Cookie Policy
Version 2 of 14 August 2026, superseding version 1 of 4 August 2026, prepared for parkpalet.com and its German-language pages. Part One is drafted for publication as it stands. Part Two sets out the wording of the consent interface and the instructions addressed to the technical team, and is not intended to appear on the website in that form.
Sequence of publication, to be observed before the present text goes online: the tables in Section 4 record the container GTM-MM6PL9J as observed on 4 August 2026, and three of the entries describe defects that the GDPR and BDSG Compliance Report classifies for correction before the German launch, namely the legacy Universal Analytics property, the remote retrieval of typefaces from Google servers, and the unconditional loading of the Mapbox component. Correction comes first, publication second. Once Instructions 2, 3, and 4 of Section 14 have been executed and verified, the rows for Universal Analytics and for Google Fonts are deleted from both tables of Section 4, the Mapbox row is amended to record loading behind functional consent, the paragraphs devoted to those three items at the end of Section 4 are removed, every reference to remotely delivered typefaces in Section 3 and in the functional entry of Section 12 is struck, and the version identifier in Section 9 is advanced. What reaches visitors must describe the configuration actually in force on the day of publication, and not a configuration the operators have already resolved to abandon.
Part One: Cookie Policy for Publication
1. Responsible Entities and Point of Contact
Operation of parkpalet.com and of its German-language section is attributable to two undertakings acting jointly: Navlungo Lojistik ve Teknoloji A.Ş., with headquarters in Istanbul, Turkey, and Navlungo GmbH i. G. (in Gründung), a limited liability company in the course of formation under German law, with its registered address at Kreuzberger Ring 24, 65205 Wiesbaden, Germany. Entry in the commercial register was still outstanding before the Registergericht when the present version was issued, so no register number, no register court, and no value added tax identification number can be stated; the particulars are inserted on the day the entry is made, and the words "i. G." are then removed. No field of the present Section may be filled with a description of that position in place of the particulars themselves. Questions concerning cookies and comparable technologies may be addressed to the general mailbox info@navlungo.com, by telephone on +49 2102 7392398, or to info@parkpalet.com.
Full identification of the controllers, the essence of their arrangement under Art. 26 GDPR, the rights available to data subjects, and the safeguards applied to transfers are set out in the Privacy Policy and are not restated here. The present document addresses one subject: what is written to, or read from, the terminal equipment of a visitor, and on what legal footing.
2. Legal Framework Governing Terminal Equipment
2.1 The Consent Rule of § 25(1) TDDDG
Storing information in the terminal equipment of an end user, and gaining access to information already stored there, is lawful under § 25(1) of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG) only where the end user has consented on the basis of clear and comprehensive information, and only where the consent obtained meets the standard of Regulation (EU) 2016/679 (GDPR). Two consequences follow. Consent must be freely given, specific, informed, and unambiguous, expressed by a statement or by a clear affirmative action, as Art. 4(11) GDPR requires. Consent must further be capable of proof by the operator under Art. 7(1) GDPR, which turns the substantive rule into an evidentiary duty.
A point of terminology deserves attention: the statute formerly cited as the TTDSG was renamed TDDDG with effect from 14 May 2024 by the Digitale-Dienste-Gesetz (DDG), and references to the TTDSG, or to the repealed Telemediengesetz, no longer describe the law in force.
2.2 Bilginin Niteliğinden Bağımsız Koruma
TDDDG § 25, ziyaretçinin cihazının bütünlüğünü korur ve hükmün uygulanması, saklanan veya okunan bilginin kişisel veri sayılıp sayılmamasına bağlı değildir. Takma adlı bir cihaz tanımlayıcısı, yerel depolamaya yazılan bir sayaç veya daha önce bırakılmış bir değeri okuyan piksel gibi işlemlerin tamamı bu kurala tabidir. Bu nedenle bir teknolojinin anonim veya yalnızca teknik olarak tanımlanması, onay gerekliliğini ortadan kaldırmaz.
2.2 Protection Independent of the Nature of the Information
Section 25 TDDDG protects the integrity of the visitor's device as such, and its application does not turn on whether the information stored or retrieved qualifies as personal data. A pseudonymous device identifier, a counter written to local storage, a pixel that reads back a previously deposited string: each operation falls within the rule, whatever view is taken of identifiability. Describing a technology as anonymous or purely technical therefore does not dispense with consent.
2.3 The Two Exceptions of § 25(2) TDDDG
Consent is not required in the two situations exhaustively described in § 25(2) TDDDG. Under No. 1, storage or access is permitted where the sole purpose is to carry out the transmission of a message over a public telecommunications network. Under No. 2, the requirement falls away where storage or access is strictly necessary for the provider of a digital service to make available a service expressly requested by the end user. Narrow construction governs both limbs. Commercial audience measurement, product improvement, session replay, unsolicited personalisation, and every form of advertising fall outside them, because the visitor requests the website and not the measurement of the visit.
2.4 Interaction with the GDPR
Observance of § 25 TDDDG resolves the question of access to the device. It does not resolve what happens afterwards to personal data obtained through that access, which requires an independent legal basis under Art. 6(1) GDPR and, where data are made available outside the European Economic Area, an instrument under Chapter V of the GDPR (Arts. 44 to 49). Two legal acts are therefore involved, even though the visitor performs a single click. Withdrawal under Art. 7(3) GDPR operates on both layers at once: the tag ceases to fire, and the consent-based processing ceases for the future.
3. Categories in Use and the Legal Basis of Each
Strictly Necessary Cookies: technologies without which the requested service cannot be delivered, including load distribution, session continuity while an order is placed, retention of the language selection, and storage of the consent decision itself. Storage and access are exempt under § 25(2) No. 2 TDDDG, while the resulting processing rests on Art. 6(1)(b) GDPR for steps necessary to perform the contract or to take pre-contractual steps at the visitor's request, and on Art. 6(1)(f) GDPR for the security and integrity of the service.
Functional Cookies: technologies adding a convenience or a feature the site could operate without, such as the interactive warehouse map, remotely delivered typefaces, embedded forms, and calls to action served by an external platform. Consent under § 25(1) TDDDG is required, and the ensuing processing rests on Art. 6(1)(a) GDPR. One member of the category stands apart: remote retrieval of a typeface neither writes information to the terminal equipment nor reads information already stored there, so § 25 TDDDG is not engaged, while the disclosure of the visitor's IP address to the font provider remains a processing operation for which Art. 6(1)(a) GDPR supplies the basis. Absence of consent removes the feature; it does not impair the underlying service.
Statistical and Behavioural Analytics Cookies: technologies that count visits, reconstruct navigation paths, record sessions, generate heatmaps, and attribute traffic to sources, admissible only on consent Cookie Policy and Consent Notice, German Market Page 3 under § 25(1) TDDDG and Art. 6(1)(a) GDPR. Session replay warrants particular caution, capturing as it does mouse movement, scrolling, and form interaction, and must be accompanied by masking of input fields.
Advertising and Remarketing Cookies: technologies that identify the browser across sessions and, in most configurations, across websites, in order to measure conversions, build audiences, and address advertising on third-party platforms. Consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR is the sole admissible basis; legitimate interest under Art. 6(1)(f) GDPR cannot be invoked instead, since the reading of the device is already conditioned on consent and cross-site profiling exceeds the reasonable expectations of the visitor.
4. Tools Loaded Through Container GTM-MM6PL9J
Tags reach parkpalet.com through the Google Tag Manager container GTM-MM6PL9J. The tables below list the tools disclosed by the operators as loaded through that container, the position being stated as at 4 August 2026 and resting on the tag inventory supplied on 31 July 2026. Where a column identifies a provider group rather than a single contracting entity, the entity that contracts with the operators is recorded in the register of processing activities and in the corresponding agreement under Art. 28 GDPR.
Tool
Provider
Identifier
Purpose
Category
Google Analytics 4
Google Ireland, with onward flows to the United States
G-WJWN91RXS5
Traffic, session, and conversion measurement
Statistics
Universal Analytics (legacy)
Google Ireland, with onward flows to the United States
UA-112428939-1
Legacy measurement property, still firing, scheduled for removal
Statistics
Framer Analytics
Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
events.framer.com
Page and event counts built into the site platform
Statistics
Hotjar
Hotjar, hosting in Ireland
Site ID 1535957
Session recording and heatmaps
Behavioural analytics
Microsoft Clarity
Microsoft
Project xnrxpf143q
Session replay, click and scroll analysis
Behavioural analytics
Contentsquare
Contentsquare SAS, France
Project 901872
Analysis of navigation paths and content engagement
Behavioural analytics
Google Ads, including DoubleClick remarketing
Google Ireland, with onward flows to the United States
AW-772507048, AW-806634043, AW-10974451073, ga-audiences
Conversion measurement and remarketing audiences
Advertising
Meta (Facebook) Pixel
Meta
2468019813274025
Conversion tracking and audience building on Meta platforms
Advertising
Microsoft Advertising UET
Microsoft
ti=343028478
Conversion tracking for Bing campaigns
Advertising
LinkedIn Insight Tag
LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
Partner ID 8681777
Conversion measurement and professional audience targeting
Advertising
HubSpot
HubSpot, forms
Portal 8639679
Customer
Functional and
Tool
Provider
Identifier
Purpose
Category
served from the EU1 instance
relationship management, forms, newsletter sign-up, calls to action, and contact analytics
statistics
Mapbox
Mapbox Inc.
Warehouse map embed on the homepage
Display of the interactive warehouse map
Functional
Google Fonts
fonts.gstatic.com
Remote delivery of web typefaces
Functional
The HubSpot integration operates through the endpoints hs-scripts, hs-analytics, hs-banner, hsadspixel, track.hubspot.com, api.hubapi.com, and cta-service-cms2, with forms served from js-eu1.hsforms.net. No live chat widget, no client-side SMS provider, and no payment tag is loaded through the container; transactional messages are dispatched from the platform on the server side, and payment operations take place inside the customer panel at parkpalet.navlungo.com.
Tool
Third-country transfer
Storage duration
Google Analytics 4
Google group, data flows to the United States
_ga and _ga_<container-id>: 2 years by default, per Google documentation at https://support.google.com/analytics/answer/11397207
Universal Analytics (legacy)
Google group, data flows to the United States
______
Framer Analytics
Framer B.V. is established in the Netherlands; the provider states that personal data are transferred outside the EEA, including to the United States, so an instrument under Chapter V must be identified and recorded before publication
______
Hotjar
Hosting in Ireland, inside the EEA; provider support access to be documented
______
Microsoft Clarity
Microsoft group, transfer to the United States to be expected
______
Contentsquare
Contentsquare SAS is established in France and hosts the data of customers established in the European Union in Ireland (AWS eu-west-1); the published subprocessor list includes entities outside the EEA, so Chapter V safeguards are to be documented
______
Google Ads, including DoubleClick remarketing
Google group, data flows to the United States
______
Meta (Facebook) Pixel
Meta group, transfer to the United States to be expected
______
Microsoft Advertising UET
Microsoft group, transfer to the United States to be expected
______
LinkedIn Insight Tag
Ireland, inside the EEA, with group access from the United States to be expected
______
HubSpot
Forms from the EU1 instance; group infrastructure in the United States
__hstc and hubspotutk: 6 months. __hssc: 30 minutes. __hssrc: session, per HubSpot documentation at https://knowledge.hubspot.com/privacy-and-consent/w hat-cookies-does-hubspot-set-in-a-visitor-s-browser
Mapbox
Mapbox Inc., United States
______
Google Fonts
Google, United States
Not a cookie. The request transmits the IP address on every page load
Which instrument governs each of the flows identified above, and on what conditions it may be relied upon, is set out in Section 6 of the Privacy Policy (Datenschutzerklärung), headed Transfers to third countries.
Universal Analytics: the legacy property UA-112428939-1 continues to fire although the service has been discontinued by the provider, producing device access and data collection without any current purpose, contrary to the purpose limitation and data minimisation principles of Art. 5(1)(b) and Art. 5(1)(c) GDPR. Removal from the container is a corrective measure rather than an optional improvement, and appears among the instructions in Section 14.
Google Fonts: typefaces are at present retrieved from fonts.gstatic.com when the page is rendered, so that the visitor's IP address, together with browser and operating system information, reaches the provider before any interaction with the consent interface. Rendering is what triggers the request, so the preference expressed by the visitor has no bearing on it, and the disclosure has already occurred by the time the interface is displayed. Local hosting of the font files removes the transmission, and with it the need for any consent, which is the remedy recorded in Section 14.
Mapbox: the warehouse map embedded on the homepage connects to the provider's servers as soon as the component loads, which entails both access to the device and disclosure of the IP address. Loading must accordingly be deferred until functional consent has been registered, a static placeholder with an activation button being displayed in the interim.
5. Storage Duration of Cookies
Durations vary with function. Session cookies are discarded when the browser closes; persistent cookies remain until the expiry set by the issuing party or until the visitor deletes them; analytics identifiers are commonly renewed on each visit, which extends their effective life beyond the nominal figure.
Where the second table shows a blank underline, the duration is the one published by the respective provider, subject to the configuration applied within the container and within the provider's own console, and is to be confirmed by the technical team against the current provider documentation and inserted before publication; no figure has been entered by assumption. Two clarifications complete the point. The lifetime of a cookie is not the retention period applied by the provider to the data collected through it. Withdrawal of Cookie Policy and Consent Notice, German Market Page 6 consent stops future collection but does not by itself delete identifiers already present on the device, which is why the interface described in Part Two must also trigger their deletion.
6. Granting, Refusing, and Withdrawing Consent
Consent is obtained through the consent interface presented when the site is first opened, and by no other means. Refusal is expressed on the same layer as acceptance, through a control of equivalent prominence, and takes effect immediately: no tag outside the strictly necessary category is executed. Selective choices are available on the second layer, where each category may be enabled or disabled independently.
Withdrawal is possible at any time with effect for the future under Art. 7(3) GDPR, and the fourth sentence of that provision requires withdrawal to be as easy as the giving of consent; a permanently accessible control in the footer of every page serves that purpose. Lawfulness of processing carried out before withdrawal remains unaffected.
Browser settings call for separate treatment, the previously published policy having referred visitors to them. Configuring a browser to block or delete cookies is a legitimate self-protective step and remains open to everyone. Such settings nonetheless do not constitute a consent mechanism within the meaning of § 25(1) TDDDG: they operate after storage rather than before it, they produce no specific and informed declaration relating to identified purposes, they cannot be differentiated by category, and they generate no record capable of discharging the burden of proof under Art. 7(1) GDPR. Reliance on them in place of a consent interface is therefore not a compliant arrangement.
7. Consequences of Refusal
Refusal carries no disadvantage in the delivery of the service. Visitors who decline every optional category retain full access to the German-language pages, to the service descriptions, and to the corporate and certification information published on the site. Requesting a shipping quote, logging into an existing merchant account, placing an order, and initiating a return all remain available, since the technologies supporting those operations belong to the strictly necessary category and are exempt under § 25(2) No. 2 TDDDG.
Contact likewise does not depend on any optional technology, although the route differs. Forms embedded in the pages are delivered by an external platform and fall within the functional category, so a visitor who withholds that consent will not see them; correspondence may instead be addressed to info@parkpalet.com or to info@navlungo.com, and registered merchants may write through the panel at https://parkpalet.navlungo.com.
Loss is confined to optional features: the interactive map is replaced by a static placeholder until activated, embedded forms and calls to action are not rendered, and no measurement, session recording, or advertising identifier is created. Access is not made conditional on acceptance, prices do not vary with the choice expressed, and no cookie wall is operated, an approach consistent with Art. 7(4) GDPR, under which regard must be had to whether performance of a service is made conditional on consent that is not necessary for that service.
8. Recognised Consent Management Services under § 26 TDDDG
German law contemplates an alternative to the repeated presentation of consent interfaces. Section 26 TDDDG authorises recognised services for the management of consent, and the Einwilligungsverwaltungsverordnung (EinwV), in force since 1 April 2025, lays down the procedure by which an independent body may recognise such a service, together with the conditions it must satisfy, among them Cookie Policy and Consent Notice, German Market Page 7 user-friendly operation and neutrality towards competitors. A visitor using a recognised service could express preferences once and have them honoured by participating websites.
Recognition has so far been granted to very few providers. Use of such a service is a possibility open to the operators and to visitors, not an obligation, and no exemption from the duties described here arises so long as none is integrated. Should integration follow, the present document will be amended to identify the service concerned.
9. Status and Last Update
The present policy supersedes the cookie information previously published in translated form under Turkish Law No. 6698 (KVKK), which declared four categories and directed visitors to their browser settings. Amendments take effect upon publication; where an amendment materially alters the categories, the tools deployed, or the purposes pursued, consent will be requested afresh and the version identifier of the interface updated accordingly.
Last updated: 14 August 2026.
Part Two: Consent Notice Wording and Implementation
10. Requirements the Consent Interface Must Satisfy
Requirement 1, No Optional Tag Before Consent: the container must execute nothing beyond the strictly necessary category until an affirmative signal has been registered, since storage or access preceding consent already completes the infringement of § 25(1) TDDDG.
Requirement 2, Equal Prominence of Acceptance and Refusal: the first layer must present acceptance and refusal controls of the same size, shape, colour contrast, and position in the reading order, because a refusal made visually subordinate deprives the resulting consent of the free and unambiguous character demanded by Art. 4(11) GDPR.
Requirement 3, No Pre-selected Options: every optional toggle must be inactive when the interface opens, in line with Recital 32 GDPR, under which silence, pre-ticked boxes, or inactivity do not constitute consent.
Requirement 4, Granularity by Category on the Second Layer: functional, statistical, and advertising technologies must be capable of acceptance or refusal separately, so that consent remains specific to identified purposes instead of being bundled into one undifferentiated permission.
Requirement 5, Permanently Accessible Withdrawal: a control reopening the interface must be reachable from every page, requiring no more interactions than the granting of consent, as the fourth sentence of Art. 7(3) GDPR prescribes.
Requirement 6, Recorded Proof of Consent: each decision must be logged in a form capable of discharging the burden under Art. 7(1) GDPR, and the log retained for as long as the consent is relied upon and for the subsequent limitation period.
Requirement 7, Information Before the Decision: the first layer must state who is responsible, which categories exist, that transfers to third countries may occur, and that withdrawal is possible, with links to the full texts, as § 25(1) TDDDG requires.
11. First Layer Wording
Heading: Your choice regarding cookies and similar technologies
Body text: We use strictly necessary technologies to operate parkpalet.com, to keep your session active, and to record the choice you make here. With your consent, we also use functional, statistical, and advertising technologies, some of which involve providers that process data outside the European Economic Area. Consent is voluntary, is not a condition of using our services, and may be withdrawn at any time with effect for the future.
Primary control, accept: Accept all
Primary control, refuse: Reject all
Secondary control, granular choice: Manage settings
Link, cookie policy: Cookie Policy, https://parkpalet.com/de/______
Link, privacy policy: Privacy Policy, https://parkpalet.com/de/______
Implementation note: the two primary controls are rendered identically. The German footer currently links the privacy notice to the path /kvkk; both links above must point to the German GDPR texts before the interface goes live, and the final paths must replace the underlines.
12. Second Layer Wording
Heading: Manage your preferences by category
Introductory line: Choose which categories you allow. You can change your decision at any time through the cookie settings link in the footer.
Strictly necessary, switch fixed in the on position and not operable: required for the website to function, including session management, load distribution, and storage of your consent decision. Deactivation is not offered, because the site cannot be delivered without these technologies, and they are exempt from the consent requirement under § 25(2) No. 2 TDDDG.
Functional, switch off by default: enables additional features you may request, including the interactive warehouse map supplied by Mapbox, embedded forms and calls to action supplied by HubSpot, and externally delivered typefaces. Refusal leaves the site fully usable; the map is then shown as a static image, and you may write to us by email.
Statistics, switch off by default: allows us to count visits, identify which pages are consulted, and measure how our service pages perform, using Google Analytics 4 and the analytics function of the site platform. Results are used to improve the content and structure of the site.
Behavioural analysis, switch off by default: allows recording of individual sessions, heatmaps, and analysis of navigation paths through Hotjar, Microsoft Clarity, and Contentsquare, for the sole purpose of identifying usability defects.
Advertising and remarketing, switch off by default: allows measurement of advertising performance and the display of our advertisements to you on third-party platforms through Google Ads, the Meta Pixel, Microsoft Advertising, and the LinkedIn Insight Tag. Identifiers created for these purposes may be read across different websites.
Confirmation control: Save my choices
Alternative control of equal prominence: Reject all
Implementation note: masking of input fields has not been evidenced for Hotjar, Microsoft Clarity, or Contentsquare, and no statement to that effect may appear in the interface until the configuration has been applied in each of the three tools and the result verified on the live pages. Once verification is recorded with the tests under Instruction 6 of Section 14, the sentence "Input fields are masked" is to be appended to the behavioural analysis entry; absent that record, the sentence remains omitted.
13. Permanent Withdrawal Point in the Footer
Footer link text: Cookie settings
Accompanying sentence for the cookie policy page: You may reopen your cookie preferences at any time using the "Cookie settings" link at the bottom of every page; withdrawal takes effect immediately, stops the technologies concerned, and does not affect the lawfulness of processing carried out beforehand.
14. Instructions for the Webmaster
Instruction 1, Block Tags in Google Tag Manager Until the Consent Signal Arrives: remove the All Pages trigger from every tag in the functional, statistics, behavioural analysis, and advertising categories within container GTM-MM6PL9J, fire them exclusively on a custom event emitted by the consent platform, and add blocking triggers as a second safeguard. Verify in preview mode that a first visit without interaction produces no request to Google, Meta, Microsoft, LinkedIn, HubSpot, Hotjar, or Contentsquare endpoints.
Instruction 2, Remove Universal Analytics: delete the tag bearing UA-112428939-1 together with its trigger and associated variables, then confirm through the network inspector that no request to the legacy collection endpoint remains.
Instruction 3, Host Typefaces Locally: download the required font files, serve them from the site's own domain, remove every reference to fonts.gstatic.com and fonts.googleapis.com from the template and from the platform settings, and confirm that no request reaches Google when the page renders.
Instruction 4, Defer Mapbox Until Functional Consent Exists: replace the map component with a static image and an activation button, and initialise the Mapbox library only after the functional category has been enabled.
Instruction 5, Record Each Consent Decision: store, for every decision, the date and time with time zone, the version identifier of the interface text presented, the categories accepted and refused, the consent identifier, and the method of collection, keeping the record in a form that can be produced on request; do not store the IP address unless a documented necessity assessment supports it.
Instruction 6, Re-test After Every Change: repeat the verification described above after each container publication, each site release, and each addition of a provider, recording the outcome, so that the consent architecture remains demonstrably effective rather than configured once and forgotten.
15. Exposure in the Event of Non-compliance
Storing information in, or accessing information stored in, terminal equipment contrary to the first sentence of § 25(1) TDDDG constitutes an administrative offence under § 28(1) No. 13 TDDDG, punishable under § 28(2) TDDDG by a fine of up to EUR 300,000. Liability attaches to the operation itself, without proof of damage to any visitor.
Processing of personal data following such access is governed by the GDPR, and infringements of the conditions for consent under Arts. 6 and 7 GDPR fall within Art. 83(5) GDPR, which provides for administrative fines of up to EUR 20,000,000 or, in the case of an undertaking, up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Civil exposure completes the picture: Art. 82 GDPR confers a right to compensation for material and non-material damage suffered as a result of an infringement, and claims of that kind are pursued by individual visitors before the ordinary courts, independently of any measure taken by a supervisory authority.
