Privacy Policy
PRIVACY POLICY
Aipax Brands e.K. • Siriusstraße 6 • 12524 Berlin • Germany Information on the processing of personal data in accordance with the EU General Data Protection Regulation (GDPR), the Telecommunications-Digital Services Data Protection Act (TDDDG), and applicable international data protection law.
PREAMBLE
Aipax Brands e.K. takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. Below, we inform you in detail about the nature, scope, and purpose of the collection and processing of your personal data within the framework of our business activities, our online shop (e-commerce, dropshipping, print-on-demand), our B2B services (web design, marketing consulting, compliance training), and our AI-powered media production.
1. CONTROLLER & CONTACT
1.1 The Controller within the meaning of the GDPR
The controller for data processing on this website and within the framework of our contracts is:
Aipax Brands e.K. Siriusstraße 6, 12524 Berlin Germany E-mail: Service@Aipax-Brands.com Phone: +49 30 55527690 Fax: 030 22185936, Registry Court: Amtsgericht Charlottenburg Registration Number: HRA 65650, VAT Identification Number according to § 27a UStG: DE354290944
1.2 Data Protection Officer
A statutory data protection officer has not been appointed for Aipax Brands e.K. and is not legally required, as the conditions for mandatory appointment according to § 38 BDSG and Art. 37 para. 1 GDPR (in particular, the continuous employment of at least 20 persons with the automated processing of personal data) are not met. You can contact our management directly at Service@Aipax-Brands.com for all data protection concerns.
2. DATA COLLECTION WHEN VISITING OUR WEBSITE
2.1 Server Log Files
When you use our website for purely informational purposes, we only collect the data that your browser automatically transmits to our web server. These server log files include: - The visited page of our website - Date and time of access - The amount of data sent in bytes - The source/reference from which you came to our site (referrer URL) - The web browser used, including version - The operating system used - The IP address used (possibly in anonymized form)
Legal Basis: Processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in ensuring the stability, functionality, and security of our systems and in warding off attack attempts. Server log files are stored for a maximum of 7 days for security reasons and then deleted. These data are not stored together with other personal data of the user.
3. COOKIES & TRACKING TECHNOLOGIES (TDDDG & GDPR)
3.1 Strictly Necessary Technologies (Essential)
We use cookies and similar technologies (e.g., Local Storage) on our website that are strictly necessary to provide the basic functions of our website (e.g., maintaining the shopping cart in the online shop, saving login status, cookie consent preferences).
Legal Basis: Access to information on the user's end device and the storage of cookies is based on Section 25 para. 2 no. 2 TDDDG. The subsequent data processing is based on Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in providing a technically flawless, optimized, and user-friendly online service.
3.2 Technologies Requiring Consent (Analytics, Marketing, Social Media)
For all other tracking and storage technologies that are not strictly necessary (e.g., Google Analytics, Meta Pixel, TikTok Pixel, Shopify Tracker), we obtain your express consent in advance via our cookie consent banner.
Legal Basis: Access to your end device is based on Section 25 para. 1 TDDDG. The subsequent data processing is based on Art. 6 para. 1 lit. a GDPR. You can adjust or completely revoke your consent at any time with effect for the future via the cookie consent banner on our website.
4. DATA PROCESSING IN E-COMMERCE & DROPSHIPPING (TRIANGULAR TRANSACTION)
4.1 Order Processing
When you purchase products in our online shop, we process your personal data (name, delivery and billing address, email address, phone number, payment data, order data) to process the purchase contract.
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance).
4.2 Logistics Processing in Dropshipping (Triangular Transaction)
Since we primarily sell products via dropshipping, we cooperate with various external production, warehousing, and logistics partners (Third-Party Logistics / 3PL) worldwide. To fulfill our contractual obligations, we pass on your delivery data (name, address, possibly phone number for notifications) to the respective dropshipping or fulfillment partner responsible for the product. This partner processes your data strictly for the purpose of manufacturing (e.g., print-on-demand) and direct shipping of the goods to you.
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance).
4.3 Data Transfer to Third Countries (Non-EU/EEA)
If the goods are shipped directly to you from a production partner or supplier in a third country outside the European Union (e.g., Asia or USA) as per the order, your address data must be transmitted to this foreign partner. - Safeguards: If there is no adequacy decision by the EU Commission for the respective third country, we secure the data transfer by concluding Standard Contractual Clauses (SCC) of the EU Commission to ensure an adequate level of data protection. - Additional Legitimation: The transfer is also legitimized by Art. 49 para. 1 lit. b GDPR, as the transfer of your address data to the foreign shipping partner is absolutely necessary for the fulfillment of the purchase contract between you and Aipax Brands e.K.
5. PAYMENT SERVICE PROVIDERS
To process payments, we use external payment service providers (e.g., Stripe, PayPal, Shopify Payments, Klarna). When a payment is made, your payment data (e.g., bank details, credit card data, amount, transaction ID) are transmitted to the selected payment service provider.
Legal Basis: Art. 6 para. 1 lit. b GDPR (payment processing for contract fulfillment). The payment providers sometimes process this data as their own data controllers. Please note the respective privacy policies of the payment service providers during the payment process.
6. DATA PROCESSING FOR B2B SERVICES & COMPLIANCE TRAINING
6.1 Mandate Processing & Consulting
If you commission us with digital and marketing services, the creation of websites, advertising campaigns, or with a consulting mandate (strategy consulting, coaching, compliance training), we process your business contact data, communication data, access data, and contract data for the execution of the service relationship.
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract performance).
6.2 Order Processing (DPA) according to Art. 28 GDPR
If, in the course of our services (e.g. web design, campaign management), we obtain access to personal data of your end customers, we act as a data processor for you. In this case, we conclude a legally required data processing agreement (DPA) in accordance with Art. 28 GDPR before commencing activities.
7. USE OF ARTIFICIAL INTELLIGENCE (AI) & MEDIA CONTENT
Aipax Brands e.K. uses state-of-the-art artificial intelligence (AI) to create and optimize creative media content, services, and its own products. The following strict data protection and transparency rules apply:
7.1 AI Media Transparency Notice (Art. 50 AI Regulation / EU AI Act)
In accordance with the transparency obligations of the European AI Act, we inform you that visual media (images, graphics, avatars, videos, animations) and auditory content (songs, melodies, synthetic voices, voiceovers) on our websites and in customer projects have been partially or fully generated using AI systems. - Risk Minimization and Exclusion of Third-Party Rights: These AI-supported generations are dynamic processes of the creative workflow. As these systems are trained on complex data, it cannot be theoretically ruled out that unforeseen acoustic, visual, or structural similarities to existing real works, persons, voices, or templates may occur. - Proactive Clarification Process: Should you believe that an AI content used by us violates trademark rights, copyrights, personal rights, or data protection rights, please contact us directly at Service@Aipax-Brands.com. We will promptly investigate your notice and, if justified, will immediately take corrective action (e.g., by replacing, modifying, or deleting the media in question).
7.2 Processing of Customer Data in AI Systems
If you provide us with image material (e.g., portrait photos for character generations), audio files, or other personal templates within the scope of an order, we will process these exclusively for the purpose of fulfilling the contract.
Legal basis: Art. 6 para. 1 lit. b GDPR. - Protection against Model Training: When using third-party AI systems to process these orders, we ensure through contractual agreements (e.g., data processing agreements with API providers, enterprise licenses) that the data you transmit (e.g., customer images) are not used for training the providers' public AI models. - Deletion: The transmitted photos and source data will be completely deleted after successful project completion and expiry of the statutory retention periods.
8. INTERNATIONAL DATA TRANSFER (THIRD COUNTRY TRANSFERS)
Due to global IT infrastructures, dropshipping structures, digital marketing channels (e.g., Meta Ads, Google Ads, TikTok Ads) and the use of globally operating software and AI providers, the transfer of data to third countries outside the EU or the EEA is unavoidable. To ensure the legal security of these data flows, we rely on: - Adequacy Decisions (Art. 45 GDPR): In particular, the EU-US Data Privacy Framework for certified service providers in the USA. - Standard Contractual Clauses (SCCs) according to Art. 46 para. 2 lit. c GDPR: For service providers and partners in third countries without an adequacy decision, we conclude the current Standard Contractual Clauses of the EU Commission. - Exceptions according to Art. 49 GDPR: For the execution of purchase contracts in dropshipping procedures directly from third countries.
9. RIGHTS OF DATA SUBJECTS
As a data subject, you have the following rights vis-à-vis Aipax Brands e.K.: - Right to information (Art. 15 GDPR): You can request information about your personal data processed by us. - Right to rectification (Art. 16 GDPR): You can request the immediate correction of inaccurate or completion of your data stored by us. - Right to erasure (Art. 17 GDPR): You can request the erasure of your data, unless the processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims. - Right to restriction of processing (Art. 18 GDPR): You can request the restriction of processing of your data as long as the accuracy of the data is being verified or erasure is refused. - Right to data portability (Art. 20 GDPR): You have the right to receive your data in a structured, commonly used and machine-readable format or to have it transmitted to another controller. - Right to withdraw consent (Art. 7 para. 3 GDPR): You can withdraw any consent given for data processing at any time with effect for the future. - Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): You can lodge a complaint with a data protection supervisory authority about our processing of your personal data.
RIGHT TO OBJECT (Art. 21 GDPR)
If we process your personal data on the basis of a balancing of interests due to our legitimate interest (Art. 6 para. 1 lit. f GDPR), you have the right to object to this processing at any time with effect for the future for reasons arising from your particular situation.
If you exercise your right to object, we will cease processing the data concerned. However, further processing remains reserved if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves to assert, exercise, or defend legal claims.
10. DATA RETENTION & DELETION
Data processed by us will be deleted or their processing restricted as soon as they are no longer necessary for their intended purpose and no legal retention obligations prevent their deletion. - Commercial law retention: 6 years according to § 257 para. 1 HGB (commercial books, inventories, opening balance sheets, annual financial statements, commercial letters, etc.). - Tax law retention: 10 years according to § 147 para. 1 AO (books, records, booking vouchers, invoices, documents relevant for taxation, etc.).
During these statutory retention periods, the data will be blocked and not processed for other purposes. After the expiry of the deadlines, the data will be deleted in compliance with data protection regulations.