Privacy Policy

Thank you for visiting our website. The protection of your data is of particular concern to us. We will use your data in compliance with the german Bundesdatenschutzgesetz (BDSG) and the EU General Data Protection Regulation. If you access another website via a link, please use the information on data protection and privacy provided there. We have no influence on the data protection practices of other site operators.

Controller of your personal data is:
Sativa Biosaatgut GmbH
Keltenweg 4
D-79798 Jestetten

Director: Amadeus Zschunke
E-Mail: sativa@sativa.bio
Internet: www.sativa.bio

We are a subsidiary company of Sativa Rheinau AG, Chorbstrasse 43, CH 8462 Rheinau. Phone: +41 52 544 06 00, Fax: +41 52 544 06 01, E-Mail: sativa@sativa.bio, Internet: www.sativa.bio. Personal data collected by us are also regularly processed in Switzerland. The level of data protection in Switzerland corresponds to that of the EU, which is why the EU Commission has issued an adequacy decision pursuant to Art. 45 DS-GVO. 

1. Your Rights
2.
Data collection and processing when visiting our website
 2.1. Cookie Policy
 2.2. Matomo
 2.3. Google Ads & Marketing Tools
 2.4. Google Maps
 2.5. Google reCAPTCHA
 2.6. Google Fonts

3.
Contact Form
4.
Newsletter
5.
Customer Account Registration
6.
Data processing for contract performance/Direct Advertising

1. Your Rights

You have the right of access, the right to rectification, to erasure ("right to be forgotten") and the right to restriction of processing of your personal data in accordance with Art. 15- 18 GDPR. You have the right to data portability in accordance with Art. 20 GDPR. You have the right to object, in particular to the processing of your data for the purposes of direct marketing and to processing which we carry out on the basis of legitimate interests in accordance with Art. 21 GDPR. You also have the right to lodge a complaint with a supervisory authority, for us this is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Dr. Stefan Brink, Postfach 10 29 32, 70025 Stuttgart, Telefon: 07 11/61 55 41-0,  Telefax: 07 11/61 55 41-15, E-Mail: poststelle@lfdi.bwl.de

2. Data collection and processing when visiting our website

When you visit our website we store in log files: the name of the file accessed, the amount of data transferred, notification of successful access, web browser, your provider, your operating system, the country of origin of the requesting system, the website from which you accessed our site (referrer) and the subwebsites. These data are not linked to certain persons. In addition, we log your IP address. We use these data for anonymous statistical evaluation in order to optimize our website and its contents and to ensure the functionality and protection of our IT systems. This serves the protection of the data processed by us. In the event of attacks on our IT systems, we are able to provide the law enforcement authorities with the necessary. These are our legitimate interests within the meaning of Art. 6 para. 1 letter f) GDPR. We store our server log files separately from any other personal data. We will erase your personal data or restrict the processing, if they are no longer necessary in relation to the purposes for which they were collected, if there is no other legal ground for the processing or if you request the erasure or restriction of your data. We process the data within the EU.

The data collected from you when you visit our website and use our forms (contact request, customer account registration, etc.) are processed on the servers of our host provider on our behalf. The servers are located within the EU.

Our legitimate interest in the use of this service within the meaning of Art. 6 Para. 1 lit f) GDPR is the trouble-safe output and presentation of our website, as well as the maintenance of information security.

2.1. Cookie Policy

We use cookies to optimize our website. These are small text files stored on your computer via your browser. Cookies contain a unique identifier (cookie ID).  This enables the visited websites and servers to recognize and assign the specific Internet browser. Cookies are used, for example, to keep your items in your shopping cart when you continue shopping. This allows you to use our website intuitively and helps us to provide better performance. This is our legitimate interest in the sense of Art. 6 para. 1 lit. f) GDPR.

You can prevent cookies from being saved by selecting "Block cookies" in your browser settings. However, this may result in a functional limitation of our website.  All common browsers also offer options for individual handling. You can install appropriate add-ons or block only third party cookies, delete all cookies at the end of the session. You can also completely disable tracking of user activity. (Do-not-Track).

 
This cookie policy has been created and updated by CookieFirst.com.

2.2. Matomo Web Analysis

We use the web analysis service Matomo, operated by Innocraft Ltd. 150 Willis St, 6011 Wellington, New Zealand.

Matomo analyzes how you interact with our website. For this purpose, cookies could be placed on your device. Cookies are used to transfer your IP address, time, place and frequency of visits to our servers.

Your IP address will be anonymized immediately.  With the collected information we create pseudonymised user profiles. This data will not be merged with any other personal data without your consent and will not serve to identify you either.

It is our legitimate interest according to Art 6 Para. 1 lit f) GDPR to use social media plugins to increase the reach of our offers and services. 

You don't want that to happen?

You can object to the collection and processing of your data by clicking on the following link. A deactivation (opt-out) cookie is set in your browser. In this case Matomo will not collect any data from you when you visit our website Attention: the Opt-Out Cookie does not work if you have activated the erasure of all cookies after the end of the session in your browser settings.  All common browsers also offer options for individual handling. You can install appropriate add-ons or block only third party cookies, delete all cookies at the end of the session. You can also completely disable tracking of user activity. (Do-not-Track).

 

For more information on terms of use and Privacy Policy, please visit https://matomo.org/privacy-policy/

2.5. Google Ads & Marketing Tools

We use Google Ads and the Google Ads Remarketing Tag, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA.

Google "cookies" are set for advertising purposes. These transfer data to Google servers in the USA. Google processes the data on the basis of international agreements and on the basis of an adequacy decision of the EU Commission in accordance with Art. 45 GDPR. The provider is certified according to the EU-US Privacy-Shield and is thus obliged to comply with EU data protection standards.

Google analyzes your surfing behavior based on your web or app browser history and also uses data from third-party providers. This allows Google to draw conclusions about e.g. age, gender, location and interests. The authenticated user IDs are temporarily linked to our target group lists. This enables us to use the information in conjunction with Google Ads campaigns to adapt advertising to target groups and to address visitors to our website again with our personalised offers (remarketing). This presupposes that your activities are tracked across different websites (3rd party tracking). The data can be passed on by Google to contract partners.

We use conversion tracking. When you click one of our ads, Google Ads stores a "conversion cookie" valid for 30 days in your browser. If you return to our site within that period, we and Google will recognize you. Personal data will not be processed. Google uses this information to compile anonymous statistics for us that tell us the number of users who clicked our ads and later visited our website.

If you have given Google permission to link the information from the browser history of your devices to your Google account this can be done across devices so that advertisements can be displayed in your smartphone browser according to your interests, which have been determined on the basis of your browser history of other devices such as PC or Tablet. You can withdraw your consent to Google by deactivating Google's cross-device personalised advertising at https://support.google.com/ads/answer/7395996. 

Our legitimate interest in the use of these services within the meaning of Art. 6 para. 1 lit f) GDPR is to analyse the use of our website in order to align our offer and our advertising to your interests.

You can prevent cookies from being saved by selecting "Block cookies" in your browser settings. However, this may result in a functional limitation of our website.  All common browsers also offer options for individual handling. You can install appropriate add-ons or block only third party cookies, delete all cookies at the end of the session. You can also completely disable tracking of user activity. (Do-not-Track).

You can also disable cookies for interest-based advertising through the advertising network initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.

For more information about Google's privacy practices and advertising, please visit https://policies.google.com/privacy or https://policies.google.com/technologies/ads

2.6. Google Maps

We use Google Maps, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

When you visit one of our pages that displays Google Maps, a direct connection is established between your browser and Google servers in the USA to integrate the fonts. The date and time of your visit, the URL of the website accessed and your IP address are transferred to and processed by Google. If you use route planning, the start address entered is also transferred and processed. Google transfers the map/route directly to your browser and integrates it into the website. The data will be processed on the basis of international agreements and on the basis of an adequacy decision of the EU Commission in accordance with Art. 45 GDPR. The provider is certified according to the EU-US Privacy-Shield and is thus obliged to comply with EU data protection standards.

If you are logged into your Google account, this data may be merged with other personal data about you. Google uses your data to create user profiles for the purpose of target-group-oriented advertising and market research and also evaluates these for the purpose of designing its own offers.

Even if you are not logged in, Google may use your data in connection with other users (e.g. browser history) for these purposes. You may object to the creation of your user profile by Google; in particular, you may deactivate Google's cross-device, personalised advertising here https://support.google.com/ads/answer/7395996.

Our legitimate interest in the use of the map service within the meaning of Art. 6 para. 1 lit. f) GDPR is to make it easy for you to find us.

You can prevent this by deactivating Java Script in your browser settings. All common browsers also offer you options for blocking embedded content. You can install appropriate add-ons. However, in this case the map displays will not work. For more information on Google's Terms of Use and Privacy Policy, please visit https://www.google.de/intl/de/policies/privacy/.

2.7. Google reCAPTCHA

We use Google reCAPTCHA, operated by Google LLC. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.

This allows us to check whether people or automated programs (bots) make entries on our site, for example in the contact form. reCAPTCHA analyzes your interaction as soon as you start browsing our site. Your IP address, duration of the visit or cursor movements in the area of the reCAPTCHA field are transferred to Google's server in the USA and evaluated. The data will be processed on the basis of international agreements and on the basis of an adequacy decision of the EU Commission in accordance with Art. 45 GDPR. The provider is certified according to the EU-US Privacy-Shield and is thus obliged to comply with EU data protection standards.

If you are logged into your Google account, this data may be merged with other personal data about you. Google uses your data to create user profiles for the purpose of target-group-oriented advertising and market research and also evaluates these for the purpose of designing its own offers.

Our legitimate interest in the use of this service within the meaning of Art. 6 para. 1 lit f) DS-GVO is to protect our pages from improper automated spying and from SPAM.

Further information about Google reCAPTCHA can be found here https://www.google.com/recaptcha/intro/ and Google‘s privacy policy here https://www.google.com/intl/de/policies/privacy/.

2.8. Google Fonts

We use Google Fonts, operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

When you visit one of our pages, a direct connection is established between your browser and Google servers in the USA to integrate the fonts. The date and time of your visit, the URL of the website accessed and your IP address are transferred to and processed by Google. The data will be processed on the basis of international agreements and on the basis of an adequacy decision of the EU Commission in accordance with Art. 45 GDPR. The provider is certified according to the EU-US Privacy-Shield and is thus obliged to comply with EU data protection standards.

It is our legitimate interest according to Art 6 Para. 1 lit f) GDPR to use Google Fonts to ensure that our texts are quickly integrated and displayed compatible on all devices.

For more information on Google's Terms of Use and Privacy Policy, please visit https://www.google.de/intl/de/policies/privacy/.

Our legitimate interest within the meaning of Art. 6 para. 1 lit. f) GDPR is to offer you comfortable search performance also from our website. For more information on Google's Terms of Use and Privacy Policy, please visit https://www.google.de/intl/de/policies/privacy/.

3. Contact Form

If you use the contact form on our website or send us an e-mail, we process your freely given personal data (e.g. your name and e-mail address) in order to answer your request. We will erase your personal data or restrict the processing, if they are no longer necessary in relation to the purposes for which they were collected, if there is no other legal ground for the processing or if you request the erasure or restriction of your data. Our legitimate interest within the meaning of Art. 6 para. 1 lit f) GDPR  is to make it easier for you to contact us. We process the data within the EU.

We would like to point out that complete data security cannot be guaranteed when communicating by e-mail. In the case of unencrypted e-mails, it is possible that unauthorised third parties may take note of these despite transport encryption.

4.  Newsletter

You can subscribe to our newsletter to receive current offers, dates, advertising or similar information about us by e-mail.

This requires your freely given consent. We proceed according to the Double-Opt-In- procedure: First you enter your name and e-mail address, if applicable with optional interests. After registration you will receive an e-mail informing you of your subscription to the newsletter and asking you to confirm it via the link provided. Among other things, this serves the purpose of preventing the misuse of external e-mail addresses. To prove that your consent meets the legal requirements Registration, confirmation or deregistration are recorded by us, i.e. your IP address and the time of registration, as well as confirmation or deregistration. Legal bases are: Art 6 para. 1 lit a) GDPR and § 7 para. 2 no. 3 and para. 3 UWG.

If you subscribe to our newsletter during or following an order in our online shop, we collect the following additional information in addition to the data mentioned above: Salutation, date of last order, total of last order. We evaluate this for the purpose of analysis and to target our offers more specifically to the customer, this is our legitimate interest.

We will transfer your e-mail address, as well as your name if applicable and optionally your interests, to a newsletter service provider CleverReach GmbH & Co. KG, Mühlenstr. 43, 26180 Rastede, Germany.

The provider evaluates the data statistically for his own purposes in order to optimise the delivery and presentation of the newsletter as well as his own offers. He will not contact you directly and will not pass on the data to third parties. For more information please visit https://www.cleverreach.com/en/data-security/.

The newsletters may contain "web beacons". These are transparent image files that are downloaded from the provider's server when the newsletter is read online. The download will be registered. We also check if and when you read the newsletter and which links you follow. We will use the information provided, including your IP address, your provider and thus your country of origin, browser and operating system, as well as access time, to optimise the newsletter service and to adapt our content to your reading behaviour and interests. Our legitimate interest in the use of these services within the meaning of Art. 6 para. 1 lit f) GDPR is to to be able to adapt our offer and advertising according to your use and interests.

Your declaration of consent is freely given and you can withdraw your consent at any time. To do so, click on the "unsubscribe" link in one of the newsletters or inform us of your withdrawal by other means using the contact details provided. If you unsubscribe, we will delete your data or restrict processing by adding you to a blacklist.

5. Customer Account Registration

You can register on our website and create a customer account. We process the data you provide (e.g. name, address, e-mail address, telephone number, fax number) to open your customer account. You have to fill out the marked mandatory fields. Without these details you can not open an account. The purpose is to simplify the ordering process or contact. When you visit our website in the future, you do not have to re-enter the data necessary to perform a contract, but you log in with your login data.  Your previous orders or requests are stored here. The login data may not be passed on to third parties and must be stored securely in order to prevent unauthorised access by other persons.

You can delete your account at any time by using the function provided for this purpose or by requesting it under the contact details provided.

We reserve the right to regularly erase inactive customer accounts in order to minimize data. Please also save the data stored in your customer account on your devices.

6. Data processing for contract performance/ Direct Advertising

If we conclude a contract, e.g. for the delivery of goods, the provision of a service or the creation of a work, we process the data provided by you (e.g. name, address, e-mail address, telephone number, fax number) for contract performance. You have to fill out the marked mandatory fields. Without these details we are not in a position to fulfil the contract.  The data will be processed in our customer database within the EU and Switzerland. The level of data protection in Switzerland corresponds to that of the EU, which is why the EU Commission has issued an adequacy decision pursuant to Art. 45 DS-GVO.

In order to protect ourselves against fraud, we may process these data to identify atypical order transactions (e.g. if the same address is given in a large number of simultaneous orders using different customer accounts).  This serves the protection of legitimate interests within the meaning of Art. 6 para. 1 lit f) GDPR.

When you order goods, we transfer the data required for delivery to a transport company for the purpose of delivery and notification. We transfer the payment data to the payment service provider selected by you or commissioned by us or to the bank commissioned with the payment. If you already hold an account with a payment service provider, you will be asked to log in during ordering process. In this case it processes your data and its privacy policy applies. The legal basis for data processing is Art. 6 para. 1 lit. b) GDPR.

We reserve the right to use your data beyond the end of the contract on the basis of legitimate interests within the meaning of Art. 6 para. 1 lit. f) GDPR. This is in particular to increase customer loyalty through advertising. For this purpose, we may send you offers and information by letter post, as well as - insofar as we are permitted within the scope of § 7 para. 3 UWG - direct advertising for our own similar goods or services by e-mail. If necessary, we transfer your data (name and address) to a service provider, who processes them on our behalf in order to send the advertising mailings. You can object to the processing of your data for this purpose at any time under the given contact information. After objection to the use for direct marketing, we restrict the processing of your data for further use and erase them after expiry of the retention periods under tax and commercial law, unless you have freely given your consent for further use.