0 Cart
0 Add all flipped products to cart Flipped

Privacy policy

Privacy Policy
 
1 DATA PROCESSING CENTER
 
The protection of your personal data is very important to us. Therefore, we would like to inform you below which data of your visit are used for which purposes.
 
Constant technological development, changes in our services or the legal situation as well as other reasons may require adjustments to our privacy policy. We therefore reserve the right to change this privacy policy at any time and ask you to be informed regularly about the current status.
 
In principle, we collect and use personal data of our users only insofar as this is necessary for the provision of a functional website and our content and services as well as for the implementation of our corporate purpose. The collection and use of personal data of our users takes place regularly only with the consent of the user. Exceptions apply in cases where prior consent cannot be obtained for real reasons and the processing of the data is permitted by law.
 
1.2 PURPOSE AND LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA
 
We process personal data only to fulfill our contractual obligations or to safeguard our overriding legitimate interests. Our legitimate interests are based on the implementation of our corporate purpose.
 
Insofar as we obtain the consent of the data subject for processing of personal data, Art. 6 para. 1 p. 1 lit. a EU General Data Protection Regulation (GDPR) as the legal basis for the processing of personal data.
 
In the processing of personal data necessary for the performance of a contract to which the data subject is a party, Art. 6 para. 1 p. 1 lit. b DSGVO as legal basis. This also applies to processing operations required to carry out pre-contractual actions.
 
Insofar as processing of personal data is required to fulfill a legal obligation that is subject to our company, Art. 6 para. 1 p. 1 lit. c DSGVO as legal basis.
 
In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 sentence 1 lit. d DSGVO as legal basis.
 
If processing is necessary to safeguard the legitimate interests of our company or a third party and if the interests, fundamental rights and fundamental freedoms of the data subject do not outweigh the former interest, Art. 6 para. 1 sentence 1 lit. f DSGVO as legal basis for processing.
 
1.3 CATEGORIES OF RECIPIENTS AND PERSONAL DATA, ORIGIN OF THE SAME DATA TRANSMISSION
 
We pass on personal data for the implementation of our corporate purpose to our business partners and service providers. To implement our corporate purpose, we typically use contact and address data of our customers and business partners. We typically receive the personal data directly from the person concerned or with the consent of the person concerned, even in exceptional cases from third parties.
 
Unless otherwise stated in the following sections, your data will not be transmitted to third parties, unless we are legally obliged to do so, or the data transfer is necessary to implement the contractual relationship or you have expressly consented to the forwarding of your data , External service providers and partner companies such as online payment providers or the shipping company commissioned with the delivery will only receive your data if this is necessary for processing your order. In these cases, however, the amount of data transmitted is limited to the minimum required. As far as our service providers come into contact with your personal data, we make sure that they comply with the rules of data protection laws in the same way. Please also note the respective privacy policy of the provider. The respective service provider is responsible for the content of external services, where we check the reasonableness of the services for compliance with legal requirements.
 
1.4 DATA SECURITY
 
We have taken extensive technical and operational safeguards to protect your data from accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security procedures are regularly reviewed and adapted to technological progress.
 
1.5 DATA DELETION AND STORAGE TIME
 
The personal data of the data subject will be deleted or blocked as soon as the purpose of the storage is deleted. In addition, such storage may take place if provided for by the European or national legislator in EU regulations, laws or other regulations to which the controller is subject. Blocking or deletion of the data also takes place when a storage period prescribed by the standards mentioned expires, unless there is a need for further storage of the data for conclusion of a contract or fulfillment of the contract.
 
2 GENERAL DATA COLLECTION WHEN CALLING OUR WEBSITE
 
In the case of merely informative use of the website, ie if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server.
 
As part of the balance of interests under Art. 6 para. 1 p. 1 lit. f DSGVO, we have considered and balanced our interest in the provision and your interest in the processing of your personal data in accordance with data protection. Since the following data for the provision of our service is technically necessary in order to provide you with our website and also to ensure the stability and security, in particular, to provide protection against misuse, we have come to the conclusion that this data - at one stand technically oriented data security guarantee, while taking due account of your interest in privacy-compliant processing.
 
Description and scope of data collection
 
Each time our website is accessed, our system automatically collects data and information from the computer system of the calling computer.
 
The following data is collected here:
 
Information about the browser type and version used
 
The operating system and user interface
 
The Internet service provider of the user
 
The IP address of the user
 
Access Status / HTTP status code
 
Date and time of access
 
Time zone difference to Greenwich Mean Time
 
Content of the request (specific website)
 
each transmitted amount of data
 
Websites from which the system of the user comes to our website
 
Websites that are accessed by the user's system through our website
 
For mobile devices: manufacturer and type designation of smartphones, tablets or other mobile devices
 
Low-level Tracer
 
The data is also stored in the log files of our system. A storage of this data together with other personal data of the user does not take place.
 
Legal basis of data processing
 
The legal basis for the temporary storage of data and log files is Art. 6 para. 1 p. 1 lit. f DSGVO.
 
Purpose of data processing
 
The temporary storage of the IP address by the system is necessary to allow delivery of the website to the computer of the user. To do this, the user's IP address must be kept for the duration of the session.
Storage in log files is done to ensure the functionality of the website. In addition, the data is used to optimize the website and to ensure the security of our information technology systems. In particular, they help us to adapt our website and our other information technology systems to the browsers, operating systems and devices used.
An evaluation of the data for marketing purposes does not take place in this context.
 
For these purposes, our legitimate interest in the processing of data according to Art. 6 para. 1 p. 1 lit. f DSGVO.
 
Duration of storage
 
The data will be deleted as soon as it is no longer necessary for the purpose of its collection. In the case of collecting the data for providing the website, this is the case when the respective session is completed.
In the case of storing the data in log files, this is the case after no more than seven days. An additional storage is possible. In this case, the IP addresses of the users are deleted or alienated, so that an assignment of the calling client is no longer possible.
 
Opposition and removal possibility
 
The collection of data for the provision of the website and the storage of the data in log files is essential for the operation of the website. There is consequently no contradiction on the part of the user.
 
3 REGISTRATION
 
On our website, we offer users the opportunity to register by providing personal information. The data is entered into an input mask and transmitted to us and stored. A transfer of data to third parties does not take place. The following data is collected during the registration process:
 
salutation
 
Academic title (optional)
 
first given name
 
Surname
 
e-mail
 
password
 
address
 
phone number
 
Company (optional)
 
country
 
At the time of registration, the following data is also stored:
 
The IP address of the user
 
Date and time of registration
 
customer number
 
Entity ID
 
E-mail hash
 
As part of the registration process, the consent of the user to process this data is obtained. After registration, you will receive a personal, password-protected access and can view and manage the data you have stored. Registration is voluntary but may be required to use our services.
 
Legal basis for data processing
 
Legal basis for the processing of the data is in the presence of the consent of the user Art. 6 para. 1 p. 1 lit. a GDPR.
 
If the registration serves the fulfillment of a contract of which the user is a party or the implementation of pre-contractual measures, an additional legal basis for the processing of the data is Art. 6 para. 1 p. 1 lit. b DSGVO.
 
Purpose of data processing
 
Registration of the user is required for the provision of certain content and services, in particular the extended use of our webshop on our website.
 
A registration of the user additionally serves to fulfill a contract with the user or to carry out pre-contractual measures. The registration particularly refers to the use of our webshop.
 
Typically, purchase agreements for the following product groups are concluded via the webshop:
 
CBD Products
Vaporizer, E-cigarettes and Liquids
Bongs and Pipes
Accessories and Gadgets
 
Duration of storage
 
The data will be deleted as soon as it is no longer necessary for the purpose of its collection.
 
This is the case for the data collected during the registration process when the registration on our website is canceled or modified.
 
Insofar as the data collected during the registration process are required to fulfill a contract or to carry out pre-contractual measures, this will only be the case if the data are no longer necessary for the execution of the contract. Even after the conclusion of the contract, there may be a need to store personal data of the contracting party in order to comply with contractual or legal obligations.
 
Personal data is stored for fraud prevention purposes.
 
Deletion deadlines for fraud prevention purposes are 6 months and 6 months for actual fraud attempts.
 
Opposition and removal possibility
 
As a user, you have the option of canceling the registration at any time. You can change the data stored about you at any time.
 
You can request  a deletion or modification of your data by sending us an e-mail.
 
If the data is required to fulfill a contract or to carry out pre-contractual measures, premature deletion of the data is only possible, unless contractual or legal obligations preclude deletion.
 
4 CONTACT
 
On our website is a contact form available, which can be used for electronic contact. If a user accepted this option, the data entered in the input mask will be transmitted to us and saved. These data are:
 
The following is a list of the data of the input mask:
 
First and Last Name
 
e-mail address
 
Subject
 
message
 
At the time of sending the message, no data is stored.
 
Alternatively, contact via the provided e-mail address is possible. In this case, the user's personal data transmitted by e-mail will be stored.
 
Legal basis for data processing
 
Legal basis for the processing of the data is in the presence of the consent of the user Art. 6 para. 1 p. 1 lit. a GDPR.
 
The legal basis for the processing of the data transmitted in the course of sending an e-mail is Article 6 (1) sentence 1 lit. f DSGVO. If the e-mail contact aims to conclude a contract, then additional legal basis for the processing is Art. 6 para. 1 p. 1 lit. b DSGVO.
 
Purpose of data processing
 
The processing of the personal data from the input mask serves us only to process the contact. In the case of contact via e-mail, this also includes the required legitimate interest in the processing of the data.
 
The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
 
Duration of storage
 
The data will be deleted as soon as it is no longer necessary for the purpose of its collection. For the personal data from the input form of the contact form and those sent by e-mail, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the relevant facts have been finally clarified.
 
The additional personal data collected during the sending process will be deleted at the latest after a period of seven days.
 
Opposition and removal possibility
 
The user has the possibility at any time to revoke his consent to the processing of the personal data. If the user contacts us by e-mail, he may object to the storage of his personal data at any time. In such a case, the conversation cannot continue.
 
The revocation of the consent as well as a protest against the storage of your personal data can be explained by email.
 
All personal data stored in the course of contacting will be deleted in this case.
 
5 INDIVIDUALIZED NEWSLETTERS
 
With your consent, you can subscribe to our newsletter, which informs you about our current interesting offers.
 
Obligatory indication for the transmission of the newsletter is the e-mail address alone. The specification of further, separately marked, information is voluntary and is used solely for personalization of the newsletter. These data will also be completely deleted upon revocation. In addition, we store your used IP addresses and times of login and confirmation. The purpose of the procedure is to prove your registration and, if necessary, to inform you about possible misuse of your personal data. After your confirmation, we will save your registration data for the purpose of sending you the newsletter. The legal basis is Art. 6 para. 1 p. 1 lit. a DS-GMO.
 
You can revoke your consent to the sending of the newsletter at any time. You can unsubscribe from all newsletters at any time and without giving reasons or only unsubscribe for special newsletters. The unsubscribe link can be found in every newsletter sent by us under "unsubscribe". You can also cancel it by clicking on the link provided in each newsletter e-mail, and by e-mai.
 
We point out that we evaluate your user behavior when sending the newsletter. For this evaluation, the emails sent contain so-called web beacons, also called tracking pixels. These are one-pixel image files that link to our website, allowing us to evaluate your user behavior. This is done by collecting web beacons that are assigned to your e-mail address and linked with your own ID. Also in the newsletter received links contain these. With the data obtained in this way, we create a user profile in order to provide you with the newsletter tailored to your interests. In doing so, we record when you read our newsletters, which links you click in and conclude your personal interests.
 
The information collected in this way is stored on a server in the European Union.
 
If you have registered in our webshop and have added products to your wish list, you will receive emails for information on discounts, re-availability and the last available copy of the products in your wish list. You can unsubscribe from these notifications at the end of the wishlist by removing the check mark.
 
6 YOUR ORDER IN OUR ONLINESHOP
 
If you wish to order in our webshop, it is necessary for the conclusion of the contract that you provide your personal data, which we need for the processing of your order. Obligatory information necessary for the execution of the contracts are marked separately, further information voluntarily. We process the data provided by you to process your order. For this we can pass on your payment data to the payment service provider you have selected. In addition, we will forward your address data to the selected shipping logistics service provider for processing the shipment.
 
The legal basis for this is Art. 6 (1) S.1 (b). DS-GMO.
 
You can also voluntarily create a user account, through which we can save your data for later purchases. This registration is based on section 3 of this declaration.
 
We reserve the right to change or amend this Privacy Policy at any time in accordance with applicable data protection laws.
 
7 COOKIE POLICY
 
Cookies are small files text, which are recorded by the sites during the user visit, those text are sent to terminals and stored. Before being re-transmitted on the next cutomer visit.
"Third parties" cookies are set by other website. This happens because in each website are present secondary elements (images, maps, sounds, specific links to web pages of other domains, etc.) that reside in different server as the one visited.
Cookies are used with this purposes: performing computer authentication, monitoring sessions, storing information of specific configurations, storing preferences, etc.

Technical cookies are used for the purposes of site optimization, are used to track user navigation on the web and create profiles on their tastes, habits, choices, etc. With these cookies, advertising messages can be transmitted to the user's terminal in line with the preferences already expressed by the same user in the online navigation.
Lugano, January 2019
NATURAL MYSTIC SWITZERLAND SAGL
 
Favourites
Your favourites are empty