This Privacy Policy explains how Grünkurs Berlin ("we", "us") collects, uses, stores and protects personal data when you visit our website, contact us about plant workshops, or attend sessions at our studio at Torstraße 126, 10119 Berlin, Germany.
Data Controller
The data controller is Grünkurs Berlin, Torstraße 126, 10119 Berlin, Germany.
Email: [email protected]
Phone: +49 30 2844 7612
Personal Data We Collect
Depending on how you interact with us, we may collect:
- Identity and contact data: name, email address, phone number, postal address where provided
- Booking data: preferred dates and times, workshop selections, group size, participant names for group bookings, visit history, cancellation records
- Communication data: messages sent via contact forms, email, phone calls or in-studio conversations
- Payment data: transaction references, invoice details and payment method type (we do not store full card numbers)
- Technical data: IP address, browser type, device information, pages visited, referral source and session identifiers (via cookies where enabled)
- Marketing preferences: opt-in status for workshop reminders or occasional studio news
- Workshop-related information: plant species you bring to sessions, apartment light conditions you describe for care advice—used solely to deliver plant education, not medical or health assessments
- Special categories: we do not request health data. Grünkurs Berlin is a plant education studio, not a medical or wellness provider. We do not process special categories of personal data under Article 9 GDPR unless you voluntarily provide information relevant to workshop participation and explicitly consent
Purposes and Legal Basis (GDPR)
We process personal data under Regulation (EU) 2016/679 (GDPR) and the German Federal Data Protection Act (BDSG) on the following bases:
- Contract / pre-contract steps (Art. 6(1)(b)): managing workshop bookings, confirming reservations, delivering plant education services and processing payments
- Legitimate interests (Art. 6(1)(f)): responding to enquiries, maintaining participant records for service continuity, improving our website and studio operations, preventing no-shows and fraud—balanced against your rights
- Legal obligation (Art. 6(1)(c)): accounting, invoicing, tax and regulatory requirements under German law
- Consent (Art. 6(1)(a)): non-essential cookies, optional marketing messages and photography consent for portfolio use
Cookies and Similar Technologies
Our website uses necessary cookies for basic operation. Analytics or preference cookies, if introduced, run only with your consent where required. See our Cookies page for categories, retention periods and how to withdraw consent.
Data Retention
- Enquiry and booking request data: up to 24 months after last meaningful contact unless an active participant relationship continues
- Workshop and visit records: up to 36 months after the last session for service continuity and dispute resolution
- Accounting records and invoices: retained for the period required by German commercial and tax legislation (typically 6–10 years)
- Marketing consent records: until you withdraw consent plus a short audit period (typically 12 months)
- Technical and security logs: up to 12 months unless longer retention is required for incident investigation
- Contact form submissions not leading to a booking: deleted or anonymised within 12 months
Who We Share Data With
We share personal data only as necessary with:
- Website hosting, email and form processing providers acting as processors under Article 28 GDPR agreements
- Payment service providers for card and bank transfer transactions
- Accounting and payroll service providers where required for business operations
- Professional advisors (accountant, legal counsel) when necessary
- Public authorities when legally obliged (e.g. Finanzamt, law enforcement)
We do not sell personal data. We do not use automated decision-making that produces legal or similarly significant effects.
International Transfers
Where tools or hosting providers process data outside the European Economic Area, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, supplementary measures where required by European Data Protection Board guidance, or rely on an adequacy decision. You may request details of transfers relevant to your data by contacting us.
Security
We apply technical and organisational measures proportionate to the risk, including:
- Access controls on studio booking systems and email accounts
- Encrypted transmission (HTTPS) on our website where supported
- Staff training on confidentiality and data minimisation
- Physical security of booking records at the studio
- Regular review of processor agreements and access permissions
No method of transmission over the internet is completely secure. Please avoid sending unnecessary sensitive information by unencrypted email.
Your Rights Under the GDPR
Depending on circumstances, you may have the right to:
- Access your personal data and obtain a copy (Art. 15)
- Rectify inaccurate or incomplete data (Art. 16)
- Erase data in certain cases, such as where it is no longer necessary (Art. 17)
- Restrict processing in defined situations (Art. 18)
- Data portability for data you provided, where processing is automated and based on contract or consent (Art. 20)
- Object to processing based on legitimate interests or for direct marketing (Art. 21)
- Withdraw consent at any time without affecting prior lawful processing (Art. 7(3))
- Not be subject to solely automated decisions with significant effects, where applicable (Art. 22)
To exercise these rights, contact [email protected]. We respond within one month, extendable by two further months where requests are complex or numerous. We may need to verify your identity before disclosing data.
Children
Our workshops are directed at adults and participants aged 14 and above. Younger participants may attend with a parent or guardian who holds the booking. We do not knowingly collect data from children under 14 without verifiable parental consent. Contact us if you believe we have received such data.
Data Protection Officer
We are not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy enquiries should be directed to the contact details above.
Complaints
If you believe your data protection rights have been infringed, you may lodge a complaint with:
Die Berliner Beauftragte für Datenschutz und Informationsfreiheit
Website: datenschutz-berlin.de
Address: Friedrichstraße 219, 10969 Berlin, Germany
You may also contact the supervisory authority in your EU country of residence. We encourage you to contact us first so we can address your concern promptly.
Changes to This Policy
We may update this Privacy Policy to reflect legal, technical or operational changes. The "Last updated" date at the top will change accordingly. Material changes may be communicated via email to active participants or a notice on this page.
Questions: [email protected]