Privacy Policy
1. Controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Louis Reinecke
Grundweg 16
34479 Breuna
Germany
Email: redaktion@culttwenty.de
No data protection officer has been appointed, as the legal requirements for doing so under Art. 37 GDPR in conjunction with section 38 BDSG are not met.
2. Principles
Personal data is processed exclusively on the basis of the statutory provisions. Only as much data is collected as is necessary for the respective purpose, and it is stored only for as long as required for that purpose or by statutory retention obligations. Data is disclosed to third parties only in the cases described in this policy.
3. Visiting the website and server log files
This website is hosted by STRATO AG, Pascalstraße 10, 10587 Berlin, Germany. Each time a page is accessed, your browser automatically transmits information to the server, where it is temporarily stored in what are known as log files:
- IP address of the requesting device
- date and time of the request
- name and URL of the file retrieved
- website from which the request originated (referrer URL)
- browser used, its version and the operating system
- volume of data transferred and notification of successful retrieval
Purpose: ensuring a trouble-free connection, providing a convenient service,
evaluating system security and stability, and defending against attacks.
Legal basis: Art. 6 (1) (f) GDPR. The legitimate interest follows from the
purposes listed above.
Retention period: log files are deleted after seven days at the latest, unless
they are exceptionally required for longer to investigate a specific security incident.
A data processing agreement pursuant to Art. 28 GDPR is in place with STRATO AG.
4. Payment processing via Stripe
Purchases are processed by the payment service provider Stripe. The provider for customers in the European Economic Area is Stripe Payments Europe Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland.
When you click the purchase button you are redirected to a TLS-encrypted payment page operated by Stripe. Payment details are entered there and nowhere else. In this context Stripe processes in particular:
- name and email address
- billing address and country
- payment method and the associated payment data (e.g. card details, IBAN)
- purchase amount, currency and time of the transaction
- IP address and device information for fraud prevention
Complete payment data such as card numbers is never collected, processed or stored on this website. As the operator I receive from Stripe only the information required to perform the contract, issue the licence and produce the invoice — in particular name, email address, billing address and purchase amount.
Legal basis: Art. 6 (1) (b) GDPR for the performance of the purchase contract and Art. 6 (1) (f) GDPR for fraud prevention and securing payment transactions. Where personal data is transferred to Stripe group companies in the United States, this takes place on the basis of the European Commission's Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR together with supplementary safeguards.
Further information on data processing by Stripe: stripe.com/privacy.
5. Supplying the software and licence administration
After a successful payment, your email address and order reference are processed in order to provide the download link and licence key and to assign the licence. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). Licence data is stored for the duration of the licence.
6. Invoice and order data
Invoice and order data is subject to commercial and tax law retention obligations and is retained for a period of ten years (section 147 of the German Fiscal Code, section 257 of the German Commercial Code). The legal basis is Art. 6 (1) (c) GDPR. Deletion before those periods expire is excluded; processing of that data is, however, restricted to the purpose of retention.
7. Contacting me by email
If you contact me by email, the information you provide (name, email address, content of the message) is processed solely in order to handle your enquiry and any follow-up questions. The legal basis is Art. 6 (1) (b) GDPR where the enquiry relates to entering into or performing a contract, and otherwise Art. 6 (1) (f) GDPR based on the legitimate interest in responding to enquiries. The data is deleted once the enquiry has been dealt with conclusively and no statutory retention periods apply.
8. Cookies and analytics
This website sets no cookies of its own, uses no analytics or tracking services, no advertising pixels and no profiling. A consent solution pursuant to section 25 TDDDG is therefore not required.
During checkout, Stripe sets cookies on its own pages that are technically necessary to process the payment and detect fraud. The operator of this website has no influence over these.
9. Fonts
The typeface used on this website is served locally from this server. No connection is made to third-party servers, and in particular no IP address is transmitted to Google or any other provider.
10. Recipients of personal data
Personal data is disclosed only to the following categories of recipient:
- the hosting provider (STRATO AG) as a processor
- the payment service provider (Stripe) for processing the payment
- tax advisers and tax authorities within the scope of statutory obligations
Data is never sold or otherwise passed on for advertising purposes.
11. Your rights
Under the GDPR you have the following rights:
- Access to the personal data being processed (Art. 15 GDPR)
- Rectification of inaccurate data and completion of incomplete data (Art. 16 GDPR)
- Erasure of stored data, provided no retention obligation applies (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)
An informal message to redaktion@culttwenty.de is enough to exercise these rights.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority here is, among others: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.
12. Obligation to provide data
You are under no statutory or contractual obligation to provide personal data. Without the information required during checkout, however, no purchase contract can be concluded and the software cannot be supplied.
13. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. The market evaluations produced by the software run locally on the user's device and relate to market data, not to individuals.
14. Data security
This website uses TLS encryption (recognisable by “https://” in your browser's address bar) to protect the transmission of content against interception by third parties. Appropriate technical and organisational measures pursuant to Art. 32 GDPR are also in place.
15. Changes to this policy
This privacy policy is updated whenever the legal situation or the actual processing operations change. The version available on this page applies in each case.
Last updated: September 2026