Privacy Policy and Data Protection Notice

Privacy Policy

Last updated: 02.08.2026

Table of Contents

  1. Controller, Contact, Supervisory Authority
  2. General Information and Definitions
  3. Legal Bases for Processing
  4. Recipients and Categories of Recipients
  5. Transfers to Third Countries
  6. Data Security
  7. Hosting and Server Log Files
  8. Contact Form, E-mail and Telephone
  9. Google reCAPTCHA
  10. Customer Account
  11. Comment Function
  12. Orders and Contract Processing
  13. Payment Methods and Payment Service Providers
  14. PayPal
  15. Shipping and Delivery Status Notifications
  16. External Inventory Management System
  17. Newsletter
  18. Direct Advertising to Existing Customers
  19. Customer Reviews
  20. Cookies and Consent Management
  21. Google Analytics
  22. Google Ads – Conversion Tracking and Remarketing
  23. Google AdSense
  24. Meta (Facebook) Remarketing and Custom Audiences
  25. Facebook Plug-ins
  26. YouTube
  27. Google Maps
  28. Fonts and Local Resources
  29. WebChat
  30. WhatsApp
  31. Social Media Presences
  32. Automated Decision-Making and Profiling
  33. Use by Minors
  34. Retention Period
  35. Rights of the Data Subject
  36. Right to Object under Art. 21 GDPR
  37. Right to Lodge a Complaint with a Supervisory Authority
  38. Currency and Amendment of this Privacy Policy

1. Controller, Contact, Supervisory Authority

The controller within the meaning of the General Data Protection Regulation (GDPR), other data protection laws applicable in the Member States of the European Union, and other provisions relating to data protection is:

Euro Coral
Passauer Str. 12
84359 Simbach am Inn
Germany

Telephone: +49 (0) 8571 983 4686
E-mail: Euro Coral e-mail address
Website: www.eurocorals.com

The person authorised to represent the company and other provider details can be found in our legal notice (Impressum).

Data Protection Officer

We have not appointed a data protection officer, as the legal requirements for doing so are not met (Art. 37 GDPR, § 38(1) BDSG). For all data protection matters, to exercise your rights, and for information requests, please contact us using the details above. We will handle your request personally.

Competent Data Protection Supervisory Authority

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, 91522 Ansbach
Telephone: +49 (0) 981 180093-0
www.lda.bayern.de


2. General Information and Definitions

We take the protection of your personal data seriously and process it exclusively on the basis of the GDPR, the Federal Data Protection Act (BDSG), the Telecommunications Digital Services Data Protection Act (TDDDG), and all other applicable provisions.

“Personal data” means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR). The other terms used in this notice — processing, controller, processor, consent, profiling, pseudonymisation — correspond to the definitions in Art. 4 GDPR.

Requirement to Provide Data

Unless otherwise stated below, the provision of your personal data is neither legally nor contractually required, nor is it necessary for entering into a contract. You are under no obligation to provide such data. Failure to provide data has no consequences in this case. Any deviations are expressly indicated for the respective processing activities.


3. Legal Bases for Processing

We base the processing of your personal data in particular on the following legal grounds:

  • Art. 6(1)(a) GDPR – your consent, revocable at any time with effect for the future;
  • Art. 6(1)(b) GDPR – performance of a contract or implementation of pre-contractual measures;
  • Art. 6(1)(c) GDPR – compliance with legal obligations, in particular commercial, tax and anti-money-laundering obligations;
  • Art. 6(1)(f) GDPR – safeguarding our legitimate interests or those of third parties, provided your interests, fundamental rights and freedoms do not override them;
  • Section 25(1) TDDDG – consent to storing information on your terminal equipment or accessing information already stored there (cookies, LocalStorage, pixels, SDKs);
  • Section 25(2) TDDDG – statutory exemption for strictly necessary technologies;
  • Section 7(3) UWG – e-mail advertising to existing customers.

Where processing is based on a legitimate interest, we expressly identify that interest for the respective processing activity.


4. Recipients and Categories of Recipients

Your data will not be disclosed to third parties without your express consent, unless this is necessary to perform the contract or is legally permitted or required. This does not apply to our service partners whom we require to process the contractual relationship, or to service providers we engage under a data processing agreement.

Recipients may belong to the following categories:

  • Shipping, logistics and freight service providers, as well as specialist couriers;
  • Payment service providers, banks and credit card companies;
  • Debt collection agencies, lawyers, credit reference agencies;
  • Providers of shop, inventory management, ERP and CRM systems;
  • Web hosting, backup, maintenance and IT security service providers;
  • Providers of e-mail dispatch, web analytics, online marketing, chat and messenger services;
  • Tax advisors and auditors;
  • Dropshipping suppliers and manufacturers, insofar as necessary for delivery;
  • Customs, veterinary, species protection, tax and law enforcement authorities, as well as courts, in the context of statutory obligations.

Insofar as service providers process personal data on our instructions, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR. These service providers are contractually obliged to use your data exclusively for the services we have commissioned and not for their own purposes.

In all cases, we strictly comply with statutory requirements. The scope of data transmission is limited to the minimum necessary.


5. Transfers to Third Countries

Personal data is transferred to countries outside the European Union or the European Economic Area (“third countries”) only where this is necessary to perform the contract, is required by law, you have given your consent, or it is based on our legitimate interests — and always in compliance with Art. 44 et seq. GDPR.

We base such transfers on:

  • an adequacy decision of the European Commission under Art. 45 GDPR, in particular the EU-U.S. Data Privacy Framework (DPF) of 10 July 2023, provided the US recipient is certified under it. Certification can be verified at https://www.dataprivacyframework.gov/list;
  • alternatively, the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914), together with a transfer impact assessment and supplementary technical and organisational safeguards (Art. 46(2)(c) GDPR);
  • otherwise, exceptions under Art. 49 GDPR, in particular your explicit consent under Art. 49(1)(a) GDPR.

Please note: Despite these measures, access by government authorities to your data in third countries — particularly the USA — cannot be entirely excluded. There may be no level of legal protection comparable to that in the European Union, and no equivalent judicial enforceability of your rights. Insofar as we obtain your consent, you expressly consent to this risk as well.

A copy of the safeguards used in each case is available on request using the contact details set out in Section 1.


6. Data Security

We take appropriate technical and organisational measures in accordance with Art. 24, 25 and 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include, in particular:

  • end-to-end TLS/SSL encryption of the website, indicated by “https://” in the address bar and the lock symbol in your browser;
  • physical, system and access controls, together with a graduated role and permission system;
  • pseudonymisation and data minimisation, privacy by design and privacy-friendly default settings;
  • encrypted data backups and documented recovery procedures;
  • regular review, assessment and evaluation of the effectiveness of these measures;
  • binding all persons involved in data processing to confidentiality.

Despite all diligence, data transmission over the internet cannot be made completely secure; complete protection against third-party access is technically not possible.


7. Hosting and Server Log Files

Hosting. Our website is hosted by an external service provider (web host) within the European Union. The host processes, on our behalf, all data arising in connection with the use of the website. The legal basis is Art. 6(1)(b) GDPR as well as Art. 6(1)(f) GDPR (legitimate interest in a secure, fast and efficient provision of our online offering). A data processing agreement pursuant to Art. 28 GDPR is in place with the host.

Server log files. You can visit our website without providing any personal information. Each time our website is accessed, usage data is transmitted by your internet browser and stored in log files (server log files). This data includes:

  • the name and URL of the page accessed, as well as the referrer URL,
  • the date and time of access,
  • the amount of data transferred and the HTTP status code,
  • the browser type and version used, operating system, and language settings,
  • the IP address and the requesting provider.

This data is used solely to ensure the trouble-free and secure operation of our website, for error analysis, to defend against attacks, and to improve our offering.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the functionality and IT security of our online offering.

Retention period: 7 days; in the case of security-relevant incidents, until the incident has been fully investigated.

This data is not combined with other data sources or evaluated for marketing purposes. We do not attribute this data to any specific person.


8. Contact Form, E-mail and Telephone

When using the contact form or contacting us by e-mail or telephone, we collect your personal data (in particular your name, e-mail address, and, where applicable, telephone number, order number, and message text) only to the extent you provide it. We additionally store the date and time of the request.

Data processing serves the purpose of contacting you and processing and answering your enquiry, including any follow-up questions.

Legal basis: Art. 6(1)(b) GDPR, insofar as the enquiry serves to initiate or perform a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries) or Art. 6(1)(a) GDPR, insofar as you have consented to the processing by submitting your message.

You may withdraw any consent given at any time by notifying us, without affecting the lawfulness of processing carried out on the basis of the consent before its withdrawal. We use your e-mail address exclusively to process your enquiry.

Your data will be deleted as soon as the underlying matter has been conclusively resolved and you have not consented to further processing and use, unless statutory retention obligations preclude this.


9. Google reCAPTCHA

We use the reCAPTCHA service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) on our website.

This query serves to distinguish whether an input is made by a human or by automated, machine processing, and protects our forms against spam and misuse.

The query involves sending Google your IP address and, where applicable, other data required by Google for the reCAPTCHA service. In particular, the following is processed: IP address, time spent on the page, mouse and keyboard movements, device and browser information, and cookies or comparable identifiers. Your IP address is first shortened by Google within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. The IP address transmitted by your browser as part of reCAPTCHA is not merged with other Google data.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. reCAPTCHA is only loaded after you have given your consent via our consent banner. You may withdraw your consent at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.

Third-country transfer: A transfer to the USA cannot be excluded; the safeguards described in Section 5 apply.

Further information and Google’s privacy policy are available at https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.


10. Customer Account

When you open a customer account, we collect your personal data to the extent provided there. This regularly includes your title, first and last name, where applicable your company name and VAT identification number, billing and delivery address, e-mail address, a password of your choosing (stored exclusively in encrypted form), and, where applicable, telephone number and date of birth. We also store your order history and any preferences you have saved.

Data processing serves the purpose of improving your shopping experience and simplifying order processing.

Legal basis: Art. 6(1)(b) GDPR for the usage agreement relating to the customer account, and Art. 6(1)(a) GDPR insofar as purely optional convenience features are concerned. You may withdraw any consent given at any time by notifying us, without affecting the lawfulness of processing carried out before the withdrawal.

You may have your customer account deleted at any time. After deletion, your data will be removed, unless statutory retention obligations or outstanding claims preclude this; in such cases, the data concerned will be blocked from further use and deleted once the relevant periods have expired.

Please choose a strong password used exclusively for our website and do not disclose your login details to third parties.


11. Comment Function

When commenting on an article or post, we collect your personal data (name or pseudonym, e-mail address, comment text) only to the extent you provide it. In addition, to prevent spam and unlawful content, we store your IP address and the time the comment was created.

This processing serves the purpose of enabling comments to be made and displayed.

Legal basis: Art. 6(1)(a) GDPR for the publication of the comment — by submitting it, you consent to the processing of the data transmitted; Art. 6(1)(f) GDPR for storing the IP address and timestamp (legitimate interest in preventing misuse, securing evidence, and limiting liability as a service provider).

You may withdraw your consent at any time by notifying us, without affecting the lawfulness of processing carried out before the withdrawal. Your comment and the associated personal data will then be deleted.

Upon publication, only the name or pseudonym you provided, together with the comment text and date, will be displayed. Your e-mail address will not be published.

We delete IP addresses associated with comments after 60 days.


12. Orders and Contract Processing

When you place an order, we collect and use your personal data only insofar as this is necessary to fulfil and process your order and to handle your enquiries. In particular, the following is processed:

  • Master data (title, first and last name, and, where applicable, company name),
  • Contact data (address, e-mail address, telephone number),
  • Contract data (items ordered, quantities, prices, order and invoice number, order date),
  • Payment data,
  • Delivery, tracking and returns data.

The purposes of processing are: conclusion and performance of the contract, shipping, invoicing, payment processing, handling of withdrawals, returns, warranty and guarantee cases, customer service, fraud prevention, and accounting.

Providing this data is necessary for the conclusion of the contract. Failure to provide it will result in the contract not being concluded.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (commercial and tax obligations), and Art. 6(1)(f) GDPR (legitimate interest in fraud prevention and in asserting and defending legal claims).

Your data will not be disclosed to third parties without your express consent. This does not apply to our service partners whom we require to process the contractual relationship, or to service providers we engage under a data processing agreement. In addition to the recipients named in the respective sections of this Privacy Policy, these include, for example, recipients in the following categories: shipping service providers, payment service providers, inventory management service providers, order processing service providers, web hosts, IT service providers, and dropshipping retailers. In all cases, we strictly comply with statutory requirements. The scope of data transmission is limited to the minimum necessary.

Special notes regarding the shipping of live animals and goods subject to authorisation. For cross-border shipping, as well as trade in species subject to the Convention on International Trade in Endangered Species (CITES), Regulation (EC) No. 338/97, the German Federal Nature Conservation Act, or the Federal Species Protection Ordinance, we are legally obliged to transmit certain data to customs, veterinary and species protection authorities and to comply with documentation, record-keeping and reporting obligations. The legal basis for this is Art. 6(1)(c) GDPR.


13. Payment Methods and Payment Service Providers

Depending on the payment method you choose, we pass on the data necessary for payment processing to the relevant payment service provider. This regularly includes name, address, e-mail address, order and invoice amount, and — depending on the payment method — bank details, card data, or date of birth.

Payment service providers act as independent controllers within the meaning of the GDPR in this respect. Their own privacy notices apply exclusively to their processing. We recommend that you review these before selecting a payment method.

We generally do not collect sensitive payment data ourselves — such as the full credit card number or card security code; this is entered directly in the secure environment of the payment service provider.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract), supplemented by Art. 6(1)(c) GDPR (Payment Services Supervision Act, Anti-Money Laundering Act, Fiscal Code) and Art. 6(1)(f) GDPR (legitimate interest in fraud prevention and payment security).

Creditworthiness and identity checks. For payment methods involving advance performance risk — for example, purchase on account or instalment purchase — payment service providers, within their own area of responsibility, carry out identity and creditworthiness checks and may obtain information from credit reference agencies for this purpose. These agencies may provide probability values (score values) based on mathematical-statistical methods. Requests for information, correction, deletion, and objection should be directed in this respect directly to the relevant payment service provider or credit reference agency. Section 32 of this Privacy Policy applies additionally.

Payment default and debt collection. In the event of payment default, we transmit the data necessary to collect the debt to a debt collection agency or lawyer. Legal basis: Art. 6(1)(b) and (f) GDPR (enforcement of contractual claims).


14. PayPal

The provider for users in the European Economic Area is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg.

PayPal processes your personal data as an independent controller, in particular for payment processing, identity and creditworthiness checks, fraud, money laundering and terrorist financing prevention, compliance with Know-Your-Customer and sanctions list requirements, and to fulfil other legal obligations. PayPal expressly also uses automated decision-making and profiling and may transmit personal data to credit reference agencies, group companies, payment networks, fraud prevention bodies, authorities, and service providers — including in third countries.

All PayPal transactions are subject to PayPal’s Privacy Policy. This can be found at:
https://www.paypal.com/de/legalhub/paypal/privacy-full?locale.x=de_DE

There you will find, in particular, the legal bases for the processing, the list of third-party recipients, information on automated decision-making, and the options for exercising your data subject rights against PayPal.


15. Shipping and Delivery Status Notifications

To deliver the ordered goods, we transmit your name and delivery address to the contracted transport company. The legal basis for this is Art. 6(1)(b) GDPR.

In addition, as part of contract processing, we pass on your e-mail address and, where applicable, your telephone number to the transport company, provided you have expressly consented to this during the order process. This disclosure serves the purpose of informing you by e-mail or message about the delivery status, or of coordinating delivery with you.

Legal basis: Art. 6(1)(a) GDPR. You may withdraw your consent at any time by notifying us or the transport company, without affecting the lawfulness of processing carried out on the basis of the consent before its withdrawal.

For the shipment of sensitive or live goods, we may use specialist couriers and temperature-controlled transport service providers; only the data necessary for delivery is transmitted to them as well.


16. Use of an External Inventory Management System

We use an inventory management system for contract processing under a data processing agreement pursuant to Art. 28 GDPR. To this end, your personal data collected in connection with the order is transmitted to the system provider and processed there on servers within the European Union.

In addition, we engage external service providers and our tax advisor for accounting, invoicing, and compliance with tax obligations.

Legal basis: Art. 6(1)(b) GDPR (contract processing) and Art. 6(1)(c) GDPR (compliance with commercial and tax obligations).

Data processing agreements pursuant to Art. 28 GDPR are in place with all service providers engaged. These service providers are contractually obliged to process your data solely on our instructions and not for their own purposes.


17. Newsletter

Independently of contract processing, we use your e-mail address exclusively for our own advertising purposes to send you our newsletter, provided you have expressly consented to this.

Double opt-in procedure. To register, we need your e-mail address; other details such as your title and name are voluntary and are used solely for personal address. After registering, you will receive a confirmation e-mail. Dispatch only begins once you have clicked the confirmation link contained in it.

Logging. To prove that the registration procedure was properly followed, we log the time of registration and confirmation, the IP address used, and the wording of the consent declaration. The legal basis for this is Art. 6(1)(c) GDPR in conjunction with Art. 5(2) and Art. 7(1) GDPR (accountability).

Legal basis for dispatch: Art. 6(1)(a) GDPR in conjunction with Section 7(2) No. 2 UWG.

Success measurement. Our newsletters may contain tracking pixels and personalised links, which we use to evaluate whether and when an e-mail was opened and which links were clicked. In doing so, technical data such as the time, IP address, and the e-mail client used are also recorded. This evaluation is carried out on a personal basis and serves to optimise and tailor our newsletters to demand. Your consent expressly also covers this success measurement. It is not technically possible to withdraw consent solely for success measurement; in such a case, you must unsubscribe from the newsletter as a whole.

Withdrawal. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out on the basis of the consent before its withdrawal. You can unsubscribe from the newsletter at any time using the corresponding link in the newsletter or by notifying us. Your e-mail address will then be removed from the mailing list. To prevent future unwanted messages, we add your e-mail address to a suppression list (legal basis: Art. 6(1)(c) and (f) GDPR). We retain proof of consent for up to three years following withdrawal.

Your data is passed on to an e-mail marketing service provider under a data processing agreement pursuant to Art. 28 GDPR. It is not disclosed to any other third parties.


18. Use of Your E-mail Address for Direct Advertising

We use your e-mail address, obtained in the context of a sale of goods or services, to send electronic advertising for our own goods or services similar to those you have already purchased from us, unless you have objected to such use.

Providing your e-mail address is necessary for the conclusion of the contract. Failure to provide it will result in the contract not being concluded.

Legal basis: Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG — legitimate interest in direct advertising to existing customers.

You may object to this use of your e-mail address at any time, free of charge, by notifying us — both when the address is collected and on each individual occasion of use. Contact details for exercising your objection can be found in Section 1 and in our legal notice. You may also use the unsubscribe link provided in the advertising e-mail. No costs will be incurred other than the transmission costs according to the basic rates.


19. Customer Reviews

Reviews you submit are published together with the details you provide, generally your first name or pseudonym, review text, and date.

Legal basis: Art. 6(1)(a) GDPR. You may withdraw your consent at any time and request the deletion of your review. Please do not include special categories of personal data or third-party data in your reviews.

If we send you an invitation to leave a review after a purchase, this is done on the basis of your consent (Art. 6(1)(a) GDPR) or on the basis of Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG. You may object at any time, free of charge.

Transparency notice under Section 5b(3) UWG: We do not verify whether published reviews originate from consumers who have actually purchased or used the products.

Reviews on third-party platforms — such as Google or Facebook — are subject to the respective platform policies as well as to the fundamental right of freedom of expression under Art. 5(1) of the German Basic Law and Art. 11 of the Charter of Fundamental Rights of the European Union. We reserve the right to take permissible legal action against false factual claims, defamatory criticism, insults, or clearly fake reviews, and to request their removal from the relevant platform.


20. Cookies and Consent Management

Our website uses cookies. Cookies are small text files that are stored in or by your internet browser on your computer system. When a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a characteristic string that allows the browser to be uniquely identified when the website is visited again. In addition to cookies, comparable technologies may be used, in particular LocalStorage and SessionStorage, tracking pixels, web beacons, tags, scripts and SDKs.

We use cookies to make our offering more user-friendly, effective and secure. Cookies also enable our systems to recognise your browser even after you navigate to another page, and to offer you services. Some functions of our website cannot be offered without the use of cookies. We also use cookies to analyse the browsing behaviour of our website visitors and to subsequently target them with tailored, interest-based advertising on other websites.

Categories

Category Purpose Legal Basis
Strictly necessary Shopping cart, login and session, language and currency selection, load balancing, attack and fraud prevention, storage of your cookie choice Section 25(2) No. 2 TDDDG in conjunction with Art. 6(1)(b) or (f) GDPR — no consent required
Functional and convenience extended shop functions, wish list, embedded videos, maps, chat Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR — consent
Statistics and analytics reach measurement, usage analysis, optimisation of the offering Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR — consent
Marketing and advertising interest-based advertising, remarketing, conversion tracking Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR — consent

Consent Banner

When you first visit our website, you will see a consent banner through which you can make your selection. Technologies that are not strictly necessary will only be loaded after you have actively given your consent. To fulfil our documentation obligation under Art. 7(1) GDPR, the consent management tool used logs, among other things, the time of consent, the categories selected, a consent ID, the shortened IP address, and the banner version displayed.

You may withdraw or change your consent at any time with effect for the future — via the “Cookie Settings” link in the footer of every page of our website.

Google Consent Mode v2

Insofar as we use Google services, your selection made in the consent banner is communicated to Google via the signals ad_storage, analytics_storage, ad_user_data and ad_personalization. No cookies are set without your consent.

Browser Settings

Cookies are stored on your computer. You therefore have full control over the use of cookies. By selecting the appropriate technical settings in your internet browser, you can prevent cookies from being stored and the data they contain from being transmitted. Cookies that have already been stored can be deleted at any time. Please note, however, that in this case you may not be able to use all functions of this website to their full extent.

The links below provide information on how to manage and disable cookies in the main browsers:

You can also find options to object to usage-based online advertising at https://optout.networkadvertising.org/, https://optout.aboutads.info/, and https://www.youronlinechoices.com/de/.


21. Use of Google Analytics

We use the web analytics service Google Analytics 4 provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”) on our website.

Data processing serves the purpose of analysing this website and its visitors. To this end, Google will use the information obtained on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activity, and to provide the website operator with further services relating to website and internet usage.

Data processed: pseudonymous client or user identifier, events such as page views, scrolling, clicks, search queries and transactions, e-commerce and shopping cart data, session duration, referrer, approximate location at country, region and city level, device, browser and operating system information, screen resolution, language settings, and the shortened IP address.

IP truncation. Google Analytics 4 shortens IP addresses by default within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area and does not store them. This truncation cannot be disabled. The IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Google Analytics is only loaded after you have given your consent via the consent banner.

Withdrawal. You may withdraw your consent at any time with effect for the future via the “Cookie Settings” link in the footer. You can also prevent the collection of data generated by cookies and related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser add-on available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de

Retention period. The retention period for user and event data at Google is limited to 14 months. This does not affect aggregated reporting data.

Third-country transfer. A transfer to the USA (Google LLC) cannot be excluded; the safeguards described in Section 5 apply.

Further information on terms of use and data protection is available at https://marketingplatform.google.com/about/analytics/terms/de/ and at https://policies.google.com/?hl=de.


22. Google Ads – Conversion Tracking and Remarketing

We use the online advertising programme Google Ads (formerly “Google AdWords”) on our website, and, within this framework, conversion tracking and remarketing. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When you click on an advertisement placed by Google, a cookie for conversion tracking is stored on your device. These cookies are valid for a limited period and are not used for direct personal identification. If you visit certain pages of our website and the cookie has not yet expired, Google and we can recognise that you clicked on the ad and were redirected to that page. Each Google Ads customer receives a different cookie; tracking across the websites of different Ads customers is therefore not possible in this way.

Purposes: creation of conversion statistics and measurement of the success of our advertisements, as well as the delivery of interest-based advertising within the Google Display Network and in Google Search to persons who have already visited our website (remarketing), including the creation of audiences and exclusion lists.

In this context, we learn the total number of users who clicked on one of our advertisements and were redirected to a page tagged with a conversion tracking tag. However, we do not receive any information that would allow us to identify users personally.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. These services are only loaded after you have given your consent; you may withdraw this at any time via “Cookie Settings” in the footer.

Third-country transfer: see Section 5.

You can also disable personalised advertising and manage your ad preferences in Google’s ad settings. More information is available at https://support.google.com/My-Ad-Center-Help/answer/12155764?hl=de and at https://adssettings.google.com/. You can also disable the use of cookies by third-party providers via the Network Advertising Initiative opt-out page at https://optout.networkadvertising.org/.

Further information, along with Google’s privacy policy, is available at https://policies.google.com/technologies/ads and https://policies.google.com/privacy?hl=de.


23. Google AdSense

Insofar as advertising space is made available on our website, we use the AdSense function provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland for this purpose.

This function serves the purpose of renting out advertising space on the website and using it to target website visitors with interest-based advertising. This function is used to display personalised, interest-based advertisements from the Google Display Network. In doing so, Google uses cookies that enable an analysis of your use of the website. The information generated by the cookie about your use of this website is transmitted to a Google server and stored there. Google may transfer this information to third parties where this is required by law or where third parties process this data on Google’s behalf. Google will not associate your IP address with any other data held by Google.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. This service is only loaded after you have given your consent; you may withdraw this at any time via “Cookie Settings” in the footer.

Third-country transfer: see Section 5.

You can also disable the use of cookies by third-party providers via the Network Advertising Initiative opt-out page at https://optout.networkadvertising.org/, and adjust your advertising settings with Google at https://adssettings.google.com/.

Further information, along with Google’s privacy policy, is available at https://policies.google.com/technologies/ads and https://policies.google.com/privacy?hl=de.


24. Meta (Facebook) Remarketing and Custom Audiences

We use the “Custom Audiences” remarketing function and the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”) on our website.

This function serves the purpose of targeting website visitors with interest-based advertising on the Facebook and Instagram social networks, and of measuring the effectiveness of our advertisements.

To this end, Meta’s remarketing tag has been implemented on the website. This tag establishes a direct connection to Meta’s servers when the website is visited. This transmits to Meta which of our pages you have visited. In particular, the following is transmitted: cookie and browser identifiers, your IP address, the pages visited, standard events triggered such as page view, cart action or purchase, the order value, and device and browser data. If you are logged into Meta, Meta assigns this information to your personal user account. If you then visit the social network, personalised, interest-based advertisements will be displayed to you.

Joint controllership. We and Meta are joint controllers within the meaning of Art. 26 GDPR for the collection and transmission of this data. The respective responsibilities are set out in Meta’s supplementary agreement, available at https://www.facebook.com/legal/controller_addendum. Under this agreement, we are responsible for providing information under Art. 13 and 14 GDPR and for obtaining consent; Meta is responsible for handling data subject rights under Art. 15 to 20 GDPR with regard to the data stored by Meta. You may nevertheless exercise your rights against us as well; we will forward any such requests to Meta.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. The pixel is only loaded after you have given your consent.

Withdrawal. You may withdraw your consent at any time via “Cookie Settings” in the footer. You can also disable this function in your Meta advertising settings: https://www.facebook.com/settings?tab=ads

Third-country transfer: see Section 5.

Further information on how Meta collects and uses this data, your related rights, and options for protecting your privacy can be found in Meta’s Privacy Policy at https://www.facebook.com/privacy/policy/.


25. Use of Facebook Plug-ins

This website uses plug-ins from the Facebook social network, operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

If you visit pages of our website containing such a plug-in, a connection to Meta’s servers is established, and the plug-in is displayed on the page by communicating with your browser. This transmits to Meta which of our pages you have visited. If you are logged in as a Facebook member at the time, Meta assigns this information to your personal user account. When you use the plug-in functions — for example, clicking the “Like” button or leaving a comment — this information is also assigned to your account.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. We integrate the plug-ins using a two-click solution: a connection to Meta is only established once you have actively activated the relevant plug-in by clicking on it. We and Meta are joint controllers within the meaning of Art. 26 GDPR for the collection and transmission of this data; the details set out in Section 24 apply accordingly.

Third-country transfer: see Section 5.

Further information on how Meta collects and uses this data, your related rights, and options for protecting your privacy can be found in the privacy notices at https://www.facebook.com/privacy/policy/.


26. Use of YouTube

We use the function to embed YouTube videos on our website. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

This function displays videos hosted on YouTube in an iFrame on the website. The “enhanced privacy mode” option is activated; embedding takes place via the domain youtube-nocookie.com. As a result, YouTube only sets cookies once you play a video. However, when the player loads, technical connection data — in particular your IP address — is transmitted to Google. Only once you watch a video is further information transmitted to and stored by YouTube.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Embedding takes place via a two-click solution; the player is only loaded after your explicit consent. You may withdraw your consent at any time via “Cookie Settings” in the footer.

Third-country transfer: see Section 5.

Further information on how YouTube and Google collect and use this data, your related rights, and options for protecting your privacy can be found in the privacy notices at https://policies.google.com/privacy?hl=de.


27. Use of Google Maps

We use the function to embed Google Maps maps provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland on our website.

This function enables the visual display of geographic information and interactive maps. When pages containing embedded Google Maps maps are accessed, Google also collects, processes and uses visitor data — in particular the IP address, location data, and browser and device information. If you are logged into your Google account, Google may associate your visit with your account.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. We embed Google Maps using a two-click solution; the map is only loaded after your explicit consent. You may withdraw your consent at any time via “Cookie Settings” in the footer.

Third-country transfer: see Section 5.

Further information on how Google collects and uses this data can be found in the privacy notices at https://policies.google.com/privacy?hl=de. You can manage your advertising and privacy settings in your Google account at https://myaccount.google.com/.


28. Fonts and Local Resources

Fonts, icons and comparable design elements — such as Google Fonts or Font Awesome — are hosted locally on our own server. When you visit our website, no connection is therefore established to third-party servers in this respect; your IP address is not transmitted to any font service providers.


29. Use of WebChat

Euro Coral uses a web chat on the website www.eurocorals.com. The web chat serves as an additional means of communication on our website and enables online conversations with Euro Coral. The conversation is conducted using a chat bot (virtual assistant, software) that answers user questions, assists with your enquiry, or provides you with information.

What personal data is processed?

When you use the web chat, the following personal data about you is processed and stored:

  • date and time of access,
  • IP address,
  • URL of the previously visited website,
  • first name, last name,
  • e-mail address,
  • chat ID and user token, stored in your browser’s local storage.

Depending on the course of the conversation with our chat bot, we process further data about you, provided you supply this during the conversation — depending on your enquiry or the issue you describe to us.

Use of the web chat is voluntary; your data is only processed in this case. Please do not submit any special categories of personal data within the meaning of Art. 9 GDPR, nor any complete payment data, via the chat.

For what purposes and on what legal basis is the data processed?

We use the aforementioned data to offer the web chat, to personally address users, to answer user enquiries, and to provide users with information and content.

Legal bases:

  • Art. 6(1)(b) GDPR, insofar as the enquiry serves to initiate or perform a contract;
  • Art. 6(1)(f) GDPR — legitimate interest in providing a web chat as a modern communication channel and in the efficient handling of enquiries;
  • Section 25(2) No. 2 TDDDG for storing the chat ID and user token in local storage. This storage only takes place once you actively open the chat, and is strictly necessary to provide the service you have explicitly requested — namely the continuation and restoration of your chat history.

How long is personal data stored?

12 months. Following an opt-out message (see below), deletion takes place after 6 months. Longer statutory retention periods apply, by way of exception, insofar as the chat history is associated with a contract (see Section 34).

To whom is data disclosed?

Data is disclosed to third parties exclusively for the purpose of fulfilling business operations, in order to process and answer your enquiry. For this purpose, your data is disclosed to Inbox Solutions GmbH, Pretzfelder Straße 7–11, 90425 Nuremberg, Germany as the technical operator of the web chat, and to Sellwerk GmbH & Co. KG, Pretzfelder Straße 7–11, 90425 Nuremberg, Germany as the intermediary body. Data processing agreements pursuant to Art. 28 GDPR are in place with the aforementioned service providers.

Google Cloud is used to store your data and chat histories. The data is transmitted to and stored on servers located in Frankfurt am Main. Google does not use this data for its own purposes. The contracting party for customers in the European Economic Area is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland.

The use of Google Cloud services is based on the legitimate interest under Art. 6(1)(f) GDPR of being able to provide the services using the necessary technical infrastructure. A data processing agreement is in place with Google (https://cloud.google.com/terms/data-processing-terms). In the event that personal data is transferred to the USA, the EU Standard Contractual Clauses have been concluded with Google. The EU Standard Contractual Clauses are a generally recognised mechanism for the lawful cross-border transfer of personal data to countries outside the European Economic Area. In addition, where applicable, the adequacy decision on the EU-U.S. Data Privacy Framework applies (see Section 5).

Further Information on the Use of the Web Chat

Visiting the website www.eurocorals.com loads the chat widget as a JavaScript file. No personal data is transmitted before you open the chat.

You have two ways of opening the web chat:

  1. manually clicking the corresponding button,
  2. manually clicking the chat icon in the bottom right of the website.

The moment you open the web chat, your chat is created as an object in the background, and a chat ID and token are stored in your browser’s local storage. The ID and token are unique identifiers that allow us to uniquely recognise your chat (chat ID) and you as a user (token) on a repeat visit, and to display previous communication histories to you. When you return to our website, the chat history is restored using the data stored in local storage. You must open the chat again manually.

In addition, the web chat history is stored. Every message you send is stored. This serves the purpose of being able to display your chat history when the started communication is continued, for example if you receive a reply at a later time.

If you receive a reply and are no longer online at that time, you will receive a link by e-mail that takes you back to the chat so that you can continue communicating there. If you click the link in your e-mail, the chat opens automatically.

You may interrupt the chat at any time; however, your data will not be automatically deleted in this case.

Opt-out. If you no longer wish to receive messages, simply send “Stop” as a message in the web chat. You will then no longer receive messages in the chat and will no longer be informed by e-mail. Your chat history and data will be automatically deleted 6 months after the stop message.

Immediate deletion. For immediate deletion of your data, send an e-mail to Euro Coral e-mail address. Your data and stored chat histories will then be deleted without delay, unless statutory retention obligations preclude this.

Human handling. You may request at any time that your enquiry be handled by a natural person. We do not make automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR via the web chat.


30. Use of WhatsApp

Insofar as you have given your consent, we process your personal data provided to us or otherwise available — for example, name, telephone number, e-mail address, messenger ID, profile picture, and message content — for communication regarding the preparation and performance of any orders, as well as for sending advertising information such as offers and newsletters, using the instant messaging service WhatsApp provided by WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

An existing messaging account is required to use this service.

Legal basis: Art. 6(1)(a) GDPR (consent) for advertising communications; Art. 6(1)(b) GDPR, insofar as the communication serves to initiate or perform a contract.

Note on data processing by WhatsApp. We would like to point out that WhatsApp Ireland Limited may disclose personal data — in particular communication metadata — to WhatsApp LLC or Meta Platforms, Inc., which may also process this data on servers located outside the European Union, in particular in the USA. WhatsApp may pass this data on to further companies within and outside the Meta group of companies. For transfers to the USA, the safeguards described in Section 5 apply; Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework, and Standard Contractual Clauses apply additionally.

Further information can be found in WhatsApp’s Business Privacy Policy (https://www.whatsapp.com/legal/business-policy/) and WhatsApp’s general Privacy Policy (https://www.whatsapp.com/legal/privacy-policy-eea).

We have neither precise knowledge of, nor influence over, the data processing carried out by WhatsApp Ireland Limited or its affiliated companies, which are independently responsible under data protection law in this respect.

Please also note that, for security reasons, we do not accept payment data, identification data, or special categories of personal data via WhatsApp.

In addition to the recipients specifically named above, we use the assistance of further service providers (processors) to fulfil our obligations.

Withdrawal. Please note that you may withdraw any consent given at any time, without giving reasons, with effect for the future, by notifying us of your withdrawal via WhatsApp with a message stating “WITHDRAWAL” or by e-mail to Euro Coral e-mail address. The lawfulness of processing carried out before the withdrawal remains unaffected.

Deletion. The aforementioned data will be deleted by us in accordance with statutory requirements as soon as any consents given for processing are withdrawn, or once the purpose of processing this data no longer applies, or the data is no longer necessary for that purpose.

Where data is not deleted because it is required for other, legally permissible purposes, its processing will be restricted to those purposes. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary to assert, exercise or defend legal claims, or to protect the rights of another natural or legal person.


31. Social Media Presences

We maintain profiles on social networks in order to communicate with prospective and existing customers and to inform them about our offerings.

When you visit our profiles, the respective providers process your data on their own responsibility — in particular usage behaviour, interactions, and device and location data — often also for market research and advertising purposes and to create usage profiles. This is done partly across devices and regardless of whether you have an account with the respective network. Processing may take place in third countries.

For the page insights and statistics provided by the networks, we and the respective provider are joint controllers within the meaning of Art. 26 GDPR. The key content of the agreement with Meta can be found at https://www.facebook.com/legal/terms/page_controller_addendum.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in communication, customer relations and public relations; supplemented by Art. 6(1)(a) GDPR, insofar as you have given consent to the network.

You may exercise your rights both against us and against the respective provider. As we have only limited influence over the processing of data by the networks, we recommend submitting requests for information and deletion directly to the relevant provider.

Privacy notices of the providers:


32. Automated Decision-Making and Profiling

We do not engage in decision-making based solely on automated processing — including profiling — that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

Insofar as payment service providers such as PayPal use automated procedures for risk, fraud and creditworthiness assessment within their own area of responsibility, their privacy notices apply (see Sections 13 and 14). Under case law of the European Court of Justice, the creation of a score value by a credit reference agency may already constitute an automated decision within the meaning of Art. 22 GDPR. Requests for information, correction and objection should in this respect be directed directly to the relevant credit reference agency or payment service provider.

Profiling for advertising purposes — such as the creation of interest groups for personalised advertising under Sections 22 to 24 — is carried out exclusively on the basis of your consent and does not produce legal effects within the meaning of Art. 22 GDPR. Your right to object under Art. 21(2) GDPR remains unaffected by this.

Transparency notice regarding AI-based systems. Insofar as a chat bot or comparable automated assistance system is used on our website (see Section 29), we expressly inform you that you are interacting with an automated system and not with a human being (Art. 50 of Regulation (EU) 2024/1689 on artificial intelligence). At your request, a natural person will handle your matter at any time.


33. Use by Minors

Our offering is intended exclusively for adults. Persons under the age of 18 should not transmit personal data to us without the consent of a parent or legal guardian.

We do not knowingly collect personal data from children and do not direct advertising at them. Should we become aware that we have collected data from a minor without the required consent, we will delete it without delay (Art. 8 GDPR).


34. Retention Period

After the contract has been fully processed, data is initially retained for the duration of the warranty and limitation periods, and thereafter, taking into account statutory retention periods — in particular under tax and commercial law — before being deleted once these periods have expired, unless you have consented to further processing and use.

In particular, the following periods apply:

Type of Data Period Basis
Contract and warranty data 3 years from the end of the year in which the claim arose Sections 195, 199 BGB
Accounting records and invoices 8 years Section 147(3) AO, Section 14b UStG
Commercial books, inventories, annual financial statements 10 years Section 257(1) No. 1, (4) HGB; Section 147(1) No. 1 AO
Commercial and business correspondence, including e-mails 6 years Section 257(1) Nos. 2 and 3 HGB; Section 147(1) Nos. 2 and 3 AO
Proof of consent (newsletter, cookies) up to 3 years after withdrawal Art. 5(2), Art. 7(1) GDPR
Server log files 7 days Art. 6(1)(f) GDPR
IP addresses relating to comments 60 days Art. 6(1)(f) GDPR
Web chat histories 12 months, 6 months after opt-out Section 29
Species protection documentation in accordance with the relevant statutory periods Regulation (EC) 338/97, BArtSchV

During an ongoing retention period, processing is restricted (blocking); the data will no longer be used for other purposes.


35. Rights of the Data Subject

Provided the statutory requirements are met, you have the following rights under Art. 15 to 20 GDPR:

  • the right to information about the data processed concerning you, including a copy (Art. 15 GDPR),
  • the right to rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR),
  • the right to erasure (Art. 17 GDPR),
  • the right to restriction of processing (Art. 18 GDPR),
  • the right to data portability (Art. 20 GDPR).

Insofar as processing is based on consent, you also have the right to withdraw it at any time with effect for the future (Art. 7(3) GDPR). The lawfulness of processing carried out before the withdrawal remains unaffected.

An informal notification to the contact details given in Section 1 is sufficient to exercise these rights. To prevent misuse, we may request additional information to confirm your identity (Art. 12(6) GDPR). We will respond without undue delay, and no later than one month after receiving your request.

You will not suffer any disadvantage as a result of exercising your rights.

Please feel free to contact us. Contact details can be found in Section 1 and in our legal notice.


36. Right to Object under Art. 21 GDPR

1. Objection to direct advertising

You have the right to object at any time, without giving reasons, to the processing of personal data concerning you for the purposes of direct advertising; this also applies to profiling insofar as it is related to such direct advertising. Following your objection, we will no longer process your personal data for these purposes (Art. 21(2) and (3) GDPR).

2. Objection on grounds relating to your particular situation

You further have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. We will then no longer process the personal data concerned, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims (Art. 21(1) GDPR).

The objection is free of charge and requires no particular form. It may be addressed to:

Euro Coral, Passauer Str. 12, 84359 Simbach am Inn
or by e-mail to Euro Coral e-mail address


37. Right to Lodge a Complaint with a Supervisory Authority

In accordance with Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data is not lawful.

You may contact the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement — or the authority responsible for us:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 27, 91522 Ansbach
Telephone: +49 (0) 981 180093-0
www.lda.bayern.de

We ask that you contact us first, so that we have the opportunity to resolve your concern directly. There is, of course, no obligation to do so.


38. Currency and Amendment of this Privacy Policy

This Privacy Policy is dated 02.08.2026.

Due to the ongoing development of our website and our offerings, or as a result of changes to legal or regulatory requirements, it may become necessary to amend this Privacy Policy. The current version can be accessed and printed at any time on our website under the “Privacy Policy” menu item.

We will obtain renewed consent where this is legally required.

Last updated: 02.08.2026