Buy 2 get 1 freeBuy 3 get 3 freeSale ends in
Data Policy
What personal data this shop processes, why, on what legal basis — and what rights you have over it.
Last updated: August 2025
Controller within the meaning of the GDPR
- Company
- HOT Productions & Vertriebs GmbH
- Company registration number
- FN 313269s
- Address
- Wagrainer Strasse 35, 4840 Voecklabruck, Austria
- office@hot-dl.com
- Telephone
- +43 7672 72 009
- Fax
- +43 7672 72 009 -9
- Data protection officer
- Alexander Klopf
- Data protection coordinator
- Alexander Klopf
The terms used in this data policy and our data protection practice follow the provisions of the EU General Data Protection Regulation (“GDPR”) and the other relevant national legislation.
Data collected in this shop
Personal data is collected from you in two ways: when you give it to us explicitly — placing an order, creating an account, or writing to us — and automatically, chiefly as technical data, when you visit the site. Some of that is collected so the site works at all; some may be used for analysis. You can browse this site without giving us any information about yourself. Placing an order, naturally, is not possible on those terms.
Orders and customer account
- Purpose
- processing your order, delivery, invoicing, your customer account and support
- Data processed
- name, email address, delivery and billing address, telephone number (if given), order contents, order history, payment status
- Legal basis
- performance of a contract (Art. 6(1)(b) GDPR); for retaining invoices, legal obligation (Art. 6(1)(c) GDPR, § 132 BAO)
- Recipients
- our shop and hosting provider, the payment provider, the carrier
- Retention
- until warranty and limitation periods expire; invoice data for seven years
The shop runs on Medusa, a commerce platform operated on our behalf on servers within the EU. That is where your account, your addresses and your orders are held. Ordering without an account is possible; in that case only the order itself is stored.
Payment
Payment is handled by external payment providers. Your full card or account details never reach us: you enter them directly with the payment provider, and we receive only the confirmation that payment was made, along with a transaction reference.
Stripe
- Provider
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland
- Purpose
- processing card and other payments, fraud prevention
- Data processed
- payment details, name, email address, billing address, amount, IP address, device and browser data
- Legal basis
- performance of a contract (Art. 6(1)(b) GDPR); legitimate interest in fraud prevention (Art. 6(1)(f))
- Recipients
- EU, USA
- More information
- stripe.com/privacy
PayPal
- Provider
- PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg
- Purpose
- processing payments made through PayPal
- Data processed
- name, email address, billing and delivery address, amount, transaction data, IP address
- Legal basis
- performance of a contract (Art. 6(1)(b) GDPR)
- Recipients
- EU, USA
- More information
- paypal.com/privacy
Hosting and server log files
- Purpose
- technical provision, operation, security and delivery of the website
- Data processed
- IP address, date and time of access, page or file requested, volume of data transferred, notification of successful retrieval, browser type and version, operating system, referrer URL, hostname of the accessing device
- Legal basis
- legitimate interest in secure and error-free operation (Art. 6(1)(f) GDPR)
- Retention
- deleted after 12 weeks at the latest
Server log files are created automatically when our website is accessed. This data is processed to ensure the functioning, security and stability of the site — in particular to prevent or trace attacks, to diagnose faults, and to deliver the site technically. Longer storage may occur in individual cases where data is needed as evidence. This data is not combined with other data sources.
Cookies and local storage
Cookies are small packets of data exchanged between your browser and the web server when you visit our site. They do no harm, cannot execute code, and serve only to recognise a returning browser. Local storage keeps data in your browser's cache, where it persists after the browser is closed unless you clear the cache.
We use them in three categories:
- Strictly necessary cookies — for the shop to work. These include Medusa's session and cart cookies, the cookie that remembers your choice of language “storefront_language”, and the cookie “storefront_consent” that records your cookie decision itself (kept for six months). The legal basis is our legitimate interest in the technically sound operation of the site; without them the shop does not function.
- Statistics cookies — to understand how visitors interact with the site. The legal basis is your consent.
- Marketing cookies — to measure and target advertising. These include the click-ID cookies woh_fbclid, woh_gclid and woh_ttclid, in which we store the identifier an ad platform used to send you to our site, so that a later purchase can be attributed to the right advertisement. The legal basis is your consent.
Your consent is voluntary and you may withdraw it at any time with effect for the future — through “Cookie settings” in the footer of every page. When you withdraw it, we delete the cookies belonging to the category you switched off. Withholding it puts you at no disadvantage. You can also set your browser to refuse cookies generally or to ask you each time, and you can delete cookies already set at any time. Disabling cookies generally may limit the site's functionality.
Audience measurement and advertising
The technologies below are only started once you have consented to the relevant category.
OpenPanel
- Purpose
- audience measurement on our own infrastructure
- Category
- statistics
- Data processed
- page views, referrer, approximate location derived from the IP address, browser and device type, interactions within the shop
- Legal basis
- consent (Art. 6(1)(a) GDPR)
- Recipients
- EU — we run the instance ourselves; the data does not leave our infrastructure
Google Analytics 4
- Provider
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA
- Purpose
- web analysis, performance measurement, conversion tracking
- Category
- statistics
- Data processed
- page views, click path, session start, interactions, time on page, internal searches, approximate location, date and time, browser and device information, referrer URL
- Legal basis
- consent (Art. 6(1)(a) GDPR)
- Basis for transfer
- EU-U.S. Data Privacy Framework
- Recipients
- EU, USA
- More information
- policies.google.com/privacy
For visitors from the EU, Switzerland and the UK, GA4 does not log IP addresses. The IP address is used only momentarily to derive a coarse location (city, region, country) and is then discarded before it is stored on Google's servers. We select the shortest retention period that serves our purpose; you may ask us at any time what it currently is.
Meta Pixel and Conversions API
- Provider
- Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland
- Purpose
- measuring and targeting advertising on Facebook and Instagram
- Category
- marketing
- Data processed
- page views and purchase events, click ID (fbclid), IP address, browser and device information and — when you place an order — your email address, telephone number and name in hashed form
- Legal basis
- consent (Art. 6(1)(a) GDPR)
- Recipients
- EU, USA
- More information
- facebook.com/privacy/policy
We use Meta in two ways: as a pixel in your browser, and through the Conversions API, where the events are sent to Meta from our server. The second exists so that purchases are attributed correctly even when the browser pixel is blocked. Both are governed by the same consent. Email address, telephone number and name are hashed with SHA-256 before transmission; Meta receives no plain-text personal data from us.
Contacting us
When you contact us by email, telephone or post, we process the information you provide in order to deal with your enquiry. The legal basis is the performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR), or our legitimate interest in answering enquiries (Art. 6(1)(f)). We keep this correspondence for as long as it is needed to handle the matter, and beyond that within the statutory retention periods.
SSL encryption
We use the widely adopted SSL/TLS method for your visit, together with the highest level of encryption your browser supports. You can tell that a page is transmitted in encrypted form by the padlock symbol in your browser's status bar. Use of this method is based on our legitimate interest in employing suitable encryption techniques.
General information on data protection
The provisions below apply in principle not only to the data collected on this website but generally to our other processing of personal data.
Personal data
Personal data is information that can be attributed to you individually — your name, postal address, email address or telephone number, for example. Figures such as the number of users visiting a page are not personal data, because they are not attributed to a person.
Legal bases for processing
Unless more specific information is given in this policy, we may process your personal data on the following legal bases:
- Consent under Art. 6(1)(a) GDPR — the data subject has given consent to processing for one or more specific purposes.
- Performance of a contract and pre-contractual steps under Art. 6(1)(b) GDPR.
- Legal obligation under Art. 6(1)(c) GDPR.
- Protection of vital interests under Art. 6(1)(d) GDPR.
- Legitimate interests under Art. 6(1)(f) GDPR, where the interests or fundamental rights of the data subject do not override them.
Please note that in addition to the GDPR, national data protection provisions in your country or in ours may apply.
Transfer of personal data
Your personal data is not transferred to third parties for purposes other than those set out in this policy. We disclose your data only where you have given express consent under Art. 6(1)(a) GDPR, where disclosure is necessary under Art. 6(1)(f) to protect legitimate interests or to establish, exercise or defend legal claims and there is no reason to assume an overriding interest of yours in non-disclosure, where there is a legal obligation under Art. 6(1)(c), or where it is necessary under Art. 6(1)(b) to perform a contract with you.
Working with processors
We select the service providers who process personal data on our behalf with care. Where we engage third parties to process personal data, this is done under a data processing agreement pursuant to Art. 28 GDPR.
Transfers to third countries
Where we process data in a third country, or where this happens through the use of third-party services, it occurs only for the reasons set out above. Subject to express consent or contractual necessity, we process data in third countries only where an adequate level of protection is recognised — such as under an adequacy decision like the EU-U.S. Data Privacy Framework — or on the basis of particular safeguards such as the European Commission's standard contractual clauses, pursuant to Art. 44 to 49 GDPR.
Retention period
Unless an express retention period is stated at the point of collection, we are obliged under Art. 5(1)(e) GDPR to erase personal data once the purpose for processing it has been fulfilled. Statutory retention obligations constitute a legitimate purpose for continued processing.
As a rule we store and retain data in personally identifiable form until the end of a business relationship or until applicable guarantee, warranty or limitation periods expire; beyond that, until the conclusion of any legal disputes in which the data is needed as evidence; and in any event until the end of the third year following the last contact.
Rights of data subjects
You have the right:
- under Art. 15 GDPR, to request information about the personal data we process about you — in particular the purposes of processing, the categories of data, the categories of recipients, the envisaged retention period, the existence of rights to rectification, erasure, restriction or objection, the existence of a right to lodge a complaint, the origin of your data, and the existence of automated decision-making including profiling;
- under Art. 16 GDPR, to obtain without undue delay the rectification of inaccurate data or the completion of your data held by us;
- under Art. 17 GDPR, to obtain the erasure of your data held by us, unless processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims;
- under Art. 18 GDPR, to obtain restriction of processing;
- under Art. 20 GDPR, to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller;
- under Art. 21 GDPR, to object to processing carried out on the basis of our legitimate interest. Where the objection concerns direct marketing, you have a general right to object which we implement without your having to give reasons;
- under Art. 7(3) GDPR, to withdraw consent once given at any time, with the effect that we may no longer continue the processing based on that consent;
- under Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule you may contact the supervisory authority of your habitual residence, your place of work, or our registered office.
The supervisory authority responsible for us is:
- Authority
- Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
- Address
- Barichgasse 40-42, 1030 Vienna, Austria
- Telephone
- +43 1 52 152-0
- dsb@dsb.gv.at
Exercising your rights
You decide how your personal data is used. If you wish to exercise one of the rights above, contact us by email at office@hot-dl.com, by post, or by telephone.
Please enclose a copy of an official photo ID with your request so that we can identify you unambiguously, and help us narrow the request down. Please state in what capacity (customer, visitor, supplier, applicant and so on) and over what period you were in a relationship with us. That allows us to deal with your request promptly.
Protection of personal data
The security of your personal data is a particular concern of ours. Under Art. 32 GDPR we therefore take appropriate technical and organisational measures — having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing — to ensure a level of security appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical access, access rights, input, disclosure, availability and separation of data. We have also established procedures ensuring that data subject rights can be exercised, that data is erased, and that threats to data are responded to. We take the protection of personal data into account when developing and selecting hardware and software, in line with the principle of data protection by design and by default under Art. 25 GDPR. We extend the same understanding of security to the processors we engage.
Currency of this policy
Further development or changes to the law may make it necessary to adapt this data policy from time to time. The current version can be retrieved and printed from this page at any time. For questions about data protection, contact us at office@hot-dl.com.