Privacy Policy

Last updated: 7/22/2026

PRIVACY POLICY


1. Controller and Contact

Controller within the meaning of the GDPR:

Hatice Kuzyurt Sole proprietor with small business regulation Wiener Neustädter Straße 102 2601 Sollenau, Austria

Commercial register number: not available (sole proprietor with small business regulation) VAT number: ATU83318018

Phone: +43 69010187207 (Telephone available 14-18 o'clock) Email: [email protected] Website: https://kuzgen.com Legal Notice: https://kuzgen.com/de/impressum

Managing Director/Owner: Hatice Kuzyurt


2. Data Protection Officer

The appointment of a data protection officer is not legally mandatory for our company. For data protection inquiries, please contact the controller mentioned above directly.


3. Overview of Processing Activities

Based on our data architecture, we process personal data in the following areas:

AreaCategories of Data Subjects
User Account & RegistrationName, email, telephone, password (hashed), region, language settings
Address ManagementFirst/last name, company, address, telephone
Order ProcessingOrder, payment, shipping data, IP address, acceptance of GTC
Payment TransactionsPayment method, payment intent IDs
Shopping CartProduct selection, session ID
WishlistProduct preferences
Product ReviewsReview text, title, rating, verification status
NewsletterEmail, language preference, subscription status
Email CampaignsOpening and click behavior
Contact InquiriesName, email, message, IP address
Service RequestsRefund/warranty data, uploaded images
CouponsUsage behavior per customer
CookiesCookie preferences, consent version and timestamp

4. Legal Bases for Processing (Art. 6 GDPR)

We process personal data exclusively on the basis of the following legal bases:

a) Consent – Art. 6(1)(a) GDPR

  • Newsletter subscription
  • Cookie settings (non-essential cookies)
  • Email marketing campaigns
  • Product reviews (voluntary submission)

b) Performance of a Contract – Art. 6(1)(b) GDPR

  • Registration and management of the user account
  • Order processing and delivery
  • Payment processing
  • Shopping cart functionality
  • Refund and warranty processing
  • Address management

c) Legal Obligation – Art. 6(1)(c) GDPR

  • Tax and commercial law retention obligations (BAO, UGB)
  • Documentation of acceptance of GTC (proof obligations)
  • Invoicing

d) Legitimate Interest – Art. 6(1)(f) GDPR

  • IP address collection for fraud prevention in orders
  • IP address collection on contact forms (abuse protection)
  • Order status history (quality assurance)
  • Internal statistics and business optimization
  • IT security and system integrity

5. User Account and Registration

5.1 Data Collected

When registering and using your user account, we process:

DataPurposeMandatory/Voluntary
Email AddressAccount login, communicationMandatory
Password (as a hash)AuthenticationMandatory
First name, last namePersonalization, salutationMandatory
Telephone numberContact for delivery questionsVoluntary
RegionTax calculation, shipping optionsAutomatic
Preferred LanguageInterface language settingAutomatic/Choice
Last Login TimeAccount securityAutomatic
Cookie PreferencesConsent managementMandatory (legal)
Cookie Consent VersionProof obligationAutomatic
Cookie Consent TimestampProof obligationAutomatic

5.2 Authentication (Auth.js)

For user authentication, we use the Auth.js framework in conjunction with Supabase Auth. The processing of your personal data within the scope of login primarily occurs within our web application.

When using the Google Social Login, the following data is transmitted from the provider to us:

  • Name
  • Email Address
  • Profile Picture (URL)
  • Unique User ID of the provider

This data is stored for the creation and management of your user account with us.

Processed data includes:

  • Email Address
  • Hashed Password
  • Authentication Tokens (Session Cookies)
  • Login Metadata

This data is stored in our own database on a virtual private server (VPS) of Hetzner Online GmbH within the EU.

5.3 Email Delivery and Verification (Resend)

For sending emails to verify your email address (emailVerified), to reset the password, or for order documents, we use the service Resend.

Provider: Resend Labs Inc., 226 Lowell St, Wilmington, MA 01887, USA Privacy Policy: https://resend.com/privacy Transfer: Standard Contractual Clauses (SCC)

5.4 Retention Period

Account data is stored for the duration of the business relationship and permanently deleted within 30 days after account deletion, unless legal retention obligations oppose this.


6. Address Data

6.1 Data Collected

For shipping and invoicing purposes, we process:

  • First name and last name
  • Company name (optional)
  • Street and house number
  • Address addition / apartment (optional)
  • City, state, postal code
  • Country
  • Telephone number (optional)
  • Designation as default address

6.2 Purpose and Legal Basis

Processing occurs for the performance of a contract (Art. 6(1)(b) GDPR) – specifically for the shipment of ordered goods and invoicing.

6.3 Multiple Addresses

You can store multiple addresses in your account and set a default address. Addresses no longer needed can be deleted by you at any time, provided they are not linked to open or archived orders.


7. Order Processing

7.1 Data Collected During the Order Process

For each order, we process:

DataPurpose
Order NumberUnique Identification
Invoice Address (Reference)Invoicing
Shipping Address (Reference)Goods Dispatch
Order Items (Product, Variant, Quantity, Price)Subject of Contract
Subtotal, Shipping Costs, Taxes, Discounts, Total AmountPrice Calculation
Order Status, Payment Status, Fulfillment StatusOrder Tracking
Payment MethodPayment Processing
Payment-Intent IDPayment assignment via payment service provider
Shipping Method, Tracking Number, Shipping ProviderDelivery Tracking
Coupon ReferenceDiscount Application
Customer NotesNotes desired by the customer
IP AddressFraud Prevention
Acceptance of GTC (Version and Timestamp)Legal Proof Obligation

7.2 IP Address in Orders

We store your IP address during order processes based on our legitimate interest (Art. 6(1)(f) GDPR) for fraud prevention and detection. The IP address is deleted 6 months after order completion, unless a fraud case exists.

7.3 Documentation of Acceptance of GTC

We document your consent to our General Terms and Conditions including the accepted version. This serves to fulfill our legal proof obligations (Art. 6(1)(c) GDPR).

7.4 Order Status History

Changes to the order status are logged with a timestamp, status value, optional comment, and the responsible employee. This serves for quality assurance and traceability (legitimate interest, Art. 6(1)(f) GDPR).

7.5 Administrative Notes

Internal notes (adminNotes) are only visible to authorized employees and serve for efficient order processing. They contain no data that is passed on to you as a customer, unless explicitly necessary.

7.6 Retention Period

Order data is stored for 7 years from the end of the calendar year of the order in accordance with Austrian tax and commercial law retention obligations (§ 132 BAO, § 212 UGB).


8. Payment Processing

8.1 Payment Service Providers

For payment processing, we use the following service provider:

Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland Privacy Policy: https://stripe.com/at/privacy

Payment in the web shop can be made using the following payment methods: Credit Card, Klarna, Apple Pay, Sofortüberweisung, Google Pay, Amazon Pay, Cartes Bancaires, Samsung Pay, Bancontact, BLIK, EPS, TWINT.

8.2 Data Processed

We transmit to the payment service provider:

  • Order amount and currency
  • Payment method
  • Your reference ID assigned by the payment service provider

We do not store or process complete credit card numbers, bank details, or other sensitive payment instruments ourselves. We only store a Payment-Intent ID for payment assignment.

8.3 Legal Basis

Performance of a contract (Art. 6(1)(b) GDPR).


9. Shopping Cart and Session Tracking

9.1 Functionality

Our shopping cart stores the products, variants, and quantities you have selected. This happens:

  • For logged-in users: Linking with your user ID (stored server-side)
  • For not logged-in users: Not available

9.2 Session ID

The session ID is a technically necessary identifier that assigns your browser session to a server-side shopping cart. It contains no personal data but enables pseudonymous assignment.

9.3 Legal Basis

  • Logged-in users: Performance of a contract (Art. 6(1)(b) GDPR)
  • Not logged-in users: Not applicable. As no guest checkout is offered, no processing takes place here.

9.4 Retention Period

Shopping carts of logged-in users remain until manual deletion or account closure.


10. Wishlist

10.1 Functionality

Logged-in users can save products on a personal wishlist. The product reference and the time of addition are stored.

10.2 Legal Basis

Performance of a contract (Art. 6(1)(b) GDPR) as part of the account service you actively use.


11. Product Reviews

11.1 Data Collected

When submitting a product review, we process:

  • Rating (stars/rating)
  • Review title
  • Comment text
  • Verification status (whether a purchase occurred)
  • Approval status (moderation)
  • "Helpful" counter

11.2 Public Visibility

After approval by moderation, your review is displayed publicly on the product page. The displayed information includes: First name and the first letter of the last name (example: "Maximilian K.").

11.3 Legal Basis

Consent (Art. 6(1)(a) GDPR). You can withdraw your review at any time by contacting us.

11.4 Verified Purchases

The field isVerified indicates whether the reviewer has actually purchased the product through our shop. This serves transparency and consumer protection.


12. Newsletter

12.1 Registration and Double-Opt-In

We offer an email newsletter. Registration occurs via a double-opt-in procedure:

  1. You enter your email address
  2. You receive a confirmation email
  3. Only after clicking the confirmation link will you be added to the distribution list

12.2 Data Collected

DataPurpose
Email AddressNewsletter Dispatch
Activity StatusSubscription Management
Registration TimestampProof of Consent
Deregistration TimestampDocumentation
Preferred LanguageNewsletter Language Selection
User Reference (if logged in)Account Linking

12.3 Deregistration

Every newsletter contains an unsubscribe link. Unsubscribing is possible at any time and effective immediately. We use personalized unsubscribe tokens (UnsubscribeToken) with limited validity to ensure the security of the unsubscribe process.

12.4 Legal Basis

Consent (Art. 6(1)(a) GDPR). The consent can be revoked at any time with effect for the future.

12.5 Newsletter Service Provider

We use the service provider Resend for sending and managing our newsletter.

Provider: Resend Labs Inc., 226 Lowell St, Wilmington, MA 01887, USA Privacy Policy: https://resend.com/privacy Transfer: Standard Contractual Clauses (SCC)


13. Email Campaigns and Tracking

13.1 Email Campaigns

We occasionally send email campaigns to newsletter subscribers. In doing so, we collect:

DataPurpose
Campaign Name and ContentManagement
Recipient ListTarget Group Segmentation
Dispatch TimeDocumentation
Target GroupRelevance Increase
Number of OpensSuccess Measurement
Number of ClicksSuccess Measurement
Dispatch CountStatistics

13.2 Email Tracking (Opens and Clicks)

Our email campaigns may contain tracking technologies:

  • Open Tracking: Embedded tracking pixels (1x1 pixel images) that trigger a server request when the email is opened
  • Click Tracking: Redirection of links via our server to record clicks

For each recipient, we log in the email log (EmailLog):

  • Recipient Email
  • Subject
  • Delivery status and error messages
  • Open time
  • Click time

13.3 Legal Basis for Email Tracking

Consent (Art. 6(1)(a) GDPR), granted as part of newsletter registration.

13.4 Objection to Tracking

You can object to email tracking by:

  • Disabling the loading of external images in your email program
  • Unsubscribing from the newsletter
  • Contacting us directly at [email protected]

14. Email System (Internal Communication)

14.1 Scope

Our internal email system processes the following data for business communication with customers:

  • Sender and recipient email addresses (including CC, BCC)
  • Subject and message content (text and HTML)
  • Priority and folder assignment
  • Thread and reference IDs (for conversation histories)
  • Sending and receiving times
  • Email attachments (file name, type, size, URL)

14.2 Email Drafts

Unsent email drafts are stored server-side and may contain recipients, subject, and content.

14.3 Legal Basis

  • Customer communication within the scope of existing contracts: Performance of a contract (Art. 6(1)(b) GDPR)
  • Documentation: Legitimate interest (Art. 6(1)(f) GDPR)

15. Contact

15.1 Contact Form

When using our contact form, we process:

DataPurpose
NameSalutation and Assignment
Email AddressResponding to your inquiry
SubjectCategorization
MessageProcessing your matter
User Reference (if logged in)Account Linking
IP AddressAbuse Protection
Read/Archived StatusInternal Administration

15.2 IP Address in Contact Inquiries

Your IP address is stored for abuse prevention (legitimate interest, Art. 6(1)(f) GDPR) and deleted after 30 days.

15.3 Legal Basis

  • For pre-contractual inquiries: Initiation of a contract (Art. 6(1)(b) GDPR)
  • For general inquiries: Legitimate interest (Art. 6(1)(f) GDPR)

15.4 Retention Period

Contact inquiries are deleted 3 years after final processing, unless further retention obligations exist.


16. Refund and Warranty Requests

16.1 Refund Requests

For refund requests, we process:

  • Order reference
  • Reason for refund
  • Detailed description
  • Refund amount
  • Uploaded images (as proof)
  • Status and administrative notes
  • Resolution time

16.2 Warranty Requests

For warranty requests, we process:

  • Order reference
  • Description of the problem
  • Uploaded photos
  • Preferred solution
  • Actual solution
  • Status and administrative notes

16.3 Communication Regarding Service Requests

Via our ContactRequest system, messages can be exchanged regarding ongoing refund and warranty cases, including uploaded files and images.

16.4 File Uploads

Uploaded files (RequestUpload) are stored securely and are only accessible to the requester and authorized employees.

Storage location of files: Hetzner Online GmbH server location Germany / EU

16.5 Legal Basis

Performance of a contract (Art. 6(1)(b) GDPR) and legal obligation (Art. 6(1)(c) GDPR) within the scope of statutory warranty (§§ 922 ff ABGB) and distance selling law (§ 11 ff FAGG).

16.6 Retention Period

Service requests are retained for 3 years after closure (oriented to the general limitation period pursuant to § 1489 ABGB).


17. Coupons and Discount Promotions

17.1 Data Collected

When using coupons, we process:

  • Assignment of coupons to eligible customers (CouponCustomer)
  • Usage history per customer and order (CouponCustomerUsage)

17.2 Purpose

  • Ensuring correct redemption
  • Preventing multiple use
  • Traceability for accounting purposes

17.3 Legal Basis

Performance of a contract (Art. 6(1)(b) GDPR).


18. Cookies and Consent Management

18.1 Cookie Consent Management

We use a cookie consent system that stores your settings as follows:

DataPurpose
Cookie PreferencesYour selected cookie categories
Consent VersionAssignment to the valid cookie policy
Consent TimestampProof of Consent

18.2 Categories of Cookies

a) Technically Necessary Cookies (No Opt-In Required)

CookiePurposeStorage Duration
CookiePurposeStorage Duration
---------
sessionAuthentication token (session status)7 days
sb-access-tokenAuthenticationSession
sb-refresh-tokenSession RenewalPersistent
cookie-consentStorage of your cookie settings12 months

b) Functional Cookies (Opt-In)

CookiePurposeStorage Duration
CookiePurposeStorage Duration
---------
langRemember preferred language12 months

c) Analytics Cookies (Opt-In)

CookieProviderPurposeStorage Duration
_ga, _gidGoogle AnalyticsUsage Analysis2 years / 24h
_ga_XXXXXXGoogle AnalyticsSession Maintenance2 years

18.3 Changing Cookie Settings

You can change or revoke your cookie settings at any time via the "Cookie Settings" link in the footer of our website.

18.4 Legal Basis

  • Technically necessary cookies: Legitimate interest (Art. 6(1)(f) GDPR) or § 165(3) TKG 2021
  • All other cookies: Consent (Art. 6(1)(a) GDPR, § 165(1) TKG 2021)

19. Hosting and Technical Infrastructure

19.1 Web Hosting

Provider: Hetzner Online GmbH Address: Industriestr. 25, 91710 Gunzenhausen, Germany Server Location: Germany (EU) Privacy Policy: https://www.hetzner.com/de/legal/privacy-policy/

19.2 Database Hosting

Our database is hosted at:

Provider: Hetzner Online GmbH Address: Industriestr. 25, 91710 Gunzenhausen, Germany Server Location: Germany (EU) Privacy Policy: https://www.hetzner.com/de/legal/privacy-policy/

19.3 File Storage (Images, Uploads)

Uploaded files and product images are stored at:

Provider: Hetzner Online GmbH Address: Industriestr. 25, 91710 Gunzenhausen, Germany Server Location: Germany (EU) Privacy Policy: https://www.hetzner.com/de/legal/privacy-policy/

19.4 Content Delivery Network (CDN)

We use a CDN to accelerate delivery:

CDN Provider: Cloudflare, Inc. Address: 101 Townsend Street, San Francisco, CA 94107, USA Privacy Policy: https://www.cloudflare.com/privacypolicy/

19.5 Server Log Files

Every time our website is accessed, the following data is automatically recorded in server log files:

  • Accessed page/file
  • Date and time of access
  • Amount of data transferred
  • Message about successful retrieval
  • Browser type and version
  • User's operating system
  • Referrer URL (previously visited page)
  • IP address (anonymized or complete)
  • Requesting provider

Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR) in ensuring technical operation and IT security.

Retention Period: Server log files are automatically deleted after 30 days.


20. Web Analysis and Tracking

20.1 Google Analytics

We use Google Analytics to analyze the use of our website.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Data Processed: IP address (anonymized), usage data (e.g., visited pages, dwell time), browser information, device data IP Anonymization: Yes (enabled by default in Google Analytics 4) Server Location: USA/Ireland Privacy Policy: https://policies.google.com/privacy Legal Basis: Consent (Art. 6(1)(a) GDPR) Opt-Out: Via the cookie banner or the browser add-on to disable Google Analytics: https://tools.google.com/dlpage/gaoptout

Data Processing Agreement: Concluded IP Anonymization: Enabled Demographic Features: Disabled Google Signals: Disabled Data Retention Period in GA: 14 months

20.2 Google Maps (Geocoding API)

We use the Google Maps Geocoding API to validate address data during checkout. This serves to ensure correct delivery.

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland Data Transmitted: Address data Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR) Privacy Policy: https://policies.google.com/privacy


21. Social Media

21.1 Social Media Links

Our website contains links to our profiles on the following social networks (stored in socialMediaLinks):

All existing social media links are available in the footer.

These are simple links (no social media plugins or embedded content). When you click on a link, you are redirected to the respective platform. Only there does data processing by the platform operator take place.


22. Data Transfer to Third Parties

22.1 Categories of Recipients

We transmit personal data to the following categories of recipients:

RecipientPurposeLegal Basis
Payment Service Providers (Stripe)Payment ProcessingPerformance of Contract
Shipping Service ProvidersGoods DispatchPerformance of Contract
Hosting Provider (Hetzner)Operation of Website & DatabaseLegitimate Interest
Email Dispatch Service (Resend)Newsletter, Transactional EmailsConsent / Performance of Contract
Authentication (Google)Social LoginConsent / Performance of Contract
Address Validation (Google)Error Prevention in CheckoutLegitimate Interest

22.2 Shipping Service Providers

For the shipment of goods, we use the shipping services of our logistics partner or provider. In this context, your data (name, delivery address) is passed on to the transport companies commissioned by the provider (e.g., Austrian Post, DPD, DHL, or comparable services) for the purpose of delivery and, if applicable, shipment tracking.

Data Transmitted: Name, delivery address, if applicable telephone number, shipment number

22.3 Data Processing Agreements

We have concluded data processing agreements pursuant to Art. 28 GDPR with all service providers who process personal data on our behalf.


23. Data Transfer to Third Countries

23.1 Overview

ServiceLocationTransfer Mechanism
ResendUSAStandard Contractual Clauses (SCC)
StripeUSA/IrelandEU-US Data Privacy Framework / SCC
Google AnalyticsUSAEU-US Data Privacy Framework / SCC
HetznerGermanyNo Transfer (EU Hosting)

23.2 Protective Measures

For data transfers to third countries without an adequacy decision, we employ the following protective measures:

  • Standard Contractual Clauses (SCC) of the European Commission
  • Supplementary technical measures (encryption, pseudonymization)
  • Transfer Impact Assessments (TIA)

24. Retention Periods – General Overview

Data TypeRetention PeriodBasis
User AccountUntil deletion by user + 30 daysPerformance of Contract
Order Data7 years from year-end§ 132 BAO, § 212 UGB
Invoice Data7 years from year-end§ 132 BAO
Payment References7 years from year-end§ 132 BAO
Newsletter Consent (Proof)3 years after deregistrationProof Obligation
Newsletter Data (Active)Until revocationConsent
Contact Inquiries3 years after processingLegitimate Interest
Service Requests3 years after closureLimitation Period
Product ReviewsUntil revocationConsent
Shopping Cart (Session/DB)Until manual deletionPerformance of Contract
IP Addresses (Orders)6 monthsLegitimate Interest
IP Addresses (Contact Form)30 daysLegitimate Interest
Server Log Files30 daysLegitimate Interest
Cookie Consent Proof3 yearsProof Obligation
Email Campaign Logs12 monthsConsent
Uploaded Files (Service)3 years after case closurePerformance of Contract

25. Data Security

We employ extensive technical and organizational measures (TOMs) to protect your personal data, including:

  • Encryption: Transport encryption (TLS/SSL) for all data transfers; encryption of data at rest in the database
  • Password Security: Passwords are stored exclusively as cryptographic hashes (passwordHash), never in plain text. Hashing method used: bcrypt (Cost factor 12)
  • Access Control: Role-based authorization concept (role field), principle of least privilege
  • Data Backup: Regular automated backups
  • Monitoring: Monitoring of system integrity and availability
  • Employee Training: Regular awareness training on data protection

26. Your Rights as a Data Subject

Under the GDPR, you have the following rights:

26.1 Right of Access (Art. 15 GDPR)

You have the right to obtain information about the personal data we process concerning you, including processing purposes, categories, recipients, and retention periods.

26.2 Right to Rectification (Art. 16 GDPR)

You have the right to have inaccurate or incomplete data corrected.

26.3 Right to Erasure (Art. 17 GDPR)

You have the right to request the deletion of your data, provided no legal retention obligations or other exceptions oppose this.

26.4 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request the restriction of the processing of your data, e.g., if you contest the accuracy.

26.5 Right to Data Portability (Art. 20 GDPR)

You have the right to receive the data concerning you in a structured, commonly used, and machine-readable format, or to request its transmission to another controller.

26.6 Right to Object (Art. 21 GDPR)

You have the right to object at any time to the processing of your personal data based on Art. 6(1)(f) GDPR (legitimate interest). We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms.

If your personal data is processed for direct marketing purposes, you have the right to object at any time. The data will then no longer be processed for this purpose.

26.7 Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on your consent, you can withdraw it at any time with effect for the future, without affecting the lawfulness of processing based on consent before its withdrawal.

26.8 Exercising Your Rights

To exercise your rights, please contact:

Email: [email protected] Post: Hatice Kuzyurt e.U. Wiener Neustädter Straße 102, 2601 Sollenau, Austria

We will respond to your request within one month of receipt. In complex cases, this period may be extended by a further two months, about which we will inform you.


27. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with the competent data protection supervisory authority:

Austrian Data Protection Authority Barichgasse 40-42 1030 Vienna Austria

Telephone: +43 1 52 152-0 Email: [email protected] Website: https://www.dsb.gv.at


28. Automated Decision-Making and Profiling

No automated decision-making including profiling pursuant to Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you.


29. Protection of Minors

Our offering is directed at persons who have reached the age of 18. We do not knowingly collect personal data from children under 18 years of age. Should we discover that data from minors has been collected without the consent of their legal guardians, it will be deleted immediately.


30. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy as needed, especially in the event of changes to our data processing processes, legal requirements, or official specifications. The current version is available on our website.

Date: 05.07.2026

Version: 1.0