Contents
- 1. Controller and Data Protection Officer
- 2. General Information and Legal Bases
- 3. Provision of the Website and Server Log Files
- 4. Content Delivery Network (Cloudflare)
- 5. Cookies and Consent Management
- 6. Contacting Us
- 7. Orders, Customer Account and Payment Data
- 8. Health-Related Data (Prescription Values)
- 9. Creditworthiness and Risk Assessment
- 10. Subscriptions
- 11. Newsletter and Direct Advertising
- 12. Wish List and Notification Emails
- 13. Customer Service
- 14. Virtual Try-On (2D/3D)
- 15. Eye-Test Appointment Booking with Partner Opticians
- 16. Fulfilment via Partner Opticians
- 17. Shipping
- 18. Fraud and Misuse Prevention
- 19. Analytics Tools
- 20. Advertising and Marketing Tools
- 21. Technical Administration and Further Service Providers
- 22. Social Media Presences
- 23. Links to Third-Party Services
- 24. Google Maps
- 25. Review Platforms
- 26. Recipients and Transfers to Third Countries
- 27. Retention Period
- 28. Minors
- 29. Your Rights as a Data Subject
- 30. Right to Object
- 31. Data Security
- 32. Currency and Amendment of this Privacy Notice
Privacy Notice
Information on the processing of your personal data under Articles 13 and 14 GDPR
Last updated: July 2026 · available at www.edel-optics.ie/Privacy.html
Controller
Edeloptics GmbH · Straßenbahnring 19a · 20251 Hamburg · Germany
Telephone +49 40 87409688 (Mon–Fri 9 am–6 pm) · info@edel-optics.de
1. Controller and Data Protection Officer
The controller within the meaning of the GDPR (Regulation (EU) 2016/679) is Edeloptics GmbH (address and contact details above).
Our Data Protection Officer is the externally appointed beck service GmbH, contactable at datenschutz@edel-optics.de or by post at the above address, marked "for the attention of the Data Protection Officer".
Because we are established in Germany, our lead supervisory authority under the one-stop-shop mechanism (Article 56 GDPR) is the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany (datenschutz-hamburg.de). Without prejudice to this, you may also contact the supervisory authority of your own place of residence: in Ireland, this is the Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (dataprotection.ie). In Malta, it is the Information and Data Protection Commissioner (IDPC), Level 2, Airways House, High Street, Sliema SLM 1549, Malta (idpc.org.mt). See also section 29.
2. General Information and Legal Bases
We process personal data in accordance with the GDPR and applicable national data protection law (in Ireland, the Data Protection Act 2018) for the purposes described in this Privacy Notice – in particular to provide our website, to initiate and perform orders and contracts, to communicate with you, to analyse and tailor our offering, for marketing, and to ensure security and fraud prevention. Depending on the processing, the applicable legal basis is:
- your consent (Article 6(1)(a); for special categories of personal data, Article 9(2)(a) GDPR);
- the performance of a contract or of pre-contractual measures (Article 6(1)(b) GDPR);
- compliance with a legal obligation (Article 6(1)(c) GDPR);
- the protection of our legitimate interests, provided that your interests do not override them (Article 6(1)(f) GDPR).
For the storing of, or gaining of access to, information already stored on your terminal equipment (cookies, local storage and similar), Regulation 5 of the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. No. 336 of 2011) applies in addition: access that is not strictly necessary takes place only with your prior, active consent.
3. Provision of the Website and Server Log Files
When you access our website, our hosting provider automatically collects information transmitted by your browser and stores it in a server log file: IP address, date and time of access, the name and URL of the file retrieved, the referrer URL, and the browser and operating system used.
The purpose is to ensure a smooth connection, system security and stability, and to investigate security incidents and misuse. The legal basis is Article 6(1)(f) GDPR. As a rule, the log files are deleted or anonymised automatically within a few days; where there are indications of a security incident or misuse, we retain the affected log files until the matter has been resolved.
Our hosting provider is OVH SAS, 2 Rue Kellermann, 59100 Roubaix, France (server location EU). A data processing agreement under Article 28 GDPR is in place.
4. Content Delivery Network (Cloudflare)
To optimise loading speed and resilience, we use the content delivery network of Cloudflare Germany GmbH, Rosental 7, c/o Mindspace, 80331 Munich, Germany. A CDN delivers large media files (graphics, scripts, product images) via a network of regionally distributed servers.
The legal basis is our legitimate interest in a fast, reliable and secure presentation of our website (Article 6(1)(f) GDPR). The processing is carried out exclusively on our behalf (Article 28 GDPR). Further information: cloudflare.com.
5. Cookies and Consent Management
We use cookies and comparable technologies. On your first visit, our consent tool consentmanager (consentmanager AB, Haltegelvägen 1b, 72348 Västerås, Sweden) asks for your consent. We distinguish between:
- strictly necessary cookies (e.g. shopping basket, login, security) – Article 6(1)(f) GDPR, no consent required;
- statistics and marketing cookies – only with your active consent (Regulation 5(3) of S.I. No. 336 of 2011 in conjunction with Article 6(1)(a) GDPR).
The analytics and marketing services described in sections 19–20 load only after you have given your consent. You can withdraw or adjust your consent at any time with effect for the future via the "Cookie settings" link in the footer. The current, complete list of the providers used can be found there.
6. Contacting Us
We provide various ways to get in touch (contact form, email, telephone). If you contact us through any of these, we process the information you provide (in particular name, email address or telephone number, and all content communicated in the course of the exchange) solely in order to respond to your enquiry.
The legal basis is Article 6(1)(f) GDPR; our legitimate interest arises from our wish to handle your request to your satisfaction. Given that you have proactively contacted us, there is no indication that any opposing interests override this.
7. Orders, Customer Account and Payment Data
To accept, process and fulfil your order, we process the necessary data (name, address, email, order details) and, where required, pass them on to service providers – such as the delivery company. Legal basis: Article 6(1)(b) GDPR. You may optionally set up a customer account (Article 6(1)(a) GDPR).
Payment data are collected in encrypted form and used solely to process the relevant transaction. Only the data required by the payment provider you have selected are transmitted:
| Payment method | Recipient |
|---|---|
| Credit card, Google Pay, Apple Pay, Sofort | Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands |
| Sofort instant bank transfer (via Klarna) | Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden |
| Purchase on account (invoice), direct debit | Ratepay GmbH, Ritterstr. 12-14, 10969 Berlin, Germany |
| PayPal | PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg |
| Prepayment, cash on delivery | no transmission to external payment service providers |
8. Health-Related Data (Prescription Values)
To manufacture and supply prescription glasses and contact lenses, we process the refraction/prescription values you provide. These are health data and therefore fall within the special categories of personal data (Article 9 GDPR).
Manufacturing your order. The legal basis is your explicit consent under Article 9(2)(a) GDPR, which you give during the order process, in conjunction with Article 6(1)(b) GDPR. You can withdraw your consent at any time with effect for the future. Without this information we cannot manufacture corrective eyewear.
Retention after completion of the order. Corrective eyewear with an individual prescription is a medical device. We retain the order-related documentation, including the prescription values, in order to handle warranty, remanufacture and product-liability matters, to assert or defend legal claims, and to the extent that product-safety and medical-device documentation obligations require. Retention is guided by the applicable limitation periods and statutory retention periods (up to ten years). Legal bases: Article 6(1)(c) and (f) in conjunction with Article 9(2)(f) GDPR (legal claims) and Article 9(2)(i) GDPR (public-interest standards of quality and safety in relation to medical devices), as supplemented by the Data Protection Act 2018. This retention is strictly limited to its purpose.
Storage in your customer account (convenience). If you have a customer account, we store the prescription values you have provided there so that you do not have to re-enter them for follow-up orders. The legal basis is the consent you give during the order process (Article 9(2)(a) GDPR). You can withdraw this at any time with effect for the future, or ask us informally to remove the values (info@edel-optics.de); the values are then removed from your customer account. Otherwise we store the values for as long as your customer account exists and review whether their storage remains necessary at appropriate intervals. The statutory order documentation described above remains unaffected by this.
Without your explicit consent, we do not use your prescription data for advertising or profiling. Prescription data are never disclosed to third-party advertising platforms.
9. Creditworthiness and Risk Assessment
For payment methods that involve an advance-performance risk (e.g. purchase on account, direct debit, subscription), we or our payment service providers carry out a creditworthiness/risk assessment. In doing so, a probability value (score) is calculated using recognised mathematical-statistical methods. Legal basis: Article 6(1)(b) and (f) GDPR (protection against payment default).
Our own assessment via CRIF GmbH. For purchase on account and for subscriptions, we transmit the necessary data to CRIF GmbH, Victor-Gollancz-Straße 5, 76137 Karlsruhe, Germany. CRIF GmbH also processes these data for the purpose of profiling (scoring). The legal bases are Article 6(1)(b) and (f) GDPR; the data exchange also serves to carry out statutory creditworthiness assessments. Further information at crif.de/datenschutz.
The check is automated. If it is negative, the payment method concerned is not available to you; other, free payment methods without a prior check remain open to you at all times. In so far as this constitutes an automated decision in an individual case within the meaning of Article 22 GDPR, you have the right to obtain human intervention, to express your point of view and to contest the decision (info@edel-optics.de).
Assessment by the payment service providers. When you select the relevant payment method, the payment service providers – in particular Ratepay GmbH, Klarna and PayPal (for example for the "pay later" or instalment options) – also carry out risk and, where applicable, creditworthiness checks on their own responsibility; for details, see the privacy policy of the respective provider.
At least one common, free payment method for which we do not carry out a creditworthiness check (e.g. prepayment) is always available.
10. Subscriptions
For our subscription model we use the checkout and subscription-management software of Circuly GmbH, Obernstr. 50, 33602 Bielefeld, Germany, to manage subscription contracts, recurring payments, invoices, returns and contract terms. In particular, name, address, payment and contract data are processed. Circuly acts as a processor on our instructions (data processing agreement under Article 28 GDPR). The legal basis is the performance of the subscription contract concluded with you (Article 6(1)(b) GDPR) and our legitimate interest in the efficient administration of our subscriptions (Article 6(1)(f) GDPR). Where personal data are transferred to a third country in this context, this is done on the basis of appropriate safeguards under Article 44 et seq. GDPR, unless an adequacy decision applies to the country concerned (see section 26). For creditworthiness checks, see section 9.
11. Newsletter and Direct Advertising
To send our newsletter and automated marketing emails, we use Klaviyo Inc., 225 Franklin Street, Boston, MA 02110, USA. The newsletter is sent using the double opt-in procedure on the basis of your consent (Article 6(1)(a) GDPR); consent is managed technically via consentmanager.
In addition, we use the email address you provided when making a purchase to send you direct advertising for our own products that are similar to those you purchased. This is done under the "soft opt-in" in Regulation 13(11) of S.I. No. 336 of 2011, without separate consent, unless you have objected; we inform you of your right to object at any time, free of charge, both when we collect your address and with every use.
You can unsubscribe at any time via the link at the end of every email or by message to info@edel-optics.de.
12. Wish List and Notification Emails
You can register for notifications about selected products (e.g. "item available again"). For this we process your email address in order to inform you when the selected event occurs. The legal basis is Article 6(1)(f) GDPR; you can object to these messages at any time without giving reasons (by email to info@edel-optics.de).
13. Customer Service
To handle your support requests (contact form, help centre, email) we use Zendesk, Inc., 989 Market Street, San Francisco, CA 94103, USA. The data you provide (name, email, request, attachments) are processed. Legal basis: Article 6(1)(b) or (f) GDPR.
To speed up processing, an initial reply to your email enquiry may be prepared with AI support; we label such messages transparently. This does not involve any solely automated final decision on your request.
Should we record telephone calls in future for quality-assurance or training purposes, we will inform you at the start of the call and will record only with your consent (Article 6(1)(a) GDPR); without consent you will be connected without any recording.
14. Virtual Try-On (2D/3D)
You can try on glasses virtually by uploading a photo or positioning your face via webcam. The technical provider is Fittingbox SA, 208 Route de Grenoble, 06200 Nice, France. Use is voluntary.
With the webcam option, no video recording or storage takes place; the camera feed is processed live only, in order to position the virtual glasses on the image. You are not identified in the process. The legal basis is Article 6(1)(a) or (f) GDPR.
An uploaded photo is automatically deleted after 14 days and is not analysed for advertising purposes.
15. Eye-Test Appointment Booking with Partner Opticians
Through our website you can arrange an appointment for an eye test with one of our partner opticians. For this we collect the contact data required to arrange the appointment (name, email, telephone number, preferred appointment/branch) and forward them to the relevant partner optician for confirmation. The examination itself takes place exclusively on site; no health or prescription data are collected via our website. Legal basis: Article 6(1)(b) GDPR.
16. Fulfilment via Partner Opticians
You can have your order delivered to a branch of our partner opticians for collection, and you can process returns, exchanges and warranty/guarantee claims there. Two of three details (order number, postcode, email address) are sufficient for authentication. The legal basis is Article 6(1)(b) GDPR and – in respect of fraud and misuse prevention during authentication – Article 6(1)(f) GDPR.
Your data remain on the systems of Edeloptics GmbH; the partner opticians act exclusively on our instructions on the basis of data processing agreements under Article 28 GDPR.
17. Shipping
Your order is shipped via UPS and DHL. For this we transmit the data required for delivery (name, delivery address, and contact data for shipment tracking where applicable). Legal basis: Article 6(1)(b) GDPR.
18. Fraud and Misuse Prevention
To protect against fraud, payment defaults and abusive behaviour, we check orders, accounts and payment transactions for anomalies and risk indicators. This also involves automated procedures as well as the security systems of our payment and service providers. The legal basis is our legitimate interest in preventing fraud and payment defaults (Article 6(1)(f) GDPR; cf. Recital 47 GDPR).
The rejection of an order may take place on a solely automated basis. This constitutes an automated decision in an individual case within the meaning of Article 22(1) GDPR, which is necessary for the prevention of fraud and payment defaults in the context of the initiation and performance of the contractual relationship (Article 22(2)(a) GDPR; cf. Recital 71 GDPR). You have the right to obtain human intervention, to express your point of view and to contest the decision – to do so, please contact info@edel-optics.de.
Internal block list. To enforce justified rejections and account blocks, we maintain an internal block list. Only the identification/contact data required for this (in particular name, email address, and address where applicable) and the reason for the block are processed.
The legal basis is Article 6(1)(f) GDPR (defence against fraud, payment defaults and abusive behaviour; cf. Recital 47 GDPR). The data are stored only for as long as necessary for the blocking purpose – as a rule, up to three years from the last documented incident; in the case of serious or repeated breaches, storage may continue beyond that. The data are not disclosed to third parties. You have a right to object under Article 21 GDPR.
19. Analytics Tools
The following services load only after you have given your consent (Article 6(1)(a) GDPR; see section 5).
Google Analytics 4. Web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, for analysing website use and measuring the success of our content. Data collection is routed through an infrastructure operated by us and placed upstream of Google; your IP address is masked in the process and is not transmitted to Google in a form that can be related to you. For transfers abroad, see section 26.
PostHog. Product analytics service of PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, for analysing and improving new features (including IP address, browser type, content visited, user interactions). Hosting takes place in the EU; depending on the configuration, this may also include the recording of entire sessions (session recording). Further information: posthog.com/privacy.
20. Advertising and Marketing Tools
The following services become active only after you have given your consent (Article 6(1)(a) GDPR). Beforehand, for technical reasons, at most anonymous reach signals without cookie storage are processed.
- Google Ads (Google Ireland Limited) – conversion measurement and remarketing, in part using hashed contact data, across our country-specific shops and Google Merchant Center.
- Meta Ads (Meta Platforms Ireland Limited) – success measurement and retargeting for advertising on Facebook/Instagram, in part using hashed contact data to attribute purchase and basket events.
- Microsoft/Bing Ads (Microsoft Ireland Operations Ltd. / Microsoft Corp., USA) – conversion tracking. The cookies set are valid for up to 180 days and do not serve to identify you personally.
- TikTok Ads (TikTok Technology Limited, Ireland) – success measurement and retargeting.
- Pinterest Ads (Pinterest Europe Ltd., Ireland) – success measurement and retargeting, in part using hashed contact data.
- Kickbite (Kickbite GmbH, Kolonnenstraße 8, 10827 Berlin, Germany) – marketing attribution and optimisation of our campaigns based on technical usage data.
You can withdraw your consent at any time via the cookie settings and via the provider-specific opt-out pages of the respective providers. For transfers abroad, see section 26.
21. Technical Administration and Further Service Providers
For the technical integration and control of the services used on our website, we use the Google Tag Manager (Google Ireland Limited). We use it to manage the code components of the tools deployed from a central point and to implement, in technical terms, the consent decision you have made via the consent tool. The Google Tag Manager does not itself carry out any substantive analysis of your usage behaviour, does not store any cookies and does not create any user profiles; its use is necessary for the technical operation of the website and the implementation of your consent (Article 6(1)(f) GDPR).
For the technical administration and optimisation of the tools named in sections 19–20, we also use further technical service providers. Data processing agreements under Article 28 GDPR are in place with each of them.
22. Social Media Presences
We operate our own company pages on Facebook and Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland). For the collection and processing of usage statistics of these pages ("Page Insights"), we are joint controllers with Meta within the meaning of Article 26 GDPR. Meta makes the joint controller arrangement available at facebook.com/legal/terms/page_controller_addendum. You can exercise your data subject rights primarily against Meta; we will support you within the scope of our possibilities.
23. Links to Third-Party Services
We have embedded links to third-party websites on our site, in particular to:
- youtube.com (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland);
- facebook.com (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland);
- instagram.com (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland);
- apps.apple.com (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland).
The mere embedding of the links does not involve any processing of personal data. Only when you activate a link are you redirected to the relevant website; the processing there is not our responsibility.
24. Google Maps
To display geographic information visually (e.g. the locations of our partner opticians), we use an interface of Google Maps, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map loads only after you have consented to this (Article 6(1)(a) GDPR); data about the use of the Maps functions are therefore transmitted to Google only after you have given your consent. Further information on the data processing carried out by Google can be found in its privacy notice at policies.google.com/privacy. For transfers abroad, see section 26.
25. Review Platforms
To collect and display customer reviews, we use the service Reviews.io (Reviews.io Ltd., London, United Kingdom); in future, Trusted Shops GmbH (Subbelrather Str. 15C, 50823 Cologne, Germany) or Trustpilot A/S (Pilestræde 58, 1112 Copenhagen, Denmark) may also be used for this. When you submit a review, the respective provider processes the data you provide (in particular name and content of the review). In so far as reviews are collected on our behalf and displayed on our website, a data processing agreement under Article 28 GDPR is in place; in so far as a review is published on the provider's own platform, or you maintain your own user account there, that processing falls under the responsibility of the provider. When the review elements embedded on our website are loaded, your IP address is also transmitted to the provider. The legal basis is our legitimate interest in meaningful customer reviews, or your consent (Article 6(1)(f) or (a) GDPR).
The invitation to submit a review is sent by us ourselves after a purchase; your data are not transmitted to the review services for this purpose. As with direct advertising for our own similar products (section 11), we send these invitations under the "soft opt-in" in Regulation 13(11) of S.I. No. 336 of 2011 and on the basis of our legitimate interest in authentic customer reviews (Article 6(1)(f) GDPR), unless you have objected. You can object at any time, free of charge – via the unsubscribe link in every invitation or by email to info@edel-optics.de; we point this out when we collect your email address and in every invitation. Should we handle the sending via a review service provider in future, we will transmit to it the data required for this (email address, name, order number); it will then act as a processor under Article 28 GDPR on our instructions.
26. Recipients and Transfers to Third Countries
A transfer to third parties takes place only where this is necessary for the performance of the contract, where a legal obligation exists, where you have consented, or where a legitimate interest overrides (Article 6(1)(b), (c), (a) or (f) GDPR). Data processing agreements under Article 28 GDPR are in place with service providers that process on our behalf.
In the course of the further development of our business, it may happen that we sell, restructure or merge our company or parts of it with other companies. In such a case, personal data may be transferred to the acquirer or legal successor to the extent necessary. The legal basis is our legitimate interest in the transfer and continuation of our business operations (Article 6(1)(f) GDPR).
Where we are affiliated with other companies under company law, we may exchange personal data within the group of companies for internal administrative purposes (e.g. central customer administration, IT, accounting), to the extent necessary for this. The legal basis is our legitimate interest in efficient internal organisation (Article 6(1)(f) GDPR, Recital 48 GDPR).
Where providers transfer data to the USA, this is done on the basis of EU Standard Contractual Clauses (Article 46(2)(c) GDPR) and/or – where the provider is certified – the EU-US Data Privacy Framework. Where recipients are located in the United Kingdom (for example the review service Reviews.io, see section 25), the transfer is covered by the European Commission's adequacy decision for the United Kingdom, to the extent that decision is in force, and otherwise by appropriate safeguards under Article 46 GDPR. Despite these safeguards, a residual risk of access by authorities in the third country remains.
27. Retention Period
We store your data only for as long as is necessary for the respective purposes or for as long as statutory retention obligations exist (in particular generally six years under applicable Irish company and tax law, e.g. section 285 of the Companies Act 2014 and section 886 of the Taxes Consolidation Act 1997). Customer accounts remain in place until they are closed. Data stored for advertising purposes are deleted or blocked as soon as you object or withdraw your consent.
28. Minors
Our offering is not specifically directed at children under 16. Persons under the age of 16 should transmit personal data to us only with the consent of a person holding parental responsibility. Where we rely on consent in relation to an information society service offered directly to a child, a child in Ireland can give valid consent from the age of 16 (section 31 of the Data Protection Act 2018).
*Note for Malta: the age of digital consent is 13 rather than 16 – see the Data Protection Act (Chapter 586 of the Laws of Malta) and its subsidiary legislation. Data subjects in Malta can therefore give valid consent for information society services from the age of 13.*
29. Your Rights as a Data Subject
You have the right of access (Article 15), the right to rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and the right to withdraw consent you have given, with effect for the future (Article 7(3) GDPR).
You also have the right to lodge a complaint with a data protection supervisory authority (Article 77 GDPR) – in particular with the supervisory authority of your habitual residence or place of work, or the authority responsible for us (see section 1). In Ireland this is the Data Protection Commission (DPC); in Malta, the Information and Data Protection Commissioner (IDPC).
30. Right to Object
Where your data are processed on the basis of legitimate interests (Article 6(1)(f) GDPR), you have the right to object on grounds relating to your particular situation (Article 21(1) GDPR). Where the objection is directed against direct marketing, there is a general, unconditional right to object (Article 21(2) GDPR). An email to info@edel-optics.de is sufficient.
31. Data Security
Within the website visit we use transport encryption (TLS) in line with the current state of the art, together with appropriate technical and organisational measures, in order to protect your data against manipulation, loss or unauthorised access by third parties. Our security measures are continuously being developed further.
32. Currency and Amendment of this Privacy Notice
This Privacy Notice is dated July 2026. As our website develops, or as a result of changed legal or regulatory requirements, an amendment may become necessary. The current version is available at all times at www.edel-optics.ie/Privacy.html.
---
*Edeloptics GmbH · Privacy Notice · dated July 2026.*