Auf lesen
This page explains our data practices and your privacy rights in simple language alongside relevant excerpts from the law.
(START OF DOCUMENT)
Privacy and Data Protection at Bakst & Friends
Updated: 16 September 2026
For quick navigation, here is an overview of all sections in this document:
- Preamble: language notes, contractual scope, and contacting us about your data
- General Principles: legal basis, your right of objection, definitions, and general context
- Default Data Processing: essential functions, non-essential features, and third-party sharing
- Web Hosting Provider: server logs and content delivery network
- Cookie Settings: essential and non-essential cookies
- Geolocation Data: essential and non-essential geolocation data and third-party use
- Optional Site Analytics: general traffic statistics and e-commerce analytics
- Embedded Content: social media and H5P interactive learning content
- Managing Your Records: privacy controls, registered accounts, and exceptions
- Data Storage and Retention: general practices and legally required archiving
- Protecting Your Data: encryption technologies, security plugin and firewall
1. Preamble
This Privacy Policy explains in detail how we and our commercial partners obtain, store, and process your data. By using our Website or associated Products or services, or by otherwise interacting or entering into a commercial relationship with us, you acknowledge the terms of this document.
If you buy our Products or otherwise engage in a commercial transaction with us, our General Terms and Conditions (GTC) govern your business relationship with us alongside this Privacy Policy. In case of conflict between any of the provisions of either document, the GTC take precedence. In such cases, the severability clause in section 9.4 of the GTC applies respectively to this Privacy Policy.
1.1. Language Notes
The Privacy Policy is available in English and German.
In the following, the text refers to:
- The e-commerce website in its entirety as the “Shop” or “Website” (or “Site” for short)
- Goods for sale in the Shop as “Products”
- The owner of this Website as “Bakst & Friends” or by equivalent first‑person pronouns such as “we” and “our”
- Anyone using the Website as a “Visitor,” and anyone using the Website while logged in with a registered account as a “User,” or Visitors and Users collectively by equivalent forms of address such as “you” and other second‑person pronouns
We strive for simple and inclusive language that meets legal standards. In balancing these aims, we sometimes rely on standard contractual clauses that may use gendered pronouns in generic references. These pronouns should be understood to include all non-binary genders.
1.2. Contractual Scope
This document governs data protection in the business relationship between us —
| Alexander Bakst Bakst & Friends – der Eigenverlag für Sprachbildung Heinersdorfer Straße 12 12209 Berlin GERMANY VAT ID no.: DE277695519 | Fon: +49 30 7974 66 53 Email: friends@bakst.de Web: https://bakst.de https://bakstandfriends.com |
— and you, the Visitor or User of the Website at https://bakst.de and associated domains such as https://bakstandfriends.com, or any person who interacts with us in a commercial capacity.
1.2.1. Policy Revisions and Further Processing
Whenever we update this Privacy Privacy, we’ll send an email to all known customer contacts in our database announcing the changes. The date at the top of this document shows the day it was last updated.
In cases where we need or want to process data not covered by this Privacy Policy, we’ll inform you separately and ask for additional consent if necessary.
1.2.2. Third-Party Processing
In the course of your visit, some data may be further processed by external providers in accordance with their respective privacy policies. We summarize key provisions of, and provide links to, those policies in this document. However, despite our efforts to monitor third-party data practices associated with our Site, we’re unable to guarantee that our Privacy Policy reflects the most recent updates to external policies.
You can help us maintain up-to-date information by alerting us to relevant changes in third-party data-protection standards. To do so, please send an email to friends@bakst.de or use our online contact form or any of the other means listed in this document.
1.3. Contacting Us
Our Website offers ways for you to manage your data and privacy options through on-site controls. In special cases where that’s not enough or you have questions or complaints, you can contact us directly.
As a very small business, we’re not in a position to hire a dedicated data privacy officer. To contact us about your privacy rights and data protection in connection with this Website, please send an email to:
You can also use our online contact form, mail us a letter at the address listed above, or call our phone number if you so wish. We’ll make every effort to respond to your inquiry quickly and effectively.
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 (‘accountability’)
GDPR Article 5 (2)
2. General Principles
Every website claims to care about your privacy. But such platitudes often mask industry practices that many people perceive as invasive.
At Bakst & Friends, we’ve decided to follow a simple principle: privacy first. That makes us different from a lot of commercial websites out there today. We’re not in the big-data game. We don’t engage in fingerprinting or cross-site tracking. We’ll never ask you to turn off your ad blocker. We don’t have AI agents scraping your data in the background. And we encourage everyone to take a proactive approach to their own digital footprint.
Of course, we try to balance this philosophy against the need to operate a modern, discoverable, and digitally competitive website. Ours relies on widely available tools to ensure adequate security, accessibility, and convenience. We also use a lightweight analytics tool to understand how Visitors as a whole are navigating the Site. We’ve configured these systems on a privacy-first basis; for example, by analyzing site traffic without setting any cookies. This approach protects your digital rights, helps us comply with the law, and makes pages load faster.
2.1. Legal Basis
German and European laws govern our e-commerce business. With regard to your privacy rights online, the most relevant statute is the General Data Protection Regulation (GDPR), a landmark law in the European Union (EU) designed to give people more control over their digital lives.
GDPR applies to anyone within the borders of the EU at the time of processing their personal data. Our business operates in Germany, where European law is implemented alongside German statutes such as the Federal Data Protection Act (Bundesdatenschutzgesetz or BDSG) or the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG).
2.1.1. Lawful Purposes for Data Processing
For us as the data controller to process your information and/or share it with third-party data processors, there has to be a lawful basis. GDPR Article 6 (1) gives six concrete reasons why data processing might be necessary, paraphrased here:
- You’ve consented to one or more specific purposes
- We’re carrying out a contract you’ve requested or entered into
- We’re required to comply with a legal obligation
- We need to protect the vital interests of you or someone else
- We’re carrying out a task in the public interest or an official capacity
- We or a third party are pursuing our legitimate interests, in which case we must ensure that your interests or fundamental rights don’t override our legitimate interests, especially if you’re a child
Justifications for Data Processing
Given the nature of our business as a self-publishing e-commerce seller, we commonly (but not solely) rely on GDPR Art. 6 (1) (a), (b), and (f) in the following scenarios:
- GDPR Art. 6 (1)(a) lets you choose to accept or reject data processing for non-essential features on our Website. Section 3.2 “Non-Essential Features” explains how this allows us to analyze anonymized usage statistics.
- GDPR Art. 6 (1)(b) is relevant if you buy our Products, in which case we’ll need to process your personal data to complete the order. This usually involves sharing some information with third-party data processors such as our fulfillment provider for shipping and returns. Because these records pertain to commerce and taxes, German law requires us to keep them for up to ten years. We may also choose to archive some data for longer periods; see section 10.3 “Legally Required Archiving” for links to the relevant statutes.
- GDPR Art. 6 (1)(f) justifies data processing for essential functions such as site security, shopping cart functionality, or language settings; see section 3.1 “Essential Functions” for details.
Further Rules and Regulations
In some cases, further statutes or regulatory schemes may supplement or supercede GDPR. For example, the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG) governs telecommunications and digital services in Germany and, in Article 2, defines consent requirements and exemptions for the storage and retrieval of data on end-user devices — in other words, cookie consent.
2.1.2. Cross-Border Transmission
GDPR includes rules on what happens to your data when it leaves the EU. Those rules are relevant to your interactions with us because our Website shares some information with third-party data processors outside the EU in countries like the United States of America or New Zealand.
For context, cross-border transfers of personal data depend on so-called adequacy decisions by the European Commission to determine if a country meets European data-protection standards. If so, then broadly speaking, “personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary.”1
The EU has issued favorable adequacy decisions for New Zealand and, in the United States, for companies certified under the EU–US Data Privacy Framework (DPF).
1 See European Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
2.2. Your Right of Objection
For personal data processed on the basis of legitimate interests per GDPR Art. 6 (1)(f), you have the legal right to object at any time for reasons arising from your particular circumstances. In that case, we’ll stop processing the data unless it serves the pursuit of a valid legal claim, or if we can otherwise demonstrate compelling reasons that outweigh your interests, fundamental rights, or freedoms in connection with the personal data.
To exert your legal right of objection as described above, you can contact us by any means listed in this document. We’ll need to know the reason for your objection so we can evaluate the claim.
2.3. What Makes Data “Personal”?
GDPR Article 4 (1) defines personal data (also called personally identifiable data or PII) as “any information relating to an identified or identifiable natural person,” also known as a data subject, “who can be identified, directly or indirectly, in particular by reference to an identifier such as a name” or other information.
Obvious data types that fall into this category are names and email addresses. But there are less obvious ones too: Location information such as zip codes or geo-tracking; ethnicity, gender, religion, and other demographics; biometric data such as fingerprint scans or facial recognition; personal beliefs and political opinions; and web cookies can all be a form of personal data.
By contrast, pseudonymous data generally conceals the person’s identity but may also fall under the definition of PII if it is easy enough to identify someone from it. GDPR Art. 4 (5) defines appropriate pseudonymization as “the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information,” which must be kept separately and not used to identify data subjects. The invasive practice of using pseudonymous data to uniquely identify an individual is commonly called fingerprinting.
2.4. Let Me Tell You About the Internet…
In practice, the simple act of visiting our Website — any website — reveals a certain amount of information about you to various actors along the data stream. This commonly includes your IP address and general geographic location, device and browser configuration, internet service provider, and other metrics that aren’t directly linked to your person but may reveal an identifying pattern.
For our part, we only process your data for contractual reasons and the narrow set of consent-based purposes and legitimate interests outlined in this Privacy Policy.
Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’)
GDPR Article 5 (1)(a)
3. Default Data Processing
Visitors can access the public pages of our Website without sharing personal data beyond what’s necessary for security logging. In this default mode, any potentially identifying data we collect in the course of your visit are either anonymized or isolated from other information. We don’t track usage statistics for default Visitors.
For more details on security and technical logs, see sections 4.1 “Server Logs” and 11.1 “Security Measures.”
Likewise, Visitors can purchase physical or downloadable Products from our Shop without registering an account and without consenting to non-essential features such as marketing analytics. In this mode, you don’t provide personal information beyond what’s necessary for the conclusion of a commercial contract (name, email, shipping address, and payment). We’ll process, store, and share (with relevant third parties such as fulfillment or payment providers) only the necessary data on the basis of GDPR Art. 6 (1)(b).
Our Website offers two levels of consent in the privacy settings: essential functions (default) and non-essential features (optional).
3.1. Essential Functions
The default configuration for new Visitors is for essential functions only, namely:
- Server logs and data processing by our web hosting provider
- Site security and spam protection, including blocking of individual and ranged IP addresses or entire regions based on geolocation data
- Page caching, content delivery networks, and load balancing
- Language and currency settings, shopping cart contents, tax and shipping estimates
Essential functions are integral to the proper functioning of our Shop and therefore always on. We use various technologies to implement essential functions for different purposes, as detailed throughout this Privacy Policy. Our use of these functions rests on GDPR Art. 6 (1)(f), wherein processing is deemed lawful if:
“[it] is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
In each case, we’ve determined that the interests, rights, and freedoms of data subjects aren’t impacted by, or at least don’t outweigh, our legitimate interests such as securing the site or showing the relevant tax rate for a Visitor’s location. We maintain appropriate technical measures to comply with broader GDPR principles such as purpose limitation, data minimization, or integrity and confidentiality.
3.2. Non-Essential Features
A pop-up dialog alerts first-time Visitors to the default privacy settings and asks for consent to opt in to non-essential features. Taking no action or choosing the “Reject” option maintains the default state of essential functions only.
Visitors who opt in to non-essentials allow us to activate the following features:
- Anonymized statistical data to understand our site traffic, as detailed under section 7 “Site Analytics”
- Geolocation data for analytical purposes, as outlined under section 6.2 “Non-Essential Geolocation Data (Analytics)”
By opting in to non-essential features, you’re basically doing us a favor: You’re allowing us to collect pseudonymous data on how you navigate the Shop. This helps us improve the Website and market our Products by analyzing usage patterns in the aggregate. What you get in return is a small convenience boost and the warm, fuzzy feeling of knowing you’re helping us improve the Website for everyone.
3.3. Third-Party Sharing
Our Shop uses a variety of systems developed and maintained by third parties. From content management to payment services, we rely on a mix of self-hosted plugins, external databases, and cloud services to ensure the basic functionality of our Website.
All third-party developers, providers, and data processors associated with the Site are named throughout this Privacy Policy. In the case of external data processing, we provide additional links to the processor’s relevant policies.
External domains are beyond the scope of our responsibilities. That means when you follow an outlink placed on our Site, the external domain’s respective owner is responsible for all data processing and content. For our part, we review third-party sources for obvious signs of harmful or unlawful content before linking to outside domains. Furthermore, external links are clearly marked on our Site to give you more agency over the websites you visit.
4. Web Hosting Provider
We’ve contracted the following service provider to host our Website on their servers:
ALL-INKL.COM – Neue Medien Münnich
Inh. René Münnich
Hauptstraße 68
02742 Friedersdorf
GERMANY
In this arrangement, we are the data controller while All-Inkl.com acts as our data processor.
4.1. Server Logs
Your browser automatically transmits certain technical data to us and our web hosting provider. We store this information in encrypted server logs, which include:
- Visitor IP address
- Server request timestamp and time difference from server to host
- Requested page or file, including transfer status and size
- Referrer URL
- Operating system and browser type, version, and language preferences
Server logs are stored separately from other databases such as the ones we use for analytics and marketing. Logged information is purely of a technical nature and serves the legitimate interest of maintaining the functionality and security of our Website.
We or the web hosting provider may store server logs in a secure archive under the terms of section 10 “Data Storage and Retention.”
4.2. Content Delivery Network
To reduce the time it takes for our webpages to load on end-user devices around the world, we use a content delivery network (CDN). This technology stores cached versions of the Website at a third-party provider whose global data centers serve the content to nearby Visitors.
We’ve contracted the following service provider to deliver our Website through their CDN:
BUNNYWAY, informacijske storitve d.o.o.
Dunajska cesta 165
1000 Ljubljana
SLOVENIA
In this arrangement, Bunnyway (or “bunny.net”) acts as a data processor on our behalf, making us the data controller. That means it is our responsibility to determine if, why, and for how long data will be stored on the CDN. The bunny.net webpage about GDPR compliance states:
Typically, bunny.net does not collect, store or distribute information that could be used in any way to identify a user or contain their personal information. [We have] taken steps to ensure no personally identifiable data is stored from your users that access your services through bunny.net by anonymizing any data that could be used to directly or indirectly identify a user.
Broadly speaking, the bunny.net CDN allows us to gather and temporarily store visitor log information such as anonymized IP addresses, URLs, country codes, or user agents. Additionally, the CDN temporarily or permanently stores files obtained from or manually uploaded to the Website. We only collect this data for technical analysis, processing, testing, and security — not for marketing or any other unstated purpose.
In most cases, the data held and collected by bunny.net does not contain any user-identifiable data. However, in some cases, it is possible for user-uploaded content and personal data such as a User’s account alias to be transmitted in the URL, User-Agent, or Referrer headers of the HTTP protocol. To the best of our abilities, we’ve taken steps in our configuration of the CDN and connected services to minimize accidental sharing of personally identifiable data.
Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’)
GDPR Article 5 (1)(b)
5. Cookie Settings
We use a small number of cookies for essential functions. With consent, we may also use cookies for non-essential features (although that’s not currently the case). You can open the privacy controls on any page to view a list of active cookies.
These are not your grandmother’s cookies. Rather, they’re unique identifiers stored locally as small text files in the memory of your browser or device. They come in two flavors: session cookies, which are deleted once you leave the website, and persistent cookies, which are stored for longer periods of time unless you manually delete them in your browser settings. The source of a cookie can be first-party (directly from us) or third-party (from outside domains).
5.1. Essential Cookies
Under GDPR precedent in Germany, we presume certain cookies to be exempt from consent requirements for essential functions such as:
- Recording cookie preferences
- Personalizing the user interface, language, or currency settings
- Remembering shopping cart contents
- Allowing load balancing
- Authenticating Users and supporting session security
Essential cookies are always on, and the Website offers no built-in way to deactivate them. You can, however, block site-specific cookies in your browser settings. Please note that this may cause our Website to act buggy on your device; for example, the Site will be unable to remember your language and currency preferences.
The legal basis for our use of essential cookies is legitimate interest per GDPR Art. 6 (1)(f) as well as the provisions of TDDDG Art. 25 (2).
5.1.1. First-Party Essential Cookies
We use essential cookies to support the e-commerce platform (WooCommerce cookies), multilingual plugin (WPML cookies), and account security (Wordfence cookies) for registered Users. These cookies are necessary for basic functions in the Shop, such as remembering shopping cart contents or processing payments.
The following tables show all possible cookies our Website can set for essential functions and non-essential features. The active cookies on your device may vary at any given time according to the page you’re viewing. The tables below only list first-party cookies, whereas section 5.2 has the list of all known third-party cookies.
Essential Session Cookies
Session cookies are deleted once you leave the Website.
| Name | Duration | Purpose |
| store_notice | Session | WooCommerce (our e-commerce platform) uses this cookie so that Visitors can dismiss a pop-up notice if we post one in our Shop. |
| woocommerce_cart_hash woocommerce_items_in_cart | Session | WooCommerce uses these cookies to detect changes in the contents of a Visitor’s shopping cart. |
| woocommerce_recently_viewed | Session | WooCommerce uses this cookie for the “Recent Viewed Products” widget. |
| wp-wpml_current_language | Session | WPML (our multilingual plugin) uses this cookie to remember what language version of our Website a Visitor is currently viewing. The language switcher won’t work without it. |
Essential Persistent Cookies
Persistent cookies are stored for longer periods of time.
| Name | Duration | Purpose |
| __stripe_sid __stripe_mid | 30 minutes 180 days | WooCommerce uses these cookies for their payment service (Stripe) to process transactions and prevent fraud. |
| mtm_consent_removed | 180 days | Matomo (our analytics tool) uses this cookie to remember when a Visitor has withdrawn their consent to non-essential data processing. |
| woo-share | 90 days | WooCommerce uses this cookie to support social sharing of Products from our Website. |
| woocommerce_geo_hash | 1 hour | WooCommerce uses this cookie to store a hash of the user’s location based on their IP address. Drawing on the external database named in section 6 of our Privacy Policy, WooCommerce uses the Visitor’s geolocation solely for essential purposes such as displaying the most appropriate tax and shipping information on our Products. |
| wp_woocommerce_session_ | 2 days | WooCommerce assigns a unique code to each Visitor so the system knows where to find corresponding cart data in the database. |
Essential Cookies for Registered Users
These persistent cookies are only relevant to registered Users.
| Name | Duration | Purpose |
| wfls-remembered-[hash] | 30 days | Wordfence (our security plugin) uses this cookie to allow registered users who use two-factor authentication (2FA) to log in with the same browser without requiring 2FA each time, for up to 30 days. This cookie only applies to users who enable the “Remember for 30 days” checkbox while logging in. |
| wfwaf-authcookie-[hash] | 12 hours | The Wordfence firewall uses this cookie to perform a capability check of the current (registered) User before WordPress has been loaded. |
| wordpress_logged_in_[hash] | 15 days | |
| wordpress_sec_[hash] | 15 days |
5.1.2. Third-Party Essential Cookies
Payment providers such as PayPal and other external partners may set additional third-party cookies in the course of rendering their services through our Site. We have no control over their cookie policies beyond allowing external scripts such as the PayPal JavaScript SDK to load in our Shop.
Conversely, external providers have no access to first-party cookies on the Website, since local cookies are generally tied to the device or IP address that originally set them.
To the best of our knowledge, we’re aware of the following third-party cookies on our Website and have determined their purpose as per the table below:
| Name | Duration | Purpose |
| PayPal: | PayPal sets these cookies wherever the “Pay with PayPal” button appears in our Shop. | |
| .c.paypal.com: __cf_bm | 30 minutes | PayPal’s content delivery network (CDN), Cloudflare, uses this cookie to distinguish between humans and bots. It’s important for site security and fraud prevention but may also support analytics reporting at PayPal and Cloudflare. |
| .stats.paypal.com: c | 180 days | PayPal uses this cookie for their own analytics in accordance with the privacy controls in your PayPal account. We have no control over this setting, as it concerns your contractual relationship with PayPal. |
| .paypal.com: [hash] | 180 days | PayPal appends a hash to this cookie for authentication and security purposes; for example, to prevent session hijacking via stolen cookies. |
| .paypal.com: l7_az | 30 minutes | PayPal uses this cookie to support secure transactions during checkout. |
| .paypal.com: sc_f | 180 days | PayPal uses this cookie to maintain persistent user states and support secure payment sessions during checkout. |
5.2. Non-Essential Cookies
Because our analytics tool uses JavaScript without setting any cookies, the number of non-essential cookies on our Site is currently zero!
| Non-Essential Cookie Name | Purpose |
| – | – |
In general, you can choose to accept non-essential cookies by opting in when prompted or by pulling up the privacy controls on any page. Otherwise, taking no action or choosing the “Reject” option will keep non-essential cookies off your device. Likewise, you can toggle “Reject” to withdraw your previously granted consent and revert your status to essential functions only. This will also deactivate analytics tracking.
Alternatively, you could close all instances of our Site on your device and clear your browser cache including cookies. Most browsers will let you do that on a per-site basis to avoid deleting desirable cookies from other websites. Once the data has been cleared from your device, our servers will treat you as a new Visitor if you decide to revisit our Site.
6. Geolocation Data
To detect the approximate geographic location of a Visitor, we use a third-party geolocation database to look up the Visitor’s IP address. The database service is provided by:
MaxMind, Inc.
51 Pleasant Street, #1020
Malden, MA 02148
UNITED STATES OF AMERICA
For residents of the EU, Switzerland, and the UK who wish to contact the provider directly, MaxMind asks that you contact their Data Protection Officer at dpo@maxmind.com or by mail to “Data Protection Officer” at the address listed above.
Our use of the MaxMind “GeoLite: free GeoIP®” database serves a dual purpose:
- Essential functions requiring no prior consent
- Non-essential features requiring additional consent
To implement this service in isolation according to purpose, we’ve configured the application programming interface (API) separately in our respective e-commerce and analytics platforms.
6.1. Essential Geolocation (Visitor Preferences)
Our Website uses the MaxMind geolocation database to set the language and currency display options according to a first-time Visitor’s geographic location. Visitors can subsequently change these display settings according to their preferences, which are then stored in a cookie on their device (see section 5 “Cookie Settings”).
Language and currency settings are considered essential functions justified as legitimate interests per GDPR Art. 6 (1)(f). As such, our use of geolocation data collected solely for this purpose requires no prior consent from Visitors.
6.2. Non-Essential Geolocation (Analytics)
Our analytics tool uses the same geolocation database by MaxMind to generate reports on usage statistics for us (see section 7 “Optional Site Analytics”). Because this is a non-essential feature, we always seek Visitor consent before using third-party geolocation services for analytical purposes.
With consent, we process non-essential geolocation data separately from the essential purposes described in section 6.1 above. To achieve this separation, our analytics tool makes its own calls to the MaxMind database and is technically isolated from the multilingual component of our e-commerce system, which processes geo-data for essential purposes only.
6.3. How MaxMind Uses Your Data
The MaxMind privacy policy, specifically the section on MaxMind’s role as a data processor in the European Union, Switzerland, and the United Kingdom, describes how they process your (and our) data in connection with your interactions on our Site:
MaxMind “generally operates as a processor on behalf of its customers that use the MaxMind’s services. The MaxMind customer, the controller, determines the purposes and means of the processing of personal data.”
However, their privacy policy also allows for MaxMind to use the data we share with them in anonymized form for their own purposes:
“Also, when MaxMind combines personal data from different customers, like many kinds of analytics services, it may do this both as a processor at its customers’ instruction and as a controller itself for the purpose of providing services to all of its customers. For example, MaxMind may process and aggregate or otherwise de-identify some of the personal data that a customer shares with MaxMind in order to make that personal data part of another database for one or more other services provided to MaxMind customers.”
In other words, MaxMind may process anonymized Visitor data for its own purposes, including data gathered through your use of essential functions on our Site. To the best of our knowledge, this information is limited in scope to the anonymized IP-based geolocation data described here.
7. Optional Site Analytics
For Visitors who agree to non-essential features, we use a lightweight, open-source, self-hosted analytical tool called Matomo Analytics to gain insights on how users as a whole are navigating our Website. The tool is provided by:
InnoCraft Limited
7 Waterloo Quay, PO Box 625
6140 Wellington
NEW ZEALAND
Because Matomo is self-hosted on our own servers, InnoCraft are not a data processor.
We use Matomo to process usage statistics on the basis of consent according to GDPR Art. 6(1)(a). The system measures, collects, analyzes, and reports statistical data to help us understand and optimize the Website. Matomo does not use automated decision-making and does not generate profiles or session recordings of Visitors.
You can change your current opt-in status by using the privacy controls on our Website or checking the box below.
7.1. General Analytics
Once enabled, our tracking is minimal. Because we’ve configured Matomo to avoid using analytical cookies altogether, the system uses a few lines of JavaScript to collect anonymized statistical data. The information we track is listed below and represents some of the most basic traffic data that websites collect today1:
- User IP address (irrevocably anonymized by 2 bits, e.g. 192.168.xxx.xxx)
- Page request timestamp
- Page title and URL
- Referrer URL (previous page used to access this page)
- Page speed
- User local time
- Screen resolution
- Files accessed or downloaded
- Outlinks followed to outside domains
- User geolocation (country, region, city, approximate latitude and longitude)
- Browser main language (
Accept-Languageheader) - Browser user agent (
User-Agentheader)
1 Adapted from: https://matomo.org/faq/general/faq_18254/
7.2. E-Commerce Analytics
For Visitors or Users who interact with e-commerce elements of our Shop, such as Product pages or the shopping cart, Matomo Analytics also “collects and reports on both individual and aggregate transaction data” in the following categories1:
- E-commerce orders in aggregate and over specific periods
- Products purchased within total orders
- Total sales revenue including subtotals, taxes, shipping fees, and discounts
- Key performance indicators such as average order value, conversion rates, or abandoned carts
2 Adapted from: https://matomo.org/faq/reports/data-measured-and-reported-by-ecommerce-tracking/
8. Embedded Content
We may sometimes embed off-site content from other providers on our own Website. Examples include videos hosted on third-party platforms, posts published on social media, or cloud-hosted elements in our online lessons. Such third-party content is hidden by default and will not load without your consent. You can choose to show the content in each instance or as a global setting in the privacy controls.
If you agree to view embedded content, you’re allowing its third-party providers and their partners to process certain data about you, particularly in connection with any accounts you hold with them. Such data includes information about your interactions with us. While we don’t retain this information on our own servers, a wide range of unaffiliated data processors will likely gain access to it.
In practice, interacting with embedded content on our Site might infuse your social-media feeds with posts about “language books” and other SEO keywords associated with our Site. Or you might start seeing related results in your online searches or AI chats and in personalized ads across the Web. These are simplified examples meant to illustrate how your data can circulate in ways we’re unable to monitor or control.
8.1. Social Media
Our presence as a business on social media is currently limited to the founder’s profiles on LinkedIn (owned by Microsoft), Instagram (Meta), YouTube (Google), and Substack. The founder also maintains a community chat server accessible by invite on Discord. In addition, individual contributors such as our independent authors and illustrators may be active on other social-media platforms, and we might feature their profiles and content on our Website from time to time.
Most mainstream social-media providers are US companies with subsidiaries in Ireland that are GDPR-compliant in the EU. Despite their compliance, some of their data practices may be at odds with our privacy-first philosophy. This notably includes their (lawful) use of unique identifiers and cross-site tracking techniques.
8.1.1. LinkedIn
Any content embedded by LinkedIn is provided by:
LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
IRELAND
Embedded content is governed by the LinkedIn Embed Terms of Use agreement. When you interact with on-Site embedded content, LinkedIn may transmit your data to countries outside the European Union. To learn more, please refer to the complete LinkedIn privacy policy.
8.1.2. Instagram
Any content embedded by Instagram is provided by:
Meta Platforms Ireland Limited
4 Grand Canal Square
Grand Canal Harbour
Dublin 2
IRELAND
Any personal information transmitted in this way from our Website to Meta Platforms Ireland Ltd. is subject to a joint responsibility agreement called the Facebook Controller Addendum. For more information, please refer to the complete Instagram privacy policy.
When you interact with Instagram on our Website, some of your data may be transmitted to servers owned and operated by Meta Platforms, Inc. in the United States of America. This type of transatlantic data transmission is based on standard contractual clauses developed by the EU Commission. At the time of writing, Meta Platforms, Inc. is certified under the EU–US Data Privacy Framework (DPF). DPF is a bilateral agreement between the European Union and the United States designed to ensure compliance with European privacy standards in the course of data processing in the US. DPF-certified companies have agreed to comply with GDPR privacy standards.
8.1.3. YouTube
Any content embedded by YouTube is provided by:
Google Ierland Limited
Gordon House
Barrow Street
Dublin 4
IRELAND
8.1.4. Discord
The platform for our community chat server is provided by Discord Inc. (444 De Haro Street, Suite 200, San Francisco, CA 94107, United States of America) through their Netherlands-based representative:
Discord Netherlands B.V.
Schiphol Boulevard 195
1118BG Schiphol
NETHERLANDS
8.2. H5P Learning Content
Our Website offers free learning material with interactive elements that may contain H5P content. H5P is an open-source platform to “create, share and reuse interactive HTML5 content in your browser” in the words of H5P’s own website.
We self-host most H5P content on our servers (see section 4 “Web Hosting Provider”). However, the system allows us to embed third-party content such as videos in the learning material we create. H5P embedded content follows the same rules outlined in section 8 above; that is, embedded content will not load without your prior consent.
In connection with H5P, we may process additional User data for registered account holders on the basis of consent; see section 9.1 “Registered Accounts” for further details.
Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)
GDPR Article 5 (1)(c)
9. Managing Your Records
To view, update, or delete any personally identifiable information you’ve shared with us, please use the options provided on our Website. You’ll find the relevant privacy controls on every page, in this Privacy Policy, and in your account settings for registered Users.
You can also send us a message and tell us what to do with your data. At your request, we can supply a complete overview of the information we have on you, and then it’s up to you what happens to it. We can modify or remove individual portions of your data, or you can ask us to delete the entire data set.
9.1. Registered Accounts
Visitors may choose to sign up for a registered account with us. This is strictly a convenience feature for Users to track their progress in interactive exercises, publish comments on our posts, and manage their account information.
No account is necessary to view our public content or purchase Products, including digital downloads, from our Shop.
9.1.1. Account Data Shared with Us
By registering for an account, you explicitly accept our General Terms and Conditions (GTC) and agree to share at least your name and email address with us. You can optionally associate a shipping address, phone number, payment methods, and other information with your account for ease of access.
By creating a User account, you accept that we may access:
- Your order history
- Your account information (but not your password)
- Your progress on interactive exercises (H5P), which we’re unable to keep confidential for technical reasons but promise not to use for marketing or any other nonconsensual purposes
9.1.2. Benefits of a User Account
Registered Users can track their learning progress and resume tasks in interactive exercises (H5P) on our Website. Users can also curate their own lists of free lessons and worksheets.
In addition, account holders are able to publish comments on selected posts on our Website. All publicly visible comments are subject to the code of conduct detailed in section 9.2 of our GTC. As a matter of content moderation, we reserve the right to withhold or delete comments at our discretion, and to disable comments altogether on individual posts or the Site as a whole at any time.
Otherwise, Users can log in to manage their account information, view their order history, and conveniently re-download purchased digital Products such as e-books (again, this is also possible without an account). User accounts also help us process customer-service requests more efficiently, offer incentives to frequent buyers, and improve our Product catalog for everyone.
9.2. Exceptions
There are some rare and clearly defined instances in which we must retain or disclose your data without consent; for example, if law enforcement serves us a legitimate warrant or court order. In the unlikely event that we process your data for reasons other than our own under GDPR Art. 6 (1)(c), we’ll inform you as permitted by law.
Stay safe out there.
Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’)
GDPR Article 5 (1)(d)
10. Data Storage and Retention
The retention period for personal information you share with us depends on its type and purpose. For example, in the case of IP address data:
- Our analytics tool immediately and irrevocably anonymizes all IP addresses
- Our e-commerce platform scrambles IP addresses after three months and deletes them after one year
- Our server logs retain a permanent archive of all server requests including IP addresses
Sections 10.1 and 10.2 explain our retention policies for different data-processing purposes on the Website.
10.1. Transient Data Storage
In the absence of another justification under GDPR, we only retain your data for as long as is necessary to process your specific request.
The following table summarizes our general retention policies for transient data:
| Purpose | Source | Retention |
| Contact form | Voluntary form submission initiated by a Visitor | 3 months (database entries) + email copies archived |
| Analytics | Anonymous traffic data from consenting Visitors collected through Matomo Analytics | 3 months (raw data logs) + reports archived after 1 year |
| Security logs and live traffic data (Wordfence) | Provided by Wordfence, our security plugin (see section 11.1 “Security Measures”) | 30 days |
10.2. Persistent Data Storage
We treat some data as persistent, meaning we retain the information for longer periods before it is archived or deleted. Persistent data on our Site mainly concerns User accounts and contractual information.
The following table summarizes our general retention policies for persistent data:
| Purpose | Source | Retention |
| Withdrawal form (for refunds and returns) | Legally mandated option to exercise your (EU and UK) right of withdrawal online | 10 years |
| Server logs (All-Inkl.com) | Processed by our web hosting provider and shared with us (see section 4 “Web Hosting Provider”) | 1 year |
10.3. Legally Required Archiving
German law further requires us to retain records of commercially relevant information for up to ten years per Handelsgesetzbuch (HGB § 328 and HGB § 257) with additional rules and procedures per Abgabenordnung (AO) § 147. This type of data includes contracts, past orders, transaction data, and other commercial records.
Expiration of the retention period doesn’t automatically oblige us to erase the information completely. The data will be scrubbed from the Website, but we may decide to keep an archived copy elsewhere in secure storage. Any decision to archive such records follows a review to determine the relevance of the content in question. We may, for example, archive data that could conceivably serve as evidence in future disputes. While the statutory period of limitation is three years per German Civil Code (Bürgerliches Gesetzbuch: BGB § 195), the law stipulates several cases in which a 30-year limitation period applies (see BGB § 197). To account for this, we may decide to archive some records for up to 30 years.
Deep archives are fully segregated from the Website. The data are generally stored in a compressed file within a password-protected folder, either in our cloud storage account or in an offline location (cold storage).
Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’)
GDPR Article 5 (1)(e)
11. Protecting Your Data
To the best of our abilities, we’ve taken reasonable steps to protect the privacy rights and digital safety of our online Visitors and Users. However, even the most low-traffic site is subject to daily intrusion attempts by automated bots, fake crawlers, impostors, and other shady online actors. The internet comes with inherent security risks. For this reason, we’re unable to guarantee 100% protection against unauthorized access by third parties.
While the hosting provider named in section 4 manages server-side security, we use our own set of tools to add another layer of frontend security. Security data are stored separate from and inaccessible to other tools such as our analytics platform. We’ll never use security data for marketing or any other unstated purpose.
Finally, as the nature of digital threats evolves, so too must our countermeasures. If we decide to implement new security measures that meaningfully impact your privacy rights, we’ll update the terms of this Privacy Policy in a timely manner.
11.1. Security Measures
To further harden our Website against abuse, we use a third-party plugin called Wordfence. This comprehensive security suite includes a firewall that checks incoming IP addresses for signs of malicious activity against a database of known bad actors. Such processing occurs in a temporary encrypted environment managed by the third-party provider.
Wordfence is provided by:
Defiant, Inc.
800 5th Ave., Suite 4100
Seattle, WA 98104
UNITED STATES OF AMERICA
In this arrangement, we’re the data controller and Defiant acts as our data processor. Defiant may process certain information on our behalf under the terms of their Data Processing Addendum.
Among other things, our Wordfence plugin processes live traffic data. In doing so, we collect the following information:
- IP address, including the ability to look up its owner through a WHOIS query and to block specific IP addresses in case of malicious activity
- Location at the country local, not city or state, called from a local database
- Server request timestamp
- Browser
User-Agent
Our system retains this data for 30 days before permanently deleting it. We don’t archive live traffic data unless a specific security incident requires longer storage for us to resolve the security issues or preserve legal evidence.
We also participate in the “Real-Time Wordfence Security Network,” a community-driven security measure that is part of the plugin. This feature reports the following information to the operator (Defiant):
- Attempts by blocked IP addresses to access the Website
- Attempts by hackers to access known malicious URLs that do not exist on the Website but are clearly a hack attempt
- Login failure attempts
Defiant may then:
[…] aggregate the data on a real-time platform to determine which IP addresses are currently engaged in the most malicious activity and need to be blocked by our community. That data is then used by your site and other Wordfence-protected sites to [temporarily] block those malicious IP addresses.
The legal basis for all security-based data processing is our legitimate interest per GDPR Art. 5 (1)(f) to monitor the Site for malicious activity and protect its data against intrusion.
11.2. Encryption Technologies
Transmissions to and from the Website are protected by Secure Sockets Layer (SSL) encryption, which you’ll recognize by the presence of the “https” protocol in the URLs of our domains and subdomains.
Please note that regular emails sent to our addresses are only encrypted in transit, not end to end.
Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)
GDPR Article 5 (1)(f)
Thanks for reading!
(END OF DOCUMENT)
︵‿୨♡୧‿︵
More About Us
If you still have unanswered questions, take solace in these links:
- Explore our complete catalog of products for learners of English and German
- Download free worksheets to get started on your learning journey in English or German
- Learn more about us and join a niche community of language nerds to connect with real native speakers
- Find out how you can achieve your business goals with B2B services wherever English and German are spoken
- Read the legal fine print about our company, shipping rates, refunds and returns, and this privacy policy
- View the shopping cart and manage your account or create one for easy access to your orders, downloads, and details
Otherwise, don’t hesitate to contact us. A real human will respond as soon as someone is free. Thanks!
