Privacy Policy
Last updated: July 2026
The protection of your personal data is important to us. This privacy policy explains which personal data we process when you visit this website, for which purposes and on which legal basis. Personal data is any information that can be used to identify you.
This website is primarily an information service for our brick-and-mortar store. There is no online shop, no payment processing, no customer account and no newsletter. You can, however, reach us via a contact form (see section 5).
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Controller: Das Ranzen-Kontor, owner Martin Herrmann
Address: Georgenstraße 24, 10117 Berlin, Germany
Phone: 030 / 23 00 20 23
E-mail: kontakt@ranzenkontor.de
We are not legally required to appoint a data protection officer and have not appointed one.
2. Basis of processing
Legal bases
We only process personal data on a valid legal basis. Depending on the processing, we rely on:
- Art. 6 (1) (a) GDPR – your consent (e.g. for statistics, maps and marketing);
- Art. 6 (1) (b) GDPR – to initiate or perform a contract (e.g. booking an appointment);
- Art. 6 (1) (f) GDPR – our legitimate interest in a secure, stable and appealing web presence;
- § 25 TDDDG – for storing or accessing information on your device (consent, unless strictly necessary).
Recipients and processors
To provide this website we use carefully selected service providers that process data on our behalf (processing on behalf under Art. 28 GDPR). We have corresponding agreements in place with these providers. No data is transferred to third parties for their own purposes unless expressly described below.
Storage period
Unless a more specific storage period is stated in this policy, your personal data remains with us until the purpose of processing no longer applies. Where processing is based on your consent, we process the data until you withdraw it. Statutory retention obligations remain unaffected.
Data security (SSL/TLS encryption)
For security reasons, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the “https://” in your browser's address bar. This means that the data you transmit to us cannot be read by third parties.
3. Your rights as a data subject
Under the GDPR you have, in particular, the following rights:
- access to the data we store about you (Art. 15 GDPR);
- rectification of inaccurate data (Art. 16 GDPR);
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- objection to processing based on Art. 6 (1) (f) GDPR, and to direct marketing at any time (Art. 21 GDPR);
- withdrawal of a given consent with effect for the future (Art. 7 (3) GDPR).
Right to object (Art. 21 GDPR) and automated decisions
Where we process data on the basis of our legitimate interest (Art. 6 (1) (f) GDPR) — for example for hosting, server log files, fonts and embedding our Instagram content — you have the right to object at any time, on grounds relating to your particular situation (Art. 21 GDPR).
No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI), Alt-Moabit 59–61, 10555 Berlin, Germany.
More information: www.datenschutz-berlin.de.
Exercising your rights
To exercise your rights, an informal message to the contact details given in section “1. Controller” is sufficient.
4. Hosting and server log files
This website is operated by an external service provider (host):
Host: Render Services, Inc., 525 Brannan Street, Suite 300, San Francisco, CA 94107, USA
Server location: Frankfurt am Main region (EU)
The host processes, on our behalf, the data generated when operating the website (in particular access and log data). We have concluded a data processing agreement (DPA) under Art. 28 GDPR with the host. Data is stored in a data centre in the EU (Frankfurt); where access from the USA is possible, it takes place on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR). The legal basis is our legitimate interest in a secure and efficient provision of the website (Art. 6 (1) (f) GDPR). Host's privacy policy: render.com/privacy.
Server log files
When you access the website, the host automatically collects and stores information in so-called server log files, which your browser transmits automatically. These are:
- browser type and version,
- operating system used,
- referrer URL,
- host name of the requesting computer,
- time of the server request,
- IP address.
This data is not merged with other data sources. It is collected to ensure smooth and secure operation of the website (Art. 6 (1) (f) GDPR) and is deleted after a short period.
5. Domain, DNS and contact by e-mail
The domain ranzenkontor.de, the associated DNS management and our e-mail mailbox are provided by:
Provider: domainFactory GmbH (Germany)
domainFactory is based in Germany (EU); no transfer of data to a third country takes place via this provider.
Contacting us by phone or e-mail
If you contact us by e-mail or phone, we process the information you provide (e.g. name, contact details, content of your enquiry) solely to handle your request. The legal basis is Art. 6 (1) (b) GDPR where your enquiry relates to the initiation or performance of a contract, otherwise our legitimate interest in answering your enquiry (Art. 6 (1) (f) GDPR) or your consent (Art. 6 (1) (a) GDPR). E-mail communication runs via the servers of our e-mail provider domainFactory. We delete your enquiries as soon as their storage is no longer necessary; statutory retention periods remain unaffected.
Contact form
On our contact page we also offer a contact form. Required fields are name, e-mail address and message; without this information we cannot process your enquiry.
The purpose of the processing is solely to respond to your enquiry. The legal basis is Art. 6 (1) (b) GDPR insofar as your enquiry relates to the initiation or performance of a contract (e.g. a consultation), and otherwise our legitimate interest in handling incoming enquiries (Art. 6 (1) (f) GDPR).
When you submit the form, we additionally process technical information required to prevent abuse and for traceability: the date and time of the enquiry, the referring page URL, your browser's user agent and your IP address. A hidden field invisible to humans (honeypot) additionally helps detect automated spam submissions; it is not used to evaluate genuine enquiries.
Your information is transmitted by e-mail to our mailbox kontakt@ranzenkontor.de. Recipients are our e-mail provider domainFactory (processor for e-mail delivery under Art. 28 GDPR) and our host Render, on whose servers the form is technically processed (see section “4. Hosting and server log files”). No further disclosure to third parties takes place.
We store the data submitted via the form only for as long as necessary to process your enquiry, and delete it afterwards; statutory retention obligations remain unaffected.
6. Consent management and cookies
This website only uses non-essential cookies or comparable technologies if you have consented beforehand.
Our consent banner
On your first visit we show you a consent banner. Your selection (necessary / statistics / marketing) is stored exclusively locally in your browser (in so-called local storage under the key “rk_consent_v1”). This is not a cookie; no data is transmitted to us or to third parties. Storing this selection is strictly necessary in order to respect your decision (§ 25 (2) no. 2 TDDDG, Art. 6 (1) (f) GDPR).
You can change or withdraw your selection at any time via the “Cookie settings” link in the footer, with effect for the future.
Google Consent Mode v2
Before Google services are loaded, consent is set to “denied” by default (Google Consent Mode v2). External content such as Google Maps is only loaded after your active consent. Where a Google Tag Manager container is used, its container script may load, but the tags it delivers may only set cookies or process personal data after your consent.
Categories
- Necessary: for operating the website and storing your consent selection. No tracking cookies are set. Always active.
- Statistics: reach measurement with Google Analytics 4 (see section 11).
- Marketing & external media: external content (Google Maps) and advertising/conversion tags (Google Ads).
7. Fonts (self-hosted)
For a consistent appearance we use the “Prometo” font. It is stored locally on our server and delivered from there. There is no connection to third-party servers — in particular not to Google Fonts — and no personal data is transmitted to third parties. The legal basis is our legitimate interest in a uniform, secure presentation of our website (Art. 6 (1) (f) GDPR).
8. Appointment booking – Calendly
To arrange consultation appointments, we offer the option of booking an appointment via the Calendly service. The provider is:
Provider: Calendly LLC, 271 17th St NW, Suite 1000, Atlanta, GA 30363, USA
The Calendly booking window is only loaded once you actively click a booking button. No connection to Calendly is established beforehand. When you book an appointment, Calendly processes the data you provide (e.g. name, e-mail address, preferred date) and technical connection data in order to arrange the appointment.
The legal basis for loading the service is your consent through the active click (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG); for handling your appointment request, our legitimate interest in providing an appointment-booking option (Art. 6 (1) (f) GDPR). Calendly is certified under the EU-US Data Privacy Framework; additionally, Standard Contractual Clauses are in place. Privacy policy: calendly.com/privacy.
9. Map service – Google Maps
To display our location, we embed a map from the Google Maps service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA).
The map is only loaded after you have consented to the “Marketing & external media” category — via the banner or via the “Load map” button. Only then does your browser establish a connection to Google, transmitting your IP address, among other data, to Google. The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). Privacy policy: policies.google.com/privacy.
10. Instagram content
On the home page we show recent posts from our public Instagram profile. We retrieve them server-side via the official interface (Instagram Graph API) using an access token of our own account. No data of our website visitors is transmitted to Instagram or Meta in the process.
We deliver the displayed images via our own server (proxy). Merely viewing the home page therefore does not establish any connection from your browser to Meta, and in particular no IP address is transmitted to Meta.
Only when you click on a post or the “Follow on Instagram” link are you redirected to Instagram; from that point on, Meta's privacy policy applies. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The legal basis for embedding our own social media content is our legitimate interest in an appealing presentation of our offering (Art. 6 (1) (f) GDPR). Meta's privacy policy: privacycenter.instagram.com/policy.
11. Web analytics – Google Analytics 4
Insofar as you have consented to the “Statistics” category, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses cookies or comparable technologies that enable an analysis of the use of the website (e.g. pages visited, time spent, approximate region, device used). Google Analytics 4 only processes the IP address in truncated form and does not store it permanently. Collection takes place exclusively after your consent.
The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG), which you can withdraw at any time via the “Cookie settings”. You can also prevent collection by Google Analytics using the browser add-on: tools.google.com/dlpage/gaoptout. Google's privacy policy: policies.google.com/privacy.
12. Tag management – Google Tag Manager
To manage and control the delivery of the tags mentioned, we use Google Tag Manager provided by Google Ireland Limited. The Tag Manager itself does not create user profiles, does not set analytics cookies and does not store any personal data; it serves solely to deliver other tags on a consent basis (see Google Consent Mode v2, section 6). When the container is loaded, a connection to Google is established.
13. Online advertising – Google Ads & conversion tracking
Insofar as you have consented to the “Marketing” category, we use Google Ads including conversion tracking, a service provided by Google Ireland Limited. This allows us to measure the success of our advertisements (e.g. whether certain actions take place after clicking an ad) and, where applicable, to use remarketing. Cookies may be set for this purpose.
The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). You can deactivate personalised advertising in the settings of your Google account: adssettings.google.com. Google's privacy policy: policies.google.com/privacy.
14. Data transfers to third countries
Some of the providers used have parent companies outside the EU. A transfer of personal data to a third country only takes place — if at all — after your consent or on the basis of appropriate safeguards:
- Google (Google LLC, USA) and Calendly (Calendly LLC, USA) are certified under the EU-US Data Privacy Framework (DPF). For US companies certified under the DPF, the EU Commission established an adequate level of data protection by decision of 10 July 2023 (Art. 45 GDPR); the DPF is therefore the operative transfer mechanism. For any processing outside the certification, the EU Standard Contractual Clauses serve as an additional safeguard.
- Our host (Render, USA) stores the data in the EU (Frankfurt); where access from the USA is possible, it takes place on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR). You can request a copy of these safeguards via the contact details in section “1. Controller”.
15. Currency and changes to this policy
The current version of this privacy policy published here applies. We will adapt it as soon as changes to our processing activities or the legal situation make this necessary.