Convenience translation. Only the German version of this privacy policy is legally binding.
Last updated: 3 October 2026
The protection of your personal data is important to us. Below we inform you in accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR) which data we process when you visit this website, use our online shop and in the course of initiating business, for which purposes and on which legal basis this is done, and which rights you have. Our offer is aimed at business customers (with the exception of remaining stock in our on-site warehouse sale).
1. Controller
Rolux Leuchten GmbH
Margarete-Steiff-Straße 18, 28844 Weyhe, Germany
Phone: +49 421 696791-0 · Fax: +49 421 696791-1
E-mail: verkauf@rolux-leuchten.com
Please address any data protection enquiries to these contact details.
2. Legal bases
We only process personal data insofar as this is permitted by law, in particular on the basis of Art. 6 (1) (a) GDPR (consent), (b) (contract and pre-contractual measures), (c) (legal obligation) and (f) (legitimate interests) and, for access to information on your terminal device, on the basis of § 25 TDDDG. We delete data as soon as the purpose of storage no longer applies and no retention obligations prevent deletion.
3. Accessing this website and hosting
When you access the website, technically necessary connection data is processed. This may include IP address, date and time of the request, requested page, browser and operating system data and referrer. The processing serves the provision, security and error analysis of the website (Art. 6 (1) (f) GDPR). Our legitimate interest is secure and trouble-free operation. Hosting and technical service providers may process this data on our behalf on the basis of a data processing agreement (Art. 28 GDPR). Log data is only stored for as long as necessary for operation and security and is then deleted, unless legal obligations or the investigation of specific security incidents require longer retention. The data is not combined with other data and no profiling takes place.
4. Online shop and hosting by Shopify
Our B2B online shop (rolux-leuchten.eu) runs on the e-commerce platform Shopify. The contractual partner for merchants in the European Economic Area is Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland ("Shopify"). Shopify provides the servers, the shop, the checkout and the customer accounts and processes the data involved on our behalf on the basis of a data processing agreement (Art. 28 GDPR; Shopify Data Processing Addendum). This includes in particular connection and device data (e.g. IP address, browser type, time of access), customer account data (company, name, e-mail address, phone number, shipping and billing addresses, VAT ID), cart, order and payment information and your messages to us. Fonts, images and scripts of the shop are delivered via Shopify's content delivery network.
Customer account and orders: Prices and ordering functions are only available in a business customer account activated by us. You sign in with your e-mail address and a verification code sent by e-mail. We process your details to verify your business status, manage your account, process orders, ship goods and issue invoices (Art. 6 (1) (b) and (c) GDPR). If you choose an online payment method at checkout, the data required for this is transmitted to the respective payment service provider. Section 7 applies to the retention of order and invoice data; you can ask us to delete your customer account at any time.
Cookies in the shop: Shopify sets technically necessary cookies and similar storage entries, e.g. for the cart, checkout, sign-in, language selection and security (e.g. protection against fraud and automated access). These are permitted without consent under § 25 (2) no. 2 TDDDG; the associated processing is based on Art. 6 (1) (b) and (f) GDPR. We only use analytics or marketing cookies with your prior consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). An overview of Shopify cookies is available at www.shopify.com/legal/cookies.
Legal basis and third countries: We use Shopify to perform contracts (Art. 6 (1) (b) GDPR) and on the basis of our legitimate interest in a secure, reliable and efficient online shop (Art. 6 (1) (f) GDPR). Shopify may transfer data to affiliated companies, in particular Shopify Inc. in Canada, and to sub-processors, including in the USA. For Canada there is an adequacy decision of the European Commission (Decision 2002/2/EC); otherwise transfers are based on the EU standard contractual clauses (Art. 46 (2) (c) GDPR, Implementing Decision (EU) 2021/914), see also section 11. For certain purposes of its own, such as fraud prevention and security, Shopify may act as an independent controller. More information: Shopify privacy policy and privacy.shopify.com; Shopify privacy contact: privacy@shopify.com.
5. Cookies and similar storage technologies
Technically necessary cookies or similar storage technologies may be used for the website to function (e.g. session and security information). Insofar as they are strictly necessary for a service expressly requested, no consent is required under § 25 (2) TDDDG. Any processing of personal data involved is based on Art. 6 (1) (f) GDPR or, insofar as it serves to process an enquiry, on Art. 6 (1) (b) GDPR. The storage period depends on the respective function; session entries usually end with the browser session. You can block or delete cookies in your browser; the functionality of the website may then be restricted.
We only use services that require consent (e.g. web analytics or marketing) after prior consent and will supplement this policy accordingly.
6. Contacting us and contact form
If you contact us via the contact form, by e-mail or by phone, we process your details and the content of your message in order to handle and answer it. In the contact form this may include: company, name, street and house number, town, e-mail address, phone number, requested product, subject and message. By ticking the box for the privacy policy you confirm that you have taken note of it and that your details may be processed to answer the enquiry. A security check (captcha) is used to protect against automated requests (spam) (Art. 6 (1) (f) GDPR).
The legal basis is Art. 6 (1) (b) GDPR for pre-contractual or contractual enquiries, otherwise Art. 6 (1) (f) GDPR based on our interest in processing enquiries. Mandatory fields are marked; without this information we cannot process your enquiry. The data will be deleted as soon as the enquiry has been finally processed and there are no statutory retention obligations or legitimate reasons for further storage. Data is only passed on insofar as this is necessary for processing or there is a legal obligation.
7. Customer and business data
Within a business relationship we process master and contact data of contact persons as well as order, delivery, invoice and payment data in order to perform the contract (Art. 6 (1) (b) GDPR) and to fulfil legal obligations (Art. 6 (1) (c) GDPR). For this purpose we may use service providers, for example for shipping and logistics, accounting, tax advice, payment processing and IT operations. Retention periods under commercial and tax law (§ 257 HGB, § 147 AO) are currently six years for commercial and business letters and eight years for accounting records; the data is then deleted.
8. Job applications
If you apply to us, we process the application documents and information submitted exclusively for the purpose of carrying out the application procedure (Art. 6 (1) (b) GDPR in conjunction with Art. 88 GDPR and § 26 BDSG). The documents are deleted after completion of the procedure, usually no later than six months after completion, unless you have consented to longer storage or there is a statutory retention obligation.
9. Fonts
For a uniform display we use the fonts "Jost" and "Inter" in the online shop. They are delivered via Shopify's servers (see section 4). No connection to Google servers is established for this purpose.
10. External links
Our website contains links to external offers, for example to Instagram, Facebook and partner sites. No plugins from these providers are integrated. Only when you click on a link do you leave our website; the respective provider is responsible for any subsequent processing.
11. Recipients and transfer to third countries
Recipients of your data are, where necessary, carefully selected and contractually bound processors (Art. 28 GDPR) as well as logistics companies, tax advisors and authorities, insofar as required by law. Data is not passed on for advertising purposes.
Data is only transferred to countries outside the EU/EEA if there is an adequacy decision of the European Commission, appropriate safeguards exist (in particular standard contractual clauses pursuant to Art. 46 GDPR) or you have expressly consented (Art. 49 (1) (a) GDPR). For the USA there is the adequacy decision on the EU-U.S. Data Privacy Framework (Decision (EU) 2023/1795), which applies to certified companies; the General Court of the European Union confirmed it on 3 September 2025. An appeal against this decision is pending.
12. Data security
We take appropriate technical and organisational measures in accordance with Art. 32 GDPR. Transmission between your browser and our website is encrypted via HTTPS (TLS).
13. Your rights
Subject to the GDPR, you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can revoke any consent given at any time with effect for the future (Art. 7 (3) GDPR).
Right to object (Art. 21 GDPR): You can object at any time to the processing of your data based on Art. 6 (1) (f) GDPR on grounds relating to your particular situation. If your data is processed for direct marketing purposes, you can object to this at any time without giving reasons.
An informal notification to the contact details given in section 1 is sufficient to exercise your rights. Exclusively automated decision-making, including profiling (Art. 22 GDPR), does not take place.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hanover, www.lfd.niedersachsen.de.
14. Updates
We adapt this information when the services used or the legal requirements change. The version published here applies.