Privacy Policy
Version date: 10 September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data-protection laws is:
Stauden Peters Pflanzenvertriebs GmbH
Drüller Weg 14
47559 Kranenburg
Germany
Phone: +49 (0)2826 9150-0
Email: info@eledesign.de
Website: www.eledesign.de
eledesign is a brand of Stauden Peters Pflanzenvertriebs GmbH.
2. General information on data processing
We process personal data only to the extent necessary to operate our website, provide our services, process orders and enquiries, perform contracts, handle payments and shipping, communicate with customers and – where you have consented – perform analytics and marketing activities.
Depending on the processing activity, the legal bases include in particular Article 6(1)(a) GDPR (consent), Article 6(1)(b) GDPR (contract or pre-contractual steps), Article 6(1)(c) GDPR (legal obligation) and Article 6(1)(f) GDPR (legitimate interests). Where information is stored on or accessed from your terminal equipment, Section 25 TDDDG also applies.
3. Hosting, content delivery and technical infrastructure
Based on the information provided to us, eledesign uses Vercel, IONOS and Cloudflare for technical operation. When you access the website, technically necessary information may be processed, including IP address, date and time of access, requested URL or file, referrer URL, browser and device information, operating system, and technical status and log data. This processing serves to deliver the website, ensure stability and security, diagnose errors and prevent misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and efficient operation of our online service. Where processing is necessary to perform a contract requested by you or to take pre-contractual steps, Article 6(1)(b) GDPR also applies.
Vercel and Cloudflare operate internationally. Personal data may therefore be transferred to third countries, particularly the United States. According to their publicly available information, Vercel and Cloudflare rely, where applicable, on mechanisms including the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses. Based on the information available, IONOS provides for processor arrangements under Article 28 GDPR.
4. Cookies, local storage and consent management
We use Silktide Consent Manager to manage your choices regarding non-essential technologies. According to Silktide documentation, the Consent Manager stores your choice in your browser’s local storage so that it can be restored on later visits and changed by you.
Storage or access that is strictly necessary may be based on Section 25(2) TDDDG. Non-essential technologies, particularly analytics or marketing technologies, are activated only with your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. You may withdraw or change your consent at any time with future effect through the privacy/consent settings provided on the website.
5. Google Analytics
Where you have consented via the Consent Manager, we use Google Analytics to measure reach and analyse the use of our website. For European users, the relevant provider is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; other Google companies may be involved in providing the service.
Data processed may include information about page views, interactions, approximate location, browser, device, operating system, referrer, session and event data. According to Google, individual IP addresses of users in the EU, Switzerland and the United Kingdom are not logged or stored and are discarded before logging. Data may nevertheless be processed internationally within Google’s infrastructure.
Data Retention:
Event-level data (such as page views and interaction events) is retained for 2 months and automatically deleted thereafter. User-level identifiers are retained for 14 months, with the retention timer resetting upon new activity prior to expiration.
Advertising Features & Signals:
Google Signals and personalized advertising features are disabled. We do not use Google Analytics for remarketing or cross-device advertising profiling.
The legal basis is your consent under Article 6(1)(a) GDPR and, for non-essential storage/access on terminal equipment, Section 25(1) TDDDG. You may withdraw your consent at any time through the privacy settings.
6. AI-assisted garden design with Neighborbrite
eledesign offers an AI-assisted garden and landscape-design function in collaboration with Neighborbrite Inc. You may upload a photograph of your garden, terrace or other outdoor area and provide design instructions. Neighborbrite processes these inputs to generate automated design suggestions and visualisations. Independently of the AI function, customers may also select and purchase ready-made garden concepts and products directly through www.eledesign.de.
According to the information you supplied, Neighborbrite uses a proprietary AI orchestration system consisting of an evolving ensemble of models. Different models may analyse the outdoor space, apply landscape-design principles, select plants, develop the composition and generate the visualisation. The specific models or third-party providers may change over time.
Data processed may include the uploaded image, design instructions and prompts, generated outputs, technical usage/session data and a pseudonymous session identifier. Based on the information provided, users of the Neighborbrite experience embedded in eledesign do not need a separate Neighborbrite account.
The purpose of processing is to provide the AI design function requested by you and, if you subsequently decide to purchase, to enable the technical handoff to eledesign so that you can continue the order process. The legal basis is Article 6(1)(b) GDPR where processing is necessary to provide the requested service or take pre-contractual steps. Where consent is required for optional technologies, Article 6(1)(a) GDPR together with Section 25(1) TDDDG applies.
According to the information supplied to us, images may be processed or stored outside the EU/EEA, including in the United States. Neighborbrite’s current public Privacy Policy also states that its sites are hosted in the United States and that personal data may be transferred there.
According to the information you supplied, uploaded images are retained for as long as Neighborbrite considers reasonably necessary to provide, maintain, evaluate and improve the service; there is currently no fixed automatic expiration period. Deletion requests may be sent to privacy@neighborbrite.com.
Also according to the information you supplied, customer images may be used by Neighborbrite to evaluate, improve and train its own systems and services. When selecting external models or service providers, Neighborbrite states that it generally prefers providers that do not use submitted customer data to train their own models, but the specific providers and terms may change. If you use Neighborbrite through its own app or website, Neighborbrite's own privacy policy additionally applies to the processing carried out there.
Where possible, please upload images that do not contain identifiable people, vehicle registration plates, house numbers or other unnecessary personal information. If images show other individuals, please ensure that you are entitled to submit them.
7. Customer accounts, guest checkout and order processing
You may purchase ready-made garden concepts and products directly through eledesign. Alternatively, you may first design your garden using the Neighborbrite function embedded in eledesign or through a Neighborbrite app. If, after finalising the design, you decide to proceed with a purchase, Neighborbrite provides a purchase link/URL to eledesign or redirects you to eledesign through that link. The actual order, selection or confirmation of the products to be purchased, entry of billing and delivery details, payment and order confirmation then take place through eledesign. The contractual partner for the purchase and order fulfilment is Stauden Peters Pflanzenvertriebs GmbH, which operates the eledesign brand. Stauden Peters Pflanzenvertriebs GmbH fulfils the order and arranges delivery. In connection with registration, ordering and contract performance, we process data such as name, billing and delivery address, email address, telephone number (where provided or required for delivery), order and product information, payment status, communications and, where applicable, account and login data.
Processing is necessary for pre-contractual steps and performance of the purchase contract under Article 6(1)(b) GDPR. Where statutory retention and evidence obligations apply, continued storage is based on Article 6(1)(c) GDPR. Under current German commercial and tax rules, accounting vouchers are generally retained for eight years, while certain other business records may be subject to six- or ten-year periods.
8. Payments with Stripe
We use Stripe for payment processing. During payment, data such as name, email address, billing address, payment amount, currency, transaction information, payment-instrument and device information may be processed. Depending on the payment method, payment credentials are processed directly by Stripe; as a rule, we do not receive complete card details.
Processing is necessary to perform the contract and the payment method selected by you under Article 6(1)(b) GDPR. Where Stripe processes data under its own responsibility for legal obligations, fraud prevention, security or regulatory purposes, Stripe’s privacy information also applies. Stripe operates internationally and may process personal data outside the EEA using the applicable transfer mechanisms.
9. Shipping with DHL
To deliver your order, we transfer the data required for shipping to DHL, in particular your name and delivery address and – where required and legally permissible for the selected delivery option – your email address and/or telephone number. The legal basis is Article 6(1)(b) GDPR. Where optional delivery notifications or recipient services require separate consent, the relevant processing is based on Article 6(1)(a) GDPR.
10. Email communications and newsletters via Resend
We use Resend, a service provided by Plus Five Five, Inc., to send technical and transactional emails as well as marketing newsletters. Data processed includes email address, name, message content, metadata, and delivery information. According to Resend's public disclosures, key processing operations take place in the United States; Resend relies on Standard Contractual Clauses and its certification under the EU–U.S. Data Privacy Framework as transfer mechanisms.
Double Opt-In & Tracking:
Newsletter subscriptions are completed using a double opt-in procedure. You will receive a confirmation email to confirm your email address before receiving marketing communications. Our newsletters sent via Resend contain tracking technologies (such as web beacons/pixels) that allow us to collect performance data, including whether an email was opened and which links were clicked. This analytics data is processed solely to evaluate campaign performance and improve our content.
Legal Basis:
Transactional emails (e.g., service notifications or order details) are processed under Article 6(1)(b) GDPR or Article 6(1)(c) GDPR. Newsletters and email performance tracking are carried out exclusively on the basis of your explicit consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time with future effect by using the unsubscribe link in any newsletter or by emailing info@eledesign.de.
11. Contacting us
If you contact us by email, telephone or contact form, we process the information you provide in order to handle your enquiry. Where the enquiry concerns a contract or pre-contractual steps, the legal basis is Article 6(1)(b) GDPR; otherwise it is Article 6(1)(f) GDPR based on our legitimate interest in efficiently handling enquiries. Where consent is obtained, Article 6(1)(a) GDPR applies.
12. Recipients and international transfers
We disclose personal data only where necessary for the relevant purpose and legally permitted. Recipients may include hosting and infrastructure providers, payment providers, shipping providers, email providers, analytics providers, IT service providers and providers involved in the AI garden-design function.
For transfers to countries outside the EU/EEA, we ensure – where required by law – that the requirements of Articles 44 et seq. GDPR are met, for example through an adequacy decision, a recipient’s participation in the EU–U.S. Data Privacy Framework, or appropriate safeguards such as Standard Contractual Clauses.
13. Retention periods
We generally retain personal data only for as long as necessary for the relevant purpose or as required by statutory retention obligations. Once the purpose no longer applies, data is deleted or restricted unless there is a legal basis for continued storage. Contract, invoice and accounting data may be retained for several years under commercial and tax law.
14. Your rights
Subject to the statutory requirements, you have rights including access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection to certain processing (Article 21). You may withdraw consent at any time with future effect (Article 7(3)).
You also have the right to lodge a complaint with a data-protection supervisory authority (Article 77 GDPR). In particular, you may contact the authority responsible for the federal state in which our company is established, or another supervisory authority competent for you.
15. Right to object
Where we process personal data on the basis of Article 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. Where personal data is processed for direct marketing, you have the right to object at any time to processing for such marketing.
16. Data security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other risks. Data transmitted through our website is generally encrypted using TLS/HTTPS.
17. Changes to this Privacy Policy
We may update this Privacy Policy if our website, service providers, processing activities or legal requirements change. The version published on www.eledesign.de is the applicable version.
