Privacy · 1 October 2026
Your information.
How we handle it.
This notice explains the processing of personal data when you use the website, contact us, place a business order or report a payment.
Controller & EU representative
BISSOLUX LLC, 30 N Gould St, Sheridan, WY 82801-6317, United States. Represented by Alban Berisha. Email: info@bissolux.com. Telephone: +49 176 34306448.
EU representative under Article 27 GDPR: Alban Berisha, Berliner Straße 104, 53757 Sankt Augustin, Germany. Contact: info@bissolux.com.
1. Scope and legal bases
This notice covers personal data processed when you visit this website, contact us or use its business-order features. The GDPR applies where we offer services to people in the European Union. Depending on the purpose, processing relies on consent, pre-contractual or contractual necessity, legal obligations or legitimate interests under Article 6(1)(a), (b), (c) or (f) GDPR. Access to information on a user's device is also subject to § 25 TDDDG where applicable.
2. Providing the website
Technical requests can involve your IP address, request date/time, requested content, referrer, browser, operating system and protocol logs. We use hosting and infrastructure services in Germany/the EU, with supplementary CDN and routing services, to provide the site and maintain stability, security, troubleshooting and abuse prevention. This processing is based on our legitimate interests under Article 6(1)(f) GDPR.
3. Cookies, consent and browser storage
We use cookies and browser storage. Non-essential device access for marketing takes place only after consent through the consent banner. You can change that choice through the cookie settings in the footer, with effect for the future.
When you choose a currency, we store only EUR, USD or GBP under bissolux.currency in your browser localStorage. This remembers your choice between pages and visits. You can change it using the currency selector or remove it by clearing this website’s browser data. It contains no contact or payment-account details.
With marketing consent, campaign and source information may be stored for the browser session under bissolux.tracking.snapshot in sessionStorage. This can include the landing page, page URL, referrer, query string, UTM parameters, click identifiers and other URL parameters. It supports internal attribution of enquiries to campaigns.
The order form separately stores a random request identifier and technical fingerprint in sessionStorage to recognise a retry and reduce duplicate submissions. Entered form text is not stored in that entry. After order acceptance, a separate session entry keeps only the order reference, a protected payment-access token and acceptance/due timestamps. It lets you retrieve the original payment instructions from the server after reloading. It stores no company or form text and is no longer used after 90 days. End your browser session on shared devices. Session entries normally end with the browser session. Marketing storage relies on consent; technically necessary storage relies on the applicable necessity and legitimate-interest provisions.
4. Google Ads and campaign attribution
With marketing consent, the Google tag for Google Ads may load from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We record successful form events and interactions such as primary contact-button or project clicks, form starts and successful enquiries or orders. Events contain the action type and a fixed page-area identifier, not the text or contact details entered in form fields.
Loading advertising scripts may involve IP address, browser/device information, time, visited URL, referrer and advertising or campaign identifiers. Campaign URLs can contain identifiers such as utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, gbraid, wbraid, msclkid, fbclid, ttclid or dclid.
Campaign identifiers are transmitted with a form enquiry only after marketing consent. They are validated server-side and may appear in internal lead notifications for source attribution and campaign evaluation. Handling the actual enquiry does not depend on marketing consent and instead relies on contractual/pre-contractual necessity or another applicable basis.
5. Contact, business orders and payment reports
When you contact us, we process the information you provide, including your name, contact details, message, project description and optional supporting information. This enables us to answer the enquiry, prepare a contract and communicate with you.
The order process additionally collects the company name, authorised contact, business address and country, and applicable tax or registration details such as VAT ID, NUI or NIPT/NUIS. It records the selected service, currency, price, package version, agreed conditions, consent and order reference. A technical delivery status helps prevent duplicate submissions. These records support contract formation, performance, correspondence and legal retention duties.
The fixed-package process can issue an automated order acceptance after a valid successful submission. The reference and payment instructions are returned in the browser and sent by email. This technical confirmation does not evaluate personal characteristics or perform credit scoring.
If you use the payment-report function, your declaration that a transfer was instructed, the associated order reference, selected bank-transfer route, stated transfer date and its processing status are recorded and communicated to our business email. This declaration is kept separate from verified bank receipt. Payment matching and related records are used for contract administration and accounting.
6. Online payments through Stripe
If you choose the offered Stripe payment option after order acceptance, we send Stripe your booking reference, service description, email address, agreed amount and currency. You enter payment details and any required billing information directly on Stripe’s hosted payment page. Full card numbers and card security codes are not collected by our server.
We store Stripe transaction identifiers, amount, currency, confirmation time and verified payment status to match your payment to the accepted order and send a payment-confirmation email. Processing supports contract performance and statutory accounting duties under Article 6(1)(b) and (c) GDPR. Stripe also processes information for its own payment, security and fraud-prevention purposes and may process information outside the EU/EEA.
The protected payment-access entry in your browser session lets us retrieve your order and verify its status when you return from Stripe. A return to the website alone never confirms payment. The Stripe privacy notice explains the Stripe entities involved, their processing and applicable international-transfer safeguards.
7. Abuse protection and information security
Cloudflare Turnstile, provided by Cloudflare, Inc., helps protect forms from automated or abusive submissions. It may process technical connection data, browser and interaction features and the generated verification token. Our legitimate interest in operating secure, usable forms is the relevant basis under Article 6(1)(f) GDPR.
We use appropriate technical and organisational measures such as transport encryption, access controls, role-based permissions, logging, backups and system hardening. These measures reduce risks; no internet service can promise absolute security.
8. Business email, domains and related services
Business email services, such as Microsoft 365 or Google Workspace, process message content, communication data and technical metadata as needed to answer enquiries, administer contracts or fulfil legal obligations. Relevant bases include Article 6(1)(b), (c) and (f) GDPR.
Where a separately agreed review-feedback service involves supplied existing-customer contact details, those details are processed to send the agreed requests or organise feedback under the applicable consent or other lawful basis. This is not an automatic part of website visits or package orders.
9. Social platforms and business profiles
When you visit our presence on third-party platforms, the operator's own privacy notice also applies. Depending on the shared processing purposes, joint controllership under Article 26 GDPR may be relevant. Following an external link takes you to a service controlled by its respective provider.
10. Recipients and international processing
The controller is established in the United States. Data handled by the controller can therefore be processed outside the EU/EEA. Google, Cloudflare and other service providers may also involve processing in third countries. Where required, appropriate safeguards, including EU Standard Contractual Clauses and supplementary measures, are used.
Service providers may support hosting/CDN, email and communications, form infrastructure, abuse protection and consent-based advertising/conversion measurement. Where they act as processors, the applicable Article 28 GDPR arrangements are required. Data is disclosed only to the extent needed for the purpose.
11. Retention and required information
Campaign sessionStorage entries normally disappear at the end of the browser session. Contact, lead and business-order data is retained for the period needed to handle the request, communicate, administer the contract, follow up where appropriate or meet statutory retention obligations. Server and security logs are rotated and then deleted or anonymised according to operational retention processes.
Certain details are necessary to handle an enquiry or conclude and perform a business contract. Without the required company, contact or order information, we may be unable to process the request or may only be able to do so in a limited way.
12. Your rights
Where the relevant conditions are met, you have rights to access, rectification, erasure, restriction of processing and data portability under Articles 15–20 GDPR. You may object to processing based on legitimate interests under Article 21 GDPR and withdraw consent at any time for the future under Article 7(3) GDPR. You may also complain to a data-protection supervisory authority in the European Union.
Contact us using the details above to exercise your rights or ask about the processing of your information. Withdrawing marketing consent does not change the lawfulness of processing that already took place, and does not cancel a separately accepted business order.
13. Changes to this notice
We may update this notice when processing activities, technology or legal requirements change. This English notice describes the same core website and business-order processing as our German notice, with the current online-order and payment-report workflow included. Last updated: 1 October 2026.
