Privacy Policy

Last updated: 1 October 2026

1 Controller and contact details

The controller responsible for the processing described below is Louis Guntrum Weinkellerei GmbH, Rheinallee 62, 55283 Nierstein, Germany, represented by its managing director Louis Konstantin Guntrum. You can contact us at info@guntrum.de or by telephone on +49 (0)6133 9717-0.

For data protection enquiries, please use the contact details above.

This policy explains how we process your data on www.guntrum.de and in the associated online shop. Personal data is information that can be linked to an individual.

2 Legal bases

We process data to take steps before entering into a contract and to perform contracts under Article 6(1)(b) GDPR, to comply with legal obligations under Article 6(1)(c) GDPR, on the basis of your consent under Article 6(1)(a) GDPR, and to pursue legitimate interests under Article 6(1)(f) GDPR. The relevant purposes and interests are explained below.

Storing information on your device or accessing information already stored on it requires your consent under section 25(1) of the German Telecommunications and Digital Services Data Protection Act (TDDDG). Under section 25(2) TDDDG, consent is not required, in particular, where the technology is strictly necessary to provide a digital service you expressly request. Subsequent processing of personal data also requires a legal basis under the GDPR.

3 Hosting and technical operation

When you access our website, we process information including your IP address, access time, requested URL, HTTP status, amount of data transferred, browser, operating system and, where applicable, the referring page. This information is used to deliver the website, diagnose errors and prevent misuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are stable and secure website operation.

Our hosting provider is IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. Where the provider acts as a processor, it processes data on our behalf.

Server logs are deleted or anonymised no later than one year after collection. Information needed to investigate specific security incidents may be retained until the incident is resolved and, where necessary, for legal proceedings.

4 Cookies and consent management

We use cookies and similar technologies for necessary website functions and to manage your privacy choices. Optional external services are used on the basis of your consent. Details of the technologies, providers, purposes and durations are available in our privacy settings.

We use Borlabs Cookie, supplied by Borlabs GmbH, to manage consent. It processes your choices and technical evidence, such as an identifier, timestamp and consent version, to the extent collected by the configuration in use. Consent management takes place on our website; according to the manufacturer, Borlabs does not receive visitor data through this function.

Processing to demonstrate consent is based on Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR. Where processing serves to manage your choices and operate the consent system, the basis is Article 6(1)(f) GDPR. Storage on or access to your device that is strictly necessary for this function is based on section 25(2) TDDDG.

Stored consent information is deleted or renewed no later than after one year, unless it remains necessary to meet statutory evidential obligations. Your choices are updated when you withdraw consent. You can change your choices and withdraw consent for the future at any time through the privacy settings.

5 Contact and enquiries

If you contact us through the contact form, by email, telephone or another channel, we process the information you provide to handle your enquiry. Form information includes company, first and last name, address, email address, telephone number, subject and message, as well as technical information necessary for transmission.

Contract-related enquiries are processed under Article 6(1)(b) GDPR. Other enquiries are processed under Article 6(1)(f) GDPR; our legitimate interest is to respond to and keep appropriate records of your communication. You can contact us by email or telephone instead of using the form.

Fields marked as required must be completed to use the relevant form. Without them, the form cannot be submitted. When you contact us by another channel, we only need the information necessary to handle your enquiry.

We use WP Mail SMTP to connect our website to our email service. Depending on the configuration, this covers contact enquiries, order notifications and account or password messages. Email delivery is configured through Mailgun’s EU SMTP endpoint smtp.eu.mailgun.org using TLS. Mailgun processes message content and delivery data in the selected EU region. Mailgun is the service provider used for website email delivery. Further information: https://www.mailgun.com/legal/privacy-policy/. Information processed includes sender, recipient, message content and technical delivery information. Delivery logs under our control are deleted within one year. Provider retention follows the agreed Mailgun configuration; the one-year period does not extend shorter provider retention.

Ordinary contact enquiries are deleted no later than one year after handling is complete, unless legal retention obligations or necessary evidential purposes require further storage. Business correspondence and accounting records are subject to the statutory periods described in section 13.

6 Google reCAPTCHA

We use Google reCAPTCHA v3 to protect our contact form against automated and abusive submissions. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA v2 may be used for additional verification.

After you enable the service, reCAPTCHA analyses technical information and interactions to produce a risk assessment. This may include your IP address, browser and device information, page address, timing and duration of use, mouse movements and other interaction data, which may be transmitted to Google. reCAPTCHA also uses cookies or similar technologies; Google identifies the _GRECAPTCHA cookie among them. Version 3 normally operates in the background without displaying a task.

Our consent system enables the service only after you consent. The legal bases are Article 6(1)(a) GDPR and, where information is stored on or accessed from your device, section 25(1) TDDDG. Without enabling the service, the protected form is unavailable; you can contact us by email or telephone instead. You can withdraw consent for the future at any time through the privacy settings.

The risk assessment may cause a submission to be rejected or additional verification to be requested. This service does not make decisions about entering into contracts or decisions with comparable significant effects.

Google cookie durations and retention of data transmitted to Google follow the applicable provider information and configuration. Our one-year deletion rule for records under our control is not a promise about Google’s own retention. Processing outside the EEA, particularly in the United States, is possible and is subject to the conditions described in section 12.

Further information: https://policies.google.com/privacy?hl=en and https://developers.google.com/recaptcha/docs/faq.

7 Online shop and customer accounts

Our shop uses WooCommerce on our WordPress website. To handle orders, we process information including your name, billing and delivery addresses, email address, telephone number where applicable, products ordered, order value, payment method, and payment and delivery status. This supports order fulfilment, invoicing, delivery, handling enquiries and compliance with legal obligations. The legal bases are Article 6(1)(b) and (c) GDPR.

If you create a customer account, we process registration and account information to provide the account under Article 6(1)(b) GDPR. Technical security information is processed under Article 6(1)(f) GDPR to protect your account and our shop. Inactive customer accounts are deleted after one year without activity. You can also request deletion earlier; order and invoice information subject to independent retention obligations is retained until those periods expire.

Necessary cookies or similar storage technologies are used for the shopping basket, session and login. Strictly necessary device storage or access is based on section 25(2) TDDDG; personal order and account information is processed under Article 6(1)(b) GDPR. Cookie names and durations are listed in the privacy settings.

Information necessary to place and deliver an order must be provided; otherwise the purchase cannot be fulfilled. Optional information is identified accordingly.

8 Payment and delivery

We offer payment by invoice, advance bank transfer and direct debit. Necessary order, invoice and payment information is processed under Article 6(1)(b) GDPR, and statutory retention obligations are fulfilled under Article 6(1)(c) GDPR.

For direct debit, we process information including the account holder, IBAN, mandate information and the data necessary to collect and reconcile payment. Information is collected in the WooCommerce shop. The banks involved receive the payment and transaction information necessary to carry out transfers and direct debits and process it under their own statutory obligations. Credit card payments are not offered.

For delivery, we share names and delivery addresses with the parcel carriers or freight companies used, predominantly DHL and DPD. The legal basis is Article 6(1)(b) GDPR. We prepare shipping labels ourselves. Sharing your email address or telephone number for delivery notifications is not intended under the procedure described to date.

9 Comments and product reviews

When you submit comments or product reviews, we process the content, the name and email address you provide, the timestamp and, where applicable, technical information such as your IP address for publication, moderation and prevention of misuse. The comment or review and chosen name are displayed publicly; the email address is not displayed publicly.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are meaningful discussion of our content and products and prevention of unlawful or abusive submissions. Where verified purchaser labels are used, we compare the necessary information with order records.

Published submissions are generally retained for the duration of publication unless deletion is required. Technical moderation information such as IP addresses, rejected submissions and spam are deleted within one year unless needed to investigate specific instances of misuse.

10 Language and age confirmation

We use Polylang for language selection. Language preferences are stored for the session to provide the language version you select. Personal preference information is processed under Article 6(1)(f) GDPR to provide the selected presentation.

We use Age Gate for age confirmation. We process your age confirmation to control access to age-related content. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is age-appropriate access. Storing the confirmation to provide the requested access function is based on section 25(2) TDDDG. Storage of the confirmation is configured for one day. A website age prompt does not automatically replace legally required age verification for sale or delivery.

11 External content and social media

The Instagram feed is displayed using Smash Balloon Instagram Feed.

We display Instagram content on our website. Instagram’s provider in the EEA is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Where content is loaded directly from Meta or other external servers, information including your IP address, browser information and the page visited may be transmitted. If you are logged into Instagram, the visit may be associated with your account.

We load such optional external content on the basis of consent under Article 6(1)(a) GDPR and, where applicable, section 25(1) TDDDG. If content is cached exclusively on our servers without a direct browser connection to the provider, displaying it does not cause that direct transmission. Meta’s information: https://privacycenter.instagram.com/policy/.

Links to our Facebook and Instagram pages lead to external services. An ordinary link does not transmit data to the linked service simply because you visit our website; processing by that service occurs when you follow the link. This policy covers website integrations. Our social media profiles may require separate notices, including for jointly controlled audience statistics.

12 Recipients and international transfers

Access is granted to authorised staff and necessary service providers, including hosting, IT, email, payment, delivery and, where applicable, accounting providers. Processors are subject to contractual arrangements under Article 28 GDPR. Other recipients act as independent controllers where applicable. Data is disclosed to authorities where a legal obligation requires it.

For transfers outside the EU and EEA, we ensure the conditions of Articles 44 et seq. GDPR are met. An adequacy decision may provide a basis; for the United States, this applies only where the specific recipient is covered by the applicable EU-US Data Privacy Framework. Otherwise, appropriate safeguards such as EU Standard Contractual Clauses, with the necessary assessment and any additional measures, may be used. Consent to a service does not automatically replace a required international transfer basis.

You can request information about the transfer basis applicable to each recipient and copies of applicable safeguards at info@guntrum.de, subject to the rights of third parties.

13 Retention and data security

We retain data only as long as necessary for its purpose or required by law. Commercial and tax retention periods depend on the document type, particularly under section 257 of the German Commercial Code and section 147 of the German Fiscal Code. Typical periods are ten years for certain accounting records, eight years for accounting vouchers and six years for commercial or business correspondence, unless different rules or extensions apply. Periods generally start at the end of the relevant calendar year, rather than automatically at the end of the customer relationship.

Where information is necessary to establish, exercise or defend legal claims, we retain it under Article 6(1)(f) GDPR for the period needed. Other data is deleted or anonymised when its purpose ends. Pending, failed or cancelled order records that are no longer needed and are not subject to legal retention are deleted within one year. Statutorily retained documents, particularly invoices, accounting vouchers and necessary direct debit records, are excluded from this one-year period.

We use appropriate technical and organisational measures, including encrypted website connections, access restrictions and backups. Backups may contain data until scheduled overwriting and are used to restore service after disruptions. Duplicator stores backups in the website’s local backup directory on the web server. Backups are deleted no later than one year after creation. Following a restore, previous deletions are applied again; backups are not used as a permanent archive.

14 Your rights

Subject to the applicable legal conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20). You can withdraw consent at any time for the future (Article 7(3)); withdrawal does not affect the lawfulness of earlier processing.

Where we process data under Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation (Article 21(1)). We will stop processing unless we demonstrate compelling legitimate grounds or processing is necessary for legal claims. You may object to processing for direct marketing at any time without giving reasons (Article 21(2)).

To exercise your rights, contact info@guntrum.de. You may complain to a data protection supervisory authority, particularly in the country of your habitual residence, workplace or the alleged infringement. The authority generally responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate: https://www.datenschutz.rlp.de, email poststelle@datenschutz.rlp.de.

15 Updates

We update this policy when our processing activities or legal requirements change. The version published on our website is the applicable version.