1. Controller
[FULL NAME OF THE CONTROLLER AND LEGAL FORM, IF APPLICABLE]
Blücherstr. 23
[POSTCODE AND CITY]
Email: [PUBLIC PRIVACY CONTACT ADDRESS]
Jakob Feddersen is the named individual; his role and the legal identity of the business still need to be confirmed. [ADD THE DATA PROTECTION OFFICER’S CONTACT DETAILS IF ONE IS APPOINTED OR REQUIRED]
2. Accessing the website and hosting
Beim Aufruf werden die für die Auslieferung notwendigen Verbindungs- und Anfragedaten verarbeitet, insbesondere IP-Adresse und angeforderte Ressource. Für anima-perfumery.de sind Cloudflare Workers und eine D1-Datenbank eingerichtet. Der konkrete Vertragspartner für das Hosting und dessen datenschutzrechtliche Rolle sind noch zu bestätigen.
[VERIFY AND ADD THE HOSTING PROVIDER’S LEGAL ENTITY AND ADDRESS, RECIPIENTS AND SUBPROCESSORS, AND THE DATA PROCESSING AGREEMENT UNDER ARTICLE 28 GDPR]
The server configuration provides for technical logging; the application logs errors in basket requests. The data actually stored by the platform in access, error and security logs — such as time, status code, browser information and referring page — and its retention periods have not yet been fully verified.
[ADD THE ACTUAL LOG FIELDS, AUTHORISED ACCESS AND SPECIFIC DELETION PERIODS CONFIRMED BY THE HOST]
The intended legal basis for necessary delivery and security is Article 6(1)(f) GDPR: our interest in a functioning, secure website. The actual purposes and balancing of interests must be checked against the hosting configuration.
3. Basket and cookies
The application can associate a requested basket selection with a random identifier. When the basket is changed on the HTTPS website, the cookie __Host-anima_cart is set; in the local HTTP preview it is called anima_cart_preview. Simply visiting a page without an existing cookie does not create a new basket cookie in the application code.
The cookie cannot be read by JavaScript and remains valid for up to 30 days after the most recent basket change. The database contains the identifier, product, format, quantity and modification time. Names, email addresses and payment details are not requested. Purchasing is currently unavailable.
This association serves only the requested selection function. Section 25(2) no. 2 TDDDG may apply; for personal data, Article 6(1)(f) GDPR is the intended basis, reflecting the interest in providing this function. The necessity of 30-day storage must be reviewed before approval.
Cookies can be deleted in the browser settings; this removes the link to an existing selection. It does not automatically delete database entries. Removed basket items are deleted in the application; automatic scheduled deletion of orphaned entries has not yet been implemented.
[JUSTIFY THE NECESSARY RETENTION PERIOD AND DEFINE AND IMPLEMENT AUTOMATIC DELETION OF INACTIVE BASKETS]
4. Contact form
The form contains email address and message fields. Both are required for local form validation. Entries are checked only within the current browser form for completeness and email format. The application does not send them to a server, store them permanently or pass them to a service provider. No message is sent.
Before message forwarding is activated, recipients, secure transmission, the legal basis and deletion criteria must be specified. Article 6(1)(b) GDPR may apply to future enquiries relating to a contract, and Article 6(1)(f) GDPR may apply to other correspondence following review. This does not describe an active forwarding function.
[ADD THE CONTACT SERVICE PROVIDER, RECIPIENTS, AGREEMENTS AND RETENTION PERIOD BEFORE ACTIVATION]
5. Fonts, media, filters and analytics
The embedded Cormorant font files, product images and films are served through the website itself. Other fonts used are system fonts. The reviewed application code does not load Google Fonts or an external video player for these purposes.
The application code contains no analytics or advertising trackers and does not use Local Storage or Session Storage. Fragrance filters are stored as parameters in the page address. This selection may therefore appear in browser history and, when a page is requested, in server logs. It serves to restore and share a selection, not to analyse user behaviour.
No consent banner has been added. Separate cookies, access controls or logging by the hosting platform must be reviewed independently before publication. The available ChatGPT sign-in helper is not called by the pages; this does not rule out platform-level access controls.
[CONFIRM PLATFORM-LEVEL SERVICES AND COOKIES, PURPOSES, DURATIONS, LEGAL BASES AND ANY CONSENT REQUIREMENTS]
6. Recipients, international transfers and deletion
Technical hosting and database service providers may be recipients. Their precise identities and contractual roles must be added to section 2. The countries in which processing or administrative access takes place have not yet been confirmed. Processing exclusively within the EU is therefore not guaranteed.
[ADD THE COUNTRIES OF PROCESSING AND, FOR TRANSFERS TO THIRD COUNTRIES, THE LEGAL BASIS UNDER ARTICLES 44 ET SEQ. GDPR, SUCH AS AN ADEQUACY DECISION OR APPROPRIATE SAFEGUARDS, AND HOW TO OBTAIN THOSE SAFEGUARDS]
Data may be retained only for as long as required by its purpose or a legal obligation. The actual retention periods for platform logs and inactive baskets are still outstanding; the cookie duration does not replace a deletion policy. Any statutory retention obligations must be added only for data types actually concerned.
7. Your rights
Subject to the GDPR, you have rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). Please contact the controller named above to exercise them. Consent may be withdrawn with effect for the future; processing that was lawful before withdrawal remains unaffected.
Right to object: Where processing is based on Article 6(1)(e) or (f) GDPR, you may object on grounds relating to your particular situation (Article 21). For direct marketing, you may object at any time without giving reasons; such marketing is not implemented in the reviewed application code.
You may lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, place of work or the alleged infringement (Article 77). [ADD THE COMPETENT STATE DATA PROTECTION AUTHORITY AND ITS CONTACT DETAILS AFTER CONFIRMING THE OPERATOR’S REGISTERED LOCATION]
Automated decision-making with legal or similarly significant effects and profiling are not implemented in the reviewed application. No form data is required simply to read the website; technically necessary connection data is generated when pages are requested.
8. Version and changes
Draft dated 29 September 2026. A further review is required before publication, before contact form delivery is enabled and before changes to hosting, cookies or sales functions.