Privacy Policy
Last updated: November 2024
1. Data Controller
The data controller responsible for processing personal data on this website is:
die Stimmgabel GmbH
Industriestraße 2H
68169 Mannheim, Germany
HRB 755770 | Ust-IdNr.: DE344214406
Email: christof@supplycloth.com | touhidul@supplycloth.com
Phone: +49-(0)157-764 750 80
2. Legal Basis for Data Processing
We process your personal data in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The legal bases for processing are:
• Art. 6(1)(a) GDPR - Consent
For analytics cookies, marketing cookies, and newsletter subscriptions.
• Art. 6(1)(b) GDPR - Contract Performance
For processing inquiries, orders, and business communications.
• Art. 6(1)(f) GDPR - Legitimate Interests
For website security, fraud prevention, and technical functionality (necessary cookies).
3. Data Categories and Processing Purposes
3.1 Contact Forms and Inquiries
When you contact us via contact form or email, we collect:
- Name and contact information (email, phone)
- Company name (if applicable)
- Message content
- IP address and timestamp
Purpose: Processing and responding to your inquiry. Legal Basis: Art. 6(1)(b) GDPR (contract performance) or Art. 6(1)(f) GDPR (legitimate interest). Retention: Until inquiry is resolved, maximum 3 years.
3.2 Booking and Consultation Services
When you book a consultation call via Cal.com, we collect:
- Name and email address
- Preferred date and time
- Company information (optional)
- Meeting notes and recordings (if applicable)
Purpose: Scheduling and conducting consultation calls. Legal Basis: Art. 6(1)(b) GDPR (contract performance). Retention: 3 years after last contact or until consent is withdrawn.
3.3 Server Log Files
Our hosting provider automatically collects and stores information in server log files:
- Browser type and version
- Operating system
- Referrer URL
- Hostname of accessing computer
- Time of server request
- IP address
Purpose: Ensuring website security and functionality, preventing abuse. Legal Basis: Art. 6(1)(f) GDPR (legitimate interest). Retention: Maximum 7 days, then automatic deletion.
4. Third-Party Services and Data Transfers
4.1 Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies to analyze website usage.
Data Transfer: Data is transferred to Google servers in the USA. Google is certified under the EU-US Data Privacy Framework. Legal Basis: Art. 6(1)(a) GDPR (consent). Opt-Out: You can disable Google Analytics via cookie settings or browser add-on.
4.2 Cal.com (Booking Service)
We use Cal.com for scheduling consultation calls. Cal.com is operated by Cal.com, Inc., 2261 Market Street #4139, San Francisco, CA 94114, USA.
Data Processed: Name, email, phone (optional), meeting preferences, calendar data. Data Transfer: Data may be transferred to US servers. Cal.com is certified under the EU-US Data Privacy Framework. Legal Basis: Art. 6(1)(b) GDPR (contract performance).
4.3 Trustpilot
We use Trustpilot widgets to display customer reviews. Trustpilot is operated by Trustpilot A/S, Pilestræde 58, 5th floor, 1112 Copenhagen K, Denmark.
Data Processed: IP address, browser information, page views. Data Transfer: Data is processed within the EU. Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in displaying reviews).
4.4 Google Fonts
We use Google Fonts (Inter font family) provided by Google Ireland Limited. When loading fonts, your IP address may be transmitted to Google servers.
Data Transfer: Data may be transferred to Google servers in the USA. Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in website design). Retention: Google stores data for up to 1 year.
5. Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
| Data Type | Retention Period |
|---|---|
| Contact form data | 3 years after last contact |
| Booking/consultation data | 3 years after last appointment |
| Server log files | 7 days |
| Cookie consent data | Until consent is withdrawn |
| Business correspondence | 10 years (tax law requirement) |
6. Your Data Subject Rights (GDPR Art. 15-22)
Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and to access your personal data and receive a copy.
Right to Rectification (Art. 16 GDPR)
You have the right to have inaccurate personal data corrected and incomplete data completed.
Right to Erasure (Art. 17 GDPR - "Right to be Forgotten")
You have the right to request deletion of your personal data, subject to legal retention obligations.
Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of processing in certain circumstances.
Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
Right to Object (Art. 21 GDPR)
You have the right to object to processing based on legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7(3) GDPR)
If processing is based on consent, you can withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
Competent Authority for Germany:
The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg
Königstraße 10a, 70173 Stuttgart, Germany
To exercise your rights, please contact us:
Email: christof@supplycloth.com
We will respond within one month of receiving your request.
7. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies. Cookies are small text files stored on your device. We use the following categories:
Necessary Cookies (Always Active)
Required for website functionality. Cannot be disabled. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
Analytics Cookies (Requires Consent)
Used to analyze website usage (Google Analytics). Legal basis: Art. 6(1)(a) GDPR (consent). You can manage preferences via our cookie banner.
Cookie Management: You can change your cookie preferences at any time by clicking the cookie icon in the bottom-right corner of the website.
8. Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- SSL/TLS encryption for data transmission
- Regular security updates and patches
- Access controls and authentication
- Regular backups and disaster recovery procedures
- Employee training on data protection
Note: While we implement strong security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
9. Children's Data
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately, and we will delete such information.
10. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in our practices or legal requirements. We will notify you of significant changes by posting the updated policy on this page with a new "Last Updated" date. We encourage you to review this policy periodically.
Last Updated: January 2025
11. Contact for Data Protection Concerns
If you have any questions, concerns, or wish to exercise your data protection rights, please contact us:
die Stimmgabel GmbH
Industriestraße 2H
68169 Mannheim, Germany
HRB 755770 | Ust-IdNr.: DE344214406
Response Time: We aim to respond to all data protection inquiries within 30 days as required by GDPR.