Privacy
1) Introduction and Contact Details of the Controller
1.1 We are delighted that you are visiting our website and thank you for your interest. In the following, we will inform you about how we handle your personal data when you use our website. Personal data refers to any information that can personally identify you.
1.2 Controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Müller di Coste GbR, Prießallee 52, 33604 Bielefeld, Deutschland, E-Mail: info@mangaguardian.com. The controller for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
2) Data Collection When Visiting Our Website
2.1 When you visit our website for informational purposes only, meaning you do not register or otherwise provide us with information, we only collect the data that your browser sends to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/referral from which you accessed the page
- Browser used
- Operating system used
- IP address used (if applicable, in anonymized form)
The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in improving the stability and functionality of our website. There is no further disclosure or other use of the data. However, we reserve the right to retrospectively check the server log files if there are concrete indications of illegal use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser's address bar.
3) Cookies
In order to make your visit to our website attractive and to enable the use of certain functions, we use cookies, which are small text files that are stored on your device. Some of these cookies are automatically deleted after you close your browser (so-called "session cookies"), while others remain on your device for a longer period of time and enable the storage of page settings (so-called "persistent cookies"). In the latter case, you can find the storage duration in the overview of your web browser's cookie settings.
If individual cookies used by us also process personal data, the processing is carried out in accordance with Art. 6 para. 1 lit. b GDPR either for the performance of a contract, pursuant to Art. 6 para. 1 lit. a GDPR in the case of your consent, or pursuant to Art. 6 para. 1 lit. f GDPR to safeguard our legitimate interests in the best possible functionality of the website as well as a user-friendly and effective design of your visit.
You can configure your browser settings to notify you when cookies are set and to allow you to accept them individually, reject them for specific cases, or reject them altogether.
Please note that if you do not accept cookies, the functionality of our website may be limited.
4) Contact
4.1 Self-assessment reminder
Exclusively based on your explicit consent pursuant to Art. 6 para. 1 lit. a GDPR, we use your email address to send you a one-time reminder to submit a review of your order. You can revoke your consent at any time by sending a message to the data controller.
4.2 In the context of contacting us (e.g., via contact form or email), personal data is processed exclusively for the purpose of processing and responding to your inquiry, and only to the extent necessary for this purpose.
The legal basis for processing this data is our legitimate interest in responding to your inquiry pursuant to Art. 6 para. 1 lit. f GDPR. If your contact is aimed at concluding a contract, an additional legal basis for processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted when it can be inferred from the circumstances that the matter concerned has been finally clarified and provided that no legal retention obligations contradict this.
5) Data Processing When Opening a Customer Account
In accordance with Art. 6 para. 1 lit. b GDPR, personal data is collected and processed to the extent necessary when you provide it to us when opening a customer account. The data required for opening an account can be found in the input mask of the corresponding form on our website.
You can delete your customer account at any time by sending a message to the above address of the controller. After deletion of your customer account, your data will be deleted provided that all contracts concluded through it have been fully processed, there are no legal retention periods, and there is no legitimate interest on our part in retaining the data.
6) Data Processing for Order Processing
6.1 To the extent necessary for contract processing for delivery and payment purposes, the personal data collected by us will be transferred to the commissioned shipping company and the commissioned bank in accordance with Art. 6 para. 1 lit. b GDPR.
If we owe you updates for goods with digital elements or for digital products based on a corresponding contract, we process the contact data (name, address, email address) you provided when ordering to inform you personally via a suitable communication channel (such as postal mail or email) about upcoming updates within the legally prescribed period, as part of our legal obligations under Art. 6 para. 1 lit. c GDPR. Your contact details will be strictly used for notifications about updates owed by us and will only be processed by us to the extent necessary for the respective notification.
To process your order, we also collaborate with the following service provider(s) who support us wholly or partially in executing concluded contracts. Certain personal data will be transmitted to these service providers according to the following information.
6.2 Use of Payment Service Providers
- Paypal
This website offers one or more online payment methods provided by the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg
When selecting a payment method from the provider where you pay in advance, your payment data provided during the ordering process (including name, address, bank and credit card information, currency, and transaction number) as well as information about the content of your order will be transferred to the provider in accordance with Art. 6 para. 1 lit. b GDPR. In this case, your data will be disclosed exclusively for the purpose of payment processing with the provider and only to the extent necessary for this purpose.
When selecting a payment method where we pay in advance, you will also be asked for certain personal data (first and last name, street, house number, postal code, city, date of birth, email address, telephone number, if applicable, data regarding an alternative payment method) during the ordering process.
To safeguard our legitimate interest in determining your creditworthiness in such cases, we will transfer this data to the provider in accordance with Art. 6 para. 1 lit. f GDPR for the purpose of a credit check. Based on the personal data you provided, as well as additional data (such as shopping cart, invoice amount, order history, payment experiences), the provider will assess whether the payment method selected by you can be granted in terms of payment and/or default risks.
The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of the score values.
You can object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may still be entitled to process your personal data if this is necessary for the contractual payment processing.
- Paypal Checkout
This website uses PayPal Checkout, an online payment system from PayPal, which consists of PayPal's own payment methods and local payment methods from third-party providers.
When paying via PayPal, credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal, we will transfer your payment data to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg ("PayPal") as part of the payment processing. The transfer is made in accordance with Art. 6 para. 1 lit. b GDPR and only to the extent necessary for payment processing.
For the payment methods credit card via PayPal, direct debit via PayPal, or – if offered – "Pay Later" via PayPal, PayPal reserves the right to carry out a credit check. For this purpose, your payment data may be disclosed to credit agencies in accordance with Art. 6 para. 1 lit. f GDPR, based on PayPal's legitimate interest in determining your creditworthiness. PayPal uses the result of the credit check regarding the statistical probability of payment default for the purpose of deciding on the provision of the respective payment method. The credit report may contain probability values (so-called score values). If score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data, among other things, is included in the calculation of the score values. You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for contractual payment processing.
When selecting the PayPal payment method "Purchase on Account," your payment data will be initially transferred to PayPal for the purpose of payment processing, after which PayPal will forward it to Ratepay GmbH, Franklinstraße 28-29, 10587 Berlin ("Ratepay"). The legal basis is Art. 6 para. 1 lit. b GDPR in each case. In this case, RatePay conducts an identity and credit check independently for the purpose of determining your creditworthiness, according to the principle already mentioned above, and discloses your payment data to credit agencies based on the legitimate interest in determining creditworthiness pursuant to Art. 6 para. 1 lit. f GDPR. A list of the credit agencies that Ratepay can access can be found here: https://www.ratepay.com/legal-payment-creditagencies/
When using a local third-party payment method, your payment data will initially be transferred to PayPal for payment preparation in accordance with Art. 6 para. 1 lit. b GDPR. Depending on your selection of an
available local payment method, PayPal will then transfer your payment data to the respective provider for payment processing in accordance with Art. 6 para. 1 lit. b GDPR:
- Sofort (SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany)
- iDeal (Currence Holding BV, Beethovenstraat 300 Amsterdam, Netherlands)
- giropay (Paydirekt GmbH, Stephanstr. 14-16, 60313 Frankfurt am Main, Germany)
- bancontact (Bancontact Payconiq Company, Rue d'Arlon 82, 1040 Brussels, Belgium)
- blik (Polski Standard Płatności sp. z o.o., ul. Czerniakowska 87A, 00-718 Warsaw, Poland)
- eps (PSA Payment Services Austria GmbH, Handelskai 92, Gate 2, 1200 Vienna, Austria)
- MyBank (PRETA S.A.S, 40 Rue de Courcelles, F-75008 Paris, France)
- Przelewy24 (PayPro SA, Kanclerska 15A, 60-326 Poznań, Poland)
For further data protection information, please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
7) Web Analytics Services
Google Analytics 4
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland ("Google"), which enables an analysis of your use of our website.
By default, when visiting the website, Google Analytics 4 sets cookies, which are small text files stored on your device and collect certain information. This information includes your IP address, which, however, is truncated by Google to exclude direct personal reference.
The information is transmitted to Google servers and processed there. Data transfers to Google LLC in the USA are also possible.
Google uses the collected information on our behalf to evaluate your use of the website, compile reports on website activities for us, and provide other services related to website usage and internet usage. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data. The data collected during the use of Google Analytics 4 is stored for a period of two months and then deleted.
All processing described above, especially the setting of cookies on the device used, only takes place if you have given us your express consent in accordance with Art. 6 para. 1 lit. a GDPR.
Without your consent, the use of Google Analytics 4 will not occur during your visit to the website. You can revoke your consent at any time with effect for the future. To exercise your right of revocation, please disable this service via the "Cookie Consent Tool" provided on the website.
We have concluded a data processing agreement with Google that ensures the protection of data of our website visitors and prohibits unauthorized disclosure to third parties.
Further legal information about Google Analytics 4 can be found at https://policies.google.com/privacy?hl=en&gl=en and https://policies.google.com/technologies/partner-sites
Demographic Features
Google Analytics 4 uses the special feature "demographic characteristics" and can thus create statistics that provide information about the age, gender, and interests of website visitors. This is done by analyzing advertising and information from third parties. This enables the identification of target groups for marketing activities. However, the collected data cannot be assigned to a specific person and will be deleted after storage for a period of two months.
Google Signals
In addition to Google Analytics 4, this website may use Google Signals to create cross-device reports. If you have enabled personalized ads and linked your devices to your Google account, Google, subject to your consent to use Google Analytics in accordance with Art. 6 para. 1 lit. a GDPR, may analyze your cross-device usage behavior and create database models, including cross-device conversions. We do not receive any personal data from Google, only statistics. If you want to stop cross-device analysis, you can disable the "Personalized Ads" feature in your Google account settings. Follow the instructions on this page: https://support.google.com/ads/answer/2662922?hl=en For more information on Google Signals, visit the following link: https://support.google.com/analytics/answer/7532985?hl=en
UserIDs
In addition to Google Analytics 4, this website may use the "UserIDs" feature. If you have consented to the use of Google Analytics 4 in accordance with Art. 6 para. 1 lit. a GDPR, have set up an account on this website, and log in with this account on different devices, your activities, including conversions, can be analyzed across devices.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision of the European Commission.
8) Page Functionalities
8.1 Instagram Plugins
Plugins of the social network provided by the following provider are used on our website: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
These plugins enable direct interactions with content on the social network.
To increase the protection of your data when visiting our website, the plugins are initially deactivated using a so-called "2-click" or "Shariff" solution integrated into the page.
This integration ensures that when a page of our website containing such plugins is called up, no connection is initially established with the provider's servers.
Only when you activate the plugins and thereby give your consent to data transmission in accordance with Art. 6 para. 1 lit. a GDPR, does your browser establish a direct connection to the provider's servers. Here, regardless of whether you are logged into an existing user profile, certain information about your device (including your IP address), your browser, and your page history is transmitted to the provider and may be further processed there.
If you are logged into an existing user profile on the provider's social network, information about interactions performed via the plugins may also be published there and displayed to your contacts.
You can revoke your consent at any time by deactivating the activated plugin by clicking on it again. However, the revocation does not affect the data that has already been transferred to the provider.
Data may also be transferred to: Meta Platforms Inc., USA.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision of the European Commission.
8.2 Vimeo
This website uses plugins for displaying and playing videos provided by the following provider: Vimeo, LLC, 555 West 18th Street, New York, New York 10011, USA.
When you access a page of our website that contains such a plugin, your browser establishes a direct connection to the provider's servers to load the plugin. Certain information, including your IP address, is transmitted to the provider in this process.
If playback of embedded videos is started via the plugin, the provider also uses cookies to collect information about user behavior, create playback statistics, and prevent abusive behavior.
If you are logged into a user account with the provider during your visit to the site, your data will be directly associated with your account when you click on a video. If you do not wish this association with your account, you must log out before pressing the playback button.
All the aforementioned processing, especially the setting of cookies to read information on the device used, only occurs if you have given us your express consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke the consent granted at any time with effect for the future by deactivating this service via the "Cookie Consent Tool" provided on the website.
For data transfers to the USA, the provider relies on standard contractual clauses of the European Commission, which are intended to ensure compliance with the European data protection level.
8.3 Google reCAPTCHA
This website uses the CAPTCHA service provided by the following provider: Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland.
Data may also be transmitted to: Google LLC, USA. For the visual design of the CAPTCHA window, the provider uses "Google Fonts," i.e., fonts loaded from the internet by Google. However, no further processing of information beyond that transferred to Google by the functionality of reCAPTCHA occurs in this context.
The service checks whether an input is made by a natural person or is abusive through automated and machine processing and blocks spam, DDoS attacks, and similar automated malicious accesses. To ensure that an action is performed by a human and not by an automated bot, the provider collects the IP address of the device used, recognition data of the browser and operating system type, as well as the date and duration of the visit and transmits this for evaluation to the provider's servers.
The legal basis is our legitimate interest in determining individual responsibility on the internet and preventing abuse and spam in accordance with Art. 6 para. 1 lit. f GDPR.
We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.
For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European data protection level based on an adequacy decision of the European Commission.
**9) Rights of the Data Subject**
**9.1** The applicable data protection law grants you the following rights (information and intervention rights) with regard to the processing of your personal data by the controller, whereby reference is made to the specified legal basis for the respective conditions for exercising these rights:
- Right to information according to Art. 15 GDPR;
- Right to rectification according to Art. 16 GDPR;
- Right to erasure according to Art. 17 GDPR;
- Right to restriction of processing according to Art. 18 GDPR;
- Right to notification according to Art. 19 GDPR;
- Right to data portability according to Art. 20 GDPR;
- Right to withdraw consent granted according to Art. 7 para. 3 GDPR;
- Right to lodge a complaint according to Art. 77 GDPR.
**9.2 RIGHT TO OBJECT**
IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTERESTS IN THE CONTEXT OF A BALANCING OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, WITH EFFECT FOR THE FUTURE.
IF YOU MAKE USE OF YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA. HOWEVER, FURTHER PROCESSING IS RESERVED IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR IF PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING. YOU CAN EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE AFFECTED DATA FOR DIRECT MARKETING PURPOSES.
**10) Duration of Storage of Personal Data**
The duration of storage of personal data is based on the respective legal basis, the purpose of processing, and, if applicable, additionally on the respective statutory retention period (e.g., commercial and tax retention periods).
If personal data is processed based on explicit consent according to Art. 6 para. 1 lit. a GDPR, the data concerned will be stored until you revoke your consent.
If there are legal retention periods for data processed within the framework of contractual or quasi-contractual obligations based on Art. 6 para. 1 lit. b GDPR, these data will be routinely deleted after the retention periods have expired, provided they are no longer required for contract fulfillment or initiation and/or there is no longer any legitimate interest on our part in continued storage.
If personal data is processed based on Art. 6 para. 1 lit. f GDPR, these data will be stored until you exercise your right to object under Art. 21 para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
If personal data is processed for direct marketing purposes based on Art. 6 para. 1 lit. f GDPR, these data will be stored until you exercise your right to object under Art. 21 para. 2 GDPR.
Unless otherwise stated in the other information in this statement about specific processing situations, stored personal data will otherwise be deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed.