We, IVY & OAK GmbH, Monbijouplatz 4, 10178 Berlin, Germany (Imprint), are the operator of the website www.ivy-oak.com. We are therefore responsible for the collection, processing and use of your personal data in terms of Data Privacy provisions, when visiting our website.

Our data protection officer can be reached under the above mentioned email-address as well as under datenschutz@ivy-oak.com.

Personal Data is information on your personal or factual circumstances. This includes your name, your e-mail-address and your address as well as all other information relating to your person or identity.

We use your personal data in compliance with the applicable data privacy provisions. Below we will describe what data we collect, how we use it and what rights you have in terms of our use of your data:

I. Scope and purpose of the collection, processing and use of personal data

1.  When visiting our website

When you visit our website, our servers temporarily save every access in a log file. The following data are automatically recorded without any action on your part and stored until automatic deletion:

  • the IP address of the accessing computer,
  • the date and time of access,
  • the name and URL of the accessed file,
  • the website from which you accessed our website (referrer),
  • your computer’s operating system and the browser used by you,
  • the name of your Internet access provider.

These data are collected and processed for the purposes of facilitating use of our website (creating the connection), guaranteeing long-term system security and stability and optimizing our web service, as well as for internal statistical purposes. This will not allow us to identify you as an individual person.

Legal basis is Art. 6 Abs. 1 Satz 1 lit. f) DSGVO. Your data is being deleted as soon as there is no need for fulfilling their initial purpose. When gathering data for providing the page, this will be the case, then closing the browser session.

In addition, we also set cookies and use web analytics during visits to our website. You can find more detailed information on this in Sections III, IV and V.

2.  When signing up for our newsletter
Subsequent we want to explain our newsletter contents, the signup, delivery and statistical analysis processes as well as your rights of withdrawal. With subscribing to our newsletter you agree to these terms.

Newsletters Content

We only send out Newsletter, E-Mails and further electronical messages with commercial purpose (hereby “newsletter”) only with your explicit opt-in or based on a legal allowance. As long as the contents are described appropriaptely during subscribtion-process, those are basis for your agreement.
Furthermore, our newsletter containt information about frequent offers and campaigns.

Double-Opt-In and logging

Subscribing to our newsletter works with the double-opt-in process. This means, after entering your email-address you will receive an email with a confirmation link. This is necessary to prevent spam.
The subscribtion is being logged in order to adhere to legal requirements. This includes logging the subscribtion and confirmation time as well as the IP-address. Furthermore your data changed within mailchimp will be logged.

Using „MailChimp“ as service provider

Our newsletter is distriputed via “MailChimp”, a mailing-platform from the US-based provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA.

Both the email-addresses of our subscribers as well as the gathered data (as explained here) will be persisted on MailChimp-servers in the USA. Mailchimp uses those data for sending out and analysing the newsletter on behalf of IVY & OAK.
Furthermore MailChimp can use this data in oder to improve their own service, e.g. optimizing the technical distribution, displaying the email appropriatly or for commercial reasons do dinstiguish the country the receiver are localized. MailChimp is not providing the data to any third party.

We trust in the reliability of MailChimp’s IT and data security. MailChimp is certified under the US-EU-data protection agreement „Privacy Shield
and hereby commits to comply with European data protection law. Furthermore we have signed a „Data-Processing-Agreement“. In this agreement Mailchimp commits to protect our customers’ data, process our data based on our data-protection law and particularly does not pass on the data to any third party.

You can view MailChimp’s data privacy statement here.

Sign-up data

To subscribe to our newsletter it is sufficient to provide your email-address.

Statistical Analysis

The newsletter contains socalled “web-beacons”. That is a pixel-sized file, which is called by the MailChimp server when opening the newsletter. With this call, technical information as to the used browser, your system, IP-address and point of time are stored. This data is used to improve the technical services and distribution quality.

Furthermore the information is stored, if and when the newsletter was opened by the user and which links have been clicked.
This information can indeed be related to a specific user, but we explicitly insist on not tracking a single user both IVY & OAK nor MailChimp. These information only help us to identify general user behaviour due to the usage of our newsletter and to improve the contents towards the optimal user experience.

Online-Call and data management

There are scenarios, where we redirect the customer to webpages of MailChimp. E.g. our newsletter contains a link which allows the user to view the newsletter online whereas this page is hosted on MailChimp servers. Furthermore, users are able to correct their data, e.g. email-address, later. Also MailChimp’s data privacy statment is only available on their sites.

We want to point out, that MailChimp uses Cookies on their sites which allows the data collectio of personal data through MailChimp, their partners and used service providers (e.h. Google Analytics).
We do not have any impact on that process. You can get more information on MailChimp’s data privacy statement.
Additionaly we want to inform you about your right for withdrawal within the EWR (see http://www.aboutads.info/choices/ and http://www.youronlinechoices.com/).

Withdrawal

You can withdraw you subscribtion at any time. This includes the withdrawal of receiving IVY & OAK newsletters from MailChimp and being part of statistical analysis.
There is no separate withdrawal of statistical analysis and newsletter distribution.

Every newsletter email contains an unsubscribtion link.

Legal basis data protection law

Based on the requirements of the general data protection regulation (GDPR) as of 25th of May 2018 we inform you, that your subscribtion of our newsletter is based Art. 6 Abs. 1 lit. a, Art. 7 DSGVO as well as § 7 Abs. 2 Nr. 3, bzw. Abs. 3 UWG.
Using MailChimp, applying statistical analysis as welll logging the subscribtion process are based on our legitimate interest as per 6 Abs. 1 lit. f DSGVO. Our interest goes towars using a both user-friendly as well as secure service provider, that adheres both to our commercial needs as well as our customer’s expectations.

We inform you, that you can withdraw future data processing of your personal data as per Art. 21 DSGVO at any time. Particularly, your withdrawal can be applied to direct mail.

3.  When using the contact form

You can use the contact form on our website for general requests. Your name, a valid e-mail-address and the reason for the request are required.  Additional data is non-mandatory.

We collect this data to know the author of the request and to reply individually and through whichever method you have specified (via mail, phone or e-mail).

4. Customer Account

When registering as customer we persist data only in the most necessary extent. Data processing happens for the purpose of improving your shopping experience as well es to optimize our fulfillment processes.
The data processing happens as per Art. 6 Absatz 1 lit. a DSGVO with your explicit consent. You can withdraw your consent at anytime without touching the legitimacy of the data processing based on your consent until your withdrawal. Your account will be deleted subsequently.

You can also create an account with your social profiles of Facebook and Instagram. If you register via Facebook or Instagram, we automatically create an account with the same email-address you are using for your appropriate social-account. If you agree to transfering the mentioned data, Facebook or Instagram will identify and redirect you to our page. With this, Facebook or Instagram will set a Cookie, which allows them to recognize you. Registering via Facebook or Instagram, data is transferred, which allows us to create an user account. You can withdraw this transfer
at any time within your Facebook or Instagram account. You have the possibility to remove the connection between your social-account and your account at IVY & OAK at any time. If you want to do so, please login into your social-account of Facebook or Instagram, go to settings, find and edit the connected apps.

By using the Instagram-Social-Login button, you agree to share the following data:

  • Public media and profileinformation

By using the Facebook-Social-Login button, you agree to share the following data:

  • Public profileinformation (username, age, profile picture and potentially further information)
  • Email-Address

II. Disclosure of Data to Third Parties for Contractual Purposes

We will share your personal data with third parties only if you have expressly agreed to this, if we are under a legal obligation to do so, or if this is required in order to assert our rights, in particular to enforce claims arising from the contractual relationship.

Beyond this, we will pass your data on to third parties to the extent that this is necessary for processing the contract. We collaborate with external companies for the purpose of processing our various payment transactions: This is Paypal Deutschland GmbH, Am Marktplatz 1, 14532 Europaparc Dreilinden, when paying via Paypal  and Klarna AB, Sveavägen 46, 111 34 Stockholm, Schweden when paying via Klarna. Klarna reviews and evaluates the data you provided and in case of legitimate interest performs a data exchange with other companies and credit rating agencies. Your personal data will be processed in accordance with applicable data protection law as described in Klarnas privacy statement.

Further third party providers, that are necessary for carrying out the contracts are: shipping provider, logistics fulfillment provider, service provider for processing our orders as well as webhoster. In any case we strictly adhere to legal requirements.
Persisted data limits to the necessary minimum.

Personal data will not be disclosed to third parties for any other purpose.

III. Cookies

We use website cookies in several areas of our website. Cookies are small files that your web browser automatically generates and are stored on the hard drive of your device (laptop, tablet, smartphone etc.) when you visit our website. Cookies do not harm your device and do not contain any viruses, Trojans or other malicious software.

Cookies store information, generated when you visit our website with your specific device.  This, however, does not mean that we receive immediate information about personal data.

We use cookies to provide you with a more user-friendly website design. We use session-cookies to recognize that you have visited specific sites of our website before. Entries and settings (e.g. language) of your visit may be stored. These session-cookies are deleted automatically when leaving our website.

Furthermore, we use cookies to evaluate the use of our website statistically and to optimize our offer to you (Sec. IV) and to provide you with interest-based information (Sec. V). These cookies, for example, identify you as registered user without logging in. These cookies are deleted automatically after a certain time (as illuded in the table below).

The use of the cookies does not allow us to obtain new personal data about you as an online visitor. The majority of Internet browsers accept cookies automatically. However, you can configure your browser to reject cookies or to notify you whenever you receive a new cookie.

Deactivation of cookies can lead to you not being able to use all of the functions of our website.

The following cookies are being set:

Cookie Description Lifetime
Newsletter_pagecount Counts the visited pages to identify when to show the newsletter popup 7 days
Newsletter_status In case the user has already seen the newsletter popup, she should not see it again. This information is handled by this cookie. 7 days
Visited_top_banner If the top-banner regarding delivery options has already been seen and clicked, it should reappear. 30 days
Visited_cookie If the top-banner regarding cookies has already been seen and clicked, it should not reappear. 30 days
PHPSESSID Unique ID for the server to identify the current user session duration of current user session
woocommercecart_hash Shopsystem checks if something changed in the cart. Lifetime of the cart (Closure through purchase, reset through removing items from the cart)
woocommerce_items_in_cart
wp_woocommerce_session+md5-hash Uniquely identifieds the customers cart Lifetime of the cart (Closure through purchase, reset through removing items from the cart)
wpml_referer_url Saves the latest visitied page of the customer for language reasons 1 day
icl_current_language Saves the currently selected language of the customer 1 day

Besides cookies we use local storage objects for the following functionality:

  • ds_recently_viewed_6: The user gets an overview of recently viewed products. This information is stored as long as the local cache of the browser is active.

IV. Web analytics

1. Google Analytics

For the purpose of demand-responsive design and ongoing optimization of our sites we use Google Analytics, a web analytics service of the Google Inc., 1600 Amphitheatrae Parkway, Mountain View, CA 94043 USA. The information generated by the Cookie about your use of this website (including your IP address) is transferred to a server by Google in the USA and is stored there. IP addresses are anonymized to exclude all possibility of such association (IP masking). The information is used to evaluate use of the website, to compile reports on website activity and to provide further services associated with website and Internet use for the purposes of market research and needs-based design of these web pages. Your data will not in any case be associated with other data from Google.

This information may be forwarded to third parties only, insofar as this is prescribed by law or insofar as these parties process the data on behalf of the commissioning party.

You can prevent the installation of cookies by adjusting your browser accordingly; in this case, however, not all functions of the website may be available to the user to their full extent.

You can also prevent the data generated by the cookie and relating to your use of the website (including your IP address) and the processing of these data by Google, by downloading and installing a browser-add-on.

As an alternative to a browser add-on, especially for browsers on mobile devices, you can also avoid the information collection by Google Analytics by clicking on this link. An opt-out cookie is then put in place, which will prevent future collection of your information whenever you visit this website. The opt-out cookie applies only to this browser and our website, and this cookie will be stored on your device. Should you delete the cookies in this browser, you will need to set the opt-out cookie again.

Further information about Google Universal Analytics can be found in the Google Analytics help pages.

We trust in the reliability of Google’s IT and data security. Google is certified under the US-EU-data protection agreement „Privacy Shield
and hereby commits to comply with European data protection law.

2. FullStory

This website uses Fullstory, a web site analysis service of Fullstory Inc., 818 Marietta Street, Atlanta, GA 30318, USA. Fullstory records user behavior on our website. Visitor recordings allow IVY & OAK to analyze them and then improve the visitors’ website experience. Fullstory stores and collects data in anonymous form using cookies. The tracking (that is, the collection of the data generated by the cookie and related to the use of the website) can be deactivated at any time. Please follow the instructions on https://www.fullstory.com/optout.
We trust in the reliability of FullStory’s IT and data security. FullStory is certified under the US-EU-data protection agreement „Privacy Shield
and hereby commits to comply with European data protection law.

Further information on the data privacy statement of FullStory can be found here.

3. Criteo data privacy

We use the technology of Criteo (Criteo GmbH, Unterer Anger 3, 80331 München) in order to track information regarding the browsing-behaviour of our customers for marketing reasons. This
happens in a purely anonymous way and cookies are set for this.

Criteo is able to analyse the browsing-behaviour and can then recommend appropriate products on ad-banners, when visiting other websites. Not in any case anonymous data can be used to
identify one single person. The data persisted by Criteo is only used to improve our marketing-offer. On any ad you can find a small “i” (for information). Clicking that link will lead you to
a page which explains the systematic and allows you to opt-out. For this, an opt-out cookie is set which prevents the ads to be displayed for you. No data is transferred to any third parties.
Further information on Criteo’s data privacy statement can be found here and < href=”https://www.criteo.com/de/privacy/”>here for opt-out options.

V. Social Plugins

1. Instagram

On our website, so-called social plugins (“plugins”) by the social network Instagram are used, which is operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”). The plugins are marked with an “Instagram button” on our website. When you click on the “Instagram-button” while you are logged into your Instagram-profile, you can link the content of our sites to your Instagram profile. This enables Instagram to connect your visit to our sites to your user account. Instagram does not inform us about which information is transmitted and how it is used. For more information, please see the privacy statement of Instagram.

2. Facebook

Our website uses social plugins provided by the social network facebook.com, operated by Facebook Inc. The plugins are identifiable by a Facebook logo or the notice “Facebook Social Plugin”. For a full list of all social plugins and their appearance please see the website of Facebook.

When you visit a page of our website that contains a social plugin, your browser establishes a direct connection to Facebook servers. Facebook directly transfers the plugin content to your browser which embeds the latter into the website, enabling Facebook to receive information about your having accessed the respective page of our website. For this purpose, the internet address of the visited site (your IP address included) is transferred to a USA-based Facebook server where the data are stored. This occurs even if you do not have a Facebook account or are not logged into Facebook at the time.

If you are logged into Facebook, your visit can be assigned to your Facebook account. If you interact with the plugins, for example by clicking “Like”, or entering a comment, the corresponding information is transmitted from your browser directly to Facebook and stored by it. The information can also be published on Facebook and shown to your Facebook friends.

For information on the purpose and scope of data collection by Facebook and how it is processed and used, as well as your rights in this respect and settings options for protecting your privacy please visit Facebook’s privacy policy.

If you are a Facebook member and do not want Facebook to connect the data concerning your visit to our website with your member data already stored by Facebook, please log off Facebook before entering our website. You can also block Facebook social Plugins by using add-ons for your browser, like the “Facebook Blocker” or you use our opt-out feature for the duration of your session. Click on the following link: https://www.ivy-oak.com/optout-for-facebook/

We trust in the reliability of Facebook’s IT and data security. Facebook is certified under the US-EU-data protection agreement „Privacy Shield
and hereby commits to comply with European data protection law.

3. Youtube

We embed videos on our website which are available via the video platform YouTube (embedded content). YouTube is a service of Google Inc. YouTube uses cookies to evaluate the videos you load and to compile reports on video usage for the holder of the YouTube accounts, to improve the usability of the service and to prevent illegal use.

The cookie provides us with statistical evaluations of YouTube about of the demand for videos embedded on our websites.

All of these videos are included in the “expanded data protection mode”, which means that no data will be stored unless you watch the videos. According to Google, no data is stored which would enable your personal identification.

However, a connection of data to your person is possible if you are logged into your account at YouTube or other Google services. If you do not want this, please log off your Google account before playing an embedded video on our website.

You can prevent the installation of cookies by adjusting your browser accordingly; in this case, however, not all functions of the website may be available to the user to their full extent.

Please find more information on data protection on YouTube in the Privacy Policy of Google.

4. Pinterest

Our website uses plugins provided by the social network Pinterest, operated by Pinterest, Inc., 808 Brannan St, San Francisco, CA 94103, USA (“Pinterest”).

When you visit a page of our website that contains a social plugin, your browser establishes a direct connection to Pinterest servers. Pinterest directly transfers the plugin content to your browser which embeds the latter into the website.

By embedding the plugins Pinterest receives information that your browser has loaded this specific site of our web presence even if you do not have a Pinterest account or are currently not logged into your Pinterest account. This information (including your IP-address) will be transferred directly to Pinterest’s servers in the USA and stored there.

If you are logged into your Pinterest account and click on the “pin it” button, Pinterest receives information that you loaded the respective site of our web presence and may connect data concerning your visit to our website to your Pinterest account. If you do not want that, please log off Pinterest before clicking the “Pin it” Button.

For the information on the purpose and scope of data collection and procession by Pinterest, as well as your rights in this respect and settings options for protecting your privacy please visit Pinterest’s privacy policy: http://pinterest.com/about/privacy.

VI. Right to Information, Correction, Blocking and Deletion

You have the right to information regarding the personal data stored under your name as well as a right to correct incorrect data, or to block and delete such data.
You have the following rights regarding your data:

  • Right to be informed (Art. 15 DSGVO)
  • Right to correct or delete your data (Art. 16 und Art.17 DSGVO)
  • Right to restrict the usage of your data (Art. 18 DSGVO)
  • Right for data portability (Art. 20 DSGVO)
  • Right for withdrawing the processing of your data(Art. 21 DSGVO)

Based on Art. 7 Abs. 3 DSGVO you have the right to withdraw you initially provided consent at any time. This means, that we are not eligible to process your data from now on.
You furthermore have the right to complain about your data being processed by us at the data privacy authority (Art. 77 DSGVO).

To get information on your personal data, to have incorrect data corrected, to have data blocked or deleted or for further questions on the use of your personal data please send an e-mail to info@ivy-oak.com.

VII. Data security

Your connection to our website is TLS-secured.

We use appropriate technical and organisational security measures to protect your stored personal data against manipulation, partial or complete loss and
against unauthorised access by third parties. Our security measures are continuously enhanced as new technology becomes available.

VIII. Validity of the privacy policy, Amendments

This privacy policy is currently valid and dated May 2018.

Through further development of the website or due to changes in legal or regulatory requirements, it might be necessary to make amendments to this privacy policy. The current privacy policy can always be retrieved and printed by you from the website www.ivy-oak.com.