Privacy Policy
for shop.iob-ev.com
Version: 31 July 2026
This Privacy Policy explains how personal data is collected, processed and protected when you visit and use the online shop shop.iob-ev.com.
Personal data means any information relating to an identified or identifiable natural person as defined in the General Data Protection Regulation (GDPR).
1. Joint Controllers pursuant to Article 26 GDPR
The processing of personal data relating to the operation of the online shop shop.iob-ev.com
is carried out under joint controllership pursuant to Article 26 GDPR by the following organisations:
IOB Internationale Organisation für naturnahe Badegewässer e.V.
Registered Office
Überseetor 14
28217 Bremen
Germany
Telephone:
+49 421 178 76 279
Email: [office@iob-ev.com](mailto:office@iob-ev.com)
VAT ID:
DE277173171
Italian Association for Natural Bathing Waters
Via Giorgio e Guido Paglia, 27
24122 Bergamo (BG)
Italy
VAT Number:
04896870161
Tax Number:
91089910334
Website:
[www.acquebalneabili.it](http://www.acquebalneabili.it)
Data subjects may exercise their rights against either of the Joint Controllers.
The internal allocation of responsibilities does not affect your statutory rights under the GDPR.
2. Joint Controllership Agreement
The Joint Controllers have concluded an agreement pursuant to Article 26 GDPR determining their respective responsibilities regarding compliance with data protection obligations.
In particular:
- IOB e.V. is responsible for technical operation of the website, hosting, website security, maintenance and system administration.
- The Italian Association is responsible for product management, commercial operations, digital content and customer-related business matters.
- Both organisations cooperate regarding order processing, payment handling, statutory record keeping and the handling of data subject requests.
The essence of this agreement will be made available to data subjects upon request where legally required.
3. Legal Basis for Processing
Personal data is processed exclusively in accordance with the applicable provisions of the General Data Protection Regulation (GDPR).
- Article 6(1)(a) GDPR — consent.
- Article 6(1)(b) GDPR — performance of a contract or pre-contractual measures.
- Article 6(1)(c) GDPR — compliance with legal obligations.
- Article 6(1)(f) GDPR — legitimate interests, including secure operation of the website, fraud prevention and legal defence.
Where information is stored on, or accessed from, a user’s terminal device, the provisions of the German Telecommunications Digital Services Data Protection Act (TDDDG) additionally apply.
Technically necessary storage and access operations are carried out pursuant to Section 25(2) TDDDG.
Any non-essential storage or access takes place only after the user’s consent in accordance with Section 25(1) TDDDG.
4. Hosting
This online shop is hosted by
Hetzner Online GmbH,
Industriestraße 25,
91710 Gunzenhausen,
Germany.
Hetzner processes personal data to the extent necessary for the technical operation,
maintenance, security and availability of this website.
Where Hetzner processes personal data on our behalf,
processing is carried out pursuant to a Data Processing Agreement in accordance with
Article 28 GDPR.
The legal basis for this processing is
Article 6(1)(f) GDPR.
Our legitimate interest consists in providing a secure,
stable and efficient online service.
5. Server Log Files
Whenever this website is accessed,
our hosting provider automatically records technical information in server log files.
This information may include:
- IP address
- Date and time of access
- Requested URL
- Referrer URL
- Browser type and browser version
- Operating system
- HTTP status code
- Transferred data volume
- Technical error messages
The processing of these data is necessary to ensure the secure operation of the website,
detect technical problems,
prevent misuse,
investigate security incidents
and maintain system stability.
The legal basis is
Article 6(1)(f) GDPR.
Server log files are retained only for as long as required for technical and security purposes.
Where necessary to investigate abuse or legal claims,
individual log entries may be retained until the matter has been fully resolved.
6. SSL/TLS Encryption and Data Security
This website uses SSL/TLS encryption in order to protect confidential communications.
Encrypted connections can be identified by the padlock symbol in your browser
and by the use of “https://” in the address bar.
We implement appropriate technical and organisational measures in accordance with
Article 32 GDPR
to protect personal data against accidental or unlawful destruction,
loss,
alteration,
unauthorised disclosure
or unauthorised access.
These measures include, among others:
- SSL/TLS encryption
- Access control systems
- Role-based permissions
- Regular software updates
- Security monitoring
- Technical backups where necessary
7. Cookies and Similar Technologies
Our website uses cookies and similar technologies where necessary for the operation
of the online shop.
Essential cookies are used to provide functions such as:
- shopping cart functionality
- checkout process
- payment processing
- security functions
- storage of your privacy preferences
Essential cookies are used pursuant to
Section 25(2) TDDDG.
The associated processing of personal data is based on
Article 6(1)(b) GDPR
(contract performance)
or
Article 6(1)(f) GDPR
(legitimate interests).
Any non-essential cookies or comparable technologies are activated only after your
prior consent pursuant to
Section 25(1) TDDDG
and
Article 6(1)(a) GDPR.
You may withdraw or modify your consent at any time via the cookie settings.
8. Consent Management (Complianz)
We use
Complianz GDPR/CCPA Cookie Consent
to manage and document cookie consent.
Complianz stores your consent preferences together with technical information,
such as:
- date and time of consent
- selected preferences
- consent identifier
- technical proof of consent
These data are processed solely for the purpose of complying with legal obligations
and documenting valid consent.
The legal basis is
Article 6(1)(c) GDPR,
Article 6(1)(f) GDPR,
and
Section 25(2) TDDDG.
Consent records are retained only for as long as necessary to fulfil legal documentation requirements.
9. Google Fonts
This website uses
Google Fonts hosted locally on our own server.
No connection to Google servers is established when you visit this website.
Consequently,
no personal data, including your IP address, is transmitted to Google
for the purpose of displaying fonts.
The local hosting of fonts ensures a consistent appearance of the website while
maximising data protection.
The legal basis for this processing is
Article 6(1)(f) GDPR.
Our legitimate interest is the secure,
privacy-friendly
and technically reliable presentation of our online services.
10. WooCommerce Online Shop
Our online shop is operated using WooCommerce,
a WordPress-based e-commerce platform.
WooCommerce is used exclusively for the technical processing of orders,
contract management and the provision of digital products.
Depending on the services you use,
the following categories of personal data may be processed:
- First and last name
- Billing address
- Email address
- Country of residence
- VAT information, where applicable
- Ordered products or services
- Order number
- Order date and time
- Selected payment method
- Payment status
- Technical information, including IP address and browser information
The processing of these data is necessary for the conclusion and performance of the purchase contract,
for payment allocation,
fraud prevention,
accounting obligations
and the delivery of digital products.
The legal basis is
Article 6(1)(b),
Article 6(1)(c)
and,
where applicable,
Article 6(1)(f) GDPR.
11. Ordering Process
This online shop does not provide permanent customer accounts.
Orders are processed solely on the basis of the information required for the individual purchase.
No user profile is created beyond the information required for fulfilling the respective order.
However,
statutory accounting,
tax and documentation obligations require us to retain certain transaction data
for the legally prescribed retention periods.
12. Digital Products
The online shop offers digital products and digital services only.
No physical goods are shipped.
Following successful payment,
customers receive access to the purchased digital products,
for example through:
- download links
- electronic tickets
- booking confirmations
- digital access credentials
- other electronic delivery methods
Personal data are processed only to the extent necessary for providing these digital products.
The legal basis is
Article 6(1)(b) GDPR.
Technical access logs and download records may additionally be processed
for fraud prevention,
system security
and legal defence.
The legal basis for such processing is
Article 6(1)(f) GDPR.
13. Transactional Emails
In connection with your order,
we send transaction-related emails that are necessary for the performance of the contract.
These emails may include:
- Order confirmations
- Payment confirmations
- Invoices
- Delivery information
- Download instructions
- Booking confirmations
- Support information regarding your purchase
These emails are not newsletters
and are not used for marketing purposes.
The legal basis is
Article 6(1)(b)
and
Article 6(1)(c) GDPR.
14. Email Communication
This website does not provide a contact form.
If you contact us by email,
we process the personal data contained in your message,
including your email address
and any additional information you voluntarily provide.
Where your enquiry relates to an existing or intended contractual relationship,
processing is based on
Article 6(1)(b) GDPR.
For all other enquiries,
processing is based on
Article 6(1)(f) GDPR,
our legitimate interest being the efficient handling of communications.
Your correspondence will only be retained for as long as necessary to process your enquiry
or for as long as statutory retention obligations require.
15. Payment Processing
To process payments for purchases made through our online shop, we use the payment
services WooPayments, Stripe and PayPal.
Depending on the payment method selected, personal data required to complete the
transaction are transmitted to the respective payment service provider.
Such data may include, in particular:
- First and last name
- Billing address
- Email address
- Order number
- Order value
- Currency
- Payment status
- IP address (where required for fraud prevention)
The processing is necessary for the performance of the purchase contract and is
based on Article 6(1)(b) GDPR.
Payment service providers may also process personal data in their own capacity
to comply with legal obligations, prevent fraud, prevent money laundering and
ensure the security of payment transactions.
16. WooPayments
Our shop uses WooPayments to provide various payment methods.
WooPayments is a payment service integrated into WooCommerce and operated by
Automattic Inc. Payment processing is technically carried out using the
infrastructure of Stripe.
WooPayments processes only the personal data necessary to execute payment
transactions securely and efficiently.
Further information is available in WooCommerce’s and WooPayments’
privacy documentation.
17. Stripe
If you choose to pay by credit card or by another payment method offered through
Stripe, payment processing is carried out by
Stripe Payments Europe, Limited,
Ireland.
Stripe may process personal data for the following purposes:
- payment processing
- identity verification
- fraud prevention
- risk analysis
- compliance with statutory obligations
- prevention of unauthorised payment transactions
Depending on the payment method selected, Stripe may process payment data,
technical device information and transaction-related information.
The legal basis is
Article 6(1)(b) GDPR.
Where Stripe carries out legally required verification procedures or fraud
prevention in its own responsibility, additional legal bases may apply under
Articles 6(1)(c) and 6(1)(f) GDPR.
Further information is available at
https://stripe.com/privacy
18. PayPal
If PayPal is selected as the payment method, payment processing is carried out by
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal,
L-2449 Luxembourg.
PayPal receives only the personal data necessary to process your payment.
PayPal may perform identity verification, fraud prevention and creditworthiness
assessments where permitted by applicable law.
The legal basis for the transfer of personal data is
Article 6(1)(b) GDPR.
Additional information is available in PayPal’s Privacy Statement.
19. Recipients of Personal Data
Personal data are disclosed only where necessary for the purposes described in
this Privacy Policy.
Recipients may include:
- the Joint Controllers
- hosting provider (Hetzner)
- WooCommerce and technically required service providers
- WooPayments
- Stripe
- PayPal
- IT service providers
- accountants and tax advisers where required by law
- public authorities where disclosure is legally required
Where service providers process personal data exclusively on our behalf,
Data Processing Agreements have been concluded in accordance with
Article 28 GDPR whenever legally required.
20. International Data Transfers
Some of the service providers used by this website may process personal data
outside the European Union (EU) or the European Economic Area (EEA).
Where such transfers occur,
they are carried out only in accordance with
Articles 44–49 GDPR.
Appropriate safeguards may include:
- an adequacy decision adopted by the European Commission;
- the EU–US Data Privacy Framework, where applicable;
- Standard Contractual Clauses adopted by the European Commission;
- additional technical and organisational safeguards where required.
Despite these safeguards,
data protection laws in third countries may differ from those applicable within
the European Union.
21. Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes
described in this Privacy Policy or as required by applicable statutory retention
obligations.
| Category of Data | Retention Period |
|---|---|
| Order and invoice data | Generally up to 10 years in accordance with applicable commercial and tax legislation |
| Payment information | As required by applicable legal obligations and the respective payment provider |
| Server log files | Only as long as technically and operationally necessary |
| Consent records | As required to demonstrate valid consent and comply with legal obligations |
| Email correspondence | Until the enquiry has been fully processed or statutory retention obligations expire |
After expiry of the applicable retention periods,
personal data are deleted or anonymised unless further storage is legally required
or necessary for the establishment,
exercise or defence of legal claims.
22. Rights of Data Subjects
Under the General Data Protection Regulation (GDPR), you have the following rights,
provided the respective legal requirements are met:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (“right to be forgotten”) (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object (Article 21 GDPR)
- Right to withdraw consent at any time (Article 7(3) GDPR)
You may exercise these rights at any time by contacting either of the Joint Controllers.
To prevent unauthorised disclosure of personal data, we may request appropriate proof of identity before processing your request.
23. Withdrawal of Consent
Where the processing of your personal data is based on your consent, you may withdraw that consent at any time with future effect.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
24. Right to Object
Where personal data are processed on the basis of Article 6(1)(f) GDPR (legitimate interests),
you have the right to object at any time on grounds relating to your particular situation.
If you object, we will cease processing the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.
We do not currently process personal data for direct marketing purposes.
Should this change in the future, you will have the right to object to such processing at any time without giving reasons.
25. Right to Lodge a Complaint
If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority pursuant to
Article 77 GDPR.
You may contact the supervisory authority in:
- the Member State of your habitual residence;
- your place of work;
- or the place of the alleged infringement.
Since this online shop is operated under joint controllership between organisations established in Germany and Italy, the competent supervisory authority will depend on the specific circumstances of the processing concerned.
26. Security of Processing
The Joint Controllers implement appropriate technical and organisational measures pursuant to
Article 32 GDPR
to ensure a level of security appropriate to the risk.
Such measures include, among others:
- SSL/TLS encrypted communication
- restricted administrative access
- role-based access management
- regular software updates
- technical monitoring of systems
- backup procedures where appropriate
- protection against unauthorised access
Security measures are regularly reviewed and adapted to technological developments where necessary.
27. Mandatory Provision of Personal Data
The provision of personal data required during the ordering process is necessary for the conclusion and performance of the purchase contract.
Without these data we are unable to:
- process your order;
- allocate your payment;
- issue legally required invoices;
- provide purchased digital products or services.
The provision of any additional information is voluntary unless expressly indicated otherwise.
28. Automated Decision-Making
The Joint Controllers do not carry out automated decision-making or profiling within the meaning of
Article 22 GDPR.
However, payment service providers may independently perform automated fraud prevention, risk analysis or identity verification where required by law or necessary for secure payment processing.
29. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy whenever necessary to reflect changes in legislation, regulatory requirements, technical developments or the services offered through this website.
The version published on this website shall always be the current and applicable version.
Version:
31 July 2026
