Privacy policy
- Home
- Privacy policy
1. Controller
The controller responsible for data processing on this website is:
Arsef Kopalian Import & Export e.K.
Mühlenhagen 40, 20539 Hamburg, Germany
Phone: +49 (0)40 25 82 61
Email: info@kopalian.de
Represented by: Arsef Kopalian
2. Hosting
This website is hosted by IONOS (IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany). The provider processes data technically required for the secure and efficient provision of the website, in particular connection and server log data. The legal basis is Art. 6(1)(f) GDPR. Where IONOS processes data on our behalf, this is carried out in accordance with Art. 28 GDPR.
3. Server logs and protection against misuse
When the website is accessed, the hosting provider may process technically required server log data, in particular the page or file accessed, date and time, volume of data transferred, retrieval status, browser type and version, operating system, referrer URL and IP address. Processing is carried out to provide, stabilise and secure the website on the basis of Art. 6(1)(f) GDPR. Our legitimate interest is the secure and trouble-free operation of the website.
To protect the form against automated misuse, the IP address is converted server-side into a value that cannot be read directly (HMAC) using a secret key. Together with the times of form attempts, this value is used solely to allow no more than five attempts within one hour. Entries are no longer taken into account after the one-hour window has expired; expired files are technically removed during subsequent form access. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is preventing spam and maintaining form availability.
4. Contact and enquiry forms
If you contact us via form, email or phone, we process the data you provide (e.g. name, company, email address, optionally phone number, details of the goods or part sought, message and any uploaded files) to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where pre-contractual measures or a contract are concerned, and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is the appropriate handling of business enquiries.
The details marked as required in the form are needed so that we can assign and answer your enquiry and assess the goods concerned or the part sought. Without these details, the form cannot be submitted and the enquiry cannot be handled by this route. Optional details are voluntary.
5. File uploads
You may voluntarily submit photos or data sheets as JPG, PNG or PDF. For this purpose, the web server stores a randomly named working copy outside the public web area. This working copy is deleted after the immediate delivery attempt. The file is also transmitted as an attachment to the enquiry email and remains stored there in accordance with the deletion criteria applicable to the enquiry. Please submit only necessary files and remove any personal content and metadata that is not needed. The legal basis is Art. 6(1)(b) or (f) GDPR.
6. Transmission of form data
Form enquiries are processed on the web server and transmitted in encrypted form via IONOS's authenticated SMTP service to info@kopalian.de. Recipients are the operator of this website and IONOS as the technical hosting and email service provider. Transmission from the browser to the website is encrypted via HTTPS.
7. Cookies and local storage
This website currently sets no cookies and stores no data in local storage or session storage. In particular, no analytics, marketing or tracking services are loaded when a page is accessed. The language is determined solely by the URL accessed and is not stored in the browser. Therefore, no consent banner is currently required.
Should services requiring consent be integrated in future, the required consent will be obtained before they are activated and this policy will be updated.
8. Fonts
We use locally hosted fonts. No connection is made to third-party servers such as Google Fonts to deliver the fonts.
9. Maps / route planning
No map is embedded or loaded automatically on this website. Only when you click “Plan route” do you leave our website and open OpenStreetMap, a service of the OpenStreetMap Foundation based in the United Kingdom, in a new tab. At that point, at least your IP address, time and browser information are technically transmitted to OpenStreetMap. OpenStreetMap’s privacy policy then applies. OpenStreetMap privacy policy .
10. Recipients and transfers outside the EU/EEA
Recipients of personal data are, where necessary, the website operator, IONOS for hosting and email delivery, and bodies entitled by law. When OpenStreetMap is actively opened, the OpenStreetMap Foundation also receives the connection data described in section 9. Where data is processed outside the EU/EEA, this takes place only in compliance with the requirements of Art. 44 et seq. GDPR.
11. Storage period and automated decisions
Enquiry and contact data, including email attachments, are deleted once the enquiry has been finally handled and the data is no longer required for an existing or prospective contractual relationship or for the establishment, exercise or defence of legal claims. Statutory retention obligations remain unaffected; in that case, processing is restricted to the respective retention purpose. The specific period therefore depends on the nature and course of the individual enquiry. Server log data is subject to the purpose-specific deletion periods set by the hosting provider.
No solely automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
12. Your rights
Subject to the statutory requirements, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20 GDPR). Where processing is based on Art. 6(1)(f) GDPR, you may object to the processing at any time on grounds relating to your particular situation (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future.
13. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement. For a company established in Hamburg, the Hamburg Commissioner for Data Protection and Freedom of Information is the competent supervisory authority.
14. Security
We take appropriate technical and organisational measures to protect your data. These include HTTPS, an access-restricted form backend, misuse protection and size, number and type checks for uploads. Absolute protection during data transmission cannot be guaranteed technically.