Data Protection

The protection of personal data is important for Accell Bike Parts GmbH.

We are committed to respecting and protecting your privacy by acting in accordance with all applicable data protection laws and regulations, including the General Data Protection Regulation ("GDPR").  In addition, we apply the following general principles of privacy and data protection:

  1. We limit the use and processing of personal data to the purposes for which we need it;

  2. We process personal data only with a legal basis that may include the performance of a contract, our legitimate interest or, in certain circumstances, your explicit consent;

  3. We will be transparent and clear about when, how and where we process personal data;

  4. We will apply the "Privacy by Design" and "Privacy by Default" standards and assess the potential impact of existing or new products or services on the privacy rights of data subjects;

  5. Personal data will not be kept longer than necessary and we will comply with all applicable data retention conditions.

Please read this Privacy Policy carefully. It contains important information about how we use your personal data (defined below) and explains your legal rights (in full transparency and in accordance with applicable laws and regulations) when you visit (www.xlc-parts.com) our website ("Website"), and/or products from us as a customer ("Customer"). ") buy.  When we refer to "processing" of personal data, we mean any use of your personal data, such as collecting, storing, modifying, forwarding and deleting.

Who are we?

Accell Bike Parts GmbH Max-Planck-Str. 6
697526 Sennfeld Germany Phone: +49 9721 6501-0 E-Mail: info@xlc-parts.com

Registered in Germany under the commercial register number HRB 5976 at the register court Schweinfurt. If you have any questions about this Privacy Policy or would like to exercise your rights set out in this Privacy Policy, please contact us by email at: (lars@ebertz-datenschutz.de).

What information do we collect about you?

For the purposes of this Privacy Policy, personal data is any information through which we can directly or indirectly identify you ("Personal Data").

The personal data we collect about you includes the following:

  1. Contact details of you. Your name, mailing address and other contact details, such as your telephone number and email address.  We may also collect the contact details of your emergency/insurance contacts from you. This includes their name,  mobile phone number and email address.

  2. Information collected automatically. Technical information, including your IP address and browser type and version, that we may collect when we use cookies, web beacons and similar technologies on our website and in our apps that collect information about the use of our website or apps. For more information, please scroll down to our Cookie Policy.

  3. Information about your use of our (online) services or the purchase of products. This includes data about the pages you visit and the products and services you like.

  4. Details of competitions. The information we collect when you participate in a survey, contest, promotion or contest that we organize from time to time.

  5. Your reviews. The opinions, experiences, preferences and interests, and product or event reviews you post on our website or app or share with us online or via social media.

  6. Communication data. Your requests, your complaints and any other data we receive when we communicate with you by email, telephone, online or via social media.

  7. Information collected from other sources. We may collect information from commercially available sources such as data aggregators and public databases. We may combine this information (e.g., name, interests, publicly observed data) with the information we collect from you to tailor our communications to you and improve our services and products, and may request your explicit consent separately where required by law.

 

Collection of your data and how we use it

We use the personal data collected for the following purposes:

  1. For the performance of our agreement with you.  To fulfil our obligations under a contract entered into between you and us and to provide you with the information and services you have requested, including the handling of your enquiries, enquiries or complaints. To develop and administer a contest, contest or promotion in which you may have participated, to run the promotion and to contact you if you win. If it is possible to order products online,  we store this data to manage and process your purchases.

  2.  For our legitimate commercial interests. We may use your personal data (both on an aggregated and individual basis), such as your contact details, account and electronic identification data, to promote our products and services and to contact you for marketing or other commercial purposes if you are an existing customer.  We may also use your personal data to analyse and improve the quality of our products and services, to understand you as a customer and to provide you with a better user experience. This allows us to create personal profiles and assess what may interest you, measure or understand the effectiveness of the advertising we offer to you and others, and deliver relevant advertising.

    We may also use your personal data for other legitimate commercial interests, such as to compile aggregated statistics about the users of our Services, to support security and fraud prevention, to administer our website and apps, and for internal operations (including troubleshooting, data analysis, testing, research, statistics and survey purposes), for system integrity purposes (e.g. preventing hacking,   Spamming, etc.), to enable you to participate in interactive features of our Services, to facilitate our business operations, to operate corporate policies and procedures, to enable us to conduct corporate transactions such as mergers, sales, divestitures, reorganizations, transfers of assets or companies, acquisitions, bankruptcies or similar events, or for other legitimate business purposes governed by applicable law are permissible.

  3. Use of information based on your consent We may use the personal data set out in the "Special Categories of Personal Data" subsection above (i.e. Health Data) for the purposes set out in this Privacy Policy, but only after we have obtained your consent to do so.

    We may use your personal data for marketing communications (based on your profiles) by email, SMS or other electronic means, but we will only do so after we have obtained your consent to do so or if we have another legal basis for doing so.

  4. To comply with our legal obligations. Any information referenced above in the section "What information do we collect about you?" may be used to maintain reasonable business records, to comply with lawful requests from public authorities and to comply with applicable laws and regulations or as otherwise required by law.

    Data collection from children: We do not allow children to register on our websites and/or apps if they are below the legal age limit.  We will obtain parental consent for children who participate in our experiences and events.


Disclosure of your information

We may share your personal information with:

  1. To Accell Group companies or affiliates in the context of providing our products and services or for internal purposes such as IT.

  2. Third-party service providers who provide us with services such as website hosting, data analysis, payment processing, order fulfillment, provision of information technology and related infrastructure, customer service, email delivery, CRM, event management, marketing intelligence, auditing, fraud detection and other third-party services.

  3. Permitted third parties who are subject to your consent or request to do so, such as to send you marketing communications, in accordance with your choices, if you have opted in to such sharing.

  4. Other parties that we deem necessary to comply with applicable laws, respond to requests from authorities or for other legal reasons and protect our rights.

  5. In addition, we may use or disclose your personal information in the event of a reorganization, merger, sale, joint venture or other sale (part) of our business, assets or shares.

 

Other websites

Our websites may from time to time contain links to and from third-party websites, such as websites of our partner networks (e.g. the retailers who sell our products), social media networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these websites or their content. Please consult the privacy policies of the respective third-party providers before submitting personal data to these websites.

Dealers

Customers purchase most of our products and services from approved dealers and other resellers. These dealers and resellers are independent companies.  We are not responsible for the handling of customer data by approved dealers and other resellers. Dealers and resellers provide us with your personal data in connection with the sale of our products and services on their own responsibility (e.g. for warranty purposes), please read their applicable privacy statements for more details.

Transfer of your personal data outside the EEA

We store your data within the European Economic Area (EEA) or from countries that have received an adequacy decision from the European Commission.

If we transfer your data to companies based outside (i) the EEA or (ii) countries that do not have an adequacy decision, we will agree on the standard contractual clauses approved by the European Commission with the receiving party and ensure that additional safeguards are put in place if necessary.

How long do we keep personal data?

We may retain your personal data for as long as is necessary to fulfil the purposes for which we collected it unless a longer period is necessary to:

  1. Compliance with a statutory retention period or other applicable legal obligation;

  2. store your personal data in relation to a legal process.

To ensure that your personal data is removed within a reasonable period of time, we use retention overviews per country.

How do we secure customer data?

The protection of your personal data is very important to Accell Group. We have put in place appropriate technical and organisational measures to ensure that your personal data is properly protected against unauthorised or unlawful use, access, disclosure or accidental or unlawful destruction and loss.

We take steps to limit access to your personal information only to those individuals who need to have access to it for any of the purposes listed in this Privacy Policy. In addition, we contractually ensure that third parties who process your personal data protect your personal data equally in accordance with applicable data protection laws and in accordance with this Privacy Policy.

Your rights

You have the following rights in relation to the personal data we hold about you:

Your right to information

You have the right to request access to your personal data. For example, the right to obtain certain information about the processing of personal data and access to this data. Please note that this right is subject to exceptions.

Your right to rectification

If the personal data we hold about you is inaccurate or incomplete, you have the right to request its rectification.

Your right to erasure

You can ask us to delete or remove your personal data in certain circumstances, such as when we no longer need it or when you withdraw your consent (if applicable).

Your right to restriction of processing

You can ask us to restrict the processing of your personal data in certain circumstances, such as if you contest the accuracy of this P-specific data or object to us. 

Your right to data portability

In certain circumstances, you have the right to receive and reuse personal data that you have provided to us (in a structured, commonly used and machine-readable format) or to ask us to transmit it to a third party of your choice.

Your right to object

You can ask us to stop processing your personal data and we will do so if we:

  1. rely on our own or another person's legitimate interests to store your P data, unless we can demonstrate compelling legal grounds for the processing; or

  2. Processing of your personal data for direct marketing purposes.

Your right to withdraw consent

If we rely on your consent (or explicit consent) as the legal basis for processing your personal data, you have the right to withdraw that consent at any time.  Please note, however, that the withdrawal of your consent does not affect the lawfulness of the processing prior to such a withdrawal.

Your right to lodge a complaint with the supervisory authority

If you have any concerns about any aspect of our privacy practices, including how we have handled your personal information, you may report this to your local supervisory authority.

Please note that some of the above; Rights may be restricted if we have an overriding interest or legal obligation to continue to take over the personal data.

Contact and complaints

The primary point of contact for all questions relating to this Privacy Policy, including a request to exercise the rights of the data subject, is our Data Protection Officer. The Country Privacy Ambassador can be contacted in the following ways:

By e-mail: lars@ebertz-datenschutz.de  By phone: +49 2778 6969 10 Postal address: L-E-C.COM GmbH, attn. Dipl.-Ing. Lars Ebertz, Lubergstraße 2, 35756 Mittenaar (Germany)

NOTE

If you have a complaint or concern about how we use your personal information, please contact us in the first instance and we will endeavor to resolve the issue as soon as possible.

 

Data collection on this website

Among other things, we use tools from companies based in the USA or other third countries that are not secure under data protection law. If these tools are active, your personal data may be transferred to and processed in these third countries. We would like to point out that in these countries no level of data protection comparable to that of the EU can be guaranteed. For example, US companies are obliged to hand over personal data to security authorities without you as a data subject being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g. secret services) process, evaluate and permanently store your data on US servers for surveillance purposes. We have no influence on these processing activities.

Cookies

Our Internet pages use so-called "cookies". Cookies are small text files and are aimed at No damage to your device. They are stored either temporarily on your device for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or they are automatically deleted by your web browser.

In some cases, cookies from third-party companies may also be stored on your device when you enter our site (third-party cookies). These enable us or you to use certain services of the third-party company (e.g. cookies for processing payment services).

Cookies have different functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies are used to evaluate user behavior or to display advertising.

Cookies that are necessary to carry out the electronic communication process, to provide certain functions desired by you (e.g. for the shopping cart function) or to optimise the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the Storage of cookies and comparable recognition technologies has been queried, the processing takes place exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); the consent can be revoked at any time.

You can set your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general and enable the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Insofar as cookies are used by third-party companies or for analysis purposes, we will inform you separately about this in the context of this data protection declaration and, if necessary, request your consent.

OneTrust Consent Management

We offer you the opportunity to decide in detail in which cases you want to consent to tracking via cookies and other technologies - for the purpose of displaying content relevant to you and offers tailored to you.

The processing of your data for the purposes stated here is partly based on legitimate interest, but in some cases we also need your consent. For this purpose, we use the Consent Management Platform (CMP) of OneTrust, LLC, 1350 Spring St NW, Atlanta, GA 30309, as a processor.

The CMP of Onetrust enables you to give us a data protection-compliant and self-determined consent to the processing of your data and to revoke it at any time. You can also object to data processing based on our legitimate interest. Further information on Data Protection and Onetrust's CMP can be found here: https://www.onetrust.de/datenschutzerklaerung/

Plugins + analysis tools and advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool used to provide tracking or statistics tools and other technologies on our website. Google Tag Manager itself does not create a User profiles, does not store cookies and does not carry out any independent analyses. It only serves the Management and playout of the tools integrated via him. However, Google Tag Manager collects your IP address, which can also be transferred to Google's parent company in the United States.

The Use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The Website operator has a legitimate interest in a quick and uncomplicated integration and administration of various tools on its website. If a corresponding consent has been requested, the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent to the storage of cookies or access to information in the End device of the user (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyse the behaviour of website visitors. The website operator receives various usage data, such as page views, length of stay, operating systems used and origin of the user. This data is summarized in a user ID and assigned to the respective end device of the website visitor.

Furthermore, with Google Analytics, we can, inter alia: Record your mouse and scroll movements and clicks. Furthermore, Google Analytics uses various modeling approaches to supplement the collected data sets and uses machine learning technologies in data analysis.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the USA and stored there.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. The consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.

Browser Plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

More information on the handling of user data by Google Analytics can be found in Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.

Order processing

We have concluded a contract with Google for order processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Google Web Fonts

This site uses so-called web fonts, which are provided by Google, for the uniform presentation of fonts. When you call up a page, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.

For this purpose, the browser you are using must connect to Google's servers. As a result, Google becomes aware that this website has been accessed via your IP address. The use of Google WebFonts is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the uniform presentation of the typeface on its website. If a corresponding consent has been requested, the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. DeviceFingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

If your browser does not support web fonts, a standard font will be used by your computer.

Further information on Google Web Fonts can be found under https://developers.google.com/fonts/faq and in Google's privacy policy: https://policies.google.com/privacy?hl=de.

Google Maps

This site uses the map service Google Maps. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

To use the functions of Google Maps, it is necessary to save your IP address. These

Information is usually transmitted to a Google server in the USA and stored there. The provider of this site has no influence on this data transfer. If Google Maps is activated, Google may use Google Web Fonts for the purpose of uniform display of fonts. When you call up Google Maps, your browser loads the required web fonts into your browser cache in order to display texts and fonts correctly.

The use of Google Maps is in the interest of an appealing presentation of our online offers and an easy findability of the places indicated by us on the website. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Provided that a corresponding Consent has been requested, the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 (1) TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

More information on the handling of user data can be found in Google's privacy policy: https://policies.google.com/privacy?hl=de.

Google reCAPTCHA

We use "Google reCAPTCHA" (hereinafter "reCAPTCHA") on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

The purpose of reCAPTCHA is to check whether the data entry on this website (e.g. in a contact form) is carried out by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website. Evaluated for analysis reCAPTCHA various information (e.g. IP address, length of stay of the website visitor on the website or mouse movements made by the user). The data collected during the analysis will be forwarded to Google.

The reCAPTCHA analyses run completely in the background. Website visitors are not informed that an analysis is taking place.

The storage and analysis of the data takes place on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offers from abusive automated spying and SPAM. If a corresponding consent has been requested, the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

For more information about Google reCAPTCHA, please refer to the Google Privacy Policy and the Google Terms of Service under the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.

YOTPO REVIEWS

On the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our online offer within the meaning of Art. 6 para. 1 lit. f. GDPR), we use the App Yotpo of the provider Yotpo, 33 West 19th Street, 5th Floor, New York, NY 10011 (https://www.yotpo.com) within our online offer in order to use its content and services to evaluate purchases. For this purpose, we forward personal data of our customers who have made a purchase to the said company.

Status of this data protection declaration (September, 07th 2022)

This Privacy Policy may be revised from time to time.  Any change will be effective at the time of publication on the Website.