Privacidad

I. Information about the processing of your data pursuant to Art. 13 of the General Data Protection Regulation (GDPR)

1. Controller and Data Protection

The controller for this website is

Andreas Hochhalter, Alexander-Schmorell-Str. 27, 33189 Schlangen.

info [at] plant-central.de

2. Data processed for the provision of the website and the creation of log files

a. What data is processed and for what purpose?

Each time you access content on the website, data is temporarily stored that may allow identification. The following data is collected:

- Date and time of access

- IP address

- Hostname of the accessing device

- Website from which the request originated

- Websites accessed via this website

- Pages visited on our website

- Notification of whether the retrieval was successful

- Amount of data transferred

- Information about the browser type and version used

- Operating system

Processing your IP address is technically unavoidable in order to deliver the content you requested to your device at all; communication over the internet is not possible without it.

In addition, we store the above data including the full IP address in log files in order to ensure the secure and uninterrupted operation of the website, to detect and prevent attacks and abusive access (for example automated scraping of content, brute-force attempts or DDoS attacks), and to investigate such incidents. These purposes also constitute our legitimate interest in the processing.

PlantCentral remains responsible for processing personal data when providing the chat and purchase enquiry features; see section 10 for details. Recipients receive the information you send and may use it outside the platform. Such independent use by recipients is separate from our processing. Only share information that you intend the recipient to receive.

b. On what legal basis is this data processed?

The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the functionality, stability and security of our information technology systems and in preventing and investigating attacks and abusive use. Without storing the IP address, such attacks could neither be reliably detected nor stopped.

Log data is evaluated automatically for attack patterns, such as repeated requests to security-relevant paths. IP addresses identified in this way may be blocked in accordance with section 7. No evaluation of the log data beyond this takes place, and it is not combined with any other data.

c. Are there any recipients of personal data besides the controller?

The website is hosted in Germany by Strato AG. The hosting provider receives the above-mentioned data as a data processor. In addition, the website is delivered via the Content Delivery Network (CDN) of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (see section 6).

d. How long is the data stored?

The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. For the mere delivery of the website this is the case when the respective connection ends.

Log files are rotated regularly and deleted after 7 days at the latest. They are only kept longer where this is necessary in an individual case to investigate or defend against a specific attack; the log data concerned is deleted as soon as the incident has been finally resolved.

This does not apply to IP addresses that have been blocked because of abusive behaviour. Section 7 of this privacy policy governs their storage.

In order to take action against fraud or criminal offences such as insults, etc., all enquiries and messages can be viewed by administrators. Access is granted as soon as a dispute or fraud incident is reported.

3. Data subject rights

a. Right of access

You may request access pursuant to Art. 15 GDPR to the personal data we process about you.

b. Right to object

You have a right to object on specific grounds (see section II below).

c. Right to rectification

If the data relating to you is inaccurate or incomplete, you may request rectification pursuant to Art. 16 GDPR.

d. Right to erasure

You may request the erasure of your personal data pursuant to Art. 17 GDPR.

e. Right to restriction of processing

You have the right to request the restriction of the processing of your personal data pursuant to Art. 18 GDPR.

f. Right to lodge a complaint

If you believe that the processing of your personal data infringes data protection law, you have the right pursuant to Art. 77(1) GDPR to lodge a complaint with a supervisory authority of your choice. This includes the supervisory authority responsible for the controller: State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, https://www.ldi.nrw.de/kontakt/ihre-beschwerde.

g. Right to data portability

You have the right to receive the data we process automatically on the basis of your consent or in performance of a contract, in a structured, commonly used and machine-readable format.

For your user account you can generate this export yourself at any time: sign in and use the “Download my data” button under “Account”. The file contains your profile details, your listings, your own messages, your wishlist, your invoices and the declarations you have given, among other things. Messages other users sent to you are not included, because they were provided by those senders and their rights must not be adversely affected (Art. 20(4) GDPR).

The collection of data for the provision of the website and the storage of log files, by contrast, are not based on consent or a contract but on Art. 6(1)(f) GDPR. For that data the conditions of Art. 20(1) GDPR are not met.

4. Cookies and web analytics (Google Analytics)

a. Cookies

This website uses cookies. Technically necessary cookies are set on the basis of Art. 6(1)(f) GDPR. Cookies for analytics purposes are only set with your explicit consent pursuant to Art. 6(1)(a) GDPR. You may revoke your consent at any time via the cookie banner.

b. Google Analytics 4 (via Google Tag Manager)

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics is integrated via Google Tag Manager and is only activated if you have given your consent via the cookie banner (legal basis: Art. 6(1)(a) GDPR).

Google Analytics uses cookies that enable an analysis of your use of the website. The information collected includes, among other things:

- Pages visited and time spent on page

- Device, browser and operating system used

- Approximate location (country/region)

- Referrer (referring website)

Google Analytics 4 does not store your IP address. It is only processed temporarily to determine your approximate location (country/region) and is then discarded; Google Analytics does not log or store the IP address. Data transfers to the USA are carried out on the basis of the EU-US Data Privacy Framework.

Google Analytics 4 is configured with retention periods of 2 months for event data and 14 months for user data. Under Google’s retention rules, the user-data period also applies to key-event data. Reset on new activity is enabled: each newly recorded event from a user restarts the 14-month retention period for that user’s identifier and associated user data. With repeated activity, this user data can therefore remain stored for longer than 14 months from its initial collection. This reset applies only to user data and does not extend the retention period of previously collected event data. Data whose retention period has expired is removed during Google’s monthly deletion process. These settings do not limit retention of aggregated standard reports.

You may revoke your consent at any time with future effect by changing the cookie settings via the cookie banner.

For more information about data protection at Google, please visit: https://policies.google.com/privacy

5. Google reCAPTCHA

We use Google reCAPTCHA, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). reCAPTCHA is used to verify whether input on our website is made by a human or by automated, machine-based processing.

reCAPTCHA is used on the following forms only:

- Registration of a user account

- Contact form

- Cancellation form

The service is only loaded on pages that contain one of these forms. On all other pages of our website it is not embedded and no data is transmitted to Google.

The legal basis for data processing is Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in protecting our website and our users from abusive automated use and spam. Without this protection the forms named above would be open to automated mass access.

Where reCAPTCHA stores or reads information on your device in the process, we consider this strictly necessary in order to provide the service you have expressly requested, namely submitting the relevant form (§ 25(2) no. 2 TDDDG). Consent is therefore not required for it. The service is not used for analytics or advertising purposes.

When using reCAPTCHA, the following data is transmitted to Google:

- IP address

- Browser and screen resolution information

- Cookies set by Google

- Mouse and keyboard behaviour on the page

Data transfers to the USA are carried out on the basis of the EU-US Data Privacy Framework.

For more information, please refer to Google’s privacy policy: https://policies.google.com/privacy

6. Cloudflare CDN

We use the Content Delivery Network (CDN) of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”). Cloudflare acts as a reverse proxy between your browser and our web server. All traffic to our website is routed through Cloudflare’s network.

Cloudflare is used to optimise loading times, protect against DDoS attacks and malicious traffic, and to ensure the general security of our website. The legal basis for data processing is Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in the secure and performant provision of our website.

The following data is processed by Cloudflare:

- IP address

- Requested website content

- Date and time of access

- Browser and operating system information

- Referrer URL

Cloudflare also stores security logs for a maximum of 72 hours in order to detect and prevent malicious traffic.

a. Cloudflare Web Analytics

We also use Cloudflare Web Analytics, a privacy-friendly web analytics service provided by Cloudflare. No cookies are set and no personal data such as IP addresses is stored. The data collected is processed exclusively in aggregated form and includes, among other things, page views, time spent on page and country of origin. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in analysing website usage).

Data transfers to the USA are carried out on the basis of the EU-US Data Privacy Framework. For more information, please refer to Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/

7. Storage of banned IP addresses (IP ban)

To protect our website and all users, we store IP addresses that have been banned due to abusive behaviour (e.g. scraping, hacking attempts, DDoS attacks or comparable actions pursuant to § 16 of the Terms of Use). The legal basis for data processing is Art. 6(1)(f) GDPR (legitimate interest). Our legitimate interest lies in protecting the security and integrity of our information technology systems and in protecting our users from harmful activities.

The following data is stored:

- IP address

- Reason for the ban

- Time and duration of the ban

Banned IP addresses are stored beyond the regular retention periods for log files, as this is technically necessary to permanently defend against recurring attacks and constitutes industry-standard security best practice. The data is deleted once the ban is lifted or the purpose of storage no longer applies.

8. User account and registration

To register you we process your username, first and last name, your address, your e-mail address and a password of your choosing (stored only as a hash), and optionally your telephone number. Business accounts additionally involve the company name, department, VAT identification number and the imprint you provide. We also record when you accepted the terms of use, when you confirmed your age and when you confirmed your e-mail address.

The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement). We send a PIN to confirm your e-mail address; the legal basis for that is Art. 6(1)(f) GDPR (preventing registrations with somebody else's address).

9. Publicly visible content

Please be aware that some of your information is public by design and can be picked up by search engines. This includes in particular your username, your profile text and profile details, your listings including images and prices, your aquarium showcases, reviews you have given and received, and activity indicators such as the number of listings and profile visits.

Business users are required by law to provide a complete imprint, which is likewise publicly visible. For private accounts your address, e-mail address and telephone number are not displayed publicly.

The legal basis is Art. 6(1)(b) GDPR, since publishing the listings is the contractual purpose of the marketplace.

10. Purchase enquiries, messages and auctions

The enquiry and messaging features let you exchange messages directly with other users. We process the sender, recipient, time and content of each message together with the details of the enquiry (item, quantity, price, status). For auctions we additionally process your bids and, if you win, your identification as the winner.

The legal basis is Art. 6(1)(b) GDPR. Delivery happens over a real-time service we operate ourselves (a WebSocket gateway), which only relays messages and does not store them.

Messages are checked automatically against a list of prohibited terms and are rejected if they match. Beyond that we do not read your messages. If a report is made under § 7 of the terms of use, or a fraud or dispute case is reported, administrators can view the conversation concerned in order to assess the case. The legal basis for this is Art. 6(1)(f) GDPR (protecting users and enforcing the terms) and Art. 6(1)(c) GDPR in conjunction with Regulation (EU) 2022/2065.

Please do not share information through these features that you would not want the other party to have.

11. Payments via PayPal

Paid service packages and offer boosts are handled exclusively through PayPal, operated by PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg.

You enter your payment details (in particular bank and card details) directly with PayPal; we never receive them. PayPal transmits to us the information needed to allocate and invoice the payment, in particular the subscription and transaction id, the payment status, the amount and payment dates, and the payer's name, e-mail address and billing address. PayPal is a controller in its own right for its processing; PayPal's privacy statement applies in addition: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full.

The legal basis is Art. 6(1)(b) GDPR. We generate invoices from these payments and retain them under commercial and tax law obligations (Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 14b UStG).

12. E-mail dispatch

We send contract-related e-mails (confirmations, invoices, cancellation confirmations and the like) on the basis of Art. 6(1)(b) GDPR, and notifications about activity on the platform (new messages, wishlist matches, auctions) on the basis of Art. 6(1)(f) GDPR. You can unsubscribe from notifications at any time using the link in the relevant e-mail or under "Account"; contract-related e-mails are excluded from this.

So that delivery can be traced, we log the e-mails we send including recipient, subject and content. These logs are deleted after 30 days. The legal basis is Art. 6(1)(f) GDPR (evidence of dispatch and fault analysis).

13. Push notifications

If you allow push notifications in your browser, we store the push address (endpoint) your browser generates, the associated encryption keys, your browser identification (user agent) and the link to your user account. Delivery is handled technically by your browser vendor's push service (for example Google, Mozilla, Microsoft or Apple), to which the push address and the encrypted message are transmitted. This may involve a transfer to a third country.

Delivery may involve processing data in the USA in particular. Google LLC and Microsoft Corporation participate in the EU-US Data Privacy Framework; transfers covered by it benefit from the European Commission adequacy decision under Art. 45 GDPR. Further information is available from Google (Firebase Cloud Messaging) and in the Microsoft privacy statement.

Apple and Mozilla describe European Commission Standard Contractual Clauses in their privacy notices as safeguards for international transfers under Art. 46 GDPR. Details and access to copies of the relevant safeguards are available through Apple (international data transfers section) and the Apple privacy contact, and through Mozilla (Firefox privacy notice) and [email protected]. Which of these providers are involved in delivery depends on your browser and operating system. Browser permission for push notifications is not separate consent to a third-country transfer under Art. 49 GDPR.

The legal basis is your consent under Art. 6(1)(a) GDPR, given when you allow notifications in the browser. You can withdraw it at any time by disabling notifications in your browser settings or under "Account"; the stored push address is then deleted.

14. Visit counters and seller statistics

We count views of listings, profiles and plant pages in order to show statistics to users and sellers (for example "most viewed offers" and the figures in the seller area). Signed-in users are recorded by their user id. For visitors who are not signed in we do not store an IP address; we store a hash generated with a secret key, which allows a repeat visit to be recognised within the statistics but does not allow the IP address to be reconstructed.

These entries are deleted after 100 days. The legal basis is Art. 6(1)(f) GDPR (understanding usage and providing statistics to sellers).

15. Terminations and withdrawal declarations

If you terminate a contract through our cancellation page, we store the details from the form (name, e-mail address, the contract concerned, the type of termination, the reason and the date on which it should take effect) together with the time it reached us and the time it was confirmed. The legal basis is Art. 6(1)(c) GDPR in conjunction with § 312k BGB, and Art. 6(1)(f) GDPR (evidence of receipt).

If you book a paid service we additionally store your declaration that performance may begin early, including the exact wording shown to you and the time it was given. The legal basis is Art. 6(1)(c) GDPR in conjunction with §§ 356, 357 BGB.

16. Error logging (Sentry)

To detect and fix technical faults we use Sentry, a service provided by Functional Software, Inc. (Sentry), 45 Fremont Street, San Francisco, CA 94105, USA. Processing takes place on servers within the European Union.

When an error occurs, the error message, the technical trace (stack trace), the address requested and information about the browser and server are transmitted. Transmitting personal data is not intended and is disabled by default; nonetheless personal data may in individual cases appear within an error message. The legal basis is Art. 6(1)(f) GDPR (secure and fault-free operation). The retention period for error events in Sentry is 30 days.

17. Automated checks

To protect the platform we run automated checks: evaluation of log files for attack patterns (see section 2), blocking of conspicuous IP addresses (see section 7), checking of forms via reCAPTCHA (see section 5), and checking of listings, messages and reviews against a list of prohibited terms.

None of this amounts to an automated decision within the meaning of Art. 22(1) GDPR producing legal effects concerning you or similarly significantly affecting you: blocking an account and removing content are decided by us case by case. You can complain about such measures under § 7 of the terms of use.

18. Recipients and processors at a glance

- Strato AG, Germany (hosting, processor)

- Cloudflare, Inc., USA (content delivery network and web analytics, see section 6)

- Google Ireland Limited, Ireland (Google Analytics and reCAPTCHA, see sections 4 and 5)

- PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg (payment processing, see section 11)

- Functional Software, Inc. (Sentry), processing in the EU (error logging, see section 16)

- Browser vendors' push services (only if push notifications are enabled, see section 13)

Beyond this we only pass data on where we are legally obliged to do so or where it is necessary to establish, exercise or defend legal claims.

19. Retention periods at a glance

- User account and the content attached to it (listings, messages, reviews, wishlist): until the user agreement ends, then at the latest six months (§ 11 no. 3 of the terms of use)

- Invoices and accounting vouchers: generally 8 years; books, accounting records and annual financial statements: 10 years; commercial and business correspondence subject to retention requirements and other tax-relevant documents: generally 6 years. Each period starts at the end of the relevant calendar year. Documents are retained longer where a statutory extension applies in an individual case, in particular for unresolved tax proceedings (§ 147(3) and (4) AO, § 14b UStG).

- Termination and withdrawal declarations: until the statutory limitation periods expire

- Web server log files: 7 days (see section 2)

- Logs of e-mails sent: 30 days (see section 12)

- Visit counters: 100 days (see section 14)

- Google Analytics 4: event data 2 months, user data and key-event data 14 months; the user-data period restarts on new activity. Deletion during the monthly deletion process (see section 4)

- Error events in Sentry: 30 days (see section 16)

- Blocked IP addresses: until the block is lifted (see section 7)

User accounts whose e-mail address has not been confirmed are deleted 7 days after registration.

II. Right to object pursuant to Art. 21(1) GDPR

You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data which is based on Art. 6(1)(f) GDPR. The controller shall then no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims. The collection of data for the provision of the website and the storage of log files are essential for the operation of the website.