Secure Checkout Fast delivery Fair prices

Privacy

DATA PROTECTION DECLARATION

for Scriptfabrik.de and the associated platform services

Status: 23. August 2026

This privacy policy informs how Scriptfabrik B.V. processes personal data when using the website, the online marketplace, customer and merchant accounts, orders, digital products, hosting and IT services, evaluation, communication and support functions.

The declaration is based in particular on the General Data Protection Regulation of the European Union (GDPR) and the additionally applicable Dutch data protection and telecommunications law. Insofar as an offer is aimed specifically at persons in another country, additional mandatory local data protection and telecommunications regulations are observed.

1. Accountable person

The controller for the processing described in this declaration is:

Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands

VAT identification number: NL869888316B01

E-mail: welcome@scriptfabrik.info
Website: https://www.scriptfabrik.de

If a data protection officer is appointed for a specific processing, his contact data will be published at this point and in the provider identification. Regardless of this, data protection requests can be directed at any time to the above-mentioned e-mail address.

2. Definitions and scope

Personal data is information relating to an identified or identifiable natural person. This includes, for example, contact, account, contract, payment, device, usage and communication data.

Processing means any handling of personal data, in particular collection, storage, use, transmission, modification, restriction or deletion.

This declaration applies to processing for which Scriptfabrik itself is responsible. External merchants, payment service providers and other independent recipients may be responsible for their own purposes and provide their own data protection notices for this purpose.

3. Principles and legal bases

Scriptfabrik processes personal data only if there is a legal basis for this. Depending on the process, the following bases are particularly suitable:

  • Contract and pre-contractual measures: where data is required for the registration, ordering, provision, payment, delivery, licensing, maintenance or execution of a contract;

  • Legal obligation: in particular for accounting, tax and platform reporting, identity checks, anti-fraud, product safety, regulatory information and the preservation of commercial documents;

  • legitimate interest: in particular, secure and stable platform operations, prevention of abuse and fraud, IT security, error analysis, appropriate direct marketing, enforcement and defence of claims and improvement of services; the interests and rights of data subjects are balanced;

  • Consent: in particular for unnecessary cookies, comparable tracking technologies, certain marketing measures or voluntary functions;

  • vital interests or tasks in the public interest: only in special situations provided for by law.

If a processing is based on consent, this can be revoked at any time with effect for the future. The legality of the processing until the revocation remains unaffected.

4. Provisional obligation

Certain data is required for registration, conclusion of contract, payment, delivery, merchant verification or legal reporting. Without this data, Scriptfabrik may not be able to provide the relevant account or the desired service.

Voluntary information shall be treated as such. A refusal to give consent to unnecessary analytical or marketing technologies does not prevent access to the essential platform functions to the extent that they can be offered without the relevant technology.

5. Visit to the website and server logs

When retrieving the website, technically necessary data are processed. These may include:

  • IP address;

  • date and time;

  • accessed address, page or file;

  • volume of data transmitted;

  • Referrer address;

  • browser, operating system and device type;

  • Status codes, error messages and technical identifiers.

The processing serves for the delivery of the website, system security, availability, error analysis and defense against abusive access. The legal basis is the legitimate interest in a secure and functional Internet offer as well as, insofar as the retrieval serves the initiation or performance of the contract, the implementation of pre-contractual or contractual measures.

In principle, security protocols are stored only as long as this is necessary for error analysis, attack detection and detection. A longer storage takes place only in the case of a specific security incident or due to legal obligations.

6. Customer account and registration

When registering and using the account, the following data can be processed:

  • name, user name and contact details;

  • invoice and delivery address;

  • encrypted password value and security features;

  • account, login and session data;

  • Order, download and license history;

  • Communication, support and setting data.

The data is processed for setting up, managing and securing the account, providing the selected functions, processing the contract and communication.

Security-relevant account changes can be logged. Passwords are not stored in plain text.

7. Multi-vendor marketplace and external traders

On the platform, in addition to Scriptfabrik, external dealers offer products and services on their own behalf and for their own account.

If a customer orders from an external dealer, he receives the data necessary for the execution of the contract. These may include:

  • name and contact details;

  • invoice and delivery address;

  • Order, product, price and payment status;

  • shipping, downloading, licensing, returns and complaint data;

  • Required messages between customer and dealer.

The transmission takes place for the initiation and implementation of the contract between customer and dealer as well as for the fulfilment of statutory marketplace obligations. The external merchant processes the transmitted data for its own contract processing as an independent controller. For additional own purposes of the merchant, in particular its advertising, Scriptfabrik is not responsible.

Scriptfabrik and dealers can be jointly responsible for individual clearly defined processing operations. In this case, the essential content of the responsibilities agreement shall be made available to the data subjects.

8. Trader Account, Verification and Legal Trader Verification

For the establishment and operation of a merchant account:

  • company name, legal form and business address;

  • the name, function and contact details of authorised representatives;

  • business register and tax data;

  • VAT identification number;

  • bank and payout data;

  • proof of identity, address and business;

  • contract, package, product and billing data;

  • Risk, safety and testing characteristics.

The processing takes place for the execution of the contract, examination and display of legally prescribed merchant details, fraud prevention, payment processing, product security, tax platform reporting and fulfillment of official obligations.

Verification data can be verified by specialized identity or payment service providers. Documents are only kept for as long as this is necessary for examination, proof, legal obligations or defence of specific claims.

9. Orders, contracts and invoices

In the case of orders and other contracts, in particular:

  • customer, contact and address data;

  • shopping cart, order and product data;

  • contract duration, tariff and status of performance;

  • billing, payment and accounting data;

  • dispatch, provision and communication data;

  • Withdrawal, return, complaint and warranty data.

Purposes are contract initiation, contract execution, delivery or digital provision, invoicing, customer service, enforcement or defense of claims and fulfillment of commercial, tax and consumer obligations.

10. Digital content, downloads, licenses and APIs

For software, scripts, plugins, templates, graphics, audio and video files, e-books, documents, license keys, API accesses and other digital products, additional processing may be carried out:

  • time of download and access;

  • IP address and technical equipment information;

  • License, activation and installation data;

  • version, update and compatibility data;

  • security, misuse and blocking features.

The processing serves for provision, license management, update supply, technical support, prevention of unauthorized multiple use and documentation of the performance of the contract. Cross-device licence control shall be used only to the necessary and proportionate extent.

Hosting, domain, server and email services

For these services, Scriptfabrik processes customer master data, contract and billing data as well as technical operating data, depending on the order. Insofar as customers store or process their own personal data on booked systems, the customer regularly decides himself about the purposes and means of this processing. Scriptfabrik then acts as a processor and, if necessary, concludes a contract for order processing.

For domain registrations, necessary owner and contact data are transmitted to registrars, registries or issuing bodies. The recipients and their roles depend on the respective domain extension and are named in the ordering process or in additional domain information.

In the case of misuse reports, security incidents or legitimate requests by authorities, technical usage and allocation data can be checked and disclosed to the extent necessary.

12. Individual programming, web design and support

For project and support services, Scriptfabrik processes the contact, project, content, access, communication and contract data provided by the customer. Where possible, only necessary accesses and test data shall be provided.

Remote accesses, logs, screenshots or backup copies are created only to the extent necessary for error analysis and service provision and are subsequently deleted, unless storage or preservation of evidence is necessary.

If customer systems contain personal data of third parties, it must be checked before access whether a contract for order processing and additional security measures are necessary.

13. Payment processing

In order to process payments, the necessary data are transmitted to the payment service provider, participating banks, card companies or other payment agencies selected in the checkout. These may include:

  • name, address and e-mail address;

  • invoice number, amount, currency and method of payment;

  • transaction identification code, status and time;

  • technical and fraud-related test characteristics.

Complete card or online banking access data is generally processed by the respective payment service provider and not by Scriptfabrik, unless otherwise stated in the checkout.

Payment service providers may be independently responsible for payment processing, fraud prevention and legal audits. The specific provider used and its data protection information are displayed in the checkout.

14. Trader payouts and platform notifications

For merchant payouts, bank details, payment amount, transactions, invoices, credits, tax, identity and audit data are processed.

The processing serves payment, billing, fraud and chargeback prevention as well as legal recording and reporting obligations. For this purpose, according to the rules on tax cooperation of platform operators, merchant identity, address, tax identification number, VAT data, financial account, remuneration, fees and transaction figures can be transmitted to the competent tax authority.

Scriptfabrik informs affected dealers about legally reported data, as far as this is required.

15. Shipping, revocation, returns and complaints

In the case of physical products, delivery data shall be transmitted to the designated dealer and the authorised shipping service provider. For shipment announcement, e-mail address or telephone number can also be used, as far as this is necessary for delivery or is permitted separately.

In the event of revocation, return, complaint or warranty, order, contact, communication, proof, refund and, if applicable, image data are processed. Health data or other particularly sensitive information should only be transmitted if this is absolutely necessary.

16. Communication between customers and dealers

If the platform provides a messaging system, Scriptfabrik processes senders, recipients, timestamps, content, attachments and technical security data to enable communication, handle complaints and prevent abuse.

News is not evaluated without reason for advertising purposes. Automated security filters can be used to detect spam, phishing, malware or prohibited circumventions. Manual access takes place only on justified occasion and by authorized persons.

17. Contact, Support and Complaints

Upon contact, the transmitted data, the means of communication, time, content and the contract or account data required for processing are processed.

Depending on the request, the legal basis is the implementation of pre-contractual or contractual measures, a legal obligation or the legitimate interest in processing, documentation and improving support.

Support processes are stored after completion only as long as this is necessary for follow-up questions, quality assurance, proof or legal obligations.

18. Reviews and public content

In the case of reviews, comments, product questions or other public contributions, in particular user name, profile information, content, evaluation, product or dealer reference, time of publication and, if applicable, the label "verified purchase" will be processed and published.

The publication takes place to provide the function desired by the user. Moderation, fraud screening and prevention of abuse are based on legal platform obligations and the legitimate interest in a trustworthy rating system.

Technical metadata and order reference can be used to check the authenticity of an evaluation. They will not be publicly displayed unless expressly stated.

The user should not publish sensitive data, private contact data or data of uninvolved third parties. Cancelled contributions may continue for a limited period in collateral or for the purposes of proof.

19 Wish Lists, Favorites and Recommendations

When using appropriate functions, Scriptfabrik processes stored products, categories, search and click interests and account settings.

Account-based wish lists and functional recommendations serve the requested platform function. Any additional cross-device or cross-service personalization will only take place on a suitable legal basis and, if necessary, with consent.

Users can deactivate personalized recommendations in the account settings or via the consent management, as far as the function provides.

20. Search, ranking and sponsored offers

For search and sorting, search terms, filters, language, location region, product data, availability, merchant performance, reviews, clicks and purchase interactions can be processed.

The processing serves the requested search and the legitimate interest in relevant and functional search results. Sponsored offers will be marked.

A significant legal or similarly significant decision about a person is not made solely on the basis of the search or recommendation profile, unless expressly communicated and permitted by law.

21. Newsletter and direct advertising

Newsletters are generally sent on the basis of consent. For registration, e-mail address, time, confirmation status and technical proof data can be processed. Scriptfabrik can use a confirmation procedure to prevent abusive registrations.

Existing customers may receive information on similar own products to the extent permitted by applicable law without separate consent. Each advertising message contains a simple objection or unsubscription option.

A revocation or advertising objection is possible at any time without incurring costs other than the transmission costs according to the basic tariff. After unsubscribing, the e-mail address can be stored in a block list in order to prevent further mailings.

22. Vouchers, promotions and partner programs

For vouchers, discount codes, sweepstakes or customer promotions, account, order, code, redemption, participation and abuse verification data can be processed.

Additional terms and privacy notices are provided when an action includes specific data, partners or publications.

23. Cookies and similar technologies

The platform uses cookies, local storage, pixels, scripts, device identifiers and similar technologies. You can store information on the device or read already stored information.

Strictly necessary technologies are used as far as they are necessary for an expressly desired service, such as shopping cart, login, security, language selection, load distribution or consent storage.

Analytics, personalization, affiliate and marketing technologies are only used after prior effective consent, unless there is a legal exception. Rejection must be as easy as consent. No preselected consents are used.

The respective technologies, providers, purposes, data categories, storage periods, third country transfers and revocation options are specifically listed in the cookie overview of the consent management. This current technical overview is part of the data protection information on cookies.

24. Consent management

Through the consent management, users can accept, reject and later change optional categories. Consent status, categories, time, version of the instructions, consent identifier and necessary device and proof data can be processed.

The storage serves the implementation of the selection and the legally required proof. A given consent can be revoked at any time via the permanently accessible link “Cookie settings” or an equivalent function.

A revocation prevents future processing. Depending on the provider, already stored cookies can also be deleted via browser or device settings.

25. Analysis and range measurement

Where analysis tools are used, page views, sessions, interactions, origin, approximate region, browser, device, technical identifiers and conversion events can be processed.

Non-necessary analysis is done only after consent. If an exclusively own, data-saving analysis service is used without third party access and without cross-user profile formation due to a legal exception, this is explained separately in the cookie overview.

IP addresses and identifiers are shortened as far as possible, pseudonymised or deleted at an early stage. Results are preferably evaluated aggregated.

26. Affiliate marketing, advertising and embedded comparison offers

The platform may contain affiliate links, banners, comparison calculators, iFrames and offers from affiliate networks, including, where applicable, CHECK24 affiliate programs, TARIFCHECK, verticalAds and communicationAds.

A usual external link transmits technically necessary retrieval data to the destination page when clicking. If tracking parameters, cookies, pixels, scripts or embedded content are used for commission assignment or advertising, they are only activated after the necessary consent.

Partners can process the click, a pseudonymous assignment, transaction or commission data and technical retrieval data. The specific active partner, purpose, storage period and any third country transfer are mentioned in the consent administration or directly at the offer.

27. External content, videos, maps, widgets and iFrames

External media and functions can technically lead to the third-party provider receiving IP address, browser, device and usage data. Such content, unless it is necessary for an expressly requested service, will only be loaded after consent.

Alternatively, a placeholder can first be displayed. By activating the content, the user consents to the described data transmission. For the further processing of the third party, its data protection notices apply.

28. Security, abuse and fraud prevention

To protect accounts, payments, platform and users, Scriptfabrik processes login, IP, device, transaction, behavior, blocking, complaint and risk data.

Measures can include rate limitation, detection of unusual logins, matching of transaction features, spam and malware filters, multifactor authentication and manual checks.

The legal basis is legal security and due diligence obligations, the execution of the contract as well as legitimate interests in fraud prevention, IT security and protection of other users. data are limited to the necessary extent; Sensitive decisions are not based solely on non-transparent or extraneous features.

29 Moderation, reporting system and administrative orders

In the case of reports of unlawful content, Scriptfabrik processes information of the reporter, reported content, reasons, evidence, affected accounts, decision, communication and remedies.

The processing serves the fulfilment of legal platform obligations, enforcement of the terms of use, danger prevention and legal defence. The identity and contact details of the reporter are not disclosed to the reported user without a legal basis.

In the case of lawful orders, necessary data may be transmitted to courts, law enforcement, supervisory, tax or product safety authorities. Scriptfabrik examines jurisdiction and scope as far as this is legally possible.

30. Automated testing and profiling

Scriptfabrik can use automated systems for spam, malware, fraud and rating review, risk detection, product recommendations and security case prioritization.

Unless an exclusively automated decision with legal or comparable significant effect is made, these measures are based on contract, legal obligations, consent or legitimate interests – depending on the respective purpose.

If a person is to be subjected to an exclusively automated significant decision, Scriptfabrik informs in advance about the legal basis, essential logic as well as meaning and possible consequences. Affected persons, where provided for by law, receive the right to human intervention, to express their own point of view and to challenge the decision.

AI systems are not used to derive particularly sensitive properties from publicly available or provided data without an appropriate basis.

31. Hosting, cloud, CDN and technical service providers

Scriptfabrik uses hosting, cloud, content delivery, email, support, security, backup and IT service providers. These processes in particular server logs, IP addresses, databases, files, messages, backups and technical usage data.

Processors are contractually bound, carefully selected and only used according to documented instructions. If a service provider acts for its own purposes, its role is identified separately.

The specific essential providers are named in this declaration, in the ordering process, in the cookie overview or on request. Changes to the service providers take place in compliance with the data protection requirements.

32. Recipients and categories of recipients

Depending on the respective process, data can be obtained:

  • external dealers and their agents;

  • payment service providers, banks and card companies;

  • shipping, logistics and returns service providers;

  • registrars, registries and certificate providers;

  • hosting, cloud, security, communication and IT service providers;

  • analytics, consent, advertising and affiliate providers subject to consent;

  • tax, legal and economic advisors;

  • insurers, debt collection agencies or audit bodies for legitimate claims;

  • courts, authorities and other legally authorized bodies.

Data will only be transmitted if this is necessary for contract, consent, legal obligation or an overriding legitimate interest.

Employees and service providers receive access according to the principle of necessity and are obliged to maintain confidentiality.

33. International data transfers

Scriptfabrik prefers processing within the European Union and the European Economic Area. For recipients in a third country, a transfer will only take place if the legal requirements are met.

In particular, an adequacy decision by the European Commission, suitable guarantees such as the standard contractual clauses, binding internal data protection regulations or a strictly interpreted legal exception are considered as a basis.

Where necessary, additional technical, organisational or contractual protective measures shall be taken. Information on the specific basis for transmission and a copy or reference of the appropriate guarantees can be requested via the data protection contact address.

A mere possibility of remote access from a third country is taken into account in the assessment.

34. Storage time

Personal data will be deleted or anonymized as soon as their purpose ceases and no reasons for retention, proof or security oppose.

The duration depends in particular on:

  • the duration of the account or contract;

  • statutory commercial, tax, money laundering, platform or product safety periods;

  • limitation and remedy periods;

  • duration of outstanding payments, chargebacks, complaints or litigation;

  • evidence of safety and abuse required;

  • documented period of validity of consent;

  • technical backup and extinguishing cycles.

Where there is no fixed deadline, Scriptfabrik regularly checks whether further storage is necessary. Data in backups is locked and deleted in the normal overwrite cycle, unless restored for compelling reasons.

Specific cookie runtimes are in the cookie overview.

35. Deletion of accounts

Users can request the closure of their account or use the dedicated account function. Publicly visible contents are deleted or anonymized, as far as no rights of third parties, documentation or legal storage obligations conflict.

In particular, immediate complete deletion is not possible as long as orders, withdrawals, chargebacks, complaints or claims are open or billing, tax, security and transaction data must be kept.

Until the final deletion, no longer required data will be blocked as far as possible and processed only for the remaining purpose.

36. Rights of data subjects

In accordance with the GDPR, affected persons have in particular the following rights:

  • access to personal data processed;

  • correcting inaccurate data or completing incomplete data;

  • deletion if there is no priority reason for retention;

  • restriction of processing;

  • receiving data provided in a structured, common and machine-readable format and transmitting it to another controller, provided that the conditions of data portability are met;

  • objecting to processing on the basis of legitimate interests or a task in the public interest;

  • any opposition to direct marketing, including related profiling;

  • withdrawal of consent with effect for the future;

  • rights relating exclusively to automated significant decisions;

  • a complaint to a data protection supervisory authority;

  • judicial remedy.

To process an application, Scriptfabrik may request additional information if there are reasonable doubts about the identity. A copy of the identity document shall only be requested if lesser funds are insufficient; Unneeded information should be blackened.

Applications will in principle be answered within one month. In the event of particular complexity or numerous requests, the period may be extended to the extent permitted by law after prior information.

37. Specific reference to the right of appeal

Where personal data are processed on the basis of legitimate interests, the data subject may object at any time for reasons arising from his particular situation. Scriptfabrik will then no longer process the data, unless compelling legitimate reasons prevail or the processing serves to assert, exercise or defend legal claims.

Direct advertising and associated profiling can be objected to at any time without giving reasons. After the objection, the data will no longer be used for these purposes.

38. Right of appeal and competent supervision

Data subjects may complain to a data protection supervisory authority, in particular in the Member State of their habitual residence, their place of work or the suspected infringement.

In principle, the following Dutch supervisory authority is responsible for Scriptfabrik:

Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ The Hague
Netherlands
Website: https://autoriteitpersoonsgegevens.nl

Scriptfabrik asks for data protection concerns first welcome@scriptfabrik.info so that an immediate clarification can be attempted. This is not a prerequisite for a complaint to the supervisory authority.

39. Data security and data breaches

Scriptfabrik implements appropriate technical and organisational measures based on risk, state of the art, implementation costs and processing methods. This may include encryption, access controls, permission concepts, logging, backups, system separation, security updates, recovery testing and employee training.

No procedure on the Internet offers absolute security. Scriptfabrik regularly reviews protective measures and adjusts them as necessary.

Data breaches are documented, evaluated and, where required by law, reported to the competent supervisory authority and data subjects.

40. Minors

The platform and its paid contracts are generally aimed at persons of legal age. Scriptfabrik does not knowingly request data from children for services not intended for them.

If Scriptfabrik becomes aware of an unauthorized processing of child data, the data will be deleted or the necessary consent or other legal basis checked.

41. No purposeless disclosure and no sale of data

Scriptfabrik does not sell any personal data as an independent commercial good. A transmission is made only for the purposes described in this declaration and on a valid legal basis.

Advertising or affiliate partners will only receive personal or device-related data if this is permitted by applicable law and – where necessary – covered by prior consent.

42. Changes to this data protection declaration

Scriptfabrik updates this privacy policy if processing, service providers or the legal situation change.

The current version will be published on the website. Scriptfabrik also provides information about material changes that significantly affect existing accounts or ongoing processing in a suitable form, for example by e-mail or in the customer account.

A new data protection declaration does not give retroactive consent. If a consent is required for a new processing, this will be obtained separately.

43. Data protection contact

Questions, requests, revocations and objections may be addressed to:

Scriptfabrik B.V.
Pastoor Jacobsweg 27
6226 VV Maastricht
Netherlands
E-mail: welcome@scriptfabrik.info

Please do not submit an ID copy or confidential access data unsolicited by email.