Privacy Policy
We take the protection of your personal data seriously. This page explains what data we collect when you use kosy-home.de, why we collect it, how long we keep it and what rights you have. The German version of this notice is the legally authoritative one.
1. Controller
Controller within the meaning of the GDPR is Fupo Konzepte GmbH, Bautzener Straße 6, 10829 Berlin, Germany. Email: mail@fupo-konzepte.de. Phone: +49 30 629379944. Managing directors: Stefan Pohl, Henry Funke.
2. Hosting
This website is hosted on the infrastructure of Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. When you visit the site, Vercel automatically collects technical access data (IP address, request URL, user agent, referrer, timestamp) and stores it in server log files. The legal basis is Art. 6 para. 1 lit. f GDPR — our legitimate interest in providing a stable, secure website. A data processing agreement (DPA) under Art. 28 GDPR is in place with Vercel; transfers to the United States are based on the EU Standard Contractual Clauses.
3. Cookies and local storage
We use only technically necessary cookies and similar storage (e.g. local storage) — for instance to remember your chosen locale or the in-progress configuration of your curtains. No tracking cookies and no third-party analytics or advertising cookies are set without your consent. Legal basis: § 25 para. 2 TTDSG and Art. 6 para. 1 lit. f GDPR.
4. Configurator data
The choices you make in the configurator (model, colour, placement, finish, light setting) are processed in your browser. If you proceed to checkout, those choices are stored together with your order for the purpose of fulfilment. Photos that you upload in the 'See it on your window' preview are processed locally in your browser only and are not transmitted to our servers.
5. Order processing and payment
When you place an order, we process the data you enter (name, delivery address, email, telephone number where provided, order details and price) to fulfil the contract under Art. 6 para. 1 lit. b GDPR. We retain order data for the statutory retention periods (up to 10 years under German commercial and tax law, § 257 HGB, § 147 AO).
Payments are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. When you pay, the payment data is transmitted directly to Stripe and processed under their own privacy policy. We never see or store full card details.
6. Customer database
Order and customer data is stored in a managed PostgreSQL database operated by Neon Inc., 209 W. Jackson Blvd., Chicago, IL 60606, USA. A data processing agreement under Art. 28 GDPR is in place; transfers to the United States are based on the EU Standard Contractual Clauses.
7. Contact by email
If you contact us by email, the data you transmit (your email address, name and the content of your message) is stored to process your enquiry. Legal basis is Art. 6 para. 1 lit. b GDPR (pre-contractual measures) or lit. f GDPR (legitimate interest in responding to enquiries). The data is deleted as soon as it is no longer required, unless legal retention obligations apply.
8. Newsletter
If you sign up for our newsletter we send you a confirmation email (double opt-in) before we add you to the list. We process your email address for the purpose of sending the newsletter and store the time you signed up and the IP address used to do so, as proof of consent. Legal basis is Art. 6 para. 1 lit. a GDPR. You can unsubscribe at any time via the link in any newsletter email; we will then delete your address.
9. Your rights
Under the GDPR you have the right to information about the data we hold about you (Art. 15), to rectification of incorrect data (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing (Art. 21). Where processing is based on consent, you can withdraw that consent at any time with effect for the future.
To exercise any of these rights, please contact us at mail@fupo-konzepte.de. You also have the right to lodge a complaint with a supervisory authority — for us, that is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin.