Privacy Policy
1. Controller
EKJ GmbH, Siezenheimer Straße 40, 5020 Salzburg, Austria
Email: info@canefelis.com
Phone: +43 660 7672305
2. Purposes and legal bases
We process personal data only where required to operate the website, online shop, customer accounts, subscriptions, Canefelis app and loyalty programme, where you have consented, or where we must comply with legal obligations or legitimate interests. The principal legal bases are Article 6(1)(a), (b), (c) and (f) GDPR.
3. Hosting and server logs
Hosting is provided by Oblak Host. When you access the site, IP address, date and time, requested URL, referrer, browser/device information and HTTP status may be processed in server logs for security, stability and troubleshooting based on our legitimate interest. Logs are normally deleted within 30 days unless they are needed longer to investigate a security incident.
4. Shop, orders, accounts and subscriptions
For orders and accounts we process identity, contact, billing and delivery details, order items, payment status, coupons, communications and technical evidence. This is necessary to take steps before and perform the contract. Commercial and tax records are normally retained for seven years. Account data is held until deletion, subject to statutory retention duties.
For subscriptions we additionally process the delivery interval, term, payment status and payment-provider reference. We do not receive full card details.
5. Payments
Payments are processed through Stripe, in particular Stripe Payments Europe, Ltd., Ireland. Depending on the chosen method, Klarna, Apple, Google, Amazon or the relevant bank may also receive data. Payment, transaction, device and fraud-prevention data is processed under Article 6(1)(b), (c) and (f) GDPR. International transfers are protected by recognised safeguards such as adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses.
6. Shipping and accounting
We send the contact, address and order details required for delivery and tracking to Sendcloud B.V. and the selected carrier. Invoice and accounting data is processed through sevDesk (sevDesk GmbH, Germany). The legal bases are contract performance and statutory obligations.
7. Brevo newsletter
We use Brevo (Sendinblue GmbH, Germany) for newsletters. We do not use Mailchimp. Registration uses double opt-in. We record email address, language, registration and confirmation time and technical evidence to document consent. The legal basis is Article 6(1)(a) GDPR. You may withdraw at any time through the unsubscribe link or by email. After unsubscribing, the address is blocked from further mailings; evidence of consent may be retained until relevant limitation periods expire.
8. Contact, forms, reviews and spam protection
We process information submitted in an enquiry in order to respond. Contact Form 7 is used as a local form system and forwards enquiries to our email system. We normally delete enquiries no later than twelve months after completion unless contractual or legal retention duties apply.
Akismet by Automattic Inc. may process technical and form data to detect spam, based on our legitimate interest in preventing abuse. For reviews we process name, rating, content, product reference and technical evidence. Publication is based on your consent or express request to publish.
9. Cookies, Google services and Microsoft Clarity
Complianz manages consent. Necessary cookies support the basket, login, security, language and consent status. Statistics and marketing services are activated in relevant regions only after consent.
With consent, we use Google Analytics 4 and features of Google Site Kit/Google for WooCommerce (Google Ireland Limited), as well as Microsoft Clarity (Microsoft Ireland Operations Limited). Usage, device, event and pseudonymous identifier data may be processed. The legal basis is Article 6(1)(a) GDPR. Consent can be changed or withdrawn through “Cookie Settings”. International transfers are protected by recognised safeguards.
10. Social login
If you voluntarily sign in through Google, Facebook or X, we receive profile data released by the selected provider, particularly an identifier, name and email address. Processing is necessary for the login you selected and, where required, based on consent. The provider's own privacy notice also applies.
11. Canefelis app and loyalty programme
For memberships, points, coupon catalogue, purchases and customer service we process account, point, transaction and usage data. Optional pet profiles, pet names and photos are processed only when you choose to provide them. Push notifications use Firebase Cloud Messaging by Google, which processes device and push tokens. Permission can be withdrawn in device settings.
Apple App Store and Google Play may separately process data when you use the app. Account deletion can be requested in the app, through the designated web page or by email. Order and invoice data subject to statutory retention is not deleted early, but is restricted from other use.
Analytics and crash reports in the app are switched off by default. They are activated only after you give explicit consent in the app; from that point Firebase Analytics and Firebase Crashlytics (Google Ireland Limited) process pseudonymous usage, event, device and crash data. Your name, address, email address, order data and pet profiles are never included. The legal basis is Art. 6(1)(a) GDPR. Your decision is stored on the device together with the time it was given and can be changed at any time in the app settings, with effect for the future.
For profile pictures the app accesses the camera or the photo library, and only after you have started the process yourself and chosen the source. The selected image is stored on our server and linked to the pet profile or to your account. No access beyond that takes place.
Feeding and refill reminders are scheduled locally on the device only. No data is transmitted to us or to third parties for this purpose.
12. Recipients and international transfers
Recipients are limited to processors and service providers necessary for each purpose, including hosting, payment, delivery, accounting, newsletter, analytics, login, push and IT providers, and authorities where required by law. Transfers outside the EEA rely on an adequacy decision, the EU-US Data Privacy Framework or Standard Contractual Clauses with supplementary safeguards.
13. Retention
We keep data only as long as required for its purpose, followed by statutory retention and limitation periods. Invoices and accounting records are normally retained for seven years, consent evidence until possible claims have expired, and enquiries normally for up to twelve months after completion.
14. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. Contact info@canefelis.com. You may also lodge a complaint with the Austrian Data Protection Authority.
15. Required data and automated decisions
Fields marked as required are necessary for contract, payment or delivery. Without them we cannot fulfil the order. We do not make solely automated decisions with legal or similarly significant effects. Individual payment providers may carry out their own automated fraud or eligibility checks.
16. Security and changes
We use appropriate technical and organisational measures to protect personal data. This Policy is updated when our services or legal requirements change. The version published here is the current version.
Last updated: 26 August 2026






