CCPA/CPRA

Notice at Collection and Privacy Policy Pursuant to the California Consumer Privacy Act of 2018, as Amended by the California Privacy Rights Act (CPRA)

Preamble and Legal Foundation

This CCPA/CPRA Privacy Notice (hereinafter "CPRA Notice" or "this Notice") is a comprehensive, standalone, and legally binding disclosure document provided by the Operator (as defined herein) to natural persons who are residents of the State of California (hereinafter "Consumers" or "California Residents") and whose Personal Information (as defined in Cal. Civ. Code § 1798.140(v)) is collected, processed, stored, shared, or otherwise handled by the Operator in connection with the Bookmer ecosystem, including Bookmer Core, Bookmer ID, LoginSign, and all associated sub-services, mobile applications, browser extensions, and APIs (collectively, the "Services").

This Notice is promulgated in strict compliance with the California Consumer Privacy Act of 2018 (California Civil Code §§ 1798.100 et seq., as amended by the California Privacy Rights Act of 2020, effective January 1, 2023) (collectively, the "CCPA/CPRA" or "the Act"), and the implementing regulations promulgated by the California Privacy Protection Agency (CPPA) codified in California Code of Regulations, Title 11, Division 6. This Notice serves a dual statutory function: (a) it constitutes the mandatory "Notice at Collection" required under Cal. Civ. Code § 1798.100(a)(1)(B), informing Consumers of the categories of Personal Information to be collected and the purposes for which such information will be used, at or before the point of collection; and (b) it constitutes the comprehensive "Privacy Policy" required under Cal. Civ. Code § 1798.130(a)(5), detailing Consumers' rights, the methods for exercising such rights, and the Operator's data handling practices over the preceding twelve (12) months.

Interpretive Note: For the avoidance of doubt, the terms "Personal Information," "Sensitive Personal Information," "Business Purpose," "Commercial Purpose," "Sell," "Share," "Third Party," "Service Provider," "Contractor," and "Consumer" shall be interpreted strictly in accordance with their statutory definitions under Cal. Civ. Code § 1798.140 and the CPRA regulations. To the extent that any provision of this Notice conflicts with the statutory definitions, the statutory definitions shall prevail.

Business Owner, Controller, and Contact Details (embedded)

Identity of the Business

For the purposes of the CCPA/CPRA, the entity that determines the purposes and means of the processing of Personal Information, and which is the legal entity operating the Bookmer ecosystem (the "Business" or "Operator"), is:

Gabriel Sgroi

Charlottenstr. 47,

73230 Kirchheim unter Teck,

Germany.

Designated Contact for Consumer Rights Requests

In accordance with Cal. Civ. Code § 1798.130(a)(2), the Business has established a dedicated and toll-free mechanism for all California Consumers to exercise their statutory rights. All verifiable consumer requests (VCRs) pertaining to the rights to know, access, delete, correct, opt-out, and limit the use of sensitive personal information, as well as all general privacy inquiries, shall be submitted to the following designated contact address, which is actively monitored by the Business's internal compliance team: support@mail.bookmer.com. The Business commits to acknowledging receipt of a consumer request within a maximum of ten (10) business days from the date of receipt, as mandated by Cal. Civ. Code § 1798.130(a)(3), and to providing a substantive response to the request within forty-five (45) calendar days, subject to a reasonable extension of an additional forty-five (45) days where reasonably necessary and upon prior notice to the Consumer.

No Sale of Personal Information

The Business does not, and has not in the preceding twelve (12) months, "sold" Personal Information in exchange for monetary compensation, as that term is traditionally understood. The Business does, however, engage in certain data sharing activities that may be interpreted as "sharing" under the broad definition in Cal. Civ. Code § 1798.140(ad)(1) (i.e., cross-context behavioral advertising) when using third-party analytics tools. Such "sharing" is done to improve the Services and is subject to the Consumer's right to opt-out, as detailed in Article IX of this Notice.

Categories of Personal Information Collected and Disclosed (past 12 Months)

Exhaustive Inventory of Categories

Over the preceding twelve (12) months preceding the effective date of this Notice, the Business has collected, and may continue to collect, the following statutory categories of Personal Information from Consumers, as defined in Cal. Civ. Code § 1798.140(v):

Statutory Category (CCPA) Specific Data Elements Collected Collected?

A. Identifiers. Full legal name (where voluntarily provided), username, email address, IP address, account alias, unique Bookmer ID, third-party OAuth ID (e.g., Google/Apple ID), and postal address (for billing). YES

B. Personal Information Categories Listed in Cal. Civ. Code § 1798.80(e). Full name, signature (where provided on physical contracts), physical address, telephone number, credit/debit card number (last four digits only; full PAN stored by processor), and bank account information (where direct debit is activated). YES

C. Characteristics of Protected Classifications. The Business does not intentionally collect or process such data. Users may voluntarily include such information in their User Content (bookmarks, notes) but this is not systematically tracked. NO (Inadvertent)

D. Commercial Information. Records of products or services purchased, obtained, or considered (subscription tier, add-ons), billing history, and transaction logs. YES

E. Biometric Information. The Business does not collect, store, or process fingerprints, faceprints, voiceprints, iris scans, or similar biometric data. Passkeys are cryptographically hashed and stored locally on the user's device; they are not transmitted to the Business's servers. NO

F. Internet or Other Electronic Network Activity Information. Browsing history (solely limited to the URLs saved by the User as bookmarks), clickstream data on the Bookmer platform, session duration, scroll depth, browser type, operating system, language preferences, and interaction with the user interface (features clicked). YES

G. Geolocation Data. Approximate location derived from IP address (city, state, country). Precise GPS coordinates are not collected. YES (Approx.)

H. Sensory Data. The Business does not collect audio, electronic, visual, thermal, olfactory, or similar information. NO

I. Professional or Employment-Related Information. Where a User registers a business or enterprise account, the Business may collect job title, company name, and professional email address. YES

J. Education Information. The Business does not collect education records or information. NO

K. Inferences Drawn from Personal Information. The Business may generate pseudonymized profiles reflecting user preferences (e.g., preferred categories of bookmarks, link types, usage frequency) to personalize recommendations and improve the discovery algorithm. However, these profiles are not used for targeted advertising outside the platform. YES

L. Sensitive Personal Information (CPRA). The Business does not collect: Social Security numbers, driver's license numbers, state ID cards, passport numbers, racial/ethnic origin, religious/philosophical beliefs, union membership, genetic data, or precise geolocation. The Business collects only email addresses and passwords (hashed), which are processed strictly for account authentication. NO

ARTICLE III: SOURCES FROM WHICH PERSONAL INFORMATION IS OBTAINED

Direct Provision by the Consumer

The vast majority of Personal Information is provided directly and voluntarily by the Consumer upon registration, during account configuration, via the upload of User Content, through the submission of support inquiries, or through the voluntary participation in surveys, feedback forms, or promotional activities.

Automated Generation and System Observation

The Business automatically generates and logs technical data, session data, telemetry data, and security logs through the inherent operation of the IT infrastructure, including server logs, load balancer metrics, API gateway analytics, content delivery network (CDN) access logs, and database query logs.

Third-Party Authentication Providers

Should the Consumer opt to sign up or log in using an external identity provider (e.g., Google LLC, Apple Inc., GitHub, Inc.), the Business may receive specific profile attributes from that external provider, strictly limited to the scopes authorized by the Consumer during the federated authentication flow, typically including the Consumer's email address, display name, profile picture URL, and unique identifier.

External Website Metadata Scraping

When a Consumer adds a bookmark by submitting a URL, the Business's backend systems send automated HTTP GET requests to the target external URL for the sole purpose of scraping Open Graph metadata, page titles, meta descriptions, and favicons to generate a link preview.

Payment Processors and Financial Institutions

The Business receives a confirmation of payment, invoice data, and a client-side tokenized representation of the Consumer's payment method from third-party processors (including Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A., Apple Inc., and Google LLC) for billing reconciliation, subscription management, and tax compliance purposes.

Purposes for Which Personal Information Is Used

Business Purposes

The Business collects and uses Personal Information for the following essential business purposes, as defined in Cal. Civ. Code § 1798.140(d):

Providing the Services: Creating and managing user accounts, enabling synchronization of bookmarks across multiple devices, facilitating public sharing and private storage, processing subscriptions and payments, and providing customer support.

Security and Integrity: Detecting, preventing, and responding to fraud, phishing, credential-stuffing attacks, denial-of-service attacks, and other malicious activities to ensure the provision of a secure service.

Debugging and Troubleshooting: Identifying and repairing errors in the Services, including the monitoring of technical logs to diagnose errors, fix bugs, and optimize system performance.

Short-Term, Transient Use: Temporary, non-persistent use of Personal Information to enable the real-time display of content and to provide interactive features.

Service Improvement: Analyzing usage patterns to enhance user interface ergonomics, improve algorithmic discovery recommendation engines, and prioritize feature development, provided that such analysis is conducted on aggregated, de-identified data.

Legal Compliance: Complying with statutory retention and disclosure obligations imposed by applicable laws, regulations, and judicial orders.

Commercial Purposes

The Business uses Personal Information for the following commercial purposes, as defined in Cal. Civ. Code § 1798.140(e):

Transaction Processing: Processing subscriptions, lifetime licenses, and add-on purchases through third-party payment processors.

Customer Communication: Sending transactional and service-related communications (non-marketing) and, where applicable, promoting similar Bookmer products or features to existing business or enterprise Consumers.

Product Development: Conducting internal research into user behavior, preferences, and usage patterns to develop new features, services, and product offerings.

ARTICLE V: CATEGORIES OF PERSONAL INFORMATION DISCLOSED FOR A BUSINESS PURPOSE (PAST 12 MONTHS)

Third-Party Service Providers

The Business has disclosed the following categories of Personal Information to third-party Service Providers (as defined in Cal. Civ. Code § 1798.140(ag)) for business purposes:

Statutory Category (CCPA) Categories of Recipients Purpose of Disclosure

A. Identifiers. Cloud hosting providers (AWS), email delivery services, payment processors, analytics providers. Service provision, authentication, billing.

F. Internet/Network Activity. Analytics providers, performance monitoring providers, CDN providers. Service optimization, error tracking.

G. Geolocation Data (Approx.). Cloud hosting providers, security monitoring providers. Fraud prevention, access control.

I. Professional Info. Email delivery services, support ticketing systems. Communication, customer support.

K. Inferences. Product analytics platforms. Product improvement.

No Sale of Personal Information

The Business has not sold any Personal Information to third parties in exchange for monetary compensation in the preceding twelve (12) months. The Business does, however, engage in limited "sharing" of Personal Information (as defined in Cal. Civ. Code § 1798.140(ad)(1)) with analytics providers for the purpose of measuring user engagement and improving the Services.

Sensitive Personal Information (CPRA)

Absence of Processing

The Business does not collect, process, or retain any Sensitive Personal Information as defined in Cal. Civ. Code § 1798.140(ae), including but not limited to Social Security numbers, driver's license numbers, passport numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, or biometric data for identification purposes.

Limited Processing of Authentication Credentials

The Business processes email addresses and passwords (hashed and salted) for the sole and exclusive purpose of authenticating Consumer accounts and providing the requested Services. This processing is strictly necessary and does not trigger the CPRA's provisions regarding the "limit the use of sensitive personal information" right, as the purpose is inherent to the service requested (Cal. Civ. Code § 1798.121(c)(3)).

Retention Criteria

General Retention Principle

The Business retains Personal Information only for as long as is reasonably necessary to fulfill the purposes for which it was collected, and in accordance with the retention standards set forth in the California Code of Regulations, Title 11, § 7005. The specific retention periods vary depending on the type of data and the legal or operational context:

Category of Data Retention Period Basis

Account Data (Active Consumers) For the entire duration of the active account, plus a reasonable transition period (up to 30 days) after account closure to facilitate data export. Service provision.

User Content For the entire duration of the active account, until the Consumer explicitly deletes the specific content, or for up to 30 days after account termination. Consumer instruction.

Authentication Logs For up to 90 days for active accounts, and up to 12 months in aggregated form. Security and fraud prevention.

Billing and Transaction Data For up to ten (10) years from the end of the calendar year in which the transaction occurred. Legal obligation (tax compliance).

Support Correspondence For up to three (3) years from the resolution of the support ticket. Customer service consistency.

Security Logs For up to twelve (12) months. Platform security.

Extended Retention for Legal Compliance

Where the Business is subject to a legal hold, pending litigation, or a valid retention request from law enforcement, the Business may extend the retention period of specific data beyond the standard periods set forth above.

California Consumer Rights (CCPA/CPRA)

Exhaustive Enumeration of Rights

California Consumers are entitled to the following specific rights under the CCPA/CPRA, which the Business is obligated to facilitate and respond to in a timely, verifiable, and cost-free manner, subject to the statutory exceptions set forth in the Act:

Right to Know (Access) (Cal

Civ. Code § 1798.100, § 1798.110). You have the right to request that the Business disclose to you the following information covering the twelve (12)-month period preceding your request: (i) the categories of Personal Information collected about you; (ii) the specific pieces of Personal Information collected about you; (iii) the categories of sources from which the Personal Information is collected; (iv) the business or commercial purpose for collecting or sharing the Personal Information; (v) the categories of third parties with whom the Business shares the Personal Information; and (vi) the categories of Personal Information disclosed for a business purpose.

Right to Delete (Cal

Civ. Code § 1798.105). You have the right to request that the Business delete any Personal Information about you which the Business has collected from you, subject to certain statutory exceptions, including where the Business needs to retain the information to complete the transaction for which the Personal Information was collected, to detect security incidents, to protect against fraudulent or illegal activity, or to comply with a legal obligation.

Right to Correct (Cal

Civ. Code § 1798.106). You have the right to request that the Business correct inaccurate Personal Information that the Business maintains about you, taking into account the nature of the Personal Information and the purposes of the processing of the Personal Information.

Right to Opt-Out of Sale/Sharing (Cal

Civ. Code § 1798.120). You have the right to direct the Business to stop "selling" your Personal Information to third parties and to stop "sharing" your Personal Information for cross-context behavioral advertising. The Business does not "sell" Personal Information for monetary compensation. However, to the extent the Business engages in "sharing" with analytics providers, Consumers may opt-out by clicking the "Do Not Sell or Share My Personal Information" link in the account settings or by enabling a Global Privacy Control (GPC) signal.

Right to Limit Use of Sensitive Personal Information (Cal

Civ. Code § 1798.121). You have the right to direct the Business to limit its use of your Sensitive Personal Information to that use which is necessary to perform the Services or as otherwise permitted by law. The Business does not collect Sensitive Personal Information for purposes other than those permitted by law.

Right to Non-Discrimination (Cal

Civ. Code § 1798.125). The Business will not discriminate against you for exercising any of your CCPA/CPRA rights. Specifically, the Business will not deny goods or services, charge different prices or rates, or provide a different level or quality of services to Consumers who exercise their rights, unless the difference is reasonably related to the value provided by the Consumer's data.

Shine the Light (Cal

Civ. Code § 1798.83). California Civil Code Section 1798.83 permits California residents to request certain information regarding the Business's disclosure of Personal Information to third parties for their direct marketing purposes. The Business does not disclose Personal Information to third parties for their direct marketing purposes without prior consent.

ARTICLE IX: EXERCISING YOUR RIGHTS AND VERIFICATION PROCESS

Submitting a Request

To exercise any of the above rights, please submit a verifiable consumer request to the Business via the designated contact address: support@mail.bookmer.com. You may also submit a request through your account settings panel, where available.

Verification Process

The Business is required to verify that the person making the request is the Consumer about whom the Business has collected Personal Information or an authorized agent of such Consumer. To verify your identity, the Business may ask you to provide certain information matching the information the Business already maintains about you, such as your email address, username, or recent transaction history. The Business will not require you to provide Sensitive Personal Information for verification purposes.

Authorized Agents

You may designate an authorized agent to make a request on your behalf. The authorized agent must provide proof of your written authorization or a valid power of attorney, and the Business may require the authorized agent to verify their own identity with the Business.

Response Timing and Format

The Business will acknowledge receipt of your request within ten (10) business days and will respond to the request within forty-five (45) calendar days. The Business may extend the response period by an additional forty-five (45) days where reasonably necessary, with prior notice to you. The Business will deliver the requested information in a portable, and, to the extent technically feasible, in a readily usable format that allows you to transmit the information to another entity without hindrance.

Minors and COPPA Compliance

No Sale of Minors' Data

The Business does not knowingly collect Personal Information from minors under the age of sixteen (16) and does not sell or share the Personal Information of minors under the age of sixteen (16). If the Business becomes aware that it has collected Personal Information from a minor under the age of thirteen (13), or under the age of sixteen (16) without opt-in consent where required, the Business will take steps to delete such information promptly.

Parental Consent

Where the Business becomes aware that a minor under the age of thirteen (13) has provided Personal Information without verifiable parental consent, such data will be deleted from the Business's active databases in accordance with the Business's data deletion procedures.

Do Not Track and Global Privacy Control

Global Privacy Control (GPC)

The Business respects the Global Privacy Control (GPC) signal, an opt-out preference signal transmitted by a user's browser or device. If the Business detects a GPC signal from your browser, the Business will treat this as a valid opt-out request and will not process or "share" your Personal Information for cross-context behavioral advertising purposes. The GPC signal, where properly configured, shall be sufficient to effectuate a verifiable consumer request to opt-out of sharing.

Do Not Track (DNT)

The Business does not respond to Do Not Track (DNT) signals due to the lack of a consistent industry standard. However, the Business's practices are fully compliant with the CPRA's requirements regarding the treatment of opt-out preference signals.

Changes to This CPRA Notice

Updates and Revisions

The Business reserves the right to modify, update, or revise this CPRA Notice from time to time to reflect changes in the Services, changes in applicable law, or changes in the Business's data processing practices. The Business will post any material changes to this Notice on the Bookmer website and will provide a prominent notice of such changes (e.g., via email to registered Consumers or via a notification upon the next login).

Effective Date of Changes

Any modifications to this Notice shall become effective as of the date posted. The Consumer's continued use of the Services following the posting of any revised Notice constitutes the Consumer's acceptance of such changes. Consumers are encouraged to periodically review this Notice to stay informed about how their Personal Information is being protected.

Contact and Further Information

Privacy Inquiries

If you have any questions, comments, or concerns regarding this CPRA Notice, the Business's privacy practices, or your California privacy rights, please do not hesitate to contact the Business using the designated contact address embedded in Article I of this Notice: support@mail.bookmer.com.

Response Timeframe

The Business endeavors to respond to all privacy inquiries and consumer requests within the statutory timeframes set forth in the CCPA/CPRA (ten (10) business days for acknowledgment; forty-five (45) calendar days for substantive response). Consumers who are dissatisfied with the Business's response may contact the California Privacy Protection Agency (CPPA) or the Office of the Attorney General of California to lodge a complaint.

BY REGISTERING FOR, ACCESSING, OR USING THE BOOKMER SERVICES, THE CALIFORNIA CONSUMER ACKNOWLEDGES THAT THEY HAVE READ, UNDERSTOOD, AND AGREE TO THE PRIVACY PRACTICES DESCRIBED IN THIS CCPA/CPRA PRIVACY NOTICE.