cflox GmbH data protection policy for customers

cflox GmbH (hereinafter “cflox” or “we”) takes the protection of personal data very seriously and processes it in accordance with the applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

cflox provides payment services for the processing of contracts for the purchase and sale of products between end customers and sellers that are concluded via the e-commerce platforms of Kaufland Marketplace GmbH (“Marketplace”). This includes, in particular, the fiduciary acceptance of payments from end customers and the forwarding of the money to the seller.

This data protection notice for end customers (“Data Protection Notice”) applies to the processing of personal data of end customers by cflox in the context of processing payments that end customers make to sellers (whether a third-party provider or the marketplace itself as a seller) when purchasing products on the marketplace’s e-commerce platform. This data protection notice is aimed at end customers, provided they are natural persons (“you”).

In the following, we explain which personal data we collect about you, how we process it and what rights you have with regard to the processing of your data. The sole purpose of this Data Protection Notice is to fulfil our information obligations pursuant to Art. 13 and 14 GDPR. This data protection notice does not create any contractual obligations for cflox.

I. Who is responsible for processing my data? How do I contact the responsible party?

Responsible party: cflox GmbH, Gaußstraße 190c, 22765 Hamburg, Germany, Phone: +49 40 22 86 97 85; E-mail: [email protected]

Data protection officer: René Hoffmann, Gaußstraße 190c, 22765 Hamburg, Germany, Phone: +49 40 22 86 97 85; E-mail: [email protected]

When contacting the data protection officer, please state the company to which your enquiry relates. Please refrain from including sensitive information, such as a copy of your ID, with your enquiry.

II. Which kind of personal data is processed? From which sources is the data taken?

In connection with the processing of payments made by you on the marketplace and in the event of refunds to you, we may collect the following personal data III as explained in more detail below in this section:

  • First name and surname;
  • Address (billing and shipping);
  • E-mail address;
  • Telephone number, if applicable (if you provided this when purchasing)
  • Content/price of the e-commerce purchase;
  • IBAN;
  • If applicable, credit card information (card number, CVC, expiry date, name of the cardholder);
  • Transaction details (amount, date, payment status, transaction IDs);
  • IP address;
  • Payment method, if applicable (only in the case of repayments);
  • Purchase history.

The above-mentioned data is collected by the end customer payment service providers contractually linked to cflox and the marketplace via the respective payment interface or by the marketplace. This data is processed by the payment service providers - generally in the role of an independent and separate controller within the meaning of Art. 4 (7) GDPR - for the provision of payment services (Adyen NV, Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands; BNP Paribas S.A., Schwanthalerstraße 31, 80336 Munich, Germany; PayPal, Inc., 2211 North First Street, San Jose, CA 95131; PayPal Pte. Ltd, 5 Temasek Boulevard #09-01, Suntec Tower Five, Singapore 038985; Ivy GmbH, Sandstraße 33, 80335 Munich, Germany; Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden).

The end customer payment service providers share the data with us, and we process it or the service providers process it on our behalf as processors in accordance with our instructions, to the extent necessary for the processing purposes specified in section III. In exceptional cases, e.g. in the case of repayments (e.g. in the case of advance payment) or FIU notifications (see section III below), we receive the data directly from the marketplace.

1.) Processing of payments

We process your data insofar as this is necessary for the processing of payments that you make as an end customer when purchasing products on the e-commerce platform of the marketplace to merchants (be it a third-party provider or the marketplace itself as a seller), the forwarding of the funds to the seller and, if necessary, for the execution of refunds to you. We base this on the necessity of processing your data to safeguard our legitimate interests in the proper provision of payment services in accordance with our contractual obligations to the seller and marketplace and the applicable legal requirements, in particular under the Payment Services Supervision Act (Art. 6 para. 1 sentence 1 f) GDPR).

2.) Money laundering and other legal requirements

We process your data insofar as this is necessary to carry out legally prescribed money laundering processes relating to merchants, in particular customer due diligence obligations and sanctions list checks. In this respect, we rely on the necessity of the processing to ensure and document compliance with our legal obligations under the Money Laundering Act (Art. 6 para. 1 (1) c) GDPR).

We also process your data to ensure and document compliance with other legal obligations, in particular retention obligations under commercial and tax law in accordance with section 257 of the German Commercial Code (HGB) and section 146 of the German Fiscal Code (AO). We base the processing on the necessity to fulfil our legal obligations or on our legitimate interest in the fulfilment of these obligations (Art. 6 para. 1 (1) c) and f) GDPR).

Furthermore, we may process your data insofar as this is necessary to protect our legitimate interests in the assertion, exercise and defence of legal claims (Art. 6 para. 1 (1) f) GDPR).

3.) Fraud prevention, systems security and product improvement

We process your data in order to

  • detect, track and prevent fraudulent behaviour;
  • prevent chargebacks;
  • protect our IT infrastructure and recognise, track and prevent cyber-attacks.

We base this processing on our legitimate interests as well as the legitimate interests of our customers and contractual partners to prevent and detect fraudulent activities and chargebacks as well as ensure the security of our services and IT infrastructure (Art. 6 para. 1 (1) f) GDPR).

IV. Who will my personal data be shared with?

We will only pass on your data to other organisations if this is necessary to achieve the processing purposes listed above in point III of this Annex. In particular, we pass on your data to the following recipients in accordance with this provision:

  • Marketplace;
  • Bank of the seller;
  • Credit card organisations (e.g. VISA, MasterCard) and payment providers;
  • Authorities (in particular investigating authorities) in the event of justified requests for information;
  • Central Financial Transaction Investigation Unit (FIU) in the event of necessary suspicious activity reports to the FIU.

In addition, we may pass on your data to service providers who act on our behalf and in accordance with our instructions (Processors). They support us in areas such as the provision and operation of our corporate IT and the implementation of money laundering prevention processes, among other things.

V. Will my personal data be processed outside the EU and the EEA?

Some of the recipients of your personal data listed above in point IV. of this Annex may be located in countries outside the European Union (EU) or the European Economic Area (EEA), i.e. third countries. Should cflox transfer your personal data to recipients in third countries which do not guarantee a level of data protection deemed adequate by the European Commission in an adequacy decision pursuant to Art. 45 GDPR, cflox has taken appropriate protective measures to ensure that your data is always adequately protected in accordance with any imminent risks. This is done in particular by agreeing to the standard contractual clauses approved by the EU Commission (pursuant to Art. 46 para. 2 c) GDPR) and, where necessary, by implementing supplementary measures such as additional technical, organisational and contractual protective measures. If appropriate protective measures cannot be concluded due to special conditions, a transfer to third countries without an adequacy decision will only take place on the basis of a legal exception within the meaning of Art. 49 GDPR. You can obtain a copy of the measures we have taken and further information on the recipients and third countries on request using the contact details provided in point I. of this Annex.

VI. How long will my personal data be stored?

Your data will only be stored for as long as is necessary to fulfil the purposes listed in point III. of this Annex. As a rule, your data will be stored for a period of up to 10 years following its termination in compliance with retention obligations under commercial and tax law. Your data will be deleted thereafter, unless deletion conflicts with statutory retention obligations in individual cases or longer storage is necessary in a specific case so as to fulfil other legal obligations or protect the legitimate interests of cflox (assertion, exercise or defence of legal claims).

VII. Do any automated decision-making processes take place? How is my personal data protected?

No decision-making takes place based solely on automated processing. We take technical and organisational measures pursuant with the requirements outlined in Art. 32 GDPR to protect your personal data.

VIII. What rights do I have in relation to the processing of my personal data and how can I exercise them?

In accordance with statutory provisions, you have the right vis-à-vis cflox as the controller responsible for the processing of your personal data to:

  • request information about the processed personal data as well as a copy of this data (right to information);
  • request the rectification of inaccurate data and, taking into account the purposes of the processing, the completion of incomplete data (right to rectification);
  • request the erasure of your data where there are legitimate grounds (right to erasure; “right to be forgotten”);
  • demand the restriction of the processing of your data, provided that the legal requirements are met (right to restriction of processing);
  • if the legal requirements are met, receive the data provided by you in a structured, commonly used and machine-readable format and to transmit this data to another controller or, if technically feasible, to have it transmitted by cflox (right to data portability).

You also have the right to object to the processing of your data for reasons arising from your particular situation in accordance with the statutory provisions (right to object). If personal data is processed for the purpose of direct marketing – which is not the case here – you have the right to object to this processing at any time without the need for special reasons.

To exercise your rights, please use the contact details listed in point I. of this Annex. In addition, without prejudice to any other legal remedies, you have the right to lodge a complaint with a supervisory authority at any time. This can be exercised, for example, with the supervisory authority responsible for cflox: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.