Privacy Policy
Last updated: September 27, 2025
Data Controller
Kumpas GmbH
Weidenbornstraße 8a
65189 Wiesbaden, Germany
Authorized Representatives: Mulliqi Kastriot
Email: info@kumpas.de
Legal Notice: https://kumpas.de/imprint
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Inventory data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication, and process data.
- Log data.
Categories of Data Subjects
- Customers and clients.
- Prospects.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Office and organizational procedures.
- Organizational and administrative procedures.
- Feedback.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Public relations.
- Business processes and operational procedures.
Relevant Legal Bases
Relevant legal bases according to the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
- Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 (1) (c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 (1) (f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. This includes in particular the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions on the right to access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission, as well as automated individual decision-making, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Note on applicability of GDPR and Swiss FADP: This privacy policy serves to provide information in accordance with both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For this reason, we ask you to note that due to the broader spatial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms "processing" of "personal data", "overriding interest" and "particularly sensitive personal data" used in the Swiss FADP, the terms used in the GDPR "processing" of "personal data" as well as "legitimate interest" and "special categories of data" are used. However, the legal meaning of the terms will continue to be determined under the Swiss FADP within the scope of application of the Swiss FADP.
Security Measures
We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs, the nature, scope, circumstances, and purposes of processing, as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
The measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access to, input, disclosure, assurance of availability, and segregation of the data. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data threats. Furthermore, we already consider the protection of personal data during the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and by default.
Securing online connections via TLS/SSL encryption technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transfers meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator for users that their data is being transmitted securely and encrypted.
Transfer of Personal Data
In the course of our processing of personal data, it may happen that the data is transferred to or disclosed to other entities, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content embedded in a website. In such cases, we comply with the legal requirements and conclude, in particular, corresponding contracts or agreements with the recipients of your data that serve to protect your data.
Data transfer within the organization: We may transfer personal data to other departments or units within our organization or grant them access to this data. If the data transfer is for administrative purposes, it is based on our legitimate business and operational interests or takes place if it is necessary for the fulfillment of our contractual obligations or if the data subjects have given their consent or a legal permission exists.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with the legal provisions as soon as the underlying consents are revoked or no other legal basis for the processing exists. This applies to cases where the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule exist if legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of other natural or legal persons must be archived accordingly.
Our privacy policy contains additional information on the retention and deletion of data that applies specifically to certain processing processes.
If there are multiple specifications for the retention period or deletion deadlines of a date, the longest period shall always prevail. Data that is no longer stored for the originally intended purpose but due to legal requirements or other reasons is processed by us exclusively for the reasons that justify its retention.
Data retention and deletion: The following general periods apply to retention and archiving under German law:
- 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets as well as the work instructions and other organizational documents necessary for their understanding (§ 147 (1) No. 1 in conjunction with (3) AO, § 14b (1) UStG, § 257 (1) No. 1 in conjunction with (4) HGB).
- 8 years - Accounting documents, such as invoices and receipts (§ 147 (1) No. 4 and 4a in conjunction with (3) sentence 1 AO as well as § 257 (1) No. 4 in conjunction with (4) HGB).
- 6 years - Other business documents: received commercial or business letters, reproductions of sent commercial or business letters, other documents insofar as they are relevant for taxation, e.g., timesheets, operating statements, calculation documents, price labels, but also payroll documents, insofar as they are not already accounting documents, and cash register slips (§ 147 (1) No. 2, 3, 5 in conjunction with (3) AO, § 257 (1) No. 2 and 3 in conjunction with (4) HGB).
- 3 years - Data that is necessary to consider potential warranty and compensation claims or similar contractual claims and rights and to process related inquiries, based on previous business experience and common industry practices, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw your consent at any time.
- Right of access: You have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the information specified by law, as well as a copy of the data.
- Right to rectification: You have the right to obtain the rectification of inaccurate personal data concerning you and, taking into account the purposes of the processing, the right to have incomplete personal data completed.
- Right to erasure and restriction of processing: You have the right to obtain the erasure of personal data concerning you without undue delay, or alternatively, to obtain restriction of processing in accordance with the law.
- Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.
Business Services
We process data of our contractual and business partners, e.g., customers and prospects (collectively referred to as "contractual partners") in the context of contractual and comparable legal relationships as well as related measures and in the context of communication with contractual partners (or pre-contractual), for example, to respond to inquiries.
We use this data to fulfill our contractual obligations. This includes in particular the obligations to provide the agreed services, any update obligations and to remedy warranty and other performance disruptions. In addition, we use the data to safeguard our rights and for the purpose of the administrative tasks associated with these obligations as well as business organization. Furthermore, we process the data on the basis of our legitimate interests in proper and business-like business management as well as security measures to protect our contractual partners and our business operations from misuse, endangerment of their data, secrets, information and rights (e.g., for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or financial authorities). Within the framework of applicable law, we only pass on the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed about other forms of processing, e.g. for marketing purposes, within the scope of this privacy policy.
We inform the contractual partners which data are required for the aforementioned purposes before or in the course of data collection, e.g. in online forms, by special labeling (e.g. colors) or symbols (e.g. asterisks or similar), or personally.
We delete the data after the expiry of statutory warranty and comparable obligations, i.e., basically after 4 years, unless the data is stored in a customer account, e.g., as long as it must be kept for legal reasons of archiving (e.g., for tax purposes usually 10 years). Data disclosed to us by the contractual partner within the scope of an order will be deleted in accordance with the specifications and basically after the end of the order.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); Payment data (e.g., bank details, invoices, payment history); Contact data (e.g., postal and email addresses or phone numbers); Contract data (e.g., subject matter of contract, term, customer category); Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, involved persons).
- Data subjects: Customers and clients; Prospects. Business and contractual partners.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; Security measures; Communication; Office and organizational procedures; Organizational and administrative procedures. Business processes and operational procedures.
- Retention and deletion: Deletion according to information in the section "General Information on Data Storage and Deletion".
- Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR); Legal obligation (Art. 6 (1) (c) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing processes, procedures and services:
- Online shop, order forms, e-commerce and performance of services: We process our customers' data to enable them to select, purchase, or order the chosen products, goods and associated services, as well as their payment and provision, or delivery, or execution. If necessary for the execution of an order, we use service providers, in particular postal, forwarding and shipping companies, to carry out the delivery or execution to our customers. For the processing of payment transactions, we use the services of banks and payment service providers. The required information is marked as such within the framework of the order or comparable acquisition process and includes the information required for delivery, or provision and billing as well as contact information in order to be able to hold any consultation; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR).
- Provision of software and platform services: We process the data of our users, registered and any test users (hereinafter uniformly referred to as "users") in order to be able to provide them with our contractual services and based on legitimate interests to ensure the security of our offer and to be able to develop it further. The required information is identified as such within the framework of the conclusion of the contract, order or comparable contract and includes the information required for the provision of services and billing as well as contact information in order to be able to hold any consultation; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR).
Payment Procedures
Within the framework of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer the data subjects efficient and secure payment options and use other service providers for this purpose in addition to banks and credit institutions (collectively "payment service providers").
The data processed by the payment service providers includes inventory data, such as name and address, bank data, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as contract, sum and recipient-related information. The information is required to carry out the transactions. However, the data entered is only processed by the payment service providers and stored by them. This means that we do not receive any account or credit card-related information, but only information with confirmation or negative information of the payment. Under certain circumstances, the data may be transmitted by the payment service providers to credit agencies. The purpose of this transmission is to check identity and creditworthiness. For this purpose, we refer to the terms and conditions and data protection information of the payment service providers.
The terms and conditions and the data protection notices of the respective payment service providers apply to the payment transactions, which can be called up within the respective websites or transaction applications. We also refer to these for the purpose of further information and assertion of revocation, information and other data subject rights.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); Payment data (e.g., bank details, invoices, payment history); Contract data (e.g., subject matter of contract, term, customer category); Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, involved persons).
- Data subjects: Customers and clients; Business and contractual partners. Prospects.
- Purposes of processing: Provision of contractual services and fulfillment of contractual obligations. Business processes and operational procedures.
- Retention and deletion: Deletion according to information in the section "General Information on Data Storage and Deletion".
- Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR). Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing processes, procedures and services:
- Stripe: Payment services (technical connection of online payment methods); Service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR); Website: https://stripe.com; Privacy Policy: https://stripe.com/de/privacy. Basis for third country transfers: Data Privacy Framework (DPF).
Provision of Online Offer and Web Hosting
We process user data in order to be able to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
- Types of data processed: Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, involved persons). Log data (e.g., log files concerning logins or retrieval of data or access times.).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Provision of our online offering and user-friendliness; Information technology infrastructure (Operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Retention and deletion: Deletion according to information in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing processes, procedures and services:
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the websites and files accessed, date and time of access, amount of data transferred, message about successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used on the one hand for security purposes, e.g., to avoid overloading the servers (especially in the case of abusive attacks, so-called DDoS attacks) and on the other hand to ensure the utilization of the servers and their stability; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Data deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.
- Hetzner: Services in the field of providing information technology infrastructure and related services (e.g., storage space and/or computing capacity); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.hetzner.com; Privacy Policy: https://www.hetzner.com/de/rechtliches/datenschutz. Data Processing Agreement: https://docs.hetzner.com/de/general/general-terms-and-conditions/data-privacy-faq/.
Contact and Inquiry Management
When contacting us (e.g., by mail, contact form, email, telephone, or via social media) and in the context of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to answer the contact inquiries and any requested measures.
- Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); Contact data (e.g., postal and email addresses or phone numbers); Content data (e.g., textual or pictorial messages and posts and the information pertaining to them, such as information on authorship or time of creation); Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, involved persons).
- Data subjects: Communication partners.
- Purposes of processing: Communication; Organizational and administrative procedures; Feedback (e.g., collecting feedback via online form). Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion according to information in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR). Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR).
Further information on processing processes, procedures and services:
- Contact form: When contacting us via our contact form, email, or other communication channels, we process the personal data transmitted to us to answer and process the respective request. This typically includes information such as name, contact information, and, if applicable, further information that is communicated to us and necessary for appropriate processing. We use this data solely for the stated purpose of contact and communication; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 (1) (b) GDPR), Legitimate interests (Art. 6 (1) (f) GDPR).
Presence on Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
We point out that user data may be processed outside the European Union. This may result in risks for users because, for example, the enforcement of user rights could be made more difficult.
Furthermore, user data within social networks is usually processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and the resulting interests of users. The latter may in turn be used, for example, to place advertisements inside and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users' computers, in which the usage behavior and interests of the users are stored. Furthermore, data may also be stored in the usage profiles independently of the devices used by the users (especially if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective processing forms and the possibilities of objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. Should you nevertheless need help, you can contact us.
- Types of data processed: Contact data (e.g., postal and email addresses or phone numbers); Content data (e.g., textual or pictorial messages and posts and the information pertaining to them, such as information on authorship or time of creation). Usage data (e.g., page views and dwell time, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing: Communication; Feedback (e.g., collecting feedback via online form). Public relations.
- Retention and deletion: Deletion according to information in the section "General Information on Data Storage and Deletion".
- Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR).
Further information on processing processes, procedures and services:
- Instagram: Social network, enables sharing of photos and videos, commenting and favoriting posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 (1) (f) GDPR); Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/. Basis for third country transfers: Data Privacy Framework (DPF).


