Privacy Policy for Mignuti Kids

This comprehensive Privacy Policy explains how Mignuti Kids handles personal data when you visit our website, translated and adapted from the provided German document for full compliance with GDPR and related laws. It details data collection, processing purposes, legal bases, user rights, and third-party tools used on the site.

Privacy Protection at a Glance

The following provides a simple overview of what happens to your personal data when you visit this website. Personal data are all data that can be used to identify you personally. Detailed information on data protection can be found in this Privacy Policy below.

Data collection on this website: Data processing occurs through the website operator, Eduard Ditler, Splitska 13, 22202 Primosten, email: kids@mignuti.com. Your data is collected either when you provide it (e.g., via contact forms) or automatically/normally with consent via our IT systems (e.g., browser type, OS, page view time). Data serves to ensure proper website functionality, analyze user behavior, and process contracts/orders if applicable.

You have the right to free information about origin, recipients, and purpose of stored data, plus rights to rectification, erasure, restriction, portability, objection, and consent withdrawal anytime. Contact us or the supervisory authority for complaints. Third-party analysis tools may evaluate browsing behavior—details follow below.

Hosting

We host our website content with an external provider. Personal data collected on this site (e.g., IP addresses, contact queries, meta/communication data, contract data, names, access logs) is stored on the hoster’s servers. External hosting fulfills contracts with customers (Art. 6(1)(b) GDPR) and ensures secure, fast provision of our online offer (Art. 6(1)(f) GDPR). Where consent is obtained, processing relies on Art. 6(1)(a) GDPR and §25(1) TDDDG (e.g., for cookies/device fingerprinting); consent is revocable anytime.

Our hoster processes data only as necessary for its duties and follows our instructions. Current hoster: Hostinger International Limited, 61 Lordou Vironos Street, 17. Lumiel Building, 4th floor, 18. Larnaca, CY 6023, Zypern.

General Notes and Mandatory Information

Operators of this site take data protection seriously, processing personal data confidentially per legal requirements and this Policy. Various personal data are collected during use. This Policy explains what data, for what purpose, and how. Note: Internet transmission (e.g., email) has security gaps; complete protection from third-party access is impossible.

Responsible entity: Eduard Ditler, Splitska 13, 22202 Primosten (controller decides on purposes/means of processing).

Storage duration: Unless specified otherwise, data is kept until processing purpose ends. Upon deletion request or consent withdrawal, data is erased unless legal retention (e.g., tax/commercial) applies.

Legal bases: Consent: Art. 6(1)(a)/(9(2)(a)) GDPR; third-country transfer with explicit consent: Art. 49(1)(a); cookies/device access with consent: §25(1) TDDDG (revocable). Contract fulfillment: Art. 6(1)(b); legal obligation: Art. 6(1)(c); legitimate interest: Art. 6(1)(f).

Recipients: Data shared only for contract fulfillment, legal duty (e.g., tax authorities), legitimate interest, or other basis. Processors bound by data processing agreements; joint controllers by joint processing agreements.

Consent withdrawal: Revocable anytime; prior processing remains lawful.

Right of objection (Art. 21 GDPR): If based on Art. 6(1)(e)/(f), object anytime for situation-specific reasons (incl. profiling); we cease unless compelling reasons override or for claims. For direct marketing: unconditional objection right.

Complaint right: To supervisory authority in your residence/workplace/ alleged violation state.

Data portability: Receive/exercise automated data (consent/contract basis) in machine-readable format; direct transfer if technically feasible.

Access, rectification, erasure: Free right per law.

Restriction: If accuracy contested (during check), unlawful (instead of erasure), no longer needed but required for claims, or during objection balancing.

SSL/TLS encryption: Used for confidential transmissions (recognizable by https:// and lock icon).

No unsolicited ads: Opposition to using published contacts for unrequested ads; legal action reserved against spam.

Data Collection on This Website

Cookies: Small packets enabling functions; session (temporary) or permanent. First/third-party. Necessary (e.g., cart, videos): Art. 6(1)(f) GDPR (legitimate interest). Others (analysis/ad): consent Art. 6(1)(a)/§25(1) TDDDG (revocable). Manage via browser (may limit functionality).

Email/phone/fax inquiries: Stored/processed for handling (Art. 6(1)(b)/(f) or consent); kept until resolved or legal retention; not shared without consent.

Comments (if applicable): Store comment, timestamp, email, username; subscription verification/deletion. Kept until content deletion/legal need; consent-based (revocable).

Social Media

Facebook: Meta Platforms Ireland Ltd.; data to US/third countries. Connection on activation; links visits to account if logged in. Consent-based (Art. 6(1)(a)/§25(1) TDDDG). Joint responsibility limited to collection/transfer; see agreement. Transfers: EU standard clauses/EU-US DPF. Privacy: facebook.com/privacy.

X (Twitter): X Corp./Twitter International Unlimited (Ireland); similar connection/linking. Consent-based; EU standard clauses/DPF. Privacy: x.com/privacy.

Instagram: Meta Platforms Ireland Ltd.; same as Facebook. Consent; joint responsibility; EU standard clauses/DPF. Privacy: privacycenter.instagram.com/policy.

Pinterest: Pinterest Europe Ltd. (Ireland); logs IP/browser/etc. to US. Consent; DPF. Privacy: policy.pinterest.com/privacy-policy.

Newsletter

Requires email + verification; used solely for dispatch (consent Art. 6(1)(a) GDPR, revocable via link). Stored until unsubscribe; possible blacklist (legitimate interest Art. 6(1)(f)).

Plugins and Tools

YouTube: Google Ireland Ltd.; connects on load, cookies/fingerprinting for stats/usability/fraud. Legitimate interest Art. 6(1)(f) or consent; DPF. Privacy: policies.google.com/privacy.

Google Fonts: Loads fonts via Google servers (IP logged). Legitimate interest Art. 6(1)(f) or consent; DPF. More: developers.google.com/fonts/faq.