Privacy Policy
Last updated: 04/2026
Table of Contents
- 1. Data Controller and Contact
- 2. Data Protection Officer
- 3. Overview of Data Processing
- 4. Legal Bases for Processing
- 5. Provision of the Online Store
- 6. Customer Account / Registration
- 7. Order Processing and Contract Fulfillment
- 8. Payment Processing
- 9. Shipping and Logistics
- 10. Contact
- 11. Newsletter and Email Marketing
- 12. Cookies and Tracking Technologies
- 13. Web Analytics and Audience Measurement
- 14. Social Media and Advertising
- 15. Reviews and Ratings
- 16. Marketplaces and Sales Channels
- 17. Content Delivery Networks (CDN)
- 18. Hosting and Infrastructure
- 19. Invoicing and Accounting
- 20. International Data Transfers
- 21. Data Retention and Deletion
- 22. Your Rights as a Data Subject
- 23. Automated Decision-Making
- 24. Changes to This Privacy Policy
1. Data Controller and Contact
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:
UNIQS GmbH
Schützenstr. 46
63263 Neu-Isenburg
Deutschland (Germany)
Commercial Register: HRB 52406
Registry Court: Amtsgericht (Local Court) Offenbach am Main
Managing director: Matthäus Wilhelm
VAT ID: DE329891274
Email: you@nakys.one
Phone: +49 (0) 170 803 91 49
Website: https://nakys.one
2. Data Protection Officer
There is currently no legal obligation for our company to appoint a data protection officer. For data protection inquiries, please contact us using the details provided in section 1.
3. Overview of Data Processing
We process personal data of our users and customers to operate our online store, fulfill orders, communicate, conduct marketing activities, and meet legal obligations. Below we provide detailed information about the type, scope, and purpose of data processing.
Types of data processed
- Identity data (e.g., name, address, date of birth)
- Contact data (e.g., email address, phone number)
- Content data (e.g., text entries, reviews, messages)
- Contract data (e.g., subject of contract, order history, term)
- Payment data (e.g., IBAN, credit card data, PayPal ID)
- Usage data (e.g., pages visited, click behavior, access times)
- Meta and communication data (e.g., IP address, device information, browser type)
- Location data (e.g., country, region – where relevant for tax calculation or market selection)
Categories of data subjects
- Customers and purchasers
- Prospects and visitors to the online store
- Newsletter subscribers
- Business partners and suppliers
4. Legal Bases for Processing
We process personal data on the basis of the following legal grounds under the GDPR:
- Art. 6(1)(a) GDPR (Consent) – The data subject has given consent to the processing (e.g., newsletter sign-up, cookies).
- Art. 6(1)(b) GDPR (Contract performance) – Processing is necessary for the performance of a contract or pre-contractual measures (e.g., order processing, customer account).
- Art. 6(1)(c) GDPR (Legal obligation) – Processing is necessary for compliance with a legal obligation (e.g., tax retention requirements).
- Art. 6(1)(f) GDPR (Legitimate interests) – Processing is necessary for the purposes of legitimate interests (e.g., fraud prevention, web analytics, direct marketing to existing customers).
5. Provision of the Online Store
When you access our online store, the following data is automatically collected by the web server (so-called server log files):
- IP address of the requesting device
- Date and time of access
- Name and URL of the requested page
- Referrer URL (previously visited page)
- Amount of data transferred
- Browser type and version
- Operating system
- Screen resolution
- Browser language setting
This data is processed for the technical provision and security of the store. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the proper provision and security of the online store. Server log files are deleted after no more than 30 days, unless further retention is required for evidentiary purposes.
We use SSL/TLS encryption for the operation of our store. You can recognize an encrypted connection by the "https://" prefix in your browser's address bar.
6. Customer Account / Registration
You have the option to create a customer account in our online store. The following data is processed:
- First and last name
- Email address
- Password (stored in encrypted form)
- Shipping address(es)
- Order history
Processing is based on Art. 6(1)(b) GDPR for the provision of the customer account and its associated functions (e.g., order overview, simplified checkout). You can delete your customer account at any time in your account area or by contacting us.
7. Order Processing and Contract Fulfillment
To process your order, we process the following data:
- First and last name
- Billing and shipping address
- Email address
- Phone number (optional, for shipping inquiries)
- Ordered products, quantity, price
- Payment method and, where applicable, payment data
- IP address (for fraud prevention)
The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (tax and commercial retention obligations). Data is deleted after the expiry of statutory retention periods (generally 6 years under § 257 HGB or 10 years under § 147 AO).
Note on discreet packaging: Your order is shipped in neutral, non-transparent packaging with no indication of the contents.
8. Payment Processing
We use the following payment service providers for payment processing. Your payment data is transmitted directly to the respective payment service provider and processed by them. We do not store complete credit card or bank account data.
8.1 Shopify Payments (Stripe)
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Payment methods: Credit card (Visa, Mastercard, American Express), Apple Pay, Google Pay.
Privacy policy: https://stripe.com/privacy
8.2 PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
Payment methods: PayPal, PayPal Express Checkout.
Privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-full
8.3 Mollie (SEPA Direct Debit)
Provider: Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands.
Payment methods: SEPA Direct Debit, possibly additional local payment methods.
Privacy policy: https://www.mollie.com/privacy
The legal basis for sharing your payment data with payment service providers is Art. 6(1)(b) GDPR (contract performance).
9. Shipping and Logistics
To fulfill shipping, we transmit the required data (name, shipping address, and where applicable email address and phone number for parcel notifications) to our contracted shipping service providers.
SendCloud
Provider: SendCloud B.V., Moermanskkade 500, 1013 BC Amsterdam, Netherlands.
SendCloud acts as a shipping platform and data processor pursuant to Art. 28 GDPR. Through SendCloud, we engage various parcel carriers (e.g., DHL, DPD, GLS, Hermes).
Privacy policy: https://www.sendcloud.com/privacy-policy/
The legal basis is Art. 6(1)(b) GDPR (contract performance). Shipping data is deleted after the expiry of statutory retention periods.
10. Contact
When you contact us by email, contact form, telephone, or via social media channels, your information is stored for the purpose of processing the inquiry and for follow-up questions.
- Data processed: Name, email address, message content, phone number (if applicable), order number (if applicable)
- Legal basis: Art. 6(1)(b) GDPR (if the inquiry is related to a contract) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries)
- Deletion: After the inquiry has been fully resolved, unless statutory retention obligations apply
11. Newsletter and Email Marketing
11.1 Newsletter Sign-Up
With your consent (Art. 6(1)(a) GDPR), you can subscribe to our newsletter. We use a double opt-in process: After entering your email address, you will receive a confirmation email with an activation link. You will only be added to our mailing list after clicking this link.
As part of the sign-up, we store:
- Email address
- Date and time of sign-up and confirmation
- IP address at sign-up and confirmation
- Any voluntarily provided additional data (e.g., first name)
You can unsubscribe from the newsletter at any time via the unsubscribe link at the bottom of each email or by contacting us.
11.2 Klaviyo
We use Klaviyo for sending and analyzing our newsletters and marketing emails.
Provider: Klaviyo, Inc., 225 Franklin Street, Boston, MA 02110, USA.
Klaviyo processes your email address, interaction data (opens, clicks), device data, and location data (country/region). This data is used for performance measurement and email personalization.
Klaviyo is certified under the EU-U.S. Data Privacy Framework.
Privacy policy: https://www.klaviyo.com/legal/privacy-notice
11.3 Email Marketing to Existing Customers (§ 7(3) UWG)
If we received your email address in connection with the purchase of goods, we may use it under § 7(3) of the German Unfair Competition Act (UWG) to send you information about similar products. You can object to this use at any time at no cost beyond basic transmission rates. The legal basis is Art. 6(1)(f) GDPR.
12. Cookies and Tracking Technologies
12.1 General Information on Cookies
We use cookies and comparable technologies (e.g., local storage, pixels, fingerprinting) to make our online store functional, improve the user experience, and optimize our marketing activities.
Cookies are small text files stored on your device. We distinguish between:
- Strictly necessary cookies: Required for basic store functions (e.g., shopping cart, language selection, login status). Legal basis: Art. 6(1)(f) GDPR / § 25(2) TDDDG.
- Functional cookies: Store your preferences and enable enhanced features (e.g., size selection, recently viewed products).
- Analytics cookies: Help us understand and improve store usage (e.g., Google Analytics).
- Marketing cookies: Used to display relevant advertising and measure campaign success (e.g., Meta Pixel, Google Ads).
12.2 Consent Management (Cookie Banner / CMP)
On your first visit to our store, a cookie banner is displayed where you can give or refuse consent to non-essential cookies. Your consent decision is saved and can be changed at any time via the "Cookie Settings" link in the store footer.
Legal basis for setting cookies based on your consent: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.
12.3 Shopify Cookies
Our store is based on the Shopify e-commerce platform. Shopify sets the following technically necessary cookies:
- _shopify_s – Session ID, store usage analytics (30 min.)
- _shopify_y – Identify returning visitors (1 year)
- cart – Shopping cart assignment (2 weeks)
- _secure_session_id – Session management (session)
- localization – Country and language selection / Shopify Markets (1 year)
- _tracking_consent – Cookie consent storage (1 year)
12.4 Third-Party Cookies
If you have given your consent via our cookie banner (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG), additional cookies and comparable technologies from the following third-party providers will be set. These cookies are activated only after you have given your consent and can be revoked at any time via the "Cookie Settings" link in the footer of our store.
Cookie | Purpose | Duration
Meta (Facebook / Instagram)
- _fbp | Browser identification for Meta advertising | 90 days
- _fbc | Storage of the click parameter (fbclid) | 90 days
- fr | Targeted advertising display and relevance measurement | 90 days
TikTok
- _ttp | Browser identification for TikTok advertising | 13 months
- tt_appInfo | Device recognition for TikTok Ads | Session
- tt_pixel_session_index | Session counter for TikTok Pixel | Session
- _pin_unauth | Identification of non-logged-in users for Pinterest advertising | 365 days
- _pinterest_ct_ua | Grouping of user actions for conversion tracking | 365 days
- _epik | Attribution of clicks on Pinterest ads | 365 days
- _derived_epik | Derived click attribution when cookie access is restricted | 365 days
Google (Analytics & Ads)
- _ga | Distinguishing individual users in Google Analytics | 2 years
- ga[ID] | Session state storage in Google Analytics 4 | 2 years
- _gid | Distinguishing individual users (short-term) | 24 hours
- _gcl_au | Storage of conversion data for Google Ads | 90 days
13. Web Analytics and Audience Measurement
13.1 Google Analytics 4
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google Analytics uses cookies and similar technologies to analyze your usage behavior on our website.
IP anonymization: Google Analytics 4 anonymizes your IP address by default before it is stored.
Data processed: Page views, time on page, scroll depth, click behavior, device type, location (country/city), referrer, conversions (e.g., completed purchases).
Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).
Opt-out: You can opt out of data collection by Google Analytics by installing the browser add-on: https://tools.google.com/dlpage/gaoptout
Google is certified under the EU-U.S. Data Privacy Framework. Privacy policy: https://policies.google.com/privacy
13.2 Shopify Analytics
Shopify provides us with integrated analytics tools that evaluate sales data, visitor statistics, and conversion rates. This processing takes place on Shopify servers as part of our store platform. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in analyzing and optimizing our store).
14. Social Media and Advertising
We use various tracking technologies on our website to measure the success of our advertising campaigns, build audiences, run remarketing campaigns, and optimize conversions. These technologies are **activated only with your prior consent** (Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG). You can revoke your consent at any time with effect for the future via the "Cookie Settings" link in the footer of our store or through the cookie consent tool integrated there.
14.1 Meta Pixel (Facebook / Instagram)
Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 N2V9, Ireland ("Meta").
Description and Purpose: With your consent, we use the Meta Pixel on our website. The Meta Pixel is a
JavaScript code that loads a tracking pixel (1×1 pixel graphic) when you visit our web pages and sets cookies on your device. This enables Meta to track that and when you visited our website and performed certain actions (e.g., page view, product viewed, added to cart, purchase completed). We use this information to: measure the success of our advertisements on Facebook and Instagram (conversion tracking), create audiences for future ads (Custom Audiences, Lookalike Audiences), show you relevant advertisements on Facebook and Instagram (remarketing/retargeting), optimize the delivery of our ads.
Data processed: IP address (truncated), cookie IDs (in particular _fbp, _fbc), HTTP header information (browser type, operating system, language setting), page views and actions performed (events), timestamps, Facebook click ID (fbclid), device information, referrer URL. If you are logged into Facebook or Instagram, Meta may associate this data with your user account.
Joint controllership (Art. 26 GDPR): For the collection and transmission of data via the Meta Pixel, we and Meta are joint controllers within the meaning of Art. 26 GDPR. We have entered into an agreement on joint controllership with Meta (the "Controller Addendum"), available at https://www.facebook.com/legal/controller_addendum. This agreement stipulates
that Meta assumes responsibility for fulfilling data subject rights under Art.
15–20 GDPR with respect to data stored by Meta. You may also exercise your
rights towards us; we will forward your request to Meta if necessary.
Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).
Third-country transfer: Meta may transfer personal data to Meta Platforms, Inc. in the USA. Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework (DPF) (see https://www.dataprivacyframework.gov/). Additionally, Meta has implemented
Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Opt-out and further information: Adjust cookie settings in the footer of our store Facebook advertising preferences: https://www.facebook.com/adpreferences Meta
Privacy Policy: https://www.facebook.com/privacy/policy
14.2 Google Ads / Google Remarketing
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Description and Purpose: With your consent, we use Google Ads Conversion Tracking. When you reach our website through a Google ad, a cookie is set on your device. This cookie enables us and Google to determine whether you performed a specific action on our website (e.g., purchase, sign-up). In addition, remarketing features may be used to show you customized advertisements on websites within the Google Display Network and in Google Search.
Data processed: IP address, cookie IDs (_gcl_au, _gac), ad click information (gclid), page views and actions performed (events), device and browser information, timestamps, referrer URL.
Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).
Third-country transfer: Google Ireland Limited may transfer data to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF).
Opt-out and further information: Adjust cookie settings in the footer of our store
Google Ads settings: https://adssettings.google.com
Browser add-on to disable Google Analytics: https://tools.google.com/dlpage/gaoptout
Google Privacy Policy: https://policies.google.com/privacy
14.3 TikTok Pixel
Provider: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland ("TikTok")
Description and Purpose: With your consent, we use the TikTok Pixel on our website. The TikTok Pixel is a JavaScript code that uses cookies and comparable technologies on your device to capture your browsing behavior on our website. This enables us to: measure the success of our advertisements on TikTok (conversion tracking), create audiences for future ads (Custom Audiences), show you relevant advertisements on TikTok (remarketing/retargeting), optimize the delivery of our ads. Additionally, we use the TikTok Events API (server-side transmission) to improve measurement accuracy. Conversion data is also transmitted to TikTok server-side.
Data processed: IP address, cookie IDs (_ttp), HTTP header information (browser type, operating system, language setting), page views and actions performed (events such as PageView, ViewContent, AddToCart, Purchase), timestamps, TikTok click ID (ttclid), device information, referrer URL. With Advanced Matching enabled, additionally hashed email address and phone number where applicable.
Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).
Third-country transfer: TikTok Technology Limited may transfer personal data to servers outside the EEA, in particular to the USA and Singapore. TikTok is not certified under the EU-U.S. Data Privacy Framework (DPF). For data transfers to third countries, TikTok relies on Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR as well as supplementary technical and organizational measures (including under TikTok's European data security initiative "Project Clover," which provides for the storage and processing of European user data in European data centers).
Note: In April 2025, the Irish Data Protection Commission (DPC) found that TikTok had breached Art. 46(1) GDPR in relation to previous data transfers to China. TikTok has since implemented technical and organizational measures (including Project Clover). We continuously monitor regulatory developments and will update this Privacy Policy as necessary.
Opt-out and further information: Adjust cookie settings in the footer of our store TikTok Privacy Policy (EEA): https://www.tiktok.com/legal/privacy-policy-eea
14.4 Pinterest Tag
Provider: Pinterest Europe Limited, Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest").
Description and Purpose: With your consent, we use the Pinterest Tag on our website. The Pinterest Tag is a JavaScript code snippet consisting of a Base Code (on all pages) and Event Codes (on specific pages) that use cookies and comparable technologies on your device. This enables us to: measure the success of our advertising campaigns on Pinterest (conversion tracking), track which actions users perform on our website after clicking on a Pinterest ad, create audiences for future ads (Actalike Audiences, retargeting lists), show you relevant advertisements on Pinterest (remarketing/retargeting), optimize the delivery of our ads. Pinterest uses an algorithm to analyze browsing behavior and can subsequently display targeted product recommendations as personalized advertising banners on the user's Pinterest account. Pinterest may combine the information collected via the Tag with additional information that Pinterest has collected through other websites and/or in connection with the use of the social network "Pinterest," thereby creating pseudonymized user profiles.
Data processed: IP address, cookie IDs (_pin_unauth, _pinterest_ct_ua, _epik, _derived_epik), HTTP header information (browser type, operating system, language setting), page views and actions performed (events such as PageVisit, ViewCategory, AddToCart, Checkout), timestamps, Pinterest click ID (epik), device information, referrer URL. With Enhanced Match enabled, additionally hashed email address where applicable.
Joint controllership (Art. 26 GDPR): For the collection and transmission of data via the Pinterest Tag, we and Pinterest are joint controllers within the meaning of Art. 26 GDPR. Pinterest provides a Joint Controller Addendum as part of the Advertising Services agreement.
Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).
Third-country transfer: Pinterest Europe Limited may transfer personal data to Pinterest, Inc. in the USA. Pinterest, Inc. is certified under the EU-U.S. Data Privacy Framework (DPF) (see https://www.dataprivacyframework.gov/). Additionally, Pinterest has implemented Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.
Note: We recommend verifying the DPF certification status of Pinterest at https://www.dataprivacyframework.gov/, as this status may change.
Opt-out and further information:
Adjust cookie settings in the footer of our store
Pinterest privacy settings: https://www.pinterest.com/settings/privacy
Pinterest Privacy Policy: https://policy.pinterest.com/en/privacy-policy
14.5 Social Media Presence
We maintain online presences on various social networks to communicate with prospective customers, existing customers, and users, and to inform them about our products. We are currently present on the following platforms:
Instagram (@nakyscondom) – Operator: Meta Platforms Ireland Limited
Facebook – Operator: Meta Platforms Ireland Limited
TikTok (@nakys.official) – Operator: TikTok Technology Limited
Pinterest – Operator: Pinterest Europe Limited
LinkedIn – Operator: LinkedIn Ireland Unlimited Company
Joint controllership (Art. 26 GDPR): When you visit one of our social media pages, we and the operator of the respective platform are jointly responsible for the data processing triggered thereby
(Art. 26 GDPR). This concerns in particular the collection and evaluation of
so-called Insights data (page statistics). The primary data processing is
carried out by the respective platform.
For our Facebook Page, we have entered into an agreement with Meta pursuant to Art. 26 GDPR regarding joint controllership for the processing of Insights data (the "Page Insights Controller Addendum," available at https://www.facebook.com/legal/terms/page_controller_addendum).
Your rights: You may exercise
your data subject rights (access, deletion, objection, etc.) both towards us
and towards the respective platform operator. We wish to point out that,
despite joint controllership, we do not have complete influence over data
processing by the platform operators.
Third-country transfer: We wish to
point out that your data may also be processed outside the European Economic Area. For details on data processing by the respective platform, please refer to the privacy policies of the platform operators:
Meta: https://www.facebook.com/privacy/policy/
TikTok: https://www.tiktok.com/legal/privacy-policy-eea
Pinterest: https://policy.pinterest.com/en/privacy-policy
LinkedIn: https://www.linkedin.com/legal/privacy-policy
15. Reviews and Ratings
Judge.me
We use Judge.me for collecting and displaying product reviews.
Provider: Judge.me, Inc., 115 W 18th St, Suite 2R, New York, NY 10011, USA.
When submitting a review, your name (or pseudonym), rating (star rating and text), any uploaded photos/videos, and your email address are processed.
Legal basis: Art. 6(1)(a) GDPR (consent through voluntary submission) and Art. 6(1)(f) GDPR (legitimate interest in authentic product reviews). Privacy policy: https://judge.me/privacy
16. Marketplaces and Sales Channels
In addition to our own online store, we sell our products through third-party marketplaces (e.g., Amazon, Otto, and additional platforms connected via ChannelEngine). The processing of your data on these platforms is governed by the privacy policies of the respective marketplace operator.
ChannelEngine
Provider: ChannelEngine B.V., Leidsevaart 558, 2014 HN Haarlem, Netherlands.
ChannelEngine acts as a data processor pursuant to Art. 28 GDPR and synchronizes order, product, and customer data between the marketplaces and our Shopify store.
Privacy policy: https://www.channelengine.com/privacy-policy
17. Content Delivery Networks (CDN)
Shopify CDN / Cloudflare
Our online store uses Shopify's content delivery network (CDN), which is partly based on Cloudflare. Your IP address is transmitted to the CDN servers. The legal basis is Art. 6(1)(f) GDPR.
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, is certified under the EU-U.S. Data Privacy Framework. Privacy policy: https://www.cloudflare.com/privacypolicy/
18. Hosting and Infrastructure
Shopify
Our online store is hosted on the Shopify platform.
Provider: Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
Shopify processes all data arising in connection with the operation of the store as a data processor pursuant to Art. 28 GDPR.
Shopify is certified under the EU-U.S. Data Privacy Framework. Privacy policy: https://www.shopify.com/legal/privacy
Email Hosting (IONOS)
Our business email accounts are hosted by IONOS.
Provider: IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
IONOS processes personal data contained in emails as a data processor pursuant to Art. 28 GDPR. Servers are located in Germany.
Privacy policy: https://www.ionos.de/terms-gtc/datenschutzerklaerung/
19. Invoicing and Accounting
19.1 Sufio
We use Sufio for automated invoice generation.
Provider: Sufio s.r.o., Bratislava, Slovakia.
Sufio receives the data required for invoicing as a data processor pursuant to Art. 28 GDPR.
Privacy policy: https://www.sufio.com/privacy-policy/
19.2 DATEV / Tax Advisor
To fulfill our tax obligations, we transmit accounting-relevant data (invoices, credit notes, payment data) to our tax advisor and DATEV eG, Paumgartnerstr. 6-14, 90329 Nuremberg, Germany. The legal basis is Art. 6(1)(c) GDPR (legal obligation).
20. International Data Transfers
Some of the service providers we use are based in countries outside the European Economic Area (EEA), in particular in the USA. Where these countries do not have a level of data protection comparable to the EU, we ensure through appropriate safeguards that your data is adequately
protected:
EU-U.S. Data Privacy Framework (DPF): The following US-based service providers are certified under the DPF (EU Commission adequacy decision pursuant to Art. 45 GDPR, Decision C(2023) 4745):
Stripe, Inc. (payment processing), Google LLC (Analytics, Ads), Meta Platforms, Inc. (Meta Pixel), Klaviyo, Inc. (email marketing), Cloudflare, Inc. (CDN), Shopify Inc. (store platform), Pinterest, Inc. (Pinterest Tag), Judge.me, Inc. (reviews).
Standard Contractual Clauses (SCC): Where no DPF certification exists or as an additional safeguard, we enter into the Standard Contractual Clauses approved by the EU Commission (Art. 46(2)(c)
GDPR). This applies in particular to: TikTok Technology Limited (no DPF; SCCs + supplementary measures under Project Clover).
Supplementary measures: Where necessary, additional technical and organizational measures (e.g., encryption, pseudonymization) are implemented to ensure an adequate level of protection.
Note: We regularly verify the certification status of our service providers under the DPF (https://www.dataprivacyframework.gov/) and update this Privacy Policy
accordingly in the event of changes.
21. Data Retention and Deletion
We store your personal data only for as long as is necessary for the respective processing purposes or as required by statutory retention periods:
- Contract / order data: 10 years after end of contract (§ 147 AO, § 257 HGB)
- Invoices and accounting records: 10 years (§ 147 AO, § 257 HGB)
- Business correspondence: 6 years (§ 257 HGB)
- Contact inquiries: After resolution + 3 years (statute of limitations)
- Newsletter consent records: 3 years after unsubscription
- Server log files: 30 days
- Customer account data: Until account deletion + statutory retention periods
After expiry of the respective period, data is routinely deleted or anonymized.
22. Your Rights as a Data Subject
Under the GDPR, you have the following rights, which you may exercise at any time by contacting the controller listed in section 1:
22.1 Right of Access (Art. 15 GDPR)
You have the right to obtain information about the personal data we process about you.
22.2 Right to Rectification (Art. 16 GDPR)
You have the right to request the correction of inaccurate or completion of incomplete personal data.
22.3 Right to Erasure (Art. 17 GDPR)
You have the right to request the deletion of your personal data, provided no statutory retention obligation applies.
22.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request the restriction of processing of your data.
22.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive the data you have provided to us in a structured, commonly used, and machine-readable format.
22.6 Right to Object (Art. 21 GDPR)
You have the right to object at any time to the processing of your personal data based on Art. 6(1)(f) GDPR.
Objection to direct marketing: If we use your data for direct marketing, you may object to the processing at any time.
22.7 Right to Withdraw Consent (Art. 7(3) GDPR)
You have the right to withdraw any consent given at any time with effect for the future.
22.8 Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for us is:
The Hessian Commissioner for Data Protection and Freedom of Information
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
Phone: +49 611 1408-0
Website: https://datenschutz.hessen.de
You may also contact the supervisory authority of your habitual residence or place of work.
23. Automated Decision-Making
We do not use fully automated decision-making processes within the meaning of Art. 22 GDPR. Should we use automated procedures in individual cases (e.g., for fraud prevention in payments), we will inform you separately and take the legally required measures.
24. Changes to This Privacy Policy
We reserve the right to amend this privacy policy to reflect changes in legal requirements, technical developments, or changes to our data processing activities. The current version is always available on this page. In case of material changes affecting your rights, we will notify you separately (e.g., by email or through a notification in the store).