Privacy Policy
Version: April 28, 2026
1. Controller
The controller for the processing of personal data on this website and in connection with the services offered is:
- Thomas Häring, Bonsai Garten München
- Schwarzstr. 12, 85604 Zorneding, Germany
- Email: bonsaigartenmunchen@gmail.com
- Phone: 015117621306
Privacy requests may be sent using the contact details above.
2. Scope of this notice
This privacy notice applies to the website www.bonsaigarten-munchen.de and to the functions offered through it, in particular contact requests, newsletter signups, user accounts, event and academy bookings, voucher requests, audiobook purchases, invoices and digital signatures.
3. What data we process
Depending on how you use the website, we may process in particular the following data:
- master data such as name, username, date of birth and email address
- account data such as encrypted password, session tokens and activation or validation tokens
- contact and communication data from contact forms, newsletter signups and emails
- booking and contract data for courses, masterclass dates, academy appointments, vouchers, audiobooks and invoices
- payment-related reference data where needed to process a payment or assign a purchase
- technical usage data such as IP address, access time, visited pages, device and browser data as well as cookie and consent information
- interaction data such as event-interest clicks captured on the website or through newsletter links
- digital signature data when an invoice is signed online
4. Purposes and legal bases
We process personal data only where a legal basis under Art. 6(1) GDPR applies. This includes in particular:
- Art. 6(1)(b) GDPR for pre-contractual measures and contract performance, for example for user accounts, bookings, voucher requests, audiobook purchases, invoices and support requests
- Art. 6(1)(c) GDPR for compliance with legal obligations such as commercial and tax retention duties
- Art. 6(1)(a) GDPR for consent-based processing, in particular newsletters and where required non-essential cookies or external analytics and marketing services
- Art. 6(1)(f) GDPR for legitimate interests such as IT security, abuse prevention, error analysis, internal administration and documenting user interactions with event offers
5. Individual processing activities
5.1 Contact requests
When you contact us, we process the data you provide to handle your request. The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR for general enquiries.
5.2 User accounts
During registration we process the account data you enter in order to create, manage and secure your account. Your password is not stored in plain text. The legal basis is Art. 6(1)(b) GDPR.
5.3 Newsletter
For newsletter subscriptions we process your email address and, where available, related profile data in order to send information about events, news and offers. The legal basis is your consent under Art. 6(1)(a) GDPR. You can unsubscribe at any time with effect for the future.
5.4 Courses, masterclass, events and academy
For course or academy bookings and for event interactions we process the data needed for reservation, organisation, communication and abuse prevention. This includes booking data, participant assignments, communication data and technical evidence of interaction with event links. The legal basis is usually Art. 6(1)(b) GDPR and, for security and documentation purposes, additionally Art. 6(1)(f) GDPR.
5.5 Vouchers
For voucher requests we process name, email address, value, message and status information in order to handle the request, assign payments and provide the voucher. The legal basis is Art. 6(1)(b) GDPR.
5.6 Audiobooks and digital purchases
When you purchase audiobooks or similar digital content, we process order, user and transaction data for payment handling, contract performance, fraud prevention and delivery of the purchased content. The legal basis is Art. 6(1)(b) GDPR.
5.7 Invoices and digital signatures
For invoices and digital signature workflows we process invoice data, identification data, signature images and technical proof in order to document the transaction. The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR where commercial or tax obligations apply.
6. Recipients and processors
We use technical and organisational service providers where this is necessary to operate the website and our services. This may include hosting, email, security, payment and analytics providers.
According to the current project setup, the following third-party services may in particular be integrated:
- Google reCAPTCHA Enterprise for anti-abuse and bot protection
- Google Analytics 4 for reach measurement and technical analysis where analytics cookies have been accepted
- Google Identity Services for login or account functions where activated
- Stripe for payment processing of digital products
Where personal data is processed by external providers on our behalf, this is done on the basis of data processing agreements or other suitable data protection safeguards.
7. Transfers to third countries
When using services from Google or Stripe, data may be transferred to third countries, especially the United States. Such transfers take place only subject to the applicable data protection requirements, in particular adequacy decisions, standard contractual clauses or explicit consent where required.
8. Retention period
We store personal data only as long as necessary for the relevant purposes or as long as statutory retention obligations apply.
- Account data is generally stored for the duration of the user account and afterwards until legal or defence-related periods have expired.
- Contract, booking, invoice and payment data is stored in accordance with statutory retention periods.
- Newsletter data is stored until consent is withdrawn or the subscription is cancelled.
- Contact requests are stored only as long as required for handling, follow-up and documentation purposes.
- Cookie and tracking information depends on the respective cookie lifetime and our cookie policy.
9. Your rights
Under the GDPR you have in particular the following rights:
- access to your personal data
- rectification of inaccurate or incomplete data
- erasure where the legal requirements are met
- restriction of processing
- data portability
- objection to processing based on Art. 6(1)(f) GDPR
- withdrawal of consent with effect for the future
- the right to lodge a complaint with a supervisory authority
10. Right to lodge a complaint
You may in particular contact the supervisory authority responsible for private entities in Bavaria:
- Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
- Promenade 18, 91522 Ansbach, Germany
- Website: www.lda.bayern.de
11. Obligation to provide data
Where certain information is required for entering into or performing a contract, we mark that data as necessary. Without this data we may be unable to provide the relevant service.
12. Automated decisions
According to the current project setup, we do not use automated decision-making within the meaning of Art. 22 GDPR.
13. Changes to this notice
We update this privacy notice where legal requirements, technical features or the services we offer materially change.