Privacy Policy
Zuletzt aktualisiert:
Preamble
This privacy policy informs you about which personal data (hereinafter also referred to as "data") we process, for which purposes, and to what extent. It applies to all processing of personal data carried out by us, both in the course of providing our services and within external online presences such as our social media profiles.
Controller
Divplate
Kiryakov, Michael und Jancen, Sofia GbR
Hohe Str. 54
53119 Bonn
Germany
Authorized representatives: Michael Kiryakov, Sofia Jancen
E-Mail: support@divplate.com
Overview of Processing Activities
Types of data processed: Inventory data, payment data, contact data, content data, contract data, usage data, meta/communication data, log data.
Categories of data subjects: Customers, prospects, communication partners, users.
Purposes of processing: Contract performance, communication, security, direct marketing, affiliate tracking, provision of our online offerings, marketing, reach measurement.
Legal Bases
We process personal data on the following legal bases under the GDPR:
Consent (Art. 6(1)(a) GDPR) — for voluntarily given consent, e.g., for newsletters
Performance of a contract (Art. 6(1)(b) GDPR) — for the fulfillment of purchase agreements
Legal obligation (Art. 6(1)(c) GDPR) — e.g., commercial and tax retention obligations
Legitimate interests (Art. 6(1)(f) GDPR) — e.g., to ensure the operation of our business
The German Federal Data Protection Act (BDSG) applies in addition.
Security Measures
We take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk. These measures include securing the confidentiality, integrity, and availability of data, as well as securing online connections through TLS/SSL encryption (HTTPS).
International Data Transfers
When using services based in the United States (Klaviyo, Polar, Zapier, Framer), data is transferred to a third country outside the EU/EEA. These transfers are based on:
Data Privacy Framework (DPF) — where the respective provider is certified (EU Commission adequacy decision of July 10, 2023)
Standard Contractual Clauses (SCCs) of the EU Commission as additional safeguards
Further information on the DPF and a list of certified companies can be found at https://www.dataprivacyframework.gov/.
General Information on Data Storage and Deletion
We delete personal data as soon as the underlying consent is withdrawn or no further legal grounds for processing exist. Exceptions apply when statutory obligations require longer retention:
10 years — Books, records, annual financial statements (§ 147 AO, § 257 HGB)
8 years — Accounting documents, invoices
6 years — Business correspondence and other business documents
3 years — Data for processing potential warranty claims (§§ 195, 199 BGB)
Rights of Data Subjects
Under the GDPR, you have the following rights:
Right to object to the processing of your data, in particular against direct marketing
Right to withdraw consent at any time
Right of access to information about the data we process about you
Right to rectification of inaccurate data
Right to erasure and restriction of processing
Right to data portability
Right to lodge a complaint with a supervisory authority, in particular at your place of residence or the alleged infringement
Business Services
We process data of our customers for the initiation, execution, and processing of contractual relationships. This includes the fulfillment of our contractual obligations, the processing of orders, and the fulfillment of statutory retention obligations.
Types of data processed: Inventory data (name, address), payment data, contact data, contract data, usage data. Data subjects: Customers, prospects. Legal bases: Art. 6(1)(b), (c), and (f) GDPR.
Sales via Online Platforms (Framer Marketplace)
We offer our digital products (website templates) on the Framer Marketplace. In this context, the privacy policies of the respective platform operator apply additionally.
Service provider: Framer B.V. (operating through Framer, Inc., 575 Market Street, San Francisco, CA 94105, USA) Legal bases: Art. 6(1)(b) and (f) GDPR (contract performance and legitimate interests). Privacy policy: https://www.framer.com/legal/privacy-policy Basis for third-country transfers: Standard Contractual Clauses and, where applicable, the Data Privacy Framework.
Payment Processing (Polar)
For payment processing, we use the payment service provider Polar, which in turn uses Stripe as its underlying technical payment processor. During checkout, your order data and the information required for payment processing (e.g., name, billing address, email address, payment method) are transmitted to Polar.
We ourselves do not receive complete payment data (e.g., credit card numbers) — only confirmation that a payment has been completed.
Service provider: Polar Software Inc., USA Legal bases: Art. 6(1)(b) GDPR (contract performance). Privacy policy: https://polar.sh/legal/privacy Basis for third-country transfers: Standard Contractual Clauses, where applicable Data Privacy Framework.
Underlying payment processor: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. Privacy policy: https://stripe.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
Newsletter and Electronic Notifications (Klaviyo)
We send newsletters, product announcements, and transactional emails through the service provider Klaviyo. For this purpose, your email address and any other voluntarily provided data are transmitted to and stored by Klaviyo.
Sign-up: Newsletter subscriptions use a double opt-in process. You will receive a confirmation email asking you to confirm your subscription.
Performance measurement: Newsletters contain a so-called "web beacon" (a pixel-sized file) that is retrieved when the email is opened. Through this, we collect technical information such as browser, operating system, IP address, and time of retrieval. This data is used solely for the technical improvement of our newsletter and analysis of our marketing.
Withdrawal: You can unsubscribe from our newsletter at any time. An unsubscribe link is included in every newsletter. Alternatively, you can contact us by email.
Retention of unsubscribed addresses: We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to prove a previously granted consent.
Service provider: Klaviyo, Inc., 125 Summer Street, Boston, MA 02110, USA Legal bases: Art. 6(1)(a) GDPR (consent) for marketing emails; Art. 6(1)(b) GDPR (contract performance) for transactional emails. Privacy policy: https://www.klaviyo.com/legal/privacy Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Automation Services (Zapier)
To connect our services (e.g., to transfer order data between Polar and Klaviyo), we use the automation service Zapier. With each order, the data required for processing (e.g., email address, order number) is processed by Zapier.
Service provider: Zapier, Inc., 548 Market St #62411, San Francisco, CA 94104, USA Legal bases: Art. 6(1)(b) and (f) GDPR (contract performance and legitimate interests). Privacy policy: https://zapier.com/privacy Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses.
Affiliate Programs and Affiliate Links
We participate in Framer's affiliate program. When users purchase our templates and subsequently subscribe to a paid Framer plan, we receive a commission. Cookies or similar technologies are used to track whether a user followed one of our affiliate links.
Types of data processed: Contract data, usage data, meta/communication data. Legal bases: Art. 6(1)(f) GDPR (legitimate interests).
Customer Reviews and Rating Procedures
We participate in the rating system of the Framer Marketplace. When you submit a review, the terms and privacy policies of Framer apply additionally.
Legal bases: Art. 6(1)(f) GDPR (legitimate interests).
Presence on Social Networks
We maintain profiles on the following social networks to communicate with active or potential customers:
X (Twitter): X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland. Privacy policy: https://x.com/en/privacy.
LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland. Privacy policy: https://www.linkedin.com/legal/privacy-policy. Basis for third-country transfers: Data Privacy Framework, Standard Contractual Clauses.
Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework.
YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Privacy policy: https://policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework.
Data on these platforms is also processed for market research and advertising purposes, including the creation of usage profiles. For information requests, please contact the respective providers directly, as they are most effective at handling them.
Legal bases: Art. 6(1)(f) GDPR (legitimate interests).
Changes and Updates
Please review the content of our privacy policy regularly. We will adapt it as soon as changes to our data processing make this necessary. Should the changes require any action on your part, we will notify you separately.