Privacy policy

The German version of this policy is authoritative. This translation is provided for your convenience.

We process personal data only to the extent necessary to operate this shop and to fulfil your order. This website uses no analytics, tracking or advertising services, embeds no social media plugins and loads no fonts or other resources from external servers. There is therefore no cookie banner: apart from the technically necessary data described below, nothing is collected.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Sebastian Boll
Bachenauerstr. 37
74254 Offenau
Germany
Phone: +39 349 7338674
Email: info@aromaitaly.com

We have not appointed a data protection officer, as the legal requirements for doing so are not met.

2. Terms and legal bases

"Personal data" means any information relating to an identified or identifiable natural person (Art. 4 no. 1 GDPR). "Processing" means any operation performed on such data (Art. 4 no. 2 GDPR).

We base each processing operation on one of the following legal grounds:

  • Art. 6 (1)(b) GDPR — performance of a contract or pre-contractual measures (your order).
  • Art. 6 (1)(c) GDPR — compliance with a legal obligation (in particular commercial and tax retention duties).
  • Art. 6 (1)(f) GDPR — legitimate interests (technically secure operation of this website, fraud prevention in payments).
  • Art. 6 (1)(a) GDPR — consent, where we expressly ask you for it in an individual case.

3. Hosting and server log files

This website runs on a virtual server we rent. The infrastructure provider is Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. A data processing agreement under Art. 28 GDPR is in place. The servers are located within the European Union.

When you visit this website the web server automatically collects data transmitted by your browser and stores it in log files: IP address, date and time of access, name and URL of the file retrieved, volume of data transferred and whether retrieval succeeded, browser type and version, operating system, and the referring page where transmitted.

This processing is based on Art. 6 (1)(f) GDPR. Our legitimate interest lies in delivering the website, ensuring its stability and security and repelling attacks. This data is not merged with other sources and is not evaluated for marketing purposes. Log files are deleted after 14 days at the latest, unless they are exceptionally needed longer to investigate a specific security incident.

4. Encryption

This website uses TLS encryption throughout (recognisable by "https://" in the address bar), so the data you transmit to us is protected in transit against being read by third parties.

5. Fonts and external content

All fonts used on this website are served from our own server. There is no connection to Google Fonts or a comparable service; your IP address is therefore not transmitted to third parties for this purpose. We embed no maps, videos or other external content.

The only external connection your browser makes on this website concerns payment processing via Stripe, and it is established solely on the checkout page (see section 7).

6. Shopping cart (local storage)

So that your cart survives moving between pages, we store the items you selected in your browser's local storage. Only the product identifier, the chosen variant and the quantity are stored — no prices and no personal data.

This data does not leave your browser until you place an order and is not used to recognise you. As it is strictly necessary for a service you have expressly requested, no consent is required under § 25 (2) no. 2 TDDDG. You can clear local storage at any time via your browser settings; your cart will then be empty.

7. Orders and payment processing via Stripe

When you place an order we process the data required for it: email address, name and delivery address, the items ordered with quantities and prices, and the date and amount of payment. The legal basis is Art. 6 (1)(b) GDPR (performance of a contract).

Payment is handled by the payment service provider Stripe. For customers in the European Economic Area the provider is Stripe Payments Europe, Limited (SPEL), 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

Your payment details never reach our server. Card details are entered in a field provided by Stripe that transmits directly to Stripe. We receive only the information whether the payment succeeded, together with the details needed for delivery.

Stripe processes payment data as an independent controller and also applies fraud detection. For this a Stripe script is loaded on the checkout page which evaluates technical characteristics of your device and your usage behaviour and may set cookies for this purpose. The legal basis is Art. 6 (1)(b) and Art. 6 (1)(f) GDPR; our legitimate interest and that of Stripe lie in preventing payment fraud.

Stripe may also transfer data to third countries, in particular the USA, on the basis of the EU Commission's standard contractual clauses. Details of Stripe's processing and your rights there: https://stripe.com/privacy.

8. Order confirmation by email

After a successful payment we send an order confirmation to the email address you provided. We are required to do so under § 312f of the German Civil Code; the legal basis is Art. 6 (1)(b) and (c) GDPR.

We use Google Workspace to send and receive email. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A data processing agreement under Art. 28 GDPR is in place. Here too a transfer to the USA may take place on the basis of the standard contractual clauses. Further information: https://policies.google.com/privacy.

We do not send a newsletter.

9. Contacting us

If you contact us by email or telephone we process your details in order to handle your enquiry. The legal basis is Art. 6 (1)(b) GDPR where your enquiry relates to a contract, and otherwise Art. 6 (1)(f) GDPR (legitimate interest in answering enquiries). We delete this data once your enquiry has been dealt with conclusively and no retention obligations prevent deletion.

10. Recipients of the data

We pass personal data only to the following recipients, and only where necessary for the purposes stated: the payment service provider Stripe; the shipping company we commission; our hosting provider; Google Ireland Limited (email); and our tax advisers and the tax authorities where legally required.

Data is never passed on for advertising purposes and is never sold.

11. Retention

We store personal data only for as long as necessary for the purposes stated. Order and invoice data is subject to commercial and tax retention periods (§ 257 HGB, § 147 AO) and is retained for up to ten years. For that period processing is restricted to retention.

12. Your rights

You have the following rights regarding your personal data: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17, where no retention obligation applies), restriction of processing (Art. 18), data portability (Art. 20) and withdrawal of consent with effect for the future (Art. 7 (3)).

An informal message to info@aromaitaly.com is enough to exercise these rights.

Right to object under Art. 21 GDPR

Where we process your data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to that processing. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

13. Obligation to provide data

Providing your data is neither required by law nor by contract. Without the details necessary for an order (email address, name, delivery address and payment data) we cannot, however, conclude a contract with you or deliver your order.

14. No automated decision-making

We do not carry out automated decision-making including profiling within the meaning of Art. 22 GDPR. Stripe's fraud detection may cause an individual payment to be declined; this does not affect your ability to place the order again with a different payment method or to contact us directly.

15. Changes to this policy

We adapt this privacy policy whenever the technology we use or the legal situation changes. The version available when you visit this website applies.

Last updated: August 2026