Legal
Privacy policy
What data we process, why, for how long – and what rights you have.
Last updated:
Note: Translation for information purposes. The German version is authoritative.
Controller
The controller responsible for data processing on keychannel.de is:
Keychannel (M. Kiwan), Owner: Mohamad Kiwan
Engerstraße 154, 32051 Herford, Deutschland
Phone: +4915259648379
Email: info@keychannel.de
We have not appointed a data protection officer because we are not legally required to do so.
The key points in brief
- We process your data in order to handle your order, deliver licence keys to you, answer your questions and operate the shop securely.
- We only use statistics and marketing services with your consent. You can change or withdraw your consent at any time via "Cookie settings" in the page footer.
- We do not sell your data.
Your rights
Under the General Data Protection Regulation (GDPR), you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can object to processing based on our legitimate interest (Art. 21) and withdraw your consent at any time with effect for the future (Art. 7(3)). An informal message to info@keychannel.de is sufficient.
You can also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Hosting and server logs
The shop runs on a server of Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, in a data centre in Frankfurt am Main. Hostinger processes the data on our behalf (Art. 28 GDPR).
Each time the site is accessed, technically necessary data is processed: IP address, date and time, page accessed, browser identifier and referrer (the page you came from). The purpose is to deliver the shop and keep it secure, for example to fend off attacks. We store security-relevant events such as failed logins together with the IP address. The legal basis is Art. 6(1)(f) GDPR. We delete these logs after 90 days at the latest.
The connection is encrypted using TLS.
Order, customer account and delivery
What data
Email address, name, shop language, the delivery address for USB shipping, the billing address, order contents, and the time and wording of your consent to immediate delivery. To prove in which country VAT is due, we also store three country indications for each order: the country of the billing address, the country our server determines from your IP address when you order (we do not store the IP address itself for this), and the country of your payment account as reported by the payment service. With a customer account, additionally your password (never in plain text, only as an irreversible hash value) and your order history.
Purpose and legal basis
Performance of the contract and delivery (Art. 6(1)(b) GDPR); statutory retention of invoices and accounting records (Art. 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code, Abgabenordnung, and § 257 of the German Commercial Code, Handelsgesetzbuch). The three country indications serve as the legally required evidence of the country of taxation under the OSS scheme (Art. 6(1)(c) GDPR in conjunction with Articles 24b, 24f and 63c of Implementing Regulation (EU) No 282/2011); they are kept for 10 years. If a payment is not completed, we send you at most one email about this order with a link to pay again, and one reminder; this serves to process your order (Art. 6(1)(b) GDPR).
Licence management
To allocate your licence key, we transmit the order number, item, quantity, email address and first and last name to our own licence management system. It runs on a server of netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, in a data centre in Nuremberg; netcup processes the data on our behalf.
Shipping the USB stick
For USB shipping, we pass your name and delivery address to DHL (Deutsche Post AG, Charles-de-Gaulle-Straße 20, 53113 Bonn, Germany) for delivery.
Emails
We send order confirmations, licence keys and contract documents via Hostinger's email server.
Confirmation page
To ensure that only you can see your key after purchase, we set a technically necessary cookie containing an access code (valid for 14 days).
Postcode lookup
When you enter a postcode in the order form, your browser requests the place name from the Zippopotam.us service. In doing so, your IP address as well as the country and postcode are transmitted. The legal basis is Art. 6(1)(f) GDPR (convenient form filling).
Incomplete orders
If you start the checkout process but do not complete it, we store your email address and basket so that we can match the order if you contact us about it. We do not send reminder emails. The legal basis is Art. 6(1)(b) GDPR. We delete this data after 30 days.
Storage period
Order data until the end of the statutory retention periods (up to 10 years). You can have a customer account deleted at any time; we must nevertheless retain invoices and accounting records until the end of the statutory periods.
Payment via Mollie
We process payments via Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, the Netherlands. Mollie receives the necessary payment and order data (amount, order number, email, where applicable name and billing address, and the details of the selected payment method). Card details are entered directly in Mollie's input fields and do not reach our server. Depending on the payment method, Mollie or the respective payment service (for example Apple, Google or your bank) pass data on to their own controllers. If credit card is selected during checkout or when paying again (including as an automatic preselection, for example because you used it last time), your browser loads a script from Mollie (js.mollie.com), and the card fields come directly from Mollie; Mollie receives your IP address and browser data in the process. Insofar as Mollie stores or reads information on your device in the process, this is strictly necessary for payment by card (§ 25(2) no. 2 TDDDG). From Mollie we receive the payment method used and, where available, the country of your payment account. The legal basis is Art. 6(1)(b) GDPR.
Contact, support and remote support
Enquiries by email, form or phone
We process your details in order to answer your enquiry (Art. 6(1)(b) or (f) GDPR). We delete them once the enquiry has been dealt with and there is no obligation to retain them.
Appointment for remote support
When you book an appointment, we store your name, email, phone or WhatsApp number, preferred appointment and your message (Art. 6(1)(b) GDPR). Remote support is provided via TeamViewer (TeamViewer Germany GmbH, Bahnhofsplatz 2, 73033 Göppingen, Germany) or RustDesk. You download and start both programs yourself; a connection is only established if you actively allow it.
Withdrawal via our website
If you declare a withdrawal via Withdraw from contract, we store your name, email address, order number, the details you provide and the time of receipt. We use this data to process the withdrawal and to confirm receipt to you by email, and we keep it as evidence until the statutory limitation period expires (usually three years from the end of the year). The legal basis is Art. 6(1)(c) GDPR in conjunction with § 356a BGB.
AI chat assistant
A chat assistant is available on our site whose answers are generated by artificial intelligence. The provider of the AI model is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland. Your messages are transmitted to OpenAI in order to answer them and may also be processed in the USA (see Transfers to third countries).
We store the chat history in order to process your enquiry and improve our support. If you provide your email address in the chat, we use it to get back to you. The legal basis is Art. 6(1)(b) GDPR (enquiry) or (f) (improving our support). We delete chat histories after 6 months. Please do not enter any sensitive data in the chat.
Statistics (only with consent)
Google Analytics 4
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics measures how our shop is used (pages accessed, time spent, device, approximate location). Cookies are set for this purpose (for example _ga). IP addresses are not stored by Google Analytics 4.
Microsoft Clarity
The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Clarity records mouse movements, clicks and scrolling behaviour so that we can identify usability problems. Entries in form fields are masked. Cookies: for example _clck, _clsk.
Google and Microsoft may also process data in the USA (see Transfers to third countries).
External content (only with consent)
We display a review seal from Trustami GmbH. To do so, your browser loads a script from trustami.com, which transmits your IP address and browser data to Trustami. Without consent, we only show an image with a link.
Language and currency by location
If you have not selected a language, our server determines your country based on your IP address and shows the shop in the appropriate language. For this we use a country database stored on our own server; your IP address is not transmitted to anyone and is not stored. We choose the currency in the same way, regardless of your language choice: visitors from Switzerland, Liechtenstein, Poland, Sweden, Denmark, Norway, the Czech Republic, Hungary, Romania and the United Kingdom see and pay prices in their local currency, everyone else in euros. You can switch between your local currency and euros; we store this choice in a cookie (kc-currency) that is necessary for shopping in the chosen currency. The legal basis for selecting the language and currency is Art. 6(1)(f) GDPR (comprehensible presentation).
Only the country is evaluated – no town and no precise location. The country database is IP Geolocation by DB-IP, licensed under Creative Commons Attribution 4.0 (CC BY 4.0).
Product reviews
You can only review a product via a personal link that appears after delivery on the confirmation page, in “My account” and in our review request email. We store the name you enter (pre-filled with your first name and the initial of your surname, freely editable), stars, text and time, and – not publicly – the email address and the link to your order. Only the name, stars, text and the note “Verified purchase” are shown publicly. The purpose is to show other customers genuine experiences. The legal basis is your consent by submitting the review (Art. 6(1)(a) GDPR). You can have your review deleted at any time; an informal message to info@keychannel.de is sufficient.
About one week after delivery, we ask you once by email to review the products you bought. For this, we use the email address from your order (Art. 6(1)(f) GDPR in conjunction with Section 7(3) of the German Act against Unfair Competition (UWG); our legitimate interest is genuine customer reviews). You can object to this at any time (Art. 21(2) and (3) GDPR) – via the link in the email or an informal message to info@keychannel.de. We then store your email address on a block list so that you do not receive any further requests; we keep this entry for as long as it is needed to respect your objection.
Notices of recent purchases
In the shop, we display short notices of real, paid orders from the last 48 hours. These show the product, the approximate time and abbreviated buyer information: for shipping to an address only the town ("A customer from Herford"), otherwise the first name with the initial of the surname ("Anna M.") or just "A customer". Surname, email address and address are never shown. The purpose is to show that people actually shop here. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). You can object to this display at any time without giving reasons; an informal message to info@keychannel.de is sufficient.
Other recipients
- Translation: The texts of our shop are translated with DeepL (DeepL SE, Maarweg 165, 50825 Köln, Germany). Only shop texts are transferred, no customer data.
- Tax advisers and authorities receive data insofar as this is required by law.
Transfers to third countries
Google, Microsoft and OpenAI may also process data in the USA. Where the provider is certified, the transfer is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (the European Commission's finding that certified US companies offer an adequate level of data protection; Art. 45 GDPR), and otherwise on EU standard contractual clauses (data protection model contracts specified by the European Commission; Art. 46 GDPR).
Automated decision-making
Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.

