Privacy Policy
Last updated: May 18, 2026
1. Controller
The controller responsible for data processing on this website is:
Helfenstein Commerce GmbHAdelheidstraße 4/5
30171 Hannover, Germany
Phone: +49 xxx xxx xxx
Email: contact@helfensteincommerce.com
VAT ID: DE326888020
For data protection inquiries, please contact: privacy@helfensteincommerce.com
2. General Information on Data Processing
We process personal data of our users only insofar as necessary to provide a functional website, our content, and our services. Processing is generally only carried out with the user's consent, except where prior consent cannot be obtained for factual reasons and processing is permitted by law.
3. Legal Basis
The legal basis for processing personal data is:
- Art. 6 (1) (a) GDPR — Consent
- Art. 6 (1) (b) GDPR — Contract performance
- Art. 6 (1) (c) GDPR — Legal obligation
- Art. 6 (1) (f) GDPR — Legitimate interests
4. Data We Collect
a) Server Log Files: IP address, browser type, operating system, referrer URL, time of access. Stored for 7 days for security.
b) Account Data: Name, email, shipping address, phone number, order history.
c) Payment Data: Processed by third-party payment providers (Stripe, PayPal, Klarna). We do not store credit card details.
d) Cookies: See Cookie Policy section below.
e) Newsletter: Email address (with double opt-in consent).
5. Recipients of Data
We share data with:
- Shipping providers (DHL, DPD, UPS)
- Payment providers (Stripe, PayPal, Klarna)
- Email marketing platform (Mailchimp/Klaviyo)
- Analytics providers (only with consent)
- Hosting provider (within EU)
All processors are GDPR-compliant via Data Processing Agreements (Art. 28 GDPR).
6. International Transfers
Data is processed primarily within the EU/EEA. Any transfers to third countries are based on Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Retention Periods
- Order data: 10 years (German tax law requirement)
- Account data: Until account deletion + 30 days
- Newsletter: Until unsubscribe
- Server logs: 7 days
- Cookies: As specified in Cookie Policy
8. Your Rights Under GDPR
You have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction (Art. 18 GDPR)
- Data Portability (Art. 20 GDPR)
- Object (Art. 21 GDPR)
- Withdraw Consent (Art. 7 (3) GDPR)
- Lodge a complaint with a supervisory authority
Supervisory Authority for Lower Saxony:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
9. Cookies
We use cookies to provide essential functions and, with your consent, for analytics and marketing. You can manage your cookie preferences at any time via the "Cookie Settings" button in the footer.
Categories:
- Necessary (always active): Session, cart, security
- Functional: Language, preferences
- Analytics: Google Analytics (anonymized IP)
- Marketing: Meta Pixel, Google Ads
10. Newsletter
We use the double opt-in process. After signing up, you receive a confirmation email. You can unsubscribe at any time via the link in every email.
11. Contact Form
Data submitted via the contact form is used solely to respond to your inquiry. Stored for 6 months unless required longer for legal reasons.
12. SSL Encryption
This site uses SSL/TLS encryption to protect the transmission of confidential content.
13. Changes to This Policy
We reserve the right to update this policy. Last updated date will reflect any changes.