Privacy Policy
1. General information
The protection of your personal data is important to us. This Privacy Policy explains which personal data are processed when you visit our website or contact us, the purposes for which such data are processed, and the rights available to you.
Personal data means any information relating to an identified or identifiable natural person.
Personal data are processed in particular in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and, where information is stored on or accessed from your terminal device, the German Telecommunications and Digital Services Data Protection Act (TDDDG).
2. Controller
The controller responsible for the processing of personal data in connection with this website is:
Gusto Palatino GmbH & Co. KG
Alte Bundesstraße 19
76846 Hauenstein
Germany
Telephone: +49 6392 92327–50
Email: info@gusto-palatino.de
Managing Directors:
Frank Wambsganss
Werner Schiessl
3. Data Protection Officer
You can contact our Data Protection Officer at:
DPC – Data Protection Consulting
Bahnhofstr. 75
76846 Hauenstein
Germany
Email:info@dpc-online.de
If you have any questions regarding data protection or wish to exercise your data protection rights, you may contact our Data Protection Officer directly.
4. Accessing our website and server log files
When you access our website, technically necessary information is processed by the web server.
This may include in particular:
-
the IP address of the accessing device,
-
the date and time of access,
-
the page or file requested,
-
the amount of data transferred,
-
information indicating whether the request was successful or unsuccessful.
These data are processed in order to provide the website technically, ensure its stability and security, and identify and investigate technical errors or abusive access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in ensuring the secure, stable and technically reliable operation of our website.
Server log data are retained only for as long as necessary for the purposes stated above. Data may be retained for a longer period where this is necessary to investigate specific security incidents or where required by law. The data are subsequently deleted or anonymised.
Where we use a hosting service provider, that provider processes the data on our behalf under a data processing agreement in accordance with Article 28 GDPR.
5. Cookies and similar technologies
Our website uses cookies and similar technologies.
Cookies are small pieces of information that may be stored on or read from your terminal device.
Technically necessary cookies
Certain cookies and comparable storage technologies are necessary to ensure the proper technical operation of the website or to provide functions expressly requested by you.
Where the storage of or access to information on your terminal device is strictly necessary, this is carried out in accordance with Section 25(2) TDDDG.
Where personal data are processed in this context, the processing is based, depending on the respective purpose, in particular on Article 6(1)(f) or Article 6(1)© GDPR.
Cookies and services requiring consent
Cookies and external services that are not strictly necessary for the operation of the website are used only after you have given your prior consent.
The legal basis for storing information on or accessing information from your terminal device is Section 25(1) TDDDG. Any subsequent processing of personal data is based on Article 6(1)(a) GDPR.
Your consent is voluntary and may be withdrawn at any time with effect for the future.
You can change your selection at any time via the Cookie Settings provided on our website.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
6. Consent management / Cookie settings
We use a consent management solution on our website that allows you to choose which optional cookies and external services you wish to accept.
For this purpose, technically necessary information may be stored on your terminal device in order to remember your selection during subsequent visits or page views.
This storage is used to manage and document your privacy and cookie preferences.
Where storage on your terminal device is strictly necessary, it is governed by Section 25(2) TDDDG.
Where personal data are processed for the purpose of documenting whether consent has been given or refused, this processing serves, in particular, to comply with our obligations under data protection law.
7. Google Maps
Our website may include maps provided by Google Maps.
Google Maps is a Google service. For users in the European Economic Area, Google services are generally provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In connection with certain processing activities, data may also be processed by Google LLC in the United States or by other companies within the Google group.
Google Maps is loaded on our website only after you have consented to the relevant processing through our cookie or privacy settings.
When Google Maps is loaded, the following data in particular may be transferred to or processed by Google:
-
your IP address,
-
technical information about your device and browser,
-
information about your visit to our website,
-
interactions with the embedded map,
-
location information where you have enabled location access on your device.
We have only limited influence over Google’s subsequent processing of such data.
Google Maps is integrated on the basis of your consent pursuant to Article 6(1)(a) GDPR. Where information is stored on or accessed from your terminal device, Section 25(1) TDDDG also applies.
You may withdraw your consent at any time with effect for the future via the Cookie Settings on our website.
Transfers of data to the United States
When Google services are used, personal data may be transferred to the United States.
Google LLC is certified under the EU‑U.S. Data Privacy Framework. Where data are transferred to an appropriately certified recipient, such transfer may take place on the basis of the European Commission’s adequacy decision pursuant to Article 45 GDPR.
Further information on Google’s processing of personal data can be found in Google’s Privacy Policy.
8. Contact by email or telephone
If you contact us by email or telephone, we process the personal data you provide in order to deal with your enquiry.
Such data may include in particular:
-
your name,
-
company,
-
position or role,
-
email address,
-
telephone number,
-
the content of your enquiry,
-
any additional information voluntarily provided by you.
Where your enquiry relates to the initiation or performance of a contract, the processing is based on Article 6(1)(b) GDPR.
For general business enquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest lies in dealing with and responding to business enquiries and maintaining our business relationships.
Where processing is necessary to comply with a legal obligation, Article 6(1)© GDPR may also apply.
The data are deleted when they are no longer required to deal with your enquiry or any subsequent business relationship and where no statutory retention obligations or legitimate interests require further retention.
9. Customers, prospective customers, suppliers and business partners
In connection with the initiation, performance and administration of our business relationships, we process personal data relating to customers, prospective customers, suppliers, service providers and other business partners as well as their contact persons.
This may include in particular:
-
names and business contact details,
-
company and position,
-
address,
-
telephone number and email address,
-
contract, quotation and order information,
-
delivery and service information,
-
invoicing and payment information,
-
correspondence and communication content.
Where processing is necessary for pre-contractual measures or the performance of a contract with a natural person, it is based on Article 6(1)(b) GDPR.
In the case of contact persons at companies and other legal entities, processing is based in particular on Article 6(1)(f) GDPR. Our legitimate interest lies in establishing, performing and maintaining our business relationships.
Where commercial, tax or other statutory retention obligations apply, processing is based on Article 6(1)© GDPR.
10. Recipients of personal data
Personal data are disclosed only where this is necessary for the respective purpose or otherwise permitted by law.
Recipients or categories of recipients may include in particular:
-
hosting and IT service providers,
-
communications and email service providers,
-
transport and logistics companies,
-
payment and financial service providers,
-
tax advisers, auditors and legal advisers,
-
public authorities and public bodies where disclosure is required by law,
-
other service providers used in the course of our business activities.
Where service providers process personal data solely on our behalf, they are engaged under a data processing agreement pursuant to Article 28 GDPR.
11. Transfers of personal data to third countries
Personal data are processed outside the European Union or the European Economic Area only where the requirements of Articles 44 et seq. GDPR are satisfied.
Such transfers may in particular be based on:
-
an adequacy decision by the European Commission,
-
appropriate safeguards such as the EU Standard Contractual Clauses,
-
or a statutory derogation.
Where services are provided by companies certified under the EU‑U.S. Data Privacy Framework, data may be transferred to the United States on the basis of the corresponding adequacy decision.
12. Retention period
We generally retain personal data only for as long as necessary for the respective processing purpose.
The data are subsequently deleted unless statutory retention obligations, legitimate interests or other legal grounds require further retention.
Business documents may in particular be subject to statutory retention requirements under commercial and tax law. The applicable retention period depends on the type and content of the relevant documents and the applicable statutory provisions.
Data processed solely on the basis of your consent will generally no longer be processed for the consent-dependent purpose after you withdraw your consent, unless another legal basis permits further processing.
13. Your rights
Subject to the applicable statutory requirements, you have in particular the following rights:
-
right of access to your personal data pursuant to Article 15 GDPR,
-
right to rectification of inaccurate or incomplete data pursuant to Article 16 GDPR,
-
right to erasure pursuant to Article 17 GDPR,
-
right to restriction of processing pursuant to Article 18 GDPR,
-
right to data portability pursuant to Article 20 GDPR,
-
right to object pursuant to Article 21 GDPR,
-
right to withdraw consent pursuant to Article 7(3) GDPR.
You may contact us or our Data Protection Officer at any time to exercise your rights.
14. Withdrawal of consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal.
Consent relating to cookies and external services can in particular be changed or withdrawn through the Cookie Settings on our website.
15. Right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right, pursuant to Article 21 GDPR, to object to such processing at any time on grounds relating to your particular situation.
We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing is necessary for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, you may object to such processing at any time.
16. Right to lodge a complaint with a supervisory authority
Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.
The supervisory authority responsible for our company is in particular:
The State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz
Germany
Telephone: +49 6131 8920–0
Email: poststelle@datenschutz.rlp.de
You may also contact another data protection supervisory authority competent for you.
17. Security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other risks.
Our website uses an encrypted connection for the transmission of data between your browser and our web server.
18. Automated decision-making
No decision based solely on automated processing, including profiling within the meaning of Article 22 GDPR, takes place in connection with the use of this website.
19. Updates to this Privacy Policy
We reserve the right to amend this Privacy Policy where our website, the services used or the applicable legal requirements change.
The current version published on this website applies.
Last updated: August 2026