This Privacy Policy explains how Tehi UG (“we”, “us”, “our”) collects, processes, and protects your personal data when you visit our website norhage.eu and utilize our digital services.
Our data processing operations strictly comply with the General Data Protection Regulation (EU GDPR) and the German Federal Data Protection Act (BDSG).
Tehi UG
Commercial Register: HRB33174
Tax Registration No.: 402 461 3576
Registered Office: Adolfstraße 1, 65185 Wiesbaden, Germany
Email: [email protected]
Phone: +49 176 6510 6609
1. Categories of Personal Data We Collect
We only collect personal data that is strictly necessary for contract fulfillment and the secure, functional operation of our website.
1.1. Data Provided Actively by You
- First name and last name
- Email address
- Telephone / mobile number
- Delivery and shipping address
- Billing details, including corporate Tax ID or VAT registration numbers
- Payment transaction details (we do not store credit card credentials on our servers)
- Communications submitted via digital contact forms
- Account login credentials (upon user registration)
1.2. Data Collected Automatically
- Anonymized or full IP address
- Browser type, engine, and version
- Operating system and device environment identifier
- Page views, session duration, and behavioral navigation metrics
- Cookie identifiers and storage preferences
1.3. Integrations and Third-Party Subprocessors
We utilize specialized external technical services that may have access to personal data to optimize shop operations:
- Google Analytics (web analytics platform)
- Google Ads (conversion tracking and marketing)
- Meta Pixel (custom audience retargeting)
- Verified Payment Service Providers (PSPs)
- Logistics and freight shipping partners
These external subprocessors handle your personal data strictly in accordance with their respective privacy frameworks and data processing agreements (DPA).
2. Purposes of Data Processing
We process your personal data solely for legitimate, predefined purposes:
2.1. Order Fulfillment and Transaction Management
- Order acceptance, validation, and administrative management
- Logistics, dispatch, and physical delivery of greenhouse systems or parts
- Secure payment capture and fraud mitigation
- Generation of legally compliant commercial tax invoices
2.2. Customer Support and Communication
- Responding to incoming pre-sales or custom configuration inquiries
- Providing post-purchase assembly and technical support
- Managing statutory warranty claims or material tracking queries
2.3. Platform Optimization and Analytics
- Statistical modeling and aggregated behavior analysis
- Enhancing user interface functionality and site performance
- Implementing technical monitoring and cybersecurity defense systems
2.4. Marketing Frameworks (Consent-Driven Only)
- Newsletter distribution
- Transmission of promotional offers or clearance alerts
- Displaying contextually personalized store content
3. Legal Basis for Data Processing
We process personal data based on the following specific pillars of the GDPR:
- Performance of a Contract pursuant to Art. 6(1)(b) GDPR (e.g., executing checkout orders)
- Compliance with a Legal Obligation pursuant to Art. 6(1)(c) GDPR (e.g., fiscal audit preservation laws)
- Legitimate Interests pursuant to Art. 6(1)(f) GDPR (e.g., maintaining platform stability and cybersecurity)
- Consent of the Data Subject pursuant to Art. 6(1)(a) GDPR (e.g., opt-in marketing newsletters or tracking cookies)
4. Data Retention Periods
Personal data is retained only for the duration required to satisfy the respective processing purpose:
- Commercial Order Records: Retained for up to 10 years to fulfill statutory tax and accounting retention mandates
- Newsletter Datasets: Retained continuously until the user formally revokes their consent
- User Profile Accounts: Retained until the user formally requests the deletion of their profile account
- Cookie Data: Purged automatically in accordance with individual cookie lifespan configurations
5. Data Sharing and Third-Party Disclosures
To safely complete orders, necessary data may be disclosed to the following entities:
- Contracted freight distribution and shipping operators
- Licensed banking institutions and payment processing clearers
- Cloud hosting infrastructure and cybersecurity contractors
- Digital accounting and tax optimization software tools
- Authorized marketing networks (strictly dependent upon explicit cookie consent)
We do not sell, rent, or trade your personal data to any external entities for commercial marketing purposes.
6. Your Rights as a Data Subject
Under the statutory provisions of the GDPR, you are entitled to the following rights:
- Right of Access (Art. 15 GDPR) to view your stored personal information
- Right to Rectification (Art. 16 GDPR) to fix inaccurate data fields
- Right to Erasure (Art. 17 GDPR, “Right to be Forgotten”) to drop data when it’s no longer legally needed
- Right to Restriction of Processing (Art. 18 GDPR) to temporarily freeze data use
- Right to Data Portability (Art. 20 GDPR) to export data in a structured machine-readable format
- Right to Withdraw Consent (Art. 7(3) GDPR) at any time for consent-based tracking
- Right to Object (Art. 21 GDPR) to data processing based on legitimate interest frameworks
- Right to Lodge a Complaint with a supervisory authority if data handling breaches legal standards
Formal complaints may be sent to our locally competent regulatory agency: The Hessen State Officer for Data Protection and Freedom of Information
https://datenschutz.hessen.de
7. Cookies and Tracking Technologies
We employ cookies to keep our shop running smoothly, analyze performance, and customize content. For granular insight and to update your consent matrix, please consult our dedicated Cookie Policy.
8. Outbound External Links
Our website may provide outbound links to independent web domains. We maintain zero authority over, and assume no liability for, the external content configurations or privacy practices of these third-party operators.
9. Data Security Infrastructure
We use rigorous technical and organizational safety measures (TOMs) to guard your data against loss or unauthorized access:
- Standardized SSL/TLS end-to-end data encryption
- Strict role-based data access restrictions
- Hardened server firewalls and database isolation
- Regular operational training for staff handling customer transactions
10. Amendments to this Privacy Policy
We reserve the right to modify this statement dynamically to maintain alignment with technical systems adjustments or evolving statutory legal updates. Any revised policies will be posted transparently on this page.
Document Last Updated:

