Privacy policy
PRIVACY POLICY
1) Introduction and Controller Information
1.1 General Information
We are pleased that you are visiting our website. Protecting your personal data is very important to us.
This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data when using our online shop.
Personal data means any information relating to an identified or identifiable natural person.
1.2 Controller
The controller within the meaning of the General Data Protection Regulation (EU) 2016/679 (GDPR) is:
BOOMEX Produktions- u. Handelsges. Chem. Techn. Artikel / FLAMMBURO-Online-Shop GmbH
Jahnstraße 61
36304 Alsfeld
Germany
Email: info@flammburo.de
The controller is the legal entity that determines the purposes and means of processing personal data.
1.3 Data Protection Officer
We have appointed a Data Protection Officer:
Nelly Born
Sophienstraße 1
10178 Berlin
Germany
Email: n.born@pagestreet.de
2) Data Collection When Visiting Our Website
2.1 Server Log Files
When you visit our website for information purposes only, we collect only the data that your browser automatically transmits to our server:
-
Visited pages
-
Date and time of access
-
Amount of data transmitted
-
Referrer URL
-
Browser type and version
-
Operating system
-
IP address (possibly anonymized)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in system stability and security).
3) Hosting
Our online shop is hosted by:
Shopify International Limited
Victoria Buildings
1–2 Haddington Road
Dublin 4
Ireland
Data may also be processed by:
Shopify Inc.
Canada
We have concluded a Data Processing Agreement pursuant to Art. 28 GDPR.
Data transfers to Canada are based on an adequacy decision of the European Commission.
4) Content Delivery Networks (CDN) and Performance Services
For performance and security optimization, we may use:
-
Cloudflare Inc.
-
Bunny.net
-
imgix
Data transfers to third countries (e.g., USA) are based on the EU Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework where applicable.
Legal basis: Art. 6(1)(f) GDPR.
5) Cookies
We use cookies to:
-
ensure technical functionality
-
improve user experience
-
analyze website usage
-
provide marketing and advertising services
Non-essential cookies are only set with your consent.
Legal basis:
-
Art. 6(1)(a) GDPR (consent)
-
Art. 6(1)(f) GDPR (legitimate interest for essential cookies)
You may withdraw your consent at any time via our cookie management tool.
6) Contacting Us
If you contact us (e.g., by email or contact form), the data you provide will be processed solely for the purpose of handling your request.
Legal basis:
-
Art. 6(1)(b) GDPR (pre-contractual measures)
-
Art. 6(1)(f) GDPR (legitimate interest)
7) Customer Account
When creating a customer account, we process the data required for registration and order handling.
Legal basis: Art. 6(1)(b) GDPR.
Data is retained as long as the account exists, subject to statutory retention obligations.
8) Order Processing and Payment
For contract performance (Art. 6(1)(b) GDPR), we process personal data required for order fulfillment and may share it with:
Shipping providers
(e.g., DHL, Hermes)
Payment providers
-
PayPal
-
Stripe
-
Klarna
-
Apple (Apple Pay)
-
Shopify (Shopify Payments)
Payment providers may conduct credit checks based on their own legal bases.
9) Analytics and Marketing Tools
Subject to your consent (Art. 6(1)(a) GDPR), we may use:
-
Google (Google Analytics 4, Google Ads, Tag Manager)
-
Microsoft (Clarity)
-
TikTok (Pixel)
-
Klaviyo
-
Shopify (Analytics)
These services may process data outside the EU. Transfers are safeguarded by appropriate mechanisms such as Standard Contractual Clauses or adequacy decisions.
You may withdraw your consent at any time.
10) Data Retention
We retain personal data:
-
as long as necessary for the respective purpose
-
in accordance with statutory retention periods (commercial and tax law)
-
until consent is withdrawn (where processing is based on consent)
11) Your Rights
Under the GDPR, you have the right to:
-
Access (Art. 15)
-
Rectification (Art. 16)
-
Erasure (Art. 17)
-
Restriction of processing (Art. 18)
-
Data portability (Art. 20)
-
Object (Art. 21)
-
Withdraw consent (Art. 7(3))
-
Lodge a complaint with a supervisory authority
Competent supervisory authority in Germany:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
12) Data Security
We use SSL/TLS encryption to protect transmitted data.
Last updated: March 2026