Privacy policy
NOTE: This English version of the Privacy Policy is provided for informational purposes only. The legally binding version of this Privacy Policy is the German version, which can be found here: [https://meama.at/policies/privacy-policy]. In the event of any discrepancies or conflicts between the English and German versions, the German version shall prevail.
1) Introduction and Contact Details of the Responsible Party
1.1 We are pleased that you visit our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data means all data by which you can be personally identified.
1.2 The responsible party for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Meama GmbH, Hauptstraße 61b/3, 3001 Mauerbach, Austria, Tel.: +436643953540, Email: support@meama.at. The responsible party for processing personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
2) Data Collection When Visiting Our Website
2.1 When using our website purely for informational purposes, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the page server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
-
The website visited
-
Date and time at the time of access
-
Amount of data sent in bytes
-
Source/referrer from which you reached the page
-
Browser used
-
Operating system used
-
IP address used (possibly in anonymized form)
Processing takes place pursuant to Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. No transfer or other use of the data takes place. However, we reserve the right to retrospectively check the server log files if there are concrete indications of unlawful use.
2.2 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the responsible party). You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser’s address bar.
3) Hosting & Content Delivery Network
3.1 Shopify
For hosting our website and displaying page content, we use the system of the following provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify")
Data is also transmitted to: Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada
All data collected on our website is processed on the provider’s servers. We have concluded a data processing agreement with the provider, which ensures the protection of our website visitors’ data and prohibits unauthorized disclosure to third parties.
When data is transmitted to Canada, an adequate level of data protection is ensured through an adequacy decision by the European Commission.
3.2 Bunny
We use a content delivery network from the following provider: BUNNYWAY d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia
This service enables us to deliver large media files such as graphics, page content, or scripts faster via a network of regionally distributed servers. Processing is based on our legitimate interest in improving the stability and functionality of our website pursuant to Art. 6 para. 1 lit. f GDPR.
We have concluded a data processing agreement with the provider, ensuring the protection of our website visitors’ data and prohibiting unauthorized disclosure to third parties.
3.3 Cloudflare
We use a content delivery network from the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA
This service enables us to deliver large media files such as graphics, page content, or scripts faster via a network of regionally distributed servers. Processing is based on our legitimate interest in improving the stability and functionality of our website pursuant to Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, ensuring the protection of our website visitors’ data and prohibiting unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection based on an adequacy decision by the European Commission.
3.4 jsDelivr
We use a content delivery network from the following provider: Volentio JSD Limited, Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, United Kingdom
This service enables us to deliver large media files such as graphics, page content, or scripts faster via a network of regionally distributed servers. Processing is based on our legitimate interest in improving the stability and functionality of our website pursuant to Art. 6 para. 1 lit. f GDPR. We have concluded a data processing agreement with the provider, ensuring the protection of our website visitors’ data and prohibiting unauthorized disclosure to third parties.
When data is transmitted to the provider’s location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
4) Cookies
To make visiting our website attractive and to enable the use of certain functions, we use cookies, i.e., small text files stored on your device. Some of these cookies are automatically deleted after closing the browser (so-called "session cookies"), while others remain on your device longer and allow the storage of site settings (so-called "persistent cookies"). In the latter case, you can see the storage duration in the overview of your web browser’s cookie settings.
If personal data is processed by individual cookies we use, processing is carried out pursuant to Art. 6 para. 1 lit. b GDPR either for the execution of the contract, pursuant to Art. 6 para. 1 lit. a GDPR in the case of given consent, or pursuant to Art. 6 para. 1 lit. f GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.
You can set your browser to be informed about cookie settings and decide individually whether to accept them or exclude acceptance for certain cases or generally.
Please note that if you do not accept cookies, the functionality of our website may be limited.
5) Contact
When contacting us (e.g., via contact form or email), personal data is processed exclusively for the purpose of handling and responding to your request and only to the extent necessary for this purpose.
The legal basis for processing this data is our legitimate interest in answering your inquiry pursuant to Art. 6 para. 1 lit. f GDPR. If your contact aims at a contract, the additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted if it can be inferred from the circumstances that the matter has been conclusively clarified and if there are no legal retention obligations.
6) Data Processing When Opening a Customer Account
Pursuant to Art. 6 para. 1 lit. b GDPR, personal data is further collected and processed to the extent necessary if you provide it when opening a customer account. Which data is required for account opening can be seen in the input mask of the respective form on our website.
You can delete your customer account at any time by sending a message to the above-mentioned address of the responsible party. After deletion of your customer account, your data will be deleted as long as all contracts concluded via the account have been fully processed, no legal retention periods prevent deletion, and we have no legitimate interest in further storage.
7) Use of Customer Data for Direct Advertising
7.1 Registration for Our Email Newsletter
If you subscribe to our email newsletter, we regularly send you information about our offers. The only mandatory information required to send the newsletter is your email address. Providing additional data is voluntary and used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure, ensuring that you only receive newsletters after you have explicitly confirmed your consent to receive the newsletter by clicking a verification link sent to the provided email address.
By activating the confirmation link, you consent to the use of your personal data pursuant to Art. 6 para. 1 lit. a GDPR. We store your IP address assigned by your Internet Service Provider (ISP) as well as the date and time of registration to track possible misuse of your email address at a later time. The data collected during newsletter registration is used strictly for this purpose.
You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by contacting the responsible party mentioned above. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, unless you have explicitly consented to further use of your data or we reserve the right to use data beyond that, permitted by law, and inform you in this declaration.
7.2 ActiveCampaign
Our email newsletters are sent through this provider: ActiveCampaign, LLC, 150 N. Michigan Ave Suite 1230, Chicago, IL, USA
Based on our legitimate interest in effective and user-friendly newsletter marketing, we forward the data you provide during newsletter registration pursuant to Art. 6 para. 1 lit. f GDPR to this provider so that they can send the newsletter on our behalf.
Subject to your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the provider also performs statistical success analyses of newsletter campaigns using web beacons or tracking pixels in the sent emails. These measure open rates and specific interactions with the newsletter contents. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated but is not merged with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider to protect our website visitors' data and prohibit third-party disclosure.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, ensuring compliance with European data protection standards based on an adequacy decision by the European Commission.
7.3 Klaviyo
Our email newsletters are sent through this provider: Klaviyo, Inc., 125 Summer St., Ste 600, Boston, MA 02110, USA
Based on our legitimate interest in effective and user-friendly newsletter marketing, we forward the data you provide during newsletter registration pursuant to Art. 6 para. 1 lit. f GDPR to this provider so that they can send the newsletter on our behalf.
Subject to your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the provider also performs statistical success analyses of newsletter campaigns using web beacons or tracking pixels in the sent emails. These measure open rates and specific interactions with the newsletter contents. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated but is not merged with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider to protect our website visitors' data and prohibit third-party disclosure.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, ensuring compliance with European data protection standards based on an adequacy decision by the European Commission.
7.4 Omnisend
Our email newsletters are sent through this provider: Soundest Ltd., Unit a3, Gateway Tower, 32 Western Gateway, London E16 1YL, England
Based on our legitimate interest in effective and user-friendly newsletter marketing, we forward the data you provide during newsletter registration pursuant to Art. 6 para. 1 lit. f GDPR to this provider so that they can send the newsletter on our behalf.
Subject to your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, the provider also performs statistical success analyses of newsletter campaigns using web beacons or tracking pixels in the sent emails. These measure open rates and specific interactions with the newsletter contents. Device information (e.g., time of access, IP address, browser type, and operating system) is also collected and evaluated but is not merged with other data sets.
You can revoke your consent to newsletter tracking at any time with effect for the future.
We have concluded a data processing agreement with the provider to protect our website visitors' data and prohibit third-party disclosure.
When data is transmitted to the provider’s location, an adequate level of data protection is ensured by an adequacy decision of the European Commission.
7.5 Cart Reminder Emails
If you abandon your shopping with us before completing the order, you have the option to be reminded once by email about the contents of your virtual shopping cart.
The only mandatory information for sending this reminder is your email address. Providing additional data is voluntary and may be used to address you personally. For sending the email, we use the so-called double opt-in procedure, ensuring that you only receive a notification after you have explicitly confirmed your consent by clicking a verification link sent to the provided email address.
By activating the confirmation link, you consent to the use of your personal data pursuant to Art. 6 para. 1 lit. a GDPR for sending a cart reminder. We store your IP address assigned by your Internet Service Provider (ISP) as well as the date and time of registration to track possible misuse of your email address at a later time. The data collected for our email notification service is used strictly for this purpose.
You can unsubscribe from cart reminders at any time by sending a corresponding message to the responsible party mentioned above. After unsubscribing, your email address will be immediately deleted from our mailing list for this service, unless you have explicitly consented to further use of your data or we reserve the right to use data beyond that, permitted by law, and inform you in this declaration.
8) Data Processing for Order Fulfillment
8.1 To the extent necessary for contract processing for delivery and payment purposes, the personal data collected by us will be forwarded in accordance with Art. 6 (1) lit. b GDPR to the commissioned transport company and the commissioned credit institution.
If, based on a corresponding contract, we owe you updates for goods with digital elements or for digital products, we process the contact data you provided during the order to personally inform you in accordance with our legal information obligations under Art. 6 (1) lit. c GDPR. Your contact data is strictly used for the purpose of communications regarding updates owed by us and is processed by us only to the extent necessary for the respective notification.
For the processing of your order, we also cooperate with the service provider(s) listed below, who support us wholly or partly in the execution of concluded contracts. Certain personal data will be transmitted to these service providers according to the following information.
8.2 Disclosure of personal data to shipping service providers
-
DHL Express
As a transport service provider, we use the following provider: DHL Express Germany GmbH, Heinrich-Brüning-Str. 5, 53113 Bonn, Germany.
We will disclose your email address and/or telephone number to the provider pursuant to Art. 6 (1) lit. a GDPR prior to delivery for the purpose of coordinating a delivery appointment or for delivery notification, provided you have given your explicit consent during the order process. Otherwise, for the purpose of delivery pursuant to Art. 6 (1) lit. b GDPR, only the recipient’s name and delivery address will be forwarded to the provider. The disclosure is only made to the extent necessary for the delivery of goods. In this case, prior coordination of the delivery date with the provider or delivery notification is not possible.
Consent may be revoked at any time with effect for the future either to the controller named above or directly to the provider.
-
DPD
As a transport service provider, we use the following provider: DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany.
[Same conditions as DHL Express described above.]
-
FedEx
As a transport service provider, we use the following provider: FedEx Express Germany GmbH, Langer Kornweg 34 k, 65451 Kelsterbach, Germany.
[Same conditions as DHL Express described above.]
-
GLS
As a transport service provider, we use the following provider: General Logistics Systems Germany GmbH & Co. OHG, GLS Germany-Straße 1–7, 36286 Neuenstein, Germany.
[Same conditions as DHL Express described above.]
-
Austrian Post
As a transport service provider, we use the following provider: Österreichische Post Aktiengesellschaft, Rochusplatz 1, 1030 Vienna, Austria.
[Same conditions as DHL Express described above.]
8.3 Use of payment service providers (payment services)
-
Apple Pay
If you choose the payment method "Apple Pay" of Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, the payment is processed via the "Apple Pay" function of your iOS, watchOS, or macOS-operated device by charging a payment card stored with Apple Pay. Apple Pay uses security features integrated into the hardware and software of your device to protect your transactions. To authorize a payment, you must enter a code previously set by you and verify via the "Face ID" or "Touch ID" function of your device.
For payment processing, your information provided during the order process, along with details of your order, is encrypted and forwarded to Apple. Apple then encrypts these data again with a developer-specific key before forwarding the payment to the payment service provider of the card stored in Apple Pay. The encryption ensures that only the website through which the purchase was made can access the payment data. After the payment has been made, Apple sends your device account number and a transaction-specific dynamic security code to the originating website to confirm the payment success.
If personal data is processed in these transmissions, it is done exclusively for the purpose of payment processing pursuant to Art. 6 (1) lit. b GDPR.
Apple stores anonymized transaction data, including approximate purchase amount, date, time, and whether the transaction was successful. The anonymization fully excludes personal reference. Apple uses anonymized data to improve Apple Pay and other Apple products and services.
When using Apple Pay on iPhone or Apple Watch to complete a purchase via Safari on Mac, the Mac and authorization device communicate via an encrypted channel on Apple servers. Apple does not process or store any of this information in a format that identifies you personally. You can disable Apple Pay on your Mac in your iPhone settings under "Wallet & Apple Pay" by disabling "Allow Payments on Mac."
Further privacy information on Apple Pay can be found here: https://support.apple.com/de-de/HT203027
-
EPS bank transfer
This website offers one or more online payment methods from the following provider: PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria.
If you choose a payment method where you pay in advance (e.g., credit card payment), your payment data (including name, address, bank and card information, currency, and transaction number) and order details are forwarded to the provider in accordance with Art. 6 (1) lit. b GDPR exclusively for payment processing purposes and only to the extent necessary.
-
Google Pay
If you choose the payment method "Google Pay" of Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), the payment is processed via the "Google Pay" application on your NFC-enabled Android device (min. version 4.4 "KitKat") by charging a payment card or verified payment method (e.g., PayPal) stored with Google Pay. Payments above €25 require device unlocking with the configured verification method (face recognition, password, fingerprint, or pattern).
For payment processing, your order information is forwarded to Google. Google then transmits a one-time transaction number representing your payment info to the originating website to verify payment. This transaction number contains no real payment data and is a one-time numeric token. Google acts solely as an intermediary for the payment process, which occurs only between you and the originating website.
If personal data is processed, it is exclusively for payment processing under Art. 6 (1) lit. b GDPR.
Google may collect, store, and analyze certain transaction-specific information (date, time, amount, merchant location and description, goods/services description, photos attached, buyer/seller names and emails, payment method, reason for transaction, offers related to the transaction) based on legitimate interests (Art. 6 (1) lit. f GDPR).
Google may also combine transaction data with other information collected from using other Google services.
Google Pay’s Terms of Use:
https://payments.google.com/payments/apis-secure/u/0/get_legal_document?ldo=0&ldt=googlepaytos&ldl=de
Google Pay privacy info:
https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=de
-
Klarna
This website offers one or more online payment methods from Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden.
If you choose a payment method requiring advance payment (e.g., credit card), your payment data (including name, address, bank/card info, currency, transaction number) and order details are forwarded to Klarna under Art. 6 (1) lit. b GDPR for payment processing only and only as necessary.
If you select a payment method where Klarna pays in advance (e.g., invoice, installment, direct debit), you will be asked to provide personal data (name, address, birthdate, email, phone, possibly alternative payment info).
To protect our legitimate interest in verifying your creditworthiness, we forward this data to Klarna for a credit check under Art. 6 (1) lit. f GDPR. Klarna assesses whether the selected payment method can be granted based on your data and other information (shopping cart, invoice amount, order history, payment experience).
For the decision, credit agencies may be consulted (see: https://cdn.klarna.com/1.0/shared/content/legal/terms/0/de_de/credit_rating_agencies).
Credit checks may include score values based on scientifically recognized statistical methods, which may include address data.
You may object to this processing at any time by notifying us or the provider. However, the provider may still process your data if necessary for contract-compliant payment.
-
PayPal
This website offers one or more online payment methods from PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
If you choose a payment method requiring advance payment, your payment data and order details are forwarded to PayPal under Art. 6 (1) lit. b GDPR only for payment processing.
If you select a payment method where we pay in advance, you must provide personal data during the order (name, address, birthdate, email, phone, possibly alternative payment info).
To protect our legitimate interest in verifying your creditworthiness, we forward this data to PayPal for a credit check under Art. 6 (1) lit. f GDPR. PayPal assesses whether the selected payment method can be granted based on your data and other info.
Credit checks may include score values, based on scientific methods, which may include address data.
You may object to this processing at any time. However, PayPal may continue processing if necessary for contract payment.
-
PayPal Checkout
This website uses PayPal Checkout, an online payment system combining PayPal’s own and third-party local payment methods.
For payments via PayPal, credit card via PayPal, direct debit via PayPal, or "Pay Later" via PayPal, your payment data is forwarded to PayPal (Europe) S.a.r.l. et Cie, S.C.A., Luxembourg under Art. 6 (1) lit. b GDPR for payment processing.
PayPal may perform a credit check for credit card, direct debit, or "Pay Later" methods, forwarding your data to credit agencies under Art. 6 (1) lit. f GDPR based on legitimate interest. Score values may be included, calculated by recognized statistical methods.
You may object to this processing at any time. PayPal may continue processing if required for payment processing.
For PayPal “Invoice Purchase” option, your payment data is first forwarded to PayPal, which then forwards it to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin for identity and credit checks under Art. 6 (1) lit. b GDPR and f GDPR. Ratepay may also forward your data to credit agencies (https://www.ratepay.com/legal-payment-creditagencies/).
If a local third-party payment provider is used, your payment data is first forwarded to PayPal under Art. 6 (1) lit. b GDPR, which then forwards it to the local provider as selected.
-
Apple Pay (Apple Distribution International (Apple), Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)
-
Google Pay (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland)
-
iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
-
bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
-
blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
-
eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria)
-
MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
-
Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)
For further data protection information, please refer to PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
-
Shopify Payments
One or more online payment methods from the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
If you select a payment method of this provider where you pay in advance (e.g., credit card payment), your payment data provided during the ordering process (including name, address, bank and card details, currency, and transaction number) as well as information about the contents of your order will be forwarded to the provider pursuant to Art. 6 para. 1 lit. b GDPR. The transmission of your data is done exclusively for the purpose of processing the payment with the provider and only to the extent necessary.
-
SOFORT
One or more online payment methods from the following provider are available on this website: SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany.
If you select a payment method of this provider where you pay in advance (e.g., credit card payment), your payment data provided during the ordering process (including name, address, bank and card details, currency, and transaction number) as well as information about the contents of your order will be forwarded to the provider pursuant to Art. 6 para. 1 lit. b GDPR. The transmission of your data is done exclusively for the purpose of processing the payment with the provider and only to the extent necessary.
-
Stripe
One or more online payment methods from the following provider are available on this website: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
If you select a payment method of this provider where you pay in advance (e.g., credit card payment), your payment data provided during the ordering process (including name, address, bank and card details, currency, and transaction number) as well as information about the contents of your order will be forwarded to the provider pursuant to Art. 6 para. 1 lit. b GDPR. The transmission of your data is done exclusively for the purpose of processing the payment with the provider and only to the extent necessary.
If you select a payment method where the provider pays in advance (e.g., invoice, installment purchase, or direct debit), you will be asked during the order process to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, and, if applicable, data about an alternative payment method).
To safeguard our legitimate interest in verifying the creditworthiness of our customers, these data will be forwarded by us pursuant to Art. 6 para. 1 lit. f GDPR for the purpose of a credit check to the provider. The provider evaluates, based on the personal data you have provided as well as further data (such as shopping cart, invoice amount, order history, payment experience), whether the selected payment method can be granted considering payment and/or default risks.
The credit check may include probability values (so-called score values). As far as score values are included in the credit check result, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of score values includes, among other data, address information.
You can object to this processing of your data at any time by contacting us or the provider. However, the provider may still be entitled to process your personal data if this is necessary for proper payment processing under the contract.