Privacy policy

Leopold Parts ApS | B2B Online Store

Effective: August 12, 2026

This Privacy Policy describes how Leopold Parts ApS processes personal data about visitors to leopold-parts.dk, as well as owners, employees, and other contact persons at our business customers, suppliers, and partners. Although the online store is aimed exclusively at businesses, information about a company’s contact persons may constitute personal data.

1. Data Controller

Leopold Parts ApS is the data controller for the processing of personal data described in this policy.

Leopold Parts ApS
CVR No. 40957960
Industrivej 7D
6580 Vamdrup
Email: info@leopold-parts.dk
Website: https://v4rmq3v5x3x.c.updraftclone.com/

2. What Information We Process

Depending on your relationship with us, we may process the following categories of general personal data:

  • Identification and contact information, including name, employer/company, job title, work address, email address, and phone number.
  • Account information, including username, encrypted password, account status, and user settings.
  • Order and transaction information, including items ordered, prices, order history, invoices, bank transfer status, shipping address, and correspondence regarding the purchase.
  • Delivery information, including the recipient’s name, address, phone number, email address, tracking number, and delivery receipt, when applicable.
  • Credit and billing information, including payment terms, credit limit, payment history, and information necessary for a manual credit assessment.
  • Communication information from emails, customer service inquiries, and other correspondence.
  • Newsletter information, including name, email address, company, consent status, and technical information regarding subscription and unsubscription.
  • Technical information, including IP address, device and browser information, log data, cookie IDs, and information about website usage.

We do not request sensitive personal information or social security numbers through our online store. Therefore, please do not send us such information.

3. Purpose and Legal Basis for Processing

Customer Accounts, Quotes, Orders, and Customer Service

We process information to create and manage B2B customer accounts, process inquiries and orders, deliver goods, issue invoices, receive bank transfers, handle complaints, and provide customer service.

The processing is carried out in accordance with Article 6(1)(b) of the General Data Protection Regulation when the data subject is a party to the agreement, and otherwise in accordance with Article 6(1)(f), because we have a legitimate interest in entering into and fulfilling agreements with the company that the contact person represents, as well as in managing the customer relationship.

Accounting and Documentation

We retain order, invoice, and payment information to comply with accounting, tax, and other laws. The legal basis is Article 6(1)(c).

Credit and Invoice Payment

If a business customer applies for invoice payment or credit, we may assess the customer’s ability to pay and establish payment terms. We use information provided by the customer, the customer’s previous payment history with us, and relevant publicly available business information. The legal basis is Article 6(1)(f), as we have a legitimate interest in limiting credit risk and preventing losses. Credit decisions are not made solely by automated means.

Operations, Safety, and Abuse Prevention

We process technical data and log information to operate and protect the online store, troubleshoot issues, document incidents, and prevent fraud or unauthorized access. The legal basis is Article 6(1)(f), because we have a legitimate interest in providing a stable and secure service.

Newsletters and Direct Marketing

When you sign up for our newsletter, we process your contact information to send you news, product information, and offers. Electronic marketing communications are sent based on valid marketing consent. The associated processing of personal data is based on Article 6(1)(a). You can unsubscribe at any time via the link in the newsletter or by contacting us. Withdrawal does not affect the lawfulness of the processing that took place prior to the withdrawal.

Statistics and Marketing Cookies

With your consent, we may use cookies and similar technologies to measure traffic, understand how the online store is used, and target marketing. The placement of cookies and the associated processing are based on your consent, see Article 6(1)(a), unless a cookie is technically necessary. You can change or withdraw your consent via the online store’s cookie settings.

4. Cookies

The online store uses necessary cookies for purposes such as session management, the shopping cart, login, security, and saving cookie preferences. These cookies are necessary for the website and the features you request to function properly.

Statistics and marketing cookies are set only after you give your consent. The current cookie list in the cookie settings specifies the name, provider, purpose, and expiration date for each cookie. Since cookies may change due to updates to WordPress, WooCommerce, and plugins, the cookie list is the continuously updated specification.

5. WooCommerce, Hosting, and Data Processors

The online store is built using WordPress and WooCommerce. Account, order, and customer information is processed in these systems as part of the online store’s operations. Simply.com provides hosting and technical infrastructure and, as a data processor, may access information to the extent necessary for operations, security, backup, and support.

We may also use providers of IT operations, security, accounting, email, and newsletter services. Such providers may only process information in accordance with our instructions and under appropriate data processing agreements when acting as data processors.

6. Who We Share Information With

We share information only when it is necessary, appropriate, and lawful. Recipients may include:

  • GLS Denmark and Danske Fragtmænd for booking, transportation, delivery, Track & Trace, and proof of delivery.
  • .com and relevant IT, security, backup, email, and system providers for the purpose of operating the online store.
  • Banks in connection with bank transfers and payment reconciliation.
  • Bookkeepers, accountants, and other professional advisors, as needed.
  • Public authorities, courts, or other entities where disclosure is required by law or by regulatory requirements, or is necessary to establish, assert, or defend a legal claim.

Shipping providers process the information they receive in accordance with their own data protection policies when they themselves determine the purposes and means of processing related to transportation.

7. Information from Third Parties

As a general rule, we receive information from you or the company you represent. We may also receive delivery status and delivery documentation from GLS or Danske Fragtmænd, payment information from our bank, and general business information from public registries. The purposes and legal bases are the same as those described above.

8. Transfers Outside the EU/EEA

We strive to process data within the EU/EEA. However, some IT, cookie, support, or email providers may process data in countries outside the EU/EEA. If this occurs, we ensure a lawful basis for the transfer, such as an adequacy decision from the European Commission or the European Commission’s Standard Contractual Clauses, supplemented as necessary by additional safeguards. You can contact us for more information about specific transfers and relevant safeguards.

9. How Long We Retain Information

  • As a general rule, order, invoice, and payment records are retained for five years from the end of the fiscal year to which they relate, to the extent required by accounting regulations.
  • Customer and account information is retained for as long as the account or customer relationship remains active. After that, the information is deleted or anonymized when it is no longer necessary, subject to accounting requirements and any legal obligations.
  • Correspondence and customer service information are retained for as long as necessary to process the inquiry and document the process, typically for no more than three years after the case is closed, unless a longer retention period is required due to a dispute or by law.
  • Credit information and internal credit assessments are retained for the duration of the credit relationship and thereafter for as long as necessary for documentation, risk management, or legal claims.
  • Newsletter information is retained until you unsubscribe. Records of consent and unsubscription may be retained thereafter for as long as necessary to demonstrate compliance with the regulations.
  • Cookie information is retained for the periods specified in the current cookie overview. Consent preferences are retained so that we can respect and document your choice.
  • Technical logs are retained only as long as necessary for operations, security, and troubleshooting, unless a specific security incident requires longer retention.

10. Your Rights

Depending on the circumstances, you have the right to:

  • to access the personal information we process about you,
  • to have incorrect or incomplete information corrected,
  • to have information deleted when the conditions are met,
  • to have the treatment limited,
  • to object to processing based on our legitimate interests and, in all cases, to direct marketing,
  • to receive information that you have provided to us in a structured, commonly used, and machine-readable format when the right to data portability applies, and
  • to revoke consent with future effect.

These rights may be limited, for example, if we are legally required to retain information, or if the information is necessary for a legal claim. Contact info@leopold-parts.dk if you wish to exercise your rights. We may ask for information necessary to verify your identity.

11. Complaint

If you are dissatisfied with how we process your personal information, please feel free to contact us first. You also have the right to file a complaint with the Danish Data Protection Agency via www.datatilsynet.dk.

12. Security and Personal Data Breaches

We implement appropriate technical and organizational security measures tailored to the nature and risk of the processing. This includes, among other things, access restrictions, individual user accounts, system and plugin updates, backups, encrypted connections (HTTPS), vendor management, and internal procedures.

Suspected security incidents are investigated and mitigated. If a personal data breach poses the risk specified by law, we will report the breach to the Danish Data Protection Agency without undue delay and, if possible, within 72 hours. Affected individuals will be notified when required by law.

13. Comments, Media, and Automated Decisions

The online store is not set up to allow public comments or media uploads by visitors. If such features are enabled in the future, we will update this policy and the relevant information provided at the time of data collection.

We do not make decisions based solely on automated processing that have legal effects or similarly significantly affect you. Any credit decisions are made with human involvement.

14. Changes

We may update our Privacy Policy when our data processing practices, systems, or policies change. The current version is published on leopold-parts.dk along with the date of the most recent update. In the event of significant changes, we will provide notice in an appropriate manner.