Welcome to our platform — thank you for your interest. Protecting your personal data is important to us. We therefore conduct our activities in accordance with the applicable legislation on the protection of personal data and on data security. Below we would like to inform you which data from your visit is used and for what purposes.
The controller within the meaning of the General Data Protection Regulation and other data protection legislation applicable in the member states of the European Union, as well as other provisions of a data protection nature, is:
phraze GmbH
Wolbecker Str. 36
48155 Münster, Germany
Email: contact form
If you have any further questions, please contact our data protection contact:
Nils Möllers
Keyed GmbH
Siemensstraße 12
48341 Altenberge, Westfalen, Germany
Telephone: 02505 / 639797
Email: [email protected]
The term personal data is defined in the German Federal Data Protection Act and in the EU GDPR. Accordingly, this means individual details about the personal or factual circumstances of an identified or identifiable natural person. This includes, for example, your name, your address, your telephone number or your date of birth.
In accordance with and in order to perform our contract with you pursuant to Art. 6(1)(b) GDPR, we process your data:
In order to provide an effective and dynamic platform in line with our legitimate interests pursuant to Art. 6(1)(f) GDPR, we may use your data for the following:
When we process your data in order to pursue our legitimate interests, we carry out a balancing test to examine whether the use of personal data is genuinely necessary to achieve our business purpose. When we carry out this balancing test, we also take into account our users' rights with regard to the protection of their privacy and take appropriate precautions to protect their personal data.
Where we obtain consent from the data subject for the processing of personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data. Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary in order to carry out pre-contractual measures. Where the processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis. If the processing is necessary to safeguard a legitimate interest of our company or of a third party, and if the interests, fundamental rights and freedoms of the data subject do not override the former interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.
Through the use of web-based structures, we learn certain technical information from the data transmitted by your browser (for example browser type/version, operating system used, pages visited on our site including the time spent on them, previously visited page). The following data may be collected in this context:
The platform uses cookies. Cookies are data that are stored by the internet browser on the user's computer system. Cookies can be transmitted to a page when it is accessed and thus enable a user to be identified. Cookies help to make the use of websites easier for users.
You may object to the setting of cookies at any time by changing the settings in your internet browser accordingly. Cookies that have been set can be deleted. Please note that if cookies are deactivated, it may not be possible to use all functions of our website to their full extent. The user data collected in this way is pseudonymised by technical means. It is therefore no longer possible to attribute the data to the user accessing the site. The data is not stored together with other personal data of the user.
The controller processes and stores the data subject's personal data only for as long as is necessary to achieve the purpose of storage. Data may also be stored beyond this where provided for by European or national legislators in Union regulations, laws or other provisions to which the controller is subject. As soon as the purpose of storage ceases to apply or a storage period prescribed by the aforementioned provisions expires, the personal data is routinely blocked or erased.
Personal data (see point 5) is stored for a period of 30 days. After this period has expired, the data is routinely erased, unless it is necessary for the initiation or performance of a contract.
In order to achieve the purposes stated above, we engage service providers as processors pursuant to Art. 28 GDPR, for example as IT service providers, for sending emails and text messages, or for making contact by telephone. These service providers may be established both within and outside the European Union or the European Economic Area. Through contractual agreements (so-called "data processing agreements") with the service providers, we ensure that they process personal data in accordance with the requirements of the GDPR, even where the data processing takes place outside the European Union or the European Economic Area in countries in which an adequate level of data protection is not otherwise guaranteed and for which no adequacy decision of the European Commission exists. For further information about the existence of an adequacy decision of the European Commission and about appropriate safeguards, and in order to obtain a copy of these safeguards, you may contact our data protection officer. Beyond this, we transfer data to third parties only where there is a legal obligation to do so. In that case, the transfer is based on Art. 6(1) sentence 1(c) GDPR.
As part of processing on our behalf, a third-party provider supplies the services for hosting and presenting the platform for us. This serves to safeguard our legitimate interests in the correct presentation of our offering, which prevail on a balancing of interests.
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or of disclosing or transferring data to third parties, this only takes place where it is done in order to perform our (pre-)contractual obligations, on the basis of your consent, on the basis of a legal obligation, or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process, or have processed, the data in a third country only where the special requirements of Art. 44 et seq. GDPR are met. This means that the processing takes place, for example, on the basis of special safeguards, such as the officially recognised determination of a level of data protection equivalent to that of the EU, or compliance with officially recognised special contractual obligations (so-called "standard contractual clauses").
We engage the following processors:
DigitalOcean LLC
101 Avenue of the Americas, 2nd Floor New York, NY 10013
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
You may request confirmation from the controller as to whether personal data concerning you is being processed by us. Where such processing is taking place, you may request information from the controller about the following:
You have the right to request information as to whether your personal data is transferred to a third country or to an international organisation. In this context, you may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
You have a right to rectification and/or completion vis-à-vis the controller where the processed personal data concerning you is inaccurate or incomplete. The controller must carry out the rectification without delay.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant of the status and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR. The supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf, Germany
Telephone: 0211/38424-0
Fax: 0211/38424-10
Email: [email protected]
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that:
You may request the restriction of the processing of your personal data under the following conditions:
Where the processing of your personal data has been restricted, such data may — apart from being stored — only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a member state. Where processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.
(1) You may request the controller to erase your personal data without undue delay, and the controller is obliged to erase that data without undue delay where one of the following grounds applies:
(2) Where the controller has made your personal data public and is obliged to erase it pursuant to Art. 17(1) GDPR, it shall take reasonable steps, including technical measures, taking account of available technology and the cost of implementation, to inform controllers that are processing the personal data that you, as the data subject, have requested the erasure by such controllers of any links to, or copies or replications of, that personal data.
(3) The right to erasure does not apply where the processing is necessary
Where you have asserted the right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data concerning you has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right vis-à-vis the controller to be informed about these recipients.
You have the right to withdraw your data protection consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.
You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision:
However, these decisions may not be based on special categories of personal data pursuant to Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) applies and suitable measures to safeguard the rights and freedoms and legitimate interests have been taken.
With regard to the cases referred to in a. and c., the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
We have put in place extensive technical and operational safeguards in order to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. Our security procedures are reviewed regularly and adapted to technological progress. In addition, data protection is continuously maintained at our company through ongoing auditing and optimisation of the data protection organisation.
phraze GmbH reserves all rights to make changes and updates to this privacy policy. This privacy policy was created by Keyed GmbH on 18 November 2021.
This is a translation provided for convenience. The German version of this privacy policy is the legally binding one.