Privacy policy
Data Protection Statement
1) Information on the collection of personal data and contact details of the controller
1.1 Thank you for visiting our website. Below, we provide information on how your personal data is processed when you use our site. Personal data is any data that can be used to identify you personally
1.2 The data controller for this website is EMMA & GRACE. The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (as defined by the EU General Data Protection Regulation —GDPR—).
1.3 This website uses SSL or TLS encryption to protect the transmission of personal data and other confidential information (such as orders or inquiries). You can recognize an encrypted connection by the address bar of your browser starting with “https://” and by the padlock icon.
2) Data collection when visiting our website
When you use our site for informational purposes only (without registering or sending us information), we only collect the data that your browser transmits to our server (so-called “server log files”). These are necessary to display the site and ensure its stability. The following data is collected:
- Page visited
- Date and time of access
- Amount of data transferred (in bytes)
- Page from which you accessed (referrer)
- Browser used
- Operating system used
- IP address used (possibly anonymized)
The processing of this data is based on our legitimate interest in improving the stability and functionality of the site, in accordance with Article 6(1)(f) of the GDPR. No further transfer or use of the data takes place, unless there are concrete indications of unlawful use, in which case the logs may be reviewed at a later date.
3) Cookies
To make our website attractive and enable the use of certain functions, we use cookies (small text files that are stored on your device). Some cookies are deleted at the end of the session (session cookies), while others remain stored to recognize your browser on future visits (persistent cookies). These cookies may collect personal data such as your browser, location, or IP address.
Persistent cookies are automatically deleted after the defined period, which varies depending on the cookie. Some cookies simplify the ordering process (e.g., by saving products in the shopping cart). If cookies process personal data, the processing is based on Article 6(1)(b) of the GDPR (performance of a contract) or Article 6(1)(f) (legitimate interest in optimal site functionality and effective user experience).
We may work with advertising partners who also store cookies on your device when you visit our website (third-party cookies). If this is the case, we will inform you in this policy about their use and scope.
You can configure your browser to notify you about the installation of cookies and decide individually whether to accept them or not. How to configure this varies depending on the browser; please refer to its help menu. Here are some useful links:
Internet Explorer
- Firefox
- Chrome
- Safari
- Opera
If you reject cookies, certain features of the site may not be available.
4) Contact
When you contact us (e.g., via a form or email), we collect your personal data. The data collected is indicated on the corresponding form. We use this data exclusively to respond to your inquiry and manage the related technical aspects. The legal basis for this processing is our legitimate interest in responding (Article 6(1)(f) of the GDPR). If your contact is for the purpose of concluding a contract, the legal basis will also be Article 6(1)(b). Once the matter has been resolved and there are no legal retention obligations, your data will be deleted.
5) Creation of customer accounts and execution of contracts
When you provide us with personal data to enter into a contract or create a customer account, we process it in accordance with Article 6(1)(b) of the GDPR. The required data is indicated on the forms. You can request the deletion of your account at any time by writing to the address mentioned above. Once the contract has been completed or the account deleted, the data will be blocked for tax and commercial reasons and deleted once these periods have expired, unless you give your consent for further use or the law permits it.
6) Use of data for direct marketing
6.1 Newsletter subscription
If you subscribe to our newsletter, we will send you regular offers. We only need your email address; other data is optional and serves to personalize the message. We use the “double opt-in” method, which means that you will receive a confirmation email and only after clicking on the link will we start sending you the newsletter.
By activating the link, you consent to the processing of your data in accordance with Article 6(1)(a) of the GDPR. We record the IP address and time of registration to prevent misuse. You can unsubscribe at any time by using the link in the newsletter or by writing to us at info@emmaandgrace.com. Once you do so, we will remove your address from our list, unless you consent to another use or the law allows it.
6.2 Sending newsletters to existing customers
If you gave us your email address when you made a purchase, we may email you offers for similar products without requiring additional consent. This is based on our legitimate interest in personalized direct marketing, in accordance with Article 6(1)(f) of the GDPR. You can object at any time by writing to us.

