Data Protection Facebook

Data protection information

for Facebook site CATRICE COSMETICS

You may know that the EuGH (European Court of Justice) has ruled that Facebook and a Facebook site operator are jointly responsible for the data processing according to the Data Protection Act (EuGH, judgement dated 05.06.2018; further information can be obtained here:

With this Data Protection Policy, we therefore inform you - as far as we are able - about the processing of personal data when using the Facebook site CATRICE cosmetics ("Fanpage").

I. Responsible entity

Jointly responsible for data processing when operating the Fanpage in the context of the GDPR (General Data Protection Regulations) are:

Facebook Ireland Ltd.
4 Grand Canal Square
Grand Canal Harbour Dublin 2



cosnova GmbH
Am Limespark 2
65843 Sulzbach

("cosnova" or "we")

As operator of Fanpage, we have concluded agreements with Facebook regarding the joint responsibility according to the Data Protection Act. The respectively relevant "Page Controller Addendum" is available here:

II. Contact to the data protection controller

You can contact the data protection controller of Facebook here:

Our data protection controller is:
Moritz Görmann, CTM-COM GmbH, Wilhelm-Leuschner-Straße 33, 64380 Roßdorf, Germany, Phone: 06154 - 57605-0, Email: m.goermann(at)

III. Data processing during Fanpage operation

As operator of Fanpage, we use the "Facebook Insights" function provided to us by Facebook. Through Facebook Insights, we receive statistical data from Facebook (e.g. total number of hits, "Like" information, site activities, etc.). This statistic data is transmitted to us only in an anonymised form, i.e. we cannot allocate this data to a certain visitor of our site. We do not have access to the data upon which this statistic is based.

In order for Facebook to be able to provide us with this data, Facebook stores Cookies on your terminal devices which you use to access Fanpage. These Cookies are small text files which contain a clear user code. The Cookies are active for the duration of two years, unless you delete them prior to that time. As far as we know, Facebook uses the data collected by the Cookies to provide you with advertising and to allow companies and advertising partners associated with Facebook to do the same.

Further information regarding the utilisation of Cookies by Facebook is available at:

Further information regarding data processing by Facebook is available in the Data Protection Policy of Facebook:

When you interact with us via Fanpage and particularly when you contact us, we may receive further information from you, e.g. due to comments made by you or private messages, which you send to us via Fanpage.

IV. Purpose of processing

We maintain this Fanpage to make our products more prominent and to communicate with you. For this purpose, we also use the data provided to us through the "Facebook Insights" function. They help us to better understand your interests and to better reach our target group. It allows us to advertise specifically and provide more relevant content on our Fanpage. Further information about us as well products is available at the following website; our Data Protection Policy is available at

Facebook furthermore uses the data collected by Facebook for market research and advertising purposes, therefore particularly to analyse your behaviour, to establish user profiles and to provide personalised advertising (also on behalf of third party companies).

Here, you can use an "opt-out" option and affect the advertising shown to you as a user of the Facebook service in the future: and Further settings can be changed here:

When you interact with us via Fanpage (e.g. to send us a private message), we process any personal data exclusively for the purpose of communication and interaction with you.

V. Data transfer

We do not transfer personal data to other entities. We cannot exclude the transfer and further processing of personal data by Facebook to Facebook Inc. with registered office in the USA or other companies outside of the EU and associated risks for affected persons. Facebook Inc. is certified under the so-called "Privacy Shield" and is thus obligated to comply with European Data Protection Specifications. Information regarding the Facebook Privacy Shield status is available here:

VI. Legal basis

We maintain this Fanpage to make our products more prominent and to interact with you. The personal data is processed based on our legitimate interest according to Art. 6 (1) sentence 1 f GDPR (General Data Protection Regulations) and an effective communication and interaction with the users as well as the optimised presentation of our products and services. We point out the affected person's right of objection in the event of data processing based on Art. 6 (1) sentence 1 f GDPR (see here VII. (f)).

VII. Your rights

You should logically and most effectively assert requests for information and the assertion of further rights as a data subject directly at Facebook as the provider of the platform. In the agreement concluded with us (the page Controller Addendum, see above) it is determined that Facebook is the primary contact entity for the assertion of the following rights as data subject and that Facebook assumes the essential obligations according to the Data Protection Act regarding the information of affected person, regarding data security or regarding the notification of violations of data protection rights. With respect to data processing concerning the Facebook Insights tool, only Facebook possesses the direct information as well as database, from which the data statistics transmitted to us are established. If our support is necessary, you can contact us at any time.

You are entitled to the following rights:

(a) Right of information

Upon request, you are entitled to receive information from us at any time regarding your personal data processed by us in accordance with Article 15 GDPR. For this purpose, you can send an application by mail or email to the address listed below.

(b) Right to the rectification of incorrect personal data

You are entitled to demand the immediate correction of any errors pertaining to your personal data. For this purpose, please contact the address listed below.

(c) Right to erasure

According to the prerequisites specified in Article 17 GDPR, you are entitled to demand the erasure of your personal data. These prerequisites for erasure particularly include if the personal data is no longer necessary for purposes for which it was collected or processed in any other manner, as well as in cases of illegal processing, the existence of an objection or the obligation for erasure according to the laws of the European Union or the laws of the member state governing us. In order to assert your rights, please contact the addresses listed below.

(d) Right to restriction of processing

You are entitled to demand the restriction of processing according to the specifications of Article 18 GDPR. This right exists particularly if the correctness of the personal data is disputed between the user and us, for the duration required to verify the correctness as well as in the event that the user demands deletion instead of restricted usage in case of an existing right to erasure, furthermore in the event that the data is no longer required for the purposes pursued by us, yet the user requires them to assert, exercise or defend legal claims, if the successful execution of an objection between the customer and us is still contested. In order to assert your right of restriction of processing, please contact the addresses listed below.

(e) Right to data portability

You have the right to receive the personal data concerning you, which you have provided to the controller, in a structured, commonly used and machine-readable format according to the specifications of Article 20 GDPR. In order to assert your right of data portability, please contact the addresses listed below.

(f) Right of objection

According to Article 21 GDPR, you have the right to lodge an objection to the processing of your personal data for reasons resulting from your special situation, among other based on Article 6 (1) lit. e) or f) GDPR. We shall cease the processing of your personal data, unless we are able to prove mandatory reasons for the processing worthy of protection, which override your interests, rights and freedoms or if the processing serves to assert, exercise or defend legal claims.

(g) Right of revocation (in the event of a granted consent)

According to Article 7 (3) GDPR, you are entitled to revoke your granted consents effective for the future at any time. By revoking the consent, the legitimacy of the processing occurred based on the consent up to the revocation remains unaffected.

(h) Right to lodge a complaint

You are furthermore entitled to contact the supervisory authority in case of complaints.