Data Protection

1. Controller and Scope

The controller responsible for the processing described in this statement is:

Fidu Brands GmbH
Otto-Hesse-Str. 19/T9
64293 Darmstadt
Germany

Represented by Managing Directors Christian Hinz and Erdem Keles. Commercial Register: Amtsgericht Darmstadt, HRB 95515.

Email: info@koaa.world
Phone: +49 6151 384340
Central contact for cross-brand data protection concerns: info@fidubrands.com

This statement applies to the service koaa under koaa.world as well as to the related customer and business processes described below. In particular, it explains the nature, purpose, legal basis, recipients, and duration of personal data processing, as well as your rights. Not every described process occurs with every visit; your usage, the specific business process, and your consents are decisive.

 

2. Data Types, Data Sources, and Legal Bases

We primarily process identification and contact data, communication content, contract, order, and billing data, as well as technical access and usage data. Which information actually arises depends on your use of our services. Pure product or sales totals without reference to an identifiable person are not personal data. Customer identifiers, cookie IDs, and hashed contact information, however, can still be personal data.

We receive data directly from you, through technically necessary processes during website visits, and within the scope of the processes described below from payment and shipping service providers, sales systems, or your company. If data of another person, such as a delivery recipient or a business contact person, is communicated to us, we process it only for the associated purpose. We will inform you about data not collected from you in accordance with Art. 14 GDPR, unless there is a legal exception.

Consent is the legal basis under Art. 6 Para. 1 lit. a GDPR. The preparation or fulfillment of a contract with you is carried out under Art. 6 Para. 1 lit. b GDPR. We fulfill legal obligations, especially regarding accounting and retention, under Art. 6 Para. 1 lit. c GDPR. Where we rely on Art. 6 Para. 1 lit. f GDPR, we will name the respective legitimate interest in the relevant section; the prerequisite is that your interests and fundamental rights do not override.

The legal basis for accessing or storing information on your terminal equipment must be assessed separately. For this, § 25 TDDDG (Telecommunications and Telemedia Data Protection Act) applies in particular. A legal basis under the GDPR does not replace a required consent under the TDDDG.

 

3. Website Operation and Hosting with Shopify

We operate our online shop with Shopify. The provider for European platform use is Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland. Shopify primarily provides hosting, content delivery, shopping cart, checkout, and customer account functionalities.

When accessed, the IP address, date and time, requested pages and files, referrer information, browser, operating system, language, device information, transmitted data volumes, as well as technical error and security information are processed. For an order, the information described in the section on contract processing is added. IP addresses and other technical identifiers can be personal data.

The processing required to carry out an order or account process requested by you is based on Art. 6 Para. 1 lit. b GDPR. General provision, troubleshooting, and protection against attacks are based on Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in the secure and functional operation of the shop. This does not form a general permission for advertising tracking.

Shopify processes shop data within the scope of its order processing according to Art. 28 GDPR. For certain of its own services and purposes, Shopify may also be independently responsible, particularly when you use your own Shopify services such as Shop or Shop Pay. The roles are to be distinguished according to the respective service used.

Shopify companies and subcontractors may process data, in particular, in Ireland, Canada, the USA, and other countries mentioned in the provider information. Shopify's contractual documents provide for adequacy decisions and/or standard contractual clauses for recorded international transfers. Details and the possibility to request information on the safeguards can also be found in the section on international data transfers.

Technical logs are retained according to their purpose for provision, troubleshooting, and investigation of security incidents. In the event of a specific incident, only the information required for this will be further processed until its clarification and any necessary legal prosecution. Order and account data are subject to the separate storage rules of this statement.

Further information: Shopify Privacy, Shopify Consumer Privacy, Shopify Data Processing Addendum.

Optional Shopify Features and Network Intelligence

When using optional personalization and marketing features based on Shopify Network Intelligence, Shopify may combine data about interactions with our shop with information from interactions with other merchants and Shopify. This may particularly include technical identifiers, device and usage data, viewed products, and purchase interactions. The processing serves the improved functions offered, such as personalized recommendations and the measurement or steering of advertising.

Insofar as this processing requires consent, we will integrate it only with your consent according to Art. 6 Para. 1 lit. a GDPR and, for corresponding device access, § 25 Para. 1 TDDDG. The necessary technical shop provision is treated separately. Consent to the general terms and conditions of purchase does not replace a tracking consent.

Insofar as Shopify is responsible for such improved services itself, Shopify explains its processing, storage rules, international recipients, and legal bases in the linked consumer privacy policy. You can change your selection for our website via the privacy settings. You can also exercise your rights vis-à-vis Shopify via the Shopify Privacy Portal. We remain your contact person for our own processing.

 

4. Cookies and Consent Management

Our website uses cookies and similar technologies. This may include entries in the local browser storage, pixels, scripts, and other methods for storing or reading information. A distinction must be made between accessing your terminal equipment and the subsequent processing of personal data.

Required Functions

Without consent, we only store or read information insofar as a legal exception applies, particularly if it is strictly necessary to provide a digital service expressly requested by you (§ 25 Para. 2 No. 2 TDDDG), or solely serves the transmission of a message (§ 25 Para. 2 No. 1 TDDDG). This may include secure session management, a shopping cart used by you, and the storage of your privacy selection. Not every useful or economically advantageous function is therefore technically necessary.

The subsequent personal data processing is based, depending on the function, on Art. 6 Para. 1 lit. b GDPR, on Art. 6 Para. 1 lit. f GDPR for the necessary technical security, or on Art. 6 Para. 1 lit. c GDPR for fulfilling legal proof obligations.

Voluntary Analysis and Marketing Functions

For non-essential analysis, personalized advertising, and other services requiring consent, your prior consent according to § 25 Para. 1 TDDDG and Art. 6 Para. 1 lit. a GDPR is decisive. The purposes and providers are explained in the respective service sections. You can refuse consent without losing the basic website or order function.

Selection, Proof, and Revocation

Your selection is managed via the cookie or privacy settings. To assign and prove, the decisions made, the time, the associated information version, and a technical consent identifier are processed. The necessary proof processing is based on Art. 6 Para. 1 lit. c in conjunction with Art. 7 Para. 1 GDPR; the device storage of the selection on § 25 Para. 2 No. 2 TDDDG. Recipients are the technical service providers used for website operation and consent management.

You can change or revoke your selection at any time with effect for the future via the cookie or privacy settings available on the website. Additionally, you can contact us via the contact details provided above. The legality of the processing until revocation remains unaffected.

Session identifiers end with the expiration of the session or their technically defined validity. Persistent identifiers exist until their expiration or your prior deletion. The specific retention periods vary depending on the technology; consent proofs are stored as long as the processing based thereon and its necessary proof persist. Legally required proofs or proofs needed for concrete legal defense can be stored for a limited period beyond that.

You can also delete or block cookies in the browser. Deletion alone does not necessarily revoke already granted consents and does not remove already transmitted data. After a browser or device change, a new selection may be required.

 

5. Contact and Customer Service

If you contact us by email, phone, contact form, or via an offered customer service, we process the information you provide. This includes name, contact information, your request, if applicable, company and function, as well as associated order, project, or complaint information. We only process voluntarily submitted files or images for handling the request. Please do not send sensitive data that is unnecessary for the inquiry.

If it concerns a contract with you or pre-contractual measures at your request, Art. 6 Para. 1 lit. b GDPR is decisive. For general inquiries or communication with employees and representatives of a business partner, Art. 6 Para. 1 lit. f GDPR is the basis. Our interest lies in the proper processing of inquiries, reliable business relationships, and the documentation of agreements. We process legally required business correspondence according to Art. 6 Para. 1 lit. c GDPR.

Recipients are the respective competent persons at Fidu and the communication and IT service providers used for email, form submission, or customer service. Contacting us does not automatically lead to a newsletter subscription or consent to personalized advertising.

Providing a suitable contact option and the information necessary to clarify the matter is required for a response. After the process is completed, information no longer needed will be deleted. Contract documents, business letters, and content required for specific legal claims are subject to separate retention rules.

 

6. Orders, Customer Account, and Contract Processing

For offers and orders, we process names, billing and shipping addresses, email addresses, ordered items, prices, discounts, payment method and payment status, and, if applicable, a phone number or business details required for the specific processing. The processing serves contract conclusion, delivery, billing, customer service, as well as the processing of warranty and other contractual claims.

The legal basis is Art. 6 Para. 1 lit. b GDPR; for contact persons of a company, the balancing of interests described in the section on business communication applies. We fulfill commercial and tax law obligations according to Art. 6 Para. 1 lit. c GDPR, in particular in conjunction with § 257 HGB and § 147 AO.

If you use a customer account, we additionally process login and account management data, stored addresses, and the orders assigned to your account. This serves the account function you requested and is carried out according to Art. 6 Para. 1 lit. b GDPR. You can request the deletion of the account; legally required order and billing documents remain separately stored.

The data marked as required in the ordering process is needed for contract processing. Without it, an order may not be possible. Voluntary information is marked accordingly. Data for newsletters, reach measurement, or personalized advertising is not a prerequisite for a purchase.

 

7. Payment Processing

For a payment, we process the identification, billing, order, amount, and transaction data required for the selected payment method. Recipients are the payment service providers, banks, and, if applicable, card or wallet providers involved in the respective payment transaction. Payment instrument data may be collected directly by the payment provider. We receive, in particular, payment status, transaction references, and the information necessary for billing or refund.

Our processing for the execution of payment is carried out according to Art. 6 Para. 1 lit. b GDPR. Legal documentation is based on Art. 6 Para. 1 lit. c GDPR. To the necessary and proportionate extent, security checks serve our legitimate interest in preventing payment fraud and financial damage (Art. 6 Para. 1 lit. f GDPR). This does not imply permission for general advertising tracking.

PayPal

If you choose PayPal, PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, receives the data required for payment. PayPal processes this data for payment processing, fraud prevention, and legal obligations also under its own responsibility. Depending on the PayPal product selected, identity, fraud, or credit checks and international transfers are possible. Further relevant information is contained in the PayPal Privacy Policy.

Shopify Payments, Card Payments, and Wallets

If you select a payment method provided via Shopify Payments, Shopify International Limited, The Sidings, 4th Floor, Grand Canal Quay, Dublin D02 E7K8, Ireland, processes the data necessary for providing the payment function. The actual payment processing is carried out by the payment processors and financial institutions integrated for the payment product. If you use a wallet, its provider also processes the payment you initiated. Which payment methods are available can be seen in the checkout; not every provider receives data with every order.

The respective payment companies involved also process data to fulfill their own legal obligations, for example, for money laundering prevention and to check payment security. Details can be found in the Shopify Payments Terms and the payment processors named therein, as well as the Shopify Privacy Policy.

For an invoice or bank transfer chosen by you, we process the necessary invoice, bank account, and payment receipt data. Payment processing does not occur solely because a payment logo is displayed on our website.

Independently responsible payment service providers determine their retention periods and, if applicable, automated review procedures according to their legal obligations and privacy notices. Your rights regarding our own order, accounting, and refund data remain unaffected.

 

8. Enterprise Resource Planning (ERP) and Order Management with Xentral

For enterprise resource planning, customer and order management, offers, invoices, deliveries, and returns, we use Xentral from Xentral ERP Software GmbH, Viktoriastraße 3b, 86150 Augsburg, Germany.

Processed data includes, in particular, customer and contact person data, contact information, billing and shipping addresses, customer and order identifiers, items and quantities, amounts, payment status, invoice and shipping information, as well as return or complaint data. Information from our sales systems can be automatically synchronized with Xentral for this purpose.

Processing for the fulfillment of a contract with you is based on Art. 6 Para. 1 lit. b GDPR. For business contacts and necessary internal organization, Art. 6 Para. 1 lit. f GDPR is decisive; our interest lies in reliable merchandise management, coordinated order processing, and error-free billing. We fulfill legal documentation and retention obligations according to Art. 6 Para. 1 lit. c GDPR.

Xentral is used as a data processor according to Art. 28 GDPR for the data processed on our behalf. Operational and support service providers receive data only within the scope of their respective tasks. A German provider address alone does not mean that all technical sub-processing takes place exclusively in Germany. For international sub-processing, the transfer regulations described below also apply.

If you use a returns portal provided via Xentral, the information required to identify the order and process the return, such as order number, contact information, affected items, and reason for return, will be processed for this purpose. Mandatory information is used to process the return; voluntary information beyond this is not a prerequisite for exercising legal rights.

The storage period depends on the respective order and the described contractual, accounting, and retention rules. Further provider information: Xentral Data Protection.

 

9. Shipping, Delivery and Returns

For delivery or return, we transmit the necessary data to the parcel or transport service provider commissioned for the specific shipping route. This includes name, delivery or pickup address, consignment and tracking number, shipping method, and, if applicable, customs information. We receive delivery, return, and, if applicable, damage information.

For shipments handled by DPD, DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg, Germany, is the recipient of the required delivery data. For any other explicitly agreed shipping method, the commissioned transport service provider receives the necessary information. The specific carrier can be found in the shipping or order information.

The transmission of necessary delivery data takes place for contract fulfillment in accordance with Art. 6 para. 1 lit. b GDPR. In the case of another designated recipient or a business contact person, Art. 6 para. 1 lit. f GDPR may be the basis; our interest lies in the proper execution of the commissioned delivery. Legal customs and documentation obligations are based on Art. 6 para. 1 lit. c GDPR.

An email address or phone number for an additional, voluntary notification service of the carrier will be transmitted based on a corresponding consent pursuant to Art. 6 para. 1 lit. a GDPR. If contact information is necessary for an explicitly commissioned special delivery service, such as appointment coordination, it will be processed for this specific purpose. The general provision of an email address with an order is not considered blanket consent for other services of the carrier.

For the actual transport, transport service providers regularly act on their own responsibility. Their own storage rules and recipients are additionally governed by their data protection information. Information on DPD: DPD Data Protection. For cross-border deliveries, necessary recipients in the destination country may be added.

Withdrawal, Returns and Complaints

In the event of a withdrawal, return, or complaint, we process the order assignment, your declaration, affected items, and necessary communication, shipping, verification, and refund information. This serves to process the contract and fulfill legal claims in accordance with Art. 6 para. 1 lit. b or lit. c GDPR. In the case of disputed claims, the necessary legal pursuit or defense may be based on Art. 6 para. 1 lit. f GDPR.

A legal withdrawal does not require justification. Voluntary information on reasons for return is treated separately from the data required for processing. Retention depends on the business process and the rules explained in the section on storage duration.

 

10. Google Analytics

We use Google Analytics for the statistical evaluation of the use of our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The evaluation helps us to assess the content, usability, and effectiveness of our offers.

After appropriate consent, page views, search and click events, sessions, visit times, referrers, technical device and browser information, approximate location information, as well as technical user and session IDs can be processed. For shop processes, product views, shopping cart actions, and purchase events with item, value, and transaction information may be added. Such identifiers can establish a personal reference, even if we do not see names in the evaluations.

IP addresses are technically processed for communication and the derivation of approximate location information. Google states for accesses from the EU, Switzerland, and the United Kingdom that individual IP addresses are not logged or stored during this Analytics data collection. This does not mean that all other Analytics data is anonymous.

Processing is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR; storage or access in the terminal device requiring consent is based on Section 25 para. 1 TDDDG. You can revoke your consent for the future via our cookie or privacy settings. A server-side transmission path or the omission of a specific cookie does not automatically replace the required legal basis.

Google processes the analysis data collected for us according to its data processing terms. Google companies and subcontractors may also process data outside the EEA, especially in the USA. The Google contract documents provide for applicable adequacy decisions or standard contractual clauses for recorded transmissions.

Storage at user and event level depends on the settings of the respective Analytics property. Google distinguishes this data from aggregated standard reports and allows for its automatic deletion after the configured period. For identifiers, an activated extension during renewed use can shift the expiry. The purpose and deletion limits applicable within our area of responsibility also remain for exports or internal evaluations; an export file must not circumvent them.

We only use consent-bound analysis information for the evaluations covered by the consent. For further internal use of reports, please refer to the section on the Fidu Portal. Additional advertising purposes are to be distinguished from pure reach measurement and are not permitted solely by a general statistics consent.

Further information: Google Privacy, Data processing for partner offers, Analytics data retention. The Google browser add-on is an additional browser-dependent option for restricting Analytics collection and does not replace our revocation option.

 

11. Google Ads, Conversion Measurement and Remarketing

We use Google Ads from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to draw attention to our offers and to measure the success of advertising campaigns. As part of conversion measurement, it can be recorded whether a specific action on our website, such as an inquiry or a purchase, occurs after an ad contact. Remarketing allows us to target previous visitors with interest-based advertising on other offers.

After appropriate consent, advertising and cookie identifiers, click information, referrers, browser and device data, IP address, viewed content, as well as event, product, and purchase value data can be processed for this purpose. Google can assign information to its own user account, provided that the corresponding assignment and its legal requirements are met. A statistical report view with us does not mean that Google only receives anonymous data.

The legal basis for personalized conversion measurement and remarketing is your consent pursuant to Art. 6 para. 1 lit. a GDPR, and for terminal device access, additionally Section 25 para. 1 TDDDG. Consent can be revoked via our cookie or privacy settings. A mere viewing of our advertising outside our website is subject to the privacy information of the respective offer.

Recipients are Google and the technical entities involved in ad delivery. For Google companies and subcontractors in third countries, Google's provided transfer regulations and the section on international transfers apply. Advertising identifiers and audience assignments are only used within the time windows valid for the respective measurement or re-engagement; after their expiration or an effective revocation, the corresponding future use ends. Google's independent storage is additionally governed by its privacy policy.

Further information: Google advertising technologies and Google Privacy Policy.

 

12. Meta, Facebook and Instagram Advertising

We use advertising and measurement services from Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This includes measuring advertising success and creating target audiences for Facebook and Instagram advertising. Insofar as events on our website are recorded via the Meta Pixel or corresponding Business Tools, this is done after your corresponding consent.

The following data may be processed: IP address, browser and device information, technical identifiers, referrers, page and product views, clicks, shopping cart actions, purchases, order values and times. Meta can thus assign an ad contact to a later action and, if possible, link the information to a Meta user account. We receive evaluations on the performance of the advertising; this does not exclude personalized processing by Meta.

The legal basis for our marketing and measurement processing requiring consent is Art. 6 para. 1 lit. a GDPR. For storage or reading of terminal device information, Section 25 para. 1 TDDDG additionally applies. You can revoke your consent in the cookie or privacy settings for the future. Meta also provides information on your own Meta account settings.

Insofar as we and Meta jointly determine the purposes and means for the collection and transmission of event data, there is a joint responsibility according to Art. 26 GDPR to the extent of the relevant Meta agreement. This agreement particularly regulates the responsibility for information, consents, security, and the processing of data subject rights. We are responsible for the lawful integration on our offer and the necessary information. Meta assumes the obligations assigned to it in the agreement within its systems. You can assert your rights against both controllers regardless of this division of tasks. For subsequent independent processing by Meta, its privacy policy applies.

Server-side transmission, for example via a Conversions API, or a comparison of hashed contact information is still subject to the respective consent and information requirements. Hash values are not automatically anonymous. The general use of our website or the completion of a purchase does not constitute blanket permission for customer list comparisons.

Data may also be processed by Meta companies and technical subcontractors in the USA or other third countries. Meta describes applicable adequacy decisions and standard contractual clauses for this purpose. The validity of these mechanisms relates to the respective recipient and processing operation. Audience and measurement identifiers are used within the validity and retention periods relevant for the specific campaign; Meta provides separate information on its own storage rules.

Further information: Meta Privacy, Meta Business Tools and Joint Controller Addendum.

 

13. Newsletter and Email Marketing with Klaviyo

For newsletters and the technical administration of our email marketing, we use Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02110, USA.

Registration and Proof of Consent

When you register for a newsletter, we process your email address and voluntary information, such as names or interests. In addition, the registration method, time, granted consent, and the technical information required to prove it are processed. The sending of communications based on your registration is based on Art. 6 para. 1 lit. a GDPR and the requirements for electronic advertising under Section 7 UWG.

If the registration method you use requests confirmation of your address, you will receive a confirmation message (double opt-in). The confirmation and the associated times are then also documented. A confirmation message does not serve as permission for further advertising beyond this.

We process necessary proofs according to Art. 6 para. 1 lit. c in conjunction with Art. 7 para. 1 GDPR and to the necessary extent for concrete legal defense according to Art. 6 para. 1 lit. f GDPR. Our legitimate interest in this case is to prove lawful communication and to defend against unjustified claims.

Content, Personalization and Automated Messages

Our newsletters inform about products, collections, promotions, and news of the brand specified during registration or the offer described there. Consent for one brand does not automatically imply consent for any other brands or communication channels.

Insofar as your consent includes personalization, interests you have indicated, customer identifiers, purchased items, order values, and times can be linked to the newsletter profile. The processing serves to provide suitable content and to avoid irrelevant mailings. The legal basis is Art. 6 para. 1 lit. a GDPR. Technically triggered advertising messages, such as shopping cart reminders, re-engagements, or review requests, also require the respective necessary sending authorization.

Required order and service messages are treated separately from advertising. Their processing is governed by the specific contract and in particular Art. 6 para. 1 lit. b GDPR. The fact that a message is sent automatically does not automatically make it advertising, nor does it automatically make it a permissible contractual message.

Unsubscribe, Recipients and Storage

You can revoke your newsletter consent at any time via the unsubscribe link in a marketing email or by contacting our data protection contact. Unsubscribing does not affect the lawfulness of processing that has already taken place. Independently required contractual messages can still be sent.

Klaviyo processes the data provided on our behalf according to its Data Processing Agreement, which is incorporated into the terms and conditions, in accordance with Art. 28 GDPR. Processing may take place in the USA. The published DPA provides for the EU-U.S. Data Privacy Framework, where applicable, and standard contractual clauses for recorded transmissions.

A newsletter profile is used for the duration of the existing sending authorization. After unsubscribing, its use for the revoked advertising purposes ends. Profile and interaction data that are no longer required are deleted or anonymized. A blocking notice limited to the email address, blocking status, and necessary proof data may be stored as long as necessary to ensure that the unsubscription is observed even with a renewed system comparison. Consent proofs are only retained for the necessary proof and, if applicable, concrete legal claims; they are not permission to continue advertising.

Further information: Klaviyo Privacy and Klaviyo Data Processing Agreement.

 

14. Newsletter Success Measurement and Website Tracking

Provided you have consented to corresponding personalized success measurement, marketing emails may contain individual tracking pixels and assignable links. This allows for the processing of retrievals and clicks, times, message and recipient identifiers, as well as technical information about the device or email program. This information helps us to evaluate content and sending times and to adapt them to interests to the permitted extent. Protection and pre-loading functions of email programs can influence the measurement values.

A mere newsletter registration or the existing customer exception does not automatically constitute consent to personalized tracking. The legal basis for the corresponding personalized success measurement is Art. 6 para. 1 lit. a GDPR; for terminal device access requiring consent, Section 25 para. 1 TDDDG additionally applies.

When using Klaviyo website technologies, with the necessary consent, page and product views, shopping cart actions, and other website events can be assigned to a known profile. This serves the personalization and success measurement covered by the consent. A newsletter consent does not replace this website tracking consent.

You can revoke website tracking consent via the privacy settings. You can inform us of a revocation of personalized email success measurement via the data protection contact; complete unsubscription from marketing emails is also possible via the unsubscribe link. Unsubscription must not be circumvented by renewed imports.

Interaction data is used within the associated sending authorization only as long as it is still required for the specific content or campaign evaluation and the consented personalization. After the purpose ends or a relevant revocation, this use ends; necessary, separate consent proofs remain unaffected. Providers, recipients, and international transfer regulations correspond to the preceding Klaviyo section.

 

15. Embedded YouTube videos

On pages with embedded YouTube videos, we use the video service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The embedding serves to display product, brand, or other video content accessed by you.

If you activate an embedding that requires consent, your browser may connect to YouTube or Google. This may transmit IP address, accessed page, device and browser information, technical identifiers, and usage and playback events. An association with a Google account is possible depending on login and settings. Google may also use the information for its own purposes as described in its privacy notices.

The embedding requiring consent is carried out in accordance with Art. 6 para. 1 lit. a GDPR and, insofar as terminal device information is stored or accessed, § 25 para. 1 TDDDG. An extended data protection mode or a different embedding domain is not, in itself, a guarantee that no data will be transmitted. Consent can be revoked via our cookie or privacy settings.

Google companies and subcontractors may also process information in the USA and other third countries. The transfer regulations and storage rules described in Google's documentation apply additionally. A simple link to a video is to be distinguished from a player already loaded on our website.

Further information: Google Privacy and YouTube Embedding Information.

 

16. External Links and Social Media

Our website may contain links to our presences on social networks. Simply displaying a plain link does not establish a connection to the target offering solely due to this link. Only when you click the link does the respective provider process information according to their own privacy notices.

Distinguishable from this are embedded posts, feeds, buttons, or other external content that establish a data connection to the provider already within our website. For such embedded content requiring consent, personal data processing is carried out according to Art. 6 para. 1 lit. a GDPR and corresponding terminal device access according to § 25 para. 1 TDDDG. IP address, visited page, device information, technical identifiers, and your interaction with the content may be transmitted. A provider may associate this data with its own user profile depending on login.

For Facebook and Instagram content, Meta Platforms Ireland Limited, Ireland, is the provider. For other social offers you activate or access, the provider information visible with the respective content applies. Operators may also process data outside the EEA; the protective mechanisms applicable to the respective embedding must also be observed.

You are not obliged to enable external content to read other content on our website or to make an inquiry. Granted consent can be revoked via the privacy settings. Settings in your own social network account are not automatically changed as a result.

 

17. Promotions, Sweepstakes and Voluntary Reviews

For a promotion, sweepstakes or review function chosen by you, we process the information required for participation, such as contact information, your contribution, an participation or order assignment, and in case of a win, a delivery address. For the execution of an agreed participation, Art. 6 para. 1 lit. b GDPR is decisive. Voluntary publications or additional promotional use require the respectively necessary separate legal basis, in particular consent.

A joint promotional partner only receives personal data to the extent necessary for the specifically described participation or separately permitted. Special recipients, publication rules and storage periods are explained with the respective offer. A sweepstake is not a blanket permission to include participants in all brand distribution lists.

Participation data will be deleted after the completion of the promotion and the processing of associated claims, unless legal evidence or effective separate consents prevent this. Promotional review requests by e-mail are treated separately from the necessary processing of an order.

 

18. Internal Company Management: Fidu Portal

Fidu Brands GmbH operates an internal data platform, the Fidu Portal. This portal provides and evaluates data from merchandise management, associated sales systems, and deployed marketing and analysis systems for operational purposes.

Data sources include, in particular, Xentral and – for shop operations – Shopify, as well as Google and Meta reports, and, where appropriate brand attribution applies, Klaviyo. Not every source system is used on every website. Simply accessing this website does not automatically lead to the processing of your data in all listed systems.

Centralized processing serves to assign and control orders, deliveries, returns, and payments, to correct data errors, and to generate sales, cost, inventory, and profitability analyses. Depending on the task, customer and order identifiers, master data, contact information, items, quantities, amounts, times, and status information are affected. For marketing reports, aggregated campaign metrics are to be distinguished from personal events and profiles.

Processing necessary for concrete contract fulfillment is based on Art. 6 para. 1 lit. b GDPR; for business contacts, Art. 6 para. 1 lit. f GDPR applies. Legally required documentation is carried out according to Art. 6 para. 1 lit. c GDPR. Necessary internal coordination and business evaluations are based on Art. 6 para. 1 lit. f GDPR after weighing the interests involved; our interest lies in correct billing, economic planning, and comprehensible business processes.

Storage in the portal does not create a new blanket permission for advertising or profiling. Consent-bound data may only be further processed within the permissible purpose; a denied or revoked consent may not be circumvented by an internal copy. Cross-brand advertising profiling is not covered by a general permission for company management.

Accesses are granted according to task and necessity. If personal individual data is not required for an evaluation, data is reduced accordingly or summarized in an appropriate form. Deletion and restriction also extend to associated copies and exports; legally required documents to be retained are treated separately.

 

19. Database and Backend Infrastructure with Supabase

For the central data platform and the Fidu Portal, we use database, backend, and infrastructure services from Supabase. The provider of the published cloud services is Supabase Pte. Ltd., Singapore.

The project set up for our portal uses the region eu-central-1 (Frankfurt am Main, Germany). This means that the primary storage of project data is set up in this region. This is not a statement that every support, security, infrastructure, or other secondary processing takes place exclusively in Germany.

The data described in the section on the Fidu Portal is processed, insofar as it is stored or processed in this infrastructure, as well as technical log, access, and authorization information required for operation. Supabase is used as a processor for this purpose in accordance with Art. 28 GDPR. The material legal basis depends on the specific purpose of the respective data processing; the choice of a database does not create additional permission.

According to the provider's documentation, Supabase and commissioned technical entities may also process data in Singapore, the USA, or other countries. For recorded transfers to countries without an adequate adequacy decision, the Supabase DPA provides for EU Standard Contractual Clauses in particular. In addition, the actual protection conditions and necessary supplementary measures must be considered. Information and a copy of the essential guarantees can be requested from us.

The duration of storage is determined by the described processing purposes and the applicable deletion or retention rules. Neither the duration of a Supabase subscription nor the mere existence of a data export justifies unlimited personal storage.

Further information: Supabase Data Processing Addendum, Supabase Subprocessors and Supabase Privacy.

 

20. Other recipients and international data transfers

Within Fidu Brands GmbH, only individuals responsible for the respective process have access. External recipients, in addition to the named providers, may include IT and communication service providers, transport and payment companies, necessary project partners, tax advisors, legal advisors, and competent authorities. Disclosure is made only to the extent necessary and on the basis specified for the specific purpose. Official disclosures require, in particular, a corresponding legal obligation or authorization.

Processors are contractually bound according to Art. 28 GDPR. Independently responsible parties, such as certain payment companies or professional confidentiality holders, do not become processors solely due to a business relationship. Joint responsibility is only assumed where actual processing and applicable regulations provide for it.

For transfers outside the EU and the EEA, we also examine the required level of data protection. An adequacy decision according to Art. 45 GDPR applies only to its specific scope. The EU-U.S. Data Privacy Framework therefore does not apply indiscriminately to all companies based in the USA. If an relevant decision is missing, in particular standard contractual clauses according to Art. 46 GDPR, together with an examination of the actual protection conditions and, if applicable, supplementary measures, are considered.

Access from a third country to data in a European data center can also be relevant. The specific basis is described in the respective service. Information and a copy of the essential agreed guarantees can be requested via our data protection contact; legitimate interests in confidentiality will be protected.

 

21. Storage Duration, Deletion and Restriction

We differentiate between ongoing business data, legal archives, consent records, and voluntary analytical or marketing data. There is no general retention obligation for all customer data.

Inquiries are deleted once they have been fully processed and there is no further permissible purpose. In the event of a contract conclusion, necessary content is incorporated into the contract documentation. Commercial and business letters are generally to be retained for six years, booking records for eight years, and certain accounting documents, inventories, or financial statements for ten years. The classification is based on § 257 HGB, § 147 AO, and the respective applicable special regulations. Commencement, extensions, and exceptions are determined by law.

Insofar as data remains necessary for the assertion, exercise, or defense of legal claims, a correspondingly limited retention can take place until the matter is clarified or until relevant deadlines expire. The legal basis is Art. 6 para. 1 lit. f GDPR. A merely abstract interest in a possible later use does not justify unlimited storage.

For newsletters, analysis identifiers, advertising target groups, consent records, and technical logs, the periods or criteria described for the respective service apply. A revocation ends the future processing covered by it. Invoices legally required to be retained and a necessary advertising block note, limited to a few details, may be excluded from this.

If data must continue to be stored after the end of its operational purpose, its further use is limited to the permissible storage purpose. Deletions and restrictions must also be considered for commissioned service providers and internal copies. Backup copies are treated according to the defined backup and recovery concept.

 

22. Your Data Protection Rights

Under the statutory conditions, you have a right to information about your personal data and the associated processing, as well as a copy of this data (Art. 15 GDPR). You can have inaccurate data corrected and incomplete data completed (Art. 16 GDPR).

You can request deletion, for example, if the data is no longer needed or if processing is unlawful (Art. 17 GDPR). This right is not unlimited; in particular, legal retention obligations or necessary legal defense may oppose it. Under the conditions of Art. 18 GDPR, you can instead request a restriction of processing.

Insofar as you have provided us with data and its automated processing is based on your consent or a contract, you have the right, according to Art. 20 GDPR, to receive this data in a structured, common, and machine-readable format and, where technically feasible, to have it transmitted to another controller.

You can revoke consents at any time for the future. The legality of the processing up to the revocation remains unaffected. For practical exercise, use the settings described in the respective section or our data protection contact.

Special note on the right to object under Art. 21 GDPR

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Art. 6 para. 1 lit. e or lit. f GDPR. This also applies to profiling based on these provisions. We will then no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.

You can object to the processing of your data for direct marketing purposes at any time without giving reasons. This includes profiling to the extent that it is related to such direct marketing. After such an objection, your data will no longer be used for these marketing purposes.

Complaints and processing of your requests

According to Art. 77 GDPR, you can lodge a complaint with a data protection supervisory authority, in particular at your habitual residence, your place of work, or the place of the alleged infringement. For our company, the Hessian Commissioner for Data Protection and Freedom of Information is particularly relevant: Contact and complaint options. You do not have to contact us first.

We generally respond to requests within one month. We will inform you of any legally permissible extension of up to two further months within the first month, stating the reasons. In case of justified doubts about the identity, we may request the additional information required for this purpose. The exercise of rights is generally free of charge; legal exceptions remain unaffected.

 

23. Profiling and Automated Decisions

The consent-based assignment of product interests or the formation of marketing segments may constitute profiling. The data used for this, purposes, and revocation options are described in the respective marketing services. An automatic evaluation is not, for that reason alone, a decision in the sense of Art. 22 GDPR.

You have the right, in accordance with Art. 22 GDPR, not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. In the case of legally permitted exceptions, the предусмотрен safeguards apply, possibly including human intervention, the right to express your point of view, and to contest the decision.

Consent to audience measurement, newsletters, or personalized advertising is not a blanket consent to legally significant automated decisions. For independent identity, fraud, or creditworthiness checks by a chosen payment service provider, its separate information on logic, significance, impact, and the exercise of your rights also applies. Your rights regarding processing for which we are responsible remain unaffected.

 

24. Data Security and Changes

We implement technical and organizational measures appropriate to the risk to protect personal data. These include, in particular, appropriate access authorizations, secure transmission paths, and procedures to maintain confidentiality, integrity, and availability. The measures are adapted to actual risks.

If our processing operations change, we will update this information accordingly. Necessary information about new purposes will be provided before the corresponding further processing. A change to this statement does not replace any new consent that may be required.