Privacy Policy

Version 3.1 (27.08.2026). Binding version on the platform: Privacy Policy.

Privacy Policy of frutra GbR

01.08.2026

1. Controller and Data Protection Contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

frutra GbR
Partners: Wolfgang Baumann and Samuel Fürle
Lindenmattenstraße 25
79117 Freiburg im Breisgau
Germany
Telephone: +49 761 429626-49
Fax: +49 761 429626-50
Email: info@frutra.de

For data protection enquiries, contact us at datenschutz@frutra.de.

2. Scope and Principles

This Privacy Policy applies to the websites at frutra.de and frutra.com and the platform at trade.frutra.de and trade.frutra.com. It explains which personal data we process when you visit, register and use the platform.

We process personal data only to the extent required to provide our websites and platform, perform the company-level Platform Use Agreement, communicate, provide security, bill fees and meet statutory obligations. Acknowledging this Privacy Policy is not consent.

2.1 Legal Bases

Depending on the processing operation, we rely in particular on:

Our legitimate interests under Article 6(1)(f) GDPR include reliably performing the Platform Use Agreement with the registered company, documenting contacts and authority to represent it, processing legally relevant declarations with evidence, securing the platform and resolving justified claims.

2.2 Recipients and International Transfers

Within frutra, access is limited to persons who need it for their responsibilities. Data is also disclosed to other Members where this is required for the Marketplace, negotiation or contract conclusion and is apparent from the platform. We further use the hosting, email, mapping and monitoring providers described in this Policy. Public authorities, courts, legal advisers, tax advisers, banks or other bodies receive data only where required by law or necessary for the establishment, exercise or defence of legal claims.

Where a provider processes data outside the European Economic Area, we rely on a European Commission adequacy decision or appropriate safeguards under Article 46 GDPR, in particular Standard Contractual Clauses, where required together with supplementary measures. Details may be requested from datenschutz@frutra.de.

2.3 No Solely Automated Decisions

We do not make decisions producing legal or similarly significant effects based solely on automated processing within the meaning of Article 22 GDPR and do not carry out profiling for that purpose. Measures concerning Member Accounts or content are reviewed and decided by the partners.

3. Accessing the Websites and Platform

3.1 Server and Security Logs

When you access our services, we process technically required connection data, in particular IP address, date and time, requested address, volume transferred, referrer, browser and operating-system information, response status and technical error and security information. This is necessary to deliver content, detect attacks and disruptions, maintain security and correct errors. The legal basis is Article 6(1)(f) GDPR.

Technical logs are kept only for as long as required for operation, troubleshooting and security and are then erased or anonymised. In a specific security or misuse incident, relevant extracts may be preserved until the incident is finally resolved and for as long as required for legal enforcement.

3.2 Hosting by Upsun

Our websites, application and databases are operated using the Upsun hosting service of the Platform.sh group. According to the available contractual records, the central provider is Platform.sh SAS, 22 rue de Palestro, 75002 Paris, France; an affiliated company identified in the customer account may act as contracting party or service provider. Data stored on the platform and technical connection, operational, backup and log data are processed. Project data and backups are stored in the selected hosting region; according to the provider, access logs may be transferred to a central collection point within the European Union.

4. Cookies and Similar Technologies

We do not use analytics, advertising or marketing cookies on our websites or platform. Only technically necessary cookies or comparable functions are used, in particular for login and sessions, security and protection against cross-site request forgery, language selection and the form or platform function requested by you.

Accessing or storing information on the device is necessary under § 25(2) no. 2 TDDDG to provide the digital service expressly requested. Subsequent personal-data processing is based on Article 6(1)(b) GDPR where the data subject is personally a party to the contract and otherwise on Article 6(1)(f) GDPR. Session cookies are generally erased at the end of the session; security or settings cookies remain only for the technically defined period required. Consent management for non-essential technologies is unnecessary for as long as such technologies are not used.

5. Registration, Companies and User Accounts

5.1 Data Categories and Purposes

During registration and account management, we process in particular:

We need this data to verify companies and contacts, provide accounts, control permissions, perform the Platform Use Agreement and prove incorporation of the contractual documents. Acknowledgement of the Privacy Policy is recorded as acknowledgement, not consent.

5.2 Verification of VAT Identification Numbers

Where provided for, we verify a submitted VAT identification number using the EU VAT Information Exchange System (VIES) or a competent authority. The VAT identification number, country and requesting entity and the result and time of the check may be processed and documented. The legal bases are Article 6(1)(c) and (f) GDPR.

5.3 Mandatory Information and Account Deactivation

Without information marked as required, we cannot verify the company or properly perform the Platform Use Agreement. Deactivation of a personal user account is distinct from erasure under data protection law and does not automatically terminate the company's Platform Use Agreement. Erasure requests are reviewed separately under Article 17 GDPR.

6. Use of the Marketplace, Negotiations and Contract Conclusions

6.1 Offers and Requests

We process product, quantity, price, delivery, location and company information posted by Members, status and time data and technical identifiers in order to display and search Offers and Requests and make them accessible to authorised Members. For lawfully anonymous Requests, the company's identity and location are concealed from unauthorised users; authorised participants receive the information required for initiation and contract conclusion.

6.2 Negotiations and Evidence Record

In negotiations we process participants, the contents and versions of Offers and counteroffers, prices, quantities, terms, validity periods, status changes, declaration and receipt times and technical events. This serves to provide the platform function, reliably attribute legally relevant declarations, prevent misuse and preserve evidence.

6.3 Purchase Contracts and Documents

When a purchase contract is concluded, we create and store a record protected against subsequent alteration and the related documents. They contain in particular the parties and their company details, the accepted negotiation state, product, quantity, price, delivery terms, times and technical evidence. The parties have access to the documents required for performance and evidence. frutra does not become a party to the purchase contract.

6.4 Communications

When Members communicate through the platform or we provide support, we process sender, recipient, time, subject, content, attachments and technical delivery information. The data is used for pre-contractual and contractual communications, support and, where necessary, investigation of misuse or legal infringements.

7. Fees, Invoices and Payments

For billing and payment monitoring, we process company type and price plan, service periods, purchase contracts concluded through the platform and assessment bases, invoice and credit-note data, invoice recipient, bank details, payment status, incoming payments, objections and reminder status. Payment reconciliation and decisions on restrictions are manual.

The legal bases are Article 6(1)(b) GDPR where the data subject is personally a party to the contract, otherwise Article 6(1)(f) GDPR, and Article 6(1)(c) GDPR for invoicing and retention obligations. Recipients may include the bank used and bodies engaged for bookkeeping, annual accounts, tax advice, legal enforcement or audits where required.

8. Email Delivery and Brevo Contact Management

We use Brevo to send necessary registration, security, platform, negotiation, contract, invoice and service messages. For companies whose platform registration has been completed and confirmed, we automatically maintain a separate “FRUTRA platform users” list. We transmit business email address, first and last name, company and internal user ID. The list is used for transactional customer and delivery management, not advertising. Changes are synchronised; when the platform account is erased, the contact is removed from this list or erased unless another legal purpose requires continued storage. A temporary Brevo outage does not prevent platform registration.

Under the contractual terms available to us, the provider for customers established in Germany is Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. The data processing agreement forms part of Brevo's contractual terms. Brevo uses subprocessors inside and outside the European Economic Area; the applicable safeguards for international transfers include adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses.

We do not create personal opening or click profiles and do not use such data for scoring or advertising automation. When sending, the lack of consent to personal opening tracking is transmitted technically. Where Brevo processes technical opening, delivery, bounce, complaint or error events only in aggregate or for delivery, we use them solely for operation, security and deliverability.

The legal bases are Article 6(1)(b) GDPR where the data subject is personally a party to the contract and otherwise Article 6(1)(f) GDPR. We send advertising emails only where a separate legal basis is available; inclusion in the platform-user list is not consent to advertising.

9. Maps and Geodata (MapTiler)

We use MapTiler AG, Zugerstrasse 22, 6314 Unterägeri, Switzerland, for maps, geocoding and address suggestions. When a map is loaded, the browser requests map tiles directly from MapTiler. MapTiler receives in particular the IP address, time, tile requested, browser data and parameters technically required for delivery. The interactive map is loaded only on platform pages where it is required for the requested function.

Address fragments for autocomplete and geocoding are transmitted to MapTiler by our server; the browser receives only the result standardised by frutra. We store the selected address and, where required for location, mapping or logistics functions, the coordinates derived from it. The legal basis is Article 6(1)(b) GDPR where the data subject is personally a party to the contract and otherwise Article 6(1)(f) GDPR.

The European Commission has adopted an adequacy decision for Switzerland. MapTiler may use subprocessors in the EEA and other countries; the DPA provides for adequacy decisions, Standard Contractual Clauses or other appropriate safeguards. A DPA including a supplementary Article 28 GDPR side letter has been incorporated with MapTiler.

10. Monitoring and Security (FoundersDeck)

We use FoundersDeck, Engin Yildirim, Jägerstraße 20, 78054 Villingen-Schwenningen, Germany, to monitor availability, response times and technical errors. Status, time, connection and error data is processed; error messages may exceptionally contain personal information. The legal basis is Article 6(1)(f) GDPR. FoundersDeck processes data as a processor and uses Netcup GmbH in Germany as a hosting subprocessor.

11. Statutory Recording and Reporting Obligations

Where frutra is a reporting platform operator under the German Platform Tax Transparency Act (PStTG/DAC7), we collect, verify and report the legally required seller and activity data to the German Federal Central Tax Office. This may include company or personal name, address, tax and VAT identification numbers, register details, tax residence, date of birth for natural persons, payment account, consideration and number of relevant activities. The legal basis is Article 6(1)(c) GDPR in conjunction with the PStTG.

Where §§ 22f and 25e of the German VAT Act apply, we record the required company and transaction information and disclose it when legally requested. Further disclosures are made where required under mandatory tax, commercial, criminal-procedure or other law.

12. Retention Periods

We erase personal data once it is no longer required for the relevant purpose and no retention obligation or overriding entitlement to continued storage applies. The following rules apply to the main platform data:

Where a specific legal dispute, official order or other statutory retention obligation applies, erasure of the affected data is suspended until that ground ceases to apply. The data is then erased or anonymised.

13. Data-Subject Rights

Subject to the statutory requirements, you have the right of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and the right to object to processing based on Article 6(1)(e) or (f) GDPR (Article 21). You may withdraw consent at any time with effect for the future (Article 7(3)).

Objection: Where processing is based on legitimate interests, you may object at any time on grounds relating to your particular situation. We will then cease processing unless we demonstrate compelling legitimate grounds or the processing is required for the establishment, exercise or defence of legal claims. You may object to direct marketing at any time without giving reasons.

Send your request to datenschutz@frutra.de or to the postal address in Clause 1. We may request additional information where necessary to verify your identity. The statutory response periods apply.

14. Right to Lodge a Complaint

You may lodge a complaint with a data protection supervisory authority, in particular at your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is:

The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Postal address: Postfach 10 29 32, 70025 Stuttgart, Germany
Telephone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
www.baden-wuerttemberg.datenschutz.de

15. Amendments

We amend this Privacy Policy when the law, processing activities or services used change. The current version is available on our websites and platform. We inform registered Members of material changes in an appropriate manner. Previous versions remain archived for evidentiary purposes.