Privacy Policy
Information on the processing of personal data under the EU GDPR, UK GDPR and applicable privacy rules.
Last updated: 31 August 2026
Provider / contracting entity
BUGO DUFT LTD
Suite 11177, 5 Brayford Square, London, United Kingdom, E1 0SG
Email: kontakt@bugoduft.de
Telephone: +49 179 3564841
1. Scope
This Privacy Policy explains how personal data is processed when you use our website, contact us, request a quote, create a customer account, place an order, upload files or communicate with us in a business context. It also applies to contact persons and employees of our B2B customers where their personal data is processed.
2. Controller and EU representative
The controller is identified from the centrally maintained company information shown on this page. Where a representative in the European Union is appointed under Article 27 EU GDPR, that representative is shown separately. An Article 27 GDPR representative is not the same role as an EU product-safety responsible person under the GPSR.
3. Categories of personal data
Depending on how you use our services, we may process:
- identity and business contact data such as name, company, business address, email address and telephone number
- account and authentication data
- quote, order, invoice, payment-status and shipping data
- communications and support requests
- uploaded logos, print files, artwork and related metadata
- technical data such as IP address, device/browser information, timestamps, referrer and security/server logs
- consent, analytics and marketing events where valid consent is required and has been given
4. Purposes and lawful bases
We process data for pre-contractual steps and contract performance, quotes, customer and order administration, customer accounts, compliance with legal obligations, IT/security purposes and communications. Depending on the activity, our lawful bases include Article 6(1)(b) EU GDPR (contract/pre-contractual steps), Article 6(1)(c) (legal obligation), Article 6(1)(f) (legitimate interests, including secure and efficient business operations) and Article 6(1)(a) (consent). Where UK GDPR applies, the corresponding UK GDPR bases are used.
5. Hosting, delivery and technical security
Our website is provided through technical service providers, including hosting, deployment, database, authentication, storage and security services. Technical log data may be processed to deliver the site, detect attacks, diagnose errors and maintain availability. We use service providers subject to the applicable data-protection requirements.
6. Customer accounts, Supabase and file uploads
Supabase may be used for account, database, authentication and storage functions. Artwork or logos submitted with quote requests may be stored in non-public storage. Access is limited to people who need it for the relevant business process. Please do not upload special-category personal data unless this is expressly necessary and lawful.
7. Quotes, orders and Shopify
We use Shopify and/or Shopify order and checkout functionality for quote and order processing. Data needed for the contract, payment, invoicing and shipping is processed and shared with participating service providers as necessary. Payment information may be processed directly by the relevant payment provider; we do not operate our own database of full card credentials or online-banking credentials.
8. Email and notifications
Transactional and quote notifications may be sent through email providers such as Resend. Recipient addresses, message data and technical delivery information may be processed for sending, deliverability, abuse prevention and troubleshooting.
9. Cookies, local storage and consent management
Strictly necessary storage/access technologies may be used where required to provide a digital service expressly requested by the user. In Germany, non-essential analytics or marketing technologies are generally activated only after consent under § 25 TDDDG together with the GDPR requirements. Consent can be changed or withdrawn at any time for the future through the cookie settings.
10. Google Analytics 4 and Meta Pixel
Where enabled in our consent settings and valid consent has been obtained where required, we may use Google Analytics 4 and Meta Pixel to measure reach, site usage, campaigns and conversions. Online identifiers, device/browser data, IP-related information and event data may be processed. These services are not loaded as a necessary condition for visiting the site. The providers’ own privacy information contains further details.
11. Communications through third-party platforms
If you contact us through WhatsApp, Instagram, Facebook or another third-party platform, that platform provider processes data under its own terms and responsibilities. We process the content you send us to handle your request. For confidential or particularly sensitive information, direct email contact is preferable.
12. Recipients and processors
Data is made available only to recipients that need it for the purposes described above. These may include hosting/cloud providers, database/storage providers, email providers, Shopify, payment providers, shipping/logistics providers, IT suppliers, professional advisers and public authorities where a lawful basis exists.
13. International transfers
Because of our international B2B structure and the cloud/platform services we use, data may be processed outside the European Economic Area or outside the United Kingdom. Where a transfer is subject to specific transfer restrictions, we use an applicable adequacy decision/regulation, standard contractual clauses, UK transfer mechanisms or another lawful transfer basis, with supplementary measures where required.
14. Retention
We keep personal data only for as long as necessary for the relevant purpose, contract administration, establishment/exercise/defence of legal claims and statutory retention obligations. Quote and communication data that does not lead to a contract is deleted or anonymised when no longer required unless a legitimate reason requires longer retention. Commercial, tax and accounting records are retained for the period required by applicable law.
15. Your rights
Subject to the applicable privacy law, you may have rights of access, rectification, erasure, restriction, data portability and objection. Consent can be withdrawn at any time for the future. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation; you may object to direct marketing at any time.
16. Complaints
You have the right to complain to a competent data-protection supervisory authority. Where UK GDPR applies, the competent UK supervisory authority may be contacted; where EU GDPR applies, the complaint rights provided by the EU GDPR remain available before a competent EU supervisory authority.
17. Automated decision-making
In our ordinary quote and order process, we do not use solely automated decisions that produce legal effects concerning you or similarly significantly affect you, unless we expressly inform you otherwise in a specific case.
18. Security
We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration and disclosure. No internet-based service can guarantee absolute security, so security measures are reviewed and developed on a risk-based basis.
19. Changes to this policy
We update this Privacy Policy when material changes occur in applicable law, services or processing activities. The displayed update date identifies the version currently published.
