Thank you for your interest in our website and online shop. Protecting your personal data is important to us. Below we inform you about how we process your personal data in accordance with the General Data Protection Regulation (GDPR).
Â
1. Controller
The controller responsible for data processing on this website is:
Nalu Canoes
Inh. Marton Buday
Winckelmannstr. 21
42287 Wuppertal
Germany
Email: nalucanoes@gmail.com
⸻
2. Collection and Storage of Personal Data
We process personal data when you:
•visit our website,
•register or place an order in our online shop,
•subscribe to our newsletter or contact us,
•interact with integrated services (payment, analytics, CRM).
The following categories of data may be collected:
•Identification and contact details (name, address, email, phone).
•Order and payment details.
•Technical usage data (IP address, browser, device type, time of access).
⸻
3. Purpose and Legal Basis of Processing
•Website operation & security (Art. 6(1)(f) GDPR – legitimate interest).
•Order processing and delivery (Art. 6(1)(b) GDPR – contract performance).
•Payment processing (Art. 6(1)(b) GDPR).
•Customer support & CRM via HubSpot (Art. 6(1)(f) GDPR – legitimate interest).
•Email newsletter if subscribed (Art. 6(1)(a) GDPR – consent).
•Analytics & marketing tools (Art. 6(1)(a) GDPR – consent).
•Legal retention of invoices and tax data (Art. 6(1)(c) GDPR – legal obligation).
⸻
4. Data Sharing with Third Parties
We only share personal data where necessary for contract performance or where legally permitted:
•WooCommerce (Automattic Inc.) – shop system, order management.
•Germanized (Vendidero GmbH) – adds legal compliance features to checkout.
•Stripe Payments Europe, Ltd. – payment processor (credit card, Apple Pay, Google Pay). Data may be transferred to the USA. Privacy policy: https://stripe.com/privacy.
•HubSpot Inc. – CRM, forms, and marketing automation. Privacy policy: https://legal.hubspot.com/privacy-policy.
•Google Analytics & reCAPTCHA (Google LLC) – web analytics and fraud prevention. Privacy policy: https://policies.google.com/privacy.
We ensure data is only processed by service providers within the EU or in countries with adequate data protection standards.
⸻
5. Cookies & Tracking
We use cookies and similar technologies for:
•website functionality (essential cookies),
•analytics (Google Analytics),
•marketing/CRM (HubSpot).
You can manage cookie preferences at any time through our cookie banner.
⸻
6. Data Retention
•Order and invoice data: 10 years (German tax law).
•Customer accounts: until deletion request.
•Newsletter data: until consent withdrawn.
•Technical logs: max. 7 days, unless needed longer for security.
⸻
7. Your Rights
You have the following rights under GDPR:
•Access to your data (Art. 15 GDPR),
•Rectification (Art. 16 GDPR),
•Erasure (Art. 17 GDPR),
•Restriction of processing (Art. 18 GDPR),
•Data portability (Art. 20 GDPR),
•Objection to processing (Art. 21 GDPR),
•Withdrawal of consent (Art. 7(3) GDPR).
You may lodge a complaint with the competent supervisory authority (Landesdatenschutzbeauftragter NRW).
⸻
8. Contact
For any questions about data protection, please contact us at:
Nalu Canoes
Inh. Marton Buday
Winckelmannstr. 21
42287 Wuppertal
Germany
Email: nalucanoes@gmail.com