Site") or otherwise communicate with us (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access any of the Services.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.
How We Collect and Use Your Personal Information
To provide the Services, we collect and have collected over the past 12 months personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us.
In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
What Personal Information We Collect
The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Information We Collect Directly from You
Information that you directly submit to us through our Services may include:
- Basic contact details including your name, address, phone number, email.
- Order information including your name, billing address, shipping address, payment confirmation, email address, phone number.
- Account information including your username, password, security questions.
- Shopping information including the items you view, put in your cart or add to your wishlist.
- Customer support information including the information or documentation you choose to include in communications with us, for example, when sending a message through the Services.
Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
Information We Collect through Cookies
We also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.
Information We Obtain from Third Parties
Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:
- Companies who support our Site and Services.
- Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
- When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy. We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party's policies or practices. For more information, see the section below, Third Party Websites and Links.
How We Use Your Personal Information
- Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to you account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for performance and to enable you to post reviews.
- Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites.
- Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.
- Communicating with you. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you.
- Service Providers: PayPal: Payment services and solutions (e.g. PayPal, PayPal Plus, Braintree); service providers: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; Website: https://www.paypal.com/de; Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full. Stripe Payments Europe, Limited (SPEL) 1 Grand Canal Street Lower Grand Canal Dock Dublin D02 H210 Ireland, Website: https://www.stripe.com/
Cookies
Like many websites, we use Cookies on our Site. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.
Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:
- With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and performance).
- With business and marketing partners, to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to provide our services or through your use of social media widgets or login integrations, with your consent.
- With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
- In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
We have, in the past 12 months disclosed the following categories of personal information and sensitive personal information (denoted by *) about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":
| Category | Categories of Recipients |
|---|---|
| Identifiers such as basic contact details and certain order and account information | Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers) |
| Commercial information such as order information, shopping information and customer support information | Business and marketing partners |
| Internet or other similar network activity, such as Usage Data | Affiliates |
We do not use or disclose sensitive personal information for the purposes of inferring characteristics about you.
We have “sold” and “shared” (as those terms are defined in applicable law) personal information over the preceding 12 months for the purpose of engaging in advertising and marketing activities, as follows.
| Category of Personal Information | Categories of Recipients |
|---|---|
| Identifiers such as basic contact details and certain order and account information | Business and marketing partners |
| Commercial information such as records of products or services purchased and shopping information | Business and marketing partners |
| Internet or other similar network activity, such as Usage Data | Business and marketing partners |
User Generated Content
The Services may enable you to post product reviews and other user-generated content. If you choose to submit user generated content to any public area of the Services, this content will be public and accessible by anyone.
We do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy or keep it secure. We are not responsible for the privacy or security of any information that you make publicly available, or for the accuracy, use or misuse of any information that you disclose or receive from third parties.
Third Party Websites and Links
Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Newsletter And Electronic Notifications
We send newsletters, e-mails and other electronic notifications (hereinafter referred to as “newsletters”) only with the consent of the recipients or a legal permission. If the contents of the newsletter are specifically described in the context of a registration for the newsletter, they are decisive for the consent of the users. Furthermore, our newsletters contain information about our services and us.
To register for our newsletters, it is generally sufficient to provide your e-mail address. However, we may ask you to provide a name for the purpose of personal contact in the newsletter, or other details if these are necessary for the purposes of the newsletter.
Double opt-in procedure: The registration for our newsletter is always done in a so-called double opt-in procedure. This means that after registration you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with foreign e-mail addresses. The newsletter registrations are logged in order to be able to prove the registration process in accordance with the legal requirements. This includes the storage of the registration and confirmation time as well as the IP address. Changes to your data stored by the shipping service provider are also logged.
Deletion and limitation of processing: We may store the unsubscribed e-mail addresses for up to three years on the basis of our legitimate interests before we delete them in order to be able to prove a previously given consent. The processing of this data is limited to the purpose of a possible defence against claims. An individual request for deletion is possible at any time, provided that the former existence of a consent is confirmed at the same time. In case of obligations to permanently observe contradictions, we reserve the right to store the e-mail address in a blacklist for this purpose alone.
The logging of the registration procedure is based on our legitimate interests for the purpose of proving that it has been carried out properly. If we commission a service provider to send e-mails, this is done on the basis of our legitimate interests in an efficient and secure sending system.
Notes on legal bases: The sending of newsletters is based on the consent of the recipients or, if consent is not required, on our legitimate interests in direct marketing, if and to the extent permitted by law, e.g. in the case of existing customer advertising. If we commission a service provider to send e-mails, this is done on the basis of our legitimate interests. The registration process is recorded on the basis of our legitimate interests in order to prove that it was carried out in accordance with the law.
Content: Information about us, our services, actions and offers.
Analysis and performance measurement: The newsletters contain a so-called “web beacon”, i.e. a pixel-sized file that is retrieved from our server when the newsletter is opened, or, if we use a mailing service provider, from their server. Within the scope of this retrieval, technical information such as information on the browser and your system, as well as your IP address and the time of the retrieval, is initially collected.
This information is used for the technical improvement of our newsletter based on the technical data or the target groups and their reading behaviour on the basis of their retrieval locations (which can be determined by means of the IP address) or the access times. This analysis also includes determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our intention nor, if used, that of the mailing service provider to observe individual users. Rather, the evaluations serve us to recognise the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.
The evaluation of the newsletter and the measurement of success are carried out, subject to the express consent of the users, on the basis of our legitimate interests for the purpose of using a user-friendly and secure newsletter system that serves our business interests and meets the expectations of the users.
A separate revocation of the performance measurement is unfortunately not possible. In this case, the entire newsletter subscription must be cancelled or objected to.
- Data types processed: inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), meta/communication data (e.g. device information, IP addresses), usage data (e.g. websites visited, interest in content, access times).
- Persons concerned: Communication partners.
- Purpose of the processing: Direct marketing (e.g. by e-mail or post).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a. GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).
- Right of appeal (opt-out): You can cancel the receipt of our newsletter at any time, i.e. revoke your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can use one of the above mentioned contact options, preferably e-mail.
Used services and service providers:
- Roundcube WebMail Bluehost - Endurance International Group, 10 Corporate Drive, Suite #300, Burlington, MA 01803; Website: https://www.bluehost.com; Privacy policy: https://endurance.clarip.com/privacycenter/?brand=bluehost.
- Sendinblue SMTP - Sendinblue, 55 Rue d'Amsterdam, 75008 Paris, France; Website: https://www.sendinblue.com; Privacy Policy: https://www.sendinblue.com/legal/privacypolicy/
Web Analysis, Monitoring And Optimization
Web analysis (also known as “reach measurement”) is used to evaluate the streams of visitors to our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of the range analysis we can, for example, identify at what time our online offer or its functions or contents are most frequently used or invite reuse. We can also understand which areas require optimization.
In addition to web analysis, we can also use test procedures, e.g. to test and optimise different versions of our online offer or its components.
For these purposes, so-called user profiles can be created and stored in a file (so-called “cookie”) or similar procedures with the same purpose can be used. This information may include, for example, content viewed, web pages visited and elements used on those pages, and technical details such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data, this data may also be processed, depending on the provider.
The IP addresses of users are also stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect the users. In general, the data stored in the context of web analysis, A/B testing and optimization are not clear user data (such as e-mail addresses or names), but pseudonyms. This means that we as well as the providers of the software used do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases: If we ask the users for their consent to the use of the third party providers, the legal basis for the processing of data is the consent. Otherwise, the users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Processed data types: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses).
- Persons concerned: Users (e.g. website visitors, users of online services).
- Purpose of the processing: Range measurement (e.g. access statistics, recognition of returning visitors), tracking (e.g. interest/behaviour-related profiling, use of cookies), visitor action evaluation, profiling (creation of user profiles).
- Security measures: IP-Masking (pseudonymization of the IP address).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a. GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).
Used services and service providers:
- etracker: Web analysis/range measurement; service provider: etracker GmbH, Erste Brunnenstraße 1 20459 Hamburg, Germany; website: https://www.etracker.com; Privacy policy: https://www.etracker.com/datenschutz/; Opt-out: https://www.etracker.de/privacy?et= [PLEASE SET YOUR ACCOUNT ID].
- Matomo (without cookies): Matomo is a data protection friendly web analysis software, which is used without cookies and in which the recognition of returning users is done with the help of a so-called “digital fingerprint”, which is stored anonymously and changed every 24 hours; with the “digital fingerprint”, user movements within our online offer are recorded with the help of pseudonymised IP addresses in combination with user-side browser settings in such a way that conclusions about the identity of individual users are not possible; service provider: Web analysis/range measurement in self-hosting; website: https://matomo.org/.
- WP Rocket - WP MEDIA, 47 Rue Duquesne, 69006 Lyon, France; Website: https://wp-rocket.me/; Privacy policy: https://wp-rocket.me/privacy-policy/.
- Cloudflare - Cloudflare, Inc., 101 Townsend St., San Francisco, California 94107; Website: https://www.cloudflare.com/; Privacy policy: https://www.cloudflare.com/privacypolicy/.
Online Marketing
We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as “Content”) based on the potential interests of users and the measurement of its effectiveness.
For these purposes, so-called user profiles are created and stored in a file (so-called “cookie”) or similar procedures are used, by means of which the user data relevant to the presentation of the aforementioned contents are stored. This information may include, for example, the content viewed, web pages visited, online networks used, but also communication partners and technical details such as the browser used, the computer system used and information on usage times. If users have consented to the collection of their location data, this data may also be processed.
The IP addresses of users are also stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect the users. In general, no clear user data (such as e-mail addresses or names) are stored in the context of the online marketing process, but pseudonyms. This means that we as well as the providers of the online marketing procedures do not know the actual identity of the users, but only the information stored in their profiles.
As a rule, the information in the profiles is stored in the cookies or by means of similar procedures. These cookies can later be read out and analysed for the purpose of presenting content on other websites that use the same online marketing procedure, and can also be supplemented with additional data and stored on the server of the online marketing procedure provider.
As an exception, clear data can be assigned to the profiles. This is the case, for example, if the users are members of a social network whose online marketing procedure we use and the network links the user profiles with the aforementioned data. Please note that users can make additional agreements with the providers, e.g. by giving their consent during registration.
As a matter of principle, we only obtain access to summarised information on the success of our advertisements. However, in the context of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e., for example, to the conclusion of a contract with us. The conversion measurement is used solely to analyse the success of our marketing measures.
Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.
Notes on legal bases: If we ask the users for their consent to the use of the third party providers, the legal basis for the processing of data is the consent. Otherwise, the users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Facebook Pixels: On the one hand, the Facebook pixel enables Facebook to determine the visitors of our online offer as a target group for the presentation of ads (so-called “Facebook ads”). Accordingly, we use the Facebook Pixel to display the Facebook Ads placed by us only to those users on Facebook and within the services of partners cooperating with Facebook (so-called “Audience Network” https://www.facebook.com/audiencenetwork/ ) who have also shown an interest in our online offering or who exhibit certain characteristics (e.g. interest in certain topics or products that can be seen from the websites visited) that we transmit to Facebook (so-called “Custom Audiences”). With the help of the Facebook pixel, we also want to ensure that our Facebook Ads correspond to the potential interest of the users and do not appear annoying. The Facebook Pixel also enables us to track the effectiveness of Facebook ads for statistical and market research purposes by seeing whether users have been redirected to our website after clicking on a Facebook ad (so-called “conversion measurement”).
- Data types processed: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), location data (information on the geographical position of a device or person)
- Persons concerned: Users (e.g. website visitors, users of online services), interested parties.
- Purpose of the processing: Tracking (e.g. interest/behavioural profiling, use of cookies), remarketing, visitor action evaluation, interest-based and behaviour-based marketing, profiling (creation of user profiles), conversion measurement (measurement of the effectiveness of marketing measures), reach measurement (e.g. access statistics, recognition of returning visitors), target group formation (determination of target groups relevant for marketing purposes or other output of content), cross-device tracking (cross-device processing of user data for marketing purposes)
- Security measures: IP-Masking (pseudonymization of the IP address).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 letter a. GDPR), legitimate interests (Art. 6 para. 1 sentence 1 letter f. GDPR).
-
Possibility of opposition (opt-out): We refer to the data protection notices
of the respective providers and the possibilities of objection
(so-called “opt-out”) indicated for the providers. If no explicit
opt-out option has been specified, it is possible to switch off cookies
in the settings of your browser. However, this may restrict the
functions of our online offer. We therefore recommend the following
additional opt-out options, which are offered in summary
form for the respective areas:
a) Europe: https://www.youronlinechoices.eu.
b) Canada: https://www.youradchoices.ca/choices.
c) USA: https://www.aboutads.info/choices.
d) Canada: https://optout.aboutads.info.
Used services and service providers:
- Google Tag Manager: Google Tag Manager is a solution with which we can manage so-called website tags via an interface and thus integrate other services into our online offering. The Tag Manager itself (which implements the tags) does not process any personal data of the users. With regard to the processing of users' personal data, please refer to the following information on Google's services. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.
- Google Analytics: Online marketing and web analytics; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://marketingplatform.google.com/intl/de/about/analytics/; Privacy policy: https://policies.google.com/privacy; Opt-out: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertising: https://adssettings.google.com/authenticated.
- Google Ads and conversion measurement: We use the online marketing process “Google Ads” to place ads on the Google advertising network (e.g., in search results, in videos, on web pages, etc.) to be displayed to users who have a presumed interest in the ads. We also measure the conversion of the ads. However, we only learn the anonymous total number of users who clicked on our ad and were redirected to a page with a so-called “conversion tracking tag”. We do not receive any information that can be used to identify users. Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.
- Google Ad Manager: We use the “Google Marketing Platform” (and services such as “Google Ad Manager”) to place ads on the Google advertising network (e.g., in search results, in videos, on web pages, etc.). The Google Marketing Platform is characterised by the fact that ads are displayed in real time based on the presumed interests of users. This allows us to better target ads for and within our online offering to show users only ads that potentially match their interests. For example, if a user is shown ads for products that he or she has been interested in on other websites, this is called “remarketing”. Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.
- Facebook-Pixel: Service provider: https://www.facebook.com, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Right of appeal (Opt-Out): https://www.facebook.com/settings?tab=ads.
Presence In Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
Please note that user data may be processed outside the European Union. This can result in risks for the users, because the enforcement of the users' rights could be made more difficult.
Furthermore, user data within social networks are usually processed for market research and advertising purposes. Thus, for example, user profiles can be created on the basis of user behaviour and the resulting interests of the users. The user profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users' computers, in which the usage behaviour and interests of the users are stored. Furthermore, data may also be stored in the user profiles independently of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective forms of processing and the possibilities of objection (opt-out), we refer to the data protection declarations and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the providers have access to the data of the users in each case and can directly take appropriate measures and provide information. Should you nevertheless require assistance, you can contact us.
- Data types processed: Inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers), content data (e.g. entries in online forms), usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses)
- Persons concerned: Users (e.g. website visitors, users of online services).
- Purpose of the processing: Contact requests and communication, tracking (e.g. interest/behavioural profiling, use of cookies), remarketing, reach measurement (e.g. access statistics, recognition of returning visitors).
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 letter f. GDPR).
Used services and service providers:
- Instagram : Social network; service provider: Instagram Inc, 1601 Willow Road, Menlo Park, CA, 94025, USA; website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy.
- Facebook: Soziales Netzwerk; Dienstanbieter: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Irland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Right of appeal (Opt-Out): Settings for advertisements: https://www.facebook.com/settings?tab=ads; Additional privacy notices: Agreement on joint processing of personal data on Facebook pages: https://www.facebook.com/legal/terms/page_controller_addendum, Privacy notices for Facebook pages: https://www.facebook.com/legal/terms/information_about_page_insights_data.
- LinkedIn: Social network; service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- Twitter: Social network; service provider: Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; Privacy Policy: https://twitter.com/de/privacy, (Settings) https://twitter.com/personalization.
- YouTube: Social network; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy Policy: https://policies.google.com/privacy; Opt-out: https://adssettings.google.com/authenticated.
Plugins And Embedded Functions And Content
We include in our online offer functional and content elements that are obtained from the servers of their respective providers (hereinafter referred to as “third party providers”). These can be, for example, graphics, videos or social media buttons and contributions (hereinafter referred to uniformly as “content”).
The integration always presupposes that the third party providers of these contents process the IP address of the users, as without the IP address they would not be able to send the contents to their browsers. The IP address is therefore required for the display of these contents or functions. We make every effort to use only such content whose respective providers use the IP address only to deliver the content. Third party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain technical information about the browser and operating system, the websites to be linked, the time of visit and other details about the use of our online offer, as well as being linked to such information from other sources.
Notes on legal bases: If we ask the users for their consent to the use of the third party providers, the legal basis for the processing of data is the consent. Otherwise, the users' data will be processed on the basis of our legitimate interests (i.e. interest in efficient, economic and recipient-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Data types processed: Usage data (e.g. websites visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), location data (information on the geographical position of a device or person), content data (e.g. entries in online forms), inventory data (e.g. names, addresses), contact data (e.g. e-mail, telephone numbers).
- Persons concerned: Users (e.g. website visitors, users of online services), communication partners.
- Purpose of the processing: Provision of our online services and user-friendliness, provision of contractual services and customer service, contact requests and communication, tracking (e.g. interest/behavioural profiling, use of cookies), interest-based and behavioural marketing, profiling (creation of user profiles), security measures, administration and response to requests.
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR), consent (Art. 6 para. 1 sentence 1 lit. a. GDPR), performance of the contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b. GDPR).
Used services and service providers:
- Facebook plugins and content: Facebook social plugins and content - This can include content such as images, videos or text and buttons that allow users to share content from this online offering within Facebook. The list and appearance of Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/; service provider: https://www.facebook.com, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Opt-out: advertising settings: https://www.facebook.com/settings?tab=ads.
- Google Fonts: We integrate the fonts (“Google Fonts”) of the provider Google, whereby the data of the users are used solely for the purpose of displaying the fonts in the browser of the users. The integration is based on our legitimate interests in a technically secure, maintenance-free and efficient use of fonts, their uniform presentation and taking into account possible licensing restrictions for their integration. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy.
- Google Maps: We integrate the maps of the service “Google Maps” of the provider Google. The processed data may include, in particular, IP addresses and location data of the users, which, however, are not collected without their consent (usually in the context of the settings of their mobile devices); service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://cloud.google.com/maps-platform; Privacy policy: https://policies.google.com/privacy; Opt-out: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertising: https://adssettings.google.com/authenticated.
- ReCaptcha: We include the function “ReCaptcha” for the detection of bots, e.g. when entering data into online forms. The behavioral data of the users (e.g. mouse movements or queries) are evaluated to be able to distinguish people from bots. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://www.google.com/recaptcha/; Privacy policy: https://policies.google.com/privacy; Opt-out: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertising: https://adssettings.google.com/authenticated.
- Twitter plugins and content: Twitter plug-ins and buttons - These can include content such as images, videos or text and buttons that allow users to share content from this online offering within Twitter. Service provider: Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA; website: https://twitter.com/de; privacy policy: https://twitter.com/de/privacy.
- YouTube videos: Video content; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Opt-out: Opt-out plug-in: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of advertising: https://adssettings.google.com/authenticated.
- DHL: Logistics services and solutions (e.g. DHL eCommerce, DHL Paket, DHL Paket International, DHL Retoure); service providers: DHL, Deutsche Post AG, Headquarters, Platz der Deutschen Post, 53113 Bonn; Website: https://www.dhl.com/global-en/home.html; Privacy policy: https://www.dhl.com/global-en/home/footer/global-privacy-notice.html.
Children's Data
The Services are not intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
Security and Retention of Your Information
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.
Your Rights and Choices
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
- Right to Access / Know. You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
- Right to Delete. You may have a right to request that we delete personal information we maintain about you.
- Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.
- Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
- Right to Opt out of Sale or Sharing or Targeted Advertising. You may have a right to direct us not to "sell" or "share" your personal information or to opt out of the processing of your personal information for purposes considered to be "targeted advertising", as defined in applicable privacy laws. Please note that if you visit our Site with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will automatically treat this as a request to opt-out of the "sale" or "sharing" of information for the device and browser that you use to visit the Site.
- Right to Limit and/or Opt out of Use and Disclosure of Sensitive Personal Information. You may have a right to direct us to limit our use and/or disclosure of sensitive personal information to only what is necessary to perform the Services or provide the goods reasonably expected by an average individual.
- Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
- Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent. Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
- Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.
You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.
We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, You may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.
We use ad services to help personalize the advertising you see on third party websites. To restrict these ad services from using your personal information for such services, please contact us.
Rights Of Data Subjects (EEA)
As data subjects, you are entitled to various rights under the GDPR, which result in particular from Art. 15 to 21 GDPR:
- Right of objection: You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data relating to you which is carried out pursuant to Art. 6 (1) (e) or (f) DPA; this also applies to profiling based on these provisions. If the personal data concerning you are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing, including profiling, insofar as it is linked to such direct marketing.
- Right of withdrawal for consents: You have the right to revoke your consent at any time.
- Right of access to information: You have the right to obtain confirmation as to whether or not data in question is being processed and to obtain information on such data, as well as further information and a copy of the data in accordance with legal requirements.
- Right of rectification: In accordance with the law, you have the right to request the completion of the data concerning you or the correction of incorrect data concerning you.
- Right of cancellation and limitation of processing: In accordance with the statutory provisions, you have the right to demand that data concerning you be deleted immediately, or alternatively, in accordance with the statutory provisions, to demand that the processing of the data be restricted.
- Right to data transferability: You have the right, in accordance with legal requirements, to receive data concerning you that you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another responsible party.
- Complaint to the supervisory authority: You also have the right, in accordance with the statutory provisions, to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of suspected infringement, if you believe that the processing of personal data concerning you is in breach of the GDPR.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. If you are not satisfied with our response to your complaint, depending on where you live you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority.
International Users
Please note that we may transfer, store and process your personal information outside the country you live in, including the United States. Your personal information is also processed by staff and third party service providers and partners in these countries.
If we transfer your personal information out of Europe, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at hey@heylisi.com or contact us at Dokudu UG, Linprunstraße 37, 80335 München, Germany.
Responsible Person &
Data Protection Officer
Dokudu UG
Linprunstr. 37,
80335 Munich
Authorized representative: Emre Can Develi (Managing Director)
E-Mail address: hey@heylisi.com