Privacy Policy
1. General Information
This Privacy Policy explains how personal data is processed when you visit the website www.bloomafterdark.com, contact us, or submit an application through our website.
Personal data means any information relating to an identified or identifiable natural person, such as a name, email address, telephone number or IP address.
We process personal data in accordance with the General Data Protection Regulation of the European Union (“GDPR”) and other applicable German and European data protection laws.
2. Data Controller
The controller responsible for the processing of personal data on this website is:
Daniel Schulz
Bahnhofstraße 50
89129 Langenau
Germany
Email: info@bloomafterdark.com
The controller determines the purposes and means of processing personal data in connection with this website.
3. Hosting
This website is hosted using services provided by Hostinger.
Depending on the specific hosting agreement, the relevant Hostinger contracting entity may be:
Hostinger International Ltd.
61 Lordou Vironos Street
6023 Larnaca
Cyprus
or another company belonging to the Hostinger group as identified in the applicable hosting agreement.
When you access this website, Hostinger’s servers may automatically process technical connection data necessary to deliver the website securely and reliably.
This may include:
IP address;
date and time of access;
requested page or file;
amount of data transferred;
browser type and browser version;
operating system;
referring website;
device information;
access status or HTTP status code; and
technical error and security information.
The processing is necessary to provide the website, maintain system security, prevent misuse and ensure the technical stability of the website.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and technically efficient operation of the website.
Hostinger processes relevant data on our behalf in accordance with Article 28 GDPR.
Hostinger may use affiliated companies and subprocessors. Where personal data is transferred outside the European Economic Area, the transfer is carried out on the basis of an applicable adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, where required.
Server log data is stored only for as long as necessary for security, technical operation and misuse prevention, unless longer storage is required to investigate a specific incident or comply with a legal obligation.
4. Website Access and Server Log Files
When you visit the website, certain technical data is processed automatically by the web server.
This processing is necessary because a website cannot ordinarily be delivered to your device without temporarily processing your IP address and related technical information.
The purposes of this processing are:
delivering the website;
ensuring a stable connection;
displaying the website correctly;
detecting and preventing attacks or misuse;
troubleshooting technical problems; and
maintaining the security of our systems.
The legal basis is Article 6(1)(f) GDPR.
We do not use server log data to create personal profiles or to track individual visitors across unrelated websites.
5. Contact by Email
You may contact us using the email address provided on this website.
When you contact us by email, we process the information contained in your message. This may include:
your name;
your email address;
the content of your message;
attachments;
the date and time of the communication; and
any other information you voluntarily provide.
We process this data to respond to your inquiry, communicate with you and handle the matter raised in your message.
Where your inquiry concerns the initiation or performance of a contract, the legal basis is Article 6(1)(b) GDPR.
For general inquiries, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is responding to inquiries and maintaining professional communications.
Where processing is necessary to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR.
We retain correspondence for as long as necessary to handle the relevant matter. Data may be retained for a longer period where statutory retention obligations apply or where the data is required to establish, exercise or defend legal claims.
Please do not send unnecessary confidential information, access credentials, identification documents, payment details or sensitive personal data by ordinary email.
6. Application and Contact Form
The website provides an application form through which prospective clients or business partners may contact Bloom After Dark.
The form may request the following information:
legal name;
email address;
telephone number;
primary platforms;
current audience or performance metrics; and
other information voluntarily submitted as part of the application.
Mandatory fields are marked accordingly. Without the required information, we may not be able to assess or respond to your application.
The data submitted through the form is used to:
receive and review your application;
assess whether a potential business relationship may be suitable;
contact you regarding your application;
answer questions;
arrange consultations; and
take steps at your request before entering into a possible contract.
The legal basis is Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract.
Where an application does not directly concern a potential contract, processing may be based on Article 6(1)(f) GDPR. Our legitimate interest is reviewing business inquiries and selecting potential clients or cooperation partners.
Application data is not used for unrelated advertising or sold to third parties.
If no business relationship is established, the application data will generally be deleted when it is no longer required for the application process. Data may be retained for a limited additional period where this is necessary to document the application process, defend against legal claims or comply with statutory obligations.
If a contractual relationship is established, relevant information may be transferred to the corresponding client or contractual records and retained in accordance with applicable statutory requirements.
7. Sensitive Information
The application form is not intended for the submission of special categories of personal data within the meaning of Article 9 GDPR.
Please do not submit information concerning, in particular:
health;
racial or ethnic origin;
political opinions;
religious or philosophical beliefs;
trade union membership;
genetic or biometric data;
sexual orientation; or
information concerning a person’s sex life,
unless this information is specifically requested and there is an appropriate legal basis for processing it.
Please also avoid submitting identification documents, banking details, passwords or other highly confidential information unless expressly requested through an appropriate and secure channel.
If such information is submitted without being requested, we will process it only insofar as necessary to review, secure or delete the submission.
8. Recipients of Personal Data
Within Bloom After Dark, personal data is accessible only to persons who require it for the relevant purpose.
Personal data may also be processed by service providers supporting the operation of the website or communication systems. These may include:
hosting providers;
website infrastructure providers;
email service providers;
IT support providers; and
professional advisers where necessary.
Service providers acting on our behalf process personal data only on documented instructions and are contractually required to maintain appropriate confidentiality and security.
We may also disclose personal data:
where required by law;
in response to a lawful request from a court or public authority;
to protect our rights or the rights of others;
to prevent fraud, misuse or security incidents; or
where necessary to establish, exercise or defend legal claims.
We do not sell personal data.
9. International Data Transfers
Some service providers or their subprocessors may process data outside Germany or outside the European Economic Area.
Where personal data is transferred to a country for which the European Commission has issued an adequacy decision, the transfer may be based on that decision.
Where no adequacy decision exists, we use appropriate safeguards where required, such as the European Commission’s Standard Contractual Clauses under Article 46 GDPR.
Additional technical and organisational safeguards may be implemented where appropriate.
You may contact us for further information about the safeguards applicable to a particular transfer.
10. Cookies and Similar Technologies
This website does not intentionally use cookies for advertising, behavioural tracking or cross-site profiling.
Technically necessary cookies or comparable local storage technologies may be used where required for:
basic website functionality;
security;
fraud or misuse prevention;
form functionality;
session management; or
remembering essential technical settings.
Where a cookie or similar technology is strictly necessary to provide a service expressly requested by the user, its use may be permitted without consent under the applicable German telecommunications and data protection rules.
Any non-essential cookies or comparable technologies requiring consent will only be used after valid consent has been obtained.
Should analytics, advertising, social-media or other non-essential services be added in the future, this Privacy Policy and, where necessary, the website’s consent mechanism will be updated before such services are activated.
11. No Analytics or Advertising Tracking
At the time of this Privacy Policy, we do not intentionally use:
Google Analytics;
Google Tag Manager for analytics or marketing purposes;
Meta Pixel;
TikTok Pixel;
Microsoft Advertising tracking;
behavioural advertising systems; or
comparable visitor profiling technologies.
We do not create advertising profiles based on your use of this website.
Technical information contained in server logs may nevertheless be processed for website security, delivery and troubleshooting as described above.
12. External Links
This website may contain links to websites or services operated by third parties.
When you follow an external link, the relevant third party may process personal data under its own responsibility. We do not control the privacy practices or content of external websites.
You should review the privacy information of the relevant third-party provider before submitting personal data.
A simple link does not normally result in personal data being transferred to the linked provider until you select or open the link. However, technical circumstances may vary depending on how the link is implemented.
13. Persons Under the Age of 18
Bloom After Dark’s services and application process are intended exclusively for adults aged 18 or older.
The website is not intended to collect personal data from children or minors.
If we become aware that a person under the age of 18 has submitted personal data without an appropriate legal basis, we will take reasonable steps to delete the data.
Parents or legal guardians who believe that a minor has provided personal data may contact us at info@bloomafterdark.com.
The age restriction does not necessarily mean that the publicly accessible website contains adult content.
14. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected.
The applicable retention period depends on:
the nature of the inquiry or application;
whether a contractual relationship is established;
applicable statutory retention obligations;
the need to document business communications;
the limitation periods applicable to potential legal claims; and
whether an ongoing dispute or security incident exists.
When personal data is no longer required and no legal basis for further retention exists, it will be deleted or anonymised.
Where deletion is temporarily prevented by a statutory retention obligation, the relevant data will be restricted and used only for the purpose justifying continued storage.
15. Legal Bases for Processing
Depending on the circumstances, we process personal data on one or more of the following legal bases:
Article 6(1)(a) GDPR: consent;
Article 6(1)(b) GDPR: performance of a contract or steps taken before entering into a contract;
Article 6(1)(c) GDPR: compliance with a legal obligation; and
Article 6(1)(f) GDPR: legitimate interests pursued by us or a third party, provided that such interests are not overridden by your interests, rights or freedoms.
Where processing is based on legitimate interests, those interests may include:
operating the website securely and reliably;
preventing fraud and misuse;
responding to inquiries;
reviewing applications;
maintaining business communications;
protecting confidential information; and
establishing, exercising or defending legal claims.
16. Requirement to Provide Personal Data
You are generally not legally required to provide personal data merely to visit the publicly accessible pages of this website.
Certain technical data is processed automatically because it is necessary to deliver the website.
Where you contact us or submit an application, the provision of certain information may be necessary to respond to you or assess your application.
Mandatory information is identified in the relevant form. Failure to provide required information may mean that we cannot process the inquiry or application.
17. Automated Decision-Making
We do not use personal data submitted through the website for decisions based solely on automated processing that produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR.
Applications may be assessed using organisational or technical tools, but final decisions are not intended to be made exclusively by an automated system.
18. Data Security
We use appropriate technical and organisational measures designed to protect personal data against:
accidental or unlawful destruction;
loss;
alteration;
unauthorised disclosure;
unauthorised access; and
other unlawful processing.
These measures may include encrypted transmission, access restrictions, secure hosting, system updates, backups and internal confidentiality controls.
No internet transmission or electronic storage system can be guaranteed to be completely secure. You should therefore avoid transmitting unnecessary confidential or sensitive information through unencrypted channels.
19. Your Rights under the GDPR
Subject to the applicable legal requirements, you have the following rights:
Right of access
Under Article 15 GDPR, you may request information about whether we process your personal data and obtain access to that data.
Right to rectification
Under Article 16 GDPR, you may request the correction of inaccurate personal data and the completion of incomplete data.
Right to erasure
Under Article 17 GDPR, you may request the deletion of your personal data where the applicable requirements are met.
The right to erasure may be restricted where continued processing is required by law or necessary for the establishment, exercise or defence of legal claims.
Right to restriction of processing
Under Article 18 GDPR, you may request that the processing of your personal data be restricted in certain circumstances.
Right to data portability
Under Article 20 GDPR, you may have the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have that data transmitted to another controller.
Right to object
Under Article 21 GDPR, you may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or Article 6(1)(f) GDPR.
We will then cease processing the relevant data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims.
You have the right to object at any time to processing of personal data for direct marketing purposes.
Right to withdraw consent
Where processing is based on consent, you may withdraw your consent at any time with effect for the future.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.
You may contact the supervisory authority responsible for your habitual residence, place of work or the place of the alleged infringement.
For a controller established in Baden-Württemberg, the competent supervisory authority is generally:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany
You are not required to contact us before lodging a complaint, although we welcome the opportunity to address your concerns directly.
20. Exercising Your Rights
To exercise your data protection rights, contact:
Daniel Schulz
Bahnhofstraße 50
89129 Langenau
Germany
Email: info@bloomafterdark.com
Please provide sufficient information to allow us to identify the relevant data and process your request.
Where reasonably necessary, we may request additional information to verify your identity and prevent unauthorised disclosure of personal data.
21. Changes to This Privacy Policy
We may update this Privacy Policy where necessary to reflect:
changes to the website;
new services or technical functions;
changes in our processing activities;
changes to service providers; or
changes in applicable legal requirements.
The current version will be published on this website together with the date of the latest update.
Where a change materially affects how personal data is processed, we will provide additional notice where required by law.
22. Contact
For questions about this Privacy Policy or the processing of your personal data, please contact:
Daniel Schulz
Bahnhofstraße 50
89129 Langenau
Germany
Email: info@bloomafterdark.com
