Data protection declaration
Welcome to our website!
We attach maximum importance to protecting your data and safeguarding your privacy. Therefore, we provide information below regarding collection and use of personal data while using our website.
Whitewall GmbH is responsible for the processing of your data on the website www.brain-effect.com. You will find additional information on the persons responsible in the legal notices.
You can contact our data protection officers at the following address:
Berliner Allee 62-66
or send an email at email@example.com.
Unless otherwise indicated below, the provision of your personal data is neither legally binding nor contractual nor required for the conclusion of a contract. You do not have to provide your data. A refusal on your part will have no consequence. This applies only to the extent that no indication to the contrary is provided for the processing operations below.
"Personal data" means all information relating to an identified or identifiable natural person.
1. Server log files
You can use our websites without submitting personal data. Every time you access our website, user data is transmitted by your internet browser and stored in protocol files (server log fils). This stored data includes the name of the site called up, date and time of the request, amount of data transferred and the provider making the request. This data serves exclusively to ensure the smooth operation of our website and to improve our offering. It is not possible to assign this data to a particular person.
The data will be deleted as soon as it is no longer necessary for the purpose of its collection. In the case of collecting the data for the website, this is the case when the respective session is completed. In the case of storing the data in log files, this is the case after no more than seven days. An additional storage is possible. In this case, the IP addresses of the users are deleted or alienated, so the assignment of the calling client is no longer possible.
2. Collection, processing, and use of personal data
2.1 when opening a customer account
When you open a customer account, we want to collect your personal data in the scope given there. The data processing is for the purpose of improving your shopping experience and simplifying order processing. The processing will be carried out on the basis of art. 6 (1) lit. a GDPR with your consent. You can withdraw your consent at any time by contacting us. Your customer account wants to be deleted.
2.2 when you post a product review
When you comment on an article, we collect your personal data (name, email address, comment text). The processing serves to allow you to comment and to display comments. By submitting the comment you agree with the processing of the transmitted data. The processing will be carried out on the basis of art. 6 (1) lit. a GDPR with your consent. You can withdraw your consent at any time by contacting us. You personal data will then be deleted.
On publication of your comment only the name you have entered.
2.3 in orders
When you submit an order, we only collect and use your personal data where it is necessary for the fulfillment and handling of your requests. The provision of data is necessary for the conclusion of a contract. Failure to provide it will prevent the conclusion of any contract. The processing wants to occur on the basis of art. 6 (1) lit. b GDPR and is required for the fulfillment of a contract with you. We do not forward your data to third parties without your consent. These only exclude our service partners which we require in a contractual relationship. Along with the recipients named in the clauses of this data protection declaration, these include: shipping providers, payment service providers, merchandise management service providers, service providers for order processing, web hosts, IT service providers and dropshipping dealers. We want to comply strictly with legal requirements in every case. The scope of data transmission is restricted to a minimum.
All PayPal transaction are covered by the PayPal Data Privacy Statement. You can found this at https://www.paypal.com/de/webapps/mpp/ua/privacy-prev?locale.x=en_GB
Payment by direct debit, credit card or Sofortüberweisung
If we enter in advance, for example, in the case of a purchase by direct debit, credit card or Sofortüberweisung we obtain a creditworthiness information on the basis of mathematical-statistical procedures at the PAYONE GmbH & Co. KG, Fraunhoferstraße 2-4, 24118 Kiel, Germany to safeguard our legitimate interests. For this purpose, we will transmit the personal data required for a credit check to PAYONE GmbH & Co. KG and use the information received on the statistical probability of a default for a balanced decision on the establishment, implementation or termination of the contractual relationship.
The credit information can contain probability values (score values) which are calculated on the basis of scientifically recognized mathematical-statistical methods and whose calculation includes, among other things, address data. Your concerns will be considered in accordance with the statutory provisions.
3. Email newsletters and direct mail advertising
3.1 Use of your email address for mailing of newsletters
We use your email address outside of contractual processing exclusively to send you a newsletter for our own marketing purposes, if you have explicitly agreed to this. The processing will be carried out on the basis of art. 6 (1) lit. a GDPR with your consent. You can withdraw your consent at any time without affecting the legality of the processing carried out with your consent up to the withdrawal. You can unsubscribe from the newsletter at any time using the relevant link in the newsletter or by contacting us. Your email address will then be removed from the distributor.
Your data will be forwarded to a service provider for email marketing in the course of order processing. It will not be forwarded to other third parties.
The newsletter is distributed via MailChimp, a newsletter distribution platform of Rocket Science Group, LLC, 675 Ponce de Leon Ave. NE, Suite 5000, Atlanta, GA 30308 USA. The e-mail addresses of our newsletter recipients and, if applicable, other data collected in connection with the newsletter dispatch are stored on the servers of MailChimp in the USA. MailChimp uses this information for sending and evaluating the newsletters on behalf of BRAINEFFECT. Furthermore, MailChimp may use this information for the purpose of optimizing or improving its own services. However, MailChimp does not use the data of our newsletter recipients to contact them or to pass them on to third parties. MailChimp is certified under the US-EU Privacy Shield, and is committed to complying with EU data protection requirements. In addition, Whitewall GmbH has entered into a 'Data Processing Agreement' with MailChimp on the basis of the EU standard contractual clauses. In it, MailChimp commits to protect the data of our users, to process in accordance with the data protection regulations provided therein and to not passing them on to third parties. The content of this contract can be viewed at the following link: https://mailchimp.com/legal/forms/data-processing-agreement/sample-agreement/
3.2 Use of your email address for mailing of direct marketing
We use your email address, which we obtained in the course of selling a good or service, for the electronic transmission of marketing for our own goods or services which are similar to those you have already purchased from us, unless you have objected to this use. You must provide your email address in order to conclude a contract. Failure to provide it will prevent the conclusion of any contract. The processing will be carried out on the basis of art. 6 (1) lit. f GDPR due to our justified interest in direct marketing. You can object to this use of your email address at any time by contacting us. You will find the contact details for exercising your right to object in our imprint. You can also use the link provided in the marketing email. This will not involve any costs other than transmission costs at basic tariffs. The dispatch of the advertising e-mails also takes place via MailChimp (see Mailchimp notes under 3.1).
3.3 Direct mail advertising and your right to object
In addition, we reserve the right to use your first and last name as well as your postal address for our own advertising purposes, e.g. to send interesting offers and information about our products by letter. This serves to safeguard our legitimate interests, which are predominantly justified in the context of a weighing up of interests, in a promotional approach by our customers in accordance with Art. 6 (1) lit. f GDPR.
4. Integration of the Trusted Shops Trustbadge
Following an order, the Trusted Shops Trustbadge is incorporated into this web page in order to display our Trusted Shops trustmark for buyers and the eventually collected reviews, as well as the Trusted Shops product offer.
In balancing the various interests, this serves to safeguard our legitimate prevailing interests in an optimised marketing of our offer. The Trustbadge and the services advertised are an offer of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Köln.
Whenever a Trustbadge is called up, the web server automatically stores a so-called server log file which contains, for example, your IP address, the date and time of retrieval, the data volume transferred and the requesting provider (access data), and documents the retrieval. This access data will not be evaluated and will be automatically overwritten seven days after your visit to the page.
Other personal information will only be transferred to Trusted Shops if you decide, after completing an order, to use Trusted Shops products or have already registered for their use. In this case, the contractual agreement between you and Trusted Shops applies.
5. Cookies, Webanalytics and Remarketing
Processing is carried out on the basis of § 15 (3) TMG (Telemedia Act) as well as art. 6 (1) lit. f GDPR due to our justified interest in the purposes above.
Using the links below, you can find out how to manage cookies (or deactivate them, among other things) in major browsers:
- Chrome Browser: https://support.google.com/accounts/answer/61416?hl=en
- Internet Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
- Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac
5.2 Use of Google Analytics
5.3 Use of the remarketing or "similar target groups" function by Google Inc.
5.4 Use of Google Adwords conversion tracking
Our website uses the online marketing programme "Google AdWords", including conversion tracking. Google conversion tracking is a service operated by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). If you click on adverts placed by Google, a cookie is placed on your computer for conversion tracking. These cookies have limited validity, do not contain any personal data and thus cannot be used for personal identification. If you visit certain pages on our website and the cookie has not yet expired, we and Google can recognise that you have clicked on the advert and were forwarded to this page. Every Google AdWords customer receives a separate cookie. Therefore, it is not possible to track cookies relating to the websites of AdWords customers. The information collected using the conversion cookie serves the purpose of producing conversion statistics. This allows us to find out the total number of users who have clicked on our adverts and were forwarded to a page equipped with a conversion tracking tag. However, they do not receive any information with which could be used to personally identify users. Processing is carried out on the basis of art. 6 (1) lit. f GDPR due to our justified interest in targeted marketing and analysis of the effectiveness and efficiency of this marketing.
You will find more information as well as Google's data protection declaration at: https://www.google.de/policies/privacy/
5.5 Use of Bing Ads (Microsoft Corporation)
This site uses Microsoft's Bing Ads conversion tracking technology (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA). Microsoft Bing Ads places a cookie on your computer if you have accessed our website via a Microsoft Bing ad. Cookies are small text files that are stored on your computer system. These cookies lose their validity after 180 days and are not used for personal identification. If the user visits certain pages on this site and the cookie has not expired yet, Microsoft and we can recognize that the user clicked on the ad and was redirected to that page (conversion page). If personal data is processed in this context, this is done in accordance with Art. 6 (1) lit. f DSGVO due to our legitimate interest in effective marketing.
The information obtained using the conversion cookie is used to generate conversion statistics, i.e. track how many users reach a conversion page after clicking on an ad. It tells us the total number of users who clicked on our ad and were redirected to a conversion tracking tag page. However, we do not receive any information that personally identifies users.
US-based Microsoft Corporation is certified under the US Privacy Shield, which ensures compliance with the level of data protection in the EU.
If you do not want to participate in tracking, you can opt out by easily disabling the Bing Ads Conversion Tracking cookie through its Internet browser under User Preferences. You will not be included in the conversion tracking statistics. Alternatively, using the EU opt-out site http://www.youronlinechoices.com/uk/your-ad-choices/, you can verify that Microsoft advertising cookies are set in your browser and disable them. For more information about the privacy practices of Microsoft Bing Ads, visit the following Internet address: https://privacy.microsoft.com/en-us/privacystatement
5.6 Use of Facebook remarketing
Our website uses the remarketing function "Custom Audiences" by Facebook Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA; "Facebook").This function serves to address the visitor to the website with interest-related advertising on the social network Facebook. We have implemented Facebook's remarketing tag on our website for this purpose. This tag sets up a direct connection to Facebook's servers when you visit our website. This informs the Facebook server which of our web pages you have visited. Facebook assigns this information to your personal Facebook user account. When you visit the social network Facebook you will then be shown personalised, interest-related Facebook ads. Processing is carried out on the basis of art. 6 (1) lit. f GDPR due to our justified interest in the above purpose.
You have the right to veto this processing of your personal data according to art. 6 (1) lit. f GDPR by contacting us, for reasons relating to your personal situation.
6. Tools and Plugins
6.1 Use of Hotjar
We use Hotjar, an analysis software of Hotjar Ltd. (Hotjar Ltd, Level 2, St Julian's Business Center, 3, Elia Zammit Street, St Julian's STJ 1000, Malta). With Hotjar it is possible to measure and evaluate the usage behavior (clicks, mouse movements, scroll heights, etc.) on the website www.brain-effect.com. It is also possible to use the tool to get feedback directly from users of the www.brain-effect.com website.
When using this tool, Whitewall GmbH pays special attention to the protection of your personal data. Thus, Whitewall GmbH only has access to the information on which buttons are clicked, the mouse's progress, how far scrolled, the screen size of the device, device type and browser information, geographic viewpoint (country only) and preferred language to represent our website. Areas of the website www.brain-effect.com in which personal data of you or third parties are displayed are automatically hidden by Hotjar and are therefore at no time traceable.
Hotjar offers every user the option of using a "Do Not Track header" to prevent the use of the tool Hotjar, so that no data on the visit of the respective website are recorded. This is a setting that supports all common browsers in current versions. For this, your browser sends a request to Hotjar, with the hint to disable the tracking of the respective user. If you use the website www.brain-effect.com with different browsers/computers, you must set up the "Do Not Track header" for each of these browsers/computers separately.
If you want to object to the use of Hotjar, you can opt out at the following link: https://www.hotjar.com/opt-out
6.2 Use of SumoMe
6.3 Using SoundCloud
On our pages plugins of the social network SoundCloud (SoundCloud Limited, Berners House, 47-48 Berners Street, London W1T 3NF, United Kingdom.) may be integrated. The SoundCloud plugins can be recognized by the SoundCloud logo on the affected pages.
When you visit our pages, a direct connection is established between your browser and the SoundCloud server after activation of the plugin. SoundCloud receives the information that you have visited our site with your IP address. If you click the "Like" or "Share" button while logged into your SoundCloud account, you may link and / or share the contents of our pages with your SoundCloud profile. This allows SoundCloud to associate your account with our pages. We point out that we as the provider of the pages are not aware of the content of the transmitted data and their use by SoundCloud. For more information, see the SoundCloud Privacy Statement at https://soundcloud.com/pages/privacy
If you do not want Soundcloud to associate the visit to our pages with your SoundCloud user account, please log out of your SoundCloud user account before enabling content from the SoundCloud plugin.
7. Using Sleeknote ApS
8. Links to third party websites
9. Duration of storage
After contractual processing has been completed, the data is initially stored for the duration of the warranty period, then in accordance with the retention periods prescribed by law, especially tax and commercial law, and then deleted after the period has elapsed, unless you have agreed to further processing and use.
10. Rights of the affected person
If the legal requirements are fulfilled, you have the following rights according to art. 15 to 20 GDPR: Right to information, correction, deletion, restriction of processing, data portability. You also have a right of objection against processing based on art. 6 (1) GDPR, and to processing for the purposes of direct marketing, according to art. 21 (1) GDPR.
You have the right to complain to the regulatory authority according to art. 77 GDPR if you believe that your data is not being processed legally.
For questions about the collection, processing or use of your personal data, information, correction, blocking or deletion of data and revocation of any given consent or objection to a particular use of data, please contact our company data protection officer at
Berliner Allee 62-66
Last update: 26.03.2020