PRIVACY STATEMENT

Privacy Statement and Information for Data Subjects Pursuant to Articles 13 and 14 of the EU General Data Protection Regulation

1. Scope and general information regarding data processing

1.1 The information regarding data protection set forth below applies to the processing of personal data by OLYMP Stores KG and by OLYMP Digital KG, both with registered offices at Höpfigheimer Straße 19, 74321 Bietigheim-Bissingen, Germany.

1.2 The processing of personal data belonging to customers of our OLYMP stores is subject to the general information regarding data protection stipulated in this Privacy Statement and the special information set forth in Section II below. The controller pursuant to Article 4 of the EU General Data Protection Regulation (hereinafter, “GDPR”) is OLYMP Stores KG, Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany, datenschutz@olymp.com.

1.3 The use of the website at www.olymp.com and of the services and offerings offered through this website is subject to the general information regarding data protection stipulated in this Privacy Statement and the special information set forth in Section III below. This website is offered by OLYMP Digital KG, Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany, shop@olymp.com as the controller pursuant to Article 4 of the GDPR.

1.4 You can contact our Data Protection Officer by e-mail at datenschutz@olymp.com or by mail at our postal address (Attention: Data Protection Officer).

1.5 Protecting your personal data is important to us, in particular, protecting your personal rights when we process and use your personal data. Personal data will be processed in compliance with the provisions of the GDPR.

2. Storage period

Your data will be used only for the period of time required for the existing customer relationship, unless you have given your consent to us or we have legitimate interests in further processing your personal data. In these cases, we will process your data until you withdraw your consent or until you object to our legitimate interests. Irrespective thereof, we are obligated by commercial and tax laws to save your address, payment and order information for a ten-year period.

3. Your rights

3.1 You have the following rights vis-à-vis us regarding your personal data. You have the right to:

- access,

- rectify or erase,

- restrict processing,

- object to processing, and

- portability.

Please forward all inquiries in writing to OLYMP Stores KG or OLYMP Digital KG, Re: Data Protection, Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany, or to datenschutz@olymp.com.

3.2 In addition, you have the right to lodge a complaint with a data protection supervisory authority if you are not satisfied with our processing of your personal data.

1. Generally, your provision of your personal data to us as part of an inquiry, an order or a purchase in one of our OLYMP Stores, or directly to OLYMP Stores KG (your last name, first name, e-mail address and/or postal address) is voluntary. This data is used to manage your contract and/or process your inquiries and/or your orders (legal basis: Article 6 (1) b) of the GDPR).

2. If you registered for the OLYMP INSIDER, we will use your data pursuant to the following consent (Article 6 (1) a) of the GDPR):

I agree to OLYMP Stores KG and OLYMP Digital KG (hereinafter jointly, “OLYMP”) collecting, storing, processing and using data provided by me for marketing, information and market research purposes.

To facilitate the provision of certain services, my data will be shared with contracted companies as required for the provision of such services. For detailed information regarding data protection and the preservation of the rights of data subjects as stipulated by Article 13 of the GDPR I can refer to OLYMP’s privacy statement available at www.olymp.com/de_en/company/datenschutz/ a paper copy of which is available at OLYMP stores.

By checking the respective box or boxes, I agree to being informed by OLYMP by mail, e-mail, telephone, text message regarding products, exclusive offerings and campaigns, the latest trends and styles, invitations to participate in customer surveys, product reviews, and news.

I hereby consent to OLYMP’s processing of my personal data for the purposes detailed above. In addition, I consent to OLYMP’s analyzing opening and click rates and my purchasing behavior in connection with e-mail advertising and evaluating such information for demand-oriented marketing. I can withdraw my consent at any time in whole or in part to take effect going forward. To withdraw my consent, I can write to OLYMP Stores KG, Re: Data Protection, at Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany or send an e-mail to datenschutz@olymp.com.


The only information you are required to provide is your preferred method of contact. The provision of all other information, marked separately, is voluntary; if provided, such information will be used to address you personally. After you have given your consent, we will store data you have provided for marketing purposes (legal basis: Article 6 (1) p. 1 a) of the GDPR).

You can withdraw your consent at any time by writing to OLYMP Stores KG, Re: Data Protection, at Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany or by sending an e-mail to datenschutz@olymp.com. In compliance with your consent, your data will be shared with and used by OLYMP Digital KG, Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany.

Please note that when we send our newsletter to you based on your consent, we will evaluate your user behavior (legal basis: Article 6 (1) a) of the GDPR). To enable us to effect such evaluation, our e-mails include web beacons or tracking pixels that display single-pixel image files saved on our website. At the time of evaluation, we link the data detailed in Section III item 2.1 below and the web beacons with your e-mail address. The data so collected is used to compile a user profile which we use to tailor our newsletter to meet your specific interests. We collect information on the date and time you read our newsletter and the links in the newsletter on which you click and we use this information to deduce your personal interests. We then link this data with your customer data. You can object to such tracking at any time to take effect going forward by writing to us at shop@olymp.com.

3. To the extent you provide us with personal data, we will not transmit any such personal data to any third party, except

- to the extent you consented to such transmission (see Section II item 2 above);

- as part of the processing of your inquiries and/or your orders and your use of our services: to subcontractors commissioned by us to whom we transmit only such data as is required to fulfill the respective assignment and such contractors will use such data for specific purposes only;

- as part of processing activities pursuant to Article 28 of the GDPR: to service providers; and

- in compliance with legal obligations: to parties authorized to obtain such personal data.

1. As part of your use of the website at www.olymp.com and the services and offerings provided through the website, the following information also applies:

2. Automated data collection and processing by the browser

2.1 As with every other website, our server collects information automatically and stores it temporarily in server log files transmitted by the browser unless you deactivate such collection. If you view content in our website, we collect the following data which for technical reasons we need if we are to display the contents of the website to you and to ensure the stability and security thereof (legal basis: Article 6 (1) f) of the GDPR):

- the IP address of the computer from which the inquiry is sent;

- the file inquired about by the client;

- the http response code;

- the Internet page from which you are visiting (referrer URL);

- the time the server inquiry is sent;

- the type and version of the browser used; and

- the operating system on the computer sending the inquiry.

No server log files are evaluated in association with an individual person. The provider is not able to associate the data with any specific person or persons at any time. The data is not merged with data from any other sources.

2.2 We use the remarketing technology of Google AdWords as well as Google Tag Manager, an advertising platform of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (hereinafter, “Google”). Using pseudonyms, users who have visited our website are approached again with targeted advertising on the pages of the Google partner network. Cookies can be used for this purpose (see 5. below), which make it possible to recognize an Internet browser again. These usage profiles are helpful in the analysis of the behavior of visitors and are used to target product recommendations and prospective customer-based advertising. The pseudonymized usage profiles are not combined with personal data concerning the person referred to by the pseudonym without the explicit and separately granted consent of that person. If and when Google transmits data to the United States in this context, Google is bound by the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). The legal basis for our use of Google AdWords is Article 6 (1) p. 1 f) of the GDPR. You can object to the collection and storage of your data for web analysis and marketing purposes at any time with effect in the future by activating Google’s deactivation link available at https://www.google.com/settings/ads/plugin. For more information on Google remarketing and to view Google’s privacy statement, please refer to http://www.google.com/privacy/ads/.

2.3 This website uses Google Analytics, a web analytics service provided by Google. Google Analytics uses text files, referred to as cookies, which are saved on your computer to facilitate analysis of your website use. The information generated by cookies (see item 5. below) regarding your use of this website typically is transmitted to and saved on a Google server located in the United States. If and when IP anonymization is activated on this website, Google will truncate your IP address for transmission among member states of the European Union or to other member states of the Agreement on the European Economic Area. Only in exceptional cases will your full IP address be transmitted to a Google server in the United States and then truncated. At the request of the operator of this website, Google will use the information to evaluate your use of this website, to compile reports on website activity, and to provide the operator of this website with other services relating to website activity and Internet use (see description of Google AdWords’ remarketing technology in item 2.2 above). The IP address transmitted from your browser as part of Google Analytics will not be merged with any other data held by Google. You may refuse the storage of cookies by selecting the appropriate settings in your browser software; however, please note that if you do so you may not be able to use the full functionality of this website.

In addition, you can object to Google’s collection of data generated by cookies which data relates to your use of this website (including your IP address) as well as to Google’s processing of the data. To do so, download and install the browser plug-in available at http://tools.google.com/dlpage/gaoptout?hl=de.

In view of the discussion about the use of analysis tools with full IP addresses, we hereby inform you that this website uses Google Analytics with the addendum _anonymizeIp(). This means that IP addresses are truncated before being processed and cannot be associated with individual persons. Please click this link, particularly if you are using a browser on a mobile device, to prevent the anonymized collection by Google Analytics for your browser on this website in the future through opt-out cookies.

In connection with Google Analytics we also use the functions of Google Signals, a service Google uses to provide reports about the number of users across devices and about diverse groups of users based on various device combinations used. To prepare these reports, Google uses data provided by users who activated the Personalized Advertising option in their Google account settings. Google Signals only is used with activated IP anonymization. This means that users’ IP addresses are truncated for transmission among member states of the European Union or to other member states of the European Economic Area. Because truncated IP addresses cannot be associated with individual persons, no assumptions can be made regarding the identity of individual users. If you object to the collection of data by Google Signals, you can deactivate the Personalized Advertising option in your Google account settings at any time: https://support.google.com/ads/answer/2662922?hl=de.

We use Google Analytics to analyze and enhance the use of our website regularly. The resulting statistics allow us to improve our offerings and make them more interesting for you, the user. In exceptional cases in which personal data is transmitted to the United States, Google is bound by the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). The legal basis for our use of Google Analytics including Google Signals is Article 6 (1) p. 1 f) of the GDPR.

Information regarding the third-party provider is as follows: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001; terms of use: http://www.google.com/analytics/terms/de.html; overview of data protection: http://www.google.com/intl/de/analytics/learn/privacy.html; privacy statement: http://www.google.de/intl/de/policies/privacy.

2.4 This website uses Google AdWords Conversion Tracking, a web analytics service provided by Google Inc. (hereinafter, “Google”). Google AdWords Conversion Tracking also uses cookies which are saved on your computer to facilitate analysis of your website use. The information generated by cookies regarding your use of this website is transmitted to and saved on a Google server located in the United States. Google will use the information to evaluate your use of this website, to compile reports on website activity on behalf of the operator of this website, and to provide other services relating to website activity and Internet use. If and when Google transmits data to the United States in this context, Google is bound by the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). The legal basis for our use of Google AdWords Conversion Tracking is Article 6 (1) p. 1 f) of the GDPR. If required, Google will transmit this information to third parties if and when such transmission is mandated by law or such information is processed by third parties on behalf of Google. At no time will Google associate such information with other information held by Google. You can prevent the use of cookies in general by disallowing the storage of cookies in your browser.

2.5 We use the services of Google Maps on this website to allow us to display interactive maps directly on the website and thus facilitate your convenient use of the map function. The legal basis for our use of Google Maps is Article 6 (1) p. 1 f) of the GDPR.

When you visit this website, Google will be notified that you have accessed the respective page. In addition, the data specified in 2.1 above will be transmitted regardless of whether you have logged into a user account created for you by Google. When you log into Google, your data will be associated directly with your account. If you do not want your data to be associated with your Google profile, log out before activating the button. Google will save your data in its user profiles and will use it on a needs basis for promotional and/or market research purposes and/or to design its website. In particular, these analyses are conducted (even for users who have not logged in) for the purposes of publishing needs-based advertising and to inform other users of the social medium of your activities on our website. You have the right to object to the creation of such user profiles; contact Google if you wish to exercise this right.

For more information regarding the purpose and scope of the collection and processing of data by the provider of the plugin and for details on your rights in this regard and on the privacy protection settings you can select, please refer to the provider’s privacy statement available at http://www.google.de/intl/de/policies/privacy. Google also will process your personal data in the U.S.A. where it is bound by the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework).

2.6 Our website uses the web analytics service of intelliAd Media GmbH, Sendlinger Str. 7, 80331 Munich, Germany (hereinafter, “intelliAd”). For the need-based design as well as the optimization of this website, anonymized usage data is collected and stored in aggregate form and usage profiles using pseudonyms are also created from this data. Cookies are stored locally when the intelliAd tracking functions are used. You can use the relevant setting in your browser software to prevent the storage of the cookies; however, please note that if you do so you may not be able to use the full functionality of this website. The legal basis for our use of intelliAd is Article 6 (1) p. 1 f) of the GDPR.

You can object to the collection and storage of data by intelliAd at any time with immediate effect for the future by clicking https://login.intelliad.de/optout.php.

2.7 We participate in the partner program set up by affilinet GmbH, Sapporobogen 6-8, 80637 Munich, Germany (hereinafter, “affilinet”) through which advertisements can be published. affilinet uses cookies to trace the origin of orders. Among other things, affilinet is able to recognize that you have clicked the partner link on this website. In addition, if an order is placed, information regarding the order, the proceeds, and any returned merchandise is transmitted to affilinet. The basis for the storage of affilinet cookies and the transmission of information is Article 6 (1) p. 1 f) of the GDPR. Our legitimate interest in participating in affilinet’s partner program is to publish target group specific advertising and ensure reasonable remuneration for our advertising partners. For more information on the use of data by affilinet, please refer to the company’s privacy statement.

2.8 We also use the Website Custom Audiences retargeting pixel provided by Facebook Inc., 1601 South California Avenue, Palo Alto, CA 94304, United States (hereinafter, “Facebook”). Website Custom Audiences is used to generate a non-reversible and non-personal checksum (hash value) from your usage data, which can be transmitted to Facebook for marketing and analysis purposes. The pixel targets the Facebook cookie. The legal basis for our use of the Website Custom Audiences retargeting pixel is Article 6 (1) p. 1 f) of the GDPR. Additional information about the scope and purpose of data collection and the subsequent processing and use of data by Facebook as well as your setting options to protect your privacy are listed in Facebook’s privacy guidelines which, for example, are available at Facebook Website Custom Audiences (https://www.facebook.com/ads/website_custom_audiences/) and Facebook Privacy (https://de-de.facebook.com/policy.php). If you do not wish to have your data collected by Website Custom Audience or if you would like to object to the use of Website Custom Audiences, deactivate the respective functions at https://www.facebook.com/ads/website_custom_audiences/.

2.9 In addition, we use the Criteo cookie developed by Criteo GmbH, Gewürzmühlstraße 11, 80538 Munich, Germany (“Criteo”). This cookie (on cookies, see item 5. below) helps us collect information regarding your user behavior in an anonymized form for marketing purposes. Based on this information, Criteo can analyze user behavior and display targeted product-related suggestions in advertising banners when you visit other websites. The data collected using this cookie is not used to identify you personally as a visitor of our website. The legal basis for our use of the Criteo cookie is Article 6 (1) p. 1 f) of the GDPR. For more information on the Criteo cookie, please refer to http://www.criteo.com/de/privacy.

We also use Criteo’s cross-device services to facilitate more personal advertising across diverse browsers and devices. This service allows us to share information, including technical identifiers in your registration information, on our website, or in our CRM system, with trustworthy advertising partners. To this end, we pseudonymize (hash) e-mail addresses, for example, and compare them with a pool of pseudonymized e-mail-addresses. This allows us to link your devices and/or environments and offer you seamless user experiences on the devices and/or environments you are using.

The legal basis for our use of Criteo’s services is Article 6 (1) p. 1 f) of the GDPR. Our legitimate interest is to ensure personalized and interest-based advertising for our customers. For more information on Criteo’s privacy policy, please refer to http://www.criteo.com/de/privacy. If you do not want your information to be stored and/or used by Criteo’s service, please go to http://www.criteo.com/de/datenschutzrichtlinie and select ON in the opt-out function. A new cookie (opt-out cookie) will then be set in your browser; it prevents Criteo’s service from collecting and processing information on your user behavior. You can reactivate this function by setting the opt-out function to OFF. Note that this setting must be saved for every browser used. If your browser has been set to prevent the activation of cookies, the opt-out cookie also will be affected.

You may refuse the storage of cookies by selecting the appropriate settings in your browser software; however, please note that if you do so you may not be able to use the full functionality of this website.

2.10 We also use a service provided by the Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, United States (hereinafter, “Microsoft”) called Bing Ads. This allows us to track the activities on our website of users who have accessed our website through Bing Ads. If you access our website through one of these ads, a cookie will be stored on your computer. A Bing Tag has been integrated into our website. A Bing Tag is a code used in connection with the cookie to store some non-personal data regarding your use of our website including the duration of your visit to our website, the sections of our website you viewed, and the ad through which you accessed our website. No information on your identity is collected. The legal basis for our use of Bing Ads is Article 6 (1) p. 1 f) of the GDPR.

The information collected can be transmitted to a Microsoft server in the United States and saved there, generally for no more than 180 days. If and when Microsoft transmits data to the United States in this context, Microsoft is bound by the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework). You can object to the collection of data generated by the cookie, which data relates to your use of our website, and the processing of this data by deactivating the storage of cookies. Doing so may limit the functionality of this website. In addition, Microsoft may apply cross-device tracking to track your user behavior across diverse electronic devices and, therefore, can display personalized advertising on or in Microsoft websites and apps. You can deactivate this function at http://choice.microsoft.com/de-de/opt-out.

You can find more information on Bing’s analytics services on the Bing Ads website at https://help.bingads.microsoft.com/#apex/3/de/53056/2. More information on data protection at Microsoft and Bing is available in Microsoft’s privacy statement available at https://privacy.microsoft.com/de-de/privacystatement.

2.11 We offer you an online guide to help you select the right size when ordering garments from our website. Operated by Fit Analytics GmbH, Sanderstraße 28, 12047 Berlin, Germany, www.fitanalytics.com, the guide can be accessed by clicking the Size Guide button. When using the size guide, you can opt to transmit the following data to Fit Analytics to obtain a recommendation regarding your size:

- height,

- weight,

- body shape (chest/belly),

- preferences regarding fitting (e.g., tight or loose),

- age (optional), and

- reference brand and product (optional).

Fit Analytics only will collect this data in an anonymized form and will process it only to determine the individual customer’s size and to continuously optimize the processes on which the recommendation feature is based. To this end, Fit Analytics uses a session cookie that saves the following data:

- recommended size,

- session ID (randomized sequence of numbers),

- time and date,

- type of browser, and

- anonymized IP address (using IP masking).

All IP addresses are saved in a truncated (anonymized) form only and in addition are encoded by hashing. IP addresses are used exclusively for purposes of identifying sessions and to fend off cyberattacks (e.g., DoS attacks). Session cookies are valid for ten days so customers returning to our website within this period of time can be identified automatically and do not need to re-enter the data required for size recommendations. If the session cookie still is active, the recommended size also can be displayed directly on the page with the product details without the customer having to reopen the size guide. The legal basis for our storage of personal data is Article 6 (1) p. 1 f) of the GDPR.

To determine which sizes to recommend, Fit Analytics also uses anonymized data relating to previous purchases and/or returned merchandise. This data is collected when orders are placed in our online shop. The data collected cannot be associated with any natural person and includes

- time and date of purchase,

- order number,

- product number,

- selected size, and

- price (if applicable, currency).

You can prevent the session cookie from being saved by configuring your web browser accordingly. To request information regarding data about you that has been stored or to request that your data be deleted, please contact Fit Analytics (datenschutz@fitanalytics.com) and provide the session ID saved in your session cookie. Because Fit Analytics does not save any information by which you can be identified personally, you will be required to provide your session ID to request information or deletion. For more details and for the contact information through which you can request more details, please refer to Fit Analytics’ privacy statement.

2.12 On this website we use a plugin provided by the web analytics service available from New Relic Inc. (hereinafter, “New Relic”). The plugin allows us to collect and analyze statistics regarding the speed of our website and to determine whether our website can be accessed and how quickly each page is displayed after being accessed. New Relic is located at 188 Spear Street, Suite 1200 San Francisco, CA 94105, U.S.A.

New Relic uses cookies. When a user accesses a website containing a New Relic plugin, the user’s browser establishes a direct connection with New Relic’s servers.

New Relic is notified through the embedded plugin that a user has accessed the respective page. If the user has logged into New Relic, New Relic can associate the visit to the user’s New Relic account. If the user is not a member of New Relic, New Relic will save the user’s IP address.

New Relic’s privacy statement at https://newrelic.com/privacy contains information on the purpose and scope of the collection, processing, and use of data by New Relic, on users’ rights in this regard, and on the setting options available to users regarding privacy protection.

Users who are members of New Relic and who do not want New Relic to collect data concerning them through our website and/or to associate such data with the member data saved by New Relic must log out from New Relic before visiting our website.

2.13 For side-wide messages and exit-intent layers on this website we use the services of Hello Bar LLC, 450 B Street #775, San Diego, CA 92101, U.S.A. Side-wide messages and exit-intent layers are special highlighted notifications we use on our website to attract your attention to specific offerings and services. The legal basis for our use of side-wide messages and exit-intent layers is Article 6 (1) p. 1 f) of the GDPR. Our legitimate interests are to make the design of our website appealing and to address prospects in a targeted manner.

2.14 Our website www.olymp.com uses cookies/marketing IDs for marketing purposes to enable us to display our advertising on partner websites and in apps and e-mails to visitors interested in our products. Retargeting technologies use cookies or marketing IDs and display advertising based on your past browsing behavior. To object to such interest-based advertising, please go to

http://www.networkadvertising.org/choices/

or

http://www.youronlinechoices.com/.

2.15 We use the function ReCaptcha from Google to recognize bots, e.g. when entering data, in online forms. Legal basis is our legitimate interest to avoid misuse of our website (Art. 6 Para. 1 f) GDPR). Further information on the purpose and scope of the data collection and processing by Google ReCaptcha can be found in the data protection declaration: https://www.google.com/policies/privacy/, opt-out into any tracking (see Section 2.3) can be found at: https://adssettings.google.com/authenticated. There you will also find further information on your rights in this regard and setting options to protect your privacy: http://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

3. Collection and processing of data provided on a voluntary basis

3.1 General contact

Generally, your provision of your personal data to us by e-mail or through our website (your last name, first name, e-mail address and/or postal address) is voluntary. This data is used to manage your contract, process your inquiries and/or your orders (legal basis: Article 6 (1) b) of the GDPR), perform our own market research or opinion polls, and send our own advertising by mail (legal basis: Article 6 (1) f) of the GDPR). The personal data you provide will not be used in any other way; in particular, it will not be shared with third parties for advertising purposes, market research or opinion polls.

3.2 Use of our online shop

If you choose to order goods through our online shop, it will be necessary for you to provide your personal data which we need to process your order so that we can enter into a contract with you. Data which is mandatory to facilitate contract management will be so marked; all other information you provide is offered on a voluntary basis. We process the data you provide to handle your order. The legal basis for this is Article 6 (1) b) of the GDPR.

You can set up a customer account in which we can store your data for your future purchases. When you create a customer account, the data you provide will be saved on a revocable basis. You can erase all other data in the Customer section at any time. To delete your customer account, please send an e-mail to shop@olymp.com.

In addition, we can process the data you provide to inform you about other products in our portfolio which may be of interest to you or to e-mail technical information to you (legal basis: Article 6 (1) f) of the GDPR).

As part of payment processing, your data will be shared with our payment services provider BS PAYONE GmbH and when you pay through PayPal, to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (legal basis: Article 6 (1) b) of the GDPR).

3.3 Klarna invoice

When you select Klarna Invoice as your payment option, you are consenting to our collecting the following personal data necessary to process your purchase and to carry out identity and credit checks: your first and last name, address, date of birth, gender, e-mail address, IP address and telephone number. We also need to collect data related to your order to process your purchase, for example, the quantity of the products, product numbers, amount of the invoice and tax as a percentage, and to transmit this data to Klarna AB, Sveavägen 46, 11134 Stockholm, Sweden (hereinafter, “Klarna”).

 

For your purchase to be processed, the data is transmitted to Klarna to enable Klarna to generate an invoice based on the invoicing method you requested as well as to enable Klarna to carry out identity and credit checks. Pursuant to the German Federal Data Protection Act (Bundesdatenschutzgesetz), Klarna has a legitimate interest in the transmittal of the buyer’s personal data and requires this data in order to obtain information from credit agencies for purposes of carrying out identity and credit checks. The following credit agencies can be used for this purpose:

 

In Germany

- Schufa Holding AG, Kormoranweg 5, 65203 Wiesbaden

- Bürgel Wirtschaftsinformationen GmbH & Co. KG, Postfach 5001 66, 22701 Hamburg

- Creditreform Boniversum GmbH, Hellersbergstr. 11, 41460 Neuss

- Deltavista GmbH, Freisinger Landstr. 74, 80939 Munich

- Arvato infoscore Consumer Data GmbH, Rheinstr. 99, 76532 Baden-Baden

 

In Austria

- CRIF GmbH, Diefenbachgasse 35, A-1150, Vienna

 

In the Netherlands

- Experian B.V., Postbus 13128, 2501 EC The Hague

- BKR, Dodewaardlaan 1, 4006 EA Tiel

- FOCUM, Postbus 768, 8000 AT Zwolle

 

In the context of its decision to establish, fulfill, or terminate the contractual relationship, in addition to data for the purpose of address verification Klarna collects and uses information about the buyer’s previous payment history as well as the probability values (score values) of such payment practices in the future. Klarna calculates those score values using a scientifically recognized mathematical statistical method. Among other things, Klarna also uses your address data for this purpose. If that calculation indicates that your credit rating is insufficient, Klarna will immediately inform you accordingly.

 

Find more information in Klarna’s privacy statement for Germany, Austria and Netherlands.


You can revoke your consent to Klarna’s use of your personal data at any time. However, under certain circumstances Klarna may retain the right to process, use, and transmit your personal data, provided this is necessary for the contractually agreed-upon payment processing by Klarna’s services, is required by law, is ordered by a court of law or is mandated by a government authority.

You can obtain information about your personal data stored by Klarna at any time. If you, as buyer, would like to have access to that data or wish to inform Klarna about changes in the stored information, write to datenschutz@klarna.de, datenschutz@klarna.at, or dataprotectie@klarna.nl

3.4 Newsletter:

I agree to OLYMP Stores KG and OLYMP Digital KG (hereinafter jointly, “OLYMP”) processing data provided by me for e-mail marketing, information and market research purposes.

 

By subscribing to the newsletter, I agree to being informed by e-mail about products, exclusive offerings and campaigns, the latest trends and styles, invitations to participate in customer surveys, product reviews, and news by OLYMP. I consent to OLYMP’s analyzing opening and click rates and my purchasing behavior and evaluating such information for demand-oriented marketing.

 

I can withdraw my consent at any time in whole or in part to be effective going forward. If I choose to withdraw my consent, I can do so by writing to OLYMP Stores KG, Re: Data Protection, at Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany or sending an e-mail to datenschutz@olymp.com.


If you subscribe to our newsletter, we will need your e-mail address and you have the option to provide your name, date of birth, and information on the OLYMP store in your vicinity. The data only will be used to communicate with you within the framework of our newsletter offerings. By subscribing to the newsletter you are declaring your consent to our storing of the aforementioned data for the purpose of sending newsletters to you until you unsubscribe. The legal basis for our processing of your data is the consent you have given as part of the double-opt-in. The products and services promoted are specified in the declaration of consent. The data will not be used for any other purpose. To withdraw your consent, you can unsubscribe at any time either from within the newsletter or by sending an e-mail to datenschutz@olymp.com.

To enable you to subscribe to our newsletter, we use the double-opt-in process. This means that after you register we will send an e-mail to you at the address you have provided. In the e-mail, we will ask you to confirm your desire to receive our newsletter. If you do not confirm your subscription within 24 hours, your information will be blocked and erased automatically after one month. In addition, we will store the IP addresses you used and the date and time of your registration and of your confirmation of your registration. The purpose of this process is to have proof of your registration and, if required, to clarify that there has been no fraudulent use of your personal data. The only information you will be required to provide to us to receive our newsletter is your e-mail address. The provision of all other information, marked separately, is voluntary; if provided, such information will be used to address you personally. After you have confirmed your registration we will store the data you provided so that we can send the newsletter to you (legal basis: Article 6 (1) p. 1 a) of the GDPR).

Based on your consent, your data will be shared with and used by OLYMP Stores KG, Höpfigheimer Str. 19, 74321 Bietigheim-Bissingen, Germany.

Please note that when we send our newsletter to you based on your consent, we will evaluate your user behavior (legal basis: Article 6 (1) a) of the GDPR). To enable us to effect such evaluations, our e-mails include web beacons or tracking pixels that display single-pixel image files saved on our website. At the time of evaluation, we link the data detailed in Section III item 2.1 above and the web beacons with your e-mail address. The data so collected is used to compile a user profile which we use to tailor our newsletter to meet your specific interests. We collect information on the date and time you read our newsletter and the links in the newsletter on which you click and will use this information to deduce your personal interests. We then link this data with your customer data.

You can object to such tracking at any time for the future by writing to us at shop@olymp.com.

To send out e-mails we use the Salesforce Marketing Cloud customer relationship management module of Salesforce.com Inc., The Landmark, One Market Street, Suite 300, San Francisco, California, CA 94105, U.S.A.. Salesforce Marketing Cloud is a database administration service. The data is processed in the U.S.A. Salesforce.com has registered this service as part of the EU-US Privacy Shield regulation. The legal basis for our use of Salesforce Marketing Cloud is Article 6 (1) p. 1 f) of the GDPR. For more information on Salesforce Marketing Cloud and the data processed, please refer to https://www.salesforce.com/de/company/privacy/.

3.5 Direct advertising by E-Mail

Your e-mail address, which we have received in connection with the sale of a product or service, is also exclusively used for direct advertising by e-mail products of ours which are similar to the ones that you ordered. You will receive these e-mails independently of whether you have subscribed to the newsletter.

You can opt out of the use of your e-mail address at any time without incurring anything other than the transmission costs at the basic tariffs. You can opt out in any advertising e-mail itself or by sending a message to our e-mail address shop@olymp.com.

When we send out direct advertising by e-mail, we analyze the behavior of our users. To send out e-mails, we use Salesforce Marketing Cloud. For more information on our analysis of user behavior and on Salesforce Marketing Cloud, please refer to 3.4 above.

3.6 Job portal

You can apply for specific vacancies and/or send blanket applications for employment to us through our job portal. Your data (name, e-mail address, contact information, application documents) will be processed only as part of your application (refer to Article 6 (1) b) of the GDPR, and § 26 of the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG)) or if you have consented to our using your data in connection with other job postings (refer to Article 6 (1) a) of the GDPR). You can withdraw your consent to our processing of your application data at any time.

Note regarding sensitive data: We hereby expressly inform you that documents which are part of your application including, but not limited to, curriculums vitae, report cards and other materials you transmit to us, may contain particularly sensitive information regarding your mental or physical health, racial or ethnic origin, political opinions, religious or philosophical convictions, membership in organization such as trade unions or political parties, or your sexual orientation.

 

If you transmit this type of information to us in your online application, you are expressly declaring your consent to our processing of such data for the purpose of managing your application. The data will be processed in accordance with this Privacy Statement and all other applicable legal provisions.


If your application is rejected or if you are not selected for the position for which you applied, the data you transmitted will be deleted four months after the application process has come to an end, at the earliest, unless there are legal provisions conflicting with such deletion or if the continued storage of the data is necessary as part of the furnishing of evidence or if you consented to such continued storage.

For our job portal we use software developed by rexx systems GmbH, Süderstraße 75-79, 20097 Hamburg, Germany. The legal basis for our use of this software is Article 6 (1) p. 1 f) of the GDPR. Our legitimate interest is to ensure the design of our user interface and the related applicant management software is appealing to applicants.

4. Transmission of personal data to third parties

To the extent you provide us with personal data, we will not transmit any such personal data to any third party, except

- to the extent you consented to such transmission (see items 3.4 and 3.5 above);

- as part of the processing of your inquiries and/or your orders and your use of our services: to subcontractors commissioned by us to whom we transmit only such data as is required to fulfill the respective assignment and such contractors will use such data for specific purposes only (e.g., providers of shipment services);

- as part of processing activities pursuant to Article 28 of the GDPR: to service providers; and

- in compliance with legal obligations: to parties authorized to obtain such personal data.

5. Cookies

We use our own cookies to make our website more user-friendly. Cookies are datasets that are transmitted from the web server to your browser and saved there for future retrieval. The cookies are used primarily to recognize the Internet browser. Cookies are used to control sessions and make statistical evaluations. These cookies contain no personal data whatsoever. If you voluntarily choose to log in to the website automatically, your login data (e-mail address and password) will be stored in an additional cookie on your computer. You can set your browser so that no cookies are stored on your hard drive and/or any cookies already stored temporarily are deleted. To do so, please follow the instructions provided in the help function of your browser regarding the blockage and deletion of cookies.

6. Social media

Our website includes links to the social network YouTube to which the following privacy statement applies:

To display our videos, we use the video service of YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, United States (hereinafter, “YouTube”).

Where YouTube videos are integrated directly into our website, the content of the embedded videos is transmitted from YouTube directly to your browser. At the same time, certain data is transmitted from your browser to YouTube. This happens only after you click on the video. The legal basis is Article 6 (1) f) of the GDPR. We have no influence on the scope of the data which YouTube collects in this context. At far as we know at the present time, this involves the following data, specifically for the display of embedded YouTube videos:

1 the website page you visited which contains the video;

2 general data transmitted by your browser (IP address, browser type and version, operating system, time); and

3 your Google user name if you are a registered YouTube/Google user and logged in.

Browser add-ons also can be used to mask out embedded YouTube videos, so that no data is collected by YouTube. For more information on the purpose and scope of the collection and processing of your personal data by YouTube, please refer to YouTube’s privacy statement available at https://www.google.de/intl/de/policies/privacy which also includes information regarding your rights and setting options to protect your privacy. Google also processes your personal data in the United States and is bound by the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework).

 

November 21, 2018