Privacy Policy
Last updated: 5 August 2026
Introduction
This privacy policy informs you which personal data (hereinafter “data”) we process, for what purposes and to what extent. It applies to all processing carried out by us, in particular on our websites, in mobile applications and within external online presences (collectively, our “online services”).
Contents
- Introduction
- Controller
- Overview of processing operations
- Applicable legal bases
- Security measures
- Transfer of personal data
- Processing in third countries
- Use of cookies
- Commercial & business services
- Payment service providers
- Newsletter
- Online marketing
- Product search & search statistics
- Social media presences
- Plugins & embedded content
- Erasure of data
- Changes to this policy
- Rights of data subjects
- Definitions
Controller
Lebendigeweine.de
Taits U.G. (haftungsbeschränkt)
Konrad-Wolf-Straße 72
13055 Berlin, Germany
Managing Director: Dimitri Taits
Email: [email protected]
Overview of processing operations
The following overview summarises the types of data processed, the purposes of processing and the data subjects concerned.
Types of data processed
- Master & contract data (e.g. names, addresses, order ID, contract terms)
- Contact data (email, telephone)
- Payment data (e.g. IBAN, Stripe token, PayPal transaction ID)
- Usage & meta/communication data (IP address, device information, log files)
- Content data (e.g. contact and review forms)
- Location data (where enabled on the device)
Categories of data subjects
- Customers & prospective customers
- Contractual partners & suppliers
- Communication partners
- Users of our online services
Purposes of processing
- Performance of contracts, shipping & payment processing
- Newsletter & direct marketing (with opt-in)
- Web analytics & audience measurement
- Security measures & fraud prevention
- Online marketing / remarketing
- Office & organisational procedures
Applicable legal bases
- Consent (Art. 6(1)(a) GDPR)
- Performance of a contract / pre-contractual measures (Art. 6(1)(b) GDPR)
- Legal obligation (Art. 6(1)(c) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
For transfers to third countries, we rely on the EU Standard Contractual Clauses (SCC) or the EU-US Data Privacy Framework (DPF), provided the provider is certified accordingly.
Security measures
We implement technical and organisational measures in accordance with Art. 32 GDPR (including SSL/TLS encryption, access control, data processing agreements and data backups).
Transfer of personal data
Data is only disclosed where this is necessary for the performance of a contract, on the basis of a legal obligation or on the basis of our legitimate interests. Categories of recipients include in particular:
- Hosting & CDN: Timme Hosting (DE), Hetzner Online GmbH (DE – search server & own services), Cloudflare (USA, SCC/DPF – CDN, web infrastructure & email delivery)
- Payment service providers: Stripe Payments (EU), PayPal (EU)
- Newsletter: Listmonk (self-hosted on a server of Hetzner Online GmbH, DE), sent via SendGrid (Twilio USA, DPF); subscription confirmations via Cloudflare (USA, SCC/DPF)
- Shipping logistics: Sendcloud (NL), DHL, UPS; wine is in some cases shipped directly from our logistics partner’s warehouse – for this purpose the partner receives your name and delivery address
- Accounting: Lexware Office (Haufe-Lexware GmbH & Co. KG, DE) – invoice and payment data
- Legal & tax advice: Thoelke Przybilla Schaffner PartG mbB (DE)
Processing in third countries
Where data is processed in countries outside the EEA, we ensure an adequate level of data protection by means of SCC, DPF certification or equivalent safeguards.
Use of cookies
We use cookies and similar technologies. Details are set out in our cookie banner (Usercentrics Cookiebot) and the consent history available there.
Commercial & business services
We process the data of customers and prospective customers for the performance of contracts, shipping and customer service. Retention period for tax-relevant data: 10 years.
Payment service providers
- Stripe Payments Europe Ltd., Ireland – Privacy Policy
- PayPal (Europe) S.à r.l., Luxembourg – Privacy Policy
Newsletter
For our newsletter (Weinbrief) we use the Listmonk software, which we host ourselves on a server of Hetzner Online GmbH in Germany. Newsletters are sent via SendGrid (Twilio Inc., USA, DPF). Subscription follows the double opt-in procedure: you receive an email (sent via Cloudflare) with which you confirm your subscription. We store the time and IP address of subscription and confirmation as proof. We analyse opens and clicks in order to improve the newsletter. You can unsubscribe at any time via the link included in every newsletter. Unsubscribed addresses are kept on a suppression list so that they are not contacted again.
Online marketing & web analytics
- Google Analytics 4 (IP anonymisation) – Google Ireland Ltd.; opt-out via browser add-on
- Meta Pixel (Facebook & Instagram Ads) – Meta Platforms Ireland Ltd.; opt-out via ad settings
Product search & search statistics
We operate the product search ourselves, on our own servers (Typesense search server, Hetzner Online GmbH, Germany). When you use the search, we process the search text entered, selected filters, number of results, language setting, time and a randomly generated session identifier that is stored only in the current browser tab and expires when that tab is closed. IP addresses and account data are not stored in the search log. Purposes: provision of the search function, measuring and improving search quality (e.g. queries without results) and protection against misuse. Search events are automatically deleted after 90 days.
If a session in which the search was used leads to an order, we store the session identifier with the order in order to measure the contribution of the search to the purchase. As a result, the search history of that session may be linked to the order for the duration of the 90-day retention period. The legal basis is our legitimate interest in measuring and improving our own services (Art. 6(1)(f) GDPR); you may object to this linking at any time (Art. 21 GDPR).
For search queries that are difficult to interpret, the search text – without names, account or order data – may be transmitted in anonymised form to Anthropic PBC (USA) for linguistic analysis; the legal basis for the transfer is the EU-US Data Privacy Framework.
Social media presences
We maintain profiles on Facebook, Instagram, LinkedIn & X. When you visit them, the privacy policy of the respective platform applies.
Plugins & embedded content
- YouTube videos (privacy-enhanced mode)
- Google Maps (only with consent)
- ReCaptcha v3 (spam protection)
- Google Fonts (hosted locally)
Erasure of data
Data is erased as soon as the purpose of processing ceases to apply and there is no statutory retention obligation. Where appropriate, data is restricted instead of erased.
Changes to this policy
We amend this privacy policy whenever changes to our data processing make this necessary. Please check it regularly.
Rights of data subjects
- Withdrawal of consent given (Art. 7 GDPR)
- Access, rectification, erasure, restriction of processing (Arts. 15–18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to direct marketing & processing based on legitimate interests (Art. 21 GDPR)
- Lodging a complaint with a supervisory authority (Art. 77 GDPR)
Definitions
Terms such as “profiling”, “consent”, “SCC” etc. have the meanings given in the GDPR (Art. 4) and the EDPB guidelines.