GDPR
1. GDPR Information (Articles 13 and 14 GDPR)
This page contains the dedicated GDPR information for Bookmer, Bookmer ID and LoginSign. It summarizes the information required under Articles 13 and 14 GDPR in one separate legal area.
Controller
Gabriel Sgroi, Charlottenstr. 47, 73230 Kirchheim unter Teck, Germany. Email: support@mail.bookmer.com.
Data Protection Officer
No data protection officer has been appointed because no appointment is currently required for the Services. Privacy requests can be sent to the controller using the contact address above.
Categories of Data Subjects
Users, account holders, visitors of public Bookmer pages, recipients of transactional emails, support contacts, developers, team members, payment contacts and people who are named or referenced in user-submitted content.
Categories of Personal Data
Account data, authentication data, Bookmer content, public-page data, technical data, payment data, communication data, developer and integration data, email delivery data, consent records, security logs and abuse-prevention records.
Sources of Data
Data is provided by you, generated through your use of the Services, imported or created when you add links and content, received from authentication providers, payment providers, email providers, browser clients, public websites used for previews, connected applications, team members or people who contact support.
Purposes and Legal Bases
Contract performance under Art. 6(1)(b) GDPR for accounts, synchronization, publishing, subscriptions and requested features. Legitimate interests under Art. 6(1)(f) GDPR for security, abuse prevention, service reliability, troubleshooting, fraud prevention, product improvement and legal defense. Legal obligations under Art. 6(1)(c) GDPR for tax, accounting, consumer-law and regulatory duties. Consent under Art. 6(1)(a) GDPR for optional cookies, optional analytics, newsletters or other consent-based features.
Recipients and Processors
Hosting, database, storage, email, payment, analytics, crash-reporting, monitoring, security, DNS, content-delivery, support and infrastructure providers may process data on our behalf. Public content may be received by visitors, search engines, messengers, crawlers and social-preview services when you publish or share a page.
International Transfers
Where data is processed outside the European Economic Area, we rely on adequacy decisions, Standard Contractual Clauses or another transfer mechanism required by GDPR.
Retention Criteria
Data is retained for as long as necessary for the account, the requested feature, public availability, billing, support, legal obligations, security, abuse prevention, backups and legal claims. Retention periods differ by data type and may be extended where a legal obligation, dispute, security incident or abuse investigation requires it.
Your GDPR Rights
You may request access, rectification, erasure, restriction, portability, objection and withdrawal of consent where applicable. You also have the right to lodge a complaint with a competent data-protection supervisory authority.
Automated Decision-Making
The Services may use automated security, abuse, rate-limit, spam, phishing or deliverability checks. We do not use automated decision-making that produces legal effects concerning you within the meaning of Art. 22 GDPR without a separate legal basis or required safeguards.