Privacy policy

Privacy & Cookie Policy

Part I — Privacy Policy

1. Data Controller

This Privacy Policy explains how we collect, use, and safeguard your personal data when you visit zellaforte.de and use our services, in accordance with the EU General Data Protection Regulation (GDPR) and applicable national data-protection law.

The controller responsible for processing your personal data in connection with the online store is:

OmniMed Global B.V.
Krom Boomssloot 5
1011 GP Amsterdam
Netherlands
KvK: 98643908 | VAT: NL868582025B01
Email: support@zellaforte.de

Anstalt für Zellforschung (Vaduz, Liechtenstein) is the brand owner and manufacturer of the products; it is not the controller of your online-store customer data. Where it processes personal data separately (e.g., for product safety or quality), it does so as an independent controller under its own responsibility.

If you have questions about this Policy or wish to exercise your rights, contact us at support@zellaforte.de. Please allow up to 30 days for a response.

2. Types of Personal Data We Collect

2.1 Information You Provide Directly

  • Account and order information: name, email address, postal address, phone number, payment details (processed securely by third-party payment processors), order history, and product preferences.
  • Communication data: information you provide when contacting us via email, contact forms, or support channels, including the content of your messages.
  • Optional information: any additional details you choose to provide.

2.2 Information Collected Automatically

  • Device information: IP address, browser type, operating system, and device identifiers.
  • Usage data: pages visited, time on page, clicks, scroll depth, referral source, and search queries.
  • Cookie and tracking data: data collected via cookies and similar technologies (see Part II).
  • Approximate location: country/city level, based on IP address.

3. Purposes and Legal Bases (GDPR Article 6)

3.1 Performance of Contract (Art. 6(1)(b))

  • Processing and fulfilling your orders.
  • Providing customer service and support.
  • Managing your account and any subscriptions.
  • Sending order confirmations, shipping updates, and invoices.
  • Processing refunds and returns.

3.2 Consent (Art. 6(1)(a))

  • Marketing emails (where you have opted in).
  • Retargeting and personalized advertising on third-party platforms.
  • Analytics and session recording.
  • Non-essential cookies (see Part II).

You may withdraw consent at any time via the unsubscribe link in marketing emails or by adjusting your cookie preferences.

3.3 Legal Obligation (Art. 6(1)(c))

  • Retaining invoices and transaction records to meet tax and accounting obligations.

3.4 Legitimate Interest (Art. 6(1)(f))

  • Preventing fraud, abuse, and security threats.
  • Improving our website, products, and services.
  • Enforcing our terms and legal rights.
  • Business administration and internal operations.

4. Recipients and Third Parties

4.1 Order Fulfillment and Logistics

As the controller and shop operator, OmniMed Global B.V. processes your order and engages logistics/shipping providers to deliver it. We share your name, address, phone number, and order details with the carrier only as needed for delivery.

4.2 Payment Processing

We share the payment data required to process your payment with PCI-DSS-compliant payment processors:

  • Shopify Payments (powered by Stripe) — card and digital-wallet payments
  • PayPal — PayPal and digital-wallet payments
  • Klarna — buy-now-pay-later / installments

Each processor operates under its own privacy policy. We do not store full card details; payment data is transmitted directly to the respective processor.

4.3 Analytics

  • Google Analytics 4 — website usage, engagement, and conversion metrics.
  • Microsoft Clarity — session recordings, heatmaps, and behavior analytics.

4.4 Advertising and Retargeting

  • Meta Pixel (Facebook/Instagram) — conversion tracking, audiences, retargeting.
  • Taboola — native advertising and conversion tracking.
  • Outbrain — native advertising and conversion tracking.

4.5 Platform Services

Our store is hosted on Shopify, which processes data for order fulfillment, analytics, and fraud detection as our processor, under Standard Contractual Clauses where applicable.

4.6 Legal and Compliance

We may disclose personal data where required by law or to protect the rights, safety, or property of OmniMed Global B.V., our customers, or the public.

4.7 Business Transfers

If our business is acquired or merged, your data may be transferred as part of that transaction; we will provide notice if it becomes subject to a different privacy policy.

5. International Data Transfers

OmniMed Global B.V. is based in the Netherlands (EU/EEA). Some service providers are located outside the EEA. Where we transfer data to a country without an adequacy decision, we rely on appropriate safeguards, in particular Standard Contractual Clauses (e.g., with Google, Meta, Microsoft, Shopify) and, where applicable, adequacy decisions. You may request a copy of the safeguards at support@zellaforte.de.

6. Data Retention

  • Order and transaction data: retained for the statutory period (generally 7 years) for tax and accounting.
  • Account information: for the duration of your account and up to 3 years after deletion or last purchase, unless the law requires longer.
  • Marketing data: until you unsubscribe or withdraw consent.
  • Analytics/behavioral data: per the analytics partners' retention (typically 14–26 months) unless you request deletion.
  • Payment data: not stored by us; retained by processors per their policies and PCI-DSS.
  • Support communications: up to 3 years for reference and dispute resolution.

After the applicable period we delete or anonymize your data. We may retain aggregated, anonymized data indefinitely.

7. Your Rights

Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21, including to direct marketing), and withdrawal of consent (Art. 7). To exercise any right, email support@zellaforte.de with enough detail to identify you and specify the right. We respond within 30 days and may ask for information to verify your identity.

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Postbus 93374, 2509 AJ Den Haag, Netherlands
Website: autoriteitpersoonsgegevens.nl

You may also lodge a complaint with the data-protection authority of the EU/EEA country where you live or work. For example, in Germany you may contact the data-protection authority of your federal state (Landesdatenschutzbehörde).

9. Security

We implement technical and organizational measures to protect your data, including SSL/TLS encryption in transit, PCI-DSS-compliant payment processing, access controls, data minimization, and incident-response procedures. No method of transmission or storage is completely secure, but we maintain reasonable safeguards.

10. Changes to This Policy

We may update this Policy to reflect changes in our practices or the law. Material changes will be communicated by email (where we have your address) or by prominent notice on our website.

11. Contact

OmniMed Global B.V.
Krom Boomssloot 5, 1011 GP Amsterdam, Netherlands
Email: support@zellaforte.de


Part II — Cookie Policy

What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help the site work, remember your preferences, and provide insight into how the site is used. Cookies may be set by us (first-party) or by third parties whose services we use (third-party).

Types of Cookies We Use

1. Strictly Necessary Cookies

Essential for the website and checkout to function; set without consent on the basis of legitimate interest (Art. 6(1)(f)).

Cookie / Provider Purpose Duration Type
Shopify session cookie Session management and authentication Session First-party
Shopify cart cookie Shopping-cart retention 30 days First-party
Shopify CSRF token Security and fraud prevention Session First-party

2. Analytics Cookies

Used to understand how visitors interact with the site. Require your consent.

Provider Purpose Duration Type
Google Analytics 4 Performance metrics, engagement, audience insights 2 years Third-party
Microsoft Clarity Session recordings, heatmaps, behavior analysis 1 year Third-party

3. Marketing & Advertising Cookies

Used for conversion tracking and retargeting. Require your consent.

Provider Purpose Duration Type
Meta Pixel (Facebook) Conversion tracking, audiences, retargeting Up to 90 days Third-party
Taboola Pixel Native-ad conversion tracking 90 days Third-party
Outbrain Pixel Native-ad conversion tracking 90 days Third-party

Legal Basis for Cookies

Strictly necessary cookies are set on the basis of legitimate interest (Art. 6(1)(f)). All other cookies (analytics, marketing, advertising) require your prior consent (Art. 6(1)(a)), obtained via our cookie banner before they are set.

Managing & Withdrawing Consent

You can manage or withdraw consent at any time via the "Cookie Settings" control on our website, or by deleting cookies in your browser settings. Withdrawing consent stops non-essential cookies on future visits but does not delete cookies already set.

Third-Party Cookie Policies

Questions?

Contact us at support@zellaforte.de.


Related: Terms & Conditions · Impressum

Last updated: 8 July 2026