Privacy policy

Status: May 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states as well as other data protection regulations is:

Großräschener Orchideen Hans-Joachim Wlodarczyk Werner-Seelenbinder-Str. 21 01983 Großräschen Germany

Phone: +49 (0) 35753 5791 Email: info@orchideen.de

2. General Information

The protection of your personal data is important to us. We treat your personal data confidentially and in accordance with the statutory data protection regulations, in particular the GDPR and the Telecommunications-Digital Services Data Protection Act (TDDDG), as well as this privacy policy.

Personal data is any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR), for example, name, address, email address, or IP address.

We point out that data transmission over the Internet (e.g., when communicating by email) can have security gaps. Complete protection of data from access by third parties is not possible.

3. Data Protection Officer

We are not required to appoint a data protection officer. In our company, fewer than 20 people are constantly involved in the automated processing of personal data; a data protection impact assessment according to Art. 35 GDPR is not required, and no processing of special categories of personal data within the meaning of Art. 9 GDPR takes place as a core activity.

If you have any questions about data protection, please contact the contact details listed under section 1 directly.

4. Your Rights as a Data Subject

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)

  • Right to rectification (Art. 16 GDPR)

  • Right to erasure (Art. 17 GDPR)

  • Right to restriction of processing (Art. 18 GDPR)

  • Right to data portability (Art. 20 GDPR)

  • Right to object to processing (Art. 21 GDPR)

  • Right to withdraw consent (Art. 7 para. 3 GDPR) with effect for the future

To exercise these rights, a simple notification to the contact details provided under section 1 is sufficient.

Right to Object to Processing Based on Legitimate Interests

If the processing of your personal data is based on Art. 6 para. 1 lit. f GDPR, you have the right to object to the processing at any time for reasons arising from your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.

Right to Lodge a Complaint with a Supervisory Authority

According to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is:

The State Commissioner for Data Protection and for the Right to Inspect Files Brandenburg Stahnsdorfer Damm 77 14532 Kleinmachnow Phone: +49 (0)33203 356-0 Email: poststelle@lda.brandenburg.de www.lda.brandenburg.de

You can also contact the data protection supervisory authority of your usual place of residence or workplace.

5. SSL/TLS Encryption

This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content (e.g., orders or inquiries that you send to us as the site operator). You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

6. Hosting

We host the content of our website with

IONOS SE Elgendorfer Straße 57 56410 Montabaur Germany

To fulfill the contract with our hosting provider, personal data (in particular IP addresses) is processed on the provider's servers. We have concluded a data processing agreement with IONOS SE in accordance with Art. 28 GDPR.

The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in a reliable and secure provision of our online offer).

7. Server Log Files

When you visit our website, the hosting provider automatically collects information in so-called server log files, which your browser transmits. These are:

  • Browser type and version

  • Operating system used

  • Referrer URL

  • Hostname of the accessing computer

  • Time of the server request

  • IP address

This data is not merged with other data sources.

The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website - for this purpose, the server log files must be recorded.

The log files are stored for a maximum of 7 days and then deleted. Data that must be retained for evidence purposes (e.g., in the case of attempted attacks) is excluded from deletion until the respective incident is finally clarified.

8. Cookies and Similar Technologies

Our website uses cookies. Cookies are small text files that are stored on your device. They do no harm and do not contain viruses.

We distinguish between:

  • Technically necessary cookies, which are indispensable for the operation of the website (e.g., shopping cart function, session management, login, language setting).

  • Non-essential cookies, which serve for reach measurement, analysis, or marketing.

Legal Bases

The storage of technically necessary cookies is based on § 25 para. 2 no. 2 TDDDG; they are absolutely necessary for us to provide the telemedia service you have requested. If personal data is processed in this context, this is based on Art. 6 para. 1 lit. b GDPR (contract performance) or Art. 6 para. 1 lit. f GDPR (legitimate interest in the trouble-free operation of the website).

All other cookies and similar technologies are only set with your consent in accordance with § 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR. You can revoke this consent at any time via the consent tool on our website.

Consent Management

We use the open-source tool "CookieConsent" (orestbida/cookieconsent) to obtain and manage your consent. The tool is delivered locally from our server and does not transmit any data to third parties. Your consent decision is stored exclusively in your browser (cookie or localStorage).

You can access and change your cookie settings at any time via the corresponding link in the footer of our website.

9. Processing in the Context of Orders (Online Shop)

Order Processing

If you order in our shop, we collect and process the personal data required for contract processing. These are in particular:

  • Salutation, first and last name

  • Billing and delivery address

  • Email address

  • Phone number (if provided)

  • Payment data according to the chosen payment method

  • Order data (ordered items, order number, order date)

The legal basis is Art. 6 para. 1 lit. b GDPR (performance of a contract or pre-contractual measures).

This data is stored for the duration of the contract processing. After contract processing, your data will be stored for the duration of the statutory retention periods (in particular 6 years according to § 257 HGB for business letters and 10 years according to § 147 AO for tax-relevant documents) and deleted after these periods have expired, unless you have consented to further processing.

Customer Account

You have the option to create a customer account in our shop. When registering, we collect the data required for the creation and use of the account (name, address, email address, password in encrypted form). The customer account facilitates future orders by not having to re-enter stored data and allows you to view your order history.

The legal basis is Art. 6 para. 1 lit. b GDPR (contract performance) and, if applicable, Art. 6 para. 1 lit. a GDPR (consent) if you have voluntarily provided data beyond the mandatory information.

You can have your customer account deleted at any time. To do so, send a corresponding message to info@orchideen.de. Any statutory retention obligations remain unaffected.

Data Transfer to Shipping Service Providers

To deliver your order, we transmit your delivery and contact data to:

DHL Paket GmbH Sträßchensweg 10 53113 Bonn Germany

The transfer is based on Art. 6 para. 1 lit. b GDPR to fulfill the purchase contract.

Data Transfer to Payment Service Providers

We offer the following payment methods: prepayment, invoice, SEPA direct debit, and PayPal.

For the payment methods prepayment, invoice, and SEPA direct debit, we process your payment data (name, IBAN, order amount, purpose) exclusively ourselves to process the payment via our house bank account. A transfer to third parties only takes place insofar as it is necessary for the payment processing with our house bank. We do not obtain a credit check.

For the payment method PayPal, the data required for payment processing is transmitted to

PayPal (Europe) S.à r.l. et Cie, S.C.A. 22-24 Boulevard Royal 2449 Luxembourg

The data processing by PayPal is carried out independently; details can be found in PayPal's privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.

The legal basis for the transfer is Art. 6 para. 1 lit. b GDPR (contract performance).

10. Contact Form and Email Contact

If you send us inquiries via the contact form or email, your details will be stored with us for the purpose of processing the inquiry and in case of follow-up questions. Mandatory information is marked as such; further information is voluntary.

Processed data:

  • Name

  • Email address

  • Content of the message

  • any other data you voluntarily provide

The legal basis is:

  • Art. 6 para. 1 lit. b GDPR, if your inquiry relates to the performance of a contract or pre-contractual measures

  • Art. 6 para. 1 lit. f GDPR in all other cases, as we have a legitimate interest in the effective processing of inquiries addressed to us

The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your inquiry has been processed). Mandatory statutory provisions – in particular retention periods – remain unaffected.

11. Newsletter

Newsletter Dispatch via Mailjet

If you order our newsletter, we collect the data required for this purpose (in particular email address, if applicable, name) and transmit it to our newsletter service provider:

Mailjet SAS 4 rue Jules Lefebvre 75009 Paris France

Mailjet is part of the Sinch group of companies. We have concluded a data processing agreement with Mailjet in accordance with Art. 28 GDPR. Mailjet processes the data exclusively within the European Union for the dispatch and analysis of our newsletters (e.g., delivery rates, open and click rates).

Further information can be found in Mailjet's privacy policy: https://www.mailjet.com/legal/privacy-policy/

Double-Opt-In Procedure

Registration for our newsletter takes place in the so-called double-opt-in procedure. After your registration, you will receive an email asking you to confirm your registration. This serves to protect against someone registering with a foreign email address. We log the time of registration, confirmation, and your IP address to be able to prove the registration in case of dispute.

Legal Basis and Revocation

The legal basis for the newsletter dispatch is your consent according to Art. 6 para. 1 lit. a GDPR and § 7 para. 2 no. 3 UWG.

You can unsubscribe from the newsletter at any time by clicking on the unsubscribe link in each newsletter email or by sending a corresponding message to info@orchideen.de. The legality of the data processing operations already carried out remains unaffected by the revocation.

After unsubscribing, your email address will be deleted from our newsletter distribution list, unless you have expressly consented to further use or we reserve the right to use data beyond this, which is legally permitted.

12. Web Analysis and Advertising

The following services are used exclusively based on your consent in accordance with § 25 para. 1 TDDDG and Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time via our consent tool.

Google Analytics 4 (GA4)

This website uses – if you have consented – functions of the web analysis service Google Analytics 4. Provider is:

Google Ireland Limited Gordon House Barrow Street Dublin 4, Ireland

Google Analytics allows us to analyze the behavior of website visitors. We receive various usage data, such as page views, duration of stay, operating systems used, and origin of the user. This data is summarized in a user ID and assigned to the respective end device of the website visitor.

We use Google Analytics with activated IP anonymization. Your IP address is therefore shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area before being transmitted to the USA.

Google Analytics 4 uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting).

Data Transfer to the USA: The data transfer to the USA is based on the EU-US Data Privacy Framework (adequacy decision of the EU Commission of July 10, 2023) and additionally on the standard contractual clauses of the EU Commission. Google LLC is certified under the EU-US Data Privacy Framework.

We have concluded a data processing agreement with Google in accordance with Art. 28 GDPR.

Storage period: The data stored by Google at the user and event level, which is linked to cookies, user IDs, or advertising IDs (e.g., DoubleClick cookies, Android advertising ID), is anonymized or deleted after 14 months.

Further information can be found in Google's privacy policy: https://policies.google.com/privacy

Google Ads and Conversion Tracking

This website uses – if you have consented – Google Ads (formerly Google AdWords) and Google Ads conversion tracking. Provider is Google Ireland Limited (see above).

We use Google Ads to draw attention to our attractive offers on external websites with the help of advertising media. Within the framework of the advertising campaigns, we can determine how successful the individual advertising measures are. We pursue the aim of showing you advertising that is of interest to you, making our website more interesting for you, and achieving a fair calculation of the advertising costs incurred.

If you click on an ad placed by Google, a cookie for conversion tracking is stored on your device. These cookies usually expire after 30 days and are not used for personal identification. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can recognize that the user clicked on the ad and was redirected to this page.

Google Ads may also involve data transfer to the USA. The transfer is based on the EU-US Data Privacy Framework and the standard contractual clauses.

Further information on Google Ads and data processing by Google can be found here: https://policies.google.com/privacy

YouTube Videos

We embed videos from the YouTube platform on our website. Provider is:

Google Ireland Limited Gordon House Barrow Street Dublin 4, Ireland

We do not use YouTube in enhanced privacy mode (youtube-nocookie.com). As soon as you call up a page with embedded YouTube videos and have agreed to the embedding, a connection to the YouTube servers is established. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.

When the video is called up, cookies and similar recognition technologies (e.g., device fingerprinting) may also be used. In this way, YouTube can obtain information about visitors to this website. This information is used, among other things, to collect video statistics, improve user-friendliness, and prevent fraud attempts.

If data is transferred to the USA, this is based on the EU-US Data Privacy Framework and the standard contractual clauses.

Further information on data protection at YouTube can be found in Google's privacy policy: https://policies.google.com/privacy

13. Social Media Links

On our website, you will find links (e.g., share buttons) to social networks such as Facebook and X (formerly Twitter). These links are designed as static links or buttons and only establish a connection to the servers of the respective providers when you actively click the button. Before that, no data is transmitted to the providers.

If you click on such a link and are redirected to the platform of the respective provider, the data protection provisions of the respective provider apply. We have no influence on the data processing by the provider.

14. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy to ensure that it always complies with current legal requirements or to implement changes to our services, e.g., when introducing new services. The new privacy policy will then apply to your renewed visit.

15. Objection to Advertising Emails

The use of contact data published within the framework of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.

Welcome coupon1

1 Valid for the first order. Your discount will be deducted automatically.

Coupon