Data Protection Information
Last updated: June 30, 2026
Thank you for visiting the online presence of HF Boy Handelsgesellschaft mbH. This privacy policy is intended to inform you in detail about the handling of your personal data when you visit this online presence.
1. Data Controller and Definitions
1.1 Data Controller
Responsible for this online presence is:
HF Boy Handelsgesellschaft mbH
represented by Managing Director Mr. Henry Boy
Herlingsburg 16
22391 Hamburg
Phone: +49 40 22612976
Email: info@boy-katzennetze.de
Website: https://www.boy-katzennetze.de
1.2 Definitions
This privacy information is based on the terms used by the General Data Protection Regulation (GDPR). The individual terms are defined in Art. 4 GDPR. For the purposes of the GDPR and this privacy information, the following terms mean:
- "personal data" any information relating to an identified or identifiable natural person;
- "data subject" any identified or identifiable natural person whose personal data is processed;
- "processing" any operation or set of operations which is performed on personal data, whether or not by automated means;
- "restriction of processing" the marking of stored personal data with the aim of limiting their processing in the future;
- "controller" the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data;
- "processor" a natural or legal person which processes personal data on behalf of the controller;
- "recipient" a natural or legal person to whom the personal data are disclosed;
- "consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes.
2. General Information
2.1 No obligation to provide data
You can visit this online presence without providing any personal information. Insofar as personal data is collected or processed, you will receive further information in this privacy policy. If the provision of personal data is necessary for the respective service, you will be specifically informed of this during the input process, e.g., by designating it as a "mandatory field".
2.2 Consequences of not providing data
If data is required but not provided, the consequence is that the requested service cannot be performed.
2.3 Collection and storage of server data
Every time you access the server on which the data of this online presence is stored, the following access data (server log files) are automatically collected:
- Name of the accessed website
- Accessed file
- Date and time of access
- HTTP status code
- Amount of data transferred
- Browser type and version
- User's operating system
- Referrer URL (the previously visited page)
- IP address of the site visitor
- Requesting provider
Server log files are stored for security reasons for a maximum of 7 days and then deleted. Data whose further retention is required for evidential purposes is exempt from deletion until the respective incident has been finally clarified. This data processing is carried out in accordance with Art. 6(1)(f) GDPR to protect legitimate interests.
2.4 Cookies and Consent (§ 25 TDDDG)
Cookies are used on this online presence. Cookies are small text files that are stored on your device. A distinction is made between:
- Technically necessary cookies: These are absolutely necessary for the operation of the website and are set without your consent. The legal basis is Art. 6(1)(f) GDPR.
- Non-necessary cookies (e.g., analytics and marketing cookies): These are only set after your prior explicit consent in accordance with § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
You can revoke your consent at any time with effect for the future via our cookie settings on the website. You can also configure your browser to inform you about the setting of cookies and individually decide on their acceptance or generally reject cookies. Further information on cookie settings can be found in the help pages of your browser (e.g., Firefox, Chrome, Safari, Edge).
2.5 Legal bases of data processing
Unless the legal basis is mentioned separately later in this privacy policy, the following applies:
- Legal basis for consent: Art. 6(1)(a) and Art. 7 GDPR
- Legal basis for fulfilling contracts and pre-contractual measures: Art. 6(1)(b) GDPR
- Legal basis for fulfilling legal obligations: Art. 6(1)(c) GDPR
- Legal basis for protecting legitimate interests: Art. 6(1)(f) GDPR
2.6 Shopify as platform and processor
This online presence is operated on the e-commerce platform Shopify. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland.
Shopify processes personal data on our behalf as a processor in accordance with Art. 28 GDPR. A Data Processing Addendum has been concluded with Shopify, available at: https://www.shopify.com/legal/dpa
Shopify may also process data outside the European Economic Area (EEA). In this case, data transmission takes place on the basis of the Standard Contractual Clauses (SCCs) of the European Commission in accordance with Art. 46(2)(c) GDPR. Further information on data protection at Shopify can be found at: https://www.shopify.com/legal/privacy
3. Rights of Data Subjects
Data protection law grants you numerous rights vis-à-vis the data controller.
3.1 Right of access
According to Art. 15 GDPR, you have the right to request confirmation as to whether data concerning you is being processed, as well as access to this data and a copy of the personal data.
3.2 Right to rectification
According to Art. 16 GDPR, you have the right to request the rectification of inaccurate data concerning you.
3.3 Right to erasure or restriction of processing
According to Art. 17 GDPR, you have the right to demand the immediate erasure of data concerning you. Alternatively, you have the right to request a restriction of processing under Art. 18 GDPR.
3.4 Right to data portability
According to Art. 20 GDPR, you have the right to receive the data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and to request its transmission to other controllers.
3.5 Right to lodge a complaint
According to Art. 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority. Our competent supervisory authority is:
The Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI)
Ludwig-Erhard-Str. 22, 7th Floor
20459 Hamburg
Email: mailbox@datenschutz.hamburg.de
Website: https://datenschutz.hamburg.de
3.6 Right of withdrawal
According to Art. 7(3) GDPR, you have the right to withdraw any consent you have given at any time with effect for the future.
3.7 RIGHT TO OBJECT
IN ACCORDANCE WITH ART. 21 GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE FUTURE PROCESSING OF YOUR PERSONAL DATA. THE OBJECTION CAN BE MADE IN PARTICULAR AGAINST PROCESSING FOR DIRECT MARKETING PURPOSES. IF YOU OBJECT TO PROCESSING FOR DIRECT MARKETING PURPOSES, YOUR PERSONAL DATA WILL NO LONGER BE PROCESSED FOR THESE PURPOSES.
4. Contacting Us
When you contact HF Boy Handelsgesellschaft mbH, your details are processed to handle the contact request:
- Within the framework of pre-contractual or contractual relationships according to Art. 6(1)(b) GDPR
- For processing other requests according to Art. 6(1)(f) GDPR
Your requests will be deleted when they are no longer necessary. The necessity is reviewed every two years. In addition, statutory archiving obligations apply.
4.1 Contact form
When visiting this online presence, you have the opportunity to get in touch via a contact form. The information you provide will be stored for the purpose of processing your request. It will not be passed on to third parties. If it involves pre-contractual or contractual inquiries, the processing is based on Art. 6(1)(b) GDPR; for other inquiries, it is based on Art. 6(1)(f) GDPR.
5. Additional Website Functions
5.1 Encryption and Data Security
When accessing this online presence, the SSL/TLS method is used in conjunction with the highest encryption level supported by your browser. Furthermore, appropriate technical and organizational security measures are applied to protect your data against accidental or intentional manipulation, partial or complete loss, as well as unauthorized access by third parties.
5.2 Use of reCAPTCHA
The "reCAPTCHA" service is integrated into this online presence. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This service is used to distinguish bots from human inputs in online forms and to prevent abuse. Data processing is based on Art. 6(1)(f) GDPR to protect legitimate interests. Insofar as data is transferred to the USA, this takes place based on the Standard Contractual Clauses (SCCs) of the European Commission according to Art. 46(2)(c) GDPR. The provider's privacy policy can be found at: https://policies.google.com/privacy
5.3 Customer account / Registration function
When visiting this online presence, you have the opportunity to create a customer account. The data collected during registration results from the input mask of the registration form. The purpose of this data processing is to fulfill the contract and enable a personalized shopping experience. The processing is based on Art. 6(1)(b) GDPR.
6. Data Processing for Contractual Purposes
6.1 Pre-contractual measures and contract fulfillment
If you use the product offerings of HF Boy Handelsgesellschaft mbH or have made a corresponding inquiry, the data you transmit will be processed for the purpose of pre-contractual measures and/or contract fulfillment. The legal basis is Art. 6(1)(b) GDPR.
6.2 Data transmission to shipping companies
For delivery, HF Boy Handelsgesellschaft mbH forwards your data to the commissioned shipping company insofar as this is necessary for the delivery of ordered goods. In the case of freight forwarded goods, this also includes your phone number to allow you to arrange a delivery date. The legal basis is Art. 6(1)(b) GDPR.
6.3 Transmission of your phone number to the shipping company
If you have given your explicit consent, HF Boy Handelsgesellschaft mbH will forward your phone number to the commissioned shipping company to give you the opportunity to arrange a delivery date. This data processing takes place according to Art. 6(1)(a) GDPR based on your consent.
7. Payment Services
To process payments as part of an order process, you are given the option to choose an external payment service provider. This data processing takes place according to Art. 6(1)(b) GDPR for contract fulfillment.
7.1 Klarna
The provider of this service is Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden. If you opt for Klarna Invoice or Klarna Installment Purchase, the personal data necessary for processing and for identity and credit checks will be transmitted to Klarna. This includes in particular first and last name, address, date of birth, email address, phone number, IP address, and order data. Klarna may obtain information from the following credit agencies in Germany for credit checks:
- SCHUFA Holding AG, Kormoranweg 5, 65201 Wiesbaden
- Creditreform Boniversum GmbH, Hellersbergstraße 11, 41460 Neuss
- Arvato Infoscore Consumer Data GmbH, Rheinstraße 99, 76532 Baden-Baden
- CRIF GmbH (formerly Deltavista GmbH), Leopoldstraße 244, 80807 Munich
Further information on data protection at Klarna can be found at: https://www.klarna.com/de/datenschutz/
Contact Data Protection Klarna: datenschutz@klarna.de
7.2 PayPal
The provider of this service is PayPal (Europe) S.à.r.l. & Cie. S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. When paying with PayPal, your contact and order information is transmitted to PayPal. PayPal's privacy policy can be found at: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
8. Web Analytics: Google Analytics 4
The "Google Analytics 4" (GA4) service is integrated into this online presence. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics 4 allows the use of this website to be analyzed. For this purpose, cookies and similar technologies are used, which are stored on your device. The information thus generated about your use of this website is transmitted to Google servers and stored there, possibly also in the USA.
This data processing is carried out exclusively on the basis of your explicit consent according to § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You can withdraw your consent at any time via our cookie settings.
Insofar as data is transmitted to the USA, this takes place based on the Standard Contractual Clauses (SCCs) of the European Commission according to Art. 46(2)(c) GDPR. Further information can be found in Google's privacy policy: https://policies.google.com/privacy
9. Google Marketing Services
Google Marketing Services are integrated into this online presence. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
This data processing is carried out exclusively on the basis of your explicit consent according to § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You can withdraw your consent at any time via our cookie settings.
Insofar as data is transmitted to the USA, this takes place based on the SCCs according to Art. 46(2)(c) GDPR. Further information: https://policies.google.com/privacy
9.1 Google Ads (Conversion Tracking)
The "Google Ads" service with conversion tracking is integrated into this online presence. If you reach this website via a Google ad, a cookie will be placed on your device. This "conversion cookie" expires after 30 days and is not used for your personal identification. The information thus collected serves to compile visit statistics and measure the success of advertising campaigns.
9.2 Google Remarketing
The "Google Remarketing" service is integrated into this online presence. With Google Remarketing, ads can be shown to users who have previously visited this website. Google Remarketing uses cookies for this purpose. Further information on Google's data use for marketing purposes: https://www.google.com/policies/technologies/ads
If you wish to opt-out of interest-based advertising by Google Marketing Services, you can use the settings and opt-out options under the following link: https://www.google.com/ads/preferences
10. Email Marketing: Klaviyo
We use the Klaviyo service to send newsletter and marketing emails. The provider is Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02111, USA.
When you subscribe to our newsletter, your email address and, if applicable, your name will be transmitted to Klaviyo and stored there. Klaviyo also allows us to analyze your usage behavior in our emails (e.g., opens, clicks) as well as your purchasing behavior in our store to send you personalized content.
The processing of your data for the newsletter dispatch takes place exclusively on the basis of your explicit consent according to Art. 6(1)(a) GDPR. The tracking pixel in emails and the use of tracking links also take place according to § 25(1) TDDDG only with your prior consent. You can withdraw your consent at any time by using the unsubscribe link in any of our emails or by contacting us directly.
Since Klaviyo is a US-based provider, your data will be transmitted to the USA. The transfer is based on the Standard Contractual Clauses (SCCs) of the European Commission according to Art. 46(2)(c) GDPR. You can view the data processing addendum with Klaviyo at the following link: https://www.klaviyo.com/privacy/dpa
Further information on data protection at Klaviyo can be found at: https://www.klaviyo.com/legal/privacy-notice
Newsletter Subscription (Double Opt-In): Subscription to our newsletter uses the double opt-in process. After subscribing, you will receive a confirmation email in which you must actively confirm your subscription. This step is necessary so that no one can subscribe using someone else's email address.
11. Product Reviews: Judge.me
On this website, you have the opportunity to submit product reviews that will be displayed publicly on the respective product page. For this purpose, we use the Judge.me service. The provider is Judge.me Limited, 77 Lower Camden Street, Dublin 2, Ireland.
When you submit a review, your name and email address, along with the content of your review, will be transmitted to and processed by Judge.me. Your name will be publicly displayed alongside the review on the website. Your email address will not be published.
The processing is based on your explicit consent according to Art. 6(1)(a) GDPR, which you grant by actively submitting the review.
Judge.me may also process data via sub-processors outside the EEA. The transfer is based on the SCCs according to Art. 46(2)(c) GDPR or based on adequacy decisions by the EU Commission according to Art. 45 GDPR.
Further information and Judge.me's privacy policy can be found at: https://judge.me/privacy
12. Web Analytics and Optimization: Hotjar
The Hotjar service is integrated into this online presence. The provider is Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141, Malta (hereinafter "Hotjar").
Hotjar enables us to analyze user behavior (so-called "session replays", heatmaps, etc.) on our website. This can record, for example, mouse movements, clicks, scroll depth, and keystrokes (with the exception of passwords and sensitive data, which are automatically anonymized). In addition, information such as your IP address (in anonymized form), screen size, browser type, location (country only), and preferred language are recorded.
This data processing is carried out exclusively on the basis of your explicit consent according to § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. This consent is obtained via our cookie consent management tool (Consentmo). Without your consent, the Hotjar tracking code will not be executed. You can withdraw your consent at any time with effect for the future via our cookie settings.
Hotjar partly processes data on servers outside the European Union or the European Economic Area (EEA), for example in the USA. Insofar as data is transmitted to third countries, this takes place based on the Standard Contractual Clauses (SCCs) of the European Commission according to Art. 46(2)(c) GDPR to ensure an adequate level of data protection.
Further information about data usage by Hotjar can be found in Hotjar's privacy policy at: https://www.hotjar.com/legal/policies/privacy/
13. International Data Transfers
As outlined in this privacy policy, your personal data is transmitted to third countries (especially to the USA). In these cases, the transfer is always based on appropriate safeguards, in particular the Standard Contractual Clauses (SCCs) of the European Commission according to Art. 46(2)(c) GDPR, or based on an adequacy decision of the EU Commission according to Art. 45 GDPR. Upon request, we will provide you with a copy of the respective SCCs.
14. Storage Duration
Personal data is only stored as long as necessary for the respective purposes or as required by statutory retention periods. Commercial and tax retention periods are generally 6 to 10 years (§§ 238 et seq. HGB, §§ 145 et seq. AO). After the respective periods have expired, the corresponding data is routinely deleted.
15. Changes to this Privacy Policy
We reserve the right to update this privacy policy as necessary to reflect changes in our data processing practices or legal requirements. The current version is available on this website. The date of the last update is indicated at the beginning of this document.