Polityka prywatności

This Privacy Policy applies to quadroshop.com and to the areas of the Help Center, blog and model database operated by us where reference is made to this Policy.

Who is responsible for processing?

The controller within the meaning of the General Data Protection Regulation is

QUADRO DER GROSSBAUKASTEN GmbH Am Schilfpark 13 21029 Hamburg Germany

Email: info@quadroshop.com

On what legal bases do we process personal data?

We process personal data only where this is necessary to provide our services, respond to inquiries, perform contracts, comply with legal obligations or pursue legitimate interests, or where you have given your consent.

Depending on the purpose of the processing, the processing is based in particular on

  • Article 6(1)(a) GDPR where you have given consent,

  • Article 6(1)(b) GDPR in order to take steps prior to entering into a contract and to perform a contract,

  • Article 6(1)(c) GDPR in order to comply with legal obligations, and

  • Article 6(1)(f) GDPR in order to pursue legitimate interests.

Section 25 TDDDG also applies to the storage of information on your device and access to information stored on it. We use technologies that are not strictly necessary only with your consent in accordance with section 25(1) TDDDG. Operations that are strictly necessary for technical purposes are based on section 25(2) TDDDG.

How do we provide our online services from a technical perspective?

When you access our online services, technically necessary connection data is processed. This includes, in particular, your IP address, the date and time of access, the address accessed, the volume of data transferred, the referring page, browser, operating system, device type, and error and security information.

The processing serves to deliver our content, ensure stability and security, and detect and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and uninterrupted operation of our online services.

For the technical provision of the online shop, checkout, customer account, order management and payments processed through these services, we use Shopify International Ltd., c/o Intertrust Ireland, 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland. In this context, the provider processes, in particular, connection, device, usage, customer, order and payment data on our behalf and, for certain services of its own, under its own responsibility under data protection law. Data may also be processed by affiliated companies and subprocessors outside the European Economic Area. According to the provider, such transfers are based in particular on adequacy decisions, binding corporate rules and standard contractual clauses. Further information is available in the provider’s Privacy Policy.

We may use BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia, to deliver fonts and static content quickly and securely. In particular, your IP address is processed where technically necessary. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in presenting our services securely and efficiently.

Technical log data is deleted or anonymized as soon as it is no longer required for the stated purposes. It is retained for longer only where this is necessary to investigate a specific security incident or to comply with legal obligations.

How do we process orders and contracts?

When you place an order, we process in particular

  • your name and contact details,

  • your billing and delivery address,

  • the items ordered, prices and discounts,

  • the payment method and payment status,

  • the shipping method and shipment information,

  • order and communication data, and

  • where applicable, information required for tax purposes.

The processing is necessary to initiate, perform and process the contract and is based on Article 6(1)(b) GDPR. Where we comply with obligations under commercial, tax or accounting law, the processing is based on Article 6(1)(c) GDPR.

Service providers involved in shop operation, inventory management, order processing, accounting, payment processing, fraud prevention, shipping and customer communication receive the data they require. These recipients receive only the data required for their respective tasks.

How does the customer account work?

You can use a customer account, in particular, to view and manage your contact details, orders and order information.

For current customer accounts, you sign in using a time-limited code sent to your email address. Where an older customer account is still used, password-related functions, including password resets, may additionally be offered.

In this context, we process in particular your email address, contact details, order information, and login and security data. The legal basis is Article 6(1)(b) GDPR. We also process security logs on the basis of Article 6(1)(f) GDPR. Our legitimate interest lies in protecting customer accounts against unauthorized access.

How do we process payments?

When you make a payment, the data required for the selected payment method is transmitted to the payment service providers, banks and card schemes involved. This may include your name, billing address, email address, order value, currency, transaction identifier, device and verification data, and payment status.

Depending on your device, browser and configured wallet, we offer payment by credit card, PayPal, Apple Pay and Google Pay. Card and wallet payments are technically processed through the provider named in the section on the provision of our online services. PayPal is provided by PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, Apple Pay by companies within the Apple group, and Google Pay by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The data is transmitted for the performance of the contract in accordance with Article 6(1)(b) GDPR. Where a payment service provider processes data for its own purposes, for example for fraud prevention, identity verification or compliance with legal obligations, it is independently responsible for that processing.

As a general rule, we do not receive complete credit card details, but only the information required to allocate and document the payment. Further details are provided in the privacy information of the selected payment service provider.

How do we process shipping and delivery?

To deliver an order, we transmit the necessary recipient, address, contact and shipment data to the shipping or logistics service provider used. These providers include, in particular, DHL and, for relevant deliveries to Switzerland, MeinEinkauf.

The legal basis is Article 6(1)(b) GDPR. A telephone number or email address is transmitted only where this is necessary for delivery, for a delivery notification requested by you, or to resolve delivery issues.

How do we handle customer service inquiries?

If you contact us by email, contact form, chat or through other communication channels, we process your contact details, the content of your inquiry, any related order information and subsequent communications.

We use Intercom R&D Unlimited Company, 124 St Stephen’s Green, Dublin 2, D02 C628, Ireland, for chat, the Help Center, automated responses and the QUADRO Bot. In this context, contact, message, order, page-view, device, connection and session data in particular may be processed. If you use an order inquiry function, the information you provide may be compared with existing order data.

Automatically generated responses are intended to provide information quickly and do not produce any legal or similarly significant effects. Do not send any special categories of personal data or payment data through the chat unless this is expressly required and provided for.

The processing is based on Article 6(1)(b) GDPR where your inquiry concerns a contract or steps prior to entering into a contract. In other cases, it is based on Article 6(1)(f) GDPR. Our legitimate interest lies in efficient customer communication. The chat window and any non-essential monitoring of page usage are activated only with your consent. The legal bases for this are Article 6(1)(a) GDPR and section 25(1) TDDDG. Once you actively open the chat, the data required for the requested communication is processed on the legal bases stated above.

Intercom may use affiliated companies and service providers in third countries, in particular in the United States. According to the provider, such transfers are based in particular on adequacy decisions and standard contractual clauses. Further information is available in Intercom’s Privacy Policy.

How do we send the newsletter?

If you subscribe to our newsletter, we process in particular your email address, the time of registration, proof of your consent, and technical delivery information.

The legal basis is your consent in accordance with Article 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by using the unsubscribe link in the newsletter or by sending us a message. This does not affect the lawfulness of processing carried out before you withdrew your consent.

We analyze newsletter opens and links clicked only where you have also consented to this. After you unsubscribe, your email address may remain stored on a suppression list where this is necessary to prevent further unwanted mailings. The legal basis for this is Article 6(1)(f) GDPR.

How do notifications about available products work?

If you request a notification when a product becomes available again, we process your email address and its association with the desired product. We use the data exclusively for the requested notification and delete it afterwards unless legal obligations or separate consent justify further storage.

The legal basis is your consent in accordance with Article 6(1)(a) GDPR. You will be subscribed to the newsletter or other advertising at the same time only if you give separate consent.

How do we use cookies and similar technologies?

We use cookies and similar technologies such as local storage, pixels, tags and scripts.

Technically necessary technologies are used in particular to provide the shopping cart and checkout, enable login to and secure the customer account, store language, region and privacy settings, balance loads, prevent fraud, and provide functions expressly requested. Section 25(2) TDDDG applies to the storage or reading of information. Depending on the purpose, the subsequent processing of personal data is based in particular on Article 6(1)(b) or (f) GDPR.

We use non-essential analytics, personalization and marketing technologies only with your consent in accordance with section 25(1) TDDDG and Article 6(1)(a) GDPR.

We use Pandectes to manage your choices. In this context, your consent status, the time of your choice, device information and a technical identifier in particular are processed. This is necessary to implement and demonstrate your choices. The legal basis is Article 6(1)(c) GDPR in conjunction with the applicable statutory record-keeping obligations and Article 6(1)(f) GDPR. Our legitimate interest lies in maintaining legally compliant records and in technically implementing your decision.

You may change or withdraw your choices at any time with effect for the future through the privacy settings. The details displayed there provide information about the categories, providers and storage periods of the technologies used.

How do we measure the reach and use of our services?

With your consent, we may use functions of the shop platform and our audience measurement solution provided at umami.quadroworld.com to understand how visitors use our services. The data processed may include, in particular, pages and products viewed, referral source, interactions with the shopping cart and checkout, device and browser data, IP address, session and event identifiers, and purchase and transaction information.

The processing is based on your consent in accordance with Article 6(1)(a) GDPR. Where information is stored on or read from your device, section 25(1) TDDDG also applies.

How do we manage services that require consent?

We use Google Tag Manager for the technical management of the analytics and marketing services described in this Policy. When it is activated, your IP address and browser, device and event data in particular may be transmitted to Google. Tag Manager is used to trigger other services and does not itself perform any independent analysis of user behavior.

The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other companies in the United States is possible.

Non-essential services are activated only with your consent in accordance with Article 6(1)(a) GDPR and section 25(1) TDDDG. Further information is available in Google’s Privacy Policy.

How do we measure advertising success and partner referrals?

With your consent, we use technologies to measure the effectiveness of our advertising, attribute orders to advertising activities and partner referrals, and create audiences. These include, in particular, Tracify provided by Tracify GmbH in Munich, X Conversion Tracking, GoAffPro provided by ARV TECH in India, web pixels of the shop platform, and Shogun provided by Shogun Labs, Inc. in the United States.

In this context, device, browser, session, click, page-view, shopping-cart, order and transaction data, as well as technical identifiers, may be processed. X is provided to users in the European Economic Area by X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland. GoAffPro may process data in India and in data centers in Germany and the United States. Shogun and other providers involved may process data in the United States.

The legal bases are your consent in accordance with Article 6(1)(a) GDPR and section 25(1) TDDDG. Without your consent, these technologies are not activated for analytics or marketing purposes. You may withdraw your consent at any time through the privacy settings.

How do we provide the appropriate language and regional version?

We use Weglot and technical regional-assignment functions to provide our services in the appropriate language and regional version. In this context, your IP address, the address accessed, browser information, selected language and inferred region in particular may be processed.

Weglot is provided by Weglot SAS, 7 Cité Paradis, 75010 Paris, France. To the extent that the processing is necessary to provide the requested language or country version, it is based on Article 6(1)(f) GDPR. Our legitimate interest lies in presenting our services in an understandable and regionally appropriate manner. Storage and access operations that are strictly necessary for technical purposes are based on section 25(2) TDDDG.

How do we protect our services against automated access?

We use hCaptcha to protect forms, logins and other functions against automated misuse. In this context, device, browser, interaction and connection data may be processed in order to distinguish between human and automated access.

The provider is Intuition Machines, Inc., United States. The processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in protecting our systems, customer accounts and forms against misuse and attacks. Where access to information on your device is strictly necessary for this purpose, section 25(2) TDDDG applies. According to the provider, recognized transfer mechanisms are used for transfers to the United States. Further information is available in hCaptcha’s Privacy Policy.

How do we embed YouTube videos?

We embed videos from YouTube. A connection to YouTube is established only after you consent to the loading or playback of a video. In this context, your IP address, device information, the page accessed, usage data and technical identifiers in particular may be transmitted. If you are signed in to Google, Google may associate your use with your account.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other companies in the United States is possible. The legal bases are your consent in accordance with Article 6(1)(a) GDPR and section 25(1) TDDDG.

How do we use the Geprüfter Webshop review system?

We use the review system provided by TISKO Consulting GmbH in Germany. If you consent to a review request, your email address and the order information required for attribution may be transmitted to the provider. The legal basis is your consent in accordance with Article 6(1)(a) GDPR.

The certification seal displayed on our website is provided locally. The provider processes further data under its own responsibility only when you open a related external link or submit a review.

How do social networks process data?

Our online services contain links to our profiles on Facebook, Instagram, Pinterest, X and YouTube. Merely displaying a link does not generally result in any data being transmitted to the respective network. The privacy policy of the relevant provider applies only when you open the link.

This does not apply to separately deployed pixels, embedded media or other marketing technologies. These are described in the relevant sections of this Privacy Policy and, where required, are activated only with your consent.

If you communicate with us or publish content on our profiles on the networks named above, we process the data you provide in order to handle the relevant interaction. The legal basis is Article 6(1)(b) GDPR for inquiries relating to a contract and Article 6(1)(f) GDPR in all other cases. The platform providers process additional usage, device and profile data under their own responsibility. We and the relevant platform provider may be joint controllers in relation to statistical analyses of our profiles.

To whom do we disclose personal data?

Personal data is disclosed only where this is permitted for the performance of a contract, compliance with legal obligations, pursuit of legitimate interests, or on the basis of your consent.

Recipients may include, in particular, hosting, shop and IT service providers; inventory management and order processing service providers; payment service providers; banks; card schemes; shipping and logistics companies; customer service and communication service providers; analytics, marketing and consent management service providers; tax and legal advisors; and public authorities and courts. Processors are engaged on the basis of contracts in accordance with Article 28 GDPR.

Some of the providers named above or their subprocessors are located outside the European Economic Area or process data there. Data is transferred only subject to the requirements of Articles 44 et seq. GDPR. Depending on the recipient, we base such transfers in particular on an adequacy decision by the European Commission, valid certification under the EU-US Data Privacy Framework, standard contractual clauses, or binding corporate rules. Additional safeguards are agreed where required.

How long do we retain personal data?

We retain personal data only for as long as it is required for the relevant purpose or for as long as statutory retention obligations or legitimate grounds for further retention apply.

Depending on the type and function of the document, contract, order and payment records are retained, in particular, for six years as commercial or business correspondence, eight years as an accounting record or invoice, and ten years as a book, record or other document subject to a long statutory retention period. As a general rule, these periods begin at the end of the calendar year in which the document was created.

Inquiries and communication data are deleted once they have been conclusively dealt with and no contractual, statutory or legal grounds for further retention exist. Data relating to a customer account is deleted once the account has been deleted, unless it is still required to comply with legal obligations or to process outstanding matters.

We retain records of consent for the duration of the consent and afterwards for as long as necessary to meet our documentation and legal-defense obligations. Newsletter data is deleted after consent is withdrawn or moved to a suppression list where this is necessary to honor the withdrawal. Analytics and marketing data is deleted or anonymized once the storage period defined for the relevant service has expired.

Data may also be retained where this is necessary for the establishment, exercise or defense of legal claims. Once the original purpose no longer applies, the data is processed only for this limited purpose until the end of the remaining period.

What data protection rights do you have?

Subject to the applicable legal requirements, you have, in particular, the right to

  • obtain access to your personal data,

  • request the rectification of inaccurate data,

  • request the erasure of your data,

  • request restriction of processing,

  • request the transfer of data you have provided,

  • object to processing based on legitimate interests, and

  • withdraw consent at any time with effect for the future.

If you object to processing that we base on Article 6(1)(f) GDPR, we will no longer process the data concerned unless there are compelling legitimate grounds or grounds for the establishment, exercise or defense of legal claims. You may object to processing for direct marketing purposes at any time without stating any reasons.

To exercise your rights, you can contact us at info@quadroshop.com.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular with the Hamburg Commissioner for Data Protection and Freedom of Information. You may also lodge a complaint with any other supervisory authority competent under Article 77 GDPR.

When are you required to provide data?

If you wish to enter into a contract with us, you must provide the data required for ordering, payment and delivery. Without this data, we cannot process the order or cannot process it in full.

There is no statutory or contractual obligation to provide data in connection with voluntary services, in particular newsletters, marketing consents or information provided voluntarily to customer service.

Do we make automated decisions?

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

Payment and security service providers may carry out automated fraud-prevention or risk-assessment checks under their own responsibility. The privacy information of the relevant service provider also applies to such checks.

How do we protect personal data?

We take appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access and unlawful disclosure. Data transmitted between your browser and our online services is generally encrypted.

Last updated: July 2026

Twój koszyk

Suma częściowa: