Privacy Policy under the General Data Protection Regulation (GDPR)
Last updated: 16 July 2026
This Privacy Policy explains how BEAD GmbH processes personal data when you visit our websites, contact us, or use our B2B retailer area. Personal data means any information relating to an identified or identifiable natural person.
1. Controller
BEAD GmbH
Tente 33
42929 Wermelskirchen
Germany
Telephone: +49 (0) 2196 8984642
Email: info@beadbags.de
Website: https://beadbags-shop.com
2. Data Protection Officer / Data Protection Contact
Stefan Schult
Tente 33
42929 Wermelskirchen
Germany
Telephone: +49 (0) 2196 8984642
Email: datenschutz@beadbags.de
3. General Principles and Legal Bases
We process personal data only insofar as this is necessary to operate the website, handle enquiries, initiate and perform contracts, comply with legal obligations, or protect legitimate interests. Depending on the processing activity, we rely in particular on the following legal bases:
- Article 6(1)(a) GDPR: consent, in particular for non-essential cookies or external content.
- Article 6(1)(b) GDPR: taking steps prior to entering into a contract and performance of a contract.
- Article 6(1)(c) GDPR: compliance with legal obligations, in particular retention obligations under commercial and tax law.
- Article 6(1)(f) GDPR: protection of legitimate interests, such as the secure, stable and commercially reasonable operation of our website, prevention of misuse, and handling of business communications.
Where we process data relating to contact persons, employees or representatives of a company who are not themselves the contracting party, processing is generally based on our legitimate interest in carrying out the business relationship pursuant to Article 6(1)(f) GDPR.
4. Provision of the Website and Server Log Files
When you access our websites, the web server processes technically necessary data. This may include, in particular, your IP address, date and time of access, the page or file requested, referrer URL, browser type and version, operating system, and internet service provider.
The processing is carried out to deliver the website, ensure technical stability and security, detect attacks and misuse, and analyse errors. The legal basis is Article 6(1)(f) GDPR. Log data is generally stored only for as long as required for these purposes. Where the hosting provider applies a specific shorter or longer period, the retention period is determined by the contractual and technical settings of the hosting package.
5. Hosting and Technical Service Providers
We may use carefully selected service providers for hosting, maintenance, backups, email delivery and other technical services. They receive personal data only to the extent necessary to provide the respective service. Where a service provider processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Article 28 GDPR.
Personal data is transferred to countries outside the European Union or the European Economic Area only where the requirements of Articles 44 et seq. GDPR are met, for example on the basis of an adequacy decision, appropriate safeguards, or a statutory derogation.
6. Cookies and Consent Management
Our websites may use technically necessary cookies or comparable technologies. These are required to provide the website, security functions, sessions, or functions expressly requested by the user. Where applicable, storage or access is based on Section 25(2) of the German Telecommunications and Digital Services Data Protection Act (TDDDG); subsequent processing is based on Article 6(1)(f) GDPR or Article 6(1)(b) GDPR.
Non-essential cookies, analytics tools or external content are used only where the required consent has been given. The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future through the cookie or privacy settings offered on the website.
7. B2B Retailer Area: Standard Orders and Customisation Enquiries
7.1 Purpose of the B2B Area
In the B2B retailer area, business customers can order preconfigured retailer packages or submit a non-binding customisation enquiry. Processing is carried out to review and handle the order or enquiry, communicate with the customer, prepare an order confirmation, perform the contract, organise production and delivery, issue invoices and maintain documentation.
7.2 Data Processed for Standard Orders
For a standard order, we process in particular:
- Company and contact details, in particular company name, contact person, email address and, where applicable, telephone number.
- Billing and delivery address and VAT identification number.
- The selected retailer package, quantity, pricing basis and, for Orange Signal or Pastel Beauty, the selected heart or anchor patch motif.
- Free-text information or comments, submission time, source page, and the documented time at which the Privacy Policy and B2B Terms and Conditions were acknowledged.
- Technical status information relating to email delivery and order processing.
A standard order constitutes a binding order. The automatically generated acknowledgement of receipt is not an order confirmation. Processing is carried out for pre-contractual steps and contract performance pursuant to Article 6(1)(b) GDPR. Where obligations under commercial or tax law apply, Article 6(1)(c) GDPR is an additional legal basis.
7.3 Data Processed for Customisation Enquiries
For a customisation enquiry, we process, in addition to company and contact details, in particular:
- The selected product base and requested quantity.
- Information on whether a motif or logo, idea or theme already exists, or whether advice from Beadbags is requested.
- Motif and wording requests, descriptions, reference links, information relating to a place, institution, target group, intended use, desired effect, symbols or landmarks.
- Free-text information and comments.
- Confirmations regarding the right to use supplied content and the use of single-colour white screen printing.
- Any uploaded files.
Processing is carried out to handle the non-binding enquiry and to take pre-contractual steps pursuant to Article 6(1)(b) GDPR. Where company contact persons are concerned, processing may additionally be based on Article 6(1)(f) GDPR.
7.4 File Uploads
As part of a customisation enquiry, up to five files may be uploaded in JPG, JPEG, PNG or PDF format, with a maximum size of 8 MB per file. Files may contain motifs, logos, sketches, photographs, references or other production-related content.
Uploaded files are not displayed publicly in the WordPress media library. They are stored under randomly generated file names in a protected server directory. Direct public access is technically blocked. Downloads are available only to logged-in, authorised administrators or shop managers through a protected download link.
Please do not submit special categories of personal data within the meaning of Article 9 GDPR or personal data relating to third parties unless this is necessary for the enquiry. Where files contain third-party rights or personal data, the sender must be authorised to submit and use them.
7.5 Storage in the WordPress Backend and Access Authorisation
Orders and customisation enquiries are stored as non-public records in the WordPress backend. Access is limited to authorised user roles, in particular administrators and expressly authorised shop managers. The stored information is not accessible through the public website.
When a B2B record is permanently deleted, the upload files assigned to that record are also deleted by the B2B system. Merely moving a record to the WordPress trash does not constitute permanent deletion.
7.6 Email Notifications and WP Mail SMTP
After submission, the B2B system generates an internal notification to Beadbags and an acknowledgement of receipt to the email address provided. Delivery is handled via the WordPress email function and the configured SMTP delivery channel. The email data required for delivery is transmitted to the email or SMTP service provider used.
The B2B record documents whether the internal notification and the customer acknowledgement were technically initiated. The order or enquiry remains stored in the WordPress backend even if an email could not be delivered successfully.
7.7 Technical Protection against Misuse
Technical security measures are used to protect the B2B form, including a security check, an invisible honeypot field, a minimum period between page access and submission, and short-term submission rate limiting. For rate limiting, a technical hash value is generated from the IP address and stored temporarily for approximately 20 seconds. The sole purpose is to prevent automated submissions or multiple submissions in immediate succession. The legal basis is Article 6(1)(f) GDPR.
7.8 Recipients of B2B Data
Within BEAD GmbH, access is limited to persons who require the data for processing. Depending on the order, data may also be transferred to the following categories of recipients:
- Hosting, IT, maintenance, backup and email service providers.
- Shipping and logistics providers, where required for delivery.
- Tax advisers, accounting providers, banks or public authorities, where required for invoicing, payment processing or legal obligations.
- Production or design partners, where required for commissioned customisation. Only the data necessary for the specific service is transferred.
7.9 Retention Period in the B2B Area
Standard orders and the resulting contractual and accounting records are stored in accordance with retention obligations under commercial and tax law. Depending on the type of document, retention periods of six, eight or ten years may apply. The period generally begins at the end of the calendar year in which the transaction was completed or the document was created.
Customisation enquiries that do not result in an order are generally deleted no later than twelve months after processing has been completed, unless further communication, consent, a legal obligation or a legitimate interest—particularly the establishment, exercise or defence of legal claims—justifies longer storage. If the enquiry results in an order, the retention periods applicable to contractual and business records apply.
Technical email and security logs are stored only for as long as necessary to monitor delivery, troubleshoot errors and ensure security.
7.10 Requirement to Provide Data and Automated Decision-Making
Information marked as mandatory is required to process an order or enquiry. Without this information, the relevant function cannot be used. No decision based solely on automated processing, including profiling within the meaning of Article 22 GDPR, takes place in the B2B area.
8. Contact by Email or Telephone
If you contact us by email or telephone, we process the information you provide in order to handle your enquiry. Where the contact concerns a contract or pre-contractual measure, Article 6(1)(b) GDPR is the legal basis. In other cases, processing is based on Article 6(1)(f) GDPR because we have a legitimate interest in handling business enquiries.
The data is deleted when the communication has ended and no statutory retention obligations or legitimate interests prevent deletion.
9. Web Analytics with WP Statistics
According to the website configuration currently published, the WordPress plugin WP Statistics is used to analyse website usage statistically. The analysis is used to measure reach and improve our services. Where the analysis is carried out without personal identifiers and without storing full IP addresses, it is based on Article 6(1)(f) GDPR. Where individual functions require consent, processing takes place only after consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Further information on the provider’s privacy practices is available at https://wp-statistics.com/privacy-and-policy/.
10. Embedded Content and External Services
Individual pages may include content or services from external providers. Where such content is not technically necessary, it is activated only after consent. On activation, the respective provider may process, in particular, your IP address, browser data, the page accessed and, where applicable, cookie or account data. The legal bases are Article 6(1)(a) GDPR and Section 25(1) TDDDG.
10.1 YouTube
We may embed videos from YouTube. The provider for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Where possible, we use enhanced privacy mode. Data is transferred to Google or YouTube no later than when a video is played. Further information: https://policies.google.com/privacy?hl=en.
10.2 Issuu and Yumpu
We may display digital catalogues or publications through Issuu and Yumpu. The providers are Issuu Inc. and i-magazine AG, Gewerbestrasse 3, 9444 Diepoldsau, Switzerland. When embedded publications are accessed or activated, usage, device and connection data may be processed and cookies may be set. Further information: https://issuu.com/legal/privacy and https://www.yumpu.com/en/info/privacy_policy.
10.3 Instagram
We may embed content from Instagram or link to Instagram. The provider for users in the European Economic Area is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Where content is embedded and activated, data may be transferred to Meta and, for logged-in users, associated with the respective account. Further information: https://privacycenter.instagram.com/policy/.
10.4 Google Fonts – External Requests Blocked
Google Fonts are not loaded directly from Google servers on our websites. External requests to fonts.googleapis.com and fonts.gstatic.com are blocked by our privacy and consent configuration; where fonts are used, they are provided locally. Therefore, no IP addresses, browser data or other personal data are transmitted to Google for font retrieval merely by visiting the website. If this technical configuration changes in the future, this Privacy Policy will be updated accordingly.
11. Data Security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access or disclosure. These measures include, in particular, access restrictions, role-based permissions, protected upload directories, randomly generated file names, secure download procedures and encrypted website transmission where technically available.
Despite these measures, data transmission over the internet can never be completely free of risk. Particularly sensitive information should be transmitted only through suitable secure communication channels.
12. Rights of Data Subjects
Subject to the applicable statutory requirements, you have in particular the following rights:
- The right of access to personal data concerning you pursuant to Article 15 GDPR.
- The right to rectification of inaccurate data or completion of incomplete data pursuant to Article 16 GDPR.
- The right to erasure pursuant to Article 17 GDPR, unless statutory retention obligations or other overriding grounds apply.
- The right to restriction of processing pursuant to Article 18 GDPR.
- The right to data portability pursuant to Article 20 GDPR, where the statutory requirements are met.
- The right to object to processing based on Article 6(1)(e) or (f) GDPR pursuant to Article 21 GDPR.
- The right to withdraw consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.
To exercise your rights, please contact datenschutz@beadbags.de or use the contact details set out above.
13. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for BEAD GmbH is, in particular:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
Telephone: +49 (0) 211 38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de
14. Changes to this Privacy Policy
We update this Privacy Policy when legal requirements, services used or processing procedures change. The version published on the website at the relevant time applies.
