Skip to content
  • Address:Handelstraße 20, 04420 Leipzig, Germany
NORDWERK4X4

Policies

Privacy policy

We collect the minimum personal data needed to build, sell and ship engineered parts, and we never sell it. This policy explains exactly what we hold, why, and what you can ask us to do with it.

Last updated 15 September 2026

Contents

Who is responsible for your data

The controller for the personal data described in this policy, within the meaning of Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679), is:

Registered company name
Trading name
Nordwerk4x4
Registered address
Handelstraße 20, 04420 Leipzig, Germany
Email

We are not required to appoint a data protection officer. Privacy questions are handled by the address above and are answered by a person, not a form.

What we collect

We collect only what we need to sell, build and ship engineered parts. Specifically:

  • Order data you give us at checkout — name, email address, phone number, billing address, delivery address, and for business customers a VAT identification number.
  • Build and fitment data — the vehicle, gearbox and specification details you send us, and any photographs you choose to share so our engineers can advise you.
  • Enquiry data — whatever you type into the contact form or send us by email.
  • Payment outcome data — confirmation from Stripe that a payment succeeded, the payment reference, and the card brand and last four digits. We never see or store your full card number.
  • Newsletter data — your email address and language, if you subscribe.
  • Technical data — the IP address, user agent, requested URL and timestamp that any web server necessarily receives, processed at the edge by our host.

We do not ask for, and have no use for, special category data as defined in Article 9. Please do not send it to us.

Why we use it, and our lawful basis

DataPurposeLawful basisRetention
Name, email, phone, billing and delivery addressTaking, building, invoicing and delivering your order; after-sales contactArticle 6(1)(b) — performance of a contractLife of the order, then the statutory accounting retention period
Order contents, prices, order reference, build notesFulfilment, warranty administration and returnsArticle 6(1)(b) — contract; Article 6(1)(c) — legal obligation for invoicesStatutory accounting retention period, typically 6–10 years
Payment confirmation, last four digits and card brand, Stripe identifiersTaking payment, matching refunds, resolving chargebacksArticle 6(1)(b) — contract; Article 6(1)(c) — anti-fraud and accounting dutiesHeld by Stripe; we retain only the reference and outcome
Enquiry form: name, email, phone, vehicle and messageAnswering your enquiry and quoting for a buildArticle 6(1)(b) — steps prior to a contract; otherwise Article 6(1)(f)24 months from the last contact, unless it becomes an order
Newsletter email address and localeSending build updates you asked forArticle 6(1)(a) — consent, withdrawable at any timeUntil you unsubscribe
Server and security logs: IP address, user agent, request path, timestampDelivering the site, blocking abuse, diagnosing faultsArticle 6(1)(f) — legitimate interest in a secure, working websiteShort-lived; retained by Cloudflare for its own logging period

Where we rely on legitimate interests, that interest is running a secure website and a functioning workshop; we have weighed it against your rights and freedoms and you can object at any time (see below). Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.

We do not make decisions about you by automated means alone, and we do not profile you. We do not sell, rent or trade personal data, and we do not share it for advertising purposes.

Who we share it with

We use a small number of service providers who process personal data on our instructions under Article 28 data processing agreements:

  • Stripe Payments Europe, Ltd. (Ireland) — payment processing. Stripe receives your name, email, billing address and card details directly through its hosted checkout and acts as an independent controller for fraud prevention and its own regulatory duties. Its privacy policy is at stripe.com/privacy.
  • Cloudflare, Inc. — hosting, content delivery, edge compute, the database in which orders are stored and the object storage holding product media. Cloudflare processes request data, including IP addresses, to serve the site and protect it from abuse. Its privacy policy is at cloudflare.com/privacypolicy.
  • Carriers and freight forwarders — we pass the delivery name, address and phone number needed to deliver your consignment and, for exports, to complete customs declarations.
  • Our accountant and, where necessary, professional advisers — invoices and transaction records, to meet accounting and tax obligations.
  • Our email provider — to send order confirmations, dispatch notices and replies to your enquiries.

We will also disclose data where we are legally obliged to — for example to a tax authority, a customs authority or a court order.

International transfers

Our data is held within the European Economic Area wherever the service allows it. Where a provider processes data outside the EEA — Cloudflare's global network and Stripe's group companies are the two that can — the transfer is covered by the European Commission's Standard Contractual Clauses and, where applicable, by an adequacy decision, together with the technical measures those providers publish.

When you buy from outside the EU, we necessarily transfer your name, address and consignment details to the carrier and to the customs authority of the destination country in order to perform the contract, as permitted by Article 49(1)(b).

How long we keep it

We keep personal data only as long as we need it, then delete it. The table above gives the period for each category. In summary:

  • Invoices and transaction records are kept for the statutory accounting retention period that applies to us — commonly between six and ten years in EU member states. We cannot delete these on request, because the law requires us to keep them.
  • Order and build records are kept for the life of the warranty plus the limitation period for a claim, so that a later warranty question can actually be answered.
  • Enquiries that do not become orders are deleted 24 months after the last contact.
  • Newsletter subscriptions are kept until you unsubscribe, and the unsubscribe record itself is kept so we do not email you again.

Your rights

Under the GDPR you have the right to:

  • Access (Article 15) — a copy of the personal data we hold about you and information about how we use it.
  • Rectification (Article 16) — correction of data that is inaccurate or incomplete.
  • Erasure (Article 17) — deletion, where we no longer have a lawful reason to keep it.
  • Restriction (Article 18) — to have processing paused while a dispute about accuracy or lawfulness is resolved.
  • Data portability (Article 20) — the data you gave us, in a structured, commonly used, machine-readable format.
  • Objection (Article 21) — to object to processing based on legitimate interests, and an absolute right to object to direct marketing.
  • Withdrawal of consent (Article 7(3)) — at any time, where consent is the basis we rely on.
  • Not to be subject to automated decision-making (Article 22) — we do not carry any out.

How to exercise your rights

Email and tell us what you want. We will respond within one month, as Article 12(3) requires, and will tell you if we need to extend that for a complex request. There is no charge.

We may ask for enough information to be sure who you are — usually the order reference and the email address used for the order. That is a safeguard for you, not an obstacle: we will not hand your order history to somebody else.

To unsubscribe from the newsletter, use the unsubscribe link in any email we send you, or write to the address above.

How to complain

If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right under Article 77 to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.

Our lead supervisory authority

A list of all national data protection authorities in the EEA is published by the European Data Protection Board at edpb.europa.eu.

Security

The site is served entirely over HTTPS. Card data never touches our systems — payment is taken inside Stripe's hosted checkout. Order data is held in a managed database on Cloudflare's platform, and access to it is limited to the people in our workshop who need it, protected by individual accounts. Administrative access is authenticated with a session cookie and is not available to customers. We apply security headers to every response, and we review access when someone leaves.

No system is perfect. If we ever suffer a breach that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and tell you directly where Article 34 requires it.

Children

This is a business selling engineering components to vehicle builders. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.

Changes to this policy

We update this policy when our processing changes — a new processor, a new service, a change in retention. The revision date is shown at the top of this page. Material changes affecting how we use data you have already given us will be notified to you directly where we can. What this site stores in your own browser is described separately in our cookie policy.