Privacy policy

PRIMORIS™ — PRIVACY POLICY

This policy explains how personal data is processed when you visit this store, purchase PRIMORIS™ Access OS, or contact us. It describes the processing actually carried out by this store.

1. Controller

Bradley Nkwetta
Schenkendorfstraße 13
53173 Bonn
Germany
Email: contact@primorisvault.com

2. Visiting the website

When you access this store, technical data is processed automatically so that the pages can be delivered and kept secure: IP address, date and time of the request, requested page, referrer, browser and device type, and status information. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a secure and functioning store.

3. Cookies and consent

Strictly necessary cookies are used to operate the store, to carry your selection through the purchase process, and to record your consent decision. Legal basis: Art. 6 (1) (f) GDPR and Section 25 (2) TDDDG.

Cookies and similar technologies that are not strictly necessary are used only after you have given consent through the consent banner. Legal basis: Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. You may withdraw consent at any time with effect for the future.

4. Purchase and contract performance

To process an order we process your name, email address, billing address, order details and payment status. This is necessary to conclude and perform the contract and to meet commercial and tax record-keeping duties. Legal basis: Art. 6 (1) (b) GDPR for contract performance and Art. 6 (1) (c) GDPR for statutory retention obligations. Providing this data is not required by law, but without it the contract cannot be concluded and access cannot be delivered.

5. Recipients and processors

We use the following service providers. Where they act on our behalf, they are bound by a data processing agreement.

Shopify — store platform, hosting, checkout, order and customer records, transactional email, and the consent banner. Provider for European merchants: Shopify International Limited, Ireland.
Shopify Payments and Google Pay — payment processing. Card details are entered directly with the payment provider and are not stored by us. Payment providers also act as independent controllers for their own regulatory duties.
Stornify — storefront event measurement used to operate and improve the store, applied only within the limits of your consent decision.
Shopify Network Intelligence — a Shopify platform feature that uses store and customer data across Shopify’s network to improve Shopify products, targeting and personalisation, as described in Shopify’s Additional Services Terms. This feature is currently active at platform level and can be switched off in the store’s privacy settings.

Other applications connected to this store are used for internal administration and legal-text maintenance and do not receive visitor or customer data for their own purposes. We do not use advertising networks, social media pixels, or third-party analytics beyond what is stated above.

6. Transfers outside the EU

Some of the providers named above may process data outside the European Economic Area, in particular in the United States. Such transfers take place on the basis of the EU standard contractual clauses under Art. 46 (2) (c) GDPR or an applicable adequacy decision under Art. 45 GDPR, with additional safeguards where required.

7. Retention

Order, invoice and transaction data is retained for the statutory retention periods under German commercial and tax law. Consent records are retained for as long as they are needed as evidence of the consent given. Other data is deleted once it is no longer required for the purpose for which it was collected.

8. Marketing

We do not send marketing email unless you have separately and expressly consented. Messages about your purchase, your access, and your legal rights are transactional, not marketing, and are sent on the basis of Art. 6 (1) (b) GDPR.

9. No automated decision-making

We do not carry out automated individual decision-making or profiling within the meaning of Art. 22 GDPR.

10. Access OS product data

PRIMORIS™ Access OS is delivered through an authenticated Shopify storefront route. Material entered or worked with inside Access OS is stored locally in your browser by the product itself and is not intentionally transmitted by Access OS to PRIMORIS™ or Shopify. Standard store and platform technical data may still be processed as described elsewhere in this policy.

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

To exercise these rights, contact contact@primorisvault.com.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

12. Changes to this policy

We may update this policy when the store, its services, or the legal requirements change. The version published here is the version that applies.