Privacy Policy

Privacy Policy

Important: This is a structured starter policy, not a final GDPR audit. It must be updated to match the actual hosting provider, analytics, forms, WooCommerce setup, payment providers, newsletter tools, cookie tools and other services used on galliumglobal.de/.

1. Controller

Gallium Global GmbH
[INSERT REGISTERED ADDRESS]
Email: [INSERT PRIVACY EMAIL]

2. Server Log Data

When the website is accessed, the hosting infrastructure may process technical data such as IP address, timestamp, requested resource, referrer, browser and operating-system information for security, delivery and error analysis. Insert the actual host and retention period.

3. Contact & RFQ Forms

Information submitted through contact or quotation forms is processed to respond to the inquiry, prepare quotations and manage potential or existing business relationships. Configure the form to collect only necessary information.

4. Customer Accounts & WooCommerce

If customer accounts or online ordering are enabled, account, order, billing, shipping and transaction data may be processed to perform contracts, meet tax/accounting obligations, prevent misuse and provide customer service.

5. Payment Providers

List each payment provider actually enabled and provide the required provider-specific information before activating checkout.

6. Cookies & Similar Technologies

Technically necessary storage may be used to provide requested website functions. Non-essential analytics, advertising or tracking technologies should only be activated in accordance with the applicable consent requirements. List the actual consent platform and services.

7. Analytics & Third-Party Services

Insert only services actually used, for example analytics, maps, video embeds, chat, CRM, newsletter or anti-spam services, together with their legal basis, recipients, transfers and retention information.

8. Recipients & International Transfers

Personal data may be shared with contracted processors and service providers where required. Document any transfers outside the EEA and the applicable transfer mechanism.

9. Retention

Personal data is retained only as long as necessary for the relevant purpose and applicable statutory obligations. Insert service-specific retention periods where required.

10. Data Subject Rights

Subject to applicable law, individuals may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, as well as the right to lodge a complaint with a competent supervisory authority.

11. Security

Appropriate technical and organizational measures are used to protect information, including encrypted HTTPS transmission where implemented.

12. Updates

This policy should be reviewed whenever plugins, tracking, checkout, hosting or other processing activities change.