Privacy Policy

Privacy Policy

1. Introduction

This website is operated by: Luc Bernard Beckmann Creative Audio.

It is very important to us to handle the data of our website visitors with trust and to protect it in the best possible way. For this reason, we make every effort to meet the requirements of the GDPR.

In the following, we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you truly understand what happens to your data.

2. General Information

2.1 Processing of Personal Data and Other Terms

Data protection applies to the processing of personal data. „Personal“ means all data with which you can be personally identified. This includes, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is processed whenever „something happens to it“. For example, the IP address is transmitted from the browser to our provider and automatically stored there. This constitutes processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable Regulations/Laws – GDPR, BDSG, and TDDDG

The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national German law.

In addition, the TDDDG supplements the regulations of the GDPR regarding the use of cookies.

2.3 The Data Controller

The entity responsible for data processing on this website is the „Controller“ within the meaning of the GDPR. This is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

You can reach the controller at:

Luc Bernard Beckmann Creative Audio
Weißenseer Weg 82, 10369 Berlin
Email: info@luvezmusic.com

2.4 Fundamental Principles of Data Processing on This Website

As already established, some data (e.g., IP address) is collected automatically. This data is primarily required for the technical provision of the homepage. Insofar as we use personal data beyond this or collect other data, we will inform you or ask for your consent.

Other personal data is provided to us knowingly by you.

Detailed information on this can be found below.

2.5 Your Rights

The GDPR grants you comprehensive rights. These include, for example, the right to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You can also request the correction, blocking, or deletion of this data, or lodge a complaint with the competent data protection supervisory authority. You can revoke any consent given at any time.

The exact details of these rights and how to exercise them are outlined in the final section of this privacy policy.

2.6 Data Protection – Our Perspective

For us, data protection is more than just an annoying obligation! Personal data is highly valuable, and mindful handling of this data should be a matter of course in our digitalized world. Furthermore, as a website visitor, you should be able to decide for yourself what happens to your data, when, and by whom. Therefore, we commit ourselves to complying with all legal regulations, collecting only the data necessary for us, and treating it with strict confidentiality.

2.7 Disclosure and Deletion

The sharing and deletion of data are also important and sensitive topics. Therefore, we would like to briefly inform you in advance about our general approach.

Data is only shared on a legal basis and only when it is unavoidable. This may particularly be the case if a so-called data processor is involved and a data processing agreement has been concluded pursuant to Art. 28 GDPR.

We delete your data when the purpose and legal basis for processing cease to apply, and no other legal obligations prevent deletion. A good overview of this is also provided by Art. 17 GDPR.

For any further information, please refer to this privacy policy or contact the controller directly with specific questions.

2.8 Hosting

IONOS

The IONOS service, offered by IONOS Group SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, is used to host this website. IONOS provides the technical infrastructure required to make the website accessible and enables additional functions such as domain management, email communication, and the provision of cloud and storage solutions. Typically, the following personal data is processed during hosting: referrer (previously visited website), accessed website or file, browser type and version, operating system, device type, time of access, and anonymized IP address for location determination. If website operators use additional functions such as contact forms or e-commerce integrations, communication content and order data may also be processed.

The processing is carried out for the purpose of technical operation and delivery of the website, ensuring security and stability, and, if applicable, enabling communication and processing inquiries and orders. The legal basis for this processing is Art. 6 Abs. 1 lit. f GDPR, based on the legitimate interest in the secure and efficient provision of the website. If data is transmitted via forms (e.g., contact requests, orders), Art. 6 Abs. 1 lit. b GDPR applies. Insofar as consent is required for specific functionalities, processing is based on Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG.

According to the current status, IONOS does not set any cookies in standard hosting that are relevant to website visitors. If individual additional services (e.g., SiteAnalytics) use cookies, they are only deployed with consent and on the basis of Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG. A transfer of personal data to third countries does not take place within the framework of IONOS standard hosting, as processing generally occurs within the European Union. Stored data will be deleted as soon as it is no longer required to achieve the purpose of its collection or legal retention periods have expired. In the event that consent is revoked, the relevant data will be deleted immediately, provided that no legal retention obligations prevent this. Further information can be found at: https://ionos-group.com.

2.9 Legal Bases

The processing of personal data always requires a legal basis. Art. 6 Abs. 1 Sentence 1 of the GDPR provides the following options:

  • a) The data subject has given consent to the processing of his or her personal data for one or more specific purposes;
  • b) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
  • c) Processing is necessary for compliance with a legal obligation to which the controller is subject;
  • d) Processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • e) Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • f) Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will specify the concrete legal basis for each respective processing operation.

3. What Happens on Our Website

By visiting our website, we process your personal data.

To protect this data as best as possible against unauthorized access by third parties, we use SSL or TLS encryption. You can recognize this encrypted connection by the https:// prefix or the lock symbol in your browser’s address bar.

Below you will learn what data is collected when visiting our website, for what purpose this happens, and on what legal basis.

3.1 Data Collection When Accessing the Website

When you access the website, information is automatically saved in so-called server log files. This includes the following information:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is temporarily required to display our website to you permanently and without problems. In particular, this data serves the following purposes:

  • System security of the website
  • System stability of the website
  • Troubleshooting on the website
  • Establishing a connection to the website
  • Displaying the website

Data processing is carried out in accordance with Art. 6 Abs. 1 lit. f GDPR and is based on our legitimate interest in processing this data, particularly our interest in the functionality and security of the website.

Where possible, this data is stored using pseudonyms and deleted once the respective purpose has been achieved.

Insofar as the server log files allow the identification of the data subject, the data is stored for a maximum period of 14 days. An exception applies if a security-related event occurs. In this case, the server log files are stored until the security-related event has been resolved and fully clarified.

Furthermore, this data is not merged with other data sources.

3.2 Data Processing via User Input

3.2.1 Contacting Us

a) Email
When you contact us by email, we process your email address and any other data contained in the message. These are stored on the mail server and partially on the respective end devices. Depending on the nature of your request, the legal basis for this is regularly Art. 6 Abs. 1 lit. f GDPR or Art. 6 Abs. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose ceases to apply and deletion is possible in accordance with legal regulations.

b) Contact Form
Elementor
The Elementor service is used on this website to provide and manage contact forms. Elementor is operated by Elementor Ltd., Thobal 40, Ramat Gan, Israel. The service enables the creation and integration of forms used to handle communication inquiries and other inputs via the website. Personal data such as names, email addresses, message content, as well as any other fields defined by the website operator and, if required, file attachments are regularly processed via these forms.

The data is processed to handle incoming contact requests, for further communication, and to manage and archive interactions. The basis for data processing is Art. 6 Abs. 1 lit. b GDPR, provided the request is aimed at initiating or executing a contract, as well as Art. 6 Abs. 1 lit. f GDPR based on the legitimate interest in efficient communication with website visitors. Elementor does not deploy cookies by default in connection with contact forms; however, functional or analytical cookies may be used through third-party integrations or additional widgets, depending on the specific configuration and legal basis. Data is not transmitted to third countries unless an additional integration with external services is active; in standard operation, the data remains on the web server where the website is hosted. A transfer of personal data to Elementor Ltd. in Israel does not fundamentally take place through form usage alone. Personal data will be deleted as soon as the purpose of its collection ceases to apply, no further statutory retention obligations exist, or consent has been revoked. Further information can be found in Elementor’s privacy policy at: https://elementor.com.

3.3 Analysis and Tracking Tools

(No entries in this section)

3.4 Social Media Plugins

Apple Music

The social media service Apple Music is integrated into our website, operated by Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, T23 YK84, Ireland. Apple Music allows the playback of music as well as the presentation and sharing of playlists, albums, or songs via an embedded web player or marketing widgets. When using the Apple Music player, the IP address (in shortened form), browser and device information, the domain of the embedding page, unique identifiers of the web player or browser (if not logged in, no link to the Apple ID occurs), as well as music usage behavior and interactions with player functions are processed.

The processing of data serves the provision of streaming content, the analysis of interactions, abuse prevention, and the optimization of the service. The legal basis is, depending on the constellation, Art. 6 Abs. 1 lit. f GDPR (legitimate interest in attractive content presentation and reach analysis) as well as Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG (consent) when embedding components and analysis functions that are not technically mandatory. Apple Music can set technically necessary cookies and, upon consent, also analysis cookies. Non-essential cookies are only set after express consent. When using the service, personal data may be transferred to the USA or other third countries. EU Standard Contractual Clauses are used as guarantees to ensure an adequate level of data protection. The storage period of the data depends on the purpose of processing; it is deleted as soon as the purpose ceases to apply or consent is revoked, provided no statutory retention periods conflict. Further information on data processing by Apple Music can be accessed at: https://apple.com.

Discord

We use functions of Discord on our website, a service for community management and social interaction provided by Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands. Discord makes it possible to provide community engagement, notifications, authentication (e.g., via OAuth2), and the integration of chat and feedback widgets. In particular, information such as username, email address, IP address, browser type, device information, interaction data (e.g., messages, invitations, actions), information from forms or webhooks, as well as technical identifiers and cookies are processed.

The processing serves to enable interactions with communities, provide participation in chats, send notifications, and technically implement authentication processes. The legal basis is regularly Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG (if consent is required, such as when using cookies or for social media functions), or alternatively Art. 6 Abs. 1 lit. f GDPR based on the legitimate interest in the efficient provision of communication and community functions. Discord uses cookies and similar technologies for technical, functional, and potentially analytical or marketing purposes. In accordance with § 25 Abs. 1 TDDDG, these may only be activated with the express consent of the user. Data transfer to third countries, particularly the USA, is possible. Discord safeguards the transfer by concluding the EU Standard Contractual Clauses. Personal data is generally deleted as soon as the purpose of the processing ceases to apply, consent has been revoked, or statutory retention periods end. Further notes on data processing can be found at: https://discord.com.

Facebook

Social media functions from Facebook are integrated into our website, a service of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Facebook enables the integration of social sharing functions, embedded content like posts or videos, comment functions, and logging in via „Login with Facebook“. Due to the integration, the IP address, device and browser information, cookies or other identifiers, visited pages, click and interaction data, and – when using the Facebook Login – Facebook profile information and possibly email addresses are generally processed.

The data processing is carried out for the purpose of improving the user-friendliness of our website, enabling social interactions, targeted advertising, and analyzing website usage. The legal basis is regularly Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG, provided consent is granted for social plugins and tracking; otherwise, the deployment is based on Art. 6 Abs. 1 lit. f GDPR due to legitimate interests in reach analysis and user-oriented provision of content. Facebook sets cookies for analysis, marketing, and functional purposes. Cookies that are not strictly necessary are only used with express consent. If data is transferred to third countries outside the EEA, particularly the USA, during the use of Facebook services, this is done on the basis of the EU Standard Contractual Clauses. The data is deleted as soon as the purpose of processing ceases to apply, consent is revoked, or statutory retention obligations expire. Further information on the processing of personal data by Facebook can be found at: https://facebook.com.

Instagram

Functions of Instagram are integrated into our website, a social media service for sharing photos and videos operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin, Dublin 2, Ireland. Instagram enables the display of and interaction with public Instagram content, such as feeds, posts, and hashtag campaigns directly on the website, to support brand loyalty, user interactions, and marketing measures. In doing so, public content (photos, videos, reels), profile information, engagement data (likes, comments, clicks, impressions), and interaction data with the integrated elements are generally processed. In the case of authenticated interfaces, further analytical data may also be processed.

The purpose of the processing is to increase reach, display user-generated content, promote brand loyalty, and marketing. The legal basis for data processing is generally consent according to Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG, provided the integration of Instagram elements allows tracking as soon as the page loads; otherwise, a legitimate interest according to Art. 6 Abs. 1 lit. f GDPR in the integration and presentation of social media content may exist. Instagram uses cookies and similar technologies for analysis, marketing, and personalization purposes. These cookies are only set based on prior consent, which can be revoked at any time. The legal basis for their use is Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG. When using Instagram, personal data may be transferred to Meta in the USA and other third countries. Instagram/Meta uses the EU Standard Contractual Clauses in accordance with Art. 46 GDPR as appropriate safeguards. Stored data will be deleted as soon as it is no longer required for the purposes of collection or consent is revoked, unless statutory retention obligations prevent this. Further information can be found in Instagram’s data policy: https://about.instagram.com/data-policy.

SoundCloud

The social media service SoundCloud is utilized on our website, operated by SoundCloud Global Limited & Co. KG, Karl-Marx-Strasse 101, 12043 Berlin, Germany. SoundCloud enables the integration and playback of music, playlists, and podcasts directly on the website. When using SoundCloud widgets, personal data such as IP address, device information, browser type, operating system, access times, interaction data with the player (e.g., playback processes, clicks, comments), and the referring website are collected.

The purpose of processing is the provision and improvement of audio content, the analysis of usage, and the optimization of the offer. The legal bases for data processing are Art. 6 Abs. 1 lit. a GDPR and § 25 Abs. 1 TDDDG, insofar as consent is required for setting cookies and transmission, as well as Art. 6 Abs. 1 lit. f GDPR for legitimate interests in the user-friendly provision of multimedia content. SoundCloud sets cookies during integration, particularly for analysis and marketing purposes. These cookies are only set with express consent. When using SoundCloud widgets, personal data is transmitted to servers in third countries, particularly the USA. SoundCloud uses the EU Standard Contractual Clauses as guarantees; nevertheless, a full data protection level in the USA cannot be completely guaranteed. Stored data is generally deleted as soon as it is no longer required for the purposes of processing, but at the latest upon expiration of statutory retention periods. Following a revocation of consent or a legitimate deletion request, deletion takes place in accordance with SoundCloud policies. Further information can be found at: https://soundcloud.com.

Spotify

Social media functions from Spotify are integrated into our website, provided by Spotify AB, Regeringsgatan 19, 5tr, 111 53 Stockholm, Stockholms Län, Sweden. Spotify enables the integration of music, podcast, and audiobook previews as well as interaction through embeds, widget elements, and sharing functions to and from social networks. When using these functions, device and browser information (such as UserAgent, operating system version, device type), IP address, as well as data on playbacks and impressions (including timestamps, track or podcast IDs, and potentially ad contacts) are processed.

The purpose of processing is the provision of social media functions, content sharing, interaction analysis, and improving the user experience on the website. The legal bases for processing are Art. 6 Abs. 1 lit. a GDPR (provided consent is obtained via consent management, particularly for optional analysis or third-party cookies) as well as Art. 6 Abs. 1 lit. f GDPR to safeguard the legitimate interest in user-friendly design and interaction analysis. Spotify sets cookies when embeds or social plugins are used, particularly to analyze interaction behavior and provide individualized content; their use occurs exclusively on the basis of granted consent according to Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG and can be revoked at any time. A transfer of personal data to third countries (outside the EU/EEA) by Spotify may occur; for these cases, Spotify uses the EU Standard Contractual Clauses as appropriate guarantees. Data is only stored as long as necessary for the stated purposes or until consent is revoked; statutory retention periods remain unaffected. Further information can be viewed at: https://spotify.com.

TikTok

Functions of TikTok are integrated into this website, a social network for publishing and interacting with video content, operated by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. The service enables the embedding of TikTok videos or feeds, content sharing, and measuring engagement, for example via the TikTok Pixel for usage analysis and conversion tracking. In particular, browser and device information (e.g., IP address, browser type, operating system), interaction data on accessed content, click and navigation behavior, TikTok-specific identifiers (such as TikTok Click IDs), technically necessary as well as analytical and marketing information from cookies, and potentially user-provided data such as email addresses for matching or target group alignment are processed.

The processing takes place for the purpose of providing social media content, reach measurement, marketing, target-group-specific advertising, and improving the website user experience. The legal basis for optionally embedded interactions and tracking mechanisms is regularly consent according to Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG; for technically necessary components required for display, Art. 6 Abs. 1 lit. f GDPR may apply. When TikTok functions are embedded, cookies can be set for functional as well as analytical and marketing purposes; these are used exclusively on the basis of a corresponding consent and can be revoked at any time via the cookie settings. A transfer of personal data to third countries, particularly to companies affiliated with TikTok outside the EU (e.g., USA, Singapore), cannot be excluded. In these cases, transfers occur on the basis of the EU Standard Contractual Clauses as appropriate safeguards within the meaning of Art. 46 Abs. 2 lit. c GDPR. Data is deleted as soon as it is no longer required for the stated purposes or a granted consent has been revoked, provided no statutory retention obligations conflict. Further information on data processing by TikTok and exercising your rights is provided in the privacy policy at: https://tiktok.com.

YouTube

Video content via the YouTube service is integrated into this website, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube enables the display of videos directly on the website, whereby multimedia content is provided for information and entertainment and user engagement can be strengthened. Personal data is regularly processed, including IP address, browser and device information, usage data such as playback and interaction behavior, and potentially account-related data if users are logged into a Google or YouTube account during use.

3.5 Third-Party Content

Elementor

We use the page builder plugin Elementor on our website, operated by Elementor Ltd., Israel. Elementor enables the visual design and editing of website content via a drag-and-drop interface as well as the creation of forms, popups, and design elements. When using Elementor, server- and system-related information such as software and versioning data, WordPress settings (e.g., permalinks, language, themes, plugins), the website URL, the email address of the WordPress administration, and – when using form functions – the content entered there, IP address, and user agent are processed. Form-related data is stored locally on our own web server by default and is not transmitted to Elementor.

The processing takes place for the purpose of provision, error analysis, and continuous optimization of website functions. The legal basis is Art. 6 Abs. 1 lit. f GDPR, the legitimate interest in attractive website design and functional content management, as well as potentially Art. 6 Abs. 1 lit. b GDPR for pre-contractual communication via forms. According to the current status, Elementor itself does not set cookies for website visitors unless additional functions or integrations from third-party providers are used within Elementor. No transfer of personal data to third countries by Elementor takes place, as all regular data processing is handled locally on the web server. A transfer to third states can occur in exceptional cases if integrations are made that explicitly provide for this; in this case, appropriate guarantees such as the EU Commission’s Standard Contractual Clauses are deployed. The data will be deleted as soon as the processing purpose ceases to apply, at the latest upon a deletion request or revocation, provided no statutory retention periods conflict. Further information is available at: https://elementor.com.

Google Fonts

Fonts from the Google Fonts service are deployed on our website, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Fonts makes it possible to integrate fonts directly from Google servers in order to provide uniform and appealing typography as well as optimal loading times via a Content Delivery Network (CDN). Within the scope of integration, the IP address of the website visitor, the requested font resource, and HTTP header information such as user agent and referrer are processed.

The purpose of data processing is the technical provision of fonts, improving design, and optimizing display across different devices and browsers. The legal basis for data processing is Art. 6 Abs. 1 lit. f GDPR, as there is a legitimate interest in an appealing and consistent website design as well as a technically secure and efficient provision. According to current information, Google Fonts does not set cookies to provide the fonts. A transfer of personal data to third countries does not take place, as processing, according to Google, is carried out in Europe by Google Ireland Limited. Personal data is only stored as long as necessary for the provision of the fonts and the security of the service; when the purpose ceases to apply or upon a legitimate deletion request, the data is deleted, provided no statutory retention obligations conflict. Further information is available at: https://google.com.

Essential Addons for Elementor

Essential Addons for Elementor is used on this website, a plugin for expanding the Elementor website builder with additional widgets and content. The provider is WPDeveloper Ltd., 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. The plugin provides various visual elements, layouts, content, and design functions, including widgets for dynamic content, contact and login forms, social media feeds, visual effects, and expansions for e-commerce presentations on the website. Depending on the chosen widget and integration, different categories of personal data may be processed, such as IP address, browser information, form data like names and contact details, content from social media profiles, or newsletter subscription data, provided these are entered through the use of corresponding widgets.

The processing takes place for the purpose of providing dynamic website content, user interaction, integrating external services, and optimizing page functionality. The legal basis is, depending on the constellation, Art. 6 Abs. 1 lit. b GDPR (contract performance, pre-contractual measures), Art. 6 Abs. 1 lit. f GDPR (legitimate interest in user-friendly content design, optimization of the website presence), or – in the case of coordinated use of functions requiring consent – Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG (such as for newsletter registrations or tracking). Essential Addons for Elementor itself does not set its own cookies via basic functions according to current knowledge, but can – depending on active widgets or integrated third-party services – use third-party functional or marketing cookies. In these cases, the use of such cookies occurs exclusively on the basis of previously obtained consent according to Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG. Insofar as a transfer of personal data to the United Kingdom takes place within the framework of individual functions, this occurs on the basis of the European Commission’s adequacy decision according to Art. 45 GDPR for the United Kingdom. A transfer to other third countries by Essential Addons for Elementor itself does not take place. Personal data is deleted as soon as the purpose of processing ceases to apply, a revocation or objection occurs, or statutory retention obligations expire. Further information on the service’s data protection can be found at: https://essential-addons.com.

3.6 Online Marketplaces

We sell goods or services on online marketplaces. For this purpose, we rely on the following providers:

Fiverr

We use functions of Fiverr on our website, an international online marketplace for digital services operated by Fiverr International Ltd., Unit 6, Damien House, The Circle, Dublin 18, D18 H070, Ireland. Fiverr enables the integration of widgets, gig carousels, affiliate links, and the display of customer reviews or testimonials through plugins or custom-developed integrations. In addition, interactive functions, chatbots, or workflow automations acquired via Fiverr can be provided on the website. When using this service, the following personal data is typically processed: name, email address, phone number, profile information, browser and device information, IP address, transaction data, usage and behavioral data (e.g., click patterns, search behavior), communication content, and, if required, verification data such as a photo ID or official documents.

The data processing is carried out for the purpose of providing and optimizing marketplace functions, automating business processes, commission billing for affiliate integrations, proof of transactions, communication between users and service providers, as well as for analysis purposes. The legal basis for processing is Art. 6 Abs. 1 lit. b GDPR for contract fulfillment, Art. 6 Abs. 1 lit. f GDPR on the basis of legitimate interest in the efficient provision of digital marketplace functions, as well as potentially Art. 6 Abs. 1 lit. a GDPR and § 25 Abs. 1 TDDDG, provided consent is granted for the use of non-necessary cookies or similar technologies. Fiverr can use cookies for functional, analysis, and marketing purposes. Cookies that are not required for technical provision are only used with consent. The legal basis for this is Art. 6 Abs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG. A transfer of personal data to third countries can occur, particularly if Fiverr uses services or subcontractors outside the European Economic Area (EEA). Insofar as data is transferred to third countries, this is done on the basis of the EU Commission’s Standard Contractual Clauses as an appropriate guarantee under Art. 46 GDPR. Data is deleted as soon as the purpose of processing ceases to apply, a granted consent is revoked, or statutory retention periods expire. Further information can be extracted from Fiverr’s privacy policy at: https://fiverr.com.

4. Other Important Matters

In conclusion, we would like to inform you thoroughly and in detail about your rights and let you know how you will be informed about changes to data protection requirements.

4.1 Your Rights in Detail

4.1.1 Right of Access under Art. 15 GDPR

You can request confirmation as to whether or not personal data concerning you is being processed. If that is the case, you can demand further information regarding the nature and manner of the processing. A detailed list can be found in Art. 15 Abs. 1 lit. a to h GDPR.

4.1.2 Right to Rectification under Art. 16 GDPR

This right includes the correction of inaccurate data and the completion of incomplete personal data.

4.1.3 Right to Erasure under Art. 17 GDPR

This so-called „right to be forgotten“ gives you the right, under certain conditions, to demand the deletion of personal data by the controller. This is generally the case if the purpose of the data processing has ceased to apply, if consent has been revoked, or if the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 Abs. 1 lit. a to f GDPR. This „right to be forgotten“ also corresponds with the controller’s obligation under Art. 17 Abs. 2 GDPR to take reasonable steps to bring about a general deletion of the data.

4.1.4 Right to Restriction of Processing under Art. 18 GDPR

This right is tied to the conditions pursuant to Art. 18 Abs. 1 lit. a to d GDPR.

4.1.5 Right to Data Portability under Art. 20 GDPR

This regulates the fundamental right to receive one’s own data in a structured, commonly used format and to transmit it to another controller. However, this only applies to data from processing based on consent or a contract pursuant to Art. 20 Abs. 1 lit. a and b GDPR and insofar as this is technically feasible.

4.1.6 Right to Object under Art. 21 GDPR

You can fundamentally object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the controller’s legitimate interest in processing and if the processing relates to direct marketing and/or profiling.

4.1.7 Right to „Decision in Individual Cases“ under Art. 22 GDPR

You fundamentally have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right also finds restrictions and additions in Art. 22 Abs. 2 and 4 GDPR.

4.1.8 Other Rights

The GDPR includes comprehensive rights to inform third parties as to whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as it is possible or feasible with a reasonable effort.

At this point, we would like to remind you again of your right to revoke any consent granted under Art. 7 Abs. 3 GDPR. The lawfulness of the processing carried out up to that point remains unaffected by this.

Furthermore, we would also like to point out your rights under §§ 32 et seq. BDSG, which, however, are largely identical in content to the rights just described.

4.1.9 Right to Lodge a Complaint under Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this regulation.

5. What Happens If the GDPR Is Abolished Tomorrow or Other Changes Take Place?

The current status of this privacy policy is July 3, 2026. From time to time, it is necessary to adjust the content of the privacy policy to react to factual and legal changes. We therefore reserve the right to change this privacy policy at any time. We will publish the amended version in the same place and recommend that you read the privacy policy regularly.