Privacy Policy
1. Privacy at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this online shop or make a purchase. Personal data is any data that can be used to personally identify you. Detailed information on the subject of data protection can be found in the privacy policy listed below this text.
Who is responsible?
The entity responsible for data processing in this online shop is Ökoweingut Markus Busch. Full contact details can be found in section 3 under “Information on the responsible entity”.
What data is collected?
Essentially, the following data is processed when visiting and using this shop:
Data that you actively provide (e.g., during an order, newsletter subscription, or in the AI sommelier chat),
Data that arises during the processing of a contract (e.g., order history),
Technical data that is automatically collected when visiting the website (e.g., IP address, browser type).
Why is your data processed?
Data processing takes place primarily for the purpose of contract fulfillment (order, shipping, payment), for providing the online shop, for fulfilling legal obligations (e.g., accounting, taxes, youth protection), as well as on the basis of your consent (e.g., for the newsletter).
What are your rights?
You have the right to free information, correction, deletion, and restriction of the processing of your data at any time, as well as the right to data portability and the right to object and lodge a complaint with a supervisory authority. Details can be found in section 3.
Who technically processes your data?
This online shop is operated via the platform of Vinolin UG (haftungsbeschränkt). Vinolin processes a portion of your data as a data processor on behalf of the aforementioned responsible entity. For certain functions (especially the central login service and the AI sommelier under the sole responsibility of Vinolin), Vinolin itself is the responsible entity; details on this can be found in sections 5, 6, and 7.
2. Hosting and technical provision
The online shop is operated on the SaaS platform “Vinolin Suite” of Vinolin UG (haftungsbeschränkt), Bildungscampus 11, 74076 Heilbronn. Vinolin processes the personal data generated in this shop as a data processor on behalf of the shop operator. A data processing agreement has been concluded with Vinolin in accordance with Art. 28 GDPR.
Vinolin uses the following sub-processors for the technical provision of the platform:
Vercel Inc. (USA, with global CDN) — Web hosting and delivery of static content
Neon Inc. (USA, data processing in Frankfurt am Main) — Database hosting
Inngest, Inc. (USA) — Background job processing
Amazon Web Services EMEA SARL (Luxembourg, data processing in Frankfurt am Main) — Sending transactional emails (e.g., order confirmations)
Google Ireland Ltd. (Ireland, data processing in Frankfurt am Main) — AI functions for the sommelier (cf. section 7)
For sub-processors based outside the EU, EU Standard Contractual Clauses (SCCs) are used in accordance with Art. 46 (2) (c) GDPR; in some cases, there is also self-certification under the EU-US Data Privacy Framework.
Processing occurs for the performance of the contract with our customers (Art. 6 (1) (b) GDPR) as well as based on our legitimate interest in a secure, fast, and efficient provision of the online shop by professional providers (Art. 6 (1) (f) GDPR).
3. General information and mandatory information
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations as well as this privacy policy.
We point out that data transmission on the Internet (e.g., in communication by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the responsible entity
The responsible entity for data processing in this online shop is:
Ökoweingut Markus Busch
Schulstraße 6
56862 Pünderich / Mosel
Phone: 065422810
Email: info@buschwein.de
VAT identification number according to § 27 a of the German Value Added Tax Act: DE249259368
Data Protection Officer
We have not appointed a data protection officer, as we are not required to do so. If you have questions about data protection, please contact us using the contact details provided under “Information on the responsible entity”.
Storage duration
Unless a more specific storage period has been mentioned in this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods according to § 257 HGB / § 147 AO; as a rule, ten years); in the latter case, deletion will occur after these reasons have ceased to apply.
General information on the legal bases of data processing
If you have consented to data processing, we process your personal data on the basis of Art. 6 (1) (a) GDPR. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 (1) (b) GDPR. Furthermore, we process your data if it is required for the fulfillment of a legal obligation on the basis of Art. 6 (1) (c) GDPR. Data processing may also occur on the basis of our legitimate interest according to Art. 6 (1) (f) GDPR. The specific legal bases applicable in each individual case are informed in the following paragraphs of this privacy policy.
Recipients of personal data
As part of our business activities, we work with various external entities. In this context, it is sometimes necessary to transmit personal data to these external entities. We only share personal data with external entities if this is necessary for contract fulfillment, if we are legally obligated to do so, if we have a legitimate interest according to Art. 6 (1) (f) GDPR in sharing, or if another legal basis allows the sharing of data. When using data processors, we only share personal data on the basis of a valid contract for data processing.
Revocation of your consent to data processing
Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object (Art. 21 GDPR)
If data processing is carried out on the basis of Art. 6 (1) (e) or (f) GDPR, you have the right at any time, for reasons arising from your particular situation, to object to the processing of your personal data; this also applies to profiling based on these provisions. If you object, we will no longer process your personal data concerned, unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
If your personal data is processed for the purpose of direct advertising, you have the right to object at any time to the processing of personal data concerning you for the purpose of such advertising. If you object, your personal data will subsequently no longer be used for the purpose of direct advertising.
Right to lodge a complaint with the competent supervisory authority
In the event of violations of the GDPR, data subjects have a right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.
Rheinland-Pfalz: The State Commissioner for Data Protection and Freedom of Information Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz.
Right to data portability
You have the right to have data that we process automatically based on your consent or in fulfillment of a contract handed over to yourself or to a third party in a common, machine-readable format. If you require the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
Information, correction, and deletion
Within the framework of the applicable legal provisions, you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of data processing and, if applicable, a right to correction or deletion of this data.
Right to restriction of processing
You have the right to demand the restriction of the processing of your personal data. You can contact us at any time for this purpose.
SSL or TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or requests that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
Objection to promotional emails
The use of contact data published as part of the legal notice obligation to send unsolicited advertising and information materials is hereby objected to. The operators of the pages expressly reserve the right to take legal steps in the event of unsolicited sending of advertising information, such as spam emails.
4. Data collection when visiting this shop
4.1 Cookies
We exclusively use technically necessary cookies in this online shop. These cookies are required for the shop to function — in particular for:
the management of your login session (if you have logged in via the Vinolin login),
the management of your shopping cart,
the secure handling of the order and payment process,
a technical identification of your session for the AI sommelier chat (conversation ID).
These cookies are set on the basis of § 25 (2) no. 2 TDDDG without consent, as they are absolutely necessary for the provision of the services expressly requested by you. The legal basis for the associated data processing is Art. 6 (1) (b) GDPR (contract fulfillment) or Art. 6 (1) (f) GDPR (legitimate interest in secure and functional operation).
We do not use cookies for tracking, analysis, or marketing. We therefore dispense with a cookie banner.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases or exclude them in general. The functionality of this shop is restricted if technically necessary cookies are deactivated.
4.2 Server log files
When calling up this online shop, information is automatically recorded in so-called server log files, which your browser automatically transmits, via the infrastructure of our platform provider Vinolin (cf. section 2). These are: browser type and browser version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, IP address.
A merger of this data with other data sources is not performed. The collection of this data takes place on the basis of Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free provision of this shop and the security of our systems. The logs are generally deleted automatically after 30 days.
5. End customer account and login (account.vinolin.com)
5.1 Central login service
For registration in this shop, we use the central login service of Vinolin UG (haftungsbeschränkt) under the domain account.vinolin.com. This service allows you to make purchases in all Vinolin shops with a single account, without having to create a separate account in each shop.
Responsible for the processing of your account data as part of this login service is Vinolin UG (haftungsbeschränkt), Bildungscampus 11, 74076 Heilbronn. The applicable privacy policy can be found at https://vinolin.com/datenschutz.
5.2 What data is processed?
During registration and login via the Vinolin account, the following data in particular is processed:
First name, last name (optional gender and profile picture)
Email address and email verification status
Phone number (optional)
Date of birth (within the scope of age specification)
Password hash, session token, OAuth tokens
IP address and user agent at the time of login
5.3 When is your data passed on to us?
Only once you make a purchase in our shop or register for our newsletter will the data necessary for these purposes be transmitted by Vinolin to us as the shop operator. From this point on, we are the responsible entity for the processing of data associated with the order or the newsletter (cf. sections 6 and 8).
6. Order processing in the shop
6.1 What data is processed during an order?
As part of an order, we process the data required for contract fulfillment. This is partially collected directly from you, and partially provided via the Vinolin account or the payment service provider:
Master and contact data (via Vinolin account):
First name and last name, email address, if applicable phone number
Date of birth (for age specification according to youth protection)
Address and payment data (via the payment service provider Stripe, cf. section 6.3):
Delivery and billing address
Payment data (e.g., credit card token; full card details are not stored by us)
Order data:
Order number, order items, quantities, prices
Order status, shipping status
Invoicing documents
6.2 Legal basis and storage duration
The processing of order data takes place on the basis of Art. 6 (1) (b) GDPR (contract fulfillment). Order data that is relevant for accounting (in particular invoices) is stored for ten (10) years in accordance with § 257 HGB / § 147 AO. The legal basis for this is Art. 6 (1) (c) GDPR (legal obligation).
6.3 Payment processing via Stripe
Payment processing in this shop takes place via the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Via Stripe, you can pay with credit card, Apple Pay, Google Pay, or Wero, among other options.
Stripe is an independent controller within the meaning of Art. 4 (7) GDPR as part of the payment processing. You enter your payment data (in particular card and bank account details, delivery and billing address) directly into Stripe. Stripe processes this data on its own responsibility for payment processing as well as for the fulfillment of legal obligations (especially in the field of money laundering prevention).
We only transmit your email address to Stripe to enable Stripe to identify your order. We receive back from Stripe status information about the payment as well as the delivery address required for shipping.
Further information can be found in Stripe's privacy policy at https://stripe.com/de/privacy.
6.4 Payment processing via PayPal
If you decide to pay with PayPal, payment processing takes place via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, Luxembourg.
PayPal is an independent controller as part of the payment processing. You enter your payment data directly into PayPal. PayPal processes this data on its own responsibility. Further information can be found in PayPal's privacy policy at https://www.paypal.com/de/legalhub/privacy-full.
6.5 Shipping of goods
We handle shipping ourselves via a shipping service provider commissioned by us (DPD, UPS). For this purpose, we transmit your delivery data and, if applicable, contact data (email address, phone number) to the shipping service provider. The legal basis is Art. 6 (1) (b) GDPR.
6.6 Sending order confirmations and status emails
As part of the order processing, you will receive automated emails (order confirmation, shipping confirmation, status information). The technical dispatch takes place via the infrastructure of our platform provider Vinolin and is handled via the sub-processor Amazon Web Services EMEA SARL (cf. section 2).
7. AI Sommelier
In this shop, an AI-supported sommelier is available to you, which can recommend suitable wines from our assortment based on your taste preferences.
7.1 Anonymous use
You can also use the AI sommelier without registering. Before the first use, you must agree to the processing of your inputs. In the case of anonymous use, the conversation history is stored; an IP address is not recorded, so that a recognition of your person across multiple sessions is not possible.
7.2 Use with registered account
If you are logged in via your Vinolin account, your name is also transmitted to enable a more personal consultation. In the future, a shop-spanning taste profile managed via the Vinolin account may also be included, provided you have consented to the creation and use of such a profile.
7.3 Responsible entity
The entity responsible for providing the AI sommelier within this shop is Ökoweingut Markus Busch as the shop operator. Vinolin processes the data generated in the sommelier dialogue as a data processor on behalf of the shop operator (cf. section 2). The processing of the shop-spanning taste profile is carried out by Vinolin on its own responsibility; details and the option for consent or revocation can be found in Vinolin's privacy policy.
7.4 AI processing via Google Vertex AI
To generate the AI responses, your inputs as well as, if applicable, your name are transmitted to Google Ireland Ltd. (Google Vertex AI). Processing takes place in a data center in Frankfurt am Main (Germany). According to Google, the transmitted data is exclusively processed to generate the respective response, is not stored permanently, and is not used for training purposes.
7.5 Legal basis and storage duration
Processing takes place on the basis of your consent according to Art. 6 (1) (a) GDPR, which you provide before the start of the chat. You can revoke your consent at any time with effect for the future.
8. Newsletter
8.1 Registration with double opt-in
On the website of this shop, you can register for our newsletter. Registration takes place using the double opt-in procedure: After entering your email address, you will receive a confirmation email with a confirmation link. Only after clicking the link will you be added to our distribution list.
8.2 What data is processed?
As part of the newsletter registration, we process:
Your email address
Confirmation status (Pending / Verified / Unsubscribed)
Confirmation and unsubscribe tokens
Timestamp of registration and confirmation
8.3 Dispatch and technical provision
We handle the technical dispatch of the newsletters via the infrastructure of our platform provider Vinolin. For this, Amazon Web Services EMEA SARL (cf. section 2) is used as a sub-processor. We remain the responsible entity in this regard; Vinolin and AWS are exclusively involved as data processors.
8.4 Legal basis and revocation
Processing takes place on the basis of your consent according to Art. 6 (1) (a) GDPR. You can revoke your consent at any time by clicking the unsubscribe link in each newsletter or by sending us a corresponding message to info@buschwein.de. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
After revocation, your data will be removed from the active newsletter distribution list. We may keep a record of your consent and revocation in order to fulfill our burden of proof (Art. 6 (1) (f) GDPR — legitimate interest in provability).
9. Further data processing outside the Vinolin platform
Accounting software
Weinbau-online GmbH & Co. KG
Große Langgasse 8, 55116 MainzWolfs, Hennen & Partner mbB
Tax advisors
Straße von Crépy 2
56856 Zell-Barl
10. Currency of this privacy policy
We reserve the right to adapt this privacy policy in the event of significant changes. The current version is available on our website.
Status: {{STAND_DATUM}}