Privacy Policy
1) Information about the collection of personal data and contact details of the controller
1.1 We are pleased that you are visiting our website and thank you for your interest. Below we inform you about how we handle your personal data when you use our website. Personal data means any data that can be used to identify you personally.
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
RAYL-Group GmbH
Sennhofweg 22B, 4310 Rheinfelden, Switzerland
Tel.: +41 79 430 72 49
Email: shop@bongiovibrand.com
1.3 For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognize an encrypted connection by “https://” and the lock symbol in your browser’s address bar.
2) Data collection when you visit our website
When you use our website for information purposes only, we collect only the data your browser transmits to our server (“server log files”):
pages visited
date and time of access
amount of data transferred
referrer URL
browser type and version
operating system
IP address (possibly in anonymized form)
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stability and security of the website). Data is generally not shared. However, we reserve the right to review the log files retrospectively if there are concrete indications of unlawful use.
3) Cookies and consent management
3.1 We use cookies and similar technologies to provide certain functions and to analyze the use of the website. Cookies are small text files stored on your device. There are session cookies and persistent cookies.
3.2 If cookies are not technically necessary, we use them only with your consent (Art. 6(1)(a) GDPR). Technically necessary cookies are used on the basis of Art. 6(1)(f) GDPR (legitimate interest in a functional website) or Art. 6(1)(b) GDPR if required for contract performance.
3.3 You can change or withdraw your consent at any time via the cookie consent tool provided on the website.
3.4 You can also manage and delete cookies via your browser settings. If cookies are disabled, the functionality of the website may be limited.
4) Contacting us
If you contact us (e.g., via contact form or email), we process the personal data you provide to handle your request.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in handling inquiries). If the contact is aimed at concluding a contract, Art. 6(1)(b) GDPR also applies.
Your data will be deleted once your request has been conclusively processed, unless legal retention obligations prevent this.
5) Customer account and contract processing
If you open a customer account or place an order, we process personal data for contract performance (Art. 6(1)(b) GDPR).
You can delete your customer account at any time. After full processing and in accordance with statutory retention periods, data will be blocked and then deleted.
6) Direct advertising / newsletter
6.1 Newsletter with consent (double opt-in)
When you sign up for the newsletter, we process your email address for sending the newsletter. Sending takes place only with your consent (Art. 6(1)(a) GDPR) and confirmation via double opt-in. For documentation, we store the time and IP address of registration.
You can unsubscribe at any time (link in the newsletter or by message to the contact address). After unsubscribing, your email address will be removed from the mailing list unless another legal basis applies.
6.2 Newsletter to existing customers
If you provided your email address when purchasing, we may send you offers for similar products (Art. 6(1)(f) GDPR – legitimate interest). You can object at any time.
7) Data processing for order fulfillment
7.1 For delivery, we pass necessary data to shipping service providers (Art. 6(1)(b) GDPR). For payment processing, we pass payment data to payment service providers (Art. 6(1)(b) GDPR).
7.2 Payment service providers (examples – keep only if actively used)
Klarna (identity/credit checks possibly with consent during checkout)
PayPal
Stripe
The privacy policies of the respective providers apply.
8) Transfers to third countries
If we use providers that process data outside the EEA (e.g., USA), this takes place only in compliance with legal requirements (e.g., EU standard contractual clauses and additional safeguards) pursuant to Art. 46 GDPR and, where required, based on your consent (Art. 6(1)(a) GDPR).
9) Social media / plugins
If social plugins or embedded third-party content (e.g., social networks) are used, a connection to the providers’ servers may be established when a page is accessed. Personal data (e.g., IP address) may be transmitted.
Where required, this occurs only with your consent via the cookie consent tool (Art. 6(1)(a) GDPR).
10) Embedded videos (e.g., YouTube)
When videos are embedded, cookies may be set and data processed. Where required, this occurs only with your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time via the consent tool.
11) Online marketing (e.g., Google Ads / remarketing)
If we use online marketing or tracking technologies (e.g., Google Ads conversion tracking, remarketing), this will be done—where required—only with your consent (Art. 6(1)(a) GDPR).
You can withdraw your consent at any time via the consent tool.
12) Rights of data subjects
You have the following rights:
access (Art. 15 GDPR)
rectification (Art. 16 GDPR)
erasure (Art. 17 GDPR)
restriction (Art. 18 GDPR)
data portability (Art. 20 GDPR)
objection (Art. 21 GDPR)
withdrawal of consent (Art. 7(3) GDPR)
complaint to a supervisory authority (Art. 77 GDPR)
13) Right to object
If we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object at any time for reasons arising from your particular situation.
If data is processed for direct marketing, you may object at any time to processing for direct marketing purposes.
14) Storage duration
We store personal data only as long as necessary for the respective purposes or as long as statutory retention obligations exist.
Data processed on the basis of consent is stored until consent is withdrawn unless another legal basis applies.
