Privacy Policy
Last updated: June 4, 2026
Table of Contents
- Data Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Transfer of Personal Data
- International Data Transfers
- Retention and Deletion of Data
- Rights of Data Subjects
- Business Services
- Registration, User Account, and Order Account
- Provision of the Online Offer and Web Hosting
- Use of Cookies
- Captcha and Spam Protection
- Contact and Inquiry Management
Data Controller
Code For Nature, Thomas Uher and Judith Boelcke GbR
Meisenweg 6
91099 Poxdorf, Germany
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects concerned.
Types of data processed
- Inventory data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
Categories of data subjects
- Customers and clients.
- Prospects.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Office and organizational procedures.
- Management of and response to inquiries.
- Feedback.
- Provision of our online services and user experience.
- Information technology infrastructure.
- Registration and user accounts.
- Spam and abuse prevention.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection rules may apply in your or our country of residence or registered office. If, in a specific case, more specific legal bases apply, we will inform you of them in this privacy policy.
- Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of personal data concerning them for one or more specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection rules in Germany: In addition to the GDPR rules, national data protection rules apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG). The BDSG contains special rules on the right of access, the right to deletion, the right to object, processing of special categories of personal data, processing for other purposes, disclosure, and automated decision-making in individual cases including profiling. In addition, data protection laws of the individual German federal states may apply.
Note on the applicability of the GDPR and the Swiss FADP: These privacy notices serve both to provide information under the Swiss Federal Act on Data Protection (Swiss FADP) and under the General Data Protection Regulation (GDPR). For this reason, please note that, due to the broader territorial scope and greater comprehensibility, the terms used are those of the GDPR. In particular, instead of the terms used in the Swiss FADP such as "processing" of "personal data", "overriding interest", and "particularly sensitive personal data", the terms used in the GDPR, namely "processing" of "personal data" as well as "legitimate interest" and "special categories of data", are used. The legal meaning of the terms, however, continues to be determined under the Swiss FADP where applicable.
Security Measures
In accordance with legal requirements and taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing as well as the varying likelihood and severity of risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access to, input, transfer, availability, and separation of the data. We have also established procedures that ensure the exercise of data subjects' rights, deletion of data, and responses to threats to data. Furthermore, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.
Transfer of Personal Data
As part of our processing of personal data, it may happen that such data are transferred to other entities, companies, legally independent organizational units, or individuals, or disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.
International Data Transfers
Processing in third countries: If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if processing takes place in the context of using third-party services or the disclosure or transfer of data to other persons, entities, or companies, this is done only in compliance with legal requirements. If the level of protection in the third country has been recognized by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the transfer. Otherwise, transfers take place only if the level of protection is otherwise secured, in particular by standard contractual clauses (Art. 46(2)(c) GDPR), express consent, or in cases of contractual or legally required transfer (Art. 49(1) GDPR). In our case, transfers to third countries may occur in particular if you select PayPal as the payment method during the ordering process. Otherwise, we inform you of the basis for any transfer to a third country with the respective provider from that country, with adequacy decisions taking priority as the basis. Information on third-country transfers and existing adequacy decisions can be found on the European Commission's information page: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
EU-US Trans-Atlantic Data Privacy Framework: If data are transferred to the USA when using PayPal, the following applies: Under the so-called "Data Privacy Framework" (DPF), the European Commission has also recognized the level of data protection for certain companies from the USA as adequate as part of the adequacy decision of 10 July 2023. The list of certified companies and further information about the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English). Within this privacy policy, we inform you which service providers used by us are certified under the Data Privacy Framework.
Retention and Deletion of Data
We delete personal data we process in accordance with statutory requirements as soon as the underlying consents are withdrawn or there are no further legal bases for processing. This applies in cases where the original purpose of processing no longer applies or the data are no longer needed. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal claims or for the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data that applies to specific processing operations. If several retention periods or deletion deadlines are stated for a data item, the longest period always applies. If a period does not explicitly begin on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the event triggering the period occurred.
Data that are no longer required for the original intended purpose, but are retained due to legal requirements or other reasons, are processed only for the reasons that justify their retention.
Further information on processing operations, procedures, and services:
- Retention and deletion of data (Germany): The following general retention periods
apply under German law for archiving:
- 10 years - retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets as well as the instructions and other organizational documents required to understand them, accounting records and invoices (§ 147(3) in conjunction with (1) nos. 1, 4 and 4a AO, § 14b(1) UStG, § 257(1) nos. 1 and 4, (4) HGB).
- 6 years - other business records: received commercial or business letters, copies of sent commercial or business letters, and other documents insofar as they are relevant for taxation, e.g. wage slips, cost accounting sheets, calculation documents, price labels, but also payroll documents, insofar as they are not already accounting records, and cash register tapes (§ 147(3) in conjunction with (1) nos. 2, 3, 5 AO, § 257(1) nos. 2 and 3, (4) HGB).
- 3 years - data required to consider potential warranty and damages claims or similar contractual claims and rights and to process related inquiries, based on prior business experience and usual industry practices, are stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, in particular under Arts. 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent you have given at any time.
- Right of access: You have the right to obtain confirmation as to whether data concerned are being processed and to request access to such data as well as further information and a copy of the data in accordance with legal requirements.
- Right to rectification: You have the right, in accordance with legal requirements, to request completion of data concerning you or correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with legal requirements, to request that data concerning you be deleted without delay, or, alternatively, to request restriction of the processing of such data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format or to request their transfer to another controller, in accordance with legal requirements.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you believe that the processing of personal data concerning you infringes the GDPR.
Business Services
We process data of our contractual and business partners, e.g. customers and prospects (collectively referred to as "contractual partners"), in the context of contractual and similar legal relationships as well as associated measures and with regard to communication with contractual partners (or pre-contractually), for example to answer inquiries.
We use this data to fulfill our contractual obligations. This includes in particular obligations to provide the agreed services, any updates, and remedies in the event of warranty and other service disruptions. In addition, we use the data to protect our rights and for administrative tasks associated with these obligations as well as for business organization. Furthermore, we process the data on the basis of our legitimate interests in proper and economically sound business management as well as in security measures to protect our contractual partners and our business operations from misuse, threats to their data, secrets, information, and rights (e.g. by involving telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisers, payment service providers, or tax authorities). Within the scope of applicable law, we only pass on the data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or for the fulfillment of legal obligations. Any further forms of processing, for example for marketing purposes, are communicated to the contractual partners within the framework of this privacy policy.
Which data are required for the aforementioned purposes is communicated to contractual partners before or in the context of data collection, for example in online forms, by special markings (e.g. colors) or symbols (e.g. asterisks), or in person.
We delete data after the expiry of statutory warranty and comparable obligations, i.e. generally after four years, unless the data are stored in a customer account, for example as long as they have to be kept for legal archiving purposes (e.g. generally ten years for tax purposes). Data disclosed to us in the context of an order by the contractual partner are deleted in accordance with the requirements and generally after the end of the order.
- Types of data processed: Inventory data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and e-mail addresses or telephone numbers); contract data (e.g. contract subject, term, customer category).
- Data subjects: Customers and clients; prospects; business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; security measures; communication; office and organizational procedures; management and response to inquiries.
- Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing operations, procedures, and services:
- Online shop, order forms, e-commerce, and delivery: We process customer data to enable them to select, purchase, or order the chosen products, goods, and related services, as well as their payment and delivery or fulfillment. If necessary for order fulfillment, we use service providers, in particular postal, freight forwarding, and shipping companies, to carry out delivery or fulfillment to our customers. For processing payment transactions, we make use of banks and payment service providers. If you select PayPal as the payment method during the ordering process, the data required for payment processing will be transferred to PayPal. The required information is marked as such in the order or comparable purchase process and includes the information needed for delivery or making available the service and billing, as well as contact information, billing and shipping addresses in order to be able to ask about any issues that may arise; Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR).
Registration, User Account, and Order Account
If you create a user account with us or register before or during the ordering process, we process the inventory, contact, and access data required for this purpose in order to enable you to use the account functions, manage your orders, and assign your order and billing data. This may include in particular name, e-mail address, password data, address data, and order-related information.
If you delete your account or have it deleted, the account data are generally deleted. Data that we must retain for commercial or tax law reasons or for the assertion, exercise, or defense of legal claims remain unaffected and are deleted only after the relevant retention periods have expired.
- Types of data processed: Inventory data; contact data; contract data; payment data; access data.
- Data subjects: Registered users; customers.
- Purposes of processing: Performance of a contract and pre-contractual requests; management of user accounts; authentication; order processing; security measures.
- Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR); legal obligation (Art. 6(1)(c) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Provision of the Online Offer and Web Hosting
We provide our online services without tracking or analytics. We do not collect usage data, metadata, or server log files for this purpose. Only the technical data required to deliver the requested page may be processed temporarily by the hosting infrastructure.
Use of Cookies
Cookies are small text files or other storage records that store information on end devices and read it back from them. We use only technically necessary cookies that are required for the operation of the website and the secure use of forms and login functions. In particular, we do not use cookies for analysis, tracking, or marketing purposes.
Cookies used:
- Session cookie (e.g. "sessionid"): Used for session management and login status. It is usually deleted at the end of the session or expires after the server-defined session duration.
- CSRF cookie (e.g. "csrftoken"): Used to protect forms against abusive requests (CSRF protection). The storage period depends on the technical configuration of the website.
Note on consent: No separate consent is required for these technically necessary cookies.
- Legal bases: Section 25(2) No. 2 TDDDG (strictly necessary cookies); performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR).
Captcha and Spam Protection
We use a captcha in forms to make automated submissions more difficult and to prevent abuse and spam. For this purpose, the entries and technical processing data required for verification are processed to the extent necessary to perform the captcha check. We do not use this for tracking or marketing purposes.
- Types of data processed: Content data; usage data in the context of form verification; technical data for abuse prevention.
- Data subjects: Users; communication partners.
- Purposes of processing: Security measures; prevention of spam and abuse; protection of forms and inquiries.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, e-mail, telephone, or social media) as well as within existing user and business relationships, the details of the inquiring persons are processed insofar as this is necessary to answer the contact requests and any requested measures.
- Types of data processed: Contact data (e.g. postal and e-mail addresses or telephone numbers); content data (e.g. textual or pictorial messages and posts as well as information related to them, such as authorship information or time of creation).
- Data subjects: Communication partners.
- Purposes of processing: Communication; management of and response to inquiries; feedback (e.g. collection of feedback via online forms).
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR).
Further information on processing operations, procedures, and services:
- Contact form: If users contact us via our contact form, e-mail, or other communication channels, we process the data provided in this context to handle the requested matter; Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
Created with the help of Datenschutz-Generator.de by Dr. Thomas Schwenke