Data Protection

Information on how we collect, use, and protect your personal data.

Controller and Contact

Controller within the meaning of the General Data Protection Regulation (GDPR) is:

dealspec UG (haftungsbeschränkt)
c/o The Delta Campus
Donaustraße 44
12043 Berlin
Germany

Represented by the managing directors: Christopher Mezler, Vincent Favro
Email: info@dealspec.de
Commercial register: Local Court (Amtsgericht) of Charlottenburg, HRB 289299 B

We have not appointed a data protection officer, as the requirements of Section 38 BDSG (German Federal Data Protection Act) do not currently apply to us. For all data protection matters, you can reach us at the address above or by email at info@dealspec.de.

Your Rights

With regard to your personal data, you have the following rights against us:

  • Access (Art. 15 GDPR): You can find out whether and which data we process about you.
  • Rectification (Art. 16 GDPR): You can have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17 GDPR): You can request the erasure of your data, unless statutory retention obligations conflict.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR): You can receive the data you have provided in a structured, commonly used and machine-readable format.
  • Withdrawal of consent (Art. 7(3) GDPR): You can withdraw consent you have given at any time with effect for the future. The lawfulness of the processing carried out until then remains unaffected.

 

Right to object under Art. 21 GDPR

Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

Where we process your data for direct marketing purposes, you can object at any time without giving reasons. Your data will then no longer be used for this purpose.

Exercising your rights

A message to info@dealspec.de is sufficient. We respond without undue delay, at the latest within one month of receiving your request. This period may be extended by a further two months where necessary due to the complexity or number of requests; in that case we will inform you of the extension and its reasons.

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin
https://www.datenschutz-berlin.de

Provision of the Website and Server Log Files

When you access this website, your browser automatically transmits data to our hosting provider. The following in particular is collected:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the file retrieved
  • Referrer URL
  • Browser type and version
  • Operating system
  • Amount of data transferred and notification of successful retrieval

 

This processing is technically necessary to deliver the website, ensure its stability and security and defend against attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the secure and trouble-free operation of the website.

Hosting

The website is operated by Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA. Webflow processes the above data as a processor under Art. 28 GDPR on our behalf; the basis is Webflow's Data Processing Addendum. Webflow is certified under the EU-U.S. Data Privacy Framework; the European Commission has determined an adequate level of data protection for certified companies. Standard contractual clauses apply in addition.

Images and editorial content of this website are delivered via Webflow's content management system and delivery network. In doing so, your IP address may be transmitted to server locations outside the European Union, because this is technically necessary to deliver the content to your browser.

Privacy policy: https://webflow.com/legal/eu-privacy-policy   Data Processing Agreement (DPA): https://webflow.com/legal/dpa

Server log files are deleted after 30 days at the latest.

Consent Management

When you first access our website, you receive a notice through which you can decide on the use of cookies and comparable technologies. All services that are not technically necessary are only loaded after you have given your consent.

For documentation purposes, we store the time of your decision, the categories you selected and the version of the notice. The associated cookie has a lifetime of six months; we retain proof of your decision for twelve months. The legal basis is Art. 6(1)(c) GDPR in conjunction with our accountability obligation under Art. 7(1) GDPR.

You can change or withdraw your decision at any time via the “Cookie settings” link in the footer of every page.

The legal basis for storing information on your device and accessing it is Section 25(1) TDDDG (consent) or Section 25(2) TDDDG, insofar as the storage is strictly necessary to provide a service expressly requested by you.

Cookies and Similar Technologies

We use cookies and comparable technologies such as localStorage in two categories.

Technically necessary

These enable the basic operation of the website, for example storing your language selection and your cookie decision, as well as cookies that our hosting provider sets to secure and deliver the site. They are set without consent, Section 25(2) no. 2 TDDDG; the legal basis for the subsequent processing is Art. 6(1)(f) GDPR.

Requiring consent

All technologies for analytics, reach measurement and marketing. We use these exclusively after your consent, Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

An overview of the cookies used, with name, purpose and lifetime, can be found in the cookie settings.

You can also delete cookies in your browser or generally restrict their storage. If cookies are blocked entirely, individual functions of this website may be limited.

We do not respond separately to “Do Not Track” signals from your browser, as there is no uniform standard for this. Your decision in the consent notice is decisive.

Contact and Appointment Booking

Contact form

When you write to us via the form on our contact page, we process the data you enter:

  • Name
  • Email address
  • Company
  • Your message

In addition, we store the time of submission.

The purpose is to process and respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR, insofar as your enquiry is aimed at concluding or performing a contract, otherwise Art. 6(1)(f) GDPR with our legitimate interest in answering enquiries.

The form submissions are stored in our website backend at Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA, which acts as a processor for us under Art. 28 GDPR. Webflow is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses under Art. 46(2)(c) GDPR apply in addition.

Privacy policy: https://webflow.com/legal/eu-privacy-policy   Data Processing Agreement (DPA): https://webflow.com/legal/dpa

Email and telephone

If you contact us directly by email or telephone, we process your contact details and the content of your message for the same purpose and on the same legal basis.

Appointment booking

To arrange meetings we use Calendly. When you click “Book a call” on our contact page, you are redirected to a Calendly page. Data is only transmitted to Calendly when this page is called up; no Calendly script is embedded on our own website.

Provider: Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. When booking, we process your name, email address, the selected appointment and the information you provide in order to organise the meeting. The legal basis is Art. 6(1)(b) GDPR. Calendly acts as a processor for us; the transfer to the USA is based on the EU-U.S. Data Privacy Framework or, in addition, on standard contractual clauses.

Privacy policy: https://calendly.com/legal/privacy-notice

Deletion

We delete your enquiries as soon as they have been conclusively processed and no statutory retention obligations conflict, but at the latest 24 months after the last contact.

Newsletter

If you subscribe to our newsletter, we process your email address in order to send you information about our services and content.

Registration takes place using the double opt-in procedure: after you register, you receive an email with a confirmation link. Only after your confirmation do we add you to the distribution list. To prove your consent, we store the time of registration, the time of confirmation and the IP address used.

The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with Section 7(2) no. 2 UWG (German Act Against Unfair Competition).

You can unsubscribe from the newsletter at any time, for example via the unsubscribe link at the end of every email. After unsubscribing, we remove your email address from the distribution list. We retain the proof of your consent until the expiry of any possible claims.

Applications

If you apply to us, we process the data you submit, in particular contact details, CV, references and other documents, exclusively to carry out the application process.

The legal basis is Section 26(1) BDSG in conjunction with Art. 88 GDPR and Art. 6(1)(b) GDPR.

If no employment results, we delete your documents six months after completion of the process. This period serves to defend against possible claims under the German General Equal Treatment Act (AGG); the legal basis in this respect is Art. 6(1)(f) GDPR. If you would like us to consider your documents for future positions beyond this, we obtain your separate consent for this.

Recipients and Transfer to Third Countries

We do not pass on your personal data to third parties for our own commercial purposes, do not sell it and do not rent it out.

Access to your data is granted exclusively to:

  • those employees of our company who need the data to perform their tasks,
  • the service providers named in this policy, whom we have bound as processors under Art. 28 GDPR,
  • authorities and courts, insofar as we are legally obliged to provide information.

Transfer to third countries

Some of the service providers we use are based outside the European Union, predominantly in the USA. For providers certified under the EU-U.S. Data Privacy Framework, the European Commission has determined an adequate level of protection by decision of 10 July 2023. In all other cases, we base the transfer on standard contractual clauses under Art. 46(2)(c) GDPR and, where applicable, on your explicit consent under Art. 49(1)(a) GDPR.

We point out that third countries need not have a level of data protection fully comparable to that of the EU and that access by state authorities cannot be excluded in every case.

You can find which service providers we use, where they are based and what the respective transfer is based on in Section 3 and Section 6.

Business transfer

Should we become part of a merger, acquisition or company sale, personal data may pass to the acquirer. We ensure that this takes place while maintaining confidentiality, and inform affected persons in advance on our website or by email.

Retention Period

We store personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations.

For documents of tax or commercial-law relevance, the retention periods under Section 147 AO (German Fiscal Code) and Section 257 HGB (German Commercial Code) apply. After the respective period has expired, we delete the data or restrict its processing.

You can find the specific retention periods of the individual processing activities in the respective sections of this policy.

Data Security

The transmission of data between your browser and our website is encrypted via TLS. You can recognise this by the address bar of your browser.

We take technical and organisational measures under Art. 32 GDPR to protect your data against unauthorised access, loss and alteration, and continuously adapt them to the state of the art. Complete protection against all conceivable attacks is technically not achievable.

In the event of a personal data breach, we fulfil our notification obligations under Art. 33 and 34 GDPR.

Changes to this Policy

We adapt this privacy policy when our processing activities or the legal framework change. The version published on this page applies in each case. We additionally inform about material changes on our website or by email.

If you have any questions, you can reach us at info@dealspec.de.

Dunkelblauer und schwarzer Verlaufshintergrund mit einem hellblauen Lichtschein unten rechts.

Start your journey

Clarity for every deal. Confidence in every decision.