Privacy policy | Waldorfshop - waldorf toys and material

Privacy policy

Privacy policy

The protection of your personal data is a high priority for Universnatur GmbH, Waldorfshop, Rankinestraße 4, 86899 Landsberg, Germany. It is important to us to inform you about which personal data we collect, how they are used and what choices you have in this regard. These data protection regulations provide you with answers to the most important questions.

With the following notes, we therefore inform you about which personal data is used by us for which purposes, in which way and for how long. By confirming the data protection information in the order process, you declare your agreement to this.

Who can I contact in case of questions and objections?

Information on the person responsible and data protection officer:
The person responsible pursuant to Art. 4 Para. 7 of the EU Data Protection Basic Regulation (DS-GVO) is
Universnatur GmbH
Rankinestrasse 4
86899 Landsberg am Lech
Phone +49 (0) 8191 - 9369 300

You can reach our data protection officer at or our postal address with the addition "data protection officer".

What personal data is processed for the purchase of products?

If you want to order in our web shop, it is necessary for the conclusion of the contract that you provide your personal data, which we need to process your order. Mandatory information required for the processing of contracts is marked separately with an asterisk (*), further information is voluntary. We process the data provided by you to process your order. For this purpose we can pass on your payment data to our house bank. The legal basis for this is Art. 6 para. 1 p. 1 lit. b DS-GVO.

You can voluntarily create a customer account, through which we can save your data for further purchases at a later date. When you create an account under "My account", the data you provide will be stored revocably. You can change all data of your user account, a deletion of the account is carried out by our customer service at

For the purpose of fulfilling your order, we will forward personal data (including your e-mail address and, if applicable, your telephone number) to a logistics company commissioned by us to ensure that the goods are delivered in accordance with your wishes. The logistics company may contact you in advance of delivery to inform you of the delivery time or to agree delivery details with you. The logistics company will delete the data after delivery.

We are obliged by commercial and tax law to store your address, payment and order data for a period of ten years. After two years, however, we will restrict processing, i.e. your data will only be used to comply with legal obligations.

To prevent unauthorized access to your personal data by third parties, especially financial data, the ordering process is encrypted.

How is a credit check carried out?

In order to be able to offer you several payment options when concluding contracts, we check your creditworthiness for new customers and every four years for existing customers in which there is a justified interest (credit risk through direct debit and direct debit). For this purpose we work together with Creditreform Boniversum GmbH, Hellersbergstraße 11, 41460 Neuss, from whom we receive the necessary data. For this purpose, we transmit your name and contact details to Creditreform Boniversum GmbH. The data protection information according to article 14 can be found here:

The credit inquiry agency for customers from other countries is CRIF GmbH, Kaiserstraße 217, 76133 Karlsruhe,

The data will be stored as long as their knowledge is necessary for the fulfilment of the purpose of storage. In case of verification, the data will be deleted on a daily basis three years after completion.

The decision about your creditworthiness is not based exclusively on automated processing, but is made by employees of our accounting department.

For the duration of your customer relationship, address data and any negative data will be transmitted to the credit agency.

Will I receive further interesting offers and information?

Newsletter and e-mail marketing

We are interested in maintaining the customer relationship with you and in providing you with information and offers. With the following information, we would like to inform you about the contents of our newsletter as well as the registration, dispatch and statistical evaluation procedure and your rights of objection. By subscribing to our newsletter or purchasing products from us, you agree to receive it and to the procedures described.

Content of the newsletter and e-mails

We send personal newsletters containing advertising information (hereinafter "newsletters") only with the consent of the recipients (Art. 6 para. 1 lit. a, 7 DSGVO). We also send personal e-mails and other electronic notifications (hereinafter e-mails) with legal permission (Art. 6 (1) (f) DSGVO, § 7 UWG) to inform you about interesting offers for similar articles.

(1) With your consent you can subscribe to our newsletter, with which we inform you about our current interesting offers. The advertised goods and services are named in the declaration of consent. 
(2) We use the so-called double-opt-in procedure to subscribe to our newsletter. This means that after your registration, we will send you an e-mail to the e-mail address provided, in which we ask you to confirm that you wish to receive the newsletter. We save your IP address and the time of confirmation. The purpose of this procedure is to be able to prove your registration and, if necessary, to clarify any possible misuse of your personal data. 
(3) Your e-mail address is the only mandatory information for sending the newsletter. The provision of further, separately marked data is voluntary and is used to address you personally. After your confirmation we will save your e-mail address for the purpose of sending you the newsletter. The legal basis is Art. 6 Paragraph 1 S. 1 lit. a DS-GVO. 
(4) You can revoke your consent to receive the newsletter at any time and unsubscribe from the newsletter. You can revoke your consent by clicking on the link provided in each newsletter e-mail, via this website form, by e-mail to or by sending a message to the contact details given in the imprint. 

(5) We would like to point out that we evaluate your user behaviour when sending the newsletter. For this evaluation, the e-mails sent contain so-called web beacons or tracking pixels, which represent one-pixel image files. For this analysis, Emarsys links the data specified in § 3 and the web beacons to an individual ID, which is assigned to your user profile in emarsys. We use the data obtained in this way to create a user profile in order to tailor individual newsletter content to your individual interests. In doing so, we record when you open our newsletters, which links you click on, and deduce your personal interests. We link this data to actions you take on our website.

You can object to this tracking at any time by clicking on the separate link provided in each e-mail or by informing us via another contact channel. The information is stored as long as you have subscribed to the newsletter. After you have unsubscribed, we store the data purely statistically and anonymously. Such tracking is also not possible if you have deactivated the display of images in your e-mail program by default. In this case the newsletter will not be displayed completely and you may not be able to use all functions. If you display the images manually, the above-mentioned tracking will take place.

Use of the "emarsys" shipping service provider

The e-mail addresses of our newsletter and e-mail recipients and, if applicable, purchase data are transmitted to Emarsys eMarketing Systems AG, Hans-Fischer-Str 10, 80339 Munich, Germany. In doing so, emarsys uses this information to send and evaluate the newsletter and e-mail on our behalf. However, emarsys does not use the data of our newsletter recipients to write to them itself or pass it on to third parties.

It is important to us to commission a service provider who is based in Germany and processes the data exclusively within the EU.

Double-Opt-In and logging of the newsletter registration

The registration to our newsletter is done in a so-called double opt-in procedure. This means that after registration you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that nobody can register with foreign e-mail addresses.

Newsletter registrations are logged in order to be able to prove the registration process in accordance with the legal requirements (Art. 7 DSGVO). This includes the storage of the time of registration and confirmation as well as the IP address. Any changes to your data stored by emarsys will also be logged.

Registration data of the newsletter

To subscribe to the newsletter, it is sufficient to enter your e-mail address. Optionally we ask you to enter your first and last name. This information is only used to personalize the newsletter.

Sending a notepad

The sending of a personal recommendation by a sender takes place on the legal basis of DSGVO 6 1 f. To this end, your e-mail address, first and last name, sender's name and e-mail address, as well as the information contained on the notepad, are transmitted to Emarsys.

Statistical survey and analyses

The newsletters contain a so-called "web beacon", i.e. a pixel-sized file that is retrieved from the emarsys server when the newsletter is opened. This retrieval process initially involves the collection of technical information, such as information about your browser and system, as well as your IP address and time of retrieval. This information is used for technical improvement of the services based on the technical data or target groups and their reading behavior based on their retrieval locations (which can be determined using the IP address) or access times.

Statistical surveys also include determining whether newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter and e-mail recipients. However, the evaluations serve us much more to identify the reading habits of our users and to adapt our contents to them or to send different contents according to the interests of our users (Art. 6 (1) f DSGVO).

Online access and data management

There are cases where we direct newsletter and e-mail recipients to emarsys websites. For example, our newsletters contain a link that allows newsletter recipients to retrieve the newsletters online (e.g. in the event of display problems in the e-mail program). Similarly, the emarsys data protection statement is only available on their website.

In this context, we would like to point out that cookies are used on emarsys websites and that personal data is processed by emarsys, its partners and the service providers used. We have no influence on this data collection. We would also like to draw your attention to the possibility of objecting to the collection of data for advertising purposes on the websites and (for the European region).


You can cancel the receipt of our newsletter as well as our e-mails with interesting offers at any time, i.e. revoke your consent. Your consent to receive the newsletter via emarsys and the statistical analyses will then cease to apply. You will find a link to cancel the newsletter and e-mails at the end of each newsletter. If you also no longer wish to receive electronic notifications in connection with the processing of your purchase, please have your e-mail address deleted at

We would also like to point out that you can object to the future processing of your personal data at any time in accordance with the legal requirements under Art. 21 DSGVO. The objection can be made in particular against processing for the purposes of direct advertising.

They are entitled to the following rights according to the EU data protection basic regulation:

  • to request information on the categories of data processed, the purposes of processing, any recipients of the data, the planned storage period (Art. 15 DPA);
  • to request the correction or completion of incorrect or incomplete data (Art. 16 FADP);
  • to revoke a granted consent at any time with effect for the future (Art. 7 para. 3 DSGVO);
  • to demand the deletion of data in certain cases within the framework of Art. 17 DSGVO - in particular if the data is no longer required for the intended purpose or is being processed illegally, or you have revoked your consent in accordance with Art. 7 Para. 3 DSGVO or have declared an objection in accordance with Art. 21 DSGVO;
  • under certain circumstances, to demand the restriction of data, insofar as deletion is not possible or the obligation to delete is disputed (Art. 18 DSGVO);
  • to data transferability, i.e. you can receive the data you have provided us with in a standard machine-readable format (CSV) and, if necessary, transfer it to others (Art. 20 DSGVO);
  • complain to the competent supervisory authority about data processing

All requests for information, deletion and correction, requests for information, requests for data transferability or objections to data processing should be sent by e-mail or by post to:

Universnatur GmbH
Rankinestraße 4
86899 Landsberg am Lech

Phone: +49 (0) 8191 9369 300

We would also like to point out that you can object to the future processing of your personal data at any time in accordance with the legal requirements under Art. 21 DSGVO. The objection can be made in particular against processing for the purposes of direct advertising.

Where is my data processed?

Your data is generally processed in Germany. Individual international service providers process the data outside Germany. Should this be the case, we will indicate this directly in the data protection information of the respective provider (see below).

When will my data be deleted?

Your personal data will be deleted, provided that this does not conflict with statutory storage obligations, if you have asserted a deletion claim, if the data is no longer required to fulfil the purpose for which it was stored or if its storage is not permitted for other statutory reasons. You will find more detailed information on the deletion periods in the respective processing procedures and providers.

How do cookies work?

This website uses the following types of cookies, the scope and function of which are explained below:

  • Session Cookies (Transiente Cookies)
  • Browser Cookies (Persistente Cookies)
  • Flash Cookies und HTML5 storage objects

Session cookies are automatically deleted when you close the browser. They store a so-called session ID, with which various requests from your browser can be assigned to the shared session. This allows your computer to be recognised when you return to our website. The session cookies are deleted when you log out or close the browser.

Browser cookies are automatically deleted after a specified period of time, which may vary depending on the cookie. You can delete the cookies in the security settings of your browser at any time.

You can configure your browser settings according to your preferences and, for example, refuse to accept third-party cookies or all cookies. Please note that you may not be able to use all the features of this website.

We use cookies to identify you for subsequent visits if you have an account with us. Otherwise you would have to log in again for each visit.

The Flash cookies used are not registered by your browser, but by your Flash plug-in. We also use HTML5 storage objects, which are stored on your end device. These objects store the required data regardless of the browser you use and have no automatic expiration date. If you do not want Flash cookies to be processed, you must install an appropriate add-on, e.g. "Better Privacy" for Mozilla Firefox ( or the Adobe Flash Killer cookie for Google Chrome. You can prevent the use of HTML5 storage objects by setting your browser to private mode. We also recommend that you regularly delete your cookies and browser history manually.

Social Media

Privacy policy for Facebook plugins (Like-Button)

We currently use Facebook social media plug-ins. We use the so-called two-click solution. This means that when you visit our site, no personal data is initially passed on to the providers of the plug-ins. You can recognize the provider of the plugin by the initial letter or logo on the box. We give you the opportunity to communicate directly with the provider of the plug-in via the button. Only if you click on the marked box and thereby activate it, the plug-in provider will receive the information that you have accessed the corresponding website of our online offer. In the case of Facebook, the IP address is anonymised immediately after it is collected, according to the respective provider in Germany. When the plug-in is activated, your personal data is transmitted to the respective plug-in provider and stored there (with US providers in the USA). Since the plug-in provider collects data in particular via cookies, we recommend that you delete all cookies via your browser's security settings before clicking on the grayed-out box.

We have no influence on the collected data and data processing procedures, nor are we aware of the full scope of data collection, the purposes of processing, the storage periods. We also have no information on the deletion of the collected data by the plug-in provider.

The plug-in provider stores the data collected about you as user profiles and uses this data for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (also for users who are not logged in) for the purpose of presenting need-based advertising and to inform other users of the social network about your activities on our website. You have a right of objection to the creation of these user profiles, whereby you must contact the respective plug-in provider in order to exercise this right. Through the plug-ins we offer you the possibility to interact with the social networks and other users, so that we can improve our offer and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Art. 6 para. 1 sentence 1 lit. f DS-GVO.

The data is passed on regardless of whether you have an account with the plug-in provider and are logged in there. If you are logged in with the plug-in provider, the data we collect from you will be assigned directly to your account with the plug-in provider. If you click on the activated button and, for example, link to the page, the plug-in provider will also save this information in your user account and share it publicly with your contacts. We recommend that you log out regularly after using a social network, but especially before activating the button, as you can then avoid being assigned to your profile with the plug-in provider.

Further information on the purpose and scope of data collection and processing by the plug-in provider can be found in the data protection declarations of these providers, as notified below. There you will also find further information on your rights and settings to protect your privacy.

Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA;
  • "="" style="box-sizing: border-box; background-color: transparent; color: rgb(185, 42, 56);">
  • Facebook has submitted to the EU-US privacy shield:
  • Analysetools

    Privacy policy for econda

    To ensure that this website is designed to meet requirements and to optimise it, anonymised data is collected and stored using solutions and technologies from econda GmbH and user profiles are created from this data using pseudonyms. For this purpose cookies can be used which enable the recognition of an internet browser. However, user profiles are not merged with data about the bearer of the pseudonym without the express consent of the visitor. In particular, IP addresses are rendered unrecognisable immediately after receipt, which makes it impossible to assign user profiles to IP addresses. The analysis of user behaviour is carried out on the basis of Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the anonymous analysis of user behaviour in order to optimise both his website and his advertising. Visitors to this website can object to this data collection and storage for the future at any time here ( The objection applies only to the device and the web browser on which it was set, please repeat the process on all devices if necessary. If you delete the opt-out cookie, requests will be sent to econda again.

    Privacy policy for Google Analytics

    This website uses Google Analytics, a web analysis service of Google Inc. ("Google"). Google Analytics uses "cookies", which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, in the event that IP anonymisation is activated on this website, your IP address will be shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. For the exceptional cases where personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, The legal basis for the use of Google Analytics is Art. 6 para. 1 sentence 1 lit. f DS-GVO.

    Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage for the website operator.

    The IP address transmitted by your browser as part of Google Analytics is not merged with other data from Google.

    You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link:

    This website uses Google Analytics with the extension "_anonymizeIp()". This allows IP addresses to be processed in a shortened form, thus excluding the possibility of personal references. If the data collected about you contains a personal reference, this is immediately excluded and the personal data is immediately deleted.

    We use Google Analytics to analyse and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user.

    Third party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001.

    This website also uses Google Analytics for a cross-device analysis of visitor flows, which is performed using a user ID.

    Dastani Consulting

    We use session cookies to analyse and classify our advertising campaigns. For this purpose, we transmit anonymized data of your purchasing behavior with regard to campaigns to Dastani Consulting GmbH, Im Westpark 8, 35435 Wettenberg. We do this on the basis of Art. 6 (1) f DSGVO.


    Integration of YouTube videos

    We have integrated YouTube videos into our online offering, which are stored at and can be played directly from our website. These are all integrated in "enhanced privacy mode", which means that no data about you as a user is transferred to YouTube if you do not play the videos. Only when you play the videos will the data mentioned below be transferred. We have no influence on this data transfer. By visiting the website, YouTube receives the information that you have visited the corresponding subpage of our website. In addition, the data mentioned below is transmitted. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether no user account exists. If you are logged in at Google, your data will be assigned directly to your account. If you don't want your profile to be associated with YouTube, you must log out before activating the button. YouTube stores your data as user profiles and uses them for purposes of advertising, market research and/or demand-oriented design of its website. Such evaluation is carried out in particular (even for users who are not logged in) for the purpose of providing needs-based advertising and to inform other users of the social network about your activities on our website. You have a right of objection to the creation of these user profiles, whereby you must contact YouTube in order to exercise this right. For more information about the purpose and scope of data collection and processing by YouTube, please see the Privacy Policy. There you will also find further information on your rights and setting options to protect your privacy: Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield,

    Facebook Website Custom Audience

    We use the remarketing service Website Custom Audience from Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA on our website to provide you with targeted information about our products. When you visit our website, a connection between your browser and the Facebook server is established via a tracking pixel created on Facebook and the use of a cookie. Facebook thereby receives the information that you have visited our website with your IP address. This enables Facebook to assign your visit to our pages to your user account. We can use the information thus obtained to display Facebook advertisements. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by Facebook. You can find further information on this in the Datenschutzerklärung von Facebook. If you do not want data collection by Custom Audiences, you can deactivate Custom Audiences hier deaktivieren.

    The website also uses the remarketing function "Custom Audiences" of Facebook Inc. ("Facebook"). This enables users of the website to be presented with interest-related advertisements ("Facebook Ads") when they visit the social network Facebook or other websites that also use the procedure. In this way, we pursue the interest in displaying advertisements that are of interest to you in order to make our website more interesting for you.

    Due to the marketing tools used, your browser automatically establishes a direct connection with the Facebook server. We have no influence on the scope and further use of the data collected by Facebook through the use of this tool and therefore inform you according to our state of knowledge: Through the integration of Facebook Custom Audiences, Facebook receives the information that you have called up the corresponding website of our Internet presence or clicked on an advertisement from us. If you are registered with a Facebook service, Facebook can assign the visit to your account. Even if you are not registered with Facebook or have not logged in, there is a possibility that the provider will find out and save your IP address and other identifying features.

    Disabling the "Facebook Custom Audiences" function is possible for logged-in users at

    The legal basis for the processing of your data is Art. 6 para. 1 sentence 1 letter f DS-GVO. Further information on data processing by Facebook is available at

    Google AdWords

    This website uses tools for "online marketing" from the company Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. This is to recognize that a visitor has come to our website via a Google ad. Google uses cookies, which are stored on your computer and enable an analysis of the use of the website. The cookies for the so-called conversion tracking are set when you click on an advertisement placed by Google. These cookies lose their validity after 30 days and are not used for personal identification. If you wish to prevent conversion tracking, you can set your browser to block cookies from the domain "". You can also exercise your right to opt-out by visiting If you would like more information about this practice and to know your choices about not having this information used by Google, click here:


    In order to display personal product recommendations in the shop and newsletter, we use the service provider Emarsys eMarketing Systems AG, Hans-Fischer-Str 10, 80339 Munich, Germany. For this purpose, a session cookie is set when you enter the shop and your customer behavior on our website is monitored and stored at Emarsys in the form of pseudonymized and anonymized data. You can object to this at any time at

    Data security

    We maintain up-to-date technical and organisational measures to ensure the security of processing, in particular to protect your personal data from risks during data transmission and from third parties gaining knowledge of them. These are adapted to the current state of the art, the need for protection of personal data and the risks to your rights and freedoms.

    Changes to this privacy policy

    The data protection information is regularly checked and updated and is marked for you. You should review it from time to time to stay informed about how we protect your data and continually improve the content of our website. By using the website, you agree to the terms of this notice on the protection of personal data.