Privacy Policy

Privacy Policy for norbertmichel.com

1. Introduction

At norbertmichel.com, we value your privacy and are committed to safeguarding the personal data you entrust to us. This Privacy Policy outlines how your personal information is collected, used, shared, and protected when you interact with our website. Our practices are designed to ensure transparency, accountability, and full compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws. We believe in privacy by design and work to uphold the highest standards of data security and user trust.

2. Scope of Policy and Data Controller Role

This Privacy Policy applies to all visitors, users, and others who access norbertmichel.com. The controller of personal data collected through this website is Norbert Michel, reachable at [email protected]. As the data controller, we are responsible for determining the purposes and means of processing the personal data we collect.

3. Categories of Data Processed

We may collect and process the following types of personal data, depending on how you interact with our website:

a. Usage Data
Includes details about your browser type, Internet Protocol (IP) address, referral URLs, pages visited, time and date of visit, session duration, and interaction patterns with the site.

b. Account Data
When you create an account or communicate with us, we may collect your full name, mailing and billing address, email address, and telephone number.

c. Profile Data
We may collect details about your preferences, interests, previous purchases, product behaviors, and how you interact with site content.

d. Communication Data
Includes records of support inquiries, email correspondence, contact form submissions, and other interactions with our customer service.

e. Technical Data
Information regarding your device type, hardware model, operating system, platform, language preferences, browser plugins, screen resolution, and system settings.

f. Transaction Data
If you make purchases through norbertmichel.com, we may collect order history, payment method (payment data is tokenized or processed by third-party providers), transaction identifiers, and shipping information.

g. Preference Data
Data that reflects your choices, including marketing opt-ins/opt-outs, communication preferences, and your expressed interests in certain products or features.

4. Legal Bases for Processing

We process your personal data using the following lawful bases, as applicable under GDPR and similar regulations:

– Performance of Contract: To fulfill obligations arising from agreements with you (such as processing orders or managing your account).
– Consent: When you have provided clear and unambiguous consent for a specific purpose, such as subscribing to newsletters.
– Legitimate Interests: When processing is necessary for our reasonable business interests, such as improving website functionality and marketing, while balancing your rights and freedoms.
– Legal Obligation: When processing is required to comply with legal obligations or respond to lawful governmental requests.

5. Your Rights

Under applicable law, you have the following rights in relation to your personal data:

– Right of Access: Request confirmation about whether we process your data and access a copy.
– Right to Rectification: Correct inaccurate or incomplete personal data.
– Right to Erasure: Request deletion of your data where legally permissible.
– Right to Restriction: Ask us to limit processing under defined conditions.
– Right to Data Portability: Receive personal data in a structured, commonly used format and transfer it to another controller.
– Right to Object: Object to processing when based on legitimate interests or direct marketing.
– Right to Withdraw Consent: At any point, if processing is based on your consent.

California residents may also invoke their specific rights under the CCPA, including:

– Right to Know: What personal data we collect, use, and disclose.
– Right to Delete: Request deletion of personal data.
– Right to Opt Out: Of the sale or sharing of personal data.
– Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Requests can be made by contacting us at [email protected].

6. Security Measures

We implement and maintain robust security measures to protect your personal data. These include, but are not limited to:

– Encryption of data in transit and at rest.
– Multi-level access controls and role-based authentication.
– Regular audits and platform vulnerability assessments.
– Secure server environments and backup systems.
– Staff training and confidentiality agreements to ensure data awareness and compliance.

Despite our efforts, no transmission of data over the internet can ever be guaranteed as 100% secure. We encourage users to remain vigilant and protect their account credentials.

7. International Transfers

We may store, process, and transfer your personal data to jurisdictions outside your country, including to the United States and other countries where our service providers operate. Where we do so, international data transfers are conducted in accordance with applicable law and protected by appropriate safeguards, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission and other regional mechanisms.

8. Data Retention

We retain your personal data for only as long as is necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting obligations. Specific retention periods include:

– Usage and Technical Data: 13 months for analytics purposes.
– Account and Profile Data: Active retention during account life and up to 6 years post-deactivation.
– Communication Data: Up to 2 years after final communication.
– Transaction Data: 6 years to comply with accounting and tax regulations.
– Marketing and Preference Data: Up to 2 years from last interaction or until you withdraw your consent.

9. Cookie Policy

We use cookies and similar technologies on norbertmichel.com to enhance functionality, analyze performance, and personalize content. Our cookies fall into the following categories:

– Essential Cookies: Required for the site to function properly (e.g., user authentication, navigation).
– Functional Cookies: Remember user choices and settings to improve user experience.
– Analytics Cookies: Collect aggregated data on site usage, page performance, and user engagement.
– Performance Cookies: Measure the effectiveness of marketing campaigns and A/B tests.

Cookies may be first-party (set by norbertmichel.com) or third-party (set by external services such as analytics providers).

10. Cookie Management and Compliance

We offer users the ability to manage their cookie preferences via in-site banners and settings. You may also control or delete cookies using your browser configurations. Acceptance of non-essential cookies is based on user consent, in line with GDPR requirements. California residents may exercise their right to opt out of cookie-related data sales or sharing as defined under CCPA by using our “Do Not Sell or Share My Info” link or by contacting [email protected].

11. Children’s Privacy

This website is not intended for children under the age of 13, and we do not knowingly collect personal data from children. If we become aware that a user under 13 has submitted personal information, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us immediately at [email protected].

12. Changes to This Privacy Policy

We reserve the right to revise this Privacy Policy to reflect changes in legal, regulatory, or operational practices. We recommend you review this page periodically to stay informed of updates. Where legally required, we will notify users of changes through appropriate channels.

13. Contact Us

If you have any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact us at:

Email: [email protected]
Website: https://norbertmichel.com

We are committed to maintaining compliance with applicable data protection laws and welcome your questions to help ensure transparency and user control over personal information.