Privacy policy
Last updated: 24 September 2026
ANATOLO, a trading name of [BEDRIJFSNAAM], handles your personal data with care. This policy explains the data we process when you visit anatolo.nl, anatolo.de or anatolo.com or place an order, why we process it, how long we retain it and your rights. We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act.
1. Data controller
[BEDRIJFSNAAM], [ADRES], the Netherlands; Chamber of Commerce number [KVK]; email [E-MAIL]; telephone [TELEFOON]. We have not appointed a data protection officer because we are not required to do so. Contact [E-MAIL] with any privacy questions.
2. Data we process and why
2.1 Website visits: server logs and security
When you visit, our Shopify platform automatically processes technical information: IP address, date and time, requested page, browser and operating system, and referring website. The purposes are displaying the website, protecting it against misuse and analysing faults. Legal basis: legitimate interests, Article 6(1)(f) GDPR. Logs are deleted or anonymised within 30 days unless needed for a security investigation.
2.2 Orders and customer accounts
To fulfil your order, we process your name, billing and delivery addresses, email address, telephone number for delivery notifications, ordered products, order number, payment method and status (not full card details), and correspondence. If you create an account, we also retain your encrypted password and order history. Purposes: performing the contract, delivery, invoicing, customer service, warranty claims and returns. Legal bases: contract performance, Article 6(1)(b) GDPR, and legal record-keeping obligations, Article 6(1)(c) GDPR. Invoice and order records are retained for 7 years under the Dutch tax record-keeping obligation in Article 52 AWR. Accounts are retained until you delete them or after 3 years of inactivity; customer-service correspondence for 2 years after resolution.
2.3 Payments
Payments are handled by the providers below. They receive the information needed for payment: name, email address, amount, order number and, depending on the method, bank or card details entered directly with them. They act as independent controllers for payment processing and publish their own privacy notices.
Shopify Payments (iDEAL, credit card, Bancontact, giropay): Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, Ireland. Processing is through Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Privacy: shopify.com/legal/privacy and stripe.com/privacy.
PayPal: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. Privacy: paypal.com/nl/legalhub/privacy-full.
Klarna (pay later, instalments and direct payment): Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. For deferred or instalment payments, Klarna assesses creditworthiness and may obtain information from credit reference agencies. The legal bases are contract performance and Klarna’s legitimate interest in preventing non-payment. Privacy: klarna.com/nl/privacy.
The legal basis for sharing information with payment providers is contract performance, Article 6(1)(b) GDPR.
2.4 Shipping
For delivery, we share your name and delivery address, and your email address and telephone number for notifications and scheduling, with DPD (DPD Nederland B.V. and, for Germany, DPD Deutschland GmbH, Wailandtstraße 1, 63741 Aschaffenburg) through Sendcloud (Sendcloud B.V., Stadhuisplein 10, 5611 EM Eindhoven). Legal basis: contract performance, Article 6(1)(b) GDPR. Email and SMS delivery notifications are based on our and your legitimate interests in a smooth delivery, Article 6(1)(f) GDPR. You may object to delivery notifications via [E-MAIL].
2.5 Customer service and chat
If you contact us by email or through Shopify Inbox chat, we process your name, contact details and message to answer your question. Legal bases: contract performance or pre-contractual steps, Article 6(1)(b) GDPR, and legitimate interests in good customer service, Article 6(1)(f) GDPR. Retention: 2 years after resolution.
2.6 Newsletter and email marketing
With your consent, we send offers, new products and care advice through Shopify Email, using your email address and first name. We measure opens and link clicks to improve the newsletter. Legal basis: consent, Article 6(1)(a) GDPR and Article 11.7 of the Dutch Telecommunications Act. We may inform existing customers about similar products without prior consent, providing a simple opt-out when collecting the address and in every email. You may withdraw consent through any unsubscribe link or [E-MAIL]. We retain data until you unsubscribe, then keep your email address on a suppression list for up to 3 years to avoid contacting you again.
2.7 Abandoned baskets
If you enter your email address during checkout but do not complete the order, we may send one or two reminders only if you agreed to them. Legal basis: consent, Article 6(1)(a) GDPR. Every email includes an unsubscribe option.
2.8 Fraud prevention
Shopify analyses orders for fraud risk, such as a mismatch in IP country or previous chargebacks. Legal basis: legitimate interests in preventing fraud, Article 6(1)(f) GDPR. We do not make solely automated decisions with legal effects; suspicious orders are manually reviewed.
2.9 Cookies, analytics and advertising
We use cookies and similar technologies. Necessary cookies for the basket, login, security and cookie preferences are used on the basis of legitimate interests. All other cookies require consent through our banner, under Article 11.7a of the Dutch Telecommunications Act and Article 6(1)(a) GDPR. With consent, we use:
Shopify Analytics (Shopify International Limited, Ireland) for shop traffic and sales statistics.
Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for website analysis with a shortened IP address. Google LLC in the USA may process data under the EU–US Data Privacy Framework. Google retention: 14 months.
Google Ads (Google Ireland Limited) for conversion measurement and remarketing in Google Search and Shopping. We use Google Consent Mode so no cookies are placed without consent.
Meta Pixel and Conversions API (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland) for conversion measurement, audience creation and remarketing on Facebook and Instagram. The Conversions API sends events, such as purchases, from the server to Meta only after consent; data is hashed before transmission. Meta may transfer data to Meta Platforms, Inc. in the USA under the EU–US Data Privacy Framework. We and Meta are joint controllers for collecting events under Article 26 GDPR. The arrangement is available at facebook.com/legal/controller_addendum.
Our cookie policy explains individual retention periods and how to change your choice. You can withdraw consent at any time through “Cookie settings” at the bottom of each page.
2.10 Social media
We have Instagram and Facebook pages. When you visit them, Meta processes data under its own policy. We are joint controllers with Meta for page statistics (“Insights”). Our website does not load social plugins that transmit data without your click.
3. Recipients and processors
We share personal data only with parties needed to provide our services and only as necessary:
• Shopify International Limited (Ireland) and Shopify Inc. (Canada), for shop hosting, order processing, accounts, email, chat and analytics. Shopify is a processor under a data processing agreement. Transfers to Canada rely on the European Commission’s adequacy decision; transfers to the USA rely on the EU–US Data Privacy Framework and/or standard contractual clauses.
• Payment providers (section 2.3), carrier and shipping platform (section 2.4).
• Our bookkeeper/accountant and, where needed, legal advisers bound by confidentiality.
• Google and Meta marketing services (section 2.9), only with your consent.
• Public authorities where required by law.
We never sell your data to third parties.
4. Transfers outside the EEA
Some providers process data outside the European Economic Area, including Canada and the USA. We ensure appropriate safeguards: an adequacy decision for Canada, EU–US Data Privacy Framework certification for Google, Meta, Shopify Inc. and Stripe, or the European Commission’s standard contractual clauses with additional measures. Request a copy of the safeguards at [E-MAIL].
5. Security
Our website uses TLS encryption (https). Only PCI-DSS-certified payment providers process payment data; we do not store complete card numbers. Customer-data access is limited to staff who need it for their work and is protected by two-factor authentication.
6. Your rights
You may access, correct or erase your personal data, restrict processing, obtain portability of data you provided, and object to processing based on legitimate interests, including direct marketing. You may withdraw consent at any time without affecting earlier lawful processing. Send requests to [E-MAIL]; we respond within one month. To prevent misuse, we may ask you to verify your identity, for example by replying from your order email address. You may complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or, if you live in Germany, the authority for your federal state.
7. Children
Our shop is not aimed at people under 18 and we do not knowingly collect children’s data.
8. Changes
We may update this policy, for example when introducing new services. The current version is always on our website. For significant changes, we inform account holders by email.