Privacy Policy

With this privacy policy we would like to inform you about how we process personal data. We are aware of the importance of processing personal data for the user. The protection of your privacy is of utmost importance to us. In our privacy policy you will learn which data we store for what reasons, what rights and choices you have and what data we use for our advertising.

1. Collection of personal data

1.1. Personal data is all data that can be related to you personally, e.g. name, address, e-mail addresses, user behaviour.

1.2. The controller, following the EU General Data Protection Regulation (GDPR) is Caelis sàrl -hello@birtznutrition.com. You can reach our data protection officer by e- mail or at our commercial postal address (Banzelt 4A, L-6921, Roodt-sur-Syre, Luxembourg) with the addition "to the data protection officer".

1.3. During the informative use of our website, we only collect the personal data that your browser transmits to our server. When you view our website, we collect the following data, which is technically necessary for us to display our website and to ensure stability and security:

- IP address
- Date and time of the request
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (concrete page)
- Access status/HTTP status code
- Data volume transferred in each case
- Website from which the request comes
- Browsers
- Operating system and its interface
- Language and version of the browser software

1.4. If you contact us, we will store your contact details in order to answer your questions.

1.5. If you register for one of our services, we store personal information about you, for example your first name and surname, the title, your contact details.

1.6. When you order something from us, we collect your purchased products and payment data.

1.7. If you use our services, i.e. order from us, set up a customer account or, for example, participate in the loyalty, subscription or bonus system, we collect data that enables us to perform customer structure analyses and user segmentation.

1.8. When you communicate with us or other users about products (e.g. evaluations) or other topics, we collect the content of your communications. Product evaluations can be published within our service.

1.9. We also use the offers of digital social networks for communication. Please note that we have no influence on the terms of use of these social networks and the services they offer and only limited influence on their data processing. Therefore, please check which personal data you share with us via these social networks.
We currently use social links from the following social networks:

- Facebook
- Instagram
- YouTube
- TikTok
- Linkedin

The links to their respective privacy policies can be found within this document in article 6.

1.10. We also collect data about the current location of your device. If you enable your device's location services for us, we will process the location data collected from your device and provided to us to provide you with location-based services. We also collect location data derived from the IP address of your device (down to city level). This procedure (so-called geolocation) is used for example, in fraud detection to identify suspicious orders (e.g. in certain situations it may be suspicious if the IP address of a country from which you have not yet placed an order is used for an order via your customer account).

1.11. Finally, when using our services, it is unavoidable that technical data is created and processed in order to provide and display the functions and content offered. Device and access data is generated with every use of an online and mobile service. Device and access data includes general device information, such as information about the type of device, the version of the operating system, configuration settings, information about the Internet connection and the app used as well as identification data, such as session IDs, cookie IDs, unique device IDs, third-party account IDs (if you use social plug-ins or social logins or payment via PayPal) and other common internet technologies in order to recognize your web browser, your device or a specific app installation.

1.12. The legal basis for the above referred processing of your personal data is our existing legitimate interest in providing updated and accurate information on our products and services, as well as lawful interaction with our users and visitors in accordance with Art. 6 (1) GDPR.

2. Your rights

You have the following rights in relation to personal data relating to you:

- Data subject's right to information: You have the right to request confirmation from us as to whether personal data relating to you are being processed and, if so, what these are, as well as the more detailed circumstances of the data processing.

- Right to rectification: You have the right to demand that we correct any inaccurate personal data relating to you without undue delay. Taking into account the purposes of the processing, you also have the right to request the completion of incomplete personal data - also by means of a supplementary declaration.

- Right to deletion: You have the right to demand that we delete personal data concerning you without delay.

- Right to restrict processing: You have the right to demand that we restrict processing.

- Right to data portability: You have the right, in the event of processing based on consent or for the performance of a contract, to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format, and to transfer this data to another controller without hindrance from us, or to have the data transferred directly to the other controller, insofar as this is technically feasible.

- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is necessary for legitimate interests on our part or for the performance of a task carried out in the public interest, or which is carried out in the exercise of official authority. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the purpose of asserting, exercising or defending legal claims.

- You have the right to object to the processing of personal data for direct marketing at any time. If you object to the processing for direct marketing purposes, we will no longer process your personal data for these purposes.

- You have the right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a supervisory authority at any time, in particular in the member state of your place of residence, or the place of the alleged infringement, if you are of the opinion that the processing of personal data concerning you violates applicable law.

- If you have given us consent, you have the right to revoke your consent at any time. All data processing that we have carried out until you revoke your consent will remain lawful in this case. To do so, you can simply click on the link contained in each email and unsubscribe from the email service, make the appropriate setting in your user account or send a message to hello@birtznutrition. If you inform us in this message that you do not wish to receive any future e-mails, we will no longer send any messages to your provided e-mail address.

3. Data sources

3.1 Much of the data we process is provided by yourself, for example, when you contact us, register or order something from our shop and provide us with your name, email address or postal address. We also receive technical device and access data that is automatically collected by us when you use our services, for example, about which device you are using. We collect further data through our own data analyses and may also receive data about you from third parties, for example from credit agencies and payment service providers.

3.2. In order to fill out the range of functions of our website and to make it more convenient for you to use, we use the so-called "cookies". With the help of these "cookies", data can be stored on your computer when you visit our website.

They serve to make the internet offer more user-friendly and effective.

-Technical cookies;
-Performance Cookies;
-Advertising Cookies;
-Sharing cookies.

Any use of cookies that is not absolutely technically necessary constitutes data processing that is only permitted with your explicit and active consent.

4. Data security, storage period and transmission of personal data to third parties

4.1. We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties (e.g. TSL encryption for our website), taking into account the state of the art, the implementation costs and the nature, scope, context and purpose of the processing, as well as the existing risks of a data breach (including its probability and impact) for the data subject. Our security measures are continuously improved in line with technological developments.

We use the data internally, but also share some with external partners. Broad
categories include:

The operators of our warehouses: "Stockabee SL":

Marketing partners and advertising platforms such as Facebook or direct mail
companies;

Software systems for the management of data such as Shopify or Klaviyo;

Web tracking data such as Google AdWords, Facebook, Google Analytics.

4.3. Data storage

We store your data if you have consented to the processing, at most until you withdraw your consent. If we need the data for the execution of a contract, at most for as long as the contractual relationship with you exists or legal retention periods run.

The legal bases stated in the context of the processing purposes apply accordingly.

Third parties engaged by us will store your data on their systems for as long as is necessary in connection with the provision of services for us in accordance with the respective order.

4.4. The following categories of recipients may have access to your personal data:

- Service providers for the operation of our website and the processing of data
stored or transmitted by the systems (e.g. for data center services, payment
processing, IT security);
- Government agencies/authorities, insofar as this is necessary for the fulfilment
of a legal obligation;
- Persons employed to carry out our business operations (e.g. auditors, banks,
insurance companies, legal advisors, supervisory authorities, parties involved in
company acquisitions or the establishment of joint ventures).

5. Web analysis

We use analytics tools in the form of tracking software to determine the frequency of use and number of users of our website.

On our website we use Google Analytics of Google LLC ("Google"), 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA. Google Analytics is used for web analysis and optimization of use on the website. Information of the third party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland. User conditions: http://www.google.com/analytics/terms/de.html Overview of data protection:
http://www.google.com/intl/de/analytics/learn/privacy.html

6. Usage-related advertising

The advertising displayed on this website is optimized by the anonymous collection and processing of usage behaviour, so that persons get ads tailored to their interests. For this purpose, a cookie is stored on your computer. This targeting is operated by third- party companies that also run advertising for websites of other companies. These are the following companies:

Google AdWords

Our website uses Google AdWords from Google LLC ("Google"), 1600 Amphitheatre Parkway, Mountain View, CA 94043 USA. AdWords is an online advertising program. You can find more information at: https://www.google.de/policies/privacy/

Facebook

This website uses the remarketing function "Custom Audiences" of Facebook Inc., 1 Meta Way, Menlo Park, California, 94025. This function is used to present interest- based advertisements ("Facebook Ads") to visitors of this website when they visit the social network Facebook. More information at: https://www.facebook.com/about/privacy/

Instagram

Our website uses so-called social plugins ("plugins") from Instagram, which is operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Dublin D04 X2K5, Ireland ("Instagram"). The plugins are marked with an Instagram logo. An overview of the Instagram data policy can be found here: https://help.instagram.com/519522125107875/?helpref=hc_fnav


For the purpose and scope of the data collection and the further processing and use of the data by Instagram, as well as your rights in this regard and setting options for protecting your privacy, please refer to the privacy policy of Instagram: https://help.instagram.com/155833707900388

YouTube

This website uses plugins from Youtube.de/Youtube.com, which are operated by YouTube, LLC, 6 Pancras Square, King's Cross, London N1C 4AG, United Kingdom. When a user calls up a website that contains such a plugin, his browser establishes a direct connection with the YouTube servers. Further information on this can be found in the privacy policy: https://policies.google.com/privacy?hl=en

Linkedin

This website offers a service of ads and marketing campaign management. It is operated by LinkedIn Ireland Unlimited Company at Wilton Place, Dublin 2, Ireland. Its privacy policy can be found below: https://www.linkedin.com/legal/privacy/eu

TikTok

Our website uses social plugins from TikTok, which is operated by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland ("TikTok"). The plugins are marked with a TikTok logo. An overview of TikTok data policy can be found here:https://www.tiktok.com/legal/page/eea/privacy-policy/en

7. Third party services

As any company, we use external domestic and foreign service providers to conduct our business (e.g. for IT, logistics, telecommunications, sales and marketing). These include:

PayPal

The PayPal service is provided by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. When paying with PayPal, you will be redirected to the PayPal website via a link. For the use of this service PayPal collects, stores and processes your personal data such as name, address, telephone number and e-mail address as well as credit card or bank account data. PayPal is solely responsible for the protection and handling of the data collected by PayPal. In this respect, the PayPal terms of use apply, which you can access at www.PayPal.com. You can find more information about the handling of your data in PayPal's privacy policy, which is available at the following link:https://www.paypal.com/lu/legalhub/paypal/upcoming-policies-full?locale.x=en_LU

Klarna

If you choose a payment method offered by "Klarna", the payment will be processed by the payment service provider Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. During the payment process you will be redirected to the website of Klarna via a link. For the use of this service Klarna collects, stores and processes your personal data such as name, address, telephone number and e-mail address as well as credit card or bank account data. Klarna is solely responsible for the protection and handling of the data collected by Klarna. In this respect, the Klarna terms of use apply, which you can access at www.klarna.com. You can find more information about the handling of your data in the Klarna privacy policy in the following link:https://www.klarna.com/international/privacy-policy/

Stripe

If you decide to use a payment method offered by "Stripe", the payment will be processed by the payment service provider Stripe Payments Europe Ltd, The One Building, 1, Lower Grand Canal Street, Dublin 2, D02 H210, Ireland (hereinafter "Stripe"), to whom we pass on the information you provided during the ordering process, together with information about your order (name, address, account number, bank code, credit card number, if applicable, invoice amount, currency and transaction number). The transfer of your data takes place exclusively for the purpose of payment processing. You can find more information about Stripe's data protection on the Internet at:https://stripe.com/de/privacy

Shopify

All our orders are processed through Shopify International Limited 2nd Floor 1-2 Victoria Building, Haddington Road, Dublin 4 D04 XN32, Ireland (hereinafter "Shopify"). Your details (name, address, email address, account number, invoice amount, currency and transaction number) provided as part of the ordering process in addition to the order details will be passed on to Shopify. The transmission of your data takes place exclusively for the processing of your order. For more information about Shopify's privacy policy, please visit:https://www.shopify.com/legal/privacy

Stockabee S.l.

The compilation of our delivery and the creation of the shipping labels is done by our contractual partner Stockabee S. L. (C/ Tapiceros 5, 28830 Torrejón de Ardoz, Madrid, Spain). To this partner we transmit the delivery data of the recipient of the goods. The transmission of the data takes place exclusively for the completion of the orders.

8. Applicable law – territorial jurisdiction and language

This website is subject to Luxembourg law and regulations. Exclusive jurisdiction is given to the Luxembourg Courts to hear any dispute relating to the use, interpretation and execution of the information and data appearing on this website. English version of this notice will be retained as the primary source.

9. Final remarks

The present data protection notice will regularly be reviewed further to legal evolution and/or if required by technological or organizational reasons.


This privacy notice is current as of October 2025.