Privacy Policy
We are pleased that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to inform you at this point which of your personal data we collect when you visit our website and for what purposes it is used.
This data protection declaration applies to the website of the The Conscius Lab UG (haftungsbeschränkt), which can be reached under the domain "theconsciouslab.com" as well as the various subdomains ("our website").
Who is responsible and how do I contact you?
Responsible
for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
The Conscious Lab UG (haftungsbeschränkt)
CEO Cherryl Duncan
Musterstr 5
81927 München
Tel.: +49 151 11785510
E-Mail: [email protected]
What is this about?
This data protection declaration meets the legal requirements for transparency in the processing of personal data. This is all information that relates to an identified or identifiable natural person. This includes, for example, information such as your name, your age, your address, your telephone number, your date of birth, your e-mail address, your IP address or user behavior when visiting a website. Information with which we cannot (or only with disproportionate effort) relate to you personally, e.g. through anonymization, are not personal data. The processing of personal data (e.g. the collection, querying, use, storage or transmission) always requires a legal basis and a defined purpose.
Stored personal data are deleted as soon as the purpose of the Processing has been achieved and there are no legitimate reasons for further retention of the data. We will inform you about the specific storage periods and criteria for storage in the individual processing operations. Regardless of this, we store your personal data in individual cases to assert, exercise or defend legal claims and if there are statutory retention requirements.
Who gets my data?
We only pass on your personal data that we process on our website to third parties if this is necessary for the fulfillment of the purposes and in individual cases is covered by the legal basis (e.g. consent or protection of legitimate interests). In addition, we pass on personal data to third parties in individual cases if this serves to assert, exercise or defend legal claims. Possible recipients can then e.g. Law enforcement authorities, lawyers, auditors, courts, etc.
Insofar as we use service providers for the operation of our website who, as part of order processing on our behalf, provide personal data in accordance with. Process Art. 28 GDPR, these recipients of your personal data can be. You can find more detailed information on the use of processors and web services in the overview of the individual processing operations.
Do you use cookies?
Cookies are small text files that we send to the browser of your device and store them as part of your visit to our website. As an alternative to using cookies, information can also be stored in the local storage of your browser. Some functions of our website cannot be offered without the use of cookies or local storage (technically necessary cookies). Other cookies, on the other hand, allow us to perform various analyses, so that we are able, for example, to recognize the browser you use when you visit our website again and to transmit various information to us (not necessary cookies). Cookies enable us to make our website more user-friendly and effective for you, for example by tracking your use of our website and by determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly through your browser. Cookies do not cause any damage to your device. You cannot run programs or contain viruses.
We inform you about the respective services for which we use cookies in the individual processing operations. Detailed information on the cookies used can be found in the cookie settings or in the Consent Manager of this website.
What rights do I have?
Under the conditions of the statutory provisions of the General Data Protection Regulation (GDPR), you as a data subject have the following rights:
- Information in accordance with Art. 15 GDPR about the data stored about you in the form of meaningful information on the details of the processing and a copy of your data;
- Correction in accordance with Art. 16 GDPR of inaccurate or incomplete data stored by us;
- Deletion in accordance with Art. 17 GDPR of the data stored by us, insofar as the processing is not necessary for the exercise of the right to freedom of expression and information, for the fulfilment of a legal obligation, for reasons of public interest or for the assertion, exercise or defense of legal claims;
- Restriction of the processing in accordance with Art. 18 GDPR, insofar as the correctness of the data is disputed, the processing is unlawful, we no longer need the data and you refuse to delete it, because you need it to assert, exercise or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR.
- Data portability in accordance with Art. 20 GDPR, insofar as you have provided us with personal data within the framework of consent pursuant to Art. 6 sec. 1 lit. a GDPR or on the basis of a contract pursuant to Art. 6 sec. 1 lit. b GDPR and these were processed by us by means of automated procedures. You receive your data in a structured, common and machine-readable format or we transmit the data directly to another responsible person, as far as this is technically feasible.
- In accordance with Art. 21 GDPR, you object to the processing of your personal data, insofar as they are carried out on the basis of Art. 6 sec. 1 lit. e, f GDPR and there are reasons for doing so, which arise from your particular situation or if the objection is directed against direct marketing. The right to object does not exist if overriding, overriding reasons for processing are proven or if the processing is carried out for the assertion, exercise or defense of legal claims. Insofar as there is no right to object in individual processing operations, this is indicated therein.
- Revocation in accordance with Art. 7 sec. 3 GDPR of your given consent with effect for the future.
- Complaint under Art. 77 GDPR to a supervisory authority if you believe that the processing of your personal data violates the GDPR. As a rule, you can contact the supervisory authority of your usual place of residence, your workplace or our company headquarters.
How will my data be processed in detail?
In the following we will inform you about the individual processing operations, the scope and purpose of the data processing, the legal basis, the obligation to provide your data and the respective storage period. An automated decision in individual cases, including profiling, does not take place.
Provision of the website
Type and scope of processing
When you visit and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
- IP address of the requesting computer
- Date and time of access
- Name and URL the retrieved file
- website from which access is made (referrer URL)
- browser used and, if applicable, the operating system of your computer, as well as the name of your access provider
Our website is not hosted by us, but by a service provider who for the purpose of the aforementioned data on our behalf in accordance with. Art. 28 GDPR processed.
Purpose and legal basis
The processing is carried out to safeguard our overriding legitimate interest in displaying our website and ensuring security and stability on the basis of the Art. 6 Para. 1 lit. f GDPR. The collection of data and storage in log files is essential for the operation of the website. There is no right to object to the processing due to the exception according to Art. 21 Para. 1 GDPR. Insofar as the further storage of the log files is required by law, the processing takes place on the basis of Art. 6 Para. 1 lit. c GDPR. There is no legal or contractual obligation to provide the data, but it is technically not possible to call up our website without providing the data.
Storage duration
The aforementioned data are used for the duration of the display of the website and for technical reasons beyond that for a maximum of 7 days.
Contact Form
Type and scope of processing
On our website, we offer you the option of contacting us using a form provided. The information that is collected via mandatory fields is required to process the request. In addition, you can voluntarily provide additional information that you believe is necessary to process the contact request.
When using the contact form, your personal data will not be passed on to third parties.
Purpose and legal basis
The processing of your data by using our contact form takes place for the purpose of communication and processing of your request on the basis of your consent in accordance with. Art. 6 para. 1 lit. a GDPR. If your request relates to an existing contractual relationship with us, processing for the purpose of fulfilling the contract is based on Art. 6 Para. 1 lit. b GDPR. There is no legal or contractual obligation to provide your data, but it is not possible to process your request without providing the information in the mandatory fields. If you do not want to provide this data, please contact us by other means.
Storage period
If you use the contact form on the basis of your consent, we will save the data collected each request for a period of three years, starting with the handling of your request or until you withdraw your consent.
If you use the contact form in the context of a contractual relationship, we will save the data collected for each request Duration of three years from the end of the contractual relationship.
Newsletter
Type and scope of processing
If you register on our website to receive our newsletter, we collect your email address and your name and save this information together with the date of Registration and your IP address. You will then receive an email in which you have to confirm your subscription to the newsletter (double opt-in). If you do not confirm your registration within 24 hours, it will automatically expire and the data will not be processed for sending the newsletter. We will send the newsletter directly. Your data will not be passed on to third parties or processors within the meaning of Art. 28 GDPR. To send the newsletter, we use a service of the service provider who collects your personal data on our behalf in accordance with Process Art. 28 GDPR. Your data will not be passed on to third parties.Purpose and legal basis
We process your data for the purpose of sending the newsletter on the basis of your consent in accordance with. Art. 6 para. 1 lit. a GDPR. By unsubscribing from the newsletter, you can withdraw your consent at any time with future effect. Declare Art. 7 Para. 3 GDPR. There is no legal or contractual obligation to provide your data, but it is not possible to send the newsletter without providing your data.
Storage period
Save after registering for the newsletter we will provide the dates a maximum of 24 hours until the registration is confirmed. After successful confirmation, we will save your data until you withdraw your consent (unsubscribe from the newsletter) and for technical reasons beyond this for a maximum of 7 days. Registration of an user accountType and scope of processing
For the use of certain areas of our website you have the possibility to register a user account. The information collected during registration via the required fields is required to provide access to the user account. In addition, you can voluntarily provide additional information for additional (comfort) features.
For the registration of a user account, the transfer of your personal data takes place exclusively in accordance with this data protection declaration.
Purpose and legal basis
We process your data for the purpose of providing a user account for the performance of a contract with you in accordance with Art. 6 sec. 1 lit. b GDPR. There is a contractual obligation to provide your data, as this information is necessary to identify you and to fulfill the contract on our part. There is no legal obligation to provide the data. Without the provision of this information, it is not possible to register a user account and thus not to enter into a contract.
In addition, the processing of additional information provided voluntarily for the purpose of providing further (comfort) functions is based on your consent in accordance with Art. 6 sec. 1 lit. a GDPR. By deactivating the functions / By deleting the voluntary information in the user account, you can declare your revocation in accordance with Art. 7 sec. 3 GDPR at any time with effect for the future.
Storage time
We store your personal data as part of the provision of the user account for the duration of the contractual relationship. After the end of the contract / deletion of the user account, further storage of your data will only take place if legal retention obligations (e.g. tax and commercial law) exist.
Additional information that you provide to us on the basis of your consent will only be stored until you revoke your consent by disabling the functions / deleting the data, but at the latest until the end of the contract on which the provision of the user account is based.
Registration of a customer account
Type and scope of processing
As part of order processing, we collect your personal data for the registration of a customer account. You can choose to order as a guest or register a permanent user account. The information collected during registration via the mandatory fields is identical in both cases and is required for the processing of the order in the online shop. When registering a permanent user account, we also collect a password that you have set yourself. In addition, you may voluntarily provide additional information that you believe is necessary to process the order. Your personal data will only be passed on to third parties (e.g. shipping service providers / forwarding agents) and processors in accordance with Art. 28 GDPR only to the extent necessary for the processing of the order.Purpose and legal basis
We process your personal data for the purpose of registering a customer account for the performance of a contract with you in accordance with Art. 6 sec. 1 lit. b GDPR. There is a contractual obligation to provide your data as far as it relates to the mandatory fields, as this information is necessary for the identification of you and for the fulfilment of the contract on our part. There is no legal obligation to provide the data. Without the provision of this information, the order in our online shop and thus a contract is not possible. There is no obligation to provide the additional information provided voluntarily. The order in our online shop is also possible without the disclosure of the voluntary information.
The additional processing of your password for the registration of the permanent user account takes place for the purpose of providing a customer account and for the presentation of your previous purchases as well as for the storage of your purchase-related data (e.g. storage of billing address, various delivery addresses) on the basis of your consent in accordance with Art. 6 sec. 1 lit. a GDPR. By deleting your customer account, you can declare your revocation in accordance with Art. 7 sec. 3 GDPR at any time with effect for the future.
Storage time
When you order as a guest, your personal data is stored until the complete processing of your order (end of contract). When registering a permanent customer account, store the purchase-related data beyond the end of the contract until your consent is revoked (deletion of the customer account). In both cases, further storage of your data will only take place if there are legal retention obligations (e.g. tax and commercial law).
Presences on social media platforms
We maintain so-called fan pages or accounts or channels on the networks mentioned below in order to provide you with information and offers within social networks and to offer you further ways to contact us and to find out about our offers. In the following, we inform you about what data we or the respective social network process from you in connection with the access and use of our fan pages/accounts.
Data we process from you
If you wish to contact us via Messenger or Direct Message via the respective social network, we will normally process your username, through which you contact us and store any other data you provide if this is necessary to process/respond to your request.
The legal basis is Art. 6(1) sentence 1 f) GDPR (processing is necessary to safeguard the legitimate interests of the controller).
(Static) Usage data we receive from the social networks
We receive automatically provided statistics about our accounts through Insights functionalities. The statistics include the total number of page views, likes, page activity and post interactions, reach, video views/views, and the proportion of men/women among our fans/followers.
The statistics contain only aggregated data which cannot be related to individuals. They are not identifiable to us.
What data you process social networks
In order to view the content of our fan pages or accounts, you do not have to be a member of the respective social network and no user account is required for the respective social network. Please note, however, that when the respective social network is accessed, the social networks also collect and store data from website visitors without a user account (e..B. technical data in order to be able to view the website to you) and use cookies and similar technologies, which we have no influence on. Details can be found in the privacy policy of the respective social network (see the corresponding links above) If you wish to interact with the content on our fan pages/accounts, e.B.g. comment, share or like our postings/posts and/or contact us via Messenger functions, prior registration with the respective social network and the provision of personal data is required. We have no influence on the data processing by the social networks in the context of your use. To our knowledge, your data will be stored and processed in particular in connection with the provision of the services of the respective social network, furthermore for the analysis of the usage behaviour (using cookies, pixel/web beacons and similar technologies) on the basis of which advertising based on your interests is played out both within and outside the respective social network. It cannot be excluded that your data will be stored by the social networks outside the EU/EEA and will be passed on to third parties.
Information on, among other things, the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines on the use of cookies and similar technologies in the context of the registration and use of social networks can be found in the social protection policy/cookie policy. There you will also find information about your rights and possibilities of objection.
Facebook page
When you visit our Facebook page, Facebook (Meta) collects, among other things, your IP address and other information that is available on your PC in the form of cookies. This information is used to provide us, as the operator of the Facebook pages, with statistical information about the use of the Facebook page. Facebook provides further information on this under the following link: Insights.
By means of the transmitted statistical information, it is not possible for us to draw conclusions about individual users. We only use these in order to be able to respond to the interests of our users and to continuously improve our online presence and to ensure the quality of it.
We collect your data via our fan page only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide "publicly."
The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f) GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1 a), Art. 7 GDPR.
Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.
Together with Facebook, we are responsible for the personal content of the fan page. Data subject rights can be asserted with Meta Platforms Ireland Ltd. as well as with us.
According to the GDPR, the primary responsibility for the processing of Insights data lies with Facebook and Facebook fulfils all obligations under the GDPR with regard to the processing of Insights data, Meta Platforms Ireland Ltd. makes the essence of the Page Insights supplement available to the data subjects.
We do not make any decisions regarding the processing of Insights data and the storage period of cookies on user devices.
Further information can be found directly on Facebook (supplementary agreement with Facebook): Information about Page Insights.
Further information on the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use can be found in Facebook's privacy policy/cookie policy:
Facebook Privacy Policy
Facebook Cookie Policy
Instagram page
When you visit our Instagram page, Instagram (Meta) collects, among other things, your IP address and other information that is available on your PC in the form of cookies. This information is used to provide us, as the operator of the Instagram pages, with statistical information about the use of the Instagram page. Instagram provides further information on this under the following link (Note: by clicking on the following link, you will be taken to the website of the social network Facebook, also part of the Meta Group. However, the information provided via the link applies equally to the social network Instagram): Facebook Insights.
By means of the transmitted statistical information, it is not possible for us to draw conclusions about individual users. We only use these in order to be able to respond to the interests of our users and to continuously improve our online presence and to ensure the quality of it.
We collect your data via our fan page only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide "publicly."
The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f) GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1 a), Art. 7 GDPR.
Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.
Together with Instagram, we are responsible for the personal content of the fan page. Data subject rights can be asserted with Meta Platforms Ireland Ltd. as well as with us.
The primary responsibility for the processing of Insights data under the GDPR lies with Instagram and Instagram fulfils all obligations under the GDPR with regard to the processing of Insights data, Meta Platforms Ireland Ltd. makes the essence of the Page Insights supplement available to the data subjects.
We do not make any decisions regarding the processing of Insights data and the storage period of cookies on user devices.
Further information can be found directly on Instagram (supplementary agreement with Facebook): Information about Page Insights.
Further information on the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use can be found in Instagram's privacy policy/cookie policy (Note: by clicking on the following link you will be taken to the website of the social network Facebook):
Meta Privacy Policy
This information can also be viewed in the help section of the Instagram website via the following link:
Instagram Terms of Use
LinkedIn page
LinkedIn is a social network of LinkedIn Inc. based in Sunnyvale, California, USA, which enables the creation of private and professional profiles of natural persons and company profiles. Users can maintain their existing contacts within the social network and make new ones. Companies and other organizations can create profiles where photos and other company information are uploaded to present themselves as employers and hire employees. Other LinkedIn users have access to this information and can write their own articles and share this content with others. The focus of the network is on the professional exchange on specialist topics with people who have the same professional interests.
When using or visiting the network, LinkedIn automatically collects data from users or visitors during use or visit, such as user name, job title and IP address. This is done with the help of various tracking technologies. LinkedIn provides benefits based on the data collected in this way, among other things, information, offers and recommendations.
We collect your data via our company profile only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide "publicly."
The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis for the processing extends to Art. 6 para. 1 a, Art. 7 GDPR.
Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.
Together with LinkedIn, we are responsible for the personal content of our company profile. Data subject rights can be asserted at LinkedIn Inc. as well as with us.
We do not make any decisions regarding the data collected on the LinkedIn site using tracking technologies.
For more information about LinkedIn, visit: about.linkedin.com.
Further information on data protection at LinkedIn can be found at: LinkedIn Privacy Policy.
Further information on the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use on LinkedIn can be found at: LinkedIn Cookie Policy.
Google Tag Manager
Type and scope of processing
We use the Google Tag Manager of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland. Google Tag Manager is used to manage website tags from a single interface and allows us to control the exact integration of services on our website
This allows us to flexibly integrate additional services to evaluate users' access to our website.
Purpose and legal basis
The use of Google Tag Manager is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR.
Storage time
The actual storage time of the processed data is not influenced by us, but is determined by Google Ireland Limited. For more information, see the privacy policy for Google Tag Manager: Google Tag Manager Terms of Service.
PayPal Express Checkout
Type and scope of processing
We have integrated components from PayPal Express Checkout on our website. PayPal Express Checkout is a service of PayPal Pte. Ltd. and offers online payment solutions worldwide.
If you choose PayPal Express Checkout payment method, your data required for the payment process will be automatically sent to PayPal Pte. Ltd., San Jose, California, US.
Within this framework, the following data is usually collected: name, address, company if applicable, e-mail address, telephone and mobile phone number and IP address.
Purpose and legal basis
The use of the service is based on the implementation of a contract, i.e. for the processing of payment transactions in accordance with Art. 6 sec. 1 lit.b. GDPR.
Storage time
The actual storage time of the processed data is not influenced by us, but is determined by PayPal Pte. Ltd.. For more information, see the privacy policy for PayPal Express Checkout: PayPal Privacy Policy.
Paypal Analytics
Type and scope of processing
We have integrated components from Paypal Analytics on our website. Paypal Analytics is a service of PayPal Pte. Ltd. and offers online payment solutions worldwide.
Paypal Analytics uses cookies and other browser technologies to evaluate user behaviour. This information is used, among other things, to verify the authenticity of payments.
Purpose and legal basis
The use of Paypal Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR.
Storage time
The actual storage time of the processed data is not influenced by us, but is determined by PayPal Pte. Ltd.. For more information, see the privacy policy for Paypal Analytics: PayPal Privacy Policy.
Stripe Payments
Type and scope of processing
We have integrated components from Stripe Payments on our website. Stripe Payments is a service of Stripe, Inc. and offers online payment solutions worldwide.
If you choose Stripe Payments payment method, your data required for the payment process will be automatically sent to Stripe, Inc., San Francisco, California, US.
Within this framework, the following data is usually collected: name, address, company if applicable, e-mail address, telephone and mobile phone number and IP address.
Purpose and legal basis
The use of the service is based on the implementation of a contract, i.e. for the processing of payment transactions in accordance with Art. 6 sec. 1 lit.b. GDPR.
Storage time
The actual storage time of the processed data is not influenced by us, but is determined by Stripe, Inc.. For more information, see the privacy policy for Stripe Payments: Stripe Privacy Policy.