Privacy Policy

Welcome to our platform — thank you for your interest. Protecting your personal data is important to us. We therefore conduct our activities in accordance with the applicable legislation on the protection of personal data and on data security. Below we would like to inform you which data from your visit is used and for what purposes.

1. Controller responsible for processing under the GDPR

The controller within the meaning of the General Data Protection Regulation and other data protection legislation applicable in the member states of the European Union, as well as other provisions of a data protection nature, is:

phraze GmbH
Wolbecker Str. 36
48155 Münster, Germany

Email: contact form

2. Data protection contact

If you have any further questions, please contact our data protection contact:

Nils Möllers
Keyed GmbH
Siemensstraße 12
48341 Altenberge, Westfalen, Germany

Telephone: 02505 / 639797
Email: [email protected]

3. What is personal data?

The term personal data is defined in the German Federal Data Protection Act and in the EU GDPR. Accordingly, this means individual details about the personal or factual circumstances of an identified or identifiable natural person. This includes, for example, your name, your address, your telephone number or your date of birth.

In accordance with and in order to perform our contract with you pursuant to Art. 6(1)(b) GDPR, we process your data:

  • in order to provide you with the platform and the associated services;
  • in order to notify you of changes to our services;
  • in order to offer you user support;

In order to provide an effective and dynamic platform in line with our legitimate interests pursuant to Art. 6(1)(f) GDPR, we may use your data for the following:

  • to ensure your safety and protection, including the review of user content;
  • to ensure that content is presented in the most effective manner for you and your device;
  • to understand how users use the platform so that we can improve, promote and further develop the platform;

When we process your data in order to pursue our legitimate interests, we carry out a balancing test to examine whether the use of personal data is genuinely necessary to achieve our business purpose. When we carry out this balancing test, we also take into account our users' rights with regard to the protection of their privacy and take appropriate precautions to protect their personal data.

Where we obtain consent from the data subject for the processing of personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data. Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary in order to carry out pre-contractual measures. Where the processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis. In the event that vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis. If the processing is necessary to safeguard a legitimate interest of our company or of a third party, and if the interests, fundamental rights and freedoms of the data subject do not override the former interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.

5. Scope of data collection and data processing

Through the use of web-based structures, we learn certain technical information from the data transmitted by your browser (for example browser type/version, operating system used, pages visited on our site including the time spent on them, previously visited page). The following data may be collected in this context:

  • information about the browser type and the version used;
  • the user's operating system;
  • the user's internet service provider;
  • the user's IP address;
  • the date and time of access;
  • websites from which the user's system reaches our website;
  • websites that are accessed by the user's system via our website.

6. Use of cookies

The platform uses cookies. Cookies are data that are stored by the internet browser on the user's computer system. Cookies can be transmitted to a page when it is accessed and thus enable a user to be identified. Cookies help to make the use of websites easier for users.

You may object to the setting of cookies at any time by changing the settings in your internet browser accordingly. Cookies that have been set can be deleted. Please note that if cookies are deactivated, it may not be possible to use all functions of our website to their full extent. The user data collected in this way is pseudonymised by technical means. It is therefore no longer possible to attribute the data to the user accessing the site. The data is not stored together with other personal data of the user.

7. Routine erasure and blocking of personal data

The controller processes and stores the data subject's personal data only for as long as is necessary to achieve the purpose of storage. Data may also be stored beyond this where provided for by European or national legislators in Union regulations, laws or other provisions to which the controller is subject. As soon as the purpose of storage ceases to apply or a storage period prescribed by the aforementioned provisions expires, the personal data is routinely blocked or erased.

8. Duration of storage of personal data

Personal data (see point 5) is stored for a period of 30 days. After this period has expired, the data is routinely erased, unless it is necessary for the initiation or performance of a contract.

9. Recipients of personal data / cooperation with processors and third parties

In order to achieve the purposes stated above, we engage service providers as processors pursuant to Art. 28 GDPR, for example as IT service providers, for sending emails and text messages, or for making contact by telephone. These service providers may be established both within and outside the European Union or the European Economic Area. Through contractual agreements (so-called "data processing agreements") with the service providers, we ensure that they process personal data in accordance with the requirements of the GDPR, even where the data processing takes place outside the European Union or the European Economic Area in countries in which an adequate level of data protection is not otherwise guaranteed and for which no adequacy decision of the European Commission exists. For further information about the existence of an adequacy decision of the European Commission and about appropriate safeguards, and in order to obtain a copy of these safeguards, you may contact our data protection officer. Beyond this, we transfer data to third parties only where there is a legal obligation to do so. In that case, the transfer is based on Art. 6(1) sentence 1(c) GDPR.

As part of processing on our behalf, a third-party provider supplies the services for hosting and presenting the platform for us. This serves to safeguard our legitimate interests in the correct presentation of our offering, which prevail on a balancing of interests.

Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or of disclosing or transferring data to third parties, this only takes place where it is done in order to perform our (pre-)contractual obligations, on the basis of your consent, on the basis of a legal obligation, or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process, or have processed, the data in a third country only where the special requirements of Art. 44 et seq. GDPR are met. This means that the processing takes place, for example, on the basis of special safeguards, such as the officially recognised determination of a level of data protection equivalent to that of the EU, or compliance with officially recognised special contractual obligations (so-called "standard contractual clauses").

We engage the following processors:

DigitalOcean LLC
101 Avenue of the Americas, 2nd Floor New York, NY 10013

10. Rights of the data subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

10.1 Right of access

You may request confirmation from the controller as to whether personal data concerning you is being processed by us. Where such processing is taking place, you may request information from the controller about the following:

  1. the purposes for which the personal data is processed;
  2. the categories of personal data that are processed;
  3. the recipients or categories of recipients to whom your personal data has been or will be disclosed;
  4. the envisaged period for which your personal data will be stored or, if specific information on this is not possible, the criteria used to determine the storage period;
  5. the existence of a right to rectification or erasure of your personal data, a right to restriction of processing by the controller, or a right to object to such processing;
  6. the existence of a right to lodge a complaint with a supervisory authority;
  7. all available information about the origin of the data, where the personal data is not collected from the data subject;
  8. the existence of automated decision-making, including profiling, pursuant to Art. 22(1) and (4) GDPR and — at least in these cases — meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

You have the right to request information as to whether your personal data is transferred to a third country or to an international organisation. In this context, you may request to be informed of the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.

10.2 Right to rectification

You have a right to rectification and/or completion vis-à-vis the controller where the processed personal data concerning you is inaccurate or incomplete. The controller must carry out the rectification without delay.

10.3 Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant of the status and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR. The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf, Germany

Telephone: 0211/38424-0
Fax: 0211/38424-10
Email: [email protected]

10.4 Right to data portability

You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that:

  1. the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, or on a contract pursuant to Art. 6(1)(b) GDPR, and
  2. the processing is carried out by automated means. In exercising this right, you further have the right to obtain that your personal data is transmitted directly from one controller to another, where technically feasible. The freedoms and rights of other persons must not be adversely affected by this. The right to data portability does not apply to processing of personal data that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

10.5 Right to restriction of processing

You may request the restriction of the processing of your personal data under the following conditions:

  1. if you contest the accuracy of your personal data, for a period enabling the controller to verify the accuracy of the personal data;
  2. the processing is unlawful and you oppose the erasure of the personal data and request instead the restriction of the use of the personal data;
  3. the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims; or
  4. if you have objected to the processing pursuant to Art. 21(1) GDPR and it is not yet clear whether the legitimate grounds of the controller override yours.

Where the processing of your personal data has been restricted, such data may — apart from being stored — only be processed with your consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a member state. Where processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.

10.6 Right to erasure

(1) You may request the controller to erase your personal data without undue delay, and the controller is obliged to erase that data without undue delay where one of the following grounds applies:

  1. The personal data concerning you is no longer necessary for the purposes for which it was collected or otherwise processed.
  2. You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing.
  3. You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
  4. The personal data concerning you has been unlawfully processed.
  5. The erasure of the personal data concerning you is necessary for compliance with a legal obligation under Union law or the law of the member states to which the controller is subject.
  6. The personal data concerning you has been collected in relation to the offer of information society services pursuant to Art. 8(1) GDPR.

(2) Where the controller has made your personal data public and is obliged to erase it pursuant to Art. 17(1) GDPR, it shall take reasonable steps, including technical measures, taking account of available technology and the cost of implementation, to inform controllers that are processing the personal data that you, as the data subject, have requested the erasure by such controllers of any links to, or copies or replications of, that personal data.

(3) The right to erasure does not apply where the processing is necessary

  1. for exercising the right of freedom of expression and information;
  2. for compliance with a legal obligation which requires processing by Union or member state law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. for reasons of public interest in the area of public health pursuant to Art. 9(2)(h) and (i) as well as Art. 9(3) GDPR;
  4. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Art. 89(1) GDPR, in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
  5. for the establishment, exercise or defence of legal claims.

10.7 Right to be informed

Where you have asserted the right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data concerning you has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right vis-à-vis the controller to be informed about these recipients.

You have the right to withdraw your data protection consent at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.

10.9 Automated individual decision-making, including profiling

You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision:

  1. is necessary for entering into, or the performance of, a contract between you and the controller,
  2. is authorised by Union or member state law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or
  3. is based on your explicit consent.

However, these decisions may not be based on special categories of personal data pursuant to Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) applies and suitable measures to safeguard the rights and freedoms and legitimate interests have been taken.

With regard to the cases referred to in a. and c., the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.

11. Security

We have put in place extensive technical and operational safeguards in order to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. Our security procedures are reviewed regularly and adapted to technological progress. In addition, data protection is continuously maintained at our company through ongoing auditing and optimisation of the data protection organisation.

12. Changes and updates to this privacy policy

phraze GmbH reserves all rights to make changes and updates to this privacy policy. This privacy policy was created by Keyed GmbH on 18 November 2021.

This is a translation provided for convenience. The German version of this privacy policy is the legally binding one.