Privacy Policy & Data Protection
European General Data Protection Regulation (GDPR) Technical Notice • Effective Version: September 2026
1. Data Controller Information
Entity Name: [LEGAL_COMPANY_NAME_PENDING]
Registered Address: [REGISTERED_OFFICE_ADDRESS_PENDING]
Company Registration ID: [REGISTRATION_NUMBER_PENDING]
VAT Identification: [VAT_NUMBER_PENDING]
Data Protection Inquiries: sales@fusionbars.eu
2. Principles of Data Collection
We collect and process customer personal information strictly under Article 6(1)(b) of the GDPR for the fulfilment of purchases, order delivery, and statutory tax compliance.
Data categories collected: Identity data (name), delivery data (postal address), contact data (email, phone for courier exceptions), and financial audit references.
We do NOT sell, rent, or monetize customer data. Customer records are retained only for the duration required by European commercial book-keeping mandates.
3. Technical Data Protection & Security Controls
All database queries are executed via encrypted TLS 1.3 connections.
Customer session tokens are cryptographically signed using HMAC-SHA256 and stored in HttpOnly, SameSite=Strict cookies.
Guest order records are protected against sequential probing by requiring dual-factor credentials (order number combined with recipient email address or cryptographically signed lookup token).
4. Rights of Data Subjects (GDPR Articles 15-22)
Right of Access (Art. 15): Customers may request a complete, machine-readable export of their personal profile, address records, and order history via their customer account dashboard.
Right to Rectification (Art. 16): Delivery addresses and customer profile fields can be modified directly within the account portal.
Right to Erasure (Art. 17): Customers may execute technical account erasure. Account profiles and saved addresses are permanently removed, and associated order records are anonymized to preserve statutory accounting totals.
Right to Restriction & Object: Inquiries can be lodged directly to sales@fusionbars.eu.