Privacy policy

Data Privacy Policy

Thank you for your interest in our online shop. Protecting your privacy is important to us. In this data privacy statement, we provide information on how we treat your data.

  1. Scope of Application

This data privacy statement applies to all content and products on the website www.dencaibiza.com (including www.ch.dencaibiza.com and www.uk.dencaibiza.com). In accordance with the German federal data protection act (Bundesdatenschutzgesetz) and electronic communications act (Telemediengesetz), it provides information on how and why our website collects and processes your personal data, including details on the type and volume of data collected.

Please note that security risks associated with transmitting data over the Internet can never be completely eliminated. Absolute protection against access by third-parties is not possible.

  1. Terminology
  2. a) Personal Data
    Personal data are data that refer to an identified or identifiable natural person, specifically data that allow this person to be identified directly or indirectly by linking name, ID number, location data, recognition of online activity (e.g. cookies), or other specific traits.
  3. b) Processing
    Processing means every method and every action in which personal data are used. In particular, the collection, recording, organization, arrangement, storage, adaptation or alteration, retrieval, consultation, use, transmission, dissemination or other form of provision, alignment or combination, restriction, deletion or destruction.

  4. Type and Use of Personal Data

a). Data on Accessing the Server

We collect data (log files) about every visit to the server that hosts our website. These data include the URL of the web page visited; file, date and time of the visit; amount of data transmitted; report on completed visit; browser type and version; the user’s operating system; referrer URL (previously visited page); the user’s IP address; the requesting provider.

Data on accessing the server are used exclusively to ensure better functionality and security, and they allow us to optimize our website and its services.

Art. 6, para. 1, sentence 1 f of the European Union’s General Data Protection Regulation (GDPR) provides the legal basis for processing these data. See Section 6 for information on third-party processing of IP addresses.

b). Cookies

Our website uses “cookies” – small text files that are stored on your computer. Your browser accesses these files.

Art. 6 para. 1 f of the GDPR provides the legal basis for using cookies. We have a legitimate interest in collecting data and therefore require cookies for direct marketing purposes, to ensure smooth functioning of our website, and for service optimization.

Most browsers can be set to block cookies. If you choose to block cookies, however, we cannot guarantee that you can access all website functions without limitation.

c). Customer Data

When you enter and submit personal data via a form on our website, the purpose of data processing depends on the type of form submitted:

  • If you order items as a registered customer, we use your personal data to manage your account and to manage contract conclusion and payment transaction (Art. 6 para. 1 sentence 1 b GDPR).
  • When you use our contact form, we use your personal data to process your request (Art. 6 para. 1 sentence 1 a, f GDPR).
  • When you write posts or comments, we use your personal data in so far as necessary to process your posts and comments.
  • When you subscribe to our newsletter, we use your personal data to send you the desired news.

We have a legitimate interest in collecting data within the meaning of Art. 6 para. 1 f GDPR, because your request (registration, order, contact, participation in promotions, newsletter subscription) cannot be processed without your data.

d). Purchasing Data

When you make purchases in our shop, we collect the relevant data on your purchase (item, purchase price, date of sale, customer number).
We use these data for the purpose of contract conclusion and payment transaction (Art. 6 para. 1 sentence 1 b GDPR) and for statistical purposes (Art. 6 para. 1 sentence 1 f GDPR).

e). Dealing with Customer Posts and Comments

When you submit a post or comment on our website, your IP address is stored to ensure our website’s security: if your text is in violation of the law, we wish to track your identity.

f). Advertisements, Subscriptions, Newsletter

You have the option to subscribe to the entire website as well as to all comments on your posts. You will receive an e-mail confirming your e-mail address. We do not pass on stored data to third parties. You have the option to cancel your subscription at any time.

  1. Data Transmission

All personal data processed are transmitted to our main office in Switzerland (see contact details below). The European Commission has determined that Switzerland offers adequate data protection (Commission Decision 2000/518/EC of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided in Switzerland, OJEU L 215 of 25 August 2000, p. 1).

  1. Third-Party Data Processing

a). Hosting

Our website is operated on the servers of the web hosting company www.shopify.de. This provider processes personal data on our behalf for the operation and optimization of our website. The legal basis is Art. 6 para. 1 sentence 1 f GDPR.

The data privacy policy of the provider contains information on the purpose, scope, and use of data on the part of the provider as well as your rights in regard to protecting your data:

Shopify International Limited’s data privacy policy:

b). Shop Service Provider

To manage purchases in our shop, we have engaged an external service provider (

When you make purchases, we pass on your personal data to the service provider if this is necessary for managing the purchasing procedures.

The data privacy policy of the service provider contains information on the purpose, scope, and use of data on the part of the service provider as well as your rights in regard to protecting your data:

Shopify International Limited’s data privacy policy:

c). Payment Transaction

To collect and process data for payment transactions, we have engaged an external service provider (

When we monitor and process payments, we pass on your personal data to the service provider if this is necessary for the payment transaction.

The data privacy policy of the service provider contains information on the purpose, scope, and use of data on the part of the service provider as well as your rights in regard to protecting your data:

Mollie B.V.’s data privacy policy:

d). Logistics and Shipping Companies

To manage purchases and arrange shipping, we have engaged an external service provider (

When we deliver your purchase, we pass on your personal data (first and last name, address) to the logistics company responsible if this is necessary for completing the delivery. When you have granted your permission, we also pass on your e-mail address and telephone number so that you are kept up-to-date on delivery status.

The data privacy policy of the service provider contains information on the purpose, scope, and use of data on the part of the service provider as well as your rights in regard to protecting your data:

Zenfullfillment’s data privacy policy (Visable GmbH):

e). Social Media Plug-Ins, Website Analytic Tools

  1. Facebook

Our website uses social media plug-ins from the social media company Facebook. These services are offered by the companies Facebook Inc. and Google Inc. (“Plug-In Providers”). Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). Google+ is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).

When you visit our web pages that have one of these plug-ins, your browser creates a direct link to the servers of Google or Facebook. The content of these plug-ins is transferred directly from the Plug-In Provider to your browser and integrated into the page. By integrating the plug-ins, the Plug-in Provider receives the information that you have visited the respective page of our website, even if you do not have a profile with the social network company or are not currently logged in. This information (including your IP address) is transmitted directly to a server of the Plug-In Provider in the US and stored there.

If you are logged into one of the social networks, the Plug-In Provider can immediately associate the visit to our website to your Facebook profile. When you interact with plug-ins, for example, when you use the “Like” or “+1” buttons, the corresponding information is also sent directly to the Plug-In Provider’s server, where it is stored. In addition, this information is published on the social network and shown to your contacts.

The data privacy policy of the Plug-In Provider contains information on the purpose and scope of data collection; on the further processing and use of the data by the Plug-In Provider; and on your rights and setting options to protect your privacy:

Facebook’s data privacy policy: http://www.facebook.com/policy.php
Google’s data privacy policy:

Facebook and Google are obliged to observe the Privacy Shield Agreement between the EU and US on the collection, use, and storage of personal data from the EU member states. The agreement was published by the US Department of Commerce. More information is available here:

Facebook: https://m.facebook.com/about/privacyshield
Google: https://support.google.com/analytics/answer/7105316?hl=de

If you do not want Google and Facebook to immediately link the data collected on our website with your profile on one of these social networks, you must log out of the networks before visiting our website. By using a script blocker such as “NoScript,” you can completely prevent plug-ins with add-ons from loading on your browser (http://noscript.net).

  1. Instagram

We have integrated Instagram functions and services on our website. These functions are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.

When you are logged on to your Instagram account, you can link the content of our pages to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to our website with your user account. Please note that we, as the website provider, have no knowledge of the content of the data transmitted nor of how Instagram uses these data.

Instagram’s data privacy policy: https://instagram.com/about/legal/privacy/

  1. Google Analytics

    Our website uses Google Analytics, a web analysis service from Google Inc. (“Google”). Google Analytics uses “cookies,” which are text files that are stored on your computer and permit how you use the website to be analyzed. The information on how you use our website that is generated by cookies is generally transmitted to a Google server in the US, where it is stored. If our website uses IP anonymization, before transmission and storage, Google will shorten your IP address within Member States of the European Union as well as in other States that are party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the US and shortened there. Google uses these data on our behalf to evaluate your use of the website, to send us reports on website activity, and to provide us with other services that are connected with online and Internet usage. The IP address transmitted from your browser for Google Analytics purposes will not be combined with other Google data. To prevent us from collecting your data via Google Analytics, you can deactivate cookies in your browser settings. Please note, however, that if you do so, you will not be able to use all functions of this website to their full extent. You can prevent the data generated by cookies about your use of the website (including your IP address) from being sent to and processed by Google, by downloading and installing the browser plug-in available via the following link:

Please note that Google Analytics has been expanded on our website by the code “gat. anonymizeIp();” in order to guarantee anonymous collection of IP addresses (so-called IP masking).

Google Analytics’ data privacy policy:

  1. Voluntary Nature of Data Provision

The provision of personal data when visiting our website is neither legally nor contractually required; it is also not required to conclude a contract. You are under no obligation to provide personal data when you visit our website; however, data on accessing the server are collected automatically when you visit our website. If you order products, register as a customer with us, or fill out the contact form, the fields marked in bold are required for submitting the form in question.

  1. Data Retention: Duration

Data on accessing the server, cookies
Data on accessing the server are stored due to security reasons (e.g. evidence in the case of abuse or fraudulent actions) for a period of 7 days at the longest. Afterwards, the data are deleted. If it is necessary to retain data as evidence, these data are exempted from the deletions until the incident has been conclusively resolved.

In the event that third-party providers process IP addresses and transaction data based on cookies, we have no influence on how long data are retained. Data privacy policies of third parties involved with our website are listed under Section 5. These statements provide information on how long data are retained.

Contractual data (data entered, purchase data)
We store personal data that we process for contractual purposes in accordance with retention periods specified by tax and commercial law or other legally defined periods (the retention periods are between 2 and 10 years). If we transfer your personal data to third parties for the purpose of contractual and payment transactions (Section 5c), we have no influence on the duration of processing by these companies. For such information, please contact these companies directly; we will be happy to provide you with their contact details.

Newsletter
If you unsubscribe from our newsletter, we will refrain from sending you newsletters in the future. Your address will be added to a so-called block list. Nevertheless, we will continue to process your first and last names as well as your e-mail address in order to deliver proof, if necessary, that you once subscribed to our newsletter.

Other data entered
We store other data entered in our online forms for as long as we need them to process your request if these data are not subject to retention periods specified by tax and commercial law or other legally defined periods (the retention periods are between 2 and 10 years).

  1. User Rights

You are free to assert your rights under the GDPR via e-mail or by regular mail. The contact details of the provider and the person responsible in the EU are found below.

a). Revocation of consent to data processing

If you have granted your consent, you have the right to revoke it. Please note that a revocation does not affect the legality of the processing granted until the revocation (no retroactive effect of the revocation).

b). Objection to processing of personal data

You have the right to object at any time to personal data processed on the basis of Art. 6 para. 1 sentence 1 f GDPR, provided that there are grounds for the objection arising from your particular situation and provided that there are no compelling security-related reasons for continuing to collect the data. If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data for such marketing purposes without stating a reason (Art. 21 GDPR).

c). Information

You have the right within the scope of GDPR to request and receive information free of charge about all personal data we have that concerns your person (Art. 15 GDPR).

d). Rectification

Furthermore, as defined in GDPR, you have the right to have personal data rectified (Art. 16 GDPR) and deleted (Art. 17 GDPR); the right to restrict the processing of personal data (Art. 18 GDPR); and the right to data portability (Art. 20 G).

e). Deletion

Within the scope of GDPR, you have the right to request that your personal data are deleted if no higher, legally defined reason prevents this.

f). Complaints to the supervisory authority

In justified cases, you also have the right to lodge a complaint at the data protection supervisory authority responsible for our website (Art. 77 GDPR).

  1. Contact Details

a). Provider

AYA Trading GmbH
Weidstrasse 12
8803 Rüschlikon
Switzerland

b). EU representative as per GDPR

Angel Pizarro
Camp de Mar 16 4o 3a
08330 Premia de Mar (BCN)
Spain

contact@dencaibiza.com

c). Data Protection Authority

Landesbeauftragter für den Datenschutz und Informationsfreiheit Baden-Württemberg
Postfach 10 29 32,

70025 Stuttgart

Phone: +49 711 615 541 - 0
Fax: +49 711 615 541 - 15
e-mail: poststelle@lfdi.bwl.de