Privacy policy
The data controller for processing is:
PiliPili GbR
Rathausstraße 85
52222 Stolberg
Germany
Emaill: kkpilipili@gmail.com
​
We appreciate your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data.
​
1. Access Data and Hosting
​
You can visit our website without providing any personal information. When you visit a webpage, the web server automatically stores a so-called server log file, which contains information such as the name of the requested file, your IP address, the date and time of the request, the amount of data transferred, and the requesting provider (access data). These access data are evaluated exclusively to ensure the trouble-free operation of the site and improve our offerings. This serves to protect our legitimate interests in a proper representation of our offer, according to Art. 6(1) sentence 1 lit. f GDPR. Access data is only processed for as long as it is necessary to achieve the processing purposes mentioned above.
​
The services for hosting and displaying the website are partially provided by our service providers within the scope of processing on our behalf. Unless otherwise explained in this privacy policy, all access data, as well as data collected in the forms on this website, are processed on their servers. For questions regarding our service providers and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined an adequate level of data protection: Israel, the United Kingdom, and the USA.
The adequacy decision for the USA serves as the basis for the transfer of data to third countries, provided that the respective service provider is certified. Certification is in place.
​
Our service providers are based in and/or use servers in these countries: Brazil, Mexico, India, and Ukraine.
​
For these countries, no adequacy decision by the European Commission is available. Our cooperation with you is based on these guarantees: Standard contractual clauses of the European Union.
​
2. Data Processing for Contract Fulfillment and Contact
​
2.1 Data Processing for Contract Fulfillment
For the purpose of contract fulfillment (including inquiries and processing of warranty and performance claims, as well as any statutory update obligations) according to Art. 6(1) sentence 1 lit. b GDPR, we collect personal data when you voluntarily provide it during your order. Mandatory fields are marked as such, as we need these data to process the contract, and without them, we cannot ship the order. The data collected is visible in the respective input forms.
​
Further information about the processing of your data, especially regarding the sharing with our service providers for order, payment, and shipping processing, can be found in the following sections of this privacy policy. After the contract is fully processed, your data will be restricted for further processing and deleted after the expiration of the tax and commercial retention periods according to Art. 6(1) sentence 1 lit. c GDPR unless you have explicitly consented to further use of your data according to Art. 6(1) sentence 1 lit. a GDPR, or we reserve the right to further data use that is legally permitted and which we inform you about in this policy.
​
2.2 Customer Account
If you have given your consent according to Art. 6(1) sentence 1 lit. a GDPR by choosing to open a customer account, we will use your data to open the customer account and store your data for future orders on our website. Deleting your customer account is always possible and can be done either by sending a message to the contact details provided in this privacy policy or through a function in the customer account. After deleting your customer account, your data will be deleted unless you have explicitly consented to further use of your data according to Art. 6(1) sentence 1 lit. a GDPR, or we reserve the right to further data use that is legally permitted and which we inform you about in this policy.
​
2.3 Contacting Us
In the context of customer communication, we collect personal data to process your inquiries according to Art. 6(1) sentence 1 lit. b GDPR when you voluntarily provide it during contact (e.g., via contact form, live chat tool, or email). Mandatory fields are marked as such, as we need these data to process your inquiry. The data collected is visible in the respective input forms. After processing your inquiry, your data will be deleted unless you have explicitly consented to further use of your data according to Art. 6(1) sentence 1 lit. a GDPR, or we reserve the right to further data use that is legally permitted and which we inform you about in this policy.
​
Live-Chat-Tool Ascend by Wix
​
For customer communication, we use the live chat tool Ascend by Wix from Wix.com Ltd., 40 Nemal St., Tel Aviv 6350671, Israel ("Wix"). This serves the legitimate interest of effective and improved customer communication according to Art. 6(1) sentence 1 lit. f GDPR. Wix acts on our behalf.
​
Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined an adequate level of data protection: Israel, the United Kingdom, and the USA. The adequacy decision for the USA serves as the basis for the transfer of data to third countries, provided the service provider is certified. Certification is in place.
​
Our service providers are based in and/or use servers in these countries: Brazil, Mexico, India, and Ukraine. For these countries, no adequacy decision by the European Commission is available. Our cooperation with you is based on these guarantees: Standard contractual clauses of the European Union.
​
3. Data Processing for Shipping Fulfillment
​
For contract fulfillment, according to Art. 6(1) sentence 1 lit. b GDPR, we pass your data to the shipping service provider responsible for the delivery, as far as it is necessary for the delivery of the ordered goods. For questions regarding our service providers and the basis of our cooperation with them, please contact the contact details provided in this privacy policy.
​
4. Data Processing for Payment Processing
​
When processing payments in our online shop, we cooperate with the following partners: technical service providers, credit institutions, and payment service providers.
​
4.1 Data Processing for Transaction Processing
Depending on the selected payment method, we pass the necessary data for processing the payment transaction to our technical service providers, who act as processors on our behalf, or to the appointed credit institutions or the selected payment service provider, as required to process the payment. This serves contract fulfillment according to Art. 6(1) sentence 1 lit. b GDPR. Some payment service providers collect the necessary data for processing the payment themselves, for example, on their website or through technical integration in the order process. The privacy policy of the respective payment service provider applies.
​
For questions about our payment processing partners and the basis of our cooperation with them, please use the contact details provided in this privacy policy.
​
4.2 Data Processing for Fraud Prevention and Payment Optimization
We may provide our service providers with additional data, which they use in combination with the data required for payment processing as our processors for fraud prevention and the optimization of our payment processes (e.g., invoicing, handling disputed payments, and assisting accounting). This serves, according to Art. 6(1) sentence 1 lit. f GDPR to protect our legitimate interest in securing ourselves against fraud or in efficient payment management.
​
5. Social Media
​
Social Buttons from Instagram (by Meta)
​
On our website, we use social buttons from social networks. These are only embedded as HTML links in the page so that no connection is established with the servers of the respective provider when you visit our website. Clicking on one of the buttons opens the website of the respective social network in a new window of your browser, where you can, for example, click the like or share button.
​
6. Contact Options and Your Rights
​
6.1 Your Rights
As a data subject, you have the following rights:
​
-
According to Art. 15 GDPR, you have the right to request information about the personal data we process about you within the scope specified there.
-
According to Art. 16 GDPR, you have the right to request immediate correction of incorrect or incomplete personal data stored with us.
-
According to Art. 17 GDPR, the right to request the deletion of your data stored with us, unless further processing is necessary for the exercise of the right to freedom of expression and information, to fulfill a legal obligation, for public interest reasons, or the assertion, exercise, or defense of legal claims.
-
According to Art. 18 GDPR, the right to request the restriction of the processing of your data if the accuracy of the data is contested, the processing is unlawful, but you oppose the deletion, we no longer need the data, but you need it for the assertion, exercise, or defense of legal claims, or you have objected to the processing under Art. 21 GDPR.
-
According to Art. 20 GDPR, you have the right to receive your data provided to us in a structured, commonly used, and machine-readable format or to request its transfer to another controller.
-
According to Art. 77 GDPR, the right to complain to a supervisory authority. Generally, you can contact the supervisory authority of your usual residence, place of work, or our company’s location for this purpose.
Right to Object
As far as we process personal data for the purposes of legitimate interests, you can object to this processing with effect for the future. If the processing is for direct marketing purposes, you may exercise this right at any time, as described above. If the processing serves other purposes, you have the right to object only in cases where there are reasons arising from your particular situation.
After exercising your right to object, we will no longer process your data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is for the assertion, exercise, or defense of legal claims.
This does not apply if the processing is for direct marketing purposes. In that case, we will not process your data for this purpose anymore.
6.2 Contact Options
​
For questions about the collection, processing, or use of your data; requests for information, correction, restriction, or deletion of data; or withdrawal of consent or objections to a specific use of data, please contact us directly via the contact details provided in our imprint.