Skip to Content

Privacy Policy

ROOOOM Service- und Generalagentur, acting as an independent commercial agency in accordance with Section 84 of the German Commercial Code (HGB)

1. Data
controller
: The data controller within the meaning of Article 4(7) of the GDPR is: ROOOOM Service- und Generalagentur, owned by Andreas Barner, Edeltraudstraße 80, 81827 Munich, Germany

Telephone: +49 172 8566635 · Email: info@roooom.com

A data protection officer does not need to be appointed, as the legal requirements set out in Article 37 of the GDPR in conjunction with Section 38 of the BDSG are not met. For any enquiries regarding data protection, please contact us directly using the contact details provided above.


2. Scope
This Privacy Policy applies to the websites and retailer platforms operated by ROOOOM, including the password-protected retailer area, as well as to the processing of personal data in the context of business initiation and transaction processing. This does not cover the websites and data processing activities of the manufacturers we represent. These manufacturers are independently responsible for the data processing carried out by them (see section 11).


3. Legal
bases
Unless otherwise stated below, the processing is based on the following legal bases:
– Article 6(1)(a) of the GDPR — consent, in particular in the case of non-essential cookies, audience measurement and the sending of product information.
– Article 6(1)(b) of the GDPR — performance of a contract or the implementation of pre-contractual measures, in particular in relation to registration, enquiries and orders.
– Article 6(1)(c) of the GDPR — compliance with legal obligations, in particular commercial and tax law retention obligations.
– Article 6(1)(f) of the GDPR — legitimate interests, in particular in the secure and trouble-free operation of the website, in brokerage activities and in direct marketing to business customers.

Section 25 of the TDDDG also applies to the storage of information on your device and access to information already stored.


4. Your rights
You have the following rights vis-à-vis ROOOOM in relation to your personal data:
– Right of access (Art. 15 GDPR)
– Right to rectification (Art. 16 GDPR)
– Right to erasure (Art. 17 GDPR)
– Right to restriction of processing (Art. 18 GDPR)
– Data portability (Art. 20 GDPR)
– Objection to processing (Art. 21 GDPR) You may withdraw any consent you have given at any time with effect for the future. The lawfulness of the processing carried out prior to the withdrawal remains unaffected.

Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of data concerning you which is carried out on the basis of Article 6(1)(f) of the GDPR. If your data is processed for the purposes of direct marketing, you have the right to object at any time without giving any reason; the data will then no longer be processed for these purposes.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach.


5. Accessing the website, server log files, hosting
(1) When you access our websites, your device’s browser automatically transmits information to the server, which is temporarily stored in a log file: the IP address of the requesting device, the date and time of access, the name and URL of the file accessed, the amount of data transferred, a notification as to whether the request was successful, the browser type and version used, the operating system, and the previously visited page (referrer).

(2) This processing is carried out on the basis of Article 6(1)(f) of the GDPR. The legitimate interest lies in establishing a connection, ensuring system security, carrying out technical administration and investigating attempts at misuse and attacks. This data is not combined with other data sources for the purpose of identifying users.

(3) Log files are automatically deleted after 14 days, unless their continued retention is necessary for the investigation of a specific security-related incident.

(4) The websites are hosted on a server leased by ROOOOM from Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, in a data centre in Germany. A contract for data processing in accordance with Article 28 of the GDPR has been entered into with Hetzner. The software used is Odoo, which is operated by ROOOOM itself; no data is transferred to the software manufacturer.

(5) The websites are accessed exclusively via an encrypted connection (TLS/HTTPS).


6. Cookies and consent management
(1) Cookies and similar technologies are used on our websites. Cookies are small text files that are stored on your device.

(2) Technically necessary cookies — such as those used for session management, logging into the retailer’s area, language selection, the shopping basket and storing your cookie preferences — are set without consent. This is based on Section 25(2)(2) of the TDDDG and Article 6(1)(f) of the GDPR.

(3) All other cookies and technologies, in particular those used for audience measurement and the integration of external content, are set only with your express consent (Section 25(1) of the TDDDG, Article 6(1)(a) of the GDPR).

(4) Consent is obtained via a consent management tool: CODENEERS Cookie Control. You can refuse consent at the same level and with the same effort as giving consent. Your decision is logged for record-keeping purposes (time, scope of consent, banner version, truncated IP address) and retained for the duration of the statutory retention period.

(5) You may withdraw your consent at any time with future effect via the cookie settings. You can find the link here: https://roooom.com/cookie-settings. In addition, you can delete cookies via your browser settings or prevent them from being stored altogether; however, this may restrict the functionality of the website.

(6) Consent given via a recognised consent management service in accordance with Section 26 of the TDDDG, read in conjunction with the Consent Management Ordinance, shall be taken into account as soon as such a service is technically connected.


7. Audience measurement
We use the open-source software Matomo for the statistical analysis of usage of our websites; we host this on our own server at Hetzner Online GmbH in Germany. No data is transferred to third parties or to third countries. In particular, the following data is processed: truncated IP addresses, pages visited, duration of visit, referrer, device used and browser. Processing is carried out on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. The data is deleted after 2 months.


8. External content: Fonts, maps, videos
(1) Fonts: All fonts used on our websites are served locally from our own server. No connection is made to third-party servers – in particular to Google Fonts – when the pages are accessed.

(2) Map service: To display directions, we integrate Google Maps, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map is only loaded once you have given your express consent (two-click solution). Only then will your IP address and other usage data be transmitted to Google, including to the USA. The legal basis is Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

(3) Videos: Videos are embedded using YouTube’s enhanced privacy mode (youtube-nocookie.com), a service provided by Google Ireland Limited, and are also only loaded once you have given your consent. When the videos are played, usage data is transmitted to Google, including to the USA. The legal basis is Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.

(4) No connection will be established with any of these providers without your consent; instead of the external content, you will see a placeholder.


9. Contact
(1) If you contact us by email, telephone, fax or via a contact form, we will process your name, your contact details, the company on whose behalf you are acting, and the content of your enquiry in order to deal with your request and in the event of any follow-up questions.

(2) The legal basis is Article 6(1)(b) of the GDPR, insofar as the enquiry serves to initiate or carry out a business transaction; in all other cases, it is Article 6(1)(f) of the GDPR on the basis of our legitimate interest in responding to enquiries.

(3) Our business email communications are handled via Microsoft 365, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement, including the Standard Contractual Clauses, is in place; processing in third countries cannot be ruled out in the context of support and operational processes.

(4) Emails are sent with transport-layer encryption, provided that the receiving system supports this. There is no end-to-end encryption; for particularly confidential content, please contact us in advance to agree on a suitable method of transmission.

(5) We delete enquiries as soon as they have been fully processed and there are no statutory retention obligations preventing us from doing so; business correspondence is generally subject to the retention periods laid down under commercial and tax law (see clause 22).


10. Registration and Retailer Area
(1) Access to the password-protected Retailer Area requires registration and authorisation by us. The data processed includes the company name, legal form, address, VAT registration number, name and business contact details of the contact persons, login details and, where applicable, proof of commercial activity.

(2) The purpose is to verify access authorisation, provide access to the dealer portal and process the transaction. The legal basis is Article 6(1)(b) of the GDPR and Article 6(1)(f) of the GDPR, in respect of our interest in making retailer terms and conditions available only to authorised commercial customers.

(3) Passwords are stored exclusively in encrypted form (using a hashing algorithm) and cannot be viewed by us in plain text.

(4) To ensure the security of access, we log login times and failed login attempts in accordance with Article 6(1)(f) of the GDPR. These logs are deleted after 90 days.

(5) Once the account has been closed, the account details will be deleted, provided that there are no retention obligations or ongoing business transactions that prevent this.


11. Orders and Forwarding to the Relevant Manufacturer
(1) ROOOOM is a commercial agency and acts as an intermediary in transactions between you and the relevant manufacturer. The supply contract is concluded exclusively between you and the manufacturer.

(2) To fulfil this purpose, we pass on your order and enquiry details to the relevant manufacturer. In particular, we transmit company and address details, delivery and billing addresses, the names and business contact details of the relevant contacts, VAT registration numbers, as well as order, project and quotation details.

(3) The legal basis is Article 6(1)(b) of the GDPR, as the disclosure is necessary for the performance of the brokerage service you have requested; in addition, Article 6(1)(f) of the GDPR applies on the basis of our legitimate interest in carrying out our brokerage activities.

(4) The relevant manufacturer is the independent data controller within the meaning of Article 4(7) of the GDPR with regard to the data transmitted to it. Its own privacy policy applies to the processing of such data. In this respect, there is no processing on behalf of a third party.

(5) If you provide us with third-party data — such as alternative delivery addresses, details of your end customers, planners or architects — you are responsible for ensuring that such disclosure is lawful and for fulfilling your duty to inform those individuals.


12. Product information and mailings
(1) We inform business customers and prospective customers by email about new products, new or amended price lists, catalogues, promotions and trade fair dates for the manufacturers we represent.

(2) The legal basis is your consent pursuant to Article 6(1)(a) of the GDPR in conjunction with Section 7(2)(2) of the UWG. We obtain your consent via the double opt-in procedure: following your registration, you will receive an email containing a confirmation link; we will only add you to the mailing list once you have confirmed. Your registration, confirmation and the time of these actions are logged for record-keeping purposes.

(3) Where we have obtained your email address in connection with a business relationship we have facilitated, we will send you information about our own similar offers on the basis of Section 7(3) of the German Unfair Competition Act (UWG) and Article 6(1)(f) of the General Data Protection Regulation (GDPR). You may object to this at any time.

(4) For mailings, we use the Brevo service provided by Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin. A data processing agreement has been entered into in accordance with Article 28 of the GDPR.

(5) Performance measurement: Our mailings may contain tracking pixels and personalised links, which enable us to determine whether and when a message has been opened and which links have been clicked. This analysis is carried out on the basis of the consent you give when you register.

(6) You can unsubscribe at any time by clicking the unsubscribe link in any message or by sending an informal email to info@roooom.com. Once you have unsubscribed, we will add your email address to a block list to ensure that you do not receive any further messages; the legal basis for this is Article 6(1)(c) and (f) of the GDPR.


13. Complaints, returns and correspondence (copies)
(1) To manage complaints and returns, we process the data provided for this purpose: order and delivery details, the reason for the complaint, photographs and descriptions of the condition of the goods, the manufacturer’s return numbers, and any correspondence between you, us and the manufacturer.

(2) In accordance with our General Terms and Conditions, you should address any complaints directly to the manufacturer and copy us in for information purposes. We process the messages copied to us in order to track the matter and assist you. The legal basis is Article 6(1)(f) of the GDPR; the legitimate interest lies in managing the transactions we have facilitated.

(3) Where goods are sent to us, we shall document the external condition of the consignment upon receipt, using photographs where necessary. This documentation serves to preserve evidence for the purposes of dealing with transport companies, manufacturers and customers; the legal basis is Article 6(1)(f) of the GDPR.

(4) Transaction data shall be deleted upon completion of the transaction, unless it is subject to the retention periods set out in clause 22 or is still required for the purpose of pursuing or defending against claims.


14. Samples
(1) Where we provide you with samples, sample cases, demonstration equipment or display items, we process the data required for handling these in our stock management system: company details, contact person, alternative delivery address, the sample provided with its identification number, dispatch date, return deadline and return status.

(2) The purposes are to organise and document dispatches, to manage our sample warehouse and the property of the respective manufacturer, and to monitor returns. The legal basis is Article 6(1)(b) and (f) of the GDPR.

(3) Before the return period expires, we will send you an automated reminder by email. If the item is not returned, we will send reminders and invoice you for the replacement value; in this respect, clause 15 applies. These reminders and notices form part of the contract fulfilment process and do not constitute advertising.

(4) Once the sample has been returned and any claims have lapsed, the transaction data shall be deleted, unless it is subject to the retention periods set out in clause 22.


15. Invoicing, receivables management and debt collection
(1) Where we provide you with services for which a fee is payable, we process the data required for invoicing: billing address, contact person, VAT registration number, description of services, amounts and payment receipts. The legal basis for this is Article 6(1)(b) and (c) of the GDPR.

(2) In the event of non-payment, we will process the data for the purposes of issuing a reminder and enforcing our claim. This may involve passing the data on to a debt collection agency, a solicitor or a court. The legal basis is Article 6(1)(f) of the GDPR; the legitimate interest lies in the enforcement of legitimate claims.

(3) We do not carry out credit checks via credit reference agencies.


16. Trade fairs, events and contact details collection
(1) At trade fairs, in-house exhibitions and events, we collect contact details from prospective customers and visitors — company name, name, business contact details, areas of interest and notes from discussions. This information is collected via business cards, contact forms, badge scans or by entering details on site.

(2) The purpose is to follow up on the discussion and to initiate a business relationship. The legal basis is Article 6(1)(b) of the GDPR for responding to specific enquiries and Article 6(1)(f) of the GDPR for general business development with commercial prospects.

(3) The sending of promotional emails to these contacts requires consent in accordance with clause 12. Receiving a business card does not constitute such consent.

17. Dispatch
of catalogues, samples and postal items
. For the dispatch of catalogues, price lists, samples and other items, we process company details, delivery addresses and contact details, and pass these on to the contracted courier company. The legal basis for this is Article 6(1)(b) and (f) of the GDPR. The courier company processes the address details under its own responsibility for the purpose of carrying out the delivery.


18. Telephone calls and video conferences
(1) In the case of telephone calls, we process the telephone number provided, the time of the call and its content, insofar as we create a record of this in our system. Telephone calls are not recorded.

(2) For video conferences, we use Microsoft Teams (Microsoft, Redmond, Washington, USA), Google Meet (Google LLC, Mountain View, California, USA) and Zoom (Zoom Communications Inc., San Jose, California, USA). The data processed includes name, email address, the time and duration of participation, and technical connection data. Recordings are only made with the prior notification and consent of all participants.

(3) The legal basis is Article 6(1)(b) of the GDPR for contract-related communications; in all other cases, it is Article 6(1)(f) of the GDPR.


19. Social media
presence
. Where we maintain profiles on social media platforms such as LinkedIn, Instagram, Facebook, TikTok, YouTube, Vimeo, Xing and similar, the respective providers process visitors’ data independently and in accordance with their own terms and conditions. According to the case law of the European Court of Justice, there is joint responsibility under Article 26 of the GDPR for the processing of usage data for statistical purposes (insights); relevant agreements with the providers are in place. We ourselves process the data you send us via these channels in order to respond to your enquiry on the basis of Article 6(1)(f) of the GDPR. These channels are not suitable for the transmission of confidential information.


20. Project registration and property protection
When you submit a building project or property for project registration, we process the necessary details: the name and address of the property, the planners, architects and clients involved along with their professional contact details, the scope of services, and the registration and protection status. We pass this data on to the relevant manufacturer, who decides on the registration. The legal basis for this is Article 6(1)(b) and (f) of the GDPR. If you provide us with third-party data in this context, clause 11(6) applies accordingly.


21. Job applications
:
We process application documents solely for the purpose of conducting the recruitment process, in accordance with Section 26(1) of the German Federal Data Protection Act (BDSG) and Article 6(1)(b) of the General Data Protection Regulation (GDPR). Once the process has been completed, the documents will be deleted within six months at the latest, unless you have consented to them being stored for a longer period.


22. Customer management, accounting and data retention
(1) We manage customer, prospective customer and transaction data in an Odoo system that we operate ourselves on our server in Germany. Access is restricted exclusively to authorised personnel within our company.

(2) Invoice and commission data, as well as business correspondence, are subject to the statutory retention periods, in particular those set out in Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO). This data is stored for the duration of the relevant retention period, and its processing is otherwise restricted. The legal basis is Article 6(1)(c) of the GDPR.

(3) We delete the data of prospective customers with whom no business relationship is established no later than 36 months after the last contact.

(4) To ensure data reliability, we create encrypted backup copies, which are stored on a separate storage system and overwritten according to a fixed schedule.


23. Recipients and data processors
We only disclose personal data where this is necessary to fulfil our obligations, where you have given your consent, or where there is a legal obligation to do so. Recipients include, in particular:
– the respective manufacturers we represent, as independent data controllers (Clause 11)
– Hetzner Online GmbH, Gunzenhausen — server hosting (data processing on behalf of a controller)
– Microsoft Ireland Operations Limited, Dublin — email and office communications (data processing on behalf of the controller)
– Sendinblue GmbH (Brevo), Berlin — sending of mailings (data processing on behalf of the controller)
– Hostinger — domain and DNS management (HOSTINGER operations, UAB, Vilnius 03230, Lithuania); CODENEERS Cookie Control for the consent management tool –
Transport and delivery companies for catalogues, samples and returns, acting as independent data
controllers – Zoom, Google Meet, Microsoft Teams –
Tax consultancy and, where applicable, auditing and legal advice, to the
extent provided for by law – Debt collection agencies, solicitors and courts, where claims need to be enforced –
Credit institutions in the context of payment processing. Contracts in accordance with Article 28 of the GDPR have been concluded with all data processors. No data is disclosed to third parties for advertising purposes.


24. Transfers
to third countries
. Where data is transferred to countries outside the European Economic Area, this will only take place if an adequacy decision by the European Commission pursuant to Article 45 of the GDPR is in place, appropriate safeguards pursuant to Article 46 of the GDPR — in particular standard contractual clauses — have been agreed, or an exception under Article 49 of the GDPR applies. The specific legal bases are set out in this statement for the respective processing operations. Upon request, we will provide you with further information and, where possible, a copy of the safeguards.


25. Data
security
We implement technical and organisational measures in accordance with Article 32 of the GDPR to protect your data against accidental or deliberate manipulation, loss, destruction and unauthorised access. These include, in particular, transport encryption (TLS), encrypted backups, an access control policy, password policies and email authentication procedures (SPF, DKIM, DMARC). Our measures are continuously adapted in line with technological developments.


26. No automated decision-making
No automated decision-making, including profiling within the meaning of Article 22 of the GDPR, takes place.


27. Obligation to provide data
The provision of your data is not required by law or by contract. However, without the information required for registration and order processing, we cannot grant you access to the dealer area or forward orders to the relevant manufacturer.


28. Changes to this Privacy Policy
We will update this Privacy Policy as soon as there are changes to our data processing activities or the legal framework. The current version published on our websites shall apply at all times.


Germany, Munich, 20 September 2026

We use AI-generated or AI-enhanced images.