Privacy Policy

Last updated: 2026-05-17-v1

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:



Phone:
E-Mail:

2. Platform operator and joint controllership

This website is technically operated by 2Brands Media GmbH as a processor within the meaning of Art. 28 GDPR. For data processed in connection with the 2Brands Media platform newsletter, there is a joint controllership pursuant to Art. 26 GDPR between the shop named above and 2Brands Media. The essential terms of this arrangement can be requested at any time.

2Brands Media GmbH
Mommsenstrasse 71
10629 Berlin
Germany
E-Mail: info@2brandsmedia.com

3. Purposes of processing

We process personal data for the following purposes:

  • Booking, management and reminders of appointments
  • Management of your customer account and booking history
  • Sending newsletters (only after explicit consent)
  • Sending birthday e-mails (after separate consent)
  • Answering requests sent via contact forms and e-mail
  • Security, fraud prevention and statutory retention obligations

4. Legal bases

Your data is processed on the following legal bases:

  • Art. 6(1)(b) GDPR for the performance of a contract (appointment booking, customer account)
  • Art. 6(1)(a) GDPR for processing based on your consent (newsletters, birthday e-mails)
  • Art. 6(1)(f) GDPR for legitimate interests (operational security, abuse prevention)
  • Art. 6(1)(c) GDPR for statutory retention obligations

5. Cookies and similar technologies

This website uses exclusively strictly necessary cookies that are required for the operation of the site, for example login session and language preference. These cookies are set on the basis of Art. 6(1)(f) GDPR and, where applicable, our legitimate interests. Tracking or marketing cookies are not set without your prior consent.

6. Newsletter and double opt-in

When you subscribe to our newsletter, we use the so-called double opt-in procedure. After you submit your e-mail address, we send you a confirmation e-mail containing an activation link. Your subscription only becomes effective once you click this link.

Double consent (shop and 2Brands Media)

By confirming, you give your explicit consent to two independent processing operations:

  1. Receiving the newsletter of with information about offers, promotions and news from this shop.
  2. Receiving platform updates from 2Brands Media GmbH, the technical operator of the booking platform, including information about new features, security notices or partner offers.

Both consents are voluntary and can be revoked independently of each other. Every newsletter e-mail contains an unsubscribe link that allows you to choose in detail which mails you no longer wish to receive.

Technical dispatch and proof of consent

Dispatch is technically carried out by 2Brands Media GmbH on behalf of the respective shop. We use the e-mail service Resend (see section 8). To document your consent, we store your e-mail address, the date and time of subscription, your IP address and the browser you used (user agent). This data is used exclusively to provide evidence in accordance with the German Act against Unfair Competition (UWG) and is not evaluated for marketing purposes.

Retention period for consent logs

Consent and revocation logs are retained for three years after the consent has been revoked. This period corresponds to the limitation period under the German Act against Unfair Competition (UWG).

7. Birthday e-mails

If you provide us with your date of birth and consent to its processing, we will send you a personal congratulatory e-mail on your birthday, possibly including a discount code. This consent is separate from the newsletter consent and can be revoked at any time via your customer account or by clicking the unsubscribe link in the birthday e-mail.

8. Sharing data with service providers

In order to provide our services, we use carefully selected service providers with whom we have concluded data processing agreements pursuant to Art. 28 GDPR:

  • Resend (Cookies, Inc.), San Francisco, USA. Sending transactional and newsletter e-mails. Data transfer based on Standard Contractual Clauses (Art. 46 GDPR).
  • Cloudflare, Inc., San Francisco, USA. CDN, DDoS protection and DNS. Data transfer based on Standard Contractual Clauses.
  • Hetzner Online GmbH, Gunzenhausen, Germany. Hosting of the booking platform. Processing exclusively within the EU.

Data is only transferred to third countries outside the EU/EEA if appropriate safeguards (in particular EU Standard Contractual Clauses) are in place.

9. Retention periods

  • Customer account: until deletion by you or after 36 months of inactivity
  • Appointment bookings: three years after the appointment date (statute of limitations)
  • Newsletter consents and revocations: three years after revocation
  • Invoice-related documents: ten years (commercial retention obligation)
  • Contact enquiries without contractual relationship: six months after the matter has been concluded

10. Your rights as a data subject

You have the right at any time to:

  • Access the personal data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7(3) GDPR)
  • Lodge a complaint with a supervisory authority (Art. 77 GDPR)

11. How to exercise your rights

For all matters relating to your data and rights, you can contact us informally:

We usually process your request within 30 days.

12. Status and updates

Status of this privacy policy: 2026-05-17-v1. We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or to changes in our services. The current version is always available on this page.

Beban Barber Shop 6.0