Privacy Policy
Last updated on 01.05.2026
The protection of your privacy when using our website is particularly important to us. In the following, we therefore inform you about the limited collection of personal data on this site.
1. Provider / Person responsible within the meaning of data protection
Cardino GmbH
Torstraße 105
10119 Berlin, Germany
Email: sales@cardino.de
Web: www.cardino.de
Entry in the register court: Berlin-Charlottenburg
Register number: HRB 251256 B
2. Data Protection Officer
Lukasz Pajak,
Cardino GmbH
Torstraße 105
10119 Berlin, Germany
4. Basics
Your personal data (e.g., name, address, e-mail address, telephone number) will be processed in compliance with the relevant statutory data protection regulations, in particular Regulation (EU) 2016/679 (the General Data Protection Regulation – GDPR), the Federal Data Protection Act (BDSG) and other data-related laws.
According to the GDPR, data processing is only permitted if the GDPR or another legal regulation expressly permits it, or if the person concerned consents. Accordingly, we use and process your personal data only within the permissible framework of contract processing, for the performance of pre-contractual measures at your request, to fulfil legal obligations, or where you have given your informed consent.
In principle, we do not pass on your personal data to third parties. Excluded from this are service partners who need the data to process the contractual relationship; in those cases the scope of transmitted data is always limited to the necessary minimum.
6. Server access logs
You can visit our website without telling us who you are. Our hosting infrastructure automatically records standard access information that is technically necessary to deliver the website and to protect it against abuse: the website from which you are visiting us (referrer URL), the pages of our website that you visit, the date and time of retrieval and the amount of data transferred, notification of successful retrieval, browser type and version, operating system, and the IP address of the requesting device.
These logs are processed solely for the secure and stable operation of the website (legal basis: Art. 6 (1) (f) GDPR — legitimate interest in IT security and abuse prevention). They are kept only for a short period and are not used to build profiles, are not merged with other data sources, and are not shared with advertisers.
7. Collection of personal data when using our services
We only collect personal data if you provide it to us voluntarily — for example by sending an inquiry through our contact form, applying for a job, or entering into a business relationship with us. In such cases we collect only the data that is necessary for the respective purpose. Data fields that are mandatory are marked with an asterisk; any additional information you provide is voluntary.
For the highest possible security of your data, all submissions are transmitted in encrypted form using SSL/TLS encryption. Your data is stored and processed on servers within the European Union. A transfer to third countries does not take place unless we are entitled or obliged to do so on the basis of a statutory provision or you have expressly consented to it in advance.
8. Data processing to fulfil the contract
8.1 Purpose of processing
If you enter into a business relationship with us, you provide your personal data as part of that process. The mandatory information marked with an asterisk is data that is required for the conclusion of a contract. You are not obliged to provide your personal data, but we cannot provide the requested service without it. Where necessary to deliver the requested service, we may pass relevant data on to commissioned service providers. The data you enter is always processed for the purpose of fulfilling the contract.
8.2 Legal Basis
The legal basis for this processing is Art. 6 (1) (b) GDPR.
8.3 Recipient Categories
In principle, we do not pass on your personal data to third parties. Depending on the service, your personal data may be passed on to: commissioned partners or processors strictly required to deliver the agreed service, payment service providers if applicable, and authorities where we are legally obliged to disclose information.
Your personal data is not transmitted to third parties for advertising purposes. We only pass on your personal data to third parties if: you have given your express consent pursuant to Art. 6 (1) (a) GDPR; it is required for the processing of contractual relationships pursuant to Art. 6 (1) (b) GDPR; there is a legal obligation pursuant to Art. 6 (1) (c) GDPR; or disclosure is required pursuant to Art. 6 (1) (f) GDPR to assert, exercise or defend legal claims.
8.4 Duration of Storage
We store the data required to process the contract until the statutory warranty and, if applicable, contractual warranty periods have expired. We store data required under commercial and tax law for the legally stipulated periods, usually ten years (cf. Section 257 HGB, Section 147 AO).
9. Processing of Applicant Data
The personal data you provide voluntarily as part of a job application will be processed by us exclusively for the advertised position for which you have applied. We process only the personal data that is necessary for the application process — name, contact details, and the information you include in your application documents (cover letter, CV, certificates, etc.). We only process special categories of data (e.g. health data) if you provide them to us voluntarily or if we have a special legal basis. The legal basis is Art. 88 GDPR in conjunction with Section 26 BDSG and, where applicable, Art. 6 (1) (b) GDPR (initiation or implementation of contractual relationships).
If the application process does not lead to employment, your data will be deleted after six months from the end of the application process, unless you have given us your express consent to store your application documents for later consideration; in that case your data will be deleted after 24 months at the latest. Should processing of your personal data be necessary to fulfil a legal obligation, the legal basis is Art. 6 (1) (c) GDPR; for the defence of legal claims it is Art. 6 (1) (f) GDPR.
You can revoke your consent at any time with effect for the future by sending an email to sales@cardino.de. In such a case, we will delete your data immediately after receiving the revocation.
10. Contact Form
If you send us inquiries via the contact form, the details from the inquiry — including the contact details you provide — will be stored by us for the purpose of processing the inquiry and any follow-up questions. We do not pass on this data without your consent unless it is necessary to provide the requested service. The data will remain with us until you ask us to delete it, you revoke your consent to storage, or the purpose for storage no longer applies (e.g. after your request has been processed). Mandatory legal provisions — in particular retention periods — remain unaffected. You can revoke your consent at any time with effect for the future. Please address the revocation to sales@cardino.de.
11. Google Web Fonts
We use fonts provided by Google ("Google Fonts", a service provided by Google Ireland Limited) on our website for a uniform presentation. When the website loads, your browser establishes a connection to Google's servers to download the corresponding font files, which transmits your IP address to Google. We use Google Fonts on the basis of our legitimate interest in a consistent and performant typography across all visitors (Art. 6 (1) (f) GDPR). No cookies are set by Google Fonts. We are evaluating self-hosting these fonts in the future to remove the need to contact Google's servers altogether.
12. Withdrawing Your Consent
If you have given us your consent under data protection law for certain data uses and/or services, you can revoke this at any time with effect for the future. A simple message to:
Cardino GmbH
Torstraße 105
10119 Berlin, Germany
Email: sales@cardino.de
13. Your rights as a data subject
As the data subject, you have various rights with regard to your personal data. We have taken appropriate measures to provide you with all information pursuant to Articles 13 and 14 of the GDPR and all communications pursuant to Articles 15 to 22 and Article 34 GDPR.
13.1 Right to Confirmation and Information
You can request confirmation as to whether personal data relating to you is being processed by us, including the purposes of processing, categories of data, recipients, planned duration of storage, and rights to correction, deletion, restriction, or objection.
13.2 Right to Rectification
You have a right to correction and/or completion if the processed personal data concerning you is incorrect or incomplete.
13.3 Right to restriction of processing
You can request the restriction of the processing of your personal data under specific conditions, including when you dispute the accuracy of the data or object to processing.
13.4 Right to Erasure
You can demand that the personal data concerning you be deleted immediately when one of the legal reasons applies (e.g., the data is no longer necessary, you revoke consent, or the data was processed unlawfully). Exceptions apply where processing is necessary for freedom of expression, legal obligations, public interest, or legal claims.
13.5 Right to Information
If you assert the right to correction, deletion or restriction of processing, we are obliged to inform all recipients to whom your personal data has been disclosed.
13.6 Right to data portability
You have the right to receive the personal data that you have provided to us in a structured, common and machine-readable format, and to transmit this data to another controller without hindrance.
13.7 Right to Object
You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data based on Article 6 (1)(e) or (f) GDPR. If your personal data is processed for direct advertising, you have the right to object at any time.
13.8 Right to revoke the declaration of consent
You have the right to revoke your declaration of consent under data protection law at any time. The revocation does not affect the legality of processing carried out up to the point of revocation.
13.9 Automated individual decision-making including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you, except where necessary for a contract, permitted by law, or with your express consent.
13.10 Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your place of residence, place of work, or place of the alleged infringement, if you believe processing of your personal data violates the GDPR.
14. Further information
If you have any further questions or suggestions on the subject of "data protection" or would like information about your data or its correction or deletion, please write to:
Cardino GmbH
Torstraße 105
10119 Berlin, Germany
Email: sales@cardino.de