Privacy Policy
1. Data Controller
Mt.Nailzone
Thi Minh Thu Nguyen
Rosenhof 21, 09111 Chemnitz
Telefon: 0176 404 186 86
E-Mail: info@mt-nailzone.de
2. General Information on Data Processing
This privacy policy explains what personal data we collect when you visit our website, for what purpose and on what legal basis we process it, and what rights you have. The applicable regulations are the General Data Protection Regulation (DSGVO/GDPR), the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
3. Hosting
This website is hosted on a dedicated server provided by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen, Deutschland
Server location: Falkenstein/Vogtland, Germany. Technical maintenance and hosting are provided by Develojo. A data processing agreement (AVV) pursuant to Art. 28 DSGVO exists between Mt.Nailzone and the hosting provider.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in the stable and secure provision of our website).
4. Server Log Files
The hosting provider automatically collects the following data in server log files when you visit our website, as transmitted by your browser:
- IP address of the requesting device
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (page accessed)
- HTTP status code
- Amount of data transferred
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
Purpose: Ensuring system security and stability, error analysis and optimization of the service.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest).
Retention period: Server log files are automatically deleted after 30 days.
5. SSL/TLS Encryption
This site uses SSL or TLS encryption for security reasons. You can recognize an encrypted connection by the fact that the address line of the browser changes from 'http://' to 'https://' and by the lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
6. Cookies
This website uses cookies. Cookies are small text files that are stored on your device and sent back to our website by your browser on your next visit.
Required Cookies
We use a technically necessary cookie to store your cookie settings (cc_cookie). This cookie is required for the website to function and cannot be deactivated.
- Name: cc_cookie
- Purpose: Storing your cookie settings / consent decision
- Retention period: 182 Tage
- Legal basis: § 25 Abs. 2 TDDDG
Optional Cookies (Google Maps)
If you consent to the 'Maps' category, additional cookies from Google will be set in connection with the embedded Google Maps map. These cookies are only loaded after your explicit consent.
- Legal basis: Art. 6 Abs. 1 lit. a DSGVO i.V.m. § 25 Abs. 1 TDDDG
You can adjust your cookie settings at any time:
7. Google Maps
We use the Google Maps mapping service to display our location on the website. The map is only loaded after your explicit consent via our cookie banner (two-click solution).
When the map is activated, the following data is transmitted to Google:
- Your IP address
- Browser type and version
- Location-related information
- Usage data
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent). Consent can be revoked at any time via the cookie settings.
Data transfer to the USA: Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF).
For more information, please refer to the Google Privacy Policy.
8. Fonts (locally hosted)
This website uses the fonts Outfit and Playfair Display. The fonts are hosted locally on our own server. No connection is made to external servers (e.g. Google). No data is transmitted to third parties.
9. Contact by Phone
If you contact us by phone (e.g. to book an appointment or for consultation), we process the resulting data (phone number, time of call, conversation content such as name and appointment request) to handle your inquiry.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of pre-contractual measures or contract fulfillment) and Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in processing customer inquiries).
Retention period: Data from contact inquiries is deleted as soon as it is no longer required for the purpose. For business relationships, statutory retention periods apply (up to 10 years under HGB/AO).
10. Social Media (Links)
Our website contains links to our profiles on Instagram and TikTok. These are simple hyperlinks, not social media plugins or embedded content. No data is transmitted to these platforms when our website is displayed. Only when you actively click on a link are you redirected to the respective platform, where their own privacy policies apply.
11. Contact via Messenger (WhatsApp & Instagram)
If you contact us via WhatsApp or Instagram direct message, we process the data you provide (e.g. name or profile name, phone number, message content, requested appointment) to handle your request. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin, Ireland. Data may also be transferred to Meta servers in the USA; Meta is certified under the EU-US Data Privacy Framework (EU Commission adequacy decision of July 2023). When you send a message, Meta also processes data (including metadata) on its own responsibility, over which we have no control; Meta's privacy policy applies in addition. If you wish to avoid this transfer, please use an alternative contact channel (phone or e-mail).
Legal basis: Art. 6(1)(b) GDPR (initiation/performance of an appointment) or (f) GDPR (efficient communication); for the transfer to the USA Art. 45 GDPR (adequacy decision EU-US Data Privacy Framework).
Retention period: We delete the data as soon as your request has been fully handled and no statutory retention obligations apply.
12. Display of customer reviews
On our website we show selected customer reviews (e.g. from Google), partly with first name/initials, review text and possibly a profile picture. This content is stored and served statically from our own server; there is no live connection to Google when the page loads. Where personal data of reviewers is processed, we rely on our legitimate interest in displaying genuine customer feedback.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in transparency and trust).
13. Your Rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 DSGVO): You have the right to request information about your personal data processed by us.
- Right to rectification (Art. 16 DSGVO): You may request the correction of inaccurate or the completion of incomplete data.
- Right to erasure (Art. 17 DSGVO): You may request the deletion of your personal data, provided there are no statutory retention obligations.
- Right to restriction of processing (Art. 18 DSGVO): You may request the restriction of processing of your data, e.g. if you dispute the accuracy of the data.
- Right to data portability (Art. 20 DSGVO): You have the right to receive the data concerning you in a common, machine-readable format.
- Right to object (Art. 21 DSGVO): You may object to the processing of your data at any time, provided the processing is based on Art. 6 Abs. 1 lit. f DSGVO.
- Right to withdraw consent (Art. 7 Abs. 3 DSGVO): You may revoke any given consent (e.g. for cookies/Google Maps) at any time with effect for the future, without affecting the lawfulness of processing carried out on the basis of the consent before its revocation.
To exercise your rights, you may contact us at any time using the contact details provided above.
14. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the DSGVO (Art. 77 DSGVO).
The supervisory authority responsible for us is:
Sächsische Datenschutz- und Transparenzbeauftragte
Dr. Juliane Hundert
Devrientstraße 5
01067 Dresden
Telefon: 0351 / 85471-101
www.datenschutz.sachsen.de
15. Currency of this Privacy Policy
Last updated: Juni 2026
This privacy policy is updated as needed, for example when changes are made to our data processing or new legal requirements arise.