1. Information about the collection of personal data and contact details of the responsible person
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. In this context, personal data is all data with which you can be personally identified.
1.2 The person responsible for data processing on this website within the meaning of the General Data Protection Regulation (DSGVO) is:
Name: Malio GmbH
Address: Thalerstrasse 19, 9424 Rheineck, Switzerland
E-mail: info@malio.ch
Telephone number: 044 592 57 17
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g. orders or requests to the controller). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.
2. Data collection when visiting our website
When you use our website for information purposes, i.e. if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the time of access
- Amount of data sent in bytes
- Source/reference from which you came to the site
- Browser used
- Operating system used
- IP address used
The processing is carried out in accordance with Art. 6 (1) lit. f DSGVO on the basis of our legitimate interest in improving the stability and functionality of our website. The data is not passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use.
3. Cookies
In order to make visiting our website more attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your terminal device. Some of the cookies we use are deleted at the end of the browser session, i.e. after you close your browser (so-called session cookies). Other cookies remain on your terminal device and enable us or our partner companies (third-party cookies) to recognise your browser on your next visit (persistent cookies). If cookies are set, they collect and process certain user information such as browser and location data as well as IP address values to an individual extent. Persistent cookies are automatically deleted after a specified period of time, which may vary depending on the cookie. In some cases, cookies are used to simplify the ordering process by storing settings (e.g. remembering the contents of a virtual shopping basket for a later visit to the website). If personal data is also processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6 Para. 1 lit. b DSGVO either for the execution of the contract or in accordance with Art. 6 Para. 1 lit. f DSGVO to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.
We may work with advertising partners who help us to make our website more interesting for you. For this purpose, cookies from partner companies are also stored on your hard drive when you visit our website (third-party cookies). Please note that you can set your browser in such a way that you are informed about the setting of cookies and can decide individually about their acceptance or can exclude the acceptance of cookies for certain cases or generally. Each browser differs in the way it manages cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. This can be found for each browser at the following links: Internet Explorer, Firefox, Chrome, Safari or Opera.
Please note that if you do not accept cookies, the functionality of our website may be limited.
4. Contact
In the context of contacting us (e.g. via contact form or e-mail), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of answering your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6 Para. 1 lit. f DSGVO. If your contact aims at the conclusion of a contract, the additional legal basis for the processing is Art. 6 (1) lit. b DSGVO. Your data will be deleted after final processing of your request, this is the case if it can be inferred from the circumstances that the matter concerned has been conclusively clarified and provided that there are no legal storage obligations to the contrary.
5. Data processing when opening a customer account and for contract processing
Pursuant to Art. 6 para. 1 lit. b DSGVO, personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. Which data is collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be done by sending a message to the above address of the person responsible. We store and use the data provided by you for the purpose of processing the contract. After complete execution of the contract or deletion of your customer account, your data will be blocked with regard to tax and commercial law retention periods and deleted after expiry of these periods, unless you have expressly consented to a further use of your data or a legally permitted further use of data has been reserved on our part, about which we inform you accordingly below.
6. Use of your data for direct advertising (newsletter)
If you register for our e-mail newsletter, we will regularly send you information about our offers. The only data required for sending the newsletter is your e-mail address. The provision of further data is voluntary and will be used to address you personally. We use the opt-in procedure for sending the newsletter. This means that we will only send you an e-mail newsletter if you have expressly confirmed that you consent to the sending of newsletters. With your registration, you give us your consent for the use of your personal data in accordance with Art. 6 para. 1 lit. a DSGVO. When you register for the newsletter, we store your IP address entered by your Internet service provider (ISP) as well as the date and time of registration in order to be able to trace any possible misuse of your e-mail address at a later date. The data collected by us when you register for the newsletter will be used exclusively for the purpose of advertising in the newsletter. You can unsubscribe from the newsletter at any time via the link provided for this purpose in the newsletter or by sending a corresponding message to the responsible person named at the beginning. After unsubscribing, your e-mail address will be deleted from our newsletter distribution list immediately, unless you have expressly consented to further use of your data or we reserve the right to use your data in a manner that goes beyond this, which is permitted by law and about which we inform you in this declaration.
7. Data processing for order processing
In order to process your order, we work together with the service provider(s) listed below, who support us in whole or in part in the execution of concluded contracts. Certain personal data is transferred to these service providers in accordance with the following information. The personal data collected by us will be passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the delivery of the goods. We pass on your payment data to the commissioned credit institution within the framework of payment processing, insofar as this is necessary for payment processing. If payment service providers are used, we explicitly inform about this below. The legal basis for the transfer of data is here Art. 6 para. 1 lit. b DSGVO.
7.1 Use of Paypal
In the case of payment via PayPal, credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment by instalments" via PayPal, we pass on your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal") as part of the payment processing. The transfer takes place in accordance with Art. 6 Para. 1 lit. b DSGVO and only insofar as this is necessary for the payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal or - if offered - "purchase on account" or "payment by instalments" via PayPal, PayPal reserves the right to carry out a credit check. For this purpose, your payment data may be passed on to credit agencies in accordance with Art. 6 Para. 1 lit. f DSGVO on the basis of PayPal's legitimate interest in determining your solvency. PayPal uses the result of the credit check in terms of the statistical probability of non-payment for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, these have their basis in a scientifically recognised mathematical-statistical procedure. The calculation of the score values includes, but is not limited to, address data. For further information on data protection law, including information on the credit agencies used, please refer to PayPal's data protection declaration. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary to process payments in accordance with the contract.
7.2 Use of Stripe
If you choose a payment method from the payment service provider Stripe, the payment will be processed via the payment service provider Stripe Payments Europe Ltd, Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland, to whom we pass on the information you provided during the ordering process, together with information about your order (name, address, account number, bank sort code, credit card number if applicable, invoice amount, currency and transaction number). Your data will only be passed on for the purpose of payment processing with the payment service provider Stripe Payments Europe Ltd. You can find more information about Stripe's data protection here.
7.3 Use of PostFinance
If you have chosen to pay by credit card (Postfinance), the payment will be processed by the payment service provider PostFinance AG, Mingerstrasse 20, 3030 Bern, Switzerland, to whom we will pass on the information you provided during the ordering process in addition to information about your order (name, address, account number, bank code, credit card number, if applicable, invoice amount, currency and transaction number). Your data will be passed on exclusively for the purpose of payment processing with the payment service provider PostFinance AG. You can find more information on PostFinance data protection here.
7.5 Use of POWERPAY's credit rating system
Your personal data will only be passed on to POWERPAY for the purpose of checking your creditworthiness. The data thus passed on may only be used by our service provider to fulfil its task. You can find more information about POWERPAY's data protection here.
7.6 Use of Twint
8. Web analytics services
AWStats
In order to be able to evaluate our website statistically, we use the AWStats program. The program is a free web analysis software. It is used to evaluate log files that web servers create based on visitor requests. The program does not use cookie files for the analysis. Statistical analysis is performed on the log files, which also contain IP addresses. As a rule, this data cannot be assigned to specific persons. A combination of this data with other data sources is not made, the data is also deleted after a statistical analysis. In contrast to other statistical programs, AWStats does not transmit any data to a third-party server. The program is installed on the own server. Thus, for example, a transfer of data abroad is also avoided, since our servers are located in Switzerland (CH)
Google Analytics
This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States . This website uses Google Analytics exclusively with the extension "_anonymizeIp()", which ensures anonymization of the IP address by shortening and excludes a direct personal reference. Through this extension, your IP address is shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. In these exceptional cases, this processing is carried out in accordance with Art. 6 (1) lit. f DSGVO on the basis of our legitimate interest in the statistical analysis of user behaviour for optimisation and marketing purposes. On our behalf, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available under the following link. As an alternative to the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent the collection by Google Analytics within this website in the future (this opt-out cookie only works in this browser and only for this domain, if you delete your cookies in this browser, you must click this link again): Google Analytics deactivate. Google LLC, based in the USA, is certified for the us-European data protection agreement "Privacy Shield", which ensures compliance with the level of data protection applicable in the EU. This website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out via a user ID. You can deactivate the cross-device analysis of your usage in your customer account under "My data", "Personal data". You can find more information on how Google Analytics handles user data in Google's privacy policy
Google AdWords
This website uses Google AdWords, an analysis service of Google, and within the scope of Google AdWords the conversion tracking. Google AdWords places a cookie for conversion tracking on your computer's hard drive (a so-called "conversion cookie") when you click on an ad placed by Google. These cookies lose their validity after 30 days and are not used for personal identification. If you visit certain pages on our website, Google and we can recognize that you have clicked on the ad and have been redirected to this page. The information obtained using the conversion cookies is used to compile statistics for AdWords customers who use conversion tracking. Through these statistics, we learn the total number of users who clicked on the ad placed by Google and visited a page tagged with a conversion tracking tag
In addition to conversion tracking, we also use the functions:
Remarketing
Audiences with common interests
custom audiences with common interests
ready-to-buy audiences
similar target groups
demographic and geographic targeting
Google's remarketing feature allows us to reach users who have already visited our website. This allows us to present our ads to audiences that are already interested in our products or services. AdWords also uses user behaviour on websites in the Google advertising network ("display network") over the last 30 days and the contextual search engine to determine the common interests and characteristics of users of our website. Based on this information, AdWords then finds new potential customers for marketing purposes whose interests and characteristics are similar to those of the users of our website. Target group-specific remarketing is carried out through the combined use of cookies, such as Google Analytics cookies and Google DoubleClick cookies. Further information on the terms of use and data protection in the context of Google Adwords can be found here.
Facebook Pixel
This website uses the pixel function of Facebook Custom Audience. The Facebook Pixel is offered by the social network Facebook. Facebook is registered in Europe as Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The Facebook pixel is integrated into this website with the "advanced matching" function. It initiates the processing of personal data by Facebook and enables the identification of the user via numerous web pages and thus target group-oriented advertising by means of a so-called tracking procedure. The Facebook pixel stores a cookie, i.e. a small text file, on your device when you call up our website. If you are logged in to Facebook at the same time or subsequently log in to Facebook, your visit to this website will be noted in your Facebook profile. The personal data is stored and processed by Facebook so that a connection to the respective user profile is possible and the data can be used for market research and advertising purposes. However, via the pixel and the "extended matching" function, data such as name, e-mail address of non-Facebook users who are not logged into a Facebook account while visiting this website are also collected. The processing of the data by Facebook takes place within the framework of Facebook's data usage policy. For more information and details about the Facebook pixel and how it works, users can visit Facebook's help section.
9. Rights of the data subject
The applicable data protection law grants you comprehensive data subject rights (rights of information and intervention) vis-à-vis the controller with regard to the processing of your personal data, which we inform you about below:
Right to information pursuant to Art. 15 DSGVO: In particular, you have the right to obtain information about your personal data processed by us, the processing purposes, the categories of personal data processed, the recipients or categories of recipients to whom your data have been or will be disclosed, the planned storage period or the criteria for determining the storage period, the existence of a right to rectification, erasure, restriction of processing, objection to processing, complaint to a supervisory authority, the origin of your data if it has not been collected from you by us, the existence of automated decision-making including profiling and, if applicable, meaningful information about the logic involved and the scope and intended effects of such processing concerning you, as well as your right to be informed about which guarantees exist in accordance with Art. 46 DSGVO in the event of forwarding of your data to third countries;
Right to rectification pursuant to Art. 16 of the GDPR: You have the right to have any inaccurate data relating to you rectified without delay and/or to have any incomplete data stored by us completed;
Right to deletion pursuant to Art. 17 DSGVO: You have the right to demand the deletion of your personal data if the requirements of Art. 17 (1) DSGVO are met. However, this right does not exist in particular if the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;
Right to restriction of processing pursuant to Art. 18 DSGVO: You have the right to request the restriction of the processing of your personal data as long as the accuracy of your data disputed by you is being verified, if you refuse the deletion of your data due to inadmissible data processing and instead request the restriction of the processing of your data, if you need your data to assert, exercise or defend legal claims after we no longer need this data after the purpose has been achieved, or if you have lodged an objection for reasons relating to your particular situation as long as it has not yet been determined whether our legitimate reasons prevail;
Right to information pursuant to Art. 19 DSGVO: If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to inform all recipients to whom the personal data concerning you have been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort. You have the right to be informed about these recipients.
Right to data portability pursuant to Art. 20 DSGVO: You have the right to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request that it be transferred to another controller, insofar as this is technically feasible;
Right to revoke consent given in accordance with Art. 7 (3) DSGVO: You have the right to revoke consent to the processing of data once given at any time with effect for the future. In the event of revocation, we will delete the data concerned without delay, unless further processing can be based on a legal basis for processing without consent. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation;
Right to lodge a complaint pursuant to Art. 77 DSGVO: If you consider that the processing of personal data concerning you infringes the GDPR, you have - without prejudice to any other administrative or judicial remedy - the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement.
10. Right of objection
If we process your personal data within the framework of a balancing of interests on the basis of our overriding legitimate interest, you have the right at any time to object to this processing with effect for the future on grounds arising from your particular situation. If you exercise your right to object, we will stop processing the data concerned. However, we reserve the right to continue processing if we can demonstrate compelling legitimate grounds for the processing which override your interests, fundamental rights and freedoms, or if the processing serves the purpose of asserting, exercising or defending legal claims. If your personal data is processed by us for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing. You can exercise the objection as described above. If you exercise your right to object, we will stop processing the data concerned for direct marketing purposes.
11. Duration of the storage of personal data
The duration of the storage of personal data is determined by the respective legal retention period (e.g. retention periods under commercial and tax law). After expiry of the period, the corresponding data is routinely deleted, provided that it is no longer required for the fulfilment or initiation of the contract and/or there is no further justified interest on our part in its continued storage.
Zurich, 21 February 2019