Data Controller & Responsible Body
Modular Merch UG (Haftungsbeschränkt), Proskauer Strasse 11, 10247 Berlin,
Duly represented by Ali Samadpour, Phillip Gunawan
Data process manager, firstname.lastname@example.org
What information we collect and why we collect it
How we use that information
Your rights with regard to the processing of personal data by Modular Merch UG
Purpose of data collection, data processing and data use
Modular Merch UG is engaged in operating online publications covering forthcoming trends and news in fashion, art, music, and culture. Modular Merch UG collects and processes personal data for the following purposes:
Operation of the website, including statistical analysis of the use
Provision of content
Execution of contracts
Groups of people concerned and the associated data and category of data
Customer and user data, data from partner companies that are needed to fulfil the purpose.
Children under 16
Our website is not directed toward children under 16 and we will not knowingly collect information for any child under the age of 16.
If you are the parent of a child under the age of 16 and have a concern regarding your child’s information on our website, please contact us at email@example.com.
Recipients or groups of recipients to whom data may be disclosed
Public authorities in connection with an overriding legal regulation, contractors in connection with a partnership in accordance with Article 28 of the General Data Protection Regulation (GDPR), external partners and internal departments of Modular Merch UG (Haftungsbeschränkt) to fulfil the purpose.
Time limits for the deletion of data
Under statutory provisions, a variety of obligations and periods apply with regard to the keeping of data. Once these retention periods have expired, the corresponding data must be erased as a matter of routine. Any data not affected by this is deleted if the purposes mentioned above ceases to apply.
Transfer of data to third countries
By using social plugins, such as Facebook like button, data may be transferred to a third country.
Legal basis for the collection and processing of personal data
Legal basis for the processing of personal data on the basis of the user’s consent is Art. 6 (1) lit. a GDPR.
Legal basis for the processing of personal data which is necessary for the conclusion or performance of a contract entered in the interest of the user is Art. 6 (1) lit. b GDPR. This also applies to pre-contractual processes.
Legal basis for the processing of personal data which is required to fulfil a legal obligation concerning Modular Merch UG is Art. 6 (1) lit. c GDPR.
Legal basis for the processing of personal data which is necessary in order to realize a legitimate interest held by either Modular Merch UG or a third party, except where such considerations are overridden by the need to protect the user’s interests or fundamental rights, is Article 6 (1) lit. f GDPR.
B. Information We Collect
We collect information to provide better services to our users and improve our business. We collect information in two ways:
Information you give us or information provided through a social network
For example, some of our services require you to sign up for an account, provide information for a contest or award, or link an account through a social network. The information we collect may include email, name, phone number, address, or credit card information. Such information is necessary to render the services requested and/or to provide contractual services. Legal basis for such data processing is Article 6 (1) lit. a, b or f GDPR. Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply, e.g. if the services are performed in full or if you unsubscribe from our services.
When you contact us, either by email or by using our contact form, we collect the data you have submitted with your request (e.g. name. email) and may keep a record of your communication to help solve any issues you might be facing. Legal basis for such data processing is Article 6 (1) lit. b and lit. f GDPR. Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply, e.g. if we have processed your request.
We work with social networks including, but not limited to Facebook, Twitter, Snapchat, Instagram, and YouTube. We have access to information you directly provide and information through those social networking services based on your privacy settings on those networks. Please see section V. below for further details. Such information serves to enhance the usability of our services. Legal basis for such data processing is Article 6 (1) lit. f GDPR. Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply.
Information we get from your use of our services
We may collect usage information when you visit different parts of our site or use our applications. We may also automatically collect certain technical information such as device-specific information (such as your hardware model, operating system version, device type, unique device identifiers, and mobile information if you use a mobile device to access the site). Please see section I. below for details. Such information is necessary to provide our services and is used in anonymized or pseudonym zed form only. Legal basis for such data processing is Article 6 (1) lit. f GDPR. Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply.
C. Information We Share
We do not share personal information with companies, outside organizations and individuals unless one of the following circumstances applies:
With your consent
We will share personal information with companies, outside organizations or individuals if we have your consent to do so. We may also seek your additional consent for purposes subsequently notified to you.
For external processing
For legal reasons
In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We will share personal information with companies, outside organizations or individuals if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to meet any applicable law, regulation, legal process or enforceable governmental request, detect, prevent, or otherwise address fraud, security or technical issues or protect against harm to the rights, property or safety of our users or the public as required or permitted by law.
In case of a sale or asset transfer
If we become involved in a merger, acquisition or other transaction involving the sale of some or all of our assets, user information, including personal information collected from you through your use of our services, could be included in the transferred assets. Should such an event occur, we will use reasonable means to notify you and ask for your consent where applicable.
In anonymous form for business purposes
We may share anonymous, non-personally identifiable information publicly and with our partners such as businesses which we have a relationship with, advertisers or connected sites. For example, we may share information to show trends about the general use of our services.
D. Information Security
We work hard to protect our users from unauthorized access to or unauthorized alteration, disclosure or destruction of information we hold however no website is entirely secure. You should protect the account information in your possession as well. We follow generally accepted standards to protect the personal information submitted to us, both during transmission and once it is received. If you have any questions about the security of your personal information, you can contact us at firstname.lastname@example.org.
I. Your Privacy Consent Management
When visiting our website, we will ask you for your consent to use certain cookies. You can at any time revoke your consent for either all services or for individual services by clicking the button below. If you have any questions or concerns on this process send an email to email@example.com.
If you choose not to accept cookies on our website, it is possible that the functionality of our website may be limited and some services may not be usable.
We and our service providers, marketing partners, and affiliates may use advertising cookies to deliver ads that we believe are more relevant to you and your interests. For example, we may use targeting or advertising cookies to customize the advertising and content you receive on our site, to limit the number of times you see the same ad on our site and to help measure the effectiveness of our advertising campaigns. These cookies remember what you have looked at on the site and other sites, and may be combined with other information acquired from third parties.
Please see below for a full list of cookies and detailed information on the associated processing of personal data and how to opt-out of the use:
II. Cookies we use with your consent only
We will only use such cookies with your prior consent. Legal basis for such data processing is Article 6 (1) lit. a GDPR. Unless statutory provisions provide otherwise, the data will be deleted if you revoke your consent or if the purpose ceases to apply. In any cases, personal data will be deleted after 24 months at the latest.
Consent “Yes” or “No”
Log file data (IP (anonymised)
This list represents all (personal) data that is collected by or through the use of this service.
Date and time of visit
Anonymized IP address
Opt-in and opt-out data
Location of Processing
Duration to store the data
The revocation certificate of a previously given consent will be kept for a period of three years. On the one hand, storage is based on our accountability according to Art. 5 para. 2 GDPR. This obliges the compliance with the processing of personal data according to the General Data Protection Regulation. On the other hand, storage in the regular limitation period according to § 195 BGB of three years. This limitation period begins with the end of the year in which the claim arose (§ 199 BGB). Consequently, the three-year limitation starts at the end of 31.12. and ends three years later on 31.12.
You can contact the data protection officer of Modular Merch at firstname.lastname@example.org
We use Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA (“Google”), on our website. Google Analytics uses so-called “cookies”, text files that are saved on your computer and that enable your use of the website to be analysed. The cookie-generated information about your use of our website is usually transmitted to and stored on a Google server in the United States. However, if you are in a country that is a member state of the European Union or a contracting party to the Agreement on the European Economic Area, and if IP address anonymization has been activated on our website, Google will first truncate your IP address. Only by way of exception will the full IP address be transmitted to a Google server in the United States and truncated there. Google will use this information on our behalf for the purposes of analysing how you use our website, compiling reports on website activity and providing further services related to website and internet use to the website operator. The IP address transmitted through Google Analytics from your browser will not be associated with any other data held by Google. You can disable cookies by setting your browser accordingly; however, if you do this you may not be able to use the full functionality of our website. You can also prevent the data generated by the cookie and related to your use of this website (including your IP address) being transmitted to and processed by Google by downloading and installing the browser plug-in available here: https://tools.google.com/dlpage/gaoptout
Google Universal Analytics
We use Google Universal Analytics, a service provided by Google LLC, to collect information about and to analyse the use of our website. During registration, a cookie containing a unique user ID is set. This allows Google to associate user behaviour on different devices with a single user. The information collected, directly and indirectly, by the cookie (technical specifications like device type, browser version, operating system, screen resolution and user behaviour like pages visited, interactions with our content, duration of your visit, products viewed and purchased in our own shop or linked to at other shops) is stored on a Google server in the US. Google has a Privacy Shield certification, which ensures an appropriate level of data protection. Google uses this data to create user profiles on our behalf. No further data will be submitted to Google that would enable identification of the user. We combine the user profiles created by Google with other data, including personal data about the user, which we collect via MailChimp (Newsletters), Google Ad Server (Advertising) and social networks like Facebook, Instagram in order to evaluate user behaviour. We use this information to improve our service and to display interest-based recommendations for content and shopping products. The user profiles will not be shared with third parties (we may share anonymous summaries and reports with our partners). The cookie expires after 24 months. The user profiles in Google Analytics are stored for 24 months. The profiles created by us are stored for 24 months. You can revoke your consent at any time at You can revoke your consent at any time at I. Cookies and by sending an email to email@example.com.
Google DoubleClick Ad Exchange and Google Tag Manager
III. Other cookies we use
Facebook Custom Audiences
Our website uses the “Custom Audiences” remarketing service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). This service allows us to advertise products and services to the visitors of our website in a targeted fashion by displaying personalized, interest-based Facebook ads to the website’s visitors, when they use the Facebook social network. Articles marked as ‘sponsored post’ may contain a Facebook Custom Audiences tag of our respective partner. In this case, the respective partner is responsible for the data processing.
If you do not want Facebook to assign this information directly to your Facebook user account, you can deactivate the “Custom Audiences” remarketing service by using the following link: https://www.facebook.com/settings/?tab=ads. You must be logged in on Facebook to do so.
We use Google Optimize on our website, a service of Google Inc. We use Google Optimize to analyse the use of our website in order to improve the usability of our website and the attractiveness of our content. For this purpose, we provide new functions and content to individual user groups and evaluate user behaviour statistically.
More detailed information about the processing of data by Google Optimize can be found under https://policies.google.com/privacy?hl=en-US .
IV. Links to external social networks and social media widgets
Our website includes links to social networks and social media features. These features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the feature to function properly. Social media features and Widgets are either hosted by a third party or hosted directly on our website. Your interactions with these features are governed by the privacy policies of the companies providing them. Please note that Modular Merch UG is not liable for the privacy policies of these companies. We recommend you to read the privacy policies of those companies after you get to one of their websites.
When you visit our Facebook page, Facebook collects personal data, even if you are not a member of Facebook. Please note that we have no control over the type and scope of such data processing. Facebook provides us with aggregated, anonymous demographic data only that helps us to better understand our audience.
Our website has links to our Instagram page and uses social plugins provided by the social network of instagram.com. The sole responsibility for Instagram and its website lies with Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”).
When you visit a page of our website that contains a social plugin of Instagram, your browser establishes a direct connection to the Instagram servers. Instagram directly transfers the plugin content to your browser which embeds the latter into the website, enabling Instagram to receive information about you having accessed the respective page of our website. Thus, we have no influence on the data gathered by the plugin and inform you according to our state of knowledge:
The embedded plugins provide Instagram with the information that you have accessed the corresponding page of our website. If you are logged into Instagram, your visit can be assigned to your Instagram account. If you interact with the plugins, the corresponding information is transmitted from your browser directly to Instagram and stored by it. Even if you are not logged into Instagram, there is possibility that the plugins transmit your IP-address to Instagram.
If you are an Instagram member and do not want Instagram to connect the data concerning your visit to our website with your member data already stored by Instagram, please log off Instagram before entering our website.
For further information regarding the purpose and scope of data collection, and regarding the further processing and use of your data by Instagram, see https://help.instagram.com/519522125107875. There you will find, amongst other things, information regarding settings for the protection of your privacy and regarding your further rights regarding the collecting, processing and use of your data by Instagram.
Our website includes functions of the Spotify music service, provided by Spotify AB, Birger Jarlsgatan 61, 113 56 Stockholm, Sweden (“Spotify”). When you visit a page of our website that contains a Spotify plugin, your browser establishes a direct connection to the Spotify servers, enabling Spotify to receive information that you have visited our website. If you click the Spotify button while being logged in to your Spotify account, you can link the content of our pages to your Spotify profile. Thus, Spotify can associate visits to our pages with your user account.
If you do not want Spotify to connect the data concerning your visit to our website with your member data already stored by Spotify, please log off Spotify before entering our website.
You have the opportunity to receive a newsletter containing targeted information via our web service or new products. In this case, we must collect and save your email address, which we will only use to send the newsletter. You can unsubscribe via our website at any time. At the end of the newsletter you will find a link intended for this purpose and provides a simple way to cancel the newsletter. In this case your data will be deleted.
For sending the newsletter we use MailChimp, a service provided by The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA. The email addresses are processed on our behalf on a MailChimp server in the USA. MailChimp has a Privacy Shield certification that ensures an adequate level of data protection. The email address will be used to send the newsletter.
The newsletters contain a so-called “web-beacon”, i. e. a pixel-sized file that is retrieved from the MailChimp server when the newsletter is opened. These beacons are used to collect the IP address and the time the newsletter was opened as well as the information as to whether the subscriber has clicked on a link contained in the newsletter. MailChimp uses this data to create reports for us about how an email campaign performed and what actions subscribers took.
If you have expressly consented to receiving our newsletter, the legal basis for such processing of personal data is Art. 6 (1) lit. a GDPR. In case we are entitled to send a newsletter based on your previous purchase of goods or services, legal basis for such processing of personal data is § 7 (3) of the German Act Against Unfair Competition (UWG). In this case, the legal basis for the processing of personal data for the purpose of analysing the campaign performance is our legitimate interest (Art. 6 (1) lit. f) GDPR) in improving the quality of our newsletter.
Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply, e.g. if you unsubscribe from the newsletter.
VI. Affiliate Marketing
We use affiliate links on our website. In order to evaluate the use and success of these affiliate offers, we store and analyse information about the use of these links. This includes the IP address and interactions with the affiliate links (like clicks). This information is combined by one of our partners with information from the connected shops. On the basis of this information, anonymous statistics about the success of affiliate offers are compiled (e.g. the number of users who clicked on an affiliate link and the type and number of products purchased in our partner’s shop).
The legal basis for this data processing is Art. 6 (1) lit. f) GDPR. The data will be deleted as soon as the purpose of the processing has ceased to exist, at the latest after 24 months.
VII. Local Storage – HTML5
We may use Local Storage, such as HTML5 to store user preferences. Third parties with whom we partner to provide certain features on our site or to display advertising based upon your web browsing activity may also use HTML 5 to collect and store information. Various browsers may offer their own management tools for removing HTML5. Legal basis for such data processing is Article 6 (1) lit. f GDPR. Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply.
VIII. Log information
When you use our services or view content provided by us, we may automatically collect and store certain information in server logs. This information may include:
Details of how you used our service, such as your navigation paths and search queries.
Mobile related information if you access our website using your mobile device.
Internet protocol address.
Device event information such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request and referral URL.
Cookies that may uniquely identify your browser, mobile device, or your account.
Browser type, operating system, and other technical information.
We may combine this automatically collected log information with other information we collect about you. We do this to improve marketing, analytics, and the products and services we offer you. Such information is used in anonymised or pseudonymized form only. Legal basis for such data processing is Article 6 (1) lit. f GDPR. Unless statutory provisions provide otherwise, the data will be deleted if the purpose ceases to apply.
You may at all times object to the use of personal data for the above mentioned, purposes by informal notification by written letter to Modular Merch UG (Haftungsbeschränkt), Proskauer Strasse 11, 10247 Berlin, Germany, or by email to firstname.lastname@example.org.
IX. Your right to information and other rights of the persons affected
Right to information
You have the right to obtain confirmation as to whether or not your personal data is being processed by us. Where that is the case, you have the right to access to the personal data and the following information:
the purposes of the processing;
the categories of personal data concerned;
the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
the right to lodge a complaint with a supervisory authority;
where the personal data are not collected from the data subject, any available information as to their source;
the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Where personal data is transferred to a third country, you have the right to be informed of the appropriate safeguards pursuant to Article 46 GDPR relating to the transfer.
Right to rectification
You have the right to obtain the rectification of inaccurate or incomplete personal data.
Right to erasure
You have the right to obtain the erasure of personal data where one of the following grounds applies:
the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
you withdraw the consent on which the processing is based according to Article 6 (1) lit a or Article 9 (2) lit. a GDPR, if there is no other legal ground for the processing;
you object to the processing pursuant to Article 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21 (2) GDPR;
the personal data have been unlawfully processed;
the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which Modular Merch UG is subject;
the personal data have been collected in relation to the offer of information society services referred to in Article 8 (1) GDPR.
If Modular Merch UG has made personal data public and is obliged to erase the personal data, Modular Merch UG, taking account of available technology and the cost of implementation, takes reasonable steps, including technical measures, to inform controllers which are processing the personal data you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
The right to erasure shall not apply to the extent that processing is necessary:
for exercising the right of freedom of expression and information;
for compliance with a legal obligation which requires processing by Union or Member State law to which Modular Merch UG is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
for the establishment, exercise or defence of legal claims.
Right to restriction of processing
You have the right to obtain restriction of processing where one of the following applies:
you have contested the accuracy of the personal data, for a period enabling Modular Merch UG to verify the accuracy of the personal data;
the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
Modular Merch UG no longer needs the personal data for the purposes of the processing, but is required by you for the establishment, exercise or defence of legal claims;
you have objected to processing pursuant to Article 21 (1) GDPR pending the verification whether the legitimate grounds of Modular Merch UG override yours
Where processing has been restricted under the above, such personal data shall, with the exception of storage, is only processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
I you have obtained restriction of processing you will be informed before the restriction of processing is lifted.
Notification regarding rectification or erasure of personal data or restriction of processing
Modular Merch UG will communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with the above to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves a disproportionate effort. On your request, Modular Merch UG informs you about those recipients.
Right to data portability
You have the right to receive the personal data you have provided to Modular Merch UG in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller, where:
the processing is based on consent pursuant to Article 6 (1) lit. a of Article 9 (2) or on a contract pursuant to Article 6 (1) lit. b GDPR; and
the processing is carried out by automated means.
In exercising your right to data portability, you have the right to have the personal data transmitted directly from one Modular Merch UG to another controller, where technically feasible.
The right to data portability shall not apply to processing necessary for the performance of a task carried out in the public interest.
Right to object
You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point Article 6 (1) lit. a or lit. f GDPR, including profiling based on those provisions. Modular Merch UG no longer processes the personal data unless Modular Merch UG demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
If you object to processing for direct marketing purposes, the personal data is no longer being processed for such purposes.
Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
This shall not apply if the decision:
is necessary for entering into, or performance of, a contract between the data subject and a data controller;
is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or
is based on the data subject’s explicit consent.
In all such cases, please refer to us by written letter to Modular Merch UG (Haftungsbeschränkt), Proskauer Strasse 11, 10247 Berlin, Germany, or by email to email@example.com.
Right to revocation
You may at all times revoke consent to the processing of personal data. You can use the function on this page at I. Cookies.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data by Modular Merch UG relating to you infringes the provisions of the GDPR.
In all such cases, please refer to us by written letter to Modular Merch UG (Haftungsbeschränkt), Proskauer Strasse 11, 10247 Berlin, Germany, or by email to firstname.lastname@example.org.
If you have any questions about data protection, please feel free to contact us at any time using the details given above.