Privacy Policy
Last updated: 2026-08-02
Please note: This is a convenience translation. The German version is the legally binding one — in case of any discrepancy, the German text prevails. References are to German and European law.
1. Controller
Collion GmbH & Co. KG
Am Schmiedlacker 56, D-84028 Landshut, Germany
Phone: +49 (871) 2066-1000
Email: info@collion.de
Represented by its general partner Collion Verwaltungs GmbH,
in turn represented by its Managing Director Andreas Bergmann
2. Data protection officer
Given the size of the company, we are not required to appoint a data protection officer (Section 38 of the German Federal Data Protection Act, BDSG — the obligation applies only where, as a rule, at least 20 persons are constantly engaged in the automated processing of personal data).
3. What data we process, and why
3.1 Orders and customer accounts
When you place an order we collect: name, address, a differing delivery address where applicable, email address, telephone number (optional), company and VAT identification number (for business customers), and payment data (depending on the payment method chosen, see 3.3). We pass the delivery and billing address to the shipping service provider engaged for the delivery.
Legal basis: Article 6(1)(b) GDPR (performance of a contract / pre-contractual measures).
Retention: For the duration of the business relationship, thereafter in accordance with statutory retention periods (as a rule 6–10 years under commercial and tax law, Sections 257 HGB, 147 AO).
3.2 Migrated existing customer accounts
When migrating from our previous web shop, only accounts with an actual login (a password set) and a genuine purchase history were transferred — guest orders and registrations without a purchase were not transferred, in the interest of data minimisation.
The passwords themselves were not transferred: because the integrity of the passwords could not have been preserved during a transfer to the new shop system without weakening security, we deliberately refrained from doing so. A new, secure password can be set via the usual password reset procedure ("forgotten password"), using control over the email account on file.
The reason for changing the shop system was the lack of functionality in the system previously used — no known security incident led to the change.
3.3 Payment processing
Depending on the payment method chosen, we pass data to the following providers:
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A.) — where payment is made by PayPal. Details: PayPal privacy statement.
- Payment in advance: bank transfer, no disclosure to third parties other than our own bank.
- Invoice: no disclosure to third parties; we do not carry out any automated credit assessment through a credit agency, approval is granted manually by us.
Legal basis: Article 6(1)(b) GDPR.
3.4 Cookies and tracking
Strictly necessary cookies (shopping basket, login session) are set without a requirement of consent (Article 6(1)(f) GDPR, Section 25(2) no. 2 TDDDG). Beyond these we currently use no analytics or tracking tools (see also section 4).
3.5 Processors / hosting
External hosting
We use the services of an external hosting provider to make our website and online shop available. The data processed in this context (for example server log files, IP addresses) is stored on that provider's servers.
The servers are located in a data centre in Germany. A data processing agreement pursuant to Article 28 GDPR has been concluded with the provider. The use of the host takes place within the scope of our legitimate interest in providing our website securely, quickly and efficiently (Article 6(1)(f) GDPR). For reasons of security and in order to protect our IT infrastructure we do not name the specific infrastructure provider here. The full contact details of the processor concerned can be requested, where there is a legitimate interest, via the contact details given in the legal notice.
Cloudflare (reserved)
In order to protect our infrastructure and for load balancing where this may become necessary, we reserve the right to secure data traffic by means of upstream services provided by Cloudflare. Data is transmitted by Cloudflare in SSL-encrypted form without breaking end-to-end encryption. This connection is currently used internally only.
Order processing and disclosure to shipping service providers
Nature and purpose of processing: The data you enter when placing an order (for example name, address, order details) is processed in order to perform the contract of sale. This order data is processed and stored exclusively on locally operated, company-owned computer systems that are not accessible from the public internet (on-premises infrastructure). No disclosure to external software-as-a-service providers or cloud providers for order management takes place.
Disclosure for shipping: In order to perform the contract we pass your data to the shipping service provider engaged with the delivery. Only that personal information which is strictly necessary for providing the transport and delivery service is transmitted (as a rule name and delivery address). No further order details are transmitted.
Legal basis: The processing and disclosure of the data is based on Article 6(1)(b) GDPR (performance of a contract). The use of an isolated, local computer system is additionally based on our legitimate interest in maximum data security and the integrity of our customer data pursuant to Article 6(1)(f) GDPR in conjunction with Article 32 GDPR (security of processing).
PayPal — see 3.3
3.6 Contacting us
If you contact us by email or contact form, we process the data provided in order to deal with your request (Article 6(1)(b) or (f) GDPR).
4. Recipients, transfers to third countries
Please note that when using the PayPal payment process you are redirected on your IT system to PayPal in order to authorise the payment. You should be aware that data processing takes place on US computer systems in that context. At no point does PayPal transmit personal data to us beyond the data required to process the order, and in particular no bank account or (credit) card information.
We would point out once again that we offer every customer payment in advance or — where the requirements are met — payment on account, in each case without any transfer of data to PayPal.
Beyond the cases described, we do not engage any external service providers to profile our customers — in particular no retargeting and no customer or purchase analysis by third parties.
5. Your rights
You have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21), as well as the right to lodge a complaint with a supervisory authority.
The supervisory authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
6. Retention in general
Unless stated otherwise above, we delete personal data as soon as the purpose no longer applies and no statutory retention obligations prevent deletion.