By clicking “Accept all cookies”, you agree to the storage of cookies on your device. These are used to personalize our website for you as much as possible, analyze website usage, and improve our marketing. You can find detailed information in our  Privacy Policy.

Privacy Policy

Last updated: April 28, 2026

Controller

The controller responsible for the processing of personal data in connection with our website, mobile application (app), and all services within the meaning of the General Data Protection Regulation (GDPR) is:

Palary GmbH

Propststr. 810178 Berlin

Email address: info@palary.io

Relevant legal bases

Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or business. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.

  • Consent (Art. 6 (1) sentence 1 lit. a) GDPR) – the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 lit. b) GDPR) – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 (1) sentence 1 lit. c) GDPR) – processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 (1) sentence 1 lit. f) GDPR) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. This includes, in particular, the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG contains specific provisions regarding the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission, as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.

Security measures

In accordance with legal requirements and taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, input, disclosure, availability, and separation of the data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. We also take the protection of personal data into account during the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

Transmission of personal data

In the course of our processing of personal data, it may happen that this data is transmitted to other entities, companies, legally independent organizational units, or persons, or disclosed to them. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.

General information on data storage and deletion

We delete personal data that we process in accordance with legal requirements as soon as the underlying consents are withdrawn or no other legal basis for processing exists. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply if legal obligations or specific interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the assertion of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.

Our privacy policy contains additional information on data retention and deletion that applies specifically to certain processing operations. If multiple retention periods or deletion deadlines are provided for a specific set of data, the longest period shall always apply.

If a period does not explicitly begin on a specific date and lasts for at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships during which data is stored, the event triggering the period is the date on which the termination or other end of the legal relationship becomes effective.

Data that is no longer required for its original purpose but is retained due to legal requirements or other reasons will be processed exclusively for the reasons that justify its retention.

Data retention and deletion: The following general periods apply to retention and archiving under German law:

  • 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, as well as the work instructions and other organizational documents required to understand them, accounting vouchers, and invoices (Section 147(3) in conjunction with (1) nos. 1, 4, and 4a AO; Section 14b(1) of the German Value Added Tax Act (UStG); Section 257(1) nos. 1 and 4, (4) HGB).
  • 6 years – Other business documents: received commercial or business letters, copies of sent commercial or business letters, and other documents relevant for taxation purposes, e.g., hourly wage slips, cost accounting sheets, calculation documents, price lists, as well as payroll documents (if not already accounting vouchers) and cash register tapes (Section 147(3) in conjunction with (1) nos. 2, 3, 5 of the German Fiscal Code (AO); Section 257(1) nos. 2 and 3, (4) of the German Commercial Code (HGB)).
  • 5 years / 3 years – Data required to account for potential warranty and damage claims or similar contractual claims and rights, as well as to process related inquiries based on past business experience and standard industry practices, will be stored for the duration of the regular statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).

Rights of data subjects

As a data subject under the GDPR, you have various rights, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right of access: You have the right to request confirmation as to whether relevant data is being processed, to access this data, and to receive further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: You have the right, in accordance with legal requirements, to request the completion of data concerning you or the correction of inaccurate data concerning you.
  • Right to erasure and restriction of processing: You have the right, in accordance with legal requirements, to request the immediate deletion of data concerning you, or alternatively to request a restriction on the processing of the data.
  • Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, or to request its transmission to another controller, in accordance with legal requirements.
  • Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you believe that the processing of your personal data violates the requirements of the GDPR.

Business services

We process data of our contractual and business partners, e.g., customers and prospective customers (collectively referred to as "contractual partners"), within the framework of contractual and comparable legal relationships as well as related measures and with regard to communication with the contractual partners (or pre-contractually), for example, to answer inquiries.

We use this data to fulfill our contractual obligations. This includes, in particular, the obligations to provide the agreed services, any update obligations, and remedies for warranty and other performance issues. Furthermore, we use the data to protect our rights and for the purpose of administrative tasks associated with these obligations as well as corporate organization. In addition, we process the data based on our legitimate interests in both proper and efficient business management and in security measures to protect our contractual partners and our business operations from misuse, threats to their data, secrets, information, and rights (e.g., for the involvement of telecommunications, transport, and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers, or financial authorities). Within the framework of applicable law, we only pass on the data of contractual partners to third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations.

We inform contractual partners about which data is required for the aforementioned purposes before or during data collection, e.g., in online forms, through special markings (e.g., colors) or symbols (e.g., asterisks or similar), or in person.

We delete data after the expiration of statutory warranty and comparable obligations, i.e., generally after four years, unless the data is stored in a customer account or must be retained for legal archiving purposes (e.g., generally ten years for tax purposes). Data disclosed to us by the contractual partner as part of an order is deleted in accordance with the specifications and generally after the order has been completed.

  • Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or telephone numbers); contract data (e.g., subject matter of the contract, term, customer category).
  • Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; communication; office and organizational procedures; business processes and administrative procedures.
  • Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legal obligation (Art. 6(1)(c) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).

Provision of the online service and web hosting

We process user data to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

  • Types of data processed: Usage data (e.g., page views and duration of stay, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, persons involved); log data (e.g., log files concerning logins or the retrieval of data or access times).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online service and user-friendliness; IT infrastructure; security measures.
  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR).

Collection of access data and log files: Access to our online service is logged in the form of "server log files." Server log files may include the address and name of the accessed websites and files, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and generally IP addresses and the requesting provider. Server log files can be used for security purposes, e.g., to prevent server overload (especially in the case of abusive attacks, so-called DDoS attacks), and to ensure server utilization and stability. Legal basis: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR). Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified.

Use of cookies

Cookies are small text files or other storage markers that store information on devices and read it from them. For example, to save login status in a user account, shopping cart contents in an e-shop, the content accessed, or the functions used on an online service. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online services, as well as creating analyses of visitor traffic.

Notes on consent: We use cookies in accordance with legal regulations. Therefore, we obtain prior consent from users unless it is not required by law. Permission is not necessary, in particular, if the storage and reading of information, including cookies, is strictly necessary to provide users with a telemedia service they have expressly requested (i.e., our online service). The revocable consent is clearly communicated to users and contains information regarding the respective cookie usage.

Storage duration: Regarding storage duration, a distinction is made between temporary cookies (session cookies) and permanent cookies. Temporary cookies are deleted at the latest after a user leaves an online service and closes their device (e.g., browser or mobile application). Permanent cookies remain stored even after the device is closed. Unless we provide users with explicit information about the type and storage duration of cookies, they should assume that these are permanent and that the storage duration can be up to two years.

Revocation and objection (opt-out): Users can revoke the consent they have given at any time and also object to the processing in accordance with legal requirements – including via their browser's privacy settings or the cookie settings in the footer of this page.

  • Legal bases: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); consent (Art. 6 (1) sentence 1 (a) GDPR).

Consent management solution: We use a consent management solution to obtain user consent for the use of cookies or the specified procedures and providers. This process is used to obtain, log, manage, and revoke consent. Users also have the option to manage and revoke their consent. Storage occurs on the server side and/or in a cookie (an "opt-in cookie") or by means of comparable technologies. Consent is stored for up to two years. Legal basis: Consent (Art. 6 (1) sentence 1 (a) GDPR).

Contact and inquiry management

When contacting us (e.g., by post, contact form, email, telephone, or via social media) as well as within the framework of existing user and business relationships, the information provided by the inquiring persons is processed to the extent necessary to respond to contact requests and any requested measures.

  • Types of processed data: Inventory data; contact details; content data (e.g., text or image messages and posts); usage data; meta, communication, and process data.
  • Data subjects: Communication partners.
  • Purposes of processing: Communication; organizational and administrative procedures; feedback; provision of our online services and user-friendliness.
  • Legal basis: Legitimate interests (Art. 6 (1) sentence 1 (f) GDPR); performance of a contract and pre-contractual inquiries (Art. 6 (1) sentence 1 (b) GDPR).

Contact form: When contacting us via our contact form, email, or other communication channels, we process the personal data provided to us to respond to and handle the respective request. This generally includes information such as name, contact details, and any other information shared with us that is necessary for appropriate processing. We use this data exclusively for the stated purpose of contact and communication.

Newsletters and electronic notifications

We send newsletters, emails, and other electronic notifications (hereinafter "newsletters") exclusively with the recipient's consent or based on a legal basis. If the contents of the newsletter are described during registration, these contents are decisive for the user's consent. Providing your email address is generally sufficient for signing up for our newsletter. To provide you with a personalized service, we may ask for your name for personal address in the newsletter or for further information if it is necessary for the purpose of the newsletter.

Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to be able to prove that consent was previously given. Processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently respect opt-outs, we reserve the right to store the email address solely for this purpose in a blocklist.

  • Types of processed data: Inventory data; contact details; meta, communication, and process data; usage data.
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g., via email or post).
  • Legal basis: Consent (Art. 6(1)(a) GDPR).
  • Right to object (opt-out): You can cancel your subscription to our newsletter at any time, i.e., withdraw your consent or object to receiving further newsletters. You will find a link to unsubscribe at the end of every newsletter, or you can use one of the contact methods provided, preferably email.

Measurement of open and click rates: The newsletters contain a "web beacon," which is a pixel-sized file that is retrieved from our server or that of our service provider when the newsletter is opened. During this retrieval, technical information, your IP address, and the time of retrieval are collected. This information is used to technically improve our newsletter and to analyze target groups and their reading behavior. Legal basis: Consent (Art. 6(1)(a) GDPR).

Promotional communication via email, mail, fax, or telephone

We process personal data for promotional communication purposes, which may take place via various channels such as email, telephone, mail, or fax, in accordance with legal requirements. Recipients have the right to withdraw their consent or object to promotional communication at any time.

Following a withdrawal of consent or an objection, we will store the data required to prove previous authorization for contact or delivery for up to three years after the end of the year in which the withdrawal or objection occurred, based on our legitimate interests. The processing of this data is limited to the purpose of potentially defending against claims.

  • Purposes of processing: Direct marketing; marketing; sales promotion.
  • Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Services and service providers used:

Sendinblue (Brevo): We use the service Brevo (formerly Sendinblue) to send email newsletters and marketing emails. The service provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany (part of the Brevo Group, headquartered in France). When you subscribe to our newsletter, your email address and any other information you provide (e.g., first and last name) are transmitted to and stored by Brevo. We use the double opt-in procedure. Brevo also allows us to perform pseudonymized analysis of newsletter delivery. Legal basis: Consent (Art. 6(1)(a) GDPR in conjunction with Section 7(2) No. 3 of the German Act Against Unfair Competition (UWG)). Brevo primarily processes data within the EU (Germany and France); transfers to third countries only occur using Standard Contractual Clauses (SCCs). Your data will be stored as long as you are subscribed to the newsletter. Privacy policy: brevo.com/legal/privacypolicy. Data processing agreement: brevo.com/legal/termsofuse.

HubSpot: We use HubSpot as a customer relationship management (CRM) system, marketing automation platform, and for customer service functions. The service provider is HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA, with offices in Ireland (HubSpot Ireland Limited, One Dockland Central, Guild Street, Dublin 1, Ireland) and Germany (HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin). HubSpot enables us to manage customer relationships, process contact requests, conduct marketing campaigns, and optimize our communication with customers and prospects. Types of data processed: Inventory data, contact data, content data, usage data, communication data, contract data. Legal bases: Consent (Art. 6(1)(a) GDPR), performance of a contract (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR). HubSpot also processes data on servers in the USA; the security of data transfers is ensured by the EU Commission's Standard Contractual Clauses (SCCs), and HubSpot is also a member of the EU Cloud Code of Conduct. Retention period: Requests from users with an account or contract are stored until two years after the end of the contract; statutory archiving obligations (6 years for commercial law, 10 years for tax law) remain unaffected. Privacy policy: legal.hubspot.com/privacy-policy. Data processing agreement: legal.hubspot.com/dpa.

Web analytics, monitoring, and optimization

Web analytics (also referred to as "reach measurement") is used to evaluate visitor traffic to our online services and may include visitor behavior, interests, or demographic information as pseudonymized values. In addition to web analytics, we may also use testing procedures to test and optimize different versions of our online services.

In addition, users' IP addresses are stored. However, we use an IP masking procedure (pseudonymization by shortening the IP address) to protect our users. For web analytics, A/B testing, and optimization, we generally do not store clear data (such as email addresses or names) but rather pseudonyms.

  • Types of data processed: Usage data; meta, communication, and procedural data.
  • Data subjects: Users (e.g., website visitors).
  • Purposes of processing: Reach measurement; profiles with user-related information; provision of our online services and user-friendliness.
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6(1)(a) GDPR); legitimate interests (Art. 6(1)(f) GDPR).

Google Analytics: We use Google Analytics to measure and analyze the use of our online services based on a pseudonymous user identification number. Google Analytics does not log or store individual IP addresses for EU users; all IP requests are processed on EU-based servers before traffic is forwarded to Analytics servers for processing. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR). Basis for third-country transfers: Data Privacy Framework (DPF). Website: marketingplatform.google.com/analytics. Privacy policy: policies.google.com/privacy. Data processing agreement: business.safety.google/adsprocessorterms. Opt-out: tools.google.com/dlpage/gaoptout.

Webflow: We use the service Webflow to host and provide our website. The service provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA. When you visit our website, usage data as well as meta and communication data are recorded in server log files. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Data is processed on Webflow servers in the USA; the security of data transfers is ensured by Standard Contractual Clauses (SCCs) and Webflow's participation in the EU-U.S. Data Privacy Framework. Privacy policy: webflow.com/legal/privacy. Data processing agreement: webflow.com/legal/dpa.

Heroku: We use the Heroku platform to host our backend infrastructure and server applications. The service provider is Salesforce, Inc., Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA. Heroku enables the operation of our server applications and processes all data necessary for the functionality of our services (inventory, contact, contract, and usage data); Heroku is used in parallel with Supabase as part of our backend infrastructure. Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR). Data may be processed on servers in the USA or the EU region; Salesforce secures data transfers through Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs). Privacy policy: salesforce.com/company/privacy. Compliance information: heroku.com/compliance.

Firebase: We use the developer platform Firebase for services including Firebase Analytics, Firebase Cloud Messaging, Firebase Authentication, and Firestore/Realtime Database. For users in the EEA and Switzerland, the service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; the parent company is Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. When used, device-related information, pseudonymized IP addresses, authentication data, and app usage data are processed. Legal bases: Consent (Art. 6(1)(a) GDPR) for analysis and marketing purposes; performance of a contract (Art. 6(1)(b) GDPR) for functional purposes. Data may be transferred to Google servers in the USA, secured by Standard Contractual Clauses (SCCs). Privacy policy: policies.google.com/privacy. Processing terms: firebase.google.com/terms/data-processing-terms.

Typeform: We use Typeform to create and provide contact forms on our website and, if applicable, to collect employee data (if requested by the employer). The service provider is TYPEFORM S.L., Carrer Bac de Roda, 163, 08018 Barcelona, Spain. When you fill out a Typeform form, your entries and technical data (IP address, device information, timestamps) are transmitted to Typeform and stored there. Legal bases: Consent (Art. 6(1)(a) GDPR); pre-contractual measures (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR). Typeform processes data primarily within the EU (Spain); transfers to subcontractors outside the EU only occur with appropriate safeguards (e.g., Standard Contractual Clauses). Privacy policy: Typeform Privacy Policy. Data processing agreement: typeform.com/dpa.

DiPocket UAB (card-issuing financial institution): As part of our card program, we work with DiPocket UAB as the card-issuing financial institution. The service provider is DiPocket UAB, Lvivo str. 25-104, 09320 Vilnius, Lithuania, an e-money institution authorized by the Bank of Lithuania (license no. 75, issued on November 10, 2020). As a regulated card issuer, DiPocket UAB is an independent controller within the meaning of Art. 4(7) GDPR for all processing of personal data that DiPocket carries out to fulfill its regulatory obligations (including identity checks/KYC, anti-money laundering/AML, sanctions screening, transaction monitoring, and record-keeping obligations to the Bank of Lithuania and Visa). In this respect, DiPocket is not a data processor for Palary; joint controllership under Art. 26 GDPR only exists where Palary and DiPocket jointly decide on the means and purposes. Types of data transmitted: Inventory data, contact data, data required for onboarding and KYC (ID data, date of birth, identification documents), transaction data, and card-related data. Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legal obligations of DiPocket under Lithuanian and European regulatory law (Art. 6(1)(c) GDPR). DiPocket UAB processes data within the EU (Lithuania); transfers to third countries only take place in compliance with GDPR requirements. Data subjects may exercise their rights both against Palary and directly against DiPocket. Privacy policy: dipocket.org/en/privacy-policy.

Supabase: We use Supabase as our backend infrastructure platform (database hosting, authentication, and API services). The service provider is Supabase, Inc., 970 Toa Payoh North, #07-04, Singapore 318992. Supabase processes all data generated during the use of our services, including inventory, contact, contract, and usage data. Legal bases: Performance of a contract (Art. 6(1)(b) GDPR); legitimate interests (Art. 6(1)(f) GDPR). Supabase may process data on servers outside the EU; the security of data transfers is ensured by Standard Contractual Clauses (SCCs). Privacy policy: supabase.com/privacy. Data processing agreement: supabase.com/legal/dpa.

Yousign: We use Yousign for the electronic signing of contracts and documents. The service provider is Yousign SAS, Rue de Suède, Avenue Pierre Berthelot, 14000 Caen, France. As part of the electronic signature process, Yousign processes names, email addresses, phone numbers, IP addresses, and audit trail data generated during the signing process; Yousign creates a tamper-proof audit trail log for every signature process. Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); performance of a contract (Art. 6(1)(b) GDPR). The data in the audit trail is stored by the third-party archiver for a period of 10 years from creation. Yousign processes data exclusively within the EU. Privacy policy: yousign.com/privacy. GDPR information: yousign.com/gdpr.

Social media presences

We maintain online presences within social networks and process user data in this context to communicate with users active there or to offer information about us. Please note that user data may be processed outside the European Union, which may result in risks for users, for example, because the enforcement of user rights could be made more difficult.

Data from users within social networks is generally processed for market research and advertising purposes; user profiles can be created based on usage behavior and the resulting interests. For a detailed description of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.

  • Types of data processed: Contact details; content data; usage data.
  • Data subjects: Users (e.g., website visitors).
  • Purposes of processing: Communication; feedback; public relations.
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

LinkedIn: We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the subsequent processing) of data from visitors for the purpose of creating "Page Insights" (statistics) for our LinkedIn profiles. We have entered into a specific agreement with LinkedIn Ireland ("Page Insights Joint Controller Addendum"), which regulates, in particular, the security measures LinkedIn must observe and in which LinkedIn has agreed to fulfill data subject rights. This joint responsibility is limited to the collection of data by and its transmission to LinkedIn Ireland Unlimited Company; any further processing, particularly transmission to the parent company, LinkedIn Corporation in the USA, is the sole responsibility of LinkedIn Ireland Unlimited Company. Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Basis for third-country transfers: Data Privacy Framework (DPF). Privacy policy: linkedin.com/legal/privacy-policy. Joint Controller Addendum: legal.linkedin.com/pages-joint-controller-addendum. Opt-out: linkedin.com/psettings/guest-controls/retargeting-opt-out.

Plug-ins and embedded features and content

We integrate functional and content elements into our online services that are retrieved from the servers of their respective providers ("third-party providers"), such as graphics, videos, or maps. This integration requires that the third-party providers process the users' IP addresses, as they would otherwise be unable to send the content to the users' browsers. Third-party providers may also use pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes.

  • Types of data processed: Usage data; meta, communication, and process data; location data.
  • Data subjects: Users (e.g., website visitors).
  • Purposes of processing: Provision of our online services and user-friendliness.
  • Legal bases: Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).

Google Maps: We integrate maps from the service "Google Maps" provided by Google. The processed data may include, in particular, users' IP addresses and location data. Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Legal basis: Consent (Art. 6(1)(a) GDPR). Basis for third-country transfers: Data Privacy Framework (DPF). Website: mapsplatform.google.com. Privacy policy: policies.google.com/privacy.

Contact

If you have any questions regarding the processing of your personal data or wish to exercise your data subject rights, please contact: info@palary.io.

In accordance with data protection laws (specifically the new version of the BDSG and the European General Data Protection Regulation "GDPR"), we provide the following information regarding the nature, scope, and purpose of the processing of personal data by Palary GmbH. These privacy policies also apply to our website, mobile application (app), and all services. For definitions of terms such as "personal data" or "processing," please refer to Art. 4 of the GDPR. The German version of this privacy policy is the only legally binding version.