1. Data Protection Overview
This privacy policy explains how EXTRA Group GmbH ("we", "us") collects, processes, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
2. Data Controller
EXTRA Group GmbH
Mathes-Deutsch-Weg 24B
84036 Landshut, Germany
Phone: +49 871 97407340
Email: service@timeless-bespoken.com
3. Data Collection
Website Visits: When you visit our website, we automatically collect:
- IP address (anonymized)
- Browser type and version
- Operating system
- Referrer URL
- Date and time of access
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in website security).
Contact Forms & Orders: When you contact us or place an order, we collect:
- Name and title
- Email address
- Phone number (optional)
- Shipping/billing address
- Body measurements (for bespoke orders)
- Payment information
Legal basis: Art. 6(1)(b) GDPR (contract performance).
4. Cookies
Essential Cookies: Required for website functionality (no consent needed).
Analytics Cookies: Used only with your explicit consent to improve our services.
You can manage cookie preferences at any time via the cookie settings.
5. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access (Art. 15): Request information about your stored data
- Rectification (Art. 16): Request correction of inaccurate data
- Erasure (Art. 17): Request deletion ("right to be forgotten")
- Restriction (Art. 18): Request limitation of processing
- Portability (Art. 20): Receive your data in machine-readable format
- Objection (Art. 21): Object to processing based on legitimate interests
- Withdraw Consent (Art. 7): Withdraw consent at any time
To exercise your rights, contact: service@timeless-bespoken.com
6. Data Retention
We retain personal data only as long as necessary:
- Order data: 10 years (German tax law)
- Contact inquiries: 3 years
- Analytics data: 26 months
7. Data Security
We implement appropriate technical and organizational measures including SSL/TLS encryption, secure servers, and access controls.
8. Third-Party Processors
We may share data with:
- Hosting providers (EU-based)
- Payment processors (PCI-DSS compliant)
- Shipping carriers (for order fulfillment)
All processors are contractually bound to GDPR compliance.
9. International Transfers
Data is primarily processed within the EU/EEA. Any transfers to third countries comply with GDPR Chapter V requirements.
10. Supervisory Authority
You have the right to lodge a complaint with:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
Last updated: December 2025