Privacy Policy
​
1) Introduction and Contact Details of the Data Controller
​
1.1 We are delighted that you are visiting our website and thank you for your interest. In the following, we will inform you about how we handle your personal data when you use our website. Personal data includes any data that can personally identify you.
1.2 The data controller responsible for processing data on this website in accordance with the General Data Protection Regulation (GDPR) is Ursus Wineries GmbH, Schneppenhäuser Str. 51, 64331 Weiterstadt, Germany, Tel.: 015157645346, Email: j.baehr@ursus-wineries.com. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.
​
2) Data Collection When Visiting Our Website
​
2.1 When you visit our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect the data that your browser sends to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you accessed the page
- Browser used
- Operating system used
- IP address used (if applicable, in anonymized form)
The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. Data will not be transferred or used for other purposes. However, we reserve the right to check the server log files subsequently if there are specific indications of illegal use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser line.
​
3) Hosting & Content Delivery Network
​
3.1 **Wix**
For hosting our website and displaying the content of the pages, we use the system of the following provider: Wix HQ, 6350671, Nemal Tel Aviv St 40, Tel Aviv-Yafo, Israel.
Data is also transferred to: Wix Inc., 500 Terry A. Francois Boulevard, San Francisco, California 94158, USA.
All data collected on our website is processed on the provider's servers. We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.
An adequate level of data protection is ensured for data transfers to the provider's location through an adequacy decision of the European Commission.
The provider has joined the EU-US Data Privacy Framework for data transfers to the USA, ensuring compliance with the European level of data protection based on an adequacy decision of the European Commission.
3.2 **Google Cloud CDN**
We use a Content Delivery Network (CDN) provided by the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
This service allows us to deliver large media files such as graphics, page content, or scripts faster through a network of regionally distributed servers. Processing is carried out to maintain our legitimate interest in improving the stability and functionality of our website in accordance with Art. 6 Para. 1 lit. f GDPR.
Data may also be transferred to: Google LLC, USA.
We have concluded a data processing agreement with the provider, ensuring the protection of the data of our website visitors and prohibiting unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, ensuring compliance with the European level of data protection based on an adequacy decision of the European Commission.
​
4) Cookies
​
To make your visit to our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted when you close your browser (so-called "session cookies"), while others remain on your device for a longer period and enable us to store your settings (so-called "persistent cookies"). In the latter case, you can find the storage period in the overview of the cookie settings of your web browser.
If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR either for the execution of the contract, pursuant to Art. 6 Para. 1 lit. a GDPR in the case of consent given, or pursuant to Art. 6 Para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the page visit.
You can configure your browser settings according to your preferences, for example, to be informed about the setting of cookies and to decide on their acceptance individually, or to exclude the acceptance of cookies for certain cases or in general.
Please note that if you do not accept cookies, the functionality of our website may be limited.
​
5) Contact
​
As part of contacting us (e.g., via contact form or email), personal data is processed – solely for the purpose of processing and responding to your request and only to the extent necessary.
The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 Para. 1 lit. f GDPR. If your contact aims at concluding a contract, an additional legal basis for processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the relevant matter has been finally clarified and there are no legal retention obligations to the contrary.
​
6) Data Processing for Order Processing
​
6.1 To the extent necessary for the processing of contracts for delivery and payment purposes, the personal data collected by us will be transferred to the commissioned transport company and the commissioned bank in accordance with Art. 6 Para. 1 lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact details you provided when ordering (name, address, email address) in order to inform you personally about upcoming updates in accordance with our legal obligations under Art. 6 Para. 1 lit. c GDPR via a suitable communication channel (e.g., by post or email) within the legally prescribed period. Your contact details will be strictly used for the purpose of informing you about updates owed by us and will only be processed by us to the extent necessary for the respective information.
To process your order, we also cooperate with the following service provider(s), who support us in whole or in part in the execution of concluded contracts. Certain personal data will be transmitted to these service providers in accordance with the following information.
6.2 Use of Payment Service Providers (Payment Services)
- PayPal
On this website, one or more online payment methods of the following provider are available: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
When selecting a payment method offered by the provider, where you pay in advance, your payment data (including name, address
, bank and credit card information, currency, and transaction number) as well as information about the contents of your order will be transmitted to them in accordance with Art. 6 Para. 1 lit. b GDPR. Your data will only be disclosed for the purpose of processing payments with the provider and only to the extent necessary for this purpose.
When selecting a payment method where we pay in advance, you will also be asked to provide certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable, data on an alternative payment method) during the order process.
To protect our legitimate interest in determining your ability to pay in such cases, we will transmit this data to the provider for the purpose of a credit check in accordance with Art. 6 Para. 1 lit. f GDPR. Based on the personal data provided by you and additional data (such as shopping cart, invoice amount, order history, payment experience), the provider checks whether the payment option selected by you can be granted in view of payment and/or default risks.
The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical method. Among other things, address data is included in the calculation of score values.
You can object to the processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual processing of payments.
​
7) Web Analytics Services
​
Polyfill
This website uses the service of the following provider: The Financial Times Ltd., Bracken House, 1 Friday Street, London, England, EC4M 9BT.
The service installs a script on our website that allows content to be displayed in high quality even on older browser versions by providing and transmitting Polyfill files to bridge missing browser functions during the browser request. For this purpose, certain technical information such as browser details and connection data including your IP address are automatically transmitted to the provider in anonymized form.
The information is used to determine which Polyfill files are required by your browser for the proper display of page content.
If personal data is also processed in this context, processing is carried out based on our legitimate interests in the optimal presentation of our website and the optimization of the user experience in accordance with Art. 6 Para. 1 lit. f GDPR.
An adequate level of data protection is ensured for data transfers to the provider's location through an adequacy decision of the European Commission.
​
8) Rights of the Data Subject
​
8.1 The applicable data protection law grants you as the data subject the following rights with regard to the processing of your personal data (data subject rights), with reference to the legal basis for the respective exercise conditions:
- Right to information according to Art. 15 GDPR;
- Right to rectification according to Art. 16 GDPR;
- Right to erasure according to Art. 17 GDPR;
- Right to restriction of processing according to Art. 18 GDPR;
- Right to notification according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to withdraw consent granted according to Art. 7 Para. 3 GDPR;
- Right to lodge a complaint according to Art. 77 GDPR.
8.2 **Right to Object**
IF WE PROCESS YOUR PERSONAL DATA AS PART OF A BALANCING OF INTERESTS BASED ON OUR PREDOMINANT LEGITIMATE INTEREST, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF PROCESSING IS FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US TO CONDUCT DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR THE PURPOSE OF SUCH ADVERTISING. YOU MAY EXERCISE YOUR RIGHT TO OBJECT AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT ADVERTISING PURPOSES.
​
9) Duration of Personal Data Storage
​
The duration of the storage of personal data is based on the respective legal basis, the purpose of processing, and, if applicable, additionally on the respective statutory retention period (e.g., commercial and tax retention periods).
For processing personal data based on explicit consent according to Art. 6 Para. 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.
If there are legal retention periods for data processed within the framework of contractual or quasi-contractual obligations based on Art. 6 Para. 1 lit. b GDPR, these data will be routinely deleted after the expiry of the retention periods, provided they are no longer required for contract performance or contract initiation and/or there is no longer a legitimate interest on our part in continuing to store them.
For processing personal data based on Art. 6 Para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 Para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.
For processing personal data for the purpose of direct advertising based on Art. 6 Para. 1 lit. f GDPR, this data will be stored until you exercise your right to object under Art. 21 Para. 2 GDPR.
Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.