PRIVACY POLICY

1. Responsible party

This company is also the operator of the website.

Habermaass GmbH & Co. KG, August-Grosch-Str. 28-38, 96476 Bad Rodach, Germany, Local Court Coburg, Commercial Register A 5220 General partner: Habermaass Administration GmbH, Bad Rodach, Local Court Coburg, Commercial Register B 4746, Managing Director: Dr. Mario Wilhelm

E-mail address: kundenservice@haba.de

Telephone: + 49 9564 929 6666

VAT ID No. DE 815 831 282

WEEE Reg. No.: DE 51463378

2. Contact for data protection queries

Habermaass GmbH & Co. KG, Data Protection Officer, August-Grosch-Str. 28-38, 96476 Bad Rodach or by e-mail: internet@haba.de.

We process personal data only to the extent necessary.

  • Webshop operation & IT security (server logs, IP address, timestamps, user agent, error logs) – Art. 6(1)(f) GDPR (legitimate interest in secure operation).

  • User account (name, email, login metadata) – Art. 6(1)(b) GDPR.

  • Information about children in the household (first name, date of birth or age, gender), insofar as you voluntarily provide this information to us – Art. 6(1)(a) GDPR (consent). We use this information exclusively to provide age-appropriate information, product recommendations and offers. Providing this information is voluntary and not required for orders. You can withdraw your consent at any time with effect for the future.

  • Order & contract processing (name, billing/delivery address, contact, payment and transaction data, shopping cart/order history) – Art. 6(1)(b) GDPR; legal obligations e.g. under HGB/AO – Art. 6(1)(c) GDPR.

  • Payment processing via selected payment service providers – Art. 6(1)(b) GDPR.

  • Customer service & communication (inquiries, warranty, returns) – Art. 6(1)(b) and (f) GDPR.

  • Fraud prevention, credit checks (B2C/B2B)Art. 6(1)(f) GDPR (risk minimization); if applicable Art. 6(1)(b) GDPR.

  • Debt collection & legal enforcementArt. 6(1)(b), (c) and (f) GDPR.

  • Reach measurement, analysis of website usage and advertising: If you have given consent, we analyze the use of our webshop to improve the offering and usability and to measure and control advertising. Tools used for this purpose include in particular Google Analytics, Microsoft Clarity, Microsoft Advertising, Criteo, Exactag and Prefixbox. Session replays, i.e. movements and inputs on a page, may also be analyzed. The legal basis is § 25(1) TDDDG and Art. 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future.

  • Affiliate marketing: We work with partner programs through which an order is assigned to the referring website. The AWIN network is used for this purpose, through which additional partners may be integrated, currently Targeting360 and R.O.EYE. Pseudonymous identifiers as well as information about the referred order are processed. The legal basis is § 25(1) TDDDG and Art. 6(1)(a) GDPR.

  • Chat and advisory services: For inquiries via our chat, we process the information you provide in the chat history to handle your request. The live chat Userlike is used for this purpose. The legal basis is Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR.

  • Marketing/Newsletter If you subscribe to our newsletter or grant corresponding marketing consents, we process your contact details, your date of birth (if provided) as well as information about the use of our newsletters (e.g. opens and clicks) in order to send you newsletters, product information, recommendations, birthday greetings and other promotional information. For this purpose, we may evaluate your interests, purchases and previous interactions with our products, our webshop and our communication offerings and form recipient groups to tailor content and offers as appropriately as possible. This may also include information about the use of our website and our webshops, in particular regarding viewed products, shopping cart contents, purchase histories and other interactions with our offerings. Where analysis, tracking or marketing technologies are used, this is done exclusively on the basis of the consents you have given for this purpose and within the framework of your chosen cookie and tracking settings. To improve the relevance of our communication, we may use statistical analyses, segmentations, predictions and automated marketing processes. In addition, we may transmit your contact details, in particular your email address, in hashed or otherwise pseudonymized form to advertising platforms, e.g. to Google. This serves to recognize existing customers on the respective platforms, to deliver targeted advertising, to exclude customers from certain campaigns or to create comparable audiences (e.g. "Customer Match" or "Custom Audiences"). The legal basis for the transmission to advertising platforms is our legitimate interest in promoting our own offers to existing customers pursuant to Art. 6(1)(f) GDPR. You can object to this processing at any time (see section 12). The legal basis for the other marketing measures described is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw a given consent at any time with effect for the future. For the sending of newsletters and the carrying out of marketing and automation measures, we use specialized service providers as processors, currently e.g. Klaviyo Inc., USA. Details on the service providers used, recipients of data and transfers to third countries can be found in sections 5 and 7.

We use cookies/similar technologies:

  • Necessary Cookies for providing the shop – § 25 para. 2 TDDDG; subsequent processing – Art. 6(1)(f) GDPR.

  • Optional cookies (e.g. comfort, statistics, marketing) – only with consent§ 25 para. 1 TDDDG, Art. 6(1)(a) GDPR.

On the first visit our Cookie banner (Cookiebot by Usercentrics).

Manage consents / Cookie overview:

https://www.haba-play.com/de-de/cookies

There you will find all cookies used (purposes, providers, durations), change your selection at any time and revoke consents. Cookiebot logs consents in a legally compliant manner.

5. Recipients – categories and specific service providers

We only disclose data if there is a legal basis for doing so (see above) or we are legally obliged. This includes in particular:

5.1 Payment service providers (PSP/Acquirer/Wallet)

5.2 Credit checks (depending on the case, B2C/B2B)

Note on scoring: CRIF/Creditreform canprobability values (score) provide that feed into credit decisions (e.g. selection/limitation of payment methods). You can set out your viewpoints and request a manual review (Art. 22, Art. 21 GDPR).

5.3 Debt collection service providers (depending on customer segment/region)

5.4 Newsletter, marketing, analytics and service providers

  • Klaviyo, Inc. – 125 Summer Street, Floor 6, Boston, MA 02110, USA; E-mail: privacy@klaviyo.com; Web: https://www.klaviyo.com (processing in the USA, section 7)

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Ads / Google Customer Match). Processing in the USA (Section 7).

  • Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (Meta Pixel / Custom Audiences). Processing also in the USA (Section 7).

  • Microsoft Ireland Operations Limited – One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland (Microsoft Clarity for the analysis of session recordings, Microsoft Advertising for ad delivery). Processing also in the USA (Section 7).

  • Criteo SA – 32 Rue Blanche, 75009 Paris, France (recognition of visitors for interest-based advertising).

  • Exactag GmbH – Theodorstraße 178, 40472 Düsseldorf, DE (measurement of advertising effectiveness).

  • Prefixbox Zrt. – Visegrádi utca 31, 1132 Budapest, Hungary (search function of the webshop and its analysis).

  • Lime Connect (Userlike) GmbH – Im Mediapark 8, 50670 Cologne, DE (live chat, formerly Userlike).

  • AWIN AG – Otto-Ostrowski-Straße 1A, 10249 Berlin, DE (affiliate network for attributing referred orders; partners integrated via the network are listed in the cookie overview under section 4).

  • With Google and Meta, the matching of contact data we transmit is carried out on our behalf. The subsequent delivery of advertising and reach measurement on the respective platforms are the responsibility of the respective provider.

5.5 Other recipients and categories

Processors / IT, hosting, website analytics, cloud outsourcing, marketing service providers, shipping/logistics companies, payment and accounting providers, lawyers, authorities/courts (for legal enforcement). Affiliated companies, e.g. HABA Group B.V. & Co. KG.

6. Social Media - Integrations

Our website contains links to social media platforms, recognizable by their respective logos. These links are purely passive; no data transfer takes place, before you click on the respective icon. Only then does your browser establish a direct connection to the server of the respective network. Legal basis: Art. 6(1)(f) GDPR (interests in user-friendly communication and external presentation).

Independent of these links, we use the Meta Pixel on our webshop pages. It is loaded exclusively on the basis of your consent. Which cookies and providers are used and how you can revoke your consent can be found in the cookie overview (sec. 4).

The following links are included:

Facebook

Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

Data protection: https://www.facebook.com/privacy/policy/

Instagram

Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland

Data protection: https://privacycenter.instagram.com/policy/

YouTube

Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Data protection: https://policies.google.com/privacy

Pinterest

Pinterest Europe Ltd., WeWork, 2 Dublin Landings, N Wall Quay, Dublin 1, D01 V4A3, Ireland

Data protection: https://policy.pinterest.com/de/privacy-policy

Facebook page

In operating our Facebook page, we process personal data jointly with Meta Platforms Ireland Limited. Information about data processing by Meta as well as about joint responsibility can be found in Meta's privacy notices and the information on Page Insights:

(https://www.facebook.com/legal/terms/page_controller_addendum and https://www.facebook.com/legal/terms/information_about_page_insights_data).

7. Transfers to third countries

Personal data is generally processed in the EU or the EEA. Transfers to third countries occur in the following cases:

  • Within the EU/EEA: CRIF (DE), Creditreform (DE), Computop (DE), Nexi (DE), Criteo (FR), Exactag (DE), Prefixbox (HU), AWIN (DE) and Userlike (DE) usually process within the EU/EEA.

  • Luxembourg: PayPal (Europe) is headquartered in Luxembourg (EU).

  • USA: Klaviyo, Inc. (Sending newsletters and marketing automation). The transfer is based on the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework (Art. 45 GDPR); Klaviyo is certified under this. To the extent and as long as Klaviyo cannot rely on this, the transfer is carried out on the basis of the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).

  • USA: Google in the context of the use of Google reCAPTCHA, Google Ads and Google Customer Match. The contractual partner is Google Ireland Limited. If data is transferred to Google LLC in the USA, this is done on the basis of the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), under which Google is certified; additionally, the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) apply.

  • USA: Meta in the context of the use of the Meta Pixel and Custom Audiences. The contractual partner is Meta Platforms Ireland Limited. If data is transferred to Meta Platforms, Inc. in the USA, this is done on the basis of the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), under which Meta is certified; additionally, the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) apply.

  • USA: Microsoft in the context of the use of Microsoft Clarity and Microsoft Advertising. The contractual partner is Microsoft Ireland Operations Limited. If data is transferred to Microsoft Corporation in the USA, this is done on the basis of the adequacy decision of the European Commission on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), under which Microsoft is certified; additionally, the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) apply.

  • Other countries outside the EU/EEA: If subprocessors are deployed in further third countries, we ensure appropriate safeguards, in particular through the EU standard contractual clauses (Art. 46 GDPR), additional measures as needed, and documented transfer assessments.

    A copy of the standard contractual clauses as well as further information on the existing safeguards can be obtained via the contact details given in Section 2.

8. Mandatory information & consequences of non-provision

Details required for contract conclusion/delivery are usually Name, address, E‑mail, payment data. Without this information, order processing is not possible. Details for optional offers (e.g. newsletter) are marked as such.

9. Retention period

  • Contract/order data: statutory retention periods (usually 6 or 10 years).

  • Customer account: until the account is deleted.

  • Information about children in the household: Until revocation of the consent given for this purpose or until deletion of the customer account.

  • Newsletter and marketing data including open and click data as well as segments derived from them: Until you withdraw your consent or unsubscribe from the newsletter.

  • Proof of your newsletter consent (Double-Opt-In record): Until the expiry of the statutory limitation period of 3 years from the end of the year of last use or unsubscription.

  • Blocklist to note unsubscribes and objections to advertising: permanent, to prevent further contact – Art. 6 para. 1 lit. c and f GDPR.

  • Contact data transmitted to advertising platforms: The transmitted data is not kept permanently on the platform by us after matching; the audiences created there are deleted at the latest upon your objection or your newsletter unsubscription.

  • Server log data: generally up to 30 days, unless longer storage is required to investigate security incidents.

  • Support/communication: case-related, regularly 3–36 months.

  • Cookie consents: according to proof obligations; durations see cookie page https://www.haba-play.com/de-de/cookies.

  • Debt collection/legal data: until the end of the limitation period or completion of the measure plus retention periods for proof.

10. Automated decisions and profiling

  • Creditworthiness checks and selection of payment methods

    Before selecting the payment methods offered in the ordering process, we check your ability to pay. To do this, we obtain probability values (scores) from the credit agencies mentioned in section 5.2 and also take into account our own findings from the previous business relationship as well as features of the specific order.

  • In the assessment, previous payment experiences, outstanding claims, order value, order characteristics and general creditworthiness information from the credit agency used are taken into account in particular. The individual factors may be weighted differently depending on the type, scope and risk of the respective order. From the overall view of this information, the risk of payment default is assessed. The decision is made for the performance of pre-contractual measures and for the fulfillment of the contract in accordance with Article 22(2)(a) GDPR. Special categories of personal data pursuant to Article 9 GDPR are not processed in this context.

    On this basis we decide automatically which payment methods we offer you. The decision affects exclusively the availability of individual payment methods. An order remains generally possible even with an unfavorable result, but possibly only with payment methods that do not require advance performance by us (e.g. prepayment).

    You have the right to present your point of view, to request human intervention and to contest the decision.

  • Analysis and marketing procedures

    To provide information, offers and advertising as needed, we may evaluate data about interests, purchases and the use of our services and newsletters (e.g. opens and clicks). For this purpose, analysis, segmentation, scoring and prediction procedures may be used to better tailor content and offers to the interests of our customers. The insights gained in this way serve solely to improve our marketing and communication measures and do not lead to automated decisions with legal effect or similarly significant consequences within the meaning of Article 22 GDPR.

  • No further automated decisions

    Apart from this, we do not use solely automated decisions that have legal effect or similarly significant consequences within the meaning of Article 22 GDPR.

11. Data security

We undertake extensive technical and organizational measures to protect your data from loss, manipulation and unauthorized access. Our security measures are regularly reviewed and adapted to technological progress.

SSL encryption

All data transmissions in our webshop are carried out via SSL/TLS encryption. You can recognize the secure connection by a padlock icon in the address bar of your browser. Personal data (e.g. name, address, payment information) is transmitted encrypted and cannot be viewed by unauthorized parties during transmission.

Use of Google reCAPTCHA

To protect our webshops and our forms from automated access, abusive entries and spam and other fraudulent activities we use Google reCAPTCHA. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google reCAPTCHA collects and analyzes technical characteristics and usage signals to assess the risk of abuse associated with an access or user action. This may in particular include processing the IP address, information about the device and browser used, time and duration of access, referrer URL, interactions with our website, and information about the action being protected. A risk assessment is created based on the analysis. Depending on the result, an additional verification may be required.

The use serves our legitimate interest in IT and form security in accordance with Art. 6(1)(f) GDPR to prevent automated abuse (bots). To the extent that information is stored on or read from your device, this is done on the basis of § 25(2) no. 2 TDDDG, insofar as and to the extent this is absolutely necessary to securely provide the webshop you explicitly requested or the function you selected.

In the course of use, personal data, in particular your IP address as well as information about your device and your usage behavior, may be transmitted to and processed by Google Ireland Limited and affiliated companies of the Google group. A transfer of data to third countries, in particular to the USA, cannot be ruled out. Please refer to Google's privacy notices for details.

Further information:

https://www.google.com/recaptcha/about/

https://policies.google.com/privacy

Google Cloud – Data processing terms https://cloud.google.com/terms/data-processing-addendum?hl=de

12. Your rights

You have the right to Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Data portability (Art. 20) and Objection (Art. 21 GDPR).

A withdrawal of consents can be made at any time with effect for the future (Art. 7(3) GDPR).

Right to object

To the extent that we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to that processing at any time for reasons arising from your particular situation (Art. 21 GDPR).

If your data are processed for direct marketing purposes, you may object to such processing at any time; this also applies to any related profiling. After your objection we will no longer process your data for these purposes.

Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The competent authority is in particular the supervisory authority of your usual place of residence, your place of work or the place of the alleged infringement.

The supervisory authority responsible for us is:

Bavarian State Office for Data Protection Supervision

Promenade 18

91522 Ansbach

Germany

Telephone: +49 (0) 981 53 1300

Fax: +49 (0) 981 53 98 1300

E-mail: poststelle@lda.bayern.de

13. Source of the data

We receive data directly from you (e.g. when ordering, creating an account, or subscribing to the newsletter). In addition, we receive creditworthiness and address data from the credit agencies named in section 5.2, as well as, in the case of an assignment, data from the debt collection service providers named in section 5.3.

14. Minors

Our webshop is aimed at Adults. Children and adolescents under 16 years of age cannot create a customer account with us, nor place orders themselves or subscribe to our newsletter. To the extent that you voluntarily provide us with information about your children (see section 3), we process this solely on the basis of your consent as the legal guardian and only for the purposes stated there.

15. Changes to this Privacy Policy

We update this statement as needed (e.g., changed legal situation, new service providers). The current version is available in the webshop.

Privacy Policy PDF Download

The free Adobe Reader is required for this and can be downloaded here.