Privacy policy
1. General Information
1.1. Controller The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
AATEILE GmbH Allensteiner Straße 26 77694 Kehl, Germany Email: contact@aateile.com Phone: +49 157 777 111 18
1.2. Data Security We use SSL or TLS encryption (Secure Socket Layer) for security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser line.
1.3. Hosting (AWS) Our website is hosted on servers provided by Amazon Web Services (AWS).
Provider: Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg.
Server Location: Germany (Frankfurt region).
Legal Basis: Art. 6 (1) lit. f GDPR (Legitimate interest in a secure, fast, and efficient provision of our online offer). AWS processes your data (e.g., IP addresses, log files) on our behalf. We have concluded a Data Processing Agreement (DPA) with AWS to ensure compliance with GDPR.
2. Data Collection on Our Website
2.1. Server Log Files The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
Browser type and browser version
Operating system used
Referrer URL
Hostname of the accessing computer
Time of the server request
IP address (anonymized/shortened) This data is not merged with other data sources. The basis for data processing is Art. 6 (1) lit. f GDPR, which permits the processing of data for the fulfillment of a contract or pre-contractual measures and for the security of the system.
2.2. Cookies Our website uses "cookies". These are small text files that are stored on your device.
Essential Cookies: Necessary for the shopping cart, login status, and security. (Legal basis: Art. 6 (1) lit. f GDPR).
Analytics/Marketing Cookies: Used to analyze user behavior (Google, HubSpot). These are only stored if you have given your express consent via our Cookie Banner (Consent Management Tool). (Legal basis: Art. 6 (1) lit. a GDPR).
2.3. Contact Form and Email If you send us inquiries via the contact form or email, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent.
3. Analytics and Advertising
3.1. Google Analytics 4 (GA4) We use Google Analytics 4, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Analysis of user behavior to optimize our website.
Configuration: We have configured GA4 so that IP addresses are anonymized. We do not use "Google Signals" for cross-device tracking of individual users.
Data Transfer: Data may be transferred to Google LLC in the USA. Google relies on the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) to ensure data protection.
Legal Basis: Your Consent (Art. 6 (1) lit. a GDPR). You can revoke this consent at any time via our Cookie Settings.
3.2. HubSpot We use the services of HubSpot for analytics and customer relationship management (CRM).
Provider: HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA. (European Headquarters: HubSpot Ireland Limited, Dublin).
Function: HubSpot uses cookies to analyze your use of our website. It also helps us manage contact forms and live chat interactions. If you subscribe to our newsletter or fill out a form, this data is linked to your user profile in HubSpot to provide you with better support.
Legal Basis:
Analytics/Tracking: Your Consent (Art. 6 (1) lit. a GDPR).
CRM/Management: Legitimate interest (Art. 6 (1) lit. f GDPR) or Contract fulfillment (Art. 6 (1) lit. b GDPR).
4. E-Commerce and Payment Providers
4.1. Processing of Customer and Contract Data We collect, process, and use personal data only insofar as it is necessary for the establishment, content organization, or change of the legal relationship (inventory data). This is done on the basis of Art. 6 (1) lit. b GDPR (performance of a contract).
4.2. Stripe We use the payment service provider Stripe to process payments (Credit Cards, Digital Wallets).
Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
Data Processing: Payment data (e.g., card number, expiration date, CVC) is transmitted directly to Stripe. We do not store full credit card details on our servers.
Legal Basis: Art. 6 (1) lit. b GDPR (Contract processing).
Stripe may transfer data to the USA. Stripe uses Standard Contractual Clauses (SCCs) and binding corporate rules to ensure compliance. For more information, please read Stripe's Privacy Policy: https://stripe.com/privacy.
4.3. Shipping Service Providers To deliver your order, we pass on your address data and, if necessary, your email address/phone number (for delivery notifications) to the shipping company:
GLS / GLS Express
DHL / DHL Express
Chronopost The legal basis for the transfer of data is Art. 6 (1) lit. b GDPR (fulfillment of contract).
5. Newsletter If you subscribe to our newsletter, we use the data you provide solely to send you the newsletter. We use the Double Opt-In procedure: You will receive an email with a confirmation link. You are only added to the distribution list after clicking this link.
System: We use the internal mailing system of our shop software (Shopware). No external newsletter provider (like Mailchimp) is used.
Tracking: Our newsletters may contain so-called "web beacons" that allow us to recognize whether an email has been opened. This helps us improve our content.
Unsubscribe: You can unsubscribe at any time via the link in the newsletter.
6. Your Rights You have the right to:
Access your stored data (Art. 15 GDPR).
Rectify incorrect data (Art. 16 GDPR).
Delete your data ("Right to be forgotten") (Art. 17 GDPR).
Restrict processing (Art. 18 GDPR).
Data Portability (Art. 20 GDPR).
Object to processing (Art. 21 GDPR).