Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains how we collect, use, store and protect personal data when you visit https://www.flexfulfillment.eu, contact us through the website, request information about our services, or subscribe to our email communications.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection and privacy laws.
1. Who We Are
The website https://www.flexfulfillment.eu is operated by:
FLEX Logistik Deutschland GmbH
Am Knühl 2
39326 Hermsdorf, Germany
Steuernummer: 114/5817/5187
VAT ID: DE346264068
EORI: DE884155763601273
In this Privacy Policy, “FLEX.”, “FLEX. Fulfillment”, “we”, “us” or “our” refers to FLEX Logistik Deutschland GmbH.
We are the controller of the personal data processed through this website, unless this Privacy Policy states otherwise.
If you have any questions about this Privacy Policy or about how we process personal data, you can contact us through the contact form on this website or at: [email protected].
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed when you:
- visit or browse this website;
- use our contact forms or request information about our fulfillment and logistics services;
- subscribe to the FLEX. operational digest or other email communications;
- interact with our website content, forms, cookies, analytics or tracking technologies;
- communicate with us in relation to our services or a potential business relationship.
This Privacy Policy does not replace any separate data processing agreement, service agreement or contract that may apply if your company becomes a FLEX. customer, supplier or business partner.
3. Personal Data We May Collect
The categories of personal data we may collect depend on how you interact with the website. We only collect data that is relevant for the purposes described in this Privacy Policy.
3.1 Contact form and business inquiry data
When you contact us through the website, request a quote or send us a business inquiry, we may process:
- your first name and last name;
- your email address;
- your phone number;
- your company name, where provided;
- your message, inquiry details, service interests and other information you choose to send us;
- the date and time of your submission;
- the page or URL from which the form was submitted;
- technical information connected with the submission, such as IP address, browser type, device type and user agent;
- anti-spam or security verification information, where such protection is enabled on the form.
3.2 Email marketing and operational digest data
If you actively tick the operational digest checkbox in our contact form or otherwise give consent to receive email communications from us, we may process:
- your email address;
- your first name and last name, where provided;
- your phone number or company/contact details, where provided and relevant;
- your subscription status;
- the date, time and source of your consent;
- the exact consent checkbox field, value and consent text shown at the time of subscription;
- the source URL, IP address and browser user agent connected with the consent record;
- email delivery, opening, clicking, unsubscribe and preference information, where available through our email marketing provider.
The current operational digest checkbox text is: “Send me the FLEX. operational digest 1–2 times a month. No spam, we promise.”
Submitting a contact form without ticking the operational digest checkbox does not add you to our marketing mailing list. In that case, we will use your contact details only to handle your inquiry and related business communication, unless another lawful basis applies.
3.3 Website, technical and usage data
When you visit the website, we may process technical and usage data such as:
- IP address;
- browser type and version;
- device type and operating system;
- referrer URL;
- pages visited and approximate interaction with the website;
- date and time of access;
- cookie and consent preferences;
- security, error and server log data.
3.4 Comments, user accounts and media uploads
If comments, user accounts or media upload functions are enabled on the website, we may process the information submitted through those functions.
If you leave a comment, we may collect the data shown in the comment form, your IP address and browser user agent string to help detect spam.
If you upload images to the website, you should avoid uploading images that contain embedded location data, such as EXIF GPS data. Visitors to the website may be able to download and extract location data from images published on the website.
4. Purposes for Which We Process Personal Data
We may process personal data for the following purposes:
- to respond to your contact form submission, request, quote inquiry or business question;
- to discuss, prepare, provide or improve our fulfillment, logistics and related services;
- to manage potential, current or past business relationships;
- to send the FLEX. operational digest, newsletters, service updates, practical logistics insights and related content where you have consented to receive them;
- to manage email marketing subscriptions, unsubscribe requests and suppression lists;
- to keep records of consent and demonstrate compliance with data protection and marketing rules;
- to operate, secure, maintain and improve the website;
- to prevent spam, abuse, fraud, security incidents or unauthorized access;
- to analyze website performance and content effectiveness, where analytics are enabled with the required consent;
- to measure or improve advertising and communication effectiveness, where marketing tracking is enabled with the required consent;
- to comply with legal, tax, accounting, regulatory or administrative obligations;
- to establish, exercise or defend legal claims.
5. Legal Bases for Processing
Depending on the purpose, we rely on one or more of the following legal bases under Article 6 GDPR:
- Consent – Article 6(1)(a) GDPR: for email marketing subscriptions, non-essential cookies, analytics cookies, marketing tracking and similar processing where consent is required.
- Pre-contractual steps or contract performance – Article 6(1)(b) GDPR: when we process your inquiry to provide information, prepare an offer, respond to a quote request or take steps before entering into a business relationship.
- Legal obligation – Article 6(1)(c) GDPR: where processing is necessary to comply with tax, accounting, regulatory, data protection or other legal obligations.
- Legitimate interests – Article 6(1)(f) GDPR: for responding to business inquiries, managing B2B relationships, securing the website, preventing abuse, keeping basic business records, improving our services, and establishing, exercising or defending legal claims.
Where we rely on legitimate interests, we consider that our interests are not overridden by your rights, freedoms and interests. You may object to processing based on legitimate interests as described in the “Your Rights” section below.
6. Contact Forms and Business Requests
When you contact us through the website, we use the information you provide to respond to your request, prepare a quote, discuss our fulfillment and logistics services with you, or manage the follow-up of a potential or existing business relationship.
We may store the content of the message, your contact details and related technical submission data so that we can properly handle the request, avoid duplicated communication, verify what was submitted and protect the website against spam or abuse.
We do not add you to our marketing mailing list only because you submitted a contact form. Marketing emails are sent only where a valid marketing consent or another applicable lawful basis exists.
7. Email Marketing, Operational Digest and Zoho Campaigns
If you tick the operational digest checkbox in our contact form or otherwise give consent to receive marketing communications from FLEX., we may use your email address and, where provided, your name and contact details to send occasional email communications about ecommerce fulfillment, logistics operations, service updates, practical insights and related content.
The FLEX. operational digest is intended to be sent occasionally, normally around 1–2 times a month. The frequency may change if there are important service, operational or compliance updates, but we aim to avoid unnecessary or excessive email communication.
The legal basis for sending these emails is your consent under Article 6(1)(a) GDPR. You can withdraw your consent at any time by using the unsubscribe link in any email or by contacting us directly. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use Zoho Campaigns to manage email marketing subscriptions, mailing lists and email campaigns. Zoho Campaigns may process your personal data on our behalf for the purpose of managing subscriptions, storing consent-related information, sending emails, handling unsubscribes and providing email performance information.
When you subscribe to our operational digest through the website, the relevant form data may be sent to Zoho Campaigns. This may include your email address, first name, last name, phone number where provided, subscription source and related subscription metadata.
We also keep a local consent log in WordPress or another internal system. This log may include the form ID, submission ID, date and time of consent, source URL, IP address, user agent, consent field name, consent value, visible consent text and the response received from Zoho Campaigns. We keep this evidence to demonstrate that the subscription was based on an affirmative opt-in action and to protect our legitimate interests in compliance, auditability and legal defense.
Every marketing email should include an unsubscribe mechanism. If you unsubscribe, we may keep limited suppression information to make sure we do not send you further marketing emails by mistake.
8. Cookies and Similar Technologies
Our website uses cookies and similar technologies to ensure proper website functionality, remember your preferences, support security and, where you consent, help us understand how visitors use the website or measure marketing activity.
8.1 Strictly necessary cookies
Strictly necessary cookies are used to provide core website functions, save cookie preferences, support security, prevent spam, maintain sessions and enable basic website operation. These cookies are necessary for the website to work correctly and are not used for optional analytics or advertising purposes.
8.2 Analytics cookies
With your consent, we may use analytics tools such as Google Analytics or similar services to understand how visitors interact with the website. Analytics data may include pages visited, approximate session activity, browser type, device type, referrer and general usage patterns.
Analytics information helps us improve the content, structure, performance and usability of the website. You can enable or disable analytics cookies through the cookie settings available on the website, where such tools are active.
8.3 Marketing and tracking technologies
With your consent, we may use marketing or conversion tracking technologies such as Meta Pixel, LinkedIn Insight Tag, Google Tag Manager or similar tools. These tools may help us measure campaign performance, understand whether visitors interact with our content after seeing our ads, build aggregated audiences or improve the relevance of our communication.
Marketing and tracking technologies should not be activated unless the required consent has been obtained through the cookie banner or consent management mechanism used on the website.
8.4 WordPress cookies
If you leave a comment on our website, you may choose to save your name, email address and website in cookies. These cookies are for your convenience so that you do not need to enter the same details again when leaving another comment. These cookies may last for up to one year.
If you visit a login page, a temporary cookie may be created to determine whether your browser accepts cookies. This cookie contains no personal data and is deleted when you close your browser.
When you log in, several cookies may be created to save your login information and screen display preferences. Login cookies usually last for two days, while screen option cookies may last for up to one year. If you select “Remember Me”, your login may persist for two weeks. When you log out, login cookies are removed.
If you edit or publish an article, an additional cookie may be saved in your browser. This cookie contains no personal data and simply indicates the ID of the article you edited. It usually expires after one day.
9. Embedded Content From Other Websites
Pages or articles on this website may include embedded content, such as videos, images, maps, articles, social media posts or external tools. Embedded content from other websites behaves in the same way as if you had visited the external website directly.
These third-party websites may collect data about you, use cookies, embed additional third-party tracking and monitor your interaction with the embedded content, including if you have an account and are logged in to that third-party website.
Where embedded content is not strictly necessary for the operation of the website, it should be loaded in accordance with the cookie and consent settings applicable on the website.
10. Anti-Spam, Security and Abuse Prevention
We may use technical measures, security tools and anti-spam services to protect the website, forms, users and our systems against spam, abuse, unauthorized access, malicious activity or fraudulent use.
These measures may process technical information such as IP address, user agent, browser information, timestamps, form submission patterns and verification tokens. The legal basis may be our legitimate interest in keeping the website secure and preventing abuse, or our legal obligation where applicable.
11. Who We Share Your Data With
We do not sell your personal data.
We may share personal data with trusted service providers and partners where this is necessary for the purposes described in this Privacy Policy. These may include:
- website hosting providers and server infrastructure providers;
- WordPress, form, security, cookie management and website maintenance tools;
- email, mailbox and communication providers;
- Zoho Campaigns and other marketing or CRM tools used to manage subscriptions and communication;
- analytics and tag management providers, where enabled with the required consent;
- advertising and conversion measurement providers, where enabled with the required consent;
- spam detection, security and abuse prevention services;
- IT, development, legal, tax, accounting and compliance service providers;
- logistics partners, carriers, customs partners, warehouse partners, fulfillment partners or operational providers where necessary to handle a specific request or service;
- public authorities, courts, regulators or other recipients where disclosure is required by law or necessary to protect our rights.
Service providers that process personal data on our behalf should process such data only under our instructions and subject to appropriate confidentiality, security and data protection obligations.
If you request a password reset, your IP address may be included in the reset email.
12. International Transfers
Some service providers or third-party tools used by the website may process, store or access personal data outside the European Union or the European Economic Area.
Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards where required by law. These safeguards may include adequacy decisions, Standard Contractual Clauses approved by the European Commission, data processing agreements, technical and organizational security measures, or other legally recognized transfer mechanisms.
Zoho Campaigns is used for email marketing and subscription management. Depending on the configuration, Zoho group entities, infrastructure, subprocessors or support teams may process or access certain data from outside the EU/EEA. Where this occurs, appropriate safeguards should apply in accordance with applicable data protection laws.
13. How Long We Retain Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
The actual retention period depends on the type of data, the purpose of processing, legal requirements and whether we need the data to protect our rights or demonstrate compliance.
- Contact form and inquiry data: retained for the time necessary to process your request and manage the business relationship. If no business relationship follows, inquiry data may be retained for a reasonable period for follow-up, documentation and legal defense purposes.
- Business, contractual and accounting records: retained for the periods required by applicable tax, accounting, commercial and legal obligations.
- Email marketing subscription data: retained for as long as you remain subscribed or until you withdraw consent, unsubscribe or request deletion, unless we need to retain limited information for compliance, suppression or legal defense.
- Consent evidence and opt-in logs: retained for as long as necessary to demonstrate that valid consent was obtained and to handle potential complaints, audits or legal claims.
- Unsubscribe and suppression data: retained as long as necessary to ensure that we do not send further marketing emails to an unsubscribed address by mistake.
- Technical and security logs: retained for limited periods necessary for website operation, troubleshooting, security and abuse prevention, unless longer retention is required for an incident investigation or legal reason.
- Comments: if comments are enabled and you leave a comment, the comment and its metadata may be retained indefinitely so that we can recognize and approve follow-up comments automatically instead of holding them in a moderation queue.
- User accounts: for users who have an account on the website, if any, we may store the personal information provided in their user profile. Users can see, edit or delete their personal information at any time, except for their username. Website administrators can also see and edit this information.
14. Data Security
We apply reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure or destruction.
These measures may include access controls, secure authentication, limited access rights, website security tools, encrypted connections where available, backups, monitoring and internal procedures for handling data protection requests or incidents.
However, no method of transmission over the Internet or electronic storage is completely secure. We make reasonable efforts to protect personal data, but we cannot guarantee absolute security.
15. Your Rights Over Your Personal Data
Under the GDPR, you may have the following rights regarding your personal data, subject to the conditions and limitations set out in applicable law:
- the right to be informed about the processing of your personal data;
- the right of access to your personal data;
- the right to rectification of inaccurate or incomplete personal data;
- the right to erasure of your personal data;
- the right to restriction of processing;
- the right to object to processing based on legitimate interests;
- the right to object to direct marketing at any time;
- the right to data portability, where applicable;
- the right to withdraw consent at any time, where processing is based on consent;
- the right to lodge a complaint with a competent supervisory authority.
You may request an exported file containing the personal data we hold about you, including any data you have provided to us. You may also request that we erase your personal data. This does not include data we are required or permitted to keep for administrative, legal, tax, accounting, security, suppression or compliance purposes.
To exercise your rights, contact us through the contact form on the website or at: [email protected].
We may ask for additional information to verify your identity before processing your request. This helps us protect personal data against unauthorized disclosure or deletion.
16. Right to Withdraw Marketing Consent and Unsubscribe
If you have subscribed to the FLEX. operational digest or other marketing communications, you can withdraw your consent at any time.
You can unsubscribe by:
- clicking the unsubscribe link included in our marketing emails, where available;
- contacting us directly at [email protected];
- using another unsubscribe or preference mechanism made available in the relevant email.
After you unsubscribe, we may retain limited information necessary to record your unsubscribe request and make sure we do not send you further marketing emails by mistake.
17. Automated Decision-Making
We do not use personal data collected through this website to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Some tools may provide analytics, segmentation, email performance metrics or anti-spam scoring, but these are used to support website operation, communication management, security or marketing analysis rather than to make legally significant automated decisions about individuals.
18. Children’s Data
This website and our fulfillment and logistics services are intended for business users and are not directed at children. We do not knowingly collect personal data from children through this website.
If you believe that a child has provided personal data to us through the website, please contact us so that we can review and, where appropriate, delete the data.
19. Special Categories of Personal Data
We do not intentionally request or collect special categories of personal data through the website, such as health data, biometric data, political opinions, religious beliefs or similar sensitive information.
Please do not include sensitive personal data in contact forms or messages unless it is strictly necessary for your request. If you provide such information voluntarily, we will process it only where permitted by law and necessary for the relevant purpose.
20. Complaint to a Supervisory Authority
You have the right to lodge a complaint with the competent data protection supervisory authority in your EU Member State of residence, place of work or place of the alleged infringement.
For the company’s registered office in Saxony-Anhalt, Germany, the relevant supervisory authority is:
Landesbeauftragter für den Datenschutz Sachsen-Anhalt
Leiterstraße 9
39104 Magdeburg, Germany
Email: [email protected]
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our website, forms, cookies, technical tools, email marketing setup, services, legal requirements or internal processes.
The version published on this page is the currently applicable version. The “Last updated” date at the top of this Privacy Policy indicates when the latest changes were made.

