1. Controller & contact
Controller: Buziness Digital, Lange Str. 14, 29451 Dannenberg, Germany
Email: datenschutz@buziness.digital
2. Scope
This Privacy Policy applies to:
- our main website
www.buziness.digital(andbuziness.digital) and the web-based online guide (the “Service”), - our account and login area,
- newsletter subscriptions and delivery (sent via our own mail server),
- our contact form on
contact.buziness.digital.
Note about Russia: We do not offer sales to users located in Russia. The Russian language version is offered for Russian-speaking users located outside Russia.
3. What data we process
3.1 Website access (technical data)
- IP address
- Date/time of access
- Requested pages/files
- Referrer URL (if provided by your browser)
- Browser/device information (user agent), operating system
- Error logs
3.2 User accounts & Service access
- Email address
- Login credentials (password stored as a secure hash)
- Access status for the purchased guide (e.g., whether access is active)
- Language preference (e.g., selected language version of the guide)
- Support messages you send us
3.3 Purchase and order references
When you purchase access, we store limited order-related references needed to grant and maintain access, such as the order identifier, purchase date/time, and payment status.
3.4 Payment data (PayPal / Stripe)
We use PayPal and Stripe to process payments. When you pay, the payment provider processes payment and transaction information (such as the payment method details and transaction identifiers). Depending on the payment method and provider, additional billing information may be processed by the provider.
We do not store full card details on our servers. We store limited payment-related references needed to grant and manage access (e.g., payment status and transaction identifiers).
3.5 Newsletter data
- Email address (required)
- Consent and subscription status (subscribed/unsubscribed)
- Proof of consent information (e.g., time of subscription/confirmation and IP address), where needed
3.6 Contact form data (contact.buziness.digital)
- Your email address (and other details you include)
- Your message content
- Technical data (e.g., IP address, timestamp) to prevent abuse and ensure delivery
4. Purposes & legal bases (GDPR)
- Contract performance / pre-contractual steps (Art. 6(1)(b) GDPR): account creation, providing access to purchased content, customer support.
- Legal obligations (Art. 6(1)(c) GDPR): accounting/tax obligations (where applicable).
- Legitimate interests (Art. 6(1)(f) GDPR): IT security, fraud prevention, and basic usage/statistics via server logs/AWStats.
- Consent (Art. 6(1)(a) GDPR): newsletter subscription and (where applicable) certain regional consent requirements.
5. Hosting (IONOS, Germany)
Our website and the Service are hosted with IONOS in Germany. In the course of hosting, technical data (including server logs) may be processed to provide hosting, maintenance, and security.
6. User accounts & access
To use the Service, you create an account with your email address and a password. We store passwords as a secure hash, not in plain text.
Access to the guide is granted after successful purchase and is provided as lifetime access. We store access status and purchase references needed to grant and maintain access and to prevent abuse (for example, account sharing).
We also process limited technical and usage data (for example: login timestamps, IP address, user agent/device information, and failed login attempts) to secure accounts, prevent fraud and abuse (including account sharing or attempts to extract content), and to ensure the stability of the Service. Legal basis: Art. 6(1)(f) GDPR (legitimate interests: security, abuse prevention, and service integrity).
You can request deletion of your account by contacting us (see Section 1). If we must retain certain data for legal reasons, we will retain only what is required and restrict further processing.
7. Payments (PayPal / Stripe)
When you click “Pay now,” you are redirected to PayPal or Stripe (depending on the option you choose) to complete the payment. Depending on the checkout configuration, payment may take place on a provider-hosted page or within an embedded checkout. The payment provider processes the payment and transaction information. We receive a confirmation and limited transaction references (for example: payment status, transaction identifier, timestamp) in order to grant access to the Service.
PayPal and Stripe may act as independent controllers for parts of their processing. Please review their privacy information as well: PayPal Privacy Statement and Stripe Privacy Policy.
8. Newsletter
If you subscribe to our newsletter, we send you information about updates, content, and offers related to our online guide. The newsletter is sent via our own mail server (no external email marketing platform).
- Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time.
- Double opt-in: we recommend (and typically use) a confirmation process so that only the owner of an email address can subscribe.
- Proof of consent: to demonstrate consent, we may store subscription/confirmation details (e.g., time and IP address) as needed.
- Identification & unsubscribe: each newsletter identifies us as sender and includes an easy unsubscribe option.
- Processing opt-outs: we process unsubscribe requests promptly and keep a minimal suppression record to ensure we respect your choice.
9. Contact form (contact.buziness.digital)
When you contact us via the contact form on contact.buziness.digital, we process the information you submit to handle your request
(e.g., answering questions, support, or business inquiries).
Legal basis: usually Art. 6(1)(b) GDPR (pre-contract/contract-related communication) or Art. 6(1)(f) GDPR (legitimate interest in responding).
10. Server logs & AWStats
We use AWStats (server-side) to create aggregated statistics from server log files (e.g., page views, error rates). We do not use third-party advertising pixels or behavioral advertising on our website.
AWStats runs on our own server and analyzes our server log files locally. We do not share AWStats analytics data or raw server log files with third-party analytics providers, and AWStats does not set marketing/analytics cookies.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests: security, stability, and basic statistical evaluation).
11. Cookies / device storage
Our website uses technically necessary cookies or similar storage to provide core functions. These are required to operate the Service.
- Login / session: to keep you signed in while using the Service.
- Security: to protect the Service (for example, CSRF/security tokens).
- Preferences: to remember settings such as language selection (if used).
We do not set marketing or advertising cookies. AWStats is based on server logs and does not rely on analytics cookies. If we add non-essential tracking in the future, we will request consent and update this policy.
12. International processing / transfers
We host the Service in Germany. If you are located outside the EU/EEA, your personal data will be processed on our servers in Germany. In addition, PayPal and Stripe are international services, so payment-related data may be processed in countries outside the EU/EEA (for example, in the United States). Where required, transfers may rely on recognized safeguards (such as Standard Contractual Clauses).
13. Retention
We store personal data only as long as necessary for the purposes described in this Privacy Policy and as required by applicable law.
- Account data: stored while your account exists (lifetime access), plus a short buffer for support and abuse prevention after account deletion (e.g., 30 days), then deleted or anonymized unless we must retain it longer.
- Access status / purchase references: stored to grant and maintain access; removed when no longer needed (for example, after account deletion), unless we must retain records for legal obligations.
- Server logs: typically stored for a limited period (e.g., 30 days) and then deleted or anonymized, unless needed longer for security investigations.
- Payment references: we keep limited transaction references (e.g., payment status, transaction ID) as needed for access provisioning, accounting, and dispute handling. We do not store full payment card details.
- Legal retention: certain records may be retained longer where we are legally required to do so (e.g., tax/accounting record-keeping obligations).
14. Your rights
If you are in the EU/EEA, you have rights under the GDPR, including the right of access, rectification, erasure, restriction, data portability, and the right to object. Where processing is based on consent, you can withdraw consent at any time.
To exercise your rights, contact us at datenschutz@buziness.digital.
15. Supervisory authority
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
16. Updates
We may update this Privacy Policy from time to time. The current version is always published on this page.
17. Language versions
We provide this Privacy Policy in multiple languages for convenience. In case of differences between translations, the English version shall prevail, unless mandatory local law requires otherwise.
18. Additional regional information
The following information is provided at a high level for some jurisdictions where we may have users. This section does not replace local legal advice.
18.1 United States
The United States has sector and state-specific privacy laws. If a state privacy law applies to us (for example, California’s CCPA when thresholds are met), you may have additional rights and disclosures. You can contact us using Section 1 to submit requests.
For marketing emails, we aim to comply with the CAN-SPAM Act (including clear opt-out, identifying us as the sender, and honoring opt-out requests).
18.2 Canada
If you are located in Canada, Canada’s Anti-Spam Legislation (CASL) may apply to commercial electronic messages. Our newsletter is sent based on consent, includes identification information, and provides an unsubscribe mechanism.
18.3 Brazil (LGPD)
If you are located in Brazil, you may have rights under LGPD. You can request assistance using the contact details in Section 1.
18.4 China (PIPL)
If you are located in the People’s Republic of China, China’s Personal Information Protection Law (PIPL) and related rules may apply, including rules on cross-border transfers. Because the Service is hosted in Germany and payments are processed by international providers, personal information may be processed outside China. Where required, we will seek any necessary consents and provide the disclosures required by applicable rules (including information about overseas recipients and how to exercise rights).
China representative: We have not appointed a representative in China at this time. If applicable law requires us to appoint one, we will update this section with the representative’s details.
18.5 Vietnam
If you are located in Vietnam, Vietnam’s personal data protection rules may apply, including rules regarding cross-border processing. Because the Service is hosted in Germany and payments are processed by international providers, personal information may be processed outside Vietnam. Where required, we will collect appropriate consent and maintain any documentation required for cross-border processing.
18.6 Japan
If you are located in Japan, certain disclosures may apply to overseas transfers under Japanese rules. For payment processing and related transfers, please also review the privacy information of PayPal and Stripe.
18.7 Thailand
If you are located in Thailand, you may have rights under Thailand’s PDPA. Transfers outside Thailand may be subject to additional conditions depending on the legal basis and provider.
18.8 Indonesia
If you are located in Indonesia, additional requirements can apply to international data transfers and processing. You can contact us for details about our processing and transfers.
18.9 Philippines
If you are located in the Philippines, processing may be subject to the Philippines Data Privacy Act and guidance of the National Privacy Commission.
18.10 Australia
If you are located in Australia, Australian anti-spam rules require consent and a functional unsubscribe option for marketing messages.
18.11 United Kingdom
If you are located in the United Kingdom, cookie and similar technology rules are governed by PECR alongside UK GDPR. If we add non-essential cookies or tracking, we will request consent and update this policy.