Data protection

We appreciate your interest in our online shop. The protection of your privacy is very important to us. Below we inform you in detail about the handling of your data.

For data controllers in the sense of the General Data Protection Regulation (DSGVO) and other data protection provisions is the

Smart Sleep GmbH
Alte Gießerei 2
40699 Erkrath
Phone: + 49 (0) 211 590 7440

1. Provision of website, access data and hosting

1.1 Automated storage of data in log files
You can visit our websites without giving any personal information. Each time a web page is called up, the web server merely automatically stores a so-called server log file containing the name of the requested file, your IP address, the date and time of the retrieval, the amount of data transferred and the requesting provider (access data) and documents the retrieval.

These access data are evaluated exclusively for the purpose of ensuring a trouble-free operation of the site as well as the improvement of our offer. In accordance with Art. 6 para. 1 sentence 1 lit. F DSGVO the preservation of our legitimate interests, which predominate in the context of a weighing up of interests, in a correct presentation of our offer. All access data will be deleted no later than seven days after the end of your page visit.

1.2 Hosting services by a third party
Within the framework of a processing on our behalf, a third party provider provides the services for hosting and displaying the website. This serves to safeguard our legitimate interests, which are predominantly justified in the interests of weighing up our interests, in order to correctly present our offer. All data collected as part of the use of this website or in designated forms in the online shop as described below will be processed on its servers. Processing on other servers takes place only in the frame explained here.This service provider is located within a country of the European Union or the European Economic Area.

2. Data collection and use for contract processing and opening a customer account

We collect personal information when you voluntarily provide it to us as part of your order, when contacting us (e.g., by e-mail) or when opening a customer account. Obligatory fields are marked as such, since in these cases we need the data for contract execution, or to process your contact or opening the customer account and you can not complete the order and / or opening the account without their information, or can not send the contact , Which data are collected, can be seen from the respective input forms. These are in particular your name, your e-mail address, with orders and / or the registration for a customer account your postal address, further contact data, Details on order (s) and payment options. If you create a customer account, we also save your access data.

We use the data communicated by you in accordance with Art. 6 para. 1 sentence 1 lit. b DSGVO for contract handling and processing of your inquiries.

After completion of the contract or deletion of your customer account, your data will be restricted for further processing and deleted after expiry of the tax and commercial retention periods, unless you have expressly consented to a further use of your data or we reserve the right to further data use, the is legally permitted and about which we inform you in this statement. The deletion of your customer account is possible at any time and can be done either by a message to the contact option described below or via a designated function in the customer account.

3. Data transfer

For fulfillment of the contract pursuant to Art. 6 para. 1 sentence 1 lit. b DSGVO we pass on your data to the shipping company responsible for the delivery, as far as this is necessary for the delivery of ordered goods. Depending on which payment service provider you select in the order process, we will forward the payment data collected to the credit institution commissioned with the payment and any payment service providers commissioned by us to process the payments or to the selected payment service. In part, the selected payment service providers also collect this data themselves, provided that you create an account there. In this case, you will be redirected to the appropriate website of the payment service provider and must log in to the payment service provider in the ordering process with your access data. In this respect, the privacy policy of the respective payment service provider applies.We use payment service providers and shipping service providers based in a state outside the European Union. The transfer of personal data to these companies takes place only in the context of the need to fulfill the contract.

4. Postal advertising

Postal advertising and your right to objectIn addition, we reserve the right to use your first and last name as well as your postal address for our own advertising purposes, e.g. to send interesting offers and information about our products by letter. This serves to safeguard our legitimate interests, which are predominantly justified in the context of a weighing up of interests, in a promotional approach by our customers in accordance with Art. 6 para. 1 sentence 1 lit. f DSGVO. You have the right to object to the processing of your data for promotional purposes at any time without giving reasons. Please direct your objection to the above address or by e-mail to Your data will be stored for the purpose of postal advertising until your opposition. Please note that even after an objection within a period of implementation of about one week, it may happen that we address you in advertising.

5. Credit check

If we are in advance, e.g. When purchasing on account, we ask our service provider for the account management to secure our purchase price claims a credit rating at the specialized service companies (credit reference agencies). Our service provider for invoice management is the heidelpay GmbH, Vangerowstrasse 18, 69115 Heidelberg. Heidelpay GmbH transmits the name and address of order customers to credit reference agencies, e.g. Schufa Holding AG, Bürgel Wirtschaftsinformationen GmbH & Co. KG, Arvato Infoscore GmbH, Deltavista GmbH, Universum Group, Regis 24 GmbH and Creditreform AG and the reporting agency (s) to report whether negative features are present , This message will be sent to us and stored at heidelpay GmbH; there is no automated decision-making or profiling. Appropriate measures to safeguard your rights, freedoms and legitimate interests will be taken into account. You have the opportunity to express your point of view and to challenge the decision by making contact with the contact options described below. After completion of the contract, your data processed for this purpose will be deleted, unless you have expressly consented to further use of your data or we reserve the right to further data usage, which is permitted by law and which we inform you in this statement. 6. Cookies and web analyticsIn order to make the visit to our website attractive and to allow the use of certain functions, to display suitable products or to analyze the use of our website, we use so-called cookies on various pages. In the case of the use of cookies, which are technically necessary for the functionality of the website, this serves to safeguard our legitimate interests, which predominate in the context of weighing interests, in an optimized presentation of our offer in accordance with Art. 6 (1) sentence 1 lit. f DSGVO. For the use of cookies for web analysis, we obtain your consent. This is the legal basis for the use of cookies, Art. 6 para. 1 sentence 1 lit. a GDPR. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the end of the browser session, ie after closing your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser on your next visit (persistent cookies). The duration of the storage can be found in the overview in the cookie settings of your web browser. You can set your browser so that you are informed about the setting of cookies and individually decide on their acceptance or exclude the acceptance of cookies for specific cases or in general. Each browser differs in the way it manages the cookie settings. This is described in the Help menu of each browser, which explains how to change your cookie settings.

These can be found for the respective browser under the following links:

Internet Explorer ™: 
Safari ™: 
Chrome ™: 
Firefox ™ 
Opera ™: 

Failure to accept cookies may limit the functionality of our website.

6.1 Use of Google (Universal) Analytics for web analytics

For website analysis, this website uses Google (Universal) Analytics, a web analytics service provided by Google LLC ( Google (Universal) Analytics uses methods that allow you to analyze the use of the website, such as cookies. It is possible to assign data, sessions and interactions across multiple devices to a pseudonymous user ID and analyze the activities of a user across devices. The automatically collected information about your use of this website is usually transmitted to a Google server in the USA and stored there. By activating IP anonymisation on this website, the IP address will be shortened prior to transmission within the member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. Google will use this information to evaluate your use of our site, to compile reports on our website activity, and to provide other services related to website activity and internet usage. Google may also transfer this information to third parties if required by law or as far as third parties process this data on behalf of Google. Google does not claim to link your IP address to any other data provided by Google.

The data sent by us and linked to cookies, user IDs (eg user IDs) or advertising IDs will be automatically deleted after 14 months with Google. The deletion of data whose retention period has been reached is done automatically once a month.

Google LLC is headquartered in the US and is certified under the EU-US Privacy Shield. A current certificate can be viewed here. Under the agreement between the US and the European Commission, the latter has established an appropriate level of data protection for companies certified under the Privacy Shield.

You can prevent the collection of the data (including your IP address) generated by the cookie and related to your use of the website from Google as well as the processing of this data by Google by downloading and installing the browser plug-in available under the following link :  .

As an alternative to the browser plug-in, you can click on this link to prevent the collection by Google Analytics on this website in the future. An opt-out cookie is stored on your device. If you delete your cookies, you must click the link again.

7. Our Facebook page

When you use our Facebook page, Facebook collects, processes and uses personal information, whether you are a Facebook member or not for profiling. Furthermore, Facebook provides us with evaluations on the use of our Facebook pages in an anonymous form. This includes in particular the following evaluations:

  • Overview of the page likes: The total and new likes for The Facebook Page; Entry Range: The total number of individuals who have seen the Facebook page and the posts it contains; Interaction: The total number of individuals who interacted with the Facebook page, broken down by type of interaction. Likes page likes: The total Likes for each day, for a period of 28 days; "Like" (Net) ": The number of new" Like "details after subtracting the removed" Like "information; the place where the likes of the Facebook page were made: Here's how many times the Facebook page was marked as "Like", broken down by the origin of the "Like" ad.

  • Reach: Contribution Reach: The number of persons for whom a contribution was provided, broken down into paid and organic coverage; Likes, comments, and shared content; Hidden posts, reported as spam, "I do not like it anymore": The negative interactions that reduce the number of people reached; Total Reach: The number of people who saw an action from the Facebook page.

  • Visits: Page and tab views: Indicates how often each tab of a Facebook page was displayed; External References: The number of times people moved from a website outside of Facebook to the Facebook page.

  • Posts: When fans of the Facebook page are online: Shows when the people who like the Facebook page are on Facebook; Contribution Types: Displays the success of each type of contribution based on average reach and interaction; Most popular posts from pages we keep track of: Shows the interactions to posts from the pages we're watching.

  • Video: Video views: how many times the videos were viewed on the Facebook page for more than 3 seconds; 30-second Views: How many times the videos were viewed on the Facebook page for more than 30 seconds. If your video is shorter than 30 seconds, the people who viewed the video at 97% are counted; Top videos: The most viewed videos for at least 3 seconds on the Facebook page.

  • People: fans of the Facebook page: displays information about the people who like the Facebook page: gender, age, place of residence and language; People reached: Displays the people for whom a post has been shown in the last 28 days; Interacting Persons: Shows the people (anonymized) in the last 28 days who have tagged, commented or shared posts on their posts or made interactions on the Facebook page. For more information, see .

For information about what Facebook collects from you, see the data policy (at ) of Facebook, particularly in the section "What types of information do we collect?". When using the Facebook pages Facebook stores cookies on your device (notebook, PC, tablet, smartphone). Please refer to the Cookie Policy of Facebook (

8. Contact and your rights

As a victim, you have the following rights:

  • pursuant to Art. 15 DSGVO, the right to request information about your personal data processed by us in the scope specified therein;
  • in accordance with Art. 16 GDPR, the right to demand immediate correction of incorrect or complete personal data stored with us;
  • according to Art. 17 DSGVO the right to demand the deletion of your personal data stored by us, unless the further processing
    • to exercise the right to freedom of expression and information;
    • to fulfill a legal obligation;
    • for reasons of public interest or
    • to assert, exercise or defend legal claims is required;
  • according to Art. 18 GDPR the right to demand the restriction of the processing of your personal data, as far as
    • the accuracy of the data is disputed by you;
    • the processing is unlawful, but you reject its deletion;
    • we no longer need the data, but you need it for asserting, exercising or defending legal claims or
    • you filed an objection against the processing in accordance with Art. 21 GDPR;
  • according to Art. 20 DSGVO, the right to receive your personal data provided to us in a structured, common and machine-readable format or to request transmission to another person responsible;
  • according to Art. 77 GDPR, the right to complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or work or our company headquarters.

Right of withdrawal

You may withdraw your consent to certain data processing at any time without giving reasons. The revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent until the revocation.

Contradiction right
Insofar as we process personal data as described above in order to safeguard our legitimate interests, you may object to this processing in accordance with Art. 21 GDPR with effect for the future. If the processing is for the purpose of direct marketing, you can exercise this right at any time as described above. Insofar as the processing takes place for other purposes, you are only entitled to a right of objection if there are reasons that arise from your particular situation.

After exercising your right to object, we will not further process your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for processing that outweigh your interests, rights and freedoms, or if the processing of the assertion, exercise or defense of Legal claims serves.

This does not apply if the processing is for direct marketing purposes. Then we will not process your personal data for this purpose.

For questions about the collection, processing or use of your personal data, information, correction, blocking or deletion of data and revocation of granted consent or objection to a particular use of data, please contact us directly via the contact details in our imprint.

9. Data security

We use the widely used Secure Socket Layer (SSL) method in conjunction with the highest level of encryption supported by your browser. In general, this is a 256-bit encryption. If Browser does not support this encryption, we'll use 128-bit v3 technology instead. Whether a single page of our website is encrypted is indicated by the closed representation of the key or lock symbol in the lower status bar or the address bar of your browser.

We also take appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or total loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

10. Change of privacy policy

We reserve the right to change this Privacy Policy from time to time to always comply with the current legal requirements or to implement changes to our services in the Privacy Policy, e.g. when introducing new services. For your renewed visit to our website, the current privacy policy applies.

As of September 2018