1. Data Protection at a Glance
General Information
The protection of your personal data is important to us. In this privacy policy, we inform you about which personal data we process when you visit our websites, use our customer portal or our online shop, contact us, subscribe to our newsletter, or enter into a business relationship with us.
This privacy policy applies in particular to the websites and online offerings under:
fischer-moebel.de
fischer-moebel.odoo.com
Personal data is any information relating to an identified or identifiable natural person, for example, name, address, email address, telephone number, customer number, order or communication data.
We process personal data only to the extent permitted by applicable data protection regulations, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and the Telecommunications-Telemedia Data Protection Act (TTDSG).
2. Controller
The controller for data processing is:
Fischer Möbel GmbH
Dieselstr. 6
73278 Schlierbach
Germany
Telephone: 07021 72 76 0
Email: info@fischer-moebel.de
3. Data Protection Officer
Our data protection officer is:
Will Seyfang
c/o Fischer Möbel GmbH
Dieselstr. 6
73278 Schlierbach
Germany
Email: info@fischer-moebel.de
If you have any questions about data protection, you can contact our data protection officer or us at any time.
4. General Legal Bases for Processing
We process personal data on the basis of the following legal grounds:
Art. 6 para. 1 lit. a GDPR, if you have given us consent;
Art. 6 para. 1 lit. b GDPR, if the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures;
Art. 6 para. 1 lit. c GDPR, if we are legally obliged to process;
Art. 6 para. 1 lit. f GDPR, if the processing is necessary to safeguard our legitimate interests or the interests of a third party and your interests, fundamental rights and freedoms do not outweigh.
Our legitimate interests particularly lie in the secure and economical provision of our websites and IT systems, the processing of inquiries, customer support, the organisation of our business processes, direct marketing to the extent permitted by law, the documentation of business transactions, IT security as well as the assertion, exercise or defence of legal claims.
5. Hosting, technical provision and Odoo
Our website, our customer portal, our online shop as well as essential internal business processes are operated via the cloud-based enterprise software Odoo.
The provider is:
Odoo S.A.
Chaussée de Namur 40
1367 Grand-Rosière
Belgium
We use Odoo primarily as an ERP, CRM, website, shop, portal, communication, newsletter, and corporate platform. Odoo is used by us to centrally organise business processes, particularly customer and contact management, quotation and order processing, online shop, customer portal, communication, invoicing, payment processing, service, complaints, internal administration, evaluations, as well as interface and automation functions.
Insofar as Odoo hosts or processes personal data on our behalf, we use Odoo as a data processor. There are corresponding contractual arrangements with Odoo for data processing.
When using Odoo, the following data may be processed depending on the transaction:
Master data, for example name, company, address, customer number;
Contact data, for example email address, telephone number, contact person;
Communication data, for example emails, messages, call notes, inquiries;
Quotation, contract, and order data;
Invoice, payment, and accounting data;
Delivery, shipping, and service data;
Complaint and support data;
Portal and login data;
Technical data, for example IP address, log data, access times, device and browser information;
Permission, usage, and modification data within our systems;
Other information that you provide to us in the context of an inquiry, order, registration, or business relationship.
The processing is carried out depending on the process based on Art. 6 para. 1 lit. b GDPR, insofar as it is necessary for the performance of the contract or for the implementation of pre-contractual measures, based on Art. 6 para. 1 lit. c GDPR, insofar as there are legal obligations, based on Art. 6 para. 1 lit. f GDPR for the organisation, administration, customer support, IT security and documentation of our business processes as well as based on Art. 6 para. 1 lit. a GDPR, insofar as consent is required.
Odoo may in turn use subprocessors, particularly for hosting, operation, maintenance, security, support and technical infrastructure. Processing outside the European Union or the European Economic Area cannot be completely excluded depending on the functions used, subprocessors, support cases or connected services. If necessary, such transmission will take place on the basis of appropriate guarantees under the GDPR, in particular adequacy decisions or EU standard contractual clauses.
6. Server log files and technical access data
When accessing our websites and online services, technical information is automatically processed that your browser or end device transmits to our systems or to the service providers we use.
This may include in particular:
IP address
Date and time of access;
accessed pages and files;
referrer URL;
Browser type and browser version
operating system used
Hostname of the accessing computer
amount of data transmitted;
status messages and error codes;
technical identifiers and security protocols.
This data is processed to technically provide the website, ensure the stability and security of the systems, detect and prevent abuse, and analyse errors.
The legal basis is Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure, stable, and error-free provision of our websites and online services. To the extent that information is stored or read on your device for this purpose, this is done based on § 25 para. 2 TDDDG.
The log data is stored only as long as necessary for the stated purposes. Longer storage may occur if this is necessary for the clarification of security incidents, for abuse prevention, or for the assertion, exercise, or defence of legal claims.
7. Cookies and similar technologies
Our websites use cookies and similar technologies. Cookies are small text files that are stored on your device. Similar technologies may include local storage, pixels, tags, or similar technical methods.
We distinguish between:
Technically necessary cookies and technologies
These are required for our websites and online services to function. This may include cookies for login, shopping cart, language settings, session management, security, load balancing, form functions, or the storage of your cookie settings.
The legal basis for the processing of personal data is Art. 6 para. 1 lit. f GDPR. To the extent that the storage or access to information on your device is necessary, this is done based on § 25 para. 2 TDDDG.
Non-essential cookies and technologies
Furthermore, we use cookies and similar technologies for analysis, reach measurement, marketing, conversion tracking, and the optimisation of our online offerings, provided you have consented.
The storage or access to information on your device occurs in these cases based on your consent in accordance with § 25 Abs. 1 TDDDG. The subsequent processing of personal data is based on Art. 6 Abs. 1 lit. a GDPR.
You can withdraw or change your consent at any time with effect for the future. You can find the relevant settings in our cookie banner or in the cookie settings of our website.
8. Cookie consent and consent management
We use a cookie or consent management system on our website to obtain, document, and manage your consents for certain cookies and technologies.
In this context, the following data may be processed:
Your consent decision;
Time of consent or withdrawal;
Information on the selected categories or services;
Technical information about the browser and device;
IP address in shortened or otherwise technically required form;
an identifier for recognising your consent decision.
The processing takes place, insofar as it is necessary for the fulfilment of legal proof and documentation obligations, on the basis of Art. 6 para. 1 lit. c GDPR. Furthermore, our legitimate interest according to Art. 6 para. 1 lit. f GDPR is to manage and document consents in a legally compliant manner.
Insofar as information is stored on your device for this purpose, this is done on the basis of § 25 para. 2 TDDDG, as far as this is technically necessary for consent management.
9. Contact via form, email, telephone or other communication
If you contact us via contact form, email, telephone or any other means, we process the data you provide to handle your request and for any follow-up questions.
This may include in particular:
Name;
Company;
Address;
Email address;
Telephone number;
Content of your request;
Communication history;
technical metadata;
if applicable, offer, project, order or service data.
Requests via our website can be directly recorded in Odoo and processed further there.
The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as your request is related to the performance of pre-contractual measures or an existing contract. In all other cases, the processing is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the proper handling and documentation of requests. Insofar as you have expressly consented, Art. 6 para. 1 lit. a GDPR is the legal basis.
The data will be deleted as soon as they are no longer required for processing, unless there are legal retention obligations or legitimate interests opposing further storage.
10. Customer account, registration and customer portal
You can register on our online offerings or use a customer account or customer portal. Depending on the function, the customer account or portal can be used to manage or view offers, orders, purchases, invoices, delivery information, messages, service cases or other business-related information.
In this context, the following data may be processed:
Name, company and contact details;
Login data;
Customer number;
Billing and delivery addresses;
Offer, order and contract data;
Billing and payment status;
Communication and service data;
Portal usage data;
technical access data.
The processing is carried out to provide and manage the customer account or customer portal as well as to conduct and manage the business relationship. The legal basis is Article 6(1)(b) GDPR. To the extent that we process data for IT security, prevention of misuse or internal administration, this is done on the basis of Article 6(1)(f) GDPR.
You are obliged to treat your access data confidentially and to protect it from third-party access.
11. Online shop, orders and contract processing
If you order products through our website or customer portal, request offers or conclude contracts with us, we process the personal data required for this.
This may include in particular:
Name, company and contact person;
Billing and delivery address;
E-mail address and telephone number;
Order, quote and contract data;
Product and configuration data;
Delivery and shipping information;
Payment data and payment status;
Billing data;
Customer history and communication history.
The processing is carried out for the initiation, execution and settlement of contracts, orders, deliveries, payments, service and warranty cases. The legal basis is Art. 6 para. 1 lit. b GDPR.
As far as we are legally obliged to retain or process certain data, the processing is based on Art. 6 para. 1 lit. c GDPR. This particularly concerns commercial, tax and accounting obligations.
In addition, we may process data on the basis of Art. 6 para. 1 lit. f GDPR, as far as this is necessary for internal organisation, customer service, fraud prevention, IT security, documentation or for the assertion, exercise or defence of legal claims.
12. Payment processing with PayPal and Stripe
We offer payments via payment service providers as part of our online offering. This includes, in particular:
PayPal
Stripe
If you select a payment via a payment service provider, the data required for payment processing will be transmitted to the respective payment service provider. This may include, in particular:
Name;
Email address;
Billing and delivery address;
Order and billing data;
Payment amount;
Currency;
Transaction data;
technical data;
information on fraud prevention and payment verification.
The processing is carried out for payment processing and contract fulfilment based on Art. 6 para. 1 lit. b GDPR. Where legal obligations exist, the processing is carried out based on Art. 6 para. 1 lit. c GDPR. Where data is processed for fraud prevention, security, or enforcement of claims, this is done based on Art. 6 para. 1 lit. f GDPR.
Payment service providers process personal data depending on the specific transaction also under their own responsibility. The privacy notices of the respective payment service provider apply additionally to the processing.
13. Delivery, shipping and freight forwarding
To process deliveries, we may transmit personal data to shipping service providers, freight forwarders, logistics partners or other service providers involved in the delivery.
This may include in particular:
Name;
Delivery address;
Telephone number;
Email address;
Order and delivery data;
Shipment and tracking information;
Information on notification or appointment coordination.
The transmission takes place, as far as it is necessary for the delivery of ordered goods or for the execution of the contract, based on Art. 6 para. 1 lit. b GDPR. As far as the transmission is necessary for efficient processing, tracking or coordination of the delivery, it is additionally based on Art. 6 para. 1 lit. f GDPR.
14. Newsletter and marketing emails via Odoo
We also use Odoo for newsletters, marketing emails and business customer communication.
If you subscribe to our newsletter, we process in particular:
Email address;
name, if provided;
Company, as far as specified;
Time of registration;
Consent status;
technical information for registration and confirmation;
Unsubscribe status;
if applicable, interests, preferences or assignment to recipient groups.
The sending of newsletters is generally based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future, for example via the unsubscribe link in the newsletter or by notifying us.
As far as we inform existing customers within the legally permissible scope about our own similar goods or services, processing may take place on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in direct marketing to existing customers. You can object to this processing at any time.
We can evaluate, as part of our newsletter dispatch, whether newsletters are opened, which content is clicked on, and how recipients interact with our emails. Such evaluations only take place if consent is given or if this is legally permissible. The evaluation serves to improve our content, offers, and customer communication.
15. Google Analytics
We use Google Analytics, as far as you have consented, to analyse and improve our online offering.
The provider is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Analytics enables us to evaluate the use of our website. In this context, the following data may be processed in particular:
visited pages;
Duration of stay;
Interactions on the website;
Referring pages;
Technical device and browser information;
Approximate location information;
Cookie or user identifiers;
IP address in technically specified form;
Events and conversion data.
Processing is only carried out on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR. The storage or access to information on your device is based on § 25 para. 1 TDDG.
You can revoke your consent at any time via the cookie settings of our website with effect for the future.
Google may also process data outside the European Union or the European Economic Area. If this occurs, the transfer is based on appropriate safeguards under the GDPR, in particular adequacy decisions or EU standard contractual clauses.
16. Google Ads and Conversion Tracking
We use, as far as you have consented, Google Ads and Google Conversion Tracking. The provider is Google Ireland Limited.
With Google Ads, we can display advertisements in Google search and the Google advertising network. With conversion tracking, we can track whether users perform certain actions on our website after clicking on an ad, such as making a request, submitting a form, viewing a product, or completing a purchase.
In this context, the following data may be processed:
Cookie and advertising identifiers;
IP address
Device and browser information;
Time of ad click;
visited pages;
Actions taken on our website;
Order or conversion information;
Referrer and campaign information.
The processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR. The storage or access to information on your device is based on § 25 para. 1 TDDG.
You can revoke your consent at any time via the cookie settings of our website with effect for the future.
Google may also process data outside the European Union or the European Economic Area. If this occurs, the transfer is based on appropriate safeguards under the GDPR, in particular adequacy decisions or EU standard contractual clauses.
17. Odoo cookies, shop functions and portal technologies
Our Odoo-based website, our online shop and our customer portal use technically necessary cookies and similar technologies that are essential for the operation of certain functions.
This may include in particular:
Session cookies;
Login and authentication cookies;
Shopping cart cookies;
Language setting cookies;
Security and CSRF protection cookies;
Cookies for storing cookie settings;
technical identifiers for providing forms, shop and portal functions.
These cookies and technologies are necessary to provide the website, the online shop and the customer portal. The legal basis is Art. 6 para. 1 lit. f GDPR or, where processing is necessary for the performance of a contract, Art. 6 para. 1 lit. b GDPR. The storage or access to information on your device is based on § 25 para. 2 TDDG.
18. Forms, product inquiries and quote requests
If you use forms on our website, for example contact forms, product inquiries, quote requests, callback forms or other inquiry forms, we process the data you enter.
This may include in particular:
Name;
Company;
Address;
Email address;
Telephone number;
desired products or services;
project information;
message text;
uploaded files, if offered;
technical metadata.
The data can be stored directly in Odoo and further processed there for the handling of your request.
The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as your request is aimed at the conclusion or execution of a contract. In all other cases, processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the processing and documentation of requests. Insofar as consent is requested, Art. 6 para. 1 lit. a GDPR is the legal basis.
19. Customer management, CRM and business partner data
We process personal data of customers, prospects, suppliers, traders, business partners, and contacts at companies in our CRM and ERP system Odoo.
This may include, depending on the business relationship:
Name, company and professional contact details;
Function or position;
Address;
Telephone number and email address;
Communication history;
Interests and request history;
Offer and order data;
Contract and project data;
Service and complaint data;
Payment and invoicing information;
internal responsibilities and processing notes.
Processing is carried out for the initiation, execution, and management of business relationships on the basis of Art. 6 para. 1 lit. b GDPR, insofar as the affected person is themselves a contractual partner. For contacts from companies, processing is regularly carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the proper execution of the business relationship with the respective company.
As far as there are legal retention and documentation obligations, processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR.
20. API interfaces and connected systems
We can connect Odoo via interfaces, APIs or automated processes with other internal or external systems. This can particularly be for the synchronisation of website, shop, payment, shipping, accounting, communication, reporting or administrative processes.
Depending on the interface, personal data may be transferred, matched or updated. This may include in particular master, contact, order, payment, delivery, invoice, communication, usage and technical data.
Processing is carried out, as far as it is necessary for the performance of the contract, on the basis of Art. 6 para. 1 lit. b GDPR. As far as it is necessary for the fulfilment of legal obligations, it is carried out on the basis of Art. 6 para. 1 lit. c GDPR. Otherwise, it is carried out on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the efficient, secure and error-free organisation of our business processes.
As far as external service providers process personal data on our behalf within the framework of interfaces, we conclude corresponding contracts for order processing. As far as external providers process data on their own responsibility, their privacy notices apply additionally.
21. No joint multi-company processing
As of now, we do not operate a joint multi-company environment with several legally independent companies that process personal data jointly for their own purposes.
Should several connected companies or legally independent entities process personal data within a shared Odoo environment in the future, we will implement the necessary data protection regulations and update this privacy policy accordingly.
22. Recipients of personal data
We only share personal data when it is legally permissible or there is a corresponding obligation.
Recipients or categories of recipients may include:
internal offices and departments involved in processing;
Odoo as a hosting, ERP, CRM, website, shop, and platform provider;
IT, hosting, maintenance, and support service providers;
payment service providers, particularly PayPal and Stripe;
shipping service providers, freight forwarders, and logistics partners;
tax advisors, auditors, banks, and accounting service providers;
lawyers, authorities, and courts, as necessary;
service providers for newsletters, marketing, analysis, and advertising, particularly Google and Odoo;
providers of connected systems and interfaces, as necessary.
Data sharing occurs only to the extent necessary for the respective purposes, if there is a legal obligation, you have consented, or we have a legitimate interest in the sharing.
23. Data transfer to third countries
The transmission of personal data to countries outside the European Union or the European Economic Area cannot be completely excluded, particularly when using international service providers, in support cases, with certain subcontractors, with Google services, payment service providers, or other connected services.
Insofar as such a transmission takes place, it only occurs if the conditions of Art. 44 et seq. GDPR are met. This can particularly be based on an adequacy decision by the European Commission, EU standard contractual clauses, additional protective measures, or your consent.
24. Storage Duration and Deletion
We only store personal data as long as this is necessary for the respective purposes or legal retention obligations exist.
The storage duration is determined particularly by:
the duration of the business relationship;
the purpose of the processing;
legal retention periods;
commercial, tax, and accounting obligations;
warranty and limitation periods;
legitimate interests in documentation and legal defence;
granted consents and their revocation.
Business and tax-relevant documents may need to be retained for six, eight, or ten years, depending on the document. After the respective periods have expired, the data will be deleted, blocked, or anonymised, provided that no further legal basis for processing exists.
We generally store data from newsletter registrations until the cancellation or withdrawal of consent. Data that is necessary to prove granted consent or an objection may also be stored.
Customer accounts and portal access are generally deleted or deactivated when they are no longer required for the business relationship and there are no legal retention obligations to the contrary.
25. Data Security
We take technical and organisational measures to protect personal data against loss, destruction, manipulation, unauthorised access and unauthorised disclosure.
These include, in particular:
encrypted data transmission via TLS/SSL;
role- and permission-based access;
user and rights management;
logging of security-relevant processes;
regular review of access rights;
technical protective measures against unauthorised access;
backup and recovery measures;
careful selection of service providers.
Please note that data transmission over the internet, particularly when communicating via email, may have security vulnerabilities. Complete protection against access by third parties is not possible.
26. Your Rights
You have the following rights within the framework of legal requirements:
Right to information according to Art. 15 GDPR;
Right to rectification according to Art. 16 GDPR;
Right to erasure according to Art. 17 GDPR;
Right to restriction of processing according to Art. 18 GDPR;
Right to data portability according to Art. 20 GDPR;
Right to object according to Art. 21 GDPR;
Right to withdraw consent according to Art. 7 para. 3 GDPR;
Right to lodge a complaint with a data protection supervisory authority according to Art. 77 GDPR.
If you have given consent, you can withdraw it at any time with effect for the future. The lawfulness of processing carried out until the withdrawal remains unaffected.
27. Right to object under Art. 21 GDPR
If we process personal data on the basis of Art. 6 para. 1 lit. f GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
If we process personal data for the purpose of direct marketing, you have the right to object to this processing at any time. This also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will no longer be used for the purpose of direct marketing.
28. Right to complain to the supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
The data protection supervisory authority responsible for us is usually:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
You can also contact any other competent data protection supervisory authority.
29. Currency and amendment of this privacy policy
We reserve the right to adjust this privacy policy if our data processing, the systems we use, our website functions, or the legal requirements change.
The current version is available on our website.
As of: June 2026