Privacy policy

Privacy Policy

The protection of your personal data is important to us. We process your personal data confidentially and in accordance with the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR).

You may withdraw any consent granted for the processing of your personal data at any time with effect for the future. Such withdrawal may be submitted by email to privacy@naksunutrition.com.

With this Privacy Policy, we would like to provide you with comprehensive information about which personal data we collect when you use our website www.naksunutrition.com, how we process such data, and for what purposes this is done. We also inform you about your rights as a data subject.

Our website is operated via the Shopify e-commerce platform. In this context, personal data is processed both by us and by Shopify, as well as by third-party providers engaged by us, to the extent necessary for the provision of our website, the processing of orders, and the maintenance of technical functionality.

Personal data is processed exclusively on the basis of the applicable legal provisions, in particular Article 6 GDPR. Where consent is required for specific processing activities, such processing will only take place after the user's prior express consent has been obtained.

Please read this Privacy Policy carefully. By accessing our website and using our services, you confirm that you have taken note of this Privacy Policy and have been informed about the processing of personal data described herein.

 

1. Data Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Naksu Nutrition S.à r.l.-S
Rue Emile Mark 40
4620 Differdange
Luxemburg

Email: privacy@naksunutrition.com

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.

 

2. Personal Data

Personal data means any information relating to an identified or identifiable natural person. This includes, in particular, information such as name, address, email address, telephone number, payment data, usage data, location data, IP addresses, and other information that can be directly or indirectly attributed to a person.

In principle, it is possible to use our website without actively providing personal data. In certain cases, however, the processing of technical data, particularly IP addresses or device information, may be necessary in order to ensure the provision and security of the website.

Certain functions and services of our website, especially the ordering of products or contacting us, require the processing of personal data.

We process personal data only to the extent necessary for providing our website, performing contracts, complying with legal obligations, or on the basis of your consent. Processing is carried out in accordance with the applicable legal provisions, in particular the General Data Protection Regulation.

In doing so, we ensure that only such personal data is collected and processed as is necessary for the respective purpose.

 

3. Visiting Our Website

3.1 General Use

When you visit our website, certain information is automatically collected and processed by the servers and technical systems. This includes, in particular, the IP address of your internet connection, the pages you access, the website from which you were referred to us, as well as the date and time of your visit.

The processing of this data is technically necessary in order to display our website correctly, ensure stable and secure use, and continuously improve our services. Processing is carried out on the basis of our legitimate interest in accordance with the General Data Protection Regulation (GDPR).

As a rule, we are unable to directly identify you from this data. This data is not combined with other data sources unless such combination is required to investigate security incidents or misuse.

The collected information is stored only for as long as necessary to achieve the aforementioned purposes and is subsequently deleted or anonymized unless statutory retention obligations require otherwise.

3.2 Automatically Stored Data (Server Log Files)

The provider of our website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. This includes, in particular, technical access data such as the date and time of access, the name of the file accessed, the previously visited page (referrer), the access status, the web browser used, the operating system used, the IP address of the requesting device, and the volume of data transferred.

This data is processed exclusively for technical and administrative purposes, in particular to ensure the uninterrupted operation of our website, maintain system security and stability, and detect, analyze, and prevent security-related incidents or abusive access. Processing is based on our legitimate interest in accordance with the GDPR.

As a rule, this data is not combined with other data sources unless required in individual cases for investigating security incidents or enforcing legal claims.

The data is stored only for a limited period necessary to achieve the aforementioned purposes and is subsequently deleted or anonymized unless legal retention obligations or other legal reasons require longer storage.

As a rule, we are unable to directly identify individual persons from this data.

3.3 Cookies and Similar Technologies

Our website uses cookies and comparable technologies to enable optimal use of our website, ensure functionality, and analyze and improve our services. Cookies are small text files stored on your device that contain certain information. Comparable technologies include tracking pixels, local storage, and similar technologies that are also used on your device and enable recognition of your browser.

Some of the cookies and technologies used are technically necessary in order to provide essential website functions, particularly the operation of the shopping cart, order processing, and the display and functionality of the website. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

In addition, we use cookies and comparable technologies to analyze user behavior on our website, compile statistical evaluations, optimize content and offers, and, where applicable, display personalized advertising.

All cookies and technologies that are not technically necessary, particularly those used for analytics and marketing purposes, are only used after obtaining your prior express consent. Processing in this respect is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR and the applicable privacy regulations concerning electronic communications.

When you first visit our website, you will be informed about the use of these technologies through an appropriate cookie banner and will have the opportunity to grant, refuse, or individually customize your consent.

You may withdraw or modify your consent at any time with effect for the future through the cookie banner.

Where personal data is processed through the use of cookies and comparable technologies, such data may be disclosed to third-party providers where necessary for the provision of the respective functions or where you have expressly consented to such disclosure.

The storage period of the cookies and technologies used depends on their respective purpose and may vary depending on the type of cookie. Once the respective purpose no longer applies, the data will be deleted or anonymized unless statutory retention obligations prevent this.

You may also prevent the storage of cookies through the corresponding settings of your browser or delete stored cookies at any time. Please note, however, that doing so may limit the functionality of our website.

3.4 Social Media Links

Our website contains links to social networks. These may include, in particular, platforms such as Facebook, Instagram, TikTok, YouTube, or comparable social networks.

These links are merely simple redirects in the form of HTML links. Therefore, when accessing our website, no automatic connection to the servers of the respective providers is established.

Only when you actively click on such a link will you be redirected to the website of the respective social network. In this context, personal data may be collected and processed by the respective provider.

Please note that we have no influence over the nature and scope of data processing carried out by the respective providers. For further information regarding the processing of your personal data, please refer to the privacy policies of the respective platform operators.

3.5 Hosting and Provision of the Website (Shopify)

Our website is operated through the Shopify e-commerce platform. The provider is Shopify International Limited, 2nd Floor Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland (hereinafter “Shopify”). Shopify provides us with the technical infrastructure required to operate our website, display our products, process orders, and ensure the functionality of our online store.

As part of your use of our website, Shopify processes personal data, in particular technical access data such as the IP address of the requesting device, information about the device used, browser type, pages visited within our online store, information about the use of our website, including navigation and interaction behavior, the website from which access originated, and derived statistical evaluations.

As part of your use of our website, Shopify processes personal data, in particular technical access data such as the IP address of the requesting device, information about the device used, browser type, pages visited within our online store, information about the use of our website, including navigation and interaction behavior, the website from which access originated, and derived statistical evaluations.

If you place an order through our website, Shopify also processes personal data for contract fulfillment purposes, including your name, email address, shipping and billing address, payment information, where applicable your telephone number, as well as order and transaction data such as ordered products, order value, and order date. If you create a customer account, login credentials and information regarding your previous orders will also be processed.

This may also include personal data generated through the use of functions such as the shopping cart, wishlist, or customer account, as well as data arising from communications with us, for example through customer service inquiries.

The processing of this data is carried out for the provision and operation of our website, the processing and fulfillment of orders, payment processing including fraud prevention, communication with you regarding your order or customer account, organization of shipping and delivery, including through external service providers, as well as for the analysis, optimization, and further development of our online offering.

Personal data may be collected directly from you, automatically through your use of our website, or through service providers acting on our behalf.

Shopify may use cookies and comparable technologies as part of providing its services in order to ensure the functionality of the website and collect information about the use of our website.

The processing of personal data is based on our legitimate interest in the secure, stable, and efficient provision of our online services, as well as for the implementation of pre-contractual measures and the performance of a contract in accordance with the General Data Protection Regulation. Where consent is required for individual processing activities, such processing will only take place on the basis of your prior express consent, which may be withdrawn at any time with effect for the future.

We have concluded a Data Processing Agreement with Shopify, ensuring that Shopify processes personal data exclusively in accordance with our instructions and in compliance with applicable data protection regulations.

In connection with the use of Shopify, personal data may be transferred to countries outside the European Union. In such cases, the transfer takes place on the basis of appropriate safeguards, in particular through the use of Standard Contractual Clauses approved by the European Commission to ensure an adequate level of data protection.

Personal data is stored only for as long as necessary to fulfill the purposes described above or as required by statutory retention obligations.

Further information regarding Shopify’s processing of personal data can be found at: https://www.shopify.com/legal/privacy

3.6 hCaptcha

To protect our website against abusive use and to prevent spam, we use the hCaptcha service. The provider is Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA.

hCaptcha is used to determine whether entries on our website are made by a human user or by automated programs. For this purpose, hCaptcha analyzes the behavior of website visitors based on various technical characteristics. In particular, information such as the IP address, details about the device and browser used, interactions on the website such as mouse movements or inputs, and the duration of the visit may be processed. The data collected during this analysis is transmitted to the provider and used for evaluation purposes.

Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

In connection with the use of hCaptcha, personal data may be transferred to countries outside the European Union, particularly the United States. In such cases, the transfer takes place on the basis of appropriate safeguards within the meaning of the applicable data protection regulations.

Further information regarding hCaptcha’s processing of personal data can be found at: https://www.hcaptcha.com/privacy

3.7 Purposes of Processing Personal Data

We process personal data for various purposes where this is necessary for providing our website and services, fulfilling contractual obligations, safeguarding our legitimate interests, or complying with legal requirements.

In particular, personal data is processed for the provision and operation of our website, the processing and fulfillment of orders, payment processing, the organization of shipping and delivery, the management of customer accounts, and the storage of order histories.

Furthermore, we process personal data to communicate with you, particularly for handling inquiries, providing customer support, and informing you about the status of orders or other matters.

Processing may also take place to ensure the security of our website, prevent and investigate abuse or fraudulent activities, and for the technical optimization and further development of our services.

Where you have provided your consent, we also process personal data for marketing and analytics purposes, in particular to send information about products and offers and to display personalized content or advertising.

Personal data may also be processed where this is necessary for compliance with legal obligations or for the establishment, exercise, or defense of legal claims.

3.8 Disclosure of Personal Data

We disclose personal data to third parties only where necessary for the performance of contractual obligations, the provision of our website and services, the protection of our legitimate interests, or where required by law.

Disclosure may in particular take place to technical service providers, hosting providers, payment service providers, shipping and logistics companies, as well as IT and support service providers who process personal data on our behalf and on the basis of appropriate contractual agreements.

Personal data may also be disclosed where necessary for payment processing, the execution of deliveries, communication with you, or ensuring the functionality and security of our website.

Furthermore, personal data may be disclosed if you have expressly consented to such disclosure, for example in connection with marketing activities or the use of specific functions, or where we are legally obliged to do so or where disclosure is necessary for the establishment, exercise, or defense of legal claims.

In connection with the use of our services, it may also be necessary to transfer personal data to service providers or contractual partners acting on our behalf and obliged to comply with the applicable data protection regulations.

3.9 Consent Management

Our website uses a consent management solution to obtain your consent for the storage of certain cookies and the use of certain technologies and to document such consent in compliance with data protection requirements.

We use the consent management solution “Avada GDPR Cookie Consent” provided by AVADA Commerce.

When you access our website, your consent preferences are requested. In this context, information regarding your granted consents and withdrawals of consent, your IP address, details about your browser and device, and the time of your visit may be processed.

This data is processed in order to demonstrate and manage legally required consents and to provide the cookie banner technically.

In connection with the use of this service, personal data may be transferred to countries outside the European Union. In such cases, data processing takes place on the basis of the applicable legal provisions and appropriate safeguards for the protection of your personal data.

Consent information is stored for as long as necessary to fulfill legal documentation obligations. Thereafter, the data is deleted or anonymized.

You may withdraw or modify your consent at any time by reopening the relevant settings via the cookie banner.

Further information regarding data processing by the provider can be found at: https://avada.io/privacy-policy/

 

4. Analytics, Tracking and Marketing Tools

4.1 Google Analytics (4)

Our website uses the web analytics service Google Analytics, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables us to analyze and evaluate the behavior of visitors to our website. In this context, information regarding the use of our website is processed, including pages visited, duration of visits, interactions on the website, devices used, operating systems, browser types, and the origin of visitors.

For the analysis of user behavior, Google Analytics uses cookies and comparable technologies that enable user recognition. The information collected is generally transmitted to Google servers and processed there.

The use of Google Analytics takes place exclusively on the basis of your prior express consent. You may withdraw or modify your consent at any time with effect for the future through the cookie banner.

The use of Google Analytics takes place exclusively on the basis of your prior express consent. You may withdraw or modify your consent at any time with effect for the future through the cookie banner.

In connection with the use of Google Analytics, personal data may be transferred to countries outside the European Union, in particular to the United States. In such cases, the transfer of data takes place on the basis of appropriate safeguards, in particular through the use of Standard Contractual Clauses approved by the European Commission to ensure an adequate level of data protection.

Further information regarding data processing by Google can be found at: https://policies.google.com/privacy and https://privacy.google.com/businesses/controllerterms/mccs/

You may also prevent the collection and processing of your data by Google Analytics by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout

Further information on how Google Analytics handles user data can be found at: https://support.google.com/analytics/answer/6004245

As part of our use of Google Analytics, we also use functions for the analysis of purchasing behavior (“E-Commerce Measurement”). In this context, information regarding orders, purchased products, order values, and interactions related to the purchasing process is collected and evaluated.

This data enables us to analyze and optimize our services and marketing activities. The collected information may be processed by Google in pseudonymized form and assigned to specific transactions or devices.

4.2 Google Ads

Our website uses Google Ads, an online advertising service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads enables us to display advertisements in the Google search engine as well as on external websites. Advertisements may be displayed based on search terms (keyword targeting) or based on user data such as location or interests (audience targeting).

In connection with the use of Google Ads, personal data may be processed, in particular information about interactions with our advertisements and technical information about the device and browser used. This data enables us to analyze and optimize the effectiveness of our advertising measures.

The use of Google Ads takes place exclusively on the basis of your prior express consent. You may withdraw or modify your consent at any time with effect for the future through the cookie banner.

In connection with the use of Google Ads, personal data may be transferred to countries outside the European Union, in particular to the United States. In such cases, the transfer of data takes place on the basis of appropriate safeguards, in particular through the use of Standard Contractual Clauses approved by the European Commission to ensure an adequate level of data protection.

Further information regarding data processing by Google can be found at: https://policies.google.com/privacy and https://privacy.google.com/businesses/controllerterms/mccs/

4.3 Google Conversion Tracking

Our website uses Google Conversion Tracking, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Conversion Tracking enables us to determine whether users perform certain actions on our website after clicking on one of our advertisements, for example making a purchase or completing another interaction. This allows us to analyze and optimize the effectiveness of our advertising measures.

In this context, information regarding interactions on our website as well as technical data such as the device used, browser, and time of use is processed. Google uses cookies or comparable technologies to recognize users.

The use of Google Conversion Tracking takes place exclusively on the basis of your prior express consent. You may withdraw or modify your consent at any time with effect for the future through the cookie banner.

In connection with the use of Google Conversion Tracking, personal data may be transferred to countries outside the European Union, in particular to the United States. In such cases, the transfer of data takes place on the basis of appropriate safeguards, in particular through the use of Standard Contractual Clauses approved by the European Commission.

Further information regarding data processing by Google can be found at: https://policies.google.com/privacy and https://privacy.google.com/businesses/controllerterms/mccs/

4.4 Meta Pixel

Our website uses Meta Pixel, a service provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

With the help of Meta Pixel, we are able to track the behavior of users after they have been redirected to our website by clicking on an advertisement. This enables us to evaluate and optimize the effectiveness of our advertising measures and to display interest-based advertising.

In this context, information regarding your use of our website may be processed, including pages visited, products viewed, interactions on the website, and technical information regarding the device used, browser, and time of access. This data may be combined by Meta with other information and assigned to an individual user profile.

Meta Pixel uses cookies and comparable technologies that enable user recognition and are used to create pseudonymous usage profiles.

The use of Meta Pixel takes place exclusively on the basis of your prior express consent pursuant to Article 6(1)(a) GDPR and applicable privacy regulations. You may withdraw or modify your consent at any time with effect for the future through the cookie banner.

To the extent that personal data is collected on our website and transmitted to Meta through the use of Meta Pixel, we and Meta Platforms Ireland Limited are jointly responsible for this data processing within the meaning of Article 26 GDPR. The joint responsibility is limited to the collection of data and its transmission to Meta. Any subsequent processing by Meta is carried out under Meta’s sole responsibility.

The agreement on joint processing concluded between us and Meta can be viewed at the following link: 

https://www.facebook.com/legal/controller_addendum

In connection with the use of Meta Pixel, personal data may be transferred to countries outside the European Union, in particular to the United States. Such transfers take place on the basis of appropriate safeguards, in particular through the use of Standard Contractual Clauses approved by the European Commission and, where applicable, on the basis of the EU-US Data Privacy Framework.

Further information regarding data processing by Meta and the applicable legal safeguards can be found at:

https://www.facebook.com/privacy/policy/

https://www.facebook.com/legal/EU_data_transfer_addendum

https://www.facebook.com/legal/terms/dataprocessing

Where we use additional Meta functions as part of our marketing activities, particularly for the creation of audiences (“Custom Audiences”) or comparable advertising technologies, this also takes place exclusively on the basis of your consent.

You may object to the use of your data for personalized advertising and adjust the corresponding settings at any time at:

https://www.facebook.com/adpreferences/ad_settings

The data collected through the use of Meta Pixel is stored only for as long as necessary to achieve the respective purposes or as required by statutory retention obligations. Thereafter, the data is deleted or anonymized.

 

5. Processing of Personal Data in the Course of Our Business Activities

5.1 Contacting Us

If you contact us, for example via a contact form, email, telephone, or social networks, the personal data you provide will be processed to the extent necessary for handling your inquiry and carrying out the requested measures.

In this context, information such as your name, email address, telephone number, and the content of your message may be processed.

The processing of your data is carried out exclusively for the purpose of handling your inquiry and communicating with you. Your data will be treated confidentially and will not be disclosed to third parties unless this is necessary for processing your inquiry or you have expressly consented to such disclosure.

The processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

The data transmitted in the course of contacting us is stored only for as long as necessary to process your request or as required by statutory retention obligations. Thereafter, the data is deleted or anonymized.

5.2 Customer Account

Contractual partners may create an account within our online offering (e.g., a customer or user account, hereinafter referred to as a “Customer Account”). Where registration of a Customer Account is required, users will be informed accordingly, including the information required for registration.

Customer Accounts are not public and cannot be indexed by search engines. As part of the registration process, subsequent logins, and use of the Customer Account, we store customers’ IP addresses together with the times of access in order to provide proof of registration and prevent possible misuse of the Customer Account.

If customers terminate their Customer Account, the data relating to the Customer Account will be deleted unless retention is required by law. Customers are responsible for securing their data before the Customer Account is terminated.

5.3 Processing of Data in Connection with Orders and Purchases

As part of our online store, we process personal data in order to enable you to select, purchase, and order our products and services and to process such orders properly.

The data provided by you during the ordering process is processed, in particular for order fulfillment, payment processing, and the organization of delivery.

The data provided by you during the ordering process is processed, in particular for the execution of the order, payment processing, and the organization of delivery. In this context, information such as your name, address, email address, payment information, as well as order and transaction data may be processed. In addition, technical data, such as your IP address or information about your device, may be processed in order to ensure a secure and smooth process.

For the execution and processing of orders, your data may be disclosed to external service providers where necessary. This includes, in particular, payment service providers for payment processing and shipping and logistics companies for the delivery of ordered goods.

Your data is processed exclusively for the purpose of contract performance, payment processing, delivery of the ordered goods, handling inquiries, and ensuring proper business operations. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

The data collected in connection with orders is stored only for as long as necessary to perform the contract and fulfill statutory retention obligations. Thereafter, the data is deleted or anonymized.

5.4 Abandoned Cart and Product Reminders

If you use our online store during an ordering process, it may happen that you interrupt the ordering process before completion. In this case, we reserve the right to remind you after a certain period of time, using the contact details provided during the ordering process, about the products you selected or viewed.

In this context, information regarding the products placed in your shopping cart or viewed by you, as well as your contact details, may be used in order to send you reminders or notifications regarding your initiated purchase.

Such reminders are sent exclusively within the framework of the applicable legal provisions. You may object to receiving such messages at any time, for example via an unsubscribe link contained in the respective message.

Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

5.5 Customer Information

If you have provided your contact details in connection with a purchase or order, we reserve the right to use this data to send you information regarding our own similar products or services that may be of interest to you.

In this context, your email address, telephone number, name, and information regarding your previous orders may be used in order to provide you with relevant information or offers.

Processing takes place exclusively within the framework of the applicable legal provisions. You have the right to object at any time to the use of your data for marketing purposes. Such objection may be made at any time, for example through an unsubscribe link contained in the respective message or by contacting us, for example via email at: support@naksunutrition.com

5.6 Newsletter

On our website, you have the opportunity to subscribe to our newsletter. As part of the subscription process, the personal data you provide is processed in order to regularly send you information about our products, offers, and promotions by email.

Providing a valid email address is required for subscription. To ensure that the subscription is actually made by you, we use a double opt-in procedure. After registration, you will receive a confirmation email in which you must confirm your subscription by clicking on a corresponding link.

In connection with newsletter distribution, information regarding your interactions with the emails sent may also be processed in addition to your email address, for example whether and when an email was opened or links contained within it were clicked.

Your data is processed exclusively for the purpose of email marketing. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

You may unsubscribe from the newsletter at any time with effect for the future, for example via the unsubscribe link contained in every email or by contacting us, for example via email at: support@naksunutrition.com

5.7 Shopify Flow

To automate internal processes and business operations, we use functions of the Shopify e-commerce platform, in particular the tool “Shopify Flow.” The provider is Shopify International Limited, 2nd Floor Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland.

Shopify Flow enables us to automate certain processes within our online store, for example in connection with orders, customer interactions, internal procedures, and marketing and communication measures. This may also include triggering automated notifications, offers, or discount campaigns based on certain events, such as a purchase or specific user actions.

In this context, personal data may be processed where necessary for the implementation and optimization of our business processes. This includes, in particular, the processing of customer and order data as well as information regarding user behavior within our online store.

Processing is carried out exclusively for the purpose of designing our processes efficiently, improving our services, and providing you with relevant information, offers, or benefits within the scope of our business activities. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

In connection with the use of Shopify Flow, personal data may be transferred to countries outside the European Union. In such cases, the transfer takes place on the basis of appropriate safeguards in accordance with the applicable data protection regulations.

Further information regarding data processing by Shopify can be found at: https://www.shopify.com/legal/privacy

5.8 Review Requests and Customer Feedback (Judge.me)

After purchasing a product, we reserve the right to contact you by email regarding your satisfaction with your order and the products purchased and to request a review or feedback, provided that you have not objected to this.

In this context, your email address, name, and information regarding your order may be processed in order to send you such requests and evaluate your feedback.

Processing is carried out exclusively for the purposes of quality assurance, improving our products and services, and obtaining customer feedback. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

For the management, processing, and display of product reviews, we use the service Judge.me. In this context, personal data may be transferred to and processed by Judge.me.

You may object at any time to the use of your data for this purpose, for example via an unsubscribe link contained in the respective email or by contacting us, for example via email at: support@naksunutrition.com

Further information regarding data processing by Judge.me can be found at: https://judge.me/privacy

5.9 Business Analytics and Optimization

For business evaluation purposes and the continuous improvement of our online offering, we process personal data within the framework of analytics and evaluation processes. This serves in particular to better understand user behavior, optimize our services, and design our business processes more efficiently.

In this context, data relating to orders, the use of our website, interactions with our content, and other information generated through the use of our online store may be processed.

Processing is carried out exclusively for internal purposes and serves business analysis, optimization of our services, and further development of our offering. Data is only disclosed where necessary for carrying out corresponding analyses or where the data has been anonymized.

Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

5.10 Payment Processing and Payment Service Providers

As part of orders placed through our website, we offer various payment methods. For the processing of payments, we cooperate with external payment service providers who enable secure and efficient payment processing.

In connection with payment processing, the personal data required for the respective transaction is processed. This includes, in particular, information such as your name, billing address, payment information, and order and transaction data.

The entry and processing of sensitive payment data generally takes place directly through the systems of the respective payment service providers. We do not receive complete payment information such as credit card or bank account details, but only information regarding the payment status.

Depending on the payment method selected, additional checks, for example identity verification or creditworthiness checks, may be carried out by the respective payment service provider.

Processing is carried out exclusively for the purpose of payment processing and contract performance. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

Further information regarding data processing by the respective payment service providers can be found in the privacy policies of the relevant providers.

5.11 Shipping, Logistics and Fulfillment Service Providers

For the delivery of the goods you order, we work with external shipping, logistics, and fulfillment service providers. As part of processing your order, the personal data required for this purpose is transferred to these service providers to the extent necessary for carrying out the delivery.

In this context, information such as your name, shipping address, and, where required, your email address or telephone number may be processed and transferred to the respective service providers, for example for the delivery of goods or the coordination of delivery dates.

Your data is processed exclusively for the purpose of carrying out the delivery and ensuring the proper fulfillment of your order. Processing is carried out on the basis of the applicable legal provisions, in particular Article 6 GDPR.

Further information regarding data processing by the respective shipping, logistics, and fulfillment service providers can be found in the privacy policies of the relevant providers.

5.12 Data Security

We implement appropriate technical and organizational measures to protect your personal data against loss, destruction, unauthorized access, manipulation, or other unlawful forms of processing.

Among other things, we use security measures such as encryption technologies and access restrictions to ensure an appropriate level of protection for your data. The transmission of personal data is generally encrypted in order to protect it from unauthorized access.

Both our employees and the service providers engaged by us are obligated to comply with the applicable data protection regulations and receive appropriate training regarding the handling of personal data.

Our security measures are regularly reviewed and continuously adapted in line with technological developments in order to ensure the highest possible level of protection.

5.13 Social Media Presence

We maintain online presences on social media platforms in order to communicate with you and provide information about our products and offers.

When you visit our social media pages, personal data is processed by the respective platform operators. This may include, in particular, the processing of usage data, interactions, and information regarding your behavior within the respective platform.

The platform providers may create user profiles that can be used, for example, to display interest-based advertising both within and outside the respective platforms. In this context, cookies or comparable technologies may also be used.

Please note that we have no influence over the data processing carried out by the respective social network providers. For further information regarding the processing of your personal data, your rights, and available settings options, please refer to the privacy policies of the respective platform operators.

If you require assistance in exercising your rights, you may contact us at any time.

 

6. External Links and Third-Party Websites

Our website may contain links to external websites or platforms operated by third parties. We have no influence over the content or data processing activities of these external providers. For further information regarding their handling of personal data, please refer to the respective privacy policies of the relevant websites.

 

7. Data of Minors

Our website is generally not intended for minors. We do not knowingly collect personal data from minors.

If we become aware that personal data of minors has been processed, such data will be deleted without undue delay.

Parents or legal guardians may contact us at any time to request the deletion of such data.

 

8. Retention Period of Personal Data

We store personal data only for as long as necessary to fulfill the respective purposes or where statutory retention obligations apply.

The specific retention period depends in particular on the type of data and the respective processing purpose. Once the respective purpose ceases to apply or statutory retention periods expire, the relevant data is deleted or anonymized.

 

9. Rights of Data Subjects

Under the applicable data protection regulations, you have extensive rights regarding the processing of your personal data. These rights include, in particular:

Right of Access:

You have the right to obtain confirmation from us as to whether personal data concerning you is being processed.

If this is the case, you have the right to obtain access to such data and further information regarding the processing, in particular the purposes of processing, the categories of data processed, the recipients or categories of recipients, the planned storage period, and your additional rights.

Right to Rectification:

You have the right to request the immediate correction of inaccurate personal data and the completion of incomplete data.

Right to Erasure (“Right to be Forgotten”):

You have the right to request the deletion of your personal data where the legal requirements for such deletion are met.

This applies in particular where the data is no longer necessary for the purposes for which it was collected, where you have withdrawn your consent, or where the processing is unlawful.

Please note that statutory retention obligations may prevent deletion.

Right to Restriction of Processing:

You have the right to request the restriction of the processing of your personal data, particularly where you contest the accuracy of the data, where the processing is unlawful and you oppose deletion, or where we no longer require the data but you need it for the establishment, exercise, or defense of legal claims.

Right to Data Portability:

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and to transmit such data to another controller or, where technically feasible, to have it transmitted by us.

Right to Object:

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on legitimate interests.

Where your personal data is processed for direct marketing purposes, you have the right to object to such processing at any time without giving reasons.

In the event of an objection, we will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing or where the processing is necessary for the establishment, exercise, or defense of legal claims.

Right to Withdraw Consent:

You have the right to withdraw any consent granted at any time with effect for the future.

The lawfulness of processing carried out prior to the withdrawal remains unaffected.

Right to Lodge a Complaint with a Supervisory Authority:

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement, if you believe that the processing of your personal data violates applicable data protection laws.

To exercise your rights, you may contact us at any time, for example by email at: privacy@naksunutrition.com

When processing your request, we reserve the right to request additional information to verify your identity in order to prevent misuse.

The exercise of your rights is subject to the applicable legal provisions. You also have the right to contact us first in order to clarify any questions or uncertainties.

 

10. International Data Transfers

In connection with the use of our website and the utilization of our services, personal data may be transferred to recipients located in countries outside the European Union (EU) or the European Economic Area (EEA), or processed there.

This applies in particular to the use of external service providers and platforms, such as hosting providers, analytics tools, or marketing service providers.

In such cases, personal data is transferred exclusively in compliance with the applicable legal requirements. Where no adequacy decision of the European Commission exists for the respective third country, we ensure that appropriate safeguards within the meaning of the General Data Protection Regulation are in place, in particular through the conclusion of Standard Contractual Clauses approved by the European Commission or comparable contractual arrangements.

Where service providers located in the United States are used, data transfers may also take place on the basis of certification under the EU-US Data Privacy Framework, provided that the respective provider is certified accordingly.

 

11. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy at any time, in particular in the event of changes to legal requirements, new technologies, or the further development of our website and services. The version valid at the time of your visit shall apply.

Where material changes are made, these will be appropriately communicated on our website.

This Privacy Policy is provided in the German language. Where translations into other languages are made available, they are provided solely for convenience and better understanding. In the event of discrepancies or inconsistencies, the German version shall exclusively prevail.

To exercise your rights or if you have any questions regarding data protection, you may contact us at any time. In individual cases, we reserve the right to request additional information to verify your identity.

 

12. Contact

If you have any questions regarding this Privacy Policy or the processing of your personal data, or if you wish to exercise your rights, you may contact us at any time via the following email address: privacy@naksunutrition.com or by mail at: Naksu Nutrition S.à r.l.-S, Rue Emile Mark 40, 4620 Differdange, Luxemburg.

Within the meaning of the applicable data protection laws, we are the controller responsible for the processing of your personal data.