Privacy Policy
How KulturCart collects, uses, shares, protects, and retains personal data, including your rights and contact options.
KulturCart Privacy Policy
Version 1.0 · 12 August 2026 · KC-LEGAL-03-EN-1.0
Table of Contents
- 1. Scope, purpose and status of this Privacy Policy
- 2. Controller and privacy contact
- 3. Allocation of roles in the KulturCart marketplace
- 4. General processing principles and legal bases
- 5. Sources of personal data
- 6. Categories of personal data
- 7. Website access, server logs and technical delivery
- 8. Cookies, local storage and consent management
- 9. Customer accounts and guest use
- 10. Marketplace orders and contract formation
- 11. Disclosure to vendors and vendor responsibility
- 12. Payment processing
- 13. Delivery, collection and logistics
- 14. Returns, refunds, warranty and complaints
- 15. Customer support and communications
- 16. Reviews, comments and other user content
- 17. Newsletters, marketing and notifications
- 18. Analytics, service improvement and research
- 19. Location, maps and local availability
- 20. Social media and embedded third-party content
- 21. Vendor onboarding, trader verification and business administration
- 22. POS, TSE and fiscalisation data
- 23. Fraud prevention, security and platform integrity
- 24. Legal compliance, reporting and claims
- 25. Applicants, suppliers, partners and other business contacts
- 26. Recipients and service providers
- 27. International data transfers
- 28. Retention, deletion and anonymisation
- 29. Technical and organisational security
- 30. Data-subject rights
- 31. Automated decisions, profiling and personalisation
- 32. Children and legal capacity
- 33. Whether data must be provided
- 34. Supervisory authority and complaints
- 35. Changes, versioning and contact
- Appendix A - Processing activity matrix
- Appendix B - Principal provider and recipient register
- Appendix C - Retention matrix
- Appendix D - Role allocation matrix
- Appendix E - Rights and request matrix
1. Scope, purpose and status of this Privacy Policy
1.1 Services and persons covered
This Privacy Policy explains how KulturCart processes personal data in connection with kulturcart.de, related marketplace functions, customer and vendor accounts, support channels, KulturCart POS and fiscalisation services where relevant, and other KulturCart services that expressly refer to this Policy. It applies to visitors, registered users, customers, vendor representatives, cashiers and other persons whose data is processed through these services.
Separate notices may apply to a specific processing context, such as a vendor contract, a job application, a security report or a particular campaign. Where a more specific notice applies, it supplements this Policy and takes precedence for the processing described in that notice.
1.2 Purpose of the information
The purpose of this Policy is to provide transparent information under Articles 12, 13 and 14 GDPR about the categories of personal data processed, the purposes and legal bases, recipients, transfers, retention, security, and the rights of data subjects. It is not intended to create consent where consent is not the applicable legal basis.
1.3 Relationship to other KulturCart documents
The General Terms and Conditions and Marketplace Terms of Use govern use of the marketplace. Vendor contractual documents govern the commercial relationship with vendors. The Cookie and Similar Technologies Notice describes device storage, access and optional tracking technologies in greater technical detail. The Customer and Vendor Policies allocate operational responsibilities. These documents should be read together where relevant.
1.4 Meaning of personal data and processing
Personal data means information relating to an identified or identifiable natural person. Processing includes collection, recording, organisation, storage, adaptation, consultation, disclosure, restriction, deletion and other use of personal data. Anonymous information that cannot reasonably be linked to a person is not personal data.
2. Controller and privacy contact
2.1 Controller
The controller for the processing described as KulturCart's own processing in this Policy is KulturCart - Ibrahim Lawal, trading as 'KulturCart', Ringstraße 22, 84347 Pfarrkirchen, Germany.
2.2 Contact channels
Privacy questions, requests and objections may be sent to info@kulturcart.de or by post to the business address above. Please identify the relevant account, order or interaction so that KulturCart can locate the information without collecting unnecessary additional data.
2.3 Data protection officer
KulturCart has not appointed and does not currently publish a separate data protection officer because the statutory conditions requiring an appointment have not been determined to apply to the present organisation. If an appointment becomes necessary, the contact details will be added to this Policy without delay.
2.4 Authoritative language
The German Privacy Policy is the authoritative version. The English text is a convenience translation. Privacy rights may be exercised in German or English.
3. Allocation of roles in the KulturCart marketplace
3.1 KulturCart as independent controller
KulturCart acts as an independent controller where it determines the purposes and essential means of processing for operating, securing and improving the marketplace; managing customer and vendor accounts; billing KulturCart services; fraud prevention; legal compliance; platform governance; complaint handling; and the establishment, exercise or defence of legal claims.
3.2 Vendors as independent controllers
A vendor ordinarily sells products in its own name and on its own account. For order fulfilment, delivery, statutory warranty, customer communication and its own legal obligations, the vendor generally acts as an independent controller. The vendor's identity and contact information are shown in the relevant offer, order or vendor store. Questions concerning a vendor's own processing may therefore need to be directed to that vendor.
3.3 Processor activities
Where KulturCart processes clearly defined personal data only on a vendor's documented instructions, the roles and obligations are governed by the applicable Data Processing Agreement. A software function or shared system does not by itself determine the legal role; the actual purpose and decision-making authority are decisive.
3.4 Payment and other independent providers
Payment providers, carriers, fiscalisation providers and other regulated or independent service providers may act as separate controllers, processors or both depending on the activity. Their own privacy information applies to processing for which they determine the purposes and means.
3.5 No automatic joint controllership
Joint controllership is not assumed merely because parties exchange data. If KulturCart and another party jointly determine purposes and essential means for a specific processing activity, the arrangement and the essence of the allocation will be documented and communicated as required.
4. General processing principles and legal bases
4.1 Performance of a contract and pre-contract steps
KulturCart processes data under Article 6(1)(b) GDPR where necessary to create or manage an account, provide requested marketplace functions, facilitate an order, respond to a pre-contract enquiry, provide support, or perform another contract with the data subject.
4.2 Legal obligations
Processing under Article 6(1)(c) GDPR may be necessary for tax and accounting records, trader verification, product-safety cooperation, fiscal records, fraud or money-laundering controls where applicable, statutory information duties, authority requests and other binding legal obligations.
4.3 Legitimate interests
Under Article 6(1)(f) GDPR, KulturCart may process data for secure and reliable platform operation, prevention of misuse, internal administration, service improvement, direct marketing to existing customers where legally permitted, protection of users and vendors, evidence, and legal claims. KulturCart balances these interests against the rights and expectations of affected persons.
4.4 Consent
Where processing is based on consent under Article 6(1)(a) GDPR, the request will be specific, informed and voluntary. Consent may be withdrawn at any time for the future. Withdrawing consent does not affect processing already lawfully carried out before withdrawal.
4.5 Special categories and criminal-offence data
KulturCart does not ordinarily request special categories of data under Article 9 GDPR. If a person voluntarily submits sensitive information in a support, complaint, accessibility or safety context, KulturCart will process it only where necessary and supported by an appropriate legal basis. Data relating to criminal convictions or offences is processed only where permitted by Article 10 GDPR and applicable law.
5. Sources of personal data
5.1 Data provided directly
KulturCart receives data when a person visits the website, creates an account, places an order, contacts support, communicates with a vendor, subscribes to messages, submits a review, reports content, exercises a right, applies to become a vendor or otherwise interacts with KulturCart.
5.2 Data provided by vendors and service providers
Vendors may provide order status, fulfilment, delivery, return, complaint and product-safety information. Payment providers may provide transaction status, risk indicators and limited payment references. Carriers may provide tracking and delivery events. Fiscalisation providers may provide TSE and export status. Support and hosting providers may generate technical records.
5.3 Automatically generated data
When the services are used, servers and applications generate IP addresses, timestamps, request paths, device and browser information, session identifiers, authentication events, error reports, performance data and security logs. Optional analytics or advertising data is collected only in accordance with the Cookie Notice and the applicable consent settings.
5.4 Public and official sources
For vendor onboarding, safety, fraud and compliance purposes, KulturCart may obtain data from public company registers, tax or VAT verification services, sanctions lists, product-safety portals, official notices, public websites and other lawful sources.
5.5 Data received from another person
A customer may provide a recipient's name, address or telephone number for delivery, or a business may provide employee and representative details. The person providing the data must be authorised to do so and should inform the affected person where appropriate.
6. Categories of personal data
6.1 Identity and contact data
This may include name, title, date of birth where legally relevant, postal address, delivery address, email address, telephone number and preferred language.
6.2 Account and authentication data
This may include account identifier, login credentials in protected form, roles, permissions, user groups, multi-factor or verification information, login history, security events and account preferences.
6.3 Order, transaction and payment data
This may include products, quantities, prices, vendor, order number, payment method, payment status, refund information, billing data, delivery or collection details, transaction references and related communications. KulturCart does not ordinarily store full card numbers where a payment provider processes them directly.
6.4 Content and communication data
This includes messages, support tickets, comments, reviews, uploaded files, complaint records, report submissions, call notes and other content a person sends or publishes.
6.5 Technical and usage data
This includes IP address, user-agent, device and browser data, identifiers, session information, page and feature usage, diagnostic data, errors, performance measurements and consent records.
6.6 Vendor, staff and POS data
This may include business and register information, authorised representatives, cashiers, employee identifiers, role and access data, POS transactions, TSE assignments, receipts, cash logs, audit records and DSFinV-K-related information.
7. Website access, server logs and technical delivery
7.1 Server requests
When a page or application function is accessed, the hosting environment processes the IP address, date and time, requested resource, referrer where transmitted, browser and operating-system information, response status and transferred data volume. This is technically necessary to deliver content and maintain service stability.
7.2 Security and diagnostic logs
Logs are used to detect attacks, troubleshoot errors, prevent abuse, reconstruct incidents and preserve evidence. The legal basis is Article 6(1)(f) GDPR and, where relevant, Article 6(1)(c) GDPR. Log access is restricted to persons and providers who need it for their tasks.
7.3 Hosting architecture
KulturCart operates workloads on infrastructure allocated to KulturCart, including infrastructure provided by Hetzner Online GmbH and dataforest GmbH/Avoro. The exact placement of a workload may change for security, capacity, continuity or migration reasons, while the applicable data-protection safeguards continue to apply.
7.4 Log retention
Routine technical logs are retained only for the period necessary for operations and security, normally for a limited period measured in days or months. Relevant records may be retained longer where an incident, dispute or legal obligation requires preservation.
8. Cookies, local storage and consent management
8.1 Strictly necessary technologies
KulturCart uses technologies necessary for functions explicitly requested by the user, such as session management, shopping carts, login, security, language selection, load distribution and consent storage. Device access that is strictly necessary is handled under § 25(2) TDDDG and the associated GDPR legal basis.
8.2 Optional technologies
Analytics, advertising, cross-service measurement, personalisation or embedded third-party technologies that are not strictly necessary are activated only where an appropriate legal basis exists and, where required, after consent under § 25(1) TDDDG and Article 6(1)(a) GDPR.
8.3 Cookie and Similar Technologies Notice
The separate Cookie and Similar Technologies Notice provides the current technical inventory, provider, purpose, duration and preference-management information. It must reflect the actual production configuration and may be updated more frequently than this Policy.
8.4 Withdrawal and settings
Consent can be changed or withdrawn through the consent-management interface. Withdrawal applies prospectively. Blocking all cookies through browser settings may impair functions that depend on local storage or sessions.
9. Customer accounts and guest use
9.1 Registration
When an account is created, KulturCart processes the information required to identify the account holder, authenticate access and provide account functions. Optional profile data is clearly distinguished from required information.
9.2 Guest checkout
Where guest checkout is available, KulturCart processes order and contact data without creating a permanent customer account. Order records remain subject to contractual, accounting, fraud-prevention and statutory retention requirements.
9.3 Account preferences
Users may manage addresses, communications, language and other preferences. Changes are logged where necessary to maintain security, evidence and correct order processing.
9.4 Account closure
A request to close an account ends future account use but does not require immediate deletion of records that KulturCart or a vendor must retain for orders, invoices, fraud prevention, legal claims or other legal obligations. Remaining data is restricted and deleted or anonymised when the applicable purpose and retention period end.
10. Marketplace orders and contract formation
10.1 Checkout and order data
KulturCart processes customer identity, contact, cart, product, vendor, price, payment, delivery and communication data to provide checkout, transmit the order, confirm the transaction and manage the order lifecycle. The legal basis is Article 6(1)(b) GDPR.
10.2 Order review and vendor acceptance
The vendor receives the data necessary to assess availability, accept or reject the order, prepare the products and communicate material changes. KulturCart records order status, timestamps and decisions for performance, support, fraud prevention and evidence.
10.3 Order confirmations and records
KulturCart and the vendor may send confirmations, receipts, invoices, delivery information and legally required notices. These are service messages and are not marketing merely because they use electronic communication.
10.4 Single- and multi-vendor transactions
The current ordering model may restrict an order to a single vendor. If future functionality supports multiple vendors, data will be separated and disclosed only to each vendor to the extent necessary for that vendor's part of the transaction.
11. Disclosure to vendors and vendor responsibility
11.1 Necessary order disclosure
KulturCart discloses to the relevant vendor the customer and order data required for sale, fulfilment, delivery or collection, customer service, returns, statutory warranty and compliance. Vendors must not use this data for unrelated purposes without their own lawful basis.
11.2 Vendor privacy information
The vendor is responsible for providing any additional information required for its independent processing. KulturCart requires vendors to maintain appropriate confidentiality and security and may enforce vendor policies where misuse is identified.
11.3 No unrestricted customer-list transfer
KulturCart does not provide vendors with unrestricted access to all marketplace users. Access is limited by role, vendor relationship, order context and system permissions.
11.4 Vendor changes or closure
If a vendor changes ownership, closes or is suspended, KulturCart may restrict access and preserve or transfer only the data required for active orders, customer remedies, legal obligations and controlled business succession.
12. Payment processing
12.1 Payment data and providers
Available payment methods are shown at checkout. Depending on the selected method, data is transmitted to the relevant payment provider. This may include customer identity, contact details, amount, currency, order reference, device information, risk data and payment status.
12.2 Stripe Connect
Where Stripe is used, the relevant Stripe group entity processes data for payment acceptance, account connection, fraud prevention, compliance, payouts, disputes and related financial infrastructure. Stripe may act as controller, processor or both depending on the activity. Stripe's current privacy information and contractual terms apply to its own processing.
12.3 Authorisation, capture and refunds
KulturCart may support payment authorisation before final stock confirmation and later capture, cancellation or refund. Transaction status and limited references are retained to reconcile orders, investigate failures and provide support.
12.4 Payment security
Full payment credentials are ordinarily entered into or tokenised by the payment provider rather than stored by KulturCart. KulturCart may receive masked details, tokens, payment-method type, authentication results and fraud indicators.
12.5 Chargebacks and disputes
Data may be shared among the customer, vendor, KulturCart, payment provider, banks and card schemes to investigate chargebacks, unauthorised payments, duplicate charges, refunds or payment disputes. The legal bases are contract performance, legal obligations and legitimate interests in preventing loss and preserving evidence.
13. Delivery, collection and logistics
13.1 Address and contact data
For delivery or collection, KulturCart and the vendor process the recipient's name, address, telephone number, delivery instructions, time slot and order information. Only data reasonably necessary for the selected fulfilment method should be disclosed.
13.2 Carriers and delivery partners
Where a carrier or delivery partner is used, the required data is transmitted for dispatch, tracking, contact, delivery evidence and problem resolution. The carrier may act as an independent controller for its transport obligations.
13.3 Proof of delivery and incidents
Delivery status, signatures where appropriate, photographs where lawful and necessary, failed-delivery reasons and complaint evidence may be processed to establish performance, resolve disputes and protect against fraud. Excessive or unrelated evidence must not be collected.
13.4 Location data
Precise device location is processed only when the user enables a location-dependent function and grants the required permission. Address-derived or approximate location may be used to display availability, delivery zones or nearby vendors.
14. Returns, refunds, warranty and complaints
14.1 Case handling
KulturCart processes order, communication, evidence, product, payment and delivery data to route and support return, refund, withdrawal, warranty and complaint cases. The vendor remains responsible for its customer obligations as seller, while KulturCart may facilitate the workflow.
14.2 Evidence
Customers and vendors may submit photographs, videos, documents or descriptions. Such evidence should be limited to what is necessary and should avoid showing unrelated people, documents or sensitive information.
14.3 Product safety and recalls
Where a product may be unsafe, KulturCart may combine order, product, vendor and contact data to identify affected persons, restrict listings, communicate warnings, coordinate recall remedies and cooperate with authorities. Processing is based on legal obligations and overriding safety interests.
14.4 Retention of case records
Complaint and remedy records are retained for the duration needed to complete the case, demonstrate compliance, handle payment disputes and protect legal claims. They may be linked to the underlying order and invoice retention period.
15. Customer support and communications
15.1 Support channels
When a person contacts KulturCart by email, telephone, form, chat or another support channel, KulturCart processes contact information, message content, account or order references, attachments and service metadata to respond and document the case.
15.2 Self-hosted support systems
KulturCart may operate support and communication software such as FreeScout or LiveHelperChat on KulturCart-controlled infrastructure. The software publisher is not automatically a recipient merely because the software is installed; access by external support personnel is permitted only where contractually and technically controlled.
15.3 Call and conversation records
Calls are not recorded unless the participant is informed in advance and a lawful basis applies. Written summaries or case notes may be created to document commitments, troubleshooting or complaints.
15.4 Service communications
KulturCart may send account, security, order, policy, support and operational notices where necessary for the requested service, legal duties or legitimate interests. These messages are distinct from optional advertising.
16. Reviews, comments and other user content
16.1 Publication
When a user submits a review, rating, comment, question, image or other public contribution, the chosen display name, content, date and related product or vendor may be visible to others. The user should not publish personal data that is unnecessary for the contribution.
16.2 Moderation
KulturCart processes content, account information, reports and moderation records to apply the Terms, Community Standards and law. Reporters and affected users may receive information about decisions to the extent required or permitted.
16.3 Authenticity and fraud prevention
Order and account information may be used to label verified purchases, detect manipulated reviews, prevent duplicate accounts and protect marketplace integrity. Review analysis does not authorise unrelated profiling.
16.4 Content licence and deletion
The rights to use user content are governed by the Terms. Deletion of an account does not necessarily remove content that must remain to preserve discussion context, evidence or legal claims; where appropriate, content is deleted or dissociated from the account.
17. Newsletters, marketing and notifications
17.1 Newsletter consent
Promotional newsletters are sent on the basis of consent unless another lawful direct-marketing rule applies. Subscription and confirmation records are retained to demonstrate the request and consent. Unsubscribe links or equivalent controls are provided.
17.2 Existing-customer marketing
Where legally permitted, KulturCart may inform existing customers about similar KulturCart services on the basis of legitimate interests and applicable direct-marketing law. The recipient may object at any time without incurring more than the ordinary transmission cost.
17.3 Vendor and partner marketing
Marketing communications to business contacts are assessed separately and are not sent merely because contact details appear in a register or website. KulturCart records objections and suppression preferences.
17.4 Push and in-app notifications
Push or in-app notifications are used only where the device, browser or application supports them and the required permission has been granted. Transactional and security notifications may remain necessary even where promotional notifications are disabled.
17.5 Advertising measurement
Advertising pixels, retargeting and cross-service measurement are not treated as automatically active. If such technologies are enabled, they are disclosed in the current Cookie Notice and activated only with the required consent.
18. Analytics, service improvement and research
18.1 Operational analytics
KulturCart analyses aggregated and pseudonymised usage, performance, conversion, error and support data to understand service quality, improve workflows and allocate capacity. Whenever possible, reporting is performed without identifying individual users.
18.2 Self-hosted analytics
KulturCart may use self-hosted analytics software such as Matomo. The applicable configuration determines whether cookies, identifiers or consent are required. The live Cookie Notice and consent interface must describe the actual configuration.
18.3 Experiments and feature evaluation
KulturCart may compare feature variants or measure implementation outcomes. Experiments must be proportionate, avoid sensitive inferences, and must not produce legal or similarly significant effects without a separate lawful basis and appropriate safeguards.
18.4 Surveys and research
Participation in surveys or interviews is voluntary unless information is required to fulfil a support or contractual request. Research responses may be aggregated or anonymised. Separate consent is obtained where a testimonial or identifiable quotation will be published.
19. Location, maps and local availability
19.1 Address-based localisation
KulturCart may convert a delivery or store address into geographic coordinates to determine delivery zones, nearby vendors, distance or service availability. This is necessary for the requested local marketplace function.
19.2 Device location
Browser or device location is processed only after the user grants permission. Refusing precise location does not prevent use of address-based functions where an address can be entered manually.
19.3 Map providers
KulturCart aims to use KulturCart-controlled or self-hosted location infrastructure where practicable. If an external map, geocoding or content provider is introduced, its identity, data flows and any consent requirement will be disclosed before activation.
19.4 Location retention
Location information is retained only for the relevant order, store configuration, fraud-prevention or service purpose. Precise location histories are not created unless a specific feature clearly requires and discloses them.
20. Social media and embedded third-party content
20.1 KulturCart profiles
When a person interacts with KulturCart through a social network, both the network operator and KulturCart may process profile, message, reaction and usage data under their respective responsibilities. The network's privacy information applies to its own platform processing.
20.2 Embedded content
Videos, maps, social posts, fonts or other external content can transmit technical data to the provider when loaded. Non-essential embeds should be blocked until consent or opened through a user-initiated link where required.
20.3 No blanket activation statement
This Policy does not claim that Meta, Google advertising, Google Maps or another optional service is active merely because it may be technically available. The current Cookie Notice and live consent configuration are authoritative for optional website integrations.
20.4 Direct links
A simple link to a third-party website does not by itself transfer data to that provider before the user activates the link, apart from ordinary display of the link by KulturCart's server.
21. Vendor onboarding, trader verification and business administration
21.1 Application and verification data
KulturCart processes vendor legal name, trading name, address, representatives, contact information, register and tax details, licences, identity evidence, bank-account confirmation, selected services and risk information to assess onboarding, establish the contract and maintain marketplace integrity.
21.2 Legal bases
Processing is based on pre-contract steps and contract performance, legal obligations, and legitimate interests in verifying counterparties, preventing fraud, protecting customers and documenting authority. KulturCart does not collect verification documents that are unnecessary for the relevant risk and legal context.
21.3 Ongoing accuracy
Vendors must keep their information current. KulturCart may request renewed evidence after a material change, risk event, expiry, complaint or legal update. Verification history is retained to show how a vendor was admitted and monitored.
21.4 Bank and payout information
Bank information is processed to confirm billing or payout instructions, collect agreed fees and prevent misdirection. Full bank details are restricted to personnel and providers who need them for the relevant financial process.
21.5 Business contacts and employees
Contact data of directors, owners, authorised representatives, store managers, cashiers and staff is processed according to their role. The vendor is responsible for providing its personnel with any required information about the disclosure to KulturCart.
22. POS, TSE and fiscalisation data
22.1 POS users and cashiers
Where KulturCart POS is used, KulturCart processes user identifiers, roles, PIN-related authentication data in protected form, shift and transaction references, cash events, device assignments and audit records to provide secure point-of-sale functions.
22.2 Transactions and receipts
POS records may include products, quantities, taxes, payment type, timestamps, receipt references, returns, discounts and customer data where the vendor enters or links it. Vendors should avoid entering unnecessary customer information into fiscal or transaction records.
22.3 TSE and fiskaly
Where Cloud-TSE or related fiscalisation services are activated, required device, client, transaction, signature, receipt, export and status data is processed through fiskaly GmbH and KulturCart systems. Roles depend on the specific function and applicable agreements.
22.4 DSFinV-K and tax exports
KulturCart may generate, store or transmit DSFinV-K and related export files for the vendor. The vendor remains responsible for its tax and retention duties. KulturCart may retain technical evidence of creation, delivery and integrity.
22.5 Fiscal retention
Fiscal, accounting and receipt data is retained according to applicable tax and commercial-law requirements, contractual obligations and the vendor's documented instructions where KulturCart acts as processor.
23. Fraud prevention, security and platform integrity
23.1 Risk signals
KulturCart uses account, device, IP, order, payment, vendor, complaint and behavioural signals to identify account takeover, payment fraud, suspicious orders, counterfeit or prohibited listings, review manipulation, circumvention and other misuse.
23.2 Protective measures
Measures may include authentication challenges, rate limits, manual review, temporary holds, access restriction, listing suspension, evidence preservation and referral to payment providers or authorities. Measures are proportionate to the risk and are reviewed where appropriate.
23.3 Legal basis
Processing is based on legitimate interests in protecting users, vendors, KulturCart and payment systems, and on legal obligations where applicable. Security logs may be retained longer when linked to an incident or claim.
23.4 Confidentiality of detection methods
KulturCart may withhold technical details of fraud or security detection where disclosure would enable circumvention or harm other persons. This does not remove applicable rights to meaningful information and human review.
24. Legal compliance, reporting and claims
24.1 Authority and legal requests
KulturCart may process and disclose data to courts, regulators, tax authorities, law-enforcement bodies, market-surveillance authorities and other competent bodies where required by law or necessary to establish, exercise or defend legal claims. Requests are assessed for authority, scope and proportionality.
24.2 Illegal content and policy reports
Reporter, affected-user, listing, communication and evidence data is processed to assess notices, take interim measures, issue reasons, handle complaints and preserve records under the applicable reporting and enforcement procedures.
24.3 Intellectual-property reports
Rights-holder notices, evidence, vendor responses and decision records are processed to investigate alleged infringement, protect legitimate content and handle repeat-abuse or restoration procedures.
24.4 Product-safety reports
Incident, product, order, customer, vendor, authority and remedy data is processed to assess hazards, warn affected persons, conduct recalls and document compliance.
24.5 Legal claims and insurance
Relevant contracts, orders, communications, logs and evidence may be retained and disclosed to advisers, insurers, debt-collection providers or courts where necessary for claims or defence.
25. Applicants, suppliers, partners and other business contacts
25.1 Applications
If KulturCart receives job, internship or contractor applications, it processes identity, contact, qualifications, employment history, communications and interview information to assess the application. A more specific applicant notice may be provided where recruitment becomes a regular activity.
25.2 Suppliers and service providers
KulturCart processes contact, contract, billing, support, access and compliance information of suppliers and their personnel to manage the business relationship and secure system access.
25.3 Business development and partnerships
Contact and communication data may be processed to evaluate partnerships, integrations, referrals, events or other business opportunities. Unsolicited marketing is not justified merely because a professional address is publicly available.
25.4 Retention
Unsuccessful application or proposal records are deleted after the relevant decision and limitation period unless consent or another lawful basis supports longer retention.
26. Recipients and service providers
26.1 Need-to-know principle
Personal data is disclosed only where necessary for a defined purpose and under an appropriate legal arrangement. Access is limited by role, system permissions and confidentiality obligations.
26.2 Hosting and infrastructure
Current infrastructure recipients may include Hetzner Online GmbH and dataforest GmbH/Avoro for hosting, network, storage, backup or related infrastructure assigned to KulturCart.
26.3 Payments and fiscalisation
Stripe group entities may receive data for payments and connected accounts. fiskaly GmbH may receive data for Cloud-TSE, fiscalisation and related export functions where activated.
26.4 Internal business systems
KulturCart may use self-hosted CS-Cart, Dolibarr, Nextcloud, FreeScout, LiveHelperChat, Matomo and similar software. Installation of software on KulturCart-controlled infrastructure does not by itself make the publisher a recipient. Google Workspace or Google Drive may be used for selected legal, administrative and collaboration records under access controls.
26.5 Professional and public recipients
Data may be disclosed to advisers, auditors, insurers, banks, debt-collection providers, postal or delivery services, authorities and courts where the purpose and legal basis require it.
26.6 Current register
Appendix B lists the principal current provider categories and known providers. The list may change as infrastructure and services evolve. Material changes are reflected in the current Policy or a more specific notice.
27. International data transfers
27.1 EEA preference
KulturCart prefers processing in Germany or the European Economic Area where reasonably practicable. A provider's group structure, support access or technical routing may nevertheless involve another country.
27.2 Adequacy decisions
Where the European Commission has adopted an adequacy decision, data may be transferred on that basis within its scope, including transfers to participating organisations under the EU-U.S. Data Privacy Framework where applicable.
27.3 Standard Contractual Clauses
Where no adequacy decision applies, KulturCart uses appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with transfer assessments and supplementary measures where required.
27.4 Provider-specific safeguards
Payment, collaboration and other global providers may rely on adequacy decisions, the Data Privacy Framework, Standard Contractual Clauses or a combination of mechanisms. Their current privacy and transfer documentation applies to their processing.
27.5 Copies and information
Information about the relevant safeguard may be requested from KulturCart, subject to protection of confidential and third-party information.
28. Retention, deletion and anonymisation
28.1 Purpose limitation
KulturCart retains personal data only as long as necessary for the relevant purpose, contract, legal obligation, security requirement or claim. Different records therefore have different retention periods.
28.2 Commercial and tax records
Invoices, accounting records, transaction evidence and business correspondence are retained in accordance with applicable German commercial and tax rules. Depending on the record type, statutory periods commonly range from six to ten years; invoice retention is generally eight years under current VAT rules.
28.3 Accounts and orders
Account data is retained during the active relationship. Order records are retained for performance, customer rights, accounting, fraud prevention and claims. Optional profile data may be deleted earlier where it is no longer needed.
28.4 Support, complaints and security
Routine support data is retained for the case and a proportionate follow-up period. Complaint, enforcement, fraud and security records may be retained for the applicable limitation period or longer where a proceeding remains open.
28.5 Backups
Deleted information may remain in protected backups until overwritten through the ordinary backup cycle. Backup data is isolated from routine use and restored only for continuity, security or legal reasons.
28.6 Anonymisation
Where information is genuinely anonymised so that a person cannot reasonably be identified, it may be retained for statistics, security, research or service improvement without being personal data.
29. Technical and organisational security
29.1 Risk-based safeguards
KulturCart applies safeguards appropriate to the risk, including access control, role separation, authentication, encryption in transit where appropriate, secure configuration, patching, backups, logging, incident response and confidentiality obligations.
29.2 Access management
Access is granted according to role and need. Privileged access is restricted, reviewed and logged where appropriate. Vendor and customer access is separated by tenant, store, account and permission controls.
29.3 Development and operations
Changes to production systems are tested and controlled according to risk. Development, staging and production data are separated where practicable. Real personal data is not used for testing unless necessary and protected.
29.4 User responsibilities
Users and vendors must protect credentials, devices and access codes, maintain accurate permissions and notify KulturCart promptly of suspected compromise. Security advice is provided in the applicable account and vendor policies.
29.5 No absolute guarantee
No system can eliminate every risk. KulturCart monitors and improves safeguards and responds to incidents, but does not represent that unauthorised access can never occur.
30. Data-subject rights
30.1 Access and information
Subject to the legal conditions, a person may request confirmation whether KulturCart processes personal data and obtain access and the information required by Article 15 GDPR.
30.2 Rectification and completion
Incorrect personal data may be corrected and incomplete data completed under Article 16 GDPR. Some account details can be updated directly through account settings.
30.3 Erasure and restriction
A person may request erasure under Article 17 GDPR or restriction under Article 18 GDPR where the legal conditions are met. These rights do not override retention duties, freedom of expression, public-interest processing or legal claims.
30.4 Data portability
Where processing is based on consent or contract and carried out by automated means, the person may request the data provided to KulturCart in a structured, commonly used and machine-readable format under Article 20 GDPR.
30.5 Objection
A person may object under Article 21 GDPR to processing based on legitimate interests for reasons arising from the person's particular situation. Processing for direct marketing may be objected to at any time.
30.6 Withdrawal of consent
Consent may be withdrawn for the future through the relevant preference control or by contacting KulturCart. The withdrawal does not affect earlier lawful processing.
30.7 Identity verification and response
KulturCart may request proportionate information to verify identity and prevent disclosure to an unauthorised person. Requests are answered within the statutory period, subject to permitted extensions for complexity or volume.
31. Automated decisions, profiling and personalisation
31.1 No undisclosed significant decisions
KulturCart does not currently make solely automated decisions producing legal or similarly significant effects on customers without human involvement, unless a specific process, legal basis and safeguards are separately disclosed.
31.2 Fraud and risk scoring
Automated signals may prioritise orders, accounts, payments or listings for review or apply temporary protective controls. Material adverse measures are reviewed under the applicable enforcement and complaint procedures where required.
31.3 Recommendations and ranking
Recommendation and ranking functions may use location, availability, relevance, popularity, quality, delivery conditions, user preferences and sponsored status. These functions generally organise content and do not constitute a legal decision about the user.
31.4 Marketing profiles
Cross-service advertising or detailed marketing profiles are created only where the required consent and disclosure exist. Users may withdraw consent or object to direct marketing.
32. Children and legal capacity
32.1 Service audience
KulturCart is not designed as a children's service. Purchases and accounts must be created by a person with the legal capacity or required representative authority for the relevant transaction.
32.2 Consent by children
Where consent is the legal basis for an online service offered directly to a child, the age and parental-authorisation requirements of Article 8 GDPR and applicable German law are observed.
32.3 Removal and protection
If KulturCart learns that personal data of a child was collected without an adequate legal basis or required authorisation, it will restrict and delete the data as appropriate, while preserving records required for safety, orders or legal claims.
33. Whether data must be provided
33.1 Contract-required information
Certain information is necessary to create an account, place and fulfil an order, deliver products, process payment or provide requested support. Without it, the relevant service or contract may not be possible.
33.2 Legally required information
Vendor verification, tax, fiscalisation, product-safety and authority requirements may make specific information mandatory. The relevant form or request identifies the required fields.
33.3 Optional information
Optional profile, marketing, survey, precise-location and similar data can generally be withheld without affecting core marketplace use, although the optional feature may then be unavailable.
34. Supervisory authority and complaints
34.1 Right to complain
A data subject has the right to lodge a complaint with a supervisory authority under Article 77 GDPR, particularly in the Member State of habitual residence, place of work or the alleged infringement.
34.2 Competent authority for KulturCart
For a private-sector controller established in Bavaria, the competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, poststelle@lda.bayern.de. The authority provides an online complaint form.
34.3 Contacting KulturCart first
A complaint to an authority is not conditional on contacting KulturCart first. KulturCart nevertheless welcomes the opportunity to investigate and resolve a concern promptly through info@kulturcart.de.
35. Changes, versioning and contact
35.1 Policy changes
KulturCart updates this Policy where processing, providers, technology, law or organisational responsibilities materially change. The current version, effective date and document ID are published with the Policy.
35.2 Notice of material changes
Where appropriate, material changes are communicated through the website, account, email or other suitable channel before they take effect. A new legal basis or consent is obtained where required; continued use is not treated as consent to processing that legally requires affirmative consent.
35.3 Archived versions
Superseded policies are retained internally with their effective periods so that KulturCart can identify the information applicable to a historical processing event.
35.4 Contact
Questions, rights requests, objections and privacy concerns may be submitted to KulturCart - Ibrahim Lawal, Ringstraße 22, 84347 Pfarrkirchen, Germany, email info@kulturcart.de, telephone +49 8561 9080851.
Appendix A - Processing activity matrix
| Activity | Main data | Purpose / legal basis | Typical recipients |
|---|---|---|---|
| Website delivery and security | IP, request, device, log and error data | Technical delivery, security and stability; Art. 6(1)(f) GDPR | Hosting and infrastructure providers |
| Accounts and authentication | Identity, contact, credential, role and login data | Account contract and security; Art. 6(1)(b), (f) GDPR | Hosting, authentication and support systems |
| Marketplace orders | Customer, vendor, product, price, payment, delivery and communication data | Contract facilitation and order management; Art. 6(1)(b) GDPR | Relevant vendor, payment provider, carrier |
| Payments | Transaction reference, amount, status, risk and limited payment details | Payment, fraud prevention and legal obligations; Art. 6(1)(b), (c), (f) GDPR | Stripe or the selected payment provider, banks and schemes |
| Support and complaints | Contact, messages, attachments, account/order references | Support, contract, legitimate interests and claims | Relevant vendor, support systems, advisers where necessary |
| Vendor onboarding | Business, representative, register, tax, bank and verification data | Contract, legal obligations and marketplace integrity | Verification sources, payment providers, advisers and authorities where necessary |
| POS and TSE | Cashier, role, device, transaction, receipt, signature and export data | POS contract, fiscal duties, security and vendor instructions | Vendor, fiskaly, infrastructure providers and authorities where required |
| Marketing and optional analytics | Contact, consent, preferences, pseudonymous usage and campaign data | Consent or legally permitted direct marketing | Consent and communication provider; optional provider disclosed in Cookie Notice |
| Reports and enforcement | Reporter, affected user, listing, evidence, decision and complaint data | Legal compliance, platform safety and claims | Affected parties, authorities, advisers and providers as necessary |
Appendix B - Principal provider and recipient register
| Provider / category | Function | Location / transfer context | Role notes |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, compute, storage, network and related infrastructure | Germany / EEA | Processor for allocated KulturCart workloads |
| dataforest GmbH / Avoro | Hosting and infrastructure for allocated self-hosted workloads | Germany / EEA | Processor for allocated KulturCart workloads |
| Stripe group entity, including Stripe Payments Europe Limited where applicable | Payments, connected accounts, payouts, risk, disputes and financial infrastructure | EEA and global group processing subject to current safeguards | Controller, processor or both depending on activity |
| fiskaly GmbH | Cloud-TSE, fiscalisation, signatures, receipt and DSFinV-K functions where activated | Austria / EEA | Processor or independent provider depending on function and agreement |
| Google Workspace / Google Drive where used | Selected legal, administrative and collaboration records | EEA and global processing under Google's current safeguards | Processor and/or independent controller depending on service |
| Carriers and delivery partners | Dispatch, tracking, delivery, handover and incident handling | According to selected carrier | Often independent controller for transport duties |
| Self-hosted software: CS-Cart, Dolibarr, Nextcloud, FreeScout, LiveHelperChat, Matomo and similar | Marketplace, ERP, cloud, support, chat and analytics on KulturCart-controlled infrastructure | Hosting location of the relevant KulturCart workload | Publisher is not a recipient merely because software is installed; external access requires a separate basis |
| Advisers, insurers, banks, auditors, authorities and courts | Advice, claims, financial processing and legal compliance | According to recipient and legal requirement | Independent controller or professional recipient |
Appendix C - Retention matrix
| Record category | Typical retention approach | Reason |
|---|---|---|
| Server and security logs | Usually days or months; longer for incidents | Operations, security and evidence |
| Account profile | Active relationship plus a limited closure period | Service, fraud prevention and claims |
| Orders, invoices and accounting records | Applicable commercial and tax periods, commonly six to ten years; invoices generally eight years | HGB, AO, UStG and claims |
| Payment and refund references | Order/accounting period plus dispute requirements | Reconciliation, chargebacks and fraud |
| Support and routine communications | Case duration plus proportionate follow-up period | Service quality and evidence |
| Complaints, enforcement and safety cases | Case duration plus limitation, regulatory or recall period | Compliance, restoration and claims |
| Vendor verification and contracts | Relationship plus legal retention and limitation periods | Counterparty verification and contractual evidence |
| POS/TSE and fiscal exports | Statutory tax/fiscal period or vendor instruction under the DPA | Fiscal compliance and evidence |
| Consent and objection records | As long as needed to demonstrate consent, withdrawal or suppression | Accountability and marketing compliance |
| Backups | Ordinary protected overwrite cycle | Continuity and disaster recovery |
Appendix D - Role allocation matrix
| Processing context | KulturCart role | Other party role | Key consequence |
|---|---|---|---|
| Marketplace platform operation, account security and governance | Independent controller | Vendor or user may be a separate controller for own purposes | Each party provides information for its own processing |
| Customer sale, fulfilment, returns and statutory warranty | Marketplace facilitator for its functions | Vendor generally independent controller and seller | Customer claims and vendor processing are primarily directed to vendor |
| Vendor-directed data functions expressly covered by the DPA | Processor | Vendor controller | Documented instructions and Art. 28 GDPR terms apply |
| Payment processing | Controller and/or processor for limited platform functions | Payment provider controller, processor or both | Provider's current privacy information applies |
| Carrier delivery | Controller for marketplace coordination | Carrier often independent controller | Only necessary delivery data is disclosed |
| Cloud-TSE and fiscalisation | Controller or processor depending on service | Vendor controller for its fiscal records; fiskaly processor/provider | Annex 1 and DPA allocate activity-specific duties |
| Optional jointly designed campaign or integration | To be assessed | Partner role to be assessed | Joint-controller arrangement is documented if purposes and essential means are jointly determined |
Appendix E - Rights and request matrix
| Request | Information to provide | Possible limitation |
|---|---|---|
| Access | Identity, account/contact reference and desired scope | Rights of others, legal privilege and excessive requests |
| Rectification | Incorrect data and correct replacement | Historical records may be preserved with correction note |
| Erasure | Data or context to be erased | Legal retention, claims, freedom of expression and public interest |
| Restriction | Processing and reason for restriction | Storage and permitted legal processing may continue |
| Portability | Account and relevant contract-based automated data | Applies only under Art. 20 GDPR conditions |
| Objection | Processing and particular situation; no reason needed for direct marketing | Compelling legitimate grounds or legal claims may override non-marketing objection |
| Consent withdrawal | Consent or technology to withdraw | Prospective only; prior lawful processing remains valid |
| Complaint | Description, dates, account/order and supporting evidence | May be referred to vendor or another controller where appropriate |
Legal Library