Privacy policy

––––––––––––––––––––
Privacy Policy
––––––––––––––––––––


1) Introduction and Contact Details of the Controller
1.1 We are pleased that you are visiting our website and thank you for your interest. In the following, we inform you about the handling of your personal data when using our website. Personal data refers to any data by which you can be personally identified.
1.2 The controller responsible for data processing on this website, within the meaning of the General Data Protection Regulation (GDPR), is Andreas Döbler, shwasy, Schlengendeich 18, 21107 Hamburg, Germany, Tel.: 015144922906, E-Mail: info@shwasy.de. The controller responsible for the processing of personal data is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.

2) Data Collection When Visiting Our Website
2.1 In the case of purely informational use of our website—that is, if you do not register or otherwise transmit information to us—we collect only the data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time of access
- Amount of data sent in bytes
- Source/reference from which you accessed the page
- Browser used
- Operating system used
- IP address used (possibly in anonymized form)
The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR on the basis of our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to subsequently review the server log files should there be concrete indications of unlawful use.
2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries sent to us), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the padlock symbol in your browser's address bar.

3) Hosting & Content Delivery Network
For the hosting of our website and the display of its content, we utilize a service provider that delivers its services—either directly or through selected subcontractors—exclusively via servers located within the European Union.
All data collected on our website is processed on these servers.
We have entered into a data processing agreement with this provider, which ensures the protection of our visitors' data and prohibits its unauthorized disclosure to third parties.

4) Cookies
To enhance the user experience on our website and enable the use of specific features, we employ cookies—small text files that are stored on your device. Some of these cookies are automatically deleted once you close your browser (known as "session cookies"), while others remain on your device for a longer period, allowing for the storage of site preferences (known as "persistent cookies"). In the latter case, you can determine the storage duration by consulting the cookie settings overview within your web browser.
Insofar as individual cookies deployed by us involve the processing of personal data, such processing is carried out in accordance with Art. 6 Para. 1 lit. b GDPR for the performance of a contract; in accordance with Art. 6 Para. 1 lit. a GDPR where consent has been granted; or in accordance with Art. 6 Para. 1 lit. f GDPR to safeguard our legitimate interests in ensuring the optimal functionality of the website and providing a user-friendly and effective browsing experience.
You can configure your browser settings to notify you whenever cookies are being placed, allowing you to decide on their acceptance on a case-by-case basis, or to generally refuse the acceptance of cookies—either for specific instances or across the board.
Please note that if you choose not to accept cookies, the functionality of our website may be limited.

5) Contacting Us
When you contact us (e.g., via contact form or email), personal data is processed solely for the purpose of handling and responding to your inquiry, and only to the extent necessary for that purpose.
The legal basis for the processing of this data is our legitimate interest in responding to your inquiry, in accordance with Art. 6 Para. 1 lit. f GDPR. If your inquiry is aimed at entering into a contract, the additional legal basis for the processing is Art. 6 Para. 1 lit. b GDPR. Your data will be deleted once it can be inferred from the circumstances that the matter in question has been conclusively resolved, provided that no statutory retention obligations preclude such deletion.

6) Data Processing for Order Fulfillment
6.1 Insofar as is necessary for the fulfillment of the contract for delivery and payment purposes, the personal data collected by us will be passed on to the commissioned transport company and the commissioned financial institution in accordance with Art. 6 Para. 1 lit. b GDPR.
If, on the basis of a corresponding contract, we owe you updates for goods with digital elements or for digital products, we process the contact data you submitted during the order process (name, address, email address) in order to personally inform you—via a suitable communication channel (e.g., by post or email) and within the legally prescribed timeframe—about upcoming updates, in fulfillment of our statutory information obligations pursuant to Art. 6 Para. 1 lit. c GDPR. In this context, your contact data is used strictly for the specific purpose of providing notifications regarding updates owed by us and is processed by us for this purpose only to the extent necessary to provide the respective information.
To process your order, we also collaborate with the service provider(s) listed below, who assist us—either wholly or partially—in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
6.2 Use of Payment Service Providers (Payment Services)
- PayPal

This website offers one or more online payment methods provided by the following provider: PayPal (Europe) S.a.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.
If you select a payment method from this provider that requires you to make an upfront payment, the payment data you provided during the order process (including your name, address, bank and payment card details, currency, and transaction number), as well as information regarding the contents of your order, will be transmitted to the provider in accordance with Art. 6 Para. 1 lit. b of the GDPR. In such cases, the transmission of your data takes place exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.
If you select a payment method where we provide the upfront payment (i.e., we extend credit to you), you will also be asked during the order process to provide certain personal data (first and last name, street name and house number, postal code, city, date of birth, email address, telephone number, and—where applicable—details regarding an alternative payment method).
In such cases, in order to safeguard our legitimate interest in verifying your creditworthiness, we transmit this data to the provider for the purpose of a credit check, in accordance with Art. 6 Para. 1 lit. f of the GDPR. Based on the personal data you have provided—as well as other data (such as the contents of your shopping cart, invoice amount, order history, and payment history)—the provider assesses whether the payment option you have selected can be granted in light of potential payment and/or default risks.
The credit report may contain probability values (so-called "score values"). To the extent that score values are incorporated into the result of the credit report, they are based on a scientifically recognized mathematical-statistical procedure. The calculation of these score values incorporates—among other factors, though not exclusively—address data. You may object to this processing of your data at any time by sending a message to us or to the provider. However, the provider may remain entitled to process your personal data if this is necessary for the contractual processing of payments.
- Shopify Payments
One or more online payment methods from the following provider are available on this website: Shopify International Limited, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.

When you select a payment method from the provider that requires you to pay in advance (such as credit card payment), your payment details provided during the ordering process (including name, address, bank and payment card information, currency, and transaction number), as well as information about the contents of your order, will be transmitted to the provider in accordance with Article 6 Paragraph 1 Letter b GDPR. In this case, your data will be transmitted exclusively for the purpose of processing the payment with the provider and only to the extent necessary for this purpose.

7) Rights of the Data Subject
7.1 Applicable data protection law grants you—as the data subject—the following rights (rights of access and intervention) vis-à-vis us—as the data controller—regarding the processing of your personal data; for the specific conditions governing the exercise of these rights, please refer to the cited legal basis:
- Right of access pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to notification pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw granted consents pursuant to Art. 7 Para. 3 GDPR;
- Right to lodge a complaint pursuant to Art. 77 GDPR.
7.2 RIGHT TO OBJECT
IF, WITHIN THE FRAMEWORK OF A BALANCING OF INTERESTS, WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTERESTS, YOU HAVE THE RIGHT—AT ANY TIME AND ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION—TO OBJECT TO SUCH PROCESSING WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE THE PROCESSING OF THE DATA IN QUESTION. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves the establishment, exercise, or defense of legal claims.
If your personal data is processed by us for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for the purpose of such marketing. You may exercise this right to object as described above.
If you exercise your right to object, we will cease processing the data in question for direct marketing purposes.

8) Duration of Personal Data Storage
The duration of the storage of personal data is determined based on the respective legal basis, the purpose of the processing, and—where applicable—additionally based on the respective statutory retention periods (e.g., retention periods under commercial and tax law).
When personal data is processed on the basis of explicit consent pursuant to Art. 6 Para. 1 lit. a GDPR, the data in question is stored until you revoke your consent.
If statutory retention periods exist for data processed within the scope of contractual or quasi-contractual obligations pursuant to Art. 6 Para. 1 lit. b GDPR, such data is routinely deleted after the expiration of these retention periods, provided that it is no longer required for the fulfillment or initiation of a contract and/or we no longer have a legitimate interest in its continued storage.
When personal data is processed on the basis of Art. 6 Para. 1 lit. f GDPR, such data is stored until you exercise your right to object pursuant to Art. 21 Para. 1 GDPR, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
When personal data is processed for the purpose of direct marketing on the basis of Art. 6 Para. 1 lit. f GDPR, such data is stored until you exercise your right to object pursuant to Art. 21 Para. 2 GDPR.
Unless otherwise indicated in the other information provided in this declaration regarding specific processing situations, stored personal data is generally deleted when it is no longer necessary for the purposes for which it was collected or otherwise processed. Copyright Notice: This Privacy Policy was drafted by the specialist attorneys at IT-Recht Kanzlei and is protected by copyright (https://www.it-recht-kanzlei.de).

Last updated: February 23, 2026, 21:28:05