This page explains what personal data we process on tileforyou.eu, why we do it, on what legal basis, and what rights you have. This document has been drawn up in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
Version 1.0 · effective as of its publication on this page.
1. Who is responsible for your data
The controller of your personal data (that is, the company that determines why and how it is processed) is:
We have not appointed a separate Data Protection Officer (DPO) — for any data-related question, please write to the address above.
2. What data we collect
Order and inquiry data. When you place an order, request samples, or write to us, we receive: your name, email, phone number, shipping address, the contents of your order, and the substance of your inquiry.
Correspondence. The emails you send to sale@tileforyou.eu and our replies — including attachments (for example, a photo of your interior for a tile match).
Account data. There is no customer account area on the site, so we do not collect account data.
Technical data and cookies. IP address, device and browser type, the pages you viewed, and cookie files. Full details are in our Cookie Policy.
What we do not collect. We neither collect nor see payment card data: the payment is handled by the payment provider Stripe on its own secure side. We have no need for special categories of data (health, beliefs, and the like) — please do not send them to us.
If the recipient's delivery address was provided by someone other than you (for example, the order was placed on another person's behalf), we received that data from the customer and use it solely to deliver that order.
Without the data required to place an order (name, contact details, shipping address), we cannot accept or fulfill the order.
3. Why we use your data and on what legal basis
The GDPR requires every processing purpose to have a legal basis (Art. 6 GDPR). Here are ours:
We do not make decisions based solely on automated processing that would have legal or similarly significant effects for you.
4. Who we share your data with
We share data only with those without whom the order cannot be fulfilled, and only to the extent needed:
We do not sell personal data and do not pass it to third parties for their own advertising.
5. Transfers of data outside the EEA
Data is stored on servers in Germany (EU). Certain services (Stripe, for example) may process data outside the EEA — in such cases, Standard Contractual Clauses (SCCs) and/or adequacy decisions apply (Chapter V GDPR).
If the shipping address is outside the EEA, we pass the carrier the data needed to deliver to the recipient's country — this is necessary for the performance of our contract with you (Art. 49(1)(b) GDPR).
6. How long we keep your data
Once the period expires or the data is no longer needed, we delete it or irreversibly anonymize it (aggregate statistics are not personal data).
7. Your rights
Under the GDPR (Art. 15–21), you may at any time:
To exercise any of these rights, write to sale@tileforyou.eu — the link opens a ready-made request email.
We will reply within one month (Art. 12 GDPR); if the request is complex, the deadline may be extended by up to two further months — we will let you know in advance. As a rule, requests are handled free of charge; where requests are manifestly unfounded or excessive (repetitive ones, for example), we may charge a reasonable fee or refuse to act (Art. 12(5) GDPR). To avoid disclosing data to the wrong person, we may ask you to confirm that the request really came from you.
8. Right to lodge a complaint with a supervisory authority
If you believe we are processing your data in breach of the GDPR, you have the right to lodge a complaint with the data protection supervisory authority of the country where we are registered, as well as with the authority of the country where you live or work in the EU/EEA.
We would appreciate it if you wrote to us first at sale@tileforyou.eu — most matters are resolved faster directly with us.
9. Data security
The connection to the site is protected by encryption (HTTPS). Access to personal data is limited to those employees and contractors who need it for their work — contractors are contractually required to protect the data and to act only on our instructions.
No method of transmitting data guarantees absolute security. If a breach occurs that could create a risk to your rights, we will notify the supervisory authority (Art. 33 GDPR), and where the risk is high, we will notify you directly as well (Art. 34 GDPR).
10. Children
The site is intended for adult buyers and is not directed at children. We do not knowingly collect data from children under 16. If you learn that a child has given us their data, please write to us and we will delete it.
11. Changes to this policy
We may update this policy — for example, when the law or our processes change. The current version is always published on this page. If the changes are significant, we will post a prominent notice on the site. The current version is 1.0 · effective as of its publication on this page.