Wall of open books

Privacy Policy

Information about the processing of personal data on the BiblioCopy GmbH website.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection legislation is:

BiblioCopy GmbH
Gneisenaustraße 2a
10961 Berlin
Germany

Phone: 030 25794343
Email: info@bibliocopy.de

Managing directors authorised to represent the company: Jule Pomierski and Michael Hewener

You may also send data protection enquiries to info@bibliocopy.de.

Data Protection Officer

You can contact our Data Protection Officer directly at:

Data Protection Officer of BiblioCopy GmbH
c/o BiblioCopy GmbH
Gneisenaustraße 2a
10961 Berlin
Email: datenschutz@bibliocopy.de

Please mark postal correspondence addressed to the Data Protection Officer as “confidential”.

2. General information on data processing

We process personal data only where this is necessary for the secure operation of our website, to handle enquiries, to prepare or perform a contract, or to comply with legal obligations.

Depending on the processing activity, we rely in particular on the following legal bases:

  • Article 6(1)(b) GDPR where processing is necessary to perform a contract or to take steps in response to a pre-contractual enquiry.
  • Article 6(1)(c) GDPR where we are legally obliged to process the data.
  • Article 6(1)(f) GDPR where processing is necessary for our legitimate interests or those of a third party and these are not overridden by the interests or fundamental rights of the data subject.
  • Article 6(1)(a) GDPR only where we expressly request voluntary consent for a particular processing activity.

Where processing is based on consent, you may withdraw that consent at any time with effect for the future. Processing carried out before the withdrawal remains lawful.

We delete personal data once the relevant purpose no longer applies and there are no statutory retention obligations or legitimate reasons for continued storage. More specific information is provided below.

3. Hosting and provision of the website

Our website and associated email mailboxes are operated by the following service provider:

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany

When you access our website, your browser transmits connection data required for technical operation to the web server. This may include the requested address and file, the date and time of access, the amount of data transferred, messages about successful or failed access, browser type and version, operating system, the previously visited page and the IP address. At least temporary processing of the IP address is necessary to deliver the website to your device.

According to STRATO, host names and IP addresses are anonymised in the access logs made available to us. Anonymised access logs are available in the STRATO customer area for a maximum of six weeks; error logs are available there for five days.

Log data is processed to provide the website technically, analyse errors and prevent or investigate attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable and error-free operation of the website.

STRATO processes the data generated through hosting and email operation on our behalf under a data processing agreement pursuant to Article 28 GDPR.

Further information:

4. Encrypted transmission

This website uses TLS encryption. This protects data you send to us while it is being transmitted between your device and our server. You can usually recognise an encrypted connection by https:// and the corresponding symbol in your browser’s address bar.

5. Language preference

The website is available in German and English. On your first visit, the preferred language configured in your browser may be evaluated in order to display the appropriate language version. This browser setting is not sent to another service for this purpose.

If you deliberately select a language using the language switcher, we store that choice under the name bc_language_preference both in your browser’s local storage and in a technically necessary cookie. Possible values are de and en.

The cookie is stored for one year. The entry in local browser storage has no automatic expiry and generally remains until you delete it, the website replaces it or the browser storage is otherwise reset. The information is not used for analytics or advertising and is not shared with third parties.

Storage on or access to your device is based on section 25(2)(2) TDDDG because it is necessary to provide the language version you expressly selected. Where the language preference can be linked to an individual, further processing is based on Article 6(1)(f) GDPR. Our legitimate interest is a consistent and user-friendly language selection.

You can delete the cookie and local storage at any time in your browser settings. On your next visit, the browser language will be considered again until you make another explicit choice.

6. Contact by email

If you contact us by email, we process your email address, the content you send, technical delivery information and any other information you provide voluntarily. This processing is used to handle your message and communicate with you.

If your message relates to a contract or a potential commission, the legal basis is Article 6(1)(b) GDPR. Other messages are processed on the basis of Article 6(1)(f) GDPR; our legitimate interest is to respond appropriately to communications addressed to us.

Emails are processed through mailboxes operated by STRATO. Within BiblioCopy, access is limited to those people who require it to handle the matter.

We delete emails that do not result in a commission no later than 180 days after the enquiry has been fully handled. If the communication results in a commission or another business transaction, the associated data may be retained for longer in accordance with statutory commercial and tax retention obligations.

7. Contact and enquiry forms

You can contact us through various forms on our website. Depending on the form and the information you provide, we process in particular:

  • Name and email address.
  • Subject and content of the enquiry.
  • For photograph and digitisation enquiries, information about the type and volume of the originals, requested resolution, storage medium, delivery, processing time, payment method, comments and a price estimate calculated from the selected options.
  • Technical information required for secure transmission and spam prevention.

The information is stored in our WordPress database on STRATO hosting and sent by email to the BiblioCopy staff responsible for handling it. Where an acknowledgement is configured, a message is also sent to the email address you provided.

Where your enquiry concerns commissioning a service or preparing a contract, processing is based on Article 6(1)(b) GDPR. General enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the efficient and traceable handling of incoming enquiries.

Mandatory fields are marked accordingly. Without the requested information, we may be unable to handle the enquiry. Additional information is voluntary. We do not use solely automated decision-making with legal or similarly significant effects, nor do we carry out profiling.

Form entries stored in the website database are deleted automatically 180 days after receipt. Data that becomes part of a commission or another business transaction subject to retention requirements may be stored outside the form system for longer in accordance with statutory requirements.

8. Form protection with Cloudflare Turnstile

We use Cloudflare Turnstile to protect our forms against automated submissions and misuse. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA.

When a form protected by Turnstile is opened, a connection is established to challenges.cloudflare.com. To detect automated access, Turnstile processes in particular the IP address, TLS characteristics, the browser user agent, the site key and the associated origin. Small checks run in the browser and a time-limited result token is then validated with Cloudflare on the server. According to Cloudflare, Turnstile does not access form field content or other communication content.

Cloudflare processes these signals on our behalf to protect the website. According to Cloudflare, it also processes certain signals under its own responsibility in order to improve bot detection.

Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is to protect our forms, systems and email mailboxes against spam and automated misuse. Where Turnstile stores or accesses information on the device for the security check, we rely on section 25(2)(2) TDDDG.

Data may also be processed in the United States. For transfers to the United States, Cloudflare relies on its certification under the EU–US Data Privacy Framework and, additionally, on the European Commission’s Standard Contractual Clauses. Cloudflare processes data on our behalf under its Data Processing Addendum.

We use Turnstile without the optional “Pre-Clearance” feature. In this configuration, the widget generates a short-lived, single-use token and no additional cf_clearance cookie.

Further information:

9. Protection of the administration area

The administration area of our website is not intended for public user accounts. To prevent automated login attempts, our WordPress installation processes in particular the IP address, time and number of failed login attempts. This allows further attempts from suspicious addresses to be temporarily limited.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are protecting the website, stored enquiries and our administrative access against unauthorised access.

The logs are deleted after 30 days unless they are required for longer to investigate a specific attack.

10. Cookies and local storage technologies

We do not use cookies for audience measurement, personalised advertising or cross-site tracking. A consent banner is therefore not provided.

  • bc_language_preference as a cookie: retains the expressly selected language; stored for one year.
  • bc_language_preference in local browser storage: retains the expressly selected language; stored until it is changed or deleted in the browser.

If the website configuration changes and services requiring consent are used in future, we will obtain the relevant consent before activating them and update this Privacy Policy.

11. Recipients of data

Within BiblioCopy GmbH, personal data is accessible only to those who require it for their respective duties. External recipients may include in particular:

  • STRATO GmbH as processor for hosting, databases and email.
  • Cloudflare, Inc. and, where applicable, affiliated companies when Turnstile is used.
  • Public authorities or other bodies where we are legally required to disclose data.

Enquiries are not routinely forwarded to Stabi Berlin, freelancers or other external bodies. No further disclosure takes place unless you have consented or there is another legal basis.

12. Your rights

Where the statutory requirements are met, you have in particular the following rights:

  • Access to the personal data processed about you under Article 15 GDPR.
  • Rectification of inaccurate data or completion of incomplete data under Article 16 GDPR.
  • Erasure under Article 17 GDPR.
  • Restriction of processing under Article 18 GDPR.
  • Data portability under Article 20 GDPR.
  • Objection to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR.
  • Withdrawal of consent with effect for the future under Article 7(3) GDPR.

To exercise your rights, you may use the contact details provided in section 1. Where necessary to prevent unauthorised disclosure, we may request suitable proof of your identity.

If you believe that the processing of your personal data infringes data protection law, you may lodge a complaint with a data protection supervisory authority. The authority with particular responsibility for our company is:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
www.datenschutz-berlin.de

13. Objection to processing based on legitimate interests

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then cease processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required to establish, exercise or defend legal claims.

14. Updates to this Privacy Policy

We update this Privacy Policy if the website, the services used or the legal requirements change. The version published on this website at the relevant time applies.

Last updated: August 2026

BiblioCopy

Send enquiry

Loading form …