Privacy Policy
upbyte® e.K.
Notice:
This English version is provided solely for convenience and informational purposes.
Only the German version is legally binding.
In case of discrepancies, conflicts or interpretation issues, the German version shall prevail.
1. Controller
The controller responsible for data processing is:
upbyte® e.K.
Owner: Riccardo Rabe
Schwastrum 60
24351 Damp
Germany
Email: [email protected]
Phone: +49 4352 9530000
Contact for data protection enquiries:
[email protected]
2. General
We process personal data only to the extent necessary for the operation of our website, the handling of enquiries, the performance of contracts, the operation of our IT and software services, or due to statutory obligations.
This privacy policy applies to our website and the associated online services of upbyte® e.K. For customer-specific hosting, SaaS, software or support services, additional contracts, service descriptions and a data processing agreement pursuant to Art. 28 GDPR may apply.
3. Hosting and Technical Provision
Our website and online services are operated on leased servers and leased infrastructure.
We use the following hosting and infrastructure providers in particular:
- Hetzner Online GmbH, Germany
- netcup GmbH, Germany
Storage and regular server operation are currently generally performed on server locations in Germany, unless otherwise stated for individual services.
Data processing agreements pursuant to Art. 28 GDPR have been concluded with the hosting providers used.
Delivery and protection via Cloudflare: The website is delivered via the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare forwards all requests to our server, protects the website against attacks and overload and caches files. In doing so, Cloudflare processes technical connection data such as IP address, time, requested address and browser information. Cloudflare may set technically necessary cookies, for example to detect automated access.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, fast and stable provision of the website. A Data Processing Addendum pursuant to Art. 28 GDPR is in place with Cloudflare. A transfer to the USA is possible; Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023), and EU Standard Contractual Clauses apply in addition. Further information: Cloudflare Privacy Policy.
When you access our website, technically necessary data is processed in order to provide the website securely and reliably. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient operation of our website and IT systems.
4. Server Log Files
When you access our website, the web server automatically processes technical access data. This may include:
- IP address of the requesting system
- Date and time of access
- Requested URL or file
- Referrer URL
- Browser type and browser version
- Operating system
- Web server status code
- Amount of data transferred
- Technical error and security information
Processing is carried out for technical provision, error analysis, abuse detection and system security.
The legal basis is Art. 6(1)(f) GDPR.
Server log files are generally deleted or anonymised after no more than 14 days, unless longer retention is required for the investigation of security incidents, abuse or technical faults.
5. Cookies and Local Storage
Our website uses technically necessary cookies and comparable storage mechanisms, insofar as these are required for the operation, security or display of the website. The storage of technically necessary information is based on Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act). The subsequent processing of personal data is based on Art. 6(1)(f) GDPR.
In addition, we use optional cookies and storage technologies for marketing and analytics purposes, exclusively after your active consent via our cookie consent banner (see Section 13). Without your consent, these services are not loaded and no corresponding cookies are set. Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR.
You may withdraw your consent at any time via the cookie settings button (bottom left of the page). You may also restrict or delete cookies via your browser settings. This may impair individual functions of the website.
6. Contact
When you contact us by email, telephone, contact form or other means of communication, we process the data you provide.
This may include:
- Name
- Company
- Email address
- Phone number
- Message content
- Technical communication data
- Project and contract information
Processing is carried out for the purpose of handling your enquiry, initiating or performing a contract, or for general communication.
The legal bases are Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
Enquiries are deleted once they have been conclusively dealt with and no statutory retention obligations, documentation requirements or ongoing contractual relationships preclude deletion.
7. Communication via WhatsApp
We offer the option of contacting us via WhatsApp at +49 170 7470333. When you contact us via WhatsApp, we process in particular your phone number, your name, profile information, message content, communication data and the times of communication.
The service is provided by WhatsApp Ireland Limited. Depending on usage, data may also be processed by companies within the Meta group. We have no full control over this data processing by WhatsApp.
The use of WhatsApp is voluntary. Alternatively, you can contact us at any time by email or telephone.
The legal basis is Art. 6(1)(b) GDPR, insofar as the communication serves the initiation or performance of a contract, and Art. 6(1)(f) GDPR for general communication. Our legitimate interest lies in simple and fast communication.
Please do not send us particularly sensitive data via WhatsApp unless this is expressly required and agreed upon.
8. Contractual and Business Data
If you are a customer, prospective customer, supplier, service provider or business partner of upbyte® e.K., we process personal data for the initiation, performance and management of the business relationship.
This may include:
- Master data
- Contact data
- Contract data
- Communication data
- Billing and payment data
- Project information
- Support and maintenance information
- Technical system information
- Access credentials, insofar as required for the service
The legal bases are Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.
Our legitimate interest lies in the performance, documentation, safeguarding and management of our business relationships.
9. Applications, Employees, Freelancers and Payroll
If you apply to us or work for us, we process personal data insofar as this is necessary for applications, selection, collaboration, time tracking, billing, payroll, contract performance or statutory obligations.
This may include:
- Master data
- Contact data
- Application documents
- Qualifications
- Contract data
- Activity and performance records
- Time tracking data
- Billing data
- Tax and social security data, insofar as required
- Communication data
The legal bases are Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR, Art. 6(1)(f) GDPR and Section 26 BDSG (German Federal Data Protection Act), where applicable.
Application data is deleted as soon as it is no longer required for the application process and no statutory deadlines or legitimate documentation interests preclude deletion.
10. Customer Projects, Software, Hosting, SaaS and Support
In the course of our services, we may process personal data that customers enter into systems developed, managed or operated by us.
This may include in particular:
- Customer data
- Prospective customer data
- User and visitor data
- Login and authentication data
- Content data
- Communication data
- Documents and files
- Log data
- Payment and transaction data
- Applicant data
- Employee data
- Time tracking data
- HR and payroll data
Insofar as we process such data on behalf of a customer, we act as a processor. In this case, the respective customer is the controller within the meaning of the GDPR. The details are governed by a separate data processing agreement pursuant to Art. 28 GDPR.
In such cases, the customer remains responsible for the lawfulness, purposes, legal bases, information obligations, data subject rights and deletion periods.
11. Technical Support and Administrative Access
In the course of support, maintenance, error analysis, migration, backup, recovery, security measures or project work, access to personal data may be required.
Such access is granted only insofar as it is necessary for the provision of services, error resolution, security or pursuant to the customer's instructions.
upbyte® e.K. also engages freelancers and technical service providers. These are bound by obligations of confidentiality, data protection and instruction compliance.
In individual cases, administrative or technical access may also occur from third countries, in particular by freelancers or technical service providers in Pakistan or the Philippines. Such access is granted only in the course of service provision and in compliance with the requirements of Art. 44 ff. GDPR.
12. AI-Powered Tools
upbyte® e.K. may use AI-powered tools to support internal work processes, development, documentation, analysis, communication or quality assurance.
Personal, confidential or sensitive customer data is not provided for the training of external AI models without a legal basis, necessity or contractual authorisation.
AI-generated results are not used unchecked as binding legal, tax, data protection or compliance advice.
13. Web Analytics, Tracking and Marketing
We use the analytics and marketing services described below on this website. These are loaded exclusively after your active consent via our cookie consent banner. Without consent, no data is transmitted to these services.
Analysis of technical server data (log files) is carried out independently of the above for the purposes of security, error analysis and operational optimisation.
13.1 Microsoft Clarity
Provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland.
Purpose: Usage analysis to improve the website. Clarity creates heatmaps and session recordings to understand how visitors use the website (clicks, scroll behaviour, page navigation). For this purpose, Clarity stores a pseudonymous identifier in a cookie; the data is therefore pseudonymised, not anonymised. No keyboard input in forms is recorded.
Cookies: _clck, _clsk (session and pageview attribution) and cookies on Microsoft domains (e.g. MUID, CLID).
Storage duration: Cookie _clck up to 12 months, _clsk 1 day. Microsoft retains recordings for 30 days and click and heatmap data as well as labelled sessions for 9 months.
Transfer to third countries: Personal data may be transferred to Microsoft Corporation (USA). Microsoft is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023).
Legal basis: Art. 6(1)(a) GDPR (consent), Section 25(1) TDDDG.
Data processing agreement: A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is in place with Microsoft.
Further information: clarity.microsoft.com/terms, Microsoft Privacy Statement.
13.2 Meta Pixel (Facebook Pixel)
Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Purpose: Reach measurement and advertising effectiveness analysis. The Meta Pixel records whether and how visitors interact with our website following an advertisement. It is not used by us for retargeting or for creating user profiles for advertising purposes.
Cookies: _fbp (browser attribution), _fbc (click identifier for ad clicks).
Storage duration: Up to 90 days (_fbc), up to 2 years (_fbp).
Data transfer to third countries: Personal data may be transferred to Meta Platforms, Inc. (USA). Meta is certified under the EU-U.S. Data Privacy Framework (EU Commission adequacy decision of 10 July 2023).
Legal basis: Art. 6(1)(a) GDPR (consent), Section 25(1) TDDDG.
Further information: Meta Privacy Policy, Meta Privacy Center.
14. Fonts, Embedded Content and External Services
Fonts are currently loaded locally from our own server. No automatic connection is made to external font providers such as Google Fonts or Adobe Fonts.
We currently do not embed any external videos, maps, social media plugins, chat tools, survey tools or comparable third-party content that would automatically transmit personal data to third parties when the website is accessed.
Should external content be embedded, this will only occur following appropriate notification and, where required, with consent.
15. Newsletter
A newsletter is currently not actively offered via this website.
Should a newsletter be offered in the future, it will only be sent with consent or on another lawful legal basis. Unsubscription will be available at any time.
16. Recipients of Personal Data
Personal data may, where necessary, be disclosed to the following recipients or categories of recipients:
- Hosting and infrastructure providers
- Providers for delivery and protection of the website (Cloudflare)
- Email and communication service providers
- IT service providers
- Freelancers and technical service providers
- Tax advisors and accountants
- Payment service providers and banks
- Legal advisors, where necessary
- Authorities, courts or public bodies, where required by law
- Customers or clients, insofar as required for contract performance
Data is not shared for advertising purposes without a legal basis or consent.
17. Third-Country Transfers
Storage and regular server operation are currently generally performed on server locations in Germany, unless otherwise stated.
In the course of technical collaboration, support, development or administration, access from third countries outside the EU/EEA may be required.
Such processing is carried out only if the requirements of Art. 44 ff. GDPR are met, in particular through:
- Adequacy decision of the European Commission
- EU Standard Contractual Clauses
- Additional technical and organisational safeguards
- Express instruction or authorisation from the customer
- Or another lawful legal basis
No blanket sale of personal data to third parties takes place.
18. Data Retention
We store personal data only for as long as is necessary for the respective purpose.
The specific retention period depends in particular on:
- Duration of enquiry processing
- Duration of the business relationship
- Statutory retention obligations
- Commercial and tax law obligations
- Documentation and limitation periods
- Technical backup and deletion cycles
- Legitimate security or documentation interests
Business and tax-relevant documents may need to be retained for 6, 8 or 10 years, depending on the type of document.
Once the purpose has ceased to apply and the relevant periods have expired, data is deleted or blocked.
19. Data Security
We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure.
These include in particular:
- Encrypted transmission via TLS/HTTPS
- Access restrictions
- Authorisation concepts
- Technical protection of servers and applications
- Careful selection of hosting providers
- Binding employees, freelancers and service providers to confidentiality
- Backup and recovery processes, where established or agreed
Absolute protection cannot be technically guaranteed.
20. Rights of Data Subjects
Subject to the statutory requirements, you have the following rights:
- Right of access pursuant to Art. 15 GDPR
- Right to rectification pursuant to Art. 16 GDPR
- Right to erasure pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to object pursuant to Art. 21 GDPR
- Right to withdraw consent with effect for the future
- Right to lodge a complaint with a data protection supervisory authority
To exercise your rights, you may contact [email protected].
21. Right to Object
Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation.
In the event of an objection, we will no longer process the data concerned unless there are compelling legitimate grounds for the processing or the processing serves the establishment, exercise or defence of legal claims.
22. Withdrawal of Consent
Insofar as processing is based on consent, you may withdraw this consent at any time with effect for the future.
To withdraw consent for marketing and analytics services (Meta Pixel, Microsoft Clarity), you may use the cookie settings button at the bottom left of the page at any time. After withdrawal, the respective services will no longer be loaded and the associated cookies will be deleted.
The lawfulness of the processing carried out prior to the withdrawal remains unaffected.
23. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority.
The competent authority for upbyte® e.K. is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein
Holstenstraße 98
24103 Kiel
Email: [email protected]
24. Changes to this Privacy Policy
We update this privacy policy when our website, our technical systems, our services, the service providers we use or legal requirements change.
The version currently published on our website shall apply.