Privacy Policy
DEGELER GmbH & Co. KG
Privacy Policy
As of: June 2026
This privacy policy has been comprehensively updated and complies with the requirements of the GDPR, the BDSG, the TTDSG, and the Digital Services Act (DSA). It replaces all previous versions.
1. General Information and Responsible Body
This privacy policy informs you about the collection, processing, and use of personal data in connection with the use of our website www.degeler.com and our online shop. We take the protection of your data very seriously and treat your personal data confidentially and in accordance with statutory data protection regulations.
Responsible body in the sense of the GDPR:
DEGELER GmbH & Co. KG
Carl-Zeiss-Str. 10/4
63322 Roedermark
Germany
Legally represented by: D & D Verwaltungs GmbH, represented by Managing Director Frank B. Degeler
Email: info@degeler.com
Phone: +49 (0) 6074 8856 99
Imprint: https://degeler.com/pages/impressum
We reserve the right to adapt this privacy policy to reflect changes in legal requirements or new technical developments. The current version can be found at www.degeler.com/datenschutz.
2. Data Protection Officer
A data protection officer has not been appointed as there is no legal obligation to do so (Art. 37 GDPR). If you have any questions about data protection, you can always contact us directly: info@degeler.com
3. Collection and Processing of Personal Data
3.1 Server Log Files and Hosting
Our website is hosted by Shopify International Ltd., Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. When you access our website, information is automatically recorded in server log files:
– Visited pages (URLs)
– Time of access
– Amount of data transferred
– Referrer
– Browser type and version
– Operating system
– IP address (anonymized, as far as technically possible)
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in stability and security). Storage period: generally 7 days.
We have a data processing agreement (DPA) with Shopify in accordance with Art. 28 GDPR. Further information: https://www.shopify.com/legal/privacy
3.2 Cookies and Similar Technologies
Our website uses cookies and similar technologies. Detailed information on this can be found in our cookie policy at www.degeler.com/cookie-policy.
3.3 Content Delivery Network (CDN)
We use Shopify's CDN to improve loading times. Data may be delivered via internationally distributed servers. Legal basis: Art. 6 (1) lit. f GDPR. Data transfer to third countries is based on EU standard contractual clauses.
4. Contacting Us
If you contact us by email or via our contact form, your information will be stored for processing and answering your request. Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual measures) or Art. 6 (1) lit. f GDPR (legitimate interest).
The data will be deleted after final processing, provided there are no statutory retention obligations (e.g., tax law retention according to § 147 AO: 10 years).
5. Newsletter Dispatch
If you subscribe to our newsletter, we process your email address and – if provided – your name. The registration takes place via a double opt-in procedure. Legal basis: Art. 6 (1) lit. a GDPR (consent).
You can withdraw your consent at any time with future effect, e.g., via the unsubscribe link in each newsletter email or by email to info@degeler.com.
Newsletters are sent via Klaviyo Inc., 225 Franklin Street, Floor 10, Boston, MA 02110, USA. A DPA exists with Klaviyo; data transfer to the USA is based on EU standard contractual clauses.
6. Online Shop and Order Processing
If you order in our online shop, we process the following data for contract execution:
– Name, delivery address, optionally different billing address
– Email address and phone number
– Payment information (transmitted directly to the payment service provider)
– Order history
Legal basis: Art. 6 (1) lit. b GDPR (contract execution). Storage period: 10 years according to commercial and tax law retention obligations.
Recipients of the data may be:
– Payment service providers: PayPal (Europe) S.a.r.l. & Cie, S.C.A. and Amazon Europe Core S.a.r.l.
– Shipping service provider: LOEWE Logistics & Care, Roentgenstr. 17, 32052 Herford
– Shopify International Ltd. (processor)
7. Web Analytics and Tracking
7.1 Shopify Analytics
We use Shopify Analytics to analyze user behavior in our shop. Processing is based on your consent (Art. 6 (1) lit. a GDPR). You can revoke your consent at any time via our cookie banner.
7.2 Google Analytics 4
We use Google Analytics 4 from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Your IP address is anonymized. The collected data is pseudonymized and not merged with other data.
Legal basis: Art. 6 (1) lit. a GDPR (consent). Data transfer to the USA is based on EU standard contractual clauses. Further information: https://policies.google.com/privacy
8. Social Media
Our website contains links to social networks (Instagram, Facebook, Pinterest). Data will only be transferred to the respective providers after you actively use the links.
We operate our own presence pages on the following platforms:
– Instagram / Facebook: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland
– Pinterest: Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland
We are jointly responsible with the respective providers for data processing on these platforms (Art. 26 GDPR). Legal basis: Art. 6 (1) lit. f GDPR.
9. Phone Numbers, SMS and WhatsApp
If you expressly consent, we collect your phone number for the following purposes:
– Order confirmation and shipping notifications
– Reminders for abandoned shopping carts (once, only with consent)
– Marketing communication (only with separate consent)
Legal basis: Art. 6 (1) lit. a GDPR (consent). You can withdraw your consent at any time, e.g., by replying "STOP" to an SMS or by email to info@degeler.com.
Your phone number will not be passed on or sold to unaffiliated third parties without explicit consent.
10. Location-based Data
DEGELER does not collect precise location data (e.g., GPS). For technical reasons, approximate location information (country/region) can be determined based on the IP address. This is solely for the technical provision of the website and compliance with legal requirements. No data is passed on to third parties.
11. Disclosure of Data to Third Parties
Personal data will only be passed on if this is necessary for the performance of the contract or if you have given your consent. Recipients may include:
– Payment service providers (PayPal, Amazon Pay)
– Shipping service providers (LOEWE Logistics & Care)
– IT service providers and hosting (Shopify)
– Email and newsletter services (Klaviyo)
– Analytics and marketing services (Google, Meta, Pinterest) – only with consent
All service providers are contractually obliged to comply with the GDPR (data processing agreements in accordance with Art. 28 GDPR).
12. Data transfer to third countries
Some of the services we use transfer data to countries outside the EU/EEA (especially the USA). This is done on the basis of:
– EU standard contractual clauses (Art. 46 para. 2 lit. c GDPR), or
– an adequacy decision by the EU Commission (e.g. EU-US Data Privacy Framework)
Upon request, we will inform you about the guarantees used in individual cases (info@degeler.com).
13. Your rights as a data subject
You have the following rights under the GDPR:
– Right of access (Art. 15 GDPR)
– Right to rectification (Art. 16 GDPR)
– Right to erasure (Art. 17 GDPR)
– Right to restriction of processing (Art. 18 GDPR)
– Right to data portability (Art. 20 GDPR)
– Right to object (Art. 21 GDPR)
– Right to withdraw consent (Art. 7 para. 3 GDPR)
To exercise your rights, please contact: info@degeler.com
In addition, you have the right to lodge a complaint with the competent data protection supervisory authority (Art. 77 GDPR). The competent authority for DEGELER is:
The Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
Postfach 3163, 65021 Wiesbaden
www.datenschutz.hessen.de
14. Storage period
Personal data will only be stored for as long as necessary to fulfil the respective purposes or as required by statutory retention periods:
– Order data: 10 years (§ 147 AO, § 257 HGB)
– Contact inquiries: until final processing, max. 3 years
– Newsletter data: until revocation of consent
– Server log files: usually 7 days
– Analytics/tracking data: depending on the provider, max. 26 months
15. Data security
We implement technical and organizational security measures to protect your data against loss, misuse, and unauthorized access. Our website is transmitted exclusively via an encrypted HTTPS connection (TLS encryption).
16. Updating this privacy policy
This privacy policy may be amended to reflect new legal or technical developments. The current version is always available at www.degeler.com/datenschutz. We will inform you separately of any significant changes.
DEGELER GmbH & Co. KG | Carl-Zeiss-Str. 10/4, 63322 Roedermark | info@degeler.com | Status: June 2026