Version: August 2026

Privacy Policy

This privacy policy explains how Impuls GmbH processes personal data on vinzar.de, in contact forms and in project requests.

In the event of discrepancies, the German version is authoritative.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is Impuls GmbH, Am Gewerbepark 43, 64823 Groß-Umstadt, Germany.

Contact: info@vinzar.de, phone: +49 6078 394959-0, website: https://vinzar.de.

VINZAR is a brand and digital service of Impuls GmbH. VINZAR is not a separate legal entity.

2. Data protection officer

No separate data protection officer has been appointed. Privacy requests may be sent at any time to info@vinzar.de.

3. Data we process

We process only data that is required to use the website, handle requests, prepare offers and secure the service, or data that you provide voluntarily.

  • Contact details such as name, email address and telephone number.
  • Project details such as selected project type, description, dimensions, budget, timeframe and wishes, where provided by you.
  • Photos, sketches, plans, PDF files, reference images and related file metadata.
  • Technical access data such as IP address, browser and device information, URL, time, status code and similar server log data.
  • Technical status data such as locale selection, browser form draft, submission ID and idempotency/rate-limit data.

4. Contact form

If you use the contact form, we process your name, email address, message, selected language and technical data for abuse prevention. The processing is used to answer your message and follow up on the communication.

The legal basis is Art. 6(1)(b) GDPR where pre-contractual communication is concerned and Art. 6(1)(f) GDPR for security, abuse prevention and evidence of communication.

5. Project requests and planning forms

The public planning forms allow you to submit requests for kitchens, custom furniture, bathroom and utility furniture, outdoor projects, and railings or French balconies.

We process the contact and project data you enter, especially description, dimensions, postal code, requested functions, style, appliance positions, existing constraints and other notes. In the one-page request forms at least one photo or reference image is required so that an initial professional assessment is possible.

The legal basis is Art. 6(1)(b) GDPR for handling your request, preparing an offer and taking pre-contractual steps.

6. Photos, plans and documents

Uploaded photos, plans, sketches, PDF files and reference images are used to assess your request professionally, understand dimensions and installation situations, and prepare questions or offers.

Please upload only project-related files. Avoid unnecessary personal data, identity documents, bank details, health data and images of uninvolved third parties unless you have the necessary permission.

Files are not displayed publicly. They are processed in the protected CRM and upload storage of Impuls GmbH.

7. Local file analysis, OCR and AI

Public uploads do not automatically send your photos to OpenAI. OpenAI Vision is disabled at launch.

OCR is not run automatically for public submissions. The existing OCR function is local and available only as a separate manually triggered tool in the protected CRM environment.

PDF or image files may be analysed locally for technical purposes, for example to record file metadata or simple text extracts. This processing supports handling your request.

8. Technically necessary browser storage

The website uses technically necessary storage to provide language selection and secure form use. This includes the NEXT_LOCALE cookie for language selection.

The kitchen planner may store a browser form draft under the key kitchenWizard:draft:v2. It stores form data, current step, a submission ID and file names, but not the actual files.

A submission ID and idempotency data may be used for duplicate prevention and secure request handling. The legal basis for technically necessary storage is § 25(2) No. 2 TDDDG; the data protection basis is Art. 6(1)(b) and (f) GDPR.

9. Server logs and security

When the website is accessed, technical server logs are generated, in particular by the web server and the application. These may include IP address, time, requested URL, status code, browser/device information and error data.

We use this data to deliver the website, analyse errors, maintain security, prevent abuse and keep the service stable. The legal basis is Art. 6(1)(f) GDPR.

Nginx access/error logs and PM2/application logs are generally stored for 14 days unless longer storage is required by legal duties, incident analysis, security incidents or legal claims.

10. Rate limiting and abuse protection

To protect forms and upload functions we use technical rate-limiting mechanisms. IP addresses or derived hashed technical identifiers may be processed.

This processing prevents spam, automated attacks, duplicate submissions and abusive uploads. The legal basis is Art. 6(1)(f) GDPR.

11. Email communication

When you submit a form, we may forward your request internally by email and send you a confirmation of receipt. The necessary contact and request information is processed for this purpose.

For email communication we use Google Workspace, provided by Google. A data processing agreement for Google Workspace has been confirmed.

When emails are delivered to your email address, your own email provider may also process personal data.

12. CRM and internal access

Requests, project data and attachments are processed in a protected CRM so that they can be reviewed, answered and prepared for offer steps.

Access is limited to management, separately authorised employees of Impuls GmbH and separately authorised contractors bound by confidentiality, where needed for processing and, where required, under a data processing agreement.

13. Hosting

The website is hosted by IONOS. The provider is IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. A data processing agreement with IONOS has been confirmed.

The hosting provider processes technical data required for operation, security, delivery and maintenance of the website. The legal bases are Art. 6(1)(f) GDPR as well as Art. 28 and Art. 32 GDPR.

14. Service providers and recipients

We use service providers only where this is necessary for operation, security, communication, request handling or legal obligations. This includes in particular hosting, email services, technical maintenance and authorised internal or contract-bound support.

Where required, service providers are engaged on the basis of Art. 28 GDPR. Data is disclosed to other recipients only if this is required to handle your request, perform a contract, fulfil legal obligations or protect legitimate interests.

15. Transfers to third countries

Within Google Workspace, subprocessors may be used and processing may take place outside the European Economic Area. Such transfers are protected under Art. 44 et seq. GDPR by an adequacy decision, standard contractual clauses or other suitable safeguards.

Hosting with IONOS is disclosed as a German provider; no specific physical data centre location is claimed here.

16. Legal bases

  • Art. 6(1)(b) GDPR: handling requests, pre-contractual steps, preparation of offers and later contract performance.
  • Art. 6(1)(c) GDPR: compliance with statutory retention, evidence and cooperation obligations.
  • Art. 6(1)(f) GDPR: operation and security of the website, server logs, rate limiting, abuse prevention, backups, error analysis and establishment, exercise or defence of legal claims.
  • Art. 28 GDPR: engagement of processors.
  • Art. 32 GDPR: security of processing.
  • Art. 44 et seq. GDPR: safeguards for transfers to third countries.

17. Retention and deletion

Purpose-bound data is deleted once it is no longer required for the stated purposes and no statutory obligations or legitimate interests prevent deletion.

  • Requests without a contract: 12 months after the last substantive contact.
  • Photos, plans and PDF files relating to requests without a contract: 12 months after the last substantive contact.
  • Contact correspondence without a subsequent contract: 12 months after completion of the communication.
  • Data that becomes part of an offer, order, contract, invoice or accounting record: according to the applicable commercial, tax and civil-law retention periods.
  • Nginx access/error logs and PM2/application logs: generally 14 days.
  • Ordinary backups: rolling 30 days.
  • Longer storage occurs only where there is a legal obligation, a fault is being investigated, a security incident is being reviewed, or legal claims are established, exercised or defended.

18. Backups

We create technical backups to restore the service and protect against data loss. Backups may contain requests, attachments and technical system data.

Ordinary backups are stored on a rolling 30-day basis. For deletion requests, data is deleted in active systems after review; in backups it is removed through the regular overwrite cycle unless a duty or legitimate interest requires longer storage.

19. Your rights

Subject to the GDPR, you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and rights relating to automated decisions (Art. 22).

You can send rights requests and deletion requests to info@vinzar.de. Before providing access, rectifying or deleting data, Impuls GmbH may carry out a proportionate identity check.

20. Right to lodge a complaint

Under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority. In particular, the following authority may be competent: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wilhelmstraße 7, 65185 Wiesbaden, Germany, email: poststelle@datenschutz.hessen.de, phone: +49 611 1408-0.

21. No automated decisions

No automated decision-making, including profiling, takes place that produces legal effects concerning you or similarly significantly affects you.

22. No marketing tracking at launch

At launch we do not use Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Microsoft Clarity, marketing cookies, advertising tracking or profiling.

23. Security of processing

We take technical and organisational measures to protect personal data. These include HTTPS, protected internal areas, upload tokens, validation of file types and sizes, access restrictions, logging, rate limiting and backups.

These measures support confidentiality, integrity, availability and resilience of the systems within the meaning of Art. 32 GDPR.

24. Validity of this version

This version applies from its publication on vinzar.de. We update this privacy policy if data processing or legal requirements change.