Privacy Policy

 

 

 

 

 

Privacy Policy

for shop.iob-ev.com
Version: 31 July 2026

This Privacy Policy explains how personal data is collected, processed and protected when you visit and use the online shop shop.iob-ev.com.

Personal data means any information relating to an identified or identifiable natural person as defined in the General Data Protection Regulation (GDPR).

1. Joint Controllers pursuant to Article 26 GDPR

The processing of personal data relating to the operation of the online shop shop.iob-ev.com
is carried out under joint controllership pursuant to Article 26 GDPR by the following organisations:

IOB Internationale Organisation für naturnahe Badegewässer e.V.

Registered Office

Überseetor 14

28217 Bremen

Germany

Telephone:
+49 421 178 76 279

 

Email: [office@iob-ev.com](mailto:office@iob-ev.com)

 

VAT ID:
DE277173171

Italian Association for Natural Bathing Waters

Via Giorgio e Guido Paglia, 27

 

24122 Bergamo (BG)

 

Italy

VAT Number:
04896870161

 

Tax Number:
91089910334

 

Website:

[www.acquebalneabili.it](http://www.acquebalneabili.it)

 

Data subjects may exercise their rights against either of the Joint Controllers.

The internal allocation of responsibilities does not affect your statutory rights under the GDPR.

2. Joint Controllership Agreement

The Joint Controllers have concluded an agreement pursuant to Article 26 GDPR determining their respective responsibilities regarding compliance with data protection obligations.

In particular:

  • IOB e.V. is responsible for technical operation of the website, hosting, website security, maintenance and system administration.
  • The Italian Association is responsible for product management, commercial operations, digital content and customer-related business matters.
  • Both organisations cooperate regarding order processing, payment handling, statutory record keeping and the handling of data subject requests.

The essence of this agreement will be made available to data subjects upon request where legally required.

3. Legal Basis for Processing

Personal data is processed exclusively in accordance with the applicable provisions of the General Data Protection Regulation (GDPR).

  • Article 6(1)(a) GDPR — consent.
  • Article 6(1)(b) GDPR — performance of a contract or pre-contractual measures.
  • Article 6(1)(c) GDPR — compliance with legal obligations.
  • Article 6(1)(f) GDPR — legitimate interests, including secure operation of the website, fraud prevention and legal defence.

Where information is stored on, or accessed from, a user’s terminal device, the provisions of the German Telecommunications Digital Services Data Protection Act (TDDDG) additionally apply.

Technically necessary storage and access operations are carried out pursuant to Section 25(2) TDDDG.

Any non-essential storage or access takes place only after the user’s consent in accordance with Section 25(1) TDDDG.


4. Hosting

This online shop is hosted by

Hetzner Online GmbH,

Industriestraße 25,

91710 Gunzenhausen,

Germany.

Hetzner processes personal data to the extent necessary for the technical operation,
maintenance, security and availability of this website.

Where Hetzner processes personal data on our behalf,
processing is carried out pursuant to a Data Processing Agreement in accordance with
Article 28 GDPR.

The legal basis for this processing is
Article 6(1)(f) GDPR.

Our legitimate interest consists in providing a secure,
stable and efficient online service.

5. Server Log Files

Whenever this website is accessed,
our hosting provider automatically records technical information in server log files.

This information may include:

  • IP address
  • Date and time of access
  • Requested URL
  • Referrer URL
  • Browser type and browser version
  • Operating system
  • HTTP status code
  • Transferred data volume
  • Technical error messages

The processing of these data is necessary to ensure the secure operation of the website,
detect technical problems,
prevent misuse,
investigate security incidents
and maintain system stability.

The legal basis is
Article 6(1)(f) GDPR.

Server log files are retained only for as long as required for technical and security purposes.
Where necessary to investigate abuse or legal claims,
individual log entries may be retained until the matter has been fully resolved.

6. SSL/TLS Encryption and Data Security

This website uses SSL/TLS encryption in order to protect confidential communications.

Encrypted connections can be identified by the padlock symbol in your browser
and by the use of “https://” in the address bar.

We implement appropriate technical and organisational measures in accordance with
Article 32 GDPR
to protect personal data against accidental or unlawful destruction,
loss,
alteration,
unauthorised disclosure
or unauthorised access.

These measures include, among others:

  • SSL/TLS encryption
  • Access control systems
  • Role-based permissions
  • Regular software updates
  • Security monitoring
  • Technical backups where necessary

7. Cookies and Similar Technologies

Our website uses cookies and similar technologies where necessary for the operation
of the online shop.

Essential cookies are used to provide functions such as:

  • shopping cart functionality
  • checkout process
  • payment processing
  • security functions
  • storage of your privacy preferences

Essential cookies are used pursuant to
Section 25(2) TDDDG.

The associated processing of personal data is based on
Article 6(1)(b) GDPR
(contract performance)
or
Article 6(1)(f) GDPR
(legitimate interests).

Any non-essential cookies or comparable technologies are activated only after your
prior consent pursuant to
Section 25(1) TDDDG
and
Article 6(1)(a) GDPR.

You may withdraw or modify your consent at any time via the cookie settings.

8. Consent Management (Complianz)

We use

Complianz GDPR/CCPA Cookie Consent

to manage and document cookie consent.

Complianz stores your consent preferences together with technical information,
such as:

  • date and time of consent
  • selected preferences
  • consent identifier
  • technical proof of consent

These data are processed solely for the purpose of complying with legal obligations
and documenting valid consent.

The legal basis is

Article 6(1)(c) GDPR,

Article 6(1)(f) GDPR,

and

Section 25(2) TDDDG.

Consent records are retained only for as long as necessary to fulfil legal documentation requirements.

9. Google Fonts

This website uses

Google Fonts hosted locally on our own server.

No connection to Google servers is established when you visit this website.

Consequently,

no personal data, including your IP address, is transmitted to Google

for the purpose of displaying fonts.

The local hosting of fonts ensures a consistent appearance of the website while
maximising data protection.

The legal basis for this processing is

Article 6(1)(f) GDPR.

Our legitimate interest is the secure,
privacy-friendly
and technically reliable presentation of our online services.


10. WooCommerce Online Shop

Our online shop is operated using WooCommerce,
a WordPress-based e-commerce platform.

WooCommerce is used exclusively for the technical processing of orders,
contract management and the provision of digital products.

Depending on the services you use,
the following categories of personal data may be processed:

  • First and last name
  • Billing address
  • Email address
  • Country of residence
  • VAT information, where applicable
  • Ordered products or services
  • Order number
  • Order date and time
  • Selected payment method
  • Payment status
  • Technical information, including IP address and browser information

The processing of these data is necessary for the conclusion and performance of the purchase contract,
for payment allocation,
fraud prevention,
accounting obligations
and the delivery of digital products.

The legal basis is
Article 6(1)(b),
Article 6(1)(c)
and,
where applicable,
Article 6(1)(f) GDPR.

11. Ordering Process

This online shop does not provide permanent customer accounts.

Orders are processed solely on the basis of the information required for the individual purchase.

No user profile is created beyond the information required for fulfilling the respective order.

However,
statutory accounting,
tax and documentation obligations require us to retain certain transaction data
for the legally prescribed retention periods.

12. Digital Products

The online shop offers digital products and digital services only.

No physical goods are shipped.

Following successful payment,
customers receive access to the purchased digital products,
for example through:

  • download links
  • electronic tickets
  • booking confirmations
  • digital access credentials
  • other electronic delivery methods

Personal data are processed only to the extent necessary for providing these digital products.

The legal basis is
Article 6(1)(b) GDPR.

Technical access logs and download records may additionally be processed
for fraud prevention,
system security
and legal defence.

The legal basis for such processing is
Article 6(1)(f) GDPR.

13. Transactional Emails

In connection with your order,
we send transaction-related emails that are necessary for the performance of the contract.

These emails may include:

  • Order confirmations
  • Payment confirmations
  • Invoices
  • Delivery information
  • Download instructions
  • Booking confirmations
  • Support information regarding your purchase

These emails are not newsletters
and are not used for marketing purposes.

The legal basis is
Article 6(1)(b)
and
Article 6(1)(c) GDPR.

14. Email Communication

This website does not provide a contact form.

If you contact us by email,
we process the personal data contained in your message,
including your email address
and any additional information you voluntarily provide.

Where your enquiry relates to an existing or intended contractual relationship,
processing is based on
Article 6(1)(b) GDPR.

For all other enquiries,
processing is based on
Article 6(1)(f) GDPR,
our legitimate interest being the efficient handling of communications.

Your correspondence will only be retained for as long as necessary to process your enquiry
or for as long as statutory retention obligations require.


15. Payment Processing

To process payments for purchases made through our online shop, we use the payment
services WooPayments, Stripe and PayPal.

Depending on the payment method selected, personal data required to complete the
transaction are transmitted to the respective payment service provider.

Such data may include, in particular:

  • First and last name
  • Billing address
  • Email address
  • Order number
  • Order value
  • Currency
  • Payment status
  • IP address (where required for fraud prevention)

The processing is necessary for the performance of the purchase contract and is
based on Article 6(1)(b) GDPR.

Payment service providers may also process personal data in their own capacity
to comply with legal obligations, prevent fraud, prevent money laundering and
ensure the security of payment transactions.

16. WooPayments

Our shop uses WooPayments to provide various payment methods.

WooPayments is a payment service integrated into WooCommerce and operated by
Automattic Inc. Payment processing is technically carried out using the
infrastructure of Stripe.

WooPayments processes only the personal data necessary to execute payment
transactions securely and efficiently.

Further information is available in WooCommerce’s and WooPayments’
privacy documentation.

17. Stripe

If you choose to pay by credit card or by another payment method offered through
Stripe, payment processing is carried out by

Stripe Payments Europe, Limited,
Ireland.

Stripe may process personal data for the following purposes:

  • payment processing
  • identity verification
  • fraud prevention
  • risk analysis
  • compliance with statutory obligations
  • prevention of unauthorised payment transactions

Depending on the payment method selected, Stripe may process payment data,
technical device information and transaction-related information.

The legal basis is
Article 6(1)(b) GDPR.

Where Stripe carries out legally required verification procedures or fraud
prevention in its own responsibility, additional legal bases may apply under
Articles 6(1)(c) and 6(1)(f) GDPR.

Further information is available at

 

https://stripe.com/privacy

 

18. PayPal

If PayPal is selected as the payment method, payment processing is carried out by

PayPal (Europe) S.à r.l. et Cie, S.C.A.

22–24 Boulevard Royal,

L-2449 Luxembourg.

PayPal receives only the personal data necessary to process your payment.

PayPal may perform identity verification, fraud prevention and creditworthiness
assessments where permitted by applicable law.

The legal basis for the transfer of personal data is
Article 6(1)(b) GDPR.

Additional information is available in PayPal’s Privacy Statement.

19. Recipients of Personal Data

Personal data are disclosed only where necessary for the purposes described in
this Privacy Policy.

Recipients may include:

  • the Joint Controllers
  • hosting provider (Hetzner)
  • WooCommerce and technically required service providers
  • WooPayments
  • Stripe
  • PayPal
  • IT service providers
  • accountants and tax advisers where required by law
  • public authorities where disclosure is legally required

Where service providers process personal data exclusively on our behalf,
Data Processing Agreements have been concluded in accordance with
Article 28 GDPR whenever legally required.

20. International Data Transfers

Some of the service providers used by this website may process personal data
outside the European Union (EU) or the European Economic Area (EEA).

Where such transfers occur,
they are carried out only in accordance with
Articles 44–49 GDPR.

Appropriate safeguards may include:

  • an adequacy decision adopted by the European Commission;
  • the EU–US Data Privacy Framework, where applicable;
  • Standard Contractual Clauses adopted by the European Commission;
  • additional technical and organisational safeguards where required.

Despite these safeguards,
data protection laws in third countries may differ from those applicable within
the European Union.

21. Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes
described in this Privacy Policy or as required by applicable statutory retention
obligations.

Category of DataRetention Period
Order and invoice dataGenerally up to 10 years in accordance with applicable commercial and tax legislation
Payment informationAs required by applicable legal obligations and the respective payment provider
Server log filesOnly as long as technically and operationally necessary
Consent recordsAs required to demonstrate valid consent and comply with legal obligations
Email correspondenceUntil the enquiry has been fully processed or statutory retention obligations expire

After expiry of the applicable retention periods,
personal data are deleted or anonymised unless further storage is legally required
or necessary for the establishment,
exercise or defence of legal claims.


22. Rights of Data Subjects

Under the General Data Protection Regulation (GDPR), you have the following rights,
provided the respective legal requirements are met:

  • Right of access (Article 15 GDPR)
  • Right to rectification (Article 16 GDPR)
  • Right to erasure (“right to be forgotten”) (Article 17 GDPR)
  • Right to restriction of processing (Article 18 GDPR)
  • Right to data portability (Article 20 GDPR)
  • Right to object (Article 21 GDPR)
  • Right to withdraw consent at any time (Article 7(3) GDPR)

You may exercise these rights at any time by contacting either of the Joint Controllers.
To prevent unauthorised disclosure of personal data, we may request appropriate proof of identity before processing your request.

23. Withdrawal of Consent

Where the processing of your personal data is based on your consent, you may withdraw that consent at any time with future effect.

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

24. Right to Object

Where personal data are processed on the basis of Article 6(1)(f) GDPR (legitimate interests),
you have the right to object at any time on grounds relating to your particular situation.

If you object, we will cease processing the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.

We do not currently process personal data for direct marketing purposes.

Should this change in the future, you will have the right to object to such processing at any time without giving reasons.

25. Right to Lodge a Complaint

If you believe that the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority pursuant to
Article 77 GDPR.

You may contact the supervisory authority in:

  • the Member State of your habitual residence;
  • your place of work;
  • or the place of the alleged infringement.

Since this online shop is operated under joint controllership between organisations established in Germany and Italy, the competent supervisory authority will depend on the specific circumstances of the processing concerned.

26. Security of Processing

The Joint Controllers implement appropriate technical and organisational measures pursuant to
Article 32 GDPR
to ensure a level of security appropriate to the risk.

Such measures include, among others:

  • SSL/TLS encrypted communication
  • restricted administrative access
  • role-based access management
  • regular software updates
  • technical monitoring of systems
  • backup procedures where appropriate
  • protection against unauthorised access

Security measures are regularly reviewed and adapted to technological developments where necessary.

27. Mandatory Provision of Personal Data

The provision of personal data required during the ordering process is necessary for the conclusion and performance of the purchase contract.

Without these data we are unable to:

  • process your order;
  • allocate your payment;
  • issue legally required invoices;
  • provide purchased digital products or services.

The provision of any additional information is voluntary unless expressly indicated otherwise.

28. Automated Decision-Making

The Joint Controllers do not carry out automated decision-making or profiling within the meaning of
Article 22 GDPR.

However, payment service providers may independently perform automated fraud prevention, risk analysis or identity verification where required by law or necessary for secure payment processing.

29. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy whenever necessary to reflect changes in legislation, regulatory requirements, technical developments or the services offered through this website.

The version published on this website shall always be the current and applicable version.

Version:

31 July 2026

© IOB Internationale Organisation für naturnahe Badegewässer e.V.andItalian Association for Natural Bathing Waters