Legal Library
Historical version · 1.0.2 · View current version
Legal Library

Privacy Policy

How KulturCart collects, uses, shares, protects, and retains personal data, including your rights and contact options.

Version
1.0.2
Effective date
Wednesday, August 12, 2026

KulturCart Privacy Policy

Version 1.0 · 12 August 2026 · KC-LEGAL-03-EN-1.0

Table of Contents

  1. 1. Scope, purpose and status of this Privacy Policy
    1. 1.1 Services and persons covered
    2. 1.2 Purpose of the information
    3. 1.3 Relationship to other KulturCart documents
    4. 1.4 Meaning of personal data and processing
  2. 2. Controller and privacy contact
    1. 2.1 Controller
    2. 2.2 Contact channels
    3. 2.3 Data protection officer
    4. 2.4 Authoritative language
  3. 3. Allocation of roles in the KulturCart marketplace
    1. 3.1 KulturCart as independent controller
    2. 3.2 Vendors as independent controllers
    3. 3.3 Processor activities
    4. 3.4 Payment and other independent providers
    5. 3.5 No automatic joint controllership
  4. 4. General processing principles and legal bases
    1. 4.1 Performance of a contract and pre-contract steps
    2. 4.2 Legal obligations
    3. 4.3 Legitimate interests
    4. 4.4 Consent
    5. 4.5 Special categories and criminal-offence data
  5. 5. Sources of personal data
    1. 5.1 Data provided directly
    2. 5.2 Data provided by vendors and service providers
    3. 5.3 Automatically generated data
    4. 5.4 Public and official sources
    5. 5.5 Data received from another person
  6. 6. Categories of personal data
    1. 6.1 Identity and contact data
    2. 6.2 Account and authentication data
    3. 6.3 Order, transaction and payment data
    4. 6.4 Content and communication data
    5. 6.5 Technical and usage data
    6. 6.6 Vendor, staff and POS data
  7. 7. Website access, server logs and technical delivery
    1. 7.1 Server requests
    2. 7.2 Security and diagnostic logs
    3. 7.3 Hosting architecture
    4. 7.4 Log retention
  8. 8. Cookies, local storage and consent management
    1. 8.1 Strictly necessary technologies
    2. 8.2 Optional technologies
    3. 8.3 Cookie and Similar Technologies Notice
    4. 8.4 Withdrawal and settings
  9. 9. Customer accounts and guest use
    1. 9.1 Registration
    2. 9.2 Guest checkout
    3. 9.3 Account preferences
    4. 9.4 Account closure
  10. 10. Marketplace orders and contract formation
    1. 10.1 Checkout and order data
    2. 10.2 Order review and vendor acceptance
    3. 10.3 Order confirmations and records
    4. 10.4 Single- and multi-vendor transactions
  11. 11. Disclosure to vendors and vendor responsibility
    1. 11.1 Necessary order disclosure
    2. 11.2 Vendor privacy information
    3. 11.3 No unrestricted customer-list transfer
    4. 11.4 Vendor changes or closure
  12. 12. Payment processing
    1. 12.1 Payment data and providers
    2. 12.2 Stripe Connect
    3. 12.3 Authorisation, capture and refunds
    4. 12.4 Payment security
    5. 12.5 Chargebacks and disputes
  13. 13. Delivery, collection and logistics
    1. 13.1 Address and contact data
    2. 13.2 Carriers and delivery partners
    3. 13.3 Proof of delivery and incidents
    4. 13.4 Location data
  14. 14. Returns, refunds, warranty and complaints
    1. 14.1 Case handling
    2. 14.2 Evidence
    3. 14.3 Product safety and recalls
    4. 14.4 Retention of case records
  15. 15. Customer support and communications
    1. 15.1 Support channels
    2. 15.2 Self-hosted support systems
    3. 15.3 Call and conversation records
    4. 15.4 Service communications
  16. 16. Reviews, comments and other user content
    1. 16.1 Publication
    2. 16.2 Moderation
    3. 16.3 Authenticity and fraud prevention
    4. 16.4 Content licence and deletion
  17. 17. Newsletters, marketing and notifications
    1. 17.1 Newsletter consent
    2. 17.2 Existing-customer marketing
    3. 17.3 Vendor and partner marketing
    4. 17.4 Push and in-app notifications
    5. 17.5 Advertising measurement
  18. 18. Analytics, service improvement and research
    1. 18.1 Operational analytics
    2. 18.2 Self-hosted analytics
    3. 18.3 Experiments and feature evaluation
    4. 18.4 Surveys and research
  19. 19. Location, maps and local availability
    1. 19.1 Address-based localisation
    2. 19.2 Device location
    3. 19.3 Map providers
    4. 19.4 Location retention
  20. 20. Social media and embedded third-party content
    1. 20.1 KulturCart profiles
    2. 20.2 Embedded content
    3. 20.3 No blanket activation statement
    4. 20.4 Direct links
  21. 21. Vendor onboarding, trader verification and business administration
    1. 21.1 Application and verification data
    2. 21.2 Legal bases
    3. 21.3 Ongoing accuracy
    4. 21.4 Bank and payout information
    5. 21.5 Business contacts and employees
  22. 22. POS, TSE and fiscalisation data
    1. 22.1 POS users and cashiers
    2. 22.2 Transactions and receipts
    3. 22.3 TSE and fiskaly
    4. 22.4 DSFinV-K and tax exports
    5. 22.5 Fiscal retention
  23. 23. Fraud prevention, security and platform integrity
    1. 23.1 Risk signals
    2. 23.2 Protective measures
    3. 23.3 Legal basis
    4. 23.4 Confidentiality of detection methods
  24. 24. Legal compliance, reporting and claims
    1. 24.1 Authority and legal requests
    2. 24.2 Illegal content and policy reports
    3. 24.3 Intellectual-property reports
    4. 24.4 Product-safety reports
    5. 24.5 Legal claims and insurance
  25. 25. Applicants, suppliers, partners and other business contacts
    1. 25.1 Applications
    2. 25.2 Suppliers and service providers
    3. 25.3 Business development and partnerships
    4. 25.4 Retention
  26. 26. Recipients and service providers
    1. 26.1 Need-to-know principle
    2. 26.2 Hosting and infrastructure
    3. 26.3 Payments and fiscalisation
    4. 26.4 Internal business systems
    5. 26.5 Professional and public recipients
    6. 26.6 Current register
  27. 27. International data transfers
    1. 27.1 EEA preference
    2. 27.2 Adequacy decisions
    3. 27.3 Standard Contractual Clauses
    4. 27.4 Provider-specific safeguards
    5. 27.5 Copies and information
  28. 28. Retention, deletion and anonymisation
    1. 28.1 Purpose limitation
    2. 28.2 Commercial and tax records
    3. 28.3 Accounts and orders
    4. 28.4 Support, complaints and security
    5. 28.5 Backups
    6. 28.6 Anonymisation
  29. 29. Technical and organisational security
    1. 29.1 Risk-based safeguards
    2. 29.2 Access management
    3. 29.3 Development and operations
    4. 29.4 User responsibilities
    5. 29.5 No absolute guarantee
  30. 30. Data-subject rights
    1. 30.1 Access and information
    2. 30.2 Rectification and completion
    3. 30.3 Erasure and restriction
    4. 30.4 Data portability
    5. 30.5 Objection
    6. 30.6 Withdrawal of consent
    7. 30.7 Identity verification and response
  31. 31. Automated decisions, profiling and personalisation
    1. 31.1 No undisclosed significant decisions
    2. 31.2 Fraud and risk scoring
    3. 31.3 Recommendations and ranking
    4. 31.4 Marketing profiles
  32. 32. Children and legal capacity
    1. 32.1 Service audience
    2. 32.2 Consent by children
    3. 32.3 Removal and protection
  33. 33. Whether data must be provided
    1. 33.1 Contract-required information
    2. 33.2 Legally required information
    3. 33.3 Optional information
  34. 34. Supervisory authority and complaints
    1. 34.1 Right to complain
    2. 34.2 Competent authority for KulturCart
    3. 34.3 Contacting KulturCart first
  35. 35. Changes, versioning and contact
    1. 35.1 Policy changes
    2. 35.2 Notice of material changes
    3. 35.3 Archived versions
    4. 35.4 Contact
  36. Appendix A - Processing activity matrix
  37. Appendix B - Principal provider and recipient register
  38. Appendix C - Retention matrix
  39. Appendix D - Role allocation matrix
  40. Appendix E - Rights and request matrix

1. Scope, purpose and status of this Privacy Policy

1.1 Services and persons covered

This Privacy Policy explains how KulturCart processes personal data in connection with kulturcart.de, related marketplace functions, customer and vendor accounts, support channels, KulturCart POS and fiscalisation services where relevant, and other KulturCart services that expressly refer to this Policy. It applies to visitors, registered users, customers, vendor representatives, cashiers and other persons whose data is processed through these services.

Separate notices may apply to a specific processing context, such as a vendor contract, a job application, a security report or a particular campaign. Where a more specific notice applies, it supplements this Policy and takes precedence for the processing described in that notice.

1.2 Purpose of the information

The purpose of this Policy is to provide transparent information under Articles 12, 13 and 14 GDPR about the categories of personal data processed, the purposes and legal bases, recipients, transfers, retention, security, and the rights of data subjects. It is not intended to create consent where consent is not the applicable legal basis.

1.3 Relationship to other KulturCart documents

The General Terms and Conditions and Marketplace Terms of Use govern use of the marketplace. Vendor contractual documents govern the commercial relationship with vendors. The Cookie and Similar Technologies Notice describes device storage, access and optional tracking technologies in greater technical detail. The Customer and Vendor Policies allocate operational responsibilities. These documents should be read together where relevant.

1.4 Meaning of personal data and processing

Personal data means information relating to an identified or identifiable natural person. Processing includes collection, recording, organisation, storage, adaptation, consultation, disclosure, restriction, deletion and other use of personal data. Anonymous information that cannot reasonably be linked to a person is not personal data.

2. Controller and privacy contact

2.1 Controller

The controller for the processing described as KulturCart's own processing in this Policy is KulturCart - Ibrahim Lawal, trading as 'KulturCart', Ringstraße 22, 84347 Pfarrkirchen, Germany.

2.2 Contact channels

Privacy questions, requests and objections may be sent to info@kulturcart.de or by post to the business address above. Please identify the relevant account, order or interaction so that KulturCart can locate the information without collecting unnecessary additional data.

2.3 Data protection officer

KulturCart has not appointed and does not currently publish a separate data protection officer because the statutory conditions requiring an appointment have not been determined to apply to the present organisation. If an appointment becomes necessary, the contact details will be added to this Policy without delay.

2.4 Authoritative language

The German Privacy Policy is the authoritative version. The English text is a convenience translation. Privacy rights may be exercised in German or English.

3. Allocation of roles in the KulturCart marketplace

3.1 KulturCart as independent controller

KulturCart acts as an independent controller where it determines the purposes and essential means of processing for operating, securing and improving the marketplace; managing customer and vendor accounts; billing KulturCart services; fraud prevention; legal compliance; platform governance; complaint handling; and the establishment, exercise or defence of legal claims.

3.2 Vendors as independent controllers

A vendor ordinarily sells products in its own name and on its own account. For order fulfilment, delivery, statutory warranty, customer communication and its own legal obligations, the vendor generally acts as an independent controller. The vendor's identity and contact information are shown in the relevant offer, order or vendor store. Questions concerning a vendor's own processing may therefore need to be directed to that vendor.

3.3 Processor activities

Where KulturCart processes clearly defined personal data only on a vendor's documented instructions, the roles and obligations are governed by the applicable Data Processing Agreement. A software function or shared system does not by itself determine the legal role; the actual purpose and decision-making authority are decisive.

3.4 Payment and other independent providers

Payment providers, carriers, fiscalisation providers and other regulated or independent service providers may act as separate controllers, processors or both depending on the activity. Their own privacy information applies to processing for which they determine the purposes and means.

3.5 No automatic joint controllership

Joint controllership is not assumed merely because parties exchange data. If KulturCart and another party jointly determine purposes and essential means for a specific processing activity, the arrangement and the essence of the allocation will be documented and communicated as required.

4. General processing principles and legal bases

4.1 Performance of a contract and pre-contract steps

KulturCart processes data under Article 6(1)(b) GDPR where necessary to create or manage an account, provide requested marketplace functions, facilitate an order, respond to a pre-contract enquiry, provide support, or perform another contract with the data subject.

4.2 Legal obligations

Processing under Article 6(1)(c) GDPR may be necessary for tax and accounting records, trader verification, product-safety cooperation, fiscal records, fraud or money-laundering controls where applicable, statutory information duties, authority requests and other binding legal obligations.

4.3 Legitimate interests

Under Article 6(1)(f) GDPR, KulturCart may process data for secure and reliable platform operation, prevention of misuse, internal administration, service improvement, direct marketing to existing customers where legally permitted, protection of users and vendors, evidence, and legal claims. KulturCart balances these interests against the rights and expectations of affected persons.

4.4 Consent

Where processing is based on consent under Article 6(1)(a) GDPR, the request will be specific, informed and voluntary. Consent may be withdrawn at any time for the future. Withdrawing consent does not affect processing already lawfully carried out before withdrawal.

4.5 Special categories and criminal-offence data

KulturCart does not ordinarily request special categories of data under Article 9 GDPR. If a person voluntarily submits sensitive information in a support, complaint, accessibility or safety context, KulturCart will process it only where necessary and supported by an appropriate legal basis. Data relating to criminal convictions or offences is processed only where permitted by Article 10 GDPR and applicable law.

5. Sources of personal data

5.1 Data provided directly

KulturCart receives data when a person visits the website, creates an account, places an order, contacts support, communicates with a vendor, subscribes to messages, submits a review, reports content, exercises a right, applies to become a vendor or otherwise interacts with KulturCart.

5.2 Data provided by vendors and service providers

Vendors may provide order status, fulfilment, delivery, return, complaint and product-safety information. Payment providers may provide transaction status, risk indicators and limited payment references. Carriers may provide tracking and delivery events. Fiscalisation providers may provide TSE and export status. Support and hosting providers may generate technical records.

5.3 Automatically generated data

When the services are used, servers and applications generate IP addresses, timestamps, request paths, device and browser information, session identifiers, authentication events, error reports, performance data and security logs. Optional analytics or advertising data is collected only in accordance with the Cookie Notice and the applicable consent settings.

5.4 Public and official sources

For vendor onboarding, safety, fraud and compliance purposes, KulturCart may obtain data from public company registers, tax or VAT verification services, sanctions lists, product-safety portals, official notices, public websites and other lawful sources.

5.5 Data received from another person

A customer may provide a recipient's name, address or telephone number for delivery, or a business may provide employee and representative details. The person providing the data must be authorised to do so and should inform the affected person where appropriate.

6. Categories of personal data

6.1 Identity and contact data

This may include name, title, date of birth where legally relevant, postal address, delivery address, email address, telephone number and preferred language.

6.2 Account and authentication data

This may include account identifier, login credentials in protected form, roles, permissions, user groups, multi-factor or verification information, login history, security events and account preferences.

6.3 Order, transaction and payment data

This may include products, quantities, prices, vendor, order number, payment method, payment status, refund information, billing data, delivery or collection details, transaction references and related communications. KulturCart does not ordinarily store full card numbers where a payment provider processes them directly.

6.4 Content and communication data

This includes messages, support tickets, comments, reviews, uploaded files, complaint records, report submissions, call notes and other content a person sends or publishes.

6.5 Technical and usage data

This includes IP address, user-agent, device and browser data, identifiers, session information, page and feature usage, diagnostic data, errors, performance measurements and consent records.

6.6 Vendor, staff and POS data

This may include business and register information, authorised representatives, cashiers, employee identifiers, role and access data, POS transactions, TSE assignments, receipts, cash logs, audit records and DSFinV-K-related information.

7. Website access, server logs and technical delivery

7.1 Server requests

When a page or application function is accessed, the hosting environment processes the IP address, date and time, requested resource, referrer where transmitted, browser and operating-system information, response status and transferred data volume. This is technically necessary to deliver content and maintain service stability.

7.2 Security and diagnostic logs

Logs are used to detect attacks, troubleshoot errors, prevent abuse, reconstruct incidents and preserve evidence. The legal basis is Article 6(1)(f) GDPR and, where relevant, Article 6(1)(c) GDPR. Log access is restricted to persons and providers who need it for their tasks.

7.3 Hosting architecture

KulturCart operates workloads on infrastructure allocated to KulturCart, including infrastructure provided by Hetzner Online GmbH and dataforest GmbH/Avoro. The exact placement of a workload may change for security, capacity, continuity or migration reasons, while the applicable data-protection safeguards continue to apply.

7.4 Log retention

Routine technical logs are retained only for the period necessary for operations and security, normally for a limited period measured in days or months. Relevant records may be retained longer where an incident, dispute or legal obligation requires preservation.

8. Cookies, local storage and consent management

8.1 Strictly necessary technologies

KulturCart uses technologies necessary for functions explicitly requested by the user, such as session management, shopping carts, login, security, language selection, load distribution and consent storage. Device access that is strictly necessary is handled under § 25(2) TDDDG and the associated GDPR legal basis.

8.2 Optional technologies

Analytics, advertising, cross-service measurement, personalisation or embedded third-party technologies that are not strictly necessary are activated only where an appropriate legal basis exists and, where required, after consent under § 25(1) TDDDG and Article 6(1)(a) GDPR.

8.3 Cookie and Similar Technologies Notice

The separate Cookie and Similar Technologies Notice provides the current technical inventory, provider, purpose, duration and preference-management information. It must reflect the actual production configuration and may be updated more frequently than this Policy.

8.4 Withdrawal and settings

Consent can be changed or withdrawn through the consent-management interface. Withdrawal applies prospectively. Blocking all cookies through browser settings may impair functions that depend on local storage or sessions.

9. Customer accounts and guest use

9.1 Registration

When an account is created, KulturCart processes the information required to identify the account holder, authenticate access and provide account functions. Optional profile data is clearly distinguished from required information.

9.2 Guest checkout

Where guest checkout is available, KulturCart processes order and contact data without creating a permanent customer account. Order records remain subject to contractual, accounting, fraud-prevention and statutory retention requirements.

9.3 Account preferences

Users may manage addresses, communications, language and other preferences. Changes are logged where necessary to maintain security, evidence and correct order processing.

9.4 Account closure

A request to close an account ends future account use but does not require immediate deletion of records that KulturCart or a vendor must retain for orders, invoices, fraud prevention, legal claims or other legal obligations. Remaining data is restricted and deleted or anonymised when the applicable purpose and retention period end.

10. Marketplace orders and contract formation

10.1 Checkout and order data

KulturCart processes customer identity, contact, cart, product, vendor, price, payment, delivery and communication data to provide checkout, transmit the order, confirm the transaction and manage the order lifecycle. The legal basis is Article 6(1)(b) GDPR.

10.2 Order review and vendor acceptance

The vendor receives the data necessary to assess availability, accept or reject the order, prepare the products and communicate material changes. KulturCart records order status, timestamps and decisions for performance, support, fraud prevention and evidence.

10.3 Order confirmations and records

KulturCart and the vendor may send confirmations, receipts, invoices, delivery information and legally required notices. These are service messages and are not marketing merely because they use electronic communication.

10.4 Single- and multi-vendor transactions

The current ordering model may restrict an order to a single vendor. If future functionality supports multiple vendors, data will be separated and disclosed only to each vendor to the extent necessary for that vendor's part of the transaction.

11. Disclosure to vendors and vendor responsibility

11.1 Necessary order disclosure

KulturCart discloses to the relevant vendor the customer and order data required for sale, fulfilment, delivery or collection, customer service, returns, statutory warranty and compliance. Vendors must not use this data for unrelated purposes without their own lawful basis.

11.2 Vendor privacy information

The vendor is responsible for providing any additional information required for its independent processing. KulturCart requires vendors to maintain appropriate confidentiality and security and may enforce vendor policies where misuse is identified.

11.3 No unrestricted customer-list transfer

KulturCart does not provide vendors with unrestricted access to all marketplace users. Access is limited by role, vendor relationship, order context and system permissions.

11.4 Vendor changes or closure

If a vendor changes ownership, closes or is suspended, KulturCart may restrict access and preserve or transfer only the data required for active orders, customer remedies, legal obligations and controlled business succession.

12. Payment processing

12.1 Payment data and providers

Available payment methods are shown at checkout. Depending on the selected method, data is transmitted to the relevant payment provider. This may include customer identity, contact details, amount, currency, order reference, device information, risk data and payment status.

12.2 Stripe Connect

Where Stripe is used, the relevant Stripe group entity processes data for payment acceptance, account connection, fraud prevention, compliance, payouts, disputes and related financial infrastructure. Stripe may act as controller, processor or both depending on the activity. Stripe's current privacy information and contractual terms apply to its own processing.

12.3 Authorisation, capture and refunds

KulturCart may support payment authorisation before final stock confirmation and later capture, cancellation or refund. Transaction status and limited references are retained to reconcile orders, investigate failures and provide support.

12.4 Payment security

Full payment credentials are ordinarily entered into or tokenised by the payment provider rather than stored by KulturCart. KulturCart may receive masked details, tokens, payment-method type, authentication results and fraud indicators.

12.5 Chargebacks and disputes

Data may be shared among the customer, vendor, KulturCart, payment provider, banks and card schemes to investigate chargebacks, unauthorised payments, duplicate charges, refunds or payment disputes. The legal bases are contract performance, legal obligations and legitimate interests in preventing loss and preserving evidence.

13. Delivery, collection and logistics

13.1 Address and contact data

For delivery or collection, KulturCart and the vendor process the recipient's name, address, telephone number, delivery instructions, time slot and order information. Only data reasonably necessary for the selected fulfilment method should be disclosed.

13.2 Carriers and delivery partners

Where a carrier or delivery partner is used, the required data is transmitted for dispatch, tracking, contact, delivery evidence and problem resolution. The carrier may act as an independent controller for its transport obligations.

13.3 Proof of delivery and incidents

Delivery status, signatures where appropriate, photographs where lawful and necessary, failed-delivery reasons and complaint evidence may be processed to establish performance, resolve disputes and protect against fraud. Excessive or unrelated evidence must not be collected.

13.4 Location data

Precise device location is processed only when the user enables a location-dependent function and grants the required permission. Address-derived or approximate location may be used to display availability, delivery zones or nearby vendors.

14. Returns, refunds, warranty and complaints

14.1 Case handling

KulturCart processes order, communication, evidence, product, payment and delivery data to route and support return, refund, withdrawal, warranty and complaint cases. The vendor remains responsible for its customer obligations as seller, while KulturCart may facilitate the workflow.

14.2 Evidence

Customers and vendors may submit photographs, videos, documents or descriptions. Such evidence should be limited to what is necessary and should avoid showing unrelated people, documents or sensitive information.

14.3 Product safety and recalls

Where a product may be unsafe, KulturCart may combine order, product, vendor and contact data to identify affected persons, restrict listings, communicate warnings, coordinate recall remedies and cooperate with authorities. Processing is based on legal obligations and overriding safety interests.

14.4 Retention of case records

Complaint and remedy records are retained for the duration needed to complete the case, demonstrate compliance, handle payment disputes and protect legal claims. They may be linked to the underlying order and invoice retention period.

15. Customer support and communications

15.1 Support channels

When a person contacts KulturCart by email, telephone, form, chat or another support channel, KulturCart processes contact information, message content, account or order references, attachments and service metadata to respond and document the case.

15.2 Self-hosted support systems

KulturCart may operate support and communication software such as FreeScout or LiveHelperChat on KulturCart-controlled infrastructure. The software publisher is not automatically a recipient merely because the software is installed; access by external support personnel is permitted only where contractually and technically controlled.

15.3 Call and conversation records

Calls are not recorded unless the participant is informed in advance and a lawful basis applies. Written summaries or case notes may be created to document commitments, troubleshooting or complaints.

15.4 Service communications

KulturCart may send account, security, order, policy, support and operational notices where necessary for the requested service, legal duties or legitimate interests. These messages are distinct from optional advertising.

16. Reviews, comments and other user content

16.1 Publication

When a user submits a review, rating, comment, question, image or other public contribution, the chosen display name, content, date and related product or vendor may be visible to others. The user should not publish personal data that is unnecessary for the contribution.

16.2 Moderation

KulturCart processes content, account information, reports and moderation records to apply the Terms, Community Standards and law. Reporters and affected users may receive information about decisions to the extent required or permitted.

16.3 Authenticity and fraud prevention

Order and account information may be used to label verified purchases, detect manipulated reviews, prevent duplicate accounts and protect marketplace integrity. Review analysis does not authorise unrelated profiling.

16.4 Content licence and deletion

The rights to use user content are governed by the Terms. Deletion of an account does not necessarily remove content that must remain to preserve discussion context, evidence or legal claims; where appropriate, content is deleted or dissociated from the account.

17. Newsletters, marketing and notifications

17.1 Newsletter consent

Promotional newsletters are sent on the basis of consent unless another lawful direct-marketing rule applies. Subscription and confirmation records are retained to demonstrate the request and consent. Unsubscribe links or equivalent controls are provided.

17.2 Existing-customer marketing

Where legally permitted, KulturCart may inform existing customers about similar KulturCart services on the basis of legitimate interests and applicable direct-marketing law. The recipient may object at any time without incurring more than the ordinary transmission cost.

17.3 Vendor and partner marketing

Marketing communications to business contacts are assessed separately and are not sent merely because contact details appear in a register or website. KulturCart records objections and suppression preferences.

17.4 Push and in-app notifications

Push or in-app notifications are used only where the device, browser or application supports them and the required permission has been granted. Transactional and security notifications may remain necessary even where promotional notifications are disabled.

17.5 Advertising measurement

Advertising pixels, retargeting and cross-service measurement are not treated as automatically active. If such technologies are enabled, they are disclosed in the current Cookie Notice and activated only with the required consent.

18. Analytics, service improvement and research

18.1 Operational analytics

KulturCart analyses aggregated and pseudonymised usage, performance, conversion, error and support data to understand service quality, improve workflows and allocate capacity. Whenever possible, reporting is performed without identifying individual users.

18.2 Self-hosted analytics

KulturCart may use self-hosted analytics software such as Matomo. The applicable configuration determines whether cookies, identifiers or consent are required. The live Cookie Notice and consent interface must describe the actual configuration.

18.3 Experiments and feature evaluation

KulturCart may compare feature variants or measure implementation outcomes. Experiments must be proportionate, avoid sensitive inferences, and must not produce legal or similarly significant effects without a separate lawful basis and appropriate safeguards.

18.4 Surveys and research

Participation in surveys or interviews is voluntary unless information is required to fulfil a support or contractual request. Research responses may be aggregated or anonymised. Separate consent is obtained where a testimonial or identifiable quotation will be published.

19. Location, maps and local availability

19.1 Address-based localisation

KulturCart may convert a delivery or store address into geographic coordinates to determine delivery zones, nearby vendors, distance or service availability. This is necessary for the requested local marketplace function.

19.2 Device location

Browser or device location is processed only after the user grants permission. Refusing precise location does not prevent use of address-based functions where an address can be entered manually.

19.3 Map providers

KulturCart aims to use KulturCart-controlled or self-hosted location infrastructure where practicable. If an external map, geocoding or content provider is introduced, its identity, data flows and any consent requirement will be disclosed before activation.

19.4 Location retention

Location information is retained only for the relevant order, store configuration, fraud-prevention or service purpose. Precise location histories are not created unless a specific feature clearly requires and discloses them.

20. Social media and embedded third-party content

20.1 KulturCart profiles

When a person interacts with KulturCart through a social network, both the network operator and KulturCart may process profile, message, reaction and usage data under their respective responsibilities. The network's privacy information applies to its own platform processing.

20.2 Embedded content

Videos, maps, social posts, fonts or other external content can transmit technical data to the provider when loaded. Non-essential embeds should be blocked until consent or opened through a user-initiated link where required.

20.3 No blanket activation statement

This Policy does not claim that Meta, Google advertising, Google Maps or another optional service is active merely because it may be technically available. The current Cookie Notice and live consent configuration are authoritative for optional website integrations.

20.4 Direct links

A simple link to a third-party website does not by itself transfer data to that provider before the user activates the link, apart from ordinary display of the link by KulturCart's server.

21. Vendor onboarding, trader verification and business administration

21.1 Application and verification data

KulturCart processes vendor legal name, trading name, address, representatives, contact information, register and tax details, licences, identity evidence, bank-account confirmation, selected services and risk information to assess onboarding, establish the contract and maintain marketplace integrity.

21.2 Legal bases

Processing is based on pre-contract steps and contract performance, legal obligations, and legitimate interests in verifying counterparties, preventing fraud, protecting customers and documenting authority. KulturCart does not collect verification documents that are unnecessary for the relevant risk and legal context.

21.3 Ongoing accuracy

Vendors must keep their information current. KulturCart may request renewed evidence after a material change, risk event, expiry, complaint or legal update. Verification history is retained to show how a vendor was admitted and monitored.

21.4 Bank and payout information

Bank information is processed to confirm billing or payout instructions, collect agreed fees and prevent misdirection. Full bank details are restricted to personnel and providers who need them for the relevant financial process.

21.5 Business contacts and employees

Contact data of directors, owners, authorised representatives, store managers, cashiers and staff is processed according to their role. The vendor is responsible for providing its personnel with any required information about the disclosure to KulturCart.

22. POS, TSE and fiscalisation data

22.1 POS users and cashiers

Where KulturCart POS is used, KulturCart processes user identifiers, roles, PIN-related authentication data in protected form, shift and transaction references, cash events, device assignments and audit records to provide secure point-of-sale functions.

22.2 Transactions and receipts

POS records may include products, quantities, taxes, payment type, timestamps, receipt references, returns, discounts and customer data where the vendor enters or links it. Vendors should avoid entering unnecessary customer information into fiscal or transaction records.

22.3 TSE and fiskaly

Where Cloud-TSE or related fiscalisation services are activated, required device, client, transaction, signature, receipt, export and status data is processed through fiskaly GmbH and KulturCart systems. Roles depend on the specific function and applicable agreements.

22.4 DSFinV-K and tax exports

KulturCart may generate, store or transmit DSFinV-K and related export files for the vendor. The vendor remains responsible for its tax and retention duties. KulturCart may retain technical evidence of creation, delivery and integrity.

22.5 Fiscal retention

Fiscal, accounting and receipt data is retained according to applicable tax and commercial-law requirements, contractual obligations and the vendor's documented instructions where KulturCart acts as processor.

23. Fraud prevention, security and platform integrity

23.1 Risk signals

KulturCart uses account, device, IP, order, payment, vendor, complaint and behavioural signals to identify account takeover, payment fraud, suspicious orders, counterfeit or prohibited listings, review manipulation, circumvention and other misuse.

23.2 Protective measures

Measures may include authentication challenges, rate limits, manual review, temporary holds, access restriction, listing suspension, evidence preservation and referral to payment providers or authorities. Measures are proportionate to the risk and are reviewed where appropriate.

23.3 Legal basis

Processing is based on legitimate interests in protecting users, vendors, KulturCart and payment systems, and on legal obligations where applicable. Security logs may be retained longer when linked to an incident or claim.

23.4 Confidentiality of detection methods

KulturCart may withhold technical details of fraud or security detection where disclosure would enable circumvention or harm other persons. This does not remove applicable rights to meaningful information and human review.

24. Legal compliance, reporting and claims

24.1 Authority and legal requests

KulturCart may process and disclose data to courts, regulators, tax authorities, law-enforcement bodies, market-surveillance authorities and other competent bodies where required by law or necessary to establish, exercise or defend legal claims. Requests are assessed for authority, scope and proportionality.

24.2 Illegal content and policy reports

Reporter, affected-user, listing, communication and evidence data is processed to assess notices, take interim measures, issue reasons, handle complaints and preserve records under the applicable reporting and enforcement procedures.

24.3 Intellectual-property reports

Rights-holder notices, evidence, vendor responses and decision records are processed to investigate alleged infringement, protect legitimate content and handle repeat-abuse or restoration procedures.

24.4 Product-safety reports

Incident, product, order, customer, vendor, authority and remedy data is processed to assess hazards, warn affected persons, conduct recalls and document compliance.

24.5 Legal claims and insurance

Relevant contracts, orders, communications, logs and evidence may be retained and disclosed to advisers, insurers, debt-collection providers or courts where necessary for claims or defence.

25. Applicants, suppliers, partners and other business contacts

25.1 Applications

If KulturCart receives job, internship or contractor applications, it processes identity, contact, qualifications, employment history, communications and interview information to assess the application. A more specific applicant notice may be provided where recruitment becomes a regular activity.

25.2 Suppliers and service providers

KulturCart processes contact, contract, billing, support, access and compliance information of suppliers and their personnel to manage the business relationship and secure system access.

25.3 Business development and partnerships

Contact and communication data may be processed to evaluate partnerships, integrations, referrals, events or other business opportunities. Unsolicited marketing is not justified merely because a professional address is publicly available.

25.4 Retention

Unsuccessful application or proposal records are deleted after the relevant decision and limitation period unless consent or another lawful basis supports longer retention.

26. Recipients and service providers

26.1 Need-to-know principle

Personal data is disclosed only where necessary for a defined purpose and under an appropriate legal arrangement. Access is limited by role, system permissions and confidentiality obligations.

26.2 Hosting and infrastructure

Current infrastructure recipients may include Hetzner Online GmbH and dataforest GmbH/Avoro for hosting, network, storage, backup or related infrastructure assigned to KulturCart.

26.3 Payments and fiscalisation

Stripe group entities may receive data for payments and connected accounts. fiskaly GmbH may receive data for Cloud-TSE, fiscalisation and related export functions where activated.

26.4 Internal business systems

KulturCart may use self-hosted CS-Cart, Dolibarr, Nextcloud, FreeScout, LiveHelperChat, Matomo and similar software. Installation of software on KulturCart-controlled infrastructure does not by itself make the publisher a recipient. Google Workspace or Google Drive may be used for selected legal, administrative and collaboration records under access controls.

26.5 Professional and public recipients

Data may be disclosed to advisers, auditors, insurers, banks, debt-collection providers, postal or delivery services, authorities and courts where the purpose and legal basis require it.

26.6 Current register

Appendix B lists the principal current provider categories and known providers. The list may change as infrastructure and services evolve. Material changes are reflected in the current Policy or a more specific notice.

27. International data transfers

27.1 EEA preference

KulturCart prefers processing in Germany or the European Economic Area where reasonably practicable. A provider's group structure, support access or technical routing may nevertheless involve another country.

27.2 Adequacy decisions

Where the European Commission has adopted an adequacy decision, data may be transferred on that basis within its scope, including transfers to participating organisations under the EU-U.S. Data Privacy Framework where applicable.

27.3 Standard Contractual Clauses

Where no adequacy decision applies, KulturCart uses appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with transfer assessments and supplementary measures where required.

27.4 Provider-specific safeguards

Payment, collaboration and other global providers may rely on adequacy decisions, the Data Privacy Framework, Standard Contractual Clauses or a combination of mechanisms. Their current privacy and transfer documentation applies to their processing.

27.5 Copies and information

Information about the relevant safeguard may be requested from KulturCart, subject to protection of confidential and third-party information.

28. Retention, deletion and anonymisation

28.1 Purpose limitation

KulturCart retains personal data only as long as necessary for the relevant purpose, contract, legal obligation, security requirement or claim. Different records therefore have different retention periods.

28.2 Commercial and tax records

Invoices, accounting records, transaction evidence and business correspondence are retained in accordance with applicable German commercial and tax rules. Depending on the record type, statutory periods commonly range from six to ten years; invoice retention is generally eight years under current VAT rules.

28.3 Accounts and orders

Account data is retained during the active relationship. Order records are retained for performance, customer rights, accounting, fraud prevention and claims. Optional profile data may be deleted earlier where it is no longer needed.

28.4 Support, complaints and security

Routine support data is retained for the case and a proportionate follow-up period. Complaint, enforcement, fraud and security records may be retained for the applicable limitation period or longer where a proceeding remains open.

28.5 Backups

Deleted information may remain in protected backups until overwritten through the ordinary backup cycle. Backup data is isolated from routine use and restored only for continuity, security or legal reasons.

28.6 Anonymisation

Where information is genuinely anonymised so that a person cannot reasonably be identified, it may be retained for statistics, security, research or service improvement without being personal data.

29. Technical and organisational security

29.1 Risk-based safeguards

KulturCart applies safeguards appropriate to the risk, including access control, role separation, authentication, encryption in transit where appropriate, secure configuration, patching, backups, logging, incident response and confidentiality obligations.

29.2 Access management

Access is granted according to role and need. Privileged access is restricted, reviewed and logged where appropriate. Vendor and customer access is separated by tenant, store, account and permission controls.

29.3 Development and operations

Changes to production systems are tested and controlled according to risk. Development, staging and production data are separated where practicable. Real personal data is not used for testing unless necessary and protected.

29.4 User responsibilities

Users and vendors must protect credentials, devices and access codes, maintain accurate permissions and notify KulturCart promptly of suspected compromise. Security advice is provided in the applicable account and vendor policies.

29.5 No absolute guarantee

No system can eliminate every risk. KulturCart monitors and improves safeguards and responds to incidents, but does not represent that unauthorised access can never occur.

30. Data-subject rights

30.1 Access and information

Subject to the legal conditions, a person may request confirmation whether KulturCart processes personal data and obtain access and the information required by Article 15 GDPR.

30.2 Rectification and completion

Incorrect personal data may be corrected and incomplete data completed under Article 16 GDPR. Some account details can be updated directly through account settings.

30.3 Erasure and restriction

A person may request erasure under Article 17 GDPR or restriction under Article 18 GDPR where the legal conditions are met. These rights do not override retention duties, freedom of expression, public-interest processing or legal claims.

30.4 Data portability

Where processing is based on consent or contract and carried out by automated means, the person may request the data provided to KulturCart in a structured, commonly used and machine-readable format under Article 20 GDPR.

30.5 Objection

A person may object under Article 21 GDPR to processing based on legitimate interests for reasons arising from the person's particular situation. Processing for direct marketing may be objected to at any time.

30.6 Withdrawal of consent

Consent may be withdrawn for the future through the relevant preference control or by contacting KulturCart. The withdrawal does not affect earlier lawful processing.

30.7 Identity verification and response

KulturCart may request proportionate information to verify identity and prevent disclosure to an unauthorised person. Requests are answered within the statutory period, subject to permitted extensions for complexity or volume.

31. Automated decisions, profiling and personalisation

31.1 No undisclosed significant decisions

KulturCart does not currently make solely automated decisions producing legal or similarly significant effects on customers without human involvement, unless a specific process, legal basis and safeguards are separately disclosed.

31.2 Fraud and risk scoring

Automated signals may prioritise orders, accounts, payments or listings for review or apply temporary protective controls. Material adverse measures are reviewed under the applicable enforcement and complaint procedures where required.

31.3 Recommendations and ranking

Recommendation and ranking functions may use location, availability, relevance, popularity, quality, delivery conditions, user preferences and sponsored status. These functions generally organise content and do not constitute a legal decision about the user.

31.4 Marketing profiles

Cross-service advertising or detailed marketing profiles are created only where the required consent and disclosure exist. Users may withdraw consent or object to direct marketing.

32. Children and legal capacity

32.1 Service audience

KulturCart is not designed as a children's service. Purchases and accounts must be created by a person with the legal capacity or required representative authority for the relevant transaction.

32.2 Consent by children

Where consent is the legal basis for an online service offered directly to a child, the age and parental-authorisation requirements of Article 8 GDPR and applicable German law are observed.

32.3 Removal and protection

If KulturCart learns that personal data of a child was collected without an adequate legal basis or required authorisation, it will restrict and delete the data as appropriate, while preserving records required for safety, orders or legal claims.

33. Whether data must be provided

33.1 Contract-required information

Certain information is necessary to create an account, place and fulfil an order, deliver products, process payment or provide requested support. Without it, the relevant service or contract may not be possible.

33.2 Legally required information

Vendor verification, tax, fiscalisation, product-safety and authority requirements may make specific information mandatory. The relevant form or request identifies the required fields.

33.3 Optional information

Optional profile, marketing, survey, precise-location and similar data can generally be withheld without affecting core marketplace use, although the optional feature may then be unavailable.

34. Supervisory authority and complaints

34.1 Right to complain

A data subject has the right to lodge a complaint with a supervisory authority under Article 77 GDPR, particularly in the Member State of habitual residence, place of work or the alleged infringement.

34.2 Competent authority for KulturCart

For a private-sector controller established in Bavaria, the competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, poststelle@lda.bayern.de. The authority provides an online complaint form.

34.3 Contacting KulturCart first

A complaint to an authority is not conditional on contacting KulturCart first. KulturCart nevertheless welcomes the opportunity to investigate and resolve a concern promptly through info@kulturcart.de.

35. Changes, versioning and contact

35.1 Policy changes

KulturCart updates this Policy where processing, providers, technology, law or organisational responsibilities materially change. The current version, effective date and document ID are published with the Policy.

35.2 Notice of material changes

Where appropriate, material changes are communicated through the website, account, email or other suitable channel before they take effect. A new legal basis or consent is obtained where required; continued use is not treated as consent to processing that legally requires affirmative consent.

35.3 Archived versions

Superseded policies are retained internally with their effective periods so that KulturCart can identify the information applicable to a historical processing event.

35.4 Contact

Questions, rights requests, objections and privacy concerns may be submitted to KulturCart - Ibrahim Lawal, Ringstraße 22, 84347 Pfarrkirchen, Germany, email info@kulturcart.de, telephone +49 8561 9080851.

Appendix A - Processing activity matrix

Activity Main data Purpose / legal basis Typical recipients
Website delivery and security IP, request, device, log and error data Technical delivery, security and stability; Art. 6(1)(f) GDPR Hosting and infrastructure providers
Accounts and authentication Identity, contact, credential, role and login data Account contract and security; Art. 6(1)(b), (f) GDPR Hosting, authentication and support systems
Marketplace orders Customer, vendor, product, price, payment, delivery and communication data Contract facilitation and order management; Art. 6(1)(b) GDPR Relevant vendor, payment provider, carrier
Payments Transaction reference, amount, status, risk and limited payment details Payment, fraud prevention and legal obligations; Art. 6(1)(b), (c), (f) GDPR Stripe or the selected payment provider, banks and schemes
Support and complaints Contact, messages, attachments, account/order references Support, contract, legitimate interests and claims Relevant vendor, support systems, advisers where necessary
Vendor onboarding Business, representative, register, tax, bank and verification data Contract, legal obligations and marketplace integrity Verification sources, payment providers, advisers and authorities where necessary
POS and TSE Cashier, role, device, transaction, receipt, signature and export data POS contract, fiscal duties, security and vendor instructions Vendor, fiskaly, infrastructure providers and authorities where required
Marketing and optional analytics Contact, consent, preferences, pseudonymous usage and campaign data Consent or legally permitted direct marketing Consent and communication provider; optional provider disclosed in Cookie Notice
Reports and enforcement Reporter, affected user, listing, evidence, decision and complaint data Legal compliance, platform safety and claims Affected parties, authorities, advisers and providers as necessary

Appendix B - Principal provider and recipient register

Provider / category Function Location / transfer context Role notes
Hetzner Online GmbH Hosting, compute, storage, network and related infrastructure Germany / EEA Processor for allocated KulturCart workloads
dataforest GmbH / Avoro Hosting and infrastructure for allocated self-hosted workloads Germany / EEA Processor for allocated KulturCart workloads
Stripe group entity, including Stripe Payments Europe Limited where applicable Payments, connected accounts, payouts, risk, disputes and financial infrastructure EEA and global group processing subject to current safeguards Controller, processor or both depending on activity
fiskaly GmbH Cloud-TSE, fiscalisation, signatures, receipt and DSFinV-K functions where activated Austria / EEA Processor or independent provider depending on function and agreement
Google Workspace / Google Drive where used Selected legal, administrative and collaboration records EEA and global processing under Google's current safeguards Processor and/or independent controller depending on service
Carriers and delivery partners Dispatch, tracking, delivery, handover and incident handling According to selected carrier Often independent controller for transport duties
Self-hosted software: CS-Cart, Dolibarr, Nextcloud, FreeScout, LiveHelperChat, Matomo and similar Marketplace, ERP, cloud, support, chat and analytics on KulturCart-controlled infrastructure Hosting location of the relevant KulturCart workload Publisher is not a recipient merely because software is installed; external access requires a separate basis
Advisers, insurers, banks, auditors, authorities and courts Advice, claims, financial processing and legal compliance According to recipient and legal requirement Independent controller or professional recipient

Appendix C - Retention matrix

Record category Typical retention approach Reason
Server and security logs Usually days or months; longer for incidents Operations, security and evidence
Account profile Active relationship plus a limited closure period Service, fraud prevention and claims
Orders, invoices and accounting records Applicable commercial and tax periods, commonly six to ten years; invoices generally eight years HGB, AO, UStG and claims
Payment and refund references Order/accounting period plus dispute requirements Reconciliation, chargebacks and fraud
Support and routine communications Case duration plus proportionate follow-up period Service quality and evidence
Complaints, enforcement and safety cases Case duration plus limitation, regulatory or recall period Compliance, restoration and claims
Vendor verification and contracts Relationship plus legal retention and limitation periods Counterparty verification and contractual evidence
POS/TSE and fiscal exports Statutory tax/fiscal period or vendor instruction under the DPA Fiscal compliance and evidence
Consent and objection records As long as needed to demonstrate consent, withdrawal or suppression Accountability and marketing compliance
Backups Ordinary protected overwrite cycle Continuity and disaster recovery

Appendix D - Role allocation matrix

Processing context KulturCart role Other party role Key consequence
Marketplace platform operation, account security and governance Independent controller Vendor or user may be a separate controller for own purposes Each party provides information for its own processing
Customer sale, fulfilment, returns and statutory warranty Marketplace facilitator for its functions Vendor generally independent controller and seller Customer claims and vendor processing are primarily directed to vendor
Vendor-directed data functions expressly covered by the DPA Processor Vendor controller Documented instructions and Art. 28 GDPR terms apply
Payment processing Controller and/or processor for limited platform functions Payment provider controller, processor or both Provider's current privacy information applies
Carrier delivery Controller for marketplace coordination Carrier often independent controller Only necessary delivery data is disclosed
Cloud-TSE and fiscalisation Controller or processor depending on service Vendor controller for its fiscal records; fiskaly processor/provider Annex 1 and DPA allocate activity-specific duties
Optional jointly designed campaign or integration To be assessed Partner role to be assessed Joint-controller arrangement is documented if purposes and essential means are jointly determined

Appendix E - Rights and request matrix

Request Information to provide Possible limitation
Access Identity, account/contact reference and desired scope Rights of others, legal privilege and excessive requests
Rectification Incorrect data and correct replacement Historical records may be preserved with correction note
Erasure Data or context to be erased Legal retention, claims, freedom of expression and public interest
Restriction Processing and reason for restriction Storage and permitted legal processing may continue
Portability Account and relevant contract-based automated data Applies only under Art. 20 GDPR conditions
Objection Processing and particular situation; no reason needed for direct marketing Compelling legitimate grounds or legal claims may override non-marketing objection
Consent withdrawal Consent or technology to withdraw Prospective only; prior lawful processing remains valid
Complaint Description, dates, account/order and supporting evidence May be referred to vendor or another controller where appropriate