Privacy policy


Last update: January 26, 2026

This Privacy Policy aims to inform users of the website casco-helmets.com (hereinafter the “Website”) about how the PUBLISHER processes personal data as the data controller within the meaning of the General Data Protection Regulation (GDPR).

The data collected in connection with the use of the Website and in relation to orders placed by users and customers are processed by the PUBLISHER, acting as data controller, in accordance with the conditions described below.

The contact details of the PUBLISHER are provided in the legal notice.

The PUBLISHER has appointed a Data Protection Officer (DPO), who can be contacted as follows:

  • by email: mail@edelmann-co.de
  • by post: Edelmann & Co. Management Consultancy, Thorsten Edelmann, +49 176 56 82 16 91


DESCRIPTION OF DATA PROCESSING ACTIVITIES IN CONNECTION WITH THE USE OF THE WEBSITE AND ORDERS

In the course of operating the Website and conducting its business activities, the PUBLISHER may collect and process personal data as the data controller in accordance with the provisions below.


Creation of a User Account

Data collected:
First name, last name, email address, password (not stored in plain text), login history, preferences, account creation date.
Data related to orders and order history.

Purposes:
Management of registration and the customer account.

Legal basis:
Legitimate interest of the PUBLISHER in enabling account creation and allowing users access to their information.

Data retention period:

  • Active database: Data are stored for the duration of account use and until the account is deleted by the user or after 2 years of inactivity. The PUBLISHER informs the user of the upcoming deletion if no response is received within 90 days.
  • Archive: After account deletion, data may be archived for 5 years based on the legitimate interest of asserting, exercising, or defending legal claims (statutory limitation period).

By way of exception, connection logs are stored only for the duration of active account use.

Mandatory and optional fields are indicated at the time of data collection. Without the required information, an account cannot be created.


Product Orders

Data collected:
Account data as well as first name, last name, billing and, where applicable, delivery address, payment method, order details, delivery method, and order-related correspondence.

Purposes:

  • Processing of orders (delivery, invoicing, warranties, customer service);
  • Management of returns and product recalls;
  • Creation of anonymized sales statistics.

Legal bases:

  • Performance of a contract (Terms and Conditions), legal obligations (accounting, invoicing);
  • Legitimate interest for statistical analyses.

Data retention period:

  • Active database: see account retention;
  • Archive: see account retention.

Invoices are stored for 10 years (legal obligation). Contracts exceeding €120 are also archived for 10 years.

Without the required information, an order cannot be placed.


Contact Form

Data collected:
Inquiry category, subject, first and last name, email address, telephone number, country, city, and optionally depending on the inquiry: serial number, fault description, attachment, comment.

Purposes:
Responding to inquiries and building a contact database.

Legal basis:
Legitimate interest of the PUBLISHER in the context of commercial contact.

Data retention period:
3 years from the last contact or until objection.

Without the required information, the contact form cannot be used.


Newsletter Distribution

Data collected:
Email address, newsletters sent, open and click data, and where applicable, first name, last name, and purchase history.

Purposes:
Sending information and promotional offers from the PUBLISHER.

Legal basis:

  • Legitimate interest for existing customers;
  • Consent for non-customers.

Data retention period:
3 years from the last contact or until consent is withdrawn.


Customer Reviews

Data collected:
First name or pseudonym, email address, rating (stars), free-text comment, submission date, reviewed product.

Purposes:
Public display of reviews, moderation, quality improvement, internal statistics.

Legal basis:
Legitimate interest in transparency and user information.

Data retention period:
3 years after publication for moderation purposes; reviews remain published in anonymized form as long as they are relevant.


User-Generated Content (UGC)

Data collected:
Social media account ID (name/pseudonym), content (photo, video, text), metadata, hashtag #CascoHelmets.

Purposes:
Display on the Website, social networks, newsletters, and marketing materials.

Legal basis:

  • Explicit consent, or
  • Legitimate interest for public content using the hashtag.

Data retention period:

  • Content: up to 5 years
  • Metadata: maximum 3 years


Cookies and Trackers

Personal data may be collected via cookies, as described in the cookie management tool.

Technical Data

  • IP address, browser, language, operating system, timestamp
  • Purpose: Security, troubleshooting, display optimization
  • Legal basis: Legitimate interest
  • Retention period: 12 months

Session Cookies

  • Session ID
  • Purpose: Session management
  • Duration: Session

Performance, Functional, Preference, Analytics, and Advertising Cookies

  • Legal basis: Consent
  • Retention period: Maximum 13 months

For third-party cookies, the PUBLISHER and its partners act as joint controllers.


RECIPIENTS OF PERSONAL DATA

Data controller: the PUBLISHER (see legal notice).

Recipients:

  • Employees of the PUBLISHER;
  • Technical service providers, payment and shipping providers, and consultants, where necessary.


RIGHTS OF DATA SUBJECTS

Data subjects have the following rights at any time:

  • Right of access
  • Right to rectification
  • Right to erasure (Article 17 GDPR)
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority
  • Right to define instructions regarding data after death


EXERCISE OF RIGHTS

These rights may be exercised: