Privacy Policy

Privacy Policy for the website

We kindly ask you to carefully read the following summary regarding the operation of our website.

The following privacy notices are intended to inform you about how we use your personal data. We will strictly adhere to the provisions of German data protection law as well as the requirements of the European General Data Protection Regulation (GDPR).

 Controller and Contact for Your Data Protection

The controller within the meaning of the GDPR, as well as other data protection laws applicable in the EU member states and other regulations of a data protection nature, is:

Nervus GmbH, Ginsterweg 7a, 239795 Bad Segeberg

Michael Romin

Phone: 04551-956730

Scope of Processing Personal Data

We generally collect and use personal data from you only to the extent necessary to provide a functioning website, as well as its content and services. For example, this includes registering on our website, logging into an existing customer account, or placing product orders. The collection and use of your personal data regularly occur only with your consent. An exception applies in cases where obtaining prior consent is not possible for factual reasons and the processing of data is permitted by statutory provisions.

The security of your personal data is a high priority for us. We protect your data stored with us through technical measures provided by Shopware and organizational measures implemented by us personally to effectively prevent loss or misuse by third parties. Should additional employees be hired to process personal data, they will be obligated to maintain strict confidentiality of our data and comply with our data protection standards. 

To ensure the ongoing protection of your data, technical security measures are regularly reviewed and, if necessary, adapted to the state of the art. These principles also apply to companies that process and use data on our behalf and in accordance with our instructions.

 Purposes of Processing and Legal Basis for Processing Your Personal Data

 We collect, process, and use your personal data for the following purposes:

  • Establishing and executing contractual relationships
  • Dispatching printed products
  • Sending newsletters (newsletters are only sent upon your explicit request)
  • Customer service and support
  • Providing telemedia, such as order processing for our online offering of goods and services

 The processing of your personal data may be based on the following legal grounds:

  •  Article 6(1)(a) of the GDPR serves as the legal basis for processing operations in which we obtain your consent for a specific processing purpose.
  • Article 6(1)(b) of the GDPR, to the extent that the processing of personal data is necessary for the performance of a contract, e.g., when you purchase a product. The same applies to processing operations that are necessary for the execution of pre-contractual measures, such as inquiries regarding our product selection or services.
  • Article 6(1)(c) of the GDPR, to the extent that we are subject to a legal obligation that requires the processing of personal data, such as fulfilling tax obligations.
  • Article 6(1)(d) of the GDPR in the event that vital interests of you or another natural person necessitate the processing of personal data.
  • Article 6(1)(f) of the GDPR is applicable on the basis of our legitimate interests, e.g., when using service providers for contract processing, such as shipping services, conducting statistical surveys and analyses, and logging registration procedures. Our interest is directed toward the use of a user-friendly, appealing, and secure presentation as well as the optimization of our web offering, which serves both our business interests and meets your expectations.

Duration of Storage and Routine Deletion of Personal Data

We process and store your personal data only for the period necessary to fulfill the purpose of storage or as required by laws or regulations. After the purpose has been achieved or fulfilled, your personal data will be deleted or blocked. In the case of blocking, deletion will take place as soon as there are no legal, statutory, or contractual retention periods preventing it, there is no reason to believe that deletion would impair your legitimate interests, and deletion does not involve disproportionate effort due to the special nature of the storage.

Collection of General Data and Information, so-called Log Files

With each visit, our website collects a set of general data and information based on Article 6(1)(f) of the GDPR, which are temporarily stored in server log files. A log file is created as part of an automatic logging process by the processing computer system. The following data can be collected:

  • Access to the website (date, time, and frequency)
  • How you accessed the website (previous page, hyperlink, etc.)
  • Amount of data sent
  • Which browser and browser version you are using
  • The operating system you are using
  • Which Internet service provider you are using
  • Your IP address, which your Internet access provider assigns to your computer when connecting to the Internet

The collection and storage of this data are necessary for the operation of the website to ensure the functionality of the website and to deliver the content of our website correctly. Additionally, the data serves us for the optimization of the website and to ensure the security of Shopware’s IT systems. For this reason, the data is stored for a maximum of 7 days as a technical precaution. 

This data is used for advertising, market research, and the demand-oriented design of our services by creating and evaluating usage profiles under pseudonyms, but only to the extent that you have not exercised your right to object to the use of your data (see information on the right to object in the “Your Rights” section).

Sending Information about Our Offers and Special Promotions, such as Newsletters

We use your data to send you information about our offers and other promotions from us to the email address you provided. The consent for sending is based on Article 6(1)(a), Article 7 of the GDPR, as well as § 7(3) of the German Unfair Competition Act (UWG).

  1. a) Newsletter Subscription on Our Website

Auf unserer Webseite besteht die Möglichkeit einen kostenfreien Newsletter zu abonnieren. Dabei werden bei der Anmeldung zum Newsletter die Daten aus der Eingabemaske an unser System übermittelt, also mindestens Ihre E-Mailadresse.
The registration is done using the so-called double opt-in procedure. After registration, you will receive an email asking you to confirm your subscription. This confirmation is necessary to prevent anyone from signing up with third-party email addresses. As part of the registration process, your consent is obtained for the processing of the data, and you are referred to these data protection notices.

  1. b) Sending Information due to the Sale of Goods and Services

If you purchase goods or services on our website, we may send you information about our own similar goods, changes, and services to your provided email address without requiring your consent.

  1. c) Postal Mailings

We may also use your data to send you information about our offers and promotions via postal mailings.

Certain informational messages that are necessary for contract processing and the functionality of our website, such as service-related messages (e.g., registration confirmation, customer service information) or messages related to a paid package, such as order confirmation, contract documents, and payment processing, cannot be unsubscribed from. You will receive these notifications at the contact information you provided.

Processing of Personal Data When Contacting, Registering, or Guest Ordering

  1. a) Contact

When you contact us via email or through a contact form, the data you provide will be stored by our system based on Article 6(1)(a) of the GDPR to answer your inquiries. The contact is logged to be able to prove the contact in accordance with legal requirements. Your consent is obtained for the processing of data through the contact form, and you are referred to these data protection notices.

  1. b) Registration

On our website, we offer you the opportunity to register by providing personal data. The data is entered into an input mask and transmitted to our system for storage. Registration is for the fulfillment of a contract or the performance of pre-contractual measures and is therefore based on Article 6(1)(b) of the GDPR.

For the conclusion and execution of contracts, we may require contact information such as names, delivery and billing addresses, email addresses, and information about the payment method you have chosen, depending on the individual case. Additionally, we use your data to maintain our customer database to ensure that only accurate data is stored there. To avoid typographical errors and ensure that your ordered items arrive at your location, we check the completeness and correctness of your address during data entry.

  1. c) Miscellaneous

Based on Article 6(1)(c) and (f) of the GDPR, we may use and store your personal data and technical information to the extent necessary to prevent abuse or other unlawful behavior on our website, such as maintaining data security in the event of attacks on Shopware’s IT system. This also includes cases where we are legally obligated to do so, such as due to official or court orders, and for the protection and defense of our rights and claims.

Disclosure of Personal Data to Third Parties

When disclosing your personal data to third parties (tax consultants, shipping service providers, direct suppliers), or for internal processing, we always strive to maintain a high level of security. Therefore, your data is only shared with our selected and contractually obligated service providers and partner companies. Furthermore, we only forward your data to entities located within the European Economic Area (EEA) and therefore subject to strict EU data protection laws, or to entities obligated to adhere to an equivalent level of protection.

  1. a) Disclosure within affiliated companies pursuant to Article 6(1)(b) of the GDPR

We share your personal data with affiliated companies in Germany for the conclusion and execution of contracts related to offers on our website. This is done for storage in central databases and for internal billing and accounting purposes within the company.

  1. b) Access by service providers pursuant to Article 6(1)(b) and (f) of the GDPR

For the operation and optimization of our website and technical processing, Shopware provides services such as IT services or hosting within our website. Shopware is not allowed to access our system without our consent. If access is necessary for technical reasons, they are strictly obligated to comply with Article 6(1)(b) and (f) of the GDPR.

Unlike data processing on behalf of us, in the following cases, we transfer data to third parties for their independent use in contract processing:

  •  When delivering goods to logistics companies and postal service providers specified during the order.
  1. c) Disclosure to other third parties pursuant to Article 6(1)(c) and (f) of the GDPR

We will disclose your data to third parties or government authorities in accordance with existing data protection laws if we are legally obligated to do so, for example, due to a governmental or court order, or if we are authorized to do so, for example, to pursue criminal activities or for the protection and enforcement of our rights and claims.

Your Rights

Requested information will be provided promptly, but no later than within one month of the request.
You have the right to receive information about your personal data, access your data, request correction,
or request deletion. In case of a legitimate complaint, you can contact the independent state data protection authority.

Independent State Center for Data Protection

Holstenstraße 98

24103 Kiel

Postfach 71 16
24171 Kiel

Phone: 0431 988-1200 
Fax: 0431 988-1223


Links to Websites of Other Companies

Our website may contain links to websites of other companies. We are not responsible for the privacy practices on external websites that you may access through these links.

Changes to Privacy Policy

To ensure that our privacy policy always complies with current legal requirements, we reserve the right to make changes at any time. This also applies in case the privacy policy needs to be adapted due to new or revised offers or services.

Data Protection Officer:

Ulrika Geiselberger
Ginsterweg 7a
23795 Bad Segeberg
Phone: 04551-956730

As of: September 2023