Privacy Policy
Privacy Policy
Data Controller:
Michał Pietraś
Wędrowna 6/91
20-819 Lublin
michal@forbiddenpen.de
Thank you for visiting our online store. We highly value your privacy and take the protection of your personal data seriously. Below, we outline in detail how we handle your information.
1. Access Data and Hosting
You can browse our website without sharing personal data. With each visit, our server automatically records technical details such as the name of the requested file, IP address, date and time of the request, data volume transferred, and the internet provider making the request. These log files are used solely to ensure the seamless operation of our website and to optimize our services, as per Art. 6(1)(f) GDPR. Log files are deleted within seven days of your website visit.
Hosting Services
Our website is hosted on servers operated by third-party providers, which process access data on our behalf. Unless stated otherwise in this policy, all data collected via online forms on our site is also processed on these servers. If you have any questions about our service providers and the legal basis of our collaboration, feel free to contact us using the details provided in this policy.
2. Data Processing for Contract Execution and Customer Communication
2.1 Processing for Contract Fulfillment
When you place an order, we collect necessary personal data to process the contract (including warranty claims and legal update obligations) under Art. 6(1)(b) GDPR. Mandatory fields are indicated as such because the data is essential for contract execution. Without it, we cannot complete the order. Details on the collected data are available in the respective input fields.
For more information regarding data transfers to service providers for order fulfillment, payment processing, and delivery, refer to the relevant sections of this privacy policy. After contract completion, your data is retained only as required by tax and commercial law regulations (Art. 6(1)(c) GDPR). If you have consented to further use of your data (Art. 6(1)(a) GDPR), or if we are legally permitted to continue processing it, we will inform you accordingly in this policy.
2.2 Customer Account
If you create a customer account, we store your data for future orders, provided you have given your consent (Art. 6(1)(a) GDPR). You may delete your account at any time via the designated function or by contacting us. After deletion, your data will only be retained if legally required or permitted.
2.3 Contacting Us
When you contact us (e.g., via a contact form or email), we process your personal data to handle your inquiry (Art. 6(1)(b) GDPR). Mandatory fields indicate the information required for processing. Your data is deleted after your request has been resolved unless further retention is justified under GDPR.
3. Data Processing for Shipping
To fulfill deliveries, we share necessary data with shipping companies in compliance with Art. 6(1)(b) GDPR.
4. Data Processing for Payment Transactions
Our payment processing partners include financial institutions and payment service providers.
4.1 Payment Processing
The data required for payments is transmitted to relevant payment processors. This is necessary for contract fulfillment (Art. 6(1)(b) GDPR). Some payment providers may collect this data independently; in such cases, their privacy policies apply.
4.2 Fraud Prevention and Payment Optimization
To prevent fraud and optimize payment processing (e.g., invoicing, dispute resolution), we may share relevant data with payment service providers in accordance with Art. 6(1)(f) GDPR.
5. Marketing Communications
5.1 Email Marketing
If you subscribe to our newsletter, we will use your email address for promotional messages based on your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time via the link in the email or by contacting us.
5.2 Review Requests
If you have consented, we may send you requests for order reviews via email. You may withdraw consent at any time through the provided link or by contacting us.
5.3 Phone Marketing
If you have consented to telephone marketing (Art. 6(1)(a) GDPR), we may use your phone number for promotional purposes. You can revoke this consent at any time.
6. Cookies and Tracking Technologies
6.1 General Information
We use cookies to enhance your browsing experience. Some are essential for website functionality, while others help us analyze traffic or offer personalized advertising.
6.2 Managing Cookies
Your browser settings allow you to control cookie preferences. For more details, refer to your browser’s help section.
7. Analytics and Online Advertising
If you have consented (Art. 6(1)(a) GDPR), we use tracking tools for analytics and marketing. You can withdraw consent at any time. Below are the services we utilize:
- Google Analytics – Analyzes website traffic through pseudonymized profiles.
- Google Ads – Enables targeted advertising based on site interactions.
- Facebook Pixel – Tracks conversions and remarketing campaigns.
- YouTube Plugin – Allows video content integration.
- Vimeo Plugin – Embeds videos while using Google Analytics for performance tracking.
For more details, refer to the respective providers’ privacy policies.
8. Social Media Integrations
We include links to social media platforms (Facebook, Instagram, YouTube, Pinterest), which only establish a connection if you click on them. Your data is processed by the respective platforms under their policies.
9. Your Rights
As a data subject, you have the following rights under GDPR:
- Right to access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
You also have the right to object to processing where it is based on legitimate interests (Art. 21 GDPR). If we process your data for direct marketing, you may object at any time.
10. Contact Information
For inquiries about data processing, corrections, or exercising your rights, please reach out via the contact details provided at the beginning of this policy.
This privacy policy ensures transparency in how we manage your data while complying with GDPR requirements.