Privacy Policy

Last updated: July 2026

Protecting your personal data is important to us. Below we inform you, in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG), which personal data we process when you visit this website and use our services, for which purposes and on which legal basis this takes place, and which rights you have.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Philipp Andreas
Hegerade 18b
24248 Mönkeberg
Germany

E-mail: info@outarc.net

We have not appointed a data protection officer, as the statutory requirements for this (Section 38 BDSG) are not met.

2. General information on data processing

As a rule, we process our users’ personal data only to the extent necessary to provide a functioning website as well as our content and services, or where you actively transmit data to us (e.g. via the contact form). Processing regularly takes place only with the user’s consent or where one of the legal bases named in Art. 6(1) GDPR applies.

Personal data is erased or blocked as soon as the purpose of storage ceases to apply and no statutory retention obligations (in particular under commercial and tax law) prevent erasure.

Our website is delivered via an encrypted SSL/TLS connection (certificate from Let’s Encrypt). You can recognise an encrypted connection by the string “https://” in your browser’s address bar.

3. Hosting

This website is hosted on servers of

netcup GmbH
Daimlerstraße 25
76185 Karlsruhe
Germany

The server location is in Germany (Nuremberg). When the website is accessed, technically necessary data (see section 4) is processed.

The legal basis for using the hosting provider is our legitimate interest in the secure and efficient provision of our online offering (Art. 6(1)(f) GDPR). Where the hosting provider processes personal data on our behalf, this takes place on the basis of a data processing agreement pursuant to Art. 28 GDPR.

4. Provision of the website and server log files

Each time our website is accessed, our system (nginx) automatically collects data and information from the accessing device. The following data is stored in what are known as server log files:

This data is not merged with other sources of personal data. The processing is technically necessary in order to deliver the website and additionally serves to ensure system security and stability as well as to prevent and investigate misuse and attacks.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest follows from the aforementioned purposes. The log files are erased as soon as they are no longer required to achieve the purpose for which they were collected, as a rule after 7 days at the latest. Storage beyond this is possible where necessary to investigate a specific misuse or security incident; in this case the log data concerned is retained until the matter has been conclusively clarified.

5. Contacting us via the contact form

A contact form is available on our website through which you can get in touch with us and send us product inquiries and orders. When you use the form, we process the following data:

In addition, for security reasons, your IP address and a timestamp are recorded and stored at the time of submission. This data serves exclusively to prevent misuse and spam (among other things, to enforce a submission limit / rate limit) and is not used for any other purposes.

The data transmitted via the contact form is stored in a database (SQLite) operated on our server (server location Germany).

The legal bases for the processing are:

Providing the data marked as mandatory fields is necessary in order to process your inquiry; without this information we cannot process your inquiry.

Your data is erased as soon as it is no longer required to achieve the purpose for which it was collected. For data collected in connection with contacting us, this is the case when the respective conversation with you has ended and the matter has been conclusively clarified. If your inquiry leads to the conclusion of a contract, we retain the data relevant to the contract and its performance for as long as statutory retention obligations exist (see section 7). IP addresses and timestamps stored to prevent misuse are erased after a short period, at the latest after 60 days, unless a specific suspicion of misuse requires longer storage.

6. Handling of orders and inquiries regarding made-to-order items

If you order accessories from us or send us an inquiry or commission for an individually manufactured module or roof rack (made to order), we process the data required for this – in particular your contact, delivery and billing data as well as the details of the desired specification – for the purposes of initiating the contract, preparing an individual quote and performing the contract.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures). Where we are required by law to retain data, Art. 6(1)(c) GDPR (compliance with legal obligations) is an additional legal basis.

Your data is passed on to third parties only where this is necessary to perform the contract, for example to the shipping or freight company commissioned with delivery, in order to deliver the goods or arrange an appointment. No further transfers take place, or only on the basis of separate consent or a statutory obligation.

7. Storage period and statutory retention obligations

Unless a more specific storage period is stated in this privacy policy, personal data is erased as soon as the purpose of its processing ceases to apply. Due to requirements under commercial and tax law (in particular Section 257 HGB, Section 147 AO), however, we are obliged to retain certain documents such as invoices, accounting records and business correspondence for statutorily prescribed periods (as a rule up to ten years). For the duration of these retention obligations, the processing of the data concerned is restricted and limited to fulfilling the statutory obligations.

8. Payment processing (in preparation)

At present, orders and inquiries are placed via our contact form; an online payment process is not yet active.

We are preparing the integration of the payment service providers PayPal and Stripe (credit card payment). As soon as these payment methods are available, payment will take place by redirecting you to the respective payment service provider. The entry and processing of payment data (e.g. credit card details) takes place exclusively at the respective payment service provider; no card data is processed or stored on our servers. Only the data required for payment processing is transmitted to the payment service provider, and only in the event of an actual payment.

The providers are:

The legal basis for processing in the course of payment handling is Art. 6(1)(b) GDPR (performance of a contract). The privacy notices of the respective payment service provider apply in addition. This privacy policy will be updated accordingly when online payment is activated.

9. Cookies and reach measurement

Our publicly accessible website does not use any analytics, marketing or tracking cookies. We use no web analytics tool (such as Google Analytics), no external font services (fonts are embedded locally on our server, there is no connection to third-party servers to load fonts), no social media plugins and no other tracking technologies.

A session cookie is set exclusively when logging in to the non-public, password-protected administration area and is strictly necessary in order to provide this expressly requested, protected service; it serves solely to maintain the logged-in session. For you as a visitor to the public website, this cookie is of no relevance. The legal basis for this technically necessary cookie is Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) in conjunction with Art. 6(1)(f) GDPR.

A consent banner (cookie consent) is not required, as there is no processing subject to consent in the public area of the website.

10. Recipients and disclosure of data

Your personal data is transferred to third parties exclusively in the cases named in this privacy policy, in particular to:

Personal data is not transferred to third countries outside the European Union or the European Economic Area. The data is processed exclusively on servers in Germany.

11. Your rights as a data subject

You have the following rights against us with regard to the personal data concerning you:

To exercise your rights, an informal message to the contact details given in section 1 is sufficient.

12. Right to object

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest) (Art. 21 GDPR).

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

The objection can be made informally and should be addressed to the contact details given in section 1.

13. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR.

The supervisory authority responsible for us is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
(Independent Centre for Privacy Protection Schleswig-Holstein)
Holstenstraße 98
24103 Kiel
Germany
Telephone: +49 431 988-1200
E-mail: mail@datenschutzzentrum.de
Website: www.datenschutzzentrum.de

Notwithstanding this, you may also contact the supervisory authority of your habitual residence or place of work.

14. Obligation to provide data; automated decision-making

Where you order goods from us or send us an inquiry, you are obliged to provide the data required for processing. Without this data we cannot process your order or inquiry, or conclude a contract with you.

A decision based solely on automated processing – including profiling – within the meaning of Art. 22 GDPR does not take place.

15. Data security

We take appropriate technical and organisational measures to protect your data against loss, destruction, manipulation and unauthorised access. These include in particular encrypted data transmission via SSL/TLS as well as the operation of the server infrastructure in a data centre in Germany. Our security measures are continuously reviewed and adapted in line with technological developments.

16. Currency and amendment of this privacy policy

This privacy policy is dated July 2026. As our website and our offerings develop further, or due to changed statutory or regulatory requirements, it may become necessary to amend this privacy policy. The current version is available on this website at any time.