Privacy Policy
Last updated: 30 July 2026
We take the protection of your personal data seriously. This Privacy Policy explains how personal data is processed when you visit wietproef.info, create or use a user account, or contact us through the website.
1. Controller
The controller responsible for processing personal data on this website is:
Wietproef.info
Email: contact@wietproef.info
Website: https://wietproef.info
The controller is the person or organisation that determines the purposes and means of processing personal data.
No data protection officer has been appointed. Questions concerning privacy or the processing of your personal data can be sent to the email address above.
2. General information about data processing
We process personal data only where this is necessary to:
- provide and secure the website;
- respond to inquiries;
- create and manage user accounts;
- provide access to restricted website content;
- send account-related and transactional messages;
- comply with legal obligations; or
- protect our website and users against misuse and security threats.
Depending on the processing activity, the legal basis may be:
- your consent under Article 6(1)(a) GDPR;
- the performance of a contract or steps taken at your request under Article 6(1)(b) GDPR;
- compliance with a legal obligation under Article 6(1)(c) GDPR; or
- our legitimate interests under Article 6(1)(f) GDPR.
3. Visiting the website and server log files
When you visit this website, technical information is automatically transmitted by your browser and may be recorded in server log files.
This information may include:
- your IP address;
- the date and time of access;
- the requested page or file;
- the referring website;
- browser type and version;
- operating system and device information;
- the amount of data transferred; and
- technical status and error information.
This processing is necessary to display the website, maintain its technical stability, identify errors, prevent misuse and protect the website against attacks.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and technically functional operation of the website.
Server log data is retained only for as long as it is required for operational and security purposes. It may be retained for longer where this is necessary to investigate a security incident or comply with a legal obligation.
4. Hosting
This website is currently hosted by:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
STRATO may process technical access data and other information stored through the website on our behalf.
We use an external hosting provider because hosting is necessary to make the website available securely and reliably. The legal basis is Article 6(1)(f) GDPR.
Where required, the hosting provider processes personal data under a data processing agreement in accordance with Article 28 GDPR.
5. Contact form and email communication
When you contact us through the contact form or by email, we process the information you provide.
Depending on the inquiry, this may include:
- your name;
- your email address;
- the subject of your inquiry;
- your message;
- attachments or other information you voluntarily provide; and
- technical information needed to transmit the form and prevent misuse.
We process this information to respond to your inquiry and communicate with you.
The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in responding to inquiries. Where your message concerns a possible agreement, cooperation or other business relationship, the legal basis may also be Article 6(1)(b) GDPR.
We normally retain ordinary inquiries for up to 12 months after the conversation has ended. Information may be retained for longer where this is necessary for contractual, legal, accounting, evidentiary or security reasons.
We do not use contact-form messages for advertising or newsletters unless you have given separate consent.
We generally aim to respond within five business days.
6. User accounts and membership access
Certain content and functions may only be available to registered users.
When you register or manage an account, we may process:
- your email address;
- your chosen username or account name;
- your password in encrypted or hashed form;
- your membership or access level;
- the date of registration;
- account status and membership history;
- login and account activity;
- password-reset and account-confirmation information; and
- other information you voluntarily enter in your account.
We process this data to:
- create and administer your account;
- authenticate you when you log in;
- provide access to restricted content;
- prevent unauthorised access;
- communicate important account information; and
- handle account-related requests.
The main legal basis is Article 6(1)(b) GDPR because the processing is necessary to provide the account and access requested by you. Security-related processing may also be based on Article 6(1)(f) GDPR.
Account data is generally retained for as long as the account remains active. When an account is deleted, the associated data will be deleted or anonymised unless continued retention is required by law, necessary to establish or defend legal claims, or technically retained for a limited period in security backups.
Current free membership
At present, registration and the basic membership level are provided free of charge. We do not currently collect payment-card or bank-account information through the website.
Before paid memberships or payment processing are introduced, this Privacy Policy will be updated to identify the payment provider, the data processed, the purposes, legal bases and applicable retention periods.
7. Transactional emails
We may send transactional or account-related emails, including:
- registration confirmations;
- login and password-reset messages;
- membership confirmations;
- security notifications;
- notifications about important account changes; and
- responses to support requests.
These messages are necessary to provide and secure your account and are not marketing newsletters.
The legal basis is Article 6(1)(b) GDPR and, where security is concerned, Article 6(1)(f) GDPR.
We do not currently add registered users to a marketing newsletter merely because they create an account.
8. Age verification
This website is intended for adults aged 18 or over.
When you enter the website, you may be asked to confirm that you meet the minimum age requirement. The age-verification function does not require you to provide your date of birth or upload an identification document.
A technically necessary cookie or similar item in your browser storage may record that you have completed the age confirmation. This prevents the age-verification notice from appearing again on every page.
The purpose is to operate the age-restricted website appropriately and provide a functional browsing experience.
The legal basis for any associated processing of personal data is Article 6(1)(f) GDPR. Storage on your device is necessary to provide the age-verification function requested by you and is based on §25(2) TDDDG.
The stored confirmation remains on your device until it expires according to the configured period or is deleted through your browser settings. Deleting it may cause the age-verification notice to appear again.
The age confirmation is not an identity check and does not provide us with proof of your actual age.
9. Cookies and similar technologies
Cookies are small text files stored on your device. The website currently uses cookies or similar browser-storage technologies that are necessary for its operation.
These may include:
- age-verification cookies;
- WordPress session and login cookies;
- membership and access-control cookies;
- security cookies;
- cookies that remember website or account preferences; and
- temporary cookies needed to submit forms or navigate the website.
Technically necessary cookies are used to provide functions requested by the visitor, maintain login sessions, protect accounts and operate the website securely.
The legal basis for associated personal-data processing is Article 6(1)(b) or Article 6(1)(f) GDPR. Storage on or access to your device is based on §25(2) TDDDG where the technology is strictly necessary.
You can delete or block cookies through your browser settings. Blocking necessary cookies may prevent login, membership access, age verification or other parts of the website from working correctly.
Analytics, advertising and tracking
We do not currently intend to use Google Analytics, Clicky, Meta Pixel or comparable analytics, advertising or cross-site tracking technologies.
Optional analytics, advertising or tracking tools will not be activated without prior consent where consent is legally required. If such services are introduced, this Privacy Policy and the website’s consent settings will be updated before they are used.
10. External links and third-party websites
The website contains links to websites operated by third parties, including websites of coffeeshops, growers, public authorities, information sources and other organisations.
When you click an external link, you leave our website. The operator of the external website is independently responsible for any personal-data processing that takes place there.
We have no control over the content, security or privacy practices of external websites. Please review the privacy information provided by the relevant website operator.
11. Embedded third-party content
We do not currently intend to use third-party videos, maps, social-media feeds or similar content that automatically sends visitor information to an external provider when a page is opened.
If third-party embedded content is introduced, it may process information such as your IP address, browser details and interactions with the embedded content. Where required, such content will be blocked until you provide consent.
This Privacy Policy will be updated when new third-party services that process visitor data are introduced.
12. Recipients and service providers
Personal data may be accessible to service providers and authorised persons who support the operation of the website.
These may include:
- our hosting provider;
- our email provider;
- authorised website administrators;
- technical maintenance and security providers; and
- professional advisers or public authorities where disclosure is legally required.
Service providers acting on our behalf may process personal data only according to our instructions and the applicable data-processing agreement.
We do not sell personal data.
13. International data transfers
Our website and its primary hosting infrastructure are intended to be operated within the European Union or European Economic Area.
We do not knowingly transfer contact-form or membership data outside the EU or EEA as part of the current basic setup.
If we introduce a provider that processes personal data outside the EU or EEA, we will ensure that a legally recognised transfer mechanism applies. This may include an adequacy decision by the European Commission, EU Standard Contractual Clauses or another safeguard permitted under the GDPR.
The relevant service and safeguards will be described in this Privacy Policy.
14. Data retention
We retain personal data only for as long as it is necessary for the purpose for which it was collected.
The applicable retention period depends on:
- the purpose of the processing;
- whether your account remains active;
- whether an inquiry has been completed;
- contractual or statutory retention obligations;
- security and fraud-prevention requirements; and
- the need to establish, exercise or defend legal claims.
After the relevant retention period ends, personal data is deleted or anonymised. Data contained in backups may remain for a limited period until the relevant backup is overwritten.
15. Your data-protection rights
Subject to the conditions of the GDPR, you have the following rights:
- the right to receive information about the processing of your personal data;
- the right of access to your personal data;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on legitimate interests;
- the right to withdraw consent at any time where processing is based on consent; and
- the right to lodge a complaint with a data-protection supervisory authority.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise your rights, contact:
Please provide enough information for us to identify the relevant data and process your request. We may request additional information where this is reasonably necessary to verify your identity. Please do not send a complete copy of an identification document unless we specifically explain why this is necessary and how unnecessary information should be concealed.
16. Right to object
Where we process your personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to that processing for reasons arising from your particular situation.
We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims.
17. Right to lodge a complaint
You have the right to lodge a complaint with a data-protection supervisory authority, particularly in the EU or EEA country of your habitual residence, your place of work or the place where you believe an infringement occurred.
The supervisory authority primarily responsible for the controller is:
[Insert the supervisory authority responsible for the controller’s legal address]
If the controller is established in Berlin, the relevant authority is:
You may contact a supervisory authority without first contacting us.
18. Data security
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.
These measures may include encrypted transmission using HTTPS, access controls, software updates, backups and security monitoring.
Nevertheless, no internet-based service or email communication can be guaranteed to be completely secure.
19. Automated decision-making
We do not currently use solely automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
20. Information concerning minors
The website is intended only for people aged 18 or over.
We do not knowingly request or collect account or contact information from children. If we become aware that personal data was submitted by a person under 18, we will review and delete the information where appropriate and legally permissible.
21. Changes to this Privacy Policy
We may update this Privacy Policy when the website, membership functions, service providers or legal requirements change.
The current version will always be made available on this page. The date of the latest revision appears at the beginning of the policy.
