Privacy Policy
As of 1 September 2026
This privacy policy explains how personal data is processed when you visit our website and online shop, and in connection with orders, customer accounts, enquiries, payments, deliveries and other business contacts.
1. Controller and data protection contact
The controller within the meaning of the General Data Protection Regulation ("GDPR") is:
Lasertack GmbH, Kasseler Straße 62, 34277 Fuldabrück, Germany. Telephone: +49 561 92017707, email: info@lasertack.com. Managing director: Alex Schatalow.
Please address data protection enquiries to info@lasertack.com, or by post marked "Datenschutz".
2. Principles of processing
Personal data is any information relating to an identified or identifiable person. We process it only where there is a legal basis for doing so, in particular to initiate and perform a contract (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR), on the basis of legitimate interests (Art. 6(1)(f) GDPR) or with your consent (Art. 6(1)(a) GDPR). Consent may be withdrawn at any time with effect for the future.
We collect only the data required for the respective purpose, limit access to the people who need it for their work, and erase or anonymise data once the purpose and any statutory retention grounds no longer apply.
3. Hosting, content delivery and server logs
The shop is delivered, protected and accelerated (content delivery network, web application firewall) and image and file downloads are provided via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Our servers for the shop backend, inventory management and email are hosted by netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe) in a data centre in Germany.
A data processing agreement is in place with both providers. When Cloudflare is used, data, in particular your IP address, may be transferred to the USA; such transfers are safeguarded by the EU Standard Contractual Clauses. The legal basis is our legitimate interest in secure and efficient operation (Art. 6(1)(f) GDPR).
When you access the website, connection data required for technical operation is processed: IP address, date and time, the URL requested, the referrer URL, the volume of data transferred, HTTP status, browser type and version, operating system, and error and security events. This data serves technical delivery, IT security, attack detection and error analysis, and is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR. Log data is stored only for as long as required for operation and security; longer retention occurs only in connection with a specific security incident or a legal obligation.
4. Cookies and local storage
This shop uses only technically necessary cookies and local storage to maintain your shopping cart, your sign-in and your session while you shop: a cart identifier, an authentication token and the colour scheme you have chosen. No cookies are used for analytics, tracking or advertising, and no user profiles are created. As this storage is strictly necessary, it does not require consent (§ 25(2) TDDDG, Art. 6(1)(f) GDPR).
The statistical evaluation described in section 5 works without cookies and stores nothing on your device. There is therefore no consent banner: there would be nothing to consent to.
When you go to the checkout and choose a payment method, the payment provider concerned loads its own scripts, which may set cookies that are technically required for processing and fraud prevention. These are loaded on the checkout page only, not during the rest of your visit.
You can delete or block cookies and local storage in your browser at any time. This may restrict technically necessary functions such as the shopping cart.
5. Statistics and audience measurement
To understand which pages of our shop are used, we run Umami. We host this software ourselves on our server in Germany. No data is passed to third parties and no data is transferred to third countries.
Umami stores no cookies and no identifiers on your device. It records the page visited, the referring page, screen size, browser, operating system, the country derived from your IP address and technical measurements of how quickly the page loaded. The IP address itself is not stored: together with your browser signature and a random value that changes daily, it goes into a checksum that can recognise a visit only within the same day. After that no attribution is possible. No user profiles are created, there is no recognition across devices or across websites, and the data is evaluated only in aggregate.
We also record the total of completed orders, when an item is added to the basket (item number, quantity and line value), which step of the checkout was reached (address, delivery or payment) and technical error messages from the website, in each case without an order number, name or contact details. We do not record page views of your customer account or your order pages. There we record only which section was opened (orders, quotes, invoices, deliveries or profile), whether a document was downloaded (the document TYPE only, such as invoice or delivery note) and whether a repeat order was started (the number of items only). No order numbers, document numbers or file names are transmitted.
The pages of your customer account and your orders are excluded from the measurement.
As nothing is stored on or read from your device, no consent under § 25 TDDDG is required for this. The legal basis for the processing is our legitimate interest in a statistical evaluation of usage in order to improve what we offer (Art. 6(1)(f) GDPR). You may object to this processing at any time (Art. 21 GDPR). If your browser sends the "Do Not Track" setting, no measurement takes place.
6. Online shop, orders and customer account
When you place an order we process in particular your name, billing and delivery address, email address, telephone number where required, company and VAT data, the products ordered, prices, payment status, shipping information, communications, IP address and time stamps. For restricted laser products we may additionally process professional or institutional evidence, your function, the end use, the end recipient and information required under export control law.
The purposes are contract formation, payment and delivery, customer service, complaints, reversals, abuse prevention and export control review. The legal bases are Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR for tax, commercial and foreign trade obligations, and Art. 6(1)(f) GDPR for fraud prevention, IT security and the establishment or defence of legal claims.
In the customer account we process access credentials in hashed form, the account and order history, saved addresses and preferences. You may request deletion of the account; order and accounting records subject to retention obligations are then restricted rather than erased. Mandatory fields are marked as such. Without the information required for the contract or for an identity, end-use or export check, we may be unable to accept or perform an order.
7. Payment processing
When you select a payment method we transmit the data required for payment to the relevant payment service provider. This may include name, address, email address, IP address, order number, amount, currency, payment status and method-specific data. We do not receive complete card or account credentials where these are entered directly with the payment provider.
- Card, Apple Pay and Google Pay through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland.
- PayPal through PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.
- Advance payment by bank transfer: no data is passed to a payment provider; we send you our bank details with the order confirmation.
The transfer is made to perform the contract (Art. 6(1)(b) GDPR) and, where necessary, for fraud and abuse prevention (Art. 6(1)(f) GDPR). The providers process certain data under their own responsibility and may carry out identity or credit checks; their own privacy notices apply in addition. Payment data may be retained to comply with commercial and tax obligations.
8. Shipping, customs and delivery communications
For delivery we transmit the necessary data to the carrier engaged, UPS (United Parcel Service Deutschland S.à r.l. & Co. OHG) or DHL (DHL Paket GmbH). This usually comprises name, delivery address and consignment data and, where required for notification or delivery, an email address or telephone number. The legal basis is Art. 6(1)(b) GDPR.
For deliveries to third countries we process the information required by law for export, customs and import and transmit it to the competent authorities and customs service providers (Art. 6(1)(c) GDPR).
9. VAT validation (business customers only)
If you provide a VAT identification number when ordering, we verify its validity via the European Commission's VIES system. The VAT identification number is transmitted to that service. This serves to fulfil our tax obligations (Art. 6(1)(c) GDPR).
10. Order processing and accounting
Order, customer and invoice data are processed in our own inventory management and ERP system (ERPNext), which runs on our own infrastructure in Germany. The processing serves order handling, invoicing and accounting (Art. 6(1)(b) and (c) GDPR).
11. Contact, quotations and support
If you contact us by email, telephone, contact form or a product enquiry, we process your contact details, the content of the enquiry, communication metadata and, where applicable, customer, product or order data. The purpose is to handle and document your enquiry. The legal basis is Art. 6(1)(b) GDPR for pre-contractual or contractual matters, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in efficient communication and documentation.
Enquiries are erased once they have been finally dealt with and no retention or evidentiary grounds apply. Business correspondence may be retained for the periods required by commercial and tax law.
12. Recipients and processors
Within Lasertack, access is granted only to people who need it for their work. External recipients are in particular hosting and IT service providers, payment service providers, banks, shipping and customs service providers, tax advisers, legal advisers, auditors and public authorities.
Service providers that process data on our behalf are contractually bound and monitored under Art. 28 GDPR. Independent controllers process data under their own privacy notices. We do not disclose data for third-party advertising purposes and we do not sell personal data.
13. Transfers to third countries
Some service providers or their sub-processors may process data outside the European Economic Area. A transfer takes place only under the conditions of Art. 44 et seq. GDPR, in particular on the basis of an adequacy decision, appropriate safeguards such as the European Commission's Standard Contractual Clauses, or a statutory derogation. For certified US companies, the adequacy decision on the EU-US Data Privacy Framework may be relied on.
Despite such safeguards, third countries may provide for different powers of official access and lower standards of legal protection.
14. Retention periods
We store personal data only for as long as required for the respective purpose. It is then erased or anonymised unless statutory retention obligations, legitimate evidentiary interests, pending legal disputes or security grounds require otherwise.
- Contract, accounting and invoice records: in line with commercial and tax retention periods, currently typically up to eight or ten years depending on the type of document.
- Business letters and contract-related communication: as a rule six years where subject to retention.
- Customer account: until deletion or until the purpose no longer applies; records subject to retention obligations are kept in restricted form.
- Statistical data: aggregated and without personal reference, see section 5.
15. Your data protection rights
Subject to the statutory requirements you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and withdrawal of consent with effect for the future (Art. 7(3)).
Objection. Where we process data on the basis of legitimate interests under Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims. You may object to direct marketing at any time without giving reasons.
To exercise your rights, a message to the contact details in section 1 is sufficient. To protect your data we may require reasonable verification of your identity.
16. Right to complain and supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for Lasertack is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, https://datenschutz.hessen.de
You are also welcome to contact us first; this does not restrict your right to complain.
17. Automated decisions, security and changes
We do not take decisions based solely on automated processing within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you. Payment and fraud prevention providers may carry out their own automated checks; their privacy notices provide information on this.
We take appropriate technical and organisational measures to protect personal data, in particular access controls, encryption in transit, authorisation concepts, backups and procedures for handling security incidents. Absolute protection for internet transmissions cannot be guaranteed.
We update this privacy policy when processing operations, providers or the legal position change. The version published on the website is the applicable one.