GDPR
BAALLO LLC
GDPR COMPLIANCE STATEMENT
1. Our Commitment to Data Protection
BAALLO LLC is committed to protecting the privacy and personal data of our customers, including those located in the European Union (EU) and European Economic Area (EEA). This GDPR Compliance Statement explains how we meet our obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) when we process the personal data of individuals located in the EU/EEA, and works alongside our main Privacy Policy.
2. Data Controller
For the purposes of the GDPR, the Data Controller responsible for your personal data is:
- Legal company name: BAALLO LLC
- Country of incorporation: United States of America (State of Wyoming)
- Business address: 1544 Lydia Ave, Elmont, NY 11003, USA
-
Customer support email: sales@baallo.com
Phone: +1 (505) 390-8454
Website: www.baallo.com
For orders and data relating to our German warehouse operations serving EU customers, data may also be processed in connection with our affiliated EU operations to fulfill and ship your order.
3. What Personal Data We Collect
When you visit our Site or place an order, we may collect the following categories of personal data from EU/EEA residents:
● Identity data — full name;
● Contact data — email address, phone number, billing and shipping address;
● Transaction data — order details, purchase history, payment confirmation (payment card details are processed directly by our PCI-DSS compliant payment processor and are not stored on our servers);
● Technical data — IP address, browser type and version, device identifiers, and other usage data collected via cookies;
● Marketing data — your preferences for receiving marketing communications from us.
4. Legal Basis for Processing
Under Article 6 of the GDPR, we only process your personal data where we have a valid legal basis to do so:
● Performance of a contract (Art. 6(1)(b)) — to process and fulfill your order, provide customer support, and manage returns;
● Consent (Art. 6(1)(a)) — for marketing emails and non-essential cookies, which you can withdraw at any time;
● Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve our Site, prevent fraud, and conduct direct marketing to existing customers, balanced against your rights and interests;
● Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and other applicable legal requirements.
5. Your Rights Under the GDPR
If you are located in the EU/EEA, you have the following rights regarding your personal data:
● Right of access — to obtain confirmation of, and access to, the personal data we hold about you;
● Right to rectification — to have inaccurate or incomplete personal data corrected;
● Right to erasure (“right to be forgotten”) — to request deletion of your personal data, subject to certain legal exceptions (e.g., order and tax records we are required to retain);
● Right to restrict processing — to request that we limit how we use your personal data in certain circumstances;
● Right to data portability — to receive your personal data in a structured, commonly used, machine-readable format;
● Right to object — to object to processing based on legitimate interests or for direct marketing purposes;
● Right to withdraw consent — at any time, where processing is based on your consent, without affecting the lawfulness of processing before withdrawal;
● Right to lodge a complaint — with the data protection supervisory authority in your EU/EEA country of residence.
To exercise any of these rights, please contact us at sales@baallo.com. We may ask you to verify your identity before responding, and we will respond to legitimate requests within one month, as required by the GDPR.
6. International Data Transfers
BAALLO is a US-based company, and certain personal data may be processed or stored on servers located in the United States. Where we transfer personal data of EU/EEA individuals to the United States or other countries outside the EU/EEA, we rely on appropriate safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs), to ensure your data continues to be protected to EU standards.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Statement and our Privacy Policy, including to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When personal data is no longer needed, it is securely deleted or anonymized.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, consistent with the requirements of Article 32 of the GDPR. Payment information is never stored on our servers and is handled exclusively by our PCI-DSS compliant payment processor.
9. Cookies and Tracking
Where required under the GDPR and the EU ePrivacy Directive, we obtain your consent before placing non-essential cookies (such as analytics or advertising cookies) on your device. You can manage or withdraw your cookie consent at any time through our cookie settings or your browser preferences. For further detail, please see our Cookie Policy.
10. Data Breach Notification
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and will inform affected individuals without undue delay where required under Articles 33 and 34 of the GDPR.
11. Changes to This Statement
We may update this GDPR Compliance Statement from time to time to reflect changes in our practices or applicable law. The updated version will be posted on this page with a revised “Effective Date.”
12. Contact Us / Supervisory Authority
If you have questions about this Statement or how we handle your personal data, please contact us:
BAALLO LLC
1544 Lydia Ave, Elmont, NY 11003, USA
Email: sales@baallo.com
Phone: +1 (505) 390-8454
Website: www.baallo.com
You also have the right to lodge a complaint directly with the data protection supervisory authority in your EU/EEA country of residence if you believe your data protection rights have been violated.