Privacy policy

Responsible for data processing:
AnYa UG (haftungsbeschränkt)
Silcherstr. 14/1
75203 Königsbach-Stein

Email: legal@anya-international.com

We are pleased about your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data.

1. Access Data and Hosting

You can visit our websites without providing any personal information. Each time a webpage is accessed, the web server automatically stores a so-called server log file, which includes, for example, the name of the requested file, your IP address, the date and time of access, the amount of data transmitted, and the requesting provider (access data). These access data are collected solely to ensure the smooth operation of the website and to improve our offering. This serves to protect our legitimate interests in presenting our offer correctly according to Article 6, Section 1, Sentence 1, letter f of the GDPR. All access data will only be processed as long as necessary for the above-mentioned purposes.

The services for hosting and displaying the website are partly provided by our service providers in the context of processing on our behalf. Unless otherwise explained in this privacy policy, all access data and all data collected in designated forms on this website are processed on their servers. For questions about our service providers and the basis for our cooperation with them, please contact the provided contact information in this privacy policy.

Our service providers are located and/or use servers in the following countries, for which the European Commission has determined an adequate level of data protection: Israel, United Kingdom, USA.

The adequacy decision for the USA serves as the basis for the transfer to third countries, provided that the respective service provider is certified. Certification is in place.

Our service providers are located and/or use servers in these countries: Brazil, Mexico, India, Ukraine.
For these countries, the European Commission has not issued an adequacy decision. Our cooperation with them is based on these guarantees: Standard contractual clauses of the European Union.


2. Data Processing for Contract Execution and Contact

2.1 Data Processing for Contract Execution

For the purpose of contract execution (including inquiries and handling of any warranty and performance claims, as well as potential legal update obligations) according to Article 6, Section 1, Sentence 1, letter b of the GDPR, we collect personal data when you voluntarily provide this information during your order. Mandatory fields are marked as such because we require this data to execute the contract, and we cannot process the order without it. The specific data collected is visible in the respective input forms.

Further information on the processing of your data, particularly regarding the transfer to our service providers for order, payment, and shipping processing, can be found in the following sections of this privacy policy. After the contract has been fully processed, your data will be restricted for further processing and deleted after the tax and commercial law retention periods expire according to Article 6, Section 1, Sentence 1, letter c of the GDPR, unless you have explicitly consented to further use of your data according to Article 6, Section 1, Sentence 1, letter a of the GDPR or we reserve a further use of data which is legally permitted and about which we inform you in this statement.

2.2 Customer Account

If you consent under Article 6, Section 1, Sentence 1, letter a of the GDPR by choosing to open a customer account, we will use your data for the purpose of creating the customer account and storing your data for future orders on our website. Deleting your customer account is possible at any time, either by sending a message to the contact information provided in this privacy policy or through a function provided in the customer account. After the deletion of your customer account, your data will be deleted unless you have explicitly consented to further use of your data according to Article 6, Section 1, Sentence 1, letter a of the GDPR or we reserve further use of data, which is legally permitted and about which we inform you in this policy.

2.3 Contact

In the course of customer communication, we collect personal data for processing your inquiries according to Article 6, Section 1, Sentence 1, letter b of the GDPR when you voluntarily provide us with this information during contact (e.g., via contact form, live chat tool, or email). Mandatory fields are marked as such, as we require this data to process your inquiry. The data collected can be seen in the respective input forms. After your inquiry has been fully processed, your data will be deleted unless you have explicitly consented to further use of your data according to Article 6, Section 1, Sentence 1, letter a of the GDPR or we reserve a further use of data, which is legally permitted and about which we inform you in this policy.

3. Data Processing for Shipping Fulfillment

 

For contract fulfillment according to Article 6, Section 1, Sentence 1, letter b of the GDPR, we forward your data to the shipping service provider tasked with the delivery, to the extent necessary for the delivery of ordered goods. For questions about our service providers and the basis for our cooperation with them, please contact the contact information provided in this privacy policy.

The same applies to the transfer of data to our manufacturers or wholesalers when they handle shipping for us (drop shipping). These are considered shipping service providers under this privacy policy.

Our service providers are located and/or use servers in the following countries: China.
For these countries, the European Commission has not issued an adequacy decision. Our cooperation with them is based on these guarantees: Standard contractual clauses of the European Commission.

Data Transfer to Shipping Service Providers for Shipment Notification

If you have given us explicit consent during or after your order, we will transfer your email address to the selected shipping service provider in accordance with Article 6, Section 1, Sentence 1, letter a of the GDPR, so that they can contact you for delivery notification or coordination before delivery.

Consent can be revoked at any time by sending a message to the contact information described in this privacy policy or directly to the shipping service provider at the contact address listed below. After revocation, we will delete the data provided for this purpose, unless you have explicitly consented to further use of your data or we reserve further use of data, which is legally permitted and about which we inform you in this policy.

General Logistics Systems Germany GmbH & Co. OHG
GLS Germany-Straße 1 - 7
DE-36286 Neuenstein
Deutschland

United Parcel Service Deutschland S.à r.l. & Co. OHG
Görlitzer Straße 1
41460 Neuss
Deutschland

Hermes Germany GmbH
Essener Straße 89
D-22419 Hamburg
Deutschland

DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Deutschland

DPD Deutschland GmbH
Wailandtstraße 1
63741 Aschaffenburg
Deutschland

Cainiao
No. 501 Fengxin Road, Yuhang District
311121 Hangzhou, Zhejiang Province
China

Our service providers are located and/or use servers in these countries: China. There is no adequacy decision from the European Commission for these countries. Our cooperation with them is based on the following guarantees: Standard contractual clauses of the European Commission.

4. Data Processing for Payment Processing

In the processing of payments in our online shop, we work with the following partners: technical service providers, credit institutions, and payment service providers.

4.1 Data Processing for Transaction Processing

Depending on the selected payment method, we forward the necessary data for processing the payment transaction to our technical service providers who act on our behalf or to the commissioned credit institutions or the selected payment service provider, as far as necessary for payment processing. This serves to fulfill the contract according to Article 6, Section 1, Sentence 1, letter b of the GDPR.

4.2 Data Processing for Fraud Prevention and Payment Process Optimization

If necessary, we provide our service providers with additional data, which they use along with the necessary data for processing the payment, to prevent fraud and optimize our payment processes (e.g., invoicing, handling disputed payments, supporting accounting). This serves according to Article 6, Section 1, Sentence 1, letter f of the GDPR to protect our legitimate interests in preventing fraud and ensuring efficient payment management.

5. Cookies and Other Technologies

 General Information

To make the visit to our website attractive and to enable certain features, we use technologies including cookies. Cookies are small text files that are automatically stored on your device. Some cookies we use are deleted after the browser session, i.e., after you close your browser (session cookies). Other cookies remain on your device and allow us to recognize your browser during your next visit (persistent cookies).

Privacy Protection on End Devices

When using our online offer, we use essential technologies to provide the requested telemedia service. Storing information on your device or accessing information already stored on your device does not require consent.

For non-essential functions, the storage or access of information on your device requires your consent. Please note that if consent is not given, certain parts of the website may not be fully functional.

Cookies and Further Technologies for Data Processing

We use technologies required for certain features of our website (e.g., shopping cart function). These technologies collect and process IP addresses, visit times, device and browser information, and information about how you use our website (e.g., information about the shopping cart content). This serves to optimize the presentation of our offer in accordance with our legitimate interests according to Article 6, Section 1, Sentence 1, letter f of the GDPR.

We also use technologies to fulfill legal obligations (e.g., to document consents to the processing of personal data) and for web analysis and online marketing. Further details on this, including the legal basis for the data processing, are provided in the subsequent sections of this privacy policy.


Cookie Settings

You can find the cookie settings for your browser at the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™

If you have consented to the use of technologies in accordance with Art. 6 (1) Sentence 1 lit. a GDPR, you can withdraw your consent at any time by sending a message to the contact option described in the privacy policy.

6. Use of Cookies and Other Technologies

We use the following cookies and other technologies from third parties on our website. Unless otherwise stated for each technology, this is done based on your consent according to Article 6 (1) sentence 1 (a) of the GDPR. After the purpose no longer applies and the use of the respective technology ends, the data collected in this context will be deleted. You can withdraw your consent at any time with effect for the future. For more information on how to withdraw your consent, please refer to the section "Cookies and Other Technologies". Further information, including the basis of our cooperation with individual providers, can be found in the details of each technology. If you have any questions regarding the providers and the basis of our cooperation with them, please contact us using the contact details provided in this privacy policy.

6.1 Use of Google Services

We use the technologies listed below from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information automatically collected by Google technologies about your use of our website is typically transmitted to and stored on a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Unless otherwise stated for each technology, data processing is based on an agreement between joint controllers in accordance with Article 26 of the GDPR. Further information on data processing by Google can be found in Google's privacy policy. Google's privacy policy.

Our service providers are located in and/or use servers in countries outside the EU and the EEA, for which the European Commission has determined an adequate level of data protection.

Our service providers are located in and/or use servers in countries outside the EU and the EEA. For these countries, no adequacy decision has been made by the European Commission. Our cooperation with them is based on the European Commission’s standard contractual clauses.

 Google Analytics

For website analysis, Google Analytics automatically collects and stores data (IP address, time of visit, device and browser information, and information about your use of our website), from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. If you visit our website from the EU, your IP address is stored on a server within the EU to derive location data, and then immediately deleted before traffic is forwarded for processing on Google's other servers. Data processing is based on an agreement on data processing by Google.

For the purpose of optimizing the marketing of our website, we have enabled the data sharing settings for "Google Products and Services." This allows Google to access the data collected and processed by Google Analytics and subsequently use it to improve Google services. The data sharing with Google under these settings is based on an additional agreement between the controllers. We have no influence over the subsequent data processing by Google.

To optimize the marketing of our website, we use the so-called User-ID feature. With this feature, we can assign a unique, permanent ID to your interaction data across one or more sessions on our online platforms and analyze your user behavior across devices and sessions.

Through the Google Analytics extension, Google Signals enables "Cross-Device Tracking." If your internet-enabled devices are linked to your Google account and you have enabled the "personalized advertising" setting in your Google account, Google can generate reports about your usage behavior (especially cross-device user numbers), even if you change your device. We do not process personal data in this regard; we only receive statistics generated by Google Signals.

For web analysis and advertising purposes, the Google Analytics extension uses the so-called DoubleClick cookie, which enables recognition of your browser when visiting other websites. Google will use this information to compile reports on website activities and provide other services related to website usage.

If you do not consent to the use of Google Analytics in accordance with Article 6 (1) sentence 1 (a) of the GDPR, no cookies will be stored or read on your device. The data processing described above will not take place. To fill gaps in web analysis through behavioral and conversion modeling, pings with data (User-Agent, information about your consent behavior, screen resolution, IP address) are sent to Google.

 Google AdSense

Our website markets ad space for third-party ads through Google AdSense. These ads will be shown to you at various locations on this website. The so-called DoubleClick cookie enables interest-based advertising by collecting and processing data (IP address, time of visit, device and browser information, and information about your use of our website), as well as automatically assigning a pseudonymous user ID, which helps determine interests based on visits to this and other websites.

 Google reCAPTCHA

To protect against abuse of our web forms and against spam by automated software (so-called bots), Google reCAPTCHA collects data (IP address, time of visit, browser information, and information about your use of our website) and analyzes your use of our website using JavaScript and cookies. In addition, other cookies stored by Google services in your browser are evaluated. No personal data is read or stored from the input fields of the respective form.

 Google Tag Manager

With Google Tag Manager, we can manage various codes and services on our website. When implementing individual tags, Google may also process personal data (e.g., IP address, online identifiers (including cookies)). Data processing is based on an agreement for data processing by Google.

By using the Google Tag Manager, integration of different services/technologies can be achieved. If you do not wish to use certain tracking services and have disabled them, the deactivation remains for all affected tracking tags integrated through the Google Tag Manager.

6.2 Use of Microsoft Services

We use the technologies described below from Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland ("Microsoft"). Data processing is based on an agreement between joint controllers in accordance with Article 26 of the GDPR. The information automatically collected by Microsoft technologies about your use of our website is typically transmitted to and stored on a server of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Further information on data processing by Microsoft can be found in Microsoft's privacy policy.

Our service providers are located in and/or use servers in countries outside the EU and the EEA, for which the European Commission has determined an adequate level of data protection.

Our service providers are located in and/or use servers in countries outside the EU and the EEA. For these countries, no adequacy decision has been made by the European Commission. Our cooperation with them is based on the European Commission’s standard contractual clauses.

 Microsoft Advertising

For advertising purposes in Bing, Yahoo, and MSN search results, as well as on third-party websites, the so-called Microsoft Advertising Remarketing Cookie is set when you visit our website, automatically collecting and processing data (IP address, time of visit, device and browser information, and information about your use of our website) and enabling interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited.

For website analysis and event tracking, we measure your subsequent usage behavior using Microsoft Advertising Universal Event Tracking (UET) when you arrive at our website via a Microsoft Advertising ad. Cookies may be used, and data (IP address, time of visit, device and browser information, and information about your use of our website based on predefined events such as visiting a website or subscribing to a newsletter) is collected, from which usage profiles are created using pseudonyms. If your internet-enabled devices are linked to your Microsoft account and you have not disabled the "Interest-Based Advertising" setting in your Microsoft account, Microsoft can generate reports about your usage behavior (especially cross-device user numbers), even if you change your device, so-called "Cross-Device Tracking." We do not process personal data in this regard; we only receive statistics generated by Microsoft UET.

We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve and market our products/services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of products/services and online activity. Additionally, we use this information for site optimization, fraud/security purposes, and advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.


6.3 Use of Facebook Services

 Use of Facebook Pixel

We use the Facebook Pixel within the technologies described below from Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Irland („Facebook (by Meta)“ or “Meta Platforms Ireland“). 

The Facebook Pixel automatically collects and stores data (IP address, time of visit, device and browser information, and information about your use of our website based on predefined events such as visiting a website or subscribing to a newsletter), from which usage profiles are created using pseudonyms. As part of the so-called extended data matching, information for matching purposes is additionally collected and stored in a hashed form, with which individuals can be identified (e.g., names, email addresses, and phone numbers). For this purpose, a cookie is automatically set when you visit our website, enabling the recognition of your browser when visiting other websites using a pseudonymous cookie ID. Facebook (by Meta) will merge this information with other data from your Facebook account and use it to generate reports about website activities and provide other services related to website usage, especially personalized and group-based advertising.

The information automatically collected by Facebook (by Meta) technologies about your use of our website is typically transmitted to and stored on a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA. Further information on data processing by Facebook (by Meta) can be found in the privacy policy of Facebbok (by Meta).

Our service providers are located in and/or use servers in the following countries, for which the European Commission has determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.

The adequacy decision for the USA serves as the basis for data transfers to third countries, as long as the respective service provider is certified. Certification is available.

Our service providers are located in and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico. For these countries, no adequacy decision by the European Commission exists. Our cooperation with them relies on these safeguards: Standard data protection clauses of the European Commission.

 Facebook Analytics

As part of the Facebook Business Tools, statistics about visitor activities on our website are created from the data collected by the Facebook Pixel regarding your usage of our website. The data processing is carried out based on a data processing agreement with Facebook (by Meta). This analysis serves the purpose of optimizing the presentation and marketing of our website.

7. Social Media

7.1 Social Buttons from Facebook (by Meta), X (formerly: Twitter), Instagram (by Meta), Pinterest

Our website uses social buttons from social networks. These are merely embedded as HTML links into the page, so no connection to the servers of the respective provider is established when you visit our website. When you click on one of the buttons, the respective social network's website opens in a new window of your browser. There, you can, for example, press the Like or Share button.

7.2 Our Online Presence on Facebook (by Meta), X (formerly: Twitter), Instagram (by Meta), YouTube, Pinterest

If you have given your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR to the respective social media operator, your data will be automatically collected and stored when you visit our online presence on the mentioned social media platforms for market research and advertising purposes. Pseudonymized usage profiles will be created from this data, which can be used to display ads that likely match your interests within and outside the platforms. Usually, cookies are used for this purpose. For detailed information on the processing and use of data by the respective social media operator, as well as contact details and your rights and privacy protection settings, please refer to the privacy notices of the providers linked below. If you need assistance with this, you can contact us.

Facebook (by Meta) is provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The data automatically collected by Meta Platforms Ireland about your use of our Facebook (by Meta) online presence is generally transmitted to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, California 94025, USA, and stored there. Data processing in connection with visiting a Facebook (by Meta) fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. For further information (Information on Insights data), please see here.

Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.

The adequacy decision for the USA serves as the basis for the transfer to third countries, provided that the respective service provider is certified. Certification is in place.

Our service providers are based in and/or use servers in the following countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
For these countries, there is no adequacy decision from the European Commission. Our cooperation with them is based on the following safeguards: standard contractual clauses of the European Commission.

X is offered by Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland (“X”). The data automatically collected by X about your use of our online presence on X is generally transmitted to a server of X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, and stored there.

Our service providers are based in and/or use servers in countries outside the EU and the EEA, for which the European Commission has determined an adequate level of data protection.

Our service providers are based in and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision from the European Commission. Our cooperation with them is based on the European Commission's standard contractual clauses.

Instagram (by Meta) is provided by Meta Platforms Ireland Ltd., Block J, Serpentine Avenue, Dublin 4, Ireland (“Meta Platforms Ireland”). The data automatically collected by Meta Platforms Ireland about your use of our Instagram (by Meta) online presence is generally transmitted to a server of Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA, and stored there. Data processing in connection with visiting an Instagram (by Meta) fan page is based on an agreement between joint controllers pursuant to Art. 26 GDPR. For further information (Information on Insights data), please see here.

Our service providers are based in and/or use servers in the following countries, for which the European Commission has determined an adequate level of data protection: USA, Canada, Japan, South Korea, New Zealand, United Kingdom, Argentina.

The adequacy decision for the USA serves as the basis for data transfers to third countries, provided that the respective service provider is certified. Certification is in place.

Our service providers are based in and/or use servers in these countries: Australia, Hong Kong, India, Indonesia, Malaysia, Singapore, Thailand, Taiwan, Brazil, Mexico.
For these countries, there is no adequacy decision from the European Commission. Our cooperation with them is based on the following safeguards: the European Commission's standard contractual clauses.

YouTube is offered by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). The data automatically collected by Google about your use of our online presence on YouTube is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, and stored there.

Our service providers are based in and/or use servers in countries outside the EU and the EEA, for which the European Commission has determined an adequate level of data protection.

Our service providers are based in and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision from the European Commission. Our cooperation with them is based on the European Commission's standard contractual clauses.

Pinterest is provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland (“Pinterest”). The data automatically collected by Pinterest about your use of our online presence on Pinterest is generally transmitted to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA, and stored there.

 Our service providers are based in and/or use servers in countries outside the EU and the EEA, for which the European Commission has determined an adequate level of data protection by decision.

Our service providers are based in and/or use servers in countries outside the EU and the EEA. For these countries, there is no adequacy decision from the European Commission. Our cooperation with them is based on the European Commission's standard contractual clauses.

8. Contact Options and Your Rights

8.1 Your Rights

As a data subject, you have the following rights:

  • According to Art. 15 GDPR, the right to request information about the personal data we process about you to the extent specified therein;
  • According to Art. 16 GDPR, the right to request the correction of incorrect or completion of your personal data stored with us;
  • According to Art. 17 GDPR, the right to request the deletion of your personal data stored with us, unless further processing is necessary for:
    • the exercise of the right to freedom of expression and information;
    • compliance with a legal obligation;
    • reasons of public interest; or
    • the establishment, exercise, or defense of legal claims;
  • According to Art. 18 GDPR, the right to request the restriction of processing of your personal data, to the extent that:
    • the accuracy of the data is contested by you;
    • the processing is unlawful, but you oppose its deletion;
    • we no longer need the data, but you require it for the establishment, exercise, or defense of legal claims; or
    • you have objected to the processing pursuant to Art. 21 GDPR;
  • According to Art. 20 GDPR, the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format, or to request its transmission to another controller;
  • According to Art. 77 GDPR, the right to file a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your habitual residence, place of work, or our company’s headquarters.

Right to Object

If we process personal data based on a legitimate interest, you have the right to object to such processing with effect for the future. If the processing is for direct marketing purposes, you can exercise this right at any time as described above. For other processing purposes, you may object only for reasons arising from your particular situation.

After exercising your right to object, we will no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing is necessary for the establishment, exercise, or defense of legal claims.

This does not apply if the processing is for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.

8.2 Contact Options

If you have questions regarding the collection, processing, or use of your personal data, or if you wish to request information, correction, restriction, or deletion of data, or withdraw previously given consents or object to specific data processing, please contact us directly using the contact details in our imprint.