Privacy policy

Privacy policy

1. Controller

The controller for the processing of personal data on this website is:

Nextherm GmbH i.G.
Krantzstraße 7
52070 Aachen
Germany

Phone: +49 177 5848872
Email: info@nextherm-cooling.com

Further details are set out in our legal notice.

We have not appointed a data protection officer; in our assessment the statutory requirements for a mandatory appointment are not met. For any questions about data protection and to exercise your rights, you can reach us using the contact details above.

2. Your rights

You have the following rights in relation to your personal data:

  • Access (Art. 15 GDPR) — you can find out whether and which data we process about you.
  • Rectification (Art. 16 GDPR) — you can have inaccurate data corrected.
  • Erasure (Art. 17 GDPR) — subject to the statutory requirements, you can request the erasure of your data, unless we are required to retain it under statutory retention obligations.
  • Restriction of processing (Art. 18 GDPR) — subject to the statutory requirements.
  • Data portability (Art. 20 GDPR) — you can receive the data you have provided to us in a commonly used format, provided the statutory requirements are met; this concerns processing that is based on consent or on a contract and is carried out by automated means.
  • Withdrawal of consent (Art. 7 (3) GDPR) — you can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to that point is not affected.

Right to object

Where we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object to that processing at any time on grounds relating to your particular situation (Art. 21 (1) GDPR). We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where your data is processed for direct marketing purposes, you can object at any time without giving reasons (Art. 21 (2) GDPR). Your data will then no longer be used for that purpose.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de

You may also contact the supervisory authority of your habitual residence or place of work.

Where Shopify acts as an independent controller for a processing operation (sections 5.2 and 5.3), the rights set out above apply to you directly against Shopify. You can exercise them through Shopify's privacy portal: https://privacy.shopify.com/en

3. Provision of the website and the online shop

Our website and our online shop run on the Shopify platform. The provider is Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland.

When you access our pages, Shopify processes the resulting data on our behalf in order to deliver the pages to your browser. For the operation of the shop, Shopify acts as our processor; we have concluded a data processing agreement with Shopify pursuant to Art. 28 GDPR.

The data of our shop, including order and customer data, is stored by Shopify in the European Union.

This processing relationship does not cover processing carried out in connection with the Shopify account, the “Shop” and “Shop Pay” services, or Shopify Network Intelligence. In those respects Shopify acts as an independent controller. Details are set out in section 5.

The legal basis is our legitimate interest in providing our offering securely and efficiently (Art. 6 (1) (f) GDPR) and, where use serves the initiation or performance of a contract, Art. 6 (1) (b) GDPR.

Shopify in turn engages service providers, among other things for cloud hosting, security and sending emails. These include Amazon Web Services, Google Cloud, Cloudflare, Twilio and Mailgun, as well as other companies of the Shopify group. Shopify publishes a current overview of these sub-processors at https://help.shopify.com/en/manual/your-account/privacy/subprocessors.

Server log files

When you access our pages, Shopify, acting as our processor, automatically processes information transmitted by your browser: IP address, date and time of access, the page accessed, the volume of data transferred, the referrer URL, browser type and operating system. We do not combine this data with other sources. It serves the technical provision of the pages, error analysis and protection against attacks.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in secure and trouble-free operation.

Operational and performance data. In addition, when a page is accessed, the shop platform transmits technical operational and performance data to Shopify — such as loading times, error messages and the page accessed — so that faults can be detected and remedied. Without your consent, no identifier that would make you recognisable is transmitted; the transaction number used for this purpose is newly assigned each time a page is accessed. Only if you consent to audience measurement (section 5.1) is a recognisable identifier transmitted as well. Shopify processes this data on our behalf; the legal basis is Art. 6 (1) (f) GDPR, our legitimate interest being secure and trouble-free operation.

This data arises on the infrastructure of our shop platform; we have no direct access to the logs. Their deletion therefore follows the retention rules of our processor. The governing criterion is that the logs are kept only for as long as they are required for secure operation, troubleshooting and the investigation of security incidents; beyond that they are deleted or anonymised. We will inform you of the current position on request.

Fonts

We use the “Inter” typeface to display our pages. The font files are delivered from our own domain and provided through the infrastructure of Shopify as our processor. No transmission to a third party independent of Shopify takes place. In particular, we do not embed any fonts from servers operated by Google LLC. This has been verified by a network analysis.

Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a consistent and technically reliable presentation of our offering.

4. Cookies and access to your terminal equipment

Cookies and comparable technologies are used on our pages. Cookies are small files stored on your device.

Strictly necessary cookies are used so that our pages can be delivered securely and so that your settings for language, region and currency are retained. They are set without your consent. The legal basis is Section 25 (2) no. 2 TDDDG (German Act on Data Protection and the Protection of Privacy in Telecommunications and Digital Services) in conjunction with Art. 6 (1) (f) GDPR.

All other cookies and forms of access to your terminal equipment — in particular those used to analyse usage — are only set if you have consented beforehand. The legal basis is Section 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR.

One exception has to be disclosed: a component of the Shopify platform sets a cookie on the domain shop.app without your consent. We cannot prevent this on our pages. What lies behind this, and what we are doing about it, is explained in section 5.3.

You manage your consent through the consent dialogue shown to you on your first visit. You can change or withdraw your decision at any time using the link labelled “Cookie preferences” in the footer of every page. On withdrawal, the consent-based cookies are deleted immediately and are not set again; we verified this on 31 August 2026.

You can also delete cookies or restrict their storage in your browser settings. If you block third-party cookies, you will also prevent the cookie on shop.app described in section 5.3.

Local storage and session storage. Besides cookies, our pages use your browser's local storage and session storage. Without your consent, the following are stored there: your privacy decision itself, a technical status value of the platform, and two entries belonging to the component described in section 5.3. The session storage entries are deleted when you close the browser tab.

Overview of the cookies used

Recorded by a measurement on 31 August 2026, using a fresh browser for each state.

Set without consent — unchanged even after “Reject all”:

Name Purpose Provider Domain Retention
_shopify_essential Secure operation of the platform and of your session Shopify nextherm-cooling.com 12 months
localization The language and region you have chosen Shopify nextherm-cooling.com 12 months
cart_currency The currency you have chosen Shopify nextherm-cooling.com 14 days
_shop_app_essential Component of the “Shop” service, see section 5.3 Shopify .shop.app 12 months

Only after your consent:

Name Purpose Provider Domain Retention Category
_shopify_y Recognition for usage statistics Shopify .nextherm-cooling.com 12 months Analytics and marketing
_shopify_s Session identifier for usage statistics Shopify .nextherm-cooling.com 30 minutes Analytics and marketing
_shopify_analytics Evaluation of usage Shopify nextherm-cooling.com 12 months Analytics
_shopify_marketing Attribution of the channel through which you found us Shopify nextherm-cooling.com 12 months Marketing

Only if you fill in our contact form:

Name Purpose Provider Domain Retention
__cf_bm Detection of automated access, see section 6 Intuition Machines (hCaptcha) .hcaptcha.com 30 minutes

This cookie is only set once you start interacting with the form — not when the page is opened.

5. Audience measurement and Shopify services

5.1 Audience measurement

We use the statistics function built into the Shopify platform in order to understand how our shop is used — for example which pages are accessed and how ordering processes proceed. The data is transmitted to Shopify servers (including monorail-edge.shopifysvc.com). The evaluation is carried out in aggregate form and serves to improve our offering.

Legal basis: your consent under Section 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR, in so far as your terminal equipment is accessed for this purpose.

Irrespective of your consent, the platform transmits technical operational data to Shopify — such as loading times, script errors and which type of page was accessed. As long as you have not consented, this happens without an identifier that makes you recognisable: the field for the session identifier is filled with zeros in that case. The legal basis in that respect is Art. 6 (1) (f) GDPR, our legitimate interest in trouble-free operation; your terminal equipment is not accessed in the process.

5.2 Shopify Network Intelligence

The “Shopify Network Intelligence” function is activated in our shop. In this context Shopify uses data about your activities in our shop together with data from other shops on the Shopify platform in order to improve products, personalisation, fraud detection and targeted advertising.

Shopify is the independent controller for this processing, not us. It does not take place on our behalf or on our instructions. According to Shopify, other merchants do not gain any insight into your data.

The legal basis for the access to your terminal equipment and for targeted advertising is your consent under Section 25 (1) TDDDG in conjunction with Art. 6 (1) (a) GDPR. You can withdraw it at any time with effect for the future (see section 4).

Which data Shopify processes for its own purposes in this context, and which rights you have directly against Shopify, is set out in Shopify's own privacy policy for consumers:

https://www.shopify.com/legal/privacy

You can exercise your rights against Shopify directly through Shopify's privacy portal:

https://privacy.shopify.com/en

You can object separately there to the use of your data for targeted advertising by Shopify:

https://privacy.shopify.com/en/subject_types?selected=limit_ads

5.3 Remaining component of the “Shop” service

We do not offer sign-in with a Shopify Shop account (“Sign in with Shop”). We have switched this function off; the sign-in buttons have been removed.

Nevertheless, a software component of the Shopify platform continues to be loaded on our pages. It belongs to the “Shop” service and is intended for synchronising the shopping cart. In doing so it can access a sign-in function of your browser. In so far as Shopify processes data for its own purposes in this context, Shopify is an independent controller; the Shopify privacy terms referred to in section 5.2 apply, and you can exercise your rights directly there.

This component is loaded without your having consented, and we are disclosing what that means.
On the first visit to our pages it sets a cookie named _shop_app_essential on the domain shop.app — that is, not on our own domain, but on the consumer platform operated by Shopify. The cookie has a lifetime of twelve months and cannot be read from our pages. In addition, two technical entries are stored in your browser's storage. No shopping cart is transferred in the process; only the time of the attempt is recorded.

In our view this access is not necessary. It is not possible to place orders in our shop, there is no shopping cart to be synchronised, and Shopify's own cookie policy does not list this cookie among those necessary for the operation of a merchant storefront. In our assessment it ought not to be set without your consent.

Even so, we cannot switch it off on our pages. The component is inserted by Shopify directly into every page; all the settings provided for this purpose are switched off on our side, and there is no further control. We have therefore asked Shopify for information and for a remedy, and we will update this section as soon as we receive a reply.

What you can do yourself: if you block third-party cookies in your browser, this cookie will not be set. The other functions of our pages are unaffected by this.

5.4 Services of other providers

We do not use analytics or advertising services of other providers. In particular we do not use Google Analytics and no advertising pixels from Meta, Google, TikTok or Pinterest. We do not offer sign-in via third-party accounts — neither via Google or Facebook nor via a Shopify Shop account.

We do not offer a live chat or chatbot on our pages. You can write to us using our contact form (section 6); there is no chat function beyond that.

6. Contact form and getting in touch

You can send us an enquiry using our contact form. The following is collected in the process: the subject of your enquiry, your name, your company, your email address, your telephone number, details of the intended application, and your message. Mandatory fields are marked in the form.

We use this data to process your enquiry and for follow-up questions relating to it. The recipients are the processors we engage for the operation of the website and for our email accounts, and — to prevent automated submissions — the anti-spam service named below. Any disclosure beyond this only takes place where it is necessary in order to deal with your enquiry, where you have consented, or where we are required to do so by law.

Legal basis: Art. 6 (1) (b) GDPR where your enquiry is directed at concluding or performing a contract; otherwise Art. 6 (1) (f) GDPR, based on our legitimate interest in responding to enquiries.

Anti-spam protection by hCaptcha. Our contact form is protected against automated submissions. For this we use the hCaptcha service. The provider is Intuition Machines, Inc., 350 Alexander Street, Princeton, NJ 08540, USA.

The service is only loaded once you start filling in the form — not when the page is opened. Anyone who merely reads the page has no contact with hCaptcha. As soon as you interact with the form, your IP address and information about your browser and your usage behaviour are transmitted to hCaptcha and evaluated there in order to determine whether the input originates from a human being. In the process, a cookie for detecting automated access (__cf_bm) is set and a frame invisible to you is embedded in the page. Data is transferred to the United States; details are set out in section 12.

Setting this cookie is necessary in order for us to be able to offer you the function you have expressly requested at all — sending a message through our form; without protection against misuse the form could not be operated. The legal basis for the access to your terminal equipment is therefore Section 25 (2) no. 2 TDDDG; consent is not required for this. For the subsequent processing of your data the legal basis is Art. 6 (1) (f) GDPR — our legitimate interest lies in protecting our form against misuse and automated submissions.

If you do not wish to use hCaptcha, you can reach us at any time by the means set out in our legal notice — by email, by telephone or via WhatsApp. hCaptcha is not loaded in those cases.

Email accounts. We operate our email accounts with IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Messages that you send us through the contact form or directly by email are stored there. IONOS SE acts as our processor; the processing takes place in the European Union.

If you contact us by email or by telephone, the same applies to the data arising in that context.

Communication via WhatsApp. You can also reach us via WhatsApp using the number given in our legal notice. We use a business account with WhatsApp Business for this. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, a company of the Meta group. If you write to us via WhatsApp, WhatsApp processes your telephone number, the content of your messages and usage data in accordance with its own terms; in that respect WhatsApp is an independent controller. A transfer to the United States also takes place in the process.

We use this data solely to deal with your request. We do not synchronise any address book with WhatsApp, so that contact details of third parties are not transmitted to WhatsApp by us.

Legal basis: Art. 6 (1) (b) GDPR where your message is directed at a contract, otherwise Art. 6 (1) (f) GDPR. Contact via WhatsApp takes place on your initiative; if you do not wish to use this route, you can reach us by the other means set out in our legal notice.

We store your enquiry and the associated correspondence until the matter has been concluded and no further questions are to be expected, but at the longest for six months after the matter has been dealt with. If your enquiry gives rise to a quotation, an order or a repair order, it constitutes a commercial letter within the meaning of the statutory retention rules; the periods set out in section 13 then apply.

7. Customer account

We do not currently offer a customer account. Should we introduce this option, we will add to this section beforehand.

8. Order processing

We currently accept orders by telephone, by email and via WhatsApp. There is no facility to order through this website; the shopping cart and checkout are not enabled. If we set them up, we will add to this section beforehand.

When you place an order with us, we process the data required to perform the contract: name, billing and delivery address, email address, telephone number, the items ordered and the details of the payment method chosen.

We pass this data on in so far as it is necessary for the performance of the contract — to the shipping company instructed to make the delivery, to our bank, and to our tax advisers for the fulfilment of tax obligations.

Legal basis: Art. 6 (1) (b) GDPR for the performance of the contract and Art. 6 (1) (c) GDPR for the fulfilment of commercial and tax law obligations.

Payments

We currently offer only advance payment by bank transfer and payment on account. Both are settled by transfer to our business account. We do not use a payment service provider. We do not collect, process or transmit any card details, any access data for payment services, or any data for card payments, PayPal or comparable procedures.

The data processed comprises your name, the invoice amount, the payment reference and — once your payment has been received — the bank details from which the transfer was made. In the case of a refund, for example after a withdrawal, we transmit these bank details to our bank so that the repayment can be carried out.

The recipients are our bank and our tax advisers. We do not carry out any credit checks. We do not query credit reference agencies and we do not report anything to credit reference agencies.

The legal basis is Art. 6 (1) (b) GDPR for the performance of the contract and Art. 6 (1) (c) GDPR in conjunction with Section 147 AO (German Fiscal Code) and Section 257 HGB (German Commercial Code) for the retention of payment records.

If we offer further payment methods at a later date — such as credit card, PayPal or Wero — payment service providers will be added as independent controllers. We will add to this section before the payment method concerned is enabled.

Shipping

Depending on the size, weight and destination of your consignment, we instruct parcel services, express services or freight forwarders to make the delivery. These companies are independent controllers for their processing; as carriers they are subject to their own statutory obligations.

We will tell you which company is carrying your consignment in the dispatch confirmation. On request we will also tell you beforehand, at any time.

For delivery we transmit your name and the delivery address to the shipping company instructed. Where you have agreed or where it is necessary in order to arrange a delivery date — for example in the case of forwarding deliveries of bulky goods — we additionally pass on your email address or telephone number so that the shipping company can arrange delivery with you.

Legal basis: Art. 6 (1) (b) GDPR. If, at your request, we deliver to an address outside the European Union, the details required for customs clearance and delivery are also transmitted to bodies in the country of destination; the legal basis for this is Art. 49 (1) subparagraph 1 (b) GDPR, because the transfer is necessary for the performance of your contract.

9. Repair orders

If you send us a cooler or a comparable component for repair, we process your contact and address details, the details of the component sent in and of the vehicle or machine in which it is used, your information on the operating fluids used, and the documentation produced in the course of inspection and repair.

Legal basis: Art. 6 (1) (b) GDPR for the performance of the repair contract. In so far as we collect information on operating fluids and hazardous substances, this additionally serves the fulfilment of our obligations relating to occupational safety and disposal (Art. 6 (1) (c) GDPR).

In so far as we involve third parties in carrying out the order, we pass on the data required for that purpose. Those that may be involved are specialist firms for individual work steps, testing and calibration services, suppliers of spare parts, and specialist waste disposal firms for operating fluids.

Photographs relating to the repair order

Images that you send us. In order to assess damage we frequently ask you for photographs of the component concerned, or you send them to us on your own initiative — by email or via WhatsApp. We store these images in the file relating to your order and use them solely to deal with that order. The legal basis is Art. 6 (1) (b) GDPR. If you send us images via WhatsApp, what is set out in section 6 about that route applies in addition.

Our own photographs. When a component arrives with us, we record its condition photographically, as well as its condition after the work has been completed. This serves as evidence of the condition in which another party's property reached us and the condition in which it left our premises — it protects you as much as it protects us, for example in the case of transport damage. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in securing evidence.

We do not photograph people. Our photographs show the component only. If you send us images on which people, registration numbers or other details are recognisable which are not required for the repair, we will remove those areas or delete the image as soon as we notice this. You can also point out such an image to us at any time; we will then take care of it.

The images form part of the order documentation. We retain them together with the rest of the order documentation until warranty claims arising from the repair order have become time-barred — regularly two years from acceptance plus a buffer for limitation periods that are running — and delete them afterwards. The longer periods set out in section 13 apply to invoices and accounting records.

10. Sales on our premises

We do not currently offer sales on our premises. Should we begin to do so, we will add to this section beforehand.

11. Internal systems

For our email accounts and our cloud storage we use services of IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, with processing in the European Union.

We do not currently use an enterprise resource planning system in which order, repair and accounting data are brought together. As soon as we put one into operation, we will add to this section beforehand.

Legal basis: Art. 6 (1) (b) and (c) GDPR.

AI functions of our shop platform

We have not activated the AI functions offered by our shop platform — such as automatic text generation or a conversational assistant. As a result, no processing of your data takes place on our pages in that respect. Should we use such a function at a later date, we will add to this section beforehand.

AI support in dealing with your enquiries

We do not currently use an AI-based tool to draft replies. The content of your messages is not transmitted to any provider of such tools. Should we use such a tool in future, we will update this privacy policy before the processing begins.

12. Transfers to third countries

The data of our shop, including order and customer data, is stored by Shopify in the European Union. However, this does not mean that it is processed exclusively within the European Union: for the operation of the platform, Shopify states that it also draws on companies of its own group and on service providers established in the United States and in Canada. The processing described in sections 5.2 and 5.3, for which Shopify is an independent controller, likewise does not take place exclusively within the European Union.

Which safeguard applies in a given case depends on the recipient:

Shopify. Our contracting party is Shopify International Limited, established in Ireland. Transfers to the Canadian parent company Shopify Inc. are based on the adequacy decision of the European Commission for Canada — such a decision establishes that a level of data protection comparable to that of the EU exists there. Transfers to other companies of the Shopify group and to sub-processors outside the European Economic Area, in particular to the United States, are based on the European Commission's standard contractual clauses pursuant to Implementing Decision (EU) 2021/914. Details are set out in Shopify's data processing addendum at https://www.shopify.com/legal/dpa

Intuition Machines, Inc. (anti-spam protection for our contact form, section 6), established in the United States, bases the transfer on the standard contractual clauses and is additionally certified under the EU-US Data Privacy Framework, for which an adequacy decision of the European Commission exists. Information on this is available at https://www.hcaptcha.com/gdpr

WhatsApp (section 6) is an independent controller for the processing of your messages. The safeguards that apply there to transfers to the United States can be found in WhatsApp's privacy policy.

We will provide you with a copy of the applicable standard contractual clauses on request.

We point out that in third countries access to data by government authorities cannot be ruled out to the same extent as within the European Union.

13. Retention periods

We delete personal data as soon as the respective purpose ceases to apply and no statutory retention or documentation obligations stand in the way.

Statutory retention periods. We retain commercial and business letters received and sent for six years, accounting records for eight years, and commercial books, inventories, opening balance sheets and annual financial statements for ten years. In each case the period begins at the end of the calendar year in which the document was created, received or sent. As long as these obligations apply, the processing of the data concerned is restricted: it remains available only for the purpose of fulfilling those obligations and is deleted once the periods have expired.

Enquiries that do not lead to a further transaction. If your enquiry does not lead to a quotation, an order or a repair order, we delete it at the latest six months after the matter has been dealt with. If it does give rise to a transaction, the period for business letters applies.

Differing periods for cookies and similar technologies (section 4), for server log files (section 3) and for the documentation of repair orders (section 9) are stated in those sections.

14. No automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place. Your request is always decided on by a person.

15. Obligation to provide data

Which information is required depends on the matter in question.

We need the information marked as mandatory in the contact form in order to be able to deal with your enquiry. For the initiation and performance of a contract we need in particular contact, billing, delivery and contract data; without this information we may not be able to conclude or perform the contract. Individual items of information may additionally be required under commercial or tax law — the billing address, for instance. Information provided voluntarily is identifiable as such.

16. Changes to this privacy policy

We adapt this policy when the legal position or our processing changes — for example when we start using new services. The version published on this page applies in each case.

Authoritative version. The German version of this privacy policy is the authoritative one.

Version: 31 August 2026