GDPR
Information Pursuant to Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679
Preamble and Scope
This GDPR Privacy Notice (hereinafter "GDPR Notice") constitutes the comprehensive, statutorily required information disclosure mandated by Chapter III, Articles 13 and 14 of the Regulation (EU) 2016/679 (the "GDPR"). This Notice is exclusively and specifically addressed to natural persons (Data Subjects) who are habitually resident in the European Economic Area (EEA), the United Kingdom, or Switzerland, and whose Personal Data is processed by the Operator in connection with the Bookmer ecosystem, including Bookmer Core, Bookmer ID, LoginSign, and all associated sub-services, mobile applications, browser extensions, and APIs (collectively, the "Services"). The Operator adopts the principles of data protection by design and by default, as codified in Art. 25 GDPR, and maintains rigorous internal records of processing activities (Art. 30 GDPR) to ensure ongoing accountability and transparency.
Controller, Representative, and Contact Details (embedded)
Identity of the Data Controller
For the purposes of the GDPR, the entity responsible for determining the purposes and means of the processing of Personal Data described herein (the "Controller" or "Operator") is:
Gabriel Sgroi
Charlottenstr. 47,
73230 Kirchheim unter Teck,
Germany.
Designated Contact for Privacy and Data Subject Requests
All formal communications, requests for information, data subject access requests (DSARs), objections to processing, and any correspondence regarding data protection matters shall be directed exclusively to the following contact point, which serves as the primary interface for all GDPR-related inquiries: support@mail.bookmer.com. This address is permanently monitored by the Controller's internal privacy handling team, and the Controller endeavors to acknowledge receipt of any such request within a maximum of forty-eight (48) hours and to provide a substantive response within the statutory timeframe of one (1) month, as mandated by Art. 12(3) GDPR. Should the Controller require an extension of an additional two (2) months due to the complexity or number of requests, the Data Subject shall be informed within the initial one-month period, along with the reasons for the delay.
Absence of a Mandatory Data Protection Officer
As stipulated in Article 37 of the GDPR, the Controller is exempt from the mandatory appointment of a Data Protection Officer (DPO), as the core processing activities of the Bookmer Services do not consist of: (a) large-scale, systematic monitoring of data subjects; nor (b) the large-scale processing of special categories of data (Art. 9 GDPR) or criminal conviction data (Art. 10 GDPR). Notwithstanding this exemption, the Controller maintains comprehensive technical and organizational measures (TOMs) to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, and has designated an internal privacy lead responsible for ensuring compliance with this Notice and responding to supervisory authority inquiries.
Categories of Data Subjects
Enumeration of Affected Individuals
The Controller processes Personal Data pertaining to the following distinct categories of Data Subjects, which are essential for the provisioning and administration of the digital ecosystem:
Registered Users: Individuals who have created a Bookmer ID account, irrespective of whether they utilize the free tier or a paid subscription, and who actively store, organize, share, or manage bookmarks, folders, collections, and related content through Bookmer Core.
Visitors: Individuals who browse public Bookmer pages, public user profiles, public collections, or public shared links without necessarily being logged into an account or having completed the registration process.
End-Users of Developer Applications: Individuals who authenticate into third-party Developer Applications through the Bookmer ID OAuth 2.0/OpenID Connect identity layer, thereby transmitting specific profile attributes to the Developer with the End-User's explicit, granular consent.
Payers and Billing Contacts: Individuals whose financial information, invoice addresses, payment histories, and subscription transaction logs are processed in connection with paid subscriptions, lifetime licenses, or add-on purchases.
Support Contacts: Individuals who voluntarily initiate correspondence with the Controller's support or legal teams via email, contact forms, live chat interfaces, or social media direct messages, thereby providing their contact details and the content of their inquiry.
Technical Administrators: System administrators, developers, team members, and authorized agents associated with business, team, or enterprise accounts who are granted specific access privileges to manage account settings, user permissions, or API integrations.
Individuals Referenced in User Content: Natural persons who are indirectly referenced, tagged, mentioned, named, or otherwise identified within bookmarks, notes, descriptions, comments, public collections, or other User Content submitted by other Users, and whose Personal Data is thereby processed incidentally by the Controller.
ARTICLE III: CATEGORIES OF PERSONAL DATA PROCESSED
Exhaustive Inventory of Data Elements
The Controller processes the following exhaustive categories of Personal Data, which are collected, stored, transmitted, and otherwise utilized in strict accordance with the principles of data minimization and purpose limitation (Art. 5(1)(b) and (c) GDPR), ensuring that only data strictly necessary for the specific processing purpose is collected:
Account and Profile Data: Full legal name (where voluntarily provided and not mandatory), chosen username, display alias, profile picture (where uploaded), biographical description or tagline, primary and secondary email addresses (including recovery addresses), hashed password credentials (salted and hashed using industry-standard cryptographic algorithms), passkey metadata (public key credentials, relying party identifiers, and credential IDs), account status (active, suspended, deleted), and granular privacy and security settings (e.g., two-factor authentication configuration, recovery codes).
Authentication and Session Data: IP addresses (both IPv4 and IPv6) from which login attempts and API requests originate, login and logout timestamps with precise date and time, session identifiers and refresh token activity logs, browser fingerprints (strictly limited to the user-agent string, accepted language headers, and common HTTP headers, excluding full canvas fingerprinting), OAuth consent logs (including the Developer Application requested, scopes authorized, and the timestamp of consent), multi-factor authentication (MFA) verification records (including the method used, such as authenticator app, SMS, or passkey), and the geographical origin of the authentication request (derived from the IP address).
Bookmer Content and Metadata: All user-created and user-uploaded content, including but not limited to stored hyperlinks (URLs), custom folder hierarchies and subfolder structures, user-defined tagging taxonomies (tags), collected notes and annotations appended to bookmarks, comments added to public or private collections, customizable style preferences (CSS variables, background wallpaper selections, accent color choices, typography preferences, and layout configuration settings), imported data from third-party bookmark services, and automated metadata extracted from linked websites (Open Graph titles, descriptions, preview images, and favicons).
Public Page Data: All information designated by the User as "Public," "Unlisted," or "Published," including public profile page content (username, display name, avatar, description), public collection titles and descriptions, public comment threads, public shares, and associated engagement metrics (view counts, external share counts, and interaction analytics generated by other Users or visitors).
Technical, Log, and Telemetry Data: Device identifiers (where provided by the operating system or browser), operating system type and version, browser type and version, browser language preference, connection timestamps, request and response times, latency measurements, page load durations, crash logs and error reports (generated exclusively for diagnostic, debugging, and error-correction purposes), API call endpoints and frequencies, and CDN access logs.
Payment and Commercial Transaction Data: Billing address (street, city, postal code, country), invoice history (invoice numbers, dates, amounts, and statuses), transaction IDs from payment processors, the last four digits of credit or debit cards (PAN truncation in compliance with PCI-DSS standards), subscription status (active, cancelled, paused, expired), and subscription tier (free, professional, business, enterprise). The full Primary Account Number (PAN), CVV/CVC codes, and full expiration dates are handled exclusively by third-party payment processors and are not stored on the Controller's servers or databases.
Developer and Integration Data: For registered Developers accessing the Bookmer ID API ecosystem, this includes the Developer Application name, the Developer's legal entity name (where applicable), contact details of technical representatives (email addresses, phone numbers), application description, redirect URIs (universal resource identifiers), client ID and hashed client secret, API usage analytics (request volumes, error rates, endpoint usage patterns), and OAuth consent screen configurations.
Communication and Correspondence Data: Full content of emails, support tickets, contact form submissions, live chat transcripts, social media direct messages, and feedback forms submitted by the User, including any attachments or screenshots provided, as well as the metadata of such communications (sender address, recipient address, timestamps, and subject lines).
Consent Records: Records of consents granted by the User regarding optional data processing activities, including but not limited to consent for the placement of non-essential tracking cookies (analytics, marketing), consent for receiving promotional newsletters or marketing communications, and consent for specific advanced profiling activities, including the timestamp of the consent, the specific consent text, the version of the consent form, and the withdrawal status of the consent where applicable.
Abuse Prevention and Security Logs: Transactional logs relating to rate-limiting enforcement, suspicious activity flagging (e.g., credential stuffing attempts, brute-force attacks), spam filtering decisions, automated security incident response triggers (e.g., IP blacklisting, session invalidation), and email deliverability monitoring logs (bounce rates, complaint rates, spam trap hits).
ARTICLE IV: SOURCES FROM WHICH PERSONAL DATA IS OBTAINED
Direct Provision by the Data Subject
The vast majority of Personal Data is provided directly and voluntarily by the Data Subject upon registration, during account configuration, via the upload of User Content, through the submission of support inquiries, or through the voluntary participation in surveys, feedback forms, or promotional activities. This includes all profile data, bookmarks, notes, and communications.
Automated Generation and System Observation
The Controller automatically generates and logs technical data, session data, telemetry data, and security logs through the inherent operation of the IT infrastructure, including server logs, load balancer metrics, API gateway analytics, content delivery network (CDN) access logs, and database query logs. This generation occurs as a necessary byproduct of delivering the Services and does not require active input from the Data Subject.
Third-Party Authentication Providers
Should the User opt to sign up or log in using an external identity provider (e.g., Google LLC, Apple Inc., GitHub, Inc., or other federated authentication services), the Controller may receive specific profile attributes from that external provider, strictly limited to the scopes authorized by the User during the federated authentication flow. These attributes typically include the User's email address, display name, profile picture URL, and unique identifier from the external provider. The Controller does not request or receive any additional data beyond what is explicitly authorized.
External Website Metadata Scraping
When a User adds a bookmark by submitting a URL, the Controller's backend systems send automated, best-effort HTTP GET requests to the target external URL for the sole and exclusive purpose of scraping Open Graph metadata, page titles, meta descriptions, and favicons to generate a link preview. The Controller does not intentionally collect, store, or process Personal Data from these external sites beyond what is strictly necessary to generate a static preview, and the Controller does not index or retain the full content of the external page beyond the standard metadata elements.
Payment Processors and Financial Institutions
The Controller receives a confirmation of payment, invoice data, and a client-side tokenized representation of the User's payment method from third-party processors (including Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A., Apple Inc., and Google LLC) for billing reconciliation, subscription management, and tax compliance purposes. The Controller does not receive full credit card numbers or bank account details; it receives only transaction confirmations, the last four digits of the payment method, and the billing address.
Connected Applications and OAuth Scopes
For Developer Applications that integrate Bookmer ID, the Controller's OAuth server transmits the specific Personal Data elements corresponding to the scopes requested by the Developer, but only upon the explicit, granular, and informed consent of the End-User, who is presented with a transparent consent screen enumerating the exact data fields to be transmitted.
Purposes of Processing and Legal Bases (art. 6 GDPR)
Contractual Performance (Art
6(1)(b) GDPR). The processing of Account Data, Authentication Data, and Bookmer Content is strictly necessary for the performance of the contract between the User and the Controller (i.e., to provide, maintain, and deliver the Bookmer Services as requested by the User). This includes, but is not limited to: creating and managing user accounts, enabling synchronization of bookmarks across multiple devices, facilitating public sharing and private storage, processing subscriptions and payments, providing customer support for account-specific technical issues, and enabling Developer API integrations as requested by the User. Without the processing of this data, the Controller would be unable to fulfill its contractual obligations, and the Services could not be provided.
Legitimate Interests Pursued by the Controller (Art
6(1)(f) GDPR). The Controller processes certain Personal Data based on a legitimate interest that is not overridden by the data subject's fundamental rights and freedoms, as per the balancing test required by Recital 47 of the GDPR. The specific legitimate interests pursued by the Controller are:
Security and Platform Integrity: Detecting, preventing, and responding to fraud, phishing, credential-stuffing attacks, brute-force attempts, denial-of-service attacks, and other malicious activities to ensure the provision of a secure and trustworthy service for all Users. This includes the processing of security logs, IP addresses, and authentication metadata.
Service Reliability and Troubleshooting: Maintaining network and information security, including the monitoring of technical logs to diagnose errors, fix bugs, optimize system performance, and prevent service disruptions. This includes the processing of telemetry data, crash logs, and performance metrics.
Product Improvement and Innovation: Analyzing anonymized or pseudonymized usage patterns to enhance user interface ergonomics, improve algorithmic discovery recommendation engines, prioritize feature development, and conduct internal research into user behavior, provided that such research is conducted on aggregated, de-identified data that does not permit re-identification of individual Users.
Direct Marketing for Existing Customers (B2B): Sending transactional and service-related communications (non-marketing) and, where applicable, promoting similar Bookmer products or features to existing business or enterprise Users who have previously purchased related services, subject to the User's right to object under Art. 21 GDPR.
Legal Defense and Enforcement: Establishing, exercising, and defending legal claims, including the enforcement of the Terms of Service, the detection of breaches, and the response to subpoenas, court orders, or other lawful requests from judicial or administrative authorities.
Legal Obligations (Art
6(1)(c) GDPR). The Controller processes data to comply with statutory retention and disclosure obligations imposed by German and European commercial, tax, and anti-money laundering laws, including but not limited to § 147 of the German Fiscal Code (Abgabenordnung - AO) and § 257 of the German Commercial Code (Handelsgesetzbuch - HGB), which mandate the retention of financial and transactional records for a period of up to ten (10) years. Additionally, the Controller processes data as necessary to respond to valid, lawful requests from law enforcement, regulatory authorities (e.g., the Bundesamt für Justiz, the Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg), or courts.
Consent (Art
6(1)(a) GDPR). For optional processing activities that are not contractually required and do not constitute a legitimate interest of the Controller, including the placement of non-essential tracking cookies (analytics, marketing, and social media cookies), the sending of promotional newsletters and marketing communications to natural persons acting in a non-business capacity (B2C), and certain advanced profiling activities involving the creation of detailed behavioral profiles for cross-platform advertising, the Controller obtains the User's explicit, freely given, specific, informed, and unambiguous consent prior to initiating such processing. This consent is obtained through a clear affirmative act (opt-in) via cookie consent banners or separate consent checkboxes, and may be withdrawn at any time with equivalent ease by adjusting the User's account settings, cookie preferences, or by clicking the unsubscribe link in any marketing email.
Recipients and Categories of Processors
Internal Access and Confidentiality
Limited, authorized personnel of the Controller (including software engineers, support staff, security analysts, and product managers) are granted access to Personal Data strictly on a need-to-know basis, governed by internal confidentiality agreements, regular data protection training, and strict role-based access controls (RBAC). All personnel are subject to a duty of confidentiality regarding Personal Data, as mandated by Art. 28(3)(b) GDPR.
External Processors (Data Processing Agreements)
The Controller engages reputable third-party processors to perform specific technical operations on the Controller's behalf. These processors are bound by Data Processing Agreements (DPAs) that comply with Art. 28 GDPR and are subject to the Controller's strict technical and organizational standards. The categories of processors include:
Cloud Hosting and Infrastructure Providers: (e.g., Amazon Web Services / AWS) providing scalable server storage, compute resources, load balancing, and virtual private cloud (VPC) networking.
Relational and Non-Relational Database Providers: Hosting application data, user content, and authentication metadata in secure, encrypted databases.
Email Delivery and Transactional Messaging Services: For sending magic links, verification codes, system notifications, password reset links, and transactional emails (e.g., SendGrid, Mailgun).
Payment Gateways and Financial Processors: (e.g., Stripe, Inc., PayPal (Europe) S.à r.l. et Cie, S.C.A.) for processing financial transactions and subscription billing.
Analytics and Performance Monitoring Providers: For service health checks, error tracking, and pseudonymized usage analytics (e.g., Sentry, Datadog).
Content Delivery Networks (CDNs): For the global, low-latency distribution of static assets (including profile images, thumbnails, favicons, and frontend JavaScript/CSS assets).
Public Recipients of Public Content
When a User designates content as "Public" (including public profiles, public collections, and shared links), this information becomes accessible to the global public internet, including search engine crawlers (e.g., Googlebot, Bingbot, DuckDuckBot), social media preview services (e.g., Open Graph parsers, Twitter/X cards, Facebook Debugger), and any visitor accessing the public URL. The Controller exercises reasonable efforts to honor no-index and no-archive requests where configured, but disclaims control over third-party caching, archiving, or indexing services (e.g., The Internet Archive, Google Cache).
Developer Applications (OAuth Recipients)
Upon explicit, granular authorization by the End-User, the Controller transmits the specific OAuth scopes and associated Personal Data elements to the Developer Application. The Developer acts as an independent, separate Data Controller for the data received and is not under the Controller's direct control or supervision. The Controller does not dictate the Developer's subsequent data processing practices, retention periods, or security measures, and the End-User is strongly urged to review the Developer's separate privacy policy prior to authorizing the OAuth flow.
International Transfers of Personal Data
Transfers to Third Countries
The Controller operates a global, multi-region cloud infrastructure, which necessarily involves the transfer of Personal Data to servers, data centers, and processing facilities located outside the European Economic Area (EEA), including specifically to the United States of America, where the primary cloud infrastructure provider (AWS) and certain sub-processors maintain their principal operations.
Safeguards and Transfer Mechanisms
To ensure an adequate level of data protection for such international transfers, in full compliance with Chapter V of the GDPR and the ruling of the Court of Justice of the European Union in Case C-311/18 (Schrems II), the Controller relies upon the following legally valid transfer mechanisms:
EU Standard Contractual Clauses (SCCs): The Controller has implemented the European Commission's Standard Contractual Clauses for the transfer of Personal Data to third countries (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), specifically Module One (Controller to Controller) for transfers to independent Data Controllers, and Module Two (Controller to Processor) for transfers to third-party processors acting on the Controller's behalf.
Supplementary Technical Measures: In addition to the SCCs, the Controller implements robust supplementary technical measures to ensure data security during transit and at rest, including end-to-end TLS 1.3 encryption for all data in transit, AES-256-GCM encryption for data at rest, pseudonymization and tokenization of identifiable data elements where feasible, and strict access controls to prevent unauthorized access.
Data Protection Impact Assessments (DPIAs): Where required, the Controller conducts comprehensive DPIAs in accordance with Art. 35 GDPR to assess and mitigate the risks associated with international transfers, particularly where the data protection laws of the recipient country do not provide an adequate level of protection.
ARTICLE VIII: RETENTION CRITERIA AND STORAGE LIMITATION
General Retention Principle
The Controller retains Personal Data only for as long as is necessary to fulfill the purposes for which it was collected, in accordance with the principle of storage limitation (Art. 5(1)(e) GDPR). The specific retention periods vary depending on the type of data and the legal or operational context:
Category of Data Retention Period Basis
Account Data (Active Users) For the entire duration of the active account, plus a reasonable transition period (up to 30 days) after account closure to facilitate data export and ensure compliance with post-termination obligations. Contractual necessity.
User Content (Bookmarks, Folders, Notes) For the entire duration of the active account, until the User explicitly deletes the specific content, or for up to 30 days after account termination. User instruction and contractual necessity.
Authentication Logs and Session Data For up to 90 days for active accounts, and up to 12 months in aggregated or anonymized form for security auditing purposes. Legitimate interest in security and fraud prevention.
Billing and Transaction Data For up to ten (10) years from the end of the calendar year in which the transaction occurred. Legal obligation under German tax law (§ 147 AO, § 257 HGB).
Support Correspondence For up to three (3) years from the resolution of the support ticket. Legitimate interest in customer service consistency and legal defense.
Consent Records For the duration of the active consent, plus up to three (3) years after consent is withdrawn to demonstrate compliance. Legal obligation (Art. 7(1) GDPR).
Security Logs and Abuse Records For up to twelve (12) months, after which logs are either deleted or fully anonymized for statistical analysis. Legitimate interest in platform security.
Developer API Usage Logs For up to six (6) months, after which they are aggregated and anonymized. Operational necessity and service monitoring.
Extended Retention for Legal Compliance
Where the Controller is subject to a legal hold, pending litigation, or a valid retention request from law enforcement, the Controller may extend the retention period of specific data beyond the standard periods set forth above. In such cases, the data will be segregated and encrypted, and will not be processed for any purpose other than fulfilling the specific legal obligation.
Your GDPR Rights (data Subject Rights)
Exhaustive Enumeration of Rights
As a Data Subject located within the EEA, UK, or Switzerland, you are entitled to the following rights under the GDPR, which the Controller is obligated to facilitate and respond to, free of charge, subject to the conditions and exceptions set forth in the GDPR:
Right of Access (Art
15 GDPR): You have the right to obtain from the Controller confirmation as to whether or not Personal Data concerning you is being processed, and, where that is the case, access to the Personal Data and the following information: the purposes of the processing; the categories of Personal Data concerned; the recipients to whom the Personal Data have been or will be disclosed; the envisaged retention period; the existence of automated decision-making; and the appropriate safeguards for international transfers. The Controller shall provide a copy of the Personal Data undergoing processing, free of charge, and may charge a reasonable fee for any additional copies requested.
Right to Rectification (Art
16 GDPR): You have the right to obtain from the Controller the rectification of inaccurate Personal Data concerning you without undue delay, and the right to have incomplete Personal Data completed, including by means of providing a supplementary statement.
Right to Erasure (Right to be Forgotten) (Art
17 GDPR): You have the right to obtain from the Controller the erasure of Personal Data concerning you without undue delay where one of the following grounds applies: (i) the Personal Data is no longer necessary in relation to the purposes for which it was collected; (ii) you withdraw consent on which the processing is based (where applicable); (iii) you object to processing pursuant to Art. 21(1); (iv) the Personal Data has been unlawfully processed; or (v) the Personal Data has to be erased for compliance with a legal obligation. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation (e.g., tax retention) or for the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing (Art
18 GDPR): You have the right to obtain from the Controller restriction of processing where: (i) you contest the accuracy of the Personal Data; (ii) the processing is unlawful and you oppose erasure; (iii) the Controller no longer needs the Personal Data for processing but you require it for legal claims; or (iv) you have objected to processing pursuant to Art. 21(1) pending verification of whether the legitimate grounds of the Controller override your interests.
Right to Data Portability (Art
20 GDPR): You have the right to receive the Personal Data concerning you, which you have provided to the Controller, in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another controller without hindrance from the Controller, where: (i) processing is based on consent or a contract; and (ii) processing is carried out by automated means. This right includes the right to have the Personal Data transmitted directly from the Controller to another controller, where technically feasible.
Right to Object (Art
21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to processing of Personal Data concerning you which is based on legitimate interests (Art. 6(1)(f)) or for direct marketing purposes. The Controller shall no longer process the Personal Data unless the Controller demonstrates compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
Right to Withdraw Consent (Art
7(3) GDPR): Where processing is based on consent (Art. 6(1)(a)), you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to Lodge a Complaint (Art
77 GDPR): You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of Personal Data concerning you infringes the GDPR. The competent supervisory authority for the Controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg, Germany.
ARTICLE X: AUTOMATED DECISION-MAKING AND PROFILING (ART. 22 GDPR)
Automated Decision-Making
The Controller does not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22(1) and (4) GDPR, without a separate legal basis or required safeguards. The Services do not utilize fully automated algorithms to make decisions regarding creditworthiness, employment, health, insurance, or similar matters.
Automated Security and Abuse Checks
The Services employ automated machine learning and rule-based algorithms to conduct security screening, spam detection, phishing detection, rate-limiting, and abuse prevention. These automated checks are inherent to the provision of secure services and do not constitute "automated decision-making" as defined in Art. 22 GDPR, as they are strictly necessary for entering into and performing the contract (Art. 22(2)(a) GDPR) and are authorized by EU or Member State law (Art. 22(2)(b) GDPR). These checks do not produce legal effects concerning you in the absence of human intervention; any significant action (e.g., account suspension) is subject to human review upon appeal.
Complaints and Supervisory Authority
Right to Lodge a Complaint
Without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work, or place of the alleged infringement, if the Data Subject considers that the processing of personal data relating to him or her infringes the GDPR. The supervisory authority with jurisdiction over the Controller is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Baden-Württemberg
Königstraße 10a,
70173 Stuttgart,
Germany.
Internal Complaint Resolution
Prior to lodging a complaint with the supervisory authority, the Controller encourages the Data Subject to contact the Controller directly to allow for an internal resolution of the issue. The Controller shall respond to all legitimate complaints within a reasonable time frame and shall provide the Data Subject with information regarding the status of the complaint and the outcome of any investigation.
BY REGISTERING FOR, ACCESSING, OR USING THE BOOKMER SERVICES, THE DATA SUBJECT ACKNOWLEDGES THAT THEY HAVE READ, UNDERSTOOD, AND AGREE TO THE DATA PROCESSING PRACTICES DESCRIBED IN THIS GDPR PRIVACY NOTICE.