Skip to content
Legal

Privacy Policy

Last updated: September 19, 2026Version 1.0
On this page
  1. 1. Controller
  2. 2. General principles
  3. 3. What data we process
  4. 4. Cookies
  5. 5. Audience measurement
  6. 6. Commission links
  7. 7. Processors and external services
  8. 8. Retention
  9. 9. No automated decision-making
  10. 10. Your rights (GDPR Art. 15 to 22)
  11. 11. Backups and deletion periods
  12. 12. Minimum age
  13. 13. Security (GDPR Art. 32)
  14. 14. Data breach notification

1. Controller

The controller for data processing within the meaning of the GDPR is:

Robert Gürgens
Software- und IT-Dienstleistungen
Suhler Straße 17
12629 Berlin
Germany

Email: dpo@gartenkern.de

We are not legally required to appoint a data protection officer. The address above reaches the controller directly.

2. General principles

We process personal data of our users only to the extent necessary to provide a functional platform and to fulfil our contractual and legal obligations (data minimisation, Art. 5 GDPR).

  • Art. 6 (1)(a) GDPR: consent, where you grant it separately for individual features
  • Art. 6 (1)(b) GDPR: performance of a contract (account, platform use)
  • Art. 6 (1)(c) GDPR: legal obligation (accounting, taxes)
  • Art. 6 (1)(f) GDPR: legitimate interests (security, abuse detection)

You may withdraw consent at any time with effect for the future (Art. 7 (3) GDPR). The lawfulness of processing carried out before withdrawal remains unaffected.

3. What data we process

DataPurposeLegal basis
Email, display nameAccount creation, loginArt. 6 (1)(b)
Workspace and garden content (plantings, journal, tasks, images)Platform useArt. 6 (1)(b)
Garden location polygonMap and weather featuresArt. 6 (1)(b)
EXIF data in uploaded imagesStripped before storage (data minimisation)not applicable
Technical checksum of uploaded imagesMatched against content we previously removed, prevents re-upload. The image itself is not stored for this.Art. 6 (1)(f)
Content you set to "Community" or "Public"Display to signed-in users or to any visitor. Voluntary, revocable at any time; shown without your name.Art. 6 (1)(a)
Reports submitted via the "Report content" button (statement, optional contact details, IP)Handling under DSA Art. 16, record of handling, abuse protection via rate limitArt. 6 (1)(c), Art. 6 (1)(f)
IP address on login and uploadSecurity, abuse detectionArt. 6 (1)(f)
Server log files (IP, timestamp, requested resource, status code)Operation, debugging, attack defenceArt. 6 (1)(f)
Payment references and subscription statusContract performance, accountingArt. 6 (1)(b), Art. 6 (1)(c)
Cancellation declaration submitted through the cancellation button (contract number, email, name, reason)Evidence under § 312k (3) and (4) of the German Civil CodeArt. 6 (1)(c)
Redemption of an invitation or promotional code (your account, garden account, plan effect granted, time; when redeemed through an invitation link, also IP address and browser identifier)Evidence of which code granted which plan and when; protection against repeated redemptionArt. 6 (1)(b), Art. 6 (1)(f)
Gartenbörse listing data (title, description, images, approximate location, price details)Publication of the listing, editorial approvalArt. 6 (1)(b)
Contact details inside a listing (name, phone, email, messenger, street and house number, exact coordinates)Disclosure to signed-in interested parties, and only for the channels you release yourselfArt. 6 (1)(b)
Contact reveal log (your account, channel revealed, timestamp, IP address)Two daily budgets against bulk harvesting of contact detailsArt. 6 (1)(f)
Order data for a listing (amount, runtime, payment reference, withdrawal)Contract performance, accountingArt. 6 (1)(b), Art. 6 (1)(c)
Platform enquiry to a provider and the replies to it (messages, the writing account, timestamp, read status and ending per side, lock by moderation)Delivery to the other side, marking unread messages; retrospective warning of interested parties should the listing turn out to be fraudulentArt. 6 (1)(b), Art. 6 (1)(f)
Consent to product news and gardening tips by email (address, timestamp, how it was given; plus IP address and browser identifier when you click the confirmation link)Sending the newsletter; proof of consent under Art. 7 (1) GDPRArt. 6 (1)(a), Art. 6 (1)(c)
Cookies (session, locale, theme)Platform function (strictly necessary)Art. 6 (1)(b) + § 25 (2) TDDDG

Gartenbörse: revealing contact details

The contact details of a listing are not shown on the public page. Signed-in interested parties reveal them deliberately, and we record every reveal: the account doing it, the channel revealed (phone, email, messenger, exact location), the timestamp and the IP address.

We do this because bulk harvesting of phone numbers would be invisible without those entries. From them we compute two daily budgets, one per account and one per IP address. Once a budget is exhausted we refuse further reveals and note that in the security logs described in section 8. The legal basis is Art. 6 (1)(f) GDPR; our legitimate interest matches that of the providers whose number would otherwise end up in somebody else's data collection.

The provider does not learn who revealed their details. We disclose neither your account nor your IP address nor the timestamp to them. Should we one day show them a number, such as how often their phone number was viewed, it stays a number with no person behind it.

Gartenbörse: the platform enquiry

If you want to write to a provider without disclosing your email address, the platform enquiry is the way. Your message then sits with us, and the provider receives it in the Gartenbörse inbox and, depending on their notification settings, also by email. Your display name goes along, your address does not: the reply travels back through the platform.

You will find the provider's reply in the Gartenbörse inbox under “Messages”. The conversation continues there, in both directions. Both sides see the whole thread, but for each message at most the display name of the person who wrote it; email address and phone number stay hidden. So that we can mark new messages as unread, we keep track of when each side last opened the thread. The other side does not see that time. If one side ends the conversation, we store which side did so and when. As long as it stays ended, nobody can reply there; if the provider side ended it, the listing also takes no new inquiry from that person. The other side learns of a new enquiry or reply by email, as a notification in Gartenkern and by push, depending on what they have chosen in their notification settings.

If you report a conversation, moderation reads its history to decide on the report.

The message stays on file after delivery, and it does so for a second purpose: should a listing be removed as fraudulent, warning the interested parties retrospectively is the most effective protection, and for that we need the list of who enquired (Art. 6 (1)(f) GDPR).

How long the entries from both subsections remain is set out in section 8.

Product news and gardening tips (newsletter)

During registration and in your settings you can agree to receive product news and gardening tips by email. Agreeing is optional and not part of the contract: without it your account works exactly the same. The legal basis is your consent under Art. 6 (1)(a) GDPR.

We only write to you once you have confirmed (double opt-in). When you tick the box, we first send a single email: the request to confirm your subscription via a link. Only when you click that link do we add you to the list. If you do not confirm, you receive no newsletter. The link is valid for seven days; after that it expires and you can subscribe again if you want to. We send a new confirmation email no earlier than five minutes after the last one.

What we record. Our database holds only a check value of the confirmation link, never the link itself. Separately from that we keep the proof Art. 7 (1) GDPR requires: your email address, what the consent covered, whether you granted or withdrew it, by which route (registration, settings, unsubscribe link) and the timestamp. When you click the confirmation link, your IP address and browser identifier are added, because that click is precisely what shows the subscription came from the mailbox in question. For the tick box during registration we store no IP address: our sign-in service does not pass it through on that route, and a wrong address would be worthless as proof.

Sending. The newsletter goes out through the same provider that delivers our other email (Proton AG, see Section 7). We do not use a separate newsletter service with open or click tracking.

Withdrawal. You can withdraw at any time, without giving reasons: via the unsubscribe link at the end of every email or via the switch in your settings. We then send you no further newsletters. If you change your account's email address, the confirmation lapses by itself: you receive newsletters again only once you have confirmed the new address too. How long the proof of consent and withdrawal is kept is set out in Section 8.

4. Cookies

We use strictly necessary cookies only:

  • ory_kratos_session: login session (essential, session cookie)
  • csrf_token_…: cross-site request forgery protection (essential)
  • NEXT_LOCALE: selected language (essential)
  • theme: light or dark preference (essential)
  • gartenkern_invite_token: validation of your invite code during the closed beta (essential, HttpOnly, expires after 2 hours)

There is no tracking and no profiling, and we embed no third-party advertising scripts. A cookie consent banner is therefore not required under § 25 (2) TDDDG. Commission links on public pages are unaffected: they are ordinary links and set no cookie on our side (see the commission links section).

5. Audience measurement

We want to know which pages are read and whether what we offer lands. For that we use no Google Analytics and no other outside service, but our own measurement on our server in Nuremberg. It sets no cookie and stores or reads nothing on your device.

For a page view we store:

  • the page you opened, in coarsened form. /gardens/8f2c… becomes /gardens/{id}; the identifier itself is discarded.
  • the language of the page (de or en)
  • the referring site, but only its address without additions: google.com/search?q=… becomes google.com. A search term never reaches us.
  • browser family (e.g. "Chrome"), operating-system family (e.g. "Android") and device class (phone, tablet, desktop)
  • the country, where the local GeoLite2 database provides it. Deliberately only the country, no city, no region.
  • a pseudonym valid for one day (see below)

We do not store your IP address. It goes into the calculation of the pseudonym and is discarded afterwards.

How the pseudonym works. From your IP address, your browser identifier and a secret random value that changes every day we compute a checksum. It lets us tell that two views on the same day likely came from the same person. Once that day's random value is deleted (after two days at the latest), the checksum cannot be traced back to a person, and the next day the same person yields a different one. Recognising and following someone across days is therefore technically impossible.

We also count certain events without a personal reference, such as "a garden was created for the first time" or "a subscription was taken out". The contents of your garden, your journal entries or your photos are not transmitted.

Search terms without results. When you submit a search on our search page and it returns nothing at all, we keep the search term. It tells us which magazine article or which plant in the encyclopedia is missing. We store only the term itself in lower case, together with a counter and the time of the last search. No IP address, no pseudonym value, no link to your account. Two searches therefore cannot be recognised as belonging together. Input that looks like personal data (email addresses, phone numbers, long digit sequences, whole sentences) is not stored at all. Neither are searches that did return results, nor the suggestions shown while you type. After 90 days without another search we delete the term.

Legal basis is our legitimate interest in data-minimising audience measurement (Art. 6 (1)(f) GDPR). Since we neither store nor read anything on your device, § 25 (1) TDDDG does not apply and no consent is required.

Retention: individual measurements are deleted after 90 days. What remains are aggregate numbers (e.g. "1,200 views of the pricing page in May") that no longer relate to a person.

Country lookup uses the GeoLite2 database by MaxMind (CC BY-SA 4.0). It sits locally on our server; no query is sent to MaxMind.

Public pages occasionally carry links to partner shops. If you buy something there, we receive a commission. The price does not change for you. Every such link is labelled as advertising; the transparency page lists the programmes we use.

What happens on our side. The link first goes to our own redirect address under gartenkern.de/go/. There we increment a daily counter per offer and page area, that is, a number of the form "offer X, 14 August, magazine: 12 clicks". We store no IP address, no cookie, no identifier and no history in the process. The number cannot be attributed to a person, not even by us.

We do not pass on where you came from. The redirect sends the header Referrer-Policy: no-referrer, so the partner does not learn which article you were reading before you clicked.

What happens at the partner. After the redirect you are on the partner's site, where their privacy policy applies. Affiliate programmes generally set their own cookie or a comparable identifier on their own domain in order to attribute a later purchase to the referral. That happens under the partner's responsibility, not ours: we are neither their processor nor a joint controller with them. We receive no personal data about you from there, only settlement totals.

Why there is no consent banner for this. § 25 (1) TDDDG requires consent where information is stored on your device or read from it. Clicking a commission link does neither. The partner's identifier is set on the partner's own site after you have opened it, and therefore outside our reach.

Because the count cannot be attributed to a person, no personal data within the meaning of Art. 4 (1) GDPR is processed. The technical access logs of the redirect are treated like all others (see the retention section).

7. Processors and external services

ProviderPurposeLocationLegal basis
netcup GmbHHostingDE NurembergDPA under Art. 28 GDPR
Hetzner Online GmbHBackup storage (encrypted)DEDPA under Art. 28 GDPR
Proton AGEmail receipt and deliveryCH (adequacy decision)DPA
Stripe Payments Europe, Ltd.Payment processing (subscriptions, invoices)IE (EU)DPA under Art. 28 GDPR
PayPal (Europe) S.à r.l. et Cie, S.C.A.Payment processing, if you choose PayPalLU (EU)Art. 6 (1)(b)
Mistral AI SASPlant recognition, AI chat, season summaries, receipt and meter OCR, disease diagnosisFR (EU)DPA under Art. 28 GDPR
OpenRouter, Inc.Public plant knowledge enrichment and DE/EN translationsUS (SCCs)Art. 28 + Art. 46 GDPR
Cloudflare, Inc.Bot check (Turnstile) on the forms without an accountUS (SCCs)DPA + Art. 46 GDPR
Google Ireland LimitedDelivery of Android app notifications (Firebase Cloud Messaging)IE (EU), also US (SCCs)DPA + Art. 46 GDPR

Mistral La Plateforme (servers in the EU, France) processes on our behalf:

  • Plant photos for recognition (plant identify) and disease diagnosis
  • AI chat requests with journal context, only if you use the AI chat
  • Season summaries about your garden, only if you generate them
  • Receipts you upload to the expense book
  • Meter reading photos you upload to meter tracking

Mistral processes this content solely for inference and deletes it from audit logs within 30 days, as contractually assured. No training use takes place. We store neither the original image nor raw Mistral responses long term; only the structured result (recognised plant, extracted receipt item, answer text) enters your garden.

For public data without personal reference (general plant knowledge enrichment in our plant knowledge base, DE/EN translations of plant content and blog articles) we additionally use OpenRouter, Inc. (USA, under EU standard contractual clauses per Art. 46 GDPR). Your journal entries, AI chat requests, and photos are never processed there; the router refuses those routes technically.

A detailed sub-processor list with models and architecture guarantees is available on request at dpo@gartenkern.de.

When you take out a paid subscription, the payment provider you choose (Stripe Payments Europe, Ltd., Ireland, or PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg) processes your payment data, for example payment method and billing address. PayPal acts as an independent controller in this respect. We ourselves store no complete payment data, only the provider's reference IDs and the subscription status.

External services your browser contacts directly

For some features, your browser contacts external services directly; for technical reasons your IP address is transmitted. Unless stated otherwise below, these services are not processors but independent recipients. The legal basis is our legitimate interest in providing the respective feature (Art. 6 (1)(f) GDPR):

ServicePurposeLocationServer contacted
OpenFreeMapMap tiles (standard map view)EU (public instance)tiles.openfreemap.org
Official aerial imagery services of the German statesAerial tiles, as soon as you switch to "aerial"DE (state authorities)the state services in the table below
Open-MeteoWeather data for your garden (no API key, no tracking)DE/EUapi.open-meteo.com
Photon (komoot GmbH)Address search on the location mapLocation of the instance not publicly statedphoton.komoot.io
Cloudflare TurnstileBot check on the forms you can submit without an accountUS (standard contractual clauses)challenges.cloudflare.com

The aerial view on the location map: The location map first shows the OpenFreeMap base map. Only when you switch to "aerial" does your browser fetch image tiles from an official surveying service. As long as the base map is showing, no request goes out to them at all. And when one does, it goes to the single service responsible for the centre of the visible map section, never to the whole list.

What is transmitted is your IP address, the requested map section (the coordinates of the individual image tile, that is, the area you are currently looking at), the time of the request and the details your browser sends with every image request, such as its user agent. The legal basis is Art. 6 (1)(f) GDPR; without an aerial view a plot of land is hard to find again on a map. These services are state bodies and therefore independent controllers: how they keep their server logs, and for how long, is up to them.

Which service is queried depends on the federal state:

Federal stateServiceServer contacted
Baden-WürttembergLandesamt für Geoinformation und Landentwicklung (LGL-BW)owsproxy.lgl-bw.de
BavariaLandesamt für Digitalisierung, Breitband und Vermessunggeoservices.bayern.de
Berlin and BrandenburgLandesvermessung und Geobasisinformation Brandenburg (LGB)isk.geobasis-bb.de
BremenLandesamt GeoInformation Bremengeodienste.bremen.de
HamburgFreie und Hansestadt Hamburg, Landesbetrieb Geoinformation und Vermessung (LGV)geodienste.hamburg.de
HesseHessisches Landesamt für Bodenmanagement und Geoinformationwww.gds-srv.hessen.de
Lower SaxonyLandesamt für Geoinformation und Landesvermessung Niedersachsen (LGLN)opendata.lgln.niedersachsen.de
Mecklenburg-Western PomeraniaLandesamt für innere Verwaltung M-V, Amt für Geoinformation, Vermessung und Katasterwesenwww.geodaten-mv.de
North Rhine-WestphaliaGeobasis NRWwww.wms.nrw.de
Rhineland-PalatinateLandesamt für Vermessung und Geobasisinformation Rheinland-Pfalz (LVermGeo RP)geo4.service24.rlp.de
SaarlandLandesamt für Vermessung, Geoinformation und Landentwicklung (LVGL)geoportal.saarland.de
SaxonyLandesamt für Geobasisinformation Sachsen (GeoSN)geodienste.sachsen.de
Saxony-AnhaltLandesamt für Vermessung und Geoinformation Sachsen-Anhalt (LVermGeo)www.geodatenportal.sachsen-anhalt.de
Schleswig-HolsteinLandesamt für Vermessung und Geoinformation Schleswig-Holstein (LVermGeo SH)dienste.gdi-sh.de
ThuringiaThüringer Ministerium für Digitales und Infrastruktur (GDI-Th)www.geoproxy.geoportal-th.de

All sixteen federal states are covered. If your garden sits outside Germany, the base map stays in place and no state service is contacted. Which state a point belongs to is decided along the state borders from the administrative areas published by the Federal Agency for Cartography and Geodesy. Those borders sit as a file inside our application and are not fetched at runtime: the agency learns nothing about your use of the map.

The address search on the location map: When you type an address into the location form, your browser asks the Photon geocoder for suggestions from the second character onwards. What is transmitted is your input verbatim, the language of your interface, your IP address and, if a point has already been set for the garden, its coordinates as a proximity hint for better matches. If you create a garden with a postal code, that postal code goes out once along the same path so the map can place the garden roughly. If you type nothing and give no postal code, no request goes out; you can also set the point directly on the map without searching.

Photon is an open geocoder built on OpenStreetMap data. The public instance at photon.komoot.io is operated by komoot GmbH, Kienberger Allee 4, 12529 Schönefeld, Germany. There is no separate privacy policy and no separate terms of use for that instance, and komoot does not publicly state where its servers are located. We therefore cannot assure you that your search input stays inside the EU. The legal basis is Art. 6 (1)(f) GDPR; we plan to run the geocoder ourselves in the medium term.

The bot check on the open forms: Forms you can submit without an account (report content, suggest a correction, enquiry for educational institutions) are protected against automated submissions by Cloudflare Turnstile. The widget loads from challenges.cloudflare.com when the form opens; what is transmitted is your IP address, technical details of your browser and the result of the check. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, USA, which acts as a processor for us in this respect; the transfer to the USA relies on the EU standard contractual clauses under Art. 46 GDPR. The legal basis is our legitimate interest in keeping these forms open without an account while not losing them to spam (Art. 6 (1)(f) GDPR).

Services our server contacts

Some features are fetched not by your browser but by our server. Your IP address does not go out in that case, but the details the respective feature needs do. The processors from the table above (Mistral, OpenRouter, Stripe, PayPal, Proton) are likewise contacted by our server; they are listed there because they process on our behalf.

The backdrop in the garden editor: The layout editor can show an aerial image of your garden behind the drawing surfaces. Our server fetches that image from the same official state service that also serves the location map; which one it is follows from the centre of your garden's map section, along the same state borders as above. What is transmitted is the map section of your garden, but not your IP address and no reference to your account. We store the image in our object storage; your browser then loads it from us, not from the state service. If your garden lies outside Germany, no request goes out, and the editor tells you so. The legal basis is Art. 6 (1)(f) GDPR.

Weather data for frost warnings and the garden journal: For the frost warning, the watering recommendation and the weather we attach to your journal entries, our server queries Open-Meteo. What is transmitted is the coordinates of your garden and the period requested, not your IP address and no reference to your account. The weather tile on the dashboard, by contrast, queries Open-Meteo directly from your browser (see above). The legal basis is Art. 6 (1)(f) GDPR.

Push notifications: If you enable notifications, your browser registers a subscription with its own push service and hands us its address. When a notification is due, our server calls that address, that is, a service run by Mozilla, Google or Apple depending on the browser. The content is encrypted for the push service (RFC 8291); it sees the address of the subscription and the time, not the text of the message. In the Android app, Firebase Cloud Messaging (Google Ireland Limited) delivers the notification; Google can read its title and short text. We store only a technical push subscription, which you can revoke at any time in your settings.

Other recipients

Calendar subscription: If you set up a calendar subscription in your settings, you receive a secret address that you can add to a calendar app of your choice. That app's provider (for example Google, Apple or Microsoft) then fetches the address on its own, regularly, and in doing so receives the titles, descriptions, locations and times of your garden dates as well as the IP address of the fetching server. Where that server is located is up to the respective provider; with Google and Microsoft, processing outside the EU is likely. The subscription is read-only, no data flows back to us from the calendar app. You can create a new address or withdraw it entirely in your settings at any time; it stops working immediately afterwards.

Notifications in the Android app: If you turn on notifications in the Android app, Firebase Cloud Messaging by Google Ireland Limited delivers them. Google receives a technical identifier of the app on your device, the time, and the title and short text of each notification. Google may also process this data outside the EU, in particular in the US; the transfer is based on the EU standard contractual clauses under Art. 46 GDPR. You can turn the notifications off at any time in your settings.

Error telemetry: We record technical errors through a self-hosted GlitchTip on our server in Germany. There is no external recipient here; no data is passed to third parties. IP addresses are not stored by default.

8. Retention

We keep the access log files of our web servers, which contain your IP address, for no longer than 15 days. After that we delete them automatically. In the cache server in front of them we additionally truncate your IP address as it is written, dropping its last block so that only the subnet remains.

We do not combine these access log files with your account. Separately from them we record security relevant events such as sign-ins, failed sign-in attempts and permission changes. These security logs contain your IP address and, where known, the reference to your account; we need them to detect and evidence attacks (Art. 6 (1)(f) GDPR). We keep them for 90 days and delete them automatically afterwards, including events that cannot be attributed to any account. For the protective measures themselves, see section 13.

Cancellation declarations submitted through the cancellation page are retained as evidence, even when they cannot be matched to a contract. § 312k (3) and (4) of the German Civil Code require us to document and confirm the receipt of a cancellation. Without that record, neither you nor we could show, in a dispute, when a cancellation was received.

Gartenbörse. 90 days after its runtime ends we hard delete the content of a listing: the description, every image, the provider's contact details and the exact location. What stays is the title, the postal code and town, the approximate location and the price details; otherwise the payment record would point at a nameless row. Anyone who wants those gone too deletes the listing in their account; it then falls in full. That period covers the two cases in which the listing is still needed after it ended: you publish it again, or its content is disputed.

We keep the order data behind it (amount, runtime, payment reference) as an accounting record for at least eight years; § 147 (3) of the German Fiscal Code, in the version in force since 01/01/2025, requires that. It is blocked from further use.

A platform enquiry from section 3 is deleted, together with all replies and the read status, 90 days after the end of the listing it went to. The clock starts at the end of the listing, not on the day of the enquiry: a message sent shortly before expiry should not outlive one sent on the first day. For the same reason, a late reply does not extend the period.

We clear the contact reveal log from section 3 in two stages. It is read for the two daily budgets only, that is over a window of 24 hours. We therefore delete your IP address from the entry after seven days; seven rather than one, so that an abuse case still under investigation can be resolved. The rest of the entry (account, channel, timestamp) is removed after 90 days in full, as is every entry belonging to a listing that gets deleted.

We store account and garden data for as long as your account exists. After a deletion request, the period in Section 10 applies. Accounting records are retained for eight years; § 147 (3) AO and § 257 (4) of the German Commercial Code require that for records of this kind. They are blocked from further use during that time.

At the end of the eight years the two kinds of record end differently. The record of a deleted subscription account is deleted outright. For a listing order we strip the personal reference from the row instead: the account, the garden account and the pointer to the listing drop out, while the amount, the runtime and the payment reference stay. The reason for the difference is that the tax retention period can be extended for as long as a transaction may still be examined; a record that can no longer be traced to anyone can safely sit out that time.

Email suppression list: If you have objected to receiving notification emails, or if you reported one of our emails as spam, we keep your email address on a suppression list. We store only the address, the reason for the entry and where it came from, and the timestamps. That entry survives the deletion of your account, and it has no expiry date. An objection does not expire; deleting the entry automatically after a few months would silently revoke it, and we would then contact you again by mistake. The legal basis is GDPR Art. 6 (1)(f). Our legitimate interest is to honour your objection under GDPR Art. 21 (3) permanently. Entries that rest solely on an address being technically undeliverable (a bounce) are deleted together with the account. You can ask us to delete your suppression entry at any time at dpo@gartenkern.de; notification emails can reach you again afterwards.

Newsletter. We keep the proof of consent and withdrawal (Section 3) for as long as we have to be able to produce it: Art. 7 (1) GDPR requires us to demonstrate a consent, and a withdrawal only takes lasting effect if it too stays on record. These entries are technically locked against later modification and against deletion. If you delete your account they lose their personal reference: email address, account reference, IP address and browser identifier fall away, while the fact of the consent and its timestamp remain.

Separate from that is the confirmation status itself, that is whether and when you clicked the link. It is attached directly to your account and is removed when the account is deleted. If you withdraw, we remove the confirmation and any open link straight away; what stays is the time of the last request, so that subscribing again respects the five-minute cool-down. A subscription you never confirmed leads to no mail being sent.

Individual audience-measurement records (Section 5) are deleted after 90 days, the daily random value after two days. Aggregate numbers without a personal reference are kept.

We keep support requests for three years from the day we closed the case; after that we delete it along with its messages and your sender address. If the request concerns a commercial transaction, such as an invoice or a cancellation, the six-year retention period under § 257 (1) no. 2 and (4) of the German Commercial Code applies instead; that period starts at the end of the calendar year. When you write to us by email, technical delivery data such as the address of the sending mail server is created as well. We delete that after 90 days, regardless of how long the case itself remains open.

9. No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The platform's AI features (plant recognition, chat, summaries) produce suggestions, not legally binding decisions about you.

10. Your rights (GDPR Art. 15 to 22)

You have the right at any time to:

  • Access (Art. 15) what we store about you, on request at dpo@gartenkern.de
  • Rectification (Art. 16), directly in your account profile
  • Erasure (Art. 17, "right to be forgotten"), on request at dpo@gartenkern.de
  • Restriction of processing (Art. 18), on request by email
  • Data portability (Art. 20), on request in a structured, commonly used format
  • Object (Art. 21) to processing based on Art. 6 (1)(f) GDPR
  • Lodge a complaint with a supervisory authority (Art. 77)

Send these requests and any other data protection questions to dpo@gartenkern.de. We respond without undue delay and at the latest within one month. Where a request is particularly complex, that period may be extended by up to two further months; we will tell you within the first month if that happens (GDPR Art. 12 (3)).

The supervisory authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59 to 61, 10555 Berlin, Germany
https://www.datenschutz-berlin.de/

You may also contact the supervisory authority of your habitual residence.

11. Backups and deletion periods

Backups are stored encrypted for 30 days. A deletion request takes immediate effect in the live database; deletion is finalised in backups through rollover within 30 days. Backups are used solely for disaster recovery.

12. Minimum age

The platform is open to persons aged 16 and over (Art. 8 GDPR). Anyone younger may use the service only with the consent of a legal guardian.

13. Security (GDPR Art. 32)

We take technical and organisational measures that reflect the state of the art: encrypted transport for all connections, passwords stored only as a secure hash and never in plain text, EXIF stripping on image uploads, strict separation between the data of different garden accounts, and a permission check on every access.

We do not list the individual mechanisms here. They evolve with the state of the art, and publishing them would make an attacker's work easier. We provide information on reasoned request.

14. Data breach notification

In the event of a personal data breach we notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33). Where the breach is likely to result in a high risk to your rights and freedoms, we also notify you without undue delay (GDPR Art. 34).