Privacy Policy

Privacy Policy

Operator: 4Unit Systems Integration GmbH Platform: OwnTheOrder Last Updated: January 23, 2026

---

Welcome to our Privacy Policy

This privacy policy explains in simple terms what data we collect, how we use it, and what rights you have.

Important: We take the protection of your personal data very seriously and comply with all German and European data protection laws.

---

1. Who is responsible for your data?

Data Controller

4Unit Systems Integration GmbH

Jahnstraße 36
34582 Borken (Hessen)
Germany

Contact:

Phone: +49 5682 73 48 26
E-Mail: info@4unit.com
Website: https://4unit.com

Data Protection Contact

For data protection inquiries, please contact our Data Protection Coordinator:

E-Mail: datenschutz@4unit.com
Phone: +49 5682 73 48 26

Note: As our company has fewer than 10 employees, appointing a Data Protection Officer is not legally required under Art. 37 GDPR.

---

2. What data do we collect?

When you place an order

Personal data:
  • Your first and last name
  • Your delivery address
  • Your email address
  • Your phone number
Order data:
  • What you ordered
  • When you ordered
  • How much you paid
  • Special requests (e.g., "no onions")
Payment data:
  • Selected payment method
  • For card payments: encrypted payment information
  • We do NOT store complete credit card numbers!

---

3. Who receives your data?

Payment Service Providers

Who:
  • Stripe (for credit cards)
  • PayPal (for PayPal payments)
  • Iyzico (for payments in Turkey)

Data Processing Agreements (DPA)

We have concluded data processing agreements pursuant to Art. 28 GDPR with all payment service providers:

  • Stripe:
    - Data processor for credit card payments
    - Third country: USA
    - Safeguards: EU-US Data Privacy Framework (Adequacy Decision)
    - DPA: Standard Contractual Clauses (SCC)
  • PayPal:
    - Data processor for PayPal payments
    - Third country: USA
    - Safeguards: EU-US Data Privacy Framework
    - DPA: PayPal Data Processing Agreement
  • Iyzico:
    - Data processor for Turkish payments
    - Country: Turkey
    - Safeguards: KVKK-compliant (Turkish data protection law)
    - DPA: Standard Data Processing Agreement

All payment data is transmitted and processed in encrypted form. We do not have access to complete credit card numbers.

---

4. How long do we store your data?

Order data

Retention period: 10 years Why: Legal retention obligation pursuant to § 147 AO (German tax law) What happens then: Automatic deletion after expiration

Customer account

Retention period: Until deletion by you or 12 months after last login You can: Delete your account at any time

Technical logs

Retention period: 90 days What happens then: Automatic deletion

Analytics data (anonymized)

Retention period: 1 year What happens then: Automatic deletion

Newsletter consent

Retention period: Until revocation You can: Revoke your consent at any time

---

5. Your rights

You have the following rights:

Right of access (GDPR Art. 15)

You can request which data we have stored about you.

Right to rectification (GDPR Art. 16)

You can have incorrect data corrected.

Right to erasure (GDPR Art. 17)

You can request deletion of your data (except data we must retain by law).

Right to data portability (GDPR Art. 20)

You will receive your data in a format that you can transfer to other providers.

Right to lodge a complaint (GDPR Art. 77)

You can file a complaint with a data protection authority:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Postfach 3163
65021 Wiesbaden, Germany
Phone: +49 611 1408-0
E-Mail: poststelle@datenschutz.hessen.de

---

Last updated: January 23, 2026 Thank you for your trust!
Back to Homepage