Veuillez patienter pendant le chargement des produits et des filtres.
Veuillez patienter pendant le chargement des produits et des filtres.
Legal
This notice explains which personal data is processed when you visit perkavia.com or voluntarily use saved items, preferences, alerts, email features, and partner links.
Telephone: +49 721 94059-0
Email: [email protected]
See the imprint for further company information.
For privacy questions or to exercise your rights, contact our data protection officer, Simon Schulze Sutthoff at [email protected] or write to the address above.
When you visit, the technical infrastructure processes data such as IP address, date and time, requested URL, referrer, browser and device details, response status, and security or error records. This is necessary to deliver the site, prevent abuse, investigate faults, and secure operations. The legal basis is Article 6(1)(f) GDPR.
Perkavia uses Cloudflare for DNS, content delivery, and security and an origin server operated by Perkavia. Cloudflare may process traffic and security data. See the Cloudflare Privacy Policy.
For the accountless saved area, Perkavia creates a random signed browser identifier. The essential HttpOnly cookie perkavia_radar_session contains no email address, uses SameSite=Lax, and expires after no more than 180 days. You can delete it earlier in your browser. Without it, saved items and preferences cannot reliably be connected to the same browser. Storage is necessary under section 25(2)(2) TDDDG; subsequent processing relies on Article 6(1)(b) or (f) GDPR.
The database stores only a hash of the identifier, language, market, voluntary preferences, saved items or searches, and enabled alert rules. Missing attributes are not inferred from other data.
An email address is processed only after you request cross-device access, an alert, or a summary. We then store the address and its hash, consent, language, status, preferences, and registration and confirmation times. A verification link remains valid for 30 minutes and can be used once. Marketing and alert emails are sent only after double opt-in and only while delivery is technically enabled. The legal basis is consent under Article 6(1)(a) GDPR; requested service messages may also rely on Article 6(1)(b) GDPR.
You can withdraw consent at any time for the future. A limited suppression record may remain so messages do not restart and the consent history can be demonstrated.
Perkavia may record bounded events such as searches, filters, page views, saves, alerts, feedback, and partner clicks. Public event endpoints reject direct contact and payment data. An event may be linked to the pseudonymous radar identifier, a deal, and limited metadata. We use this information to verify functionality, prevent abuse, measure 30-day periods, and improve ordering under Article 6(1)(f) GDPR.
The personal area uses voluntary preferences, saved content, and limited interaction signals. It does not make solely automated decisions with legal or similarly significant effects. Perkavia does not currently install public advertising pixels or third-party web analytics.
When you open a clearly labelled partner link, Perkavia records the selected deal, time, source channel, a random attribution identifier, and technical referrer and browser details. The destination URL may contain a pseudonymous campaign or sub-ID, but intentionally contains neither your name nor email address. This supports link delivery, attribution, settlement, and fraud prevention under Article 6(1)(f) GDPR.
The click may pass through Awin or another partner service before reaching the provider. From that point, the relevant network and destination provider process data under their own notices and may use tracking technologies. Purchasing or booking takes place only with the destination provider. See the Awin Privacy Policy.
Recipients may include providers engaged for operations, security, database, object storage, and email. The radar database currently uses Supabase, Inc. in a Frankfurt region. Supabase processes customer data on the relevant customer's instructions. See the Supabase Privacy Policy. When you click a partner link, network and destination providers also receive the data needed for redirection and attribution. We do not sell saved-list email addresses.
Some providers or their subprocessors may process data outside the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses, and supplementary safeguards. Destination providers are responsible for processing on their own sites.
We retain personal data only while required for its purpose, security, or legal evidence and retention duties. The browser identifier expires after 180 days and verification links after 30 minutes. Saved items, preferences, and active email data remain until deletion, unsubscribe, or lasting inactivity. Click, security, and settlement evidence may be needed longer for fraud prevention, attribution, and statutory limitation periods. Data that is no longer needed is deleted or anonymized.
Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or object to processing. You can withdraw consent at any time for the future. We may request proportionate verification where there are reasonable doubts about identity. You may also complain to the Baden-Württemberg data-protection authority or another competent supervisory authority.
We update this notice when features, providers, or legal requirements change. Last updated: 6 September 2026.