Privacy Policy
ROOOOM Service and General Agency as a commercial agent for CHORS
1. Data Controller
The data controller within the meaning of Article 4(7) of the GDPR is:
ROOOOM Service- und Generalagentur, owned by Andreas Barner
Edeltraudstraße 80, 81827 Munich, Germany
Telephone: +49 172 8566635 · Email: info@roooom.com
A Data Protection Officer does not need to be appointed, as the legal requirements set out in Article 37 of the GDPR in conjunction with Section 38 of the German Federal Data Protection Act (BDSG) are not met. For any enquiries regarding data protection, please contact us directly using the contact details provided above.
2. Scope
This privacy policy applies to the websites and retailer platforms operated by ROOOOM: roooom.com, herlighting.de, chors.de and fenix-profil.de [add further domains], including the password-protected retailer area, as well as to the processing of personal data in the context of business initiation and transaction processing.
This does not cover the websites and data processing activities of the manufacturers we represent. These manufacturers are independently responsible for the data processing carried out by them (see section 11).
3. Legal bases
Unless otherwise stated below, the processing is based on the following legal bases:
– Article 6(1)(a) of the GDPR — consent, in particular in the case of non-essential cookies, audience measurement and the sending of product information.
– Article 6(1)(b) of the GDPR — performance of a contract or the implementation of pre-contractual measures, in particular in relation to registration, enquiries and orders.
– Article 6(1)(c) of the GDPR — compliance with legal obligations, in particular commercial and tax law retention obligations.
– Article 6(1)(f) of the GDPR — legitimate interests, in particular in the secure and trouble-free operation of the website, in brokerage activities and in direct marketing to business customers.
Section 25 of the TDDDG also applies to the storage of information on your device and access to information already stored.
4. Your rights
You have the following rights vis-à-vis ROOOOM with regard to your personal data:
– Right of access (Article 15 of the GDPR)
– Rectification (Art. 16 GDPR)
– Erasure (Art. 17 GDPR)
– Restriction of processing (Art. 18 GDPR)
– Data portability (Art. 20 GDPR)
– Objection to processing (Art. 21 GDPR)
You may withdraw any consent you have given at any time with effect for the future. The lawfulness of the processing carried out prior to the withdrawal remains unaffected.
Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of data concerning you which is carried out on the basis of Article 6(1)(f) of the GDPR. If your data is processed for the purposes of direct marketing, you have the right to object at any time and without giving reasons; the data will then no longer be processed for these purposes.
Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.
5. Accessing the website, server log files, hosting
(1) When you access our websites, your device’s browser automatically transmits information to the server, which is temporarily stored in a log file: the IP address of the requesting device, the date and time of access, the name and URL of the file accessed, the volume of data transferred, a notification of whether the request was successful, the browser type and version used, the operating system, and the previously visited page (referrer).
(2) This processing is carried out on the basis of Article 6(1)(f) of the GDPR. The legitimate interest lies in establishing a connection, ensuring system security, technical administration and investigating attempts at misuse or attacks. This data is not combined with other data sources for the purpose of identifying users.
(3) The log files are automatically deleted after 14 days, unless their continued retention is necessary to investigate a specific security-related incident.
(4) The websites are hosted on a server leased by ROOOOM from Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, in a data centre in Germany. A contract for data processing in accordance with Article 28 of the GDPR has been concluded with Hetzner. The software used is Odoo, which is operated by ROOOOM itself; no data is transferred to the software manufacturer in this process.
(5) The websites are delivered exclusively via an encrypted connection (TLS/HTTPS).
6. Cookies and consent management
(1) Cookies and similar technologies are used on our websites. Cookies are small text files that are stored on your device.
(2) Technically necessary cookies — for example, for session management, logging into the retailer’s area, language selection, the shopping basket and saving your cookie preferences — are set without consent. This is based on Section 25(2)(2) of the TDDDG and Article 6(1)(f) of the GDPR.
(3) All other cookies and technologies, in particular those used for audience measurement and the integration of external content, are set only with your express consent (Section 25(1) of the TDDDG, Article 6(1)(a) of the GDPR).
(4) Consent is obtained via a consent management tool: CODENEERS Cookie Control. You can refuse consent on the same page and with the same ease as giving it. Your decision is logged for evidence purposes (time, scope of consent, banner version, truncated IP address) and retained for the duration of the statutory retention period.
(5) You may withdraw your consent at any time with future effect via the cookie settings. You will find the link to this [specify the location of the link, e.g. in the footer of every page]. In addition, you can delete cookies via your browser settings or prevent them from being stored altogether; however, this may restrict the functionality of the website.
(6) Consent granted via a recognised consent management service in accordance with Section 26 of the TDDDG in conjunction with the Consent Management Regulation will be taken into account as soon as such a service is technically integrated.
7. Audience measurement
We use the open-source software Matomo for the statistical analysis of the use of our websites; we operate this on our own server hosted by Hetzner Online GmbH in Germany. No data is transferred to third parties or to third countries. In particular, the following data is processed: truncated IP addresses, pages visited, duration of visit, referrer, device used and browser. Processing is carried out on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. The data is deleted after 2 months.
8. External content: fonts, maps, videos
(1) Fonts: All fonts used on our websites are served locally from our own server. No connection is made to third-party servers, in particular to Google Fonts, when the pages are accessed.
(2) Map service: To display directions, we integrate Google Maps, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map is only loaded once you have given your express consent (two-click solution). Only then will your IP address and other usage data be transmitted to Google, including to the USA. The legal basis is Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
(3) Videos: Videos are embedded in enhanced privacy mode from YouTube (youtube-nocookie.com), a service provided by Google Ireland Limited, and are also only loaded once you have given your consent. When the video is played, usage data is transmitted to Google, including to the USA. The legal basis is Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
(4) Without your consent, no connection is established with any of these providers; instead of the external content, you will see a placeholder.
9. Contacting Us
(1) If you contact us by email, telephone, fax or via a contact form, we will process your name, your contact details, the company on whose behalf you are acting, and the content of your enquiry in order to deal with your request and in the event of any follow-up questions.
(2) The legal basis is Article 6(1)(b) of the GDPR, insofar as the enquiry serves to initiate or carry out a business transaction; otherwise, it is Article 6(1)(f) of the GDPR on the basis of our legitimate interest in responding to enquiries.
(3) Our business email communications are handled via Microsoft 365, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement, including the Standard Contractual Clauses, is in place; processing in third countries cannot be ruled out in the context of support and operational processes.
(4) Emails are transmitted with transport-layer encryption, provided the receiving system supports this. There is no end-to-end encryption; for particularly confidential content, we ask that you consult with us in advance to agree on a suitable transmission method.
(5) We delete enquiries as soon as they have been fully processed and there are no statutory retention obligations to the contrary; business correspondence is generally subject to the retention periods under commercial and tax law (see clause 22).
10. Registration and Dealer Area
(1) Access to the password-protected dealer area requires registration and activation by us. The data processed in this context includes the company name, legal form, address, VAT registration number, name and business contact details of the contact persons, login details and, where applicable, proof of commercial activity.
(2) The purpose is to verify access authorisation, provide access to the dealer area and process the brokerage transaction. The legal basis is Article 6(1)(b) of the GDPR and Article 6(1)(f) of the GDPR with regard to our interest in making dealer terms and conditions accessible only to authorised commercial customers.
(3) Passwords are stored exclusively in encrypted form (using a hashing algorithm) and cannot be viewed by us in plain text.
(4) To ensure the security of access, we log login times and failed login attempts on the basis of Article 6(1)(f) of the GDPR. These logs are deleted after [insert duration].
(5) Once access has been revoked, account data will be deleted, provided that this does not conflict with any retention obligations or ongoing business transactions.
11. Orders and Forwarding to the Relevant Manufacturer
(1) ROOOOM is a commercial agency and acts as an intermediary in transactions between you and the relevant manufacturer. The supply contract is concluded exclusively between you and the manufacturer.
(2) To fulfil this purpose, we forward your order and enquiry data to the relevant manufacturer. In particular, the following data is transferred: company and address details, delivery and billing addresses, the name and business contact details of the contact persons, VAT registration number, as well as order, project and quotation data.
(3) The legal basis is Article 6(1)(b) of the GDPR, as the transfer is necessary for the performance of the brokerage service you have requested; additionally, Article 6(1)(f) of the GDPR applies on the basis of our legitimate interest in carrying out our brokerage activities.
(4) The respective manufacturer is the independent data controller within the meaning of Article 4(7) of the GDPR with regard to the data transmitted to it. Its own privacy policy applies to the processing of such data. In this respect, there is no processing on behalf of a controller.
(5) If you provide us with data relating to third parties — such as alternative delivery addresses, your end customers, planners or architects — you are responsible for ensuring the lawfulness of this transfer and for fulfilling the information obligations towards these persons.
12. Product information and mailings
(1) We inform business customers and prospective customers by email about new products, new or amended price lists, catalogues, promotions and trade fair dates for the manufacturers we represent.
(2) The legal basis is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2)(2) of the Unfair Commercial Practices Act (UWG). We obtain your consent via the double opt-in procedure: following your registration, you will receive an email containing a confirmation link; we will only add you to the mailing list once you have confirmed. Your registration, confirmation and the time of these actions are logged for verification purposes.
(3) Where we have received your email address in connection with a business relationship we have facilitated, we will send you information about our own similar offers on the basis of Section 7(3) of the German Unfair Competition Act (UWG) and Article 6(1)(f) of the GDPR. You may object to this at any time.
(4) We use the Brevo service provided by Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, to send these emails. A contract for data processing has been entered into in accordance with Article 28 of the GDPR.
(5) Performance measurement: Our emails may contain tracking pixels and personalised links, which enable us to determine whether and when a message has been opened and which links have been clicked. This analysis is carried out on the basis of the consent you provided when you registered.
(6) You can unsubscribe at any time via the unsubscribe link in each message or by sending an informal request to info@roooom.com. Once you have unsubscribed, we will add your email address to a block list to ensure that you do not receive any further messages; the legal basis for this is Article 6(1)(c) and (f) of the GDPR.
13. Complaints, returns and copies of correspondence
(1) To manage complaints and returns, we process the data provided for this purpose: order and delivery details, reason for the complaint, photographs and descriptions of the condition of the goods, the manufacturer’s return numbers, and correspondence between you, us and the manufacturer.
(2) In accordance with our General Terms and Conditions, you must address complaints directly to the manufacturer and copy us in for information purposes. We process the messages copied to us in order to track the process and provide you with support. The legal basis is Article 6(1)(f) of the GDPR; the legitimate interest lies in the management of transactions facilitated by us.
(3) If goods are sent to us, we document the external condition of the consignment upon receipt, using photographs where necessary. This documentation serves to preserve evidence vis-à-vis transport companies, the manufacturer and customers; the legal basis is Article 6(1)(f) of the GDPR.
(4) Transaction data is deleted upon completion of the transaction, unless it is subject to the retention periods set out in clause 22 or is still required to pursue or defend against claims.
14. Provision of Samples
(1) Where we provide you with samples, sample cases, demonstration equipment or exhibition items, we process the data required for handling these in our inventory management system: company details, contact person, alternative delivery address, the sample provided with its identification number, dispatch date, return deadline and return status.
(2) The purposes are the organisation and documentation of dispatch, the management of our sample warehouse and the property of the respective manufacturer, as well as the monitoring of returns. The legal basis is Article 6(1)(b) and (f) of the GDPR.
(3) Before the return period expires, we will send you an automated reminder by email. If the sample is not returned, we will send reminders and invoice you for the replacement value; in this respect, clause 15 applies. These reminders and notices are part of the contract fulfilment process and do not constitute advertising.
(4) Once the sample has been returned and any claims have lapsed, the transaction data will be deleted, unless it is subject to the retention periods set out in clause 22.
15. Invoicing, debt management and reminders
(1) Where we provide you with services subject to a fee, we process the data required for invoicing: billing address, contact person, VAT registration number, description of services, amounts and receipt of payments. The legal basis for this is Article 6(1)(b) and (c) of the GDPR.
(2) In the event of non-payment, we process the data for the purposes of issuing reminders and enforcing our claim. This may include passing the data on to a debt collection agency, a solicitor or a court. The legal basis is Article 6(1)(f) of the GDPR; the legitimate interest lies in the enforcement of legitimate claims.
(3) We do not carry out credit checks via credit reference agencies.
16. Trade fairs, events and contact details collection
(1) At trade fairs, in-house exhibitions and events, we collect contact details from prospective customers and visitors — company name, name, business contact details, areas of interest and notes from discussions. This information is collected via business cards, contact forms, badge scans or by entering details on site.
(2) The purpose is to follow up on the discussion and to initiate a business relationship. The legal basis is Article 6(1)(b) of the GDPR for responding to specific enquiries and Article 6(1)(f) of the GDPR for general business development with commercial prospects.
(3) The sending of promotional emails to these contacts requires consent in accordance with clause 12. The receipt of a business card does not constitute such consent.
17. Dispatch of catalogues, samples and postal items
For the dispatch of catalogues, price lists, samples and other items, we process company details, delivery addresses and contact persons and pass these on to the contracted dispatch company. The legal basis is Article 6(1)(b) and (f) of the GDPR. The courier company processes the address details on its own responsibility for the purpose of carrying out the delivery.
18. Telephone calls and video conferences
(1) In the case of telephone calls, we process the telephone number provided, the time and the content, insofar as we create a note in our system to this effect. Telephone calls are not recorded.
(2) For video conferences, we use [specify the service used, e.g. Microsoft Teams; add provider and registered office]. The data processed includes name, email address, time and duration of participation, and technical connection data. Recording takes place only with prior notification and consent from all participants.
(3) The legal basis is Article 6(1)(b) of the GDPR for contract-related communication; in all other cases, Article 6(1)(f) of the GDPR.
19. Presence on social media
Where we maintain profiles on social media platforms [list the platforms used or delete this clause], the respective providers process visitors’ data on their own responsibility and in accordance with their own terms and conditions. With regard to the processing of usage data for statistical purposes (insights), case law of the European Court of Justice establishes joint controllership under Article 26 of the GDPR; corresponding agreements with the providers are in place. We ourselves process the data you send us via these channels to respond to your enquiry on the basis of Article 6(1)(f) of the GDPR. These channels are not suitable for the transmission of confidential information.
20. Project registration and property protection
If you register a construction project or property for project registration, we process the information required for this purpose: the name and address of the property, the planners, architects and clients involved along with their professional contact details, the scope of services, and the registration and protection status. We pass this data on to the relevant manufacturer, who decides on the registration. The legal basis is Article 6(1)(b) and (f) of the GDPR. If you provide us with third-party data in this context, clause 11(6) applies accordingly.
21. Job applications
[Retain only if job applications are accepted — otherwise delete.] We process application documents exclusively for the purpose of conducting the recruitment process on the basis of Section 26(1) of the German Federal Data Protection Act (BDSG) and Article 6(1)(b) of the GDPR. Once the process has been completed, the documents will be deleted within six months at the latest, unless you have consented to them being stored for a longer period.
22. Customer management, accounts and record-keeping
(1) We manage customer, prospective customer and transaction data in an Odoo system operated by us on our server in Germany. Access is restricted to authorised personnel within our company.
(2) Invoice and commission data, as well as business correspondence, are subject to the statutory retention periods, in particular under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO). This data is stored for the duration of the respective retention period, and processing is otherwise restricted. The legal basis is Article 6(1)(c) of the GDPR.
(3) We delete data relating to prospective customers with whom no business relationship is established no later than [insert duration; 24 to 36 months is standard] after the last contact.
(4) To ensure data reliability, we create encrypted backup copies, which are stored on a separate storage system and overwritten according to a fixed cycle.
23. Recipients and data processors
We only disclose personal data insofar as this is necessary to fulfil our duties, where you have given your consent, or where there is a legal obligation to do so. Recipients include, in particular:
– the respective manufacturers we represent, as independent data controllers (Clause 11)
– Hetzner Online GmbH, Gunzenhausen — server hosting (data processing)
– Microsoft Ireland Operations Limited, Dublin — email and office communications (data processing)
– Sendinblue GmbH (Brevo), Berlin — sending mailings (data processing on behalf of the controller)
– Hostinger — domain and DNS management [enter the exact name and registered office of the contractual partner; check the data processing agreement]
– [Enter the provider of the consent management tool]
– Transport and delivery companies for catalogues, samples and returns, acting as independent data controllers
– Zoom, Google Meet, Microsoft Teams
– Tax consultancy and, where applicable, auditing and legal advice, to the extent provided for by law
– Debt collection agencies, solicitors and courts, where claims need to be enforced
– Credit institutions in connection with payment processing
Contracts in accordance with Article 28 of the GDPR are in place with all data processors. No data is disclosed to third parties for marketing purposes.
24. Transfers to third countries
Where data is transferred to countries outside the European Economic Area, this takes place only if an adequacy decision by the European Commission under Article 45 of the GDPR has been issued, suitable safeguards under Article 46 of the GDPR — in particular standard contractual clauses — have been agreed, or an exception under Article 49 of the GDPR applies. The specific legal bases are set out in this statement for the respective processing operations. Upon request, we will provide you with further information and, where possible, a copy of the safeguards.
25. Data security
We implement technical and organisational measures in accordance with Article 32 of the GDPR to protect your data against accidental or deliberate manipulation, loss, destruction and unauthorised access. These include, in particular, transport encryption (TLS), encrypted backups, an access control policy, password policies and email authentication procedures (SPF, DKIM, DMARC). Our measures are continuously adapted in line with technological developments.
26. No automated decision-making
No automated decision-making, including profiling within the meaning of Article 22 of the GDPR, takes place.
27. Obligation to provide data
The provision of your data is not required by law or by contract. However, without the information required for registration and order processing, we cannot activate your access to the dealer area or forward orders to the relevant manufacturer.
28. Changes to this Privacy Policy
We will update this privacy policy as soon as our data processing activities or the legal framework change. The current version published on our websites shall apply at all times.