Datenschutzerklärung/Privacy Policy

02.02.2022

Smile Ira Fotografie takes your privacy very seriously and processes your personal data in agreement with the respective applicable legal data protection requirements. Personal data in the sense of this information are all information that can show a reference to your person, so e.g. name, address, e-mail and IP address or user behavior. 

With the following data protection information, we inform you about the processing of your personal data by us. We also provide an overview of your data protection rights. Which data is processed in detail and how it is used depends largely on the functions used or services requested or agreed upon.

Responsible entity and data protection officer

(1) The responsible body pursuant to Article 4 (7) of the General Data Protection Regulation (DSGVO) or service provider pursuant to Section 13 of the German Telemedia Act (TMG) is:

Smile Ira Fotografie
Irina Zdyrko
Bergfelder Str. 44
16567 Muehlenbeck

(2) Our company is not obliged to appoint a data protection officer. Inquiries regarding data protection matters can be directed to

Smile Ira Fotografie
Irina Zdyrko
Bergfelder Str. 44
16567 Muehlenbeck

E-Mail: info@smileira.com

Source of personal data

We process personal data that we receive from you in the course of your visit to our website or in the course of your contacting us by e-mail or via a contact form. We also process personal data that we receive from you in the course of your purchase in our online store.

Categories of personal data that are processed

(1)  If you visit or use our website purely for information purposes, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. We collect the following data, which is technically necessary for us to display our website to you and to ensure its stability and security (legal basis is Art. 6 para. 1 lit. f) DSGVO):

  • Your IP address

  • Date, time and duration of your visit

  • Content of the request (specific page)

  • Access status/http status code

  • Website from which the request came

  • Your browser

  • Your operating system

This data is used for internal statistical purposes only.

(2)  In addition to the aforementioned data, cookies are stored on your computer when you use our website. Cookies are small text files that are stored on your hard drive associated with the browser you are using and through which certain information flows to the place that sets the cookie. Cookies cannot execute programs or transfer viruses to your computer. They are used to make the website as a whole more user-friendly and effective. This website uses the following types of cookies:

  • Functional and necessary cookies: These cookies enable navigation on our website and the use of essential functions of our website.

  • Analytics and performance cookies: These cookies collect information about the interaction on our website by visitors.

We also use cookies to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you. These cookies enable us to automatically recognize that you have already been to our site when you visit it again. They are automatically deleted after a defined period of time.

We also use cookies to perform tracking and measures. In this way, we want to ensure a needs-based design and continuous optimization of our website.

If you have explicitly agreed to the setting of cookies for the use of analysis and performance services when you call up our website, we set these cookies and process the data collected by cookies based on your consent pursuant to Art. 6 (1) sentence 1 lit. a) DSGVO. You can find more details in the description of the services. These cookies are automatically deleted after a defined period of time. Insofar as we use cookies based on your consent, you can revoke your consent for the future at any time via the cookie management tool. Most browsers are set to accept cookies. However, you can also deactivate the storage of cookies in your browser or set your browser so that you receive a message as soon as cookies are sent. We would like to point out, however, that if you completely deactivate cookies, you may not be able to use all the functions of this website.

This stored information is stored separately from any other data provided to us. In particular, the data of the cookies are not linked with your other data.

(3)  If you contact us by e-mail or via a contact form, the data you provide (e.g. name, e-mail address, telephone number, if applicable, reason for contact) will be stored by us in order to process your request. The legal basis is Art. 6 para. 1 p. 1 lit. a) DSGVO.

(4)  When you purchase in our online store, we collect personal data that is required to process your order (name, address, telephone number, payment method). To process your order, we work with a carefully selected service provider.

Our partner who prints and ships the work you ordered and paid for is:

WhiteWall Media GmbH
Europaallee 59
50226 Frechen, Germany

Tel.: +44 (0) 20 3411 1846
E-Mail: info@whitewall.com

Commercial register: Cologne Local Court

Commercial register number: HRB 59223

Sales tax ID number: DE 253731136

Managing director: Alexander Nieswandt, Thomas Alscheid

You can find the privacy policy of our partner here:

https://www.whitewall.com/eu/privacy-policy

Transfer to third countries

(1) A transfer of personal data to countries outside the European Economic Area (EEA) shall only take place if the requirements of Art. 44 ff. DSGVO are given. A third country is a country outside the European Economic Area (EEA) in which the DSGVO is not directly applicable.

(2) The EU Commission has not issued an adequacy decision for the USA pursuant to Article 45 (1) DSGVO. This is because, according to the European Court of Justice in its judgment of 17.07.2020 (Case C-311/18, "Schrems II"), there is no level of data protection in the USA comparable to that in the EU. When personal data is transferred to the USA, there is a risk that US authorities may gain access to the personal data on the basis of the PRISM and UPSTREAM surveillance programs based on Section 702 of the FISA (Foreign Intelligence Surveillance Act) and on the basis of Executive Order 12333 or Presidential Police Directive 28. According to the European Court of Justice, EU citizens have no effective legal protection against these accesses in the USA or the EU.

(3) We transfer your personal data to the USA or other third countries only if either:

  • the recipient provides sufficient guarantees in accordance with Article 46 of the DSGVO for the protection of personal data - for example, the conclusion of standard contractual clauses between us and the recipient (Article 46(2)(c) of the DSGVO) or binding internal data protection rules approved by the competent data protection authorities (Article 46(2)(b) of the DSGVO). In doing so, the recipient assures to sufficiently protect the data and thus to ensure a level of protection comparable to the DSGVO.

  • one of the exceptions listed in Art. 49 DSGVO applies - for example, your explicit consent (Art. 49 (1) a) DSGVO) - or

  • if the transfer is necessary for the fulfillment of contractual obligations between you and us (Art. 49 (1) (b) DSGVO). 

Other functions and offers of our website

(1) In addition to the purely informational use of our website, we offer various services that you can use if you are interested. For this purpose, you usually have to provide further personal data that we use to provide the respective service and to which the aforementioned data processing principles apply.

(2) We operate an online store on our website where you can purchase our print photography. Within the scope of the purchase process, as well as the order processing, personal data is collected and processed.

In the context of online orders, the following personal data is required from you: name, address, telephone number and e-mail address. This data is required to carry out the purchase transaction and is accordingly based on Art. 6 para. 1 lit. b) DSGVO as the legal basis.

We offer you different payment options. So you can pay your order via Paypal, ApplePay or by credit card. For credit card payments, we involve the payment service provider Stripe.

For order processing, the following personal data in particular will be transmitted to the payment service provider:

  • Payment data: Amount, date, time

  • Card data: Card number, card type (e.g. VISA, Mastercard, American Express), card expiration date.

  • Financial data: Account coverage, credit limit of overdraft facility (if any), turnovers

  • Master data: Name, address, telephone number

You can find the privacy statements of the payment service providers here:

Analyse-Tools

(1) Google Analytics with IP anonymization

Insofar as you have given your consent, Google Analytics, a web analytics service provided by Google LLC, is used on this website. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Scope of processing

Google Analytics uses cookies that enable an analysis of your use of our websites. The information collected by means of the cookies about your use of this website is usually transferred to a Google server in the USA and stored there.

We use the function 'anonymizeIP' (so-called IP masking): Due to the activation of IP anonymization on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

During your visit to our website, the following data, among others, is collected:

  • The pages you visit, your "click path".

  • Achievement of "website goals" (conversions, e.g. newsletter sign-ups, downloads, purchases)

  • Your user behavior (for example, clicks, dwell time, bounce rates)

  • Your approximate location (region)

  • Your IP address (in shortened form)

  • Technical information about your browser and the end devices you use (e.g., language setting, screen resolution)

  • Your internet service provider

  • The referrer URL (via which website/advertising medium you came to this website)

Processing purposes

On behalf of the operator of this website, Google will use this information for the purpose of evaluating your (pseudonymous) use of the website and compiling reports on website activity. The reports provided by Google Analytics are used to analyze the performance of our website.

Receiver

The receiver of the data is

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

as an order processor. For this purpose, we have concluded an order processing agreement with Google. Google LLC, based in California, USA, and, if applicable, US authorities can access the data stored by Google.

Transmission to third countries

A transfer of data to the USA cannot be ruled out.

Storage period

The data sent by us and linked to cookies are automatically deleted after 14 months. The deletion of data whose retention period has been reached takes place automatically once a month.

You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by

a. Not giving your consent to the setting of the cookie or

b. downloading and installing the browser add-on to disable Google Analytics hier .

You can also prevent the storage of cookies by configuring your browser software accordingly. However, if you configure your browser to refuse all cookies, you may experience limitations in functionality on this and other websites.

Legal basis and withdrawal option

for this data processing is your agreement, Art. 6 para.1 p.1 lit. a) DSGVO. You can revoke your agreement at any time with effect for the future by calling up the cookie settings and changing your selection there.

For more information on Google Analytics' terms of use and Google's privacy policy, please visit https://policies.google.com/privacy?hl=en and https://policies.google.com/?hl=en.  

(2) Gmail Workspace Integration

We use the Gmail Workspace Integration of Google LLC in our company. The responsible service provider in the EU is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").

Scope of processing

The following personal data is collected in this process:

  • Pseudonymous analysis of incoming e-mails

Purposes of processing

On behalf of the operator of this website, Google will use this information for the purpose of evaluating the (pseudonymous) use of e-mail activities and compiling reports on e-mail activities. The reports provided by Google Analytics are used to analyze the performance of our incoming emails. Google has no insight into the content of the emails.

Recipient

The recipient of the data is

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

as an order processor. We have concluded an order processing agreement with Google for this purpose. Google LLC, based in California, USA, and, if applicable, US authorities may access the data stored by Google.

Transmission to third countries

A transfer of data to the USA cannot be excluded.

Storage period

The reports on e-mail activities provided by Google are automatically deleted after 14 months. The deletion of data whose retention period has been reached takes place automatically once a month.

The storage period of the e-mails is based on the legal requirements. E-mails are regularly deleted when the purpose of processing is no longer given, unless legal retention periods prevent deletion.

Legal basis and revocation option

We base the data processing on a legitimate interest within the meaning of Art.6 para.1 p.1 lit. f) DSGVO.

You can find more information on the terms of use of Google Analytics and on data protection at Google here https://policies.google.com/?hl=en.

(3) Squarespace Analytics

Where you have given your consent, Squarespace Analytics is used on this website, a web analytics service provided by Squarespace, Inc. 8 Clarkson St 12th Floor New York, NY 10014 ("Squarespace"). 

Scope of processing

Squarespace Analytics uses cookies that enable an analysis of your use of our website. The information collected by means of the cookies about your use of this website is generally transmitted to a Squarespace server in the USA and stored there.

During your website visit, the following data, among others, is collected pseudonymously:

  • Traffic (e.g. visitors to the website, page views, estimate of total number of visitors).

  • Sales analysis (e.g. products sold, orders completed, key figures on orders, e.g. average order total)

  • User behavior (e.g., products viewed, products added to shopping cart and "checked out" activity, shopping cart abandoned)

  • Technical data (e.g. Internet provider, the referrer URL [via which website/advertising medium you came to this website])

Purposes of processing

On behalf of the operator of this website, Squarespace will use this information to evaluate the (pseudonymous) use of our website and to compile reports on the use. The reports provided by Squarespace Analytics are used to analyze the performance of our website.

Recipient

The recipient of the data is

  • Squarespace Analytics used, a web analytics service provided by Squarespace, Inc. 8 Clarkson St 12th Floor New York, NY 10014

as an order processor. For this purpose, we have concluded an order processing agreement with Squarespace. Squarespace, Inc. LLC, based in New York, USA, and, if applicable, US authorities may access the data stored at Squarespace.

Transmission to third countries

A transfer of data to the USA cannot be excluded.

Storage period

The reports provided by Squarespace on the use of the website are automatically deleted after a defined period. The deletion of data whose retention period has been reached takes place automatically once a month.

Legal basis and revocation option

for this data processing is your consent, Art.6 para.1 p.1 lit. a) DSGVO. You can revoke your consent at any time with effect for the future by calling up the cookie settings and changing your selection there.

For more information on the terms of use of Squarespace Analytics and data protection at Squarespace, please visit https://www.squarespace.com/privacy.

Social-Media-Plug-Ins 

(1) We currently use the following social media plug-ins:

Instagram, part of the Meta Platforms Ireland Limited group of companies, 4 Grand Canal Square, Dublin 2, Ireland.

(2) We use the so-called Shariff solution. This means that when you visit our site, no personal data is initially passed on to the providers of these plug-ins. You can recognize the provider of the plug-in by the initial letter or logo. The contact to the services or the query is made from the server, so instead of the visitor's IP address, only the server address is transmitted to Meta Platforms. Only when you press the link to share content, the plug-in provider receives the information that you have accessed the corresponding web page of our online offer. In the case of Meta Platforms, according to the respective providers in Germany, the IP address is anonymized immediately after collection. By activating the plug-in, personal data is therefore transmitted and stored there (in the case of US providers, in the USA). Since the plug-in provider collects data in particular via cookies, we recommend that you delete all cookies via your browser's security settings before clicking on the provider's logo. We base the data processing on Art. 6 para. 1 p. 1 lit. f) DSGVO.

(3) We have no influence on the collected data and data processing operations, nor are we aware of the full extent of the data collection, the purposes and the storage periods. We also have no information about the deletion of the collected data by the plug-in provider.

(4) The plug-in provider stores this data as usage profiles and uses it for purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (also for users who are not logged in) for the display of tailored advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these usage profiles, whereby you must contact the respective plug-in provider to exercise this right. Via the plug-ins, we offer you the opportunity to interact with the social networks and other users, so that we can improve our offer and make it more interesting for you as a user.

(5) The data transfer takes place regardless of whether you have an account with the plug-in provider or are logged in there. If you are logged in to the plug-in provider, your data will be directly assigned to your account with the plug-in provider. If you click the activated button and link to the page, for example, the plug-in provider also saves this information in your user account and shares it publicly with your contacts. We recommend that you log out regularly after using a social network, but especially before activating the button, as this allows you to avoid an assignment to your profile with the plug-in provider.

(6) Further information on the purpose and scope of the data collection and its processing by the plug-in provider can be found in the following privacy statements of these providers. There you will also receive further information about your rights in this regard and setting options for protecting your privacy.

(7) Addresses of the respective providers and URL with their privacy notices:

Social media performances

This privacy policy also applies to various social media channels operated by or through us. These are described in detail below.

Instagram

You can reach our Instagram presence via https://www.instagram.com/smileira/.

Processing of personal data by Instagram

When you visit our Instagram appearance, Instagram collects personal data from you. Instagram states in its privacy policy the personal data collected, the purposes for which this data is processed and recipients of the personal data (https://help.instagram.com/519522125107875).

When you visit our Instagram page and your browser allows cookies to be stored, Facebook Ireland stores information in the form of small text files in your browser's memory (hereinafter "cookies") and can access this information when you visit the Facebook platform or a website that embeds Facebook technologies. For more information on the purpose of the cookies used, on the integration of these cookies by other websites and on your control options in this regard, please refer to the information on Instagram cookies.

We would like to point out that Facebook Ireland is able to track your user behavior (across devices for registered users) on other websites beyond the Instagram platform by means of the cookies used. This applies both to persons registered with the Instagram platform and to persons not registered there.

We would also like to point out that we have no influence on the data processing carried out by Facebook Ireland in connection with cookies. Visiting our Instagram page is also possible if you configure your browser so that no cookies are stored by the Facebook platform. Information on how to adjust the settings for cookies in your browser can be found in the help section of the browser you are using.

If you are registered or logged in to the Instagram or Facebook platform and would like to avoid Facebook Ireland being able to associate your visit to our Instagram page with your Instagram or Facebook user account, you should log out of Facebook or disable the "stay logged in" feature, delete the cookies present on your device, and exit and restart your browser.

Direct Messages

When you contact us by e-mail or direct message, we process the personal data provided for this purpose (user name, e-mail address, if applicable, and the content of the message).

Categories of recipients of personal data

(1) We have some of the aforementioned processes and services carried out by carefully selected service providers who comply with data protection requirements. These external service providers are bound by our instructions and are regularly monitored. They will not pass on your data to third parties. The specific recipients of personal data are named in this data protection notice.

(2) With regard to the disclosure of data to other recipients, we will only disclose information about you if required by law, you have consented or we are authorized to disclose. If these requirements are met, recipients of personal data may include:

  • Public places and institutions (e.g. tax authorities, law enforcement agencies) in the event of a legal or official obligation.

  • Other companies or comparable institutions to which we transfer personal data in order to carry out the business relationship with you (e.g. credit agencies, possibly others)

Purposes of the processing of personal data and their legal basis

We process your personal data in compliance with the applicable legal data protection regulations. In this context, the processing is lawful beyond the purposes and legal bases described above in the context of the tools used, if the following conditions are met:

Consent (Art. 6 para. 1 lit. a) DSGVO:

The lawfulness for the processing of personal data is given in case of consent for processing for specified purposes (e.g. processing of your/your request, use of data for marketing purposes). Consent given can be revoked at any time with effect for the future. This also applies to the revocation of declarations of consent given to us before the DSGVO came into force, i.e. before May 25, 2018.

Due to contractual obligations (Art. 6 para. 1 lit. b) DSGVO:

In order to fulfill our contractual obligations or also to carry out pre-contractual measures, which take place upon request, we process personal data. The purposes of the data processing result primarily from your specific request. Examples:

  • For order processing

  • For shipping products

  • For the creation of offers

Within the framework of the balancing of interests (Art. 6 para. 1 lit. f) DSGVO:

Where necessary, we process your data beyond the actual performance of the contract to protect legitimate interests of us or third parties. Examples:

  • Assertion of legal claims and defense in legal disputes,

  • To ensure IT security and IT operations,

  • To improve the use of our website. 

Due to legal requirements (Art. 6 para. 1 lit. c) DSGVO:

Smile Ira Fotografie is subject to various legal obligations. These include, among others:

  • Commercial and tax law retention requirements in accordance with the German Commercial Code and the German Fiscal Code,

  • Fulfillment of control and reporting obligations under tax law

Intention to transfer personal data to a third country or to an international organization

An active transfer of personal data to a third country only takes place if this has been expressly indicated within the scope of the aforementioned services.

Criteria for determining the duration for which personal data are stored

(1) The data will be stored in accordance with statutory provisions on data processing and in compliance with statutory retention periods. We process and use your data exclusively for the purposes for which you have authorized us and for as long as the data is required for these purposes.

(2) If the data are no longer required for the purpose or for the fulfillment of legal obligations, they are usually deleted, unless their further processing - limited in time and scope if necessary - is required for the following purposes:

  • The fulfillment of retention obligations under commercial and tax law: These include the German Commercial Code (HGB) and the German Fiscal Code (AO). These stipulate retention and documentation periods of up to 10 years.

  • The preservation of evidence within the framework of the statutory limitation provisions: According to §§ 195 ff. of the German Civil Code (BGB), the regular limitation period is three years, but under special circumstances up to 30 years.

Data protection rights of data subjects

(1) You have the following rights against us regarding the personal data concerning you:

  • Right to information, Art. 15 DSGVO,

  • Right to rectification and erasure, Art. 16, 17 DSGVO,

  • Right to restriction of processing, Art. 18 DSGVO,

  • Right to object to processing, Art. 21 DSGVO,

  • Right to data portability, Art. 20 DSGVO.

(2) Within the scope of the right to information (Art. 15 DSGVO) and the right of deletion (Art. 16, 17 DSGVO), the restrictions according to §§ 34, 35 BDSG apply.

(3) You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data relating to you which is carried out on the basis of Article 6 (1) (e) DSGVO (data processing in the public interest) and Article 6 (1) (f) DSGVO (data processing on the basis of a balance of interests); this also applies to profiling based on this provision within the meaning of Article 4 No. 4 DSGVO.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims

In individual cases, we process your personal data for the purpose of direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising; this also applies to profiling, insofar as it is associated with such direct advertising.

If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

The objection can be made form-free and should preferably be addressed to:

Smile Ira Fotografie
Irina Zdyrko
Bergfelder Str. 44
16567 Muehlenbeck

E-Mail: info@smileira.com

(4) Consent given can be revoked at any time with effect for the future. This also applies to the revocation of declarations of consent given to us before the DSGVO came into force, i.e. before May 25, 2018.

(5) Furthermore, you have the right to lodge a complaint about the processing of your personal data by us with a competent data protection authority (Art. 77 DSGVO in conjunction with Section 19 BDSG).

Data security

(1) We protect your information through modern security systems and comply with data protection and security regulations within the framework of the DSGVO.

(2) We use current technical measures to ensure data security, in particular to protect your personal data from risks during data transmission and from third parties gaining knowledge, and we adapt these measures as necessary in accordance with the state of the art.

(3) We use SSL encryption to protect the information you enter in our online forms and when processing orders on our website. However, we cannot guarantee that the information sent cannot be viewed by third parties during transmission. Therefore, you should not send passwords or other information that you wish to keep secret.

Obligation to provide and possible consequences of not providing personal data

In the context of order processing in our online store, you must provide those personal data that are necessary for the fulfillment of the purpose or which we are required to collect by law. Without this data, we will generally not be able to conclude the contract with you or to execute it.

The purely informational visit to our website only requires the collected personal data in the form of the necessary cookies. Further functions that require your consent do not have to be provided. However, we would like to point out that our website may not be able to be used to its full extent if you do not provide the personal data.

Existence of automated decision making including profiling

As a matter of principle, we do not use fully automated decision-making or profiling pursuant to Art. 22 DSGVO. Should we use these procedures in individual cases, we will inform you about this separately if this is required by law.

Changes to the data protection notice

If we add new functionalities that have an impact on the way your personal data is processed, we will inform you in good time in our privacy notices. This privacy policy is valid as of February 2022.