Privacy policy

We are committed to protecting your personal data and respecting your privacy. This Policy explains how we collect, use, disclose and safeguard your information when you visit our website and purchase from our online shop.

1. Who We Are and How to Contact Us

Data Controller: HERDES
Registered company: WELOVEPAPER S.L. (CIF B66790254)
Address: Carrer de Bruc 136, 08037 Barcelona, Spain
Email: shop@herdes.eu

2. Scope and Applicable Law

This Policy applies to www.herdes.eu and the HERDES online shop. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), and the Spanish Law 34/2002 on Information Society Services and e‑Commerce (LSSI‑CE).

3. Categories of Data We Process

  • Identification and contact data (name, email, postal address, phone)
  • Transaction and delivery data (billing/shipping addresses, order contents, payment status)
  • Account data (login, preferences, communication consents)
  • Device and usage data (IP address, browser, pages viewed, cookies/analytics IDs)
  • Communications data (emails, customer service chats)
  • Marketing preferences and consent records

4. Purposes and Legal Bases

We use your data for the following purposes under the legal bases indicated:

  • To process your orders, payments and deliveries; to handle customer service (Art. 6(1)(b) GDPR — contract).
  • To manage your account and authentication (Art. 6(1)(b) GDPR — contract).
  • To comply with legal obligations (tax, accounting, consumer protection) (Art. 6(1)(c) GDPR).
  • To send service communications (order updates, policy changes) (Art. 6(1)(b) and/or (c) GDPR).
  • To prevent fraud and ensure security (Art. 6(1)(f) GDPR — legitimate interests).
  • To conduct analytics and improve our services and website performance (Art. 6(1)(f) GDPR — legitimate interests).
  • Direct marketing by email:
    • Newsletter and general promotions: only with your prior, explicit consent (Art. 6(1)(a) GDPR; Art. 21 LSSI‑CE).
    • Soft opt‑in: if you purchase from us, we may email you offers about products similar to those you bought, unless you object (Art. 21.2 LSSI‑CE; Art. 6(1)(f) GDPR). You can opt out at any time via the unsubscribe link or by contacting us.

5. Cookies and Similar Technologies

We use first‑party and third‑party cookies for strictly necessary functions, preferences, analytics and advertising. On your first visit, our cookie banner allows you to accept, reject or manage categories (except strictly necessary cookies). You can change your preferences at any time via the cookie settings or your browser. For details of cookies used, retention times and vendors, please see our Cookie Table (available via the cookie banner).

6. Disclosure of Data and Processors

We share data with service providers acting on our behalf (processors) such as hosting, payment processing (e.g., Stripe, PayPal), email service providers, fulfilment and logistics, analytics and customer support tools. These providers process data under written contracts and appropriate safeguards. We may disclose data where required by law or to establish, exercise or defend legal claims.

7. International Transfers

Where data is transferred outside the European Economic Area, we ensure appropriate safeguards such as adequacy decisions, the European Commission’s Standard Contractual Clauses, and additional technical/organisational measures where necessary.

8. Retention Periods

  • Order and invoicing data: for the statutory period required by tax and accounting laws (generally up to 6–10 years in Spain).
  • Account data: for as long as your account remains active.
  • Marketing data: until you withdraw consent or object, and in any case regularly reviewed for minimisation.
  • Customer service records: as long as necessary to handle your request and for legitimate business purposes.

9. Your Rights

You have the right to request access, rectification, erasure, restriction, portability and to object to processing, including direct marketing. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. To exercise your rights, contact shop@herdes.eu. You also have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD).

10. Children

Our services are intended for individuals aged 18 and over. We do not knowingly process children’s data.

11. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or loss.

12. Marketing Communications and Newsletter

Newsletter subscription requires your explicit consent (opt‑in). You may unsubscribe at any time using the link provided in our emails or by contacting us. If you have purchased from us, we may contact you with offers about products similar to those you previously purchased unless you object (soft opt‑in). We do not automatically add purchasers to our general newsletter list without consent.

13. Cookies Policy Details

Categories include: strictly necessary (site operation and security), functionality (preferences), analytics (usage statistics) and advertising (ad personalisation/measurement). Third‑party cookies may collect data across sites. You can revoke or adjust consent at any time via the cookie banner.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated on our website and, where appropriate, by email.

15. Contact

For privacy queries or to exercise your rights, please contact: shop@herdes.eu