Buy for 200,00 € more to get FREE SHIPPING.
Privacy Policy
Information on data processing under the GDPR
1. Controller
Ferdinand Maier – Isolite
Kirchstr. 9
85777 Fahrenzhausen
Germany
Phone: +49 1520 2921872
Email:
info@isolite-extracts.com
No Data Protection Officer has been appointed. For all privacy-related requests, please use the contact details above.
2. Scope of this Policy
This Privacy Policy applies to the use of our website, our online store, and related electronic communications with
professional customers and institutional contacts. It does not cover third-party websites or services that may be linked
from our site and are operated under their own privacy policies.
3. Legal Bases under the GDPR
- Art. 6(1)(b) GDPR – performance of a contract or steps prior to entering into a contract (e.g., processing institutional orders).
- Art. 6(1)(c) GDPR – compliance with legal obligations (e.g., tax and commercial retention duties).
- Art. 6(1)(a) GDPR – consent, where required (e.g., non-essential cookies, optional marketing).
- Art. 6(1)(f) GDPR – legitimate interests, such as IT security, fraud prevention, business analytics and efficient customer communication.
4. Data We Process, Purposes & Recipients
Website access & server logs
When our website is accessed, our systems automatically process log data (e.g., IP address, date/time of access, accessed
URL, referrer URL, browser and device information, error codes). This data is required to ensure technical delivery of the
site, maintain stability and security and, where applicable, create anonymised statistics.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation of the website).
Orders, customer accounts & B2B communication
When professional customers place orders or contact us regarding research-use products, we process identification and
business contact data (e.g., name, role, institution/company, billing and shipping address, email, order details,
payment status, communication history) in order to review, process and fulfil the business relationship, including
pre-contractual inquiries, performance of the contract and customer service.
Legal basis: Art. 6(1)(b) GDPR (contract/performance), Art. 6(1)(c) GDPR (legal obligations).
Payments (institutional customers)
Depending on the payment method selected by the customer, payment processing is carried out via external payment service
providers. For this purpose, the payment service provider receives the data necessary to process the payment (e.g., amount,
currency, payment instrument details, transaction identifiers, fraud prevention information).
Typical categories of recipients include banks and payment service providers (e.g., card networks, payment platforms or
financial institutions involved in SEPA transfers). Exact providers depend on the payment methods currently offered in our
store and are indicated during checkout where relevant.
Legal basis: Art. 6(1)(b) GDPR (contract and payment processing), Art. 6(1)(f) GDPR (fraud prevention and security),
and where applicable Art. 6(1)(a) GDPR (consent, e.g., for optional additional services).
Shipping & logistics
For dispatch and delivery of research-use consignments, we transmit necessary delivery data (e.g., contact person,
institution name, delivery address, tracking information) to logistics partners such as parcel and courier services.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
Support, email & messaging (e.g., WhatsApp)
When you contact us (e.g., via email, contact form or messaging services indicated on our site), we process the data you
provide (e.g., name, institution, contact details, content of the inquiry, attachments) in order to handle your request and
document the communication.
Legal basis: Art. 6(1)(b) GDPR (contract-related communication) or Art. 6(1)(f) GDPR (legitimate interest in effective
handling of professional inquiries).
Cookies & similar technologies
We use technically necessary cookies to enable core functions of the site (e.g., maintaining a session, shopping cart
functionality, security features). These cookies are required for the operation of the online store and cannot be deactivated
via our systems.
Legal basis for necessary cookies: Art. 6(1)(f) GDPR (legitimate interest in functional operation of the website).
Non-essential cookies or similar technologies (e.g., analytics or marketing tools, where used) are implemented only on the
basis of your prior consent, which you can give and withdraw at any time via the cookie settings on our website.
Legal basis for non-essential cookies: Art. 6(1)(a) GDPR (consent).
5. Consent Management
Where we use a consent management tool, your choices (e.g., consent or refusal for specific cookie categories) are stored in
a consent log (e.g., time, scope of consent, device/browser information). This allows us to document and manage consents in
line with legal requirements. You may adjust your preferences at any time with effect for the future via the cookie banner or
browser settings.
6. Processors & Other Recipients
For the provision of our services and operation of the online store, we use carefully selected service providers (e.g.,
hosting providers, IT service providers, payment processors, logistics companies, analytics providers). Where such parties
act as processors, they process personal data only on our documented instructions and on the basis of appropriate data
processing agreements in accordance with Art. 28 GDPR.
7. International Data Transfers
Where service providers are located outside the European Economic Area (EEA) or data is processed in such jurisdictions,
we ensure that an adequate level of data protection is in place, for example via EU adequacy decisions or by concluding
the European Commission’s Standard Contractual Clauses and implementing additional safeguards where necessary.
8. Retention Periods
-
Order, contract and invoice data are stored for the duration of the business relationship and subsequently for the
statutory retention periods (typically 6–10 years under tax and commercial law). -
Communication and support records are generally retained for as long as necessary to handle the inquiry and for documented
follow-up, then deleted or anonymised in line with our retention rules. -
Server log data is usually retained for a short technical period (e.g., 30–90 days), unless required longer for security
investigations or legal purposes. -
Cookies and consent records are retained in accordance with the respective cookie lifetime and applicable legal
documentation requirements.
9. Data Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss,
alteration or destruction, taking into account the state of the art, implementation costs and the nature, scope, context and
purposes of processing. Despite these measures, no method of transmission over the Internet or method of electronic storage
is completely risk-free.
10. Your Rights
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing based on legitimate interests (Art. 21 GDPR)
- Right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, please contact us at
info@isolite-extracts.com
.
For security reasons and to prevent misuse, we may ask you for additional information to verify your identity before fulfilling
your request.
11. Professional & Non-Consumer Focus
Our website, online store and products are aimed at professional users, such as laboratories, research institutions and
businesses. We do not target private consumers or minors. If you believe that personal data of a minor has been provided to
us without appropriate authority, please contact us so that we can take appropriate steps.
12. Automated Decision-Making
We do not carry out automated decision-making, including profiling, which produces legal effects concerning you or similarly
significantly affects you within the meaning of Art. 22 GDPR.
13. Changes to this Privacy Policy
We may revise this Privacy Policy from time to time to reflect changes in our data processing activities or legal
requirements. The current version is published on this page. Where appropriate, we will provide additional notice of
material changes (e.g., via a banner or email).
Last updated: 14 April 2026
