Privacy policy

Privacy Policy

Last updated: July 2026

§ 1 Controllers and joint controllership (Art. 26 GDPR)

This website is operated jointly by two controllers:

  • UNKO GmbH, Beckers Kull 13, 47445 Moers, Germany, represented by its management — responsible for orders, invoicing, and contract processing.
  • KEYDVO Health Solutions FZCO, Dubai CommerCity Business Cluster, Building 2, BCB2 324A, Dubai, UAE, represented by its management — responsible for website operation, marketing, and analytics.

The two controllers have concluded an agreement on joint controllership pursuant to Art. 26 GDPR. The essence of the agreement: each controller is responsible for the processing areas assigned to them (see above) and for fulfilling the information obligations in their area. You may exercise your data subject rights (see § 13) against either of the two controllers.

Central contact point for all data protection-related enquiries: info@coresatin.com.

§ 2 Data collection when visiting the website (server log files)

When you use the website purely for information purposes, we only collect the data that your browser transmits to the site server (server log files): visited page, date and time of access, amount of data transferred, source/reference (referrer), browser used, operating system used, and IP address (anonymised where applicable). Processing is based on Art. 6 (1) (f) GDPR on the basis of our legitimate interest in the stability and functionality of the website. For security reasons, this website uses SSL/TLS encryption.

§ 3 Hosting

For hosting the website and displaying the site content, we use the Shopify platform of Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Data may also be transferred to Shopify Inc., 150 Elgin St, Ottawa, ON K2P 1L4, Canada, and to Shopify servers in the USA. We have concluded a data processing agreement with the provider. An adequacy decision of the European Commission exists for data transfer to Canada; for data transfer to the USA, Shopify relies on the EU-US Data Privacy Framework and Standard Contractual Clauses.

§ 4 Types of data processed and purposes

We process in particular: inventory data (e.g. name, address), contact data (e.g. email, phone), contract and order data, payment data (via Stripe/PayPal), content data (e.g. messages), usage and meta/communication data (e.g. IP address, device information).

Legal bases:

  • Contract performance (Art. 6 (1) (b) GDPR): order processing, delivery, customer service.
  • Legal obligation (Art. 6 (1) (c) GDPR): retention of invoices (commercial/tax law, up to 10 years), VAT.
  • Legitimate interests (Art. 6 (1) (f) GDPR): web analytics, inventory management, security, fraud prevention.
  • Consent (Art. 6 (1) (a) GDPR): marketing emails, cookies requiring consent, and tracking.

§ 5 Data processing for order fulfilment

Where necessary for contract processing, we pass on personal data pursuant to Art. 6 (1) (b) GDPR to the following service providers:

  • Asset GLI Germany (Ettore Bugatti Straße 18, 51149 Cologne) — fulfilment and shipping preparation.
  • DPD and UPS — shipping. If you have expressly consented in the order process (Art. 6 (1) (a) GDPR), we pass on your email address and/or phone number for delivery notification; otherwise only name and delivery address.

§ 5a Exercising the right of withdrawal via the online withdrawal function

On our website we provide an electronic withdrawal function ("Cancel contract") through which you can withdraw from a contract concluded online. We are legally required to do so under § 356a BGB.

If you use this function, we process: your name, the information identifying the contract (order number), the email address to which we send the acknowledgement of receipt, and the date and time your withdrawal declaration was received. Your IP address is also logged to prevent misuse.

The legal basis is Art. 6(1)(c) GDPR (compliance with a legal obligation) in conjunction with § 356a BGB, and Art. 6(1)(b) GDPR (performance and reversal of the contract).

We collect only the information required to allocate your withdrawal to the correct contract (data minimisation, Art. 5(1)(c) GDPR). Stating a reason for withdrawal is voluntary and is not required for your withdrawal to be effective.

The data is stored for the duration of the statutory retention periods (§ 257 HGB, § 147 AO) and then deleted.

We use 401layers UG (haftungsbeschränkt), Hilden, Germany to technically provide the withdrawal function. We have concluded a data processing agreement with this provider pursuant to Art. 28 GDPR.

§ 6 Payment service providers

If you select a payment method in which you pay in advance (e.g. credit card), the payment data communicated as part of the order process is passed on to the respective provider for payment processing pursuant to Art. 6 (1) (b) GDPR:

  • Stripe Payments Europe Ltd. (Ireland) — card payments / Shopify Payments.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) — where activated.

Transfer only takes place to the extent necessary for payment processing.

§ 7 Newsletter and promotional email communication

We handle the dispatch of our newsletters and other promotional email communication (including abandoned cart reminders) via the Shopify platform of Shopify International Limited, Victoria Buildings, 2nd Floor, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland. Details of this processor and the associated third-country transfers are set out in § 3.

Registration takes place in the double opt-in procedure: after you enter your email address, we send you a confirmation email, and you are only added to our subscriber list once you have confirmed. The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR. We store the date and time of your consent in order to document it. You can unsubscribe at any time via the unsubscribe link contained in every email, or by sending us a message, and withdraw your consent with effect for the future.

Note: Dispatch to existing customers for similar goods may additionally be based on § 7 (3) UWG in conjunction with Art. 6 (1) (f) GDPR; you may object to such dispatch at any time.

§ 8 Cookies, web analytics, and tracking

To make our website attractive and enable certain functions, we use cookies. Strictly necessary cookies are set on the basis of Art. 6 (1) (f) GDPR or (b) GDPR. All non-strictly-necessary cookies and consent-requiring services (in particular the analytics and marketing services below) are set exclusively on the basis of your express consent pursuant to Art. 6 (1) (a) GDPR in conjunction with § 25 (1) TDDDG, which you provide via the Cookie Consent Tool displayed when the page is loaded and which you can withdraw at any time with effect for the future.

  • Google Analytics (Google Ireland Limited, Ireland) — web analytics; IP truncation; data transfer to the USA on the basis of the EU-US Data Privacy Framework.
  • Meta Pixel and Meta Conversion API (Meta Platforms Ireland Ltd., Ireland) — conversion measurement and reach analysis for advertisements on Facebook/Instagram. With consent activated, event-based data (e.g. page views, purchases) is transmitted to Meta both client-side (Pixel) and server-side (Conversion API). Data transfer to the USA on the basis of the EU-US Data Privacy Framework.
  • Apollo.io website visitor identification (Apollo.io, Inc., USA) — if consented, Apollo processes usage data (e.g. IP address, pages visited, referrer) to identify the companies from which our website is visited, for the purpose of B2B sales and distribution enquiries. Identification takes place at company level. For data transfers to the USA, the provider relies on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.

§ 8a Shopify Network Intelligence

To improve fraud detection, ad optimisation (including Shopify Audiences for targeted advertising), and personalised product recommendations, we use Shopify Network Intelligence. In this process, pseudonymised, aggregated usage and order data are shared with other Shopify merchants via the Shopify network. No directly personal data such as name, email address, or invoice data are shared.

The legal basis for the use of the fraud detection component is Art. 6 (1) (f) GDPR (legitimate interest in fraud prevention and economic operation). The legal basis for the use of the ad optimisation component is your consent pursuant to Art. 6 (1) (a) GDPR. You can object to this processing at any time via our cookie consent manager or by contacting info@coresatin.com.

§ 9 Customer account

If you open a customer account, we process the data required for this pursuant to Art. 6 (1) (b) GDPR. Deletion of your customer account is possible at any time. After deletion, your data will be deleted, provided that all contracts have been completely settled and no statutory retention periods conflict with this.

§ 10 Cosmetovigilance (reporting of incompatibility reactions)

If you report an undesirable effect or incompatibility reaction in connection with a Coresatin® product, we process the data required for this and forward the notification to our EU Responsible Person MedNet EC-REP GmbH (Borkstraße 10, 48163 Münster). To the extent that you share health-related data in this process, it is processed exclusively to handle your notification and on the basis of your express consent pursuant to Art. 9 (2) (a) GDPR and to fulfil cosmetics regulatory obligations pursuant to Art. 6 (1) (c) GDPR in conjunction with Regulation (EC) No. 1223/2009.

§ 11 Third-country transfers

Transfer of personal data to third countries (in particular the USA, UAE, Canada) only takes place on the basis of appropriate safeguards pursuant to Art. 44 ff. GDPR, in particular an adequacy decision (e.g. Canada), the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC), and with appropriate technical and organisational measures. Your data is stored largely on Shopify servers in the USA.

§ 12 Storage duration

The storage duration depends on the respective legal basis, the processing purpose, and any statutory retention periods. Orders and invoices: 10 years (§ 257 HGB, § 147 AO). Customer account: until deletion by the customer. Data based on consent (e.g. marketing): until withdrawal. Data based on legitimate interests: until exercise of an objection pursuant to Art. 21 GDPR, unless mandatory grounds worthy of protection stand against it.

§ 13 Rights of the data subject

You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), withdrawal of consent given (Art. 7 (3) GDPR), and complaint to a supervisory authority (Art. 77 GDPR).

RIGHT TO OBJECT: If we process your personal data on the basis of Art. 6 (1) (f) GDPR, you have the right to object at any time to this processing on grounds relating to your particular situation. If your data is processed for direct marketing purposes, you have the right to object at any time without giving any reason.

To exercise your rights, please contact: info@coresatin.com. We will respond to your request within the statutory period of one month (Art. 12 (3) GDPR).