Privacy policy
Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how we process personal data when you visit www.novawear.de, shop with NOVAWEAR, use a customer account, communicate with us, submit a review or use our other services. Personal data means any information relating to an identified or identifiable natural person.
This Privacy Policy takes into account, in particular, the European Union General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG) and, where applicable, the Swiss Federal Act on Data Protection (FADP).
Contents
- Controller and privacy contact
- Principles, legal bases and data categories
- Shopify, hosting and Shopify Network Intelligence
- Server logs and security
- Cookies, consent management and Pandectes
- Orders, contracts and customer accounts
- Personalised fashion products and design data
- Contact, email, telephone, WhatsApp and live chat
- Product reviews with Loox
- Email and SMS marketing with Klaviyo
- Production and fulfilment
- Shipping and tracking
- Payment processing
- Invoices, accounting and statutory retention
- eBay, Etsy and Shopify Collective
- Analytics, advertising and conversion measurement
- YouTube videos and social media links
- Recipients and international transfers
- Retention periods
- Your data protection rights
- Additional information for individuals in Switzerland
- Children
- Changes to this Privacy Policy
1. Controller and privacy contact
The controller responsible for the processing described in this Privacy Policy is:
Ingo Sieger, trading as NOVAWEAR
Jägersburger Straße 42
64625 Bensheim
Germany
Telephone: +49 6251 8614056
Email: info@novawear.de
Privacy requests: datenschutz@novawear.de
No data protection officer has been appointed. Please send privacy questions and requests to exercise your rights directly to datenschutz@novawear.de.
2. Principles, legal bases and data categories
2.1 Processing principles
We process personal data only where necessary for a specified purpose. In particular, we follow the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.
2.2 Legal bases
Depending on the activity, we rely in particular on the following legal bases:
- Article 6(1)(a) GDPR: you have consented to the processing, for example to newsletters, SMS marketing, marketing cookies or advertising pixels.
- Article 6(1)(b) GDPR: processing is necessary to take steps before entering into a contract or to perform a contract, including orders, payments, production, delivery, returns and customer accounts.
- Article 6(1)(c) GDPR: processing is necessary to comply with a legal obligation, particularly commercial, tax and consumer protection obligations.
- Article 6(1)(f) GDPR: processing is necessary for our legitimate interests or those of a third party, provided that your interests or fundamental rights do not override those interests. This includes IT security, fraud prevention, legal claims, efficient business operations and responding to general enquiries.
Where technologies store information on or access information from your device, non-essential technologies are used only with your consent under section 25(1) TDDDG. Strictly necessary access is based on section 25(2) TDDDG.
2.3 Categories of data
Depending on how you use our services, we may process:
- identity data such as name, title and customer or account identifiers;
- contact and address data such as email address, telephone number, billing and delivery address;
- order, product, size, variant, return and contract data;
- payment, transaction, invoice and accounting data;
- communications, support enquiries and return messages;
- customisation details, text, designs and files you provide;
- reviews, ratings, photographs and videos;
- consent, preference and marketing data;
- usage, device and log data such as IP address, browser, operating system, referrer, timestamps, page views and interactions;
- advertising and conversion data such as product views, cart events and purchases.
2.4 Sources and required information
We generally receive data directly from you, from Shopify, integrated service providers, payment and shipping partners or, for marketplace orders, the relevant marketplace. Mandatory information indicated for ordering, payment, production and delivery is required to enter into and perform the contract. Without it, we may be unable to accept or fulfil your order. Other information is voluntary unless we expressly state that it is legally or contractually required.
2.5 Automated decisions and profiling
NOVAWEAR does not generally make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Payment providers may use automated fraud and credit risk checks; their own notices apply. With your consent, marketing providers may analyse usage and purchase data for audience creation, personalisation and measurement. You may withdraw consent at any time through the cookie settings or the unsubscribe mechanism provided.
3. Shopify, hosting and Shopify Network Intelligence
3.1 Shopify platform
Our online shop is operated using Shopify. Depending on the service, contractual partners and recipients may include Shopify International Limited, 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland; Shopify Inc., 151 O'Connor Street, Ground Floor, Ottawa, Ontario K2P 2L8, Canada; and their affiliates and subprocessors.
Shopify may process device and browser information, IP address, cookie and session identifiers, pages viewed, searches and shop interactions, contact details, account data, cart, order, payment and transaction information and support communications. The purposes include secure operation, product display, cart and checkout functionality, payment processing, fraud prevention, customer accounts, order management, analytics and other Shopify features.
Where Shopify acts on our instructions, processing is governed by our agreement and Shopify's data processing terms. The applicable legal bases depend on the activity and include Articles 6(1)(b), (c) and (f) GDPR. Consent-based functions rely on Article 6(1)(a) GDPR together with section 25(1) TDDDG.
The hosting location selected in our Shopify admin is the European Union. Shopify and its subprocessors may nevertheless process data in Canada, the United States or other countries when providing the services. Please see the Shopify Consumer Privacy Policy and the Shopify Data Processing Addendum.
3.2 Shopify Network Intelligence and Enhanced Services
Shopify Network Intelligence is enabled for our store. Shopify may securely combine certain customer data with other Shopify data to provide Enhanced Services for our store. These may include a more personalised shopping experience, more relevant advertising, measurement and analysis of shop and ad interactions, fraud prevention and Shop or Shop Pay features. According to Shopify, no other merchant can access our store data.
For certain Enhanced Services, Shopify does not act solely as our processor but processes personal data for purposes described in its terms as an independent controller. Shopify explains the data it receives, its purposes and available choices in the Shopify Consumer Privacy Policy.
To the extent that Shopify Network Intelligence or related technology is not strictly necessary, it is activated for visitors in consent-required regions only after the relevant selection in the cookie banner. You may withdraw consent at any time through the cookie settings.
3.3 STRATO email infrastructure
We use services of STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany, for business email. STRATO may process sender and recipient addresses, timestamps, technical delivery information and email content as necessary to provide and secure the service. The legal basis is Article 6(1)(b), (c) or (f) GDPR depending on the communication. Please see STRATO Privacy Information.
4. Server logs and security
When you access our shop, technically necessary connection and log data is processed. This may include IP address, date and time, requested URL, referrer URL, browser, operating system, device information, data volume and status codes. It is required to deliver the website, maintain stability and security, detect technical errors and prevent attacks and misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and abuse-free operation of the shop. Logs are retained only as long as necessary for these purposes. Data relating to a security incident may be kept longer to investigate the incident, preserve evidence and establish, exercise or defend legal claims.
We and our providers use appropriate technical and organisational measures, including TLS encryption, access controls, authorisation concepts, backups and monitoring. Absolute security of data transmitted over the internet cannot, however, be guaranteed.
5. Cookies, consent management and Pandectes
5.1 Cookies and similar technology
Our shop uses cookies and similar technologies such as local storage, pixels, tags, SDKs and server-side events. Strictly necessary technologies support navigation, cart, checkout, fraud prevention, language settings, customer accounts, security and storage of your privacy choices.
Strictly necessary access to your device is based on section 25(2) TDDDG. Subsequent processing is based, depending on the purpose, on Article 6(1)(b), (c) or (f) GDPR.
Analytics, personalisation and marketing technologies are activated in consent-required regions only after you consent. The legal basis is section 25(1) TDDDG together with Article 6(1)(a) GDPR. Consent is voluntary and may be withdrawn at any time with future effect.
5.2 Consent management with Pandectes
We use Pandectes GDPR Compliance as our consent management platform. The provider is Pandectes, Pudisoo küla, Männimäe/1, 74626 Kuusalu vald, Estonia. Pandectes displays the cookie banner, manages your preferences, blocks analytics and marketing services until the required consent has been provided and records your decision.
It may process consent status, selected categories, timestamps, full or truncated IP address, device and browser information and a pseudonymous consent identifier. Processing is necessary to apply your choices and demonstrate compliance. The legal bases are Articles 6(1)(c) and (f) GDPR and section 25(2) TDDDG. Please see the Pandectes Privacy Policy.
You can change your choice through the cookie icon or “Cookie settings” link provided on our website. Withdrawal does not affect the lawfulness of processing before withdrawal.
6. Orders, contracts and customer accounts
6.1 Orders and contract performance
When you place an order, we process your name, contact, billing and shipping information, products, sizes and variants, discounts, payment status, order and transaction identifiers and communications, shipping, return and complaint data. Processing is necessary to enter into and perform the contract, receive payment, produce and deliver products, provide support, handle returns and warranties and manage legal claims.
The legal bases are Article 6(1)(b) GDPR for contract performance, Article 6(1)(c) GDPR for statutory documentation and retention and Article 6(1)(f) GDPR for fraud prevention, misuse protection and claims management.
6.2 Shopify customer accounts
You may use Shopify's new customer accounts at account.novawear.de. We process name, email address, authentication data or login tokens, saved addresses, order history, return data and communications. Authentication may use a code sent by Shopify to your email address or another method made available by Shopify.
Processing provides the account, order and address management, communications and self-service functions. The legal basis is Article 6(1)(b) GDPR. Security and abuse checks are additionally based on Article 6(1)(f) GDPR.
6.3 Self-service returns, cancellations and withdrawal
You may submit return and cancellation requests through your customer account. We process contact details, order number, affected items, reason, status, timestamps, communications and, where relevant, photographs supporting a complaint. The purposes are to handle the request, reverse the contract, issue refunds, process warranty claims and comply with legal documentation duties.
The legal bases are Articles 6(1)(b) and (c) GDPR and Article 6(1)(f) GDPR for assessing and defending against unjustified claims. You may also send withdrawal notices to retoure@novawear.de.
7. Personalised fashion products and design data
For customisable products, we process information you provide for design and production. This may include requested text, names, size and colour details, print positions, design choices, designs, image files, logos and production instructions. Information may be provided using the input methods offered in the shop or during the order and communication process.
The data is used only to assess feasibility, prepare a preview, manufacture the product, perform quality control, ship it and handle questions or complaints. The legal basis is Article 6(1)(b) GDPR. Articles 6(1)(c) and (f) GDPR additionally apply where statutory documentation or legal claims require retention.
Production data is shared, to the extent necessary, with the selected production and fulfilment provider. Please submit only content you are entitled to use. If a design contains an image or personal data of another person, you must ensure that the required rights and, where necessary, consents are in place.
Production files are deleted or restricted once they are no longer needed for production, re-orders, complaints or legal evidence, unless longer retention has been agreed or is legally required.
8. Contact, email, telephone, WhatsApp and live chat
8.1 Contact form, email and telephone
If you contact us by form, email or telephone, we process your contact details, the content of your enquiry and, where relevant, order, contract and product information. If the enquiry concerns an order, pre-purchase advice or an existing contract, the legal basis is Article 6(1)(b) GDPR. Other enquiries are handled on the basis of Article 6(1)(f) GDPR, reflecting our legitimate interest in reliable and documented communications. Legal documentation duties are based on Article 6(1)(c) GDPR.
8.2 WhatsApp Business
If you voluntarily contact us through WhatsApp, we process your mobile number, WhatsApp name, profile information, messages, attachments, timestamps and other information you provide. The provider for individuals in the EEA is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, part of the Meta group.
Processing enables us to respond. The legal basis is Article 6(1)(b) GDPR for contract-related messages and Article 6(1)(f) GDPR for general enquiries. WhatsApp is optional; you may contact us by email instead. WhatsApp processes data under its own terms and may process metadata, device and usage data and transfer data internationally. Please see the WhatsApp Privacy Policy.
8.3 Live chat, if displayed
If a live chat is displayed and activated by you, we use HB Contact Service of Händlerbund Management AG, Kohlgartenstraße 11-13, 04315 Leipzig, Germany, with Giosg.com Ltd. The chat may process technical connection data, chat and interaction data and contact details and messages you enter.
Consent-based chat technology is loaded only after you consent. The legal basis is Article 6(1)(a) GDPR together with section 25(1) TDDDG. Article 6(1)(b) GDPR additionally applies when responding to a contract-related enquiry. If the chat is disabled or not displayed, we do not process data through this service.
9. Product reviews with Loox
We use Loox, provided by Loox Online Ltd., 40 Tuval Street, 14th Floor, Ramat Gan 5252247, Israel, to collect, verify and display authentic product reviews. Loox may process order and product information, name, email address, review status, rating, review text, photographs, videos, timestamps, IP address and device and usage information.
After a purchase, we may send a review request where permitted by law or where you have consented. You can opt out of further requests using the unsubscribe mechanism. The legal basis for technical delivery and verification is, depending on the circumstances, Article 6(1)(a) or (f) GDPR, subject to applicable electronic marketing rules.
If you voluntarily submit a review, photograph or video, we process and publish the content you select and the display name or initials provided. Your email address is not displayed publicly. The legal basis is your consent under Article 6(1)(a) GDPR or your requested use of the review service. You may withdraw relevant consent and request deletion, subject to legal exceptions.
According to the information you provided, we do not offer a discount in exchange for reviews and do not import reviews from external sources. Please see the Loox End User Privacy Policy.
10. Email and SMS marketing with Klaviyo
10.1 Newsletters and SMS
We use Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02111, USA, and its affiliates for email newsletters, SMS marketing, forms, segmentation, personalised recommendations and automated marketing flows. Klaviyo may process name, email address, mobile number, consent status, language, country-level location, customer and order data, product interests, cart, purchase and return events and technical usage data.
Email and SMS marketing is based on your consent under Article 6(1)(a) GDPR and applicable electronic marketing law. Sign-up is confirmed using double opt-in. To demonstrate consent, we retain the sign-up and confirmation time, source, wording of consent and technical evidence. This evidence processing is based on Articles 6(1)(c) and (f) GDPR.
You may unsubscribe from email through the link in each message and from SMS using the method described in the message or by contacting us. After unsubscribing, we may retain your identifier on a suppression list to prevent further marketing. The legal basis is Article 6(1)(f) GDPR.
10.2 Open, click and performance analytics
With your consent, messages may contain tracking pixels and personalised links. Klaviyo and we may learn whether a message was delivered or opened, which links were used and whether a purchase or other interaction followed. This may be associated with your customer profile and used to optimise, segment and personalise communications.
The legal basis is Article 6(1)(a) GDPR and, where information is stored on or read from your device, section 25(1) TDDDG. You may withdraw consent at any time.
10.3 Abandoned cart messages
If you have consented to marketing and leave products in your cart, we may send a reminder through Klaviyo. Contact, cart, product, interaction and potentially order data is processed. The legal basis is Article 6(1)(a) GDPR. Where existing-customer advertising is exceptionally used under a statutory exception, it is used only if all legal requirements are met and on the basis of Article 6(1)(f) GDPR. You may object at any time.
Please see the Klaviyo Privacy Notice and Klaviyo Data Processing Agreement.
11. Production and fulfilment
Some of our fashion products are manufactured on demand and shipped directly after your order. Depending on the product, we share necessary production and shipping data with:
- MarketPrint / MarketConsultive GmbH, Allgäuerstraße 20, 87719 Mindelheim, Germany;
- Shirtee.Cloud / Boender und Beutel GmbH, Vogelsanger Straße 356-358, 50827 Cologne, Germany.
Data may include name, delivery address, contact details, order number, product, size, colour, quantity, print and customisation data and shipping or complaint information. The providers use it for production, quality control, packaging, delivery and complaints. The legal basis is Article 6(1)(b) GDPR. Statutory evidence is based on Article 6(1)(c) GDPR and fraud and claims checks on Article 6(1)(f) GDPR.
Further information: MarketPrint Privacy Information and Shirtee.Cloud Privacy.
12. Shipping and tracking
For shipping, delivery and tracking, we disclose necessary information to DHL, the relevant DHL Group entity and, where applicable, delivery partners. This may include name, delivery address, email address, telephone number, order and shipment number and delivery preferences.
Name, address and shipment data are shared to perform the contract under Article 6(1)(b) GDPR. Email address or telephone number may be provided for delivery notifications and flexible delivery where necessary for the agreed delivery, otherwise legally permitted or based on your consent. The applicable legal basis is Article 6(1)(b) or (a) GDPR.
Please see DHL Group Data Protection.
13. Payment processing
Depending on country, device, order value and availability, different payment methods may be offered at checkout. Payment, contact, billing, order, device and transaction data is shared with Shopify and the selected payment provider. Providers may additionally process data for authentication, fraud prevention, credit or risk assessment and their own legal obligations.
Payment processing is based on Article 6(1)(b) GDPR. Statutory checks, documentation and retention are based on Article 6(1)(c) GDPR. Security and fraud prevention may be based on Article 6(1)(f) GDPR. Optional consent-based technologies rely on Article 6(1)(a) GDPR together with section 25(1) TDDDG.
13.1 Shopify Payments and payment cards
We use Shopify Payments. Depending on the method, Shopify entities, payment processors appointed by Shopify, banks, card schemes and technical providers may be involved. Methods may include Visa, Mastercard, American Express, Maestro, UnionPay and EPS. Full card information is generally submitted directly to the payment provider; we usually receive status, identification and settlement information only.
13.2 Shop Pay
When you use Shop Pay, Shopify processes account, contact, payment, device and transaction data required for accelerated checkout and recognition. Please see the Shopify Consumer Privacy Policy.
13.3 PayPal
If PayPal is selected, necessary information is transferred to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Depending on the PayPal feature selected, additional payment or credit providers may be involved. Please see the PayPal Privacy Statement.
13.4 Klarna
For a Klarna payment method, Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden, receives information necessary for payment, identity verification and, where relevant, credit assessment. Klarna independently decides whether to offer the method. Please see Klarna Privacy.
13.5 Apple Pay and Google Pay
With Apple Pay or Google Pay, the payment is authorised through the wallet stored on your device and the payment providers involved. Apple or Google may process device, wallet, authentication and transaction information under their own terms. Please see Apple Privacy and the Google Privacy Policy.
The checkout identifies the payment methods available for your transaction and the relevant provider.
14. Invoices, accounting and statutory retention
We use Lexware Office and Sufio to create, send and retain invoices, credit notes and tax-relevant documents. They may process identity data, addresses, email address, order items, prices, discounts, taxes, payment status, invoice numbers and other accounting information.
- Lexware Office is provided by Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany.
- Sufio is a cloud invoicing service operated by Sufio s.r.o., Slovakia.
The legal bases are Article 6(1)(b) GDPR for contract-related invoicing and Article 6(1)(c) GDPR for commercial and tax obligations. Article 6(1)(f) GDPR may additionally apply to proper commercial organisation.
Please see Lexware Privacy and the Sufio Privacy Policy.
15. eBay, Etsy and Shopify Collective
15.1 eBay and Etsy
We may also sell products through eBay and Etsy. When you interact with or order from us there, the marketplace provides information required for communications, contract performance, payment, production, shipping and support. This may include username, name, contact data, billing and delivery address, products, payment status, messages and transaction data.
eBay or Etsy is responsible under its own privacy terms for processing within the marketplace. NOVAWEAR's subsequent processing is governed by the purposes and legal bases in this Policy, particularly Articles 6(1)(b), (c) and (f) GDPR. Please see the eBay Privacy Notice and Etsy Privacy Policy.
15.2 Shopify Collective
Shopify Collective enables collaboration between Shopify retailers and suppliers. Where an order contains a Collective product, order, customer, delivery, product, return and settlement information may be exchanged between us, Shopify and the participating supplier or retailer. Processing supports product display, inventory coordination, contract performance, direct delivery, returns and settlement. The legal bases are Articles 6(1)(b) and (c) GDPR and Article 6(1)(f) GDPR for secure coordination and fraud prevention.
16. Analytics, advertising and conversion measurement
16.1 General information
With your consent, we use analytics and marketing services to understand shop usage, measure campaigns, create audiences, personalise advertising and evaluate results. Providers may process browser and device information, IP address, cookie and advertising identifiers, pages viewed, searches, product views, cart and checkout events, purchases, order value and pseudonymised or hashed contact information.
Browser-based and server-side events are controlled by Pandectes according to your consent. The legal basis is Article 6(1)(a) GDPR together with section 25(1) TDDDG. You may withdraw consent through the cookie settings. Without consent, analytics and marketing pixels remain blocked for visitors in consent-required regions.
16.2 Meta Pixel and Conversions API
We use Meta Business Tools, including the Meta Pixel and server-side event transmission, provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. They help us measure actions after ad interactions, create audiences and display interest-based advertising on Facebook and Instagram.
Meta may combine information with Meta accounts and other data and process it for its own purposes. We and Meta may be joint controllers for the collection and transmission of certain event data; Meta is independently responsible for its subsequent processing. Please see the Meta Privacy Policy.
16.3 Google & YouTube, Google Analytics and Google Ads
We use services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, including the Google & YouTube sales channel, Google Analytics 4 and Google Ads conversion, audience and advertising features. Google may process device and usage information, IP address, cookie and advertising identifiers, shop interactions, product and purchase data and, for enhanced measurement, hashed contact information.
Google uses the information for reporting, campaign measurement, audience creation, ad personalisation and, depending on your Google settings, its own purposes. Please see the Google Privacy Policy and How Google uses information from sites or apps that use its services.
16.4 Pinterest Tag
We use the Pinterest Tag and server-side events from Pinterest Europe Ltd., Waterloo Exchange, 3rd Floor, Waterloo Road, Dublin 4, Ireland, and Pinterest, Inc., USA. This allows us to measure conversions, create audiences and personalise Pinterest advertising. Pinterest may process event, device, cookie, purchase and hashed contact information. Please see the Pinterest Privacy Policy.
16.5 TikTok Pixel and Events API
We use the TikTok Pixel and server-side event features of TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, TikTok Information Technologies UK Limited and, where relevant, affiliated entities. Processing supports ad measurement, attribution, audience creation and personalised advertising. TikTok may process device, browser, cookie, event, purchase and hashed contact information and associate it with TikTok accounts.
Please see the TikTok Privacy Policy.
16.6 Klaviyo web and server tracking
With your consent, Klaviyo receives web and server-side events to update customer profiles and segments, trigger forms and marketing flows, personalise recommendations and measure campaigns. Section 10 of this Policy also applies.
17. YouTube videos and social media links
17.1 Embedded YouTube videos
We embed campaign videos using YouTube. The provider for the EEA and Switzerland is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Loading a video may transmit IP address, device and browser data, referrer, video and interaction information, cookie identifiers and, if you are signed into Google, account information.
YouTube is loaded in consent-required regions only after you consent. The legal basis is Article 6(1)(a) GDPR together with section 25(1) TDDDG. Without consent, the video will not load or only a placeholder will be shown. Please see the Google Privacy Policy.
17.2 Linked social media profiles
Our website contains ordinary links to profiles including Instagram, Facebook, TikTok and YouTube. A link alone generally does not establish a connection to the platform until you select it. After selecting a link, you leave our area of responsibility and the platform operator's privacy terms apply.
18. Recipients and international transfers
We disclose personal data only where permitted for contract performance, legal compliance, legitimate interests or with your consent. Recipients may include:
- shop, hosting, email, IT, security and support providers;
- production, print-on-demand, fulfilment and shipping providers;
- payment providers, banks, card schemes and fraud prevention services;
- invoicing, accounting, tax and legal advisers;
- marketing, analytics, review and consent management providers;
- marketplaces, distribution partners and Shopify Collective partners;
- authorities, courts and public bodies where disclosure is required.
Some providers or subprocessors are located outside the EU, EEA or Switzerland, particularly in Canada, Israel and the United States. Transfers take place only where legal requirements are met. Safeguards may include an adequacy decision, including for Canada, Israel or US recipients certified under the EU-US Data Privacy Framework, the European Commission's Standard Contractual Clauses and additional technical and organisational measures. Where you have expressly consented to a third-country transfer, Article 49(1)(a) GDPR may also apply.
For individuals in Switzerland, we additionally comply with the FADP requirements and use recognised countries or appropriate safeguards for disclosures abroad.
19. Retention periods
We keep personal data only for as long as necessary for the purpose or required by law. Relevant criteria include:
- Order, contract, invoice and tax information: for statutory commercial and tax periods, generally six or eight years and longer in certain cases;
- Customer account: until account deletion; order records subject to contract or retention duties remain unaffected;
- Contact and support information: until the matter is complete and then as required for limitation and evidence;
- Returns, withdrawal, warranty and complaints: for handling and subsequent statutory limitation and evidence periods;
- Production and customisation data: until production, potential re-order and complaint handling are complete, unless longer retention is required or agreed;
- Marketing information: until withdrawal or objection; evidence and suppression records may be kept longer to defend legal claims and prevent unwanted messages;
- Reviews: generally until deletion, withdrawal of relevant consent or the purpose ceases;
- Cookie and analytics data: for the duration indicated in the consent tool or by the provider;
- Security logs: generally for a short period; incident data may be kept until investigation and claims handling are complete.
After the relevant period, data is deleted or anonymised unless another legal or contractual basis applies.
20. Your data protection rights
Subject to the legal requirements, you have the following rights:
- access under Article 15 GDPR;
- rectification under Article 16 GDPR;
- erasure under Article 17 GDPR;
- restriction under Article 18 GDPR;
- data portability under Article 20 GDPR;
- objection under Article 21 GDPR;
- not to be subject to a solely automated decision under Article 22 GDPR;
- withdrawal of consent at any time with future effect.
Objection to processing based on legitimate interests
You have the right to object, on grounds relating to your particular situation, at any time to processing based on Article 6(1)(f) GDPR. Where personal data is processed for direct marketing, you may object at any time without giving reasons. Following a valid objection, we will no longer process the relevant data for those purposes.
Withdrawal of consent
You may withdraw consent at any time with future effect. Withdrawal does not affect the lawfulness of processing before withdrawal. Cookie consent can be managed through the cookie settings; marketing consent can also be withdrawn through an unsubscribe link or by contacting us.
Exercising your rights
Please send requests to datenschutz@novawear.de. To protect your information, we may request reasonable proof of identity. For data Shopify processes as an independent controller, you may also contact Shopify or use the Shopify Privacy Portal.
Right to complain
You have the right to lodge a complaint with a data protection authority. The authority particularly responsible for us is:
The Hessian Commissioner for Data Protection and Freedom of Information
Postfach 3163
65021 Wiesbaden
Germany
Telephone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Website: https://datenschutz.hessen.de
You may also contact the authority at your habitual residence, place of work or the place of the alleged infringement.
21. Additional information for individuals in Switzerland
For individuals in Switzerland, the Swiss Federal Act on Data Protection additionally applies. We process personal data lawfully, in good faith, proportionately, transparently and only for specified purposes.
Subject to the Swiss FADP, you may request access, correction, deletion or destruction, restriction or cessation of processing and, where applicable, the release or transfer of personal data.
For disclosures abroad, we ensure an adequate level of protection through a recognised country, appropriate data protection clauses or a statutory exception. Complaints may be addressed to:
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern
Switzerland
Website: https://www.edoeb.admin.ch
22. Children
Our services are not directed to children under 16. Where consent is the legal basis, individuals under 16 should provide personal data only with the authorisation of a parent or legal guardian. If we learn that a child's data was processed without required authorisation, we will take appropriate steps to delete it.
23. Changes to this Privacy Policy
We update this Privacy Policy when our processing activities, providers or applicable law change. The version published on this website is the current version. Where legally required, we will notify you appropriately of material changes.
Last updated: 23 July 2026