Privacy Policy
1. Information on the Collection of Personal Data and Contact Details of the Controller
1.1
We are pleased that you visit our website and thank you for your interest. Below, we inform you about how we handle your personal data when using our website. Personal data refers to all data that can personally identify you.
1.2
The controller responsible for data processing on this website in accordance with the EU General Data Protection Regulation (GDPR) is:
Johanna Urbais
Solsaemro 48gil, 17-22
Seoul, South Korea
Tel.: +821092814024
Email: mdclshop@gmail.com
The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
2. Data Collection When Visiting Our Website
When using our website for informational purposes only, we collect only data that your browser transmits to our server (so-called “server log files”). When you access our website, we collect the following data, which is technically necessary to display the website to you:
-
Visited website
-
Date and time of access
-
Amount of data sent in bytes
-
Referrer URL (the page from which you came)
-
Browser used
-
Operating system used
-
IP address (possibly anonymized)
Processing is based on Art. 6(1)(f) GDPR, based on our legitimate interest in improving the stability and functionality of our website. We reserve the right to retrospectively review server log files if there are concrete indications of unlawful use.
Hosting Services by a Third Party
A third-party provider hosts and displays the website on our behalf, processing data on its servers. The service provider is based in the USA, and the processing is governed by the EU standard contractual clauses.
By using our website, you consent to allow third parties to process your IP address to determine your location for currency conversion. You also consent to storing this currency in a session cookie (temporary cookie removed after closing your browser). This ensures selected currency remains consistent while browsing our website.
3. Cookies
To make the visit to our website attractive and enable certain functions, we use cookies—small text files stored on your device.
-
Session cookies: Deleted after closing your browser
-
Persistent cookies: Remain on your device, enabling us or our partners (third-party cookies) to recognize your browser on your next visit
Cookies may process personal data for contractual purposes (Art. 6(1)(b) GDPR) or to safeguard our legitimate interest in website functionality (Art. 6(1)(f) GDPR).
You can configure your browser to notify you of cookie placement and to accept or reject cookies. Browser-specific instructions can be found here:
Please note that declining cookies may limit the functionality of our website.
4. Web Analytics
Our website uses Google Analytics, a web analytics service from Google Inc. (“Google”), which uses cookies to analyze your use of the website. Information generated by these cookies, including your IP address, is transmitted to and stored on Google servers in the USA.
Google uses this information to evaluate website usage, compile reports for website operators, and provide other services related to website and internet usage. Google may also transfer this information to third parties if legally required or if third parties process it on Google’s behalf. Google will not associate your IP address with other data held by Google.
You can prevent cookies from being installed by adjusting your browser settings, but this may limit full use of website functions.
Social Media Plugins
We use social plugins from Facebook, Twitter, Pinterest, and Instagram. When you visit a page containing such a plugin, your browser connects directly to the provider’s servers, transmitting information (including your IP address). If logged in, the provider may associate your visit with your account. Interactions, such as likes or shares, are also transmitted and stored.
For privacy policies and options of these providers, see:
You can prevent plugin tracking by logging out of social networks before visiting our website or using browser add-ons like NoScript (link).
5. Contact
When you contact us (e.g., via contact form or email), personal data is collected. Data collected through contact forms is used solely to respond to your inquiry and for related technical administration.
The legal basis is our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR). If your contact aims to conclude a contract, the legal basis is additionally Art. 6(1)(b) GDPR. Data will be deleted after your inquiry has been fully processed, unless legal retention obligations exist.
6. Data Processing for Order Fulfillment
6.1 Third-Party Service Providers
For order processing, we work with service providers who may receive necessary personal data for contract execution.
-
Shipping companies receive data required to deliver the order
-
Payment providers receive data needed for payment processing
The legal basis is Art. 6(1)(b) GDPR.
6.2 Payment Providers
-
PayPal: Payment data is shared with PayPal (Europe) S.a.r.l. et Cie, Luxembourg, only as necessary for payment processing. Credit checks may be performed based on legitimate interest (Art. 6(1)(f) GDPR). More info: PayPal Privacy
-
Stripe: Payment is processed by Stripe Payments Europe Ltd, Dublin, Ireland. Order and payment information is shared only for processing purposes. More info: Stripe Privacy
You can object to data processing by these providers, but they may still process your data as necessary for payment execution.
7. Rights of Data Subjects
7.1 You have the following rights under GDPR:
-
Right of access (Art. 15 GDPR)
-
Right to rectification (Art. 16 GDPR)
-
Right to erasure (Art. 17 GDPR)
-
Right to restriction of processing (Art. 18 GDPR)
-
Right to notification (Art. 19 GDPR)
-
Right to data portability (Art. 20 GDPR)
-
Right to withdraw consent (Art. 7(3) GDPR)
-
Right to lodge a complaint (Art. 77 GDPR)
7.2 Right to Object
You may object at any time to processing based on our legitimate interest (Art. 6(1)(f) GDPR) for reasons related to your particular situation. We will stop processing unless compelling legitimate grounds exist or processing serves legal claims.
You may also object to processing for direct marketing purposes at any time.
8. Data Retention
Personal data is stored according to legal retention periods (e.g., commercial or tax law). After this period, data is routinely deleted unless required for contract fulfillment or if a legitimate interest for further storage exists.