Skip to content
KHGKAREN HUBER GROUP
SYS/LEGAL-01

Privacy policy

What we collect, why we collect it, where it is stored, and how to make us delete it. Written to be read, not to be survived.

Last updated [DATE]Version [N] · [N] min read

Draft for review. This is a structural template with the company's own practices described in plain language. It must be reviewed against Iranian e-commerce and data-protection law by qualified counsel before it is published.

01 · Who we are

[LEGAL NAME], registered in Iran under number [REG. NO.] at [REGISTERED ADDRESS], is responsible for the personal data described here. Where one of our stores collects data under its own brand, that store is named in its own notice and this policy applies to the group services behind it.

02 · What we collect

Three kinds of thing. What you type into a form — your name, company, email, phone and whatever you write in the message box. What an order needs — delivery address, order contents and the payment reference our provider returns to us. And what a web server records — IP address, browser, the pages you opened and when.

We do not ask for national ID numbers, and we never store card numbers. Payment happens on the provider's page, not ours.

03 · Why we collect it

To answer you, to fulfil an order or a contract, to keep the accounting records the law requires us to keep, and to see which pages are worth writing more of. Marketing email goes only to people who asked for it, and every message has a one-click unsubscribe.

04 · Cookies and analytics

This site sets the cookies it needs to work — your language choice and your session — and nothing else by default. Analytics run on our own servers with [ANALYTICS TOOL]; there is no advertising network, no cross-site tracking and no third-party tag manager on any page.

05 · Where your data lives

On servers we run inside Iran, at [FACILITY], [CITY]. Backups stay in the same jurisdiction. If a specific service ever required data to leave the country we would name it here first and ask you before it did.

06 · Who else sees it

Only the parties an order needs: the payment gateway [PROVIDER], the courier handling your delivery, and where the law requires it, the relevant authority. We do not sell personal data, and we do not share it with advertisers. Suppliers who process data on our behalf are bound by written agreement and may not use it for anything else.

07 · How long we keep it

Enquiries for [N] months unless they become a project. Order and accounting records for [N] years, because the tax rules say so. Server logs for [N] days. Newsletter details until you unsubscribe, then we keep only the fact that you did, so we do not add you again by mistake.

08 · Your rights

You can ask what we hold about you, ask us to correct it, ask us to delete it, and withdraw consent for marketing at any time. Write to [PRIVACY@DOMAIN] and we will answer inside [N] days. Deletion may be refused only for records we are legally required to keep, and we will tell you which ones and why.

09 · Security

Traffic is encrypted in transit, access to production systems is limited to named staff with individual accounts, and backups are encrypted and tested. No system is perfect: if a breach ever affected your data we would tell you and the relevant authority, with what we know and what we are doing about it.

10 · Changes and contact

When this policy changes we update the date at the top and keep the previous versions available. If a change materially affects how we use data you have already given us, we will say so directly rather than quietly. Questions go to [PRIVACY@DOMAIN] or [PHONE].

Something here unclear?

A privacy policy nobody understands is not a privacy policy. Tell us which line and we will rewrite it.