We're launching soon! Launch on 01.10.2026!01.10.2026

Privacy policy

Last updated: August 2026

This privacy policy explains which personal data we process when you visit and use this online shop, for which purposes, on which legal basis, and which rights you have. It applies to the “Sevdesk Templates” offering.

1. Controller

The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

Fritz Benning, Tiemannhof 3, 26123 Oldenburg, Germany, email: mail@fritzbenning.de.

We have not appointed a data protection officer because the statutory requirements of Article 37 GDPR and Section 38 BDSG are not met. For privacy requests, please use the email address above.

3. Hosting and server log files

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA (“Vercel”). Vercel processes the technical data required to deliver the website on our behalf.

When pages are requested, the hosting provider typically records server log files. These may include IP address, date and time of the request, requested URL, referrer URL, browser type and version, operating system, and status code.

This processing is necessary to provide the website, maintain system security, and investigate incidents (Article 6(1)(f) GDPR). Log data is stored only as long as needed for these purposes and is then deleted or anonymised, unless a longer retention is legally required for evidence.

Product files for download may be delivered via Vercel’s object storage (Vercel Blob). Technical access data required to deliver the file is processed in that context.

Further information: https://vercel.com/legal/privacy-policy

4. Cookies and storage on your device

On the shop pages we operate, we do not set cookies for advertising, tracking, or profiling. We do not use social media plugins or remarketing.

Technically necessary storage may still occur where it is essential for the service to function, for example for hosting the session or for payment with the payment provider. The legal basis is Article 6(1)(b) or (f) GDPR in conjunction with Section 25(2) TDDDG where access to the device is strictly necessary.

If you are redirected to Stripe Checkout via the purchase button, Stripe may set cookies and similar technologies on its own pages. Stripe is independently responsible for that processing. Details are set out in Stripe’s privacy policy.

5. Reach measurement (Vercel Analytics)

We use Vercel Web Analytics to understand which pages are visited and how the shop is used. The service does not use its own cookies and is designed not to store directly identifying details such as names or email addresses.

It processes aggregated usage data such as pages viewed, referrer, approximate country-level location, device type, and technical identifiers created by Vercel for the analysis. Vercel processes this data on our behalf.

The legal basis is Article 6(1)(f) GDPR (legitimate interest in designing and statistically evaluating the shop). You may object on grounds relating to your particular situation by contacting us at the email address in the imprint.

Vercel’s notes: https://vercel.com/docs/analytics/privacy-policy

6. Google Fonts

To display fonts consistently, we load typefaces from Google Fonts. When you open a page, your browser requests the required font files from servers of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, or affiliated companies of Google LLC in the United States.

Your IP address is transmitted to Google. Google may also process other technical browser data. We have no control over Google’s further processing.

The legal basis is Article 6(1)(f) GDPR (legitimate interest in a consistent and technically reliable presentation). Google’s privacy policy: https://policies.google.com/privacy

7. Orders, payment, and download

If you buy a template, we process the data required to conclude the contract, take payment, provide the download, and communicate with you as a customer.

Payment is handled via Stripe Checkout with Stripe Managed Payments. Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin, D02 H210, Ireland, and affiliated companies, in particular Stripe, Inc., USA) acts as merchant of record. Stripe is independently responsible under data protection law for payment processing, tax collection, fraud prevention, and invoicing in that respect.

At checkout, Stripe collects in particular your email address, payment details, billing or payment information, and technical transaction data. Which fields are required follows from the checkout form. Details: https://stripe.com/privacy

After successful payment we receive from Stripe the information needed to fulfil the contract, in particular your email address, the checkout session ID, the purchased product or price, and the order language. We store this data to provide the download, send order confirmations, prevent abuse, and meet statutory retention duties.

The legal basis for our processing in connection with the order is Article 6(1)(b) GDPR. Where we retain data due to tax or commercial law, this is based on Article 6(1)(c) GDPR. Transfer to Stripe to carry out payment is for contract performance (Article 6(1)(b) GDPR).

After purchase you can download the file on the confirmation page and via a link sent by email. The link is tied to the order. We may technically log download access (for example time and count) to provide the service and limit abuse (Article 6(1)(b) and (f) GDPR).

8. Email sending

We send transactional and notification emails through the provider Resend (Resend, Inc., USA). Resend processes recipient address, content, and technical delivery data on our behalf.

This includes in particular order confirmations with a download link, availability notification confirmations, newsletters about new templates, and delivery of contact requests to us.

The legal basis depends on the purpose: contract performance (Article 6(1)(b) GDPR) for order emails; consent (Article 6(1)(a) GDPR) for the newsletter and availability notifications; legitimate interest or pre-contractual communication (Article 6(1)(f) or (b) GDPR) for contact requests.

Further information: https://resend.com/legal/privacy-policy

9. Newsletter

If you sign up for notices about new templates, we process your email address to tell you about new designs. Sign-up is completed by entering the address and submitting the form.

The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw consent at any time, for example via the unsubscribe link in the email or by writing to the address in the imprint. Withdrawal does not affect the lawfulness of processing before the withdrawal.

We store your email address with Resend in a dedicated recipient group until you unsubscribe or we discontinue the newsletter. We then remove the address from the list unless another legal basis requires further storage.

10. Availability notification

While orders are not yet possible, you can ask to be notified by email when the shop opens. We process your email address and, where provided, the product you are interested in.

The legal basis is your consent (Article 6(1)(a) GDPR) or steps prior to entering a contract at your request (Article 6(1)(b) GDPR). We use the address only for this notification, not for other marketing, unless you have also subscribed to the newsletter.

After we send the opening notice, or if you object or withdraw consent, we delete the address from this list unless another retention duty applies.

11. Contact and enquiry forms

If you use the support form or the custom template form, we process the information you provide. This is typically name, email address, and message, and optionally company and topic.

We use the data solely to handle your request and communicate with you about it. We do not pass it on to third parties except where an email provider (Resend) is technically involved or we are legally obliged to do so.

The legal basis is Article 6(1)(b) GDPR if the request relates to entering into or performing a contract (for example support for a purchase or an enquiry about a custom template). Otherwise the legal basis is Article 6(1)(f) GDPR (legitimate interest in responding to incoming requests).

We store enquiries for as long as handling them requires and then delete them unless a statutory retention duty applies. Correspondence that constitutes business records may be subject to commercial and tax retention periods.

12. Recipients and processors

We disclose personal data only where this is necessary for the purposes described, you have consented, or a legal duty applies. Categories of recipients include in particular:

  • hosting and infrastructure providers (Vercel) for operating the website, delivery, and file storage,
  • payment providers (Stripe) for checkout, payment, tax, and invoices,
  • email providers (Resend) for sending and contact management,
  • Google for delivering fonts,
  • tax, payment, or legal service providers where legally or contractually required.

13. Transfers to third countries

Some of the providers named above are based in the United States or may process data in the US or other third countries. For the US, the European Commission has adopted an adequacy decision for the EU-US Data Privacy Framework where the respective provider is certified.

Where no adequacy decision applies, we rely on appropriate safeguards under Article 46 GDPR, in particular the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional measures of the provider.

A transfer to a third country may in some cases involve a risk, for example because public-authority access under local law may go further than in the EU. We choose providers that offer contractual privacy safeguards and limit transferred data to what is necessary.

14. Retention

We store personal data only as long as needed for the respective purposes or as required by law. Unless a shorter period is stated above, the following in particular applies:

  • order and billing data generally for ten years under tax and commercial law (Section 147 AO, Section 257 HGB),
  • contract and customer data for performance and any warranty, then deletion or restriction where retention duties still apply,
  • newsletter and waitlist addresses until withdrawal or until the purpose is achieved,
  • contact requests until handling is complete plus a reasonable follow-up period,
  • technical log and measurement data only for the short period required.

15. Your rights

Under the GDPR you have the following rights vis-à-vis us, provided the statutory requirements are met:

  • access to personal data stored about you (Article 15 GDPR),
  • rectification of inaccurate data or completion of incomplete data (Article 16 GDPR),
  • erasure (Article 17 GDPR),
  • restriction of processing (Article 18 GDPR),
  • data portability (Article 20 GDPR),
  • objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR),
  • withdrawal of consent with effect for the future (Article 7(3) GDPR).

16. Objection and withdrawal

If we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. We will then assess whether compelling grounds on our side override yours.

You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. A simple message to mail@fritzbenning.de is sufficient.

17. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement (Article 77 GDPR).

The authority competent for us is the State Commissioner for Data Protection of Lower Saxony (Die Landesbeauftragte für den Datenschutz Niedersachsen), Prinzenstraße 5, 30159 Hannover, Germany, https://lfd.niedersachsen.de.

18. Obligation to provide data

You are not legally or contractually required to provide personal data if you only browse the website for information. Certain details are required to conclude a contract, download after purchase, or answer an enquiry. Without those data we cannot provide the respective service.

We do not use automated decision-making including profiling within the meaning of Article 22 GDPR. Stripe may run its own checks as part of payment processing and fraud prevention; Stripe is responsible for that.

19. Data security

This website uses TLS encryption to protect transmission between your browser and our server. Within the services we use, we limit access to personal data to what is necessary.

We cannot guarantee absolutely secure transmission over the internet. Please take this into account if you send us unencrypted email.

20. Changes

We update this privacy policy if processing, the law, or our offering changes. The version published on this page applies. If material changes affect your rights, we will inform you where possible and reasonable, for example on the website or by email if we have your address for that purpose.

Provider details are available in our Imprint.