Privacy Policy

This privacy policy is intended to inform you as a user of this web shop (hereinafter referred to as “website”) about the type, scope and purpose of the collection and use of personal data by me, the web shop operator utoppa GmbH, hereinafter referred to as Utoppa.

We take your data protection very seriously and treat your personal data confidentially and in accordance with the legal regulations. Since new technologies and the constant development of this website may result in changes to this data protection declaration, we recommend that you read the data protection declaration again at regular intervals.

Personal data is information about the personal or factual circumstances of a specific or identifiable natural person. This includes information such as your real name, address, telephone number and date of birth (if provided). The definitions of the terms used in this data protection declaration (e.g. “personal data” or “processing”) can also be found in Art. 4 of the General Data Protection Regulation (GDPR).

Name and contact details of the controller
This privacy information applies to data processing by:

Responsible:

Nico Albrecht and Maximilian Sänger Managing Directors utoppa GmbH

IIndustriestr 22 65366 Geisenheim Germany
E-Mail: Contact@utoppa.com

person responsible for data processing

You can direct any questions regarding data protection in relation to my online shop to the above address or email address at any time.

  1. Collection and storage of personal data as well as the type and purpose of their use
  2. visit to the website

When you visit our website, the browser used on your device automatically sends information to our website's server. This information is temporarily stored in a so-called log file. The following information is recorded without your intervention and stored until it is automatically deleted:

  • IP address of the requesting computer,
  • date and time of access,
  • Name and URL of the retrieved file,
  • Website from which access is made (referrer URL),
  • browser used and, if applicable, the operating system of your computer and the name of your access provider.

This data is stored anonymously in accordance with the Telemedia Act (TMG). The creation of personal user profiles is therefore excluded. This data is deleted or anonymized after the end of the connection.

We process the data mentioned for the following purposes:

  • Ensuring a smooth connection to the website,
  • Ensuring a comfortable use of our website,
  • Evaluation of system security and stability as well as
  • for further administrative purposes.

The legal basis for data processing is Art. 6 Paragraph 1 Clause 1 Letter f of GDPR. Our legitimate interest arises from the purposes for data collection listed above. Under no circumstances do we use the data collected for the purpose of drawing conclusions about you personally.

In addition, we use cookies and analysis services when you visit my website. You can find more detailed information about this in sections 4 and 5 of this privacy policy.

newsletter

On our website we offer the option of signing up for our newsletter. After registration, we will regularly inform you about news by email. Furthermore, after a certain period of time you will be reminded by email of the items you have placed in your shopping cart and whose order you had to interrupt or whose purchase you were unable to complete. A valid email address is required to register for the newsletter. To verify your email address, you will first receive a registration email, which you must confirm using the link. If you subscribe to the newsletter on our website, we process personal data such as your email address based on your consent. The legal basis for the processing is art. 6 para. 1 subpara. 1 lit. a GDPR. You can unsubscribe from our newsletter at any time, for example by contacting us using the corresponding link in the email you received or by writing an email to contact@utoppa.com .

Google Web Fonts

This website uses so-called web fonts for the uniform display of fonts, which are provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter "Google"). When you call up a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.

For this purpose, the browser you use must connect to Google's servers. This tells Google that our website was accessed via your IP address. Google Web Fonts are used in the interest of a uniform and appealing presentation of our online offerings. This represents a legitimate interest within the meaning of Art. 6 (1) (f) GDPR.

If your browser does not support web fonts, a standard font from your computer will be used.

For more information about Google Web Fonts, see

https://developers.google.com/fonts/faq

and in Google's privacy policy:

https://www.google.com/policies/privacy .

Using our contact form or product reviews

If you have any questions, we offer you the opportunity to contact us using a form provided on the website. You must provide a valid email address and your first and last name so that we know who the request came from and can answer it. You must also enter a category, your country and the subject of the request in our contact form so that we can classify and answer your request in the correct language and quickly and reliably. We collect the information as mandatory fields, in particular because our customers are mostly professionals who rely on us to answer support questions promptly when using our products professionally.

The data processing for the purpose of contacting us is carried out in accordance with Art. 6 Paragraph 1 Clause 1 Letter a of GDPR on the basis of your voluntarily granted consent by using the contact form. You can revoke this consent at any time. To do so, simply send an informal email to contact@utoppa.com. The legality of the data processing operations carried out up to the time of revocation remains unaffected by the revocation.

The personal data we collect when you use the contact form will be deleted after your request has been processed.

email contact

If you contact us by email, we will save your details to process your request and in case follow-up questions arise. We only save and use other personal data if you consent to this or if this is legally permissible without special consent.

product reviews and form

If you write a product review for us, we will save your details and publish your product review on our website. We will also share your data with the software we use to process the product review. By submitting product reviews, you agree to this. You can request the deletion of your review and personal data at any time.

sharing of data

Your personal data will not be transferred to third parties for purposes other than those listed below.

We will only share your personal information with third parties if:

  • You have given your express consent in accordance with Art. 6 Paragraph 1 Clause 1 Letter a of GDPR,
  • the disclosure is necessary in accordance with Art. 6 (1) sentence 1 lit. f GDPR to assert, exercise or defend legal claims and there is no reason to assume that you have an overriding legitimate interest in not disclosing your data,
  • in the event that there is a legal obligation to disclose data pursuant to Art. 6 (1) sentence 1 lit. c GDPR, and
  • this is legally permissible and is necessary for the processing of contractual relationships with you according to Art. 6 Paragraph 1 Clause 1 Letter b of GDPR.

cookies

We use cookies on our website. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our website. Cookies do not cause any damage to your device and do not contain any viruses, Trojans or other malware.

The cookie stores information that is related to the specific device used. However, this does not mean that we receive direct knowledge of your identity.

The use of cookies serves, on the one hand, to make the use of our services more pleasant for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our website. These are automatically deleted after you leave my site.

In addition, we also use temporary cookies to optimize user-friendliness. These are stored on your device for a specific period of time. If you visit our site again, it will automatically recognize that you have already visited us and what entries and settings you have made so that you do not have to enter them again.

We also use cookies to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you. These cookies enable us to automatically recognize that you have already visited our site when you visit it again. These cookies are automatically deleted after a defined period of time.

The data processed by cookies are necessary for the purposes mentioned to protect our legitimate interests and those of third parties in accordance with Art. 6 (1) sentence 1 lit. f GDPR.

Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or so that a warning always appears before a new cookie is created. However, completely disabling cookies may mean that you cannot use all the functions of our website.

Ai Trillion Marketing Tool

We use Ai Trillion (www.aitrillion.com) to send customer information, newsletters and product recommendations and integrate components into our website for this purpose. The provider is Ai Trillion INTELLI AI TRILLION TECHNOLOGIES PRIVATE LIMITED , 2093 Philadelphia Pike #9505 Claymont, DE 19703 , United States (hereinafter " Ai Trillion "). Ai Trillion offers marketing automation software for marketing services and products, including SEO and content creation, lead management, newsletters, email and SMS marketing and web analytics.

Ai Trillion uses cookies and other browser technologies to evaluate user behavior and identify users. This information is used, among other things, to compile reports on website activity and to provide customers with personalized communications (e.g. reminders of incomplete purchases, information about products customers have viewed, etc.). In addition, Ai Trillion is used to store and transmit data entered in forms using cookies, including your IP address. In this case, your data will be passed on to Ai Trillion .

The data you enter to subscribe to the newsletter (e.g. email address) will be stored on Ai Trillion 's servers in the United States, Canada and India.

The data you provide to us for the purpose of subscribing will be stored by us until you unsubscribe from us or the service provider and will be deleted from the mailing list after you unsubscribe. Data that we have stored for other purposes will remain unaffected.

Google Analytics

We use the Google Analytics analysis service on the basis of Art. 6 Paragraph 1 Clause 1 Letter f of GDPR. With the tracking measures used, we want to ensure that our website is designed to meet your needs and is continuously optimized. We also use the tracking measure to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you. These interests are to be regarded as legitimate within the meaning of the aforementioned provision. Furthermore, the data collected can be used for remarketing campaigns.

For the purpose of needs-based design and continuous optimization of our pages, we use Google Analytics, a web analysis service of Google Inc. ( https://www.google.de/intl/de/about/ ) (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter referred to as "Google"). In this context, pseudonymized user profiles are created and cookies (see section 4) are used. The information generated by the cookie about your use of this website, such as

  • browser type/version,
  • operating system used,
  • Referrer URL (the previously visited page),
  • Hostname of the accessing computer (IP address),
  • time of the server request,

are transferred to a Google server in the USA and stored there. The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage for the purposes of market research and needs-based design of these Internet pages. This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf of Google. Under no circumstances will your IP address be merged with other data held by Google. The IP addresses are anonymized so that they cannot be assigned to a specific user (IP masking).

You may prevent the installation of cookies by setting your browser software accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.

You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by downloading and installing a browser add-on ( https://tools.google.com/dlpage/gaoptout?hl=de ).

As an alternative to the browser add-on, especially for browsers on mobile devices, you can also prevent Google Analytics from collecting data by clicking on this link. An opt-out cookie will be set that prevents your data from being collected in the future when you visit this website. The opt-out cookie is only valid in this browser and only for our website and is stored on your device. If you delete the cookies in this browser, you must set the opt-out cookie again.

Further information on data protection in connection with Google Analytics can be found in the Google Analytics Help ( https://support.google.com/analytics/answer/6004245?hl=de )

Social Media, Youtube and Vimeo Links

Based on Art. 6 Paragraph 1 Clause 1 Letter f of GDPR, we use links to the social networks Facebook and Twitter as well as to the YouTube and Vimeo sites on our website in order to make our company better known. The advertising purpose behind this is to be regarded as a legitimate interest within the meaning of the GDPR. The responsibility for data protection-compliant operation must be guaranteed by the respective provider. By clicking on the corresponding link, you will be redirected to the Facebook, Twitter, YouTube or Vimeo website.

YouTube

Our website uses plug-ins from the YouTube site operated by Google. The site is operated by “YouTube”, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.

When you visit one of our pages equipped with a YouTube plug-in, a connection to the YouTube servers is established. The YouTube server is informed which of our pages you have visited.

If you are logged into your YouTube account, you allow YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

We use YouTube in the interest of presenting our online offerings in an appealing manner. This represents a legitimate interest in accordance with Art. 6 (1) (f) GDPR.

Further information on how user data is handled can be found in YouTube’s privacy policy at: https://www.google.de/intl/de/policies/privacy .

  1. Collection and handling of personal data within the customer account

We offer our customers the opportunity to place orders for the products we offer and to use certain services in connection with the ordered products via a personal form on our web shop. Before using the service for the first time, you must register once. For this we need the following information from you:

  • First name Last Name,
  • E-mail address

To process orders in our online shop, we also require the following information from you:

  • Billing address (if applicable, company and additional address, street, house number, postal code, city),
  • Delivery address (title, first name, last name, if applicable company and additional address, street, house number, postal code, city, mobile phone number),
  • Payment data (PayPal data, bank details),
  • phone number.

A customer number will also be automatically assigned to your customer account.
We need the telephone number in order to pass it on to the logistics companies DHL/DPD/UPS. They need your telephone number in order to be able to contact you regarding the delivery. You can find more information about DPD under point 10 of this data protection declaration.

We use data that you send to us during registration and when ordering in the online shop for the following purposes:

  • provision of the customer account,
  • Making your customer profile available on our website,
  • Use of the online shop at shop.tentacle.de
  • delivery of product deliveries,
  • payment processing,
  • Inquiries related to your customer account and/or orders placed,
  • Information about changes to the terms and conditions or data protection notices,
  • internal statistical market research,
  • Sending the newsletter, if expressly ordered

customer account

When you open a customer account, we collect your personal data to the extent specified there. The data processing serves the purpose of improving your shopping experience and simplifying order processing. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter a of GDPR with your consent. You can revoke your consent at any time by notifying us, without affecting the legality of the processing carried out on the basis of the consent until the revocation. Your customer account will then be deleted.

Collection, processing and transfer of personal data when placing orders

When you place an order, we only collect and process your personal data to the extent that this is necessary to fulfil and process your order and to process your enquiries. The provision of the data is necessary for the conclusion of the contract. Failure to provide the data means that no contract can be concluded. The processing is carried out on the basis of Art. 6 Paragraph 1 Letter b of GDPR and is necessary for the fulfilment of a contract with you. Your data is passed on, for example, to the shipping companies, payment service providers, service providers for order processing and IT service providers you have chosen. In all cases, we strictly observe the legal requirements. The scope of data transmission is limited to a minimum.

Your data will be transferred to Canada, among other places. The EU Commission has issued an adequacy decision for data transfers to Canada.

The range of functions offered by uttopa.com may be limited if you do not provide any additional, voluntary personal data. You can change or delete your profile within your customer account at any time. The data will then be automatically removed from our system. To ensure that the data is transmitted securely, it is sent via a secure SSL connection.

payment provider "PayPal"
On our website we offer payment via PayPal, among other things. The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"). If you choose to pay via PayPal, the payment data you enter will be sent to PayPal. Your data will be sent to PayPal on the basis of Art. 6 Para. 1 lit. a GDPR (consent) and Art. 6 Para. 1 lit. b GDPR (processing to fulfill a contract). You have the option of revoking your consent to data processing at any time. A revocation does not affect the effectiveness of data processing operations that have taken place in the past.


Shopify Payments
We use the payment service provider “Shopify Payments”, 3rd Floor, Europa House, Harcourt Building, Harcourt Street, Dublin 2. If you choose a payment method offered by the payment service provider Shopify Payments, payment processing will be carried out by the technical service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, to whom we pass on the information you provided during the ordering process together with information about your order (name, address, account number, bank code, possibly credit card number, invoice amount, currency and transaction number) in accordance with Art. 6 Paragraph 1 Letter b GDPR. Your data will be passed on exclusively for the purpose of payment processing with Stripe Payments Europe Ltd. and only to the extent that it is necessary for this purpose. Further information on Shopify Payments’ data protection can be found at the following internet address: https://www.shopify.com/legal/privacy. Data protection information about Stripe Payments Europe Ltd. can be found here: https://stripe.com/de/privacy

Use of personal data when selecting Klarna payment options
In order to offer you Klarna's payment options, we will transmit personal data, such as contact details and order data, to Klarna. This enables Klarna to assess whether you can use the payment options offered by Klarna and to adapt the payment options to your needs. General information about Klarna can be found at: https://www.klarna.com/de/ . Your personal information will be processed by Klarna in accordance with the applicable data protection regulations and in accordance with the information in the Klarna privacy policy at https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/privacy treated.

logistics company DHL
To process your order, we work with the following service provider, who supports us in whole or in part in the implementation of concluded contracts. Certain personal data is transmitted to this service provider in accordance with the following information.


The personal data we collect will be passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the (re)delivery of the goods. In the event of a complaint, your device may be forwarded to a service partner. The data is passed on for the purpose of fulfilling legal or contractual obligations from the purchase contract, Art. 6 Para. 1 lit. b GDPR, and for our interest in effective error checking and correction, Art. 6 Para. 1 lit. f GDPR.


We will pass on your payment details to the commissioned credit institution as part of the payment processing if this is necessary for the payment processing. If payment service providers are used, we will inform you explicitly about this below. The legal basis for the transfer of data is Art. 6 Para. 1 lit. b GDPR.
In order to fulfil our contractual obligations to our customers, we work with external shipping partners. We pass on your name and delivery address to a shipping partner selected by us exclusively for the purposes of delivering the goods (Art. 6 Para. 1 lit. b GDPR).
The goods are delivered by the transport service provider DHL (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn), DPD or UPS. In the case of a delivery by a forwarding agent, we will also pass on your email address and telephone number to DHL, DPD or UPS in accordance with Art. 6 Paragraph 1 Letter f of GDPR before the goods are delivered for the purpose of coordinating a delivery date or to notify you of the delivery.

disclosure to other third parties

Finally, we will pass on your data to third parties or government agencies within the framework of the existing data protection laws pursuant to Art. 6 Paragraph 1 Letters c and f of GDPR if we are legally obliged to do so, e.g. due to an official or court order, or if we are entitled to do so, e.g. because this is necessary for the prosecution of criminal offenses or for the exercise and enforcement of our rights and claims.

  1. rights of those affected

You have the right:

  • to request information about your personal data processed by us in accordance with Art. 15 GDPR. In particular, you can request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected from us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information on its details;
  • to request the immediate correction of inaccurate or incomplete personal data stored by us in accordance with Art. 16 GDPR;
  • to request the deletion of your personal data stored by us in accordance with Art. 17 GDPR, unless the processing is necessary to exercise the right to freedom of expression and information, to fulfill a legal obligation, for reasons of public interest or to assert, exercise or defend legal claims;
  • to request the restriction of the processing of your personal data pursuant to Art. 18 GDPR if you contest the accuracy of the data, the processing is unlawful but you refuse to delete it and we no longer need the data, but you require it to assert, exercise or defend legal claims or you have objected to the processing pursuant to Art. 21 GDPR;
  • pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transmitted to another controller;
  • pursuant to Art. 7 Paragraph 3 GDPR, to revoke your consent at any time. This means that we may no longer continue the data processing based on this consent in the future and
  • to complain to a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or work or of our company headquarters.

  1. right of objection

If your personal data is processed on the basis of legitimate interests in accordance with Art. 6 Paragraph 1 Clause 1 Letter f of GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, provided there are reasons for doing so that arise from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right of objection, which we will implement without specifying a particular situation.

If you would like to exercise your right of withdrawal or objection, simply send an email to contact@utoppa.com .

  1. data security

When you visit our website, we use the common SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser. This is usually 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is being transmitted using encryption by the closed display of the key or lock symbol in the lower status bar of your browser.

We also use suitable technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

  1. Current status and changes to this privacy policy

This privacy policy is currently valid and is dated June 2024.

Due to the further development of our website and offers on it or due to changes in legal or official requirements, it may become necessary to change this privacy policy. You can access and print out the current privacy policy on the website at any time.