Privacy Policy

General

As the operator of this website and as a company, we come into contact with your personal data. This refers to all data that provides information about you and can be used to identify you. In this privacy policy, we would like to explain how, for what purpose and on what legal basis we process your data.

The following entity is responsible for data processing on this website and within our company:

Skéina Skincare GmbH Korbacherstr. 41, 34134 Kassel, Germany Telephone: 01725209301 Email: info@skeina.de

General information

SSL or TLS encryption

When you enter your data on websites, place online orders or send emails via the internet, you must always be aware that unauthorised third parties may access your data. There is no such thing as complete protection against such access. However, we do everything in our power to protect your data as best we can and to close any security gaps to the extent possible.

An important security measure is the SSL or TLS encryption of our website, which ensures that data you transmit to us cannot be read by third parties. You can recognise the encryption by the padlock icon before the web address in your browser and by the fact that our web address begins with https:// rather than http://.

Encrypted payment transactions

Payment data, such as account or credit card numbers, is particularly sensitive. For this reason, all payment transactions using standard payment methods are conducted exclusively via an encrypted SSL or TLS connection.

How long do we store your data?

In some sections of this privacy policy, we inform you about how long we, or the companies that process your data on our behalf, store your data. If no such information is provided, we store your data until the purpose of the data processing no longer applies, you object to the data processing, or you withdraw your consent to the data processing.

In the event of an objection or withdrawal, however, we may continue to process your data if at least one of the following conditions applies:

  • We have compelling legitimate grounds for continuing the data processing which override your interests, rights and freedoms (only in the case of an objection to data processing; if the objection relates to direct marketing, we cannot invoke any legitimate grounds).
  • Data processing is necessary to assert, exercise or defend legal claims (this does not apply if your objection relates to direct marketing).
  • We are legally obliged to retain your data.

In this case, we will delete your data as soon as the condition(s) no longer apply.

Data transfer to the USA

We also use tools on our website from companies that transfer your data to the USA, where it is stored and, where applicable, further processed. The European Commission has adopted an adequacy decision regarding the EU-US data protection framework. This establishes that the US ensures an adequate level of protection for personal data from the EU that is transferred to US companies. This decision is based on new safeguards and measures introduced by the US to meet data protection requirements. The adequacy decision includes, among other things, restrictions and safeguards regarding access to data by US intelligence services. Binding safeguards have been introduced to limit access by US intelligence services to what is necessary and proportionate for the protection of national security. In addition, enhanced oversight of the activities of US intelligence services has been established to ensure that restrictions on surveillance activities are complied with. An independent redress mechanism has also been set up to handle and resolve complaints from European citizens regarding access to their data. The EU-US Privacy Shield framework thus enables European companies to transfer data to certified US companies without having to implement additional data protection safeguards. You can view a list of all certified companies at the following link: https://www.dataprivacyframework.gov/s/participant-search

A change to the European Commission’s decision cannot be ruled out.

Your rights

Objection to data processing

IF YOU READ IN THIS PRIVACY POLICY THAT WE HAVE LEGITIMATE INTERESTS IN PROCESSING YOUR DATA AND THEREFORE PROCESS IT ON THE BASIS OF ART. 6(1)(f) F) of the GDPR, YOU HAVE THE RIGHT UNDER ARTICLE 21 OF THE GDPR TO OBJECT TO THIS. THIS ALSO APPLIES TO PROFILING CARRIED OUT ON THE BASIS OF THE AFOREMENTIONED PROVISION. THE PREREQUISITE IS THAT YOU CITE REASONS FOR THE OBJECTION THAT ARISE FROM YOUR PARTICULAR SITUATION. A JUSTIFICATION IS NOT REQUIRED IF THE OBJECTION IS DIRECTED AGAINST THE USE OF YOUR DATA FOR DIRECT MARKETING.

THE CONSEQUENCE OF THE OBJECTION IS THAT WE ARE NO LONGER PERMITTED TO PROCESS YOUR DATA. THIS DOES NOT APPLY IF ONE OF THE FOLLOWING CONDITIONS IS MET:

  • WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS.
  • THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.

THESE EXCEPTIONS DO NOT APPLY IF YOUR OBJECTION IS DIRECTED AGAINST DIRECT MARKETING OR AGAINST PROFILING RELATED TO SUCH MARKETING.