Privacy Policy
Last updated: 1 October 2026
1. General Information
This Privacy Policy explains how VIRUS Sportartikel GmbH processes personal data when you visit or use this online shop, contact us, create a customer account, place an order, subscribe to our newsletter or otherwise interact with our services.
Personal data means any information relating to an identified or identifiable natural person.
We process personal data only where this is permitted under applicable data protection law, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
2. Controller
The controller responsible for processing personal data on this website is:
VIRUS Sportartikel GmbH
Industriering 8
63868 Großwallstadt
Germany
Phone: +49 6022 655553
Email: info@virus-snowsports.com
3. Categories of Personal Data
Depending on how you use our website, we may process the following categories of personal data:
- name and contact details;
- billing and shipping addresses;
- email address and telephone number;
- customer account information;
- order and transaction information;
- payment-related information;
- communication and support requests;
- newsletter subscription information;
- IP address;
- browser, device and operating-system information;
- log and security data;
- cookie and consent information;
- usage, analytics and marketing information where consent has been given.
4. Purposes and Legal Bases
We process personal data for the following purposes:
Website Operation and Security
We process technically necessary information in order to provide the website, ensure stability and security, prevent misuse and protect our systems.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and efficient operation of our online shop.
Where access to or storage of information on your device is strictly necessary to provide a service expressly requested by you, Section 25(2) TDDDG applies.
Orders and Contract Processing
We process personal data required to process orders, payments, deliveries, returns, customer service and contractual claims.
The legal basis is Art. 6(1)(b) GDPR.
Where processing is required to comply with statutory accounting, tax or commercial-law obligations, the legal basis is Art. 6(1)(c) GDPR.
Pre-Contractual Enquiries and Contact
If you contact us regarding a product, an order or the possible conclusion of a contract, we process your information pursuant to Art. 6(1)(b) GDPR.
For general enquiries that are not directly related to a contract, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest is the efficient handling of enquiries and communication with customers and interested parties.
Customer Accounts
Where you create a customer account, we process the data necessary to provide and manage that account and to facilitate your purchases.
The legal basis is Art. 6(1)(b) GDPR.
Optional processing that is not necessary for the customer account is carried out only on the applicable legal basis, including consent where required.
5. Shopify
This online shop is operated using the Shopify ecommerce platform.
For customers in the European Economic Area, personal data may be processed through:
Shopify International Limited
Ireland
Shopify provides the technical ecommerce infrastructure required for functions including website delivery, shopping carts, customer accounts, checkout, order administration and related services.
VIRUS Sportartikel GmbH generally acts as the controller for customer data processed through the shop. Where Shopify processes customer data on our instructions, Shopify acts as a processor.
Shopify may use affiliated companies and subprocessors in other countries, including Canada and the United States, in order to provide its services.
Where personal data are transferred outside the European Economic Area, such transfers are made in accordance with the requirements of Chapter V GDPR, for example on the basis of an adequacy decision or appropriate safeguards such as standard contractual clauses.
Where additional Shopify consumer services, such as Shop, Shop Pay or other optional Shopify services, are activated, Shopify may process certain personal data under its own responsibility in accordance with its applicable privacy terms.
6. Cookies and Similar Technologies
Our website uses cookies and comparable technologies.
Strictly Necessary Technologies
Certain cookies and technologies are required for functions such as:
- shopping cart;
- checkout;
- fraud prevention;
- security;
- customer login;
- language or regional settings;
- consent management.
Where these technologies are strictly necessary to provide a service expressly requested by the user, they are used pursuant to Section 25(2) TDDDG.
Any subsequent processing of personal data is based on the applicable provisions of Art. 6 GDPR, in particular Art. 6(1)(b), Art. 6(1)(c) or Art. 6(1)(f) GDPR depending on the purpose.
Analytics and Marketing Technologies
Analytics, advertising and marketing technologies that are not strictly necessary are activated only where you have given your consent.
The legal bases are:
- Section 25(1) TDDDG for access to or storage of information on your device; and
- Art. 6(1)(a) GDPR for the associated processing of personal data.
You may withdraw your consent at any time with effect for the future through the cookie settings available on the website.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
7. Cookie Consent Management
We currently use TinyCookie to manage cookie preferences and consent.
TinyCookie is used to:
- display the consent interface;
- record and manage consent decisions;
- communicate your preferences to connected services;
- prevent non-essential services from being activated before the required consent has been obtained.
For consent-dependent processing, the legal basis is Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
Where consent information is stored in order to demonstrate compliance with legal requirements, processing is based on Art. 6(1)(c) GDPR and, where applicable, Art. 6(1)(f) GDPR.
You can change or withdraw your choices at any time through the cookie settings.
8. Server Logs and Security Data
When you access our website, technical information may automatically be processed, including:
- IP address;
- date and time of access;
- requested page or resource;
- referrer URL;
- browser type and version;
- operating system;
- device information;
- technical error and security information.
The processing is carried out for the secure and reliable operation of the website, troubleshooting and protection against attacks and misuse.
The legal basis is Art. 6(1)(f) GDPR.
Log information is retained only for as long as required for these purposes unless longer retention is necessary for security investigations, legal obligations or the establishment, exercise or defence of legal claims.
9. Contact Forms and Email Communication
When you contact us through a contact form or by email, we process the information you provide in order to respond to your enquiry.
Where the enquiry concerns an existing or potential contract, the legal basis is Art. 6(1)(b) GDPR.
For other enquiries, processing is based on Art. 6(1)(f) GDPR.
We retain correspondence only for as long as necessary for the respective purpose, subject to applicable statutory retention obligations.
10. Orders, Customers and Contract Data
When you place an order, we may process:
- name;
- contact information;
- billing and delivery addresses;
- products ordered;
- order history;
- payment status;
- delivery information;
- communication concerning the order.
The processing is necessary for the performance of the contract and is based on Art. 6(1)(b) GDPR.
Relevant accounting and transaction records may also be processed pursuant to Art. 6(1)(c) GDPR in order to comply with statutory commercial and tax retention obligations.
11. Shipping and Delivery Providers
Where necessary for delivery, we transmit the information required for shipment to the shipping or logistics provider responsible for the delivery.
This normally includes the recipient's name, delivery address and, where required for delivery coordination, additional contact information.
The legal basis is Art. 6(1)(b) GDPR.
12. Payment Processing
Depending on the payment method selected during checkout, data necessary for payment processing are transmitted to the respective payment service provider.
The legal basis for transmitting payment information required to complete your purchase is Art. 6(1)(b) GDPR.
PayPal
Where PayPal is selected as the payment method, the required data are transmitted to:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
PayPal processes certain information under its own responsibility in accordance with its own privacy terms.
Only the information required for payment processing and associated security and fraud-prevention functions is transmitted insofar as necessary.
If additional payment providers are activated in the shop, their processing must be reflected in this Privacy Policy accordingly.
13. Newsletter
You may subscribe to our email newsletter through the website.
For this purpose, we process your email address and information required to document your subscription and consent.
Newsletter advertising is sent on the basis of your consent pursuant to Art. 6(1)(a) GDPR unless another legal basis permitted by law applies.
Where a double-opt-in procedure is used, we may also store confirmation information such as the date and time of registration and confirmation in order to demonstrate that valid consent was obtained.
You may withdraw your newsletter consent at any time with effect for the future, for example by using the unsubscribe function contained in our marketing emails.
After withdrawal, your email address will no longer be used for consent-based newsletter advertising.
Information required to demonstrate previous consent or to prevent further marketing after an objection may be retained for the period necessary to establish, exercise or defend legal claims or comply with legal obligations.
14. Social Media Links
Our website may contain links to social media platforms such as Facebook and Instagram.
A normal external link does not by itself transmit data to the respective platform merely because the page containing the link is displayed.
When you actively follow such a link, you leave our website and the privacy rules of the respective platform apply.
15. Meta Pixel and Meta Advertising Services
If and insofar as Meta advertising or measurement technologies are used, we activate non-essential Meta technologies only after you have given the required consent.
The provider for users in the European Economic Area is generally:
Meta Platforms Ireland Limited
Merrion Road
Ballsbridge
Dublin 4, D04 X2K5
Ireland
Depending on the configuration, data such as:
- IP address;
- device and browser information;
- pages viewed;
- interactions with the shop;
- transaction or conversion events;
- cookie or advertising identifiers
may be processed.
The purpose is advertising measurement, conversion tracking, audience creation and optimisation of advertising campaigns.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
Meta may process certain information for its own purposes. International transfers may occur in accordance with the applicable requirements of Chapter V GDPR.
Consent can be withdrawn at any time through the cookie settings.
16. Embedded YouTube Content
If YouTube videos are embedded on our website, data may be transmitted to Google when the video service is activated.
For users in the European Economic Area, the relevant provider is generally:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Where the embedding requires access to information on your device or the transmission of personal data for a non-essential purpose, the content is activated only after consent.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
Data may also be processed by Google companies outside the European Economic Area in accordance with applicable international transfer requirements.
17. Embedded Vimeo Content
If Vimeo videos are embedded on our website, data such as your IP address and technical information may be transmitted to Vimeo when the video is activated.
Provider:
Vimeo.com, Inc.
330 West 34th Street
New York, NY 10001
USA
Where consent is required, Vimeo content is activated only after consent.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
Transfers to the United States are carried out subject to the applicable requirements for international data transfers.
18. Google Maps
If Google Maps is used on individual pages, technical information, including your IP address, may be transmitted to Google when the map service is activated.
Provider for users in the European Economic Area:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Where consent is legally required, Google Maps is activated only after consent.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
19. Cloudflare
We may use services provided by Cloudflare for website security, network protection, content delivery and performance optimisation.
In connection with these services, Cloudflare may process technical data such as:
- IP addresses;
- request information;
- security events;
- network and traffic metadata.
Processing is based on Art. 6(1)(f) GDPR.
Our legitimate interests are the security, availability, performance and protection of the website against malicious traffic.
Cloudflare operates internationally and personal data may therefore also be processed outside the European Economic Area. Appropriate safeguards are used where required under Chapter V GDPR.
20. Technical Service Providers
We use technical service providers to maintain, secure and operate the online shop.
Such providers may obtain access to personal data only insofar as this is necessary to provide the agreed services.
Where a service provider processes personal data on our behalf, processing is governed by a data processing agreement in accordance with Art. 28 GDPR.
Service providers are not permitted to process personal data for unrelated purposes unless an independent legal basis applies.
21. International Data Transfers
Some service providers used by us operate internationally.
Where personal data are transferred to a country outside the European Economic Area, we ensure that the requirements of Chapter V GDPR are met.
Depending on the recipient and destination country, transfers may be based on:
- an adequacy decision of the European Commission;
- standard contractual clauses approved by the European Commission;
- another legally recognised transfer mechanism.
Where required, additional safeguards are applied.
22. Retention of Personal Data
We retain personal data only for as long as necessary for the purpose for which they were collected or as required by law.
In particular:
- customer-account information is generally retained while the account remains active and is deleted when no longer required, subject to statutory obligations;
- enquiry and communication data are deleted when the matter has been finally resolved unless continued retention is necessary;
- newsletter data are processed until consent is withdrawn or another applicable legal basis ends;
- consent records may be retained for as long as necessary to demonstrate lawful processing;
- order, invoice and accounting information is retained in accordance with applicable German commercial and tax-law retention requirements;
- technical log and security information is retained only for the period necessary for operation and security unless an incident or legal requirement requires longer retention.
German law may require certain commercial documents to be retained for six years and accounting records or invoices for eight years, while some documents may be subject to longer statutory periods.
After expiry of the applicable retention period, personal data are deleted or anonymised unless further storage is required for the establishment, exercise or defence of legal claims.
23. Recipients of Personal Data
Depending on the relevant processing activity, recipients of personal data may include:
- Shopify and its authorised subprocessors;
- hosting, security and infrastructure providers;
- payment providers;
- shipping and logistics companies;
- IT and technical service providers;
- newsletter or communication service providers;
- analytics and advertising providers where consent has been given;
- tax advisers, auditors and professional advisers where necessary;
- public authorities where disclosure is legally required.
Personal data are not disclosed to third parties for unrelated advertising purposes without an appropriate legal basis.
24. Your Rights
Subject to the applicable legal requirements, you have the right to:
- obtain information about personal data processed about you pursuant to Art. 15 GDPR;
- request correction of inaccurate data pursuant to Art. 16 GDPR;
- request deletion pursuant to Art. 17 GDPR;
- request restriction of processing pursuant to Art. 18 GDPR;
- receive applicable data in a structured, commonly used and machine-readable format pursuant to Art. 20 GDPR;
- object to processing based on Art. 6(1)(e) or (f) GDPR pursuant to Art. 21 GDPR;
- withdraw consent at any time pursuant to Art. 7(3) GDPR.
Withdrawal of consent has effect for the future and does not affect the lawfulness of processing carried out before withdrawal.
To exercise your rights, you may contact:
25. Right to Object
Where personal data are processed on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
Where personal data are processed for direct marketing purposes, you have the right to object to such processing at any time.
26. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
For VIRUS Sportartikel GmbH, the competent supervisory authority is generally:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Phone: +49 981 180093-0
Email: poststelle@lda.bayern.de
You may also contact another competent supervisory authority in accordance with Art. 77 GDPR.
27. SSL/TLS Encryption
This website uses SSL/TLS encryption to protect data transmitted between your device and our systems.
You can normally recognise an encrypted connection by the use of HTTPS in your browser.
28. Changes to this Privacy Policy
We may update this Privacy Policy where our services, technologies, processing activities or legal requirements change.
The current version published on this website applies.