Privacy Policy

Privacy Policy

Controller

The controller within the meaning of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA) for the processing of personal data on this website is the operator of Winissimo (hereinafter referred to as "we" or "Winissimo"). If you have any questions regarding data protection, you can contact us at any time at the following email address: [email protected].

This privacy policy informs you about what personal data we collect, how we process it, and what rights you have under the UK GDPR and the DPA.

General Information on Data Processing

Personal data means any information relating to an identified or identifiable natural person. We generally process personal data of our users only to the extent necessary to provide a functional website as well as our content and services. Processing is regularly carried out only with the consent of the data subject or on the basis of a legal permission, in particular under UK GDPR Art. 6(1)(a) (consent), (b) (contract performance), (c) (legal obligation), or (f) (legitimate interest).

Collection and Storage of Personal Data

3.1 When Visiting the Website

When you access our website winissimo.co, the browser used on your device automatically sends information to our website's server. This information is temporarily stored in a log file. The following information is collected without any action on your part and stored until automated deletion:

  • IP address of the requesting.
  • Date and time of.
  • Name and URL of the retrieved file.
  • Website from which access was made (referrer URL).
  • Browser used and, if applicable, the operating system of your device as well as the name of your access.

The legal basis for the temporary storage of data and log files is UK GDPR Art. 6(1)(f). Our legitimate interest lies in ensuring the smooth operation of our website and guaranteeing system security.

3.2 Registration and User Account

If you register an account with Winissimo, we collect the data required for account creation, such as your name, email address, and password. The processing of this data is carried out for the performance of a contract with you or for the implementation of pre-contractual measures pursuant to UK GDPR Art. 6(1)(b).

3.3 Payment Processing

To process payments on our platform, we work with external payment service providers. In the United Kingdom, these typically include providers for credit and debit card payments (Visa, Mastercard), Apple Pay, Google Pay, PayPal, and bank transfers. As part of payment processing, we transmit the data necessary for contract performance (e.g, name, billing address, payment amount) to the respective payment service provider. The legal basis for this is UK GDPR Art. 6(1)(b). The respective payment service providers process the data partly as independent controllers and are subject to their own privacy policies.

Cookies and Comparable Technologies

Our website uses cookies. These are small text files that are stored on your device. We distinguish between technically necessary cookies, which are required for the operation of the website (legal basis: UK GDPR Art. 6(1)(f)), and optional cookies, such as for analysis or marketing purposes, which are only set with your prior consent (legal basis: UK GDPR Art. 6(1)(a)). You can adjust or revoke your consent at any time via our cookie consent tool.

Contacting Us

If you contact us via email at [email protected] or via a contact form, the data you provide (e.g, name, email address, message text) will be stored by us for the purpose of processing your inquiry and in case of follow-up questions. The legal basis for processing is UK GDPR Art. 6(1)(b) if the inquiry is related to a contract, and otherwise UK GDPR Art. 6(1)(f) based on our legitimate interest in answering inquiries.

Transfer of Data to Third Parties

Your personal data will only be transferred to third parties if this is necessary for the performance of the contract, if we are legally obliged to do so, or if you have given your explicit consent. This particularly concerns:

  • IT service providers and hosting providers who supply us with technical.
  • Payment service providers for processing.
  • Accountants and authorities in the context of statutory reporting.

We conclude data processing agreements pursuant to UK GDPR Art. 28 with service providers that process personal data on our behalf.

Data Transfer to Third Countries

If data is transferred to service providers outside the United Kingdom or the European Economic Area, we ensure that an adequate level of data protection is guaranteed, such as through adequacy regulations or the use of standard contractual clauses pursuant to UK GDPR.

Storage Period

We store personal data only for as long as is necessary to fulfill the respective purposes or as required by statutory retention periods, in particular under UK company and tax laws, which may stipulate retention periods of up to six years. After these periods expire, the data is routinely deleted.

Your Rights as a Data Subject

You have the following rights against Winissimo under the UK GDPR:

RightLegal Basis
Right of accessUK GDPR Art. 15
Right to rectificationUK GDPR Art. 16
Right to erasure ("right to be forgotten")UK GDPR Art. 17
Right to restriction of processingUK GDPR Art. 18
Right to data portabilityUK GDPR Art. 20
Right to objectUK GDPR Art. 21
Right to withdraw consentUK GDPR Art. 7(3)

To exercise these rights, an informal notification to [email protected] is sufficient.

Right to Object to Direct Marketing

If we process your data to operate direct marketing, you have the right to object at any time to the processing of your personal data for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct marketing.

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes the UK GDPR. The supervisory authority responsible for us is the Information Commissioner's Office (ICO) in the United Kingdom, which you can contact to submit a complaint.

Data Security

When you visit the website, we use the widespread TLS (Transport Layer Security) encryption system. In addition, we take appropriate technical and organisational measures pursuant to UK GDPR Art. 32 to protect your data against accidental or intentional manipulation, partial or total loss, destruction, or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

Automated Decision-Making and Profiling

Automated decision-making within the meaning of UK GDPR Art. 22, which produces legal effects concerning you or similarly significantly affects you, does not generally take place at Winissimo. Should this be the case in individual instances, we will inform you separately.

Protection of Minors

Our services are not directed at persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that such data has been collected without the required parental consent, it will be deleted immediately.

Currency and Modification of this Privacy Policy

This privacy policy is currently valid and has the status of July 2026. Due to the further development of our website and offers or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. You can always find the current privacy policy on our website.

Contact

For questions, suggestions, or to exercise your rights, please contact:

Winissimo

E-Mail: [email protected].