EUR

en_US
Currency
  • ALL
  • AMD
  • AZN
  • BYR
  • BGN
  • HRK
  • DKK
  • EUR
  • GEL
  • HUF
  • ISK
  • KZT
  • MKD
  • MDL
  • NOK
  • PLN
  • RON
  • RUB
  • RSD
  • UAH
Country/Language
  • eu
  • es
  • de
  • si
  • co.uk
  • fr
  • it
  • se
Shipping to United States

Privacy Policy

Privacy Policy

Last updated: July 10, 2025

Welcome to MARO GmbH's privacy policy. Your privacy is critically important to us; we are committed to protecting personal data in full compliance with the EU General Data Protection Regulation (GDPR) and all related legislation. This document describes how we collect, use, disclose, transfer, and store your personal data when you visit our website tooaleta.eu or engage our services.

1. Data Controller & Contact

Data Controller:
MARO GmbH
Bahnhofplatz 5/Top 9,
9020 Klagenfurt am Wörthersee, Austria
Email: info@tooaleta.eu
Phone: +43 463 503 130

Data Protection Officer (DPO):
Email: dpo@tooaleta.eu
Office hours: Mon–Fri, 9:00–17:00 CET

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data (collection, storage, use, transfer, deletion).
  • Data Subject: An individual whose personal data is processed by MARO GmbH.
  • Controller: The entity determining the purposes and means of processing personal data.
  • Processor: Third-party service provider acting on behalf of the controller.

3. Data We Collect & Why

3.1. Identity Data

Name, title, date of birth — to verify identity for account creation, order processing, and support.

3.2. Contact Data

Email, phone, billing/shipping address — to communicate, deliver goods, send invoices, and customer service.

3.3. Payment Data

Card or bank details — processed securely by Stripe, Klarna, or our bank. We do not store full payment details on our servers.

3.4. Technical & Usage Data

IP address, browser type, device identifiers, browsing behavior — to ensure site functionality, detect fraud, and improve UX.

3.5. Marketing & Preference Data

Subscription status, consent records — to send newsletters, promotions, and tailored offers with your permission.

4. Lawful Basis for Processing (Art. 6 GDPR)

PurposeLawful BasisRetention
Order fulfillment Performance of contract 10 years
Compliance with legal obligations Legal obligation As required
Fraud prevention & security Legitimate interest 3 years
Marketing communications Consent Until withdrawal + 2 years

5. Data Retention & Deletion

We retain data only for the period necessary to fulfill the processing purposes and legal requirements. Once no longer required, data is securely deleted or anonymized.

6. Cookies & Tracking Technologies

6.1. Categories of Cookies

  • Strictly Necessary: Essential for site operation (e.g., session cookies).
  • Performance & Analytics: Google Analytics, Hotjar — to analyze site usage and performance.
  • Functionality: Remember choices (language, region).
  • Marketing: Tracking pixels (Facebook, Google Ads) — to deliver tailored ads.

6.2. Managing Cookies

You can manage your preferences in our Cookie Settings or via browser settings. Disabling essential cookies may affect site functionality.

7. Sharing & Disclosure

7.1. Service Providers / Processors

  • Payment processors: Stripe, Klarna
  • Logistics: DHL, GLS, DPD, Kuehne+Nagel
  • Hosting: AWS, Cloudflare
  • Email & Marketing: Mailchimp

7.2. Legal Requirements

We may disclose data to comply with court orders, legal processes, or governmental requests.

8. International Data Transfers

Transfers outside the EEA occur only under approved mechanisms, such as:

  • EU Standard Contractual Clauses (SCCs)
  • EU-US Data Privacy Framework participants

9. Your Rights

As a data subject, you have the right to:

  • Access & receive a copy of your data (Art. 15 GDPR)
  • Correct inaccurate data (Art. 16)
  • Delete your data (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent anytime for marketing (Art. 7)
  • Lodge complaints with a supervisory authority (e.g., Austrian DPA)

To exercise any right, contact our DPO at dpo@tooaleta.eu. We will respond within one month.

10. Security Measures

  • Encryption (HTTPS/SSL)
  • Access controls & authentication
  • Regular security assessments & penetration testing
  • Data minimization & pseudonymization practices

11. Data Breach Notification

In the event of a data breach compromising your rights, we will notify you and the relevant supervisory authority within 72 hours, per GDPR requirements.

12. Minors

Our website is not intended for individuals under 16 years of age. We do not knowingly collect data from minors. If you believe we have inadvertently collected data for a minor, contact our DPO immediately.

13. Changes to This Policy

We may update this policy periodically. We will post the revised version with an updated "Last updated" date. Significant changes will be communicated via email for registered users.

14. Contact & Complaints

For any questions, requests, or complaints, please contact:

Data Protection Officer: dpo@tooaleta.eu

Or write to: MARO GmbH, Bahnhofplatz 5/Top 9, 9020 Klagenfurt am Wörthersee, Austria.


Copyright©, Tooaleta Group, Maro GmbH