1. Scope and controller
This Privacy Policy applies when you visit hyprcart.com, contact us about HYPRCART, subscribe to or use a HYPRCART account, or act as a representative, employee or contractor of a HYPRCART customer or prospective customer.
The controller for these activities is admorris GmbH, Eduard-Bodem-Gasse 2, 6020 Innsbruck, Austria, company register number FN 610372g, Landesgericht Innsbruck, VAT ID ATU79789668 ("admorris", "HYPRCART", "we", "us" or "our").
Privacy enquiries and data-subject requests may be sent to legal@hyprcart.com or to our postal address. We have not appointed a data protection officer. This contact is monitored by the team responsible for privacy matters.
2. Personal data we process
Depending on how you interact with HYPRCART, we process the following categories:
- Website and device data: IP address, request time, requested URL, referrer, browser/device information, security signals and operational logs.
- Sales and contact data: name, business contact details, company, role, store information, requirements and the content of messages.
- Account and authentication data: name, email address, password hash, authentication-provider identifiers, verification status, session data, role, permissions, security settings and sign-in records.
- Customer and service data: organisation and staff records, storefront and catalogue configuration, support requests, imports, integrations, audit events and service usage.
- Commercial data: orders, selected plan, billing contact, invoice, VAT and payment-status information for paid subscriptions. Card details are handled by the payment provider and are not stored by HYPRCART in raw form.
- Communication data: service messages, delivery status, support correspondence, preferences and suppression records.
We receive data directly from you, from the organisation you represent, from an authentication or payment provider you choose, from integrations configured by a customer, and automatically from your browser or device.
3. Purposes and legal bases
| Purpose | Legal basis under GDPR |
|---|---|
| Responding to sales enquiries, providing demonstrations and arranging onboarding | Steps requested before a contract, Art. 6(1)(b), and our legitimate interest in B2B sales, Art. 6(1)(f) |
| Creating and administering a customer account and providing the service | Contract performance, Art. 6(1)(b); for customer staff, legitimate interests of us and the customer, Art. 6(1)(f) |
| Security, abuse prevention, troubleshooting, logging and service improvement | Our legitimate interests in a secure, reliable B2B service, Art. 6(1)(f), and legal duties where applicable, Art. 6(1)(c) |
| Subscription billing, tax, accounting and legal record keeping | Contract performance, Art. 6(1)(b), and legal obligations, Art. 6(1)(c) |
| Requested product updates and direct marketing | Consent, Art. 6(1)(a), where required; otherwise our legitimate interests and the applicable Austrian electronic-marketing rules |
| Establishing, exercising or defending legal claims | Legitimate interests, Art. 6(1)(f) |
Where we rely on legitimate interests, we balance those interests against your rights and expectations. You may object as described below. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.
4. Customer Personal Data and our processor role
A HYPRCART customer controls the personal data it submits to the platform about its buyers, contacts, staff or other individuals ("Customer Personal Data"). For that data, the customer is normally the controller and admorris GmbH is its processor. The customer decides why the data is used and is responsible for providing its own privacy notices and lawful instructions.
Our processing of Customer Personal Data is governed by the Data Processing Agreement. It is incorporated into and becomes binding automatically when a Customer accepts a HYPRCART subscription or other Order incorporating the Terms, without requiring a separate signature. It governs Customer Personal Data from the start of our processing, as set out in the DPA.
We remain an independent controller for our own account administration, security, service billing, legal compliance and business communications.
5. Recipients and service providers
We disclose personal data only as necessary to:
- cloud infrastructure, database, search, email, authentication, support and payment providers;
- professional advisers, auditors, insurers and corporate transaction advisers under confidentiality;
- authorities, courts or other parties where required by law or necessary to protect rights and security;
- the customer organisation that administers your HYPRCART account; and
- integrations or apps enabled by a customer, under that customer's responsibility.
Our current processor-side vendor register is available on the Subprocessor List. Payment providers, tax authorities, identity providers and customer-selected integrations may act as independent controllers for their own regulated or customer-directed activities.
6. International transfers and security
We favour European service regions where practical, including primary database and email regions in the EU. Some providers and support teams may process data outside the EEA. Where required, we use an adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework where applicable, and supplementary contractual and technical safeguards.
We use measures appropriate to the risk, including encrypted transport, access controls, tenant scoping, authentication safeguards, logging, backup and recovery controls, vulnerability and dependency management, and incident procedures. No internet service can guarantee absolute security. Customers must protect account credentials and configure their access rights appropriately.
7. Retention
We retain personal data only for as long as needed for the relevant purpose, a customer instruction, and applicable legal or claims periods. In particular:
- sales enquiries are kept while we evaluate and communicate about a potential business relationship and are periodically reviewed for deletion;
- account and service data is kept for the customer relationship and a limited wind-down, export and backup period afterwards;
- standard authentication sessions may remain valid for up to 30 days unless ended earlier;
- accounting and tax records are generally retained for the legally required period, commonly seven years in Austria; and
- security, audit and support records are retained according to risk, operational need and limitation periods.
Data may remain in access-restricted backups until the relevant backup cycle expires. Anonymised data that no longer relates to an identifiable person may be retained.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests or direct marketing. You may also withdraw consent and complain to a supervisory authority.
In Austria, the competent authority is the Austrian Data Protection Authority. You may also contact the authority where you live or work. We may need to verify your identity. If your request concerns data controlled by a HYPRCART customer, please contact that customer first; we will assist it as required by the DPA.
9. Cookies, communications and automated decisions
The public HYPRCART website currently uses only storage necessary for delivery, security, preferences and requested account functions. Details are in our Cookie Policy. We will request consent before adding non-essential analytics or advertising storage where consent is required.
A sales enquiry allows us to respond, arrange a demonstration and send closely related information about HYPRCART. It does not permit unrelated marketing. You can opt out of product updates at any time. Essential subscription, service and security messages cannot be disabled while an account is active where they are necessary to perform the contract or protect the service.
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on website visitors, sales contacts or users.
10. Changes and contact
We may update this policy as our service, providers or processing changes. The version and effective date above identify the applicable text. Material changes affecting existing customers will be communicated through an appropriate channel.
Contact: legal@hyprcart.com, +43 512 209060, or admorris GmbH, Eduard-Bodem-Gasse 2, 6020 Innsbruck, Austria.