Privacy Policy

 

1. General information

The pro­tec­tion of your per­so­nal data is important to us. This Pri­va­cy Poli­cy explains which per­so­nal data are pro­ces­sed when you visit our web­site or cont­act us, the pur­po­ses for which such data are pro­ces­sed, and the rights available to you.

Per­so­nal data means any infor­ma­ti­on rela­ting to an iden­ti­fied or iden­ti­fia­ble natu­ral per­son.

Per­so­nal data are pro­ces­sed in par­ti­cu­lar in accordance with the Gene­ral Data Pro­tec­tion Regu­la­ti­on (GDPR), the Ger­man Fede­ral Data Pro­tec­tion Act (BDSG) and, whe­re infor­ma­ti­on is stored on or acces­sed from your ter­mi­nal device, the Ger­man Tele­com­mu­ni­ca­ti­ons and Digi­tal Ser­vices Data Pro­tec­tion Act (TDDDG).


2. Controller

The con­trol­ler respon­si­ble for the pro­ces­sing of per­so­nal data in con­nec­tion with this web­site is:

Gus­to Pala­ti­no GmbH & Co. KG
Alte Bun­des­stra­ße 19
76846 Hau­en­stein
Ger­ma­ny

Tele­pho­ne: +49 6392 92327–50
Email: info@gusto-palatino.de

Mana­ging Direc­tors:
Frank Wamb­s­ganss
Wer­ner Schiessl


3. Data Protection Officer

You can cont­act our Data Pro­tec­tion Offi­cer at:

DPC – Data Pro­tec­tion Con­sul­ting
Bahn­hofstr. 75
76846 Hau­en­stein
Ger­ma­ny

Email:info@dpc-online.de

If you have any ques­ti­ons regar­ding data pro­tec­tion or wish to exer­cise your data pro­tec­tion rights, you may cont­act our Data Pro­tec­tion Offi­cer direct­ly.


4. Accessing our website and server log files

When you access our web­site, tech­ni­cal­ly neces­sa­ry infor­ma­ti­on is pro­ces­sed by the web ser­ver.

This may include in par­ti­cu­lar:

  • the IP address of the acces­sing device,

  • the date and time of access,

  • the page or file reques­ted,

  • the amount of data trans­fer­red,

  • infor­ma­ti­on indi­ca­ting whe­ther the request was suc­cessful or unsuc­cessful.

The­se data are pro­ces­sed in order to pro­vi­de the web­site tech­ni­cal­ly, ensu­re its sta­bi­li­ty and secu­ri­ty, and iden­ti­fy and inves­ti­ga­te tech­ni­cal errors or abu­si­ve access.

The legal basis is Artic­le 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in ensu­ring the secu­re, sta­ble and tech­ni­cal­ly relia­ble ope­ra­ti­on of our web­site.

Ser­ver log data are retai­ned only for as long as neces­sa­ry for the pur­po­ses sta­ted abo­ve. Data may be retai­ned for a lon­ger peri­od whe­re this is neces­sa­ry to inves­ti­ga­te spe­ci­fic secu­ri­ty inci­dents or whe­re requi­red by law. The data are sub­se­quent­ly dele­ted or anony­mi­sed.

Whe­re we use a hos­ting ser­vice pro­vi­der, that pro­vi­der pro­ces­ses the data on our behalf under a data pro­ces­sing agree­ment in accordance with Artic­le 28 GDPR.


5. Cookies and similar technologies

Our web­site uses coo­kies and simi­lar tech­no­lo­gies.

Coo­kies are small pie­ces of infor­ma­ti­on that may be stored on or read from your ter­mi­nal device.

Technically necessary cookies

Cer­tain coo­kies and com­pa­ra­ble sto­rage tech­no­lo­gies are neces­sa­ry to ensu­re the pro­per tech­ni­cal ope­ra­ti­on of the web­site or to pro­vi­de func­tions express­ly reques­ted by you.

Whe­re the sto­rage of or access to infor­ma­ti­on on your ter­mi­nal device is strict­ly neces­sa­ry, this is car­ri­ed out in accordance with Sec­tion 25(2) TDDDG.

Whe­re per­so­nal data are pro­ces­sed in this con­text, the pro­ces­sing is based, depen­ding on the respec­ti­ve pur­po­se, in par­ti­cu­lar on Artic­le 6(1)(f) or Artic­le 6(1)© GDPR.

Cookies and services requiring consent

Coo­kies and exter­nal ser­vices that are not strict­ly neces­sa­ry for the ope­ra­ti­on of the web­site are used only after you have given your pri­or con­sent.

The legal basis for sto­ring infor­ma­ti­on on or acces­sing infor­ma­ti­on from your ter­mi­nal device is Sec­tion 25(1) TDDDG. Any sub­se­quent pro­ces­sing of per­so­nal data is based on Artic­le 6(1)(a) GDPR.

Your con­sent is vol­un­t­a­ry and may be with­drawn at any time with effect for the future.

You can chan­ge your sel­ec­tion at any time via the Coo­kie Set­tings pro­vi­ded on our web­site.

With­dra­wal of con­sent does not affect the lawful­ness of pro­ces­sing car­ri­ed out on the basis of con­sent befo­re its with­dra­wal.


6. Consent management / Cookie settings

We use a con­sent manage­ment solu­ti­on on our web­site that allows you to choo­se which optio­nal coo­kies and exter­nal ser­vices you wish to accept.

For this pur­po­se, tech­ni­cal­ly neces­sa­ry infor­ma­ti­on may be stored on your ter­mi­nal device in order to remem­ber your sel­ec­tion during sub­se­quent visits or page views.

This sto­rage is used to mana­ge and docu­ment your pri­va­cy and coo­kie pre­fe­ren­ces.

Whe­re sto­rage on your ter­mi­nal device is strict­ly neces­sa­ry, it is gover­ned by Sec­tion 25(2) TDDDG.

Whe­re per­so­nal data are pro­ces­sed for the pur­po­se of docu­men­ting whe­ther con­sent has been given or refu­sed, this pro­ces­sing ser­ves, in par­ti­cu­lar, to com­ply with our obli­ga­ti­ons under data pro­tec­tion law.


7. Google Maps

Our web­site may include maps pro­vi­ded by Goog­le Maps.

Goog­le Maps is a Goog­le ser­vice. For users in the Euro­pean Eco­no­mic Area, Goog­le ser­vices are gene­ral­ly pro­vi­ded by Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land. In con­nec­tion with cer­tain pro­ces­sing acti­vi­ties, data may also be pro­ces­sed by Goog­le LLC in the United Sta­tes or by other com­pa­nies within the Goog­le group.

Goog­le Maps is loa­ded on our web­site only after you have con­sen­ted to the rele­vant pro­ces­sing through our coo­kie or pri­va­cy set­tings.

When Goog­le Maps is loa­ded, the fol­lo­wing data in par­ti­cu­lar may be trans­fer­red to or pro­ces­sed by Goog­le:

  • your IP address,

  • tech­ni­cal infor­ma­ti­on about your device and brow­ser,

  • infor­ma­ti­on about your visit to our web­site,

  • inter­ac­tions with the embedded map,

  • loca­ti­on infor­ma­ti­on whe­re you have enab­led loca­ti­on access on your device.

We have only limi­t­ed influence over Goo­g­le’s sub­se­quent pro­ces­sing of such data.

Goog­le Maps is inte­gra­ted on the basis of your con­sent pur­su­ant to Artic­le 6(1)(a) GDPR. Whe­re infor­ma­ti­on is stored on or acces­sed from your ter­mi­nal device, Sec­tion 25(1) TDDDG also appli­es.

You may with­draw your con­sent at any time with effect for the future via the Coo­kie Set­tings on our web­site.

Transfers of data to the United States

When Goog­le ser­vices are used, per­so­nal data may be trans­fer­red to the United Sta­tes.

Goog­le LLC is cer­ti­fied under the EU‑U.S. Data Pri­va­cy Frame­work. Whe­re data are trans­fer­red to an appro­pria­te­ly cer­ti­fied reci­pi­ent, such trans­fer may take place on the basis of the Euro­pean Com­mis­si­on’s ade­quacy decis­i­on pur­su­ant to Artic­le 45 GDPR.

Fur­ther infor­ma­ti­on on Goo­g­le’s pro­ces­sing of per­so­nal data can be found in Goo­g­le’s Pri­va­cy Poli­cy.


8. Contact by email or telephone

If you cont­act us by email or tele­pho­ne, we pro­cess the per­so­nal data you pro­vi­de in order to deal with your enquiry.

Such data may include in par­ti­cu­lar:

  • your name,

  • com­pa­ny,

  • posi­ti­on or role,

  • email address,

  • tele­pho­ne num­ber,

  • the con­tent of your enquiry,

  • any addi­tio­nal infor­ma­ti­on vol­un­t­a­ri­ly pro­vi­ded by you.

Whe­re your enquiry rela­tes to the initia­ti­on or per­for­mance of a con­tract, the pro­ces­sing is based on Artic­le 6(1)(b) GDPR.

For gene­ral busi­ness enqui­ries, pro­ces­sing is based on Artic­le 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in deal­ing with and respon­ding to busi­ness enqui­ries and main­tai­ning our busi­ness rela­ti­onships.

Whe­re pro­ces­sing is neces­sa­ry to com­ply with a legal obli­ga­ti­on, Artic­le 6(1)© GDPR may also app­ly.

The data are dele­ted when they are no lon­ger requi­red to deal with your enquiry or any sub­se­quent busi­ness rela­ti­onship and whe­re no sta­tu­to­ry reten­ti­on obli­ga­ti­ons or legi­ti­ma­te inte­rests requi­re fur­ther reten­ti­on.


9. Customers, prospective customers, suppliers and business partners

In con­nec­tion with the initia­ti­on, per­for­mance and admi­nis­tra­ti­on of our busi­ness rela­ti­onships, we pro­cess per­so­nal data rela­ting to cus­to­mers, pro­s­pec­ti­ve cus­to­mers, sup­pli­ers, ser­vice pro­vi­ders and other busi­ness part­ners as well as their cont­act per­sons.

This may include in par­ti­cu­lar:

  • names and busi­ness cont­act details,

  • com­pa­ny and posi­ti­on,

  • address,

  • tele­pho­ne num­ber and email address,

  • con­tract, quo­ta­ti­on and order infor­ma­ti­on,

  • deli­very and ser­vice infor­ma­ti­on,

  • invoi­cing and pay­ment infor­ma­ti­on,

  • cor­re­spon­dence and com­mu­ni­ca­ti­on con­tent.

Whe­re pro­ces­sing is neces­sa­ry for pre-con­trac­tu­al mea­su­res or the per­for­mance of a con­tract with a natu­ral per­son, it is based on Artic­le 6(1)(b) GDPR.

In the case of cont­act per­sons at com­pa­nies and other legal enti­ties, pro­ces­sing is based in par­ti­cu­lar on Artic­le 6(1)(f) GDPR. Our legi­ti­ma­te inte­rest lies in estab­li­shing, per­forming and main­tai­ning our busi­ness rela­ti­onships.

Whe­re com­mer­cial, tax or other sta­tu­to­ry reten­ti­on obli­ga­ti­ons app­ly, pro­ces­sing is based on Artic­le 6(1)© GDPR.


10. Recipients of personal data

Per­so­nal data are dis­c­lo­sed only whe­re this is neces­sa­ry for the respec­ti­ve pur­po­se or other­wi­se per­mit­ted by law.

Reci­pi­ents or cate­go­ries of reci­pi­ents may include in par­ti­cu­lar:

  • hos­ting and IT ser­vice pro­vi­ders,

  • com­mu­ni­ca­ti­ons and email ser­vice pro­vi­ders,

  • trans­port and logi­stics com­pa­nies,

  • pay­ment and finan­cial ser­vice pro­vi­ders,

  • tax advi­sers, audi­tors and legal advi­sers,

  • public aut­ho­ri­ties and public bodies whe­re dis­clo­sure is requi­red by law,

  • other ser­vice pro­vi­ders used in the cour­se of our busi­ness acti­vi­ties.

Whe­re ser­vice pro­vi­ders pro­cess per­so­nal data sole­ly on our behalf, they are enga­ged under a data pro­ces­sing agree­ment pur­su­ant to Artic­le 28 GDPR.


11. Transfers of personal data to third countries

Per­so­nal data are pro­ces­sed out­side the Euro­pean Uni­on or the Euro­pean Eco­no­mic Area only whe­re the requi­re­ments of Artic­les 44 et seq. GDPR are satis­fied.

Such trans­fers may in par­ti­cu­lar be based on:

  • an ade­quacy decis­i­on by the Euro­pean Com­mis­si­on,

  • appro­pria­te safe­guards such as the EU Stan­dard Con­trac­tu­al Clau­ses,

  • or a sta­tu­to­ry dero­ga­ti­on.

Whe­re ser­vices are pro­vi­ded by com­pa­nies cer­ti­fied under the EU‑U.S. Data Pri­va­cy Frame­work, data may be trans­fer­red to the United Sta­tes on the basis of the cor­re­spon­ding ade­quacy decis­i­on.


12. Retention period

We gene­ral­ly retain per­so­nal data only for as long as neces­sa­ry for the respec­ti­ve pro­ces­sing pur­po­se.

The data are sub­se­quent­ly dele­ted unless sta­tu­to­ry reten­ti­on obli­ga­ti­ons, legi­ti­ma­te inte­rests or other legal grounds requi­re fur­ther reten­ti­on.

Busi­ness docu­ments may in par­ti­cu­lar be sub­ject to sta­tu­to­ry reten­ti­on requi­re­ments under com­mer­cial and tax law. The appli­ca­ble reten­ti­on peri­od depends on the type and con­tent of the rele­vant docu­ments and the appli­ca­ble sta­tu­to­ry pro­vi­si­ons.

Data pro­ces­sed sole­ly on the basis of your con­sent will gene­ral­ly no lon­ger be pro­ces­sed for the con­sent-depen­dent pur­po­se after you with­draw your con­sent, unless ano­ther legal basis per­mits fur­ther pro­ces­sing.


13. Your rights

Sub­ject to the appli­ca­ble sta­tu­to­ry requi­re­ments, you have in par­ti­cu­lar the fol­lo­wing rights:

  • right of access to your per­so­nal data pur­su­ant to Artic­le 15 GDPR,

  • right to rec­ti­fi­ca­ti­on of inac­cu­ra­te or incom­ple­te data pur­su­ant to Artic­le 16 GDPR,

  • right to era­su­re pur­su­ant to Artic­le 17 GDPR,

  • right to rest­ric­tion of pro­ces­sing pur­su­ant to Artic­le 18 GDPR,

  • right to data por­ta­bi­li­ty pur­su­ant to Artic­le 20 GDPR,

  • right to object pur­su­ant to Artic­le 21 GDPR,

  • right to with­draw con­sent pur­su­ant to Artic­le 7(3) GDPR.

You may cont­act us or our Data Pro­tec­tion Offi­cer at any time to exer­cise your rights.


14. Withdrawal of consent

Whe­re pro­ces­sing is based on your con­sent, you may with­draw that con­sent at any time with effect for the future.

With­dra­wal does not affect the lawful­ness of pro­ces­sing car­ri­ed out on the basis of your con­sent befo­re its with­dra­wal.

Con­sent rela­ting to coo­kies and exter­nal ser­vices can in par­ti­cu­lar be chan­ged or with­drawn through the Coo­kie Set­tings on our web­site.


15. Right to object

Whe­re we pro­cess per­so­nal data on the basis of Artic­le 6(1)(f) GDPR, you have the right, pur­su­ant to Artic­le 21 GDPR, to object to such pro­ces­sing at any time on grounds rela­ting to your par­ti­cu­lar situa­ti­on.

We will then no lon­ger pro­cess the per­so­nal data con­cer­ned unless we can demons­tra­te com­pel­ling legi­ti­ma­te grounds for the pro­ces­sing which over­ri­de your inte­rests, rights and free­doms, or whe­re the pro­ces­sing is neces­sa­ry for the estab­lish­ment, exer­cise or defence of legal claims.

Whe­re per­so­nal data are pro­ces­sed for direct mar­ke­ting pur­po­ses, you may object to such pro­ces­sing at any time.


16. Right to lodge a complaint with a supervisory authority

Pur­su­ant to Artic­le 77 GDPR, you have the right to lodge a com­plaint with a data pro­tec­tion super­vi­so­ry aut­ho­ri­ty if you belie­ve that the pro­ces­sing of your per­so­nal data inf­rin­ges appli­ca­ble data pro­tec­tion law.

The super­vi­so­ry aut­ho­ri­ty respon­si­ble for our com­pa­ny is in par­ti­cu­lar:

The Sta­te Com­mis­sio­ner for Data Pro­tec­tion and Free­dom of Infor­ma­ti­on of Rhi­ne­land-Pala­ti­na­te
Hin­te­re Blei­che 34
55116 Mainz
Ger­ma­ny

Tele­pho­ne: +49 6131 8920–0
Email: poststelle@datenschutz.rlp.de

You may also cont­act ano­ther data pro­tec­tion super­vi­so­ry aut­ho­ri­ty com­pe­tent for you.


17. Security

We use appro­pria­te tech­ni­cal and orga­ni­sa­tio­nal mea­su­res to pro­tect per­so­nal data against loss, mani­pu­la­ti­on, unaut­ho­ri­sed access and other risks.

Our web­site uses an encrypt­ed con­nec­tion for the trans­mis­si­on of data bet­ween your brow­ser and our web ser­ver.


18. Automated decision-making

No decis­i­on based sole­ly on auto­ma­ted pro­ces­sing, inclu­ding pro­fil­ing within the mea­ning of Artic­le 22 GDPR, takes place in con­nec­tion with the use of this web­site.


19. Updates to this Privacy Policy

We reser­ve the right to amend this Pri­va­cy Poli­cy whe­re our web­site, the ser­vices used or the appli­ca­ble legal requi­re­ments chan­ge.

The cur­rent ver­si­on published on this web­site appli­es.

Last updated: August 2026