Privacy Policy

Privacy Policy | BEARPAW Products GmbH

1. Name and Address of the Controller

BEARPAW GmbH
Hannebach 30
96269 Großheirath
Germany
+49 (0) 9565 616 88 0
info@bearpaw-products.com

2. Contact Details for Data Protection Inquiries

Please direct all data protection inquiries to:

BEARPAW GmbH
Hannebach 30
96269 Großheirath
Germany
info@bearpaw-products.com

3. General Information on Data Processing

We process personal data only to the extent necessary to provide a functional website and our services. Processing is carried out only based on consent or legal authorization.

4. Rights of the Data Subject

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to lodge a complaint with a supervisory authority.

5. Website Provision & Server Log Files

When accessing our website, technical data such as IP address, access time, browser type, and pages visited are automatically recorded. This data is processed to ensure the technical functionality and security of the website.

6. Use of Cookies

We use cookies to optimize the website and for statistical purposes. Processing is based on your consent (Art. 6 para. 1 lit. a GDPR) or, in the case of technically necessary cookies, on legitimate interests (Art. 6 para. 1 lit. f GDPR).

7. Consent Management with Pandectes GDPR

We use the Pandectes GDPR consent tool to obtain and manage consents. Your selection is saved and can be adjusted at any time. More information at: pandectes.io

8. Registration & Customer Account

When registering, we process your personal data to set up and manage a customer account. Processing is based on your consent or for the fulfillment of a contract.

9. Online Store via Shopify

Our online store is operated via Shopify, provided by Shopify International Limited, Dublin. Servers are located in Canada and the USA. Shopify acts as a data processor according to Art. 28 GDPR. More info at: shopify.com

10. Payment Processing

We offer various payment methods via third-party providers (e.g., Klarna, PayPal). Payment processing is based on Art. 6 para. 1 lit. b GDPR. For more information, see the privacy policies of the respective providers.

11. Shipping Providers

To deliver your order, we transmit relevant data to our shipping partners (e.g., DHL, GLS). This is based on your consent or for contract fulfillment.

12. Newsletter & Email Marketing (Klaviyo, Shopify)

When subscribing to our newsletter, your email address and possibly other data are processed. Sending is done via Klaviyo (USA) and Shopify Email. We use the double opt-in procedure. Legal basis: Consent under Art. 6 para. 1 lit. a GDPR.

13. Contact Forms & Email Communication

When contacting us via forms or email, your information will be processed to handle the request. Legal basis is your consent or contract initiation.

14. Customer Support & Live Chat (Freddy AI / Freshdesk)

We use Freddy AI (Freshchat) from Freshworks Inc. to provide a live chat. Communication occurs via an embedded widget. Legal basis: legitimate interest or Art. 6 para. 1 lit. b GDPR. Info: freshworks.com

15. Web Analytics & Tracking

We use tools such as Google Analytics, Meta Pixel, TikTok Pixel, Pinterest Conversion Tracking, and Google Ads Conversion Tracking to analyze user behavior and optimize our advertising. Processing only takes place with consent according to Art. 6 para. 1 lit. a GDPR.

16. Google Tag Manager

Google Tag Manager is used to manage website tags. It does not process any personal data itself.

17. Use of Social Media & Business Platforms

We maintain company profiles on platforms like Instagram, Pinterest, YouTube, LinkedIn, and XING. When you interact with us there, personal data may be processed. For details, refer to the privacy policies of the respective platforms.

18. Geotargeting

To provide regional targeting, IP address or postal code may be used. This is based on legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.

19. Plugins Used

Our website uses plugins (e.g., Instagram, YouTube, Pinterest) that may transmit data to the respective providers. Data processing takes place only with your consent.

20. Customer Reviews via Judge.me

We use the Judge.me service to display and manage customer reviews. Personal data such as name, email address, and review content may be processed and publicly displayed on our website. The processing is based on Art. 6 para. 1 lit. f GDPR to display user feedback and improve our services. More information: judge.me/privacy

21. Use of Xentral ERP

We use the ERP system Xentral (Xentral ERP Software GmbH, Fuggerstraße 11, 86150 Augsburg, Germany) to process and manage orders, inventory, and shipping. Personal data such as name, address, order, and payment data is processed based on Art. 6 para. 1 lit. b GDPR for contract fulfillment and Art. 6 para. 1 lit. f GDPR (organizational purposes).

22. Data Transfers to Third Countries

When using Shopify, Klaviyo, Google, Meta, TikTok, and other tools, data may be transferred to third countries. These transfers are based on appropriate safeguards such as EU Standard Contractual Clauses pursuant to Art. 46 GDPR.

23. Retention Period

We store personal data only as long as necessary for the respective processing purposes or as legally required. Once the purpose ceases or statutory retention periods expire, data is routinely deleted.

Criteria for storage duration include statutory retention periods (e.g., up to 10 years under tax and commercial law), duration of the customer relationship, consent, technical requirements, or legitimate interests.

24. Updates

This privacy policy is currently valid. We reserve the right to change or update it as needed.