Privacy policy

This English translation is provided for convenience only. The German version is legally binding.

Last updated: August 19, 2026

1. Controller

The controller responsible for data processing on this website is:

galactics GmbH Mühlenstraße 8a 14167 Berlin

Phone: +49 (0)30 75437055 E-mail: info@acid-berlin.de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data. A data protection officer has not been appointed, as the statutory requirements for a mandatory appointment are not met.

2. General Information

2.1 Legal Bases

We process personal data only where a legal basis permits this. The following in particular may apply:

  • Art. 6(1)(a) GDPR — your consent (revocable at any time with effect for the future);
  • Art. 6(1)(b) GDPR — performance of a contract or pre-contractual measures (e.g. order processing);
  • Art. 6(1)(c) GDPR — compliance with legal obligations (e.g. retention requirements under commercial and tax law);
  • Art. 6(1)(f) GDPR — safeguarding legitimate interests, provided your interests do not override them.

Where information is stored on or read from your device (e.g. cookies), this is additionally governed by Section 25 of the German TDDDG (Telecommunications Digital Services Data Protection Act): consent is required under Section 25(1) TDDDG, with an exemption for strictly necessary storage and read operations under Section 25(2) TDDDG. We state the applicable legal basis for each individual processing operation.

2.2 Recipients and Processing on Our Behalf

We disclose personal data only where this is necessary for the performance of a contract, where a legal obligation exists, where you have given consent, or where another legal basis permits the disclosure. Data processing agreements pursuant to Art. 28 GDPR are in place with service providers that process data on our behalf.

2.3 Data Transfers to Third Countries

Some of the services described below also process data outside the EU or the EEA. Transfers to the USA are based on adequacy decisions of the European Commission for providers certified under the EU-US Data Privacy Framework (DPF) (Art. 45 GDPR) and, additionally, on standard contractual clauses (Art. 46(2)(c) GDPR). Adequacy decisions also exist for Israel and Canada (commercial providers). Details are provided for each individual service.

2.4 Storage Period (General Principle)

Unless a more specific period is stated, we store personal data until the purpose of the processing no longer applies. If you assert a legitimate request for erasure or withdraw consent, we will erase your data unless legally permissible grounds for continued storage exist (in particular retention periods under commercial and tax law, see Section 13); in that case, erasure takes place once those grounds cease to apply.

2.5 Encryption

This website uses TLS encryption. As a result, data that you transmit to us (e.g. orders or inquiries) generally cannot be read by third parties during transmission.

3. Hosting and Technical Provision

3.1 Shopify

Our online shop is operated on the e-commerce platform Shopify. The provider is Shopify International Limited, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland; the parent company is Shopify Inc. (Canada), which also uses sub-processors in the USA.

When you access the website, Shopify processes technical access data (IP address, date and time, page accessed/referrer, browser and device data) in server log files; these serve the provision, stability and security of the shop. The storage period of the log files is governed by Shopify's deletion cycles (see Shopify's privacy policy); we do not analyze the log files ourselves. When you place an order, Shopify also processes the order and customer data (Section 5). Shopify sets technically necessary cookies for the operation of the shop (details in our Cookie Policy).

Legal bases: Art. 6(1)(b) GDPR (shop operation and order processing) and Art. 6(1)(f) GDPR (legitimate interest in secure, stable provision); for technically necessary cookies, Section 25(2) no. 2 TDDDG. An adequacy decision of the European Commission exists for Canada; for US sub-processors, Shopify relies on the DPF and standard contractual clauses. A data processing agreement is in place with Shopify. Details: https://www.shopify.de/legal/datenschutz

3.2 Cloudflare (Delivery and Security Infrastructure)

The website is delivered via the infrastructure of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (content delivery network, protection against attacks and malicious traffic). Traffic between your browser and the shop is routed through Cloudflare; for this purpose, Cloudflare processes your IP address and sets certain security cookies. Legal basis: Art. 6(1)(f) GDPR (secure and high-performance provision); Section 25(2) no. 2 TDDDG. Cloudflare is certified under the DPF; standard contractual clauses additionally apply. Details: https://www.cloudflare.com/privacypolicy/

3.3 Integration of Individual Function Scripts via Third-Party CDNs

Individual functional components of the shop (e.g. the cart slider) are delivered via the content delivery network jsDelivr (an external CDN service; privacy information: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net). When these scripts are loaded, your IP address is transmitted to the CDN; we do not transfer any further data there. As the CDN uses delivery locations distributed worldwide, the IP address may in this process be transferred to third countries. Legal basis: Art. 6(1)(f) GDPR (efficient and secure provision of functional components).

4. Cookies and Consent Management

4.1 Cookies

This website uses cookies and comparable technologies. We use technically necessary cookies (e.g. shopping cart, login, language setting, storage of your cookie decision) on the basis of Art. 6(1)(f) GDPR and Section 25(2) no. 2 TDDDG. All non-essential cookies and analytics technologies are used exclusively with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). An overview of the specific cookies used, including their storage periods, can be found in our Cookie Policy.

4.2 Consent Management (iubenda)

To obtain, document and manage your consents, we use the iubenda Cookie Solution. The provider is iubenda s.r.l., Via San Raffaele 1, 20121 Milan, Italy. When you access the website, the consent banner is loaded; your decision (consent, refusal, selection of individual purposes) is stored in a cookie on your device and logged for evidentiary purposes. The data processed comprises your consent decision, its time, and technical data (truncated IP address, browser information).

Legal bases: Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (proof of consent) and Section 25(2) TDDDG for storing your decision. A data processing agreement is in place with iubenda. Details: https://www.iubenda.com/privacy-policy/

Your consent decision is additionally passed to the consent interface of our shop system (Shopify Customer Privacy). Only then — and only where consent has been given — are the services requiring consent (Section 8) started.

Withdrawal: You can change or withdraw your consents at any time with effect for the future — via the "Cookie Settings" link in the page footer.

5. Orders, Contract Processing and Payment

5.1 Order Data

When you place an order with us, we process the data required for contract processing: name, delivery and billing address, e-mail address, telephone number where applicable, products ordered, order and payment status. Legal basis: Art. 6(1)(b) GDPR. The provision of this data is necessary for the conclusion and performance of the contract; without it, we cannot accept and fulfill your order. After the transaction has been fully completed, the data is stored for as long as statutory retention periods apply (Section 13).

Our offering is directed exclusively at adults (18+); under our Terms and Conditions, the conclusion of a contract requires legal age. Insofar as we process information in this regard, this is done to comply with our sales restrictions (Art. 6(1)(b) and (f) GDPR).

5.2 Payment Exclusively by Prepayment (Bank Transfer/GiroCode)

We offer payment exclusively by prepayment (bank transfer). For your convenience, we provide a GiroCode (a QR code containing our bank details and the payment reference); the code is generated from the order data, and no data of yours is transmitted to a payment service provider in the process. We do not use external payment service providers (credit card, PayPal, Klarna or similar).

Upon receipt of your transfer, we receive the usual transaction data from our bank (account holder's name, IBAN, amount, payment reference). Legal basis: Art. 6(1)(b) GDPR; retention pursuant to Art. 6(1)(c) GDPR (Section 13).

For outstanding prepayment orders, we send automated payment reminders by e-mail via an application integrated into our shop system (processing on our behalf). Legal basis: Art. 6(1)(b) GDPR.

5.3 Disclosure to Shipping Service Providers

For delivery, we pass on your name and delivery address to the shipping company commissioned with the delivery. We pass on your e-mail address or telephone number to the shipping company only insofar as this is necessary for announcing or handling the delivery, or where you have given consent. Legal basis: Art. 6(1)(b) GDPR, otherwise Art. 6(1)(a) GDPR.

6. Customer Account (Optional)

You may voluntarily create a customer account with us. In doing so, we process your e-mail address, your name, saved addresses and your order history to enable you to manage your orders. Legal basis: Art. 6(1)(b) GDPR. Orders can also be placed without a customer account. You can have your customer account deleted at any time (request to info@acid-berlin.de); data subject to statutory retention periods will be blocked and deleted once those periods have expired.

7. Newsletter

7.1 Sign-up and Double Opt-in

To receive our newsletter, we require your e-mail address. Sign-up uses the double opt-in procedure: after signing up, you receive a confirmation e-mail and are added to the mailing list only after you click the confirmation link. For evidentiary purposes, we log the time of sign-up and of confirmation as well as the IP address used.

Legal bases: Art. 6(1)(a) GDPR (consent to receive the newsletter) and Art. 6(1)(f) GDPR in conjunction with Art. 7(1) GDPR (proof of consent). You can unsubscribe from the newsletter at any time via the unsubscribe link in every e-mail or by sending us a message; the lawfulness of the processing carried out until withdrawal remains unaffected.

Our newsletter is directed exclusively at persons aged 18 or over. Where we link sign-up to a benefit (e.g. a discount code for signing up), you will receive it after completing the double opt-in; the conditions of participation are stated at sign-up.

7.2 Dispatch Service Provider

For dispatch, we use a newsletter dispatch service provider based in Germany or the European Union that processes your data exclusively on our behalf and on the basis of a data processing agreement (Art. 28 GDPR). Processing takes place on servers within the EU. The service provider does not use your data for its own purposes.

7.3 Storage Period and Suppression List

Your data is stored in the mailing list until you unsubscribe and is then deleted from the mailing list. To ensure that you do not receive any further e-mails after unsubscribing, your e-mail address may be stored in a suppression list (Art. 6(1)(f) GDPR). We retain the consent logs for evidentiary purposes even after unsubscription, for as long as claims could be asserted on their basis.

8. Web Analytics

Analytics services that set cookies or access your device run on this website exclusively with your consent given via the consent banner (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). Without consent, these services are not loaded. You can withdraw your consent at any time via the "Cookie Settings" link in the page footer. In addition, we use Plausible for cookie-free audience measurement (Section 8.3).

8.1 Google Analytics 4 (Only with Consent)

This website uses Google Analytics 4. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables us to analyze user behavior (e.g. page views, time spent on the site, traffic sources, devices used). For this purpose, Google Analytics 4 stores and reads cookies and processes the IP address only at the time of collection; it is not stored permanently (for data collection in the EU, IP addresses are truncated or discarded on EU servers).

We have configured Google Analytics in a data-minimizing manner: Google signals are deactivated and personalized advertising features are switched off; we use Google Consent Mode, whose default setting denies all storage purposes until your consent has been given. We do not link the data with your Google account.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent, revocable at any time). Data may be transferred to the USA; Google LLC is certified under the DPF, and standard contractual clauses additionally apply. A data processing agreement is in place with Google. The retention period for event data in Google Analytics is limited to 14 months. Details: https://policies.google.com/privacy

8.2 Microsoft Clarity (Only with Consent)

This website uses Microsoft Clarity, a web analytics service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

Clarity records how visitors use our website (mouse movements, clicks, scrolling behavior, page views, device and browser data) and creates session recordings and heatmaps from this, which we use to identify and fix usability problems. Clarity uses cookies and comparable technologies for this purpose. We have configured Clarity so that text and form inputs are masked; content you enter is not transmitted or stored in plain text.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent, revocable at any time). Clarity is not loaded unless you give consent. A transfer to Microsoft Corporation (USA) cannot be ruled out; Microsoft is certified under the DPF (Art. 45 GDPR). Details: https://privacy.microsoft.com/de-de/privacystatement

8.3 Plausible Analytics (Cookie-Free, Without Consent)

We use Plausible Analytics, a privacy-friendly web analytics service provided by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia.

Plausible operates without cookies and without persistent identifiers. No cross-device profiles are created and no data is shared with third parties. Only aggregated information is collected, such as pages visited, traffic source, approximate origin at country level, and device type and browser; the IP address is used only transiently to process the page view and is not stored. Processing takes place on servers within the European Union.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimizing audience measurement). As Plausible neither stores information on your device nor accesses information stored there, consent under Section 25(1) TDDDG is not required. You may object to the processing at any time (Art. 21 GDPR). Details: https://plausible.io/data-policy

9. Customer Reviews (Loox)

To display and manage customer reviews, we use the service Loox (Loox App Ltd., Tel Aviv, Israel). The review widget is loaded when you access the website; in the process, your IP address is transmitted to Loox. If you have placed an order with us, you may receive an e-mail via Loox asking you to review a product; for this purpose, order information (e-mail address, products ordered) is transmitted to Loox. Reviews are displayed with the label "Verified purchase" if they are based on a verified order.

Legal bases: Art. 6(1)(f) GDPR (legitimate interest in authentic customer reviews); for review invitations by e-mail, Section 7(3) of the German Act Against Unfair Competition (UWG) or Art. 6(1)(a) GDPR. An adequacy decision of the European Commission exists for Israel (Art. 45 GDPR). A data processing agreement is in place with Loox. Details: https://loox.io/privacy

10. Contact Options

10.1 Contact Form, E-mail, Telephone

If you contact us via the contact form, by e-mail or by telephone, we process your information (name, contact details, content of the inquiry) to handle your request and for follow-up questions. Legal bases: Art. 6(1)(b) GDPR (contract-related inquiries), otherwise Art. 6(1)(f) GDPR (effective handling of inquiries). The data remains with us until the purpose no longer applies (handling completed), you request erasure, or statutory retention obligations preclude erasure.

10.2 Spam Protection (hCaptcha)

To protect our forms against automated misuse, our shop system uses hCaptcha (Intuition Machines, Inc., USA). hCaptcha uses technical characteristics (including IP address, browser information, interaction behavior) to check whether an input originates from a human. Legal bases: Art. 6(1)(f) GDPR (protection against spam and misuse) and Section 25(2) no. 2 TDDDG. EU standard contractual clauses apply to transfers to the USA (Art. 46(2)(c) GDPR). Details: https://www.hcaptcha.com/privacy

10.3 WhatsApp (WhatsApp Business)

For customer communication, we additionally offer WhatsApp (WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). Communication is end-to-end encrypted; however, WhatsApp receives metadata (e.g. sender, recipient, time) and shares personal data with its parent company Meta Platforms, Inc. (USA). We use the Business version of WhatsApp and have deactivated automatic address book synchronization on the devices used.

Legal basis: Art. 6(1)(f) GDPR (fast communication requested by customers). The use of WhatsApp is voluntary — alternatively, you can reach us at any time by e-mail or telephone. Meta and WhatsApp respectively are certified under the DPF; standard contractual clauses additionally apply. Details: https://www.whatsapp.com/legal/privacy-policy-eea

To embed the WhatsApp chat button on the website, we use a Shopify app; when the page is accessed, its script is loaded from the app provider's servers, in the course of which your IP address is processed (Art. 6(1)(f) GDPR). The app provider does not receive the content of your chats.

11. Job Applications

You can apply to us for a position (e.g. by e-mail). We process your application data (contact details, documents, notes from interviews) exclusively to decide on the establishment of an employment relationship. Legal bases: Section 26 of the German Federal Data Protection Act (BDSG), Art. 6(1)(b) GDPR and, for information provided voluntarily, Art. 6(1)(a) GDPR. Only the persons involved in the procedure have access.

If no employment results, we retain the documents for up to 6 months after the conclusion of the procedure for evidentiary purposes (Art. 6(1)(f) GDPR) and then delete them, unless you have consented to longer storage (applicant pool, maximum of two years, Art. 6(1)(a) GDPR).

12. Your Rights

Under the GDPR, you have the following rights:

  • access to your stored data (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20),
  • withdrawal of consent given, with effect for the future (Art. 7(3)).

Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(e) or (f) GDPR, you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for the purposes of direct marketing at any time without stating reasons.

Automated decision-making: Automated individual decision-making, including profiling (Art. 22 GDPR), does not take place.

To exercise your rights, an informal message to info@acid-berlin.de is sufficient.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin, https://www.datenschutz-berlin.de.

13. Retention Periods

Data category Period
Order, invoicing and accounting data 8 years (accounting records, Section 147 of the German Fiscal Code (AO)/Section 257 of the German Commercial Code (HGB) as amended with effect from 2025) or 10 years (commercial books, annual financial statements)
Business letters (including e-mail correspondence with contract-related content) 6 years
Newsletter consent logs for the duration of the subscription and beyond, for as long as proof is required
General contact inquiries deletion after final handling, at the latest upon expiry of civil-law limitation periods
Application documents 6 months after conclusion of the procedure (pool: max. 2 years with consent)
Consent logs (cookie banner) for as long as proof is required

14. Changes to this Privacy Policy

We will amend this privacy policy whenever the legal situation, our services or our data processing change. The current version published here applies in each case; the effective date can be found at the beginning of this document.