Skip to main content

Privacy Policy

This Privacy Policy applies to quadroshop.com, the Help Center we operate at helpcenter.quadroworld.com, the QUADRO Blog and the QUADRO Model Database, wherever they refer to this Privacy Policy.

The following sections apply only to the online service and function where the processing described actually takes place. Information relating to the online store, orders, customer accounts, payments, shipping and product notifications applies exclusively to quadroshop.com.

Separate QUADRO country stores on other domains are governed by the privacy policies provided on those domains.

Controller

The controller within the meaning of the General Data Protection Regulation is

QUADRO DER GROSSBAUKASTEN GmbH
Am Schilfpark 13
21029 Hamburg
Germany

Legal bases for processing

We process personal data only to the extent necessary to provide our services, respond to inquiries, perform contracts, comply with legal obligations or pursue legitimate interests, or where you have given your consent.

Depending on the purpose, processing is based in particular on

• Article 6(1)(a) GDPR where you have given consent,

• Article 6(1)(b) GDPR to take steps prior to entering into a contract and to perform a contract,

• Article 6(1)(c) GDPR to comply with legal obligations, and

• Article 6(1)(f) GDPR to pursue legitimate interests.

Section 25 TDDDG also applies when information is stored on your terminal device or accessed from it. We use technologies that are not strictly necessary only with your consent in accordance with Section 25(1) TDDDG. Strictly necessary technical operations are based on Section 25(2) TDDDG.

Technical provision of our online services

When you access our online services, technically necessary connection data is processed. This includes, in particular, your IP address, the date and time of access, the URL accessed, the amount of data transferred, the referring page, browser, operating system, device type, and error and security information.

The processing serves to deliver our content, ensure stability and security, and detect and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our online services.

We use Shopify International Ltd., c/o Intertrust Ireland, 2nd Floor, 1–2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32, Ireland, for the technical provision of the online store, checkout, customer account and order management, and for payments processed through these services. In this context, the provider processes, in particular, connection, device, usage, customer, order and payment data, either on our behalf or, for certain services of its own, under its own responsibility under data protection law. Data may also be processed by affiliated companies and subprocessors outside the European Economic Area. According to the provider, such transfers are based in particular on adequacy decisions, binding corporate rules and standard contractual clauses. For more information, see the provider’s privacy policy: https://www.shopify.com/legal/privacy/consumers

We may use BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia, to deliver fonts and static content quickly and securely. For technical reasons, this involves processing, in particular, your IP address. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and efficient presentation of our services.

Technical log data is deleted or anonymized as soon as it is no longer required for the purposes stated. It is retained for longer only where necessary to investigate a specific security incident or comply with legal obligations.

Use of the QUADRO Blog and QUADRO Model Database

When you use the QUADRO Blog and the QUADRO Model Database, we process technically necessary connection and device data as well as, in particular, the content you access, your search and filter queries, and the interactions you initiate.

The processing serves to provide the requested content and functions, ensure stability and security, and analyze errors. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, functional and user-friendly operation of these services.

We analyze usage where this is not necessary only with your consent in accordance with Article 6(1)(a) GDPR and, where information is stored on or read from your terminal device, Section 25(1) TDDDG.

Orders and contracts

When you place an order, we process in particular

• your name and contact details,

• billing and shipping addresses,

• items ordered, prices and discounts,

• payment method and payment status,

• shipping method and shipment information,

• order and communication data, and

• tax information, where applicable.

The processing is necessary to initiate, perform and process the contract and is based on Article 6(1)(b) GDPR. Where we comply with obligations under commercial, tax or accounting law, the processing is based on Article 6(1)(c) GDPR.

Service providers involved in store operations, inventory management, order fulfillment, accounting, payment processing, fraud prevention, shipping and customer communications receive the necessary data. These recipients receive only the data required for their respective tasks.

Customer account

You can use a customer account in particular to view and manage your contact details, orders and order information.

For current customer accounts, you sign in using a time-limited code sent to your email address. Where an older customer account is still used, additional password-related functions, including password reset, may be available.

In this context, we process, in particular, your email address, contact details, order information, and login and security data. The legal basis is Article 6(1)(b) GDPR. We also process security logs on the basis of Article 6(1)(f) GDPR. Our legitimate interest is protecting customer accounts against unauthorized access.

Payments

When you make a payment, the data required for the selected payment method is transmitted to the payment service providers, banks and card organizations involved. This may include, in particular, your name, billing address, email address, order value, currency, transaction identifier, device and verification data, and payment status.

Depending on your device, browser and configured wallet, we offer payment by credit card, PayPal, Apple Pay and Google Pay. Technical payment processing for card and wallet payments is handled by the provider named in the section on the technical provision of our online services. PayPal is provided by PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg; Apple Pay by companies in the Apple group; and Google Pay by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The data is transmitted to perform the contract in accordance with Article 6(1)(b) GDPR. Where a payment service provider processes data for its own purposes, for example for fraud prevention, identity verification or compliance with legal obligations, it is independently responsible for that processing.

As a general rule, we do not receive complete credit card details, but only the information required to allocate and document the payment. For more details, see the privacy notice of the selected payment service provider.

Shipping and delivery

To deliver an order, we transmit the necessary recipient, address, contact and shipment data to the shipping or logistics service provider used. These providers include, in particular, DHL and, for relevant deliveries to Switzerland, MeinEinkauf.

The legal basis is Article 6(1)(b) GDPR. A telephone number or email address is transmitted only where necessary for delivery, a delivery notification you have requested or the resolution of delivery problems.

Customer service via the Help Center and QUADRO Bot

When you contact us by email, contact form, chat or other means of communication, we process your contact details, the content of your inquiry, related order information and subsequent communications.

We use Intercom R&D Unlimited Company, 124 St Stephen’s Green, Dublin 2, D02 C628, Ireland, for chat, the Help Center, automated responses and the QUADRO Bot. In particular, contact, message, order, page-view, device, connection and session data may be processed. If you use an order inquiry function, the information you provide may be matched against existing order data.

Automatically generated responses are intended to provide information quickly and do not produce any legal or similarly significant effects. Do not submit special categories of personal data or payment data through the chat unless this is expressly necessary and intended.

The Help Center may use cookies and local storage. Without consent, we use only technologies that are strictly necessary to provide the Help Center or a function you have expressly requested. We use technologies that are not necessary, including technologies that monitor page usage, only with your consent. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG. Strictly necessary storage and access operations are based on Section 25(2) TDDDG.

The processing of an inquiry that you actively submit is based on Article 6(1)(b) GDPR where it relates to a contract or steps prior to entering into a contract. In other cases, it is based on Article 6(1)(f) GDPR. Our legitimate interest is efficient customer communication.

Intercom may use affiliated companies and service providers in third countries, particularly in the United States. According to the provider, such transfers are based in particular on adequacy decisions and standard contractual clauses. For more information, see Intercom’s privacy policy: https://www.intercom.com/legal/privacy

Newsletter

If you subscribe to our newsletter, we process, in particular, your email address, the time of registration, evidence of your consent and technical delivery information.

The legal basis is your consent in accordance with Article 6(1)(a) GDPR. You may withdraw your consent at any time with future effect by using the unsubscribe link in the newsletter or sending us a message. The lawfulness of processing carried out before withdrawal remains unaffected.

We analyze newsletter opens and clicked links only where you have also consented to this. After you unsubscribe, your email address may remain stored on a suppression list where necessary to prevent further unwanted delivery. The legal basis for this is Article 6(1)(f) GDPR.

Product availability notifications

If you request notification when a product becomes available again, we process your email address and its association with the requested product. We use the data solely for the notification you requested and subsequently delete it unless legal obligations or separate consent justify further storage.

The legal basis is your consent in accordance with Article 6(1)(a) GDPR. We will register you for the newsletter or other advertising at the same time only with separate consent.

Cookies and similar technologies

We use cookies and similar technologies such as local storage, pixels, tags and scripts.

Technically necessary technologies are used in particular to provide the cart and checkout, enable login to and secure the customer account, store language, region and privacy settings, balance loads, prevent fraud, and provide expressly requested functions. Section 25(2) TDDDG applies to the storage of or access to information. Depending on the purpose, the subsequent processing of personal data is based in particular on Article 6(1)(b) or (f) GDPR.

We use nonessential analytics, personalization and marketing technologies only with your consent in accordance with Section 25(1) TDDDG and Article 6(1)(a) GDPR.

Managing your consent

To manage your choices, we use the consent management solution provided within the relevant online service. We use Pandectes for this purpose on quadroshop.com. In the Help Center, we use the consent management solution provided there.

This involves processing, in particular, your consent status, the time of your choice, device information and a technical identifier. This is necessary to implement and document your choices. The legal basis is Article 6(1)(c) GDPR in conjunction with statutory documentation obligations and Article 6(1)(f) GDPR. Our legitimate interest is to maintain legally compliant evidence of your decision and implement it through technical controls.

You may change or withdraw your choices at any time with future effect through the privacy settings available in the relevant online service. The details displayed there provide information about the categories, providers and storage periods of the technologies used.

Audience measurement and usage analytics

With your consent, we may use functions of the store platform and the audience measurement service we provide at umami.quadroworld.com to understand how visitors use our services. This may involve processing, in particular, the pages and products accessed, the source of the visit, interactions with the cart and checkout, device and browser data, IP address, session and event identifiers, and purchase and transaction information.

The processing is based on your consent in accordance with Article 6(1)(a) GDPR. Where information is stored on or read from your terminal device, Section 25(1) TDDDG also applies.

Managing services that require consent

We use Google Tag Manager to manage the analytics and marketing services described in this Privacy Policy. When activated, it may transmit, in particular, your IP address, browser, device and event data to Google. Tag Manager is used to trigger other services and does not itself independently analyze usage behavior.

The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other companies in the United States is possible.

Nonessential services are activated only with your consent in accordance with Article 6(1)(a) GDPR and Section 25(1) TDDDG. For more information, see Google’s privacy policy: https://policies.google.com/privacy?hl=en

Measuring advertising performance and partner referrals

With your consent, we use technologies to measure the effectiveness of our advertising, attribute orders to advertising campaigns and partner referrals, and create audiences. These include, in particular, Tracify by Tracify GmbH in Munich, X Conversion Tracking, GoAffPro by ARV TECH in India, web pixels from the store platform, and Shogun by Shogun Labs, Inc. in the United States.

This may involve processing device, browser, session, click, page-view, cart, order and transaction data, as well as technical identifiers. X is provided to users in the European Economic Area by X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland. GoAffPro may process data in India and in data centers in Germany and the United States. Shogun and other providers involved may process data in the United States.

The legal bases are your consent in accordance with Article 6(1)(a) GDPR and Section 25(1) TDDDG. Without consent, these technologies are not activated for analytics or marketing purposes. You may withdraw your consent at any time through the privacy settings.

Language and regional display

We use Weglot and technical regional allocation functions to display our services in the relevant language and regional format. This may involve processing, in particular, your IP address, the URL accessed, browser information, selected language and inferred region.

Weglot is provided by Weglot SAS, 7 Cité Paradis, 75010 Paris, France. Where the processing is necessary to provide the requested language or country version, it is based on Article 6(1)(f) GDPR. Our legitimate interest is presenting our services in a comprehensible and regionally appropriate manner. Strictly necessary storage and access operations are based on Section 25(2) TDDDG.

Protection against automated access

We use hCaptcha to protect forms, login processes and other functions against automated misuse. Device, browser, interaction and connection data may be processed to distinguish human access from automated access.

The provider is Intuition Machines, Inc., United States. The processing is based on Article 6(1)(f) GDPR. Our legitimate interest is protecting our systems, customer accounts and forms against misuse and attacks. Where access to information on the terminal device is strictly necessary for this purpose, Section 25(2) TDDDG applies. According to the provider, recognized transfer mechanisms are used for transfers to the United States. For more information, see hCaptcha’s privacy policy: https://www.hcaptcha.com/privacy

Embedding YouTube videos

We embed videos from YouTube. A connection to YouTube is established only after you consent to loading or playing a video. This may involve transmitting, in particular, your IP address, device information, the page accessed, usage data and technical identifiers. If you are signed in to Google, Google may associate your use with your account.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Processing by Google LLC and other companies in the United States is possible. The legal bases are your consent in accordance with Article 6(1)(a) GDPR and Section 25(1) TDDDG.

Geprüfter Webshop rating system

On quadroshop.com, we use the rating system of TISKO Consulting GmbH in Germany. If you consent to a review request, your email address and the order information required for attribution may be transmitted to the provider. The legal basis is your consent in accordance with Article 6(1)(a) GDPR.

The certification seal displayed on quadroshop.com is provided locally. The provider processes further data under its own responsibility only if you open an associated external link or submit a review.

Social networks

Our online services contain links to our profiles on Facebook, Instagram, Pinterest, X and YouTube. Merely displaying a link generally does not transmit any data to the relevant network. The privacy policy of the relevant provider applies only when you open the link.

This does not apply to pixels, embedded media or other marketing technologies used separately. These are described in the relevant sections of this Privacy Policy and, where required, are activated only with your consent.

If you communicate with us or publish content on our profiles on the networks named above, we process the data you transmit to handle the relevant interaction. The legal basis is Article 6(1)(b) GDPR for inquiries relating to a contract and otherwise Article 6(1)(f) GDPR. Platform providers process further usage, device and profile data under their own responsibility. We may be joint controllers with the relevant platform provider for statistical evaluations of our profiles.

Recipients of personal data

Personal data is disclosed only where permitted for the performance of a contract, compliance with legal obligations, pursuit of legitimate interests or on the basis of your consent.

Recipients may include, in particular, hosting, store and IT service providers; inventory management and order fulfillment service providers; payment service providers; banks; card organizations; shipping and logistics companies; customer service and communications providers; analytics, marketing and consent management providers; tax and legal advisers; and public authorities and courts. Processors are engaged on the basis of contracts in accordance with Article 28 GDPR.

Transfers to third countries

Some of the providers named above or their subprocessors are located outside the European Economic Area or process data there. Data is transferred only in accordance with the requirements of Articles 44 et seq. GDPR. Depending on the recipient, we rely in particular on an adequacy decision of the European Commission, valid certification under the EU-U.S. Data Privacy Framework, standard contractual clauses or binding corporate rules. Where necessary, additional safeguards are agreed.

Retention periods

We retain personal data only for as long as necessary for the relevant purpose or for as long as statutory retention obligations or legitimate reasons for further retention apply.

Depending on the type and function of the document, contract, order and payment records are retained in particular for six years as commercial or business correspondence, eight years as accounting documents or invoices, and ten years as books, records or other documents subject to long-term statutory retention. As a general rule, these periods begin at the end of the calendar year in which the document was created.

Inquiry and communication data is deleted once the matter has been fully resolved and there are no contractual, statutory or legal grounds for further retention. Data associated with a customer account is removed when the account is deleted unless it remains necessary to comply with legal obligations or complete outstanding transactions.

We retain evidence of consent for the duration of the consent and thereafter for as long as necessary to comply with documentation obligations and defend against claims. Newsletter data is deleted after consent is withdrawn or transferred to a suppression list where necessary to honor the withdrawal. Analytics and marketing data is deleted or anonymized when the retention period specified for the relevant service expires.

Data may also be retained where necessary for the establishment, exercise or defense of legal claims. Once the original purpose no longer applies, the data is processed only for this limited purpose until the remaining period expires.

Data protection rights

Subject to the statutory requirements, you have, in particular, the right to

• request access to your personal data,

• request rectification of inaccurate data,

• request erasure of your data,

• request restriction of processing,

• request the transfer of data you have provided,

• object to processing based on legitimate interests, and

• withdraw your consent at any time with future effect.

If you object to processing that we base on Article 6(1)(f) GDPR, we will no longer process the data concerned unless there are compelling legitimate grounds or grounds for the establishment, exercise or defense of legal claims. You may object to processing for direct marketing purposes at any time without giving reasons.

To exercise your rights, you may contact [email protected].

You also have the right to lodge a complaint with a data protection supervisory authority, in particular the Hamburg Commissioner for Data Protection and Freedom of Information. You may also lodge a complaint with any other supervisory authority competent under Article 77 GDPR.

Any mandatory additional data protection rights and complaint mechanisms under the law of your place of residence remain unaffected.

Provision of data

If you wish to enter into a contract with us, you must provide the data necessary for ordering, payment and delivery. Without this data, we cannot process the order or cannot process it in full.

For voluntary services, in particular newsletters, marketing consent or voluntary information provided to customer service, there is no statutory or contractual obligation to provide data.

Automated decision-making

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

Payment and security service providers may carry out automated fraud-prevention or risk-assessment checks under their own responsibility. The privacy notices of the relevant service providers also apply to these checks.

Children’s data

Our interactive functions are intended for adults, parents, legal guardians and professional users. Children should not submit personal data to us.

If we become aware that a child’s personal data has been submitted to us without the consent required by law, we delete it unless a statutory retention obligation or another legal basis prevents us from doing so. Parents and legal guardians may contact [email protected] in this regard.

Data security

We implement appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access and unlawful disclosure. Data transmitted between your browser and our online services is generally encrypted.

Effective date and changes

Effective as of July 14, 2026

We update this Privacy Policy when our data processing activities or the legal requirements change. We will notify you of material changes by displaying a notice in our online services or, where necessary, by other appropriate means.

Did this answer your question?