All for One - Merch & More Shop

Privacy

 

The All for One Group is very serious about the protection of your personal data and processes it exclusively in accordance with the applicable legal provisions.

In order to fulfil our information obligations in accordance with Art. 13 and 14 GDPR, we are pleased to provide you the following privacy notice:

 

Who is responsible for processing my personal data (data controller)?
All for One Group SE
Rita-Maiburg-Straße 40
70794 Filderstadt-Bernhausen
Germany
Phone: +49 711 788 07-0
E-mail: info@all-for-one.com

 

How can I reach your Data Protection Officer?
All for One Group SE
- attn. Data Protection Officer -
Rita-Maiburg-Straße 40
70794 Filderstadt
Germany
Phone: +49 711 788 07-0
E-mail: datenschutz@all-for-one.com

 

Which of my personal data are processed? For what purposes and on what legal basis is this done?

When you use the internal webshop to order marketing materials (e.g. banners, flyers), we process only the personal data necessary to handle your order. This typically includes:

What is authentication and user data?

User login is handled via Single Sign-On (SSO) using Microsoft Entra ID (formerly Azure Active Directory). Your basic user data (e.g., name, email, department) is synchronized from the company’s Master Data Management system. This ensures up-to-date and secure access management. No additional personal data is collected through the SSO process beyond what is necessary for authentication.

Purpose of processing:

We process this data to enable you to order and receive company marketing materials efficiently. This includes order confirmation, preparation, shipping, and internal documentation.

Legal basis:

The legal basis for processing your data is Article 6(1)(f) GDPR (legitimate interests). Our legitimate interest lies in enabling smooth internal logistics and providing employees with the tools and materials needed for their work.

Because access to webshop is restricted by login, user authentication, we rely on Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures), where necessary to provide access to the service.

Will my personal data be transmitted to third parties?

Your data is only accessible to internal departments responsible for handling orders. And, where necessary, to trusted service providers (e.g., print or shipping vendors) under appropriate data processing agreements under Article 28 GDPR.

How long will my personal data be stored?

Personal data related to your order is stored only as long as necessary for order fulfillment and documentation purposes, unless legal or business documentation obligations require a longer retention period.

What rights do I have as a data subject?

We do not use your survey responses for profiling or automated decision-making. Your privacy is important to us, and you have the following rights under the General Data Protection Regulation (GDPR):

Does automated decision-making take place?

Automated decision-making does not take place.

Changes to this privacy notice.

We regularly update this privacy notice if circumstances arise that make this necessary.

Last update: 29.04.2025