Skip to main content Skip to search Skip to main navigation

Privacy Policy

Status: March 2025


1. Controller and Contact Details

NatureWatt GmbH
Bergham 55
83624 Otterfing
Phone: +49 8027 9085 670
E-mail: office@naturewatt.de

Managing Directors: Andreas Beckmeier, Christoph Leitgeb
Registered office: Otterfing
Local Court of Munich | HRB 294612
Tax No.: 139/133/10025
VAT ID No.: DE369559209

NatureWatt GmbH acts as the controller under the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revFADP).


2. Collection and Processing of Personal Data

We process personal data of our users only insofar as this is necessary to provide a functional website and our services. Personal data are any information relating to an identified or identifiable natural person. Under Swiss law, the term “personal data” (Personendaten) is commonly used.

a) When visiting our website

When you access our website, the following data are collected automatically, which do not allow direct identification of a person:

  • IP address (if applicable, pseudonymised)

  • Date and time of access

  • Browser type and version

  • Operating system

  • Referring website (referrer URL)

  • Access status (e.g. error code)

These data are used exclusively to ensure the trouble-free operation of the website, for statistical purposes and to improve our offering.
Retention period: Server log files are stored for seven days and then routinely deleted.

b) When using our online shop and contact form

If you order goods in our online shop or contact us via our contact form, we collect and process the following data:

  • Name, address, e-mail address, telephone number

  • Payment details (e.g. credit card data, bank account details – insofar as necessary)

  • Order data (items, quantity, price, delivery address)

  • Other information required for the performance of the contract


3. Purpose of Processing and Legal Bases

Your personal data are processed for the following purposes:

  • Performance of contract and customer management:
    To process orders, deliver goods, handle payments and provide customer service.
    Legal basis: EU GDPR Art. 6(1)(b) (performance of a contract); Switzerland: Art. 13(2)(a) revFADP.

  • Provision and optimisation of the website:
    To ensure trouble-free operation, perform web analytics, diagnose errors and improve our offering.
    Legal basis: EU GDPR Art. 6(1)(f) (legitimate interests); Switzerland: Art. 13(2)(c) revFADP.

  • Communication and marketing:
    To respond to your enquiries, inform you about changes, offers and newsletters (provided you have consented).
    Legal basis: EU GDPR Art. 6(1)(a) (consent) and/or Art. 6(1)(f) (legitimate interests); Switzerland: Art. 13(2)(c) revFADP.


4. Disclosure of Data to Third Parties

Your personal data are disclosed only where necessary for the performance of the contract – e.g. to shipping providers, payment service providers or IT service providers – or where you have expressly consented. No further transfer to third parties takes place.

Data transfers to third countries: If data are transferred to third countries (outside the EU/EEA or Switzerland), we ensure an adequate level of data protection through appropriate safeguards (e.g. standard contractual clauses).


5. Cookies and Tracking

Our website uses cookies to facilitate use of the site and provide certain functions. These are small text files stored on your device.

a) Necessary cookies

These cookies are technically required to provide the website and functions such as the shopping cart in the online shop.
Storage period: These cookies are usually deleted at the end of your browser session.

b) Functional and statistical cookies

These cookies enable us to analyse use of the website and optimise our offering.
Legal basis: Processing is carried out on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR (EU) and Art. 13(2)(c) revFADP (Switzerland).
Storage period: 30 days or individual, depending on the cookie provider.

You can prevent the storage of cookies via your browser settings. Please note that this may lead to functional restrictions of the website.


6. Web Analytics and Tracking Tools

If we use web analytics tools (e.g. Google Analytics or comparable services), this is done in compliance with legal requirements. Detailed information on data processing by the respective provider and instructions on opt-out options can be found in the provider’s separate privacy notices.
Note: If you use Google Analytics, ensure that IP anonymisation is activated and, where applicable, include a link to the browser opt-out.


7. Social Media Plugins

Our website may contain plugins from social networks. These allow you to share content in your social networks. Personal data may be transmitted to the respective providers in this context. For further information, please refer to the privacy notices of the respective social networks.


8. Storage Periods and Deletion of Data

We store personal data only for as long as necessary to achieve the respective processing purposes or where statutory retention periods apply.

Log files and technical data: Stored for seven days and then deleted.

Order data: Stored in accordance with statutory retention periods (generally up to 8 years), unless a shorter period is permissible.

Customer account data: Remain stored until you terminate your customer account.

Once the processing purpose ceases to apply and/or statutory periods expire, the data are routinely deleted unless statutory retention obligations prevent this.


9. Rights of Data Subjects

You have the right to:

  • Obtain information about the personal data stored by us.

  • Request the rectification of inaccurate data.

  • Request the deletion of your personal data, insofar as no statutory retention periods apply.

  • Request restriction of processing.

  • Request data portability.

  • Object to the processing of your personal data where reasons arise from your particular situation.

  • Lodge a complaint with a supervisory authority.

To exercise your rights, please contact us using the contact details provided above.

The competent supervisory authorities are:

For Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Phone +41 (0)58 462 43 95, E-mail info@admin.ch

For Liechtenstein: Data Protection Office of the Principality of Liechtenstein, Städtle 38, P.O. Box 684, FL-9490 Vaduz, Phone +423 236 60 90, E-mail info.dss@llv.li


10. Data Security

We implement technical and organisational security measures to protect the personal data we process from unauthorised access, loss, destruction or manipulation. Our measures are continuously adapted to the state of the art.

Examples of our security measures include:

  • Use of SSL encryption (Secure Socket Layer) for data transmission,

  • Regular review and updating of our IT security protocols,

  • Access restrictions to sensitive data.


11. Updates to this Privacy Policy

NatureWatt GmbH reserves the right to amend this Privacy Policy at any time to reflect current legal requirements or changes to our services. The current version is available on our website. In the event of material changes, we will inform you appropriately about the updates.


12. Contact for Data Protection

If you have any questions about data protection or wish to exercise your rights, you can contact our Data Protection Officer at any time:

Data Protection Officer of NatureWatt GmbH
Christoph Leitgeb
office@naturewatt.de
+49 8027 9085 670


13. Hosting and Server Locations

Our hosting is provided by Amazon Web Services EMEA SARL, whose server locations are in Germany/EU. Where data are processed outside the EU/EEA or Switzerland, this is carried out using the European Commission’s Standard Contractual Clauses.


14. Further Details on Third-Party Providers and Specific Processing

If we use specific third-party providers (e.g. payment service providers, shipping providers, web analytics providers) with separate privacy notices, we refer to their own privacy policies.

In case of discrepancies or inconsistencies, the German version shall prevail.

Privacy Policy


Language and Validity:
This privacy policy is provided in German (original version) as well as in English and French translations. The German version is definitive and legally binding; in the event of any contradiction or uncertainty, only the German text shall prevail.

Effective: March 2025


1. Controller and Contact Details

NatureWatt GmbH
Bergham 55
83624 Otterfing, Germany
Phone: +49 8027 9085 670
E-mail: office@naturewatt.de
Managing Directors: Andreas Beckmeier, Christoph Leitgeb
Registered Office: Otterfing
Local Court Munich | HRB 294612
Tax Number: 139/133/10025
VAT ID No.: DE369559209

NatureWatt GmbH is the data controller within the meaning of the EU General Data Protection Regulation (GDPR).


2. Collection and Processing of Personal Data

We process personal data of our users only to the extent necessary to provide a functional website and our services. Personal data are all information relating to an identified or identifiable natural person.

a) When Visiting Our Website

When accessing our website, the following data are automatically collected, which do not allow direct identification of individuals:

  • IP address (possibly pseudonymised)
  • Date and time of access
  • Browser type and version
  • Operating system
  • Referring website (Referrer URL)
  • Access status (e.g. error code)

These data are used exclusively to ensure uninterrupted operation of the website, for statistical purposes and to improve our offering.
Retention Period: Server log files are stored for seven days and then routinely deleted.

b) When Using Our Online Shop and Contact Form

If you place orders in our online shop or contact us via our contact form, we collect and process the following data:

  • Name, address, e-mail address, telephone number
  • Payment data (e.g. credit card information, bank details – where required)
  • Order details (items, quantity, price, delivery address)
  • Other information necessary for performing the contract

3. Purpose of Data Processing and Legal Basis

The processing of your personal data takes place for the following purposes:

  • Contract performance and customer management:
    To process orders, deliver goods, handle payments and provide customer service.
    Legal basis: Art. 6(1)(b) GDPR
  • Provision and optimisation of the website:
    To ensure uninterrupted operation, perform web analytics, diagnose errors and improve our offering.
    Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
  • Communication and marketing:
    To respond to your enquiries, inform you about changes, offers and newsletters (if you have consented).
    Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(f) GDPR (legitimate interest)

4. Disclosure of Data to Third Parties

Your personal data are shared only if necessary for contract performance—for example with shipping service providers, payment service providers or IT service providers—or if you have given your express consent. Apart from this, data are not passed on to third parties.

Data transfer to third countries:
If data are transferred to third countries (outside the EU/EEA), we ensure that an adequate level of data protection is guaranteed by appropriate safeguards (e.g. Standard Contractual Clauses of the European Commission).


5. Cookies and Tracking

Our website uses cookies to facilitate usage and provide certain functions. These are small text files stored on your device.

a) Necessary Cookies

These cookies are technically required to provide the website and functions such as the shopping cart in the online shop.
Retention Period: These cookies are typically deleted at the end of your browser session.

b) Functional and Statistical Cookies

These cookies enable us to analyse website usage and optimise our offering.
Legal basis: Processing is based on our legitimate interest under Art. 6(1)(f) GDPR.
Retention Period: 30 days or individually, depending on the cookie provider.

You can prevent cookies from being stored by adjusting your browser settings. Please note that this may result in limited functionality of the website.


6. Web Analytics and Tracking Tools

Where we use web analytics tools (e.g. Google Analytics or comparable services), this is done in compliance with legal requirements. For detailed information on data processing by the respective provider and instructions on opting out, please refer to the provider’s own privacy notices.
Note: If you use Google Analytics, please ensure that IP anonymisation is activated and include, if applicable, a link to the browser opt-out.


7. Social Media Plugins

Our website may contain plugins from social networks. These enable you to share content on your social network profiles. In doing so, personal data may be transmitted to the respective providers. For more information, please refer to the privacy notices of the respective social networks.


8. Retention Period and Deletion of Data

Personal data are stored by us only as long as necessary to achieve the respective processing purposes or as required by statutory retention obligations.

  • Log files and technical data: Stored for seven days and then deleted.
  • Order data: Stored in accordance with statutory retention periods (generally up to 8 years), unless a shorter period is permissible.
  • Customer account data: Remain stored until you terminate your customer account.
    After the purpose of processing ceases to apply or statutory periods expire, the data are routinely deleted, provided no statutory retention obligations conflict.

9. Data Subject Rights

You have the right to:

  • Access: Request information about your personal data we store.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion of your personal data, provided no statutory retention periods apply.
  • Restriction: Request restriction of processing.
  • Data portability: Request transfer of your data.
  • Objection: Object to processing of your personal data where grounds arise from your particular situation.
  • Complaint: Lodge a complaint with a supervisory authority.

To exercise your rights, please contact the above contact details.


10. Data Security

We implement technical and organisational security measures to protect your personal data processed by us against unauthorised access, loss, destruction or manipulation. Our measures are continuously updated to reflect the state of the art.

Examples of our security measures include:

  • Use of SSL encryption (Secure Socket Layer) for data transmission.
  • Regular review and updating of our IT security protocols.
  • Access restrictions to sensitive data.

11. Changes to This Privacy Policy

NatureWatt GmbH reserves the right to adjust this privacy policy at any time to reflect current legal requirements or changes in our services. The current version is available on our website. In case of material changes, we will inform you in an appropriate manner.


12. Contact for Data Protection

For questions regarding data protection and to exercise your rights, you may contact our Data Protection Officer:

Data Protection Officer of NatureWatt GmbH
Christoph Leitgeb
office@naturewatt.de
Phone: +49 8027 9085 670


13. Hosting and Server Locations

Our hosting is provided by Amazon Web Services EMEA SARL, whose server locations are in Germany/EU. If data are processed outside the EU/EEA, this is done using Standard Contractual Clauses of the European Commission to ensure adequate data protection.


14. Further Details on Third-Party Providers and Specific Data Processing

If we use specific third-party providers (e.g. payment service providers, shipping service providers, web analytics providers) that have their own privacy notices, we refer to their respective privacy policies: