Privacy policy
1. Controller
Cullatec GmbH
Managing Directors: Max Arendt, Alexander Stephan Rieth
Saarland University, Building A 1.1
66123 Saarbrücken, Germany
Phone: +49 160 95822847
Email: info@cullatec.com
2. Hosting and server logs
When you access our website or shop, the server processes data including your IP address, time of access, requested address, amount of data transferred, referrer, browser and operating system. This data is required to deliver content, detect attacks and secure technical operations. Our legitimate interest is a secure and reliable service. The legal basis is Article 6(1)(f) GDPR.
Our hosting provider is ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. Server logs are generally deleted or anonymised after no more than seven days. If a specific security incident occurs, affected logs may be retained for longer until the incident and any legal claims have been resolved.
3. Strictly necessary cookies and browser storage
Shop sessions, baskets, checkout, language selection and storage of your privacy choice require cookies or local or session browser storage. Without these functions, the shop service you explicitly request cannot be provided in full. Storage or access is permitted without consent under section 25(2)(2) TDDDG; subsequent processing is based on Article 6(1)(b) or (f) GDPR depending on the function. Our legitimate interest is a secure, usable website and verifiable observance of your choice.
Your privacy choice is stored in your browser for up to 180 days. Shop session data generally ends when the session expires or is deleted. You may delete browser data at any time in your browser.
4. Analytics, marketing and campaign attribution
Analytics and marketing are activated only after your corresponding voluntary choice. The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You may change your choice at any time for the future through “Cookie settings” in the footer.
After analytics or marketing consent, we store campaign parameters and click identifiers supplied with the page request together with the landing page, referrer, time and a randomly generated session identifier for up to 90 days in your browser. This enables visits and purchases to be attributed to campaigns. The event parameters we set ourselves contain no names, email addresses, telephone numbers, postal addresses, free text, engraving text or payment data. Automatic matching by the OpenAI Pixel operates separately, as described in the OpenAI section below.
5. Contact, newsletter and sound download
We process contact-form and email enquiries to handle your request under Article 6(1)(b) GDPR for pre-contractual or contractual matters and otherwise under Article 6(1)(f) GDPR. Our legitimate interest is responding to legitimate enquiries. Enquiries are generally stored until handling is complete and then no longer than the end of the regular statutory limitation period, unless a longer obligation or legal dispute applies.
Newsletter registration uses double opt-in and is based on your consent. For a requested sound download, we use your email address to send the link. Voluntary information, such as the expected month of birth, is used only to select suitable content and offers. You may withdraw consent at any time. After unsubscribing, we delete distribution-list data; evidence of consent may be retained for up to three years to defend legal claims.
6. Customer account, order and withdrawal
For customer accounts, checkout, orders and withdrawals we process in particular master, contact, delivery, order, status and communication data. Mandatory fields are required to conclude and perform the contract; without them we cannot process the order. The legal bases are Article 6(1)(b) GDPR and Article 6(1)(c) GDPR for commercial and tax obligations.
Customer-account data is stored until the account is deleted, unless a retention obligation applies. Contract and order data is stored for performance and statutory claims. Accounting records are generally retained for eight years and commercial correspondence for six years. Data submitted through the electronic withdrawal function is processed to handle and evidence the withdrawal and to confirm its receipt without delay.
7. Payments
For classic advance bank transfer, we process payment reference, account holder and receipt of payment. For credit or debit card, Apple Pay, Google Pay, Revolut Pay and Pay by Bank we use Revolut Bank UAB, Konstitucijos ave. 21B, 08130 Vilnius, Lithuania. Data required for the selected payment method is transmitted, in particular order reference, amount, currency and technical transaction data. Depending on the payment method, participating banks, card networks and Apple or Google are also involved. We do not store full card details in the shop.
The legal basis is Article 6(1)(b) GDPR. Security and fraud checks are based on Article 6(1)(f) GDPR; our legitimate interest is preventing abusive payments. Further information: Revolut Pay Checkout, Apple Privacy and Google Privacy.
8. Shipping and transactional emails
We provide the carrier appointed for the particular order with the name, delivery address and contact details needed for delivery. Order, payment, dispatch, invoice and withdrawal messages are sent through our email services hosted by ALL-INKL.COM. The legal bases are Article 6(1)(b) and (c) GDPR.
9. Google Analytics 4 and Google Ads
After analytics consent, we use Google Analytics 4 from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to analyse reach, origin, page sequences and funnel activity. Data processed includes shortened IP and device information, page views, campaign parameters, product views, basket and checkout steps, order number and purchase value. Google Signals is disabled. Personal shop fields and payment data are not transmitted as events.
Google Ads does not receive a second parallel purchase measurement; it uses the GA4 purchase conversion linked to the Google Ads account. User and event data in the standard GA4 property is retained for no more than 14 months in accordance with the configured retention period; aggregated reports may continue to exist. The legal basis is your consent. Google Privacy.
10. Meta Pixel
After marketing consent, we use the Meta Pixel from Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, to measure and optimise advertising. Page and shop events, technical browser and device information, campaign identifiers and, for purchases, order number and purchase value are transmitted. Names, contact details, postal addresses, engraving text and payment data are not transmitted as events. The legal basis is your consent. Meta Privacy.
11. TikTok Pixel and Events API
After marketing consent, we use the TikTok Pixel and, for purchase events, the TikTok Events API from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. Browser and server reports use the same event identifier so that a purchase is not counted twice. Page and purchase events, campaign and cookie identifiers, IP address, browser identifier, order number, purchase value and, where available, the TikTok click identifier are processed. Names, email addresses, telephone numbers, postal addresses, payment data and engraving text are not transmitted as tracking events. The legal basis is your consent. TikTok Privacy.
12. Recipients and international transfers
Recipients are limited to service providers required for hosting, communication, payment, delivery, statutory duties and consented analytics or advertising. Google, Meta and TikTok may transfer data to affiliated companies and service providers outside the European Economic Area. Where no adequacy decision applies to the recipient country, transfers are based in particular on standard contractual clauses approved by the European Commission and additional safeguards; the EU-US Data Privacy Framework may apply to certified US recipients. You may request a copy or more information about the applicable safeguards from info@cullatec.com.
13. Affiliate and influencer programme
Only if you apply for or participate in the affiliate or influencer programme do we process master, contact, participation, attribution, commission and payout data to operate and settle the programme under Article 6(1)(b) and (c) GDPR. Abuse and settlement checks are based on Article 6(1)(f) GDPR. Unsuccessful applications are generally deleted after six months unless consent to longer contact or another legal basis applies.
14. Your rights and supervisory authority
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, portability and objection. Consent may be withdrawn at any time for the future. No solely automated decision with legal or similarly significant effect is made.
You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is Unabhängiges Datenschutzzentrum Saarland, Fritz-Dobisch-Straße 12, 66111 Saarbrücken, www.datenschutz.saarland.de. Please send questions and requests concerning your rights to info@cullatec.com.
OpenAI Ads Pixel and Conversions API
After your new consent to advertising measurement, we use the OpenAI Ads Pixel and Conversions API from OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. We measure visits, selected content interactions and steps from product views to purchases to understand which ads work. This involves event times, page and campaign information, browser information, IP addresses, and advertising click, browser and event identifiers. The pixel uses cookies for attribution.
OpenAI can recognise matching information to attribute purchases to an advertisement. Your email address, phone number and name are not transmitted as readable text. The pixel creates comparison values in your browser from email addresses, phone numbers, first and last names (SHA-256 hashes). These values enable matching and are not anonymous. City, region, country and postcode are instead transmitted as normalised, readable information. After consent, detection can occur while you type into a form, before submission; it can also detect supported information in technically provided page data and page content.
We report order submission from our server as a separate step, not yet as a purchase. We report a purchase only after accepting the order and confirming payment, potentially after you leave the website. We transmit event and item identifiers, quantities, amount, currency and available attribution identifiers. Stable event identifiers help prevent retries from being counted as additional purchases. The server-side event parameters we set contain no contact information, postal addresses, payment instrument data, engraving text or other free text; the browser pixel’s automatic matching described above operates separately.
Under the OpenAI Conversion Terms, OpenAI may also use data for reporting and for providing, developing and improving its products and services. The terms also cover custom audiences; we have not configured such audience creation through this integration. We flag transmitted events to exclude their use for future user-level personalisation. OpenAI normally processes the data as an independent controller under the Ad Tools DPA.
The legal bases for our consent-dependent collection and transmission are Article 6(1)(a) GDPR and, for access to browser storage, Section 25(1) TDDDG. You can change your selection through “Cookie settings”. Withdrawal applies going forward; it does not automatically delete previously transmitted data. For rights relating to data we process, contact info@cullatec.com; for OpenAI’s processing, use OpenAI’s privacy portal.
The OpenAI Pixel uses a click-identifier cookie (up to 30 days), a browser-identifier cookie (up to 365 days) and a consent-status cookie (up to 30 days). Consent status is also kept in local browser storage until overwritten or deleted. Setting a cookie again may restart its lifetime. To link your consent and withdrawal, we also use our own protected browser identifier lasting 180 days. Its server-side context is likewise valid for at most 180 days; this validity limit does not promise automatic deletion of all evidence records afterward. Browsers may remove stored data earlier.
OpenAI does not specify one fixed retention period for conversion data. Retention depends on processing purposes, the type of data, and security, dispute-resolution and legal retention requirements. Processing may take place outside the EEA. OpenAI identifies adequacy decisions or standard contractual clauses for onward transfers; you can request more information and a copy of the safeguards from OpenAI. Details about retention, recipients, transfers and rights are available in OpenAI’s European privacy policy.
Our own analysis of visitor journeys
After you consent to statistics, we use our own servers to analyse which pages and content you view and which shop steps you complete. The server records a genuine order submission, confirmed payment and acceptance of the order as separate states. A purchase is measured only when payment is confirmed and the order has been accepted. An order awaiting payment or acceptance is not treated as an abandoned purchase. Refunds and failed payments are not inferred from general order or status data alone. Analysis records contain event times, approved page, content and campaign identifiers, the device category and the placement of clicked links. Shop actions also include product identifiers, item quantities, amount, currency and the payment method category. Technical matching identifiers connect these steps without storing names, contact details, payment credentials or form text in the analysis records. These identifiers can connect related visits and shop states; this analysis is therefore not anonymous.
When you confirm your newsletter subscription by email and have already consented to OpenAI advertising measurement, we temporarily store a random identifier in your browser and on our server. It links the confirmed subscription to your consent, contains no form details and is valid for ten minutes. The server-side receipt is then deleted automatically, usually within a further five minutes; technical failures may delay deletion.
We use our own protected browser identifier, valid for up to 180 days, to associate your consent and its withdrawal across these purposes. The server-side consent context is also valid for no more than 180 days. Withdrawal blocks the previous permission for the relevant purpose; later consent does not reactivate older order snapshots. This validity limit does not mean that all consent evidence or order records are automatically deleted afterward.
Our own analysis events are stored in protected daily files. Files dated more than 90 days ago are removed during the next cleanup in ongoing analytics operation. For failed transmissions, the browser keeps no more than 100 events in session storage for retry. Events older than 24 hours are not sent again and are removed the next time the queue is checked; withdrawal discards pending analysis events.