Privacy Policy
Version dated 3 August 2026
1. Controller
Happy Diskus – e.Kfr., Proprietor: Claudia Seidel, Ernst-Geßner-Straße 8, 08294 Lößnitz, Germany. Telephone: +49 (0) 3771 2543-0. Email: datenschutz@happy-diskus.de.
No data protection officer has been appointed. Privacy enquiries may be sent directly to the contact details above.
2. General information on legal bases and retention
We process personal data only where a legal basis exists. Depending on the processing activity, we rely in particular on Article 6(1)(a) GDPR for consent, Article 6(1)(b) GDPR for pre-contractual steps or performance of a contract, Article 6(1)(c) GDPR for compliance with legal obligations and Article 6(1)(f) GDPR for legitimate interests.
The storage of information on your terminal device or access to information already stored there is additionally governed by section 25 of the German Telecommunications and Digital Services Data Protection Act (TDDDG). Strictly necessary technologies are used under section 25(2)(2) TDDDG. Non-essential technologies are used only after consent.
Personal data is deleted or its processing restricted once the relevant purpose no longer applies and no statutory retention, evidentiary or limitation periods require further storage. Deleted operational data may remain in backups for up to 30 days; backups are not restored for ordinary use and are overwritten afterwards.
3. Access data, server operation and hosting
When our website is accessed, the web server automatically processes technical access data. This may include your IP address, date and time of access, requested file or page, amount of data transferred, referrer URL, browser, operating system and requesting provider.
Processing serves the secure and reliable provision of the shop, error analysis, prevention of misuse and technical administration. The legal basis is Article 6(1)(f) GDPR. Server log files are generally retained for 30 days and then deleted unless longer retention is required to investigate a specific security incident.
The shop is operated on our own root server hosted by Hetzner Online GmbH in a German data centre. Backups are also stored within Hetzner infrastructure and retained for no longer than 30 days.
Email services are currently operated on our own root server hosted by IONOS and are being migrated to a second root server hosted by Hetzner. In each case, the systems are administered by us.
HIS GmbH is engaged as a technical processor for shop administration under an Article 28 GDPR processing agreement. Administrative access is logged; administration logs are generally retained for twelve months.
4. Orders and contract processing
When you place an order, we process the master, contact, delivery, order and payment data you provide in order to accept, fulfil, invoice and ship the order and to handle claims relating to cancellation, defects, guarantees or performance issues. Mandatory fields are marked during checkout. The legal basis is Article 6(1)(b) GDPR.
Order and customer data generally remains in the active shop system for five years. Full order records are then transferred to an archive accessible only to the shop administrator, are no longer used for routine analysis and are permanently deleted after a total of ten years. Where mandatory commercial or tax law requires a different period, the applicable statutory period prevails.
Order-related emails, including order confirmations, dispatch messages and correspondence concerning cancellations, complaints and defects, are generally retained for five years unless a specific matter requires longer retention.
Our 42 ERP system is operated on our own server at our premises. SoftproTEK receives support access only in individual cases after express approval. An Article 28 GDPR processing agreement is in place.
5. Customer account, guest checkout and account functions
You may order as a guest or voluntarily create a customer account. For a customer account, we process the data you provide to make the account available, administer orders and invoices and provide the account functions described below. The legal basis is Article 6(1)(b) GDPR.
Orders and invoices can be accessed in the customer account. Guest customers receive a paper invoice with the shipment; upon request, an invoice may also be sent manually by email.
Saved shopping carts are deleted after 30 days. Wish lists remain stored until the customer account is deleted. Customer accounts are to be deleted after five years of inactivity, provided that no open contractual relationship, complaint, statutory retention duty or other legal basis requires continued storage. Deletion must be requested through our privacy contact address or contact form.
Deleting a customer account also deletes wish lists and bonus points stored in that account. Order and invoice data subject to retention requirements remains unaffected and is blocked or archived for further use.
The login session ends when the browser is closed. To facilitate a later login, an internal identifier may be used to display the most recently used email address in the login field for up to two years. The browser may also store the address independently through its autocomplete function.
Passwords are stored only as Argon2id hashes and are never visible to us in plain text. The “Forgot password” function sends a single-use reset link.
6. Bonus programme
Every customer account participates in the bonus programme by default. One bonus point is credited for each EUR 20.00 of qualifying purchase value after expiry of the 14-day cancellation period; one point is worth EUR 0.50. Points may be collected or redeemed on later orders and currently do not expire.
Processing is limited to calculating and administering the bonus balance as a customer-account function under Article 6(1)(b) GDPR. No profiling based on individual products, product groups or interests takes place. Participation may be objected to at any time by contacting us. Bonus points are permanently deleted when the customer account is deleted.
7. Contact and contact form
When you contact us by email, telephone or contact form, we process the information you provide in order to deal with your enquiry. First name, last name, email address and message are mandatory fields in the contact form. The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a contract or pre-contractual steps, and otherwise Article 6(1)(f) GDPR.
Contact enquiries that do not lead to an order, complaint or other contractual relationship are retained for no longer than two years and then deleted unless statutory or legitimate evidentiary interests require longer retention.
We protect the contact form with the self-hosted Securimage image CAPTCHA and server-side rate limiting. No data is transferred to an external CAPTCHA provider. The legal basis is Article 6(1)(f) GDPR.
8. Online cancellation form
Through the online cancellation form, we process first name, last name, email address, order number and whether the cancellation is complete or partial. Processing serves to receive, allocate, confirm and handle the cancellation. The legal bases are Article 6(1)(b) and (c) GDPR.
An automatic confirmation of receipt is sent by email after submission. The data is received by email and processed in the ERP system or existing order workflow. No separate ticketing system is used.
9. Shipping and drop-shipping
To fulfil the contract, we transfer the data required for delivery to DHL, Emons or Kuehne+Nagel. The legal basis is Article 6(1)(b) GDPR.
DHL receives the email address for shipment notification only where no objection recorded by DHL is present. For freight deliveries, Emons and Kuehne+Nagel receive the email address and telephone number where required to announce and coordinate delivery.
Where a manufacturer or wholesaler ships goods directly to you, we transfer only the data required for that specific shipment. Email address and telephone number are disclosed only where needed for delivery, particularly for freight shipments.
10. Payment processing
Depending on the payment method selected, we process payment and transaction data ourselves or transfer the required data to the selected payment provider. A payment provider is technically connected only after you actively select the relevant payment method.
Payment in advance, invoice, direct debit and cash on delivery are processed by us.
PayPal payments are processed through PayPal.
Klarna receives contact, order and payment data and independently decides which Klarna payment methods are offered to a particular customer. We have no influence over that decision.
Credit-card and Wero payments are processed through Nexi/Computop. Nexi/Computop may perform its own security, risk and fraud-prevention checks.
The legal basis is Article 6(1)(b) GDPR. Where payment providers carry out their own checks or decisions, they act as separate controllers. Their own privacy notices also apply.
Depending on the payment provider, data may be processed outside the EU or EEA. In that case, transfers are based on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses.
11. Accounting, tax advice and enforcement of claims
To comply with commercial and tax obligations, we process invoice, accounting and business data in our own accounting system and transfer the required data to our tax adviser. The tax adviser uses DATEV systems under its own responsibility. The legal basis is Article 6(1)(c) GDPR.
Where due claims remain unpaid, the contractual, invoice and contact data required to enforce the claim may be transferred to an instructed lawyer. The legal basis is Article 6(1)(f) GDPR. We do not use a debt collection agency.
12. Complaints, defects and manufacturer contacts
To handle complaints, statutory defect claims or guarantees, we process the necessary order, communication and technical data, for example serial numbers, proof of purchase or device data.
Personal customer data is transferred to manufacturers or suppliers only after the customer's express approval. With approval, email address and telephone number may also be disclosed so that communication can take place directly between the customer and the manufacturer or supplier. No personal data is transferred to manufacturers outside the EU or EEA for this purpose.
13. Gift vouchers
When purchasing a gift voucher, the buyer may provide the beneficiary's name and email address and a personal message. Once paid, the voucher is sent directly to the specified email address.
Processing is necessary to perform the voucher contract with the buyer and is based on Article 6(1)(b) GDPR. The buyer may provide the beneficiary's personal data only where authorised to do so. The personal message is not analysed for any other purpose.
The beneficiary's name and email address, the message, voucher code, value, redemption status and remaining balance are generally retained for five years and then deleted unless statutory retention or evidentiary obligations require otherwise.
14. Product reviews
Product reviews may be submitted only by customers who actually purchased the reviewed product. Reviews are checked manually before publication. Only initials, for example “A.K.”, are shown publicly.
The email address and the internal confirmation that the product was purchased are retained for allocation, abuse prevention and possible follow-up. Order number, purchase date, IP address and browser data are not permanently linked to the review. Reviews are displayed only in our own shop and are not transferred to third parties.
Published reviews may remain visible while the product and review are carried in the shop. Internal review data is to be deleted or anonymised after five years unless an abuse case, legal dispute or other evidentiary interest requires longer retention. Requests for amendment or deletion may be sent to our privacy contact address.
15. Newsletter and email marketing
If you actively subscribe to our newsletter, we process your email address on the basis of your consent under Article 6(1)(a) GDPR. The checkbox in checkout is not preselected. Guest customers may also subscribe. Newsletters are sent only through our own mail server. Openings and link clicks are not tracked.
Subscription is generally confirmed using a double opt-in procedure. In future, the subscription and confirmation time, source of subscription, version of the consent wording and unsubscribe time are to be logged in addition. After unsubscribing, the address is removed from the active mailing list and placed on a suppression list.
Where the requirements of section 7(3) of the German Unfair Competition Act are met, we may use an email address obtained in connection with a sale to advertise our own similar goods. The customer is informed of this when the address is collected and may object at any time without costs other than the basic transmission charge.
Automatic review reminders will in future be sent only where separate, voluntary and non-preselected consent has been given. Such consent may be withdrawn at any time.
16. Cookies and local storage technologies
We use cookies and comparable technologies. Strictly necessary technologies enable the shopping cart, login, session control, consent selection and secure operation of the shop. They are used under section 25(2)(2) TDDDG and, where personal data is processed, Article 6(1)(b) or (f) GDPR.
Our own consent solution allows you to choose between “necessary cookies only” and “accept all”. The selection is stored for 365 days and may be changed or withdrawn at any time through the cookie settings.
The most recently selected language and shop view are each stored for 365 days solely to restore the display selected by the user.
Google Consent Mode is initialised when the first page is accessed. The consent states ad_user_data, ad_personalization, ad_storage and analytics_storage are initially passed to Google's consent controls as “denied”. A technical connection to Google may therefore already exist before you make a selection. Analytics and advertising storage, the use of advertising user data and personalised advertising are not granted in this state. If you select “accept all”, the relevant states are changed to “granted”. You may change or withdraw your selection at any time through the cookie settings.
17. Google Analytics 4
After your consent, we use Google Analytics 4, an analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics processes general usage data such as page views, sessions, device and browser information and technical interactions. Under our configuration, order value, order number, internal search terms, name, email address and delivery address are not sent to Google Analytics.
We do not use the User-ID function, Google Signals or cross-device analysis. Additional data sharing for Google products and services is not enabled. Our consent controls pass only the consent states described above to Google.
Processing takes place only on the basis of your consent under section 25(1) TDDDG and Article 6(1)(a) GDPR. You may withdraw consent at any time through the cookie settings.
Retention is currently configured for two months for event data and 14 months for user data. Google may also process data on servers in the United States. Where Google is certified under the EU-U.S. Data Privacy Framework, the transfer is based on the European Commission's adequacy decision; Standard Contractual Clauses may be used in addition.
18. Google Ads Conversion Tracking
After your consent, we use Google Ads Conversion Tracking provided by Google Ireland Limited to measure whether a click on a Google advertisement resulted in an order.
Under our configuration, only order value and currency are transmitted for a conversion. Order number, name, email address, address and other direct identifiers are not transmitted. We do not use Enhanced Conversions, Customer Match or remarketing lists.
The legal basis is your consent under section 25(1) TDDDG and Article 6(1)(a) GDPR. Consent may be withdrawn at any time through the cookie settings.
19. YouTube videos
YouTube videos are embedded on certain product pages. At present, the YouTube player is technically loaded when the relevant page is opened; playback begins only after you actively start the video. A connection to YouTube or Google may therefore be established and technical data such as IP address, browser and device information may be transmitted before playback.
The provider is Google Ireland Limited; further processing may be carried out by Google LLC in the United States. The integration will be changed to a consent solution using a fully local neutral placeholder and loading the player only after consent. Until that change is implemented, information in this Privacy Policy does not replace any consent that may be legally required.
20. Trusted Shops money-back guarantee
A Trusted Shops badge or review widget is not generally loaded when the shop is visited. The relevant Trusted Shops function is integrated only after you actively click “money-back guarantee” following completion of an order.
In that case, order value, order number and email address may be processed and transferred to Trusted Shops SE, Subbelrather Straße 15C, 50823 Cologne, Germany, in order to check eligibility or registration for buyer protection and offer the guarantee. Further processing is governed by the contractual and privacy information of Trusted Shops.
21. External links to social networks
Our website contains only ordinary links to our Facebook and Instagram profiles. No Meta plugins, feeds or pixels are loaded merely by visiting our shop pages. When you click such a link, you leave our shop; the relevant platform operator is responsible for subsequent processing.
22. Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR. Customer accounts are blocked only in individual cases after manual review. Payment providers may perform automated risk or fraud checks under their own responsibility.
23. Your rights
Subject to the statutory requirements, you have in particular the following rights:
access under Article 15 GDPR
rectification under Article 16 GDPR
erasure under Article 17 GDPR
restriction of processing under Article 18 GDPR
data portability under Article 20 GDPR
objection under Article 21 GDPR
withdrawal of consent with effect for the future under Article 7(3) GDPR
the right to lodge a complaint with a supervisory authority under Article 77 GDPR
Where we process data on the basis of legitimate interests, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without giving specific reasons.
To exercise your rights, please contact datenschutz@happy-diskus.de.
24. Competent supervisory authority
Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden, Germany. Telephone: +49 351 85471-101. Email: post@sdtb.sachsen.de. Website: https://www.datenschutz.sachsen.de




