Privacy Policy

Privacy Policy

Protection of your Data is important to us!

For NIVEA not only the care and protection of your skin is important. We also attach great importance to the protection of your personal data. That's why we respect your privacy and want you to be able to trust us as much when it comes to data protection as when it comes to skin care. We always inform you transparently about what we need your data for and if and for how long we store it. This allows you to decide for yourself for which purposes we may use your data. To ensure the best possible security, the information is always transmitted to us in encrypted form. If you no longer wish us to use your data, please let us know informally, for example by email. 

Content of this Privacy Policy

1. General Information 
1.1. Processing of Personal Data 
1.2. Controller 
1.3. Rights of the Data Subject 
1.4. Disclosure to Authority  

2. Collection and Processing of Personal Data when visiting our Website 
2.1 Cookies 
2.2 Web Analytics 
2.3 Social Plug-ins 
2.4 Social Login 
2.5 YouTube-Videos 
2.6 Online Advertising 
2.7 Google Tag Manager

3. Further services offered (on- and offline)
3.1 Contacting
3.2 Newsletter
3.3 Campaigns (e.g. Sweepstakes, Surveys, Product Tests)
3.4 Login Profile
3.5 Loyalty Program / NIVEA FOR ME
3.6 Postal Mailings
3.7 Ratings and Reviews
3.8 Live Chat
3.9 Web Shop

4. Objection or Withdrawal of your consent to the Processing of Personal Data

General Information

General Information

The purpose of this privacy policy is to provide you with information concerning the processing of personal data when using our website and related services. 

1.1. Processing of Personal Data

Personal data within the meaning of Art. 4 of the EU General Data Protection Regulation (GDPR) are all information relating to an identified or identifiable natural person, e.g. name, address, email address, etc.

1.2. Controller

Responsible for the processing of personal data within the meaning of Art. 4 (7) GDPR is: Beiersdorf UK, Trinity Business Park, Birmingham, B37 7ES, Tel: +44 (0)121 329 8800 [Dataprotection[at]Beiersdorf.com] (see our imprint).

Contact details of the data protection officer: Dataprotection[at]Beiersdorf.com or via the postal address of the controller for the attention of the “data protection officer”.

1.3. Rights of the Data Subject

As data subject affected by the data processing activity, you have the following rights with regard to your personal data according to Art. 15 et seqq. GDPR:

  • Right of access;
  • Right to rectification and to erasure;
  • Right to restriction of processing;
  • Right to data portability; and 
  • Right to object. 

Furthermore, you have the right to lodge a complaint with a supervisory authority concerning the processing of your personal data.

When we work on your above-mentioned right, we may ask you for proof of your identity. For more information on how we process your data, see 3.1.

1.4. Disclosure to Authority

In the event of a legal obligation, we reserve the right to disclose information about you if we are required to surrender it to competent authorities or law enforcement bodies.

Legal basis: Art. 6 (1) c) GDPR

Collection & Processing

Collection & Processing of Personal Data when visiting our Website

In addition to the purely informational use of our website, we offer various other services, for which we process your personal data. 

If we use contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. 

External service providers have been carefully selected and commissioned by us, are bound by our instructions and are regularly checked.

We may also disclose your personal data to third parties when we offer promotions, sweepstakes, contracts or similar services in conjunction with partners. Further information can be obtained at the time when you provide the data or in the description of the services below.

Contrary to 1.2, in some cases a Beiersdorf Company is Controller for the services offered below, which has already been named to you as part of the communication. If reference is therefore made to sections of this privacy policy, e.g. by link, and a Controller has already been named, e.g. in the footer/signature of an e-mail or campaign card, this person is the Controller in accordance with. Art. 4 No. 7 GDPR. 

If our service providers are based in a country outside the European Economic Area (EEA), international data transfers can occur. We will inform you of the consequences of this circumstance in the description of the service below.

3.1 Contacting

When communicating and/or collaboration with us, e.g. by email or via contact form on our website, data exchange platform, be it e.g. as a consumer, test person, business partner or customer, the data you provide (your email address, if applicable your name and your telephone number, or personal data submitted during the conversation) will be stored and processed by us in order to e.g. answer your questions, requests or for the purpose of business related correspondence. We delete the data arising in this context once storage is no longer necessary, unless statutory retention obligations exist or periods of limitation must be observed. 

When processing data arising in the course of communication, we have a legitimate interest in processing the data in accordance with legal requirements, for internal verification or in accordance with the respective communication request. In order to combat terrorism, we are obliged by law to carry out a comparison with sanctions lists. Therefore, we also process your data to meet legal requirements for comparison with these lists. Furthermore, we process your data in the Beiersdorf Group for the prevention and investigation of criminal offences and other misconduct, the assessment and control of risks, for internal communication and for corresponding administrative purposes. You can object to this processing according to the requirements under 4.In case of consumer inquiries through our internal consumer management tool the personal data will be usually deleted after one year. As an exception, the data will be kept longer if the data is necessary for the establishment, exercise or defence of legal claims.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, call center service providers) in accordance with the purposes required (e.g. for establishing contacts, business related correspondence and customer care). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en. 

Legal basis: Art. 6 (1) b GDPR.

3.2 Newsletter

The newsletter contains news, offers and further information on the selected Beiersdorf brands. By subscribing to the newsletter you will receive in accordance with the consent you have given in each case  personalized information about the products, services or suggestions for participation in promotions, such as competitions or product tests by e-mail or advertising on your own or third-party channels (e.g. via social media).

With your registration for the newsletter you will receive a newsletter tailored to your needs (if the newsletter is "personalized", "individualized" or "customized"). We evaluate your purchase and click behavior on our websites or within the newsletter in order to compile the information relevant to you. 

The newsletter is usually sent once a month ("regularly"). In individual cases (e.g., for special actions), weekly emailing may also occur.

We also use remarketing measures to show you the relevant online advertising. 

The data will be forwarded to our customer management platform, which service providers may also have access to support and implement the newsletter. Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

These collected data are automatically deleted after 24 months if they no longer respond to the newsletter, e.g. open (inactivity). If you no longer wish to receive the newsletter, you can unsubscribe at any time. Click on the link contained in each newsletter, you will then be guided through the unsubscribe process, or send us your withdrawal by email.

Legal basis: Art. 6 (1) a GDPR.

3.3 Campaigns (e.g. Sweepstakes, Surveys, Product Tests)

When you participate in sweepstakes, surveys or similar campaigns, we use the personal information you provide to conduct the campaign. Further information on the purposes can be found in the respective terms and conditions of the campaign. 

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, shipping, processing service providers) in accordance with the purposes required (to carry out the campaign). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted after the final processing of the campaign (see terms and conditions of participation), unless this conflicts with statutory retention obligations or statutes of limitations. 

The provision of your personal data is necessary for the performance of a contract. You are not obliged to provide your personal data. If your data is not provided, you cannot participate in the campaign.

Further information can be found in the respective terms and conditions of the campaign.

Legal basis: Art. 6 (1) b GDPR.

3.4 Login Profile / myNIVEA Account

By registering a profile, we provide you the opportunity to write reviews, to create a favourite list, get the newsletter and get other personalised offers and campaign material. From this we will provide you personalised content based on your behaviour. We use this data to contact you individually, considering clicks, redemptions, activities, or other actions to suggest future interest in content, campaigns such as sweepstakes or product tests. We will contact you via such communication channels that you provide to us in connection with your consent to contact us, for example by email, if you provide your e-mail address. Finally, we also use your data to analyze and improve the effectiveness of our websites. By completing a profile, you consent to your data being stored and used for market research and advertising purposes. We can then send you individualized advertising about our products or services.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, consumer database, marketing agency, review supplier) in accordance with the required purposes (to carry out the advertising etc.). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted as soon as you have logged off from the program, unless this conflicts with legal storage obligations or statutes of limitations. In order to delete your data, please log in to your customer account and complete the unsubscribe process or send us your withdrawal to the data processing by email. We delete your personal data automatically after 24 months inactivity.

Legal basis: Art. 6 (1) a GDPR.

3.5 Loyalty Program

If participate in our loyalty program (online or offline), your personal data will be processed as follows:

By participating, you may receive your personal customer magazine, product samples and special offers via individualized email, post or online advertising (link to section online advertising) on your own or third-party channels (e.g. social media). We evaluate your purchase and click behavior on our websites or within the newsletter (if subscribed to) in order to compile the information relevant to you. In addition, we use this data to contact you individually, taking into account already started or completed purchase transactions, or to suggest participation in campaigns such as sweepstakes or product tests. We will contact you via such communication channels that you provide to us in connection with your consent to contact us, for example by email, if you provide your e-mail address. Finally, we also use your data to analyze and improve the effectiveness of our websites. Your data will be stored and used for market research and advertising purposes. We can then send you individualized advertising about our products or services. 

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, shipping, processing service providers) in accordance with the required purposes (to carry out the sending of the magazine, product samples, advertising etc.). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted as soon as you have logged off from the program, unless this conflicts with legal storage obligations or statutes of limitations. In order to delete your data, please log in to your customer account and complete the unsubscribe process, or send us your withdrawal to the data processing by email. 

Legal basis: Art. 6 (1) a GDPR

3.6 Postal Mailings

As a selected customer, business partner, test person and/or consumer, you will also receive individual product information, offers, news and product samples from us by post (letter). 

This is a special form of direct marketing, which is also our legitimate interest and intensifies loyalty by providing the above-mentioned persons exclusive information.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contractors (e.g. customer/consumer management service providers, marketing agency, postal service provider) in accordance with the required purposes (postal mailings). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted as soon as you have unsubscribed, unless this conflicts with legal storage obligations or statutes of limitations. You can unsubscribe or object to further postal mailings as stated within the letter or in the section objection below [link to 4. objection]. We further delete your personal data automatically after 24 months inactivity (e.g. when you do not use the sent coupons).

Legal basis: Art. 6 (1) f GDPR

3.7 Ratings and Reviews

Registered users have the possibility to submit ratings and reviews of products, processes or other evaluations within the scope of the website's offers in accordance with the terms of use. It is our legitimate interest that users can give their free opinion about products.

Your rating will be published with your username. We recommend that you use a pseudonym instead of your clear name. The ratings are not reviewed before publication. We reserve the right to delete comments if they are objected to as unlawful by third parties.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contractors (e.g. hosting service providers, customer management service providers) in accordance with the required purposes (for publication on the website).

We also transfer ratings and reviews to our retail partners to be displayed on their websites also. This is carried out through a third party. We only share information needed to validate the review - e.g. your username, the review itself, and the corresponding details.

The comments are deleted accordingly to the account.

Legal basis is Art. 6 (1) f GDPR 

3.8 Live Chat

This website uses Userlike's live chat software. Userlike uses cookies to keep the chat content available while surfing the website and to connect you to the same operator if possible when chatting again. The data collected is not used to personally identify the visitor to this website and is not merged with personal data about the bearer of the pseudonym, unless personal data is provided voluntarily during the use of the live chat.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. call centers) in accordance with the required purposes (for personal consultation). 

Your data will be deleted as soon as you have logged out of the live chat, unless this is contrary to legal retention obligations or statute of limitations.

The provision of your personal data is not required for the conclusion of a contract. You are not obliged to provide personal data. If your personal data is not provided, we can still offer you the live chat services.

Used Cookies: Type A. For further information, see Cookie Section.

Cookie lifetime: up to 2 years.

Maximum storage period of data: up to 14 months.

Legal basis: Art. 6 (1) b GDPR. 

3.9 Webshop

If you would like to order products in our web shop, it is required for the conclusion of the contract that you enter your personal data, which we need for the completion and execution of your order. Required information for the execution of the order is marked separately, any other information you provide is voluntary. We process the data provided by you only to process and execute your order. 

For this purpose we might transmit on the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contractors (e.g. payment providers, fulfilment providers, customer management service providers, content management provider) in accordance with the required purposes (processing and execution of the order). To prevent unauthorized access to your personal data, especially financial data, the order process is encrypted using TLS technology.

In addition, you can voluntarily create a customer account through which we can store your data for future purchases. When you create such an account on the website, the data you have provided will be stored revocably. All other data, including your user account, can always be deleted in the customer area.

We may also process the information you provide to inform you of other interesting products in our portfolio or to send you emails containing technical information.

We are obliged by commercial and applicable tax laws to store your address, payment and order data for a period of up to ten years. 

Used Cookies: Type A. For further information, see Cookie Section.

Cookie lifetime: up to 2 years.

Maximum storage period of data: up to 14 months.

Legal basis: Art. 6 (1) b GDPR.

Further Services

In addition to the purely informational use of our website, we offer various other services, for which we process your personal data. 

If we use contracted service providers for individual functions of our offer or would like to use your data for advertising purposes, we will inform you in detail about the respective processes below. 

External service providers have been carefully selected and commissioned by us, are bound by our instructions and are regularly checked.

We may also disclose your personal data to third parties when we offer promotions, sweepstakes, contracts or similar services in conjunction with partners. Further information can be obtained at the time when you provide the data or in the description of the services below.

Contrary to 1.2, in some cases a Beiersdorf Company is Controller for the services offered below, which has already been named to you as part of the communication. If reference is therefore made to sections of this privacy policy, e.g. by link, and a Controller has already been named, e.g. in the footer/signature of an e-mail or campaign card, this person is the Controller in accordance with. Art. 4 No. 7 GDPR. 

If our service providers are based in a country outside the European Economic Area (EEA), international data transfers can occur. We will inform you of the consequences of this circumstance in the description of the service below.

3.1 Contacting

When communicating and/or collaboration with us, e.g. by email or via contact form on our website, data exchange platform, be it e.g. as a consumer, test person, business partner or customer, the data you provide (your email address, if applicable your name and your telephone number, or personal data submitted during the conversation) will be stored and processed by us in order to e.g. answer your questions, requests or for the purpose of business related correspondence. We delete the data arising in this context once storage is no longer necessary, unless statutory retention obligations exist or periods of limitation must be observed. 

When processing data arising in the course of communication, we have a legitimate interest in processing the data in accordance with legal requirements, for internal verification or in accordance with the respective communication request. In order to combat terrorism, we are obliged by law to carry out a comparison with sanctions lists. Therefore, we also process your data to meet legal requirements for comparison with these lists. Furthermore, we process your data in the Beiersdorf Group for the prevention and investigation of criminal offences and other misconduct, the assessment and control of risks, for internal communication and for corresponding administrative purposes. You can object to this processing according to the requirements under 4.In case of consumer inquiries through our internal consumer management tool the personal data will be usually deleted after one year. As an exception, the data will be kept longer if the data is necessary for the establishment, exercise or defence of legal claims.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, call center service providers) in accordance with the purposes required (e.g. for establishing contacts, business related correspondence and customer care). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en. 

Legal basis: Art. 6 (1) b GDPR.

3.2 Newsletter

The newsletter contains news, offers and further information on the selected Beiersdorf brands. By subscribing to the newsletter you will receive in accordance with the consent you have given in each case  personalized information about the products, services or suggestions for participation in promotions, such as competitions or product tests by e-mail or advertising on your own or third-party channels (e.g. via social media).

With your registration for the newsletter you will receive a newsletter tailored to your needs (if the newsletter is "personalized", "individualized" or "customized"). We evaluate your purchase and click behavior on our websites or within the newsletter in order to compile the information relevant to you. 

The newsletter is usually sent once a month ("regularly"). In individual cases (e.g., for special actions), weekly emailing may also occur.

We also use remarketing measures to show you the relevant online advertising. 

The data will be forwarded to our customer management platform, which service providers may also have access to support and implement the newsletter. Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

These collected data are automatically deleted after 24 months if they no longer respond to the newsletter, e.g. open (inactivity). If you no longer wish to receive the newsletter, you can unsubscribe at any time. Click on the link contained in each newsletter, you will then be guided through the unsubscribe process, or send us your withdrawal by email.

Legal basis: Art. 6 (1) a GDPR.

3.3 Campaigns (e.g. Sweepstakes, Surveys, Product Tests)

When you participate in sweepstakes, surveys or similar campaigns, we use the personal information you provide to conduct the campaign. Further information on the purposes can be found in the respective terms and conditions of the campaign. 

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, shipping, processing service providers) in accordance with the purposes required (to carry out the campaign). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted after the final processing of the campaign (see terms and conditions of participation), unless this conflicts with statutory retention obligations or statutes of limitations. 

The provision of your personal data is necessary for the performance of a contract. You are not obliged to provide your personal data. If your data is not provided, you cannot participate in the campaign.

Further information can be found in the respective terms and conditions of the campaign.

Legal basis: Art. 6 (1) b GDPR.

3.4 Login Profile / myNIVEA Account

By registering a profile, we provide you the opportunity to write reviews, to create a favourite list, get the newsletter and get other personalised offers and campaign material. From this we will provide you personalised content based on your behaviour. We use this data to contact you individually, considering clicks, redemptions, activities, or other actions to suggest future interest in content, campaigns such as sweepstakes or product tests. We will contact you via such communication channels that you provide to us in connection with your consent to contact us, for example by email, if you provide your e-mail address. Finally, we also use your data to analyze and improve the effectiveness of our websites. By completing a profile, you consent to your data being stored and used for market research and advertising purposes. We can then send you individualized advertising about our products or services.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, consumer database, marketing agency, review supplier) in accordance with the required purposes (to carry out the advertising etc.). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted as soon as you have logged off from the program, unless this conflicts with legal storage obligations or statutes of limitations. In order to delete your data, please log in to your customer account and complete the unsubscribe process or send us your withdrawal to the data processing by email. We delete your personal data automatically after 24 months inactivity.

Legal basis: Art. 6 (1) a GDPR.

3.5 Loyalty Program

If participate in our loyalty program (online or offline), your personal data will be processed as follows:

By participating, you may receive your personal customer magazine, product samples and special offers via individualized email, post or online advertising (link to section online advertising) on your own or third-party channels (e.g. social media). We evaluate your purchase and click behavior on our websites or within the newsletter (if subscribed to) in order to compile the information relevant to you. In addition, we use this data to contact you individually, taking into account already started or completed purchase transactions, or to suggest participation in campaigns such as sweepstakes or product tests. We will contact you via such communication channels that you provide to us in connection with your consent to contact us, for example by email, if you provide your e-mail address. Finally, we also use your data to analyze and improve the effectiveness of our websites. Your data will be stored and used for market research and advertising purposes. We can then send you individualized advertising about our products or services. 

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. hosting, shipping, processing service providers) in accordance with the required purposes (to carry out the sending of the magazine, product samples, advertising etc.). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted as soon as you have logged off from the program, unless this conflicts with legal storage obligations or statutes of limitations. In order to delete your data, please log in to your customer account and complete the unsubscribe process, or send us your withdrawal to the data processing by email. 

Legal basis: Art. 6 (1) a GDPR

3.6 Postal Mailings

As a selected customer, business partner, test person and/or consumer, you will also receive individual product information, offers, news and product samples from us by post (letter). 

This is a special form of direct marketing, which is also our legitimate interest and intensifies loyalty by providing the above-mentioned persons exclusive information.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contractors (e.g. customer/consumer management service providers, marketing agency, postal service provider) in accordance with the required purposes (postal mailings). Platform/hosting providers will have access to personal data from a third country (countries outside the European Economic Area). As an appropriate safeguard we have agreed on standard contractual clauses pursuant to Art. 46 GDPR with these providers or they are (additionally) EU-U.S. Privacy Shield certified. More information on this topic is published here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.

Your data will be deleted as soon as you have unsubscribed, unless this conflicts with legal storage obligations or statutes of limitations. You can unsubscribe or object to further postal mailings as stated within the letter or in the section objection below [link to 4. objection]. We further delete your personal data automatically after 24 months inactivity (e.g. when you do not use the sent coupons).

Legal basis: Art. 6 (1) f GDPR

3.7 Ratings and Reviews

Registered users have the possibility to submit ratings and reviews of products, processes or other evaluations within the scope of the website's offers in accordance with the terms of use. It is our legitimate interest that users can give their free opinion about products.

Your rating will be published with your username. We recommend that you use a pseudonym instead of your clear name. The ratings are not reviewed before publication. We reserve the right to delete comments if they are objected to as unlawful by third parties.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contractors (e.g. hosting service providers, customer management service providers) in accordance with the required purposes (for publication on the website).

We also transfer ratings and reviews to our retail partners to be displayed on their websites also. This is carried out through a third party. We only share information needed to validate the review - e.g. your username, the review itself, and the corresponding details.

The comments are deleted accordingly to the login account.

Legal basis is Art. 6 (1) f GDPR 

3.8 Live Chat

This website uses Userlike's live chat software. Userlike uses cookies to keep the chat content available while surfing the website and to connect you to the same operator if possible when chatting again. The data collected is not used to personally identify the visitor to this website and is not merged with personal data about the bearer of the pseudonym, unless personal data is provided voluntarily during the use of the live chat.

We transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contract processors (e.g. call centers) in accordance with the required purposes (for personal consultation). 

Your data will be deleted as soon as you have logged out of the live chat, unless this is contrary to legal retention obligations or statute of limitations.

The provision of your personal data is not required for the conclusion of a contract. You are not obliged to provide personal data. If your personal data is not provided, we can still offer you the live chat services.

Used Cookies: Type A. For further information, see Cookie Section.

Cookie lifetime: up to 2 years.

Maximum storage period of data: up to 14 months.

Legal basis: Art. 6 (1) b GDPR. 

3.9 Webshop

If you would like to order products in our web shop, it is required for the conclusion of the contract that you enter your personal data, which we need for the completion and execution of your order. Required information for the execution of the order is marked separately, any other information you provide is voluntary. We process the data provided by you only to process and execute your order. 

For this purpose we might transmit on the collected data to the relevant internal departments for processing and to other affiliated companies within the Beiersdorf Group or to external service providers, contractors (e.g. payment providers, fulfilment providers, customer management service providers, content management provider) in accordance with the required purposes (processing and execution of the order). To prevent unauthorized access to your personal data, especially financial data, the order process is encrypted using TLS technology.

In addition, you can voluntarily create a customer account through which we can store your data for future purchases. When you create such an account on the website, the data you have provided will be stored revocably. All other data, including your user account, can always be deleted in the customer area.

We may also process the information you provide to inform you of other interesting products in our portfolio or to send you emails containing technical information.

We are obliged by commercial and applicable tax laws to store your address, payment and order data for a period of up to ten years. 

Used Cookies: Type A. For further information, see Cookie Section.

Cookie lifetime: up to 2 years.

Maximum storage period of data: up to 14 months.

Legal basis: Art. 6 (1) b GDPR.

Objection OR Withdrawal of Your Consent

If you have given your consent (Art. 6 (1) a GDPR) to the processing of your data, you can withdraw your consent at any time. Such a withdrawal influences the permissibility of processing your personal data after you have given it to us.

If we base the processing of your personal data on the weighing of interests (Art. 6 (1) f GDPR), you may object to the processing. This is the case if processing is not necessary in particular to fulfil a contract with you, which is described by us in the description of the functions / services. When exercising such objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either stop or adjust data processing or point out to you our compelling reasons worthy of protection, on the basis of which we will continue processing. 

Of course, you can object to the processing of your personal data for purposes of advertising and data analysis at any time. You can inform us about your objection under the above-mentioned contact details for the controller.