Privacy policy
We take privacy seriously. The protection and security of your personal data, i.e. all information about you (hereinafter referred to as "personal data"), is our highest priority.
Therefore, we handle any information you entrust to us with the utmost care and in accordance with applicable data protection rules, i.e. the General Data Protection Regulation (hereinafter referred to as "GDPR") and applicable national data protection legislation.
Below you will find information about what information we collect about you, how we collect it and on what legal basis, for what purpose we use it, how we protect it and what rights you have in connection with its processing.
I. DATA CONTROLLER
The controller of your personal data when you visit our website at www.westwing.no or our app, including the sale of goods and provision of services we offer, as well as our Westwing accounts on the social media platforms "Facebook", "Instagram", "TikTok" and "Pinterest", among others, pursuant to the GDPR, is:
Westwing GmbH, Moosacher Straße 88, 80809 Munich, Germany, e-mail: service@westwing.no, (hereinafter referred to as "Westwing" or "we").
Westwing GmbH and Westwing Group SE, headquartered at Moosacher Straße 88, 80809 Munich, are in some cases also jointly responsible for processing. In this context, Westwing and Westwing Group SE have defined in a contract in accordance with Art. 26 GDPR which data protection obligations they assume.
II. DATA PROTECTION OFFICER
You can also contact our Data Protection Officer at any time if you have any questions about the processing of your personal data or the exercise of your rights. You can contact him via the following contact details:
Christian Volkmer Projekt 29 GmbH & Co. KG, Ostengasse 14, 93047 Regensburg, e-mail: anfrage@projekt29.de, website: www.projekt29.de
III. CATEGORIES OF PERSONAL DATA PROCESSED
Personal data collected when you visit our website, app or social media accounts can be classified into the following categories:
Information collected when you browse our website or app, depending on which of our cookies you have consented to (e.g. login data, i.e. the date and time you logged in to our website, language settings, products in your shopping basket or information about your preferences, e.g. in relation to product categories),
Information collected when you create a user account (e.g. name, address, email address, preferred title (if provided), phone number (if provided), the encrypted password for your account),
Data processed in connection with your order (e.g. about the products you have purchased or the services you have used and the payment details you have provided to us),
Information collected when you contact us (e.g. name, e-mail address, telephone number, customer, order and item number, as well as any other information you provide to us),
Information about you that we may transfer to our third-party service providers to communicate with you on our website or app and to personalise the communication (e.g. your name, email address or products relevant to you based on your browsing behaviour),
Data collected when you consent to receive newsletters, customer satisfaction surveys, product reminders and your behaviour in relation to the content of our email campaigns (e.g. when you open the newsletter or click on a link in the newsletter),
Information about you that we in certain cases receive from our business partners (e.g. credit bureaus, technical service providers, debt collection service providers or payment service providers),
Data we process in order to participate in competitions (e.g. name and e-mail address),
statistical or aggregated information about your user behaviour on our social media accounts,
Information about you that we receive from a friend or other contact who wants to invite you to use our website or app (e.g. your email address).
IV. THE PURPOSES FOR WHICH WE PROCESS YOUR PERSONAL DATA
We use your personal data for various purposes, for example:
to provide certain technical functions on our website and app (e.g. to store your items in the shopping basket) and to protect our website and app,
to analyse your behaviour on our website so that we can optimise our offer and contributions for you and make them more interesting,
To create a user account,
to fulfil and process orders for goods and services that have been sent to us (e.g. for the dispatch of goods),
to contact you (e.g. to answer all your questions, send you order confirmations and order notifications, or inform you about changes that are important to you, e.g. applicable general terms and conditions or this privacy policy),
for advertising and marketing purposes (e.g. to send you our newsletter, to notify you of coupons or special promotions, to remind you of your shopping basket history, to send you product ratings and polls or for other similar promotional activities),
to process payments from us or our affiliates, to verify fraud by us or our affiliates and to recover claims from our affiliates;
for participation in competitions,
for statistical analysis of your behaviour on our social media accounts to optimise our offering and contributions to you,
to invite a friend or other contact to use our website or app.
At no time do we process special categories of personal data pursuant to Art. 9 GDPR (e.g. health data or data concerning your religion), unless you provide us with relevant information unsolicited when communicating with our customer service.
If we wish to collect and process additional personal data from you, we will inform you separately in advance and, if necessary, obtain your consent.
V. LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA
Your data will only be processed on one of the specified legal bases, i.e. if you have given your consent (Art. 6 (1) (a) GDPR), we have a legitimate interest in the processing (Art. 6 (1) (f) GDPR), we need your data to fulfil or perform a contract with you (Art. 6 (1) (b) GDPR) or it is necessary for compliance with a legal obligation (Art. 6 (1) (c) GDPR). If a purpose of the processing is necessary to pursue a legitimate interest of Westwing or a third party, Westwing will perform a balancing test of the underlying interests, which is available upon request sent to Westwing using the contact details listed above.
VI. RECIPIENTS OF YOUR PERSONAL DATA
Westwing is at all times responsible for the processing of your personal data collected via our website or our app.
Your data will only be passed on to third parties in the following cases on the basis of the legal provisions listed in each individual case:
if disclosure of your data is necessary for the fulfilment or performance of your contract (Article 6(1)(b) of the GDPR); this includes, for example, disclosure of data to payment and logistics service providers, carriers and suppliers if they deliver directly to you); or
if it is necessary for compliance with a legal obligation (Article 6(1)(c) of the General Data Protection Regulation; this includes, for example, disclosure of information to public agencies and other authorities in order to comply with our legal obligations to provide information and disclose information or seek legal remedies), or
on the basis of our legitimate interest (Article 6(1)(f) of the GDPR); this includes, for example, communication of data in connection with the transfer of claims or in connection with administrative purposes within a group);
if we use external service providers, so-called data processors, when processing your personal data, who are obliged to treat your data with care and who act exclusively on our behalf and in accordance with our instructions (Article 28 of the GDPR; this includes, for example, data processors in IT, logistics, telecommunications, sales and marketing).
VII. TRANSFER OF DATA TO THIRD COUNTRIES
In order to ensure that there are adequate safeguards for when personal data is processed outside the EU/EEA, we will always transfer personal data in accordance with the GDPR transfer rules.
We will only transfer your personal data to third countries where an adequate level of protection has been confirmed by the European Commission, or where there is a level of protection comparable to the level of protection in the EU or EEA, or where an adequate level of protection can be ensured through contractual agreements or other appropriate safeguards pursuant to Chapter V of the GDPR.
VIII. ERASURE OF YOUR PERSONAL DATA
Unless there are statutory retention periods (e.g. under commercial and tax legislation) that indicate otherwise, we will only store your personal data for as long as necessary for the relevant purpose of the processing or until you inform us that your personal data must be deleted.
Retention periods according to tax or trade legislation apply, for example, to data related to your orders, such as invoices. The latter are stored for ten years, for example.
Accounts of customers who have not actively used their account for more than six years will be deleted.
We collect log files when you use our website or app to ensure online security and prevent misuse. The log files are usually stored for 20 days and only in individual cases. The log files may be stored for 180 days if necessary to investigate possible cyber-attacks, fraud or abuse. Thereafter, your data will be deleted or anonymised in such a way that it can no longer be linked to you as a person.
IX. DETAILS ABOUT THE PROCESSING OF YOUR DATA ON OUR WEBSITE
1. DATA PROCESSING WHEN YOU VISIT OUR WEBSITE
When you visit our website, the following information is automatically collected and stored in so-called "server log files". Your browser automatically transmits this information to us so that our website can be displayed in your browser and you can use our website:
The IP address of your internet service provider,
the website you visit us from and the websites you visit from our website,
date and time of access and crash data,
information about the browser and operating system used,
if applicable, the email address you use to register on our website,
identification numbers that are stored in so-called cookies or eTags on your end device and that we can use to recognise your end device on the website,
location data,
visit or click on pages and products.
The processing or storage of the above-mentioned access data or your IP address is necessary for technical reasons in order to ensure and safeguard the system security of our website.
In addition, we use the log files on your server exclusively for the purpose of designing and optimising our online offer according to requirements, whereby we assign you an individual user ID when you visit our website, which we merge or combine with your email address only if an error occurs on the website.
If you visit our website to find out more about or use our range of products and services, the basis for the temporary storage and processing of access data is Article 6 (1) (b) of the GDPR, because the processing of personal data is permitted for the fulfilment of a contract or for the implementation of pre-contractual measures.
In addition, the processing or temporary storage of your technical access data is based on the fulfilment of our legitimate interest in accordance with Art. 6 (1) (f) GDPR. In particular, it is our legitimate interest to be able to offer you a technically functional, simple and secure website.
The access data collected when you visit our website is only stored for as long as is necessary to fulfil the above purposes. Server log files are stored for a maximum of 180 days and then deleted.
2. PROCESSING OF PERSONAL DATA WHEN REGISTERING OR CREATING A USER ACCOUNT
In order to register and create your account, we need the email address and password you choose. We also collect and process your contact information, i.e. name, address, e-mail address, the form of contact you would like us to use (if you provide one) and telephone number (if you provide one). The e-mail address serves as an access code to your user account. Once you have registered, you will automatically receive a confirmation email. You may also store your personal data in your user account and use it to make convenient purchases on our website , while billing and delivery address information is automatically stored in your account as described in section 3 below. You can update your information at any time in the personal area of your user account ("My Account"). We use this information to, among other things, process orders, offer payment options and process payments and any returns.
We want to make your visit to our website as comfortable as possible by using the "Stay logged in" feature. This feature allows you to use our services without having to log in every time. Technically, the cookie is stored on your device, so you do not need to log in again on subsequent visits to our website. This feature is not available to you if you have disabled this cookie via your cookie settings or if you have deleted it in your browser settings after you have logged out of our website.
The legal basis for the data processing in question is Article 6(1)(b) of the GDPR, which states that the processing of personal data is permissible for the performance of a contract or for taking steps prior to entering into a contract.
The data collected when you create or register a user account will only be stored for as long as this data is necessary to fulfil the above-mentioned purposes or as long as you have an active user account with Westwing.
3. PROCESSING OF PERSONAL DATA IN ORDER TO PROCESS YOUR ORDER
When you place an order with us, your data is processed for the purpose of entering into and fulfilling the agreement and for processing your order, including payment and delivery. We store the billing information and (possibly different) delivery addresses you provide in your customer account so that you do not have to re-enter them the next time you make a purchase. You can change this information at any time for the future.
The legal basis for the data processing in question is Article 6(1)(b) of the GDPR, which states that the processing of personal data is permissible for the performance of a contract or for taking steps prior to entering into a contract.
We delete your personal data processed as part of orders at the latest after the expiry of the legal obligations for tax and accounting retention.
3.1. CHOOSE PAYMENT METHOD
Depending on the payment method you choose, you will be asked to provide the information required to use the respective payment service provider. These payment details are transmitted directly to the relevant payment service provider and are not stored by us. The relevant payment service provider is responsible for your payment details. Information about this can be found on the website of the relevant payment service provider.
If you do not agree with the payment methods offered, you can inform us in writing by sending an email to service@westwing.no. We will then reconsider our decision and take your point of view into account.
3.1.1. PAYMENT BY CREDIT CARD
When you pay by credit card, we receive a so-called payment ID and the last four digits of your credit card number from our payment service provider Stripe Payments Europe Ltd, 1 Grand Canal Street Lower, Grand Canal Doc, Dublin, D02 H210, Ireland.
This data is used to authenticate and attribute your order and is therefore transmitted for your security. The personal data required for payment processing is collected directly by the payment service provider mentioned above.
The legal basis for the above data processing is Article 6 (1) (b) of the GDPR, which states that the processing is permitted for the fulfilment of a contract.
You can find more information about Stripe Payments Europe Ltd's data protection on their website: https://stripe.com/en-de/privacy.
3.1.2. APPLE PAY
If you choose Apple Pay as your payment method to pay for purchases directly through your bank account, we will receive the relevant account information from our payment service provider Stripe Payments Europe, 1 Grand Canal Street Lower, Grand Canal Doc, Dublin, D02 H210, Ireland. The personal data required for the payment processing is collected directly by the payment service provider mentioned above.
The legal basis for the above data processing is Article 6 (1) (b) of the GDPR, which states that the processing is permitted for the fulfilment of a contract.
You can find more information about data protection in Apple Pay on the Apple Pay website: https://www.apple.com/es/legal/privacy/data/es/apple-pay/.
3.1.3. GOOGLE PAY
If you choose the payment method Google Pay to pay for purchases directly through your bank account, we will receive the relevant account information from our payment service provider Stripe Payments Europe, 1 Grand Canal Street Lower, Grand Canal Doc, Dublin, D02 H210, Ireland. The personal data required for the processing and execution of payments is collected directly by the above-mentioned payment service provider.
The legal basis for the above data processing is Article 6 (1) (b) of the GDPR, which states that the processing is permitted for the fulfilment of a contract.
You can find more information about data protection in Google Pay on the Google Pay website: https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=buyertos&ldr=ES.
3.1.4. PAYPAL
If you choose PayPal as your payment method, your personal data (i.e. first and last name, delivery address, email address, telephone number, amount to be paid and IP address) will be transferred to PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, so that you can authorise us to pay via PayPal. For this you need a PayPal account.
The legal basis for the above data processing is Article 6(1)(b) of the GDPR, which states that the processing of personal data is permissible for the performance of a contract or for taking steps prior to entering into a contract.
You can find more information about data protection at PayPal on the PayPal website: https://www.paypal.com/es/webapps/mpp/ua/privacy-full.
4. PREVENTION OF FRAUD
To prevent fraud and non-payment, we check for frequent fraud patterns and irregularities. For this purpose, order and payment data (e.g. address, item, payment method) and device data (e.g. device, browser) are processed. The legal basis is Article 6(1)(f) of the General Data Protection Regulation (GDPR) on the basis of our legitimate interest in protecting against misuse.
You can find more information about the payment methods offered in our General Terms and Conditions (GTC).
5. DATA PROCESSING WHEN YOU CONTACT US
5.1. CHANNELS FOR CONTACTING US
You have several options to contact us. You can contact our customer service through the following communication channels:
Phone number
by fax,
Mail
Email,
We can use the contact form.
In order to process your enquiry, we collect your name, email address, telephone number, customer, order and item number, as well as any other information you provide to us, depending on the communication channel you use to contact us.
The legal basis for this is Article 6(1)(b) of the GDPR, which states that the processing of the data is necessary for the performance of a contract.
5.2. OUR CUSTOMER SUPPORT SYSTEM ZENDESK
We use the customer support system Zendesk to process your contact enquiries. The provider is Zendesk, Inc, 1019 Market Street in San Francisco, CA 94103 USA.
We use Zendesk to process your enquiries quickly and efficiently. As a reminder, you can also submit questions by entering your email address instead of your name.
We have entered into an order processing contract with Zendesk. This is an agreement that ensures that your personal data is only processed according to our instructions and in accordance with GDPR and other applicable laws.
Your data may be transferred to Zendesk's servers in the United States and stored there. The legal basis for this is an adequacy decision of the European Commission of 10 July 2023 (so-called Data Privacy Framework) in accordance with Article 45 of the GDPR and your consent.
6. PROCESSING OF DATA FOR ADVERTISING PURPOSES
6.1. SEND ADVERTISING E-MAILS
If you have consented to this, Westwing will regularly send you the Westwing Newsletter by email to keep you informed about the latest trends in the Home & Living area, "must-have" Home & Living styles, prominent features of Westwing's online shops and stores, as well as special offers or "Sale of the Day" and "Sale of the Week" ("Newsletter"). Further information on this can be found in section 6.1.1.
Subject to your consent, you will also receive email notifications from us about personalised benefits - such as coupons or special promotions - reminders about the products in your shopping cart, reviews of Westwing products you have purchased, and surveys about Westwing or Westwing services ("Notifications"). Details on this can also be found in section 6.1.1.
If you have already purchased a product or service from us and have not opted out of receiving it, you will also receive promotional emails from us about similar products and/or services via email. Further information about this can be found in section 6.1.2.
6.1. SEND ADVERTISING BY E-MAIL BASED ON YOUR CONSENT
If you have given your consent on our website by ticking the checkbox, we will send you newsletters and/or email notifications.
Please note, however, that we will only send you newsletters and/or e-mail notifications if you have expressly confirmed to us in advance by clicking the button that you wish to receive relevant e-mails. We will send you a corresponding button in the e-mail notification once we have received your consent to the e-mail address you have provided (the so-called "double opt-in process"). This serves to prevent misuse by third parties who may use your e-mail address to register for Westwing newsletters or Westwing notifications without your consent. The legal basis for the double opt-in procedure is Art. 6 (1) (f) GDPR, as we have an overriding legitimate interest in preventing such misuse and documenting your consent.
The relevant legal basis under data protection law for the processing of your personal data in connection with the sending of the above-mentioned promotional emails is your consent in accordance with Article 6 (1) (a) of the GDPR.
You can withdraw your consent at any time with effect for the future as follows:
Click on the unsubscribe link at the end of our promotional emails to be redirected (depending on whether you wish to unsubscribe from newsletters or email notifications) to the newsletter or notification management section of your user account (collectively "Manage Promotional Emails"). There you can easily uncheck the boxes of newsletters or notifications that you no longer wish to receive.
You can also log in to your user account and then click on the "My Newsletters" or "My Notifications" tab (depending on the type of email you wish to unsubscribe from), and then unsubscribe from relevant newsletters or notifications that you no longer wish to receive in the newsletter or notification manager above by unchecking the relevant option.
You can also withdraw your consent to receive newsletters and/or alerts and unsubscribe from receiving relevant promotional emails by sending an email to service@westwing.no.
Using our aforementioned advertising email management, we give you the opportunity to declare and revoke your consent to receive our newsletters and/or notifications in a number of different ways. By ticking or unticking the box, you can decide if and when or how often you want to receive a newsletter or email alert, depending on which newsletter you are interested in or which alert you find useful and how often you want to receive the newsletter or alerts.
Please note that we use standard marketing technology in our email advertising to measure the opening of emails and/or links that you click on. We use this data for general statistical evaluations and to optimise and further develop our content and customer communication. This is done with the help of small graphic elements that are embedded in the newsletter (so-called pixels). The legal basis for this is our legitimate interest in optimising and further developing our content and customer communication (Art. 6 (1) (f) GDPR). If you do not want this analysis of your usage behaviour, you can unsubscribe from receiving promotional emails at any time or deactivate the graphics in your email program by default.
Our newsletters and notifications are sent via the postal service provider Mapp Digital Germany GmbH, Dachauer Straße 63, 80335 Munich, Germany ("Mapp"). An order processing agreement has been concluded with Mapp for the processing of personal data in accordance with Article 28 of the GDPR. You can find more information in Mapp's privacy policy. https://mapp.com/de/privacy/.
6.2. SEND NEWSLETTERS VIA WHATSAPP
We also give you the option to receive our newsletter via the "WhatsApp" message. We use the WhatsApp Business app to send newsletters via WhatsApp.
For this purpose, we co-operate with our data processors charles GmbH, Gartenstraße 86-87, 10115 Berlin, Germany and Braze, Inc, 318 West 39th Street, 5th Floor, New York, New York 10018, USA, ("Braze").
With regard to the use of WhatsApp, the data protection provisions of WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland apply. They stipulate, among other things, that each WhatsApp message is end-to-end encrypted and therefore protected from access by third parties.
The legal basis for Westwing's processing of your data is Art. 6 (1) a) GDPR, because you have consented on our website and confirmed via your WhatsApp message that you would like to receive newsletters via this channel, i.e. news about new products and interior trends. You can withdraw your consent at any time with effect for the future by sending a "Stop" message.
Westwing is committed to complying with the WhatsApp Business Privacy Policy, which can be found here: https://business.whatsapp.com/privacy-protections.
7. PROCESSING OF DATA TO COMMUNICATE WITH YOU ON OUR WEBSITE AND THROUGH OUR APP
We also use the service provider Braze to communicate with you on our website and in our app. For this purpose, we show you so-called "layers" with the possibility of interaction, for example.
Braze is also used to send push notifications in our app.
Braze processes, among other things, the following personal data for this purpose: your IP address, device-related data such as device type, model, operating system, browser type and version, usage information such as usage time, name, email hash, data on interaction with Braze SDK and messaging, installation ID, device ID.
The legal basis for the processing of your personal data is Article 6(1)(a) of the General Data Protection Regulation. You can withdraw your consent at any time with effect for the future. The easiest way to withdraw your consent is through our Cookie Consent Manager.
You can find more information about Braze's compliance with the Privacy Policy here: https:www.braze.com/privacy/.
8. PROCESSING OF DATA FOR PARTICIPATION IN COMPETITIONS
If you participate in competitions, we will only process the data necessary to organise the competition (Article 6(1)(b) of the GDPR). Please note the privacy information in the terms and conditions of the relevant tender.
9. PROCESSING OF DATA IN THE EVENT OF LEGAL PROCEEDINGS
In addition, we process your personal data in individual cases in order to assert legal claims of any kind or to defend ourselves against legal claims, or if it is necessary to defend ourselves against or prosecute criminal offences.
The legal basis for this is the protection of our legitimate interests in accordance with Article 6(1)(f) of the GDPR.
10. DATA PROCESSING WHEN USING FAN PAGES ON SOCIAL NETWORKS
Westwing is active and present on social networks and social platforms to communicate with interested parties and users and inform them about other offers of Westwing. Below we provide you with an overview of our processing and use of your personal data or your use of the social media platforms listed below:
10.1. FACEBOOK AND INSTAGRAM
We operate social media "fan pages" on Facebook and Instagram together with Meta Platforms Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Meta"), to communicate with our fans (such as our customers and stakeholders) and inform them about our products, competitions and other promotions.
You can see the contract with Meta here: https:www.facebook.com/legal/terms/page_controller_addendum
Using metastatistics about the use of our fan pages (e.g. numbers, names, interactions such as "likes" and comments, as well as aggregated demographics and other information or statistics; "Insights Data"), we obtain information about how our fan page is used, what visitors to our fan pages are interested in, and what topics and content are particularly popular, so that we can optimise the content of our fan page and tailor it to our users. Insights data only contains statistical and depersonalised data about visitors to a fan page and therefore cannot be assigned to a specific person. You can find more information about the type and scope of these statistics in the information about Facebook page statistics. You can find more information about the respective areas of responsibility and Facebook's processing of your data in the so-called "Facebook Pages Information Supplement" at: https:www.facebook.com/legal/terms/information_about_page_insights_data
Please note that we have no control over the data processing that Meta carries out at its own risk in accordance with Meta's terms of use. However, please note that when you visit "Fanpages", data about your usage behaviour is transferred from Facebook and "Fanpages" to Facebook. Facebook itself processes your personal data in order to compile the above-mentioned statistics and for its own market research and advertising purposes. We do not have access to this information.
To the extent that we receive personal data about you in connection with the operation of fan pages, you have the rights set out in this privacy policy. If you wish to exercise your rights towards Facebook beyond this, please contact Facebook directly. We will be happy to assist you in exercising your rights to the extent possible and will refer your enquiries to Facebook.
The legal basis for this data processing is Article 6 (1) (f) GDPR on the basis of our aforementioned legitimate interest in being able to offer you our Facebook fan pages for marketing and advertising purposes.
You can find more information about this in Meta's data policy at: https://es-es.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0
10.2. YOUTUBE
On the YouTube.com platform, we use so-called "plugins" to embed our own videos and make them available to the public. YouTube is a service provided by a third party that is not affiliated with us, namely YouTube LLC operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; ("Google").
As soon as you access our YouTube channel, your browser establishes a connection to YouTube and transmits information. The integration of YouTube content only takes place in the so-called "extended data protection mode". This is a function offered by YouTube itself, which, according to its own information, ensures that YouTube user data (e.g. cookies) is only stored on your device when the video is played. When you access and open the videos in question, your IP address, unique identifiers, browser type and settings, device type and settings, operating system, mobile network information, e.g. mobile provider name and phone number, and app version number are transmitted to YouTube. YouTube also collects data about how its apps, browsers and devices interact with its own services. The transfer of data to YouTube's partners is not necessarily excluded by the extended data protection mode. YouTube establishes a connection to the Google DoubleClick network, regardless of whether you watch the video or not. The data transmitted includes the IP address, crash reports, system activity as well as the date, time and referral URL of your request. In addition, YouTube collects information about your activities (e.g. the terms you search for, the videos you watch, etc.). All data collected about you through our YouTube channel is processed by YouTube. According to YouTube, this information is used, among other things, to compile video statistics, improve usability and prevent abuse. YouTube also uses cookies to collect information about user behaviour. The storage of these cookies can be prevented by means of appropriate settings and browser extensions. If you are logged in to your YouTube account, you allow YouTube to associate your browsing behaviour directly with your personal profile. You can prevent this by logging out of your YouTube account before activating the play button.
In addition, we occasionally integrate videos stored on YouTube directly into our website using so-called "plug-ins". With this integration, the content of the YouTube website is displayed in parts of the browser window. However, YouTube videos can only be opened by clicking on them separately. This technique is also known as "framing". If you access a (sub)page of our website where YouTube videos are embedded in this way, a connection is made to YouTube's servers and the content is displayed on the website by notifying your browser. We have no influence on the scope and content of the data transmitted to YouTube and possibly other YouTube partners by activating the plug-in. Among other things, the YouTube server receives information about which of our pages you have visited.
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
For more information about what information YouTube receives and how it is used, please see YouTube's privacy policy at: https://policies.google.com/privacy.
10.3. TIKTOK
We publish short video clips on the TikTok platform and TikTok app to promote our products and sales. If you visit the TikTok website or app, TikTok Inc, 10100 Venice Blvd, Culver City, CA 90232, USA ("TikTok") collects and processes your personal data.
TikTok makes a certain amount of this data available to TikTok profile holders in anonymised and aggregated form. It is the number of new followers, demographic information such as gender and country, without reference to identifiable individuals. Westwing can therefore not identify any visitors to the TikTok profile. As the owner of this profile, Westwing receives anonymised statistical data (so-called "Insights data") from TikTok. This information cannot be used to draw conclusions about the visitor in question. We use the statistical data exclusively to analyse user behaviour so that we can better adapt our TikTok profile and our offer to the needs and interests of our visitors.
Further information about TikTok's data processing can be found in TikTok's privacy policy at: https://www.tiktok.com/legal/page/eea/privacy-policy/en.
10.4. PINTEREST
We operate a Westwing account on Pinterest and the Pinterest app, where we post home and living inspiration and advertise our products. Pinterest Inc, 808 Brannan Street, San Francisco, CA 94103, USA ("Pinterest") is responsible for Pinterest.
When you sign up for an account, Pinterest processes the information you provide, such as your name, email address, phone number, photos, pins and comments. In addition, Pinterest collects and processes your IP address, which is used to estimate your location if you choose to share your exact location, as well as other web and online activity (including "pins" you click, "boards" you create, and the text you add to your comment or description).
The legal basis for this data processing is Art. 6 (1) (f) GDPR on the basis of our legitimate interest in being able to offer you our Pinterest platform for marketing and advertising purposes.
You can find more information at https://policy.pinterest.com/en/privacy-policy.
11. PROCESSING OF PERSONAL DATA BY SHOPIFY
To provide our online store and process your payments, we work with the service provider Shopify International Limited, Victoria Buildings 1-2, Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify"). Shopify allows us to manage our online store through Shopify's cloud computing infrastructure and they also process your payments for us.
Your data may be transferred to Shopify servers in the United States and stored there. The United States does not provide the appropriate level of data protection required by the GDPR. With regard to the collection, transfer, and processing of personal data in the United States, Shopify ensures the protection of personal data by participating in the Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023) in accordance with Article 45 of the GDPR together with the EU Standard Contractual Clauses.
Shopify is used to provide our online store and process your payments. The legal basis is therefore the fulfilment of your contract in accordance with Article 6(1)(b) of the GDPR.
Shopify acts as our data processor or data controller, depending on the processing activity.
For more information about data processing and Shopify's privacy policy, please visit https://www.shopify.com/legal/privacy.
X. COOKIES AND SIMILAR TECHNOLOGIES
We use so-called "cookies" and similar technologies (e.g. so-called "web beacons", "pixels", "tags") on our websites. Web beacons are small GIF files that may be hidden in other graphics, emails or similar. Web beacons can identify your computer and evaluate your user behaviour, such as your reactions to advertising campaigns. The information collected by web beacons cannot be used to identify you. Cookies are small text files that are transferred from an internet server to your browser and stored on your hard drive. There are so-called "session cookies", which are deleted as soon as you close your browser, and so-called "persistent cookies", which are stored on your device for a longer period or indefinitely. The cookie contains a characteristic string of characters that allows your browser to be uniquely identified when you return to the website. This helps us to customise our offering, make it easier to use, more efficient and secure, and enable us to provide certain features.
Under the "Cookie settings" button, you can specify at any time which cookies you want to allow. Necessary cookies, which ensure essential functions of the website, cannot be switched off.
There are basically four different categories of cookies:
1. ABSOLUTELY NECESSARY COOKIES
These cookies enable basic functionalities and are essential for the website to function properly. They are used, for example, to process orders or to enable you as a registered user to remain logged in at any time when accessing various subpages on our website. Thanks to these cookies, you do not have to re-enter your login details every time you access a new page.
The legal basis for the use of strictly necessary cookies on our website is our legitimate interest in providing a technically error-free and simple website (Article 6(1)(f) GDPR). The use of strictly necessary cookies is possible and legally permissible without your prior consent.
2. FUNCTIONAL COOKIES
These cookies enable us to store information that you have already entered (such as your registered name) and provide you with improved and more personalised features.
The data processing is carried out on the basis of your consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future, most easily through the Cookie Consent Manager.
You can also refuse the use of cookies by changing your browser settings to "Reject cookies", for example, if you do not want your computer to be recognised on your next visit. You can find instructions on how to do this in your browser's user manual.
With the correct browser settings, you will be informed about the installation of cookies and you can only allow cookies in certain cases or exclude the acceptance of cookies in certain cases or in general. It is also possible to activate the automatic deletion of cookies when you close your browser. If you refuse the use of certain cookies, the use of certain parts of our website may be restricted.
3. PERFORMANCE COOKIES
These cookies enable us to count visits and traffic so that we can measure and improve the performance of our website. The information collected by the cookies allows us to understand, among other things, which pages are most popular, which are least used, and how visitors move around our website. All data collected by these cookies is aggregated and cannot be easily attributed to you.
The data processing is carried out on the basis of your consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future, most easily through the Cookie Consent Manager.
4. COOKIES AND MARKETING PIXELS
These cookies and similar technologies (e.g. pixels) enable us to show you personalised and thus relevant advertising content and to measure the effectiveness of our advertising measures. It is therefore not possible to draw direct conclusions about an individual. These cookies are placed not only on our website but also on websites ("third-party cookies"). So-called "retargeting" is used to place relevant advertising on other websites and to analyse the relevant target groups for the products.
The data processing is carried out on the basis of your consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future, most easily through the Cookie Consent Manager. If you do not allow these cookies, you will see less relevant advertising.
5. DETAILS ABOUT THE COOKIES WE USE
5.1. NECESSARY COOKIES
5.1.1. GOOGLE RECAPTCHA
We use the reCAPTCHA service offered to persons in the EEA and Switzerland by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
With the help of this service, we can distinguish between whether the entry is made by a natural person or whether it is made using machine and automated processing.
When you use the service, your IP address and any other data required by Google for the reCAPTCHA service will be transferred to Google.
This data is processed on the basis of our legitimate interest in exercising online personal responsibility and preventing abuse and spam (Article 6 (1) (f) GDPR). Storing information and accessing information on your end device is essential.
The data in question may be transferred to Google servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
For more information about Google reCAPTCHA and Google's privacy policy, please visit: https://www.google.com/intl/en/policies/privacy/.
5.1.2. ONE TRUST
We work with service provider OneTrust, LLC, 1350 Spring St NW, Atlanta, GA 30309 ("OneTrust") to obtain and manage your consent. This is done by means of our "cookie banner", which is displayed on your first visit to our website or app and which informs you about the processing of data or, in particular, about cookies and other technologies on our website and allows you to refuse or accept the setting of individual cookies and other technologies. However, you can reapply for the cookie banner and change your choice. In addition, a cookie banner will be displayed when you visit our website if you have disabled the storage of cookies or if OneTrust has deleted cookies or they have expired.
In particular, your consents or revocations, your IP address, data about your browser and your end device at the time of your visit will be transmitted to OneTrust and the data will be stored on your end device.
The relevant legal basis is Article 6(1)(f) of the GDPR, as we have a legitimate interest in complying with the statutory documentation of your consents to cookies and cookie management.
The relevant data may be transferred to OneTrust servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
5.2. FUNCTIONAL COOKIES
5.2.1. VIMEO PLUGINS
For video integration we use, among others, Vimeo LLC, 555 West 18th Street, New York 10011, USA ("Vimeo").
So-called add-ons are used for this purpose. When you access websites with such a plugin, a connection to the Vimeo servers is established and information is transmitted about which of our websites you have visited. If you are logged in to Vimeo, Vimeo assigns this data to your personal user account. When you use the plugin, for example by clicking the button to start a video, this information is also assigned to your user account.
Relevant data may be transferred to Vimeo's servers in the USA and stored there. The United States does not offer the appropriate level of data protection set out by the GDPR. With regard to the collection, transfer and processing of personal data in the United States, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information about data processing and privacy notices from Vimeo at https://vimeo.com/privacy.
5.2.2 ALGOLIA
We use the service Algolia SAS, 55 Rue d'Amsterdam, 75008 Paris, France ("Algolia") to search and index the content of our website and app. To do this, your IP address and search queries are transmitted to the Algolia server.
Algolia also creates reports for us with associated evaluations and analyses of searches.
In this way, Algolia helps us improve the searchability of our offers, as well as the search experience and customer satisfaction of our customers.
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information in Algolia's privacy policy: https://algolia.com/policies/privacy.
5.3. PERFORMANCE COOKIES
5.3.1. GOOGLE ANALYTICS WITH CONVERSION TRACKING
We use Google Analytics, a web analytics service provided by Google that, among other things, installs pixels and performance cookies to store data on your end device.
This enables us to assign cross-device data, sessions and interactions to a pseudonymous user ID and thus analyse your user behaviour across devices and improve our website and make it more interesting for you. For this purpose, we also receive statistics from Google about your use of our website.
Google Analytics 4 also uses artificial intelligence to analyse and enrich data automatically. This is primarily used to predict the future behaviour of website visitors based on structured event data (e.g. sales forecast, purchase probability and cancellation probability). These forecast values can also be used to predict target audiences. More information at: https://support.google.com/analytics/answer/9846734?hl=en
Google Analytics 4 also models conversions if there is not enough data available to optimise the data analysis. More information about this can be found at: https://support.google.com/analytics/answer/10710245?hl=en.
Google Analytics 4 does not record or store individual IP addresses. However, Google Analytics 4 provides approximate geolocation data by deriving the following metadata from IP addresses: city (and derived latitude and longitude for the city), continent, country, region, subcontinent (and ID-based duplicates). For traffic in the EU, IP address data is only used to obtain geolocation data before it is immediately deleted. It is not recorded, accessible or used for any other purpose.
The data in question may be transferred to Google servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023). Due to the activation of IP anonymisation on this website, your IP address will be shortened before transmission to the USA or EU member states or EEA countries. Only in exceptional cases will your full IP address be transferred to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we do not use this service unless you have given your consent to use Google Analytics with conversion tracking. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can also prevent Google from collecting information about you (including your IP address) and processing this data by downloading and installing the browser add-on available at the following link: http:tools.google.com/dlpage/gaoptout?hl=es. An opt-out cookie will be set to prevent future collection of your information when you visit this website. The opt-out cookie is only valid in this browser and only for our website and it is stored on your device. If you delete cookies from this browser, you will need to reinstall the opt-out cookie.
Further information on the processing of data by Google Analytics with conversion tracking can be found at: http:www.google.com/analytics/terms/es.html, http://www.google.com/intl/es/analytics/learn/privacy.html, http://www.google.es/intl/de/policies/privacy.
5.4. COOKIES AND MARKETING PIXELS
5.4.1. FACEBOOK CUSTOMISED AUDIENCE / METAPIXEL
On our website, we use Facebook Custom Audiences with a so-called pixel feature ("Meta Pixel") and a server-side conversion API, which for visitors from outside the USA and Canada is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Grand Canal Harbour, Dublin 2, Ireland ("Meta").
This enables us to show you interest-based advertising when you visit Facebook, Instagram or other Meta apps and websites and to track the effectiveness of our advertising. Through meta-pixels embedded on our website, your browser automatically connects to Meta's servers for enhanced synchronisation of the embedded meta-pixel. This provides Meta with information, for example, that you have clicked on a particular advert or product on our website, which in turn enables us to show you interest-based ads on our website or on other websites.
If you are registered with the Meta service, Meta can assign a visit to the website to your account, as we transmit your personal data in the form of an e-mail address and IP address to Meta in a hashed form via pixels and partially enriched with existing tracking data. The country in which you are located is also transferred. Even if you are not registered on Facebook or Instagram or are not logged in, Meta can learn your personal data above and use it to create a profile.
The relevant data may be transferred to Meta's servers in the USA and stored there. The United States does not offer the appropriate level of data protection stipulated by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we do not use these services unless you have given your consent to the use of personalised audiences or the Facebook pixel. You can withdraw your consent at any time with effect for the future in the easiest possible way through our consent manager. If you are logged into your Facebook account, you can also object to the processing of your data via the following link: https:www.facebook.com/adpreferences/ad_settings/?entry_product=account_settings_menu
Further information, in particular about our and Meta's joint responsibility and about the purpose and scope of Meta's data processing as well as about the setting options to protect your privacy, can be found in Meta's privacy policy: https:www.facebook.com/about/privacy/.
5.4.2. PINTEREST TAG
In order to further optimise our Pinterest campaigns and measure their success, we use the "Pinterest Tag" service of the social network, which is offered to visitors in the European Economic Area by Pinterest Europe Ltd, Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest").
We use the "Pinterest tag" in combination with the server-side conversion API to show our Pinterest adverts only to those Pinterest users who have shown interest in our offer. At the same time, this ensures that the content of our adverts is highly likely to match the interests of the user in question. We can also track the behaviour of Pinterest users who click on one of our ads. To do this, Pinterest processes data collected by the service using cookies, web beacons and comparable storage technologies on our website.
When you use the service, the following data is processed: device data (e.g. type, brand), operating system used (e.g. iOS 11), IP address of the device used, time of access to our offer, type and content of the campaign and reaction to the corresponding campaign (e.g. click on a button), as well as device identifiers consisting of the individual characteristics of your end device. We may also use these device identifiers to identify your device on the website. The data collected in this way is anonymised for us and does not allow conclusions to be drawn about your identity. If you log into your Pinterest account after visiting our website, or if you visit our website while logged in, Pinterest may store and process this information, which we would like to inform you about. Pinterest may associate this information with your Pinterest account and use it for its own advertising purposes.
The relevant data may be transferred to Pinterest's servers in the USA and stored there. The United States does not offer the appropriate level of data protection stipulated by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have given your consent to use Pinterest Tag. You can withdraw your consent at any time with effect for the future, most easily through our Consent Manager.
You can find more information about the purpose and scope of data processing and your options for protecting your privacy in Pinterest's Privacy Policy, which can be accessed via the following link: https:policy.pinterest.com/en/privacy-policy.
5.4.3. MICROSOFT BING ADVERTS
On our website, we use Bing conversion tracking from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.
Microsoft Bing Ads places a cookie on your computer if you have come to our website via Microsoft Bing Ads. This allows us to recognise that you have clicked on an advert and that you have been redirected to our website. This helps us understand how effective a particular advert is. However, we only receive information about the total number of users who have clicked on a Bing advert and been redirected to our website. No information about the user's identity is communicated.
The relevant data may be transferred to Microsoft's servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided for by the GDPR. With regard to the collection, transfer and processing of personal data in the United States, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
Further information on data processing and cookies used by Bing Ads can be found at: https:privacy.microsoft.com/es-es/privacystatement.
5.4.4. GOOGLE ADS (FORMERLY ADWORDS) AND CONVERSION TRACKING
We use Google Adwords and Google Conversion Tracking, which are provided to persons in the European Economic Area and Switzerland by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
This enables us to place Google AdWords adverts that take into account your interests and location.
When you click on a Google advert, a cookie is temporarily placed on your computer that allows us to recognise that you have clicked on the advert and that you have been redirected to this page.
Using the conversion statistics created from this, we know the total number of people who clicked on your advert and were redirected to the conversion tracking tag page. However, we do not receive any personal information about the users.
If you use a Google Account, Google may associate your browsing and app history with your Google Account and use information from your Google Account to personalise ads based on the settings stored in your Google Account. If you do not want this association with your Google Account, you should log out of Google before visiting our website. You can also prevent the installation of cookies by changing the settings in your browser or on the Google website.
The data in question may be transferred to Google servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
More information about Google Ads and conversion tracking, as well as Google's privacy policy, can be found at: https:www.google.com/privacy/ads and https://policies.google.com/privacy.
5.4.5. GOOGLE DYNAMIC REMARKETING
We also use the remarketing function of Google Ads. This service is used to display interest-based adverts on other websites after you have visited our website. The adverts are based on the products and services you clicked on during your last visit to our website. To do this, Google sets cookies that are temporarily stored in your browser. The data collected is not used to identify a person. Google only stores data such as your web request, IP address, browser type, browser language, date and time of the request.
If you use a Google Account, Google may associate your browsing and app history with your Google Account and use information from your Google Account to personalise ads based on the settings stored in your Google Account. If you do not want this association with your Google Account, you should log out of Google before visiting our website. You can also prevent the installation of cookies by changing the settings in your browser or on the Google website.
The relevant data may be transferred to Microsoft's servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided for by the GDPR. With regard to the collection, transfer and processing of personal data in the United States, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information about Google's dynamic retargeting and Google's privacy policy at: https:www.google.com/privacy/ads and https://policies.google.com/privacy.
5.4.6. GOOGLE AD MANAGER (FORMERLY DOUBLECLICK)
We also use Google Ad Manager (formerly Doubleclick). This service uses cookies, pixels and other technologies to serve adverts based on your interests and previous visits to our website or other websites. It also enables us to track the success of our advertising campaigns. Google also processes data to optimise its own products and services.
If you use a Google Account, Google may associate your browsing and app history with your Google Account and use the information in your Google Account to personalise ads based on the settings stored in your Google Account. If you do not want this association with your Google Account, you must log out of Google before visiting our website. You can also prevent the installation of cookies by changing the settings in your browser or on the Google website.
The data in question may be transferred to Google servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information about Google Ad Manager and Google's privacy policy at: https:www.google.com/privacy/ads and https://policies.google.com/privacy.
5.4.7. YOUTUBE IN EXTENDED DATA PROTECTION MODE
Among other things, we use the service provider YouTube LLC, 901 Cherry Ave, San Bruno, CA 94066, USA ("YouTube") to embed videos on our website. When you visit our website with embedded YouTube videos, your browser establishes a direct connection to YouTube's servers to show you the content. The content you access may be recorded by your browser. If you are logged in to your YouTube account, YouTube may associate your usage behaviour with your personal profile. You can prevent this by logging out of your YouTube account before visiting our website.
The relevant data may be transferred to YouTube's servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the United States, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information about YouTube's data processing in YouTube's privacy policy at: https:policies.google.com/privacy?hl=es&gl=es.
5.4.8. SEGMENT
We also use a segment service provided by Segment Inc, 101 15th St San Francisco, CA 94103, USA ("Segment").
The segment collects and stores information about you that can be used to create usage profiles using pseudonyms. These usage profiles are used to analyse your usage behaviour and are evaluated to improve our offering to you. For this purpose, cookies may be used, which allow us to recognise you when you visit our website again. Pseudonymised user profiles are not merged with the personal data of the holder of the pseudonym.
The relevant data may be transferred to Segment's servers in the USA and stored there. The United States does not provide the appropriate level of data protection set out in the GDPR. With regard to the collection, transfer and processing of personal data in the United States, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information in Segment's privacy policy: https://segment.com/docs/legal/privacy/.
5.4.9. HOTJAR
We use the web analytics service Hotjar, provided by Hotjahr Limited, Dragonara Road, Paceville St. Julian's STJ 3141, Malta ("Hotjar").
Hotjar uses cookies and other technologies to analyse and evaluate your user behaviour and interaction with our website. This helps us to optimise your user experience on our website by giving us a better understanding of users' experiences on our website (e.g. clicks, scrolling, mouse movements).
Your IP address is truncated before the usage statistics are analysed so that no direct conclusions can be drawn about your identity.
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information in the "About Hotjar" section at https://help.hotjar.com/hc/en-us/sections/115003204947.
5.4.10. BRAZE
We use the web analytics service Braze, Inc, 318 West 39th Street, 5th Floor, New York, New York 10018, USA, ("Braze") to interact with you on our website and understand how our mobile content works and is used on your device. For example, we display pop-ups with the interaction option. Braze is also used to send push notifications in our app. We also use Braze to send you personalised promotions and information about our products. We also use Braze to notify you about items that you have forgotten in your shopping basket.
The relevant data may be transferred to Braze's servers in the USA and stored there. The United States of America does not provide the appropriate level of data protection set out by the GDPR. With regard to the collection, transfer and processing of personal data in the United States, Braze ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information about Braze's compliance with the Privacy Policy here: https:www.braze.com/privacy/.
5.4.11. CRITEO
We also use the remarketing tool of Criteo, SA, 32 Rue Blanche, 75009 Paris, France, on our website and in our app to show you personalised ads on partner websites and in product apps that interest you, based on the products you have clicked on our website or in our app. In order to do this, Criteo links the above-mentioned data about your past browsing behaviour to a unique identifier, such as an ID cookie or other similar technology (e.g. mobile advertising ID and non-cookie based technologies).
Criteo and Westwing act as joint controllers pursuant to Article 26 of the GDPR.
The legal basis under data protection law is your consent in accordance with Article 6 (1) (a) of the General Data Protection Regulation. You can withdraw this consent at any time with effect for the future - the easiest way is through our Cookie Consent Manager or at the following link https://www.criteo.com/es/privacy/disable-criteo-services-on-internet-browsers/ - withdraw your consent.
If Criteo transfers personal data to countries outside the EU or outside the EEA, Criteo will do so on the basis of an adequacy decision of the European Commission in accordance with Article 45 of the GDPR or on the basis of appropriate data protection safeguards in accordance with Article 46 of the GDPR, for example by entering into EU Standard Contractual Clauses. Your data will be deleted as soon as it is no longer necessary for the specified purposes of the processing.
You can find more information about how Crite processes your data here: https: //www.criteo.com/privacy/.
5.4.12. KLEAR
We use the influencer marketing service Klear from Meltwater Deutschland GmbH, Jannowitz Centre, Brückenstrasse 6, 10179 Berlin. This enables us to set up influencer marketing programs and measure and analyse influencer campaigns. Klear uses cookies to track the success of campaigns on our website. These analyses help us, among other things, search for social media influencers by region, language, sector, hashtag and previous collaborations, and make data-driven decisions about our influencer marketing strategy.
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future in the easiest way through our consent manager.
You can find more information about privacy compliance here: https:klear.com/legal/cookies; https://klear.com/legal/privacy-notice-for-influencers.
5.4.13. GOOGLE CUSTOMER MATCH
We also use Google's Google Customer Match service, which enables us to serve interest-based ads to our website visitors based on their past browsing behaviour on our website and on third-party websites, apps and emails.
The data in question may be transferred to Google servers in the USA and stored there. The United States does not offer the appropriate level of data protection provided by the GDPR. With regard to the collection, transfer and processing of personal data in the USA, Google ensures the protection of personal data by participating in the so-called Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023).
The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager. If you do not wish to receive interest-based adverts from Google Customer Match, you can also opt out of the following websites: http:www.networkadvertising.org/choices/; http://www.youronlinechoices.com/
You can find more information about Google's privacy policy compliance here: https://support.google.com/google-ads/answer/6334160?sjid=2821624592503930728-EU
5.4.14. LEAD FORENSICS
This website also utilises Lead Forensics, a B2B sales and marketing tool from Lead Forensics, headquartered in the United Kingdom, Communication House, 26 York Street, London, W1U 6PZ, United Kingdom.
Lead Forensics uses a tracking code to identify companies that visit our websites, based on their commercial IP addresses. These are not cookies. Lead Forensics' tracking code only provides publicly available information. It cannot and will not provide any personal or sensitive information about who has visited our website. Under no circumstances will the data be used to personally identify an individual visitor. If IP addresses are collected, they are anonymised immediately after storage.
Lead Forensics does not provide us with IP addresses. It only provides us with information about which companies have visited our website, the date and duration of their visit, and which websites they have visited. This information enables us to analyse the use of our website and, if necessary, to contact these companies.
The information generated by the Lead Forensics tracking code is transferred to Lead Forensics' servers in the United Kingdom, where it is processed and stored. The legal basis for this is the European Commission's decision of 28 June 2021 on the adequacy of the level of protection for transfers to the United Kingdom, in accordance with Article 45 of the GDPR.
The legal basis for the processing of your data is your consent, cf. Article 6(1)(a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager. To unsubscribe from tracking, you can also use the following link: https:optout.leadforensics.com/?clientID=786109
5.4.15. TIKTOK ADS
We use the TikTok Ads service provided by TikTok Inc, 10100 Venice Blvd, Culver City, CA 90232, USA ("TikTok"), which enables us to serve interest-based ads to visitors to our website based on their past browsing behaviour on our website and on third-party websites, apps and emails.
When you visit our website, a connection is made to TikTok's servers by installing pixels, and data such as your IP address, pages visited and interactions may be recorded.
The corresponding data may also be transferred to TikTok servers in the United States and the United Kingdom. Although the United States and the United Kingdom are outside the EU, there is an adequate protection basis for the transfer of data pursuant to European Commission Decision 2021/1772 of 28 June 2021 and the Data Privacy Framework (approved by the European Commission's adequacy decision of 10 July 2023). The legal basis for the processing of your data is your consent, cf. Article 6(1), first sentence, point (a) of the General Data Protection Regulation. This means that we will not use this service unless you have consented to its use. You can withdraw your consent at any time with effect for the future, most easily through our Cookie Consent Manager.
You can find more information about TikTok's privacy policy compliance here: https:ads.tiktok.com/help/article/app-retargeting?lang=es or here: https:www.tiktok.com/legal/page/eea/privacy-policy/es.
XI. TECHNICAL AND ORGANISATIONAL MEASURES FOR DATA SECURITY
We have implemented technical and organisational security measures and measures to protect your personal data against loss, destruction, manipulation and unauthorised access by third parties, and to ensure an adequate level of protection and protect your personal rights.
We encrypt personal data, including sensitive content such as contact requests, before transferring it. All our employees, as well as service providers and data processors working for us, are obliged to comply with applicable regulations and data protection laws.
We regularly check whether our security measures are adequate and modern.
XII. YOUR RIGHTS AS A DATA SUBJECT
In accordance with the legal provisions on data protection, you have the following rights in relation to your personal data at all times:
1. RIGHT OF ACCESS
You have the right to request and receive information about the data we process about you in accordance with the rights you have as a data subject under the GDPR, including: the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipients to whom the personal data have been or will be disclosed, the envisaged retention periods or the criteria for determining the relevant periods, your data protection rights, the existence of automated decision-making, including profiling (if applicable), information on appropriate safeguards for the transfer of data to third countries. You also have the right to receive a copy of this information.
2. RIGHT TO RECTIFICATION
You have the right to request the rectification of inaccurate data and, with regard to the purpose of the processing, the completion of incomplete data.
3. RIGHT TO ERASURE ("RIGHT TO BE FORGOTTEN")
You have the right to request deletion of your data for the following reasons:
Storage of the data is no longer necessary for the purposes for which it was collected or processed,
withdraw the consent on which the processing was based and there is no other legal basis for the processing,
You object to the processing and there are no compelling legitimate grounds for the processing,
that the personal data in question has been processed unlawfully,
or erasure of personal data is necessary for compliance with a legal obligation under Union or Member State law.
Please note that there may be reasons that prevent immediate erasure, e.g. in the case of statutory storage obligations. Regardless of whether you exercise your right to erasure, we will erase your data immediately and completely, provided that the storage is no longer necessary for the relevant purpose of the processing and that there are no statutory or regulatory retention obligations to the contrary.
4. RIGHT TO RESTRICTION OF PROCESSING
You have the right to request that the processing of your data be restricted, provided that
you dispute the accuracy of your personal data,
the processing is unlawful and you object to the erasure of your personal data and instead request that the use of your personal data be restricted;
we no longer need the personal data for the purpose of the processing, but you need it to establish, exercise or defend your rights in legal proceedings; or
you have objected to the processing in accordance with Article 21(1) of the GDPR until it is clarified whether our legitimate grounds are stronger than yours.
5. RIGHT TO DATA PORTABILITY
If the legal requirements are met, you have the right to receive the provided data in a structured, commonly used and machine-readable format and to transmit this data to another controller or, if technically feasible, to request Westwing to transmit it.
6. RIGHT TO LODGE A COMPLAINT WITH THE COMPETENT DATA PROTECTION AUTHORITY
You also have the right to lodge a complaint with the competent data protection supervisory authority via: poststelle@lda.bayern.de. However, we prefer to be contacted before you consider contacting the relevant authorities.
7. RIGHT TO OBJECT
If the processing of personal data is based on our legitimate interest in accordance with Article 6(1)(f) of the GDPR, you also have the right to object to the processing of your personal data on the basis of your particular situation, e.g. by email to: service@westwing.no. In this case, we will no longer process your personal data for these purposes, unless our legitimate interest outweighs this in the individual case.
8. RIGHT TO WITHDRAW YOUR CONSENT
If the processing of your personal data is based on your consent pursuant to Article 6 (1) (a) of the GDPR, you have the right to withdraw your consent at any time with effect for the future, e.g. by sending an email to: service@westwing.no.
If you wish to exercise any of these rights in relation to us, please contact our Data Protection Officer by email at: anfrage@projekt29.de.
XIII. CHANGES TO THIS PRIVACY POLICY
We reserve the right to change this privacy policy if necessary, for example due to the use of new technology.
If fundamental changes are made to this privacy policy, we will post them on our website. We will also check whether there is an obligation to provide further notice of changes to this privacy statement in individual cases and, if necessary, we will fulfil this obligation.
Status May 2025