Privacy Policy
1 Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is informations & kommunikations systeme GmbH, represented by Managing Director Johannes Backes, Markus Backes, Heiligkreuzstr. 2-4, 66709 Weiskirchen, Germany, email: [email protected], phone: +49 6876 99 0000.
2 Subject of Data Processing
We process personal data that is necessary for the provision, use, and billing of our application “Seedback”. This includes in particular:
- Registration and contact data (e.g. name, email address, payment data) – Legal basis: performance of contract (Art. 6(1)(b) GDPR).
- Usage data such as IP address, date and time of access, operating system and browser – Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Review data submitted by your customers via the QR codes provided by Seedback – Legal basis: legitimate interest and performance of contract.
3 Purposes of Processing
We use your personal data to provide our services, manage your account, provide support, collect reviews and forward them to Google, as well as for technical analysis and improvement of our offerings.
4 Recipients
To provide our services, we use trusted data processors:
- Hetzner Online GmbH (Gunzenhausen, Germany) – Hosting of the platform and database on servers in Germany (Falkenstein).
- Paddle.com Market Ltd (Dublin, Ireland) – Payment and subscription processing.
- Brevo (Sendinblue GmbH) (Berlin, Germany) – Sending emails (donation certificates, feedback messages). Processing on servers in the EU.
- Google LLC (Mountain View, CA, USA) – Google Maps/Places service for finding your business profile. When using the location search, your IP address and input are transmitted to Google. Data transfer to the USA based on the EU-US Data Privacy Framework.
- Other recipients may include IT service providers and consultants.
We have concluded data processing agreements with all processors. For data transfers to third countries, appropriate safeguards (e.g. EU Standard Contractual Clauses) are agreed upon.
5 Storage Duration
We store your personal data only as long as necessary for the above-mentioned purposes or until you delete your account. Review data is stored anonymously, unless statutory retention obligations apply.
6 Your Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20 GDPR). You may object to processing at any time (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority.
7 Cookies and Tracking
The application does not use tracking tools or marketing cookies. Technically necessary cookies are only set to ensure the functionality of the app (e.g. for authentication).
8 Automated Decisions
No automated decision-making within the meaning of Art. 22 GDPR takes place. No user profiles are created.
9 Updates
We reserve the right to update this privacy policy to adapt it to changed legal situations or changes to the service. The current version is always available in the app.