1. CONTROLLER
The controller for the processing of personal data on offprism.com is:
EURO CLOTHING S.R.L.
operating under the brand "OffPrism"
Strada Primăverii Nr. 55
507190 Sânpetru, Județul Brașov
Romania
E-mail: info@offprism.com CUI: 47727871 Commercial register number: J08/20/2024
2. GENERAL PRINCIPLES
We process personal data only insofar as this is necessary for the operation of the website, the execution of orders, the provision and activation of software licenses, the answering of enquiries, the fulfilment of legal obligations or on the basis of consent.
Personal data are all information relating to an identified or identifiable natural person.
3. WEBSITE ACCESS AND SERVER LOGS
When accessing our website, the following data in particular may be processed
- IP address;
- date and time of access;
- page or file accessed;
- amount of data transferred and access status;
- browser type, browser version and operating system;
- referrer URL;
- technical error and security information.
The processing is necessary in order to deliver the website, to ensure its stability and security, and to detect misuse and attacks.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and demand-oriented operation of our online offering.
Server logs are stored only for as long as this is necessary for security, error analysis and abuse prevention. Longer storage takes place only if a security-relevant incident is investigated, a legal claim is pursued or a legal obligation must be fulfilled.
Hosting provider:
netcup GmbH
Emmy-Noether-Straße 10
76131 Karlsruhe
Germany
Insofar as an external hosting provider is used, it processes the data on our behalf in accordance with Art. 28 GDPR.
4. TECHNICALLY NECESSARY COOKIES AND LOCAL STORAGE
We use technically necessary cookies and local browser storage so that the website and its basic functions can be used. These include in particular:
- storage of the selected language;
- local storage of the shopping cart;
- session and security information for the customer portal;
- storage of the selected privacy settings;
- technically necessary information for the assignment of an order.
The processing is necessary for the provision of the expressly requested website functions or for carrying out pre-contractual measures and the contract. The legal bases are Art. 6(1)(b) and (f) GDPR as well as the applicable provisions on terminal equipment and electronic communications.
Technically necessary storage cannot be deactivated if the affected function is to be used. It is deleted as soon as it is no longer necessary for the respective purpose. Shopping cart information may remain locally in the browser until it is deleted by the user or browser.
5. OWN REACH MEASUREMENT AND CREATOR TRACKING
Only with your prior consent do we measure, in our own infrastructure, the use of our website and the assignment of referrals or creator discounts.
In doing so, the following data in particular may be processed
- pages accessed;
- time and approximate session duration;
- pseudonymised identifier;
- referrer or referral identifier;
- creator or campaign identifier;
- assignment of an order to a referral;
- technical device and browser information;
- pseudonymised or hashed value of the IP address.
The data are not used to track you across websites. The full IP address is not used as an analytics identifier.
The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the website's privacy settings with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
The analytics data are deleted or anonymised as soon as they are no longer needed for reach measurement and billing or verification of a referral assignment. After withdrawal, no new analytics data are collected on the basis of this consent.
6. ORDERS AND CONTRACT PROCESSING
In the case of an order, we process the data necessary for the initiation and execution of the contract. These may include:
- name and, where applicable, company;
- billing address and country;
- e-mail address;
- where applicable, VAT identification number;
- ordered software, edition, quantity and number of devices;
- order number, price, currency and tax information;
- payment status and selected payment method;
- time of the order;
- documentation of the consent to immediate performance of the contract;
- invoice, refund and support information.
The legal basis is Art. 6(1)(b) GDPR. Data that we must store to fulfil tax, commercial or accounting obligations we process on the basis of Art. 6(1)(c) GDPR.
Without the necessary order data, no purchase contract can be concluded and no license can be provided.
7. PAYMENT PROCESSING BY STRIPE
For payment processing we use Stripe. Depending on country, currency and order, card payment, EPS, iDEAL/Wero, Przelewy24 and Multibanco in particular may be offered.
The provider for payments in the European Economic Area is as a matter of principle:
Stripe Payments Europe, Limited
1 Grand Canal Street Lower
Grand Canal Dock
Dublin, Ireland
Stripe processes in particular contact, billing, payment, device, transaction and fraud prevention data. Complete card and account data are as a matter of principle collected directly by Stripe and are not stored on our systems.
The processing is necessary for carrying out the payment and the contract, Art. 6(1)(b) GDPR. Fraud prevention and security checks are also based on legitimate interests of us and Stripe pursuant to Art. 6(1)(f) GDPR as well as, where applicable, on legal obligations.
Stripe may use other companies of the Stripe group and service providers and may also process data outside the European Economic Area. According to its own information, Stripe bases such transfers on appropriate safeguards such as adequacy decisions or standard contractual clauses.
Further information: https://stripe.com/de/privacy
8. PURCHASE ON ACCOUNT FOR B2B CUSTOMERS
In the case of an approved purchase on account for entrepreneurs, we additionally process the data necessary for company identification, creditworthiness and payment processing. These may include company, register data, business contact data, VAT details, invoice, payment term and receipt of payment.
The legal bases are Art. 6(1)(b) and (f) GDPR. Our legitimate interest lies in avoiding payment defaults and managing outstanding receivables. Insofar as an external credit report is obtained before an approval, the specific provider must be added at this point before its use and the customer must be informed thereof.
9. CUSTOMER PORTAL
For the customer portal we process in particular
- e-mail address and order number;
- session and security identifier;
- order, invoice, download and license information;
- time of successful and failed accesses;
- IP address and technical security information.
The processing is necessary for the provision of the portal and for performance of the contract, Art. 6(1)(b) GDPR. Security logs are based on our legitimate interest in preventing unauthorised access, Art. 6(1)(f) GDPR.
10. LICENSE ACTIVATION AND DEVICE MANAGEMENT
To activate, verify and manage the acquired device slots, the following data may be processed:
- license key and order number;
- software, edition and version;
- number of permitted and used activations;
- pseudonymised device or installation identifier;
- operating system and technical version information;
- time of activation, verification, release and device change;
- IP address as well as error and security information.
The data are processed in order to provide the acquired license, to enable device changes and to prevent unauthorised multiple use. The legal bases are Art. 6(1)(b) and (f) GDPR. Our legitimate interest lies in protecting the software and the license system from misuse.
The device identifier is intended to be designed such that it contains no more data than is necessary for license management. Already activated software can as a matter of principle be used offline in accordance with the product details.
11. CONTACT AND SUPPORT
When you contact us, we process your contact data, the content of the message as well as, where applicable, order, license, device and error data in order to handle your enquiry.
The legal basis is Art. 6(1)(b) GDPR if the enquiry is connected with a contract or pre-contractual measures. In other cases, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in answering enquiries and documenting support.
Provider for the sending and receipt of order, license and support e-mails:
ALL-INKL.COM – Neue Medien Münnich
Hauptstraße 68
02742 Friedersdorf
Germany
12. RECIPIENTS OF DATA
Personal data may – insofar as necessary in each case – be transmitted to the following recipients:
- hosting, infrastructure and e-mail service providers;
- Stripe and the payment providers involved in the selected payment method;
- tax advisors, accounting, legal advisors and auditors;
- IT, security and support service providers;
- authorities, courts and other public bodies where there is a legal obligation;
- banks and bodies involved in refunds or the collection of legitimate receivables.
Processors are contractually bound in accordance with Art. 28 GDPR. Data are not sold.
13. INTERNATIONAL DATA TRANSFERS
Insofar as data are processed outside the European Economic Area, this takes place only in compliance with Art. 44 to 49 GDPR. In particular, an adequacy decision of the European Commission, standard contractual clauses or a statutory exception may serve as a basis.
14. STORAGE PERIOD
We store personal data only for as long as this is necessary for the respective purpose.
In particular, the following criteria apply
- Contract, invoice and payment data are stored for the duration of the contract and subsequently in accordance with the applicable tax, accounting and commercial retention obligations.
- License and activation data are as a matter of principle stored for the duration of the perpetual license and beyond that only insofar as this is necessary for abuse prevention or legal claims.
- Support communication is stored until the completion of the enquiry and subsequently for the period in which contractual or statutory claims can be asserted.
- Records of consent are stored for the duration of the consent and thereafter for as long as this is necessary to demonstrate its lawfulness.
- Data are stored longer if a legal dispute, a security incident or a legal order requires this.
After expiry of the respective period, the data are deleted or anonymised.
15. RIGHTS OF DATA SUBJECTS
Under the statutory conditions, you have in particular the following rights
- access to your personal data, Art. 15 GDPR;
- rectification of inaccurate data, Art. 16 GDPR;
- erasure, Art. 17 GDPR;
- restriction of processing, Art. 18 GDPR;
- data portability, Art. 20 GDPR;
- objection to processing on the basis of Art. 6(1)(e) or (f) GDPR, Art. 21 GDPR;
- withdrawal of a consent with effect for the future, Art. 7(3) GDPR;
- lodging a complaint with a data protection supervisory authority, Art. 77 GDPR.
To exercise your rights, you can contact info@offprism.com.
16. OBJECTION TO PROCESSING BASED ON LEGITIMATE INTERESTS
Insofar as we process data on the basis of legitimate interests, you can object at any time on grounds relating to your particular situation. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds worthy of protection that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
17. RIGHT TO LODGE A COMPLAINT
You can in particular contact the Romanian data protection supervisory authority responsible for us:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru Nr. 28–30 Sector 1, 010336 București Romania
Telephone: +40 31 805 9211 E-mail: anspdcp@dataprotection.ro Website: https://www.dataprotection.ro/
You can also contact a data protection supervisory authority at your habitual residence, your place of work or the place of the alleged infringement.
18. AUTOMATED DECISIONS
OffPrism as a matter of principle does not make solely automated decisions with legal or similarly significant effect. Stripe may carry out its own automated checks in the context of payment and fraud prevention. Details can be found in Stripe's privacy information.
19. DATA SECURITY
We use appropriate technical and organisational measures to protect personal data from loss, unauthorised access, alteration and disclosure. These include in particular encrypted transmission, access restrictions as well as security and update measures.
20. CHANGES TO THIS PRIVACY POLICY
We may adapt this privacy policy if processing operations, service providers or legal requirements change. The current version in each case is published on offprism.com.
21. COMMUNITY, PROFILE PICTURES AND POST IMAGES
When using the community, we process in particular display name, profile picture, voluntary status message, posts, ratings, post counters, timestamps and, where applicable, images attached to posts. Public posts, display names, status messages and profile pictures are publicly visible. Order-related support areas are accessible exclusively to the account holder concerned and authorised administrators.
Uploaded images are stored exclusively as newly generated WebP files. Metadata and the original file code are discarded in the process. Post images are automatically deleted no later than 90 days after upload. Profile pictures remain stored until they are replaced or the account is deleted.
Users can embed external HTTPS images in posts. When such an image is loaded, the browser establishes a direct connection to the respective third-party server. In doing so, in particular the IP address may be transmitted to the operator of the third-party server. OffPrism does not transmit any referrer in the process. The operator of the external offering is responsible for its content and data protection.
The legal bases are Art. 6(1)(b) and (f) GDPR. Our legitimate interest lies in the operation and moderation of a safe product community as well as in the prevention of misuse.