Last Updated May 24, 2018
A. What is Personal Information?
Personal information is information about you that can be used by itself, or combined with other information, to identify you personally (referred to as “Personal Information”). We collect this Personal Information directly from you when you provide it to us.
B. Who are we?
The Website is operated by BRAGI GmbH, Sendlinger Straße 7/Angerblock 2. OG, 80331 Munich, Germany (referred to as “BRAGI”, “we”, “our”, or “us”).
C. What Personal Information do we collect?
We collect Personal Information in a number of different ways:
1) Website including online shop
When you purchase our products you give us certain Personal Information. This includes your name, e-mail address, phone number(s) (optional), shipping and billing address, payment information (e.g. credit card number etc.) and any other information you provide us with.
When you connect to our Website, your browser automatically sends information. This data may include your internet protocol (IP) address, browser type and settings, the date and time of your requests and how you used our Website. We only use and process this data where legally permitted.
We are present on various social media platforms, such as Facebook and Twitter. From these platforms, we receive anonymized and aggregated demographic and use information related to our presence on the respective social media platform. This happens when you visit us on those sites or communicate with us.
Please refer to section D below to understand for what other purposes we collect data and which third-party providers we use for these purposes.
What do we use this data for?
We use information that we collect about you or that you provide to us on our Website, including any Personal Information, to:
- Provide our Website services to you, including, e.g. interactive features, promotions or a newsletter (if subscribed);
- Provide our Website in your language, based on the location indicated by your IP address;
- Keep you informed about BRAGI’s upcoming product releases, in case you signed up for our newsletter;
- Deliver products and services you request;
- Process your payment via a credit card (or other authorized methods of payment, as applicable); the information regarding payment will be stored until your account is charged;
- Save your payment information and contact information if you make a purchase on our Website so that you can use it the next time you want to buy something, provided that you have given us your consent;
- Offer you customized content and send you updates and notifications;
- Respond to your customer concerns, questions and complaints, and send you communications upon your request;
- Analyze, use and learn about the interests of our users in the aggregate to better understand your interests and needs, to aid us in serving you better or to evaluate the performance of our Website and provide you with a better user experience;
- Customize and/or personalize your communications and shopping experience with us;
- Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;
- Protect, investigate, and deter against fraudulent, unauthorized, illegal activity, or violations of our policies;
- And in any other way we may describe when you provide the information for any other purpose with your consent or, as the case may be, the consent of a parent or legal guardian.
2) E-mail communication
You may provide us with your e-mail address when you purchase a product, subscribe to our newsletter or otherwise contact us.
What do we use this data for?
We may also communicate with you concerning your order, or to address your questions.
Legal Basis for Processing Personal Information Under General Data Protection Regulation (GDPR)
Bragi may process your Personal Information because:
- We need to perform a contract with you
- You have given us consent to do so
- We must comply with the law
- The processing is in our legitimate interests, part of a product features, and it's not overridden by your rights
Performance of a contract with you
We process your personal information to perform our obligations under the Terms and Conditions applicable to the product or service you are using. This Terms and Conditions are provided before you enter into a contract with us or before you have access to our services.
We process your personal information if you have consented to the processing activity. You may revoke your consent at any time. Doing so will bar us from further processing of your personal information based on your consent but will not impact the lawfulness of processing based on your consent before it was withdrawn. Some of the features of our products and services might be only available based on consent.
We process your personal information as needed to comply with laws and regulations.
We process your personal information to further our legitimate interests, such as in connection with managing, developing, testing, securing, and in limited circumstances marketing, advertising, and making recommendations regarding our products and services. Any such processing is conducted subject to appropriate measures to protect your fundamental rights and freedoms related to your personal information, and in any event will be subject to the restrictions provided in this Policy. Further information or specification of our legitimate interests may be provided before you purchase a Bragi product or use Bragi’s services.
D. How and when do we share information?
We will only share your Personal Information when we have a legal basis to do so.
E. Third parties that we use to perform our services
Some services that we provide require the involvement of third parties. We have carefully selected those third parties and concluded contracts with them that ensure that your Personal Information is adequately protected.
F. Analytics software
Google Analytics is a web analysis service provided by Google Inc., located in the USA. We use Google Analytics to track and examine the use of our Website. Our integration of Google Analytics anonymizes your IP address. It works by shortening all your IP addresses, including those within Member States of the European Union or in other contracting states to the agreement on the European Economic Area.
Marketing e-mails (MailChimp)
Zendesk, Inc. located in the USA, provides a cloud-based customer service platform, which we use for the Bragi Support Center. This platform includes ticketing services, self-service options, and customer support features.
When you buy something, we share your payment information and other information about the transaction (e.g. date and time of the order, amount, currency, transaction ID) with the payment company used for completing the transaction. The payment company we currently use is Adyen, Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands. Adyen itself may use other payment companies, depending on my choice of the payment method. Adyen will only use the aforementioned data in the context of the payment and will not use this data for other purposes. The aforementioned data will be stored until your account is charged.
Storage by us
Your Personal Information is stored by us in the data centers of Amazon Web Services, Inc. (USA). The data centers are located in Ireland and Germany.
Nelio A/B Testing from Nelio Software, S.L., located in Barcelona, is a split testing tool for WordPress. It is used for the execution of multivariate testing to compare the user experience of new designs on our live website. The results provided by Nelio are collected aggregately and do not attempt to identify individual visitors.
We may share your Personal Information if sharing is reasonably necessary to comply with a law, regulation or legal request or legal process; to protect the safety, rights, or property of the public, any person, or us; or to detect, prevent, or otherwise address fraud, security or technical issues. If not legally forbidden, we will inform you as soon as possible about any sharing of your Personal Information that we are obliged to.
We may also share aggregated or non-personally identifiable information with our partners, advertisers, or others, where legally permitted.
G. How we store and secure your Personal Information
We are concerned about safeguarding the confidentiality of your Personal Information. We use industry standard practices to protect the confidentiality, integrity, and availability of your data, e.g. by access controls. All Personal Information you provide to us is secured using industry standard procedures. Any payment transactions will be encrypted in transit using SSL. We strive to update our security measures on a regular basis to keep track of new industry standards.
G.1 How long do we retain Personal information?
We endeavor to only collect personal information that is necessary for the purposes for which they are collected and to retain such data for no longer than is necessary for such purposes. The length of time personal information is retained, and criteria for determining that time, are dependent on the nature of the personal information and the purpose for which it was provided.
G.2 Transfer of Personal Information
Information, including Personal Information, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
H. Our policy on children’s information
The Website is not directed to children under 14. If you learn that your child under 14 has provided us with Personal Information without your consent, please contact us immediately and we will delete such information within reasonable time.
I. What rights do you have?
Right to access, modify or delete your Personal Information
You can always access your Personal Information by asking us what Personal Information we hold about you.
You may modify, add, delete or update your Personal Information or request deletion of Personal Information by emailing us at firstname.lastname@example.org or by contacting us as described in section H below. We will usually respond to all access requests within 30 days. We will retain your Personal Information as needed to provide you with our services.
In case you request to delete Personal Information, you may no longer be able to use all features and functions of our services.
Please note that we may be required to keep some of your Personal Information for legal reasons, for instance to comply with statutory retention periods or for tax purposes. In such cases, we will mark your Personal Information accordingly to make sure that it is not used for any other purpose than complying with the retention requirement.
Right to opt-out of marketing
If you signed up for our newsletter and no longer want us to use your Personal Information for marketing purposes you can unsubscribe from marketing-related e-mails by following the unsubscribe instructions included in each e-mail.
Other rights to opt-out
J. How to contact us
Sendlinger Straße 7 / Angerblock 2.OG
Germany / Deutschland
Phone: +49 (0) 89 215 484 210