Privacy Policy

(“POLICY”)

In order for you to benefit from our website at www.navlungo.com (“Navlungo”) in the most efficient way and to improve your user experience, cookies are used by Navlungo Lojistik ve Teknoloji Anonim Şirketi (“Company”). The purpose of this Policy is to provide information regarding the cookies collected by Navlungo within the services it offers (“Services”), the types of these cookies, the purposes for which they are collected, and your cookie settings. You can find detailed information about the personal data collected by Navlungo in the “Navlungo Privacy Policy and Clarification Text” published on the Navlungo website.


What is Cookie Technology?

Cookies are text files downloaded to your device (computer, mobile phone, or other mobile devices) when you visit a website. Cookies are a system widely used by websites. Since web browsers are pre-defined to accept them, they help remember information device language, settings, preferences, etc., related to your visit. This information obtained during your visit to the website is stored in information files downloaded to your device as cookies.

Cookie Types


Necessary Cookies

Definition: These cookies make it possible to provide the requested Services. Without these cookies, it is not possible to properly benefit from the requested Services. Purpose: These are cookies that must be collected for the continuity of the Services provided by NAVLUNGO through its website.


Performance Cookies

Definition: These cookies collect information about how users use the services offered, for example, which pages users visit most frequently and whether they receive error messages on these web pages. These cookies collect anonymous information about the pages visited. All information collected by these cookies is aggregated and therefore anonymous. It is used solely to improve the performance of services. Web analytics that use cookies to collect data to improve the performance of a website fall into this category. For example, they may be used to test designs and ensure a consistent look and feel for the user. This category does not include cookies used for behavioral/targeted advertising networks. Purpose: We use performance cookies to analyze how NAVLUNGO Services are accessed, how they are used, or how they perform. We use this information to maintain, develop, and continuously improve NAVLUNGO Services. We may also obtain information from email newsletters or other communications we send to you, including whether you opened an email newsletter, forwarded it to anyone else, or clicked on any of its content. This information lets us know how effective our newsletters are and ensures we are providing information that interests you.


Functionality Cookies

Definition: These cookies allow the website to remember the choices you make (such as your username, language, or region) and offer enhanced, more personal features. These cookies may also be used to remember changes you make to text size, fonts, and other parts of web pages that you can customize. The information collected by these cookies can be anonymized and cannot track your browsing activities on other websites. These cookies remember choices you make to improve your experience. If the same cookie is used for retargeting, it can also be included in the "targeting or advertising cookies" category. Purpose: These cookies allow NAVLUNGO to personalize its Services according to your preferences. For example, when you continue to use NAVLUNGO Services, we can remember information such as username and address based on the information we obtain, and we can present pages you previously viewed and/or stayed on for a long time or visited frequently to your attention.


Targeting or Advertising Cookies

Definition: These cookies are used to deliver advertisements that are relevant to you and your interests. They are also used to limit the number of times you see an advertisement as well as to help measure the effectiveness of advertising campaigns. They are placed by advertising networks with the permission of the website operator. These cookies remember that you have visited a website and this information is shared with other organizations, such as advertisers. Targeting or advertising cookies are often linked to site functionality provided by other organizations. These cookies collect information about your browsing habits to make advertisements relevant to you and your interests. Purpose: We use these cookies to deliver interest-based advertisements while you receive NAVLUNGO Services. This information may also be used to record the number of times a particular advertisement has been shown to you, to avoid showing you the same advertisements repeatedly, and to help us measure how effective these advertisements are.


We also work with website publishers, application developers, ad networks, and service providers to deliver ads promoting NAVLUNGO on other websites and Services. Cookies may be used to show you advertisements on other websites, apps, and devices that may be relevant to you and your interests, to customize the advertisements you receive, and to measure how effective they are.


Additionally, we may allow NAVLUNGO business partners to use cookies within or outside NAVLUNGO’s Services, over time and across different websites, applications, and/or devices, to collect information about your online activities, for the same purposes defined above.


Managing Cookies

If you do not want cookies to be stored on your device, you can always withdraw your consent regarding cookies and delete cookies. You can change your cookie settings through your web browser's settings section to block the collection of cookies or to delete collected cookies.


If you delete your cookies, your preferences within the website will also be deleted. In addition, if you block the collection of cookies, you will not be able to benefit from [*] of the Services provided by NAVLUNGO. In this context, we recommend that you allow the use of cookies in order to benefit from the Services.


Amendments to the Policy

NAVLUNGO reserves the right to unilaterally make amendments to the Policy. Significant changes made to the Policy will be notified to you through one or more methods such as email or in-website pop-up notifications.


Contact Information

Navlungo Lojistik ve Teknoloji Anonim Şirketi Sanayi Mah. Teknopark Bulvarı Teknopark 4A Apt. No: 1/4A/101 Pendik/ Istanbul Email: info@navlungo.com

Fields to be completed: every blank underscore field must be filled in before the notice goes live. Outstanding are the registered office of the Turkish company, the register court, the HRB number, and the VAT identification number. The storage periods in Section 7 are the periods recommended for the German operation; they differ from the flat ten-year period currently applied under Turkish law and must be confirmed and technically implemented before the notice is published. Three further items await completion: the date of the joint controller arrangement, the date on which the Standard Contractual Clauses are concluded, and the web address of the Cookie Policy. Identity of the payment service provider operating inside the merchant panel, together with its role under data protection law and the data it receives, must likewise be inserted.

Version note, to be removed before publication: the present text is version 2, issued on 14 August 2026, and it supersedes version 1 of 4 August 2026. Incorporated are the revisions requested on 11 August 2026 and the particulars supplied on 13 August 2026, namely the general contact address, the telephone number of the German operation, and the position of the certifications previously held under ISO/IEC 27001, ISO 9001, and ISO 45001.

Version note, to be removed before publication: the present text is version 2, issued on 14 August 2026, and it supersedes version 1 of 4 August 2026. Incorporated are the revisions requested on 11 August 2026 and the particulars supplied on 13 August 2026, namely the general contact address, the telephone number of the German operation, and the position of the certifications previously held under ISO/IEC 27001, ISO 9001, and ISO 45001.

Last updated: 14 August 2026

The present notice describes how personal data are collected, used, disclosed, stored, and erased in connection with the ParkPalet logistics platform, the websites https://navlungo.com and https://parkpalet.com including the German pages published at https://parkpalet.com/de/, the merchant panel accessible at https://parkpalet.navlungo.com, and the support channels operated alongside them. Information is given in fulfilment of Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter the GDPR) and, where German law supplements or specifies those duties, of the Bundesdatenschutzgesetz (BDSG) of 30 June 2017.

The present notice describes how personal data are collected, used, disclosed, stored, and erased in connection with the ParkPalet logistics platform, the websites https://navlungo.com and https://parkpalet.com including the German pages published at https://parkpalet.com/de/, the merchant panel accessible at https://parkpalet.navlungo.com, and the support channels operated alongside them. Information is given in fulfilment of Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter the GDPR) and, where German law supplements or specifies those duties, of the Bundesdatenschutzgesetz (BDSG) of 30 June 2017.

1. Controllers

1.1 Identity and contact details

Responsibility for the processing operations described in Section 4 is shared by two companies of the Navlungo group, which decide together on the purposes and on the essential means of those operations.

  • Navlungo Lojistik ve Teknoloji A.Ş.: a joint stock company incorporated under the laws of Turkey, registered office at _______________________________________, Istanbul, Turkey, operator of the ParkPalet brand, of the platform, and of the technical infrastructure supporting it, contactable at info@navlungo.com.


  • Navlungo GmbH i. G. (in Gründung): a limited liability company in the course of formation under German law, registered office at Kreuzberger Ring 24, 65205 Wiesbaden, Germany, to be entered in the commercial register kept by the Local Court (Amtsgericht) of ______ under HRB ______, VAT identification number DE ______, contactable at info@parkpalet.com and on +49 2102 7392398. On the day the register entry is made, the particulars are inserted and the words "i. G." are removed.

Incorporation of Navlungo GmbH was still pending before the Registergericht when the present version was issued; the register and tax identifiers will be inserted as soon as the entry has been made. Fulfilment operations for the German market are carried out from the warehouse located at Dornierstr. 16, 89231 Neu-Ulm, Germany.

1.2 Essence of the joint controller arrangement

Both companies act as joint controllers within the meaning of Article 26(1) GDPR. Under the arrangement concluded on ____________________, the respective responsibilities have been allocated as follows, the essence of that allocation being reproduced here as Article 26(2) GDPR requires.

  • Purposes and means: the two companies determine jointly which processing operations run on the platform, which data fields are collected at registration, at quotation, and at dispatch, and which service providers are engaged.

  • Transparency duties: the master version of the present notice is maintained by Navlungo Lojistik ve Teknoloji A.Ş., while publication, translation, and updating on the German pages fall to Navlungo GmbH.

  • Requests from data subjects: Navlungo GmbH receives and coordinates requests originating in the European Economic Area, obtains from the Turkish company the information held on its systems, and documents the outcome.

  • Security and personal data breaches: the measures required by Article 32 GDPR are implemented centrally by Navlungo Lojistik ve Teknoloji A.Ş.; assessment of incidents and, where applicable, notification under Articles 33 and 34 GDPR are handled jointly, with correspondence towards the German supervisory authority conducted by Navlungo GmbH.

  • Records: each company keeps its own record of processing activities under Article 30 GDPR and assists the other in dealings with supervisory authorities.

Regardless of the internal allocation set out above, Article 26(3) GDPR entitles you to exercise your rights under the Regulation in respect of and against each of the two controllers. A request addressed to either company is therefore effective, whichever of them holds the data concerned.

2. Data protection contact point

No data protection officer has been designated under Articles 37 to 39 GDPR or under § 38 BDSG. Enquiries concerning the processing of personal data, requests under Articles 15 to 22 GDPR, and reports of suspected incidents are handled by the following contact point.

  • Data protection contact point: enquiries, requests, and reports are addressed to the general mailbox info@navlungo.com, monitored by the persons responsible for data protection within the two companies, by telephone on +49 2102 7392398, or by post at the address of Navlungo GmbH given in Section 1.1. Correspondence may be conducted in German or in English.

Should a data protection officer be designated at a later stage, the name and contact details of that person will be published in the present Section.

3. Scope of the notice and categories of data subjects

Coverage extends to the corporate and public-facing websites, to the merchant panel, to the order and warehouse management system used internally, and to the correspondence channels listed in Section 4.8. Where a link leads to a website operated by a third party, such as a marketplace, a carrier tracking page, or a social network, the operator of that site processes personal data under its own responsibility and its own privacy information.

Four groups of persons are concerned by the processing described below.

  • Merchants and business users: sellers, shippers, and their authorised representatives, employees, or contact persons who register an account and use the platform for fulfilment and dispatch.

  • Recipients of consignments: buyers and other addressees whose parcels are prepared, dispatched, delivered, or returned through the network.

  • Website visitors: persons who consult the public pages, request a shipping quotation, or subscribe to newsletters and other electronic communications.

  • Persons contacting support: individuals who submit a request through the contact form, by electronic mail, through the merchant panel, or through the social channels operated under the ParkPalet and Navlungo names.

4. Processing operations, purposes, legal bases, and recipients

Every operation below is described with its purpose, the categories of data involved, the legal basis under Article 6(1) GDPR, and the recipients. Storage periods are gathered in Section 7, which sets out the statutory framework governing retention, while Section 5 identifies the recipients in detail.

4.1 Registration and administration of merchant accounts

Opening an account requires the company legal (trade) name, trade registry details, the tax or VAT identification number, the business address, and the contact details of the authorised representative, namely name, business electronic mail address, and telephone number. Credentials, permissions granted to individual users, and a log of account activity are added during use. Registration data are collected through the platform operated by Navlungo Lojistik ve Teknoloji A.Ş. and serve the conclusion and the performance of the platform contract, authentication, and the allocation of shipments and inventory to the correct account. Where the merchant is a natural person or a sole trader, the legal basis is Article 6(1)(b) GDPR. Where the merchant is a legal person, the data of its representatives are processed on the basis of Article 6(1)(f) GDPR, the legitimate interest pursued being the administration of the contractual relationship through an identified point of contact. Access is confined to the support and operations teams described in Section 6 and to the hosting provider acting as processor.

4.2 Billing and invoicing

Invoices issued by the two controllers for platform fees, carriage charges, and fulfilment services contain the name and trade title, the tax number, the billing address, the telephone number, the electronic mail address, the services rendered, and the amounts due. Two legal bases operate in parallel: Article 6(1)(b) GDPR, since invoicing forms part of the performance of the contract, and Article 6(1)(c) GDPR, because the orderly keeping of accounting documents is imposed by § 147 of the Abgabenordnung (AO) and by § 257 of the Handelsgesetzbuch (HGB). Accounting data reach the tax authorities where a statutory duty so requires, as well as tax advisers and auditors bound by professional secrecy, and retention follows the statutory scale reproduced in Section 7.

4.3 Order and return data of recipients

Data concerning addressees reach the platform from the merchant or through the marketplace integrations described in Section 4.7, and comprise the name and surname, the electronic mail address, the telephone number, the delivery (receiver) address, the order reference, the contents declared for the parcel, and the status of any return. Purposes are the preparation of the consignment in the warehouse, the handover to the carrier, the notification of dispatch and delivery, and the settlement of returns and refunds. Where the addressee is party to the transport relationship, processing rests on Article 6(1)(b) GDPR; in the remaining cases the basis is Article 6(1)(f) GDPR, the legitimate interest consisting in the correct execution of an order placed with the merchant. Recipients are the carriers named in Section 5.1, the warehouse teams, and, for cross-border consignments, the customs authorities.

4.4 Generation of shipping quotations

Quotations are calculated from item details supplied by the merchant: item name, category, declared price, weight, and the carrier selected, all of them linked to the merchant account and to the destination address. Article 6(1)(b) GDPR applies, the calculation being a step taken at the request of the data subject prior to entering into a contract of carriage. Quotations that do not result in a shipment are erased twelve months after they are generated; accepted quotations are stored with the corresponding shipment record. Beyond the hosting provider, no third party receives data at the quotation stage.

4.5 Execution of the shipment and delivery by carriers

Dispatch requires the transmission to the selected carrier of the recipient's name, delivery address, telephone number, and electronic mail address for delivery notifications, together with the parcel reference, weight, and, for cross-border movements, the customs data relating to the goods. Transmission rests on Article 6(1)(b) GDPR where the addressee is party to the transport relationship, and on Article 6(1)(f) GDPR in the remaining cases, the legitimate interest being the delivery of an order placed with the merchant. As regards customs and export formalities, disclosure of consignment data to the competent authorities is required by Regulation (EU) No 952/2013 laying down the Union Customs Code and by the national provisions applicable to the movement concerned, so that Article 6(1)(c) GDPR applies. Carriers decide independently how the delivery data are used within their own networks, as explained in Section 5.1, and shipment records remain stored for the periods listed in Section 7.

4.6 Documents uploaded in support of returns and claims

Recipients and merchants may upload supporting material when a return is initiated or a claim raised, in particular photographs of damaged goods and of the packaging, delivery notes, proof of purchase, and written descriptions of the defect. Examination of that material serves the assessment of the claim, the decision on the refund or the replacement, and the recourse against the carrier responsible for the damage. The legal basis is Article 6(1)(b) GDPR where the assessment forms part of the contractual return process, and Article 6(1)(f) GDPR where the file is retained for the establishment, exercise, or defence of legal claims. Uploaded files may be disclosed to the carrier concerned and, if litigation arises, to legal advisers and to the competent court. Users are asked not to include in such uploads any information falling within Article 9(1) GDPR, since no category listed there is required for the evaluation; material of that kind, if incidentally visible, is removed. Claim files are stored for the period indicated in Section 7.

4.7 Marketplace and store integrations

Merchants may connect their own sales channels, among them Amazon, eBay, and Shopify, so that orders, shipping addresses, and return requests flow into the order and warehouse management system without manual entry. Authorisation is granted by the merchant through the interface of the marketplace concerned, and the data transmitted are limited to the order identifier, the addressee details, the article data, and the return status. Article 6(1)(b) GDPR governs the operation as an element of the service owed to the merchant, while Article 6(1)(f) GDPR covers the maintenance and monitoring of the interface itself, the legitimate interest being the reliability of automated order intake. Operators of marketplaces remain controllers for the data they hold in their own systems.

4.8 Customer support

Support requests arrive through the contact form on the website, through the electronic mail addresses info@parkpalet.com and info@navlungo.com, through the ticket function of the merchant panel, and through the social channels operated on X, Facebook, and Instagram. Handling a request involves the identity and contact details of the sender, the shipment or account reference, the content of the message and of any attachment, and the internal notes recorded during the resolution. Where the request relates to an existing contract, Article 6(1)(b) GDPR applies; for general enquiries, including those from prospective merchants, the basis is Article 6(1)(f) GDPR, the legitimate interest being the answering of questions addressed to the business. Tickets sit in the customer relationship management system operated by a processor, while messages sent through social channels also pass through the systems of the platform operators, who act as controllers in their own right. Retention follows Section 7.

4.9 Marketing communications

Campaign, promotional, and newsletter messages are sent by electronic mail and by SMS solely to persons who have given a separate, express, and freely revocable consent at registration or through a subscription form, distinct from the acceptance of the service terms. Consent is the legal basis under Article 6(1)(a) GDPR, and the requirement of prior express agreement for advertising by electronic mail follows from § 7(2) No. 2 of the Gesetz gegen den unlauteren Wettbewerb (UWG). Data processed for that purpose are the electronic mail address or mobile number, the name, and the record of the consent given, including its date and the form used. Withdrawal is possible at any time under Article 7(3) GDPR through the unsubscribe link contained in every message or by writing to the contact point named in Section 2, and takes effect for the future without affecting the lawfulness of the messages already sent. Dispatch and reading statistics are generated within the customer relationship platform acting as processor.

4.10 Platform security and technical logs

Operation of the platform generates log entries containing the IP address, the date and time of the request, the resource requested, the response status, the browser and operating system identifiers, and, for authenticated sessions, the account concerned. Administrative access by the technical team, connections over the corporate virtual private network, and changes made to production systems are recorded separately. Purposes are the detection of malfunctions, the investigation of unauthorised access attempts, the prevention of abuse and fraud, and the ability to reconstruct who accessed which record. Article 6(1)(f) GDPR provides the legal basis, the legitimate interest lying in the availability, integrity, and confidentiality of the platform, which Article 32 GDPR also requires the controllers to safeguard. Access to log data is confined to the technical staff responsible for security, and deletion follows the short periods stated in Section 7.

4.11 Cookies, measurement, and advertising

Storage of information on your terminal equipment, and access to information already stored there, occur only with your consent under § 25(1) of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG), save for the narrow cases in which such storage or access is strictly necessary to provide the digital service you have expressly requested, which § 25(2) TDDDG exempts from the consent requirement. Subsequent processing of the data obtained through analytics, session analysis, and advertising technologies rests on Article 6(1)(a) GDPR, and processing associated with strictly necessary techniques on Article 6(1)(f) GDPR. Details of the individual technologies, of their providers, of the storage duration of each cookie, and of the means by which consent may be given, refused, or withdrawn are set out in the separate Cookie Policy published at ____________________________________, which forms part of the information provided here and is not reproduced.

5. Recipients of personal data

Disclosure occurs only where a legal basis permits it and, in the case of processors, only under a contract meeting the requirements of Article 28(3) GDPR.

5.1 Carriers acting as independent controllers

DHL, DPD, GLS, Hermes, and UPS receive the delivery data described in Section 4.5 and use them under their own responsibility: routing of the parcel, documentation of delivery attempts, storage of proof of delivery, and the duration of their own records are matters each of them decides, subject to the statutory duties applicable in the postal and transport sector. Each carrier is therefore an independent controller and not a processor, and the information duties concerning the delivery data it holds are met through its own privacy notice, published on its website.

Reference to the carrier's own notice concerns a distinct stage of the journey of the data and does not displace our responsibility for the stage that precedes it. Up to the moment of handover, the delivery data are processed by the two controllers named in Section 1.1, who answer for their collection, their accuracy, their security, and their erasure, and against whom the rights described in Section 8 may be exercised in full. From the handover onwards, the carrier pursues purposes of its own, among them the organisation of its transport network, the proof of delivery it retains under the rules governing the postal and transport sector, the handling of complaints addressed to it directly, and the prevention of fraud inside its own operation. Purposes decided by the carrier cannot lawfully be described by us, and the retention applied inside its systems can be neither shortened nor extended on our instruction, which is the reason the Regulation attributes the corresponding information duty to the carrier rather than to us.

Practical consequences for you are limited and precise. A request concerning the data held on our platform, the address supplied to the carrier and the record of the consignment included, is handled by us under Section 8, and consulting a carrier's website is not required for that purpose. A request concerning what the carrier itself recorded, such as the identity of the person who accepted the parcel or the period for which proof of delivery is kept, is answered by the carrier, and on request we identify the carrier that handled the consignment and supply the address of its notice, so that the request reaches the right addressee without loss of time. A complaint may in either case be brought before the supervisory authority named in Section 8.4. Delivery data are transmitted for the purpose of carriage alone; use of those data by a carrier for advertising of its own would require a legal basis established by that carrier, and no such use is instructed, authorised, or remunerated by us.

5.2 Service providers acting as processors

Providers engaged to perform technical or administrative tasks act exclusively on documented instructions, are bound to confidentiality, must apply appropriate security measures, and may not engage a further processor without prior authorisation.

  • Hosting and storage: application data, files, and backend infrastructure run on Amazon Web Services in the eu-west-1 region (Ireland), so that the primary storage location lies within the European Economic Area.

  • Website platform: the public marketing pages are built and served on the Framer platform, which processes the technical data generated when a page is called up.

  • Customer relationship management and communications: HubSpot supports the contact forms, the ticket history, the newsletter dispatch, and the associated statistics, with forms served from the European instance of that provider.

  • Measurement and session analysis: the providers activated once consent has been obtained are identified individually in the Cookie Policy, together with their role and the data they receive.

5.3 Authorities, advisers, and payment institutions

  • Customs and tax authorities: consignment and accounting data are disclosed where a duty to do so arises under customs legislation, under § 147 AO, or under an enforceable order, the legal basis being Article 6(1)(c) GDPR.

  • Courts, law enforcement, and supervisory bodies: data are transmitted where a statutory obligation, a court order, or the defence of legal claims so requires, on the basis of Article 6(1)(c) or Article 6(1)(f) GDPR.

  • Professional advisers: lawyers, tax advisers, and auditors receive the data necessary for their mandate and are bound by professional secrecy, the legal basis being Article 6(1)(f) GDPR.

  • Payment institutions: payments are processed inside the merchant panel at https://parkpalet.navlungo.com. The identity of the payment service provider, its role under the Regulation, and the corresponding transfer position are to be completed before publication: 

6. Transfers to third countries

Support, incident resolution, and platform maintenance are provided centrally from Turkey. Personnel of Navlungo Lojistik ve Teknoloji A.Ş. belonging to the customer support and solution centre, to operations and warehouse management, and to the technical team access account, shipment, ticket, and log data stored on the European infrastructure, strictly on a need-to-know basis, which constitutes a transfer within the meaning of Chapter V GDPR.

  • Absence of an adequacy decision: the European Commission has not adopted a decision under Article 45 GDPR in respect of Turkey, so the transfer cannot rely on a finding of adequate protection.

  • Safeguards relied on: the transfer is to be governed by Module One, controller to controller, of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, to be concluded between the two controllers on ____________________, in accordance with Article 46(2)(c) GDPR, and accompanied by an assessment of the legal framework of the country of destination following the judgment of the Court of Justice of the European Union of 16 July 2020 in Case C-311/18.

  • Limit on the instrument: Recital 7 of Commission Implementing Decision (EU) 2021/914 confines the use of those clauses to processing by the importer that is not itself subject to Regulation (EU) 2016/679. To the extent that the processing carried out by Navlungo Lojistik ve Teknoloji A.Ş. falls within the Regulation through its German operation, an alternative safeguard under Article 46 GDPR is documented in the transfer file, and the position is reassessed when the Commission adopts the additional set of clauses for importers already subject to the Regulation.

  • Supplementary measures: access runs only over the corporate virtual private network, connections to production systems from outside the controlled network are blocked, export, local download, copying, and offline storage of customer data are prohibited, permissions are role-based and logged so that activity remains auditable, and personnel are bound by written confidentiality undertakings.

Certain processors are established in the United States or belong to groups whose parent companies are established there. Transfers to such recipients rest on the adequacy decision adopted by the European Commission on 10 July 2023 concerning the EU-U.S. Data Privacy Framework, provided that the recipient is an active participant when the transfer takes place, a point verified in the official list published at https://www.dataprivacyframework.gov; failing participation, the Standard Contractual Clauses referred to above apply instead.

A copy of the safeguards adopted under Article 46 GDPR may be obtained on request, as Articles 13(1)(f) and 14(1)(f) GDPR provide, by writing to info@navlungo.com; commercially confidential terms unrelated to data protection may be redacted before the copy is released.

7. Storage periods

Personal data are erased once the purpose for which they were collected has ceased, unless a statutory retention duty requires the contrary. German commercial and tax law fixes the periods by reference to the type of document rather than to the customer record as a whole, and every period starts to run at the end of the calendar year in which the document was created.

Category

Storage period

Criterion or statutory basis

Commercial books, annual accounts, inventories

10 years

§ 257 HGB, § 147 AO

Invoices and other accounting vouchers

8 years

§ 257 HGB, § 147 AO, as shortened with effect from 1 January 2025

Shipment records with accounting or customs relevance

8 years

§ 257 HGB, § 147 AO

Operational tracking events and scans without accounting relevance

12 months from delivery, extended until final resolution where a claim remains open

Art. 5(1)(e) GDPR, § 195 BGB

Commercial correspondence with merchants

6 years

§ 257 HGB, § 147 AO

Merchant account and profile data

Duration of the relationship, then 3 years from the end of the calendar year in which it ended

§ 195 and § 199(1) BGB

Quotation records not converted into a shipment

12 months

No further contractual purpose

Uploaded documents and claim files

12 months from closure of the claim, extended to 3 years from final resolution where a claim is asserted

Art. 5(1)(c) and 5(1)(e) GDPR, § 195 BGB

Support requests and ticket history

24 months after closure of the request; 3 years from the end of the calendar year where the request is linked to a claim

Traceability of the service provided

Records of marketing consent and withdrawal

Duration of the consent, then 3 years from the end of the calendar year in which it was withdrawn or last used

Evidence under Articles 5(2) and 7(1) GDPR

Telephone advertising consents

5 years from the grant of consent and from each use

§ 7a UWG

Analytics and session recording data

14 months, and immediately on withdrawal of consent

Art. 5(1)(e) GDPR, § 25(1) TDDDG

Advertising identifiers and conversion data

13 months, and immediately on withdrawal of consent

Art. 5(1)(e) GDPR, § 25(1) TDDDG

Web server and application logs

30 days

Security monitoring

Authentication and administrative access logs

90 days

Auditability of privileged access

Periods are extended where legal proceedings, an audit, or an administrative investigation are pending and the data are needed for that purpose. Where a request for erasure concerns data covered by a statutory retention duty, the records are not deleted but blocked from operational use. Refusal of erasure follows from Article 17(3)(b) GDPR read with the retention duties in § 257 HGB and § 147 AO, and the block is applied as an organisational measure giving effect to Articles 5(1)(b) and 5(1)(e) GDPR. Blocked records are excluded from search, reporting, support access, marketing selection, and analytics, and remain accessible only to the finance function for the purpose that justifies their retention.

8. Your rights

8.1 Rights conferred by the Regulation

  • Access, Article 15 GDPR: you may obtain confirmation whether data concerning you are processed and, if so, a copy of those data with the information listed in that provision.

  • Rectification, Article 16 GDPR: inaccurate data must be corrected without undue delay, and incomplete data completed by means of a supplementary statement.

  • Erasure, Article 17 GDPR: deletion may be requested on the grounds listed in that Article, subject to the exceptions set out in Section 7.

  • Restriction, Article 18 GDPR: processing may be limited to mere storage while accuracy is contested or while an objection is examined.

  • Portability, Article 20 GDPR: data you provided, processed by automated means on the basis of consent or of a contract, may be received in a structured, commonly used, and machine-readable format, or transmitted directly to another controller where technically feasible.

  • Objection, Article 21 GDPR: processing based on legitimate interests, and processing for direct marketing, may be objected to as described in Section 8.3.

  • Withdrawal of consent, Article 7(3) GDPR: consent may be withdrawn at any time with effect for the future, the lawfulness of earlier processing remaining unaffected.

  • Automated decisions, Article 22 GDPR: decisions producing legal effects may not be taken solely by automated means, subject to the position described in Section 9.

8.2 How to exercise your rights

Requests may be submitted informally, by electronic mail to info@navlungo.com or info@parkpalet.com, or by post to the address of either controller stated in Section 1.1. Where reasonable doubts exist as to the identity of the applicant, additional information may be sought under Article 12(6) GDPR. A reply follows without undue delay and in any event within one month of receipt, as Article 12(3) GDPR requires; the period may be extended by two further months where the request is complex or where several requests have been submitted, in which case you are informed of the extension and of its reasons within the first month. No fee is charged, in accordance with Article 12(5) GDPR, unless a request is manifestly unfounded or excessive, in particular because of its repetitive character.

8.3 Right to object

Right to object, Article 21 GDPR, presented separately as Article 21(4) GDPR requires: you have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is carried out on the basis of Article 6(1)(f) GDPR, including profiling based on that provision; following such an objection the data concerned will no longer be processed unless compelling legitimate grounds are demonstrated which override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defence of legal claims. Where personal data are processed for direct marketing purposes, you have the right to object at any time and without stating reasons, and the data will thereafter no longer be processed for those purposes. An objection is subject to no formal requirement and may be addressed to info@navlungo.com or to the postal address given in Section 1.1.

8.4 Complaint to a supervisory authority

Article 77 GDPR grants every data subject the right to lodge a complaint with a supervisory authority, in particular in the Member State of habitual residence, of place of work, or of the place of the alleged infringement. Competence for the registered seat in Wiesbaden lies with the Hessian authority.

  • Bayerisches Landesamt für Datenschutzaufsicht: Promenade 18, 91522 Ansbach, Germany; telephone +49 981 180093-0; electronic mail poststelle@lda.bayern.de; website https://www.lda.bayern.de, competent for the private sector in Bavaria and therefore for processing connected with the warehouse in Neu-Ulm.

Recourse to a supervisory authority leaves untouched any judicial remedy, including the right to compensation under Article 82 GDPR.

9. Automated decision-making and profiling

Decisions producing legal effects concerning you, or similarly significantly affecting you, are not taken on the basis of automated processing alone within the meaning of Article 22(1) GDPR. Two operations deserve a word of clarification. First, on stores based on Shopify the refund is released automatically once the return workflow has been completed and the returned item booked in at the warehouse; the step executes a decision already taken by the merchant under its own return conditions and involves no evaluation of personal aspects relating to the buyer. Second, the ranking of shipping options shown after a quotation reflects price, weight, destination, and transit time, with the final selection made by the merchant.

Profiling within the meaning of Article 4(4) GDPR occurs solely in the context of the measurement and advertising technologies described in the Cookie Policy, and only where consent has been given; the resulting analyses serve the evaluation of campaigns and the composition of advertising audiences, produce no legal effects, and do not restrict access to the service. Withdrawal of consent brings the associated profiling to an end.

10. Security of processing

Technical and organisational measures appropriate to the risk are maintained under Article 32 GDPR and reviewed periodically. Without disclosing details that would themselves create a vulnerability, the following may be stated: production data are hosted within the European Economic Area; access rights are assigned by role on a need-to-know basis, granted only over the corporate virtual private network, and logged so that activity remains auditable; export, download, and offline storage of customer data outside the controlled environment are prohibited; each customer account is logically separated from every other; personnel are trained, bound by confidentiality undertakings, and act under documented security procedures. Absolute security in the transmission of data over the internet can be guaranteed by no provider, and a residual risk therefore remains.

11. Provision of personal data and consequences of refusal

Part of the data described in Section 4 must be provided for a contract to be concluded and performed, a point Article 13(2)(e) GDPR requires to be made express. Registration cannot be completed without the company identification and the contact details of the authorised representative; an invoice complying with German tax law cannot be issued without the billing details; and a consignment cannot be handed to a carrier without the name, delivery address, and at least one contact channel of the recipient. Refusal to supply those data means that the corresponding service cannot be rendered, in whole or in part, and an incomplete customs declaration exposes a cross-border consignment to detention or return. Consent to marketing communications, by contrast, is entirely voluntary: neither its refusal nor its later withdrawal affects the platform contract, the prices, or the handling of shipments.

12. Amendments to the notice

Changes in the services offered, in the providers engaged, in the technologies used on the websites, or in the applicable legal framework may make an amendment of the present notice necessary. The version in force is the one published on the websites named in the introduction, and it governs all processing carried out from the date of publication onwards. Where an amendment concerns the purposes, the legal bases, the recipients, or the storage periods, and thus materially affects the position of data subjects, registered merchants are informed in advance by electronic mail or by a notice in the merchant panel; where the change requires consent, that consent is obtained before the new processing begins. Earlier versions are archived and may be requested from the contact point named in Section 2.

Last updated: 14 August 2026

Get in touch now, Immediately, Visit Our Warehouse!

Get in touch now, immediately and visit our warehouse on a day that is convenient for you!

Get in touch now, Immediately, Visit Our Warehouse!

Get in touch now, immediately and visit our warehouse on a day that is convenient for you!

ParkPalet Cookie Policy

/