1. Controller
- Company
- Fan Intelligence GmbH
- Address
-
Poststraße 21
40822 Mettmann
Germany - Phone
- +49 151 72383620
2. Scope of processing
When you simply visit the website, we process technical access data. We receive further personal data only when you contact us or expressly subscribe to the email newsletter.
The website does not use analytics, advertising or social-media tracking services. We do not carry out automated decision-making or profiling within the meaning of Article 22 GDPR.
3. Website delivery and hosting
The website is hosted by Timme Hosting GmbH & Co. KG, Marie-Curie-Straße 5, 21337 Lüneburg, Germany. The hosting provider processes data on our behalf under Article 28 GDPR; the servers used are located in the European Union.
When the website is requested, server logs may process the IP address, date and time, requested address or file, referrer, browser and operating-system information, HTTP status and transferred data volume. This is necessary to deliver the website, maintain stability, diagnose errors and protect against attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the website.
4. Contacting us
When you contact us, we process the information you provide to review and respond to your inquiry. The contact form requires your name, email address and message; your organisation and phone number are optional. The selected language version is also transmitted.
If your inquiry relates to a contract or pre-contractual steps, the legal basis is Article 6(1)(b) GDPR. For other business or general inquiries, we rely on Article 6(1)(f) GDPR; our legitimate interest is orderly and reliable communication. We cannot process the form without the required fields. We do not use the information for advertising or subscribe you to a newsletter automatically.
We use Brevo's transactional email service as a processor for internal delivery and the automated receipt confirmation. This processing covers the form data, sender and recipient addresses, a case reference and technical delivery data. The confirmation does not include a copy of your message. Form senders are not added to Brevo contact lists, campaigns or automations.
5. Technical abuse protection for forms
To protect our forms against automated or repeated submissions, we use signed, time-limited, single-use challenges, invisible empty fields, request limits and duplicate detection. The IP address and user agent are processed server-side solely to create an HMAC-protected verification value. Their clear values are not stored in these security files.
Single-use and duplicate records are retained for no more than one hour; pseudonymised rate-limit records for no more than 48 hours. Contact-message content is not written to application logs. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the availability and integrity of the communication channels we provide.
6. Cloudflare Turnstile
Cloudflare Turnstile may be prepared on pages that contain a form; the actual security check runs only when the form is submitted. The provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Turnstile processes signals such as the IP address, TLS fingerprint, user-agent header, site key and associated origin to distinguish humans from automated access. Our configuration does not issue a pre-clearance cookie.
Cloudflare processes the signals as our processor to secure our forms and may process them as a controller to improve bot detection. The legal basis is Article 6(1)(f) GDPR. Access to device information is strictly necessary under Section 25(2)(2) TDDDG to provide the communication channels expressly requested by the user securely.
8. Recipients
Data is disclosed only to parties that need it for the purposes described above.
- responsible employees and management of Fan Intelligence GmbH
- Timme Hosting GmbH & Co. KG as hosting processor
- Brevo as processor for transactional email, double opt-in, newsletter contact management and newsletter delivery, as well as the configured mailbox provider
- Cloudflare, Inc. solely in connection with Turnstile
- authorities, courts or other bodies where disclosure is required by law
9. Transfers outside the EEA
Turnstile data may be processed by Cloudflare in the United States and other countries. Cloudflare is certified under the EU-US Data Privacy Framework. Where that certification does not apply or ceases to apply, Cloudflare's Data Processing Addendum provides for the EU Standard Contractual Clauses and supplementary safeguards.
Brevo may use subprocessors in countries outside the European Economic Area to provide its service. Where no adequacy decision applies, the Data Processing Agreement provides appropriate safeguards, including the EU Standard Contractual Clauses and supplementary measures.
Beyond this, we do not intend to transfer personal data to countries outside the European Economic Area.
10. Retention
Server log data is deleted or anonymised once it is no longer needed for operation, security and troubleshooting. If a specific security incident occurs, relevant data may be retained until the incident has been investigated and evidence secured.
We delete contact inquiries and correspondence once the inquiry has been finally handled and no legitimate evidentiary interests or statutory retention obligations remain. If a contractual relationship arises, the applicable commercial and tax retention periods apply. Technical form-security records are deleted according to the periods stated in section 5. Brevo transactional logs and email-content previews are retained for no more than 30 days.
Newsletter data is stored in Brevo until consent is withdrawn or the contact unsubscribes. Unconfirmed subscriptions are not added to the newsletter list. Necessary records of consent and unsubscribe events may be restricted and retained within applicable limitation periods where required for the establishment, exercise or defence of legal claims.
11. Your rights
Where the legal requirements are met, you have the following rights in particular:
- access to your personal data (Article 15 GDPR)
- rectification of inaccurate data (Article 16 GDPR)
- erasure (Article 17 GDPR)
- restriction of processing (Article 18 GDPR)
- data portability (Article 20 GDPR)
- objection to processing based on legitimate interests (Article 21 GDPR)
- withdrawal of consent with effect for the future
12. Right to object
Where we process personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for the establishment, exercise or defence of legal claims. You may submit your objection informally to info@fan-intelligence.com. You can also unsubscribe from the newsletter at any time using the link in every edition.
13. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is, in particular, the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, poststelle@ldi.nrw.de.
15. Updates to this information
We update this privacy information when the website, the services used or legal requirements change. The date above identifies the current version.