Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws is:

TurnFriendly Software GmbH
Schillstraße 4
90491 Nuremberg
Germany

Phone: +49 911 937 88 0
Email: hello@turnfriendly.com

Represented by its Managing Directors:
Marco Rothberg and Sebastian Seyler

2. Data Protection Officer

The Data Protection Officer of TurnFriendly Software GmbH is:

Sven Lünke
Sepire GmbH
Am Felsenkeller 12
90530 Wendelstein
Germany

Phone: +49 9129 9076899
Email: info@sepire.de

3. General Information on Data Processing

We take the protection of your personal data seriously and process your data confidentially and in accordance with applicable data protection laws.

This Privacy Policy explains which personal data we process when you visit our website, contact us, schedule an appointment, apply for a position with us or use the services and technologies provided on our website.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, contact details, IP address, device information or information about your use of our website.

“Processing” means any operation performed on personal data, including in particular the collection, recording, storage, organisation, retrieval, use, transmission, alteration or deletion of personal data.

We process personal data only where there is a lawful basis for doing so. The applicable legal framework includes, in particular, the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG) and the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG).

4. Legal Bases for Processing

Depending on the nature and purpose of the respective processing activity, we rely in particular on the following legal bases:

4.1 Consent – Art. 6(1)(a) GDPR

Where you provide us with your consent, we process the relevant personal data on the basis of that consent.

You may withdraw your consent at any time with effect for the future.

4.2 Contract and Pre-Contractual Measures – Art. 6(1)(b) GDPR

Where processing is necessary for the performance of a contract or in order to take steps at your request prior to entering into a contract, we process personal data on the basis of Art. 6(1)(b) GDPR.

4.3 Legal Obligations – Art. 6(1)(c) GDPR

Where we are legally required to process personal data, such processing is carried out on the basis of Art. 6(1)(c) GDPR.

4.4 Legitimate Interests – Art. 6(1)(f) GDPR

Where processing is necessary for the purposes of our legitimate interests or those of a third party and your interests, fundamental rights and freedoms do not override those interests, processing is carried out on the basis of Art. 6(1)(f) GDPR.

Our legitimate interests include, in particular, the secure and efficient operation of our website, IT security, the handling of business enquiries, the conduct of our business activities and the establishment, exercise or defence of legal claims.

5. Hosting and Server Log Files

Our website is hosted by:

STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany

We have entered into a data processing agreement with STRATO in accordance with Art. 28 GDPR.

When you access our website, STRATO processes technical data that is required for hosting purposes. This may include in particular:

  • IP address,
  • date and time of access,
  • page or file accessed,
  • amount of data transferred,
  • referrer URL,
  • browser type and browser version,
  • operating system used,
  • hostname or requesting provider, and
  • other technical connection data.

The processing is carried out in order to provide our website securely, reliably and efficiently and to detect and prevent attacks. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of our online services.

According to STRATO, IP addresses of website visitors are stored for a maximum of seven days for the purpose of detecting and preventing attacks. The web server log files made available to us contain anonymised hostnames or IP addresses.

STRATO makes web server log files available for the previous six weeks.

According to STRATO, the data processing relating to the hosting services we use takes place exclusively in data centres located in Germany.

6. SSL/TLS Encryption

For security purposes and to protect the transmission of confidential information, our website uses SSL/TLS encryption. This means that data you transmit to us via our website is encrypted during transmission between your browser and our server.

You can identify an encrypted connection, in particular, by the fact that the address of the page you are visiting begins with “https://”.

We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other unlawful processing. However, absolute security of electronic data transmission cannot be guaranteed.

7. Recipients and Disclosure of Personal Data

We disclose personal data only where there is a lawful basis for doing so.

Recipients of personal data may include, in particular:

  • hosting and IT service providers,
  • software and platform providers,
  • providers of communication and appointment scheduling services,
  • consent management providers,
  • advertising and marketing platforms where you have consented to their use,
  • external advisers or service providers where this is necessary and legally permitted,
  • public authorities, courts or other public bodies where we are legally obliged to disclose data.

Where external service providers process personal data solely on our behalf, we enter into the required data processing agreements with them in accordance with Art. 28 GDPR.

Individual providers may also process personal data as independent controllers or within the framework of joint controllership. Where applicable, we provide specific information on this in the sections relating to the respective services.

We do not sell your personal data.

8. Transfers of Data to Third Countries

When individual services are used, personal data may be processed outside the European Union or the European Economic Area.

Such transfers take place only in accordance with the requirements of Art. 44 et seq. GDPR.

Where the European Commission has determined that a country ensures an adequate level of data protection, personal data may be transferred on the basis of an adequacy decision pursuant to Art. 45 GDPR.

For appropriately certified organisations in the United States, transfers may in particular be based on the adequacy decision concerning the EU-U.S. Data Privacy Framework.

Where no adequacy decision applies, the Standard Contractual Clauses approved by the European Commission pursuant to Art. 46 GDPR and, where appropriate, supplementary safeguards may be used.

Further information on potential transfers to third countries can be found in the sections relating to the respective services.

9. Storage Period

We generally store personal data only for as long as necessary for the respective purpose of processing.

Personal data may also be retained where statutory retention obligations apply or where the data is required for the establishment, exercise or defence of legal claims.

Where processing is based on your consent, the relevant data is generally processed until you withdraw your consent or until the purpose of the processing no longer applies, unless another legal basis or statutory retention obligation permits or requires continued storage.

Where specific retention periods apply to individual services, these are described in the relevant sections of this Privacy Policy.

10. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Cookies are small data records stored on your device. Similar technologies may include, for example, local storage, pixels, tags, scripts or other identifiers.

We distinguish between technologies that are technically necessary and technologies used in particular for marketing, conversion measurement, analytics or retargeting purposes.

10.1 Technically Necessary Technologies

Technologies that are strictly necessary to provide a digital service expressly requested by you may be used without prior consent.

Where information is stored on or accessed from your device, this is carried out on the basis of Section 25(2) TDDDG.

Any associated processing of personal data is carried out, depending on the purpose, in particular on the basis of Art. 6(1)(b) or Art. 6(1)(f) GDPR.

10.2 Technologies Requiring Consent

Technologies used for marketing, conversion measurement, retargeting or similar purposes are generally activated only after you have expressly consented to their use.

The storage of information on your device or access to information already stored on your device is based on your consent pursuant to Section 25(1) TDDDG.

The associated processing of personal data is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR.

You can change your choices at any time via the cookie or privacy settings available on our website.

11. Consent Management with CCM19

We use the CCM19 consent management platform provided by:

Papoo Software & Media GmbH
Auguststr. 4
53229 Bonn
Germany

CCM19 is used to obtain, manage, implement and document your choices regarding the use of cookies and similar technologies. In particular, this enables us to ensure that services requiring consent are activated only after you have given the relevant consent.

We use the cloud version of CCM19.

The following information may be processed as part of consent management:

  • an individual consent ID,
  • date and time of your decision,
  • your consent or refusal decision,
  • selected services and categories,
  • language and settings of the consent banner, and
  • technical information relating to the page request.

The processing serves, in particular, to implement your privacy choices and to provide evidence of consent that has been given.

Where information is stored on or accessed from your device and such storage or access is technically necessary for managing your privacy choices, this is carried out on the basis of Section 25(2) TDDDG.

The processing of personal data is carried out in particular on the basis of Art. 6(1)(c) GDPR in connection with our obligation to be able to demonstrate that consent has been obtained. In addition, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the legally compliant, transparent and user-friendly management of your privacy choices.

Papoo Software & Media GmbH processes personal data in this context as a processor pursuant to Art. 28 GDPR.

According to the provider, the data processed within the scope of consent management is stored exclusively on servers in Germany. According to the provider, no transfer to third countries takes place in connection with the CCM19 consent management service.

When the CCM19 cloud version is used, the individual consent ID generated for documenting your decision is stored for one year according to CCM19.

You may change your choices at any time via the cookie or privacy settings available on our website or withdraw previously granted consent with effect for the future.

The cookies and similar technologies currently used on our website, including their providers, purposes and storage periods, can also be found in the cookie settings.

12. Meta Pixel

After you have provided your consent, we use the Meta Pixel on our website.

The provider for users within the European Union and the European Economic Area is:

Meta Platforms Ireland Limited
Merrion Road
Dublin 4
D04 X2K5
Ireland

The Meta Pixel is part of the Meta Business Tools and enables us, in particular, to measure the effectiveness of our advertising on Facebook and Instagram, record conversions, analyse and optimise advertising campaigns and, where applicable, create audiences for subsequent advertising.

12.1 Data Processed

Depending on the specific use and configuration, the following information in particular may be processed or transmitted to Meta:

  • websites and URLs accessed,
  • time of page access,
  • referrer information,
  • IP address,
  • browser and device information,
  • cookie or similar identifiers,
  • information about interactions with our website,
  • events or conversions defined by us, and
  • information used to attribute a website visit or conversion to an advertising campaign.

Meta may combine information received via the Meta Pixel with other information already available to Meta, for example through the use of Facebook, Instagram or other Meta services.

Where Meta processes this information as an independent controller, the subsequent processing is carried out under Meta’s own responsibility.

12.2 Purposes of Processing

We use the Meta Pixel in particular for:

  • conversion measurement,
  • measuring the effectiveness of our advertising on Meta platforms,
  • analysing advertising campaign performance,
  • optimising our advertising activities, and
  • where applicable, creating audiences for retargeting.

12.3 Legal Basis

The Meta Pixel is activated only after you have provided your consent.

The legal bases are:

  • Section 25(1) TDDDG for storing information on or accessing information from your device, and
  • Art. 6(1)(a) GDPR for the associated processing of personal data.

You may withdraw your consent at any time with effect for the future via our cookie or privacy settings.

12.4 Responsibility of Meta and TurnFriendly

For certain processing operations involving personal event data in connection with the Meta Business Tools, TurnFriendly Software GmbH and Meta Platforms Ireland Limited may act as joint controllers within the meaning of Art. 26 GDPR.

This joint controllership relates in particular to the collection of certain personal data via the Meta Pixel and its subsequent transmission to Meta for certain purposes defined by Meta.

For other processing activities, Meta may act as a processor or as an independent controller. The specific allocation of data protection responsibilities depends on the respective purpose of processing and the contractual terms applicable to the Meta Business Tools.

12.5 Storage Period

Under the terms applicable to the Meta Business Tools, Meta may store event data for a maximum period of two years.

Audiences created on the basis of such event data may, under Meta’s terms, be stored until they are deleted using the relevant account tools.

We have no direct influence over any additional processing or retention periods applied by Meta.

12.6 Transfers to Third Countries

Personal data may also be processed by Meta Platforms, Inc. and other Meta companies in the United States or other countries outside the European Economic Area.

Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework for certain categories of data, including the Meta Business Tools.

Where the relevant requirements are met, such transfers may be based on the corresponding adequacy decision of the European Commission. Depending on the specific processing activity, additional transfer mechanisms may also apply.

Further information about data processing by Meta and about your privacy and settings options can be found in Meta’s privacy information and the terms applicable to the Meta Business Tools.

13. LinkedIn Insight Tag

After you have provided your consent, we use the LinkedIn Insight Tag on our website.

The provider is:

LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2
Ireland

The LinkedIn Insight Tag is a JavaScript-based tracking technology that enables us, in particular, to measure the effectiveness of our LinkedIn advertising campaigns, record conversions, optimise campaigns and, where applicable, retarget visitors to our website with advertising on LinkedIn.

13.1 Data Processed

LinkedIn may collect the following information in particular via the Insight Tag:

  • URL of the page visited,
  • referrer URL,
  • IP address,
  • time of the visit,
  • device and browser characteristics,
  • pseudonymous identifiers,
  • information about page views, and
  • information about defined website actions or conversions.

The Insight Tag may use cookies and other identifiers for these purposes.

We generally do not receive information from LinkedIn that enables us to directly identify individual LinkedIn members. In particular, LinkedIn provides us with campaign, conversion and audience information in aggregated or otherwise processed form.

13.2 Purposes of Processing

We use the LinkedIn Insight Tag in particular for:

  • conversion measurement,
  • measuring the performance of our LinkedIn advertising campaigns,
  • campaign optimisation,
  • creation of campaign and audience analyses, and
  • where applicable, retargeting visitors to our website on LinkedIn.

13.3 Legal Basis

The LinkedIn Insight Tag is activated only after you have provided your consent.

The legal bases are:

  • Section 25(1) TDDDG for storing information on or accessing information from your device, and
  • Art. 6(1)(a) GDPR for the associated processing of personal data.

You may withdraw your consent at any time with effect for the future via our cookie or privacy settings.

13.4 Responsibility of LinkedIn

For the processing of personal data in connection with the LinkedIn Insight Tag and associated LinkedIn marketing services such as conversion tracking and website retargeting, LinkedIn processes personal data as an independent controller in accordance with the applicable contractual terms.

LinkedIn may use the data received, in particular, to provide, support and improve its services and for reporting and performance purposes.

13.5 Storage Period

LinkedIn states that information directly identifying an individual member is removed from data received via the Insight Tag within seven days in order to pseudonymise the data.

According to LinkedIn, the remaining pseudonymised data is deleted within 180 days.

13.6 Transfers to Third Countries

LinkedIn states that Insight Tag data is stored on servers in the United States.

For corresponding transfers, LinkedIn may rely in particular on the EU-U.S. Data Privacy Framework and, where required, the European Commission’s Standard Contractual Clauses.

Further information on the processing of personal data, cookies and privacy and advertising settings can be found in LinkedIn’s privacy information.

14. Adobe Fonts (Typekit)

For the consistent presentation of fonts, we use Adobe Fonts, formerly Adobe Typekit, a service provided by Adobe.

For users outside North America and Japan, the relevant Adobe entity is generally:

Adobe Systems Software Ireland Limited
4-6 Riverwalk
City West Business Campus
Saggart, Dublin 24
Ireland

When you access our website, your browser loads the required fonts from Adobe servers. In this process, your IP address in particular is technically transmitted to Adobe. According to Adobe, the IP address is required in order to deliver the fonts to your browser but is not stored.

In addition, information relating to the fonts delivered, the Web Project ID, the type of integration, the Adobe account associated with the web project, the server used and the hostname of the website accessed may be processed.

According to Adobe, no cookies are set for the delivery of Adobe Fonts on websites.

The processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the consistent, technically reliable and visually appropriate presentation of our website.

Adobe may also process personal data outside the European Economic Area as part of its services. According to Adobe, the transfer mechanisms provided for under applicable data protection law are used for such transfers.

Further information about data processing by Adobe can be found in Adobe’s Privacy Policy and the privacy information relating to Adobe Fonts.

15. Contacting Us and Contact Form

You may contact us using our contact form, by email, by telephone or by other means.

15.1 Data Processed

Depending on the nature of your enquiry, we may process in particular:

  • name,
  • email address,
  • telephone number,
  • company,
  • position or function,
  • industry,
  • preferred date or time for a meeting,
  • content of your message,
  • other information provided voluntarily,
  • time of submission, and
  • where applicable, technical information such as your IP address for the purpose of preventing misuse.

Mandatory fields are marked accordingly in the relevant form. Any additional information is provided voluntarily.

15.2 Purpose and Legal Basis

We use your data to process and respond to your enquiry and for any further business communication that may be required.

Where your enquiry relates to entering into or performing a contract or to a specific pre-contractual consultation, processing is carried out on the basis of Art. 6(1)(b) GDPR.

For other business enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in processing and responding to business communications addressed to us.

Where technical data is processed in order to secure the form or prevent misuse, such processing is also based on Art. 6(1)(f) GDPR.

Separate consent under data protection law is generally not required solely for the purpose of processing an enquiry that you have initiated yourself.

15.3 Storage Period

We store data processed in connection with your enquiry for as long as necessary to deal with your request and for any subsequent business communication.

If the enquiry results in a contractual or business relationship, the data may continue to be stored within the context of that relationship and in accordance with applicable statutory retention obligations.

Data may also be retained for longer where this is necessary for the establishment, exercise or defence of legal claims.

16. Appointment Scheduling via Calendly

For the scheduling of certain consultation appointments, we provide a link to the Calendly appointment scheduling service.

The provider is:

Calendly LLC
115 E Main Street
Suite A1B
Buford, GA 30518
USA

Calendly is currently not embedded directly into our website as a booking widget. Only when you actively open the relevant Calendly link do you leave our website and establish a connection with Calendly.

16.1 Processing When Booking an Appointment

When you book an appointment with us via Calendly, the following data may be processed depending on the information you provide:

  • name,
  • email address,
  • appointment details,
  • time zone,
  • telephone number, where applicable,
  • additional information voluntarily provided by you, and
  • technical usage and connection data.

The information you provide as part of the appointment scheduling process is made available to us in order to organise and conduct the appointment.

Where Calendly processes personal data as part of the appointment scheduling service commissioned by us, such processing is carried out as a processor on the basis of an appropriate agreement.

In connection with the operation of its own websites and certain of its own functions, Calendly may also process personal data as an independent controller.

16.2 Purpose and Legal Basis

We process the data for the purpose of arranging and conducting the appointment requested by you.

Where the appointment relates to specific pre-contractual discussions or consultation, processing is carried out on the basis of Art. 6(1)(b) GDPR.

For other business appointments, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the efficient and user-friendly organisation of appointments.

16.3 Transfers of Data to the United States

Calendly processes personal data, among other locations, in the United States.

For transfers of personal data from the European Economic Area, Calendly provides in particular for the use of the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework.

Further information on data processing by Calendly can be found in Calendly’s privacy information.

17. External Links and Social Media Services

Our website may contain links to external websites and platforms, in particular LinkedIn and YouTube.

Simply accessing our website does not generally result in personal data being transmitted to the respective external platform solely because a standard external link is present.

Only when you actively open such a link do you leave our website and establish a direct connection to the servers of the respective provider. From that point onwards, the provider may process personal data in accordance with its own privacy policy.

We have no control over the nature and scope of data processing carried out on external providers’ websites.

18. YouTube

We provide links to content and to our company presence on YouTube.

YouTube is a service provided by Google.

At present, YouTube videos are not embedded directly into our website. Therefore, simply visiting our website does not generally establish a connection to YouTube solely as a result of a standard YouTube link.

Only when you open the relevant link do the privacy provisions of the respective YouTube or Google service apply.

If YouTube videos are embedded directly into our website in the future, the data protection setup and this Privacy Policy will be adjusted accordingly.

19. Applications

You may apply for positions at TurnFriendly using the contact methods specified on our website, in particular by email or by post.

19.1 Data Processed

As part of an application process, we may process in particular:

  • first and last name,
  • contact details,
  • postal address,
  • telephone number,
  • email address,
  • information regarding education and professional experience,
  • CV,
  • references and evidence of qualifications,
  • application photograph, if provided by you,
  • information contained in cover letters and other application documents, and
  • other information you voluntarily provide as part of your application.

Please provide only information that is necessary for the application process.

19.2 Purpose and Legal Basis

We process applicant data for the purpose of deciding whether to establish an employment relationship.

The legal basis is Section 26(1) BDSG in conjunction with Art. 88 GDPR.

Where processing does not fall directly within Section 26 BDSG, Art. 6(1)(b) GDPR may apply in addition.

Where you expressly consent to specific additional processing, such processing is carried out on the basis of Art. 6(1)(a) GDPR or Section 26(2) BDSG.

Where special categories of personal data within the meaning of Art. 9 GDPR are processed, this takes place only where an appropriate legal basis applies.

19.3 Storage Period

If an employment relationship is established, the application data required for the employment relationship will continue to be processed in accordance with the applicable legal requirements.

If your application is unsuccessful, we generally delete application data no later than six months after completion of the application process, unless longer storage is required due to statutory obligations or for the establishment, exercise or defence of legal claims.

Any further storage for future recruitment processes takes place only where there is an appropriate legal basis, in particular your consent.

19.4 Provision of Data

The provision of the personal data required for the application process is necessary in order for us to process your application.

Without this information, it may not be possible to carry out the application process.

20. Minors

Our website is primarily directed at businesses, business customers, prospective customers and applicants and is not specifically directed at children.

We do not intentionally request personal data from children under the age of 16.

Where consent is required in relation to the processing of a child’s personal data in connection with an information society service, the statutory requirements of Art. 8 GDPR apply.

21. Automated Decision-Making

In connection with the use of our website, we do not use decisions based solely on automated processing within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.

The marketing technologies we use may be used to assign individuals to advertising audiences and to measure and optimise advertising campaigns. However, TurnFriendly does not use these technologies to make automated decisions within the meaning of Art. 22 GDPR that have legal or similarly significant effects on website visitors.

22. Your Rights

Where the applicable legal requirements are met, you have the following data protection rights in particular.

22.1 Right of Access

Under Art. 15 GDPR, you have the right to request information as to whether we process personal data concerning you and, where applicable, which personal data we process.

22.2 Right to Rectification

Under Art. 16 GDPR, you have the right to request the correction of inaccurate personal data or the completion of incomplete personal data.

22.3 Right to Erasure

Under the conditions set out in Art. 17 GDPR, you have the right to request the deletion of your personal data.

In particular, the right to erasure does not apply where further processing is required to comply with a legal obligation or for the establishment, exercise or defence of legal claims.

22.4 Right to Restriction of Processing

Under the conditions set out in Art. 18 GDPR, you have the right to request restriction of the processing of your personal data.

22.5 Right to Data Portability

Where the conditions of Art. 20 GDPR are met, you have the right to receive personal data that you have provided to us in a structured, commonly used and machine-readable format or, where technically feasible, to request its transmission to another controller.

22.6 Withdrawal of Consent

You may withdraw consent you have given at any time with effect for the future in accordance with Art. 7(3) GDPR.

Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

You may change or withdraw consent relating to cookies and similar tracking technologies at any time via the cookie or privacy settings available on our website.

22.7 Right to Object

Under Art. 21 GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you where such processing is based on Art. 6(1)(e) or Art. 6(1)(f) GDPR.

We will then no longer process the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where processing is necessary for the establishment, exercise or defence of legal claims.

>Where personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing.

22.8 Right to Lodge a Complaint with a Supervisory Authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes applicable data protection law.

For TurnFriendly Software GmbH, the competent supervisory authority is in particular:

Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht – BayLDA)
Promenade 18
91522 Ansbach
Germany

Irrespective of this, you may also contact any other data protection supervisory authority competent under Art. 77 GDPR.

23. Exercising Your Data Protection Rights

To exercise your rights or if you have questions regarding the processing of your personal data, you may contact us or our Data Protection Officer directly.

TurnFriendly Software GmbH
Schillstraße 4
90491 Nuremberg
Germany

Phone: +49 911 937 88 0
Email: hello@turnfriendly.com

or:

Sven Lünke
Sepire GmbH
Am Felsenkeller 12
90530 Wendelstein
Germany

Phone: +49 9129 9076899
Email: info@sepire.de

Where we have reasonable doubts regarding the identity of the person making a request, we may ask for additional information required to verify their identity.

24. Amendments to this Privacy Policy

We may amend this Privacy Policy where changes to our website, the technologies we use, our processing activities or the applicable legal or regulatory framework make this necessary.

The version of this Privacy Policy currently published on our website applies.

Last updated: August 2026








Questions? Contact us!

Our team is happy to answer your questions.