PRIVACY POLICY

INFORMATION REGARDING ART 13, 14 GDPR

We take the protection of your personal and company-related data very seriously and work hard to make sure our services are safe for you to use. We are committed to complying with statutory data protection requirements. This data protection policy describes the type of data that we collect from you, how and for what we use it, and how we protect it.

Table of Contents:

Area of Applicability

Which data do we record?

Cookies and Web Tracking

Conversion measurement with Facebook pixel

Sharing

Use of data

Data security and forwarding

Your data protection rights and contact details

1. Area of Applicability

This policy applies to the website available at http://www.lyconet-store.com. Please take into consideration that this refers to other Cashback World websites, including those of other countries for which different data protection rules apply.

Responsible under data protection law

Lyoness Europe AG

Bahnhofstraße22,

9470 Buchs, Switzerland

office@lyoness.ch

Data protection officer

Peter Oskar Miller

HXS GmbH

Millergasse 3

1060 Vienna, Austria

data.protection@lyoness.com

In the course of further website development to improve our services, it may occur that supplements to this Data Protection Declaration are necessary. In this case, we will inform you in advance and obtain your separate consent if needed.

2. What data is collected?

The personal and company-related data that we process includes all data on personal or factual circumstances that we obtain from you in the course of your Lyconet Store order and that can be directly or indirectly traced back to you. These are your member ID, full name, title, your postal address, your telephone number(s), country code, e-mail address.

3. Cookies and web tracking

Our websites use cookies. Cookies are small text files that are stored on your computer and can be retrieved from there later. Cookies enable your registration for our services and make it possible for us to personalize your experience while you are visiting our website.

You can use part of our web offer also without registering and/or logging on. In this case, too, certain information is recorded automatically to collect statistical data about the use and efficiency of our web offer and to adapt it to the demands and requirements of our users. To this end we collect and process information about your IP address, the time and length of your visit on our website, the number of your visits, your use of forms, your search settings, your view mode, your setting of favourites on our website. The period of cookie storage varies. We use mainly cookies that are automatically deleted when you have logged off from our website (referred to as "session cookies"). Each access to our website and each download of files available from our site is logged automatically. The cookies placed by us are used only as a source of information for us and are processed by mWS myWorld Solutions AG on behalf of Lyoness Europe AG.

We use JavaScript to record your traffic flow and browsing behaviour on our website with the aim of adjusting our web services to our users' requirements. In doing so we register your browser type, location, time and length of your visit, URL and site designation and the referral website. You can refuse the registration of these data by deactivating JavaScript directly via your web browser.

We use the following tools in addition:

Google Analytics

This is a web analytics tool from Google Inc., 1600 Amphitheater Parkway Mountain View, CA 94043 USA, herein after referred to as "Google", to log your online activity on our website, to find out how many users visit us and to record the number of times they access each page. This process is anonymous. Google Analytics' cookies (gat_UA-102544931-1: Google Analytics Universal Tracking, _ga: Google Analytics Universal Tracking, __gid: Google Analytics Universal Tracking) – including the Google Analytics Tool "Anonymous IP Address" and usage data – are typically sent to a Google server in the United States and stored there. For further information, please refer to https://support.google.com/analytics/answer/6004245?hl=de. To stop your data from being logged, please visit Google Analytics at https://tools.google.com/dlpage/gaoptout?hl=de.

Piwik Open Analytics Platform

We use the Piwik Open Analytics platform to record your online activities on our site and to determine how many users visit us on the internet and what content of our site is viewed how often. The statistical analysis is anonymous. The cookies are stored on your computer. For more information please visit https://piwik.org/faq/.

Google AdWords

This is used to record website visits for advertising purposes (re-marketing) on Google and in the Display Network. When you visit the site, your browser saves cookies (IDE: Google AdWords Cookie) which make it possible to recognise you as a visitor when you visit other websites belonging to Google's advertising network. On these pages, visitors can then be presented with advertisements that refer to the content previously viewed on other websites that use Google's re-marketing feature. You can reject Google AdWords' tracking at http://www.google.com/settings/ads.

Conversion Tracking of Google AdWords

This is how we create conversion statistics that measure the effectiveness of our online advertising campaigns. The conversion tracking cookie (IDE: Google AdWords Cookie) is set when a user clicks on an ad served by Google. According to Google's privacy policy, no personally identifiable information or company information is processed. If you do not want to be tracked, you can disable the Google Conversion tracking cookie through your Internet browser's internet settings.

Salesforce Marketing Cloud

We use this tool to record your user behaviour on our website to optimise our offer. We determine how many users visit us on the internet and what content of our site is viewed how often. The statistical analysis is anonymous and is used automatically by means of Predictive Intelligence for improved offer presentation. For registered members, the user-related behavior on the website is recorded to improve the user experience and to display relevant content. The cookies of Salesforce are usually transmitted to a Salesforce server in the USA and saved there.

Microsoft Application Insights

Application Insights is a service from Microsoft that enables us to monitor and improve the performance and usability of the Website. The service stores and analyzes anonymized telemetry data (Number of pageviews, page load times, exceptions encountered and tracing of AJAX dependencies). The cookies (-ai_user, ai_session) are usually transmitted to a Microsoft server in the USA and stored there.

Hotjar

We collect non-personal information, including standard internet log information and details of your behavioural patterns when you visit our website. This is done to enable us to provide you with a better user experience, to identify preferences, to diagnose technical problems, to analyse trends and to improve our website.

The following information may be collected related to your device and browser: device’s IP address (captured and stored in an anonymized form), device screen resolution, device type (unique device identifiers), operating system, and browser type, geographic location (country only), and preferred language used to display our website. The following information is collected related to your user interaction: mouse events (movements, location and clicks), keypresses.

For a sampling of visitors, Hotjar also records information which is collected from our website: referring URL and domain, pages visited, geographic location (country only), preferred language used to display our website, date and time when the website pages were accessed.

You may opt-out from having Hotjar collect your information when visiting our website at any time by visiting the Opt-out page https://www.hotjar.com/opt-out and clicking 'Disable Hotjar'.

In addition to the cookies described in the analysis tools used, the following additional cookies are used:

Cookie

Issuer

Purpose / Function

Language

Lyoness

This cookie stores the user's language settings.

cookiesession1

Lyoness

This cookie is used to distribute the load of HTTP requests in the network infrastructure.

authSession

Lyoness

Cookies that are created for the duration of a session and contain a session ID.

authToken

Lyoness

Authentication cookie created for logged-in users so that they can be identified.

LyoToolbar_SessionID

Lyoness

This cookie is used for communication with the Cashback bar.

lyo_AT_cookie_privacystatement

Lyoness

This cookie is used to track whether the user has agreed to the use of cookies.

__RequestVerificationToken

Lyoness

An anti-fraud token cookie used to prevent CSRF attacks.

Please note that most internet browsers are set to accept cookies by default. You can change the settings in your browser so that certain cookies are rejected or so that you are asked if you would like to accept new cookies. You will find instructions on how to do this under the "Help" function in the menu bar on most browsers. These instructions will normally tell you how to delete existing cookies as well.

Please note that you may not be able to use all the features and services on our websites if you do not accept any or all cookies.

By using our website, or, if necessary, by consent, which we obtain separately, you agree that the above cookies and tools may be used.

4. Conversion tracking with Facebook-Pixel

We use the "Facebook-Pixel" by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ("Facebook") (fr: Facebook Cookie for Opt-Out identification) within it's website with your consent. This is a cookie; a small text file that is stored on your computer which can be retrieved. It can be used to track users' actions after they have viewed or clicked on a Facebook ad. This enables us to track the effectiveness of Facebook advertising for statistical and market research purposes. The data collected in this way is anonymous for us, so it does not provide any inference as to the identity of the users. However, the Facebook data is stored and processed so that a connection to the respective user profile can be made, and Facebook can use the data for its own advertising purposes, according to the Facebook Data Usage Guideline (https://www.facebook.com/about/privacy/). You can enable Facebook and its partners to place advertising on and outside of Facebook. A cookie for these purposes can also be stored on your computer. By using the website, you agree to the use of the visitor action pixel.

5. Sharing

The website includes share buttons of the social networks Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA, XING, operated by XING AG, Dammtorstraße 30, 20354 Hamburg, Germany, LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA, Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA, and GooglePlus of the social network Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States. A share button for e-mail messages is also integrated in the website. The share buttons can be recognised by their respective logos.

All share buttons comply with the data protection provisions. Only by clicking on a share button on this website (and only then) will a direct connection between your browser and the server of the operator of the respective social network be established. According to the operators of the social networks referred to above, no personal data is recorded by the social network if their respective share buttons are not clicked. Such data, including among others the IP address, is only recorded and processed for members who are logged on. If you do not wish that your visit of our website can be traced back to your user account with the social network please log off the user account of the respective social network.

We would like to point out that we, as provider of the website, do not receive information about the content of the transmitted data nor of its use by the social networks. Further information on the use of data by social networks is available in the privacy statements of the social networks referred to above.

6. Use of data

We use your personal and company-related data exclusively in compliance with legal requirements. We record and process the personal data that you provide to us when ordering at the Lyconet Store only within the framework of our contractual obligations (Art 6 Sec 1 lit b GDPR). In addition, we use your data if there is a legal obligation (Art. 6 Sec 1 lit c GDPR), In addition, we use your personal or company-related data only in cases and to the extent to which you give us your specific consent (Art. 6 Sec 1 lit a GDPR).

We use your data, for example, to communicate with you, to verify your identity to process your queries and orders, and to provide our services to you. We use your data to determine the member benefits to which you are entitled to and to allocate these benefits to you.

If you have granted your separate approval, we will also use your data, for example, to inform you about offers and campaigns of our partner companies.

7. Data security and forwarding

In order to protect your data, we use, among other things, encryption for data transmission (SSL encryption), firewalls, hacker defence programmes and other state-of-the-art security devices. When communicating via e-mail, the security of the data can only be guaranteed by us according to the latest state of the art technology.

The use of your personal and company-related data will be handled by Lyoness Europe AG as the contractual partner and as the responsible entitiy for the processing of your data. Lyoness Europe AG uses mWS myWorld Solutions AG and the myWorld or Lyoness company with which you have concluded your membership agreement, as a service provider for the processing. Your personal data and company-related data can, however, be transferred / delivered to certain other service providers, as well as within to other companies of the Lyoness Group.

To carry out our services, communicate with you and manage our online presence we use the services of certain service providers. We assure you that we carefully select these service providers to ensure legal and secure data processing. In addition, we have obligated the service providers to use your personal data and company-related data only according to our instructions and according to the Austrian Data Protection Acts and the Data Protection Acts of the European Union. Further use of the data by these service providers is prohibited.

In addition, we will pass on your personal data and company-related data to the myWorld Group, insofar as this is necessary for the purpose of carring out the Cashback World Program, recording purchases at Loyalty Merchants, calculating the resulting Member Benefits, calculating and invoicing the agreed margins ensuring the necessary data security measures are taken. The myWorld Group companies are also obligated only to use your personal data and company-related data for the sole purpose for which it was given, as provided for in the Austrian Data Protection Acts and the Data Protection Acts of the European Union. In particular, the affected services are as follows: contact via electronic messages (e.g. e-mail, SMS or push notifications), by fax, by telephone or by letter for information about Loyalty Merchant and B2B Loyalty Merchants products and promotions, identification of promotions which are of interest to you, conducting satisfaction surveys, operating hotlines, and processing transactions. We will transmit your necessary personal data to the Loyalty Merchant or B2B Loyalty Merchant if and as far as it is necessary to be able to provide a concrete service for you or if you give us your explicit consent. The Loyalty Merchants and B2B Loyalty Merchants are obliged only to use your personal data and company-related data for the sole purpose for which it was given, as provided for in the Austrian Data Protection Acts and the Data Protection Acts of the European Union.

myWorld Group is an international corporation. Our business activities, management structure and our technical infrastructure transcend national borders. We can therefore send your personal data and company-related data to other myWorld companies abroad, as far as this is necessary to carry out the Cashback World Program, to record the purchases you have made as well as the resulting Member Benefits or the resulting margin calculations. A transfer of your personal or company-related data to the Member States of the European Economic Area, to Switzerland and to other countries with adequate level of data protection requires no further consent. If, however, your personal and company-related data is transferred to any country other than those mentioned above, we will inform you and of course comply with the applicable data protection regulations, provide you with appropriate guarantees and ensure the enforcement of your rights and remedies.

We will not pass on your personal data and company data to any persons other than the above-mentioned Loyalty Merchants, B2B Loyalty merchants, service providers and myWorld companies, unless you have given us your consent or if there is a legal obligation to do so.

8. Your data protection rights and contact information

You have the right to obtain information about the personal or company-related data that we process about you and may request their correction, deletion or restriction of processing. You also have the right of objection and the right to data portability (Which means you have the right to receive the data in a structured, common and machine-readable format).

If you believe that the processing of your personal or company-related data violates the EU General Data Protection Regulation, you have the right to lodge a complaint with the Austrian Data Protection Authority (www.dsb.gv.at) or a supervisory authority of another EU Member State.

If the use of your personal or company-related data on this website is based on your consent you have the right to revoke your consent for the processing of this data for the future at any time without having to provide any reasons. By withdrawing your approval, your data may no longer be used. Please inform us in writing of your wish to withdraw approval (by post or e-mail) using the following address':

mWS myWorld Solutions AG

Grazbachgasse 87-93,

8010 Graz,

Austria

Tel: +43(0) 316 / 70 77 0

E-mail: international@lyconet.com

Please also use this contact information for any questions regarding the use of your data as well as for information about the enforcement of your data protection rights.

Laden
Laden