The

PRIVACY POLICY

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR), other national data protection laws of the Member States, and other data protection provisions is:

LOTY
Plöck 71
69117 Heidelberg
Germany
Email: hi@loty-hd.com
Phone: +49 1726223783
Website: https://loty-hd.com/

2. General Information on Data Processing

We process personal data of our users only to the extent necessary to provide a functional website as well as our content and services.
Processing of personal data generally only takes place with the user’s consent or where it is permitted by law.

3. Legal Bases for Processing

Where we obtain consent from the data subject for processing operations, Article 6(1)(a) GDPR serves as the legal basis.
For processing necessary for the performance of a contract, Article 6(1)(b) GDPR applies.
Where processing is necessary to comply with a legal obligation, Article 6(1)(c) GDPR applies.
For processing necessary for the purposes of legitimate interests pursued by us or a third party, Article 6(1)(f) GDPR applies.

4. Data Collection When Visiting Our Website

When accessing our website, the following data are automatically collected and stored in server log files:

- IP address of the accessing device

- Date and time of access

- Name and URL of the file retrieved

- Website from which access occurs (referrer URL)

- Browser type and version, and possibly the operating system

These data are required to deliver the website to your device, ensure system security, and prevent misuse or attacks.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in technical functionality and security).

5. Cookies and Consent Management (TTDSG)

We use cookies on our website. Cookies are small text files stored on your device.

5.1 Technically Necessary Cookies

These cookies are required for the website to function (e.g., shopping cart, language preferences).
Legal basis: Section 25(2) TTDSG, Article 6(1)(f) GDPR.

5.2 Analytics and Marketing Cookies

These cookies are used only with your explicit consent.
Legal basis: Section 25(1) TTDSG, Article 6(1)(a) GDPR.

You may withdraw your consent at any time via our cookie banner or through your browser settings.
Further details can be found in our Cookie Policy [insert link].

6. Order Processing in the Online Shop

When you place an order in our online shop, we process your data to handle the purchase.
This includes:


  • Name, address, email address, phone number

  • Payment and shipping information

Legal basis: Article 6(1)(b) GDPR (performance of a contract).
For payment processing, we may share data with payment providers (e.g., PayPal, Klarna, Stripe).
For shipping, we may share data with logistics partners (e.g., DHL, Hermes).

7. Newsletter and Marketing

If you subscribe to our newsletter, we process your email address for sending marketing communications.
Legal basis: Article 6(1)(a) GDPR, Section 7(2)(3) UWG (German Unfair Competition Act).
You can revoke your consent at any time via the “unsubscribe” link in the newsletter.

For existing customers, we may send marketing emails under Section 7(3) UWG, if we received your email in connection with a purchase. You may object to this use at any time.

8. Contact

If you contact us via form, email, or telephone, we process the information you provide in order to handle your inquiry.
Legal basis: Article 6(1)(b) GDPR (pre-contractual measures) or Article 6(1)(f) (legitimate interest in customer communication).

9. Web Analytics and Statistics

If you have given consent, we use analytics tools (e.g., Google Analytics,) to analyze website usage.
Legal basis: Article 6(1)(a) GDPR, Section 25(1) TTDSG.
Data may be transmitted to Google LLC (USA). In such cases, Standard Contractual Clauses (SCCs) pursuant to Article 46 GDPR are used to ensure an adequate level of data protection.

10. Data Retention

Personal data will be deleted as soon as the purpose for which it was collected no longer applies, no legal retention obligations exist, and no legitimate interests require continued storage.

11. Your Rights

Under the GDPR, you have the following rights:


  • Right of access (Article 15 GDPR)

  • Right to rectification (Article 16 GDPR)

  • Right to erasure (“right to be forgotten”) (Article 17 GDPR)

  • Right to restriction of processing (Article 18 GDPR)

  • Right to data portability (Article 20 GDPR)

  • Right to object to processing (Article 21 GDPR)

  • Right to withdraw consent (Article 7(3) GDPR)

  • Right to lodge a complaint with a supervisory authority (Article 77 GDPR)


12. Data Security

We implement appropriate technical and organizational measures to protect your data against loss, destruction, unauthorized access, alteration, or disclosure.
Our security measures are continuously improved in line with technological developments.

13. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in legal requirements or our services.
The current version is always available on our website.

Last updated: 22.10.2025