Privacy Policy
Please note: This text is a draft and must be reviewed for legal compliance by a lawyer or by the client before launch, and adapted to the actual processing activities. It does not constitute legal advice.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
B&G Holding B.V. (brand Bright & Green)
Westervoortsedijk 73 KB2
6827 AV Arnhem, Netherlands
Represented by Managing Director François van Burk
Phone: +49 157 5613 9185
Email: office@brightandgreen.de
Overview and Scope
This privacy policy informs you about the nature, scope and purpose of the processing of personal data when you visit this website. Personal data is any data with which you can be personally identified.
This website is a purely informational site with no user accounts, no tracking and no analytics or advertising cookies. We process personal data only where this is technically necessary or when you contact us via the contact form.
Hosting and Server Log Files
This website is operated on the servers of a hosting provider located within the European Union (Hetzner, Germany). When you access the website, the web server automatically records information transmitted by your browser in so-called server log files. This includes, in particular: IP address, date and time of access, the page or file requested, the volume of data transferred, the browser type and operating system used, and the previously visited page (referrer).
This data is processed to deliver the website, to ensure stability and security, and for error analysis. The legal basis is our legitimate interest in the secure and functional operation of the website (Art. 6(1)(f) GDPR).
SSL / TLS Encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser begins with „https://“. When encryption is active, the data you transmit to us cannot be read by third parties.
Contact Form
If you contact us via the contact form, we process the data you provide: name, email address, message and, optionally, your phone number. We use this data solely to handle your enquiry and any follow-up questions.
Processing is carried out to take pre-contractual steps or to perform a contract, where your enquiry is directed towards this (Art. 6(1)(b) GDPR), and otherwise on the basis of our legitimate interest in effectively handling enquiries (Art. 6(1)(f) GDPR).
To send the message triggered via the form, we use the transactional email service Postmark (see section „Recipients and Processors“).
Storage Duration
We process and store your personal data only for as long as is necessary to achieve the respective processing purpose or as required by statutory retention obligations.
Data submitted via the contact form is stored until your enquiry has been conclusively handled, unless statutory retention periods apply. Server log files are stored only for a short period necessary to ensure operation and are deleted thereafter.
Recipients and Processors
To provide this website and handle your enquiries, we use carefully selected service providers who process personal data on our behalf and in accordance with our instructions (processing within the meaning of Art. 28 GDPR):
- Hosting: Hetzner (servers within the EU) — provision and operation of the website.
- Email delivery: Postmark (Wildbit / ActiveCampaign) — sending the transactional emails triggered via the contact form. The data processed comprises name, email address, message and, where applicable, phone number.
We have concluded the data processing agreements required under data protection law with these service providers.
Transfer to Third Countries
The Postmark service is operated by a provider based in or with infrastructure in the United States of America. Sending emails may therefore involve a transfer of personal data to a third country outside the European Union or the European Economic Area.
For such transfers we rely on appropriate safeguards within the meaning of Art. 44 et seq. GDPR, in particular the Standard Contractual Clauses adopted by the European Commission, unless another suitable transfer mechanism applies. We will provide further information on the safeguards in place upon request.
Cookies
This website does not use any tracking, analytics or advertising cookies. Only technically necessary processing operations required for the proper operation of the website are carried out.
Fonts are self-hosted and not loaded via external content delivery networks such as Google Fonts; no associated transfer of your data to third parties takes place.
Your Rights as a Data Subject
Within the framework of the statutory provisions, you have the following rights:
- Access to the data processed about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on a legitimate interest (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a message to the contact details listed in the „Controller“ section is sufficient.
Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
You may contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.
Changes to this Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or in order to reflect changes to our services in the privacy policy, for example when introducing new features. The respective current version applies to your next visit.