Privacy Policy (Marketplace)
I. General Information about Data Processing
b13 GmbH (“we” or “us”) takes data protection seriously and is committed to protecting your privacy. This Privacy Policy explains how we collect, process, and safeguard your personal data when you visit our shop, purchase digital products, and manage your subscriptions.
We process your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our shop and services, you consent to the data processing practices described in this policy.
Data Controller: b13 GmbH, Hauptstätter Str. 59, 70178 Stuttgart, Germany
II. Responsible Party (Data Controller)
Company Name: b13 GmbH
Address: Hauptstätter Str. 59, 70178 Stuttgart, Germany
Phone: +49 (0) 711 460 589 70
Email: [email protected]
Website: https://b13.com
b13 GmbH is responsible for the processing of personal data on this website and in our shop. We process data solely on the basis of legitimate purposes and legal requirements. If you have any questions about our data processing, please contact us using the details above.
III. Data Protection Officer (DPO)
You can reach our Data Protection Officer via:
TÜV SÜD Akademie GmbH
Westendstraße 160
80339 München, Germany
Email: [email protected]
Our Data Protection Officer is available to answer your privacy-related questions and to support you in exercising your data protection rights.
IV. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to information: You can request what data we hold about you.
- Right to correction: You can request that we correct inaccurate personal data.
- Right to deletion: You can request deletion of your personal data (right to be forgotten), subject to legal exceptions.
- Right to restrict processing: You can request that we limit how we process your data.
- Right to data portability: You can request a copy of your data in a structured, commonly used, and machine-readable format.
- Right to object: You can object to the processing of your personal data for certain purposes.
- Right to withdraw consent: Where processing is based on your consent, you can withdraw consent at any time.
- Right to lodge a complaint: If you believe we have violated your rights, you can lodge a complaint with the relevant data protection authority (in Germany: the state data protection commissioner).
To exercise any of these rights, please contact us at [email protected] or [email protected]. We will respond to your request within 30 days (extendable by two months for complex cases).
V. Data Processing for Website Visits
When you visit our website and shop, we automatically collect certain technical information:
Information collected:
- IP address
- Browser type and version
- Operating system
- Pages visited and time spent on each page
- Referrer URL
- Date and time of access
- Device identifiers
Purpose: These logs help us maintain security, troubleshoot technical issues, and understand usage patterns.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) – to operate and secure our services, and to comply with legal obligations.
Retention: Server logs are typically retained for 30 days, unless longer retention is required by law.
VI. Cookies
We use cookies and similar tracking technologies to enhance your experience and analyze site performance.
Types of cookies we use:
- Essential/Functional Cookies
- Purpose: Enable core functionality (login, cart, checkout)
- Legal basis: Consent (Article 7 GDPR) or legitimate interest
- Duration: Session or persistent
-
Can be disabled: May affect functionality
-
Analytical Cookies
- Purpose: Understand how users interact with the shop
- Tools: Google Analytics (see Section XI)
- Legal basis: Consent
- Duration: Up to 2 years
-
Can be disabled: No impact on functionality
-
Marketing/Advertising Cookies
- Purpose: Personalize content and measure campaign performance
- Legal basis: Consent
- Duration: Up to 1 year
- Can be disabled: Yes
Your cookie choices: You can manage cookie preferences through our cookie banner on first visit. You can also control cookies via your browser settings, though this may limit functionality.
VII. Additional Functions and Services
User Accounts:
When you create an account, we collect:
- Name and email address
- Password (encrypted)
- Account preferences
- Login history
Purpose: To provide account management, secure access, and personalized service.
Legal basis: Contract performance (Article 6(1)(b) GDPR) – to fulfill your subscription services.
Retention: As long as your account is active, plus 30 days after deletion (for legal compliance).
VIII. Contact Forms
When you submit a contact form or inquiry, we collect:
- Name and email address
- Message content
- Optional phone number
Purpose: To respond to your inquiry and provide customer support.
Legal basis: Consent (Article 7 GDPR) and contract performance (Article 6(1)(b) GDPR).
Retention: 90 days, unless longer retention is needed for legal or contractual reasons.
IX. Blog and Content
Our blog may contain comments, and we process:
- Name and email (if you choose to comment)
- Comment content
- IP address
- User agent
Purpose: To manage comments and prevent spam.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) – to maintain community standards and prevent abuse.
Retention: Comments are retained as long as the blog post exists.
X. Cloudflare Content Delivery Network
We use Cloudflare to optimize site performance and security. Cloudflare processes:
- IP address
- Request metadata
- Cookies and device identifiers
Purpose: To provide CDN services, DDoS protection, and improve performance.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR).
Data Protection: Cloudflare is an approved data processor under GDPR. You can review Cloudflare’s privacy policy at https://www.cloudflare.com/privacy/
Retention: Cloudflare retains logs for 30 days.
XI. Google Analytics
We use Google Analytics to understand website traffic and user behavior.
Data processed:
- Visitor behavior and device information
- Geographic location
- Pages visited
- Time on site
- Traffic sources
Purpose: To analyze site performance and improve user experience.
Legal basis: Consent (Article 7 GDPR).
Data Protection: Google Analytics is configured to anonymize IP addresses (IP masking enabled). Google is a data processor under the EU-US Data Privacy Framework.
Your choices:
- Opt out via Google Analytics settings: https://tools.google.com/dlpage/gaoptout
- Install Google Analytics Opt-Out Browser Add-on
Review Google’s privacy policy at https://policies.google.com/privacy
XII. VG Wort (German Copyright Society)
Our website contains tracking pixels from VG Wort (Verwertungsgesellschaft Wort), a German copyright collective.
Purpose: VG Wort uses anonymous tracking to measure content views for copyright remuneration.
Data processed:
- Anonymous usage data
- No personal identification
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) – to ensure fair compensation for digital content creators.
Your choices: You can object to VG Wort tracking by setting your browser to reject cookies or by using the opt-out mechanism at https://www.vgwort.de
XIII. Paddle as Payment Processor and Merchant of Record
Paddle Payments Ltd (UK) / Paddle.com Market Ltd (EU) serves as our payment processor and Merchant of Record for transactions in our shop.
What is Paddle?
Paddle handles the complete transaction process for digital product sales, including payment processing, billing, tax compliance, and subscription management. When you purchase our products, Paddle acts as the merchant of record and data processor.
Paddle Entities:
- Paddle Payments Ltd – Payment processing (UK-registered)
- Paddle.com Market Ltd – EU merchant of record for EU customers
- Website: https://www.paddle.com
Data Collected by Paddle
When you make a purchase or manage a subscription through our shop, Paddle collects and processes:
Purchase Data:
- Full name
- Email address
- Billing address (street, city, postal code, country)
- Payment method information (credit/debit card number, expiration date, CVV—processed securely)
- IP address
- Device information
- Transaction ID and amount
- Product/license purchased
- Purchase date and time
Subscription Data:
- Billing cycle information
- Renewal dates
- Subscription status (active, cancelled, renewed)
- License keys and activation data
- Usage metrics
Account Data:
- Customer account information in Paddle system
- License management details
- Download history
- Invoice records
Purpose of Data Processing
Paddle processes your data for:
- Payment authorization and fraud prevention
- Billing and invoice generation
- Tax compliance (VAT, sales tax)
- Subscription management and renewals
- License key generation and management
- Dispute resolution and customer service
- Anti-money laundering (AML) and know-your-customer (KYC) compliance
- Analytics and reporting
Legal Basis for Processing
- Contract performance (Article 6(1)(b) GDPR) – to process your purchase and manage subscriptions
- Legal obligation (Article 6(1)(c) GDPR) – to comply with tax and financial regulations
- Legitimate interest (Article 6(1)(f) GDPR) – fraud prevention, security, and business analytics
Data Sharing
We share the following data with Paddle:
- Your personal information necessary to process your order
- Product selection and subscription details
- Billing information
Paddle may share data with:
- Payment networks (Visa, Mastercard, etc.) for processing
- Financial institutions
- Tax authorities (where legally required)
- Fraud detection services
- Third-party service providers assisting with their operations
Data Protection and Security
Paddle’s Responsibilities:
- Processes data as a data processor under Article 6 GDPR
- Maintains PCI DSS Level 1 compliance for payment security
- Uses encryption for sensitive data transmission (SSL/TLS)
- Implements access controls and security measures
- Does not retain full payment card data after transaction completion
Our Responsibilities:
- Ensure lawful basis for data sharing with Paddle
- Include appropriate data processing agreements
- Monitor Paddle’s compliance with GDPR
Data Retention
Paddle retains:
- Payment card data: Not retained (tokenized for recurring payments)
- Invoice and billing records: For 10 years (legal requirement in many jurisdictions)
- Subscription data: For the duration of the subscription, plus 3 years
- Anonymized analytics: Indefinitely
For details on Paddle’s data retention, see their privacy policy.
International Data Transfers
Paddle processes data in the European Union and other jurisdictions. Where transfers occur outside the EEA:
- Paddle relies on adequacy decisions or appropriate safeguards (Standard Contractual Clauses)
- You consent to such transfers when making a purchase
- Transfers comply with GDPR Chapter 5
Review Paddle’s data transfer mechanisms in their privacy policy.
Your Rights with Paddle
As Paddle acts as the data processor, you can:
- Request access to your payment data processed by Paddle
- Request correction of billing information
- Request deletion of certain data (subject to legal retention requirements)
- Contact Paddle directly for privacy requests
Paddle Privacy Policy: https://www.paddle.com/privacy
Paddle Data Processing Agreement: https://www.paddle.com/company/gdpr-sccs
Contact Paddle directly:
- Email: [email protected]
- Data Protection Officer: [email protected]
Customer Support and Disputes
For issues related to:
- Refunds and cancellations: Contact us at [email protected], and we’ll work with Paddle
- License activation: Contact us at [email protected]
- Billing inquiries: Check your Paddle account or contact us
We retain customer communication records for 3 years for dispute resolution.
XIV. License Keys and Product Access
When you purchase a digital product, we provide:
- License key(s) via email
- Access to download links (if applicable)
- Subscription/activation credentials
Data processed:
- License key associations (linked to your email)
- Activation records
- Device information for license validation
Purpose: To enable product access and manage licenses.
Legal basis: Contract performance (Article 6(1)(b) GDPR).
Retention: For the duration of the license/subscription, plus 3 years for dispute resolution.
XV. Email Communications
When you purchase or subscribe, we send:
- Order confirmation
- Invoice and receipt
- License key and setup instructions
- Renewal notices (before subscription expires)
- Account update notifications
- Important service announcements
We may also send marketing emails if you’ve opted in.
Legal basis:
- Contract performance (Article 6(1)(b) GDPR) – for transactional emails
- Consent (Article 7 GDPR) – for marketing communications
Unsubscribe: All marketing emails include an unsubscribe link. Transactional emails cannot be unsubscribed from while your account is active.
XVI. Third-Party Services and Integrations
We may use third-party tools for:
- Email delivery (transactional and marketing)
- Analytics and reporting
- Customer support platforms
- Cloud hosting and storage
Each third party that processes personal data:
- Has a data processing agreement with b13 GmbH
- Is GDPR-compliant
- May be a “data processor” or “joint controller” as appropriate
You can request a list of our data processors at [email protected].
XVII. Data Security
We implement technical and organizational measures to protect your data:
- Encryption in transit (SSL/TLS)
- Encryption at rest for sensitive data
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
- Incident response procedures
However, no system is 100% secure. If we discover a data breach affecting you, we will notify you and relevant authorities within 72 hours as required by law.
XVIII. Retention of Personal Data
We retain your data according to:
- How long we need it to provide services
- Legal retention requirements (tax, financial, etc.)
- Legitimate business purposes (dispute resolution, fraud prevention)
Summary:
- Account data: Duration of active account + 30 days
- Transaction/billing data: 10 years (legal requirement)
- Email communications: 3 years
- Support tickets: 90 days – 3 years
- Marketing data: Until unsubscribe
- Log files: 30 days
- Cookies: As specified above
XIX. Children’s Privacy
Our products and services are not directed to children under 16. We do not knowingly collect data from children under 16. If we become aware that a child under 16 has provided data, we will delete it immediately. Parents/guardians can contact [email protected] to request deletion of a child’s data.
XX. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or other factors. We will notify you of material changes via email or a prominent notice on our website. Your continued use of the shop after changes indicates acceptance of the updated policy.
XXI. Contact and Complaints
For privacy questions or requests:
Email: [email protected]
Address: b13 GmbH, Hauptstätter Str. 59, 70178 Stuttgart, Germany
For data protection complaints:
Email: [email protected]
DPO via TÜV SÜD Akademie GmbH (contact details in Section III)
To lodge a complaint with a supervisory authority:
In Germany: The Data Protection Commissioner for your state
EU: Your national data protection authority
UK: Information Commissioner’s Office (ICO)
XXII. Legal Notice
This Privacy Policy, combined with our Terms of Service and other agreements, governs how we collect and use your information. If any provision is found invalid, the remaining provisions remain in effect. English is the original language; translations are for convenience only.
Effective Date: April 2026
Last Updated: April 2026