M cenaly.ru
🇩🇪 Германия · Клиенты

Privacy Notice (Datenschutzerklärung)

Website/business privacy notice under Article 13 of the Datenschutz-Grundverordnung (DSGVO, the German-facing text for the EU GDPR) plus the Bundesdatenschutzgesetz (BDSG) — a Data Protection Officer (Datenschutzbeauftragter "DSB") is mandatory once at least 20 people are continuously involved in automated processing of personal data (§ 38 BDSG), and cookie/tracking consent must comply with § 25 TDDDG.

Все шаблоны
Страна
🇩🇪 Германия
Раздел
Клиенты
Язык текста
EN
Версия
1

⚠️ Это шаблон-болванка, а не юридическая консультация: перед использованием проверьте текст у юриста и адаптируйте под своё законодательство и конкретную ситуацию.

У этого шаблона опциональных разделов нет: текст одинаковый для всех. Поля показаны подписями: на сайте шаблон только для чтения, значения подставляются в системе.

Документ

PRIVACY NOTICE (DATENSCHUTZERKLÄRUNG)

Business name (responsible party), Business address Effective date: Effective date

This notice explains how Business name (responsible party) (the "Company", the responsible party / controller) collects, uses and protects personal data, in accordance with Article 13 of the EU General Data Protection Regulation (Datenschutz-Grundverordnung "DSGVO") and the Bundesdatenschutzgesetz "BDSG".

1. RESPONSIBLE PARTY 1.1. Business name (responsible party) is responsible for the processing described in this notice (Art. 4 Nr. 7 DSGVO). 1.2. Data Protection Officer (Datenschutzbeauftragter), if appointed: Data Protection Officer (Datenschutzbeauftragter), if any 1.3. ⚠️ Under § 38 BDSG, appointing a DSB is mandatory once at least 20 people are continuously engaged in the automated processing of personal data — this is easy to reach for a small restaurant/hotel/shop once part-time staff, POS terminals and marketing tools are counted.

2. WHAT DATA WE COLLECT AND WHY 2.1. What data is collected and why

3. PURPOSES AND LEGAL BASIS 3.1. Purposes and legal basis of processing

4. RECIPIENTS AND TRANSFERS ABROAD 4.1. Recipients & transfers abroad 4.2. Transfers of personal data outside the EU/EEA require either an adequacy decision covering the destination country or appropriate safeguards (e.g. EU standard contractual clauses).

5. RETENTION 5.1. Retention period

6. YOUR RIGHTS 6.1. Data subject rights 6.2. You may also lodge a complaint with the competent state data protection authority (Landesdatenschutzbehörde) if you believe your data has been mishandled.

7. COOKIES AND TRACKING 7.1. Cookies/tracking consent 7.2. Under § 25 Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG), storing or reading information on a visitor's device (cookies, tracking pixels, etc.) beyond what is strictly necessary for the service requested requires the visitor's prior, informed consent — a clear cookie-consent banner with a genuine "reject" option is required, not just an "accept" button.

8. CONTACT US 8.1. Questions about this notice, or requests to exercise your rights, may be sent to Privacy contact email.

⚠️ If CCTV, guest Wi-Fi logging, or staff monitoring is used, describe it explicitly in section 2 above and register it in the internal record of processing activities (Verzeichnis von Verarbeitungstätigkeiten, Art. 30 DSGVO) — this is typically the first document a supervisory authority asks for.

— — — ⚠️ This is a boilerplate template, not legal advice. German employment, consumer-protection, data-protection and workplace-safety law (BGB, Nachweisgesetz "NachwG", ArbSchG, MiLoG, SGB IV, DSGVO/BDSG, DDG, EGBGB Art. 246a) changes frequently and includes sector-specific exceptions — notably § 2a Gesetz gegen Schwarzarbeit "SchwarzArbG", which keeps the Gaststätten- und Beherbergungsgewerbe (restaurants and hotels) on paper-only Schriftform even after the BEG IV digitalisation reform. Statutory figures (Mindestlohn, Minijob-Grenze) are re-indexed periodically — have this document reviewed and adapted by a German employment/legal advisor (Rechtsanwalt/Steuerberater) and verified against the current rates before use. Where a German-language version of this document is also used, that version prevails in case of conflict.

Поля документа

Поля выключенных разделов приглушены — их не спрашивают.

  • Business name (responsible party)строкаобязательноеавто
  • Business addressтекстобязательноеавто
  • Privacy contact emailстрокаобязательное
  • Data Protection Officer (Datenschutzbeauftragter), if anyстроканеобязательное

    Mandatory once ≥20 persons are continuously involved in automated data processing, § 38 BDSG

  • What data is collected and whyтекстобязательное

    e.g. bookings, orders, CCTV, guest Wi-Fi, loyalty/marketing data

  • Purposes and legal basis of processingтекстобязательное
  • Recipients & transfers abroadтекстобязательное

    Processors, and any transfer outside the EU/EEA

  • Retention periodтекстобязательное
  • Data subject rightsтекстобязательное

    Access, rectification, erasure, objection, and the right to complain to the state data protection authority

  • Cookies/tracking consentтекстобязательное

    Consent required per § 25 TDDDG before non-essential cookies/tracking are set

  • Effective dateдатаобязательное

В Cenaly этот шаблон заполняется автоматически

2 из 11 полей берутся из карточки компании, сотрудника или контрагента, опросник можно надиктовать ИИ, а готовый документ выдаётся с номером, PDF и подтверждением ознакомления.