Privacy Policy
Information pursuant to Art. 13 and 14 GDPR on the processing of personal data
This is a convenience translation. The German version of this document is legally authoritative.
At GKM Interactive, the trust of our visitors comes first. We are committed to protecting your privacy and ensuring the security of your personal data.
This privacy policy informs you, pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we collect, how we process it and what rights you have. Personal data is always processed in accordance with the GDPR and the country-specific data protection provisions applicable to us.
Controller
The controller within the meaning of the GDPR is:
GKM Interactive UG (haftungsbeschränkt)
Wasserstraße 5
37186 Moringen
Germany
Email: [email protected]
Data Collection
Provided Directly
Identification data
If you request a quote, subscribe to our newsletter or use our services, we may collect your name, your email address, your telephone number and company details.
Automatically
Usage data & analytics
When you visit our website or use our apps, we automatically collect certain information such as IP address, browser type, operating system, device identifier, referring URLs and interactions with our content.
Payment Data
In-app purchases & subscriptions
For purchases in our mobile applications, transaction-related data is processed via RevenueCat. The actual payment processing is carried out by the app stores (Apple/Google).
Legal Bases for Processing
Your personal data is processed on the basis of the following legal bases under the GDPR:
- Art. 6(1)(a) GDPR - Consent: For the use of analytics cookies and marketing tools such as Google Analytics.
- Art. 6(1)(b) GDPR - Performance of a contract: For the provision of our services, the processing of purchases and communication within the scope of business relationships.
- Art. 6(1)(f) GDPR - Legitimate interest: For ensuring IT security (Cloudflare), optimizing our services and preventing fraud.
Cloudflare
We use the content delivery network (CDN) and the security services of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework.
Purpose of Processing
- Acceleration of website delivery through a worldwide server infrastructure
- Protection against DDoS attacks and malicious traffic
- SSL/TLS encryption of data transmission
- Web Application Firewall (WAF) for protection against attacks
Data Processed
IP address, system configuration information, HTTP request data (method, URL, HTTP version, referrer, user agent) as well as security logs. The data is stored in logs for a maximum of 24 hours.
Legal Basis
Art. 6(1)(f) GDPR (legitimate interest in IT security)
Further information: Cloudflare Privacy Policy
Google Analytics
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For users from the EEA and Switzerland, Google Ireland Limited is the controller responsible for the data processing.
Note: Google Analytics is only activated with your express consent (cookie consent).
Purpose of Processing
- Analysis of user behavior in order to optimize our website
- Compilation of statistics on page views, time spent and navigation
- Measurement of the effectiveness of marketing campaigns
Data Processed
Shortened IP address (IP anonymization enabled), browser type/version, operating system, referrer URL, host name of the accessing computer, time of the server request, device identifier, usage behavior (page views, clicks, scroll depth).
Retention Period
The data is stored for 14 months and then deleted automatically.
Legal Basis
Art. 6(1)(a) GDPR (consent)
Withdrawal of Consent
You can withdraw your consent at any time by adjusting your cookie settings. Alternatively, you can install the browser add-on to deactivate Google Analytics: Google Analytics Opt-Out
Further information: Google Privacy Policy
Firebase (Google)
We use various services from Firebase, a development platform of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Firebase is certified under the EU-U.S. Data Privacy Framework.
Firebase Services Used
- Firebase Authentication: Management of user accounts and logins. Data processed: email address, password hash, IP address, user agent.
- Firebase Firestore / Realtime Database: Cloud database for storing user data and app content. The data is stored in the EU (eur3 region).
- Firebase Cloud Messaging (FCM): Sending of push notifications. Data processed: device token, message metadata.
- Firebase Crashlytics: Recording of app crashes for troubleshooting. Data processed: crash reports, device information, app status at the time of the crash.
- Firebase Hosting: Hosting of web content with global CDN distribution.
Legal Basis
Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest)
Further information: Firebase Privacy
Google Cloud Platform
We use the Google Cloud Platform (GCP) of Google Ireland Limited for our cloud infrastructure. Data processing takes place in European data centers (europe-west region).
GCP Services Used
- Cloud Run / App Engine: Hosting and execution of backend applications
- Cloud Storage: Storage of files and media
- Cloud Functions: Serverless execution of code
- Cloud SQL: Managed relational databases
Data Storage Location
All data is stored and processed exclusively in data centers within the European Union. Google is certified under the EU-U.S. Data Privacy Framework and provides standard contractual clauses for data transfers.
Security Measures
- Encryption of all data during transmission and storage (AES-256)
- ISO 27001, SOC 2 and SOC 3 certified
- Regular security audits and penetration tests
Legal Basis
Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest)
Further information: Google Cloud Privacy
RevenueCat
For the management of in-app purchases and subscriptions in our mobile applications, we use RevenueCat, Inc., 633 Tarava St Suite 101, San Francisco, CA 94116, USA. RevenueCat is certified under the EU-U.S. Data Privacy Framework.
Purpose of Processing
- Management of subscriptions and in-app purchases
- Synchronization of the purchase status across different platforms (iOS, Android)
- Analysis of revenue data and subscription metrics
- Detection and prevention of fraud
Data Processed
- App user ID (anonymized or assigned by us)
- Purchase receipts from the Apple App Store / Google Play Store
- Product IDs, date and time of purchase, transaction status
- Device and platform information
- Country (based on the store setting, no precise location determination)
Note: RevenueCat does not receive complete payment data such as credit card numbers. Payment processing is carried out exclusively via Apple and Google.
Retention Period
Transaction data is stored for the duration of the active subscription plus the statutory retention periods.
Legal Basis
Art. 6(1)(b) GDPR (performance of a contract)
Further information: RevenueCat Privacy Policy
Transfer of Data to Third Countries
Some of our service providers are based in the USA. The transfer of personal data to the USA takes place on the basis of the following safeguards:
- EU-U.S. Data Privacy Framework: Google, Cloudflare and RevenueCat are certified under the EU-U.S. Data Privacy Framework. This framework has been recognized by the European Commission as providing an adequate level of protection (adequacy decision of 10 July 2023).
- Standard Contractual Clauses (SCCs): In addition, the standard contractual clauses approved by the EU Commission, which ensure an adequate level of data protection, are concluded with all US service providers.
Cookies
Our website uses cookies. Cookies are small text files that are stored on your end device and saved by your browser.
Types of Cookies
- Strictly necessary cookies: These cookies are absolutely essential for the operation of the website (e.g. session cookies, security cookies). Legal basis: Art. 6(1)(f) GDPR.
- Analytics cookies (Google Analytics): These cookies help us to understand how visitors interact with our website. They are only set with your consent. Legal basis: Art. 6(1)(a) GDPR.
- Cloudflare cookies: Cloudflare sets a cookie (__cf_bm) in order to detect malicious traffic. This cookie is necessary for security and expires after 30 minutes.
Managing Cookie Settings
You can adjust your cookie preferences at any time via our cookie banner or deactivate all cookies in your browser settings. Please note that this may impair the functionality of our website.
Your Data Protection Rights
Under the GDPR, you have the following rights with regard to your personal data:
Right of Access (Art. 15 GDPR)
You have the right to request confirmation as to whether personal data is being processed, and to obtain access to that data as well as further information and a copy of the data.
Right to Rectification (Art. 16 GDPR)
You have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data.
Right to Erasure (Art. 17 GDPR)
You have the right to request the erasure of your personal data, provided that the conditions of Art. 17 GDPR are met (e.g. if the data is no longer necessary for the purposes).
Right to Restriction (Art. 18 GDPR)
You have the right to request the restriction of the processing of your personal data, e.g. if you contest the accuracy of the data.
Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
Right to Object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you.
Right to Withdraw Consent (Art. 7(3) GDPR)
You have the right to withdraw consent you have given at any time with effect for the future. This does not affect the lawfulness of the processing carried out on the basis of the consent up to the withdrawal.
Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data infringes the GDPR. The competent supervisory authority is Die Landesbeauftragte für den Datenschutz Niedersachsen.
Data Security
We use technical and organizational security measures in order to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons:
- SSL/TLS encryption: All data transmissions are encrypted via HTTPS.
- Firewall & DDoS protection: Cloudflare WAF and DDoS protection secure our infrastructure.
- Access control: Strict access rights and authentication for employees.
- Regular backups: Encrypted backups to ensure data availability.
Changes to This Privacy Policy
We reserve the right to amend this privacy policy in order to adapt it to changes in the legal situation or to changes in our services. The new privacy policy then applies from its date of publication. In the event of material changes, we will inform you separately.
Contact
Questions about data protection?
If you have any questions about our data protection practices or about exercising your rights, we are happy to help.
Email: [email protected]
Wasserstraße 5, 37186 Moringen, Germany
