Privacy notice for business contacts

Information pursuant to Article 14 GDPR · As of 22 September 2026

You are reading this because you received an email from us with a business offer, and you never gave us your address. We took it from a source your business publishes itself.

When personal data is not collected from the person it belongs to, Article 14 GDPR requires the sender to say who he is, where the data came from, what he does with it, how long he keeps it and how to stop it. That information has to arrive with the first message at the latest (Article 14(3)(b) GDPR). Our email gives you the short version and links here; this page is the full one.

Who is responsible

Article 14(1)(a) and (b) GDPR

The controller for this processing is Benedict Herrnleben, sole trader, trading as Digitale Stempelkarten, Berlepschstraße 1, 14165 Berlin, Germany.

You reach him by email at hello@stempelkarten.store or by telephone on +49 152 33532268.

There is no data protection officer. German law requires one only above a threshold that a one person business does not reach (Article 37 GDPR, Section 38 BDSG). Benedict Herrnleben answers data protection questions himself, at the address above.

The controller is established in the European Union, so there is no representative under Article 27 GDPR.

Why you received an email from us

Article 14(1)(c) GDPR

We write to independent cafes, bakeries, hairdressers and nail salons in Ireland, the Netherlands, France and Finland with one business offer: a digital stamp card that your customers add to Apple Wallet or Google Wallet, without installing an app.

The purpose is that one offer and the conversation that may follow from it. You get a first email and, if you do not reply, at most one follow-up after 7 to 10 days. Then we stop.

We do not use your address for anything else. There is no newsletter, no mailing list, no profiling, no enrichment from other sources, no sale and no transfer to anyone else. The email concerns your business only and is addressed to you in your professional capacity.

What data we hold about you

Article 14(1)(d) GDPR

The entry for your business holds:

  • the name and postal address of the business and the country it is in,
  • the business email address you publish,
  • the name and role of the owner or contact person, where your business publishes them; in Finland we note the role, because the national rule depends on it,
  • the source the address came from and the date we noted it,
  • which template we sent, when we sent it, whether you replied, whether a call was arranged and whether you objected,
  • the date on which the entry falls due for deletion.

We hold no private addresses, no data taken from social networks, no bank details and no data about your own customers.

Where the data comes from

Article 14(2)(f) GDPR

Your data comes from a publicly accessible source: the website of your business or its Google Business Profile, that is, the pages your business publishes itself so that people can get in touch.

We buy no address lists, we take nothing from address brokers, and we run no scraper that mails everything it finds. A person looks at every entry before an email goes out.

Who else sees the data

Article 14(1)(e) GDPR

The email is sent through our email provider mailbox.org GmbH, Berlin, Germany. It processes the data on our behalf under Article 28 GDPR and runs its servers in Germany.

Nobody else receives your data. There is no CRM provider, no marketing platform, no analytics and no address trade. The list of leads is a file under the controller's own control. Public authorities receive data only where the law obliges us to hand it over.

Transfers outside the EU

Article 14(1)(f) GDPR

There are none. The data stays with the controller in Germany and with mailbox.org in Germany. We transfer it to no country outside the European Economic Area and to no international organisation, so no adequacy decision and no standard contractual clauses are needed for it.

How long we keep the data

Article 14(2)(a) GDPR

Three cases, and they cover every entry:

  • You do not reply: we delete the entry 6 months after the last email.
  • You become a customer: the data moves into our customer records, and from that point the privacy policy for customers applies to it. You find it in the footer of this page.
  • You object: we keep your email address permanently on a separate suppression list, so that a second email can never reach you. Nothing is kept with it except the date and the reason. The legal basis for that list is Article 6(1)(c) together with Article 21(3) GDPR: once you have objected, we may not process your address for direct marketing again, and a list of addresses not to write to is the only way to keep that promise.

Your right to object

Article 21 GDPR

You can object to this processing at any time. You do not have to give a reason, and it costs you nothing.

Two ways, both of which reach a person:

We enter the objection within 24 hours, and after that you will never get another email from us. For direct marketing this right is absolute (Article 21(2) and (3) GDPR): there is no balancing of interests, we do not ask you to justify it, and we do not ask you to confirm it a second time.

There is deliberately no form on this page. An objection that arrives as an email is one we can prove we received, and you keep your own copy of it.

Your other rights

Article 14(2)(c) and (d) GDPR

For as long as we hold data about you, you have the rights the GDPR gives you: access to that data (Article 15), rectification of anything wrong (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20).

Write to hello@stempelkarten.store and say what you want. We answer within one month (Article 12(3) GDPR), and if we ever need longer we tell you why and by how much. Exercising a right costs you nothing.

There is no consent here to withdraw: this processing is not based on consent (Article 6(1)(a) GDPR), so the withdrawal under Article 7(3) does not apply to it. The right that matters here is the right to object above.

Complaint to a supervisory authority

Article 14(2)(e) and Article 77 GDPR

You can complain to a data protection supervisory authority, and you do not have to contact us first. The authority responsible for the controller is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany, mailbox@datenschutz-berlin.de, www.datenschutz-berlin.de

You may also complain to the supervisory authority of the EU country where you live, where you work or where you believe the infringement happened (Article 77 GDPR): the Data Protection Commission in Ireland, the Autoriteit Persoonsgegevens in the Netherlands, the CNIL in France, the Office of the Data Protection Ombudsman in Finland.

No automated decision making

Article 14(2)(g) GDPR

There is no automated decision making and no profiling in this processing. A person decides which businesses to write to, and a person writes each email. No software scores you, ranks you or decides anything about you.