Privacy Policy

Version: September 2026

We take the protection of your personal data seriously. In accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), we inform you below about which data we process when you visit our website and in the course of our business relationship, for what purposes and on what legal basis.

1. Controller

The controller responsible for data processing is:

Ayyildiz Hali GmbH, Computacenter Park 2-4, 50170 Kerpen-Sindorf, Germany
Represented by the Managing Directors Mustafa Yilmaz and Yilmaz Yilmaz
Phone: +49 (0) 2275 913990 · Email: info@ayyildizhali.de

2. Data Protection Officer

You can reach our external data protection officer at: HBSN GmbH, Schloßbergstraße 28, 38315 Hornburg, Germany, phone: +49 5334 9488467, email: datenschutz@hbsn-gruppe.de

3. Visiting the Website and Server Log Files

You can visit our website without providing any personal information. Each time a page is accessed, the web server automatically stores access data in server log files, in particular IP address, date and time of access, page or file requested, amount of data transferred, browser type and version, operating system and the previously visited page (referrer).

This processing serves to provide the website, ensure its smooth operation and maintain IT security. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in these purposes. Log files are deleted no later than seven days after the end of your visit, unless longer retention is required for evidentiary purposes (e.g. in the event of attacks).

Our website is hosted by an external service provider that processes the data exclusively on our behalf and in accordance with our instructions (processing on behalf pursuant to Art. 28 GDPR).

4. SSL/TLS Encryption

For security reasons, our website uses SSL/TLS encryption. You can recognise an encrypted connection by “https://” and the padlock symbol in your browser’s address bar.

5. Cookies

We only use technically necessary cookies that are required for the operation of the website, e.g. a session cookie (PHPSESSID) and cookies that store settings such as your selected language. These cookies are deleted at the end of the session or when they expire.

The legal basis is Section 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6(1)(f) GDPR; our legitimate interest lies in the technically error-free provision of the website. We do not use analytics, tracking or marketing cookies.

You can set your browser to refuse or delete cookies. In this case, not all functions of the website may be available.

6. Contacting Us

If you contact us via the contact form, email or phone, we process the information you provide (e.g. name, company, email address, phone number, content of your message and any uploaded files) in order to handle your enquiry.

The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry relates to a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). We delete the data once your enquiry has been fully dealt with, provided there are no statutory retention obligations.

7. Customer Registration (“Become a Customer”)

Via the “Become a Customer” form, we collect company name, contact person, address, country, phone number, email address, your message and proof of your business registration. We use this data to verify that you are a business customer and to set you up as a customer in our system.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). If a business relationship is established, we store your customer data for its duration and beyond that in accordance with statutory retention obligations (see clause 8). If no business relationship is established, we delete the data, including the proof of business registration, after completion of the review.

8. Business Relationship, Dealer Login and Contract Processing

In the course of the business relationship, we process the data of our customers and their contact persons (e.g. name, company, addresses, contact details, order, delivery and payment data, VAT ID number). Existing customers can enter orders directly into our system via our dealer login (B2B shop); for this purpose, we process their login data and the order data entered. The legal basis is Art. 6(1)(b) GDPR; insofar as we process data of our customers’ contact persons, Art. 6(1)(f) GDPR (legitimate interest in communicating with our business partners).

For delivery, we pass on the name, delivery address and, where applicable, phone number or email address to the commissioned transport company (parcel service or freight forwarder) insofar as this is necessary for delivery and delivery notification. For payment processing, we pass on the necessary data to the bank commissioned with the payment.

Due to commercial and tax law requirements (Section 257 HGB, Section 147 AO), we retain business records for six to ten years (Art. 6(1)(c) GDPR).

9. Fulfilment and Dropshipping

Our customers send us dropshipping orders, in particular via the dealer login, for which we ship goods directly to their end customers. We process the end customers’ data required for this purpose (in particular name and delivery address and, where applicable, phone number or email address for delivery) exclusively on behalf of and in accordance with the instructions of our customer as a processor pursuant to Art. 28 GDPR. Our respective customer is the controller of this data; we forward enquiries from end customers to them.

10. Spam Protection with Google reCAPTCHA

To protect our forms (e.g. contact form) against misuse and spam, we use Google reCAPTCHA, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). reCAPTCHA checks whether an entry is made by a human or by an automated program. For this purpose, your IP address, information about your browser and device and your behaviour on the page, among other things, are transmitted to Google.

The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting our website against spam and automated attacks. A transfer to the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework, on the basis of which an adequate level of data protection exists (Art. 45 GDPR). Further information: https://policies.google.com/privacy

11. Google Fonts

To display fonts consistently, our website uses Google Fonts provided by Google Ireland Limited. When a page is accessed, your browser loads the required fonts from Google servers; in the process, your IP address is transmitted to Google. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in a consistent and appealing presentation. The information in clause 10 applies accordingly to transfers to the USA. Further information: https://developers.google.com/fonts/faq/privacy

12. Recipients and Transfers to Third Countries

We only pass on your data insofar as this is described in this privacy policy, permitted by law or you have given your consent. Recipients may in particular be hosting and IT service providers, transport companies, banks, tax advisors and auditors as well as authorities within the scope of statutory obligations. Data is only transferred to countries outside the EU or EEA if there is a legal basis for this under Art. 44 et seq. GDPR (e.g. an adequacy decision or EU standard contractual clauses).

13. Storage Period

We only store personal data for as long as is necessary for the respective purpose or as required by statutory retention obligations. The data is then deleted or, if it is still required for other purposes, its processing is restricted.

14. Your Rights

You have the following rights with regard to your personal data:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
  • Complaint to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, www.ldi.nrw.de

To exercise your rights, an informal message to the contact details stated in clause 1 is sufficient.

15. Right to Object (Art. 21 GDPR)

Insofar as we process your data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. If we process your data for direct marketing purposes, you may object to this at any time without giving reasons.

16. No Automated Decision-Making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

17. Changes to this Privacy Policy

We will update this privacy policy if our data processing or the legal situation changes. The version published on our website applies.