Direkt zum Seiteninhalt springen
b13 GmbH

Hauptstätter Str. 59
70178 Stuttgart
Germany
+49 (0) 711 460 589 70 [email protected]

Privacy Policy (Marketplace)

I. General Information about Data Processing

b13 GmbH (“we” or “us”) takes data protection seriously and is committed to protecting your privacy. This Privacy Policy explains how we collect, process, and safeguard your personal data when you visit our shop, purchase digital products, and manage your subscriptions.

We process your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our shop and services, you consent to the data processing practices described in this policy.

Data Controller: b13 GmbH, Hauptstätter Str. 59, 70178 Stuttgart, Germany

II. Responsible Party (Data Controller)

Company Name: b13 GmbH
Address: Hauptstätter Str. 59, 70178 Stuttgart, Germany
Phone: +49 (0) 711 460 589 70
Email: [email protected]
Website: https://b13.com

b13 GmbH is responsible for the processing of personal data on this website and in our shop. We process data solely on the basis of legitimate purposes and legal requirements. If you have any questions about our data processing, please contact us using the details above.

III. Data Protection Officer (DPO)

You can reach our Data Protection Officer via:

TÜV SÜD Akademie GmbH
Westendstraße 160
80339 München, Germany
Email: [email protected]

Our Data Protection Officer is available to answer your privacy-related questions and to support you in exercising your data protection rights.

IV. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right to information: You can request what data we hold about you.
  • Right to correction: You can request that we correct inaccurate personal data.
  • Right to deletion: You can request deletion of your personal data (right to be forgotten), subject to legal exceptions.
  • Right to restrict processing: You can request that we limit how we process your data.
  • Right to data portability: You can request a copy of your data in a structured, commonly used, and machine-readable format.
  • Right to object: You can object to the processing of your personal data for certain purposes.
  • Right to withdraw consent: Where processing is based on your consent, you can withdraw consent at any time.
  • Right to lodge a complaint: If you believe we have violated your rights, you can lodge a complaint with the relevant data protection authority (in Germany: the state data protection commissioner).

To exercise any of these rights, please contact us at [email protected] or [email protected]. We will respond to your request within 30 days (extendable by two months for complex cases).

V. Data Processing for Website Visits

When you visit our website and shop, we automatically collect certain technical information:

Information collected:
- IP address
- Browser type and version
- Operating system
- Pages visited and time spent on each page
- Referrer URL
- Date and time of access
- Device identifiers

Purpose: These logs help us maintain security, troubleshoot technical issues, and understand usage patterns.

Legal basis: Legitimate interest (Article 6(1)(f) GDPR) – to operate and secure our services, and to comply with legal obligations.

Retention: Server logs are typically retained for 30 days, unless longer retention is required by law.

VI. Cookies

We use cookies and similar tracking technologies to enhance your experience and analyze site performance.

Types of cookies we use:

  1. Essential/Functional Cookies
  2. Purpose: Enable core functionality (login, cart, checkout)
  3. Legal basis: Consent (Article 7 GDPR) or legitimate interest
  4. Duration: Session or persistent
  5. Can be disabled: May affect functionality

  6. Analytical Cookies

  7. Purpose: Understand how users interact with the shop
  8. Tools: Google Analytics (see Section XI)
  9. Legal basis: Consent
  10. Duration: Up to 2 years
  11. Can be disabled: No impact on functionality

  12. Marketing/Advertising Cookies

  13. Purpose: Personalize content and measure campaign performance
  14. Legal basis: Consent
  15. Duration: Up to 1 year
  16. Can be disabled: Yes

Your cookie choices: You can manage cookie preferences through our cookie banner on first visit. You can also control cookies via your browser settings, though this may limit functionality.

VII. Additional Functions and Services

User Accounts: When you create an account, we collect:
- Name and email address
- Password (encrypted)
- Account preferences
- Login history

Purpose: To provide account management, secure access, and personalized service.

Legal basis: Contract performance (Article 6(1)(b) GDPR) – to fulfill your subscription services.

Retention: As long as your account is active, plus 30 days after deletion (for legal compliance).

VIII. Contact Forms

When you submit a contact form or inquiry, we collect:
- Name and email address
- Message content
- Optional phone number

Purpose: To respond to your inquiry and provide customer support.

Legal basis: Consent (Article 7 GDPR) and contract performance (Article 6(1)(b) GDPR).

Retention: 90 days, unless longer retention is needed for legal or contractual reasons.

IX. Blog and Content

Our blog may contain comments, and we process:
- Name and email (if you choose to comment)
- Comment content
- IP address
- User agent

Purpose: To manage comments and prevent spam.

Legal basis: Legitimate interest (Article 6(1)(f) GDPR) – to maintain community standards and prevent abuse.

Retention: Comments are retained as long as the blog post exists.

X. Cloudflare Content Delivery Network

We use Cloudflare to optimize site performance and security. Cloudflare processes:
- IP address
- Request metadata
- Cookies and device identifiers

Purpose: To provide CDN services, DDoS protection, and improve performance.

Legal basis: Legitimate interest (Article 6(1)(f) GDPR).

Data Protection: Cloudflare is an approved data processor under GDPR. You can review Cloudflare’s privacy policy at https://www.cloudflare.com/privacy/

Retention: Cloudflare retains logs for 30 days.

XI. Google Analytics

We use Google Analytics to understand website traffic and user behavior.

Data processed:
- Visitor behavior and device information
- Geographic location
- Pages visited
- Time on site
- Traffic sources

Purpose: To analyze site performance and improve user experience.

Legal basis: Consent (Article 7 GDPR).

Data Protection: Google Analytics is configured to anonymize IP addresses (IP masking enabled). Google is a data processor under the EU-US Data Privacy Framework.

Your choices:
- Opt out via Google Analytics settings: https://tools.google.com/dlpage/gaoptout
- Install Google Analytics Opt-Out Browser Add-on

Review Google’s privacy policy at https://policies.google.com/privacy

XII. VG Wort (German Copyright Society)

Our website contains tracking pixels from VG Wort (Verwertungsgesellschaft Wort), a German copyright collective.

Purpose: VG Wort uses anonymous tracking to measure content views for copyright remuneration.

Data processed:
- Anonymous usage data
- No personal identification

Legal basis: Legitimate interest (Article 6(1)(f) GDPR) – to ensure fair compensation for digital content creators.

Your choices: You can object to VG Wort tracking by setting your browser to reject cookies or by using the opt-out mechanism at https://www.vgwort.de

XIII. Paddle as Payment Processor and Merchant of Record

Paddle Payments Ltd (UK) / Paddle.com Market Ltd (EU) serves as our payment processor and Merchant of Record for transactions in our shop.

What is Paddle?

Paddle handles the complete transaction process for digital product sales, including payment processing, billing, tax compliance, and subscription management. When you purchase our products, Paddle acts as the merchant of record and data processor.

Paddle Entities:
- Paddle Payments Ltd – Payment processing (UK-registered)
- Paddle.com Market Ltd – EU merchant of record for EU customers
- Website: https://www.paddle.com

Data Collected by Paddle

When you make a purchase or manage a subscription through our shop, Paddle collects and processes:

Purchase Data:
- Full name
- Email address
- Billing address (street, city, postal code, country)
- Payment method information (credit/debit card number, expiration date, CVV—processed securely)
- IP address
- Device information
- Transaction ID and amount
- Product/license purchased
- Purchase date and time

Subscription Data:
- Billing cycle information
- Renewal dates
- Subscription status (active, cancelled, renewed)
- License keys and activation data
- Usage metrics

Account Data:
- Customer account information in Paddle system
- License management details
- Download history
- Invoice records

Purpose of Data Processing

Paddle processes your data for:
- Payment authorization and fraud prevention
- Billing and invoice generation
- Tax compliance (VAT, sales tax)
- Subscription management and renewals
- License key generation and management
- Dispute resolution and customer service
- Anti-money laundering (AML) and know-your-customer (KYC) compliance
- Analytics and reporting

Legal Basis for Processing

  • Contract performance (Article 6(1)(b) GDPR) – to process your purchase and manage subscriptions
  • Legal obligation (Article 6(1)(c) GDPR) – to comply with tax and financial regulations
  • Legitimate interest (Article 6(1)(f) GDPR) – fraud prevention, security, and business analytics

Data Sharing

We share the following data with Paddle:
- Your personal information necessary to process your order
- Product selection and subscription details
- Billing information

Paddle may share data with:
- Payment networks (Visa, Mastercard, etc.) for processing
- Financial institutions
- Tax authorities (where legally required)
- Fraud detection services
- Third-party service providers assisting with their operations

Data Protection and Security

Paddle’s Responsibilities:
- Processes data as a data processor under Article 6 GDPR
- Maintains PCI DSS Level 1 compliance for payment security
- Uses encryption for sensitive data transmission (SSL/TLS)
- Implements access controls and security measures
- Does not retain full payment card data after transaction completion

Our Responsibilities:
- Ensure lawful basis for data sharing with Paddle
- Include appropriate data processing agreements
- Monitor Paddle’s compliance with GDPR

Data Retention

Paddle retains:
- Payment card data: Not retained (tokenized for recurring payments)
- Invoice and billing records: For 10 years (legal requirement in many jurisdictions)
- Subscription data: For the duration of the subscription, plus 3 years
- Anonymized analytics: Indefinitely

For details on Paddle’s data retention, see their privacy policy.

International Data Transfers

Paddle processes data in the European Union and other jurisdictions. Where transfers occur outside the EEA:
- Paddle relies on adequacy decisions or appropriate safeguards (Standard Contractual Clauses)
- You consent to such transfers when making a purchase
- Transfers comply with GDPR Chapter 5

Review Paddle’s data transfer mechanisms in their privacy policy.

Your Rights with Paddle

As Paddle acts as the data processor, you can:
- Request access to your payment data processed by Paddle
- Request correction of billing information
- Request deletion of certain data (subject to legal retention requirements)
- Contact Paddle directly for privacy requests

Paddle Privacy Policy: https://www.paddle.com/privacy
Paddle Data Processing Agreement: https://www.paddle.com/company/gdpr-sccs

Contact Paddle directly:
- Email: [email protected]
- Data Protection Officer: [email protected]

Customer Support and Disputes

For issues related to:
- Refunds and cancellations: Contact us at [email protected], and we’ll work with Paddle
- License activation: Contact us at [email protected]
- Billing inquiries: Check your Paddle account or contact us

We retain customer communication records for 3 years for dispute resolution.

XIV. License Keys and Product Access

When you purchase a digital product, we provide:
- License key(s) via email
- Access to download links (if applicable)
- Subscription/activation credentials

Data processed:
- License key associations (linked to your email)
- Activation records
- Device information for license validation

Purpose: To enable product access and manage licenses.

Legal basis: Contract performance (Article 6(1)(b) GDPR).

Retention: For the duration of the license/subscription, plus 3 years for dispute resolution.

XV. Email Communications

When you purchase or subscribe, we send:
- Order confirmation
- Invoice and receipt
- License key and setup instructions
- Renewal notices (before subscription expires)
- Account update notifications
- Important service announcements

We may also send marketing emails if you’ve opted in.

Legal basis:
- Contract performance (Article 6(1)(b) GDPR) – for transactional emails
- Consent (Article 7 GDPR) – for marketing communications

Unsubscribe: All marketing emails include an unsubscribe link. Transactional emails cannot be unsubscribed from while your account is active.

XVI. Third-Party Services and Integrations

We may use third-party tools for:
- Email delivery (transactional and marketing)
- Analytics and reporting
- Customer support platforms
- Cloud hosting and storage

Each third party that processes personal data:
- Has a data processing agreement with b13 GmbH
- Is GDPR-compliant
- May be a “data processor” or “joint controller” as appropriate

You can request a list of our data processors at [email protected].

XVII. Data Security

We implement technical and organizational measures to protect your data:
- Encryption in transit (SSL/TLS)
- Encryption at rest for sensitive data
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
- Incident response procedures

However, no system is 100% secure. If we discover a data breach affecting you, we will notify you and relevant authorities within 72 hours as required by law.

XVIII. Retention of Personal Data

We retain your data according to:
- How long we need it to provide services
- Legal retention requirements (tax, financial, etc.)
- Legitimate business purposes (dispute resolution, fraud prevention)

Summary:
- Account data: Duration of active account + 30 days
- Transaction/billing data: 10 years (legal requirement)
- Email communications: 3 years
- Support tickets: 90 days – 3 years
- Marketing data: Until unsubscribe
- Log files: 30 days
- Cookies: As specified above

XIX. Children’s Privacy

Our products and services are not directed to children under 16. We do not knowingly collect data from children under 16. If we become aware that a child under 16 has provided data, we will delete it immediately. Parents/guardians can contact [email protected] to request deletion of a child’s data.

XX. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in law, our practices, or other factors. We will notify you of material changes via email or a prominent notice on our website. Your continued use of the shop after changes indicates acceptance of the updated policy.

XXI. Contact and Complaints

For privacy questions or requests: Email: [email protected]
Address: b13 GmbH, Hauptstätter Str. 59, 70178 Stuttgart, Germany

For data protection complaints: Email: [email protected]
DPO via TÜV SÜD Akademie GmbH (contact details in Section III)

To lodge a complaint with a supervisory authority: In Germany: The Data Protection Commissioner for your state
EU: Your national data protection authority
UK: Information Commissioner’s Office (ICO)

XXII. Legal Notice

This Privacy Policy, combined with our Terms of Service and other agreements, governs how we collect and use your information. If any provision is found invalid, the remaining provisions remain in effect. English is the original language; translations are for convenience only.

Effective Date: April 2026
Last Updated: April 2026