Controller
- Company
- BEEBUCKET GmbH
- Address
- Neunkirchenweg 22
89077 Ulm
Germany - Phone
- +49-731-7903 8050
- hello@beebucket.ai
- Managing Director
- Florian Mauer-Endler
- Register
- Amtsgericht Ulm, HRB 741249 · VAT ID DE337986141
This is a translation provided for convenience. The German version of this privacy policy is the authoritative one and prevails in the event of any discrepancy.
General information on data processing and legal bases
1.1. This privacy policy informs you about the nature, scope and purpose of the processing of personal data within our online offering and the websites, functions and content connected with it (hereinafter jointly referred to as the “online offering” or “website”). The privacy policy applies regardless of the domains, systems, platforms and devices (e.g. desktop or mobile) on which the online offering is run.
1.2. The terms used, such as “personal data” or its “processing”, refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Types of data processed and categories of data subjects
2.1. The personal data of users processed within this online offering includes:
- master data (e.g. names and addresses of customers),
- contact data (e.g. email, telephone numbers),
- communication data,
- contract data (e.g. services used, names of contact persons, payment information),
- usage data (e.g. the pages of our online offering visited, interest in our products),
- meta and communication data (e.g. device information, IP addresses), and
- content data (e.g. entries in a contact enquiry).
2.2. The term “users” covers all categories of persons affected by the data processing. It includes our business partners, customers, prospective customers and other visitors to our online offering. The terms used are to be understood as gender-neutral.
2.3. We process users' personal data only in compliance with the applicable data protection provisions. This means that users' data is processed only where there is a legal basis for doing so — in particular where the processing is necessary or legally required in order to provide our contractual services (e.g. handling orders) and online services, where the user has given consent, or where we can rely on our legitimate interests within the meaning of Article 6 (1) (f) GDPR (i.e. an interest in the secure, economical operation and the optimisation of our online offering).
2.4. We point out that the legal basis for consent is Article 6 (1) (a) and Article 7 GDPR; the legal basis for processing in order to perform our services and carry out contractual measures is Article 6 (1) (b) GDPR; the legal basis for processing in order to fulfil our legal obligations is Article 6 (1) (c) GDPR; and the legal basis for processing in order to safeguard our legitimate interests is Article 6 (1) (f) GDPR.
2.5. The following persons are affected by the data processing:
- contractual and business partners,
- users of our online offering,
- prospective customers who are interested in our online offering or who contact us for other reasons, and
- customers.
Security measures
In accordance with Article 32 GDPR, we take appropriate organisational, contractual and technical security measures in line with the state of the art, taking into account the cost of implementation and the nature, scope, circumstances and purposes of the processing as well as the varying likelihood and severity of the risk to rights and freedoms, in order to ensure an appropriate level of protection for your data. In doing so, we ensure compliance with the provisions of data protection law and protect this data against accidental or deliberate manipulation, loss, destruction and access by unauthorised persons.
3.1. The security measures include, in particular, the encrypted transmission of data between your browser and our server. You can recognise such encrypted connections by the fact that the URL in your browser's address bar begins with “https://”. This is a communication protocol that allows data to be transmitted securely by means of transport encryption.
Disclosure of data to third parties and third-party providers
4.1. Data is disclosed to third parties only within the framework of the statutory requirements. We pass users' data on to third parties only where this is necessary for contractual purposes, for example on the basis of Article 6 (1) (b) GDPR, or on the basis of legitimate interests pursuant to Article 6 (1) (f) GDPR in the economical and effective operation of our business.
4.2. We engage subcontractors to provide our services only where we have taken appropriate legal precautions and corresponding technical and organisational measures to ensure the protection of the personal data processed in accordance with the relevant statutory provisions.
4.3. Where content, tools or other means from other providers (hereinafter jointly referred to as “third-party providers”) described in this privacy policy are used, we observe the statutory requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect it.
4.4. Where we engage a third-party provider whose stated registered office is in a third country (outside the European Union or the European Economic Area), it must be assumed that data is transferred to the country in which that provider is established. Data is transferred to third countries only where an adequate level of data protection, the user's consent or some other legal permission exists.
Provision of contractual services
5.1. We process master data (e.g. names and addresses as well as contact data of users) and contract data (e.g. services used, names of contact persons, payment information) for the purpose of fulfilling our contractual obligations and providing our services pursuant to Article 6 (1) (b) GDPR. We inform contractual partners which data is required for the aforementioned purposes before or in the course of collecting it, for example by means of special marking, or in person. Within the framework of applicable law, we pass this data on to third parties only to the extent necessary for the aforementioned purposes or for the fulfilment of legal obligations, or where you have consented (e.g. to telecommunications, transport and other auxiliary service providers involved, as well as subcontractors, banks, tax and legal advisers, payment service providers or tax authorities).
5.2. We delete the data once statutory warranty and comparable obligations have expired, i.e. as a rule after four years, unless the data has to be retained for statutory archiving reasons (e.g. for tax purposes, normally ten years). Data disclosed to us by a contractual partner in the course of a contractual relationship is deleted in accordance with the provisions of the contract, as a rule once the contractual services have been performed.
Contacting us and the contact form
6.1. When you contact us (by contact form, email or telephone), the user's details are processed in order to handle and process the enquiry pursuant to Article 6 (1) (b) GDPR. In doing so, we process only the data we need to deal with your request.
6.2. Users' details may be stored in our customer relationship management system (“CRM system”) or a comparable enquiry management system.
6.3. A contact form is available on this website. It collects your name and email address (mandatory), company and telephone number (optional) and the content of your message. The processing takes place in order to handle your enquiry pursuant to Article 6 (1) (b) GDPR or, where there is no connection to a contract, on the basis of our legitimate interest in responding to enquiries pursuant to Article 6 (1) (f) GDPR.
6.4. The form is technically provided via the “Netlify Forms” service of our hosting provider Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. When the form is submitted, the data you have entered and your IP address are transmitted to Netlify's servers and stored there on our behalf until we retrieve and delete it. We have concluded a data processing agreement with Netlify pursuant to Article 28 GDPR. For transfers to the USA, Netlify states that it relies on the European Commission's standard contractual clauses (Implementing Decision 2021/914) as well as on certification under the EU-U.S. Data Privacy Framework. The provider's privacy statement: netlify.com/privacy.
6.5. To protect against automated spam submissions, the form contains an input field that is invisible to users (a “honeypot”) and is filled in only by automated programs. In addition, Netlify checks incoming submissions using the spam filter “Akismet” of Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. No cookies are set for this purpose and no user profiles are created.
6.6. We delete the details submitted via the form once your enquiry has been conclusively dealt with and no statutory retention obligations prevent deletion. Enquiries that are not followed by a contractual relationship are generally deleted after six months.
Web hosting and server log files
7.1. In order to provide our online offering securely and efficiently, we use the services of a web hosting provider. This website is hosted with Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA (see section 6.4). We use the services of providers from whose servers (or servers managed by them) the online offering can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space and database services as well as security services and technical maintenance services.
7.2. On the basis of our legitimate interests within the meaning of Article 6 (1) (f) GDPR, we collect data about every access to the server on which this service is located (so-called server log files). The access data includes the name of the web page accessed, the file, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user's operating system, the referrer URL (the previously visited page), the IP address and the requesting provider.
7.3. For security reasons (e.g. to investigate misuse or fraud), log file information is stored for a maximum of seven days and then deleted. Data whose further retention is necessary for evidentiary purposes is exempt from deletion until the incident in question has been finally clarified.
7.4. The web hosting services also include the sending, receipt and storage of emails. For these purposes, the addresses of the recipients and senders as well as further information about the email transmission (e.g. the providers involved) and the content of the respective emails are processed. Even though our email communication uses transport encryption, the content is not encrypted on the servers from which it is sent and received. The content of email communication is therefore fundamentally susceptible to manipulation.
Cookies
8.1. Cookies are pieces of information that are transferred from our web server or third-party web servers to users' web browsers and stored there for later retrieval. A distinction must be made between cookies set by the operator of a website when it is visited (“first-party cookies”) and cookies set by third-party providers (“third-party cookies”). We also count as cookies other technologies that perform the same functions as cookies (e.g. storing users' details by means of pseudonymous online identifiers, also referred to as a “user ID”).
8.2. This website does not set any cookies of its own and does not use cookies for analysis, marketing or personalisation purposes. No audience measurement and no tracking take place.
8.3. If you generally do not wish cookies to be stored on your computer, you can deactivate the corresponding option in your browser's system settings. Stored cookies can be deleted in the browser's system settings.
8.4. Should we use cookies in the future that are not necessary for the operation of this online offering, we will ask users in advance for their consent, which can be withdrawn at any time (Article 6 (1) sentence 1 (a) GDPR). An objection to the use of cookies for online marketing purposes can also be declared via the websites optout.aboutads.info and youronlinechoices.com.
Integration of third-party services and content
9.1. Within our online offering, we integrate content or service offerings from third-party providers on the basis of our legitimate interests (i.e. an interest in the analysis, optimisation and economical operation of our online offering within the meaning of Article 6 (1) (f) GDPR) or on the basis of your consent (Article 6 (1) (a) GDPR), in order to embed their content and services, such as fonts (hereinafter uniformly referred to as “content”). This always presupposes that the third-party providers of this content are aware of users' IP addresses, since without the IP address they would not be able to send the content to their browsers. The IP address is therefore necessary in order to display this content. We endeavour to use only content whose respective providers use the IP address solely to deliver the content.
9.2. The following overview lists the third-party providers we use, together with links to their privacy policies:
- Google Fonts — external fonts provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Fonts are embedded by means of a server call to Google (usually in the USA), during which the user's IP address is transmitted. Privacy policy: policies.google.com/privacy.
9.3. In addition, we use Netlify as our hosting provider and to operate the contact form; details can be found in sections 6.4, 6.5 and 7.1.
9.4. Beyond this overview, we do not integrate any analysis, marketing or social media services from third parties on this website.
Rights of the data subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
10.1. Right of access
You may request confirmation from the controller as to whether personal data concerning you is being processed by us. Where such processing is taking place, you may request information from the controller about the following:
- the purposes for which the personal data is processed;
- the categories of personal data being processed;
- the recipients or categories of recipients to whom the personal data concerning you has been or will be disclosed;
- the envisaged period for which the personal data concerning you will be stored or, if specific information is not possible, the criteria used to determine that period;
- the existence of a right to rectification or erasure of the personal data concerning you, a right to restriction of processing by the controller or a right to object to such processing;
- the existence of a right to lodge a complaint with a supervisory authority;
- all available information about the origin of the data, where the personal data was not collected from the data subject;
- the existence of automated decision-making, including profiling, pursuant to Article 22 (1) and (4) GDPR and — at least in these cases — meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject.
You have the right to request information as to whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you may request to be informed of the appropriate safeguards pursuant to Article 46 GDPR in connection with the transfer.
10.2. Right to rectification
You have a right to rectification and/or completion vis-à-vis the controller where the processed personal data concerning you is inaccurate or incomplete. The controller must carry out the rectification without delay.
10.3. Right to restriction of processing
You may request the restriction of the processing of the personal data concerning you under the following conditions:
- where you contest the accuracy of the personal data concerning you, for a period enabling the controller to verify the accuracy of the personal data;
- where the processing is unlawful and you object to the erasure of the personal data and request the restriction of its use instead;
- where the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims; or
- where you have objected to the processing pursuant to Article 21 (1) GDPR and it has not yet been established whether the controller's legitimate grounds override yours.
Where the processing of personal data concerning you has been restricted, this data may — apart from being stored — be processed only with your consent, or for the establishment, exercise or defence of legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State. Where the processing has been restricted under the above conditions, the controller will inform you before the restriction is lifted.
10.4. Right to erasure
a) Obligation to erase. You may request that the controller erase the personal data concerning you without delay, and the controller is obliged to erase this data without delay, where one of the following grounds applies:
- The personal data concerning you is no longer necessary for the purposes for which it was collected or otherwise processed.
- You withdraw your consent on which the processing was based pursuant to Article 6 (1) (a) or Article 9 (2) (a) GDPR, and there is no other legal basis for the processing.
- You object to the processing pursuant to Article 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21 (2) GDPR.
- The personal data concerning you has been processed unlawfully.
- The erasure of the personal data concerning you is necessary for compliance with a legal obligation under Union or Member State law to which the controller is subject.
- The personal data concerning you was collected in relation to the offer of information society services pursuant to Article 8 (1) GDPR.
b) Information to third parties. Where the controller has made the personal data concerning you public and is obliged to erase it pursuant to Article 17 (1) GDPR, the controller shall, taking account of available technology and the cost of implementation, take reasonable steps — including technical measures — to inform controllers processing the personal data that you, as the data subject, have requested the erasure of all links to, or copies or replications of, that personal data.
c) Exceptions. The right to erasure does not apply where processing is necessary
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health pursuant to Article 9 (2) (h) and (i) as well as Article 9 (3) GDPR;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Article 89 (1) GDPR, insofar as the right referred to under a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- for the establishment, exercise or defence of legal claims.
10.5. Right to be informed
Where you have asserted the right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is obliged to communicate this rectification or erasure of the data, or the restriction of processing, to all recipients to whom the personal data concerning you has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right vis-à-vis the controller to be informed about those recipients.
10.6. Right to data portability
You have the right to receive the personal data concerning you which you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, where
- the processing is based on consent pursuant to Article 6 (1) (a) GDPR or Article 9 (2) (a) GDPR, or on a contract pursuant to Article 6 (1) (b) GDPR, and
- the processing is carried out by automated means.
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one controller to another, where technically feasible. The freedoms and rights of other persons must not be adversely affected as a result. The right to data portability does not apply to processing of personal data that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
10.7. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6 (1) (e) or (f) GDPR; this also applies to profiling based on those provisions.
The controller will then no longer process the personal data concerning you, unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves the establishment, exercise or defence of legal claims.
Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is connected with such direct marketing. Where you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for those purposes.
You have the option, in connection with the use of information society services and notwithstanding Directive 2002/58/EC, of exercising your right to object by automated means using technical specifications.
10.8. Right to withdraw consent under data protection law
You have the right to withdraw your consent under data protection law at any time. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of that consent up to the point of withdrawal.
10.9. Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision
- is necessary for entering into, or the performance of, a contract between you and the controller,
- is authorised by Union or Member State law to which the controller is subject and which lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or
- is based on your explicit consent.
However, such decisions must not be based on special categories of personal data pursuant to Article 9 (1) GDPR, unless Article 9 (2) (a) or (g) applies and suitable measures to safeguard your rights and freedoms as well as your legitimate interests have been taken. In the cases referred to in (1) and (3), the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
10.10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority — in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement — if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority with which the complaint has been lodged will inform the complainant of the progress and outcome of the complaint, including the possibility of a judicial remedy pursuant to Article 78 GDPR.
Erasure of data
11.1. The data stored by us is erased as soon as it is no longer required for its intended purpose and no statutory retention obligations prevent erasure. Erasure also takes place, in particular, where other grounds for permissibility cease to apply. Where users' data is not erased because it is required for other, legally permissible purposes, its processing is restricted, i.e. the data is blocked and not processed for other purposes. This applies, for example, to users' data that has to be retained for commercial or tax law reasons.
11.2. Under statutory requirements, data is retained for six years pursuant to section 257 (1) of the German Commercial Code (HGB) (commercial books, inventories, opening balance sheets, annual financial statements, commercial letters, accounting vouchers, etc.) and for ten years pursuant to section 147 (1) of the German Fiscal Code (AO) (books, records, management reports, accounting vouchers, commercial and business letters, documents relevant to taxation, etc.).
Right to object
Users may object at any time to the future processing of their personal data in accordance with the statutory requirements. An objection may be lodged in particular against processing for direct marketing purposes.
Changes to this privacy policy
13.1. We reserve the right to amend this privacy policy in order to adapt it to changes in the law or to changes in the service and in data processing. This applies only with regard to statements about data processing, however. Where users' consent is required, or where parts of the privacy policy contain provisions of the contractual relationship with users, the changes will be made only with the users' agreement.
13.2. Users are asked to inform themselves regularly about the content of this privacy policy.