Privacy notice for business contacts
Information pursuant to Article 14 GDPR · As of 22 September 2026
You are reading this because you received an email from us with a business offer, and you never gave us your address. We took it from a source your business publishes itself.
When personal data is not collected from the person it belongs to, Article 14 GDPR requires the sender to say who he is, where the data came from, what he does with it, how long he keeps it and how to stop it. That information has to arrive with the first message at the latest (Article 14(3)(b) GDPR). Our email gives you the short version and links here; this page is the full one.
Who is responsible
Article 14(1)(a) and (b) GDPR
The controller for this processing is Benedict Herrnleben, sole trader, trading as Digitale Stempelkarten, Berlepschstraße 1, 14165 Berlin, Germany.
You reach him by email at hello@stempelkarten.store or by telephone on +49 152 33532268.
There is no data protection officer. German law requires one only above a threshold that a one person business does not reach (Article 37 GDPR, Section 38 BDSG). Benedict Herrnleben answers data protection questions himself, at the address above.
The controller is established in the European Union, so there is no representative under Article 27 GDPR.
Why you received an email from us
Article 14(1)(c) GDPR
We write to independent cafes, bakeries, hairdressers and nail salons in Ireland, the Netherlands, France and Finland with one business offer: a digital stamp card that your customers add to Apple Wallet or Google Wallet, without installing an app.
The purpose is that one offer and the conversation that may follow from it. You get a first email and, if you do not reply, at most one follow-up after 7 to 10 days. Then we stop.
We do not use your address for anything else. There is no newsletter, no mailing list, no profiling, no enrichment from other sources, no sale and no transfer to anyone else. The email concerns your business only and is addressed to you in your professional capacity.
Legal basis and our legitimate interest
Article 6(1)(f) and Article 14(2)(b) GDPR
We process your data on the basis of our legitimate interest, Article 6(1)(f) GDPR. Recital 47 of the GDPR names direct marketing as a legitimate interest.
Our interest is to let a small number of businesses know that this product exists. Without the address a business publishes for contact, a first approach is not possible at all, and advertising or travelling to another country is out of proportion for a one person business.
Your interests were weighed before the first email went out. Anyone who publishes a business address so that people can get in touch can expect offers about that business. The intrusion is small: the data is public and business related, there are no special categories of data (Article 9 GDPR), no data about children, no profiling and no scoring. The emails are written and sent one by one, 20 to 30 a day, with no attachment, no image and no tracking pixel. The balancing test is written down, dated, and reviewed before every new country.
Whether an advertising email is allowed at all also follows from the law of your own country. We rely on Regulation 13(2) of S.I. No. 336/2011 in Ireland, Article 11.7(2)(a) Telecommunicatiewet in the Netherlands, Article L34-5 CPCE with the CNIL guidance on business prospection in France, and Section 200 of the Act on Electronic Communications Services (917/2014) in Finland. We send no cold emails to Germany, Austria, Switzerland or Luxembourg.
What data we hold about you
Article 14(1)(d) GDPR
The entry for your business holds:
- the name and postal address of the business and the country it is in,
- the business email address you publish,
- the name and role of the owner or contact person, where your business publishes them; in Finland we note the role, because the national rule depends on it,
- the source the address came from and the date we noted it,
- which template we sent, when we sent it, whether you replied, whether a call was arranged and whether you objected,
- the date on which the entry falls due for deletion.
We hold no private addresses, no data taken from social networks, no bank details and no data about your own customers.
Where the data comes from
Article 14(2)(f) GDPR
Your data comes from a publicly accessible source: the website of your business or its Google Business Profile, that is, the pages your business publishes itself so that people can get in touch.
We buy no address lists, we take nothing from address brokers, and we run no scraper that mails everything it finds. A person looks at every entry before an email goes out.
Who else sees the data
Article 14(1)(e) GDPR
The email is sent through our email provider mailbox.org GmbH, Berlin, Germany. It processes the data on our behalf under Article 28 GDPR and runs its servers in Germany.
Nobody else receives your data. There is no CRM provider, no marketing platform, no analytics and no address trade. The list of leads is a file under the controller's own control. Public authorities receive data only where the law obliges us to hand it over.
Transfers outside the EU
Article 14(1)(f) GDPR
There are none. The data stays with the controller in Germany and with mailbox.org in Germany. We transfer it to no country outside the European Economic Area and to no international organisation, so no adequacy decision and no standard contractual clauses are needed for it.
How long we keep the data
Article 14(2)(a) GDPR
Three cases, and they cover every entry:
- You do not reply: we delete the entry 6 months after the last email.
- You become a customer: the data moves into our customer records, and from that point the privacy policy for customers applies to it. You find it in the footer of this page.
- You object: we keep your email address permanently on a separate suppression list, so that a second email can never reach you. Nothing is kept with it except the date and the reason. The legal basis for that list is Article 6(1)(c) together with Article 21(3) GDPR: once you have objected, we may not process your address for direct marketing again, and a list of addresses not to write to is the only way to keep that promise.
Your right to object
Article 21 GDPR
You can object to this processing at any time. You do not have to give a reason, and it costs you nothing.
Two ways, both of which reach a person:
- reply to our email with the word STOP, or
- write to hello@stempelkarten.store from any address and name the business.
We enter the objection within 24 hours, and after that you will never get another email from us. For direct marketing this right is absolute (Article 21(2) and (3) GDPR): there is no balancing of interests, we do not ask you to justify it, and we do not ask you to confirm it a second time.
There is deliberately no form on this page. An objection that arrives as an email is one we can prove we received, and you keep your own copy of it.
Your other rights
Article 14(2)(c) and (d) GDPR
For as long as we hold data about you, you have the rights the GDPR gives you: access to that data (Article 15), rectification of anything wrong (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20).
Write to hello@stempelkarten.store and say what you want. We answer within one month (Article 12(3) GDPR), and if we ever need longer we tell you why and by how much. Exercising a right costs you nothing.
There is no consent here to withdraw: this processing is not based on consent (Article 6(1)(a) GDPR), so the withdrawal under Article 7(3) does not apply to it. The right that matters here is the right to object above.
Complaint to a supervisory authority
Article 14(2)(e) and Article 77 GDPR
You can complain to a data protection supervisory authority, and you do not have to contact us first. The authority responsible for the controller is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany, mailbox@datenschutz-berlin.de, www.datenschutz-berlin.de
You may also complain to the supervisory authority of the EU country where you live, where you work or where you believe the infringement happened (Article 77 GDPR): the Data Protection Commission in Ireland, the Autoriteit Persoonsgegevens in the Netherlands, the CNIL in France, the Office of the Data Protection Ombudsman in Finland.
No automated decision making
Article 14(2)(g) GDPR
There is no automated decision making and no profiling in this processing. A person decides which businesses to write to, and a person writes each email. No software scores you, ranks you or decides anything about you.