Legal

Privacy policy

How we process personal data on this website, on what legal basis this happens and which rights you have.

1.Data protection at a glance

General notes

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on data protection can be found in the privacy policy set out below this text.

Data collection on this website

Who is responsible for the data collection on this website?

Data processing on this website is carried out by the website operator. You will find their contact details in the section “Note on the controller” in this privacy policy.

How do we collect your data?

Your data is collected firstly by you providing it to us. This may be data you enter when registering or in your user profile, for example.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or the time the page was accessed). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure the website is provided without errors. Other data may be used to analyse your user behaviour.

Which rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have a right to demand the rectification or erasure of this data. If you have given consent to data processing, you can withdraw that consent at any time with effect for the future. You also have the right, under certain circumstances, to demand the restriction of the processing of your personal data. Furthermore, you have a right to lodge a complaint with the competent supervisory authority.

You can contact us at any time about this and about any other questions on the subject of data protection.

2.Hosting and content delivery networks (CDN)

We host the content of our website with the following provider:

Amazon Web Services (AWS)

The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg (hereinafter AWS).

When you visit our website, your personal data is processed on AWS servers. Storage takes place in data centres in the European Union (AWS region eu-central-1, Frankfurt am Main). Personal data may also be transferred to AWS's parent company in the USA. The data transfer to the USA is based on the EU standard contractual clauses. You will find details here: https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/.

For further information please see the AWS privacy policy: https://aws.amazon.com/de/privacy/?nc1=f_pr.

AWS is used on the basis of Art. 6 (1) (f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where corresponding consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time.

The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000TOWQAA4&status=Active

Amazon CloudFront CDN

We use the content delivery network Amazon CloudFront CDN. The provider is Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg (hereinafter “Amazon”).

Amazon CloudFront CDN is a globally distributed content delivery network. Technically, the transfer of information between your browser and our website is routed through the content delivery network. This allows us to increase the worldwide availability and the performance of our website.

The use of Amazon CloudFront CDN is based on our legitimate interest in providing our web offering as error-free and securely as possible (Art. 6 (1) (f) GDPR).

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. You will find details here: https://aws.amazon.com/de/blogs/security/aws-gdpr-data-processing-addendum/.

You will find further information on Amazon CloudFront CDN here: https://d1.awsstatic.com/legal/privacypolicy/AWS_Privacy_Notice__German_Translation.pdf.

The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000TOWQAA4&status=Active

3.General notes and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.

We point out that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.

Note on the controller

The controller for data processing on this website is:

Mukibasar
Owner: Martin Januschke
Josef-Karl-Str. 3
92421 Schwandorf, Germany

The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g. names, email addresses etc.).

Retention period

Unless a more specific retention period is stated within this privacy policy, your personal data remains with us until the purpose for the data processing no longer applies. If you assert a justified request for erasure or withdraw consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case the data is deleted once those grounds cease to apply.

General notes on the legal bases for data processing on this website

If you have consented to the data processing, we process your personal data on the basis of Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR where special categories of data pursuant to Art. 9 (1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, the data processing is additionally based on Art. 49 (1) (a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), the data processing is additionally based on § 25 (1) TTDSG. Consent can be withdrawn at any time. If your data is required to perform a contract or to carry out pre-contractual measures, we process your data on the basis of Art. 6 (1) (b) GDPR. Furthermore, we process your data where this is necessary to comply with a legal obligation, on the basis of Art. 6 (1) (c) GDPR. Data processing may also take place on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. The legal bases relevant in each individual case are set out in the following paragraphs of this privacy policy.

Recipients of personal data

In the course of our business activities we work with various external bodies. In some cases this also requires the transfer of personal data to these external bodies. We only pass personal data to external bodies where this is necessary to perform a contract, where we are legally obliged to do so (e.g. passing data to tax authorities), where we have a legitimate interest in the transfer pursuant to Art. 6 (1) (f) GDPR, or where another legal basis permits the transfer. When engaging processors we only pass on our customers' personal data on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your explicit consent. You can withdraw consent already given at any time. The lawfulness of the data processing carried out until the withdrawal remains unaffected by the withdrawal.

Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)

IF THE DATA PROCESSING IS BASED ON ART. 6 (1) (E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 (1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSES OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 (2) GDPR).

Right to lodge a complaint with the competent authority

In the event of infringements of the GDPR, data subjects have a right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or the place of the alleged infringement. This right to complain exists without prejudice to other administrative or judicial remedies.

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.

Information, rectification and erasure

Within the framework of the applicable statutory provisions you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing, and where applicable a right to rectification or erasure of this data. You can contact us at any time about this and about any other questions on the subject of personal data.

Right to restriction of processing

You have the right to demand the restriction of the processing of your personal data. You can contact us about this at any time. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of the personal data we store about you, we usually need time to check this. For the duration of the check you have the right to demand the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can demand the restriction of the data processing instead of erasure.
  • If we no longer need your personal data but you need it to exercise, defend or establish legal claims, you have the right to demand the restriction of the processing of your personal data instead of erasure.
  • If you have lodged an objection pursuant to Art. 21 (1) GDPR, a balancing of your interests and ours has to be carried out. As long as it has not been determined whose interests prevail, you have the right to demand the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data – apart from being stored – may only be processed with your consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the browser's address bar changing from “http://” to “https://” and by the padlock symbol in your browser bar.

When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Encrypted payment transactions on this website

If, after concluding a paid contract, there is an obligation to send us your payment details (e.g. account number for a direct debit authorisation), this data is required for payment processing.

Payment transactions using the common means of payment (Visa/ MasterCard, direct debit) take place exclusively via an encrypted SSL/TLS connection. You can recognise an encrypted connection by the browser's address bar changing from “http://” to “https://” and by the padlock symbol in your browser bar.

With encrypted communication, the payment details you transmit to us cannot be read by third parties.

Objection to advertising emails

The use of contact data published under the obligation to provide an imprint for sending advertising and information material that has not been expressly requested is hereby objected to. The site operators expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam emails.

4.Data collection on this website

Cookies

Our web pages use so-called “cookies”. Cookies are small data packets and do no harm to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are deleted automatically after your visit ends. Permanent cookies remain stored on your device until you delete them yourself or your web browser deletes them automatically.

Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable certain services of third-party companies to be integrated within web pages (e.g. cookies for handling payment services).

Cookies have various functions. Numerous cookies are technically necessary because certain website functions would not work without them (e.g. the shopping basket function or the display of videos). Other cookies may be used to evaluate user behaviour or for advertising purposes.

Cookies required to carry out the electronic communication process, to provide certain functions you have requested (e.g. for the shopping basket function) or to optimise the website (e.g. cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6 (1) (f) GDPR unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, the processing takes place exclusively on the basis of that consent (Art. 6 (1) (a) GDPR and § 25 (1) TTDSG); consent can be withdrawn at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be limited.

Which cookies and services are used on this website can be found in this privacy policy.

Enquiries by email or telephone

If you contact us by email or telephone, your enquiry including all personal data resulting from it (name, enquiry) is stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR where your enquiry is connected with the performance of a contract or is necessary to carry out pre-contractual measures. In all other cases the processing is based on our legitimate interest in effectively handling the enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) where this has been requested; consent can be withdrawn at any time.

The data you send us with your enquiry remains with us until you ask us to delete it, withdraw your consent to its storage or the purpose for storing the data no longer applies (e.g. after your request has been dealt with). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.

Registration on this website

You can register on this website in order to use additional functions on the site. We use the data entered for this purpose only to use the respective offer or service for which you registered. The mandatory details requested during registration must be provided in full. Otherwise we will refuse the registration.

For important changes, for example to the scope of the offer or for technically necessary changes, we use the email address provided during registration to inform you.

The data entered during registration is processed for the purpose of carrying out the usage relationship established by the registration and where applicable to initiate further contracts (Art. 6 (1) (b) GDPR).

The data collected during registration is stored by us for as long as you are registered on this website and is deleted afterwards. Statutory retention periods remain unaffected.

5.The MukiBasar app

At app.mukibasar.de we provide the MukiBasar app, with which organizers can organize bazaars and sellers can take part in them. The following sections describe the data processing in the app.

Responsibilities: platform and bazaars

For the processing of your platform account data (registration, sign-in, profile, account settings, technical operation) we are the controller within the meaning of Art. 4 no. 7 GDPR.

If you register as a seller for a bazaar, we process your bazaar-related data (registration, articles, sales, hand-in and settlement data as well as the profile data visible to the organizer) on behalf of the respective organizer. The controller for this processing is the organizer; we are the processor pursuant to Art. 28 GDPR. We conclude a data processing agreement with every organizer for this purpose. You will find more detailed information for sellers in the privacy information for sellers.

Registration and sign-in by email code

Signing in to the app is passwordless: you enter your email address and receive a one-time sign-in code or sign-in link by email. To provide your user account we process your email address as well as the data you enter in your profile (name, address, phone number). The address is converted into geo-coordinates in order to show bazaars near you (see “Map display and geocoding”). The legal basis is Art. 6 (1) (b) GDPR (performance of the usage relationship).

Hosting of the app data (Supabase)

We operate the database, authentication and file storage of the app with Supabase. The provider is Supabase, Inc. (USA). Our Supabase project is hosted exclusively in the AWS region eu-central-1 (Frankfurt am Main, Germany). A data processing agreement is in place with Supabase; insofar as data may be transferred to third countries (e.g. in the course of support access), this is based on the EU standard contractual clauses. Details: https://supabase.com/privacy. The legal basis is Art. 6 (1) (b) GDPR as well as our legitimate interest in the secure and reliable operation of the app (Art. 6 (1) (f) GDPR).

Transactional emails (Amazon SES)

To send transactional emails (e.g. confirmations of bazaar registrations, waiting list, hand-in, reminders and invitations) we use Amazon Simple Email Service (SES) of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg, in the AWS region eu-central-1 (Frankfurt am Main). The recipient's email address, display name and the content of the respective notification are processed. Our internal delivery log is deleted after 90 days. The legal basis is Art. 6 (1) (b) GDPR.

Error diagnostics (Sentry)

To detect and remedy technical errors we use Sentry. The provider is Functional Software, Inc. dba Sentry (USA). We use Sentry's EU data region; error reports are processed via servers in the European Union (ingest.de.sentry.io, Frankfurt am Main). Error reports contain technical details about the error that occurred (e.g. error message, programme state, browser and device information). We do not transmit IP addresses to Sentry and filter email addresses out of error messages automatically. The legal basis is our legitimate interest in providing the app stably and free of errors (Art. 6 (1) (f) GDPR). Details: https://sentry.io/privacy/.

Profile pictures (avatars)

You can voluntarily upload a profile picture. Profile pictures are stored in our file storage (Supabase, Frankfurt am Main) and are only visible to signed-in users of the app via time-limited, signed retrieval links. The legal basis is your consent given by uploading (Art. 6 (1) (a) GDPR); you can remove the profile picture in the settings at any time.

Map display and geocoding (OpenStreetMap/Nominatim)

To display maps (e.g. bazaar venues) the app loads map tiles directly from the servers of the OpenStreetMap Foundation (OSMF), St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. Your IP address is transmitted to the OSMF in the process.

If you store an address in your profile or enter a venue when creating a bazaar, this address is transmitted directly from your browser to the OSMF's geocoding service Nominatim (nominatim.openstreetmap.org) for conversion into geo-coordinates. The address entered and your IP address are passed on to the OSMF. Under data protection law the United Kingdom is regarded as a safe third country (adequacy decision of the EU Commission). The legal basis is Art. 6 (1) (b) GDPR (provision of the functions you use) as well as our legitimate interest in an appealing presentation of our offering (Art. 6 (1) (f) GDPR).

Visibility of profile data to organizers

When you register for a bazaar, the administrators of the organizing association can view your profile data (name, address, email address, phone number) as well as your bazaar-related data (articles, sales, hand-in status) insofar as this is necessary to run the bazaar. The controller for this processing is the respective organizer (see “Responsibilities” above).

Retention period, account deletion and data export

We store your account data for as long as your user account exists. You can permanently delete your account yourself at any time in the app settings; this deletes your profile, your articles and your memberships. Statutory retention periods (e.g. for settlement data) remain unaffected. On request to the email address stated in the imprint we will provide you with a copy of the data we store about you in a common, machine-readable format (Art. 20 GDPR).

6.Analytics tools

Pirsch Analytics

This website uses Pirsch Analytics, a privacy-friendly web analytics service. The provider is Emvi Software GmbH, Hamburg, Germany. Pirsch works without cookies and without cross-device tracking. When a page is accessed, the page requested, the referrer, browser and device type as well as the country of origin are recorded, among other things. The IP address is not stored but is only used to form an identifier valid for a maximum of 24 hours that cannot be reversed. The data is processed on servers in the European Union.

Pirsch is used on the basis of our legitimate interest in the statistical analysis of visitor behaviour in order to optimise our web offering (Art. 6 (1) (f) GDPR). Since Pirsch does not set cookies and neither stores nor reads information on the device, consent pursuant to § 25 TTDSG is not required. Details: https://pirsch.io/privacy.

7.Plugins and tools

OpenStreetMap

We use the map service of OpenStreetMap (OSM).

We embed the map material of OpenStreetMap from the server of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The United Kingdom is regarded as a safe third country under data protection law. This means that the United Kingdom has a level of data protection corresponding to the level of data protection in the European Union. When the OpenStreetMap maps are used, a connection to the servers of the OpenStreetMap Foundation is established. In the process your IP address and further information about your behaviour on this website may be forwarded to the OSMF, among other things. For this purpose OpenStreetMap may store cookies in your browser or use comparable recognition technologies.

OpenStreetMap is used in the interest of an appealing presentation of our online offerings and so that the places we state on the website can be found easily. This constitutes a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. Where corresponding consent has been requested, the processing takes place exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be withdrawn at any time.

Nominatim (place search)

On the “Bazaar dates” page you can search for a place in order to display bazaars near you. For this purpose your search entry is transmitted directly from your browser to the geocoding service Nominatim of the OpenStreetMap Foundation (nominatim.openstreetmap.org); your IP address is also passed on to the OSMF. If you optionally use your browser's location determination, this only happens after your explicit confirmation; your location is then used only locally in your browser. The legal basis is Art. 6 (1) (b) GDPR (provision of the function you requested).

8.eCommerce and payment providers

Processing of customer and contract data

We collect, process and use personal customer and contract data to establish, structure the content of and amend our contractual relationships. We only collect, process and use personal data about the use of this website (usage data) insofar as this is necessary to enable the user to use the service or to bill for it. The legal basis for this is Art. 6 (1) (b) GDPR.

The customer data collected is deleted after the order has been completed or the business relationship has ended and any applicable statutory retention periods have expired. Statutory retention periods remain unaffected.

Transfer of data when concluding contracts for services and digital content

We only transfer personal data to third parties where this is necessary in the course of handling the contract, for example to the credit institution commissioned with the payment processing.

No further transfer of the data takes place, or only if you have explicitly consented to the transfer. Your data is not passed on to third parties without explicit consent, for example for advertising purposes.

The basis for the data processing is Art. 6 (1) (b) GDPR, which permits the processing of data to perform a contract or pre-contractual measures.

Payment services

We integrate payment services of third-party companies on our website. When you make a purchase from us, your payment data (e.g. name, payment amount, bank details, credit card number) is processed by the payment service provider for the purpose of payment processing. The respective contractual and data protection provisions of the respective providers apply to these transactions. Payment service providers are used on the basis of Art. 6 (1) (b) GDPR (performance of the contract) and in the interest of a payment process that is as smooth, convenient and secure as possible (Art. 6 (1) (f) GDPR). Insofar as your consent is requested for certain actions, Art. 6 (1) (a) GDPR is the legal basis for the data processing; consent can be withdrawn at any time with effect for the future.

We use the following payment services / payment service providers on this website:

Stripe

The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter “Stripe”).

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. You will find details here: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation.

You can read details about this in Stripe's privacy policy at the following link: https://stripe.com/de/privacy.

Back to the home page