Privacy Policy (English Translation)

LEGAL DISCLAIMER: This English translation is provided solely for informational purposes and ease of understanding. It has no legal validity or binding effect. Only the German version of this Privacy Policy ("Datenschutzerklärung") constitutes the legally binding agreement between the parties. In case of any discrepancies, contradictions, or ambiguities between this English translation and the German original, the German version shall prevail exclusively.


Cumin & Potato GmbH - Privacy Policy for the PXL Clock System

Notice regarding relationship to Terms and Conditions: This Privacy Policy supplements our General Terms and Conditions (https://docs.pxlclock.com/de/agb) in the same version. It does not regulate additional contractual obligations but informs about the processing of personal data when using the PXL Clock system. To the extent this declaration and the Terms and Conditions contain different statements, mandatory data protection provisions take precedence. Contractual rights and obligations arise from the Terms and Conditions.

Language version: Only the German version is binding; translations serve orientation purposes only.

Data Controller:
Cumin & Potato GmbH
Holzhofallee 21
64295 Darmstadt
Commercial Register: HRB 107113, Local Court of Darmstadt
Phone: +49 6151 7866583
Email: info@cuminandpotato.com
VAT ID: DE449775915
WEEE Reg. No.: DE 41629348
Lucid Registration: DE4940239725994 (Dual System Zentek)

Supervisory Authority:
Hessian Commissioner for Data Protection and Freedom of Information
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de


§ 1 General Information

This Privacy Policy supplements the General Terms and Conditions (Terms and Conditions) of Cumin & Potato GmbH. It informs about the processing of personal data in connection with the PXL Clock product as well as our website and online shop in accordance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG).

This document is written in German. Any translations into other languages serve solely for better understanding. In case of deviations or contradictions, only the German version shall be authoritative.

§ 2 Data Processing for Product Purchase

Purpose: Contract processing, customer service, provision of website and online shop
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment), Art. 6 para. 1 lit. f GDPR (legitimate interest in secure and efficient website provision)
Data: Name, address, email address, telephone number, payment data, IP address, browser and device information
Storage Duration: 10 years after contract termination (commercial and tax law retention obligations according to § 147 AO, § 257 HGB)
Recipients: Wix.com Ltd., Nemal St. 40, Tel Aviv, Israel. Our website and online shop are hosted via the Wix.com platform. Wix processes personal data in the context of providing hosting, shop functionalities and support services. Wix may transfer data to sub-processors in third countries (particularly the USA). Israel has an adequacy decision from the EU Commission according to Art. 45 GDPR. For transfers to the USA, the EU-US Data Privacy Framework applies. We have concluded a data processing agreement (Data Processing Addendum) with Wix. Further information can be found in Wix's privacy policy: https://de.wix.com/about/privacy
Cookies: Cookies are used when visiting our website. Details see § 3a of this Privacy Policy.

§ 3 Cookies and Similar Technologies

Legal Basis: § 25 TTDSG (Telecommunications-Telemedia Data Protection Act)
The PXL Clock device itself does not use cookies. The optional mobile app and cloud services only use technically necessary session cookies that do not require consent (§ 25 para. 2 no. 2 TTDSG).

Should non-necessary cookies or tracking technologies be used in the future, this will only occur after your explicit consent via a cookie banner (§ 25 para. 1 TTDSG).

§ 3a Website Cookies and Tracking

(1) Cookie Overview

Our website uses cookies for various purposes:
Necessary Cookies (no consent required)

Purpose: Shopping cart function, user login, security (CSRF protection), language selection
Provider: Wix.com / Cumin & Potato GmbH
Storage Duration: Browser session or maximum 24 hours
Legal Basis: § 25 para. 2 no. 2 TTDSG

Analytics Cookies (only with your consent)

Purpose: Visitor statistics, website performance improvement
Provider: Wix Analytics, possibly Google Analytics
Storage Duration: 12 months
Legal Basis: Art. 6 para. 1 lit. a GDPR

Marketing Cookies (only with your consent)

Purpose: Measuring success of advertising campaigns, personalized advertising
Provider: Google Ads, Facebook (if activated)
Storage Duration: 90 days
Legal Basis: Art. 6 para. 1 lit. a GDPR

(2) Wix Platform Cookies

As a Wix-hosted website, the following technical cookies are automatically set:

XSRF-TOKEN, _wixCIDX (security)
svSession, hs (session management)
SSR-caching (performance optimization)
fedops.logger.sessionId (error analysis)

Detailed information on Wix cookies: https://www.wix.com/about/privacy

(3) Your Cookie Settings

First visit: A cookie banner appears on first website visit for selecting your preferences
Subsequent changes: Adjustable at any time via the "Cookie Settings" link in the footer
Browser settings: You can also manage or delete cookies directly in your browser
Objection: By email to datenschutz@cuminandpotato.com

(4) Third-Party Services

Depending on your consent and our configuration, the following services may be active:

Google Analytics (if activated)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: Web analysis, user behavior, reach measurement
IP Anonymization: Activated
Opt-out option: https://tools.google.com/dlpage/gaoptout

Google Ads Conversion Tracking (if activated)

Purpose: Measuring effectiveness of Google advertising campaigns
Storage Duration: 90 days

Facebook Pixel (if activated)

Provider: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland
Purpose: Measuring advertising success, remarketing

Data transfers to the USA are based on the EU-US Data Privacy Framework.

(5) Functional Limitations Without Cookies

Without necessary cookies: Online shop not usable (shopping cart does not work)
Without analytics cookies: No restrictions on shop functions
Without marketing cookies: You see general instead of personalized advertising

(6) Do-Not-Track

We respect Do-Not-Track signals from your browser. When DNT is activated, only necessary cookies are automatically set.

(7) Further Information

Wix Cookie Policy: https://de.wix.com/about/cookie-policy
General information on cookies: https://www.verbraucherzentrale.de/wissen/digitale-welt/datenschutz/cookies-kontrollieren-und-verwalten-11996

§ 4 Device Data and Telemetry

Purpose: Device functionality, security
Legal Basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)
Data:

  • Device information (serial number, firmware version)
  • IP address (for device identification and security)
  • Usage statistics (non-personal)
  • Error reports and performance data
  • Network connection data
    Balancing of Interests: Our legitimate interest lies in ensuring device security, error analysis and product improvement. Processing is data-minimized and can be deactivated at any time.
    Storage Duration: 24 months from collection or until withdrawal of consent

§ 5 Cloud Backend (optional)

Purpose: Synchronization of settings and content
Legal Basis: Art. 6 para. 1 lit. a GDPR (consent)
Data: User settings, self-created animations, device configuration
Storage Duration: Until deletion by user or withdrawal of consent
Location: Germany (EU servers at AWS Frankfurt)

§ 6 Mobile App (optional)

Purpose: Remote control and configuration of PXL Clock
Legal Basis: Art. 6 para. 1 lit. a GDPR (consent)
Data: App usage data, device communication
Storage Duration: Until app uninstallation
Permissions: Network access (for device communication)

§ 7 Software Updates

Purpose: Maintaining functionality and security
Legal Basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)
Data: Firmware version, installation status
Storage Duration: For the duration of update provision obligation (according to § 327f BGB)
Automatic Updates: Require separate consent

§ 8 Newsletter and Advertising (optional)

If you subscribe to our newsletter, we process:
Purpose: Sending product information and updates
Legal Basis: Art. 6 para. 1 lit. a GDPR (consent)
Data: Email address, registration time, IP address at registration
Double Opt-In: We use the double opt-in procedure
Withdrawal: You can withdraw your consent at any time via the unsubscribe link in each newsletter or by email to info@cuminandpotato.com

§ 9 Data Subject Rights

You have the following rights:

  • Access to processed data (Art. 15 GDPR)
  • Rectification of incorrect data (Art. 16 GDPR)
  • Erasure of data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of consent (Art. 7 GDPR)

Exercise of Rights: Email to datenschutz@cuminandpotato.com

§ 10 Data Security

We implement technical and organizational measures:

  • Encryption of data transmission (TLS 1.2+)
  • Encryption of data storage (AES-256)
  • Access control and authentication
  • Regular security updates
  • Privacy by design

§ 11 International Data Transfers

Data transfers outside the EU only occur:

  • With adequacy decision from EU Commission
  • With EU standard contractual clauses (through Wix.com Ltd.)
  • With your explicit consent

§ 12 Deletion and Storage Duration

  • Contract data: 10 years after contract termination (legal retention obligations)
  • Telemetry data: 24 months from collection
  • Cloud data: Until active deletion by user
  • App data: Until uninstallation
  • Newsletter data: Until withdrawal of consent

§ 13 Changes to this Privacy Policy

This Privacy Policy may be adapted in case of changes to data processing or legal requirements. Material changes will be communicated by email.

§ 14 Contact

For questions regarding data protection, contact:

§ 15 Right to Complain

You have the right to file a complaint with the competent supervisory authority:

Hessian Commissioner for Data Protection and Freedom of Information
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de


Status: July 2025, Version 1

© 2025 Cumin & Potato GmbH. All rights reserved.