Data Protection

Privacy Policy of Leica Camera AG

Using the website leica-camera.com involves the processing of personal data (hereinafter simply “data”). Because the protection of our users’ privacy is important to us, we would like to inform you which personal data we collect when you use the website and the associated services as well as the purposes for which we process the data.

With a view to protecting the privacy of your end devices (computer or mobile device), we will also provide you with information about storage and access to information on your end device via cookies or similar technologies.

1. Controller / Contact Details

Leica Camera AG
Am Leitz-Park 5
35578 Wetzlar
Germany

Email: data-protection@leica-camera.com

Should you have any questions or suggestions regarding data protection or this Privacy Policy, or if you would like to contact us to assert your rights, please use the above-mentioned contact details when submitting your query.

2. Data Protection Officer

You can contact our data protection officer at: DPO@leica-camera.com.

3. Automated Data Processing

When accessing our website, your end device automatically transmits certain data for technical reasons, which is required to establish the connection and access the queried and embedded contents (e.g., shopping cart, texts, images, videos and product information as well as data provided for downloading). This comprises:

  • the IP address or device ID allocated to the respective end device
  • the type of end device in question
  • browser type/version
  • the operating system used
  • the visited website
  • the previously visited website (referrer URL)
  • the date and time of the server query
  • the HTTP status code

The collection and subsequent processing is intended to deliver the contents of our website and make the functions and services associated with our website available to you.

We store this data for the following purposes:

  • to ensure the security of our IT systems, e.g., to defend against specific attacks on our systems and to detect attack patterns
  • to ensure the proper operation of our IT systems, e.g., when faults occur which we can only resolve by storing the IP address
  • for law enforcement, hazard prevention or prosecution if there is specific evidence of crimes

The data is processed on the basis of our overriding legitimate interests specified above; Art. 6 para. 1(f) of the General Data Protection Regulation (GDPR).

We store this data for a period of 14 days. We then delete or anonymize this data, including the IP addresses.

The data is only stored for a longer period when there are specific indications to warrant a justified suspicion of unlawful use which necessitates an additional review and processing of the data for this reason.

4. Hosting

We use the services provided by Amazon Web Services EMEA S.a.r.l., 38 avenue John F. Kennedy, L-1855 (“AWS”) based in Luxembourg and Profihost GmbH, Expo Plaza 1, 30539 Hannover, Germany (“Profihost”) for the hosting and operation of our website. AWS and Profihost process your personal data on our behalf, i.e., exclusively in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).

5. Data Processing When Visiting the Website and the Related Functions and Services

We process your personal data to provide the functions available when using the website and the associated functions and services.

When you use specific functions in connection with the website or define any settings such as search and filter functions, place products in the shopping cart or select a language, we will process the information you provided and the settings you defined in order to provide these functions.

The processing is required in order to provide you with the requested functions. The legal basis for the respective data processing is Art. 6 para. 1(b) GDPR.

You can create an account in order to use additional functions of the website and associated services such as product registration.

6.1 Registration/Login

When registering your account, you must provide the following information:

  • country and language
  • your first and last name
  • your email address
  • your chosen password

You can also specify your preferred salutation (optional).

We process mandatory information:

  • to create and manage your account for you
  • to provide you with the functions and services associated with the account
  • to prevent and uncover cases of fraud in connection with the account

You will neither be able to create an account nor use the functions and services associated with the account if you do not provide this information. The legal basis for the processing is Art. 6 para. 1(b) GDPR. Processing is required to execute the contractual relationship with you.

We process the information you provide on a voluntary basis so that we can use your preferred salutation when responding to queries you submit. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.

We also process the data related to the login to authenticate your login. We have a legitimate interest in ensuring that only authorized persons have access to the respective account, Art. 6 para. 1(f) GDPR.

6.2 Using and Managing the Account

You can also provide additional information in your account. For example, you can supplement, amend and manage:

  • your profile (title, address, date of birth, (mobile) phone number, professional ties to photography and alternative [delivery] addresses)
  • your interests regarding specific topics, such as photography interests, Leica products and events as well as Leica Camera Stores and their events for which you would like to receive related information
  • information regarding products you use that were made by other companies
  • your preferences and consent settings for receiving advertising communication and the corresponding processing (item 19)

We process your personal data to manage your account for you, provide the full range of functions available with your account and store the consent settings you provide. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.

6.3 Product Registration

You can also register and manage your Leica products in your account to make it easier to retrieve firmware updates, instructions and supplemental information on your product.

To register a product, you have to:

  • select the product you wish to register (model designation)
  • enter the product’s serial number

Optionally, you can add the date of purchase and include a comment.

The processing of mandatory information is required to register the product. Moreover, we process this data, including the optional information provided, to provide you with a comprehensive overview of your camera and sport optics portfolio and to allow you to manage your account, Art. 6 para. 1(b) GDPR.

6.4 Erasing Your Data

We generally save your personal data for the duration of the usage relationship. The data is deleted when you delete your account. 

If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.

If you submit an order to us or book tickets for a Leica Akademie event, we will process your data for the receipt and processing of your order or booking.

7.1 Order or Booking as a New Customer / Registration

You must provide the following information in order to submit an order to us or book a ticket for a Leica Akademie event:

  • your salutation
  • your first and last name
  • your address including country
  • your phone number
  • your email address

You must also select a password if you also wish to create a Leica customer account along with your order or booking. However, you do not need an account to place the order.

If you want your order to be delivered to a different delivery address, we will also need additional information about the recipient:

  • salutation
  • first and last name
  • address including country

You can also add the company and department.

In addition, you have the option of providing your date of birth and the name of your company, including VAT ID (sales tax number).

7.2 Order or Booking as a Current Customer

If you are already registered as a customer of ours, we use the information provided in your account to fulfill the order or booking you place.

7.3 Data Collection from a Third Party

Your personal data will be provided to us by the orderer in the event that you are the recipient of a product but did not place the order, or if tickets for a Leica Akademie event are for you but were booked by a third party.

7.4 Reservation and Pick-up (Click & Collect) in a Leica Store

You can also designate your order for pick-up at a Leica Store. To do so, you must also select the Leica store at which you want to reserve and pick up your product.

For this purpose, we transfer the data provided during your reservation to the store you selected. This comprises:

  • your first and last name
  • your address
  • your email address
  • your phone number
  • your reservation data: product, price, quantity and item number

7.5 Using and Managing the Leica Customer Account

You can also provide additional information in your account and use the functions and services provided there. For example, you can:

  • supplement, amend and manage your delivery and invoice address and your preferred payment method
  • manage your e-shop vouchers
  • view your order history and the status of your current orders
  • download booked Leica Akademie tickets

7.6 Purposes and Legal Basis for Processing

To fulfill the contract, it is necessary to process mandatory information, including the processing of data collected for the product order concerning deviating delivery addresses and optional address supplements, as well as of data required for the reservation. We will also process the corresponding data related to your order or booking for this purpose. In particular, this includes invoice, product and booking data as well as the customer and order number. The above-mentioned data is also processed for managing returned items as well as contract terminations and withdrawals. The legal basis for this is Art. 6 para. 1(b) GDPR.

In the event that you decide to sign up for a Leica customer account when making an order or booking, we process the above-mentioned data:

  • to create and manage your account for you
  • to provide you with the functions and services associated with the account
  • to prevent and uncover cases of fraud in connection with the account

The legal basis for the processing is Art. 6 para. 1(b) GDPR. Processing is required to execute the contractual relationship with you.

Your date of birth is processed to verify your legal capacity and this processing is based on our legitimate interest in verifying your legal capacity (Art. 6 para. 1(f) GDPR).

We process data related to a recipient other than the orderer or deviating participants of Leica Akademie events that we collect for product orders or ticket bookings in order to execute the order as instructed. This also constitutes our legitimate interest as per Art. 6 para. 1(f) GDPR.

7.7 Erasing Your Data

Where the data is processed for the fulfillment and processing of orders or bookings and/or the provision of the account, the data is erased following the complete fulfillment of the contract and/or following the expiration of the statutory warranty obligations or contractual guarantee or, with respect to the Leica customer account, when you delete this account.

If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.

8. Payments

You have the option of choosing between several payment methods for orders and bookings of Leica Akademie events. We use the services provided by various payment service providers to process payments.

The respective service providers are responsible for processing your data and may forward your data to credit agencies in order to verify your identity and perform a credit check; they may also pass on your data to other third parties or service providers for their own purposes. Further information on the processing of your data can be found in the privacy policies issued by the various service providers, which we link to below.

8.1 Payments via PayPal

 “Direct to PayPal” is a service of PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg (“PayPal”). You can find the PayPal Privacy Statement at www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=en_en.

If you use the “Direct to PayPal” function, your data that is required for the forwarding to your PayPal account and the execution of the payment process is automatically transmitted to PayPal. This data is:

  • your IP address
  • the total amount of your order and/or booking
  • reference to the PayPal account

If you have entered your PayPal account, your email address assigned to the PayPal account can also be accessed via PayPal. PayPal will then transmit the required data regarding your order and/or booking to us for processing. Therefore, PayPal provides us with the following data:

  • your first and last name
  • your invoice and/or delivery address, as needed

Moreover, PayPal will inform us whether the payment has been completed properly.

8.2 Payments via Google Pay

“Pay with Google Pay” is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). You can find Google’s Privacy Policy for Google Pay at https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice&ldl=en.

When you use the “Pay with Google Pay” function, we will transfer the data required for forwarding to your Google Pay account to Google. This data includes:

  • your IP address
  • the date, time and amount of the transaction
  • the dealer’s location and description
  • a description of the purchased products and/or booked Leica Akademie events or test drives
  • your email address, as needed

When you make a payment via Google Pay, Google provides us with the following data:

  • your email address
  • information on the payment method
  • your first and last name
  • your delivery address

Moreover, Google will inform us whether the payment has been completed properly.

8.3 Payments via Credit Card, ONEY and Apple Pay

If you choose to pay for your orders and/or bookings by credit card, or where available via ONEY (Oney Bank S.A. RSC Lille Metropole 546 380 197; BP6 - 59895 Lille cedex 9, France) or Apple Pay (Apple, Inc., 1 Apple Park Way, Cupertino, CA 95014, USA), we will use the services provided by our payment service provider Adyen B.V., Simon Carmiggeltstraat 6 - 50, 1011 DJ Amsterdam, Netherlands (“Adyen”) for payment processing and to credit any refunds to your account.

You can find further information on the processing of your data in Adyen’s Privacy Statement at https://www.adyen.com/policies-and-disclaimer/privacy-policy. The privacy policies for Apple Pay is available at https://www.apple.com/legal/privacy/data/en/apple-pay/.

Adyen collects and processes your payment data in order to process the payment. For this purpose, we automatically forward the data required for the payment method you have selected to Adyen. For payment via ONEY and Apple Pay, these are: 

  • your salutation
  • your first and last name
  • your billing and delivery address
  • your telephone number
  • products purchased
  • purchase amount and currency
  • time of login and 
  • your IP address

If you have opted to pay via credit card, we transmit the following data to Adyen:

  • your IP address
  • purchase amount
  • payment ID
  • your credit card data – this is encrypted during collection by Adyen so that we do not have access to this data at any time
  • your customer number and
  • your email address

Adyen will inform us whether the payment has been completed properly.

8.4 Payments via Findomestic

If available in the checkout process, you have the option to make your payment via Findomestic (financing IT), a service of Findomestic Banca S.p.A. Firenze via Jacopo da Diacce-to 48, 50129, Firenze, Italy ("Findomestic"). Findomestic's privacy notice can be found at https://www.findomestic.it/servizi/privacy.shtml

We will transfer the following data to Findomestic:

  • your first and last name
  • your Tax ID
  • your email address and
  • your date of birth

Findomestic will inform us whether the payment has been completed properly.

8.5 Payments via Scalapay (“pay in 3 installments”)

If available in the checkout process, you have the option to make your payment via Scalapay, a service of Scalapay S.r.l, Via Giuseppe Mazzini 9, 20123 Milano, Italy (“Scalapay”). Scalapay’s privacy policy is available at https://www.scalapay.com/privacy?country=EN.

We will transfer the following data to Scalapay:

  • your first and last name
  • your billing and delivery address
  • product purchased
  • purchase amount and currency and
  • your IP address

Scalapay will inform us whether the payment has been completed properly.

8.6 Purposes and Legal Basis

The data must be processed for the purpose of contract fulfillment, in particular payment processing, including the processing of any chargebacks, Art. 6 para. 1(b) GDPR. 

8.7 Erasing Your Data

Data that is processed for the fulfillment and processing of orders and/or bookings (including payment processing) is erased following the complete fulfillment of the contract or following the expiry of the statutory warranty obligations or contractual guarantee. 

If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored. 

9. Financing

If you have opted for purchase price financing when ordering, we will forward your: 

  • first and last name
  • address including country
  • the purchase price details

to our financing partner, Novuna Personal Finance, which trades under the name Mitsubishi HC Capital UK PLC, Thorpe Road, Staines-upon-Thames, Surrey, TW18 3HP, United Kingdom (“Novuna”) in order to verify and process your financing application. The European Commission has adopted an adequacy decision for the UK in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection. 

Novuna processes your data on its own responsibility and may forward your data to credit agencies in order to verify your identity and perform a credit check; it may also pass on your data to other third parties or service providers for its own purposes. Further information on the processing of your data is available in Novuna’s Privacy Policy at https://www.novuna.co.uk/privacy-policy/.

The data must be processed in order to execute the order in connection with financing of the purchase price, Art. 6 para. 1(b) GDPR.

Data that is processed for the fulfillment and processing of orders is erased following the complete fulfillment of the contract or following the expiry of the statutory warranty obligations or contractual guarantee. 

If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored. 

10. Fraud Prevention

We analyze the information provided by our customers during the booking as well as the technical information transferred from your end device to protect ourselves against fraudulent bookings. 

When doing so, we use the services provided by Adyen B.V., Simon Carmiggeltstraat 6 – 50, 1011 DJ Amsterdam, Netherlands (“Adyen”). Adyen processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).

The processing is required to safeguard our legitimate interest in preventing and uncovering fraud, Art. 6 para. 1(f) GDPR. 

We will erase this data following the complete fulfillment of the contract or following the expiry of the statutory warranty obligations or contractual guarantee. If the data is required for a longer period for statutory reasons or for the (potential) safeguarding, asserting or enforcing of legal rights (see item 31), it will continue to be stored.

11. Personal Consultation (Speak to Leica Experts) and Test Drive

You have the opportunity to book a personal consultation with one of our Leica Experts and / or to participate in our test drive covering various Leica systems.

11.1    Personal Consultation, including Test Drive Consultation

You must provide the following information if you wish to book a personal consultation with one of our Leica Experts:

•    your preferred time slot (date and time)
•    your first and last name
•    your email address
•    the desired type of contact (via Microsoft Teams, by phone or in person in one of our Leica stores)
•    if you wish to be contacted by telephone, your telephone number; in other cases, the tele-phone number is optional,
•    the planned purpose of consultation
•    your level of experience in photography

In addition, you can provide optional information on the camera or camera system you are currently using.
We use the Calendly service provided by Calendly LLC, 271 17th St NW Ste 1000, Atlanta, Georgia, 30363, USA (“Calendly”) for booking the appointment. Calendly processes your personal data on our behalf and in accordance with our instructions (see Art. 4 no. 8 and Art. 28 GDPR).
Your personal data are processed in the US. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-U.S. Data Privacy Framework, which serves as the basis for data transfers to certified companies and organizations in the US. Calendly is a certified company under the Data Privacy Framework. 
The processing of your personal data is required to book the personal consultation, Art. 6 para. 1(b) GDPR.

11.2    Forwarding of Data to Leica National Subsidiaries and Leica Stores

We transfer the personal data necessary to book and conduct the personal consultation that you have requested to the respective Leica national subsidiary or Leica stores that are responsible for the performance of the personal consultation. Such transfer of your personal data is necessary for the booking and performance of your personal consultation, Art. 6 para. 1(b) GDPR.
For personal consultations in the United Kingdom, Ireland, and the Channel Islands, we forward your data to Leica Camera Ltd., 6–8 James Street, 4th floor, London, W1U 1ED, United Kingdom. The European Commission has adopted an adequacy decision for the UK in line with Art. 45 para. 1 GDPR, which states that the United Kingdom ensures an adequate level of data protection. 

11.3    Performance of the Personal Consultation

If you book a consultation via phone or an in-person consultation in one of our Leica stores, we will process your personal data to contact you and conduct the consultation.
For online consultation, we use Microsoft Teams, a service provided by Microsoft Ireland Operations Ltd., One Microsoft Court, South County Business Park, Leopardstown, Dublin 18, D18 DH6k, Ire-land („Microsoft”). Microsoft transfers personal data to the US, in particular to the Microsoft Corpora-tion, and to third countries not covered by an adequacy decision of the European Commission. The European Commission has adopted an adequacy decision in line with Art. 45 para. 1 GDPR for the EU-U.S. Data Privacy Framework, which serves as the basis for data transfers to certified compa-nies and organizations in the US. Microsoft Corporation is a certified company under the Data Priva-cy Framework. In other cases, Microsoft will use standard data protection clauses approved by the European Commission as per Art. 46 para. 2(c) GDPR to ensure an adequate level of data protec-tion.

When using Microsoft Teams, we process:

•    your first and last name, 
•    your email address, 
•    your password, 
•    your IP address, 
•    other information about your end device, 
•    the meeting ID and, as needed, other access data, 
•    the start and end times of your participation as well as
•    the topic of the online meeting 

In addition, you have the option of providing further data, including a profile image. 
If you use the chat or questions function during the consultation, we will process the text you input to display the text during the consultation. The data from your end device’s microphone and, if applica-ble, the images from the video camera of your end device will be processed for the duration of the consultation in order to allow the display of videos and the playback of audio. However, you can turn off or mute the camera or microphone yourself at any time via the applications provided by Microsoft Teams.
Reports on the online meetings (meeting metada