Last Updated:
1. Data Controller Information
The data controller responsible for your personal data is:
Company Name: Wraxylongrexalon
Address: 10 Mönckebergstraße, 20095 Hamburg, Germany
Email: inquiry@wraxylongrexalon.world
Website: https://wraxylongrexalon.world
2. Introduction
At Wraxylongrexalon, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services, in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG), and other applicable data protection laws.
By accessing our website or submitting your personal data to us, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our website or services.
3. Categories of Personal Data We Collect
We may collect the following categories of personal data:
3.1 Information You Provide Directly
- Contact Information: Name, email address, phone number (optional), and postal address
- Order Information: Product orders, delivery details, and transaction history
- Communication Data: Messages, inquiries, and correspondence you send to us
- Consent Records: Records of any consents you have given
3.2 Information Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device type
- Usage Data: Pages visited, time spent on pages, navigation paths, click patterns
- Cookie Data: Information collected through cookies and similar technologies (see our Cookie Policy)
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 of the GDPR:
- Consent (Art. 6(1)(a) GDPR): Where you have given explicit consent for specific processing activities, such as receiving marketing communications or enabling certain cookies
- Contract Performance (Art. 6(1)(b) GDPR): Where processing is necessary to fulfill our contractual obligations to you, such as processing your orders and delivering products
- Legal Obligation (Art. 6(1)(c) GDPR): Where we are required to process data to comply with legal requirements, such as tax and accounting obligations
- Legitimate Interests (Art. 6(1)(f) GDPR): Where processing is necessary for our legitimate business interests, provided these do not override your rights and freedoms. Our legitimate interests include fraud prevention, website security, and improving our services
5. Purposes of Data Processing
We use your personal data for the following purposes:
- Processing and fulfilling your orders, including delivery and payment processing
- Communicating with you about your orders, inquiries, and customer service matters
- Managing your account and providing customer support
- Sending marketing communications (only with your explicit consent)
- Improving our website, products, and services through analysis
- Ensuring the security and proper functioning of our website
- Complying with legal obligations and protecting our legal rights
- Preventing fraud and unauthorized access
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Order Data: Retained for 10 years after the order date to comply with German commercial and tax law requirements (§ 147 AO, § 257 HGB)
- Marketing Consent Records: Retained for the duration of your consent plus 3 years after withdrawal for legal defense purposes
- Website Analytics Data: Anonymized or deleted after 26 months
- Customer Service Records: Retained for 3 years after the last interaction
- Cookie Consent Records: Retained for 12 months, after which you will be asked to renew your preferences
After the retention period expires, your data will be securely deleted or anonymized.
7. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): You have the right to request a copy of the personal data we hold about you and information about how we process it
- Right to Rectification (Art. 16 GDPR): You have the right to request correction of inaccurate or incomplete personal data
- Right to Erasure (Art. 17 GDPR): You have the right to request deletion of your personal data under certain circumstances ("right to be forgotten")
- Right to Restriction (Art. 18 GDPR): You have the right to request restriction of processing under certain circumstances
- Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, machine-readable format
- Right to Object (Art. 21 GDPR): You have the right to object to processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. In Germany, you may contact the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit)
To exercise any of these rights, please contact us using the information provided in Section 1.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for all data transmissions
- Secure server infrastructure with regular security updates
- Access controls limiting data access to authorized personnel only
- Regular security assessments and monitoring
- Employee training on data protection practices
- Secure data backup procedures
9. Data Sharing and Third-Party Processors
We may share your personal data with the following categories of recipients:
- Service Providers: Companies that help us operate our business, such as payment processors, shipping carriers, and email service providers. These parties process data only on our behalf and under our instructions
- Legal Requirements: Authorities or third parties when required by law or to protect our legal rights
We do not sell your personal data to third parties.
9.1 International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Binding Corporate Rules where applicable
10. Cookies and Similar Technologies
Our website uses cookies and similar technologies to enhance your browsing experience. For detailed information about the cookies we use and how to manage your preferences, please refer to our Cookie Policy.
11. Children's Privacy
Our website and services are not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete such information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the new Privacy Policy on this page with an updated "Last Updated" date. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns about our data practices, please contact us:
Wraxylongrexalon
Address: 10 Mönckebergstraße, 20095 Hamburg, Germany
We aim to respond to all legitimate requests within one month. If your request is particularly complex or you have made multiple requests, we may need up to three months to respond, in which case we will notify you accordingly.