Privacy policy

Privacy Policy

Last updated: 3 October 2026

This Privacy Policy explains how personal data is processed when you visit our website parax.de (including its language and country versions) and when you shop in our online store.

1. Controller

PARAX GmbH
Bockeldamm 19
59199 Bönen
Germany
Email: info@parax.de

Data protection contact:
PARAX GmbH – Data Protection
Email: info@parax.de

2. Scope & Definitions

This policy applies to all pages under parax.de (including subpages, product, blog and help pages), our social media profiles, embedded content and the functions offered through the website (e.g. customer accounts, shopping cart, checkout, newsletter, reviews, contact forms and WhatsApp links).

Terms such as “personal data”, “processing”, “controller” and “processor” have the meanings set out in Article 4 of the General Data Protection Regulation (GDPR). The storage of and access to cookies and similar technologies are governed by Section 25 of the German Telecommunications and Digital Services Data Protection Act (TDDDG).

3. Legal Bases for Processing

We process your data on the basis of the GDPR, in particular:

  • Article 6(1)(b) GDPR (performance of a contract / steps prior to entering into a contract) – e.g. orders, payments, customer accounts and support.

  • Article 6(1)(c) GDPR (legal obligation) – e.g. retention requirements under commercial and tax law.

  • Article 6(1)(f) GDPR (legitimate interests) – e.g. IT security, fraud prevention, audience measurement in anonymised form and the commercial operation of our business.

  • Article 6(1)(a) GDPR (consent) – e.g. cookies/tracking that are not technically necessary and newsletters.

4. Hosting / Store Operation (Shopify)

Our website and store are operated on the Shopify platform. The service provider (processor) is Shopify International Ltd., 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland. Depending on the function used, data may be transferred to other affiliated Shopify companies and processed in third countries (particularly Canada and the USA). Shopify provides a Data Processing Addendum (DPA), Standard Contractual Clauses and additional safeguards.

Data processed: Usage data and metadata (IP address, timestamps, device/browser data, page views), order data, payment and delivery information, customer account data and support enquiries.

Purposes: Providing the website and store functions, optimising display and loading (CDN), checkout, fraud prevention, security, analysing store performance and sending essential system emails.

Legal basis: Article 6(1)(b), (c) and (f) GDPR; for non-essential functions, where applicable, Article 6(1)(a) GDPR in conjunction with Section 25 TDDDG.

5. Server Logs & IT Security

When you visit our pages, server log files are processed automatically (including IP address, date/time, requested URL, referrer, HTTP status, amount of data transferred and user agent/device). These are stored to ensure stability, functionality and security (e.g. error analysis and protection against misuse and attacks).

Retention period: Generally 7–30 days; longer retention only for evidentiary purposes.

Legal basis: Article 6(1)(f) GDPR.

6. Consent Management, Cookies & Similar Technologies

We use consent or preference management for cookies and similar technologies. We use technically necessary cookies/tools without consent because they are required to provide the store (e.g. shopping cart, language settings, payment processing and security). We only use non-essential cookies/tools (e.g. marketing/convenience features) with your consent (Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR).

Note on web analytics: For audience measurement, we use etracker in its standard cookieless mode, which does not require consent (Article 6(1)(f) GDPR). Additional etracker functions, such as A/B testing using cookies, are only activated if you consent (Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).

You can change your selection at any time using the “Cookie Banner” link in the footer. There you will also find the current, dynamically updated cookie list for each category.

7. Orders, Contract Performance & Customer Accounts

Data categories: Basic customer details (name, billing/delivery address), contact details (email and, optionally, telephone number), order and line-item data, payment data (tokens/references, depending on the payment method), communication content and, where applicable, returns/warranty data.

Purposes: Processing orders, delivery, customer communication, accounting/legal obligations and customer account management.

Legal basis: Article 6(1)(b) GDPR; legal obligations under Article 6(1)(c) GDPR (e.g. retention for tax purposes for up to 10 years).

Customer accounts (B2B): Only business customers (B2B) can create a customer account. We process the data provided during registration to provide and manage the account. Legal basis: Article 6(1)(b) GDPR; where applicable, consent under Article 6(1)(a) GDPR. Deletion: on request, provided that statutory retention requirements do not prevent this.

Fraud prevention / automated decisions: An automated risk assessment may take place during checkout (e.g. based on scoring or rules). Legal basis: Article 6(1)(f) GDPR. You have the right to request human review and to express your point of view (Article 22(3) GDPR).

8. Payments

Payments are made through the payment services you select. These receive the data required to process the payment (order total, currency, reference, name, billing/delivery address and email; depending on the method, payment instrument details may also be included).

Available payment methods (depending on availability/country):

  • Credit card: Usually processed through Shopify Payments.

  • PayPal: Including PayPal Express at checkout.

  • Klarna: E.g. payment by invoice/instalments; Klarna may use its own credit reference agencies

×