Legal
Privacy policy
How PureSource handles personal data on this website. Last updated: September 2026.
Who is responsible
The controller under the EU General Data Protection Regulation (GDPR) is:
PureSource Natural Solutions GmbH
Römerweg 21
86391 Stadtbergen
Germany
Email: a.papp@puresource.gmbh
Phone: +49 174 2415257
For any question about your data, write to the email address above.
The short version
This website sets no cookies and uses no analytics, advertising or tracking tools. The fonts come from our own server, so your browser does not contact Google or any other font provider. The enquiry forms send nothing from this site: they open an email in your own mail program, and nothing reaches us until you send it yourself.
When you visit the site
The site is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. To deliver the pages and keep the site secure, the host automatically records technical data in server log files: your IP address, the date and time of the request, the page requested, the page you came from, and your browser and operating system. We never receive these log files ourselves — they stay with the host.
The legal basis is our legitimate interest in running a secure, working website (Art. 6(1)(f) GDPR). The logs are deleted after no more than 30 days. We have a data processing agreement with the host (Art. 28 GDPR).
Our host is based in the United States, so this technical data may be processed outside the EU. The transfer rests on the standard contractual clauses that form part of our data processing agreement with the host (Art. 46(2)(c) GDPR).
To show the site in English or German, your browser’s language setting is read when you first arrive. It is used for that one redirect and not stored.
When you contact us
If you email or phone us, or send an enquiry through one of the forms (which opens your own mail program), we process what you give us — usually your name, company, contact details and what you are looking for — to answer and, where it leads there, to prepare an offer.
The legal basis is Art. 6(1)(b) GDPR where the enquiry relates to a possible contract, and otherwise our legitimate interest in answering (Art. 6(1)(f) GDPR). We keep enquiries until they are dealt with. Where they become business correspondence, commercial and tax law require us to keep them for six to ten years (§ 257 HGB, § 147 AO).
Links to other websites
The Partners and Portfolio pages link to our partners’ own websites. Nothing is sent to them unless you click a link; from then on, their own privacy policies apply.
Your rights
You have the right to access the data we hold about you, to have it corrected or deleted, to restrict its processing, and to receive it in a portable format (Art. 15–20 GDPR). Where we rely on our legitimate interest, you can object to the processing at any time (Art. 21 GDPR).
You can also complain to a data protection supervisory authority. The one responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Data protection officer
We are not required to appoint a data protection officer (§ 38 German Federal Data Protection Act, BDSG).
Encryption
The site is served over an encrypted connection (TLS), which you can recognise by the lock symbol and “https://” in your browser’s address bar.
Language
This English version is provided for convenience. The German version of this privacy policy is legally binding.