COMPUMAC COMPUTERVERTRIEB GMBH
Privacy Policy
Contents of this page
This is a translation for your convenience. Only the German version is legally binding.
Last updated: October 2026
This privacy policy applies to our website and our online shop at www.compumac.de and to our services in our store, in our workshop, by phone and via messenger services.
1. Controller
CompuMac Computervertrieb GmbH
Werastraße 42
88045 Friedrichshafen
Germany
Represented by the Managing Director Todi Vasilia
Phone: +49 7541 9203-0
Email: info@compumac.de
We have not appointed a data protection officer because we are not legally required to do so. If you have any questions about data protection, you can reach us using the contact details above.
2. Key points at a glance
- Legal bases: We process your data to perform contracts or to handle pre-contractual enquiries (Art. 6(1)(b) GDPR), to comply with legal obligations, such as retention obligations under tax and commercial law (point (c)), on the basis of our legitimate interests (point (f)) or with your consent (point (a)). We only store information on your device or access information stored on it where this is strictly necessary for the service you have requested, or with your consent (Section 25 of the Telecommunications Digital Services Data Protection Act (TDDDG)).
- Recipients: We use carefully selected service providers that process data on our behalf and in accordance with our instructions (processors, Art. 28 GDPR), for example for hosting, email and telephony. Other recipients – such as payment providers, shipping companies, Apple in the case of repairs, leasing and insurance partners or our tax adviser – only receive data to the extent necessary for the respective purpose and process it as independent controllers. We name the individual service providers in the following sections.
- Transfers to third countries: Some service providers are based outside the EU and the EEA or access data from there. We only transfer data to such countries if the European Commission has determined that they ensure an adequate level of data protection – for example for Canada or for US companies certified under the EU-US Data Privacy Framework – or if appropriate safeguards are in place, in particular EU standard contractual clauses (Art. 45 and 46 GDPR). You can obtain a copy of the safeguards on request.
- Storage period: We delete data as soon as we no longer need it for the purpose and there is no obligation to retain it. We retain commercial and business letters for six years, invoices and accounting vouchers for eight years, and books of account and annual financial statements for ten years, in each case from the end of the calendar year (Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)). We store data that we need to assert or defend against claims until the limitation period has expired.
- Mandatory information: Information that we need for a contract is marked as a mandatory field. Without it, we cannot conclude or perform the contract. All other information is voluntary.
- Automated decisions: We do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR. Payment and financing providers such as Klarna and PayPal, as well as our leasing and financing partners (section 17), may use automated procedures for their own decisions, for example when checking your creditworthiness; they provide information about this in their privacy notices.
3. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw any consent you have given at any time with effect for the future (Art. 7(3)). An informal message to info@compumac.de is sufficient.
If information about your customer data is requested from Shopify or your customer data is deleted there, Shopify notifies our own system so that we can also deal with your request in our systems. For this purpose, we record the request with your email address, your phone number and your Shopify customer number, together with the dates of receipt and completion. In the case of deletion, we delete your education proofs immediately; the result of the review remains until the end of the period stated in section 7a. An employee checks our other data and deletes it unless we are required to retain it. We keep the record of how the request was handled for as long as we need it to be able to prove that your rights have been fulfilled (Art. 6(1)(c) GDPR in conjunction with Art. 5(2) and Art. 12 GDPR).
Right to object (Art. 21 GDPR): Where we process your data on the basis of legitimate interests, you may object to the processing at any time on grounds relating to your particular situation. You may object to processing for direct marketing purposes at any time without giving reasons.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Heilbronner Straße 35, 70191 Stuttgart (postal address: Postfach 10 29 32, 70025 Stuttgart), phone 0711 615541-0, email poststelle@lfdi.bwl.de, www.baden-wuerttemberg.datenschutz.de.
4. Website, online shop and hosting
Our website and our online shop run on the Shopify platform. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. On our behalf, Shopify provides servers, a content delivery network, the shopping cart, checkout, customer accounts and forms, and processes the data you enter there.
When you access the website, technically necessary access data is processed: IP address, date and time, page accessed, referrer URL, browser, operating system and device information. This is necessary to deliver the website, to ensure its stability and security and to prevent misuse (Art. 6(1)(f) GDPR). This access data is only stored for as long as necessary for these purposes.
Shopify transfers data to its parent company Shopify Inc. in Canada, for which an adequacy decision of the European Commission exists, and uses sub-processors in the USA, among other countries; EU standard contractual clauses or a certification under the EU-US Data Privacy Framework are in place for this. Where Shopify processes data for its own purposes, for example for fraud prevention or when you use Shop Pay or the Shop app, Shopify is itself the controller for this processing; for details, see www.shopify.com/de/legal/datenschutz.
Shopify Network Intelligence. Our shop has the Shopify feature “Network Intelligence” switched on. Shopify uses data from our shop, such as information about orders and shopping behaviour, together with data from other Shopify shops to improve its services, for example the selection and order of payment methods at checkout, features of the Shop app, advertising and personalisation, and emails such as the reminder about an unfinished purchase. Other merchants cannot see your data. The legal basis is our legitimate interest in a simple, secure and suitable shopping experience (Art. 6(1)(f) GDPR); where information is stored on or read from your device for this, this only happens with your consent via our cookie banner (Section 25 TDDDG, Art. 6(1)(a) GDPR). Where Shopify uses this data for its own purposes, Shopify is itself the controller; for details, see www.shopify.com/de/legal/datenschutz. You can object to this processing at any time (Art. 21 GDPR); a short email to info@compumac.de is enough.
We load fonts from Shopify servers; we do not use Google Fonts. To protect our forms against spam, Shopify uses automatic spam protection, which analyses technical characteristics of your browser for this purpose (Art. 6(1)(f) GDPR).
5. Cookies and consent
We use cookies and similar technologies, such as your browser's local storage. We set strictly necessary cookies – for the shopping cart, checkout, sign-in, security and storing your cookie choices – on the basis of Section 25(2) no. 2 TDDDG and Art. 6(1)(b) or (f) GDPR.
We only use cookies and services for preferences, statistics and marketing if you have given your consent in the cookie banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). The banner is provided by Shopify; your choice is stored in a cookie so that we do not have to ask you again on every visit. You can change or withdraw your choice at any time via the “Cookie settings” link at the bottom of every page. There you can also see which categories exist and what they are used for.
6. Statistics and advertising
We only use statistics and advertising services that process data about your visit with your consent. We integrate the Google services via the Shopify app “Google & YouTube”, which passes your choice in the cookie banner on to Google (Google Consent Mode, version 2). As long as you have not given your consent, Google Analytics and Google Ads conversion tracking are not loaded. The provider of the Google services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-US Data Privacy Framework.
Google Analytics 4
With your consent for analytics purposes, we use Google Analytics 4 to evaluate how our website is used, for example pages accessed, time spent on the site, source of the visit, device type, approximate region and purchases. Google Analytics 4 does not store complete IP addresses. User-level and event-level data is deleted after the configured retention period, at the latest after 14 months.
Google Ads conversion tracking
With your consent for marketing purposes, we measure whether you came to us via a Google ad and then, for example, completed a purchase. This tells us how many visitors come to us via our ads and place an order; we do not identify individual persons in the process.
Google Merchant Center
Via Google Merchant Center, we provide product data such as price and availability for ads and product listings on Google. We do not transmit any personal data of visitors in the process.
Price comparison portals Geizhals and idealo
Our offers are listed on the price comparison portals Geizhals (Preisvergleich Internet Services AG, Vienna, Austria) and idealo (idealo internet GmbH, Berlin). For this purpose, we transmit product data, not visitor data. If you come to us via a link on these portals, we can see from the address accessed or from the referrer which portal you came from; this is only analysed within the scope of your consent for analytics purposes. The portals themselves are responsible for the processing on their own websites.
7. Orders, customer account and business account
For your order, we process your name, address, email address, phone number (optional), order data, payment status and shipping data in order to process the contract, to send you the acknowledgement of receipt, the order confirmation and status messages, and to keep our accounts (Art. 6(1)(b) and (c) GDPR). The acknowledgement of receipt is sent by Shopify; our team sends you the order confirmation separately by email via our email system IceWarp (section 14), including after an order or reservation by phone. We process order data in Shopify and in our own systems in Friedrichshafen; for order processing and invoicing, we also use our order management system Fixably (section 11). If you order a laser engraving, we also process the engraving text or design, the requested position and your approval; before engraving, our workshop contacts you by email or phone to agree the details (Art. 6(1)(b) GDPR).
“My CompuMac” customer account: To sign in, we send a code to your email address; we do not store passwords. Sign-in is provided for us by Shopify. Sign in with Google: If you choose “Continue with Google” instead, Shopify redirects you to Google. After you sign in there, Google sends us your name and email address so that we can assign you to your customer account; we do not receive your Google password, and Google learns that you are signing in with us (Art. 6(1)(b) GDPR). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-US Data Privacy Framework. Google explains how it processes your data when you sign in in its own privacy notice. In your account, you can see your orders and – where applicable – your repair orders and appointments, which we assign to you using your email address (Art. 6(1)(b) GDPR). You can request the deletion of your account at any time; data that we are required to retain is blocked until the retention period expires.
Business account: For business customers, we additionally process the company name, VAT identification number, contact person, where applicable the legal form and proof of business status, individual prices and orders on invoice (Art. 6(1)(b) and (f) GDPR). Before activating the account, we check the information about your company. Shopify sends orders placed via the order form for business customers by email to our mailbox; our own systems take them over from there and create the order with your prices in Shopify.
7a. Education prices and proof of eligibility
If you would like to buy at education prices in our online shop, you select your group in your “My CompuMac” customer account – students, school pupils aged 16 and over or apprentices, teachers and staff of an educational institution, or parents buying for their child who is a student – and upload proof, such as a certificate of enrolment, a school ID card or a staff ID card (as a PDF, JPG or PNG). In doing so, we process your Shopify customer number, the group you selected, the proof, your name and email address from your customer account, our decision with the date and, where applicable, the reason, and your orders at the education price. We do this to check whether you are entitled to the education price and to process your orders at the education price (Art. 6(1)(b) GDPR). If you are buying as a parent for your child who is a student, you upload your child's certificate of enrolment; we only process the information it contains about your child in order to check eligibility (Art. 6(1)(f) GDPR – our legitimate interest is to grant education prices only to those who are eligible).
Your browser reduces the size of photos before uploading them and saves them again; this removes location and camera data. The proof is encrypted in your browser and reaches our own server in Friedrichshafen via Shopify's signed interface (app proxy) and Cloudflare's relay service (section 12); both only see it in encrypted form. We store the proof as well as your name and email address in encrypted form. Only employees authorised to do so can view the proof in our system; every time it is opened, this is logged. An internal email that contains no information about you informs us of new proof. Whether we accept the proof is decided by an employee; no automated decision is made. If we do not accept the proof, we inform you of this by email, stating the reason.
Once you have uploaded the proof, we provisionally unlock education prices in your customer account. To do so, we set a marker on your customer account at Shopify (“edu-vorlaeufig”, and “edu-freigegeben” after our review) and store the status, the group and the date until which the unlock is valid in a field there. Shopify does not receive the proof itself. We create orders at the education price in Shopify with a corresponding note; after our review, we transfer them to our order management system Fixably like any other order (section 7).
We delete the proof as well as your name and email address from our systems 30 days after our decision; if proof was never reviewed, 30 days after the unlock expires. We delete files that were uploaded but not submitted with proof after 24 hours. After that, only the result of the review remains – customer number, group, decision and date. We keep it for three years after our decision – if proof was never reviewed, three years after the unlock expires – so that we can trace orders at the education price, and then also delete the marker and the field on your customer account. We keep a record of your orders at the education price for twelve months in order to check the maximum quantities per device type; the statutory retention periods apply to the orders themselves (section 2). To prevent misuse, we count uploads, proofs and order attempts per customer account without storing the customer number in plain text for this purpose, and delete these counts after two days (Art. 6(1)(f) GDPR – our legitimate interest is to protect the function against misuse).
7b. Stock check for business customers
If you are signed in with an approved business account, you can check current stock levels on product pages and in the shopping cart using “Check stock now”. For this purpose, Shopify transmits your Shopify customer number and the item numbers of the products queried to our own system in Friedrichshafen via the signed interface (app proxy) and Cloudflare's relay service (section 12). We check whether your business account is approved and query the stock in our order management system Fixably and – via our merchandise management system – with our suppliers; they only receive item numbers, no information about you (Art. 6(1)(b) GDPR). To prevent overload, we count the queries per customer number and delete these counts after two days (Art. 6(1)(f) GDPR – our legitimate interest is to protect the query against overload). Beyond this, we do not store anything about your queries.
8. Payment
You enter your payment details directly with the respective payment provider; we do not receive full card details. We receive confirmation of the payment and the information required for accounting. The legal basis for the transfer to the payment providers is Art. 6(1)(b) GDPR, and for fraud prevention measures Art. 6(1)(f) GDPR.
- Credit card, Apple Pay, Google Pay and Klarna: These payment methods are handled by Shopify Payments; the payment service provider is Stripe (Stripe Payments Europe, Limited, Dublin, Ireland). Stripe processes some data as an independent controller, for example for fraud prevention and to comply with legal obligations. With Apple Pay and Google Pay, Apple or Google respectively also process data in accordance with their own privacy policies. If you choose Klarna, Klarna Bank AB (publ), Stockholm, Sweden, also processes your data as an independent controller and, depending on the payment method, checks your identity and creditworthiness.
- PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, processes the data as an independent controller and may check your creditworthiness – for example for a deferred payment or payment in instalments.
- Bank transfer (payment in advance): If you pay by bank transfer, we process the information from your transfer – account holder, IBAN, amount and payment reference – in order to match the payment to your order and to transfer refunds, for example after a withdrawal, to your account (Art. 6(1)(b) GDPR). The recipient of this data is our bank.
- Purchase on invoice (approved business customers only): We process invoice and payment data ourselves; the previous point applies accordingly to incoming bank transfers.
- PayPal payment link for orders: For a repair or service order, we can send you a PayPal payment link by email that you can use to pay the outstanding invoice amount or a deposit. For this purpose, we transmit the amount, our order and invoice number and a payment reference to PayPal; you enter your payment details directly with PayPal. If we send you an invoice via PayPal instead, PayPal also receives your name and email address. After your payment, we receive confirmation from PayPal and record the payment against your order in our order management system Fixably (section 11). We store the information about the payment link for as long as we need it to allocate the payment and for our accounting (Art. 6(1)(b) and (c) GDPR). The point “PayPal” applies to processing by PayPal.
9. Shipping and collection
For delivery, we pass on your name and delivery address to the shipping company commissioned: DHL Paket GmbH, Bonn, or United Parcel Service Deutschland S.à r.l. & Co. OHG, Neuss (Art. 6(1)(b) GDPR). We only pass on your email address and phone number to the shipping company if you have consented to this (Art. 6(1)(a) GDPR). When you collect items from our store, we check your ID; we do not make a copy of it.
10. Digital products
If you buy a software product key, for example for Microsoft 365, Parallels Desktop, Excire Foto or an antivirus program, we assign a key to your order and send it to your email address by email. We store the link between key and order so that we can prove the licence and answer queries, and for the statutory retention periods (Art. 6(1)(b) and (c) GDPR). Upon activation, the manufacturer, for example Microsoft, processes your data as an independent controller.
11. Repair, data recovery and remote support
For repair and service orders, we process your contact details, information about the device (model, serial number, IMEI), the fault description, diagnostic and repair data, the warranty and AppleCare status, photos documenting the condition of the device and communication relating to the order (Art. 6(1)(b) and (c) GDPR). We store order data for the duration of the order and of the liability for defects, and within the scope of the statutory retention periods.
- Fixably: Our order and repair management system, including the repair portal compumac.repairportal.com, where you can check the status of your order, is operated by Fixably Oy, Helsinki, Finland, as a processor. We use Fixably to send you messages about the status of your order.
- Apple: As an Apple Authorized Service Provider, we transmit the data required for warranty checks, repairs and ordering parts – serial number, IMEI, diagnostic and repair data and your contact details – to Apple (Apple Distribution International Ltd., Cork, Ireland, and Apple Inc., USA) via Apple's GSX service platform. Apple also processes this data as an independent controller, for example for warranty, quality assurance and security purposes; for details, see www.apple.com/de/legal/privacy.
- Partner drop-off points: If you hand in your device at one of our partner drop-off points – currently EDEKA Looks in Wangen-Neuravensburg and media@home Kraus in Kempten – the drop-off point records your contact details, the device and the fault description on our behalf and forwards them to us.
- Order status on our website: You can check the status of your repair order on our website. To do so, you enter your order number and surname; we check in Fixably whether the two match and show you the status (Art. 6(1)(b) GDPR). The request reaches our own system by the same route as appointment bookings (Shopify app proxy and Cloudflare, section 12). We do not store your surname. To prevent anyone from trying out other people's orders, we record every request with the time, the IP address and – if the details match – the order number in a log, and count the requests per order number and IP address for a short time (Art. 6(1)(f) GDPR – our legitimate interest is to protect your order data against unauthorised access). We only store the log for as long as we need it to detect and investigate attempted misuse.
- Content on your device and data recovery: We only look at personal content to the extent required by the order, for example for a data recovery or data transfer you have commissioned. Complex data recoveries are carried out on our behalf, after your approval, by our partner KLDiscovery Ontrack GmbH, Böblingen; for this purpose, Ontrack receives the storage medium and the information required for the order.
- Remote support: For remote support, we use AnyDesk from AnyDesk Software GmbH, Stuttgart. The connection is only established once you grant access on your device; we only see your screen during the session. To establish the connection, AnyDesk processes connection data such as the IP address and the AnyDesk ID of your device (Art. 6(1)(b) GDPR).
- Shipping devices for a repair (DHL, UPS): If you send us a device for repair and buy a shipping label from us in our service portal, or if we return your device to you after the repair, we pass the data needed for shipping to the carrier chosen by you or by us – Deutsche Post AG or DHL Paket GmbH, Charles-de-Gaulle-Straße 20, 53113 Bonn, or United Parcel Service Deutschland S.à r.l. & Co. OHG, Görlitzer Straße 1, 41460 Neuss: your name, your company if any, your address, our job number as the shipment reference and the parcel weight, and to UPS also your phone number if you have given us one. We do not pass your email address on to the carrier (Art. 6(1)(b) GDPR). The carrier processes the data as an independent controller for the transport; details are given in the privacy notices of DHL (www.dhl.de/datenschutz) and UPS (www.ups.com). You pay for a shipping label through our online shop's checkout; section 8 applies. We store the label encrypted while the repair job is running and as long as it is needed for queries about the shipment; we keep the invoice within the statutory retention periods.
11a. Purchase of used devices and private sales
Buy-back and trade-in: If we buy a used device from you or accept it as a trade-in, we process your contact details, information about the device such as model, serial number and condition, the agreed price and your bank details for the payout, as well as the information we need to verify the lawful origin of the device (Art. 6(1)(b), (c) and (f) GDPR). Before reselling the device, we reset it; this deletes all data stored on it.
Trade-in calculator and request by email: On the page “What’s my device worth?” we show you a non-binding guide value for your used device. Your browser processes your choice of device type, model and condition; it loads the list of guide values from our own server in Friedrichshafen via Shopify’s signed interface (app proxy) and a forwarding service on Cloudflare servers. We do not store any personal data in the process. We calculate the guide values from publicly available market values, which our server retrieves once a day; no data about you is transmitted in the process. If you request an offer by email using the form, we process your name, email address, phone number (optional), the selected device, its condition, the guide value shown and your note (optional) in order to make you an offer (Art. 6(1)(b) GDPR). Your details reach us by the same route, are stored in our system and forwarded to our team by email; you receive a confirmation of receipt by email. To prevent misuse, we count requests per IP address and per email address for no more than two days, without storing them in plain text (Art. 6(1)(f) GDPR – our legitimate interest is protecting the form against automated mass requests). We delete your request six months after receipt; if a purchase follows, the preceding paragraph applies to the data collected then.
Private sales: If we broker the sale of a device for you as a private seller, we process your contact details, information about the device such as model, serial number and condition, the price you have set, the commission and your bank details for the payout (Art. 6(1)(b) GDPR), as well as the information we need to verify the lawful origin of the device; for this purpose we look at your ID (Art. 6(1)(c) and (f) GDPR). We store the brokerage details in our own system on our server in Friedrichshafen; your bank details are only on the signed brokerage agreement, we only use them for the payout and do not pass them on. Your name does not appear in the online shop. When a buyer reserves the device, we give them your name and town of residence with the reservation confirmation; if they buy in our store without a reservation, before the purchase (Art. 6(1)(b) GDPR). After the sale, your name and town also appear in the buyer's order in our order management system (section 11) and on the buyer's receipt. The buyer only receives your full address if they need it to assert claims under the purchase contract. Conversely, we give the seller the buyer's name, and likewise the buyer's full address only if the seller needs it to enforce or defend against claims under the purchase contract (Art. 6(1)(b) and (f) GDPR).
Reserving a private sale: If you reserve a device from a private sale, we process your name, email address and phone number in order to verify your email address via a confirmation link, hold the device for you, send you the reservation confirmation and complete the purchase in our store (Art. 6(1)(b) GDPR). We store this information in our own system on our server in Friedrichshafen and only pass it on to the seller as far as necessary for the transaction. Payment and handover only take place in our store; we accept the purchase price there in the seller's name. We delete an unconfirmed reservation after 30 minutes. If the reservation does not lead to a purchase, we delete your details 30 days after it ends; if the purchase goes ahead, we keep them within the statutory retention periods. If we are obliged to report under the Platform Tax Transparency Act (PStTG), we additionally collect the seller's information required by that Act, such as date of birth and tax identification number, and transmit the information required by law to the Federal Central Tax Office (Bundeszentralamt für Steuern) (Art. 6(1)(c) GDPR). We store the brokerage data for its duration and within the scope of the statutory retention periods.
11b. Device release online and in store (waiver and release declaration)
If you would like to hand over a device to us, you can also complete and sign the waiver and release declaration on our website. In doing so, we process your name, your contact details, the information about the device including the serial number, the order number if provided, your declarations and your signature drawn on the screen (Art. 6(1)(b) GDPR). The information reaches our own system on our server in Friedrichshafen by the same route as for appointment bookings (Shopify app proxy and Cloudflare, section 12). From it, we create a PDF that both you and we receive by email. If the order number provided belongs to a repair order, we also file the PDF with that order in Fixably (section 11). On our server, we keep the declaration for one year from receipt as proof of the handover and then delete it there; the periods for order and business records apply to the copies in our email system and in Fixably.
If you sign the declaration on paper in our store, it contains your name, your address, your phone number or email address, the information about the device including the serial number, the order number if applicable, the date and the name of our employee. If the device belongs to an order, we file a copy of the declaration without signatures as a PDF with that order in Fixably, not visible in the repair portal (section 11). This serves as proof that the device was handed over to us (Art. 6(1)(b) and (f) GDPR). The periods for order and business records apply to the paper original and the copy.
12. Appointment booking and training registration
If you book an appointment online, we process your name, email address, phone number, preferred appointment, the type of service and the information you provide about your request in order to arrange the appointment, send you a reminder and prepare for your visit or the remote support session (Art. 6(1)(b) GDPR). For a repair drop-off appointment, we also record your device and, if you provide it, its serial number; with this information, we may create an order in our order management system Fixably before your visit (section 11).
Your information reaches our own system on our server in Friedrichshafen via a signed Shopify interface (app proxy) and a relay service of Cloudflare, Inc., USA. Cloudflare forwards the data to our server; we do not use the relay service as a repository for your information. When providing and securing the transmission, Cloudflare may process connection and log data such as your IP address. Cloudflare is certified under the EU-US Data Privacy Framework. We enter the appointment in our business calendar in the IceWarp email and calendar system (section 14). You will receive the confirmation, with your appointment number and a personal link that you can use to reschedule or cancel the appointment, from termine@compumac.de.
Drop-off appointment at a partner drop-off point: If you book an appointment to hand in your device at one of our partner drop-off points – currently media@home Kraus in Kempten and EDEKA Looks in Wangen-Neuravensburg – the selected drop-off point receives by email your name, your phone number and email address, the appointment, the information about the device and your request, and the preferred pick-up location, so that it can accept your device at the agreed time. If you cancel the appointment, it also receives the cancellation (Art. 6(1)(b) GDPR).
If you register for a training course, we process your name, email address, phone number and company (both optional), the number of participants, your prior knowledge, your comment and the Thursdays that suit you. The registration reaches us by the same route, is stored in our system and is forwarded by email to our training team so that we can set a course date and invite you to it (Art. 6(1)(b) GDPR). On our website, we only show the number of registrations and free places for each Thursday, without names or other information. If you register by phone via Ivy (section 15), we record your name, your phone number and, if you provide it, your email address.
We only store appointment and registration data for as long as we need it for the appointment or training course, its follow-up and as proof of your declarations (section 12a). We keep paid appointments and course places as business transactions within the statutory retention periods (section 2). If an appointment results in an order, the periods for order data apply.
12a. Paid appointments and training places
You pay for chargeable appointments such as remote support and for places on training courses in advance via a payment link. For this purpose, we create a draft order in our Shopify shop – with your email address, the service with date and time, the amount and our internal appointment number; we do not pass on your name or phone number. If you book on our website, you are taken directly to the payment; you also receive the link by email. Payment works in the same way as for an order in the online shop; you enter your billing and payment details yourself at checkout (sections 7 and 8). Until payment is made, we hold the appointment for you – 30 minutes for a booking on the website and 24 hours for a booking by phone, in each case at most until the appointment starts; for a training place, we tell you the payment deadline. If you do not pay within the deadline, we delete the draft, release the appointment or place again and inform you of this by email if we sent you the link by email (Art. 6(1)(b) GDPR).
Before you pay for a training place, you confirm the booking on our website and – if the course starts within the withdrawal period – your request that we begin before that period expires. We store the time and the version of the text as proof (Art. 6(1)(b) and (f) GDPR – our legitimate interest is to be able to prove your declaration). After payment, we record it for our accounting (section 18); for this purpose, a receipt with your name, your contact details and your address from the checkout may be created in our order management system Fixably (section 11; Art. 6(1)(b) and (c) GDPR).
12b. “Wanted device” notification (pre-owned marketplace)
On our pre-owned marketplace page you can tell us which used device you are looking for. We will then notify you by email as soon as a matching or similar device is online.
What data: your email address, optionally your first name, the details of the device you are looking for (device type, model and optionally storage or size, colour, minimum condition, maximum price), the language of the page, the time of your request, the time of your confirmation and the version of the consent text. To prevent misuse of our forms we count requests per requesting IP address for at most two days; we store only a checksum, not the address itself.
Purpose and legal basis: the email notification about matching and similar devices, based on your consent (Art. 6(1)(a) GDPR). We use a double opt-in procedure: after submitting, you receive an email with a confirmation link; the notification only becomes active once you click it. We store proof of your consent (time and text) together with your request (Art. 7(1) GDPR). Counting requests serves to prevent misuse (legitimate interest, Art. 6(1)(f) GDPR).
How often: at most one email per day; we notify you of each device only once. The email contains the name, price, condition, a photo and a link to the device. The photo is loaded from the servers of our shop provider Shopify when your email program displays images; we use no tracking pixels and do not evaluate whether you open the email or click links.
Withdrawal: you can withdraw your consent at any time with effect for the future – with one click on “Unsubscribe” in any of our emails, via your email program's unsubscribe function, or informally to info@compumac.de. Your request is then deleted immediately.
Storage period: we delete an unconfirmed request after 72 hours and a confirmed one six months after confirmation, immediately on unsubscribing. Together with the request we delete the proof of your consent and the list of devices reported to you. For the “one email per day” limit, a checksum of your email address with the time of the last email is kept for at most two days.
Recipients: the request reaches our own server in Friedrichshafen via the shop platform Shopify (see section 4) and Cloudflare's relay service (section 12); the data is stored there. We send the emails via our own email system. The data is not passed on to third parties for advertising purposes.
13. Online withdrawal
If you use our “Withdraw from contract” function, we process your name, your email address, the order details and the scope of the withdrawal. The information reaches our own system on our server in Friedrichshafen by the same route as for appointment bookings (Shopify app proxy and Cloudflare). There, we record your declaration with the date and time of receipt, send you the acknowledgement of receipt required by law by email and inform our team (Art. 6(1)(c) GDPR in conjunction with Section 356a of the German Civil Code (BGB), and Art. 6(1)(b) GDPR). We keep the declaration as proof for as long as claims under the contract can be asserted and within the scope of the statutory retention periods.
14. Contact via form, email, phone, chat and WhatsApp
When you contact us, we process the information you provide – such as name, email address, phone number, company, subject and message – in order to handle your enquiry (Art. 6(1)(b) GDPR for contract-related enquiries, otherwise point (f)). We delete enquiries that do not result in a contract as soon as they have been dealt with conclusively and there is no obligation to retain them.
- Contact form: Shopify sends messages from the contact form by email to our mailbox.
- Email and calendar: Our email and calendar system is operated by IceWarp on our behalf. We transmit emails with transport encryption (TLS) where the other party's server supports it. Please do not send us passwords or device passcodes by email.
- Telephone: Our telephone system is operated by Gamma Placetel GmbH, Köln, on our behalf. In the process, phone numbers and the time and duration of calls are processed; we only store this connection data for as long as necessary to operate the telephone system and to handle your request.
- Chat (Shopify Inbox): If you write to us via the chat on our website or via the Shop app, we process your messages and the contact details you provide with Shopify Inbox, a Shopify service (section 4), in order to answer your enquiry.
- WhatsApp Business: If you write to us via WhatsApp, we process your phone number, your profile name and your messages in order to deal with your request (Art. 6(1)(b) or (f) GDPR). The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; data may be transferred to Meta Platforms, Inc. in the USA, which is certified under the EU-US Data Privacy Framework. WhatsApp also processes metadata as an independent controller. Alternatively, you can reach us at any time by email or phone.
15. AI telephone assistant “Ivy”
Some calls to us are answered by our AI telephone assistant “Ivy”. At the start of the call, Ivy tells you that she is an AI assistant. Ivy answers general questions, for example about opening hours and repair prices, arranges appointments, reserves products, provides the status of an order once you give the order number and surname, and passes on requests to our team.
For this purpose, your phone number, your speech, which is converted into text in real time, the content of the conversation and the information needed for your request are processed, such as name, email address, preferred appointment or order number. If Ivy books a chargeable appointment or takes your registration for a training course, she asks once for your email address so that we can send you the payment link (section 12a); if you prefer not to give one, our team will contact you on your phone number. At your request, Ivy sends you the appointment details by text message via our telephone system. Ivy is a service of Gamma Placetel GmbH, Köln, which provides the speech and AI processing on our behalf and uses its own sub-processors for this. For appointments, reservations and information, Ivy queries our own system; these queries run via Cloudflare's relay service (section 12). You can reschedule or cancel an appointment using the link in your appointment confirmation or through our team.
Speech and AI processing takes place through the Placetel service we use. Conversation transcripts held there are deleted after 30 days. Our own system stores no complete conversation transcripts, but does store the structured results needed for your request, such as enquiries, appointment details or reservation data. These data and technical logs are subject to the purposes and retention rules stated for them in this privacy policy. The legal basis is Art. 6(1)(b) GDPR where a contract, an appointment or a reservation is concerned, and otherwise our legitimate interest in being easily reachable by phone (Art. 6(1)(f) GDPR). Ivy only books appointments and reservations according to the rules we have set, such as free time slots and available stock, and does not itself conclude any chargeable contracts; a chargeable appointment only becomes binding once you have paid (section 12a). If Ivy cannot handle a request, she passes it on to our team. If you do not wish to speak to Ivy, ask Ivy to pass your request on to our team, or send us an email. Please do not give passwords, device passcodes or bank details over the phone.
16. Newsletter
You will only receive our newsletter with your consent (Art. 6(1)(a) GDPR). After you sign up, we send you an email with a confirmation link (double opt-in). As proof, we store your email address, the times of sign-up and confirmation, and the IP address. We send the newsletter using Shopify Email. With your consent, we analyse whether a newsletter was opened and which links were clicked in order to improve our content.
If you have subscribed to the newsletter, we also send you automated emails using Shopify Messaging: a reminder about a checkout or shopping cart you did not complete, a reminder about products you viewed – only if you have also consented to marketing in the cookie banner (section 5) – and a thank-you email after a purchase. Only newsletter subscribers receive these emails; without a newsletter subscription, you will not receive such reminders; the legal basis is your consent (Art. 6(1)(a) GDPR). Every one of these emails contains a link to unsubscribe.
You can unsubscribe at any time via the link in every email. After you unsubscribe, we store your email address on a block list so that you no longer receive newsletters, and we keep the sign-up records for up to three years in order to be able to prove your consent (Art. 6(1)(c) and (f) GDPR).
17. Leasing, financing and device protection
Online request for leasing and financing: If you submit a leasing or financing request on our website, we process the information you provide in the form: title, name, address, email address and phone number, your bank details (bank, bank location, IBAN, BIC), the desired term, an order number if available, as well as your other information and your message to us. For leasing, information about your company is added – company name, legal form, date of establishment, address and phone number – as well as the desired offer, the desired devices and, if you provide it, a different location of the devices; if you come from our iPhone leasing configurator, we take over the device configuration you selected there. For financing, information about your housing situation (resident since, previous address if less than two years, type of residence), marital status and car, and occupation and employer is added (if less than two years, also the previous employer), plus the direct debit date and, if you provide it, what you would like to finance. For leasing, you may voluntarily upload further documents, such as an extract from the commercial register; your browser reduces the size of images before sending them and removes location and camera data in the process. We process this information in order to review your request, advise you and – if you wish – prepare an application to the partner responsible for your request (Art. 6(1)(b) GDPR). Submitting the form does not currently send an application to a bank or leasing company; before we forward any information to a specific partner, we tell you which partner it is and which information will be transmitted.
Your information and documents are encrypted in your browser and only decrypted again on our own server in Friedrichshafen. They reach us via a signed Shopify interface (app proxy) and a relay service of Cloudflare, Inc., USA; both only receive your information in encrypted form, and we do not use them as a repository for your documents. Connection and log data may be processed in the process (section 12). Cloudflare is certified under the EU-US Data Privacy Framework. On our side, we store your request in encrypted form. Our team receives an email that only contains your first name and a link to our system; the request is only opened there. To protect against misuse, we count requests per IP address and per email address without storing these in plain text (Art. 6(1)(f) GDPR – our legitimate interest is to protect the form against automated mass requests).
We retain the details of your enquiry for as long as they are needed to handle it. For open enquiries, we regularly review whether continued storage is necessary. If no contract is concluded, we delete the enquiry no later than six months after processing has been completed. Individual details that remain necessary to meet statutory retention obligations or to establish, exercise or defend legal claims are retained only for that purpose. If a contract is concluded, we transfer the necessary information to our order management system Fixably (section 11); the periods for order data and the statutory retention periods then apply (section 2). We delete the note containing your bank details there as soon as the information has been transmitted to our partner.
- Leasing (business customers and educational institutions only): For the leasing application, we transmit the necessary information – company, managing director or owner, contact details, bank details, desired devices and terms – to TARGO Leasing GmbH, Düsseldorf. It decides on the application under its own responsibility and may check your creditworthiness for this purpose; how it verifies your information and your identity in the process is explained in its own privacy notice (Art. 6(1)(b) GDPR).
- Financing: Once we offer financing applications via our website, we transmit the necessary information for your application – name, address, contact details, housing situation, occupation and employer, bank details, term and direct debit date – to CreditPlus Bank AG, Stuttgart. It decides on the application under its own responsibility and may check your creditworthiness for this purpose (Art. 6(1)(b) GDPR). Deferred payments or payments in instalments that you select in the checkout via Klarna or PayPal are handled by these providers under their own responsibility (section 8).
- Device protection (WERTGARANTIE): We currently offer device protection from WERTGARANTIE SE in our store; taking it out online through our website is not yet available. If you tell us by email or through our service portal that you are interested in device protection, we process your name, your contact details and the details of your device in order to contact you and prepare the contract in our store (Art. 6(1)(b) GDPR); we do not transmit anything to WERTGARANTIE SE at this stage. Once we offer online sign-up for device protection from WERTGARANTIE SE, Hannover, we integrate two modules of WERTGARANTIE SE for this purpose (“Shop Connect”): a plan calculator on the product pages and an application on our “Device protection” page. We only load both when you open them. They are then loaded from WERTGARANTIE SE servers and call its interfaces; in the process, WERTGARANTIE SE receives technical connection data such as your IP address and the address of the page accessed. For the duration of the session, the modules store technical data, such as an access token and the plan you have selected, in your browser's session storage; this is strictly necessary for the function you have opened (Section 25(2) no. 2 TDDDG). On the product page, our page passes information about the product displayed – item number, product name, device category, price and manufacturer – to the plan calculator so that it shows the appropriate plans; we do not pass on any information about you. After your order (likewise only once we offer online sign-up): If you ticked the box “Offer device protection after the order” when ordering, we send you an email with a personal link to our “Device protection” page; the link is valid for 60 days. If you open the page via this link or while signed in to your customer account, it loads your order data from our systems. Only when you select “Get device protection now” do we load the WERTGARANTIE SE application and pass it your first name and surname, email address, address, company name if applicable, and the devices purchased with item number, description, device category and price, so that you do not have to enter this information again. Your further entries in the application – such as your choice of plan, information about the device and your payment details for the premium – go directly to WERTGARANTIE SE; we do not store them. WERTGARANTIE SE concludes and performs the contract under its own responsibility; it explains the details in its own privacy notice. After a contract has been concluded, WERTGARANTIE SE may send us a confirmation with the number of your order with us; we use it to help you with questions about device protection and to settle accounts for the brokerage. Legal bases: for the email with the link, the loading of your order data and the transfer to the application, Art. 6(1)(b) GDPR, because you have requested device protection; for loading the modules and the confirmation sent to us, Art. 6(1)(f) GDPR – our legitimate interest is to offer you device protection and to settle accounts for the brokerage. If you take out device protection in our store, we transmit the necessary information – name, address, contact details, device, serial number, date of purchase and purchase price – to WERTGARANTIE SE.
18. Accounting and tax advice
We transmit invoices and receipts to our tax adviser, who processes the data as an independent controller and subject to professional secrecy. For this purpose, we upload them to the systems of DATEV eG, Nürnberg (Art. 6(1)(c) GDPR). For the retention period, see section 2.
19. Instagram and external links
We operate a company profile on Instagram, a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. We do not embed Instagram on our website but only link to our profile; data is only transmitted to Meta when you click the link. If you visit our profile, Meta processes your data in accordance with Meta's Privacy Policy. We are joint controllers with Meta for the statistics on our profile (“Insights”) (Art. 26 GDPR); Meta assumes primary responsibility, and you can find the essential content of the agreement at www.facebook.com/legal/terms/page_controller_addendum. We process messages that you send us via Instagram in order to answer your enquiry (Art. 6(1)(b) or (f) GDPR). Data may be transferred to Meta Platforms, Inc. in the USA, which is certified under the EU-US Data Privacy Framework.
Links to external services, such as Google Maps and Apple Maps for route planning, only open these services when you click the link. From then on, the privacy policy of the respective provider applies.
20. Job applications
We receive applications by email; our careers page itself does not collect any applicant data. We process application documents in order to carry out the application process (Art. 6(1)(b) GDPR). If no employment relationship results, we delete the documents no later than six months after the end of the process, unless you have consented to longer storage.
21. Data security and changes
We protect your data by means of technical and organisational measures in accordance with Art. 32 GDPR, such as encrypted transmission (TLS) and access restrictions. Our own systems in Friedrichshafen cannot be reached directly from the internet; requests from the website only reach them via the interface described.
We update this privacy policy when our services or the legal situation change. The version published on this page at any given time applies.





