Privacy Policy
The essential information about how we process your personal data.
Last updated: 16 August 2026
1. Data controller
The controller is Möbel Montage Dienst, proprietor: Justyna Pelczarska, Rekumer Str. 160, 28777 Bremen, Germany. You can contact us by telephone at +49 1575 7958211 or by email at info@kuchebremen.de.
2. Website delivery and security
This website is delivered through Cloudflare, Inc. When you open it, Cloudflare processes technical data such as your IP address, the date and time of the request, the requested URL, user-agent and referrer. This data is needed to deliver and secure the website and diagnose errors. The legal basis is Art. 6 (1) (f) GDPR — our legitimate interest in operating a secure and reliable website.
Depending on the plan in use, technical data may remain visible in short-lived Cloudflare logs for up to seven days. We do not place form contents in URLs or write them to our own application logs.
3. Language settings, consent and Google Maps
We do not use analytics tools or tracking cookies. After you choose a language, we store the
functional first-party cookie preferred-language for one year and the same value in
localStorage. This allows the selected language version to open. The legal basis is
Art. 6 (1) (f) GDPR together with § 25 (2) no. 2 TDDDG.
We also store your privacy-banner decision (cookie-consent) and map choice
(maps-consent) in localStorage. Google Maps loads only after your
consent. Google Ireland Limited may then receive technical data including your IP address,
user-agent and referrer and, if you are signed in to Google, your account identifier. The legal
basis is Art. 6 (1) (a) GDPR together with § 25 (1) TDDDG. You can withdraw consent at any time
through “Manage consents” in the footer or by deleting the stored browser values.
4. Inquiries, correspondence, CRM and scheduling
When you submit the contact form, we process your name, email address, message, inquiry type and, if provided, telephone number and city. Your name, email address and message are required so that we can handle the inquiry; the form cannot be submitted without them. The form also uses technical data and Cloudflare Turnstile to protect against spam and automated submissions.
We send a form-inquiry notification as a separate message to each designated operational email inbox. A recipient sees only their own address, and an employee's reply is directed to the customer without being redistributed to other employees. If a reply is accidentally copied to our public address, we identify it using technical message identifiers and do not store it as a new customer inquiry.
The first message sent directly to info@kuchebremen.de is processed as a new inquiry under the same rules in our internal CRM. Replies in the same email conversation may be associated with that existing inquiry, and a plain-text copy is sent to designated operational email inboxes for prompt handling.
Before an incoming email is added to the CRM, it is automatically checked for clear spam and fraud. We send the sender, reply address, subject, up to 20,000 characters of the newest plain-text content, a truncation indicator and attachment file types to an automated anti-spam filter. We do not send attachment files, raw HTML or complete headers. Messages clearly classified as spam or fraud are neither stored in our CRM nor forwarded to operational inboxes. An unclear result is admitted for human handling. A technical message identifier and the filtering outcome may be stored temporarily without message content to prevent duplicate processing. If you believe a legitimate message was rejected, please use the contact form or telephone us.
We store the inquiry and subsequent correspondence in an internal CRM on Cloudflare D1. A case may include contact details, message subject and content, limited attachment metadata, processing and delivery status, assigned staff member, internal notes, project stage, next action and manually recorded telephone calls, meetings or WhatsApp contacts. We do not retrieve or store attachment files and do not synchronise WhatsApp conversations.
We may also create an internal schedule entry for a consultation, measurement, design work, order, delivery, installation or service. It may contain the date and time, title, branch, location, order reference, assigned staff member, note and a link to your inquiry. The schedule is not synchronised with external calendar services.
We process this data to answer your inquiry, prepare a quotation, take steps before entering into a contract and deliver our services. The legal basis is Art. 6 (1) (b) GDPR. Without the data required for the relevant step, we cannot answer the inquiry, prepare a quotation or perform the service. Organising correspondence, protecting against misuse and documenting business contacts are additionally based on Art. 6 (1) (f) GDPR — our legitimate interest in secure and orderly customer service.
5. Recipients and transfers outside the EEA
Data may be disclosed to the service providers that operate our systems:
- Cloudflare, Inc. — hosting, Cloudflare D1 database, security, abuse prevention and Turnstile;
- Plus Five Five, Inc. (Resend) — sending and receiving email and providing delivery information;
- The anti-spam filter provider — automated detection of spam and fraud in incoming emails;
- Google Ireland Limited — only after consent to load the map.
Cloudflare, Resend and Google may process some data in the United States. To the extent applicable, transfers rely on the EU-US Data Privacy Framework and Standard Contractual Clauses approved by the European Commission. Resend account data, including email metadata and logs, is stored in the United States. More information is available from Cloudflare, Resend and Google.
6. How long we keep data
- language setting — one year or until deleted in your browser;
- locally stored choices — until changed or deleted;
- inquiry, correspondence, notes and project data in the CRM — generally 730 days from creation of the case;
- schedule entry — generally 730 days after the later of the end of the appointment and the latest update;
- email data at Resend — 30 days by default;
- anti-spam check data — not stored by our application as a request or response; short-term technical processing or logging by the anti-spam filter provider follows its contractual settings;
- copies of correspondence in our mailbox — generally up to 24 months after the last contact.
We may retain data for longer where accounting or tax law requires it or where this is needed to establish, exercise or defend legal claims. In that case, use of the data is restricted to that purpose.
7. Links to other services
Facebook and WhatsApp references are ordinary links. We do not embed their plugins or tracking pixels. Data is transferred to those services only after you click the link, from which point the respective provider's privacy terms apply.
8. Your rights
Depending on the legal basis and circumstances, you may request access, rectification, erasure, restriction of processing and data portability, and object to processing based on legitimate interests. You can withdraw consent at any time with effect for the future. To exercise your rights, write to either address in section 1. We will respond without undue delay, generally within one month.
9. Complaints and automated decisions
You may lodge a complaint with a data protection authority in the place of your habitual residence, workplace or the alleged infringement. Our competent authority is Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen, datenschutz.bremen.de.
The automated spam and fraud check decides only whether an incoming email is technically accepted. It does not evaluate a person, is not used for profiling and is not intended to make a decision producing legal or similarly significant effects within the meaning of Art. 22 GDPR.