Privacy Policy

With this privacy policy, we inform you about how personal data is processed when using our online shop. Personal data is any information relating to an identified or identifiable natural person.

1. Controller

The controller for data processing on this website is:

GIOTELLI Europe GmbH
Lohstraße 84
47798 Krefeld
Germany

E-mail: hello@giotelli.com
Phone: +49 (0) 2151 513 23 53

For questions about data protection or to exercise your data protection rights, you can contact us using the contact details provided above.

Note: The term "Data Protection Officer" should only be used if a data protection officer has actually been appointed.

2. Provision of the Website and Technical Data

When you access our website, technically necessary information is processed. This may include, in particular, IP address, date and time of access, pages accessed, referrer URL, browser type, operating system, and technical device information.

Processing takes place, as far as necessary, for the secure and stable provision of our online shop, for error analysis, and for preventing abusive or fraudulent use. The legal basis is Art. 6 para. 1 lit. f GDPR, insofar as processing is based on our legitimate interest in a secure and functional online offering.

3. Shopify

Our online shop is operated via the e-commerce platform Shopify. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland; affiliated Shopify companies may also be involved in the processing.

Shopify processes personal data to the extent necessary for the operation and provision of the online shop. Depending on the function, Shopify can act as a processor or, in certain areas, as an independent controller.

As part of the use of Shopify, personal data may be processed outside the European Economic Area. Where necessary, the transfer takes place on the basis of appropriate safeguards in accordance with Art. 44 et seq. GDPR.

Further information on data processing by Shopify can be found in Shopify's current privacy notices.

4. Orders and Contract Fulfillment

When you place an order in our online shop, we process the data required for processing and fulfilling your order. This may include, in particular, name, billing and delivery address, email address, telephone number, ordered items, order and transaction data, and information on the selected payment and shipping method.

Processing takes place for the performance of pre-contractual measures and for the fulfillment of the purchase contract concluded with you in accordance with Art. 6 para. 1 lit. b GDPR. If there are legal retention obligations, further storage is based on Art. 6 para. 1 lit. c GDPR.

5. Customer Account

If you create or use a customer account, we process the data required for this, such as contact details, login data, order history, and account information you have stored.

Processing takes place for the provision and management of the customer account in accordance with Art. 6 para. 1 lit. b GDPR. If a customer account is offered voluntarily and used independently of a contract, processing may additionally be based on Art. 6 para. 1 lit. f GDPR.

6. Payment Processing

For payment processing, the necessary data is transmitted to the payment service provider you selected. Depending on the chosen payment method, this may include, in particular, name, billing address, order value, transaction identifiers, and payment information.

Processing takes place for the processing of your order in accordance with Art. 6 para. 1 lit. b GDPR. Payment service providers may additionally process personal data on their own responsibility, for example, for fraud prevention, identity verification, or compliance with legal obligations.

Before going live, the payment providers actually offered in the GIOTELLI checkout must be individually supplemented here, e.g., Shopify Payments, PayPal, Klarna, Apple Pay, or other providers actually activated.

7. Shipping and Delivery

To deliver your order, we transmit the necessary shipping data to the respective shipping or logistics company. This includes, in particular, name, delivery address, and – if necessary for delivery or provided by you – contact information.

Processing takes place for contract fulfillment in accordance with Art. 6 para. 1 lit. b GDPR.

The specific shipping service provider should be added before publication as soon as it is finally determined which provider will actually be used in the shop.

8. Contact and Customer Service

If you contact us by email, contact form, telephone, or any other communication channel we offer, we process your information to handle your request. This may include, in particular, name, email address, telephone number, order number, and the content of your message.

If your request relates to an existing or planned contract, processing takes place on the basis of Art. 6 para. 1 lit. b GDPR. In other cases, it is based on our legitimate interest in the proper processing of inquiries in accordance with Art. 6 para. 1 lit. f GDPR.

9. Newsletter and Email Marketing

If you subscribe to our newsletter or other promotional email communications, we use your email address and any other information you provide to send the relevant information.

The sending takes place on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR, unless another legal basis applies. You can revoke a given consent at any time with effect for the future, for example, via the unsubscribe link in the respective email.

The revocation does not affect the lawfulness of the processing carried out on the basis of the consent until revocation.

10. Cookies and Similar Technologies

Our online shop uses cookies and similar technologies. Some of these are technically necessary for basic functions of the shop to be provided, such as shopping cart, checkout, security functions, or language settings.

Insofar as cookies or similar technologies are not technically necessary – in particular for analysis, personalization, or marketing – they are generally only used according to your selection in the cookie or consent banner.

You can change or revoke your selection via the data protection settings provided on the website.

The old static cookie list should not be adopted. The cookies actually used change depending on the Shopify configuration, theme, apps, tracking, and marketing services. The information must match the real cookie/consent setup.

11. Analytics, Marketing, and External Services

If we use analytics, marketing, social media, or other external services, information about the use of our website may be processed and, if applicable, transmitted to the respective providers.

Non-technically necessary services are – where legally required – only activated after your consent. The legal basis in these cases is Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time with effect for the future via the cookie or privacy settings.

Before going live, the freelancer or shop administrator must check all active Shopify Apps, tracking pixels, analytics, advertising, review, chat, currency, search/filter, and social media integrations. Every service actually used must be correctly represented in the privacy policy and consent banner.

12. Currency and Language Settings

If functions for automatic currency or language adjustment are used, technical information such as IP address, location information, language settings, or cookies may be processed for this purpose. Such processing only takes place to the extent necessary for the respective function, or – if consent is required – on the basis of your consent.

Only retain this section if a corresponding geolocation, currency, or localization function is actually active in the final shop. The generic old wording should not be adopted unchanged.

13. Recipients of Personal Data

We only pass on personal data if this is necessary for the stated purposes, there is a legal obligation, or a corresponding legal basis exists. Recipients may include IT and hosting service providers, Shopify and affiliated service providers, payment providers, shipping and logistics companies, communication and marketing service providers, and professional advisors commissioned by us.

14. Data Transfers to Third Countries

When using individual service providers, personal data may be transferred to countries outside the European Union or the European Economic Area. Insofar as there is no adequacy decision for the respective third country, we ensure an adequate level of data protection – where necessary – by suitable safeguards, for example, standard contractual clauses.

15. Storage Period

We store personal data only as long as this is necessary for the respective processing purposes or legal retention obligations exist.

Contract and invoice data may be stored for the legally prescribed duration, in particular due to commercial and tax law requirements. Data based on consent is generally processed until revocation, unless another legal basis or retention obligation exists.

16. Your Data Protection Rights

Insofar as the legal requirements are met, you have the following rights in particular:

·         Information about the data processed about you (Art. 15 GDPR)

·         Rectification of inaccurate or incomplete data (Art. 16 GDPR)

·         Erasure of personal data (Art. 17 GDPR)

·         Restriction of processing (Art. 18 GDPR)

·         Data portability (Art. 20 GDPR)

·         Objection to certain processing operations (Art. 21 GDPR)

·         Revocation of given consents with effect for the future (Art. 7 para. 3 GDPR)

To exercise your rights, you can contact us at hello@giotelli.com.

17. Right to Lodge a Complaint with a Supervisory Authority

You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. You can contact in particular the data protection supervisory authority responsible for our company's registered office or another supervisory authority competent according to the GDPR.

18. Data Security

We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction. Data transfer between your browser and our website is generally encrypted.

For security reasons, we do not publish general technical assurances regarding specific encryption algorithms or storage methods, unless these are demonstrably applicable to all systems used.

19. Minors

Our online shop is not specifically aimed at children. Insofar as consent is required for certain data processing operations, the legal requirements for the capacity of minors to consent apply.

20. Changes to this Privacy Policy

We may adapt this privacy policy if our data processing operations, services used, or legal requirements change. The current version is available on this website.

Status: September 2026