Your basket

It’s empty in here!

bitiba uses Cookies to ensure the proper functioning of our website, to personalise content and advertising and to analyse our data traffic. We also inform our advertising and analysis partners about your use of our website. By using this website, you agree to the use of cookies. Accept Cookies

The bitiba app

Use app
Free delivery from £45 (T&C’s apply)**

Privacy Statement

Dear bitiba customers and visitors to our website,

We value your trust, so protecting your data and respecting your right to privacy and informational autonomy in the collection, processing and use of your personal data is very important to us. The following information explains which data we collect and process about you in connection with your use of our website. A short overview can be found in our Privacy One-Pager.

bitiba GmbH, Herzog-Wilhelm-Strasse 12, D-80331 Munich, represented by the members of the Management Board Dr Cornelius Patt, Andreas Maueröder and Dr. Mischa Ritter, is responsible for the data protection on this website. You can contact us by phone 0044 1865 951302 or by email at service@bitiba.co.uk. You can also get in touch with our Data Protection Officer Mr Philipp Herrmann, HWData GmbH, Leonrodstrasse 54, D-80636 Munich, email: ph@hwdata.de.

1. Subject of this Privacy Statement

The subject of this Privacy Statement is the information explaining which personal data are collected on the bitiba web pages and the purpose for which they are processed. To the extent that we link to other pages, we have neither influence nor control over the linked content nor the respective data protection regulations. We recommend that you check the privacy policies on the linked web pages to determine whether and to what extent personal data is collected, processed, used and made accessible to third parties.

2. Definitions and Terms

Below is a selection of some of the legal definitions that will help you to understand the Privacy Statement. The full text of the General Data Protection Regulation (GDPR) along with further definitions and terms can be found here.

Personal data

All information relating to an identified or identifiable natural person ("Affected Person"). A natural person is considered identifiable when this person can be identified directly or indirectly, particularly by means of assignment to an identifier such as a name, an identification number, location data, an Online ID or to one or more specific characteristics that express the physical, physiological, genetic, psychological, economic, cultural or social identity of this natural person.

Processing

Any process or series of processes performed with or without the aid of automated procedures related to personal data, such as collecting, recording, organizing, filing, storing, adapting, modifying, reading, querying, using, disclosing by submitting, distributing or otherwise providing, adjusting, linking, limiting, erasing or destroying.

Responsible party

Refers to the natural or legal person, public authority, agency or other body that alone or jointly with others decides on the purposes and means of the processing of personal data. If the purposes and means of processing are prescribed under EU law or the law of Member States, the responsible party or the specific criteria for the responsible party's appointment may be provided for under EU law or the law of Member States.

Recipient

Refers to a natural or legal person, public authority, agency or other body to whom personal data may be disclosed, regardless of whether it is a third party or not. Authorities that may obtain personal data in the context of a specific investigation under EU law or the law of Member States, however, are not considered recipients. The processing of these data by the authorities named shall be carried out in accordance with the applicable data protection regulations in accordance with the purposes of the processing.

Third party

This is a natural or legal person, public authority, agency or other body, with the exception of the person affected, the responsible party, the order processor and the persons who, under the direct responsibility of the responsible party or the order processor, are authorized to process the personal data.

3. Categories of Personal Data processed on our Website

Area concerned: Visiting the website, Creation of log files

Personal data: IP address, cookie identifier

Description and purpose of the data processing

When you call up the bitiba website, bitiba gathers so-called access data, which includes the IP address, and saves it in a log file. This log file also stores the name of the web page you requested, the retrieved file, the date and time of retrieval, the amount of data transferred, a notification of successful retrieval, the browser type and version, the operating system, the so-called referrer URL (the previously visited page) as well as the requesting provider. You cannot be personally identified, however, based on this data.

Cookies are also stored on your end device (laptop, tablet, smartphone or PC) when you visit our website. For details about the cookies used on the website, their specific purpose and a description of how to delete them, please see the Information on the Right to Object to the Processing of Data.

We gather log file data, including the IP address, to ensure a seamless connection and comfortable usage of our website by the users. The log file is also used to evaluate system security and stability, as well as for administrative purposes. Cookies also help us to make our services and website more user friendly by enabling us to determine, for example, whether you have already visited a page of our website. With the help of the cookie identifier, we also receive information about the behavior of the users on our website and the search queries that take you to our site so that we can adapt our offers to the user's interests for future visits.

Interest in the processing of data

Log file data, including the IP address, serve only to optimize the technology and configuration of our website and our systems' security (e.g., in the context of an IT attack or a security incident). When calling up our website, no personal identification can be derived from the data in the log file, including the IP address. A personal reference is only produced when you log in to your customer account at the same time. In this case, we are able to associate the IP address with you directly. With the help of the cookie identifier we learn, for example, if and to what extent you have already visited our websites, whether you have already registered with us with a specific ID and when you have returned to this ID. For details and information on how to delete cookies, please see the Information on the Right to Object to the Processing of Data.

Recipient and processor of the data

Our website and webshop are hosted by both our own data center as well as an external service provider.

Provider

Purpose of data processing

Details of provider & privacy policy

Amazon Webservices

Inc., 410 Terry Drive Ave North, WA 98109-5210 Seattle, USA

Hosting and backup

The data processing takes place exclusively in the Amazon Web Services data centers located in Europe. 

https://aws.amazon.com/de/data-protection/

https://aws.amazon.com/de/compliance/eu-data-protection/

https://aws.amazon.com/de/compliance/data-center/data-centers/

Privacy Shield

 

Length of data storage: Log files, including the IP address, are automatically deleted two (2) months after their collection. Prior to this, the IP address is anonymized and saved for administrative (technical) purposes only.

Legal basis: Article 6 (1 f) GDPR

Provision of data stipulated or required: The provision of the aforementioned personal data is neither legally nor contractually required. However, without the IP address and cookie identifier, the service and the functionality of our website is not guaranteed and individual applications and services may not be available or restricted.

Area concerned: Visiting the website, Web analytics

Personal data: IP address, cookie identifier

Description and purpose of the data processing

We use so-called tracking and web analytics tools on our website. Described is the collection of access data on our website and the evaluation of the behavior of our visitors for the purpose of optimizing our offers.

These tools can be used to investigate from where the visitors originated, how they accessed our website, which areas of the website are visited more often and how often and for how long which subpages and categories are viewed. We can also determine which search terms and websites the user has entered and evaluate how many users visit our pages altogether and which information or offers are most in demand. The aim is to use the knowledge gained to help structure our offers and our website in a user-friendly manner.

Interest in the processing of data

By statistically analyzing the user profiles, we can deduce information about the operation and the success of our websites such as how often information pages for specific product groups are called up and how many visitors clicked on certain offers. With the help of the tracking tools, we can better target our offers to our customers, visitors and interested parties. Details about the provider and functionality, as well as information on how to delete the cookies used and prevent tracking can be found at Information on the Right to Object to the Processing of Data.

Recipient and processor of the data

The following providers of tracking and web analytics tools process the access data on our behalf for the purpose of user analysis and statistical processing. To do this, we have concluded the corresponding order processing contracts with vendors. For further details about the tools' technical operation, as well as information on how you can prevent the transmission of data (tracking), please see the Information on the Right to Object to the Processing of Data.

For the display of our Trusted Shops quality seal and the collected reviews as well as for the offer of the Trusted Shops products for buyers after an order the Trusted Shops Trustbadge (seal) is integrated on our website. When the trust badge is called, the web server automatically saves a server log file (see above), especially your IP address. These access data will not be evaluated and automatically deleted at the latest seven days after the end of your page visit.

Provider

Tool

Details of the provider & privacy policy

Google Inc.
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Google Analytics

 

//www.google.com/policies/

https://support.google.com/analytics/answer/6004245?hl=de

Privacy Shield

Adobe Systems Software Ireland Limited,
4-6 Riverwalk, Citywest Business Campus, Dublin 24, Republic of Ireland

Omniture (Adobe Analytics)

https://www.adobe.com/de/privacy.html

Privacy Shield

Optimizely, Inc.,
San Francisco, 631 Howard Street, Suite 100. San Francisco, California 94105 (USA)

Optimizely

https://www.optimizely.com/de/privacy/

https://www.optimizely.com/de/security/

Privacy Shield

Trusted Shops
Subbelrather Straße 15c, 50823 Köln

Trusted Shops

https://www.trustedshops.de/impressum/

 

Length of data storage: Details of the cookies and the technologies used in the context of these tracking tools, their storage duration, as well as information about how you can delete these data, can be found in the Information on the Right to Object to the Processing of Data.

Legal basis: Article 6 (1 f) GDPR

Provision of data stipulated or required: The provision of the aforementioned personal data is neither legally nor contractually required.

Profiling

With the help of the tracking tools, the interests and behavior of the website visitor can be evaluated and analyzed. To do this, we create a pseudonymous user profile. In addition, when you log in to "my account" with your user data, we can use this profile to determine your identity.

Area concerned: Visiting the website, Advertising

Personal data: IP address, cookie identifier, order ID

Description and purpose of the data processing

The website also uses so-called advertising tracking tools. With the help of these advertising tracking tools, we can display or arrange for the display of individual advertisements on our websites that are selected (automated) based on the visitor's preferences. Technically, advertising tracking is usually performed via advertising IDs through which cookies, among others, are used by ad network providers to create user profiles and display the advertisement based on the cookie profile when the website is called up. By using tracking pixels on various websites, the first time a user visits an advertising partner's website, cookies are stored on the user's end device by the advertising partners. Through such remarketing offers, a user can be "tracked" on the Internet and shown especially appealing offers (supposedly). In many cases, tracking is performed via so-called browser fingerprints, which use information such as the individual setting of screen resolution, color depth, time zone and installed plug-ins to recognize users and user groups.

Via so-called affiliate networks we advertise our products on third party websites. By clicking on these advertisements, you will be directed to the corresponding product in our web shop. The respective third-party provider receives the order ID only for billing the commission, if the visitor did purchase.

Interest in the processing of data            

With the help of advertising tracking tools, we can better target our offers to our customers, visitors and interested parties. Advertising tracking tools and the associated advertising campaigns also make it possible for us or a third party to earn money from the advertisements. In addition, user behavior helps us to determine which areas of our website are potentially of particular interest to the visitors so that we can selectively display advertising. The ads are displayed according to the thematic orientation of a website and the related search behavior of the user. As a result, advertising tracking tools can find out where the visitors originated and which areas on a web page were visited, how often and for how long which subpages and categories were viewed. Common methods of advertising include retargeting and remarketing campaigns, in which users can be readdressed at other times and places on the Internet, for example, by advertising products from websites previously visited by the user that may be of interest. For details and other information about the providers of these tools, please see the Information on the Right to Object to the Processing of Data.

Recipients of the abovementioned data

The following providers of web analytic tools process access data on our behalf for the purpose of evaluating user behavior and customized advertising. To do this, we have concluded the corresponding order processing contracts with vendors. Further details about the technical operation of the tools and information on how you can prevent the transmission of data (tracking), please see the Information on the Right to Object to the Processing of Data.

Provider

Tool

Details of the provider & privacy policy

Adobe Systems Software Ireland Limited
4–6 Riverwalk, Citywest Business Campus, Dublin 24, Republic of Ireland

Adobe Audience Manager

Adobe Dynamic Targeting

https://www.adobe.com/de/privacy.html

https://www.adobe.com/de/privacy/opt-out.html

Privacy Shield

Certona Inc.
10431 Wateridge Circle, Suite 200
San Diego, CA 92121 (USA)

Certona

//www.certona.com/privacy/

 

Google Inc. (Google)

1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

DoubleClick

Google Adwords Remarketing

Google AdWords User Lists

Google Dynamic Remarketing

Google Analytics Audiences

//www.google.com/settings/ads

//www.google.com/privacy/ads/.

//www.google.com/policies/

//www.google.com/policies/technologies/ads/

Privacy Shield

Length of data storage: Details of the cookies that are used in the context of these tracking tools, their storage duration and information about how you can delete these cookies, can be found Information on the Right to Object to the Processing of Data.

Legal basis: Article 6 (1 f) GDPR

Provision of data stipulated or required: The provision of the aforementioned personal data is neither legally nor contractually required.

Profiling

With the help of the tracking tools, the interests and behavior of the website visitor can be evaluated and analyzed. To do this, we or the above advertising partners create a pseudonymous user profile.

Area concerned: Webshop, Order

Personal data: Email address, title, first and last name, shipping address, billing address, payment data (no credit card data!), login data (in the case of registered customers), IP address, cookie identifier

Description and purpose of the data processing

We process data within the framework of an initial order or, if you are an existing customer, to provide your customer account. With the help of the data given, we are able to enter your order, tailor the product selection according to your tastes and preferences and make recommendations to this effect. The data are then used for the processing, handling and delivery of your ordered products to you. Should you have a customer account, we will require your login data to verify this account.

With the help of the analytic and tracking tools used in the context of your order or selection process (webshop search), we can personalize our offer for you and provide you with special product proposals.

Recipient and processor of the data

We share your data with the recipient solely on the basis of contracts relating to order processing and only insofar as it is necessary for the contractual provision of the services (e.g., in the case of logistics companies). When paying by invoice, we carry out a credit query prior to the acceptance of your order. For this purpose, the stated data is forwarded to specially designated service providers in order to provide them with information about your payment history and credit information on the basis of mathematical-statistical scoring procedure. This processing is carried out solely on the basis of your separate consent (Article 6 (1a) GDPR).

Depending on your selected payment method, your payment data is transferred to the corresponding payment service provider. The responsibility for your payment data shall be borne by the payment service provider. Information, especially about the responsible body of the payment service providers, the contact data for the payment service provider's Data Protection Officer and the categories of personal data to be processed by the payment service provider, can be found at payment.

Delivery service providers

  • Purpose of data processing: Shipping and delivery of goods (For more details, please refer to the shipping company shipping costs.

Payment service providers

  • Purpose of data processing: Settlement of payment by credit card (For more details, please refer to the respective payment service providers payment.

Length of data storage

We process and/or delete invoices and order confirmations based the applicable tax and commercial retention periods, unless you have expressly consented to the further use of your data. In addition, we store your data for the duration of statutory limitation periods for claims for defects (usually 2 years after purchase). When you have a customer account, we also store your data for the duration of your customer account. The deletion of your customer account is possible at any time and can be requested by sending a message using one of the contact options listed below.

Legal basis: Article 6 (1 a, b, f) GDPR

Provision of data stipulated or required: The provision of the abovementioned personal data for the shop is contractually required. Otherwise, it is not possible to place an order.

Area concerned: Customer account

Personal data: Email address, customer number, first and last name, shipping address, billing address, login data, order history

Description and purpose of the data processing

We process your data in order to provide you with a customer account through which you can manage your orders as well as the various applications and services offered by bitiba. This includes the ability to set delivery, payment and newsletter preferences, view your order history and access your bonus point account. The login data serves to verify your customer account.

Length of data storage

We store your account data for the duration of the existence of your customer account or until you ask us to delete it. The retention periods in the area "Webshop" also apply. You can revoke the consent to the processing of your data at any time. The legality of the processing based on your prior consent shall remain unaffected with your revocation of this consent.

Legal basis: Article 6 (1 a) GDPR

Provision of data stipulated or required: The provision of the aforementioned personal data is not required. However, use of the customer account is not possible without the processing of data.

Area concerned: Newsletter, News and special offers

Personal data: Email address, title, first and last name, order history

Description and purpose of the data processing

When you subscribe to our email newsletter, we will send you periodic information about our offers and promotions, as well as news about bitiba. The information required to receive the newsletter is your email address and your name so that we are able to address you personally. We send the newsletter using the so-called double-opt-in procedure. This means that we will send you an email newsletter only when you have explicitly given us your confirmation that you agree to receive the newsletter. We will send you a confirmation email asking you to confirm by clicking a link that you wish to receive newsletters in the future. Only by activating the confirmation link you consent to our use of your personal data. The data will be used exclusively for promotional purposes by means of the newsletter.

By sending the newsletter, we also automatically evaluate your user behavior. To do this evaluation, the emails sent include so-called web beacons and tracking pixels, which help us to determine whether you have received and opened the newsletter and clicked on any links contained in the newsletter. Using the data gathered, we create a user profile to tailor the newsletter to your individual interests. In some circumstances, we link this data to your activities on our website by means of tracking.

Recipient and processor of the data

The following provider of the newsletter tool prepares the data on our behalf for the purpose of sending and statistical processing, as well as to conduct a user analysis. To ensure this, we have concluded a corresponding order processing contract with the provider.

Supplier

Tool

Details zur Funktionsweise/Informationen zum Datenschutz/Privacy Shield

Episerver AB
Regeringsgatan 67, Box 7007, 103 86 Stockholm (Schweden)

Optivo

https://www.episerver.com/legal/privacy-statement/

Privacy Shield

 

Length of data storage: You can object to the receipt of newsletters, at any time, including the processing of your aforementioned data for the purpose of email advertising. If you no longer wish to receive emails, you can click on the "unsubscribe" link found in every email or contact us at service@bitiba.co.uk. To do so, only transmission costs are incurred in accordance with the basic tariffs. The legality of the processing based on your consent remains unaffected until your revocation of this consent. You can object to this tracking at any time by clicking on a separate link provided in every email or informing us via another means of contact. Doing this will simultaneously unsubscribe you from the newsletter. Until that time, your data will be stored for the duration of your subscription to the newsletter. After you unsubscribe from the newsletter, we store the data only for purely statistical purposes on an anonymous basis.

Legal basis: Article 6 (1 a) GDPR

Provision of data stipulated or required: The provision of personal data is neither legally nor contractually required. However, the dispatch, as well as the receipt of the newsletter, are not possible without the provision of an email address.

Area concerned: Contact, Customer service

Personal data: Email address, first and last name, date, time, comment (request/concern)

Description and purpose of the data processing

We use contact functions on our website to exchange ideas with our customers and interested parties and to answer your requests and inquiries. We process the inquiries and information sent to us in this regard in order to answer your inquiry and contact you. At the same time, the data is used to match your profile in the event that you as a customer register with the same data.

We use Google's reCAPTCHA service in the scope of our contact options. The use of reCAPTCHA serves to distinguish whether the input is made by a human or improperly made using automated, mechanical processing. The query includes sending Google the IP address and any additional data needed by Google for the reCAPTCHA service. For this purpose, your input will be transmitted to Google and analyzed. The rationale for this tool is our interest in the accuracy of the data provided, the avoidance of automatic registrations, inquiries by so-called bots and the economical operation of our online offers (Article 6 (1 f) GDPR). For Privacy Shield certification, see above. Please visit the following links for more information about Google reCAPTCHA and Google's privacy policy.

Length of data storage: We use the data until the respective communication with you comes to an end. Communication ends when it can be inferred from the circumstances that the relevant facts have been finally clarified. In addition, we store the communication for the duration of the contractual relationship with you or until the termination of your customer account, but no later than the request for us to delete the communication. You may revoke your consent to data processing at any time without affecting the legality of the processing carried out on the basis of your consent until you revoke this consent.

Legal basis: Article 6 (1 a) GDPR

Provision of data stipulated or required: The provision of personal data is neither legally nor contractually required. However, processing the request is not possible without the provision of this data.

4. Your rights in connection with the processing of this data

You have the right at any time to request a confirmation from bitiba about whether we are processing your personal data and the right to information about this personal data. You also have the right to rectification, erasure and restriction of data processing, as well as the right at any time to object to the processing of personal data or to revoke your consent for the processing of data or to request the transfer of data. For any information needs or requests, revocations or objections to the processing of data, please send an email to our Data Protection Officer or to the contact details above. In addition, you have the right to complain to a supervisory authority when violations of privacy occur.