Privacy policy

Data Protection & Privacy Policy

Responsible Party

The responsible party pursuant to data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:

Julie Hansen & Laura Traver-Herold

Your Rights as a Data Subject

You can exercise the following rights at any time using the contact details of our data protection officer:

  • Information on your data stored by us and its processing (Art. 15 GDPR)
  • Rectification of inaccurate personal data (Art. 16 GDPR)
  • Deletion of your data stored by us (Art. 17 GDPR)
  • Restriction of data processing if we cannot delete data due to legal obligations (Art. 18 GDPR)
  • Objection to data processing (Art. 21 GDPR)
  • Data portability, if you have consented or entered into a contract with us (Art. 20 GDPR)

If you have given consent, you may withdraw it at any time. You can also contact a supervisory authority with a complaint, e.g., your local authority or the authority overseeing us. A list of authorities is available here.

General Information Collected on Our Website

Type and Purpose of Processing

When you visit our website without registering or submitting information, general data is automatically collected (server log files), including:

  • Web browser type
  • Operating system
  • Domain name of your internet service provider
  • IP address

This data is used to ensure website functionality, system security, stability, and for administrative purposes. It is not used to identify individual users and may be analyzed statistically to improve our website.

Legal Basis

Art. 6 Para. 1 (f) GDPR – our legitimate interest in improving website stability and functionality.

Recipients

Technical service providers involved in website operation and maintenance may access this data as processors.

Retention Period

Data is deleted once it is no longer needed, usually after the session ends.

Mandatory or Optional Provision

Providing this data is not legally required, but some website functions may not work properly without it.

Website Registration

Registration allows access to personalized services. Personal data collected includes name, contact details, and other registration information. Registered users can edit or delete data anytime.

Legal Basis

Art. 6 Para. 1 (a) GDPR – user consent.
Art. 6 Para. 1 (b) GDPR – if registration is part of contractual obligations or pre-contractual measures.

Recipients

Technical service providers managing website operations as processors.

Retention Period

Data is retained only with consent and deleted when consent is withdrawn, unless legal obligations require otherwise.

Mandatory or Optional Provision

Providing personal data is voluntary but required to access content and services.

Newsletter

Your data will be used for sending newsletters. Name and email are used for personal addressing and identification for GDPR rights. Registration requires a valid email. Data is never shared with third parties.

Newsletter emails can be used for marketing purposes via Meta.

Legal Basis

Art. 6 Para. 1 (a) GDPR – consent. You can withdraw consent anytime via the unsubscribe link in each newsletter.

Recipients

Newsletter processors.

Retention Period

Data is processed only with consent and deleted afterward.

Mandatory or Optional Provision

Providing personal data is voluntary; newsletter cannot be sent without consent.

Contact Form

Data submitted via the contact form is used for communication. Name and valid email are required; additional information is optional.

Legal Basis

Art. 6 Para. 1 (f) GDPR – legitimate interest in efficient communication.
Art. 6 Para. 1 (b) GDPR – if contacting us for a contract offer.

Recipients

Contact form processors.

Retention Period

Data deleted 6 months after processing, or longer if statutory retention applies.

Mandatory or Optional Provision

Providing personal data is voluntary but necessary for processing inquiries.

Google Analytics

We use Google Analytics for website usage analysis. IP anonymization is enabled; data is sent to Google in the USA under Privacy Shield compliance.

Legal Basis

Art. 6 Para. 1 (a) GDPR – user consent.

Recipients

Google LLC as processor.

Retention Period

Data deleted when no longer necessary for analysis.

Mandatory or Optional Provision

Providing data is voluntary; disabling cookies may limit website functionality.

Google AdWords

We use Google Conversion Tracking to measure ad performance. Cookies track clicks but do not personally identify users.

Legal Basis

Art. 6 Para. 1 (a) GDPR – user consent.

Recipients

Google LLC in the USA.

Retention Period

Cookies expire after 30 days; no personal identification.

Mandatory or Optional Provision

Providing data is voluntary; disabling cookies may limit functionality.

Revision of Our Privacy Policy

We reserve the right to amend this privacy policy to comply with legal requirements or update our services. Your next visit will be subject to the new policy.

Questions for the Data Protection Officer

If you have any questions regarding data protection, please contact us via email: hello@nouinoui.com

Trusted Shops Trustbadge

We use Trusted Shops Trustbadge for reviews and buyer protection. Personal data processed through the Trustbadge follows Art. 6 Para. 1 (f) GDPR. Further details are available at Trusted Shops Privacy Policy.