Privacy policy
- Responsible Party and Data Protection Officer
- Rights of the Data Subject
- How Your Data is Collected?
- Objection to Promotional Emails
- Cookies
- Embedded Content from Other Websites
- Processing of Payment Information
1. RESPONSIBLE PARTY AND DATA PROTECTION OFFICER
This privacy policy informs users of this website about the nature, scope, and purpose of the collection and use of personal data by the website operator www.kern-medien.de and www.shop.kern-medien.de . We take your privacy very seriously and always treat your personal data confidentially and in accordance with legal regulations. Due to new technologies and the constant development of this website, changes to this privacy policy may be made. Therefore, we recommend that you visit our privacy policy at regular intervals.
Date of the privacy policy: August 2026
1.1. THE RESPONSIBLE PARTY IN TERMS OF ART. 4 NO. 7 GDPR IS
For all questions related to data protection concerning our website and our services or for exercising your rights as a data subject, please contact our data protection officer:
Dennis-Michael Kern
Tschaikowskistraße 6
18069 Rostock
Email: info@kern-medien.de
Phone: +49 381 12779523 / +49 157 37529299
1.2. Legal Framework
Please note that all references to laws and regulations within this privacy policy pertain to German law. This privacy policy is designed to comply with the General Data Protection Regulation (GDPR) as it is applied in Germany, along with any other applicable German data protection laws.
2. RIGHTS OF THE DATA SUBJECT
You can exercise your data protection rights at any time. Our data protection officer reviews and responds to each concern individually. You can find their contact details in section 1.1.
2.1. RIGHT TO INFORMATION ACCORDING TO ART. 15 GDPR
You have the right to obtain information free of charge at any time about whether we process personal data about you.
2.2. RIGHT TO RECTIFICATION ACCORDING TO ART. 16 GDPR, RIGHT TO ERASURE ACCORDING TO ART. 17 GDPR, RIGHT TO RESTRICTION OF PROCESSING ACCORDING TO ART. 18 GDPR, RIGHT TO DATA PORTABILITY ACCORDING TO ART. 20 GDPR, AND THE RIGHT TO OBJECT ACCORDING TO ART. 21 GDPR
Furthermore, you have the option to exercise the rights to rectification, erasure, or restriction of processing. You can also object to the processing of your data by us at any time.
2.3. WITHDRAWAL IN CASE OF CONSENT ACCORDING TO ART. 7 PARAGRAPH 3 GDPR
If we process your personal data based on consent, you have the right to withdraw your consent at any time for the future. However, your withdrawal only becomes effective from the moment you declare it and does not have retroactive effects. The legality of the data processed until the withdrawal remains unaffected.
2.4. DATA SECURITY
All data you personally transmit is encrypted using the commonly used and secure standard TLS (Transport Layer Security). TLS is a secure and tested standard that is also used in online banking, for example. You can recognize a secure TLS connection, among other things, by the attached ‘s’ at the http (thus https://..) in the address bar of your browser or by the lock symbol in the upper part of your browser.
Furthermore, we use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulations, partial or complete loss, destruction, or against unauthorized access by third parties. Our security measures are continuously improved in line with technological development.
2.5. Right to Data Portability
You have the right to receive data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or a third party in a standard, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent that it is technically feasible.
2.6. RIGHT TO OBJECT ACCORDING TO ART. 21 GDPR
If your personal data is processed based on legitimate interests in accordance with Art. 6 Para. 1 S. 1 lit. f) GDPR, you have the right, according to Art. 21 GDPR, to object to the processing of your personal data, provided there are reasons for this arising from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right to object, which will be implemented by us without specifying any particular situation. If you wish to exercise your right to object, an email to info@kern-medien.de is sufficient.
2.7. RIGHT TO LODGE A COMPLAINT UNDER ARTICLE 77 GDPR
If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, place of work or the place of the alleged infringement. This right is without prejudice to other administrative or judicial remedies. The supervisory authority responsible for Kern Medien is the State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Vorpommern.
3. HOW YOUR DATA IS COLLECTED?
Your data is collected in two ways. Firstly, the data you provide us with. This could be data that you enter into a contact form, for example.
Other data is collected automatically or with your consent when you visit our website by our IT systems. These are primarily technical data (e.g., internet browser, operating system, or time of the page view). This data is collected automatically as soon as you enter our website.
3.1. What is your data used for?
Contact form spam protection (Cloudflare Turnstile). On pages with a corresponding contact form, we use Turnstile by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, to prevent automated spam. Cloudflare processes IP addresses, browser and connection characteristics, technical verification signals and the website visited. Processing in the USA and Cloudflare’s use of these signals to improve its bot detection are possible. Our integration does not send message contents to Turnstile. Short-lived verification tokens are checked on our server. The legal basis is our legitimate interest in a secure, accessible contact form (Article 6(1)(f) GDPR); section 25(2)(2) TDDDG applies insofar as access to device storage is strictly necessary for this purpose. You can alternatively contact us by email or telephone. Details on processing and retention of technical signals are available in Cloudflare’s Turnstile privacy notice.
Part of the data is collected to ensure error-free provision of the website. Other data can be used to analyze your user behavior.
3.2. Storage Duration of Your Data
Unless a more specific storage period has been mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, the deletion will take place after these reasons cease to apply.
3.3. Where Your Data Is Sent
Your data is stored on our server in Germany. We have implemented technical and organizational measures to ensure the security of your data and to prevent unauthorized access, unauthorized use, disclosure, or loss of your data.
We do not share your personal data with third parties unless it is required by law or you have given explicit consent. However, we work with certain service providers who process data on our behalf. These service providers may transfer your data to a country outside the European Union (EU) and process it there. We strive to ensure that all service providers who process your data adhere to EU data protection regulations and take appropriate security measures to protect your data.
3.3.1. Note on Data Transfer to the USA and Other Third Countries
We also use tools from companies based in the USA or other data protection non-secure third countries. When these tools are active, your personal data can be transferred to and processed in these third countries. We would like to point out that these countries do not offer a level of data protection comparable to that of the EU. For example, US companies are required to release personal data to security authorities without you as the data subject being able to take legal action against this. Therefore, it cannot be excluded that US authorities (e.g., intelligence services) process, evaluate, and permanently store your data located on US servers for monitoring purposes. We have no influence on these processing activities.
If you have any questions or concerns about the transfer or storage of your data, please feel free to contact us. We will make every effort to answer your questions and alleviate any concerns.
4. OBJECTION TO PROMOTIONAL EMAILS
We hereby object to the use of contact data published within the scope of the imprint obligation for the transmission of not explicitly requested advertising and information material. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
5. COOKIES
Language selection: When you explicitly choose German or English, the necessary km_language cookie remembers your choice for up to 180 days. Your browser language is checked locally only to offer a language suggestion; there is no automatic redirect. If you dismiss the suggestion, km_language_suggestion remembers this in session storage until the tab is closed. This does not involve tracking. Legal bases: Section 25(2), no. 2 TDDDG and Article 6(1)(f) GDPR (convenient language selection).
We manage your privacy choices through our own consent manager, “Kern Medien – Privatsphäre”, hosted on our server. No external consent provider is loaded for this purpose. The controller is Kern Medien, Dennis-Michael Kern; our contact details appear at the beginning of this privacy policy.
The necessary km_consent cookie remembers your choice for up to 180 days. If a choice, including a withdrawal, cannot be saved or verified because of a storage or network error, km_consent_pause keeps optional services blocked as a precaution until the next saved choice, for no more than 180 days. A short-lived, salted verification value protects this storage against large numbers of automated requests and is deleted after no more than ten minutes. The connection IP contributes to this value but is not stored in plain text for this purpose. We ask again if no valid choice is available, your choice has expired or the relevant information changes. You can change your choice or withdraw consent at any time through Privacy settings. Withdrawal applies for the future and does not affect the lawfulness of processing carried out beforehand.
To document your decision, we store a random identifier, date and time, selected services, the action taken and the version of the displayed information on our server. The identifier is used solely to verify your most recently confirmed choice, prevent outdated permissions from being reused after withdrawal and provide your decision history; it is not used for advertising or visitor profiles. The consent log does not store an IP address or browser fingerprint. These records are retained for 36 months from each respective decision and then deleted automatically. This documented operational retention period supports a traceable record of permissions and withdrawals and the clarification of related inquiries; it is not a general statutory retention period. The choice cookie and the records have different retention periods. Storing the choice is based on section 25(2)(2) TDDDG; necessary consent records are based on Article 6(1)(c) in conjunction with Article 7(1) GDPR.
Google Analytics and the separate analysis of inquiry sources are optional and are each enabled only after your consent. The legal bases are section 25(1) TDDDG and Article 6(1)(a) GDPR. Without the respective consent, these optional functions remain disabled. Consent is not required to send an inquiry or enter into a contract.
Inquiry basket and catalogue view: The inquiry basket uses the kv_cart_token cookie to associate your selection with a random identifier. This session cookie is set only after a successful basket action, not merely when the catalogue is opened. The server-side basket expires 24 hours after its last change. The basket and cookie are deleted when the basket is cleared or an inquiry is successfully submitted. Existing baskets are migrated when used again; unused legacy baskets expire within the remaining time of their previous 30-day lifetime, without extending that period. After you switch between list and grid, kvCatalogViewMode in session storage remembers your selected catalogue view until the tab session ends. The default view is not stored merely because the catalogue is loaded.
Login and protected customer areas: When the corresponding functions are used, wordpress_test_cookie checks whether cookies are available for the session. wp-resetpass-* supports password resets for the session. wordpress_logged_in_* and wordpress_sec_* enable login, by default for two days or up to 14 days when “Remember me” is selected. Protected customer links use kmear_portal_*, kmear_intake_access and kmear_intake_* for up to two hours; kmear_intake_done_* lasts five minutes and kmear_withdrawal_session lasts two hours.
Our own website statistics: The existing page counter records page views even without statistics cookies. It processes the time, requested path, referring domain, available campaign parameters, pseudonymised IP and browser information, device and operating system characteristics, and information about interaction with and visibility of the page. To determine geographic information, the visitor’s IP address is sent from our server to the external service ipwho.is. This collection takes place independently of the choice in the privacy dialog. The current statistics retention setting is 3,650 days.
6. EMBEDDED CONTENT FROM OTHER WEBSITES
Our website may contain embedded content (e.g., videos, images, articles, etc.) from other websites. Embedding this content can result in cookies from third-party providers being stored on your device and data about your interaction with this content being collected, including your IP address and browser information.
These third-party providers may also use your data for their own purposes, such as advertising or analysis. We have no control over the collection and use of data by these third-party providers and accept no responsibility or liability for their privacy practices. If you want to learn more about how these third-party providers use your data, you should read the privacy policies of these websites or contact the respective companies directly.
Please note that you can block or delete the use of cookies by third-party providers in your browser settings. Information on this can be found in the help function of your browser.
We have made efforts to use only content from trustworthy sources that comply with applicable data protection regulations. However, if you have any concerns or further questions about the use of embedded content, please feel free to contact us.
6.1. Google
We use services from the online service provider Google LLC (Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter “Google”). Google’s own privacy policy can be found at: https://policies.google.com/privacy
6.1.1. AdSense
Our website uses Google AdSense, an online service for integrating advertisements from Google LLC (“Google”). Google AdSense uses cookies to store on your device which ads have been displayed to you and how often they were clicked. The processing is based on Art. 6 para. 1 lit. f GDPR and in the interest of displaying advertising that could be of interest to you.
By using Google AdSense, data is also collected, processed, and used by Google. This data includes information about which ads were shown to you, which ads you clicked on, and which pages you visited. This information is usually transferred to a Google server in the USA and stored there. Google commits to maintaining an adequate level of data protection through its Privacy Shield certification.
You can prevent the use of cookies by Google AdSense by adjusting your browser software accordingly or by deactivating personalized advertising on the Google website at https://www.google.com/settings/ads/onweb/.
6.1.2. Google Analytics
We use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to analyse use of our website. We load Analytics only after your consent. Data processed includes page views, interactions, device information, an approximate location and pseudonymous identifiers. Consent is voluntary and can be withdrawn at any time through Privacy settings. The legal bases are Article 6(1)(a) GDPR and section 25(1) TDDDG.
Google Analytics 4 uses IP addresses to derive location information; according to Google, individual IP addresses are not logged or stored. The _ga and _ga_* cookies have a standard duration of up to two years; browsers may shorten it. If you withdraw consent, our Analytics integration is blocked and technically accessible Analytics cookies belonging to our website are deleted.
Processing by Google LLC in the United States is possible. Google explains its use of the EU-US Data Privacy Framework and Standard Contractual Clauses in its data transfer frameworks. Further information about processing and retention is available in Google’s privacy policy. Google describes its handling of IP addresses in its Analytics privacy help.
6.2. External Music Links
We link to external music services, including Spotify. No Spotify players are embedded on our website. When you open a music link, you leave our website and access the respective provider’s service. Its privacy notice applies to the processing of your data there.
6.3. Contact Form
We process your personal data that you provide to us via our contact form to process your inquiry or message. The legal basis for processing your data is Art. 6 para. 1 lit. b) GDPR for processing contract inquiries or Art. 6 para. 1 lit. f) GDPR to safeguard legitimate interests, for example, to respond to your inquiry. We store your personal data only as long as necessary for processing your request or as required by law.
Inquiry sources: Only with your separate consent do we determine the landing page during your form visit, the referring domain and available campaign parameters (UTM) to understand which pages and campaigns lead to inquiries. kmcf_landing_page stores the landing page in browser session storage until the tab is closed or you withdraw consent. On submission, permitted source details are stored on our server with your inquiry and may therefore be linked to your contact details. The server also accepts these details only if valid consent is present. This function does not send source details to Google. You can submit an inquiry without this analysis. The legal bases are Article 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw consent at any time for the future through Privacy settings. Source details already stored with an inquiry are subject to the retention information above and your data protection rights.
Please note that data transmission over the Internet can have security gaps. Complete protection of data against access by third parties is not possible. Therefore, we recommend not transmitting confidential information via the contact form, but rather contacting us directly by email or phone.
If you provide us with personal data via the contact form, you have the right at any time to request information about the data we have stored about you, correction, deletion, or restriction of processing of your data, as well as the right to data portability. If you have given your consent to the processing of your data, you can revoke it at any time with effect for the future. Please send us an email to info@kern-medien.de for this purpose.
6.4. Inquiries by Email or Phone
When you contact us by email, phone, or fax, your inquiry, including all resulting personal data (name, inquiry), is stored and processed by us for the purpose of handling your request. We do not share this data without your consent. The processing of this data is based on Art. 6 para. 1 lit. b) GDPR if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in effectively processing the inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested. The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.
7. PROCESSING OF PAYMENT INFORMATION
Payment Processing for Digital Products: For the purchase of digital products such as photos or music on our website, we offer payment options via credit card and SEPA transfer. The processing of these payments is carried out through our partner WooPayments for credit card transactions and directly via bank transfer for SEPA transfers. The choice of payment method is yours. To process the payments, your payment information is securely collected, processed, and stored. Depending on the chosen payment method, this includes information such as the last four digits of the credit card number, expiration date, and account number and bank code for SEPA transfers. Our website and the associated payment systems use HTTPS to ensure the secure transmission of your data.
7.1. Use of Payment Service Providers
WooPayments and Direct Bank Transfer: For the secure processing of payments, we utilize WooPayments, an integrated service from WooCommerce, for credit card transactions and enable payment via SEPA transfer directly to our bank account at N26. Your payment data is transmitted exclusively for the purpose of payment processing to WooPayments or our bank and processed there. Further information on data processing by WooPayments can be found in WooCommerce’s privacy policy. For direct bank transfers, you provide us with the necessary information to carry out the transfer.
7.2. Security Measures for Payment Information
Security of Your Payment Information: Protecting your personal information is of utmost importance to us. All payment information is transmitted using TLS encryption (Transport Layer Security) to ensure the security of data during transmission over the Internet. In addition, we employ various security measures to restrict access to your payment information and protect it against unauthorized access, misuse, or disclosure.
7.3. Retention Periods for Payment Information
Retention and Deletion of Payment Information: Your payment information is stored only as long as necessary for the processing of the payment and to comply with legal retention obligations. After the completion of the transaction and the expiry of the legal periods, your payment information will be securely deleted or anonymized.
7.4. Changes to Products or Services
Processing of Personal Data in Connection with the Sale of Digital Products: When purchasing digital products on our website, we collect personal data necessary for the processing of the purchase. This includes your name, email address, payment information, and details about the purchased products. This data enables us to process your purchase, grant you access to the purchased products, and provide customer support if needed.
7.5. Use and Disclosure of Personal Data
Disclosure of Data: Your personal data is treated with the utmost confidentiality and will not be shared with third parties without your explicit consent, unless necessary for payment processing, due to legal requirements, or to fulfill our contractual obligations towards you.
