top of page

Privacy Policy

1. Who Is Responsible for Your Data

 

The controller responsible for the processing of personal data through Galovirexa is:

 

KRENTA UG (haftungsbeschränkt)

Lehmweg 53

20251 Hamburg

Germany

 

Commercial Register: Amtsgericht Hamburg, HRB 200236

Managing Director: Fred Kramer

 

Website: galovirexa.com

 

Electronic enquiries can be submitted through the Contact page on the website.

 

2. Purpose of This Privacy Policy

 

This Privacy Policy explains how personal data may be collected and used when customers visit Galovirexa, place an order, contact the business, create an account where available, or otherwise use the website.

 

Personal data means information relating to an identified or identifiable person.

 

3. Data We May Process

 

Depending on how the website is used, the following categories of personal data may be processed:

 

- Name and contact details

- Billing and delivery address

- Order and transaction information

- Payment-related information received from or passed to payment service providers

- Account information where customer accounts are available

- Messages and customer-service correspondence

- Technical information such as IP address, device information, browser information and security logs

- Cookie or similar-technology information where used

- Marketing preferences where a user has made a choice about marketing communications

 

Galovirexa does not need to receive or store a customer's full payment-card details where payment is handled directly by an external payment provider.

 

4. Why We Process Personal Data

 

Personal data may be processed for the following purposes:

 

a. Processing and fulfilling orders

 

Data is used to receive orders, process payment, prepare products, arrange delivery, provide order information and handle returns or complaints.

 

The legal basis is normally the performance of a contract or steps requested before entering into a contract.

 

b. Customer service

 

Data may be used to answer questions, respond to requests, resolve problems and manage customer communication.

 

The legal basis may be contract performance or the legitimate interest in providing effective customer support.

 

c. Legal and accounting obligations

 

Certain order, invoice, tax or business records may need to be retained to comply with legal obligations.

 

The legal basis is compliance with legal requirements.

 

d. Website security and fraud prevention

 

Technical and transaction information may be processed where reasonably necessary to protect the website, customers and the business against fraud, abuse, unauthorised access or security incidents.

 

The legal basis may be a legitimate interest in maintaining a secure and reliable online service.

 

e. Marketing

 

Where marketing emails or similar communications are offered, personal data will be used for this purpose only where there is an appropriate legal basis, such as consent or another basis permitted by law.

 

Where processing is based on consent, consent can be withdrawn for the future.

 

5. Cookies and Similar Technologies

 

The website may use cookies or similar technologies that are necessary for functions such as security, shopping-cart operation, checkout, customer login or preference storage.

 

Non-essential cookies or technologies for analytics, marketing or similar purposes will be used only where permitted by applicable law and, where required, after the user has given consent.

 

Users can manage available cookie choices through the website's consent tools where provided.

 

6. Service Providers and Recipients

 

Personal data may be shared with service providers only where this is reasonably necessary for operating the store or fulfilling legal and contractual duties.

 

Recipient categories may include:

 

- Website hosting and e-commerce service providers

- Payment service providers

- Delivery and logistics providers

- IT, security and technical-support providers

- Accounting, tax or professional advisers where necessary

- Public authorities where disclosure is legally required

 

These recipients process data under their own legal responsibilities or under appropriate processing arrangements, depending on their role.

 

7. International Data Transfers

 

Some technology or service providers may process data outside Germany or the European Economic Area.

 

Where personal data is transferred internationally, the business will use an appropriate legal mechanism where required, such as an adequacy decision, approved contractual safeguards or another transfer mechanism permitted by applicable data-protection law.

 

8. Retention

 

Personal data is kept only for as long as necessary for the purpose for which it was collected and for any additional period required by law.

 

Order, accounting and tax information may need to be retained for statutory retention periods.

 

Customer-service records may be kept for a reasonable period where needed to resolve enquiries, defend legal claims, prevent abuse or document transactions.

 

When data is no longer needed and no legal reason requires further retention, it will be deleted or anonymised where appropriate.

 

9. Your Rights

 

Subject to the conditions of applicable data-protection law, individuals may have the right to:

 

- Request access to personal data

- Request correction of inaccurate data

- Request deletion of data

- Request restriction of processing

- Object to certain processing

- Receive eligible data in a portable format

- Withdraw consent at any time for future processing where consent is the legal basis

- Lodge a complaint with a data-protection supervisory authority

 

Exercising a right does not affect processing that was lawful before a withdrawal of consent.

 

10. Right to Object

 

Where personal data is processed on the basis of legitimate interests, a person may have the right to object to that processing for reasons relating to their particular situation.

 

Where personal data is processed for direct marketing, the person may object to such processing at any time.

 

11. Data Security

 

Reasonable technical and organisational measures are used to protect personal data against accidental loss, unlawful access, unauthorised alteration and other inappropriate processing.

 

No internet service can guarantee absolute security, but appropriate safeguards should be maintained and updated according to the risks involved.

 

12. Children's Data

 

Galovirexa is not intended to knowingly collect personal data from children who are not legally able to make purchases or provide valid consent on their own.

 

13. External Links

 

The website may contain links to third-party websites or services. Galovirexa is not responsible for the privacy practices of independent third parties. Users should review the privacy information provided by those third parties.

 

14. Complaints to the Supervisory Authority

 

Individuals may lodge a data-protection complaint with the competent supervisory authority.

 

For a company established in Hamburg, the relevant authority is:

 

The Hamburg Commissioner for Data Protection and Freedom of Information

Ludwig-Erhard-Straße 22

20459 Hamburg

Germany

 

15. Updates to This Privacy Policy

 

This Privacy Policy may be updated when website functions, service providers, business processes or legal requirements change.

 

The current version will be made available on galovirexa.com.

bottom of page