Privacy Policy
1. Introduction
Protecting your personal data is a top priority. This privacy policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "data") in connection with our online services. This includes the associated website, functions, and content, as well as external online presences such as social media profiles (hereinafter collectively referred to as "online services"). Your personal data is treated confidentially, and we strictly comply with statutory data protection regulations and the provisions of this privacy policy.
We act in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679, which has been in effect since May 25, 2018.
Please note that data transmitted via the Internet (e.g., via email communication) may be subject to security breaches. Complete protection of your data against access by third parties is not possible.
General Information
This privacy policy provides a comprehensive overview of what happens to your personal data when you visit this website.
Personal data is any information that can be used to personally identify you. Please refer to this full privacy policy for detailed information regarding data protection.
Controller
Data processing on this website is carried out by the website operator. You can find the controller's contact details in the "Controller" section of this privacy policy.
Collection of Your Data
Personal data is collected, on the one hand, when you actively provide it—for example, by filling out a contact form. Other data is recorded automatically or with your consent by the controller's IT systems when you visit the website. This primarily involves technical data (e.g., internet browser, operating system, or the time the page was accessed). This data collection occurs automatically as soon as you enter the website.
Use of Your Data
Some data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior in order to optimize our services and tailor them to your needs.
Data transfer to external parties
In the course of the data controller's business operations, it may be necessary to transfer personal data to external parties. Such transfers take place only under specific conditions: if the transfer is necessary for the performance of a contract; if there is a legal obligation (e.g., to tax authorities); if there is a legitimate interest pursuant to Art. 6(1)(f) GDPR; or if another legal basis permits the data transfer. When external service providers are used for data processing, personal data is transferred solely on the basis of a valid data processing agreement pursuant to Art. 28 GDPR. If data is processed jointly with other parties, a joint controllership agreement pursuant to Art. 26 GDPR is concluded.
Withdrawal of consent to data processing
Certain data processing activities may only be carried out with your explicit consent. You may withdraw this consent at any time. The withdrawal of consent does not affect the lawfulness of data processing carried out prior to the withdrawal.
Right to object to specific data processing activities and advertising measures (Art. 21 GDPR)
If your personal data is processed on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object to such processing at any time for reasons arising from your particular situation. This also applies to profiling based on these provisions. You can find the specific legal basis for the data processing in this privacy policy. In the event of an objection, the controller will no longer process your personal data unless compelling legitimate grounds can be demonstrated that override your interests, rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims (objection pursuant to Art. 21(1) GDPR).
If your personal data is used for direct marketing purposes, you have the right to object to such processing at any time. This also applies to profiling, insofar as it is related to direct marketing. Following your objection, the controller will no longer use your personal data for such marketing purposes (objection pursuant to Art. 21(2) GDPR).
2. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Company: WellMarin UG (haftungsbeschränkt)
Address: Am Vierrutenberg 34A, 13469 Berlin, Germany
Website: www.wellmarin.com
E-mail: info@wellmarin.com
3. Processors
We work with various processors who process data on our behalf. These service providers are contractually obliged to treat the data confidentially and to use it exclusively within the scope of the respective service. There are also instances where responsibility for data processing is shared with other entities. In such cases, responsibilities are clearly defined and documented to ensure compliance with data protection requirements.
4. Definitions
To ensure the transparency of this privacy policy and make it understandable to everyone, this statement primarily uses terms that are also defined in the General Data Protection Regulation (GDPR). The full legal definitions can be found in Art. 4 GDPR. The key terms relevant to this privacy policy are explained below:
Personal data: This includes all information relating to an identified or identifiable natural person (hereinafter referred to as the "data subject"). A person is considered identifiable if they can be identified, directly or indirectly—particularly by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or one or more specific factors expressing the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
Processing: This term encompasses any operation or set of operations performed on personal data, whether or not by automated means. This may include the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of data.
Controller: This refers to the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor: A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Website: The website refers to the entire online offering provided by the controller under a specific URL. This includes all content, information, functions, and services published by the controller and made accessible to the user via this URL. The website serves as a digital platform for providing information and services and for interaction between the controller and the users.
Terminal device: A terminal device is an electronic device capable of accessing the Internet and loading websites. This includes, among others, computers, laptops, tablets, and smartphones. These definitions help in better understanding the privacy policy and comprehending the meaning of the terms used.
5. Hosting
This website is hosted on the servers of an external service provider to ensure reliable and secure use of this online service.
Data processing by the hosting provider takes place in accordance with Art. 6(1)(f) GDPR, as the controller has a legitimate interest in providing a stable and secure website. If it is necessary to obtain the user's consent (for example, for the use of certain cookies or tracking technologies), data processing is based on the user's consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TTDSG. You may revoke your consent at any time with effect for the future.
The hosting provider is:
STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
E-Mail: datenschutz@strato.de
Details regarding data processing and data protection can be found in the hosting provider's privacy policy. You can access it here: https://www.strato.de/datenschutz/
To ensure that your data is processed in compliance with applicable data protection regulations, a data processing agreement (DPA) has been concluded with the hosting provider. This agreement obliges the hosting provider to process the personal data of website visitors exclusively in accordance with the controller's instructions and in compliance with the GDPR. The hosting provider guarantees comprehensive protection of your data through technical and organizational measures.
6. SSL/TLS Encryption
To protect the security of your data during transmission, state-of-the-art encryption methods (e.g., SSL or TLS) are used via HTTPS. SSL (Secure Socket Layer) and TLS (Transport Layer Security) are protocols for encrypting data transmissions on the Internet. This ensures that the data exchanged between your browser and the server is protected against unauthorized access. You can recognize an encrypted connection by the fact that the browser's address bar changes from "http://" to "https://" and by the lock icon in the browser bar.
7. Storage of user information in log files
Each time the website is accessed, general information transmitted by your browser to the server is automatically collected. This information is stored in so-called log files and generally includes:
a) IP address of the requesting computer
b) Date and time of access
c) Name and URL of the retrieved file
d) Website from which access originated (referrer URL)
e) Browser used and user agent string
f) Operating system
g) Name of your internet service provider
h) HTTP status code
This data is stored for security reasons to ensure a smooth connection to the website, to facilitate convenient use of the website, to evaluate system security and stability, and for other administrative purposes.
The legal basis for this data processing is Art. 6(1)(f) GDPR. The legitimate interest arises from the aforementioned purposes of data collection. Under no circumstances is the collected data used to draw conclusions about your identity. The stored data is anonymized or deleted unless statutory retention obligations apply.
8. Cookies
This website uses cookies. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit the site. Cookies do not damage your device and do not contain viruses, Trojans, or other malicious software.
Information related to the specific device used is stored in the cookie. However, this does not mean that the controller thereby gains direct knowledge of your identity.
On the one hand, cookies are used to make the use of the service more pleasant for you. For instance, the controller uses "session cookies" to recognize that you have already visited individual pages of the website. These are automatically deleted after you leave the site.
Furthermore, the controller uses temporary cookies to optimize user-friendliness; these are stored on your device for a specific, defined period. If you visit the pages again to use the services, the system automatically recognizes that you have been there before and recalls the inputs and settings you made, so you do not have to enter them again.
On the other hand, the controller uses cookies to statistically record website usage and analyze it for the purpose of optimizing the service for you. These cookies enable the controller to automatically recognize that you have visited the site before. These cookies are automatically deleted after a defined period.
9. Cookie Consent Banner
This website uses a cookie consent banner to manage your consent regarding the use of cookies. The provider of this service is:
STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
Functionality and Purpose
The cookie consent banner sets a technically necessary cookie to store these cookie consents. This cookie does not process any personal data. It merely stores the settings you selected upon entering the website, including:
a) Consent to or rejection of specific cookies
b) Time of consent
c) Duration of setting storage
d) Legal basis for data processing
Data processing via the cookie consent banner is carried out in accordance with Art. 6(1)(f) GDPR. The controller’s legitimate interest lies in ensuring lawful consent for the use of cookies. If consent has been requested, processing is based on Art. 6(1)(a) GDPR.
Storage duration and deletion
The stored data remains saved until you delete the cookies in your browser yourself or revoke your consent. You can change your settings at any time in the cookie settings section of this website.
10. Use of the contact form
For questions of any kind, you have the option to contact the controller using a form provided on this website. To identify the sender of the inquiry and to respond to it, the following data is required: first name, last name, company/organization/institution, address, and email.
When you send us inquiries via the contact form on our website, you agree—prior to submitting your data—that the information from the inquiry form, including the contact details you provided, may be used to process the inquiry and stored and used by us for any follow-up questions, within the scope of the consent you have given.
Processing of the data entered into the contact form is based solely on your consent (Art. 6(1)(a) GDPR). You may revoke this consent at any time. To do so, please send an informal email to info@wellmarin.com.
The lawfulness of data processing operations carried out prior to the revocation remains unaffected by the revocation. The information you provide in the contact form remains with us until you ask us to delete it, revoke your consent for storage, or the purpose for data storage ceases to apply (for example, after your request has been processed). Statutory provisions—particularly retention periods—remain unaffected.
11. Inquiries via email or telephone
You may direct inquiries to the controller via email or telephone. The personal data transmitted in this process (e.g., name, email address, telephone number, and the inquiry itself) will be processed and stored by the controller exclusively for the purpose of handling the inquiry and any subsequent follow-up questions.
12. Prohibition of sending promotional emails
The use of contact details published in the legal notice (Imprint) for the purpose of sending unsolicited advertising and information materials is hereby prohibited. Any unauthorized use of contact details for promotional purposes constitutes an infringement of the rights of the website operator and will not be tolerated. The website operator expressly reserves the right to take legal action in the event of violations, particularly regarding the unsolicited sending of promotional information such as spam emails.
Sending to existing customers without consent
Newsletters may be sent to existing customers without their express consent under certain conditions. This is permissible under Art. 6(1)(f) GDPR if the following conditions are met:
a) Existing customer status: The customer provided their email address in connection with the sale of a good or service.
b) Direct marketing of the company's own similar products or services: The newsletter contains only advertising for the company's own similar products or services.
c) Notice of right to object: The customer was clearly and explicitly informed—both when the email address was collected and in every newsletter—that they may object to the use of their email address at any time, incurring no costs other than the transmission costs at basic rates.
d) No objection from the customer: The customer has not objected to the use of their email address.
This method of sending newsletters is based on the controller's legitimate interest in informing existing customers about similar products or services and maintaining the business relationship. Data processing is carried out in accordance with Art. 6(1)(f) GDPR. Customers may, of course, object to the use of their email address for this purpose at any time. An informal notification via email to the controller or the use of the "unsubscribe" link in the respective newsletter is sufficient for this purpose.
13. Processing of Customer and Contract Data
Personal customer and contract data are collected, processed, and used for the purpose of establishing, structuring, and modifying contractual relationships. This may include names, addresses, email addresses, and telephone numbers. This information is necessary to provide services and to communicate. Depending on the selected payment method, payment information—such as credit card details, bank account details, or information regarding other payment services—is also collected and used exclusively for the payment process.
In addition, usage and order data are processed, including information regarding orders, the services provided, prices, and delivery details.
Personal data concerning the use of this website (usage data) are collected, processed, and used only to the extent necessary to enable the user to utilize the service or to bill for it.
The processing of personal data is based on various legal grounds. In accordance with Art. 6(1)(b) GDPR, data processing is carried out for the performance of a contract or to take steps prior to entering into a contract—for example, to process orders and provide services. Furthermore, processing is carried out pursuant to Art. 6(1)(c) GDPR to fulfill legal obligations, including statutory retention requirements. Furthermore, processing is carried out in accordance with Art. 6(1)(f) GDPR to safeguard legitimate interests, such as improving services and ensuring IT security.
The collected customer data will be deleted upon completion of the order or termination of the business relationship and the expiration of any applicable statutory retention periods. Statutory retention periods remain unaffected.
14. Shipping and delivery of goods
If goods are shipped to customers, the controller collects and processes additional personal data necessary for handling the shipment. This includes, in particular, the name, delivery address, and any specific delivery instructions. These data are used exclusively for carrying out the shipping process and delivering the ordered goods.
The processing of these data is based on Art. 6(1)(b) GDPR, as it is necessary for the performance of the contract—specifically, the delivery of the ordered goods.
As part of the shipping process, your data are passed on to commissioned shipping service providers to the extent necessary for delivery. These service providers are contractually obliged to treat your data confidentially and to use them only for the purpose of providing the service.
Once shipping is complete and the contractual relationship has been fulfilled, your shipping data are stored in accordance with statutory retention periods and subsequently deleted, unless there are further legal obligations requiring their retention.
15. Conclusion of contracts for services or digital content
When contracts for services or digital content are concluded, the controller collects and processes your personal data in order to fulfill contractual obligations. These data include, in particular, your contact information—such as name, address, and email address—as well as relevant information regarding the use of the services or digital content.
The processing of your data is based on various legal grounds: Pursuant to Art. 6(1)(b) GDPR, the controller processes your data to fulfill the contract and to carry out pre-contractual measures, such as the provision and use of the services. Furthermore, processing takes place pursuant to Art. 6(1)(c) GDPR to fulfill legal obligations, including compliance with statutory retention requirements. In addition, processing is carried out pursuant to Art. 6(1)(f) GDPR to safeguard legitimate interests, such as improving services and ensuring IT security. The data collected is used exclusively for the execution and fulfillment of contracts and is deleted after the contractual relationship has ended and any statutory retention periods have expired. Your data may be passed on to third parties involved in service provision—such as IT service providers—as part of the contract fulfillment process. These third parties are contractually obliged to treat your data confidentially and to use it solely for the purpose of providing the service.
The controller ensures that your data is only passed on to the extent necessary for contract fulfillment. No further transmission of data takes place unless you have expressly consented to such transmission. Your data will not be passed on to third parties without express consent, for instance for advertising purposes.
16. Processing of orders via dropshipping
When processing orders via dropshipping, the controller works with external suppliers who ship the ordered goods directly to you. During this process, your personal data is collected and processed in order to properly handle the orders and ensure the delivery of the goods.
The data processed includes, in particular, your contact information (such as name, address, and email address) as well as order details and delivery information. This data is forwarded to the relevant dropshipping suppliers responsible for fulfilling the order.
The processing of personal data is based on Art. 6(1)(b) GDPR, as it is necessary for the fulfillment of the contract—specifically, the processing of your orders. Furthermore, processing takes place pursuant to Art. 6(1)(f) GDPR to safeguard the controller's legitimate interests, such as optimizing the delivery process and ensuring customer satisfaction.
The controller ensures that dropshipping suppliers are contractually obliged to treat your data confidentially and to use it solely for the purpose of providing the service. No further transmission of the data takes place unless you have expressly consented to such transmission.
Following the completion of the order and delivery of the goods, your data will be stored in accordance with statutory retention periods and subsequently deleted, unless further statutory retention obligations apply. Your data will not be passed on to third parties for other purposes—particularly for advertising purposes—without your express consent.
17. Credit Check Prior to Contract Conclusion
To ensure customer solvency, credit checks may be conducted under certain circumstances before a contract is concluded. These checks serve to minimize the risk of payment defaults and ensure a secure business relationship.
As part of the credit check, personal data—such as name, address, date of birth, and contact details—may be transmitted to specialized credit reference agencies. These agencies use the data to assess creditworthiness and provide the relevant information. The credit check is performed exclusively to evaluate credit risk and to make decisions regarding the establishment, execution, or termination of a contractual relationship.
The processing of personal data for the credit check is based on Art. 6(1)(b) GDPR, as it is necessary for the implementation of pre-contractual measures taken at your request. Furthermore, processing is based on Art. 6(1)(f) GDPR to safeguard legitimate interests—specifically, protection against payment defaults and ensuring contract fulfillment.
Should the credit check yield a negative result, the controller reserves the right to refuse the conclusion of the contract or to offer alternative payment methods. Naturally, all data collected and processed during the credit check will be treated confidentially in accordance with applicable data protection regulations and stored only for as long as is necessary for the purpose of the credit check. No further transmission of data to third parties will occur unless express consent for such transmission has been given.
18. Security Tool
This website uses a security tool to ensure the integrity, confidentiality, and availability of data and to enhance protection against cyberattacks. The security tool may process personal data when you use the website.
This website uses the security tool from:
STRATO GmbH
Otto-Ostrowski-Straße 7, 10249 Berlin, Germany
