parallax background

Privacy Policy

responsible for data processing:
Kevin Don Gaubitz
No: 440/107, 3rd Lane Palm Grove Estate
Kadirana, Negombo
Sri Lanka
(+94) 31 223 0766 / 77 618 4343
contact@malorganic.com
Thank you for your interest in our online shop. The protection of your privacy is very important to us. In the following we inform you in detail about the handling of your data.
1. access data and hosting
You can visit our websites without providing any personal information. Each time a website is accessed, the web server only automatically saves a so-called server log file, which contains the name of the requested file, your IP address, date and time of access, transferred data volume and the requesting provider (access data) and documents the access.
These access data are evaluated exclusively for the purpose of ensuring trouble-free operation of the site and improving our services. In accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO, this serves to safeguard our predominantly legitimate interests in a correct presentation of our offer as part of a weighing of interests. All access data will be deleted at the latest seven days after the end of your page visit.
Hosting services by a third-party provider
In the context of processing on our behalf, a third party provider provides us with the services of hosting and display of the website. All data collected within the framework of the use of this website or in the forms provided for this purpose in the online shop as described below will be processed on its servers. Processing on other servers will only take place within the scope described here.
This service provider is located in a country for which there is no European Union adequacy decision. The cooperation is therefore based on standard data protection clauses of the European Commission.
2. data collection and use for contract processing, contacting and opening a customer account
We collect personal data when you voluntarily provide us with it in connection with your order or when contacting us (e.g. via contact form or e-mail). Mandatory fields are marked as such, because in these cases we need the data to process the contract or to process your contact and you can not send the order or contact without their information. Which data are raised, are evident from the respective input forms. We use the data provided by you in accordance with Art. 6 Para. 1 S. 1 lit. b DSGVO for contract processing and processing your enquiries.
If you have given your consent in accordance with Art. 6 Para. 1 S. 1 lit. a DSGVO by deciding to open a customer account, we will use your data for the purpose of opening a customer account.
After complete completion of the contract or deletion of your customer account, your data will be restricted for further processing and deleted after expiry of the retention periods under tax and commercial law, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this declaration. The deletion of your customer account is possible at any time and can take place either by a message to the contact possibility described below or over a function intended for it in the customer account.
3. data transfer
In order to fulfil the contract pursuant to Art. 6 Para. 1 S. 1 lit. b DSGVO, we pass on your data to the shipping company commissioned with the delivery, insofar as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the ordering process, we will pass on the payment data collected for this purpose to the credit institution and payment service provider commissioned by us or to the selected payment service in order to process payments. In some cases, the selected payment service providers also collect this data themselves if you create an account there. In this case, you must register with the payment service provider using your access data during the ordering process. In this respect, the data protection declaration of the respective payment service provider applies.
4. cookies and web analysis
In order to make visiting our website attractive and to enable the use of certain functions, to display suitable products or for market research, we use so-called cookies on various pages. This serves to safeguard our predominantly legitimate interests in an optimised presentation of our offer in accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO as part of a weighing of interests. Cookies are small text files that are automatically stored on your terminal device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your end device and enable us to recognise your browser the next time you visit (persistent cookies). You can find the duration of the storage in the overview in the cookie settings of your web browser. You can set your browser so that you are informed about the setting of cookies and decide individually whether to accept them or whether to exclude the acceptance of cookies in certain cases or in general. Each browser differs in the way it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. These can be found for each browser under the following links:
Internet Explorer™
Safari™
Chrome™
Firefox™
Opera™
If cookies are not accepted, the functionality of our website may be restricted.
Use of Google (Universal) Analytics for Web Analytics
This website uses Google (Universal) Analytics for website analysis. The web analytics service is provided by Google Ireland Limited, a company incorporated and operated under Irish law and having its registered office at Gordon House, Barrow Street, Dublin 4, Ireland (www.google.de). This serves to safeguard our predominantly legitimate interests in an optimised presentation of our offer in accordance with Art. 6 para. 1 sentence 1 lit. f DSGVO. Google (Universal) Analytics uses methods that enable the analysis of your use of the website, such as cookies. The automatically collected information about your use of this website is generally transmitted to a Google server in the USA and stored there. By activating IP anonymisation on this website, the IP address is shortened before transmission within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. The anonymous IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. The data collected in this context will be deleted after we have stopped using Google Analytics for the intended purpose and at the end of its use.
Where information is transmitted to and stored by Google on servers located in the United States, the U.S. company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. On the basis of this agreement between the USA and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield.
You can prevent Google from collecting the data generated by the cookie and related to your use of the website (including your IP address) and Google from processing this data by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
As an alternative to the browser plug-in, you can this link click to prevent Google Analytics from capturing data on this website in the future. An opt-out cookie is stored on your end device. If you delete your cookies, you must click the link again.
This website also uses Google Signals. This is an extension function of Google Analytics that enables so-called "cross-device tracking". This means that if your Internet-enabled devices are linked to your Google Account, Google can generate reports on usage patterns (especially cross-device user numbers) even if you change your terminal device. Google will use data for this purpose if you have activated the "personalised advertising" setting in your Google Account.
This serves to safeguard our predominantly legitimate interests in an optimised presentation of our offer in accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO as part of a weighing of interests.
We do not process personal data in this respect; we only receive statistics based on Google Signals.
You can deactivate the setting "personalised advertising" in your Google account at any time and thus object to a recording by Google Signals.
5. online marketing
Google reCAPTCHA
For the purpose of protection against misuse of our web forms and against spam, we use the Google reCAPTCHA service within the framework of some forms on this website. Google reCAPTCHA is a service provided by Google Ireland Limited, a company incorporated and operated under the laws of Ireland and located at Gordon House, Barrow Street, Dublin 4, Ireland. (www.google.de). By checking a manual entry, this service prevents automated software (so-called bots) from performing abusive activities on the Website. Pursuant to Art. 6 para. 1 sentence 1 lit. f DSGVO, this serves to safeguard our predominantly legitimate interests in the protection of our website from misuse and in a trouble-free presentation of our online presence as part of a balancing of interests.
Google reCAPTCHA uses a code embedded in the website, a so-called JavaScript, to check the methods that allow an analysis of the use of the website by you, such as cookies. The automatically collected information about your use of this website including your IP address is usually transferred to a Google server in the USA and stored there. In addition, other cookies stored in your browser by Google services are evaluated by Google reCAPTCHA. A reading or saving of personal data from the input fields of the respective form does not take place.
Insofar as information is transferred to Google servers in the USA and stored there, the American company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. On the basis of this agreement between the USA and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield.
You can prevent Google from collecting the data (including your IP address) generated by JavaScript or the cookie and relating to your use of the website and from processing this data by Google by setting your browser settings to prevent the execution of JavaScript or the setting of cookies. Please note that this may restrict the functionality of our website for your use.
Further information on Google's data protection policy can be found here.
Google Fonts
On this website the script code "Google Fonts" is integrated. Google Fonts is an offer from Google Ireland Limited, a company incorporated and operated under Irish law with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland. (www.google.de). This serves to safeguard our predominantly legitimate interests in a uniform presentation of the contents on our website in accordance with Art. 6 para. 1 lit. f) DSGVO. Within this framework, a connection is established between the browser you use and the Google servers. As a result, Google becomes aware that our website has been accessed via your IP address. Where information is transmitted to and stored by Google on servers in the United States, the U.S. company Google LLC is certified under the EU-US Privacy Shield. A current certificate can be viewed here. As a result of this agreement between the USA and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield. For more information about data processing by Google, please see Google's Privacy Notice. 6 Social Media
Using social plugins from Facebook, Twitter, Instagram
So-called social plugins ("plugins") from social networks are used on our website.
When you access a page of our website that contains such a plugin, your browser establishes a direct connection to the servers of the respective social network. The content of the plugin is transmitted directly from the respective provider to your browser and integrated into the page. By integrating the plugins, the providers receive the information that your browser has called the corresponding page of our website, even if you do not have a profile or are not logged in. This information (including your IP address) is transmitted by your browser directly to a server of the respective provider (possibly to the USA) and stored there. If you are logged in to one of the services, the providers can assign the visit to our website directly to your profile in the respective social network. If you interact with the plugins, for example by pressing the "Like" or "Share" button, the corresponding information is also transmitted directly to a server of the provider and stored there. The information is also published in the social network and displayed there to your contacts. This serves to protect our predominantly legitimate interests in an optimal marketing of our offer in accordance with Art. 6 Para. 1 S. 1 lit. f DSGVO.
The purpose and scope of the data collection and the further processing and use of the data by the providers on their pages, as well as a contact option and your rights and setting options in this regard to protect your privacy, please refer to the data protection information of the providers:
https://www.facebook.com/policy.php
https://twitter.com/de/privacy
https://help.instagram.com/155833707900388
If you do not want social networks to directly associate the information collected through our website with your profile on that service, you must log out of that service before visiting our website. You can also completely prevent the plugins from loading with add-ons for your browser, e.g. with the script blocker "NoScript".
Our online presence on Facebook, Twitter
Our presence on social networks and platforms serves a better, active communication with our customers and prospective customers. We inform them about our products and ongoing special promotions.
When you visit our online presence in social media, your data may be automatically collected and stored for market research and advertising purposes. From this data, so-called usage profiles are created using pseudonyms. These can be used, for example, to place advertisements inside and outside the platforms that presumably correspond to your interests. Cookies are generally used on your terminal device for this purpose. The visitor behaviour and the interests of the users are stored in these cookies. This serves in accordance with Art. 6 Para. 1 lit. f. DSGVO to safeguard our predominantly legitimate interests in an optimised presentation of our offer and effective communication with customers and interested parties within the scope of a weighing of interests. If you are asked by the respective social media platform operators for their consent to data processing, e.g. with the help of a checkbox, the legal basis for data processing is Art. 6 Para. 1 lit. a DSGVO.
Insofar as the aforementioned social media platforms have their headquarters in the USA, the following applies: The European Commission has issued an adequacy decision for the USA. This goes back to the EU-US Privacy Shield. A current certificate for the respective company can be viewed here.
The detailed information on the processing and use of the data by the providers on their pages as well as a contact option and your rights and settings to protect your privacy, in particular opt-out options, can be found in the data protection information of the providers linked below. Should you nevertheless require help in this regard, you can contact us.
Facebook: https://www.facebook.com/about/privacy/
Data processing is carried out on the basis of an agreement between jointly responsible parties pursuant to Art. 26 DSGVO, which you can view here.
Further information on data processing in the context of visiting a Facebook fan page (information on Insights data) can be found here.
Twitter: https://twitter.com/de/privacy
Possibility of objection (opt-out):
Facebook: https://www.facebook.com/settings?tab=ads
Twitter: https://twitter.com/personalization
7. contact possibilities and your rights
As a data subject, you have the following rights:
pursuant to Art. 15 DSGVO, you have the right to request information about your personal data processed by us to the extent specified therein;
pursuant to Art. 16 DSGVO, you have the right to immediately request the correction of incorrect or incomplete personal data stored by us;
pursuant to Art. 17 DSGVO, you have the right to demand the deletion of your personal data stored by us, unless further processing is prohibited.
on the exercise of freedom of expression and information;
to fulfil a legal obligation;
for reasons of public interest, or
is necessary for the assertion, exercise or defence of legal claims;
pursuant to Art. 18 DSGVO, the right to demand the restriction of the processing of your personal data, provided that
the correctness of the data is denied by you;
the processing is unlawful, but you refuse to delete it;
we no longer need the data, but you need it to assert, exercise or defend legal claims, or
you have lodged an objection against the processing under Article 21 DSGVO;
pursuant to Art. 20 DSGVO, you have the right to receive your personal data which you have provided to us in a structured, common and machine-readable format or to request the transfer to another responsible party;
pursuant to Art. 77 DSGVO, you have the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority at your usual place of residence or workplace or at our company headquarters.
If you have any questions regarding the collection, processing or use of your personal data, for information, correction, restriction or deletion of data as well as revocation of consent given or objection to a specific use of data, please contact us directly via the contact data in our imprint.
right of objection
Insofar as we process personal data as described above in order to safeguard our predominantly legitimate interests as part of a weighing of interests, you may object to this processing with effect for the future. If the processing is carried out for the purposes of direct marketing, you can exercise this right at any time as described above. If the processing is carried out for other purposes, you are only entitled to object if there are reasons arising from your particular situation.
After exercising your right of objection, we will not process your personal data further for these purposes unless we can prove compelling reasons worthy of protection for the processing, which outweigh your interests, rights and freedoms, or if the processing serves the assertion, exercise or defence of legal claims.
This does not apply if the processing is carried out for the purposes of direct marketing. Then we will not further process your personal data for this purpose.