Privacy Policy
As at: 1 October 2026
This privacy policy explains how personal data is processed when you visit our website and when you contact Optic-Handel Fragstein.
1. Data controller and contact details
Optic-Handel Fragstein, owner Leszek Fragstein
Carlo-Schmid-Straße 13, 52146 Würselen, Germany
Telephone: +49 (0) 2405 409970
Email: info@optic-handel.de
If you have any questions regarding data protection or the exercise of your rights, you can contact us at any time using the contact details provided above. The supplementary Information requirements for the purchase, repair and maintenance of equipment Include the privacy policy and contact details published to date.
2. Accessing the website and hosting
Our website is hosted on a server at IONOS SE, Elgendorfer Straße 57, 56410 Montabaur. In order to deliver the pages you access, the server and its network services process connection data that is technically necessary. This includes, in particular, your IP address, the time and destination of the request, as well as the technical details transmitted by your browser, such as the browser identifier and, where applicable, the page you visited previously.
Data processing is carried out for the purpose of providing and securing the website on the basis of Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring reliable operation and preventing disruptions and unauthorised access. The provision of this technical data is necessary for accessing the website.
The application does not feature continuous logging of all page views. Technical operational and error logs may be generated in the event of malfunctions. These are used for error analysis and security purposes; once this purpose has been fulfilled, they are deleted or overwritten as part of the limited log rotation. In the event of a specifically identified security incident, the data required for this may be retained until the incident has been resolved and, where necessary, for the enforcement or defence against claims. IONOS processes data in connection with the provision of the hosting infrastructure.
3. Wishlist and local storage
When you add a device to your wishlist, we store its listing ID in your browser’s local storage under the key “ohf-saved”. This storage enables your wishlist to be retained across multiple page views. The wishlist is not stored as a personal user profile on our server.
Local access is provided for the expressly requested function in accordance with Section 25(2)(2) of the TDDDG. Insofar as personal data is processed in this context, Article 6(1)(f) of the GDPR forms the legal basis; our legitimate interest lies in providing this function. The data remains stored until you remove the entries or clear your browser’s website data. You can also use the website without a wish list.
The special offers function stores special offers created by the editor locally in their browser under ‘ohf-offers’. This data is only created via the relevant administration function and remains stored until the offers are removed or the browser data is cleared.
4. Contact details and forms
If you contact us by email, telephone or post, we will process your contact details, the content of your message and, where applicable, details of your company or device in order to deal with your enquiry. The legal basis is Article 6(1)(b) of the GDPR, insofar as this relates to a contract with you or pre-contractual measures in response to your enquiry. In the case of company contacts and other enquiries, the processing is based on Article 6(1)(f) of the GDPR; our legitimate interest is the proper handling of business correspondence.
When you submit a contact, product or service form, the contact details you enter, your message and, where applicable, the selected listings are stored on our server and displayed to authorised staff in the secure administration area for processing. Device images submitted previously remain accessible to authorised staff in the secure administration area. Form enquiries are not automatically forwarded to an email service. To limit abusive form submissions, a checksum derived from the IP address is stored temporarily together with a request counter.
Incoming emails to the domain optic-handel.de are processed via Microsoft’s Exchange Online infrastructure. In doing so, Microsoft and the subcontractors used for the service may process email addresses, message content, attachments and technical delivery information. Microsoft’s European contact is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Depending on the service, support and recipient of your message, processing may also take place outside the European Union or the European Economic Area. Microsoft describes contractual data protection safeguards for this purpose, including EU Standard Contractual Clauses, in its privacy policy for products and services. You can request information on this and on the available safeguards via our data protection contact.
Enquiries are deleted as soon as processing is complete and no further retention is required. Where correspondence relates to a contract, where statutory retention obligations apply, or where data is required to enforce or defend claims, we shall retain the relevant information for the applicable statutory period or until the purpose of retention ceases to apply. Retention based on legal obligations is grounded in Article 6(1)(c) of the GDPR. Without the information necessary for processing, we may not be able to respond to your enquiry.
5. Access to advert management
Advert management is intended for authorised editors. For user management, the user ID, role, account status, encrypted password hash and creation time are stored. Login sessions are verified using a random token; its hash value is stored in the database. The technically necessary ‘optic_admin’ cookie enables login and expires after eight hours. Upon logging out, the session is terminated and the cookie is removed.
To protect against repeated login attempts, user IDs, attempt counters and time windows are processed. A time window is scheduled for deletion after one day; the data is cleared upon the next login attempt. Expired session records are cleared upon the next successful login. Account data is stored for as long as authorisation is required and is subsequently deleted, provided there are no legal obligations or necessary evidence to the contrary.
The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in secure user and rights management. The session cookie is required for the expressly requested administrative access in accordance with Section 25(2)(2) of the TDDDG. This cookie is not set for visitors without administrative login credentials.
6. Recipients and integrated services
Access to personal data is granted only to individuals and service providers who require it for the purposes stated. This includes, in particular, authorised employees, the hosting provider and, in the case of email contact, the email service provider. Other recipients may, in individual cases, be authorities with statutory responsibility or service providers required to process a specific order. Data will only be transferred where there is a corresponding legal basis.
The website does not use any embedded analytics or marketing services. Fonts, images and videos are hosted by the website itself. Google Maps, social media platforms and other external services are merely linked to. Only when you open such a link does your browser establish a connection with the respective provider; their data processing is governed by their own privacy policies. Simply visiting our website does not result in any embedded maps or social media plugins being loaded.
7. Your rights
Subject to the relevant legal requirements, you have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). Where processing is based on your consent, you may withdraw this consent at any time with effect for the future. The lawfulness of the processing up to the point of withdrawal remains unaffected.
Right to object under Article 21 of the GDPR
You may, at any time, object to processing based on Article 6(1)(e) or (f) of the GDPR on grounds relating to your particular situation. We will then cease to process the data in question unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. You may object to processing for the purposes of direct marketing at any time without having to provide specific reasons.
You may also lodge a complaint with a data protection supervisory authority, in particular at your usual place of residence, your place of work or the place where the alleged infringement occurred. The State Commissioner for Data Protection and Freedom of Information in North Rhine-Westphalia is responsible for our registered office: Kavalleriestraße 2–4, 40213 Düsseldorf, telephone 0211 38424-0, email poststelle@ldi.nrw.de.
8. Automated decisions and changes
We do not use automated decision-making, including profiling, within the meaning of Article 22 of the GDPR on this website. Should the actual functions or services used change, we will amend this privacy policy accordingly.
