This Privacy Policy explains how www.hatorganica.com, operated by Durmaz Handels GmbH, collects, uses, stores and handles personal data when you visit our website, contact us, place an order or use our services.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), applicable German data protection legislation and other applicable European data protection requirements.
For the purposes of this Privacy Policy, the data controller is:
www.hatorganica.com
operated by Durmaz Handels GmbH
Registered Address:
Fruchtbahnhofstr. 3 – 15
68159 Mannheim
Germany
Email: boutique@hatorganica.com
Telephone: +49 6213009920
Website: www.hatorganica.com
For privacy-related enquiries, please contact us using the email address above.
Depending on how you interact with www.hatorganica.com, we may collect the following categories of personal data:
We only request information that is relevant to the relevant purpose of processing.
We may process personal data for the following purposes:
We use customer information to receive and process orders, confirm purchases, arrange order fulfilment, provide order-related communications and handle customer enquiries.
The legal basis is generally Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract or for steps taken at the customer’s request before entering into a contract.
Payments made through www.hatorganica.com are processed using Stripe.
When a customer selects a payment method provided through Stripe, relevant payment and transaction information is transmitted to Stripe for payment processing.
Depending on the payment method and circumstances, this information may include:
We do not require customers to provide complete payment-card details directly to us where such information is collected through Stripe’s payment interface.
Stripe may process personal data in its capacity as a payment service provider and, depending on the specific processing activity, may act as a data processor on behalf of the merchant or as a separate data controller for its own legally permitted processing activities.
Stripe’s own privacy practices are described in its Privacy Policy and Privacy Centre.
When you contact us by email, telephone or other available communication methods, we process the information you provide in order to respond to your enquiry and manage the matter concerned.
The legal basis may be Article 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual request, or Article 6(1)(f) GDPR where processing is necessary for our legitimate business interests.
Personal data may be processed where necessary to comply with applicable legal, accounting, tax, commercial and regulatory obligations.
The legal basis for such processing is Article 6(1)(c) GDPR.
Certain commercial and accounting records are subject to statutory retention periods under German law. Where a statutory retention period applies, the relevant records will be retained for the period required by law.
Personal data may be retained and processed where necessary for the establishment, exercise or defence of legal claims.
The legal basis may include Article 6(1)(f) GDPR and, where applicable, Article 9(2)(f) GDPR where special-category data are lawfully involved in a specific legal context.
Depending on the circumstances, we process personal data on one or more of the following legal bases under the GDPR:
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We retain personal data only for as long as necessary for the relevant purpose or for as long as required by applicable law.
Different categories of information may therefore be retained for different periods.
Information relating to completed orders may be retained for the duration necessary to administer the contractual relationship, handle returns and customer enquiries, meet applicable legal obligations and establish, exercise or defend legal claims.
Certain accounting documents, business records and transaction-related records are subject to statutory retention periods under German commercial and tax law.
Where German statutory retention requirements apply, relevant records may need to be retained for periods such as six or ten years, depending on the type of record and the applicable legal requirement.
The statutory retention period generally runs from the end of the calendar year specified by the applicable legislation.
Customer correspondence is normally retained for as long as reasonably necessary to handle the enquiry, maintain appropriate business records and address any related contractual or legal matters.
Where personal data are processed on the basis of consent for direct marketing, the relevant information will be retained until consent is withdrawn or the information is no longer required for that purpose, subject to any separate legal retention obligation.
Website access information may be retained for a limited period appropriate to the purpose for which it was collected, including the operation of the website, detection of irregular activity and administration of website services.
When personal data are no longer required and no statutory retention obligation applies, they will be deleted or otherwise removed from active processing in accordance with our data retention practices.
Personal data may be disclosed only where necessary for the purposes described in this Privacy Policy or where disclosure is required or permitted by applicable law.
Depending on the circumstances, recipients may include:
Where a service provider processes personal data on our behalf, appropriate contractual arrangements are used where required by the GDPR.
We use Stripe to process payments made through our website.
Stripe receives information necessary to process a transaction when a customer chooses a Stripe-supported payment method. The information processed may include transaction details, customer contact information, billing information and payment method information.
Stripe may process certain personal data as our processor for payment services. Stripe may also process certain information as an independent controller for purposes such as complying with legal obligations and carrying out activities permitted under its own privacy framework.
For further information regarding Stripe’s processing of personal data, customers may consult the Stripe Privacy Policy and Stripe Privacy Centre.
www.hatorganica.com may use cookies and similar technologies to provide essential website functions, remember relevant preferences and understand website usage.
Where consent is required under applicable law, non-essential cookies will only be used following the appropriate consent mechanism.
You may manage available cookie preferences through the cookie settings provided on the website.
Where personal data are transferred outside the European Economic Area, such transfers will be carried out in accordance with the requirements of the GDPR.
Where required, appropriate safeguards may include an adequacy decision adopted by the European Commission, Standard Contractual Clauses or another legally recognised transfer mechanism.
For payment processing, Stripe may process personal data through its relevant corporate entities and service providers in accordance with its applicable privacy framework and contractual arrangements.
Subject to the conditions and limitations established by applicable law, you may have the following rights under the GDPR:
These rights are subject to the conditions and exceptions established by applicable law.
Where we process personal data on the basis of Article 6(1)(e) or Article 6(1)(f) GDPR, you may have the right to object to such processing on grounds relating to your particular situation.
Where personal data are processed for direct marketing purposes, you may object to such processing at any time in accordance with Article 21 GDPR.
If you consider that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority.
For a company established in Mannheim, the competent German supervisory authority may be identified according to the applicable German data protection framework and the relevant processing circumstances.