Skip to content

Privacy Policy

This is a convenience translation of our German privacy policy. In case of any discrepancy, the German version is the legally binding one.

This privacy policy applies to wallinberg.com, including www.wallinberg.com, the /all-in-one page and all other subpages.

We do not set any cookies ourselves. However, our hosting and security provider Cloudflare may set technically necessary security cookies, currently in particular the session cookie _cfuvid.

Optional web analytics are loaded only with your consent. This website uses no external fonts and no advertising networks. No contact form is offered.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Glantra Global GmbHAm Ziegenberg 5534128 KasselGermany

Represented by: Mohsen Asi, Managing DirectorPhone: +49 160 5078460Email: info@glantraglobal.de

2. Hosting and technical connection data

This website is hosted by, or delivered via the network of, Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.

Each time the website is accessed, technically necessary connection data is processed. This includes in particular:

  • IP address,
  • date and time of access,
  • page requested,
  • referrer,
  • browser and operating system information,
  • technical information about the device used.

This processing is necessary so that the website can be delivered, operated reliably and protected against misuse and attacks. The website cannot technically be delivered without processing the IP address.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and functional operation of the website.

Under the current configuration, we do not keep separate server log files ourselves. The technical connection data is processed by Cloudflare. It is not stored for longer than is necessary for delivery, security and error analysis. The specific storage period depends on the logging and security features enabled in the Cloudflare account.

A data processing agreement pursuant to Art. 28 GDPR is in place with Cloudflare, provided that the Cloudflare account and the agreement are held by Glantra Global GmbH. The agreement can be viewed in the Cloudflare Data Processing Addendum (opens in a new tab).

Where Cloudflare participates in the EU-U.S. Data Privacy Framework as a certified company and the specific transfer is covered by it, data is transferred to the USA on the basis of Art. 45 GDPR. Where this is not the case, the transfer is based on the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR, including appropriate supplementary safeguards.

3. Technically necessary cookies and local storage

Cloudflare security cookie

To protect against overload and to limit abusive requests, Cloudflare may set the cookie _cfuvid.

The cookie enables Cloudflare to distinguish individual visitors even when several people use the same IP address, for example on a mobile network or a shared Wi-Fi network.

The cookie:

  • is set by Cloudflare, not by us;
  • serves exclusively the technical security function;
  • is not used for advertising, web analytics or profiling;
  • is a session cookie and is generally deleted when you close your browser.

Storing it is strictly necessary in order to provide the digital service you have accessed securely and reliably. The legal basis is Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG). The associated processing of personal data is based on Art. 6(1)(f) GDPR.

When this security service is used, your IP address may be transmitted to Cloudflare in the USA. The transfer takes place under the transfer mechanisms set out in section 2.

Depending on the Cloudflare security features enabled, further technically necessary security cookies may be added. They are not used for advertising or analytics purposes.

Local storage

To store your decision on web analytics, this website uses your browser's local storage (localStorage) under the key wallinberg-cookie-consent.

The entry contains only the value “accepted” or “rejected”. It remains stored until you delete it via your browser settings.

The entry serves to store your decision so that the notice is not shown again on every visit. It is not transmitted to our server and is not used for analytics, advertising or profiling purposes.

Insofar as this storage is solely necessary to take account of the choice you have expressly made, it takes place without separate consent pursuant to Section 25(2) no. 2 TDDDG.

The selected product finish is not stored permanently in local storage. It is passed on via the URL parameter ?finish=. Your product selection is not stored permanently.

4. Web analytics with Cloudflare Web Analytics

We only use Cloudflare Web Analytics if you have first clicked “Accept” in the web analytics notice.

The analytics script is loaded from static.cloudflareinsights.com only after you have given your consent. For technical reasons, your IP address is transmitted to Cloudflare in the process. Technical usage and performance data may also be processed, in particular page views, referrers, loading times and basic information about the browser and device.

According to Cloudflare, Cloudflare Web Analytics itself uses no cookies or local storage for analytics, no fingerprinting and no cross-device identifiers. According to Cloudflare, no personal usage profiles are created for advertising purposes.

The legal basis for processing personal data is your consent pursuant to Art. 6(1)(a) GDPR. Insofar as information is stored on or read from your device for web analytics, this is additionally based on Section 25(1) TDDDG.

According to Cloudflare's current documentation, non-aggregated beacon data is stored for seven days. After that, the data is aggregated. The specific storage period depends on the Cloudflare configuration used. Further information: Cloudflare Web Analytics (opens in a new tab).

You can withdraw your consent at any time with effect for the future. To do so, use the “Privacy settings” button, which can be found at the bottom of every page. After withdrawal, your stored choice is deleted, the page is reloaded and the analytics script is no longer loaded.

5. Fonts

The fonts used, Teko and Inter, are embedded locally and delivered via our hosting provider as described in section 2.

There is no connection to Google Fonts or other external font services. In this respect, no data is transmitted to external font providers.

6. Contacting us and Microsoft 365

This website does not contain a contact form.

The email and telephone links merely open the email or telephone application set up on your device. Simply clicking them does not transmit any data to our website via a form.

If you contact us by email or telephone, we process the data you provide, in particular your name, contact details and the content of your enquiry, in order to handle and respond to your request.

Our email communication is processed via Microsoft 365 (Microsoft Ireland Operations Limited). Microsoft acts as our processor in this respect. Processing takes place on the basis of Microsoft's product and data protection terms and the applicable data processing agreement.

Depending on the service, tenant configuration and support or security function, data may be processed in third countries, in particular the USA, or be accessible from there. For such transfers, Microsoft uses, among other things, the standard contractual clauses applicable to the respective services. Further information can be found in the Microsoft Products and Services Data Protection Addendum (opens in a new tab).

The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to entering into or performing a contract. In all other cases, processing is based on Art. 6(1)(f) GDPR.

The data is deleted as soon as the purpose of processing no longer applies and no statutory retention periods prevent this. Business-related emails may be stored for longer due to statutory retention obligations.

7. External links and Amazon

This website contains a link to a product page on Amazon.

No Amazon content is embedded when you simply visit this website. A connection to Amazon is only established when you click the link. In the process, your IP address, referrer and browser data in particular may be transmitted to Amazon.

The Amazon URL currently used contains no tracking or attribution parameters.

Purchases and data processing on Amazon are governed exclusively by Amazon's privacy notice and conditions of use. Amazon is independently responsible for the data processing there.

Should Amazon attribution or affiliate links be used in future, this privacy policy will be supplemented accordingly.

8. Your rights

Under the GDPR, you have in particular the following rights:

  • right of access pursuant to Art. 15 GDPR;
  • right to rectification pursuant to Art. 16 GDPR;
  • right to erasure pursuant to Art. 17 GDPR;
  • right to restriction of processing pursuant to Art. 18 GDPR;
  • right to data portability pursuant to Art. 20 GDPR;
  • right to withdraw any consent given, with effect for the future.

To exercise your rights, please use the contact details given in section 1.

9. Right to object pursuant to Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where this processing is based on Art. 6(1)(e) or (f) GDPR.

This also applies to profiling based on these provisions.

To exercise your right to object, a message to the contact details given in section 1 is sufficient.

10. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority.

The competent authority is, in particular:

The Hessian Commissioner for Data Protection and Freedom of InformationPostfach 316365021 WiesbadenGermany

Phone: +49 611 1408-0Email: poststelle@datenschutz.hessen.deWebsite: https://datenschutz.hessen.de (opens in a new tab)

11. TLS encryption

For security reasons, this website uses TLS encryption. You can recognise an encrypted connection by the fact that your browser's address bar begins with “https://”.

12. No automated decision-making

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.

13. Last updated

This privacy policy was last updated in September 2026.

Back to home