Privacy
Privacy information.
This page explains concisely how Records.de processes personal data when you visit the website or use its services.
01
Controller
Nico Gräfenhan, Records.de, Linderbacher Weg 30, 99099 Erfurt, Germany. Email: mail@records.de. Telephone: +49 361 676 390 51.
02
Website, security and local storage
When you open the website, necessary connection and security data may be processed, including the IP address, time, requested address, referrer, browser, operating system and security signals. This is necessary to deliver the website, detect errors and prevent abuse. The legal basis is Article 6(1)(f) GDPR. Merely visiting Records.de does not use analytics or advertising technologies that require consent. Browser storage is used only where necessary for a function you expressly request, such as the cart, login, a selection or the Concierge. Section 25(2) no. 2 TDDDG applies to that access; the related processing is based on Article 6(1)(b) or (f) GDPR, depending on the function.
03
Contact, collection enquiries and applications
If you contact us, we process the contact details, message and information needed for your request. A collection enquiry may include information about the collection and voluntarily submitted photos, videos, lists or documents. Required fields are needed to reply; optional uploads and additional details are voluntary. No decision with legal or similarly significant effects is made solely by automated means. Article 6(1)(b) GDPR applies to contractual or pre-contractual requests; other correspondence and necessary abuse prevention are based on Article 6(1)(f) GDPR. Application data is processed under section 26(1) BDSG and, if no employment follows, is normally deleted no later than six months after the process ends unless a specific legal defence or statutory duty requires longer retention.
04
Shop and orders
If you use the cart, account or checkout, we process the contact, account, order, payment, shipping and status data required for that purpose under Article 6(1)(b) GDPR. Records that must be retained by law are processed under Article 6(1)(c) GDPR. Security and error data is processed under Article 6(1)(f) GDPR to keep the ordering process secure and traceable.
05
Reviews and external content
Selected review texts, star ratings and displayed names from our public Google business profile are delivered by Records.de itself. The source is the review published there. We show customer experiences under Article 6(1)(f) GDPR; reviewers may request correction or removal at mail@records.de. A connection to Google Maps, YouTube or another external service is made only when you actively open the relevant link or content. The respective provider is responsible for the subsequent processing.
06
Records.de Concierge
If you start the Concierge, we process your input, language and a time-limited conversation context in order to respond. Voluntary ratings or problem reports are used for quality improvement. Do not enter contact, customer, order, payment or other personal data; use email or telephone for a specific case. Processing is based on Article 6(1)(b) GDPR for contractual or pre-contractual use and otherwise on Article 6(1)(f) GDPR. The necessary technical session ends no later than 24 hours after it starts.
07
Recipients and international transfers
Data is received only by parties that need it for the relevant task. These include Cloudflare for hosting and security, Resend and webgo or Google Workspace for email, OpenAI when the Concierge is used and the relevant payment and shipping providers for orders. Authorities or advisers receive data only where required by law or needed to establish, exercise or defend legal claims. Some providers may process data outside the EEA, particularly in the United States. Depending on the provider, transfers rely on an EU adequacy decision, including the EU-U.S. Data Privacy Framework, or on standard contractual clauses. Information about the applicable safeguards is available from mail@records.de.
08
Retention
Personal data is kept only for as long as the relevant purpose requires. Session data normally ends with the session; persistently selected functions remain until deletion, change or logout. Contact, Concierge and security data is deleted or anonymised once the matter and necessary protection periods are complete and no justified claims require continued storage. Contract and accounting records follow statutory commercial and tax retention periods.
09
Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction or portability. You may object to processing based on legitimate interests and withdraw consent for the future. To exercise these rights, email mail@records.de. You may also complain to a data-protection supervisory authority.