Privacy Policy
1. Data Controller
The data controller responsible for the collection, processing and use of personal data under data protection law is:
Agentur kama.
Katharina Glas
Schönberg 65
8411 Hengsberg
Austria
Tel: +43 664 4708987
Email: hello@buyganic.com
VAT ID: ATU 70970112
This privacy policy is intended to inform you about the collection, processing and use (hereinafter referred to as “use”) of personal data. You will also find out how to object to the use of your personal data in accordance with applicable data protection regulations.
2. Collection, Processing and Use of Personal Data
Personal data refers to information relating to your personal or factual circumstances, especially your name, date of birth, email address, telephone number, or postal address.
We use the personal data you provide only to the extent necessary to establish, carry out, or terminate a legal or similar contractual relationship with you, or to provide a service you have requested. This may include newsletter subscriptions or responding to inquiries. We use your data solely to handle your request. It is entirely your decision whether to share your data for these purposes.
buyganic Newsletter
If you wish to subscribe to our newsletter, we require your email address and information that allows us to verify that you are the owner of the email address and agree to receive the newsletter. No further data is collected or only on a voluntary basis. We use this data exclusively for sending the requested information and do not share it with third parties.
The processing of data entered in the newsletter registration form is based solely on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke your consent at any time, for example via the “unsubscribe” link in the newsletter. The legality of prior data processing is not affected by the revocation.
Your data will be stored until you unsubscribe and will be deleted afterwards. Any data stored for other purposes remains unaffected.
BREVO
Use of the email service provider “Brevo”
We use Brevo (Sendinblue GmbH) to manage contacts and send newsletters or messages. These services enable us to track message activity (e.g. whether and when the message was read, which links were clicked, etc.).
-
Brevo Email (Sendinblue GmbH)
Personal data collected: cookies, email, usage data
Processing locations: Germany, France
Privacy Policy: https://www.brevo.com/de/legal/privacypolicy/
-
Brevo Marketing Automation
Allows user profile creation and message automation.
Same data, same processing locations, same policy as above.
Data Processing Agreement
We have signed a data processing agreement with Brevo, committing them to protect our customers’ data and not share it with third parties.
WhatsApp Newsletter / Contact via WhatsApp
We use Brevo (Sendinblue GmbH) for WhatsApp messaging and newsletters. Any data you provide will be processed and stored by Brevo. Brevo collects and processes data independently; for more information, see Brevo’s privacy policy.
Your data will only be used for communication purposes and deleted upon request. You can unsubscribe at any time using the link provided in the message.
When contacting us via WhatsApp, we use your phone number to communicate and may also process your WhatsApp name, device, profile picture, messages, and shared files.
Communication is stored in transcripts to maintain context. Read receipts may also be recorded to manage active/inactive contacts.
WhatsApp Ireland is the controller under GDPR. WhatsApp may transfer data outside the EU and combine it with other services. We have no influence on this.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
3. Duration of Storage
Your data is stored only as long as needed for the purpose it was collected or to meet legal obligations.
If you’ve given us consent for advertising (e.g. newsletter), we’ll store your data until you revoke that consent, which you can do at any time.
4. Limited Disclosure
We may share data with affiliated companies or external service providers acting on our behalf (e.g. mailing samples, sending marketing material, or handling giveaways). These providers are obligated to handle your data in accordance with this privacy policy and data protection law.
We do not sell, rent, or share data with third parties without your consent.
5. Use of Cookies and Web Analytics
We use cookies on our website. You can adjust your cookie preferences at any time.
We also use Google Analytics for web analysis. This tool uses cookies. You can prevent cookie storage via your browser or by disabling performance cookies.
Details:
-
Google Analytics (Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA, USA)
Uses cookies to analyze usage and provide reports. IP anonymization is enabled, meaning your IP is truncated within the EU/EEA.
More info:
-
etracker
This site uses etracker (etracker GmbH) to collect anonymized data for marketing and optimization. Usage profiles may be created under pseudonyms. No personal identification takes place. Data collection and storage can be objected to at any time.
6. Social Plug-ins
Provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, USA
Features from Instagram may be embedded. If logged in to your Instagram account and interact with our content, Instagram may link this to your account.
Privacy Policy: https://instagram.com/about/legal/privacy
7. Use of Payment Providers
PayPal
Provider: PayPal (Europe) S.à.r.l. et Cie, S.C.A., Luxembourg
When selecting PayPal, your payment data will be shared with PayPal.
Legal basis:
-
Art. 6 para. 1 lit. a GDPR (consent)
-
Art. 6 para. 1 lit. b GDPR (contractual necessity)
Consent can be revoked at any time. Past processing remains lawful.
Stripe
Provider: Stripe, 510 Townsend St., San Francisco, CA, USA
Legal basis:
-
Art. 6 para. 1 lit. f GDPR (legitimate interest)
-
Art. 6 para. 1 lit. b GDPR (contract fulfillment)
Shared data: name, email, customer/order number, payment details, transaction data, etc.
Stripe acts as both controller and processor. It complies with EU Standard Contractual Clauses (SCCs).
More info: https://stripe.com/privacy-center/legal
Data is stored until payment completion, including refunds and fraud prevention.
8. Contact, Access, Revocation, Blocking, Deletion
You may object to the future use of your personal data at any time, request correction, blocking, partial or full deletion, or access to the data stored. Simply contact us by email at hello@buyganic.com – no formalities required.
9. Data Security
We implement technical and organizational measures to protect your data from loss, alteration, or unauthorized access. These measures are regularly improved as technology evolves.
10. Updates and Changes
Parts of this policy may be updated or changed without prior notice. Please review this privacy policy before using our website to stay informed.
Last updated: August 2025