Privacy Policy

1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER

1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website (www.rhea-toronto.com). Personal data refers to all data that can personally identify you.

1.2 The controller responsible for data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Rhea Toronto. The controller responsible for processing personal data is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data.

1.3 This website uses SSL or TLS encryption for security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to the controller). You can recognize an encrypted connection by the string "https://" and the lock symbol in your browser line.

2) DATA COLLECTION WHEN VISITING OUR WEBSITE

When using our website purely for informational purposes, i.e., if you do not register or otherwise transmit information to us, we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website;
- Date and time at the time of access;
- Amount of data sent in bytes;
- Source/reference from which you accessed the page;
- Used browser;
- Used operating system;
- Used IP address (if applicable: in anonymized form).

The processing is carried out in accordance with Art. 6(1)(f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively if there are specific indications of unlawful use.

3) COOKIES

To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files stored on your end device. Some of the cookies we use are deleted after the end of the browser session, i.e., after you close your browser (so-called session cookies). Other cookies remain on your end device and enable us or our partner companies (cookies from third parties) to recognize your browser on your next visit (persistent cookies). If cookies are set, they collect and process certain user information such as browser and location data as well as IP address values individually. Persistent cookies are automatically deleted after a specified duration, which can vary depending on the cookie.

Partly, the cookies serve to simplify the order process by storing settings (e.g., remembering the contents of a virtual shopping cart for a later visit to the website). Insofar as personal data is also processed by individual cookies implemented by us, the processing is carried out in accordance with Art. 6(1)(b) GDPR either for the performance of the contract or in accordance with Art. 6(1)(f) GDPR to safeguard our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

We may work with advertising partners who help us make our internet offer more interesting for you. For this purpose, in this case, cookies from partner companies are also stored on your hard drive (cookies from third parties) when you visit our website. If we cooperate with the aforementioned advertising partners, you will be informed individually and separately about the use of such cookies and the scope of the information collected within the following paragraphs.

Please note that you can set your browser to inform you about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general. Each browser differs in how it manages the cookie settings. This is described in the help menu of each browser, which explains how you can change your cookie settings. You can find these for the respective browsers under the following links:
- Internet Explorer: https://support.microsoft.com/en-us/help/17442/windows-internet-explorer-delete-manage-cookies;
- Firefox: https://support.mozilla.org/en/kb/cookies-allow-and-reject;
- Chrome: https://support.google.com/chrome/answer/95647?hl=en&hlrm=en;
- Safari: https://support.apple.com/kb/ph21411?locale=en_US;
- Opera: https://help.opera.com/en/latest/web-preferences/#cookies.

Please note that if you do not accept cookies, the functionality of our website may be restricted.

4) CONTACTING US

When contacting us (e.g., via contact form or email), personal data is collected. The specific data collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6(1)(f) GDPR. If your contact aims to conclude a contract, then the additional legal basis for the processing is Art. 6(1)(b) GDPR. Your data will be deleted after the final processing of your inquiry; this is the case if it can be inferred from the circumstances that the relevant facts have been conclusively clarified and provided there are no statutory retention obligations.

5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING

According to Art. 6(1)(b) GDPR, personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. The specific data collected can be seen from the respective input forms. Deleting your customer account is possible at any time and can be done by sending a message to the address of the controller mentioned above. We store and use the data you provide for contract processing. After the complete processing of the contract or deletion of your customer account, your data will be blocked considering tax and commercial law retention periods and deleted after these periods unless you have expressly consented to further use of your data or a legally permitted further data use on our part has been reserved, about which we inform you below.

6) USE OF YOUR DATA FOR DIRECT ADVERTISING

6.1 Subscription to our email newsletter

If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. Providing further data is voluntary and will be used to address you personally. For sending the newsletter, we use the so-called double opt-in procedure. This means that we will only send you an email newsletter if you have expressly confirmed to us that you consent to the sending of newsletters. We will then send you a confirmation email asking you to confirm that you wish to receive the newsletter by clicking on a corresponding link.

By activating the confirmation link, you give us your consent to use your personal data in accordance with Art. 6(1)(a) GDPR. When registering for the newsletter, we store your IP address entered by the Internet Service Provider (ISP) as well as the date and time of registration to be able to trace any possible misuse of your email address at a later time. The data collected by us when registering for the newsletter is used exclusively for the purpose of advertising via the newsletter. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending a corresponding message to the controller mentioned above. After unsubscribing, your email address will be immediately deleted from our newsletter distribution list, unless you have expressly consented to further use of your data or we reserve the right to use data beyond this, which is permitted by law and about which we inform you in this statement.

6.2 Newsletter dispatch to existing customers
If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range by email. For this, we do not need to obtain separate consent from you. The data processing in this respect is carried out solely based on our legitimate interest in personalized direct advertising in accordance with Art. 6(1)(f) GDPR. If you initially objected to the use of your email address for this purpose, no email will be sent by us. You are entitled to object to the use of your email address for the aforementioned advertising purposes at any time with effect for the future by notifying the controller mentioned at the beginning. For this, you only incur transmission costs according to the basic tariffs. After receiving your objection, the use of your email address for advertising purposes will cease immediately.

7) DATA PROCESSING FOR ORDER PROCESSING

7.1 The personal data collected by us will be passed on to the transport company commissioned with the delivery as part of the contract processing, insofar as this is necessary for the delivery of the goods. We will pass on your payment data to the commissioned credit institution as part of the payment processing, provided this is necessary for the payment processing. If payment service providers are used, we explicitly inform you about this below. The legal basis for the transfer of the data is Art. 6(1)(b) GDPR.

7.2 Use of payment service providers (payment services)
- PayPal
For payments via PayPal, credit card via PayPal, direct debit via PayPal, or - if offered - "purchase on account" or "installment payment" via PayPal, we pass on your payment data within the payment processing to PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal"). The transfer is carried out in accordance with Art. 6(1)(b) GDPR and only to the extent that it is necessary for the payment processing.

PayPal reserves the right to conduct a credit check for the payment methods credit card via PayPal, direct debit via PayPal, or - if offered - "purchase on account" or "installment payment" via PayPal. For this purpose, your payment data may be processed in accordance with Art. 6(1)(f) GDPR based on PayPal's legitimate interest in determining your solvency and passed on to credit agencies. The result of the credit check regarding the statistical probability of default is used by PayPal to decide on the provision of the respective payment method. The credit report can contain probability values (so-called score values). Insofar as score values are included in the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. Address data is included in the calculation of the score values, among other things. Further data protection information, including the credit agencies used, can be found in PayPal's privacy policy: https://www.paypal.com/en/webapps/mpp/ua/privacy-full

You can object to this processing of your data at any time by sending a message to PayPal. However, PayPal may still be entitled to process your personal data if this is necessary for the contractual payment processing.

- SOFORT
If you select the "SOFORT" payment method, the payment will be processed via the payment service provider SOFORT GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter "SOFORT"), to whom we pass on your information provided during the order process along with the information about your order in accordance with Art. 6(1)(b) GDPR. SOFORT GmbH is part of the Klarna Group (Klarna Bank AB (publ), Sveavägen 46, 11134 Stockholm, Sweden). The transfer of your data is solely for the purpose of payment processing with the payment service provider SOFORT and only to the extent necessary. You can find more information about SOFORT's privacy policy at the following internet address: https://www.klarna.com/sofort/privacy-policy 

8) CONTACT FOR REVIEW REMINDER

Own Review Reminder (No Sending by a Customer Review System)
We use your email address for a one-time reminder to submit a review of your order for our review system, provided you have given us your explicit consent to do so during or after your order in accordance with Art. 6(1)(a) GDPR. You can revoke your consent at any time by sending a message to the data controller.

9) USE OF SOCIAL MEDIA: SOCIAL PLUGINS

9.1 Facebook Plugins with Shariff Solution
Special additional customs clearance costs and/or import duties are not included in the price and are the customer's responsibility. Our website uses so-called social plugins ("plugins") of the social network Facebook, operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins but only using an HTML link. This embedding ensures that when a page on our website containing such buttons is accessed, no connection is yet established with Facebook servers. If you click the button, a new browser window opens and calls up the Facebook page, where you can (possibly after entering your login details) interact with the plugins there. Facebook Inc. in the USA is certified for the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. For the purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as your related rights and settings options for protecting your privacy, please refer to Facebook's privacy policy: https://www.facebook.com/policy.php

9.2 Google+ Plugins with Shariff Solution
Our website uses so-called social plugins ("plugins") of the social network Google+, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins but only using an HTML link. This embedding ensures that when a page on our website containing such buttons is accessed, no connection is yet established with Google servers. If you click the button, a new browser window opens and calls up the Google+ page, where you can (possibly after entering your login details) interact with the plugins there. Google LLC in the USA is certified for the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. For the purpose and scope of the data collection and the further processing and use of the data by Google, as well as your related rights and settings options for protecting your privacy, please refer to Google's privacy policy: https://www.google.com/intl/en/policies/privacy/

9.3 Instagram Plugin with Shariff Solution
Our website uses so-called social plugins ("plugins") of the online service Instagram, operated by Instagram LLC., 1601 Willow Rd, Menlo Park, CA 94025, USA ("Instagram"). To increase the protection of your data when visiting our website, these buttons are not fully integrated as plugins but only using an HTML link. This embedding ensures that when a page on our website containing such buttons is accessed, no connection is yet established with Instagram servers. If you click the button, a new browser window opens and calls up the Instagram page, where you can (possibly after entering your login details) interact with the plugins there. Instagram LLC in the USA is certified for the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. For the purpose and scope of the data collection and the further processing and use of the data by Instagram, as well as your related rights and settings options for protecting your privacy, please refer to Instagram's privacy policy: https://help.instagram.com/155833707900388/

10) ONLINE MARKETING

10.1 DoubleClick by Google
This website uses the online marketing tool DoubleClick by Google, operated by Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("DoubleClick"). DoubleClick uses cookies to show relevant ads to users, improve campaign performance reports, or avoid showing the same ad multiple times to a user. Google uses a cookie ID to track which ads are displayed in which browser and can thus prevent them from being shown multiple times. The processing is based on our legitimate interest in the optimal marketing of our website in accordance with Art. 6(1)(f) GDPR. Furthermore, DoubleClick can use cookie IDs to track conversions related to ad requests. This is the case when a user sees a DoubleClick ad and later visits the advertiser's website with the same browser and makes a purchase there. According to Google, DoubleClick cookies do not contain personal information. Due to the marketing tools used, your browser automatically establishes a direct connection to Google's server. We have no influence on the scope and further use of the data collected by Google through the use of this tool and therefore inform you according to our level of knowledge: By integrating DoubleClick, Google receives the information that you have accessed the corresponding part of our internet presence or clicked on one of our ads. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, it is possible that the provider may obtain and store your IP address. If you wish to opt-out of this tracking process, you can disable cookies for conversion tracking by setting your browser to block cookies from the domain www.googleadservices.com, https://www.google.de/settings/ads, whereby this setting will be deleted if you delete your cookies. Alternatively, you can obtain information about the setting of cookies and adjust your settings at the Digital Advertising Alliance at the internet address www.aboutads.info. Finally, you can set your browser to inform you about the setting of cookies and decide individually about their acceptance or exclude the acceptance of cookies for certain cases or in general. If cookies are not accepted, the functionality of our website may be restricted. Google LLC in the USA is certified for the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. Further information about DoubleClick by Google's privacy policy can be found at: https://www.google.de/policies/privacy/

10.2 Use of Google AdWords Conversion Tracking
This website uses the online advertising program "Google AdWords" and, within the framework of Google AdWords, the conversion tracking of Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). We use Google AdWords to draw attention to our attractive offers with the help of advertising materials (so-called Google AdWords) on external websites. We can determine the success of individual advertising measures in relation to the data of the advertising campaigns. We pursue the interest of showing you advertisements that are of interest to you, making our website more interesting for you, and achieving a fair calculation of advertising costs. The conversion tracking cookie is set when a user clicks on a Google-served AdWords ad. These cookies are small text files stored on your computer system. These cookies usually expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page. Each Google AdWords customer receives a different cookie. Thus, cookies cannot be tracked via the websites of AdWords customers. The information obtained using the conversion cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. Customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive information that personally identifies users. If you do not wish to participate in tracking, you can opt-out of this use by easily disabling the Google Conversion Tracking cookie through your internet browser under user settings. You will then not be included in the conversion tracking statistics. We use Google AdWords based on our legitimate interest in targeted advertising according to Art. 6(1)(f) GDPR. Google LLC in the USA is certified for the US-European data protection agreement "Privacy Shield," which ensures compliance with the data protection level applicable in the EU. Further information about Google's privacy policy can be found at: https://www.google.de/policies/privacy/ You can permanently disable cookies for ad preferences by preventing them from being saved by adjusting your browser software settings accordingly or by downloading and installing the browser plug-in available at the following link: https://www.google.com/settings/ads/plugin?hl=en.
Please note that certain functions of this website may not be available or may be limited if you have disabled the use of cookies.

11) WEB ANALYSIS SERVICES

Google (Universal) Analytics
This website uses Google Analytics, a web analysis service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses "cookies," which are text files stored on your computer that enable the analysis of your use of the website. The information generated by the cookie about your use of this website (including the shortened IP address) is usually transmitted to a Google server in the USA and stored there.

This website uses Google Analytics exclusively with the "_anonymizeIp()" extension, which ensures that IP addresses are anonymized by truncation and excludes direct personal reference. With this extension, your IP address is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. In these exceptional cases, this processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in the statistical analysis of user behavior for optimization and marketing purposes.

On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide us with other services related to website and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other data from Google.

You can prevent the storage of cookies by adjusting your browser software accordingly; however, we would like to point out that, in this case, you may not be able to use all the functions of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: [https://tools.google.com/dlpage/gaoptout?hl=en](https://tools.google.com/dlpage/gaoptout?hl=en).

As an alternative to the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent the collection by Google Analytics within this website in the future (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies in this browser, you must click this link again): Deactivate Google Analytics.

Google LLC, based in the USA, is certified for the US-European "Privacy Shield" data protection agreement, which ensures compliance with the data protection level applicable in the EU.

This website also uses Google Analytics for a cross-device analysis of visitor flows, which is carried out via a user ID. When a page is called up for the first time, the user is assigned a unique, permanent, and anonymized ID that is set across devices. This allows interaction data from different devices and from different sessions to be assigned to a single user. The user ID contains no personal data and does not transmit such data to Google.

The collection and storage of data via the user ID can be objected to at any time with effect for the future. To do this, you must disable Google Analytics on all systems you use, for example in another browser or on your mobile device. You can perform the deactivation using a Google browser plugin ([https://tools.google.com/dlpage/gaoptout?hl=en](https://tools.google.com/dlpage/gaoptout?hl=en)). As an alternative to the browser plugin or within browsers on mobile devices, please click on the following link to set an opt-out cookie that will prevent the collection by Google Analytics within this website in the future (this opt-out cookie only works in this browser and only for this domain; if you delete your cookies in this browser, you must click this link again): Deactivate Google Analytics.

Further information on Universal Analytics can be found here: [https://support.google.com/analytics/answer/2838718?hl=en&ref_topic=6010376](https://support.google.com/analytics/answer/2838718?hl=en&ref_topic=6010376).

12) RETARGETING/REMARKETING/REFERRAL ADVERTISING

Facebook Custom Audience via the Pixel Method
This website uses the "Facebook Pixel" from Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA ("Facebook"). With explicit consent, this allows the behavior of users to be tracked after they have seen or clicked on a Facebook ad. This process is used to evaluate the effectiveness of Facebook ads for statistical and market research purposes and can help optimize future advertising measures.

The data collected is anonymous to us, meaning we do not see the personal data of individual users. However, the data is stored and processed by Facebook, allowing a connection to the respective user profile and enabling Facebook to use the data for its own advertising purposes in accordance with the Facebook Data Usage Policy ([https://www.facebook.com/about/privacy/](https://www.facebook.com/about/privacy/)). The data can allow Facebook and its partners to display ads on and off Facebook. For these purposes, a cookie can be stored on your computer. These processing operations are only carried out with explicit consent in accordance with Art. 6(1)(a) GDPR.

Consent to the use of the Facebook Pixel may only be declared by users older than 13 years of age. If you are younger, please ask your guardians for permission.

Facebook Inc., based in the USA, is certified for the US-European "Privacy Shield" data protection agreement, which ensures compliance with the data protection level applicable in the EU.

To disable the use of cookies on your computer, you can set your internet browser to no longer store cookies on your computer in the future or to delete already stored cookies. Disabling all cookies may result in some functions on our website not being executed. You can also disable the use of cookies by third-party providers such as Facebook on the following Digital Advertising Alliance website: [https://www.aboutads.info/choices/](https://www.aboutads.info/choices/).

Google AdWords Remarketing
Our website uses the functions of Google AdWords Remarketing, which allows us to advertise this website in Google search results and on third-party websites. The provider is Google LLC., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). For this purpose, Google sets a cookie in your device's browser, which automatically enables interest-based advertising using a pseudonymous cookie ID and based on the pages you visit. The processing is based on our legitimate interest in the optimal marketing of our website in accordance with Art. 6(1)(f) GDPR.

Further data processing only takes place if you have agreed with Google that your internet and app browsing history is linked to your Google account and information from your Google account is used to personalize ads you view on the web. In this case, if you are logged into Google while visiting our website, Google will use your data together with Google Analytics data to create and define audience lists for cross-device remarketing. For this purpose, your personal data is temporarily linked by Google with Google Analytics data to form target groups.

You can permanently deactivate the setting of cookies for ad preferences by downloading and installing the browser plugin available at the following link: [https://www.google.com/settings/ads/onweb/](https://www.google.com/settings/ads/onweb/).

Alternatively, you can inform yourself about the setting of cookies and make adjustments at the Digital Advertising Alliance website at [www.aboutads.info](http://www.aboutads.info). Finally, you can set your browser to inform you about the setting of cookies and decide individually whether to accept them or exclude the acceptance of cookies for certain cases or in general. Not accepting cookies can limit the functionality of our website.

Google LLC, based in the USA, is certified for the US-European "Privacy Shield" data protection agreement, which ensures compliance with the data protection level applicable in the EU.

Further information and the privacy policy regarding advertising and Google can be viewed here: [https://www.google.com/policies/technologies/ads/](https://www.google.com/policies/technologies/ads/).

13) RIGHTS OF THE DATA SUBJECT

The applicable data protection law grants you comprehensive rights (rights of access) against the controller regarding the processing of your personal data.

13.2 Right to Object

If we process your personal data on the basis of our predominant legitimate interest in the context of a balancing of interests, you have the right to object to this processing at any time for reasons arising from your particular situation, with effect for the future.

If you exercise your right to object, we will stop processing the affected data. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or if the processing serves the assertion, exercise, or defense of legal claims.

If your personal data is processed by us for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes. You can exercise the objection as described above.

If you exercise your right to object, we will stop processing the affected data for direct marketing purposes.

14) DURATION OF STORAGE OF PERSONAL DATA

The duration of the storage of personal data is determined by the respective statutory retention period (e.g., commercial and tax retention periods). After the period expires, the corresponding data is routinely deleted, provided it is no longer necessary for the fulfillment or initiation of the contract and/or there is no legitimate interest in further storage on our part.