Privacy policy
Last updated: 30 July 2026
In short
You can read these pages without telling us your name. On our own server your IP address is not stored; when images are fetched, our image network logs it briefly (details below). We count visits anonymously; we set a cookie only if you agree to it. We need personal details only when you order — then your name, email and delivery address, so the parcel arrives.
We do not sell data, we run no advertising networks, and we embed no third-party fonts, maps or videos. The detailed version follows below.
Controller
The controller under the GDPR is Rosaluce — owner Manuel Zorzi · Georg-Eisenreich-Str. 4 · 85540 Haar · Germany · Email: kontakt@rosaluce.com · Phone: +49 179 4470375.
Data protection officer
We are not required to appoint a data protection officer (§ 38 (1) BDSG) and have not appointed one. Questions about data protection are answered by the controller in person at the address above.
Hosting and server logs
The site runs entirely on a server we rent from DigitalOcean, LLC in the EU region Frankfurt am Main — pages, orders, database and administration. Unlike the image network described below, which carries images only, everything passes through here. DigitalOcean processes the data as our processor under Art. 28 GDPR on the basis of a data processing agreement.
When a page is requested, the server processes technical connection data without which no connection can be made:
- IP address of the requesting device
- date and time of the request
- the address requested and the volume transferred
- the status code of the response
- the referring page, where transmitted
- browser and operating system identifier (user agent)
The legal basis is our legitimate interest in operating and securing the site (Art. 6 (1) (f) GDPR). We need your IP address to deliver the response and to curb abuse (for instance too many order attempts in a short time); for that it sits briefly in a volatile cache.
On this server it is not stored: our access logs contain only the internal address of our own intermediate server, not yours. Nor do we record an IP address in the database for visits. The only place where our application stores IP addresses is logins to the internal administration area — and those are ours alone. Image requests are different; the next section covers them.
The remaining log entries (page address, time, status code, browser identifier) are not evaluated for analytics and are not combined with other data. They run in a size-capped ring buffer that overwrites itself continuously.
Image delivery (Cloudflare)
The images under img.rosaluce.com are delivered through the content delivery network of Cloudflare, Inc. Without that step, a saint's page would take many times as long to load. When an image is requested, Cloudflare processes your IP address and technical connection data in order to serve the request and to fend off attacks.
Cloudflare acts as our processor under Art. 28 GDPR; the basis is the Cloudflare data processing addendum including the EU standard contractual clauses. The legal basis for the processing is our legitimate interest in fast and reliable delivery (Art. 6 (1) (f) GDPR). Cloudflare sets no cookies for our images.
Unlike on our own server, your IP address is logged here: Cloudflare keeps a log of the requests at its network edge which, besides the time, the image requested and the browser identifier, contains the IP address. Cloudflare keeps it only briefly and states that it may delete such logs from 72 hours onwards; we do not retrieve or evaluate these logs ourselves. Our image server also keeps a short operational log of the requests reaching it — as a rule that shows Cloudflare's forwarding address, and only on a direct request bypassing the image network the address of whoever made it.
This concerns the images alone: the pages themselves — text, ordering, checkout — are served directly from our server in Frankfurt and do not pass through Cloudflare. Anyone who does not load the images does not appear in that log.
Cloudflare additionally runs the name service (DNS) for rosaluce.com, which translates addresses into server addresses. In doing so Cloudflare sees not you but the name server of your provider, which makes the query on your behalf.
PostHog as our processor
The analytics data is processed by PostHog Inc. on our behalf on servers in the EU (PostHog Cloud EU, Frankfurt), under a data processing agreement per Art. 28 GDPR. Form inputs are masked in session recordings.
Configurator and basket
While you are only designing, everything stays on your device: the configurator prices your choices against our price list, and the basket sits in your browser. Only when you go to checkout is the configuration transmitted to us and stored — we need it to make that particular piece. The legal basis is performance of the contract, or steps taken at your request before it (Art. 6 (1) (b) GDPR).
Orders and fulfilment
To handle an order we process your name, email address, delivery and where applicable billing address, the chosen configuration, the order amount and a payment reference. The legal basis is Art. 6 (1) (b) GDPR (contract), and for the tax retention additionally Art. 6 (1) (c) GDPR (legal obligation).
We pass your name and address to the shipping company as far as delivery requires it. We never see your payment details — card number, IBAN and the like; those are entered exclusively with our payment provider (see below).
Order data is held in our self-hosted business system on the same server in Frankfurt; only the controller has access.
Payment processing (Stripe)
Payments are handled for us by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. At the payment step you enter your payment and contact details directly with Stripe; Stripe processes them as an independent controller in its own right, among other things for fraud prevention and to meet its own legal obligations. Stripe's privacy policy applies to that: https://stripe.com/privacy
What Stripe returns to us is your name, email address, delivery address, the amount, the payment status and a payment reference — not your full payment credentials. The legal basis is Art. 6 (1) (b) GDPR (performance of the contract).
Stripe may transfer data to group companies in the USA. The US company Stripe, LLC holds an active certification under the EU-US Data Privacy Framework (looked up by us in the official list, most recently on 31 July 2026); the EU standard contractual clauses apply in addition. Our contracting party itself — Stripe Payments Europe, Limited — is based in Ireland and therefore within the EU.
Order confirmation and email
After a purchase we send you a confirmation with your configuration and the amount paid, and later a note when it ships. That is part of the contract (Art. 6 (1) (b) GDPR), not advertising. We do not currently send a newsletter; should that change, it will happen only with your express consent and with an unsubscribe link in every email.
Contacting us
If you write to us, we process your email address and the content of your message in order to reply. The legal basis is Art. 6 (1) (b) GDPR where a contract is involved, otherwise our legitimate interest in answering your enquiry (Art. 6 (1) (f) GDPR). We deliberately do not offer a contact form — an email to kontakt@rosaluce.com is enough.
Who receives your data
Apart from the parties named here there are no recipients. In detail:
- DigitalOcean, LLC — server operation (processor, EU region Frankfurt)
- Cloudflare, Inc. — image delivery (processor)
- PostHog, Inc. — audience measurement (processor, EU hosting in Frankfurt)
- Stripe Payments Europe, Limited — payments (independent controller)
- the shipping company engaged for your parcel
- tax advisers and authorities, where the law requires it
We do not sell data and do not pass it on for advertising.
Transfers to third countries
Our servers and our analytics are in the EU. Processing in the USA may occur at the US companies named above, for instance when their staff access systems for maintenance.
DigitalOcean, Cloudflare and PostHog hold an active certification under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023); the EU standard contractual clauses under Art. 46 (2) (c) GDPR apply in addition. We do not check this against what the providers say about themselves, but look it up in the official list at dataprivacyframework.gov; most recently on 31 July 2026.
Stripe needs a distinction: our contracting party Stripe Payments Europe, Limited is based in Ireland, hence inside the EU — the framework does not apply to it for that reason alone. What is certified is the US group company Stripe, LLC, to which data may be passed on.
How long we keep things
We keep data as long as we need it — and no longer:
- Server logs (no visitor IP in them): continuously overwritten, deleted at the latest when the application is next updated
- IP addresses from visits: not stored at all on our server; in the image network's log (image requests only) a few days, deletable from 72 hours onwards per Cloudflare
- Order and invoice data: ten years, because tax and commercial law require it (§ 147 AO, § 257 HGB)
- Proof of your cookie decision: for the duration of the consent and three years beyond it (Art. 7 (1) GDPR)
- Analytics data in PostHog: twelve months at most; the masked session replays one month at most
- Email correspondence: until the matter is settled; commercial letters six years (§ 257 HGB)
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Consent you have given can be withdrawn at any time with effect for the future (Art. 7 (3) GDPR) — for the cookie consent the “Privacy choices” link in the footer of every page is enough.
Where we rely on a legitimate interest, you may object to the processing on grounds relating to your particular situation (Art. 21 (1) GDPR). For the anonymous audience measurement we have built in a control for exactly that — it sits in the section further up. An informal email to kontakt@rosaluce.com always suffices; we reply within one month.
You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany; you may equally contact the authority where you live.
No automated decision-making
We take no decisions about you based solely on automated processing, and we do not carry out profiling within the meaning of Art. 22 GDPR. There is no credit check and no scoring.
Data security
The connection to this site is encrypted end to end with TLS; you can see it by the padlock in the address bar. The server sits in an EU data centre, access is limited to the controller, and backups run encrypted. Passing your data on for anything beyond the purposes named above is ruled out.
Changes to this policy
If our processing changes, this text changes with it — with a new date at the top. If the scope of measurement changes, we ask for your consent again; consent given to an earlier version then no longer applies.