This version reflects Plantalume’s current technical and commercial setup. A renewed legal review is required before enabling real payments, new service providers or additional markets.
1. Controller
The controller for personal data processed on plantalume.com is Cinecart GmbH, Am Schlahn 1, 14476 Potsdam, Germany, represented by Sebastian Merk, email: mail@plantalume.com, commercial register: Amtsgericht Potsdam, HRB 25776 P.
2. Website access and server logs
When the website is accessed, the server processes technical connection data including IP address, date and time, requested address, transferred volume, HTTP status, referrer and browser/device information. This supports secure and stable delivery, troubleshooting and attack prevention. The basis is Art. 6(1)(f) GDPR and our legitimate interest in secure operation. Logs are retained only as long as operationally or security-wise necessary, then deleted or anonymised unless an incident requires longer retention.
3. Essential device storage
The application uses the essential “_plantalume_session” cookie for login, cart and session security. It is configured as HttpOnly, SameSite=Lax and Secure in production. The browser also stores “plantalume-cookie-consent” solely to remember dismissal of the banner. Subsequent personal-data processing relies on Art. 6(1)(b) or (f) GDPR; access to the device is essential under section 25(2)(2) TDDDG for the service explicitly requested. No analytics or marketing services are currently embedded, so “Accept all” does not activate additional providers.
4. Account and login
Registration processes name, email address, a password stored only as a cryptographic hash, and creation/change timestamps. Login also uses session and security information and temporarily rate-limits failed attempts. Purposes are account setup, account security and access to orders and subscriptions. The basis is Art. 6(1)(b) GDPR, with Art. 6(1)(f) for security. Account data remains until account deletion; order information subject to retention duties is restricted rather than erased beforehand.
5. Cart, checkout and orders
Cart contents are stored in the encrypted session. Checkout processes account data, products, quantities, prices, shipping name, street, postal code, city, country, order and payment status and technical references. This is necessary for pre-contractual steps, fulfilment, delivery, complaints and statutory records under Art. 6(1)(b) and (c) GDPR. Order and accounting records are kept for applicable commercial and tax periods, generally up to ten years, and then erased or anonymised unless open claims require retention.
6. Growpad subscriptions
Subscription management processes account, product, herb variety, delivery interval, next delivery, status and pause/cancellation timestamps under Art. 6(1)(b) GDPR. A test-mode planning record does not become paid without separate price and payment confirmation. Details remain until termination and thereafter only as required for contractual evidence, accounting or legal claims.
7. Contact
If you email us, we process sender address, message and voluntarily supplied details to respond. The basis is Art. 6(1)(b) GDPR for contract-related enquiries and otherwise Art. 6(1)(f) based on reliable communication. Correspondence is erased when no longer needed unless retention or evidence duties apply.
8. Recipients and processors
Access is limited to authorised personnel needing it for operations, support, shipping, accounting or administration. Necessary data may be shared with hosting and IT providers, carriers, payment providers and tax or legal advisers. Processors are bound under Art. 28 GDPR. The current checkout has no external payment provider. Before adding payment, newsletter, analytics or marketing services, this notice will identify provider, data, legal basis, retention and any international transfers.
9. International transfers
The current delivery does not envisage transfers outside the EU or EEA. Any future transfer will rely on an adequacy decision or suitable safeguards under Art. 44 et seq. GDPR, with advance information about the basis and risks.
10. Retention
Personal data is kept only as long as required for its purpose, legal retention, warranties, limitation periods or legal defence, then erased or anonymised. Criteria include contract duration, account status, commercial and tax duties and unresolved claims. Backups are overwritten in their cycle and isolated from ordinary access until then.
11. Your rights
Subject to legal requirements, you have rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21). Consent may be withdrawn prospectively at any time. Email mail@plantalume.com to exercise rights. Objection to direct marketing ends that use without balancing interests; no direct marketing currently occurs.
12. Complaint
Under Art. 77 GDPR you may complain to a supervisory authority. The authority particularly responsible for Cinecart GmbH is Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, email: Poststelle@LDA.Brandenburg.de, www.lda.brandenburg.de.
13. Automated decisions and security
There is no automated decision-making, including profiling, under Art. 22 GDPR. Appropriate safeguards include TLS transport encryption, secure session cookies, access controls, password hashing, request rate limiting and protections against common web attacks. No system can guarantee absolute security.
14. Changes
This notice is updated when features, providers or law change. The current version remains available here. Material changes affecting an account or contract will be communicated appropriately.