privacy policy

The protection of your personal data is very important to us. When you visit our website and online shop, we process personal data (any information relating to an identified or identifiable natural person) insofar as we are permitted to do so by law, the Personal Information Protection and Electronic Documents Act (PIPEDA) or with your consent. This privacy policy sets out below the details of how we process your personal data (hereinafter also referred to as just "data processing" or "processing").

 

Person responsible for data processing

The person responsible for data processing on this website is:

 

Ahyoka Nail Studio

Palma de Mallorca, Spain

 

Phone: 687-23-03-98

Email: ahyokanailstudio@gmail.com

Web: www.ahyokanailstudio.com

 

 

Operation and hosting of our website

Our website is operated in our name and on our behalf by a full-service eCommerce service provider (SquareSpace), which carries out all of our data processing in connection with the use of our website for us. This data processing takes place on the servers of a hosting service provider who connects the website to the Internet on our behalf.

 

Overview of our data processing

We process data in the following contexts:

 

When you make a purchase from or booking with us, we process data from you that is necessary for the establishment and performance of a purchase contract ("contract performance");

When you call up and surf our website ("website use"), we process data from and on your terminal device, some of which could enable us to identify you personally;

Finally, we process your data if you wish to contact us ("communication"), for example by subscribing to our newsletter, rating an article or sending us a message via the communication channels provided by us.

 

Performance of the contract

In the course of making a booking or your purchase in our online shop, we ask you for the following individual personal data:

 

·       First name;

·       surname;

·       Billing/delivery address;

·       e-mail address;

·       Payment data;

·       Phone Number.

 

Scope and purposes of processing

The personal data requested from you will be processed by us for the following purposes:

 

·       to email you the confirmation of receipt and, if applicable, the order confirmation with the legally required information as well as status reports on the dispatch of the ordered goods;

·       to process your payment;

·       to send you the invoice for an order;

·       to deliver the ordered goods to you; and

·       if necessary, to assign revocations, complaints and other post-contractual inquiries from you to your person and order and to be able to process your request.

 

If you have voluntarily created a customer account under "Log in - Register now", we will also process this data in order to register you as a customer of Ahyoka Nail Studio for future potential visits or purchases in our online shop, so that you do not have to re-enter this data, which is necessary for the fulfillment of the contract, for each further order and can view purchases already made in your customer account at any time. After registering, you can also save products from our online shop as favourites in your customer account so that you can buy them later if necessary.

 

Data transfer/recipients

The recipients of your data are the technical operator and the hosting service provider of our website. Insofar as it is necessary for the fulfillment of the contract, your data will also be passed on to companies commissioned by us with the receipt and processing of your order. These are in detail:

 

·       Shipping service providers for the purpose of dispatch, delivery or collection of goods;

·       the banking company/credit institution commissioned with the payment in each case (PayPal or Stripe).

 

Storage period

If you do not create a customer account, your data will be blocked after fulfillment of the individual purchase contract, i.e. it will only be processed by us to a limited extent. On the one hand, this is necessary in the event that you assert claims against us within the statutory limitation periods (usually three years), which we must assign to your person and the business transaction with you. On the other hand, we are obliged under commercial and tax law to retain business documents that may contain your data for a maximum period of ten years. As soon as these purposes have been fulfilled or the periods have expired, your data will be deleted by us.

 

If you have voluntarily created a customer account, we will process your data in it until you have had the customer account deleted by us.

 

Legal basis of the processing

Data processing is carried out because it is necessary for the fulfillment of the contract. In some cases (sending of confirmation of receipt and communication of mandatory information in the case of distance selling or consumer loans, transmission for creditworthiness checks), it is also carried out to fulfill a corresponding legal obligation.

 

If you have created a customer account, we will also process your data on the basis of your consent given to us at the same time.

 

Right of revocation

You can revoke your consent to the management of your customer account at any time with effect for the future by notifying us at one of the contact addresses listed above. We will then delete your customer account.

 

Website use

Each time you visit our website, we process certain personal data from and in some cases also on your computer/end device. These processing operations can be divided into the following categories:

 

·       Logging of your visit/use of functional cookies

·       Website usage analysis with Google Analytics

·       Use of tracking technologies for interest-based Internet advertising

·       Use of so-called "social plug-ins" for linking to social media

 

Logging of your visit/use of functional cookies

Each time you visit our website and each time you download a file from our website, the following log data is automatically processed by us:

 

·       Host name of your computer/end device (IP address);

·       date and time of the call/download;

·       the page called up;

·       if applicable, the name of the downloaded file;

·       type of browser used;

·       operating system of your terminal device;

·       the web site from which you are visiting us.

 

In addition, we use functional cookies to operate our website. These are small text files that are stored by us on your computer/end device. Firstly, these are so-called session cookies, which are only set for the duration of your visit to our website. Secondly, so-called persistent cookies are used. They remain on your computer/end device for longer. Both types of cookies contain a characteristic alphanumeric character string which, in the case of persistent cookies, can enable your browser to be recognized on a subsequent visit to our website.

 

The data is processed by us for the following purposes:

 

·       To identify and defend against attacks on our website;

·       to determine whether your internet browser supports cookies;

·       to prevent pop-ups from being displayed to you more than once;

·       to show you the language you have selected for our website; and

·       to show you the version of our website for the country of delivery you have selected.

·       3. data transfer/recipients

 

The recipients of your data are the technical operator and the hosting service provider of our website.

 

The data will be stored for the following duration:

 

·       Log data: until the purpose is achieved, maximum three months;

·       Session cookies: until you leave our website;

·       persistent cookies: one year

 

The processing is based on our interest in the functionality and security of our website. After our consideration, this legitimate interest is not opposed by any overriding interests or fundamental rights and freedoms of data subjects. Upon request, we will provide you with further information about our balancing of interests.

 

You have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process this data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the assertion, exercise or defence of legal claims. You can submit your objection to us using the contact details provided in A. above. Alternatively, you can control whether or which types of cookies may be set via the settings of your internet browser. Insofar as you do not accept the use of functional cookies, this may lead to restrictions in the functionality of our website.

 

For further details, please visit our Cookie Policy and for more general information on cookies, please visit www.allaboutcookies.org

 

Website usage analysis with Google Analytics & Optimize

We use Google Analytics including Google Optimize, a web analytics service provided by Google Limited ("Google").

 

Google uses cookies. These are text files that are stored on your computer/end device and enable an analysis of your use of our website. The following information is processed in the process:

 

·       Browser type

·       Operating system

·       Last website visited

·       Host name of your computer/end device (IP address, shortened)

·       Time of the request at our server

 

On our behalf, Google will process the information collected via the cookie for the purpose of evaluating your use of our website, compiling reports on website activity and providing us with other services relating to website activity and internet usage. We use the Google Optimize sub-service to test new content and functions of our website on a proportion of visitors in order to statistically evaluate any changes in usage. In doing so, we refrain from processing data that could be used to identify you. In particular, the cookie does not contain a user ID. The shortened IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

 

The information generated by the cookie about your use of our website will be transmitted to and stored by Google Limited and, as a rule, also to a server of the associated Google LLC in the USA. By deactivating the user ID function and activating IP anonymisation (shortening the IP address by the last octet), the data can no longer be assigned to your connection or computer/end device.

 

The processed data will be stored for a period of 14 months and then deleted by Google.

 

The data processing is carried out on the basis of our interest in the statistical evaluation of the use and, derived from this, the efficiency of our website. According to our assessment, this legitimate interest does not conflict with any overriding interests or fundamental rights and freedoms of data subjects. Upon request, we will be happy to provide you with the information on which the weighing of interests is based.

 

You have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process this data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the assertion, exercise or defence of legal claims. You can prevent the collection of the data generated by the cookie and related to your use of the website, as well as its processing by Google, by moving the slider for website usage analysis in the cookie banner that appears when you call up our website or at the top of this page from the right (green) to the left (grey) or by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en.

 

Use of social plugins

We use so-called social plugins ("plugins")  on our website.

To ensure the protection of your data, the plugins are not directly integrated into the page, but only using an HTML link (so-called "Shariff solution" from c't). This ensures that when you call up one of our web sites that contains such plugins, there is still no connection with the servers of the provider of the respective social network. If you click on one of the buttons, a new window of your browser opens and calls up the page of the respective social network on which you can (if necessary after entering your login data) e.g. click on the Like or Share button.

 

For the purpose and scope of the data collection and the further processing of the data by the providers, as well as your rights in this regard and setting options for protecting your privacy, please refer to the privacy policies of the providers.

 

Communication

Newsletter

You can voluntarily subscribe to our e-mail newsletter service on our website by entering your personal details including your e-mail address in the input field. The order for the newsletter and your consent required for this only become effective when you confirm this by clicking on the link sent to you by us via the e-mail address entered (so-called double opt-in procedure). The granting of your consent is logged by us in a log file. The following information is processed:

 

·       E-mail address;

·       first name;

·       surname,

·       Date and time consent was given (time stamp).

 

We process the e-mail address confirmed by you in order to inform you at irregular intervals with our e-mail newsletter in accordance with the consent.  If indicated, we process your first name and/or surname in order to address you personally in the newsletter. Your consent is recorded so that we can prove it.

 

The recipients of the data are the technical operator and the hosting service provider of our website as well as a newsletter delivery service provider commissioned by us.

 

We store your e-mail address, any additional personal information entered and the log data about your consent until you unsubscribe from the newsletter again or revoke the respective consent to data processing. The log data will then be stored by us for the duration of the limitation period of your claims (three years) plus a safety margin of one month for service of process, i.e. a total of 37 months. The processing is based on your consent.

 

Your newsletter consent is valid until revoked, which you can declare at any time with effect for the future, for example by notifying us accordingly under the contact details given above, or by clicking on the unsubscribe link, which you will find at the very end of each newsletter. Your optional consent to the processing of additional personal information for the purposes mentioned above is also valid until revoked, which you can also declare separately at any time, for example by notifying us accordingly under the contact details given above or by deselecting the processing not desired in each case on our newsletter page.

 

Making an appointment

You can make an appointment under "Book Now". In doing so, the following data will be processed by us:

 

·       Selected date with time;

·       Your name;

·       Your e-mail address;

·       Your telephone number;

·       Your message.

·       Payment details for your Deposit

 

We process your data in order to process your inquiry, to arrange a appointment with you and, for this purpose, to contact you by e-mail or, if you have voluntarily provided a telephone number, by telephone. The recipients of the data are the technical operator and the hosting service provider of our website. We store the data you enter via the appointment form until we have arranged an appointment with you. The data processing is carried out for the implementation of pre-contractual measures.

 

Contacting us

You can contact us in various way on the website and social media. In doing so, we process the data that you provide in your message to us, i.e. your specific request and, in the case of e-mail inquiries, your e-mail address, in the case of letters your postal address, in the case of calls your telephone number and, when using our contact form, the reason for your inquiry (according to the selection in the drop-down menu), your name and e-mail address and, if applicable, the place of residence.

 

We process your data in order to process your inquiry and to contact you for the purpose of answering it. The recipients of the data are the technical operator and the hosting service provider of our website. We store your data until we have answered your inquiry.

 

The processing is carried out on the legal basis of the implementation of pre-contractual measures or for the fulfillment of a contract. Insofar as it does not concern pre-contractual or contractual matters, the legal basis is our legitimate interest in processing your inquiry. We assume that no overriding interests or fundamental rights and freedoms of you conflict with this. Upon request, we will be happy to provide you with the information on which the weighing of interests is based.

 

You have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process this data for these purposes and, if necessary, no longer answer your inquiry. You can submit your objection to us using the contact details provided in A. above.

 

Your further rights as a person affected by data processing

With regard to your personal data, you have the following further rights in addition to those already mentioned above in the context of the respective data processing:

 

·       Right of access: you can request information from us about the personal data we process about you.

·       Right to rectification: You may request us to rectify inaccurate and complete incomplete personal data.

·       Right to erasure: You may, under certain conditions, request us to erase your personal data.

·       Right to restriction: You may, under certain conditions, request that we restrict the processing of your personal data.

·       Right to withdraw your consent: Insofar as we should ask you for your consent for the processing of personal data, you have the right to withdraw this consent at any time with effect for the future.

·       Right to complain to a supervisory authority: You can also contact a supervisory authority with a complaint.

·       Right to object to direct marketing: You have the right to object at any time to the processing of your personal data for the purpose of direct marketing; this also applies to profiling, insofar as it is related to such direct marketing. We will then no longer process this data for these purposes. You can submit your objection to us, for example, using the contact details provided above.

 

Data security

The personal data we request from you on our website is transmitted to us via a secure SSL connection ("Secure Socket Layer") with 256-bit encryption so that it is protected against unauthorized access.

 

In addition, we take further technical and organizational security precautions to prevent the loss, destruction and misuse of data. For example, access to any customer account you may have created is only possible by entering your personal password. You yourself can contribute to the protection of your data by choosing a password that is as difficult to reconstruct as possible (e.g. a combination of letters, numbers and characters) and keeping it strictly secret.

 

Automated decision-making

We do not use automated decision-making or profiling.

 

Do Not Sell My Personal Information

We do not sell information that directly identifies you, like your name, address or phone records.

 

Accuracy

It is important that the data we hold about you is accurate and current, therefore please keep us informed of any changes to your personal data.

 

External Links

Our website contains links to the online offers of other providers. We hereby point out that we have no influence on the content of the linked online offers and the compliance with data protection regulations by their providers.

 

Personal data of children

Most of our website are designed and intended for adults. If a website provides content for a younger audience, we will obtain consent from a parent or guardian prior to collecting personal information if we deem it appropriate or if required by applicable law (the age of consent varies by country). If children's personal information has been provided to us, it will be deleted from our database. The child's parents (or guardians) may contact us to request deletion of the data or opt-out (see below for contact information). For this purpose, we may request a copy of an identification document confirming the parental or educational relationship.

 

Information, deletion and correction

Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipient and the purpose of the data processing and, if applicable, the right to correction or deletion of this data. For this purpose, as well as for further questions on the subject of personal data, you can contact us at any time.

 

Direct marketing

The legal basis for the processing of your personal data in the context of direct marketing measures is either your consent or our legitimate interest in marketing and promoting our courses and services. The purpose of processing your personal data in the context of direct marketing measures is to send information, offers and, if applicable, to promote sales.

 

Your personal data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected; this is the case in particular upon receipt of the revocation or objection. You can revoke your consent at any time for the future or object to the processing of your personal data in the context of direct marketing measures at any time for the future.

 

When you send a data subject access request

The legal basis for the processing of your personal data in the context of handling your data subject access request is our legal obligation and the legal basis for the subsequent documentation of the data subject access request is both our legitimate interest and our legal obligation. The purpose of processing your personal data in the context of processing data when you send a data subject access request is to respond to your request. The subsequent documentation of the data subject access request serves to fulfill the legally required accountability.

 

Your personal data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. In the case of the processing of a data subject access request, this is three years after the end of the respective process. You have the possibility at any time to object to the processing of your personal data in the context of the processing of a data subject access request for the future. In this case, however, we will not be able to further process your request. The documentation of the legally compliant processing of the respective data subject access request is mandatory. Consequently, there is no possibility for you to object.

 

Legal defense and enforcement of our rights

The legal basis for the processing of your personal data in the context of legal defense and enforcement of our rights is our legitimate interest. The purpose of processing your personal data in the context of legal defense and enforcement of our rights is the defense against unjustified claims and the legal enforcement and assertion of claims and rights.

 

Your personal data will be deleted as soon as they are no longer necessary to achieve the purpose for which they were collected. The processing of your personal data in the context of legal defense and enforcement is mandatory for legal defense and enforcement of our rights. Consequently, there is no possibility for you to object.

 

Social Media

The data you enter on our social media pages, such as comments, videos, pictures, likes, public messages, etc. are published by the social media platform and are not used or processed by us for any other purpose at any time. We only reserve the right to delete content if this should be necessary. Where applicable, we share your content on our site if this is a function of the social media platform and communicate with you via the social media platform. The legal basis is our legitimate interest. The data processing is carried out in the interest of our public relations and communication.

 

If you wish to object to certain data processing over which we have an influence, please contact us. We will then examine your objection. If you send us a request on the social media platform, we may also refer you to other secure communication channels that guarantee confidentiality, depending on the response required. You always have the option of sending us confidential inquiries to our address stated in the imprint.

 

As already stated, where the social media platform provider gives us the opportunity, we take care to design our social media pages to be as data protection compliant as possible. With regard to statistics that the provider of the social media platform makes available to us, we can only influence these to a limited extent and cannot switch them off. However, we make sure that no additional optional statistics are made available to us.

 

Data processing by the operator of the social media platform

The operator of the social media platform uses web tracking methods. The web tracking can also take place regardless of whether you are logged in or registered with the social media platform. As already explained, we can unfortunately hardly influence the web tracking methods of the social media platform. We cannot, for example, switch this off.

 

Please be aware: It cannot be ruled out that the provider of the social media platform uses your profile and behavioral data, for example to evaluate your habits, personal relationships, preferences, etc. We have no influence on this. In this respect, we have no influence on the processing of your data by the provider of the social media platform.

 

Changes to the privacy policy

In the event of changes to the privacy policy, we will post the amended version and the effective date of the change on this website. We recommend that you read our privacy policy at regular intervals. We will only make changes that affect consent you have given us by obtaining your consent again.