Privacy Policy
Privacy Policy
This privacy policy explains how Apfel Park processes personal data when you use this website, contact us, request repairs, place orders, or communicate with us by email.
1. Controller
- Apfel Park, Wilhelm-Strauß-Weg 2b, 21109 Hamburg
- Email: [email protected] | Phone: 040 58978787
- You can contact us at any time using the details above for privacy-related questions.
2. Categories of data processed
- Contact and communication data such as name, email address, phone number, and message content.
- Repair and device data such as repair requests, device type, issue description, status updates, cost estimates, and repair notes.
- Order and invoice data where required for sales, repairs, invoicing, or legal retention duties.
- Technical usage data such as IP address, timestamps, browser details, and security-related logs required to protect and operate the website.
3. Purposes and legal bases
- Article 6(1)(b) GDPR: handling contact requests, repair orders, purchases, and pre-contractual inquiries.
- Article 6(1)(c) GDPR: complying with legal obligations, especially accounting and retention obligations.
- Article 6(1)(f) GDPR: IT security, abuse prevention, system monitoring, and reliable website operation.
- Article 6(1)(a) GDPR together with Section 25 TDDDG: loading external services such as Google Maps and, if enabled, Google reCAPTCHA only after consent.
4. Recipients and service providers
- Hosting and server operations run on a rented server with Hetzner. The website also uses Cloudflare for DNS and technical protection features.
- Email communication and repair-status emails are processed through our self-hosted mail system.
- Maps are provided only after consent through Google Maps. When enabled, Google may process technical usage data.
- If spam protection through Google reCAPTCHA is enabled, this external service is also loaded only after consent.
- We share data with other recipients only where necessary for contract performance or where we are legally required to do so.
5. Cookies, local storage, and consent
- We use necessary cookies or local storage for language selection, theme preference, secure admin sessions, and technical delivery of the website.
- External content such as Google Maps and, if applicable, Google reCAPTCHA is loaded only after you allow external services.
- We store your consent choice so that your preference does not need to be requested again on every visit.
6. Retention periods
- We keep contact and repair-request data only as long as necessary for processing, follow-up, warranty, and legal obligations.
- Invoice and accounting data is retained according to applicable statutory retention periods.
- Security and server logs are stored only as long as required for stability, abuse prevention, and troubleshooting.
7. International transfers
- When external services such as Google Maps or Google reCAPTCHA are loaded, a transfer of personal data to third countries, especially the United States, cannot be ruled out.
- These services are therefore not loaded by default and are activated only after your consent.
8. Your rights
- You have the right to access, rectify, erase, restrict processing, and receive data portability subject to the legal requirements.
- Where we process data on the basis of legitimate interests, you have the right to object. You may withdraw consent at any time for the future.
- You also have the right to lodge a complaint with a competent data protection supervisory authority.
