Privacy Policy

Last updated: 21 September 2026

1. DATA CONTROLLER

NORTHÉ GmbH Tarpenring 14 22419 Hamburg Germany Managing Director: Björn Schwabe Email: hey@northe-artisans.com

2. GENERAL INFORMATION

We process personal data only insofar as this is necessary to provide this website, handle enquiries, process orders or comply with legal obligations. Personal data means any information that can be used to identify a natural person directly or indirectly.

3. HOSTING AND SERVER LOG DATA

This website is hosted by Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. When you access the website, the hosting provider processes data including your IP address, the date and time of access, the file or URL accessed, the referring URL, browser type, browser version, operating system and HTTP status code. This processing serves to provide the website securely and reliably and to detect and prevent misuse and attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and economical operation of our website. Where Hostinger processes data on our behalf, this is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR. Log data is deleted as soon as it is no longer required for the purposes stated, unless security incidents or statutory retention obligations require it to be stored for a longer period.

4. CONTACT AND CONTACT FORM

If you contact us by email or via the contact form, we process the information you provide, in particular your name, email address, message and any other information provided voluntarily. This information is processed for the purpose of handling and responding to your enquiry. If your enquiry relates to a contract or pre-contractual measures, the legal basis is Art. 6(1)(b) GDPR. In all other cases, processing is based on our legitimate interest in appropriate communication pursuant to Art. 6(1)(f) GDPR. Your information will be deleted once your enquiry has been fully dealt with and there are no statutory retention obligations or legitimate reasons requiring further storage.

5. CUSTOMER ACCOUNT

When you create a customer account, we process the personal, contact, address and login details you provide in order to make the account available and manage orders. The legal basis is Art. 6(1)(b) GDPR. You may request the deletion of your customer account. Information relating to completed orders will remain stored where statutory retention obligations apply.

6. ORDERS PLACED THROUGH THE ONLINE SHOP

When you place an order, we process information including your name, billing and delivery address, email address, the products ordered, order and payment information and, where applicable, other information necessary to perform the contract. This information is processed for the purposes of processing the contract, delivering the goods, issuing invoices and handling any enquiries or warranty claims on the basis of Art. 6(1)(b) GDPR. Where retention obligations under commercial or tax law apply, we additionally process the relevant data on the basis of Art. 6(1)(c) GDPR. Accounting records are generally retained for eight years and commercial or business correspondence for six years. Longer retention periods may apply in individual cases.

7. PAYMENT VIA STRIPE

We use Stripe to process card payments and, where applicable, other payment methods offered during checkout. For customers in the European Economic Area, the provider is Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. If you use a payment method provided by Stripe during checkout, the data required to process the payment is transmitted to Stripe. This may include your name, billing and delivery address, email address, order value, currency, order number, payment information, IP address and technical device and browser data. Stripe also processes data for authentication, fraud prevention, risk assessment and compliance with its own legal obligations. The data required to process the payment is transmitted for the performance of the contract pursuant to Art. 6(1)(b) GDPR. Insofar as the processing serves to secure the payment transaction and prevent fraud, it is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in secure payment processing and the prevention of payment defaults and misuse. Access to information on your device required for the payment method you have selected takes place as part of the expressly requested payment transaction in accordance with Section 25(2), no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). Stripe may process data under its own responsibility and may involve affiliated companies and subcontractors. This may include processing outside the European Union or the European Economic Area. Further information can be found in Stripe’s Privacy Policy.

8. SHIPPING VIA UPS

To deliver your order, we transmit the necessary information to United Parcel Service Deutschland S.à r.l. & Co. OHG (UPS). This includes your name, delivery address and, where required for delivery or requested by you, your email address and telephone number, as well as information relating to the shipment. The information is transmitted for the performance of the contract pursuant to Art. 6(1)(b) GDPR. Further information can be found in the UPS Privacy Notice.

9. TECHNICALLY NECESSARY COOKIES AND SIMILAR TECHNOLOGIES

We use only technically necessary cookies and comparable technologies that are required for the website and online shop functions you request. These include a cookie for storing the selected language (pll_language), WooCommerce cookies for the shopping cart and session (in particular woocommerce_cart_hash, woocommerce_items_in_cart and wp_woocommerce_session_*) and the cookies and security features required for a payment transaction processed via Stripe. Stripe is embedded only on pages and in functions on which payment processing is requested or prepared. In this context, the cookies _stripe_mid and _stripe_sid may be used in particular. They serve to provide secure payment processing, authentication and fraud prevention. Information is stored on or accessed from your device in accordance with Section 25(2), no. 2 TDDDG. The subsequent processing of personal data is based on Art. 6(1)(b) GDPR where it is necessary to perform a contract requested by you and, in all other cases, on Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a secure and functional website and online shop. Technologies requiring consent pursuant to Section 25(1) TDDDG, in particular technologies used for analytics, marketing or profiling purposes, are not currently used.

10. LOCALLY HOSTED WEB FONTS

The web fonts used on this website are hosted locally on our own server. Retrieving the fonts therefore does not establish a connection to Google Fonts, Adobe Fonts or any other external font provider.

11. INSTAGRAM

Our website contains a link to our Instagram profile. For users in the European Economic Area, the provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. As long as you do not open the link, no data is transmitted from our website to Instagram merely as a result of the external link. Once you click the link, you leave our website; Meta is responsible for the subsequent processing of your data. Further information can be found in Instagram’s Privacy Policy.

12. RECIPIENTS AND TRANSFERS TO THIRD COUNTRIES

We disclose personal data only where this is necessary to perform a contract, where there is a legal obligation to do so, where you have given your consent or where the disclosure is based on a legitimate interest. Recipients may include hosting, IT, payment, shipping, tax and legal service providers, as well as public authorities. Where service providers process data in a country outside the European Union or the European Economic Area, we ensure compliance with the requirements of Art. 44 et seq. GDPR, for example by relying on an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

13. STORAGE PERIOD

We store personal data only for as long as it is required for the respective purpose. The data is subsequently deleted or anonymised unless statutory retention obligations, the establishment, exercise or defence of legal claims or other legally permissible grounds require it to be stored for a longer period.

14. YOUR RIGHTS

Subject to the applicable legal requirements, you have the following rights in particular:
  • the right to obtain information about your personal data being processed (Art. 15 GDPR),
  • the right to have inaccurate data corrected (Art. 16 GDPR),
  • the right to have your data deleted (Art. 17 GDPR),
  • the right to restrict processing (Art. 18 GDPR),
  • the right to data portability (Art. 20 GDPR),
  • the right to object to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR),
  • the right to withdraw consent with effect for the future (Art. 7(3) GDPR).
To exercise your rights, simply send a message to hey@northe-artisans.com.

15. RIGHT TO LODGE A COMPLAINT

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: The Hamburg Commissioner for Data Protection and Freedom of Information Ludwig-Erhard-Straße 22 20459 Hamburg Germany Telephone: +49 40 42854-4040 Email: mailbox@datenschutz.hamburg.de Website: datenschutz-hamburg.de

16. DATA SECURITY

We take appropriate technical and organisational measures to protect personal data against loss, manipulation and unauthorised access. Data transmitted through this website is encrypted using TLS/SSL.

17. UPDATES TO THIS PRIVACY POLICY

We update this Privacy Policy whenever changes are made to the website, the services used or the applicable legal requirements. The version published on this website at the relevant time shall apply.