Privacy policy
Data Protection & Privacy Policy
Responsible Party
The responsible party pursuant to data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:
Julie Hansen & Laura Traver-Herold
Your Rights as a Data Subject
You can exercise the following rights at any time using the contact details of our data protection officer:
- Information on your data stored by us and its processing (Art. 15 GDPR)
- Rectification of inaccurate personal data (Art. 16 GDPR)
- Deletion of your data stored by us (Art. 17 GDPR)
- Restriction of data processing if we cannot delete data due to legal obligations (Art. 18 GDPR)
- Objection to data processing (Art. 21 GDPR)
- Data portability, if you have consented or entered into a contract with us (Art. 20 GDPR)
If you have given consent, you may withdraw it at any time. You can also contact a supervisory authority with a complaint, e.g., your local authority or the authority overseeing us. A list of authorities is available here.
General Information Collected on Our Website
Type and Purpose of Processing
When you visit our website without registering or submitting information, general data is automatically collected (server log files), including:
- Web browser type
- Operating system
- Domain name of your internet service provider
- IP address
This data is used to ensure website functionality, system security, stability, and for administrative purposes. It is not used to identify individual users and may be analyzed statistically to improve our website.
Legal Basis
Art. 6 Para. 1 (f) GDPR – our legitimate interest in improving website stability and functionality.
Recipients
Technical service providers involved in website operation and maintenance may access this data as processors.
Retention Period
Data is deleted once it is no longer needed, usually after the session ends.
Mandatory or Optional Provision
Providing this data is not legally required, but some website functions may not work properly without it.
Website Registration
Registration allows access to personalized services. Personal data collected includes name, contact details, and other registration information. Registered users can edit or delete data anytime.
Legal Basis
Art. 6 Para. 1 (a) GDPR – user consent.
Art. 6 Para. 1 (b) GDPR – if registration is part of contractual obligations or pre-contractual measures.
Recipients
Technical service providers managing website operations as processors.
Retention Period
Data is retained only with consent and deleted when consent is withdrawn, unless legal obligations require otherwise.
Mandatory or Optional Provision
Providing personal data is voluntary but required to access content and services.
Newsletter
Your data will be used for sending newsletters. Name and email are used for personal addressing and identification for GDPR rights. Registration requires a valid email. Data is never shared with third parties.
Newsletter emails can be used for marketing purposes via Meta.
Legal Basis
Art. 6 Para. 1 (a) GDPR – consent. You can withdraw consent anytime via the unsubscribe link in each newsletter.
Recipients
Newsletter processors.
Retention Period
Data is processed only with consent and deleted afterward.
Mandatory or Optional Provision
Providing personal data is voluntary; newsletter cannot be sent without consent.
Contact Form
Data submitted via the contact form is used for communication. Name and valid email are required; additional information is optional.
Legal Basis
Art. 6 Para. 1 (f) GDPR – legitimate interest in efficient communication.
Art. 6 Para. 1 (b) GDPR – if contacting us for a contract offer.
Recipients
Contact form processors.
Retention Period
Data deleted 6 months after processing, or longer if statutory retention applies.
Mandatory or Optional Provision
Providing personal data is voluntary but necessary for processing inquiries.
Google Analytics
We use Google Analytics for website usage analysis. IP anonymization is enabled; data is sent to Google in the USA under Privacy Shield compliance.
Legal Basis
Art. 6 Para. 1 (a) GDPR – user consent.
Recipients
Google LLC as processor.
Retention Period
Data deleted when no longer necessary for analysis.
Mandatory or Optional Provision
Providing data is voluntary; disabling cookies may limit website functionality.
Google AdWords
We use Google Conversion Tracking to measure ad performance. Cookies track clicks but do not personally identify users.
Legal Basis
Art. 6 Para. 1 (a) GDPR – user consent.
Recipients
Google LLC in the USA.
Retention Period
Cookies expire after 30 days; no personal identification.
Mandatory or Optional Provision
Providing data is voluntary; disabling cookies may limit functionality.
Revision of Our Privacy Policy
We reserve the right to amend this privacy policy to comply with legal requirements or update our services. Your next visit will be subject to the new policy.
Questions for the Data Protection Officer
If you have any questions regarding data protection, please contact us via email: hello@nouinoui.com
Trusted Shops Trustbadge
We use Trusted Shops Trustbadge for reviews and buyer protection. Personal data processed through the Trustbadge follows Art. 6 Para. 1 (f) GDPR. Further details are available at Trusted Shops Privacy Policy.

