Last updated: July 23, 2026
1. Scope
This Privacy Policy applies to the service portal available at https://service.both3d.de/.
The online shop accessible via links at https://www.both3d.de/, as well as any other external websites, are governed by their respective privacy policies.
2. Data Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Tobias Both
BOTH3D
Wasserfuhrstraße 60
51643 Gummersbach
Germany
Phone: +49 151 51501679
Email: info@both3d.de
3. General Information on Data Processing
Personal data means any information relating to an identified or identifiable natural person.
We process personal data only to the extent necessary to provide and secure this service portal, respond to inquiries, comply with legal obligations, or—where optional external media are involved—based on your consent.
Personal data will only be disclosed where necessary to fulfill the purposes described above, where required by law, where you have given your consent, or where a service provider processes data on our behalf under a data processing agreement.
Your personal data will never be sold.
4. Hosting and Server Log Files
This service portal is hosted by:
ALL-INKL.COM – Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68
02742 Friedersdorf
Germany
The hosting provider supplies web hosting, databases, DNS services, SSL certificates, email services, backups, and security-related services.
Where the hosting provider processes personal data on our behalf, this is carried out under a Data Processing Agreement (DPA) in accordance with Article 28 GDPR.
Whenever you access this website, technically necessary access data is processed. This may include:
- IP address of the requesting device
- Date and time of access
- Requested URL or file and transferred data volume
- HTTP status code
- Referrer URL (if provided by your browser)
- Browser type and version
- Operating system
- Language settings
- Device information
The processing of this data is necessary to ensure the reliable delivery of the website, maintain system stability, detect and resolve technical issues, protect against attacks and misuse, and safeguard our systems.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and reliable operation of this service portal.
Server log data is generally retained only for as long as necessary for operational and security purposes.
According to the hosting provider’s published information, standard web server log files are deleted no later than seven days after collection. Longer retention may occur where necessary to investigate or document security incidents, attacks, or legal violations. In such cases, the relevant data will be retained until the matter has been resolved and, where applicable, until statutory limitation or retention periods have expired.
According to the hosting provider, all data center services are operated in Germany.
Further information can be found in the privacy policy of ALL-INKL.COM.
5. Website Content, Search Function, and Downloads
This service portal provides FAQs, link collections, documentation, and downloadable files.
When you use the search function, the search term you enter is transmitted to our server and processed solely to provide matching search results.
Search terms are not combined into user profiles and are not evaluated for advertising or analytics purposes. However, they may temporarily form part of the server log files described in Section 4.
When downloading files or documentation, the server processes the connection and access data required to deliver the requested file.
No additional download statistics based on personal data are created, and no user profiling takes place.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest is the provision of the requested service content, troubleshooting, and protection against misuse.
6. WordPress and Polylang
This service portal is operated using a self-hosted WordPress installation. Public user registration, customer accounts, and comments are disabled.
Based on the current technical configuration, simply visiting this website does not transmit any personal data to WordPress.com or Automattic.
The website uses the locally installed Polylang WordPress plugin to provide German and English language versions.
Polylang sets the pll_language cookie. This cookie stores the selected or automatically detected language code (for example, de or en) and is required to display the website in the appropriate language.
The cookie is transmitted over an encrypted connection, uses the SameSite=Lax attribute, and is currently stored for one year.
The storage of this cookie is necessary to provide the selected language version in a user-friendly manner.
Where Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies, the cookie is stored pursuant to Section 25(2) No. 2 TDDDG.
The legal basis for the associated processing of personal data is Article 6(1)(f) GDPR. Our legitimate interest is the consistent delivery of the user’s preferred language.
7. Consent Management and Local Storage
This service portal uses its own consent management system for optional external media.
Your choice is stored exclusively in your browser’s local storage under the key:
both3d_consent_v1
The following information is stored:
- whether external media are permitted (true or false)
- the date and time of your decision
- the version of the consent settings
This information is not used for analytics or advertising purposes and is not transmitted to our servers solely because it is stored.
It remains stored until you delete your browser’s website data or change your selection via the Cookie Settings link in the website footer.
The storage is necessary to respect your choice, document and manage your consent where applicable, and avoid asking for your decision every time you visit another page.
Where Section 25 TDDDG applies, storage is based on Section 25(2) No. 2 TDDDG.
The legal bases for the associated processing are Article 6(1)(c) and Article 6(1)(f) GDPR.
8. YouTube Videos (Only with Your Consent)
Some FAQ articles may contain embedded YouTube videos.
For users within the European Economic Area (EEA), the service is generally provided by:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
The parent company is:
Google LLC
1600 Amphitheatre Parkway
Mountain View, CA 94043
United States
A YouTube video is not loaded automatically when you visit a page.
Instead, a locally hosted placeholder is displayed first.
Only after you select “Allow External Media” or “Load Video” is an iframe loaded from www.youtube-nocookie.com.
Once activated, Google may receive information including:
- your IP address
- date and time of access
- the page you visited
- referrer information
- browser and device information
- interaction data
Google may also set cookies or use similar technologies and may associate the collected information with your Google account if you are signed in.
Please note that using youtube-nocookie.com does not prevent Google from processing personal data after you activate a video.
Videos are only activated based on your consent pursuant to Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG.
Your consent is voluntary.
Without your consent, all other content of this service portal remains fully available; only the respective video cannot be played.
You may withdraw your consent at any time via the Cookie Settings link in the footer.
Previously performed processing remains lawful until your consent is withdrawn.
After withdrawal, YouTube iframes currently loaded on the page will be removed. However, we cannot delete any data that has already been transmitted to Google.
Google may process personal data outside the European Union or the European Economic Area, particularly in the United States.
According to Google, transfers to Google LLC are based, among other mechanisms, on the EU–U.S. Data Privacy Framework and, where required, the Standard Contractual Clauses (SCCs).
Further information regarding the nature, scope, purposes, and storage of data processing can be found in Google’s Privacy Policy and information about Google cookies.
9. External Links
This service portal contains links to external providers, including the BOTH3D online shop, Amazon, AliExpress, manufacturers’ websites, and other external resources.
Simply viewing a page containing these links does not establish a connection to the respective external provider.
A connection is only established once you actively click an external link.
At that point, you leave our area of responsibility.
The respective provider receives the technically necessary access data and processes it under its own responsibility and in accordance with its own privacy policy.
Please refer to the privacy policy of the respective provider for further information.
10. Contact by Email or Telephone
If you contact us by email or telephone, we process the contact details you provide, the content of your message, the time of your inquiry, and any additional information required to process your request.
Where your inquiry relates to a contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR.
For all other inquiries, processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the proper handling and documentation of your request.
Where statutory retention obligations apply, Article 6(1)(c) GDPR also serves as the legal basis.
Communication data will be deleted once your request has been fully processed, unless statutory retention obligations, documentation requirements, or legal claims require longer storage.
Please do not send special categories of personal data unless this is absolutely necessary.
11. Administration, Login, and Security Features
The administration area of this website is intended exclusively for the website operator.
When accessing the login page or signing in, technically necessary WordPress cookies may be set. These include, in particular:
- a test cookie
- authentication and session cookies
- cookies for personal backend preferences
These cookies are required to ensure secure authentication and administration.
Session cookies are generally deleted when your browser session ends.
Authentication cookies are typically stored for the current session, approximately two days, or up to 14 days if the “Remember Me” option is selected.
Backend preference cookies may remain stored for up to one year.
To protect the website against unauthorized access, failed login attempts are rate-limited.
For this purpose, a pseudonymized verification value is generated from the username and IP address using a server-side secret key and stored together with the number of failed login attempts for up to 15 minutes.
Authorized administrators may additionally use two-factor authentication (2FA).
The legal basis for this processing is Article 6(1)(f) GDPR.
Our legitimate interest is the protection of this service portal, its content, and the data processed on it against attacks and unauthorized access.
12. Recipients and Data Processors
Recipients of personal data may include, in particular:
- ALL-INKL.COM – Neue Medien Münnich, acting as the hosting provider, email service provider, and data processor where applicable.
- Google Ireland Limited and other Google companies, solely after you have given your consent to load YouTube videos.
- IT service providers, legal advisors, or tax consultants where necessary and legally permissible.
- Public authorities, courts, or other governmental bodies where disclosure is required by law or necessary for the establishment, exercise, or defense of legal claims.
13. Data Retention
Unless a specific retention period is stated elsewhere in this Privacy Policy, personal data will only be stored for as long as necessary to fulfill the respective purpose.
Afterwards, the data will be deleted or anonymized unless statutory retention obligations, legitimate documentation requirements, or the establishment, exercise, or defense of legal claims require longer storage.
Deleted data may remain in technically required backup copies until those backups are routinely overwritten.
Backup copies are used exclusively for disaster recovery and system restoration and are not evaluated for any other purpose.
14. Data Security
This service portal is transmitted using encrypted HTTPS connections.
In addition, appropriate technical and organizational security measures are implemented, including:
- restricted access permissions
- security headers
- a Content Security Policy (CSP)
- disabled public registration and comments
- a protected administration interface
- login attempt limitation
- strong password policies
- optional two-factor authentication
- secure upload validation
- regular software updates
- regular backups
Despite these measures, complete security of data transmission over the Internet cannot be guaranteed.
15. Your Rights
Subject to the applicable legal requirements, you have the following rights in particular:
- the right of access to your personal data (Article 15 GDPR)
- the right to rectification of inaccurate or incomplete data (Article 16 GDPR)
- the right to erasure (“right to be forgotten”) (Article 17 GDPR)
- the right to restriction of processing (Article 18 GDPR)
- the right to data portability (Article 20 GDPR)
- the right to object to processing (Article 21 GDPR)
- the right to withdraw any consent previously given with future effect (Article 7(3) GDPR)
- the right to lodge a complaint with a supervisory authority (Article 77 GDPR)
To exercise your rights, simply send an informal request to:
To prevent unauthorized disclosure of personal data, we may request appropriate proof of your identity before processing your request.
16. Right to Object (Article 21 GDPR)
Where we process personal data on the basis of Article 6(1)(f) GDPR (legitimate interests), you have the right to object to such processing at any time on grounds relating to your particular situation.
If you object, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims.
17. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority.
The supervisory authority responsible for the registered office of the data controller is:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de/
You may also contact any other competent data protection supervisory authority within the European Union.
18. Obligation to Provide Data and Automated Decision-Making
The technically necessary connection data must be processed in order to provide this service portal, search results, and downloadable content. Without this processing, the website cannot function properly.
Providing personal data when contacting us by email or telephone is voluntary. However, if you do not provide the information necessary to process your request, we may be unable to respond.
Consent to the loading of YouTube videos is entirely voluntary and is not required to use any other features of this service portal.
No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.
19. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy whenever changes to this website, the services used, or applicable legal requirements make this necessary.
The version published on this page is always the current and applicable version.