Data Protection

Privacy Policy

Last updated: 11 May 2026

1. Data controller

The controller within the meaning of the General Data Protection Regulation (EU GDPR, Regulation 2016/679) and the UK GDPR is:

Martac Store, Bischoffring 8/2, 53797 Lohmar, Germany
Email: contact@martac.digital, phone: +49 157 784 859 73

2. Data we collect

  • Order data: name, shipping address, email and payment details — to perform the contract (Art. 6(1)(b) GDPR).
  • Enquiry data: name, email and message content when you use the contact form — to answer your request (Art. 6(1)(a), (b) GDPR).
  • Technical data: IP address, browser type and server log files — to keep the site secure and working (Art. 6(1)(f) GDPR, legitimate interest).

3. Processors

Our shop runs on Shopify (Shopify International Ltd., Ireland), which processes order and payment data on our behalf under a data processing agreement (Art. 28 GDPR). Transfers outside the EU/UK take place only with appropriate safeguards (Art. 44–49 GDPR), such as Standard Contractual Clauses.

4. Cookies

We use strictly necessary cookies to run the cart and checkout (§ 25(2) TDDDG; PECR in the UK). Optional cookies (analytics, marketing) are only used with your consent.

5. Retention

We keep personal data only as long as necessary. Order data is kept for the statutory retention periods (up to 10 years under § 147 AO, up to 6 years under § 257 HGB). Enquiry data is deleted once the conversation is finished unless further storage is required.

6. Your rights

Under Art. 15–21 GDPR you have the right to:

  • access your data (Art. 15);
  • rectify inaccurate data (Art. 16);
  • erasure ("right to be forgotten", Art. 17);
  • restrict processing (Art. 18);
  • data portability (Art. 20);
  • object to processing (Art. 21);
  • withdraw consent at any time (Art. 7(3)).

To exercise your rights, email contact@martac.digital. You may also complain to a supervisory authority — in Germany the LDI NRW, in the UK the Information Commissioner's Office (ICO).

7. Security

We use technical and organisational measures (TLS encryption, access restrictions) to protect your data against unauthorised access, loss and alteration (Art. 32 GDPR).