Privacy Policy

Privacy at a Glance
General Information
This section provides a simple overview of what happens to your personal data when you visit this website. Personal data refers to any information that can uniquely identify you. For detailed information, please see the full Privacy Policy below.

Data Collection on This Website
Responsible Party
Data processing on this website is carried out by the website operator. Their contact details can be found in the “Note on the Responsible Party” section.

How We Collect Your Data
You provide data directly, for example via contact forms.
Other data is collected automatically or with your consent, such as technical details (browser, OS, timestamps), by our IT systems upon visiting the site.

Purposes of Data Processing
To ensure error-free website delivery.
To analyze user behavior.
For contract offers, orders, or other inquiries submitted via the site.

Your Data Rights
You can request, free of charge, access to the origin, recipients, and purpose of your data. You have rights of correction, deletion, processing restrictions, and to withdraw consent at any time. You may also file a complaint with supervisory authorities.

Hosting
Our website content is hosted by:
IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.
IONOS logs including IP addresses are collected. Refer to IONOS’s privacy policy for details.

Legal Basis
Based on Art. 6(1)(f) GDPR (legitimate interest in website reliability).
With consent, based on Art. 6(1)(a) GDPR & § 25(1) TDDDG (e.g., cookie storage or device fingerprinting). Consent is revocable.

General Legal & Mandatory Information
Data Protection Statement
We treat your personal data confidentially per legal regulations and this policy.

Transmission Security Disclaimer
Data transfer over the internet (e.g., email) may involve security vulnerabilities; absolute protection is not guaranteed.

Note on Responsible Party
Kollektiv Stromzirkel
Christian Fakler
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen

The responsible party determines the purposes and means of processing personal data.

Storage Duration
Your personal data is stored until the purpose of processing is no longer valid. If you request deletion or withdraw consent, data is erased unless legally required retention applies (e.g., tax or commercial law).

Legal Bases for Data Processing
With Consent: Art. 6(1)(a), Art. 9(2)(a) GDPR; consent can include third‑country transfers per Art. 49(1)(a).
Contractual: Art. 6(1)(b) GDPR.
Legal Obligation: Art. 6(1)(c) GDPR.
Legitimate Interest: Art. 6(1)(f) GDPR, as specified for each processing activity.

Transfers to Third Countries
Tools from non-EU countries (e.g. USA) may process your data outside the EU. Such countries may not guarantee adequate data protection. We do not control these processes and U.S. authorities may request personal data.

Withdrawal of Consent
You may withdraw any consent at any time. Processing before withdrawal remains lawful.

Right to Object (Arts. 21(1) & 21(2) GDPR)
Art. 6(1)(e, f): You may object any time for reasons related to your situation, including profiling. After objection, data processing ceases unless we can show overriding legitimate grounds or legal claims.
Direct Marketing: You have a separate right to object. After objection, your data will no longer be used for direct marketing or related profiling.

Right to Complain
You may lodge a complaint with a supervisory authority in your country of residence or where the alleged violation occurred, without affecting other legal remedies.

Right to Data Portability
You can request the data we process automatically via consent or contract in a machine-readable format. Direct data transfer to another controller is possible if technically feasible.

Rights to Access, Rectify, Erase
Within legal limits, you can request free access to your data, its origin, recipients, and purpose. You can also request correction or deletion. Contact us at any time.

Right to Restrict Processing
You may request processing restrictions in specific cases, such as:
Disputed accuracy of data (while verification occurs).
Unlawful processing; limitation instead of erasure may apply.
Data no longer needed by us, but required by you for legal claims.
Pending an Art. 21(1) GDPR objection, until interests are balanced.

During restriction, your data may only be processed for your consent, legal claims, rights of others, or important public interest.

Data Collection on This Website
SSL/TLS Encryption
This site uses SSL/TLS for secure transmission. Look for https:// and the lock icon. Data transmitted is unreadable by third parties.
Cookies
Session Cookies: Temporary, deleted after browsing session.
Persistent Cookies: Remain until manually deleted or browser clears them.
First-Party & Third-Party Cookies: Used for site functionality, payments, analytics, or advertising.
Necessary cookies are based on Art. 6(1)(f) GDPR. Other cookies require your consent, and consent may be revoked. Browser settings can manage cookie acceptance.
Details on specific cookies and services are included in this privacy policy.

Social Media Integration
Instagram
Embedded Instagram features connect directly to Meta’s servers.
If you’re logged in, Instagram may link this visit to your account.
We do not control data usage by Instagram.
Processing is based on your consent (Art. 6(1)(a) GDPR & § 25(1) TDDDG).
We are jointly responsible with Meta for data collection and transfer; find details in Meta’s controller addendum.
U.S. data transfer is based on EU standard contractual clauses. Meta is certified under the EU‑US Data Privacy Framework.

YouTube
Embedded YouTube videos connect your device to Google Ireland.
Google may set cookies/device fingerprints and collect usage data.
If logged in, visits may be linked to your account.
Processing is based on legitimate interest (Art. 6(1)(f)) unless consent is obtained (then Art. 6(1)(a) GDPR & § 25 TDDDG).
Google is EU‑US Data Privacy Framework certified.

Spotify
Embedded Spotify plugins connect your browser to Spotify AB.
Spotify collects data, and may use Google Analytics cookies.
We are not responsible for data processing by Spotify.
Processing is based on legitimate interest (Art. 6(1)(f)) or—if consented—Art. 6(1)(a) GDPR & § 25 TDDDG.
You can log out of Spotify to prevent linking visits to your account.

Source
Original template (in German) from e‑recht24: https://www.e-recht24.de