Legal Library
Historical version · 1.0.0 · View current version
Legal Library

Privacy Policy

How KulturCart collects, uses, shares, protects, and retains personal data, including your rights and contact options.

Version
1.0.0
Effective date
Wednesday, August 12, 2026
KulturCart Privacy PolicyVersion 1.0 · 12 August 2026 · KC-LEGAL-03-EN-1.0 Table of Contents 1. Scope, purpose and status of this Privacy Policy 1.1 Services and persons covered 1.2 Purpose of the information 1.3 Relationship to other KulturCart documents 1.4 Meaning of personal data and processing 2. Controller and privacy contact 2.1 Controller 2.2 Contact channels 2.3 Data protection officer 2.4 Authoritative language 3. Allocation of roles in the KulturCart marketplace 3.1 KulturCart as independent controller 3.2 Vendors as independent controllers 3.3 Processor activities 3.4 Payment and other independent providers 3.5 No automatic joint controllership 4. General processing principles and legal bases 4.1 Performance of a contract and pre-contract steps 4.2 Legal obligations 4.3 Legitimate interests 4.4 Consent 4.5 Special categories and criminal-offence data 5. Sources of personal data 5.1 Data provided directly 5.2 Data provided by vendors and service providers 5.3 Automatically generated data 5.4 Public and official sources 5.5 Data received from another person 6. Categories of personal data 6.1 Identity and contact data 6.2 Account and authentication data 6.3 Order, transaction and payment data 6.4 Content and communication data 6.5 Technical and usage data 6.6 Vendor, staff and POS data 7. Website access, server logs and technical delivery 7.1 Server requests 7.2 Security and diagnostic logs 7.3 Hosting architecture 7.4 Log retention 8. Cookies, local storage and consent management 8.1 Strictly necessary technologies 8.2 Optional technologies 8.3 Cookie and Similar Technologies Notice 8.4 Withdrawal and settings 9. Customer accounts and guest use 9.1 Registration 9.2 Guest checkout 9.3 Account preferences 9.4 Account closure 10. Marketplace orders and contract formation 10.1 Checkout and order data 10.2 Order review and vendor acceptance 10.3 Order confirmations and records 10.4 Single- and multi-vendor transactions 11. Disclosure to vendors and vendor responsibility 11.1 Necessary order disclosure 11.2 Vendor privacy information 11.3 No unrestricted customer-list transfer 11.4 Vendor changes or closure 12. Payment processing 12.1 Payment data and providers 12.2 Stripe Connect 12.3 Authorisation, capture and refunds 12.4 Payment security 12.5 Chargebacks and disputes 13. Delivery, collection and logistics 13.1 Address and contact data 13.2 Carriers and delivery partners 13.3 Proof of delivery and incidents 13.4 Location data 14. Returns, refunds, warranty and complaints 14.1 Case handling 14.2 Evidence 14.3 Product safety and recalls 14.4 Retention of case records 15. Customer support and communications 15.1 Support channels 15.2 Self-hosted support systems 15.3 Call and conversation records 15.4 Service communications 16. Reviews, comments and other user content 16.1 Publication 16.2 Moderation 16.3 Authenticity and fraud prevention 16.4 Content licence and deletion 17. Newsletters, marketing and notifications 17.1 Newsletter consent 17.2 Existing-customer marketing 17.3 Vendor and partner marketing 17.4 Push and in-app notifications 17.5 Advertising measurement 18. Analytics, service improvement and research 18.1 Operational analytics 18.2 Self-hosted analytics 18.3 Experiments and feature evaluation 18.4 Surveys and research 19. Location, maps and local availability 19.1 Address-based localisation 19.2 Device location 19.3 Map providers 19.4 Location retention 20. Social media and embedded third-party content 20.1 KulturCart profiles 20.2 Embedded content 20.3 No blanket activation statement 20.4 Direct links 21. Vendor onboarding, trader verification and business administration 21.1 Application and verification data 21.2 Legal bases 21.3 Ongoing accuracy 21.4 Bank and payout information 21.5 Business contacts and employees 22. POS, TSE and fiscalisation data 22.1 POS users and cashiers 22.2 Transactions and receipts 22.3 TSE and fiskaly 22.4 DSFinV-K and tax exports 22.5 Fiscal retention 23. Fraud prevention, security and platform integrity 23.1 Risk signals 23.2 Protective measures 23.3 Legal basis 23.4 Confidentiality of detection methods 24. Legal compliance, reporting and claims 24.1 Authority and legal requests 24.2 Illegal content and policy reports 24.3 Intellectual-property reports 24.4 Product-safety reports 24.5 Legal claims and insurance 25. Applicants, suppliers, partners and other business contacts 25.1 Applications 25.2 Suppliers and service providers 25.3 Business development and partnerships 25.4 Retention 26. Recipients and service providers 26.1 Need-to-know principle 26.2 Hosting and infrastructure 26.3 Payments and fiscalisation 26.4 Internal business systems 26.5 Professional and public recipients 26.6 Current register 27. International data transfers 27.1 EEA preference 27.2 Adequacy decisions 27.3 Standard Contractual Clauses 27.4 Provider-specific safeguards 27.5 Copies and information 28. Retention, deletion and anonymisation 28.1 Purpose limitation 28.2 Commercial and tax records 28.3 Accounts and orders 28.4 Support, complaints and security 28.5 Backups 28.6 Anonymisation 29. Technical and organisational security 29.1 Risk-based safeguards 29.2 Access management 29.3 Development and operations 29.4 User responsibilities 29.5 No absolute guarantee 30. Data-subject rights 30.1 Access and information 30.2 Rectification and completion 30.3 Erasure and restriction 30.4 Data portability 30.5 Objection 30.6 Withdrawal of consent 30.7 Identity verification and response 31. Automated decisions, profiling and personalisation 31.1 No undisclosed significant decisions 31.2 Fraud and risk scoring 31.3 Recommendations and ranking 31.4 Marketing profiles 32. Children and legal capacity 32.1 Service audience 32.2 Consent by children 32.3 Removal and protection 33. Whether data must be provided 33.1 Contract-required information 33.2 Legally required information 33.3 Optional information 34. Supervisory authority and complaints 34.1 Right to complain 34.2 Competent authority for KulturCart 34.3 Contacting KulturCart first 35. Changes, versioning and contact 35.1 Policy changes 35.2 Notice of material changes 35.3 Archived versions 35.4 Contact Appendix A - Processing activity matrix Appendix B - Principal provider and recipient register Appendix C - Retention matrix Appendix D - Role allocation matrix Appendix E - Rights and request matrix 1. Scope, purpose and status of this Privacy Policy 1.1 Services and persons covered This Privacy Policy explains how KulturCart processes personal data in connection with kulturcart.de, related marketplace functions, customer and vendor accounts, support channels, KulturCart POS and fiscalisation services where relevant, and other KulturCart services that expressly refer to this Policy. It applies to visitors, registered users, customers, vendor representatives, cashiers and other persons whose data is processed through these services. Separate notices may apply to a specific processing context, such as a vendor contract, a job application, a security report or a particular campaign. Where a more specific notice applies, it supplements this Policy and takes precedence for the processing described in that notice. 1.2 Purpose of the information The purpose of this Policy is to provide transparent information under Articles 12, 13 and 14 GDPR about the categories of personal data processed, the purposes and legal bases, recipients, transfers, retention, security, and the rights of data subjects. It is not intended to create consent where consent is not the applicable legal basis. 1.3 Relationship to other KulturCart documents The General Terms and Conditions and Marketplace Terms of Use govern use of the marketplace. Vendor contractual documents govern the commercial relationship with vendors. The Cookie and Similar Technologies Notice describes device storage, access and optional tracking technologies in greater technical detail. The Customer and Vendor Policies allocate operational responsibilities. These documents should be read together where relevant. 1.4 Meaning of personal data and processing Personal data means information relating to an identified or identifiable natural person. Processing includes collection, recording, organisation, storage, adaptation, consultation, disclosure, restriction, deletion and other use of personal data. Anonymous information that cannot reasonably be linked to a person is not personal data. 2. Controller and privacy contact 2.1 Controller The controller for the processing described as KulturCart's own processing in this Policy is KulturCart - Ibrahim Lawal, trading as 'KulturCart', Ringstraße 22, 84347 Pfarrkirchen, Germany. 2.2 Contact channels Privacy questions, requests and objections may be sent to info@kulturcart.de or by post to the business address above. Please identify the relevant account, order or interaction so that KulturCart can locate the information without collecting unnecessary additional data. 2.3 Data protection officer KulturCart has not appointed and does not currently publish a separate data protection officer because the statutory conditions requiring an appointment have not been determined to apply to the present organisation. If an appointment becomes necessary, the contact details will be added to this Policy without delay. 2.4 Authoritative language The German Privacy Policy is the authoritative version. The English text is a convenience translation. Privacy rights may be exercised in German or English. 3. Allocation of roles in the KulturCart marketplace 3.1 KulturCart as independent controller KulturCart acts as an independent controller where it determines the purposes and essential means of processing for operating, securing and improving the marketplace; managing customer and vendor accounts; billing KulturCart services; fraud prevention; legal compliance; platform governance; complaint handling; and the establishment, exercise or defence of legal claims. 3.2 Vendors as independent controllers A vendor ordinarily sells products in its own name and on its own account. For order fulfilment, delivery, statutory warranty, customer communication and its own legal obligations, the vendor generally acts as an independent controller. The vendor's identity and contact information are shown in the relevant offer, order or vendor store. Questions concerning a vendor's own processing may therefore need to be directed to that vendor. 3.3 Processor activities Where KulturCart processes clearly defined personal data only on a vendor's documented instructions, the roles and obligations are governed by the applicable Data Processing Agreement. A software function or shared system does not by itself determine the legal role; the actual purpose and decision-making authority are decisive. 3.4 Payment and other independent providers Payment providers, carriers, fiscalisation providers and other regulated or independent service providers may act as separate controllers, processors or both depending on the activity. Their own privacy information applies to processing for which they determine the purposes and means. 3.5 No automatic joint controllership Joint controllership is not assumed merely because parties exchange data. If KulturCart and another party jointly determine purposes and essential means for a specific processing activity, the arrangement and the essence of the allocation will be documented and communicated as required. 4. General processing principles and legal bases 4.1 Performance of a contract and pre-contract steps KulturCart processes data under Article 6(1)(b) GDPR where necessary to create or manage an account, provide requested marketplace functions, facilitate an order, respond to a pre-contract enquiry, provide support, or perform another contract with the data subject. 4.2 Legal obligations Processing under Article 6(1)(c) GDPR may be necessary for tax and accounting records, trader verification, product-safety cooperation, fiscal records, fraud or money-laundering controls where applicable, statutory information duties, authority requests and other binding legal obligations. 4.3 Legitimate interests Under Article 6(1)(f) GDPR, KulturCart may process data for secure and reliable platform operation, prevention of misuse, internal administration, service improvement, direct marketing to existing customers where legally permitted, protection of users and vendors, evidence, and legal claims. KulturCart balances these interests against the rights and expectations of affected persons. 4.4 Consent Where processing is based on consent under Article 6(1)(a) GDPR, the request will be specific, informed and voluntary. Consent may be withdrawn at any time for the future. Withdrawing consent does not affect processing already lawfully carried out before withdrawal. 4.5 Special categories and criminal-offence data KulturCart does not ordinarily request special categories of data under Article 9 GDPR. If a person voluntarily submits sensitive information in a support, complaint, accessibility or safety context, KulturCart will process it only where necessary and supported by an appropriate legal basis. Data relating to criminal convictions or offences is processed only where permitted by Article 10 GDPR and applicable law. 5. Sources of personal data 5.1 Data provided directly KulturCart receives data when a person visits the website, creates an account, places an order, contacts support, communicates with a vendor, subscribes to messages, submits a review, reports content, exercises a right, applies to become a vendor or otherwise interacts with KulturCart. 5.2 Data provided by vendors and service providers Vendors may provide order status, fulfilment, delivery, return, complaint and product-safety information. Payment providers may provide transaction status, risk indicators and limited payment references. Carriers may provide tracking and delivery events. Fiscalisation providers may provide TSE and export status. Support and hosting providers may generate technical records. 5.3 Automatically generated data When the services are used, servers and applications generate IP addresses, timestamps, request paths, device and browser information, session identifiers, authentication events, error reports, performance data and security logs. Optional analytics or advertising data is collected only in accordance with the Cookie Notice and the applicable consent settings. 5.4 Public and official sources For vendor onboarding, safety, fraud and compliance purposes, KulturCart may obtain data from public company registers, tax or VAT verification services, sanctions lists, product-safety portals, official notices, public websites and other lawful sources. 5.5 Data received from another person A customer may provide a recipient's name, address or telephone number for delivery, or a business may provide employee and representative details. The person providing the data must be authorised to do so and should inform the affected person where appropriate. 6. Categories of personal data 6.1 Identity and contact data This may include name, title, date of birth where legally relevant, postal address, delivery address, email address, telephone number and preferred language. 6.2 Account and authentication data This may include account identifier, login credentials in protected form, roles, permissions, user groups, multi-factor or verification information, login history, security events and account preferences. 6.3 Order, transaction and payment data This may include products, quantities, prices, vendor, order number, payment method, payment status, refund information, billing data, delivery or collection details, transaction references and related communications. KulturCart does not ordinarily store full card numbers where a payment provider processes them directly. 6.4 Content and communication data This includes messages, support tickets, comments, reviews, uploaded files, complaint records, report submissions, call notes and other content a person sends or publishes. 6.5 Technical and usage data This includes IP address, user-agent, device and browser data, identifiers, session information, page and feature usage, diagnostic data, errors, performance measurements and consent records. 6.6 Vendor, staff and POS data This may include business and register information, authorised representatives, cashiers, employee identifiers, role and access data, POS transactions, TSE assignments, receipts, cash logs, audit records and DSFinV-K-related information. 7. Website access, server logs and technical delivery 7.1 Server requests When a page or application function is accessed, the hosting environment processes the IP address, date and time, requested resource, referrer where transmitted, browser and operating-system information, response status and transferred data volume. This is technically necessary to deliver content and maintain service stability. 7.2 Security and diagnostic logs Logs are used to detect attacks, troubleshoot errors, prevent abuse, reconstruct incidents and preserve evidence. The legal basis is Article 6(1)(f) GDPR and, where relevant, Article 6(1)(c) GDPR. Log access is restricted to persons and providers who need it for their tasks. 7.3 Hosting architecture KulturCart operates workloads on infrastructure allocated to KulturCart, including infrastructure provided by Hetzner Online GmbH and dataforest GmbH/Avoro. The exact placement of a workload may change for security, capacity, continuity or migration reasons, while the applicable data-protection safeguards continue to apply. 7.4 Log retention Routine technical logs are retained only for the period necessary for operations and security, normally for a limited period measured in days or months. Relevant records may be retained longer where an incident, dispute or legal obligation requires preservation. 8. Cookies, local storage and consent management 8.1 Strictly necessary technologies KulturCart uses technologies necessary for functions explicitly requested by the user, such as session management, shopping carts, login, security, language selection, load distribution and consent storage. Device access that is strictly necessary is handled under § 25(2) TDDDG and the associated GDPR legal basis. 8.2 Optional technologies Analytics, advertising, cross-service measurement, personalisation or embedded third-party technologies that are not strictly necessary are activated only where an appropriate legal basis exists and, where required, after consent under § 25(1) TDDDG and Article 6(1)(a) GDPR. 8.3 Cookie and Similar Technologies Notice The separate Cookie and Similar Technologies Notice provides the current technical inventory, provider, purpose, duration and preference-management information. It must reflect the actual production configuration and may be updated more frequently than this Policy. 8.4 Withdrawal and settings Consent can be changed or withdrawn through the consent-management interface. Withdrawal applies prospectively. Blocking all cookies through browser settings may impair functions that depend on local storage or sessions. 9. Customer accounts and guest use 9.1 Registration When an account is created, KulturCart processes the information required to identify the account holder, authenticate access and provide account functions. Optional profile data is clearly distinguished from required information. 9.2 Guest checkout Where guest checkout is available, KulturCart processes order and contact data without creating a permanent customer account. Order records remain subject to contractual, accounting, fraud-prevention and statutory retention requirements. 9.3 Account preferences Users may manage addresses, communications, language and other preferences. Changes are logged where necessary to maintain security, evidence and correct order processing. 9.4 Account closure A request to close an account ends future account use but does not require immediate deletion of records that KulturCart or a vendor must retain for orders, invoices, fraud prevention, legal claims or other legal obligations. Remaining data is restricted and deleted or anonymised when the applicable purpose and retention period end. 10. Marketplace orders and contract formation 10.1 Checkout and order data KulturCart processes customer identity, contact, cart, product, vendor, price, payment, delivery and communication data to provide checkout, transmit the order, confirm the transaction and manage the order lifecycle. The legal basis is Article 6(1)(b) GDPR. 10.2 Order review and vendor acceptance The vendor receives the data necessary to assess availability, accept or reject the order, prepare the products and communicate material changes. KulturCart records order status, timestamps and decisions for performance, support, fraud prevention and evidence. 10.3 Order confirmations and records KulturCart and the vendor may send confirmations, receipts, invoices, delivery information and legally required notices. These are service messages and are not marketing merely because they use electronic communication. 10.4 Single- and multi-vendor transactions The current ordering model may restrict an order to a single vendor. If future functionality supports multiple vendors, data will be separated and disclosed only to each vendor to the extent necessary for that vendor's part of the transaction. 11. Disclosure to vendors and vendor responsibility 11.1 Necessary order disclosure KulturCart discloses to the relevant vendor the customer and order data required for sale, fulfilment, delivery or collection, customer service, returns, statutory warranty and compliance. Vendors must not use this data for unrelated purposes without their own lawful basis. 11.2 Vendor privacy information The vendor is responsible for providing any additional information required for its independent processing. KulturCart requires vendors to maintain appropriate confidentiality and security and may enforce vendor policies where misuse is identified. 11.3 No unrestricted customer-list transfer KulturCart does not provide vendors with unrestricted access to all marketplace users. Access is limited by role, vendor relationship, order context and system permissions. 11.4 Vendor changes or closure If a vendor changes ownership, closes or is suspended, KulturCart may restrict access and preserve or transfer only the data required for active orders, customer remedies, legal obligations and controlled business succession. 12. Payment processing 12.1 Payment data and providers Available payment methods are shown at checkout. Depending on the selected method, data is transmitted to the relevant payment provider. This may include customer identity, contact details, amount, currency, order reference, device information, risk data and payment status. 12.2 Stripe Connect Where Stripe is used, the relevant Stripe group entity processes data for payment acceptance, account connection, fraud prevention, compliance, payouts, disputes and related financial infrastructure. Stripe may act as controller, processor or both depending on the activity. Stripe's current privacy information and contractual terms apply to its own processing. 12.3 Authorisation, capture and refunds KulturCart may support payment authorisation before final stock confirmation and later capture, cancellation or refund. Transaction status and limited references are retained to reconcile orders, investigate failures and provide support. 12.4 Payment security Full payment credentials are ordinarily entered into or tokenised by the payment provider rather than stored by KulturCart. KulturCart may receive masked details, tokens, payment-method type, authentication results and fraud indicators. 12.5 Chargebacks and disputes Data may be shared among the customer, vendor, KulturCart, payment provider, banks and card schemes to investigate chargebacks, unauthorised payments, duplicate charges, refunds or payment disputes. The legal bases are contract performance, legal obligations and legitimate interests in preventing loss and preserving evidence. 13. Delivery, collection and logistics 13.1 Address and contact data For delivery or collection, KulturCart and the vendor process the recipient's name, address, telephone number, delivery instructions, time slot and order information. Only data reasonably necessary for the selected fulfilment method should be disclosed. 13.2 Carriers and delivery partners Where a carrier or delivery partner is used, the required data is transmitted for dispatch, tracking, contact, delivery evidence and problem resolution. The carrier may act as an independent controller for its transport obligations. 13.3 Proof of delivery and incidents Delivery status, signatures where appropriate, photographs where lawful and necessary, failed-delivery reasons and complaint evidence may be processed to establish performance, resolve disputes and protect against fraud. Excessive or unrelated evidence must not be collected. 13.4 Location data Precise device location is processed only when the user enables a location-dependent function and grants the required permission. Address-derived or approximate location may be used to display availability, delivery zones or nearby vendors. 14. Returns, refunds, warranty and complaints 14.1 Case handling KulturCart processes order, communication, evidence, product, payment and delivery data to route and support return, refund, withdrawal, warranty and complaint cases. The vendor remains responsible for its customer obligations as seller, while KulturCart may facilitate the workflow. 14.2 Evidence Customers and vendors may submit photographs, videos, documents or descriptions. Such evidence should be limited to what is necessary and should avoid showing unrelated people, documents or sensitive information. 14.3 Product safety and recalls Where a product may be unsafe, KulturCart may combine order, product, vendor and contact data to identify affected persons, restrict listings, communicate warnings, coordinate recall remedies and cooperate with authorities. Processing is based on legal obligations and overriding safety interests. 14.4 Retention of case records Complaint and remedy records are retained for the duration needed to complete the case, demonstrate compliance, handle payment disputes and protect legal claims. They may be linked to the underlying order and invoice retention period. 15. Customer support and communications 15.1 Support channels When a person contacts KulturCart by email, telephone, form, chat or another support channel, KulturCart processes contact information, message content, account or order references, attachments and service metadata to respond and document the case. 15.2 Self-hosted support systems KulturCart may operate support and communication software such as FreeScout or LiveHelperChat on KulturCart-controlled infrastructure. The software publisher is not automatically a recipient merely because the software is installed; access by external support personnel is permitted only where contractually and technically controlled. 15.3 Call and conversation records Calls are not recorded unless the participant is informed in advance and a lawful basis applies. Written summaries or case notes may be created to document commitments, troubleshooting or complaints. 15.4 Service communications KulturCart may send account, security, order, policy, support and operational notices where necessary for the requested service, legal duties or legitimate interests. These messages are distinct from optional advertising. 16. Reviews, comments and other user content 16.1 Publication When a user submits a review, rating, comment, question, image or other public contribution, the chosen display name, content, date and related product or vendor may be visible to others. The user should not publish personal data that is unnecessary for the contribution. 16.2 Moderation KulturCart processes content, account information, reports and moderation records to apply the Terms, Community Standards and law. Reporters and affected users may receive information about decisions to the extent required or permitted. 16.3 Authenticity and fraud prevention Order and account information may be used to label verified purchases, detect manipulated reviews, prevent duplicate accounts and protect marketplace integrity. Review analysis does not authorise unrelated profiling. 16.4 Content licence and deletion The rights to use user content are governed by the Terms. Deletion of an account does not necessarily remove content that must remain to preserve discussion context, evidence or legal claims; where appropriate, content is deleted or dissociated from the account. 17. Newsletters, marketing and notifications 17.1 Newsletter consent Promotional newsletters are sent on the basis of consent unless another lawful direct-marketing rule applies. Subscription and confirmation records are retained to demonstrate the request and consent. Unsubscribe links or equivalent controls are provided. 17.2 Existing-customer marketing Where legally permitted, KulturCart may inform existing customers about similar KulturCart services on the basis of legitimate interests and applicable direct-marketing law. The recipient may object at any time without incurring more than the ordinary transmission cost. 17.3 Vendor and partner marketing Marketing communications to business contacts are assessed separately and are not sent merely because contact details appear in a register or website. KulturCart records objections and suppression preferences. 17.4 Push and in-app notifications Push or in-app notifications are used only where the device, browser or application supports them and the required permission has been granted. Transactional and security notifications may remain necessary even where promotional notifications are disabled. 17.5 Advertising measurement Advertising pixels, retargeting and cross-service measurement are not treated as automatically active. If such technologies are enabled, they are disclosed in the current Cookie Notice and activated only with the required consent. 18. Analytics, service improvement and research 18.1 Operational analytics KulturCart analyses aggregated and pseudonymised usage, performance, conversion, error and support data to understand service quality, improve workflows and allocate capacity. Whenever possible, reporting is performed without identifying individual users. 18.2 Self-hosted analytics KulturCart may use self-hosted analytics software such as Matomo. The applicable configuration determines whether cookies, identifiers or consent are required. The live Cookie Notice and consent interface must describe the actual configuration. 18.3 Experiments and feature evaluation KulturCart may compare feature variants or measure implementation outcomes. Experiments must be proportionate, avoid sensitive inferences, and must not produce legal or similarly significant effects without a separate lawful basis and appropriate safeguards. 18.4 Surveys and research Participation in surveys or interviews is voluntary unless information is required to fulfil a support or contractual request. Research responses may be aggregated or anonymised. Separate consent is obtained where a testimonial or identifiable quotation will be published. 19. Location, maps and local availability 19.1 Address-based localisation KulturCart may convert a delivery or store address into geographic coordinates to determine delivery zones, nearby vendors, distance or service availability. This is necessary for the requested local marketplace function. 19.2 Device location Browser or device location is processed only after the user grants permission. Refusing precise location does not prevent use of address-based functions where an address can be entered manually. 19.3 Map providers KulturCart aims to use KulturCart-controlled or self-hosted location infrastructure where practicable. If an external map, geocoding or content provider is introduced, its identity, data flows and any consent requirement will be disclosed before activation. 19.4 Location retention Location information is retained only for the relevant order, store configuration, fraud-prevention or service purpose. Precise location histories are not created unless a specific feature clearly requires and discloses them. 20. Social media and embedded third-party content 20.1 KulturCart profiles When a person interacts with KulturCart through a social network, both the network operator and KulturCart may process profile, message, reaction and usage data under their respective responsibilities. The network's privacy information applies to its own platform processing. 20.2 Embedded content Videos, maps, social posts, fonts or other external content can transmit technical data to the provider when loaded. Non-essential embeds should be blocked until consent or opened through a user-initiated link where required. 20.3 No blanket activation statement This Policy does not claim that Meta, Google advertising, Google Maps or another optional service is active merely because it may be technically available. The current Cookie Notice and live consent configuration are authoritative for optional website integrations. 20.4 Direct links A simple link to a third-party website does not by itself transfer data to that provider before the user activates the link, apart from ordinary display of the link by KulturCart's server. 21. Vendor onboarding, trader verification and business administration 21.1 Application and verification data KulturCart processes vendor legal name, trading name, address, representatives, contact information, register and tax details, licences, identity evidence, bank-account confirmation, selected services and risk information to assess onboarding, establish the contract and maintain marketplace integrity. 21.2 Legal bases Processing is based on pre-contract steps and contract performance, legal obligations, and legitimate interests in verifying counterparties, preventing fraud, protecting customers and documenting authority. KulturCart does not collect verification documents that are unnecessary for the relevant risk and legal context. 21.3 Ongoing accuracy Vendors must keep their information current. KulturCart may request renewed evidence after a material change, risk event, expiry, complaint or legal update. Verification history is retained to show how a vendor was admitted and monitored. 21.4 Bank and payout information Bank information is processed to confirm billing or payout instructions, collect agreed fees and prevent misdirection. Full bank details are restricted to personnel and providers who need them for the relevant financial process. 21.5 Business contacts and employees Contact data of directors, owners, authorised representatives, store managers, cashiers and staff is processed according to their role. The vendor is responsible for providing its personnel with any required information about the disclosure to KulturCart. 22. POS, TSE and fiscalisation data 22.1 POS users and cashiers Where KulturCart POS is used, KulturCart processes user identifiers, roles, PIN-related authentication data in protected form, shift and transaction references, cash events, device assignments and audit records to provide secure point-of-sale functions. 22.2 Transactions and receipts POS records may include products, quantities, taxes, payment type, timestamps, receipt references, returns, discounts and customer data where the vendor enters or links it. Vendors should avoid entering unnecessary customer information into fiscal or transaction records. 22.3 TSE and fiskaly Where Cloud-TSE or related fiscalisation services are activated, required device, client, transaction, signature, receipt, export and status data is processed through fiskaly GmbH and KulturCart systems. Roles depend on the specific function and applicable agreements. 22.4 DSFinV-K and tax exports KulturCart may generate, store or transmit DSFinV-K and related export files for the vendor. The vendor remains responsible for its tax and retention duties. KulturCart may retain technical evidence of creation, delivery and integrity. 22.5 Fiscal retention Fiscal, accounting and receipt data is retained according to applicable tax and commercial-law requirements, contractual obligations and the vendor's documented instructions where KulturCart acts as processor. 23. Fraud prevention, security and platform integrity 23.1 Risk signals KulturCart uses account, device, IP, order, payment, vendor, complaint and behavioural signals to identify account takeover, payment fraud, suspicious orders, counterfeit or prohibited listings, review manipulation, circumvention and other misuse. 23.2 Protective measures Measures may include authentication challenges, rate limits, manual review, temporary holds, access restriction, listing suspension, evidence preservation and referral to payment providers or authorities. Measures are proportionate to the risk and are reviewed where appropriate. 23.3 Legal basis Processing is based on legitimate interests in protecting users, vendors, KulturCart and payment systems, and on legal obligations where applicable. Security logs may be retained longer when linked to an incident or claim. 23.4 Confidentiality of detection methods KulturCart may withhold technical details of fraud or security detection where disclosure would enable circumvention or harm other persons. This does not remove applicable rights to meaningful information and human review. 24. Legal compliance, reporting and claims 24.1 Authority and legal requests KulturCart may process and disclose data to courts, regulators, tax authorities, law-enforcement bodies, market-surveillance authorities and other competent bodies where required by law or necessary to establish, exercise or defend legal claims. Requests are assessed for authority, scope and proportionality. 24.2 Illegal content and policy reports Reporter, affected-user, listing, communication and evidence data is processed to assess notices, take interim measures, issue reasons, handle complaints and preserve records under the applicable reporting and enforcement procedures. 24.3 Intellectual-property reports Rights-holder notices, evidence, vendor responses and decision records are processed to investigate alleged infringement, protect legitimate content and handle repeat-abuse or restoration procedures. 24.4 Product-safety reports Incident, product, order, customer, vendor, authority and remedy data is processed to assess hazards, warn affected persons, conduct recalls and document compliance. 24.5 Legal claims and insurance Relevant contracts, orders, communications, logs and evidence may be retained and disclosed to advisers, insurers, debt-collection providers or courts where necessary for claims or defence. 25. Applicants, suppliers, partners and other business contacts 25.1 Applications If KulturCart receives job, internship or contractor applications, it processes identity, contact, qualifications, employment history, communications and interview information to assess the application. A more specific applicant notice may be provided where recruitment becomes a regular activity. 25.2 Suppliers and service providers KulturCart processes contact, contract, billing, support, access and compliance information of suppliers and their personnel to manage the business relationship and secure system access. 25.3 Business development and partnerships Contact and communication data may be processed to evaluate partnerships, integrations, referrals, events or other business opportunities. Unsolicited marketing is not justified merely because a professional address is publicly available. 25.4 Retention Unsuccessful application or proposal records are deleted after the relevant decision and limitation period unless consent or another lawful basis supports longer retention. 26. Recipients and service providers 26.1 Need-to-know principle Personal data is disclosed only where necessary for a defined purpose and under an appropriate legal arrangement. Access is limited by role, system permissions and confidentiality obligations. 26.2 Hosting and infrastructure Current infrastructure recipients may include Hetzner Online GmbH and dataforest GmbH/Avoro for hosting, network, storage, backup or related infrastructure assigned to KulturCart. 26.3 Payments and fiscalisation Stripe group entities may receive data for payments and connected accounts. fiskaly GmbH may receive data for Cloud-TSE, fiscalisation and related export functions where activated. 26.4 Internal business systems KulturCart may use self-hosted CS-Cart, Dolibarr, Nextcloud, FreeScout, LiveHelperChat, Matomo and similar software. Installation of software on KulturCart-controlled infrastructure does not by itself make the publisher a recipient. Google Workspace or Google Drive may be used for selected legal, administrative and collaboration records under access controls. 26.5 Professional and public recipients Data may be disclosed to advisers, auditors, insurers, banks, debt-collection providers, postal or delivery services, authorities and courts where the purpose and legal basis require it. 26.6 Current register Appendix B lists the principal current provider categories and known providers. The list may change as infrastructure and services evolve. Material changes are reflected in the current Policy or a more specific notice. 27. International data transfers 27.1 EEA preference KulturCart prefers processing in Germany or the European Economic Area where reasonably practicable. A provider's group structure, support access or technical routing may nevertheless involve another country. 27.2 Adequacy decisions Where the European Commission has adopted an adequacy decision, data may be transferred on that basis within its scope, including transfers to participating organisations under the EU-U.S. Data Privacy Framework where applicable. 27.3 Standard Contractual Clauses Where no adequacy decision applies, KulturCart uses appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with transfer assessments and supplementary measures where required. 27.4 Provider-specific safeguards Payment, collaboration and other global providers may rely on adequacy decisions, the Data Privacy Framework, Standard Contractual Clauses or a combination of mechanisms. Their current privacy and transfer documentation applies to their processing. 27.5 Copies and information Information about the relevant safeguard may be requested from KulturCart, subject to protection of confidential and third-party information. 28. Retention, deletion and anonymisation 28.1 Purpose limitation KulturCart retains personal data only as long as necessary for the relevant purpose, contract, legal obligation, security requirement or claim. Different records therefore have different retention periods. 28.2 Commercial and tax records Invoices, accounting records, transaction evidence and business correspondence are retained in accordance with applicable German commercial and tax rules. Depending on the record type, statutory periods commonly range from six to ten years; invoice retention is generally eight years under current VAT rules. 28.3 Accounts and orders Account data is retained during the active relationship. Order records are retained for performance, customer rights, accounting, fraud prevention and claims. Optional profile data may be deleted earlier where it is no longer needed. 28.4 Support, complaints and security Routine support data is retained for the case and a proportionate follow-up period. Complaint, enforcement, fraud and security records may be retained for the applicable limitation period or longer where a proceeding remains open. 28.5 Backups Deleted information may remain in protected backups until overwritten through the ordinary backup cycle. Backup data is isolated from routine use and restored only for continuity, security or legal reasons. 28.6 Anonymisation Where information is genuinely anonymised so that a person cannot reasonably be identified, it may be retained for statistics, security, research or service improvement without being personal data. 29. Technical and organisational security 29.1 Risk-based safeguards KulturCart applies safeguards appropriate to the risk, including access control, role separation, authentication, encryption in transit where appropriate, secure configuration, patching, backups, logging, incident response and confidentiality obligations. 29.2 Access management Access is granted according to role and need. Privileged access is restricted, reviewed and logged where appropriate. Vendor and customer access is separated by tenant, store, account and permission controls. 29.3 Development and operations Changes to production systems are tested and controlled according to risk. Development, staging and production data are separated where practicable. Real personal data is not used for testing unless necessary and protected. 29.4 User responsibilities Users and vendors must protect credentials, devices and access codes, maintain accurate permissions and notify KulturCart promptly of suspected compromise. Security advice is provided in the applicable account and vendor policies. 29.5 No absolute guarantee No system can eliminate every risk. KulturCart monitors and improves safeguards and responds to incidents, but does not represent that unauthorised access can never occur. 30. Data-subject rights 30.1 Access and information Subject to the legal conditions, a person may request confirmation whether KulturCart processes personal data and obtain access and the information required by Article 15 GDPR. 30.2 Rectification and completion Incorrect personal data may be corrected and incomplete data completed under Article 16 GDPR. Some account details can be updated directly through account settings. 30.3 Erasure and restriction A person may request erasure under Article 17 GDPR or restriction under Article 18 GDPR where the legal conditions are met. These rights do not override retention duties, freedom of expression, public-interest processing or legal claims. 30.4 Data portability Where processing is based on consent or contract and carried out by automated means, the person may request the data provided to KulturCart in a structured, commonly used and machine-readable format under Article 20 GDPR. 30.5 Objection A person may object under Article 21 GDPR to processing based on legitimate interests for reasons arising from the person's particular situation. Processing for direct marketing may be objected to at any time. 30.6 Withdrawal of consent Consent may be withdrawn for the future through the relevant preference control or by contacting KulturCart. The withdrawal does not affect earlier lawful processing. 30.7 Identity verification and response KulturCart may request proportionate information to verify identity and prevent disclosure to an unauthorised person. Requests are answered within the statutory period, subject to permitted extensions for complexity or volume. 31. Automated decisions, profiling and personalisation 31.1 No undisclosed significant decisions KulturCart does not currently make solely automated decisions producing legal or similarly significant effects on customers without human involvement, unless a specific process, legal basis and safeguards are separately disclosed. 31.2 Fraud and risk scoring Automated signals may prioritise orders, accounts, payments or listings for review or apply temporary protective controls. Material adverse measures are reviewed under the applicable enforcement and complaint procedures where required. 31.3 Recommendations and ranking Recommendation and ranking functions may use location, availability, relevance, popularity, quality, delivery conditions, user preferences and sponsored status. These functions generally organise content and do not constitute a legal decision about the user. 31.4 Marketing profiles Cross-service advertising or detailed marketing profiles are created only where the required consent and disclosure exist. Users may withdraw consent or object to direct marketing. 32. Children and legal capacity 32.1 Service audience KulturCart is not designed as a children's service. Purchases and accounts must be created by a person with the legal capacity or required representative authority for the relevant transaction. 32.2 Consent by children Where consent is the legal basis for an online service offered directly to a child, the age and parental-authorisation requirements of Article 8 GDPR and applicable German law are observed. 32.3 Removal and protection If KulturCart learns that personal data of a child was collected without an adequate legal basis or required authorisation, it will restrict and delete the data as appropriate, while preserving records required for safety, orders or legal claims. 33. Whether data must be provided 33.1 Contract-required information Certain information is necessary to create an account, place and fulfil an order, deliver products, process payment or provide requested support. Without it, the relevant service or contract may not be possible. 33.2 Legally required information Vendor verification, tax, fiscalisation, product-safety and authority requirements may make specific information mandatory. The relevant form or request identifies the required fields. 33.3 Optional information Optional profile, marketing, survey, precise-location and similar data can generally be withheld without affecting core marketplace use, although the optional feature may then be unavailable. 34. Supervisory authority and complaints 34.1 Right to complain A data subject has the right to lodge a complaint with a supervisory authority under Article 77 GDPR, particularly in the Member State of habitual residence, place of work or the alleged infringement. 34.2 Competent authority for KulturCart For a private-sector controller established in Bavaria, the competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, poststelle@lda.bayern.de. The authority provides an online complaint form. 34.3 Contacting KulturCart first A complaint to an authority is not conditional on contacting KulturCart first. KulturCart nevertheless welcomes the opportunity to investigate and resolve a concern promptly through info@kulturcart.de. 35. Changes, versioning and contact 35.1 Policy changes KulturCart updates this Policy where processing, providers, technology, law or organisational responsibilities materially change. The current version, effective date and document ID are published with the Policy. 35.2 Notice of material changes Where appropriate, material changes are communicated through the website, account, email or other suitable channel before they take effect. A new legal basis or consent is obtained where required; continued use is not treated as consent to processing that legally requires affirmative consent. 35.3 Archived versions Superseded policies are retained internally with their effective periods so that KulturCart can identify the information applicable to a historical processing event. 35.4 Contact Questions, rights requests, objections and privacy concerns may be submitted to KulturCart - Ibrahim Lawal, Ringstraße 22, 84347 Pfarrkirchen, Germany, email info@kulturcart.de, telephone +49 8561 9080851. Appendix A - Processing activity matrix Activity Main data Purpose / legal basis Typical recipients Website delivery and security IP, request, device, log and error data Technical delivery, security and stability; Art. 6(1)(f) GDPR Hosting and infrastructure providers Accounts and authentication Identity, contact, credential, role and login data Account contract and security; Art. 6(1)(b), (f) GDPR Hosting, authentication and support systems Marketplace orders Customer, vendor, product, price, payment, delivery and communication data Contract facilitation and order management; Art. 6(1)(b) GDPR Relevant vendor, payment provider, carrier Payments Transaction reference, amount, status, risk and limited payment details Payment, fraud prevention and legal obligations; Art. 6(1)(b), (c), (f) GDPR Stripe or the selected payment provider, banks and schemes Support and complaints Contact, messages, attachments, account/order references Support, contract, legitimate interests and claims Relevant vendor, support systems, advisers where necessary Vendor onboarding Business, representative, register, tax, bank and verification data Contract, legal obligations and marketplace integrity Verification sources, payment providers, advisers and authorities where necessary POS and TSE Cashier, role, device, transaction, receipt, signature and export data POS contract, fiscal duties, security and vendor instructions Vendor, fiskaly, infrastructure providers and authorities where required Marketing and optional analytics Contact, consent, preferences, pseudonymous usage and campaign data Consent or legally permitted direct marketing Consent and communication provider; optional provider disclosed in Cookie Notice Reports and enforcement Reporter, affected user, listing, evidence, decision and complaint data Legal compliance, platform safety and claims Affected parties, authorities, advisers and providers as necessary Appendix B - Principal provider and recipient register Provider / category Function Location / transfer context Role notes Hetzner Online GmbH Hosting, compute, storage, network and related infrastructure Germany / EEA Processor for allocated KulturCart workloads dataforest GmbH / Avoro Hosting and infrastructure for allocated self-hosted workloads Germany / EEA Processor for allocated KulturCart workloads Stripe group entity, including Stripe Payments Europe Limited where applicable Payments, connected accounts, payouts, risk, disputes and financial infrastructure EEA and global group processing subject to current safeguards Controller, processor or both depending on activity fiskaly GmbH Cloud-TSE, fiscalisation, signatures, receipt and DSFinV-K functions where activated Austria / EEA Processor or independent provider depending on function and agreement Google Workspace / Google Drive where used Selected legal, administrative and collaboration records EEA and global processing under Google's current safeguards Processor and/or independent controller depending on service Carriers and delivery partners Dispatch, tracking, delivery, handover and incident handling According to selected carrier Often independent controller for transport duties Self-hosted software: CS-Cart, Dolibarr, Nextcloud, FreeScout, LiveHelperChat, Matomo and similar Marketplace, ERP, cloud, support, chat and analytics on KulturCart-controlled infrastructure Hosting location of the relevant KulturCart workload Publisher is not a recipient merely because software is installed; external access requires a separate basis Advisers, insurers, banks, auditors, authorities and courts Advice, claims, financial processing and legal compliance According to recipient and legal requirement Independent controller or professional recipient Appendix C - Retention matrix Record category Typical retention approach Reason Server and security logs Usually days or months; longer for incidents Operations, security and evidence Account profile Active relationship plus a limited closure period Service, fraud prevention and claims Orders, invoices and accounting records Applicable commercial and tax periods, commonly six to ten years; invoices generally eight years HGB, AO, UStG and claims Payment and refund references Order/accounting period plus dispute requirements Reconciliation, chargebacks and fraud Support and routine communications Case duration plus proportionate follow-up period Service quality and evidence Complaints, enforcement and safety cases Case duration plus limitation, regulatory or recall period Compliance, restoration and claims Vendor verification and contracts Relationship plus legal retention and limitation periods Counterparty verification and contractual evidence POS/TSE and fiscal exports Statutory tax/fiscal period or vendor instruction under the DPA Fiscal compliance and evidence Consent and objection records As long as needed to demonstrate consent, withdrawal or suppression Accountability and marketing compliance Backups Ordinary protected overwrite cycle Continuity and disaster recovery Appendix D - Role allocation matrix Processing context KulturCart role Other party role Key consequence Marketplace platform operation, account security and governance Independent controller Vendor or user may be a separate controller for own purposes Each party provides information for its own processing Customer sale, fulfilment, returns and statutory warranty Marketplace facilitator for its functions Vendor generally independent controller and seller Customer claims and vendor processing are primarily directed to vendor Vendor-directed data functions expressly covered by the DPA Processor Vendor controller Documented instructions and Art. 28 GDPR terms apply Payment processing Controller and/or processor for limited platform functions Payment provider controller, processor or both Provider's current privacy information applies Carrier delivery Controller for marketplace coordination Carrier often independent controller Only necessary delivery data is disclosed Cloud-TSE and fiscalisation Controller or processor depending on service Vendor controller for its fiscal records; fiskaly processor/provider Annex 1 and DPA allocate activity-specific duties Optional jointly designed campaign or integration To be assessed Partner role to be assessed Joint-controller arrangement is documented if purposes and essential means are jointly determined Appendix E - Rights and request matrix Request Information to provide Possible limitation Access Identity, account/contact reference and desired scope Rights of others, legal privilege and excessive requests Rectification Incorrect data and correct replacement Historical records may be preserved with correction note Erasure Data or context to be erased Legal retention, claims, freedom of expression and public interest Restriction Processing and reason for restriction Storage and permitted legal processing may continue Portability Account and relevant contract-based automated data Applies only under Art. 20 GDPR conditions Objection Processing and particular situation; no reason needed for direct marketing Compelling legitimate grounds or legal claims may override non-marketing objection Consent withdrawal Consent or technology to withdraw Prospective only; prior lawful processing remains valid Complaint Description, dates, account/order and supporting evidence May be referred to vendor or another controller where appropriate