1. Controller
The controller for data processing within the meaning of the GDPR is:
Robert Gürgens
Software- und IT-Dienstleistungen
Suhler Straße 17
12629 Berlin
Germany
Email: dpo@gartenkern.de
We are not legally required to appoint a data protection officer. The address above reaches the controller directly.
2. General principles
We process personal data of our users only to the extent necessary to provide a functional platform and to fulfil our contractual and legal obligations (data minimisation, Art. 5 GDPR).
Legal bases
- Art. 6 (1)(a) GDPR: consent, where you grant it separately for individual features
- Art. 6 (1)(b) GDPR: performance of a contract (account, platform use)
- Art. 6 (1)(c) GDPR: legal obligation (accounting, taxes)
- Art. 6 (1)(f) GDPR: legitimate interests (security, abuse detection)
You may withdraw consent at any time with effect for the future (Art. 7 (3) GDPR). The lawfulness of processing carried out before withdrawal remains unaffected.
3. What data we process
| Data | Purpose | Legal basis |
|---|---|---|
| Email, display name | Account creation, login | Art. 6 (1)(b) |
| Workspace and garden content (plantings, journal, tasks, images) | Platform use | Art. 6 (1)(b) |
| Garden location polygon | Map and weather features | Art. 6 (1)(b) |
| EXIF data in uploaded images | Stripped before storage (data minimisation) | not applicable |
| Technical checksum of uploaded images | Matched against content we previously removed, prevents re-upload. The image itself is not stored for this. | Art. 6 (1)(f) |
| Content you set to "Community" or "Public" | Display to signed-in users or to any visitor. Voluntary, revocable at any time; shown without your name. | Art. 6 (1)(a) |
| Reports submitted via the "Report content" button (statement, optional contact details, IP) | Handling under DSA Art. 16, record of handling, abuse protection via rate limit | Art. 6 (1)(c), Art. 6 (1)(f) |
| IP address on login and upload | Security, abuse detection | Art. 6 (1)(f) |
| Server log files (IP, timestamp, requested resource, status code) | Operation, debugging, attack defence | Art. 6 (1)(f) |
| Payment references and subscription status | Contract performance, accounting | Art. 6 (1)(b), Art. 6 (1)(c) |
| Cancellation declaration submitted through the cancellation button (contract number, email, name, reason) | Evidence under § 312k (3) and (4) of the German Civil Code | Art. 6 (1)(c) |
| Cookies (session, locale, theme) | Platform function (strictly necessary) | Art. 6 (1)(b) + § 25 (2) TDDDG |
4. Cookies
We use strictly necessary cookies only:
ory_kratos_session: login session (essential, session cookie)csrf_token_…: cross-site request forgery protection (essential)NEXT_LOCALE: selected language (essential)theme: light or dark preference (essential)gartenkern_invite_token: validation of your invite code during the closed beta (essential, HttpOnly, expires after 2 hours)
There is no tracking, no profiling, and no third-party advertising. A cookie consent banner is therefore not required under § 25 (2) TDDDG.
5. Audience measurement
We want to know which pages are read and whether what we offer lands. For that we use no Google Analytics and no other outside service, but our own measurement on our server in Nuremberg. It sets no cookie and stores or reads nothing on your device.
For a page view we store:
- the page you opened, in coarsened form.
/gardens/8f2c…becomes/gardens/{id}; the identifier itself is discarded. - the language of the page (
deoren) - the referring site, but only its address without additions:
google.com/search?q=…becomesgoogle.com. A search term never reaches us. - browser family (e.g. "Chrome"), operating-system family (e.g. "Android") and device class (phone, tablet, desktop)
- the country, where the local GeoLite2 database provides it. Deliberately only the country, no city, no region.
- a pseudonym valid for one day (see below)
We do not store your IP address. It goes into the calculation of the pseudonym and is discarded afterwards.
How the pseudonym works. From your IP address, your browser identifier and a secret random value that changes every day we compute a checksum. It lets us tell that two views on the same day likely came from the same person. Once that day's random value is deleted (after two days at the latest), the checksum cannot be traced back to a person, and the next day the same person yields a different one. Recognising and following someone across days is therefore technically impossible.
We also count certain events without a personal reference, such as "a garden was created for the first time" or "a subscription was taken out". The contents of your garden, your journal entries or your photos are not transmitted.
Search terms without results. When you submit a search on our search page and it returns nothing at all, we keep the search term. It tells us which magazine article or which plant in the encyclopedia is missing. We store only the term itself in lower case, together with a counter and the time of the last search. No IP address, no pseudonym value, no link to your account. Two searches therefore cannot be recognised as belonging together. Input that looks like personal data (email addresses, phone numbers, long digit sequences, whole sentences) is not stored at all. Neither are searches that did return results, nor the suggestions shown while you type. After 90 days without another search we delete the term.
Legal basis is our legitimate interest in data-minimising audience measurement (Art. 6 (1)(f) GDPR). Since we neither store nor read anything on your device, § 25 (1) TDDDG does not apply and no consent is required.
Retention: individual measurements are deleted after 90 days. What remains are aggregate numbers (e.g. "1,200 views of the pricing page in May") that no longer relate to a person.
Country lookup uses the GeoLite2 database by MaxMind (CC BY-SA 4.0). It sits locally on our server; no query is sent to MaxMind.
6. Processors and external services
| Provider | Purpose | Location | Legal basis |
|---|---|---|---|
| netcup GmbH | Hosting | DE Nuremberg | DPA under Art. 28 GDPR |
| Hetzner Online GmbH | Backup storage (encrypted) | DE | DPA under Art. 28 GDPR |
| Proton AG | Email receipt and delivery | CH (adequacy decision) | DPA |
| Stripe Payments Europe, Ltd. | Payment processing (subscriptions, invoices) | IE (EU) | DPA under Art. 28 GDPR |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payment processing, if you choose PayPal | LU (EU) | Art. 6 (1)(b) |
| Mistral AI SAS | Plant recognition, AI chat, season summaries, receipt and meter OCR, disease diagnosis | FR (EU) | DPA under Art. 28 GDPR |
| OpenRouter, Inc. | Public plant knowledge enrichment and DE/EN translations | US (SCCs) | Art. 28 + Art. 46 GDPR |
Mistral La Plateforme (servers in the EU, France) processes on our behalf:
- Plant photos for recognition (plant identify) and disease diagnosis
- AI chat requests with journal context, only if you use the AI chat
- Season summaries about your garden, only if you generate them
- Receipts you upload to the expense book
- Meter reading photos you upload to meter tracking
Mistral processes this content solely for inference and deletes it from audit logs within 30 days, as contractually assured. No training use takes place. We store neither the original image nor raw Mistral responses long term; only the structured result (recognised plant, extracted receipt item, answer text) enters your garden.
For public data without personal reference (general plant knowledge enrichment in our plant knowledge base, DE/EN translations of plant content and blog articles) we additionally use OpenRouter, Inc. (USA, under EU standard contractual clauses per Art. 46 GDPR). Your journal entries, AI chat requests, and photos are never processed there; the router refuses those routes technically.
A detailed sub-processor list with models and architecture guarantees is available on request at dpo@gartenkern.de.
When you take out a paid subscription, the payment provider you choose (Stripe Payments Europe, Ltd., Ireland, or PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg) processes your payment data, for example payment method and billing address. PayPal acts as an independent controller in this respect. We ourselves store no complete payment data, only the provider's reference IDs and the subscription status.
External services your browser contacts directly
For some features, your browser contacts external services directly; for technical reasons your IP address is transmitted. These services are not processors but independent recipients. The legal basis is our legitimate interest in providing the respective feature (Art. 6 (1)(f) GDPR):
| Service | Purpose | Location |
|---|---|---|
| OpenFreeMap | Map tiles (standard map view) | EU (public instance) |
| MapTiler AG | Map tiles (satellite and hybrid) | CH (adequacy decision) |
| Open-Meteo | Weather data for your garden (no API key, no tracking) | DE/EU |
Push notifications: If you enable browser notifications, they are delivered via your browser's push service, for example Mozilla, Google, or Apple depending on the browser. We store only a technical push subscription, which you can revoke at any time in your settings.
Error telemetry: We record technical errors through a self-hosted GlitchTip on our server in Germany. No data is passed to third parties. IP addresses are not stored by default.
7. Retention
The access log files of our web servers, which contain your IP address, are rotated daily. We keep 14 generations and delete older ones automatically. Your IP address is therefore stored for no longer than 15 days after the request, and is irreversibly deleted afterwards. These log files are never combined with your account.
Cancellation declarations submitted through the cancellation page are retained as evidence, even when they cannot be matched to a contract. § 312k (3) and (4) of the German Civil Code require us to document and confirm the receipt of a cancellation. Without that record, neither you nor we could show, in a dispute, when a cancellation was received.
We store account and garden data for as long as your account exists. After a deletion request, the period in Section 10 applies. Invoices and accounting records are retained for ten years under § 147 AO and § 257 HGB; they are blocked from further use.
Individual audience-measurement records (Section 5) are deleted after 90 days, the daily random value after two days. Aggregate numbers without a personal reference are kept.
8. No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The platform's AI features (plant recognition, chat, summaries) produce suggestions, not legally binding decisions about you.
9. Your rights (GDPR Art. 15 to 22)
You have the right at any time to:
- Access (Art. 15) what we store about you, on request at dpo@gartenkern.de
- Rectification (Art. 16), directly in your account profile
- Erasure (Art. 17, "right to be forgotten"), on request at dpo@gartenkern.de
- Restriction of processing (Art. 18), on request by email
- Data portability (Art. 20), on request in a structured, commonly used format
- Object (Art. 21) to processing based on Art. 6 (1)(f) GDPR
- Lodge a complaint with a supervisory authority (Art. 77)
Send these requests and any other data protection questions to dpo@gartenkern.de. We respond without undue delay and at the latest within one month. Where a request is particularly complex, that period may be extended by up to two further months; we will tell you within the first month if that happens (GDPR Art. 12 (3)).
The supervisory authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59 to 61, 10555 Berlin, Germany
https://www.datenschutz-berlin.de/
You may also contact the supervisory authority of your habitual residence.
10. Backups and deletion periods
Backups are stored encrypted for 30 days. A deletion request takes immediate effect in the live database; deletion is finalised in backups through rollover within 30 days. Backups are used solely for disaster recovery.
11. Minimum age
The platform is open to persons aged 16 and over (Art. 8 GDPR). Anyone younger may use the service only with the consent of a legal guardian.
12. Security (GDPR Art. 32)
We take technical and organisational measures that reflect the state of the art: encrypted transport for all connections, passwords stored only as a secure hash and never in plain text, EXIF stripping on image uploads, strict separation between the data of different garden accounts, and a permission check on every access.
We do not list the individual mechanisms here. They evolve with the state of the art, and publishing them would make an attacker's work easier. We provide information on reasoned request.
13. Data breach notification
In the event of a personal data breach we notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33). Where the breach is likely to result in a high risk to your rights and freedoms, we also notify you without undue delay (GDPR Art. 34).
