Privacy Policy
Last Updated: December 16, 2024
Table of Contents
- Introduction
- Who We Are
- Data We Collect
- How We Use Your Data
- Data Security and Protection
- Your Privacy Rights
- International Data Transfers
- Changes to This Privacy Policy
1. Introduction
This Privacy Policy explains how We Love X GmbH (“we,” “us,” or “our”) collects, uses, and protects your personal information when you visit our website. This policy applies to all visitors, regardless of location, with specific provisions for European Union residents (under GDPR) and United States residents.
2. Who We Are
We Love X GmbH Cuvrystraße 4 10997 Berlin, Germany
For privacy-related inquiries, you can contact our Data Protection Officer:
ePrivacy GmbH Represented by Prof. Dr. Christoph Bauer Burchardstrasse 14 20095 Hamburg, Germany
For sensitive privacy matters, we recommend contacting our Data Protection Officer via postal mail rather than email due to security considerations.
3. Data We Collect and Legal Basis
The legal bases for processing your data are:
- Consent (Article 6(1)(a) GDPR)
- Legitimate interests (Article 6(1)(f) GDPR)
- Legal obligations (Article 6(1)(c) GDPR)
- Contract performance (Article 6(1)(b) GDPR)
Legal Bases Table
Processing Activity | Legal Basis | Purpose |
---|---|---|
IP Address Processing | Legal Obligation | Fraud prevention |
User Agent Collection | Legitimate Interest | Analytics |
Affiliate tracking | Legitimate Interest | Commission tracking |
A. Affiliate Links
Our website contains affiliate links, which are typically displayed as call-to-action buttons. When you click these links:
- You will be redirected to other websites through a tracking system
- The affiliate tracking service (CAKE) will collect certain information about your visit
- This data collection occurs after you leave our website
- The affiliate tracking service’s privacy policy will govern their use of your data
B. Content Delivery Network
We use Cloudflare as our content delivery network to:
- Improve website performance
- Enhance security
- Ensure reliable access
- Protect against cyber threats
Cloudflare may collect certain technical information as described in their privacy policy.
C. Third-Party Websites and Services
Our website contains links to other websites and services. Please note that:
- We are not responsible for the privacy practices of any third-party websites
- When you leave our website, any information you provide is subject to that site’s privacy policy
- We encourage you to read the privacy policies of any website you visit
- We cannot control and are not responsible for the collection, use, or disclosure of your information by third parties
- Clicking on external links or affiliate links means you will be subject to that website’s privacy practices
D. Google Ads
We use Google Ads for advertising purposes. When you interact with our Google Ads:
- Google collects information about your interactions with our ads
- Conversion tracking helps us measure ad performance
- Remarketing features may be used to show you relevant ads
- Your IP address and user agent are processed by Google
- Google’s privacy policy applies to their data collection
Data collected includes:
- Ad interaction data
- Conversion actions
- Device information
- IP address (anonymized)
- Cookie-based identifiers
E. Microsoft Advertising
We utilize Microsoft Advertising (Bing Ads) for promotional purposes. This service:
- Tracks ad interactions and conversions
- Uses Universal Event Tracking (UET)
- Collects data about your interactions with our ads
- May use remarketing features
- Follows Microsoft’s privacy standards
Data collected includes:
- Ad click information
- Conversion data
- Device and browser information
- IP address (anonymized)
- Microsoft Advertising cookie data
4. How We Use Your Data
We use advertising data to:
- Measure ad campaign effectiveness
- Optimize ad targeting and performance
- Track conversion rates
- Improve return on ad investment
- Provide more relevant ads to users
Advertising data processing follows these principles:
- Data minimization
- Purpose limitation
- Storage limitation
- Regular audit and cleanup
5. Data Security and Protection
A. Security Measures
We implement various security measures to protect your data:
- Encryption: All data is encrypted in transit and at rest
- Data Aggregation: Analytics data is aggregated for reporting
- Secure Infrastructure: Use of trusted service providers
B. Data Breach Notification
In the event of a data breach:
- Our CEO and Data Protection Officer are immediately notified
- Affected stakeholders will be informed within 72 hours
- Appropriate authorities will be notified as required by law
- Remedial actions will be taken to prevent future incidents
6. Your Privacy Rights
A. For European Union Residents (GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Request erasure of your personal data
- Restrict or object to processing
- Data portability
- Withdraw consent
- Lodge a complaint with a supervisory authority
B. For United States Residents
California Residents (CCPA/CPRA)
You have the right to:
- Know what personal information we collect and disclose
- Access your personal information
- Delete your personal information
- Correct inaccurate personal information
- Limit the use and disclosure of sensitive personal information
- Opt-out of the sharing of personal information for cross-context behavioral advertising
- Non-discrimination for exercising your rights
Virginia Residents (VCDPA)
You have the right to:
- Confirm whether we are processing your personal data
- Access your personal data
- Correct inaccuracies in your personal data
- Delete your personal data
- Obtain a copy of your personal data in a portable format
- Opt out of processing for targeted advertising
- Appeal any denial of your privacy request within 45 days
Colorado Residents (CPA)
You have the right to:
- Access your personal data
- Correct inaccuracies in your personal data
- Delete personal data
- Obtain your personal data in a portable format
- Opt out of targeted advertising and profiling
- Appeal any denial of your privacy request within 45 days
Connecticut Residents (CTDPA)
You have the right to:
- Access your personal data
- Correct inaccuracies in your personal data
- Delete your personal data
- Obtain your personal data in a portable format
- Opt out of targeted advertising and profiling
- Appeal any denial of your privacy request
Utah Residents (UCPA)
You have the right to:
- Access and delete your personal data
- Receive your data in a portable format
- Opt out of targeted advertising
- Non-discrimination for exercising your rights
How to Exercise Your Rights
- You can exercise your privacy rights by:
- Contacting our Privacy Team at the address provided in Section 11
- Adjusting your browser settings for cookie control
- Verification Process:
- We will verify your identity before fulfilling your request
- We may request additional information to ensure the security of your data
- We aim to respond to all verified requests within 45 days
- Response Timing:
- We will respond to verifiable requests within 45 days
- If we require more time (up to 90 days), we will inform you in writing
- If we deny your request, we will explain the reasons and your right to appeal
- Cost:
- We do not charge a fee for processing your request
- If requests are excessive or manifestly unfounded, we may charge a reasonable fee or decline to act on the request
Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights. This means we will not:
- Deny you goods or services
- Charge different prices or rates
- Provide a different quality of goods or services
- Suggest that you may receive different pricing or service
7. Data Retention Periods
We retain your personal data for the following periods:
- Server logs (no IP addresses): 14 days
- Analytics data: aggregated format only
8. International Data Transfers
We store and process data in the European Union. For visitors from outside the EU, including the United States, please note that your information may be transferred to, stored, and processed in the European Union, where our servers and central database are located.
We ensure appropriate safeguards for international data transfers through:
- Standard contractual clauses
- Appropriate security measures
- Data processing agreements with third parties
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Significant changes will be notified through:
- Website notifications
- Updated “Last Modified” date at the top of this policy
10. Children’s Privacy
Our website is not intended for children under the age of 16. We do not knowingly collect or process personal information from children under 16. If you believe we have collected personal information from a child under 16, please contact us to have the data removed.
11. Contact Us
For any privacy-related questions or concerns:
- Email: [email protected]
- Postal Mail: We Love X GmbH, Cuvrystraße 4 10997 Berlin, Germany
- Expected Response Time: Within 7 business days
12. Document Information
- Last Updated: December 16, 2024
- Last Reviewed: December 16, 2024
- Next Scheduled Review: May 12, 2025