Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") we process, for what purposes, and to what extent. This privacy policy applies to all personal data processing carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: March 10, 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing Activities
- Relevant Legal Bases
- Security Measures
- Transmission of Personal Data
- International Data Transfers
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Business Services
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Blogs and Publication Media
- Contact and Inquiry Management
- Newsletters and Electronic Notifications
- Web Analytics, Monitoring and Optimization
- Online Marketing
- Presences in Social Networks (Social Media)
- Plugins and Embedded Functions and Content
- Changes and Updates
- Definitions
Controller
Meriem Rebai | reelistiq
Kollwitzstraße 76
10435 Berlin
Authorized representative: Owner Meriem Rebai
Email address: hello@reelistiq.com
Legal notice: https://reelistiq.com/en/impressum
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Master data.
- Employee data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Employees.
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
- Third parties.
- Whistleblowers.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organizational procedures.
- Target group formation.
- Organizational and administrative procedures.
- Feedback.
- Marketing.
- Profiles with user-related information.
- Provision of our online offering and user experience.
- Information technology infrastructure.
- Whistleblower protection.
- Public relations.
- Business processes and operational procedures.
Relevant Legal Bases
Relevant legal bases under the GDPR: The following provides an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR regulations, national data protection regulations may apply in your or our country of residence. Should more specific legal bases be applicable in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6 para. 1 s. 1 lit. a) GDPR) — The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Contract performance and pre-contractual inquiries (Art. 6 para. 1 s. 1 lit. b) GDPR) — Processing is necessary for the performance of a contract to which the data subject is a party, or for pre-contractual measures taken at the data subject's request.
- Legal obligation (Art. 6 para. 1 s. 1 lit. c) GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR) — Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
National data protection regulations in Germany: In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains special provisions on the right to access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, transmission, and automated decision-making in individual cases including profiling. State data protection laws of the individual German states may also apply.
Security Measures
We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.
These measures include in particular the protection of confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access, input, disclosure, ensuring availability and their separation. We have also established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to threats to the data. Furthermore, we take the protection of personal data into account as early as the development and selection of hardware, software and processes, in accordance with the principle of data protection by design and by default.
TLS/SSL encryption (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser, protecting the data from unauthorized access. When a website is secured with an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL.
Transmission of Personal Data
In the course of processing personal data, it may be transmitted to or disclosed to other entities, companies, legally independent organizational units or persons. Recipients of this data may include IT service providers, or providers of services and content integrated into a website. In such cases, we observe the legal requirements and in particular conclude appropriate contracts or agreements that serve the protection of your data with the recipients of your data.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transmitting data to other persons, entities or companies, this is always done in accordance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission on July 10, 2023. In addition, we have concluded standard contractual clauses with the respective providers that meet the requirements of the EU Commission.
For data transfers to other third countries, appropriate safeguards apply, in particular standard contractual clauses, explicit consent, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the EU Commission's information offering: EU Commission Information.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal requirements as soon as the underlying consents are revoked or there are no longer any legal bases for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other persons, must be archived accordingly.
Retention periods under German law:
- 10 years — Books and records, annual financial statements, inventories, management reports, opening balance sheets, and related working instructions and organizational documents (§ 147 para. 1 no. 1 AO, § 14b para. 1 UStG, § 257 para. 1 no. 1 HGB).
- 8 years — Accounting documents such as invoices and expense receipts (§ 147 para. 1 no. 4 AO, § 257 para. 1 no. 4 HGB).
- 6 years — Other business documents: received and sent commercial letters, other documents relevant to taxation (§ 147 para. 1 no. 2, 3, 5 AO, § 257 para. 1 no. 2 and 3 HGB).
- 3 years — Data required to consider potential warranty, compensation or similar contractual claims, based on prior business experience and customary industry practices, stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).
Rights of Data Subjects
As a data subject under the GDPR, you have various rights, arising in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to receive information about this data, as well as further information and a copy of the data in accordance with legal requirements.
- Right to rectification: You have the right, in accordance with legal requirements, to request the completion or correction of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with legal requirements, to request the immediate deletion of data concerning you, or alternatively to request restriction of processing in accordance with legal requirements.
- Right to data portability: You have the right to receive data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format in accordance with legal requirements, or to request its transmission to another controller.
- Right to lodge a complaint with a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively "contractual partners"), for the purpose of initiating, performing and completing contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken at request, as well as communication in connection with the respective contractual relationship.
The data processed includes in particular master data such as name, address and company name, contact data such as email address and phone number, contract and service data, payment and billing data, as well as communication content and histories.
The legal basis for processing is Art. 6 para. 1 lit. b GDPR for the performance of contracts and pre-contractual measures, Art. 6 para. 1 lit. c GDPR for compliance with legal obligations, and Art. 6 para. 1 lit. f GDPR for legitimate interests.
- Types of data processed: Master data; payment data; contact data; contract data.
- Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing: Provision of contractual services; communication; office and organizational procedures; business processes.
- Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 s. 1 lit. b) GDPR); Legal obligation (Art. 6 para. 1 s. 1 lit. c) GDPR); Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
Further information:
- Agency services: We process the data of our clients within the scope of our contractual services, which may include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation of campaigns and processes, server administration, data analysis/consulting services and training services; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 s. 1 lit. b) GDPR).
Provision of the Online Offering and Web Hosting
We process users' data to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
- Types of data processed: Usage data; meta, communication and process data; log data.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of our online offering; IT infrastructure; security measures.
- Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
Further information:
- Hosting on rented server space: For the provision of our online offering, we use storage space, computing capacity and software that we rent from a server provider (also called "web host"); Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of "server log files". Server log files may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and generally IP addresses and the requesting provider. Log files are used for security purposes (e.g. to prevent server overload in the event of abusive attacks, so-called DDoS attacks) and to ensure server load and stability; Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymized.
- 1&1 IONOS: Services in the area of provision of information technology infrastructure and related services (e.g. storage space and/or computing capacities); Service provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Website: https://www.ionos.de; Privacy policy: https://www.ionos.de/terms-gtc/terms-privacy.
Use of Cookies
The term "cookies" refers to functions that store and read information on users' devices. Cookies can be used for various purposes, including to ensure the functionality, security and convenience of online offerings, and to analyze visitor flows. We use cookies in accordance with legal requirements. Where required, we obtain users' prior consent. If consent is not required, we rely on our legitimate interests.
Storage duration:
- Temporary cookies (session cookies): Temporary cookies are deleted at the latest when a user leaves an online offering and closes their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, the login status can be saved and preferred content can be displayed directly when the user revisits a website. The storage period of permanent cookies can be up to two years unless otherwise stated.
- Types of data processed: Meta, communication and process data.
- Data subjects: Users.
- Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Consent (Art. 6 para. 1 s. 1 lit. a) GDPR).
Blogs and Publication Media
We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is only processed for the purposes of the publication medium to the extent necessary for its presentation and for communication between authors and readers, or for security reasons.
- Types of data processed: Master data; contact data; content data; usage data; meta, communication and process data.
- Data subjects: Users.
- Purposes of processing: Feedback; provision of our online offering.
- Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by mail, contact form, email, phone or via social media) and in the context of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to respond to the contact inquiries and any requested measures.
- Types of data processed: Contact data; content data; meta, communication and process data.
- Data subjects: Communication partners.
- Purposes of processing: Communication; organizational and administrative procedures; feedback; provision of our online offering.
- Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Contract performance and pre-contractual inquiries (Art. 6 para. 1 s. 1 lit. b) GDPR).
Further information:
- Contact form: When you contact us via our contact form, email or other communication channels, we process the personal data you provide in order to respond to and process the respective inquiry. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 s. 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
- HubSpot CRM: Management of customer contacts, tracking of sales activities, automation of marketing campaigns, analysis of sales data, creation and management of email campaigns, integration with other tools and platforms, management of customer support requests; Service provider: HubSpot Ireland Limited, Ground Floor, Two Dockland Central Guild Street, Dublin 1, Ireland; Legal bases: Contract performance and pre-contractual inquiries (Art. 6 para. 1 s. 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Website: https://www.hubspot.com; Privacy policy: https://legal.hubspot.com/privacy-policy; Data processing agreement: https://legal.hubspot.com/dpa. Third-country transfer basis: Data Privacy Framework (DPF), Standard contractual clauses.
Newsletters and Electronic Notifications
We send newsletters, emails and other electronic notifications (hereinafter "newsletter") only with the consent of the recipients or on a legal basis. Where the contents of the newsletter are described when registering for it, those contents are determinative for the user's consent. To register for our newsletter, it is generally sufficient to provide your email address.
Deletion and restriction of processing: We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to demonstrate previously given consent.
Contents: Information about us, our services, promotions and offers.
- Types of data processed: Master data; contact data; meta, communication and process data; usage data.
- Data subjects: Communication partners; users.
- Purposes of processing: Direct marketing; provision of contractual services.
- Legal bases: Consent (Art. 6 para. 1 s. 1 lit. a) GDPR).
- Opt-out: You can cancel the receipt of our newsletter at any time, i.e. withdraw your consent, or object to further receipt. You can find a link to unsubscribe from the newsletter at the end of every newsletter, or you can use the contact options listed above, preferably by email.
Web Analytics, Monitoring and Optimization
Web analytics (also referred to as "reach measurement") serves to evaluate the flow of visitors to our online offering and may include behavior, interests or demographic information about visitors, such as age or gender, as pseudonymous values.
IP addresses of users are stored but we use IP masking (pseudonymization by shortening the IP address) to protect users. Generally, no clear data of users (such as email addresses or names) are stored in the context of web analytics, but pseudonyms.
- Types of data processed: Usage data; meta, communication and process data.
- Data subjects: Users.
- Purposes of processing: Reach measurement; profiles with user-related information; provision of our online offering.
- Security measures: IP masking (pseudonymization of IP address).
- Legal bases: Consent (Art. 6 para. 1 s. 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
Further information:
- Google Analytics: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. Google Analytics does not log or store individual IP addresses for EU users. Analytics provides coarse geographic location data by deriving metadata from IP addresses: city, continent, country, region. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6 para. 1 s. 1 lit. a) GDPR); Privacy policy: https://policies.google.com/privacy; Third-country transfer basis: Data Privacy Framework (DPF), Standard contractual clauses; Opt-out: Opt-out plugin: https://tools.google.com/dlpage/gaoptout.
Online Marketing
We process personal data for the purposes of online marketing, which in particular includes the marketing of advertising space or the display of advertising and other content (collectively "content") based on the potential interests of users, as well as the measurement of their effectiveness.
IP addresses of users are stored but we use IP masking for user protection. Generally, no clear data of users are stored in the context of online marketing, but pseudonyms.
Opt-out options:
a) Europe: https://www.youronlinechoices.eu
b) USA: https://optout.aboutads.info/
c) Cross-territory: https://optout.aboutads.info
- Types of data processed: Usage data; meta, communication and process data.
- Data subjects: Users.
- Purposes of processing: Reach measurement; tracking; target group formation; marketing; profiles with user-related information.
- Security measures: IP masking.
- Legal bases: Consent (Art. 6 para. 1 s. 1 lit. a) GDPR).
Further information:
- LinkedIn Insight Tag: Code that is loaded when a user visits our online offering and tracks user behavior and conversions, and stores them in a profile; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Consent (Art. 6 para. 1 s. 1 lit. a) GDPR); Privacy policy: https://www.linkedin.com/legal/privacy-policy; Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Presences in Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to provide information about us.
We point out that user data may be processed outside the European Union. This may result in risks for users because it could, for example, make it more difficult to enforce users' rights. Furthermore, user data within social networks is generally processed for market research and advertising purposes.
- Types of data processed: Contact data; content data; usage data.
- Data subjects: Users.
- Purposes of processing: Communication; feedback; public relations.
- Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
Further information:
- Instagram: Social network allowing the sharing of photos and videos, commenting and favoriting posts, sending messages, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Privacy policy: https://privacycenter.instagram.com/policy/. Third-country transfer basis: Data Privacy Framework (DPF).
- LinkedIn: Social network — We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of data from visitors that is used to create "Page Insights" (statistics) for our LinkedIn profiles; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Privacy policy: https://www.linkedin.com/legal/privacy-policy; Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- YouTube: Social network and video platform; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Privacy policy: https://policies.google.com/privacy; Third-country transfer basis: Data Privacy Framework (DPF). Opt-out: https://myadcenter.google.com/personalizationoff.
Plugins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter "third-party providers"). These may include, for example, graphics, videos or maps (hereinafter uniformly referred to as "content").
The integration always requires that the third-party providers of this content process the IP address of the users, as without the IP address they could not send the content to their browser.
- Types of data processed: Usage data; meta, communication and process data.
- Data subjects: Users.
- Purposes of processing: Provision of our online offering.
- Legal bases: Consent (Art. 6 para. 1 s. 1 lit. a) GDPR); Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR).
Further information:
- Google Fonts (retrieved from Google servers): Retrieval of fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to currency and loading times, their uniform rendering and consideration of possible licensing restrictions. The provider of the fonts is informed of the user's IP address so that the fonts can be made available in the user's browser; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6 para. 1 s. 1 lit. f) GDPR); Privacy policy: https://policies.google.com/privacy; Third-country transfer basis: Data Privacy Framework (DPF).
Changes and Updates
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as the changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an action on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and please verify the information before contacting us.
Definitions
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Controller: The "controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data, whether collecting, evaluating, storing, transmitting or deleting.
- Cookies: Cookies are small text files that are stored on users' devices. They can serve different purposes — ensuring functionality, security and convenience of online offerings, and creating analyses of visitor flows.
- Tracking: "Tracking" refers to when the behavior of users can be traced across multiple online offerings. As a rule, behavioral and interest information is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling).
- Reach measurement: Reach measurement (also referred to as web analytics) serves to evaluate the flow of visitors to an online offering and may include the behavior or interests of visitors in certain information, such as the content of web pages.
Created with free privacy policy generator by Dr. Thomas Schwenke