Privacy Policy


Privacy Policy

NILION Trading GmbH ensures that the collection, processing and use of personal data fully complies with the requirements of the EU General Data Protection Regulation (GDPR) as well as all relevant statutory provisions.

1. Controller

The controller responsible for data processing on this website is:

NILION Trading GmbH
Hosnedlgasse 12, Objekt 3
1220 Vienna
Austria

Email: service@nilion-wholesale.com

2. Collection and Storage of Personal Data and the Nature and Purpose of Its Use

a) When Visiting the Website

When you access our website, your device's browser automatically transmits information to our server. This information is temporarily stored in log files. The following data is recorded:

  • IP address of the requesting device,
  • date and time of access,
  • name and URL of the retrieved file,
  • website from which access was made (referrer URL),
  • browser used and, where applicable, the operating system and the name of your access provider.

Data processing is carried out for the purpose of providing the website, ensuring system security and stability, and for other administrative purposes. The legal basis for this is Art. 6(1)(f) GDPR.

Retention period: The data collected is stored for as long as necessary for the purposes stated above and is then deleted. Log file data is regularly deleted after 7 days, unless further retention is required for evidentiary purposes.

b) Use of Services

We use the following services on our website:

  • Google Analytics: We use Google Analytics 4 to analyse and improve our offering. Data processing is carried out on the basis of your consent in accordance with Art. 6(1)(a) GDPR. For more information, please refer to the rel="noreferrer" target="_blank" href="https://policies.google.com/privacy" >Google Privacy Policy.

  • Google Tag Manager: Enables the management of website tags via a single interface. The Google Tag Manager itself does not process any personal data. However, the tags do set cookies that collect data.

  • Google reCAPTCHA v3: Our website uses Google reCAPTCHA v3 to ensure that interactions on our site originate from real users and not from automated bots. reCAPTCHA is used exclusively for spam and abuse prevention and has no impact on your shopping experience.

  • Newsletter via Rapidmail: We use Rapidmail to send our newsletter. With your consent in accordance with Art. 6(1)(a) GDPR, we collect and process your email address for the purpose of sending it. Dispatch is carried out using the double opt-in procedure to ensure that you have actively agreed to receive the newsletter.

  • Shopware and Shopware Extensions: These platforms are used to provide and manage our online shop. Data such as contact information, orders and payment data are processed in this context. The legal basis for this is the performance of a contract in accordance with Art. 6(1)(b) GDPR.

Transfer to third countries: When using Google services and social media platforms, data may be transferred to the USA or other third countries. Such transfers are made on the basis of standard contractual clauses of the EU Commission or other appropriate safeguards to ensure the protection of your data.

c) Service Emails

In addition to transaction-related messages (e.g. order or shipping confirmations), we may occasionally inform our customers by email about important changes in the shop, such as shipping methods, shipping costs or payment options. These emails do not constitute advertising but serve to provide information about contract-relevant changes. Customers may object to receiving such communications at any time, without incurring any costs other than transmission costs at basic rates.

d) Email Contact

When you contact us by email, the data you provide (e.g. email address, name, message content) will be stored and processed for the purpose of handling your enquiry. The legal basis for this is Art. 6(1)(b) GDPR (pre-contractual measures or performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in processing enquiries). The data will be deleted once it is no longer required for processing, provided no statutory retention obligations exist.

3. Data Storage in the Web Shop

In order to facilitate the purchasing process and for subsequent contract processing, the web shop operator stores the IP address of the account holder via cookies, as well as name, address and email. The data you provide is necessary for the performance of the contract and for carrying out pre-contractual measures (Art. 6(1)(b) GDPR).

Data is not transferred to third parties, with the exception of transfers to payment service providers (credit card data) for the purpose of debiting the purchase price, to the shipping or logistics company commissioned by us for delivery of the goods, and to our tax adviser for the fulfilment of our tax obligations.

Should you abandon the purchasing process, this data will be deleted. In the event of a contract being concluded, all data relating to the contractual relationship will be stored until the expiry of the statutory tax retention period (7 years). We additionally store data for product liability purposes (10 years). Data processing is carried out on the basis of § 96(3) TKG as well as Art. 6(1)(a) and (b) GDPR.

4. Disclosure of Data

Your personal data will not be transferred to third parties for purposes other than those listed below. We only pass on your personal data to third parties if:

  • you have given your express consent to this,
  • the disclosure is necessary for the processing of contractual relationships with you,
  • there is a legal obligation to disclose,
  • the disclosure is necessary for the assertion, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data.

5. Your Rights

You have the right:

  • pursuant to Art. 15 GDPR, to request information about your personal data processed by us,
  • pursuant to Art. 16 GDPR, to request the immediate rectification of inaccurate or completion of incomplete personal data stored by us,
  • pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us,
  • pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data,
  • pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request its transfer to another controller,
  • pursuant to Art. 7(3) GDPR, to withdraw your consent at any time with effect for the future,
  • pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority.

6. Right to Object

Where your personal data is processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right, pursuant to Art. 21 GDPR, to object to the processing of your personal data, provided there are grounds arising from your particular situation or the objection is directed against direct marketing.

7. Data Security

During your visit to the website, we use the widely employed SSL (Secure Socket Layer) protocol in conjunction with the highest level of encryption supported by your browser. We also employ technical and organisational security measures to protect your data against manipulation, loss, destruction or unauthorised access.

8. Cookies

Our website uses cookies to ensure the functionality of the website and to analyse the use of our website. Cookies are small text files stored on your device that can save information such as preferred settings.

You have the option to manage cookies via our cookie banner. You can choose whether to allow essential cookies only or to also accept marketing and statistics cookies.

9. Fonts

When you access this website, your browser loads fonts and stores them in the cache. As a visitor to the website, you receive data from the service provider, which means Google may set or analyse cookies on your device. The use of "Google Fonts" serves to optimise our service and to ensure the consistent display of content. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR.

Further information about Google Fonts can be found at: href="https://developers.google.com/fonts/faq" target="_blank" rel="noreferrer" >Google Fonts

10. Currency and Amendments to This Privacy Policy

This privacy policy is currently valid. As our website and the services offered through it continue to develop, or due to changes in statutory or regulatory requirements, it may become necessary to amend this privacy policy.

Version: November 2018